1   1  /  1  页   跳转

[求助] 怎样才能删除该病毒

怎样才能删除该病毒

[D:\Program Files\Thunder Network\Thunder\Plugins\XLSafeHost\ThunderRAV\bin\scanexec.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17]
    [D:\Program Files\Thunder Network\Thunder\Plugins\XLSafeHost\ThunderRAV\bin\unexe.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5]
    [D:\Program Files\Thunder Network\Thunder\Plugins\XLSafeHost\ThunderRAV\bin\scanex.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 75]
    [D:\Program Files\Thunder Network\Thunder\Plugins\XLSafeHost\ThunderRAV\bin\extfile.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 29]
    [D:\Program Files\Thunder Network\Thunder\Plugins\XLSafeHost\ThunderRAV\bin\pearc.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5]
    [D:\Program Files\Thunder Network\Thunder\Plugins\XLSafeHost\ThunderRAV\bin\scanpack.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9]
    [D:\Program Files\Thunder Network\Thunder\Plugins\XLSafeHost\ThunderRAV\bin\revm.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 8]
    [D:\Program Files\Thunder Network\Thunder\Plugins\XLSafeHost\ThunderRAV\bin\urutils.dll]  [, 20, 0, 0, 6]
    [D:\Program Files\Thunder Network\Thunder\Plugins\XLSafeHost\ThunderRAV\bin\ur000.dat]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 18]
    [D:\Program Files\Thunder Network\Thunder\Plugins\XLSafeHost\ThunderRAV\bin\scriptci.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
    [D:\Program Files\Thunder Network\Thunder\Plugins\XLSafeHost\ThunderRAV\bin\ur001.dat]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
    [D:\Program Files\Thunder Network\Thunder\Plugins\XLSafeHost\ThunderRAV\bin\ur023.dat]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 1]
    [D:\Program Files\Thunder Network\Thunder\Plugins\XLSafeHost\ThunderRAV\bin\uroutine.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26]
    [D:\Program Files\Thunder Network\Thunder\Plugins\XLSafeHost\ThunderRAV\bin\scansct.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9]
[PID: 2488 / Administrator][D:\千千静听\TTPlayer.exe]  [Alen Soft, 5, 1, 0, 0]
    [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
    [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [D:\千千静听\ttpcomm.dll]  [N/A, ]
    [D:\千千静听\ttpres.dll]  [Alen Soft, 5, 1, 0, 0]
    [D:\千千静听\msdmo.dll]  [Microsoft Corporation, 6.03.01.0400]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\千千静听\AddIn\ttp_asf.dll]  [N/A, ]
    [D:\千千静听\AddIn\ttp_aac.dll]  [N/A, ]
    [D:\千千静听\AddIn\ttp_ac3dts.dll]  [N/A, ]
    [D:\千千静听\wmadmod.dll]  [Microsoft Corporation, 10.00.00.3646]
[PID: 2152 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [C:\WINDOWS\system32\IEFRAME.dll]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [C:\WINDOWS\system32\IEUI.dll]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [C:\WINDOWS\system32\xmllite.dll]  [Microsoft Corporation, 1.00.1018.0]
    [D:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\Program Files\Internet Explorer\ieproxy.dll]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
    [d:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.5.29]
    [C:\Program Files\Tencent\QQToolbar\IEBar.dll]  [TENCENT, 2, 0, 25, 10]
    [C:\Documents and Settings\Administrator\Application Data\TENCENT\QQToolbar\buttons\Toolbar.dll]  [TENCENT, 2, 0, 25, 10]
    [C:\Documents and Settings\Administrator\Application Data\TENCENT\QQToolbar\buttons\QQMail.dll]  [TENCENT, 2, 1, 1, 12]
    [C:\Documents and Settings\Administrator\Application Data\TENCENT\QQToolbar\buttons\Shuqian.dll]  [TENCENT, 2, 1, 1, 12]
    [C:\Documents and Settings\Administrator\Application Data\TENCENT\QQToolbar\buttons\Wenwen.dll]  [TENCENT, 2, 1, 1, 12]
    [C:\Documents and Settings\Administrator\Application Data\TENCENT\QQToolbar\buttons\Weather.dll]  [TENCENT, 2, 1, 1, 13]
    [C:\Documents and Settings\Administrator\Application Data\TENCENT\QQToolbar\buttons\PopupBlocker.dll]  [TENCENT, 2, 1, 1, 11]
    [C:\Documents and Settings\Administrator\Application Data\TENCENT\QQToolbar\buttons\HighLight.dll]  [TENCENT, 2, 1, 1, 10]
    [C:\Documents and Settings\Administrator\Application Data\TENCENT\QQToolbar\buttons\QQDoctor.dll]  [TENCENT, 2, 1, 1, 10]
    [D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 8, 96]
    [D:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 18]
    [D:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
    [C:\WINDOWS\system32\IEBHO.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\ieapfltr.dll]  [Microsoft Corporation, 7.00.5824.16386]
    [d:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[PID: 4028 / Administrator][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [C:\WINDOWS\system32\IEFRAME.dll]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [C:\WINDOWS\system32\IEUI.dll]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [C:\WINDOWS\system32\xmllite.dll]  [Microsoft Corporation, 1.00.1018.0]
    [D:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\Program Files\Internet Explorer\ieproxy.dll]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
    [d:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.5.29]
    [C:\Program Files\Tencent\QQToolbar\IEBar.dll]  [TENCENT, 2, 0, 25, 10]
    [C:\Documents and Settings\Administrator\Application Data\TENCENT\QQToolbar\buttons\Toolbar.dll]  [TENCENT, 2, 0, 25, 10]
    [C:\Documents and Settings\Administrator\Application Data\TENCENT\QQToolbar\buttons\QQMail.dll]  [TENCENT, 2, 1, 1, 12]
    [C:\Documents and Settings\Administrator\Application Data\TENCENT\QQToolbar\buttons\Shuqian.dll]  [TENCENT, 2, 1, 1, 12]
    [C:\Documents and Settings\Administrator\Application Data\TENCENT\QQToolbar\buttons\Wenwen.dll]  [TENCENT, 2, 1, 1, 12]
    [C:\Documents and Settings\Administrator\Application Data\TENCENT\QQToolbar\buttons\Weather.dll]  [TENCENT, 2, 1, 1, 13]
    [C:\Documents and Settings\Administrator\Application Data\TENCENT\QQToolbar\buttons\PopupBlocker.dll]  [TENCENT, 2, 1, 1, 11]
    [C:\Documents and Settings\Administrator\Application Data\TENCENT\QQToolbar\buttons\HighLight.dll]  [TENCENT, 2, 1, 1, 10]
    [C:\Documents and Settings\Administrator\Application Data\TENCENT\QQToolbar\buttons\QQDoctor.dll]  [TENCENT, 2, 1, 1, 10]
    [D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 8, 96]
    [D:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 18]
    [D:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
    [C:\WINDOWS\system32\IEBHO.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\ieapfltr.dll]  [Microsoft Corporation, 7.00.5824.16386]
    [d:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [D:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 4, 23]
[PID: 3616 / Administrator][F:\xilvx\sreng2\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
    [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [F:\xilvx\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1      localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1756, D:\PROGRAM FILES\STORMII\STORMLIV.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1504, D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\THUNDER5.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2488, D:\千千静听\TTPLAYER.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================

[/CODE]

用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
分享到:
gototop
 

回复:怎样才能删除该病毒

扫SRENG日志发这论坛来
下载SRENG2.6版:http://bbs.ikaka.com/attachment.aspx?attachmentid=399427

1 下载的是压缩包,必须解压缩(建议直接解压到系统Windows文件夹里)
2 运行SREng***.EXE
3 选择主界面左边的:智能扫描=》扫描=》保存报告
4 把报告保存后,直接将日志文件以附件的形式发这论坛来。

一定以附件形式发这论坛来。
点击你自己的主题贴右下角的“引用”或最右下角的那个较大的“回复”然后就应该知道怎么发了。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT