瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求高手救救小弟,杀不掉的病毒,我快崩溃了,谢谢

1   1  /  1  页   跳转

求高手救救小弟,杀不掉的病毒,我快崩溃了,谢谢

求高手救救小弟,杀不掉的病毒,我快崩溃了,谢谢

2007-02-15,14:07:45

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <bgswitch><C:\WINDOWS\system32\bgswitch.exe>  [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <RavTask><"D:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <ATICCC><"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay>  [N/A]
    <upxdnd><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.exe>  [N/A]
    <mppds><C:\WINDOWS\mppds.exe>  [N/A]
    <wsttrs><C:\WINDOWS\wsttrs.exe>  [N/A]
    <wsvbs><C:\WINDOWS\wsvbs.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <twin><C:\WINDOWS\system32\ctfnom.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe>  [(Verified)Microsoft Corporation]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]

==================================
启动文件夹
N/A

==================================
服务
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart][Stopped/Auto Start]
  <C:\WINDOWS\system32\ati2sgag.exe><>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"D:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"D:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>

==================================
驱动程序
[ati2mtag / ati2mtag][Running/Manual Start]
  <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[BaseTDI / BaseTDI][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\basetdi.sys><Beijing Rising Technology Co., Ltd.>
[C-Media WDM Audio Interface / cmuda][Running/Manual Start]
  <system32\drivers\cmuda.sys><C-Media Inc>
[ExpScaner / ExpScaner][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\ExpScan.sys><>
[HookCont / HookCont][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\HookSys.sys><Rising>
[MEMSCAN / MEMSCAN][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[Netgroup Packet Filter / NPF][Running/Manual Start]
  <system32\drivers\npf.sys><CACE Technologies>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
  <\??\D:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139/810x Family Fast Ethernet NIC NT Driver / rtl8139][Running/Manual Start]
  <system32\DRIVERS\R8139n51.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[SIS AGP Bus Filter / sisagp][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\sisagp.sys><Silicon Integrated Systems Corporation>
[squellabcd / squellabcd][Running/Manual Start]
  <2 - 系统找不到指定的文件。
><N/A>

==================================
浏览器加载项
[番茄花园]
  {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.tomatolei.com, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>

==================================
正在运行的进程
[PID: 424][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 480][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 508][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4131]
[PID: 552][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 564][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 712][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4131]
    [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2500]
[PID: 724][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 820][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 904][D:\Program Files\Rising\Rav\CCenter.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 920][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1016][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1088][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1124][D:\Program Files\Rising\Rav\Ravmond.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 43]
    [D:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [D:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [D:\Program Files\Rising\Rav\rfwctrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [D:\Program Files\Rising\Rav\RsPPsys.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
    [D:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [D:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [D:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [D:\Program Files\Rising\Rav\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [D:\Program Files\Rising\Rav\HOOKSYS.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
    [D:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
    [D:\Program Files\Rising\Rav\libload.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [D:\Program Files\Rising\Rav\VirusLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [D:\Program Files\Rising\Rav\regmon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
    [D:\Program Files\Rising\Rav\HookWeb.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
    [D:\Program Files\Rising\Rav\MemMon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
    [D:\Program Files\Rising\Rav\expscan.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [D:\Program Files\Rising\Rav\mPorts.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
    [D:\Program Files\Rising\Rav\HookCont.dll]  [Rising, 19, 0, 0, 0]
    [D:\Program Files\Rising\Rav\SpamEng.dll]  [N/A, 18, 0, 0, 6]
    [D:\Program Files\Rising\Rav\engine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 25]
    [D:\Program Files\Rising\Rav\PostTrt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
    [D:\Program Files\Rising\Rav\UnExe.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [D:\Program Files\Rising\Rav\ScanExec.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [D:\Program Files\Rising\Rav\ScanEx.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 40]
    [D:\Program Files\Rising\Rav\ExtFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 25]
    [D:\Program Files\Rising\Rav\NvFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
    [D:\Program Files\Rising\Rav\ScanMac.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
    [D:\Program Files\Rising\Rav\ScanSct.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [D:\Program Files\Rising\Rav\Unpacker.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [D:\Program Files\Rising\Rav\ScanPack.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [D:\Program Files\Rising\Rav\RsVM.dll]  [N/A, 19, 0, 0, 15]
    [D:\Program Files\Rising\Rav\Uroutine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 21]
    [D:\Program Files\Rising\Rav\ScanNet.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [D:\Program Files\Rising\Rav\Uscript.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 18]
最后编辑2007-02-15 14:53:57.997000000
分享到:
gototop
 

试下
签名
gototop
 

[PID: 1680][C:\Program Files\ATI Technologies\ATI.ACE\cli.exe]  [ATI Technologies Inc., 1.11.0.0]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Implementation.dll]  [ATI Technologies Inc., 1.2.2271.38977]
    [C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.dll]  [ATI Technologies Inc., 1.2.2208.29985]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Foundation.dll]  [ATI Technologies Inc., 1.2.2208.29986]
    [C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.Service.dll]  [ATI Technologies Inc., 1.2.2271.39124]
    [C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29991]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Foundation.XManifestation.dll]  [ATI Technologies Inc., 1.2.2271.39124]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Component.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39124]
    [C:\Program Files\ATI Technologies\ATI.ACE\ATICCCom.dll]  [ATI Technologies Inc., 1.0.0.0]
    [C:\Program Files\ATI Technologies\ATI.ACE\AEM.Foundation.dll]  [ATI Technologies Inc., 1.2.2208.29985]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Caste.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29987]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Caste.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39119]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Component.Runtime.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29988]
    [C:\Program Files\ATI Technologies\ATI.ACE\DEM.Foundation.dll]  [ATI Technologies Inc., 1.11.0.0]
    [C:\Program Files\ATI Technologies\ATI.ACE\DEM.Graphics.I0601.dll]  [ATI Technologies Inc., 1.11.0.0]
    [C:\Program Files\ATI Technologies\ATI.ACE\ACE.Graphics.DisplaysManager.Shared.dll]  [ATI Technologies Inc., 1.11.0.0]
    [C:\WINDOWS\system32\ATIDEMGR.dll]  [ATI Technologies Inc., 1.2.2271.38961]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MultiVPU2.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39011]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MultiVPU2.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29991]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MultiVPU.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39031]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MultiVPU.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.30001]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VeryLargeDesktop.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39011]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VeryLargeDesktop.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29993]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.Radeon3D.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39048]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.Radeon3DLegacy.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39045]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39015]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.30007]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysColour.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39076]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysColour.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29990]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MMVideo.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39062]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MMVideo.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.30001]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VideoOverlay.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39124]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VideoOverlay.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29989]
    [C:\Program Files\ATI Technologies\ATI.ACE\ACE.Graphics.VideoOverlay.Shared.dll]  [ATI Technologies Inc., 1.11.0.0]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.SmartGart.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39043]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VPURecover.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39036]
gototop
 

[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.VPURecover.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29988]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.WorkstationConfig.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39034]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39096]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCRT.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2236.29147]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCRT2.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39021]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCRT2.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2236.29162]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39087]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceLCD.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29994]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceLCD2.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39015]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceLCD2.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29993]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCV.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39092]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCV.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2236.29179]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.CustomFormats.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2236.29132]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCV2.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39023]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCV2.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2236.29197]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceTV2.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39083]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceTV.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39079]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39089]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceDFP.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2236.29212]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceDFP2.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39018]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceDFP2.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2236.29221]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.OverDrive3.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39054]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.OverDrive3.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2231.27329]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.OverDrive2.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39059]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.PowerPlay3.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39052]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.PowerPlay3.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29989]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39070]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.IntegratedUMAFrameBuffer.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39065]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.InfoCentre.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39068]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.InfoCentre.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29990]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39026]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.30002]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.Radeon3D.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2232.28756]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.Radeon3DLegacy.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2232.28758]
    [C:\Program Files\ATI Technologies\ATI.ACE\DEM.Graphics.I0600.dll]  [ATI Technologies Inc., 1.11.0.0]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.SmartGart.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29990]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.WorkstationConfig.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29988]
    [C:\Program Files\ATI Technologies\ATI.ACE\DEM.Graphics.I0602.dll]  [ATI Technologies Inc., 1.11.0.0]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceProperty.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29987]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceProperty2.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29986]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceTV2.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.30001]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceTV.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29993]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.OverDrive2.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29989]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29993]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.IntegratedUMAFrameBuffer.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29988]
    [C:\Program Files\ATI Technologies\ATI.ACE\APM.Foundation.dll]  [ATI Technologies Inc., 1.2.2208.30002]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[PID: 1720][D:\Program Files\Rising\Rav\Ravmon.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 45]
    [D:\Program Files\Rising\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
    [D:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [D:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [D:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [D:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [D:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [D:\Program Files\Rising\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [D:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 1764][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2012][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 452][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 2312][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2788][C:\Program Files\ATI Technologies\ATI.ACE\cli.exe]  [ATI Technologies Inc., 1.11.0.0]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Implementation.dll]  [ATI Technologies Inc., 1.2.2271.38977]
    [C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.dll]  [ATI Technologies Inc., 1.2.2208.29985]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Foundation.dll]  [ATI Technologies Inc., 1.2.2208.29986]
    [C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.Service.dll]  [ATI Technologies Inc., 1.2.2271.39124]
    [C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29991]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Foundation.XManifestation.dll]  [ATI Technologies Inc., 1.2.2271.39124]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Component.Wizard.dll]  [ATI Technologies Inc., 1.2.2271.39004]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Foundation.Clients.dll]  [ATI Technologies Inc., 1.2.2208.29986]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Component.Wizard.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29987]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Component.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39124]
    [C:\Program Files\ATI Technologies\ATI.ACE\ATICCCom.dll]  [ATI Technologies Inc., 1.0.0.0]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Caste.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29987]
    [C:\Program Files\ATI Technologies\ATI.ACE\AEM.Foundation.dll]  [ATI Technologies Inc., 1.2.2208.29985]
    [C:\Program Files\ATI Technologies\ATI.ACE\ACE.Graphics.DisplaysManager.Shared.dll]  [ATI Technologies Inc., 1.11.0.0]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Caste.Graphics.Wizard.dll]  [ATI Technologies Inc., 1.2.2271.39006]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Caste.Graphics.Wizard.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29990]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCV.Graphics.Wizard.dll]  [ATI Technologies Inc., 1.2.2271.38995]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCV2.Graphics.Wizard.dll]  [ATI Technologies Inc., 1.2.2271.38998]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll]  [ATI Technologies Inc., 1.2.2271.38989]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceLCD2.Graphics.Wizard.dll]  [ATI Technologies Inc., 1.2.2271.38992]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceTV.Graphics.Wizard.dll]  [ATI Technologies Inc., 1.2.2271.38985]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceTV2.Graphics.Wizard.dll]  [ATI Technologies Inc., 1.2.2271.38987]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll]  [ATI Technologies Inc., 1.2.2271.39001]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.Radeon3D.Graphics.Wizard.dll]  [ , 1.2.2271.38978]
gototop
 

打开冰刃,所有操作在冰刃下进行,不让使用我的电脑和注册表的地方千万不要使用

在冰刃的进程里面,结束如下进程:


在冰刃的服务里面,禁用下列服务:


在冰刃的注册表中找到如下项,删除对应键值。
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
<upxdnd><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.exe> [N/A]
<mppds><C:\WINDOWS\mppds.exe> [N/A]
<wsttrs><C:\WINDOWS\wsttrs.exe> [N/A]
<wsvbs><C:\WINDOWS\wsvbs.exe> [N/A]

在冰刃的文件里面,删除如下文件,删除不了的强制删除,如果还不行给我发信息。仔细查找,如果没有就算了。
C:\WINDOWS\wsvbs.exe
C:\WINDOWS\wsttrs.exe
C:\WINDOWS\mppds.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.dll
在c:\windows\system32和c:\windows\下寻找wsvbs.dll、wsttrs.dll、mppds.dll,有则删除
清空C:\Documents and Settings\用户名\Local Settings\Temp文件夹中所有文件及文件夹

特殊处理


怀疑文件


希望您可以做到:
把所有准备删除的病毒文件
Temp文件夹下面所有大小小于1MB的EXE文件和DLL文件
瑞星病毒隔离系统目录c:\ravbin\下面的所有隐藏的.bin文件
整理到一个文件夹中,用WinRAR压缩后发送到我邮箱(最大附件10MB),方便我留下病毒副本

冰刃下载地址http://www.ttian.net/website/2005/0829/391.html
gototop
 

[C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MMVideo.Graphics.Wizard.dll]  [ATI Technologies Inc., 1.2.2271.38980]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.TransCode.Local.Wizard.dll]  [ATI Technologies Inc., 1.2.2271.39012]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.InfoCentre.Graphics.Wizard.dll]  [ATI Technologies Inc., 1.2.2271.38982]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCV.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2236.29179]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceProperty.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29987]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceCV2.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2236.29197]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceProperty2.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29986]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceLCD.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29994]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceLCD2.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29993]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceTV.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29993]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.DeviceTV2.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.30001]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.Radeon3D.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2232.28756]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.MMVideo.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.30001]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.TransCode.Local.Shared.dll]  [ATI Technologies Inc., 1.2.0.0]
    [C:\Program Files\ATI Technologies\ATI.ACE\atixclib.dll]  [ , 1.0.0.0]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Aspect.InfoCentre.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29990]
[PID: 2796][C:\Program Files\ATI Technologies\ATI.ACE\cli.exe]  [ATI Technologies Inc., 1.11.0.0]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Implementation.dll]  [ATI Technologies Inc., 1.2.2271.38977]
    [C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.dll]  [ATI Technologies Inc., 1.2.2208.29985]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Foundation.dll]  [ATI Technologies Inc., 1.2.2208.29986]
    [C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.Service.dll]  [ATI Technologies Inc., 1.2.2271.39124]
    [C:\Program Files\ATI Technologies\ATI.ACE\LOG.Foundation.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29991]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Foundation.XManifestation.dll]  [ATI Technologies Inc., 1.2.2271.39124]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Component.Systemtray.dll]  [ATI Technologies Inc., 1.2.2271.39105]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Caste.Graphics.Shared.dll]  [ATI Technologies Inc., 1.2.2208.29987]
    [C:\Program Files\ATI Technologies\ATI.ACE\CLI.Component.Runtime.dll]  [ATI Technologies Inc., 1.2.2271.39124]
    [C:\Program Files\ATI Technologies\ATI.ACE\ATICCCom.dll]  [ATI Technologies Inc., 1.0.0.0]
    [C:\Program Files\ATI Technologies\ATI.ACE\ACE.Graphics.DisplaysManager.Shared.dll]  [ATI Technologies Inc., 1.11.0.0]
    [C:\Program Files\ATI Technologies\ATI.ACE\AEM.Foundation.dll]  [ATI Technologies Inc., 1.2.2208.29985]
    [C:\Program Files\ATI Technologies\ATI.ACE\APM.Foundation.dll]  [ATI Technologies Inc., 1.2.2208.30002]
[PID: 3600][E:\下载工具\ckrz.exe]  [, 0, 0, 7, 0]
[PID: 3948][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  [Macromedia, Inc., 8,0,22,0]
    [E:\杀毒\SREng【teyqiu】.COM]  [Smallfrogs Studio, 2.3.13.690]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
N/A

==================================
gototop
 

删除方法看4楼
gototop
 

upxdnd.dll删不掉,TEMP下的也不能清空,怎么强制删?谢谢
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT