瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】eraseme_xxxxx.exe病毒如何彻底清除

1   1  /  1  页   跳转

【求助】eraseme_xxxxx.exe病毒如何彻底清除

【求助】eraseme_xxxxx.exe病毒如何彻底清除

eraseme_xxxxx.exe病毒清除后一会又有,来自不同IP地址,不知如何能彻底清除。
以下为扫描日志:
Logfile of HijackThis v1.99.1
Scan saved at 11:01:38, on 2006-12-13
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\CNNIC\Cdn\cdnup.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\SOUNDMAN.EXE
E:\杀毒\windows木马清道夫注册机版\ftcsetup\Windows木马清道夫 8.8上网必备绿色注册可升级版\ftcsetup\Trojanwall.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\Program Files\263 SuperMail\263 SuperMail.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE
C:\WINNT\system32\internat.exe
C:\WINNT\system32\conime.exe
D:\Foxmail\Foxmail.exe
C:\WINNT\system32\svchost.exe
C:\PROGRA~1\Sina\ddt\RssReader.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\TheWorld\TheWorld.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Kingsoft\PowerWord 2006\XDICT.EXE
E:\杀毒\电脑扫描工具\ha_hijackthis_1991\HijackThis.exe

O2 - BHO: IDDTInitObj Class - {15DDE989-CD45-4561-BF99-D22C0D5C2B74} - C:\PROGRA~1\Sina\ddt\DDTInit.dll
O2 - BHO: ThunderBHO - {352E3B39-CAB5-4DBC-B940-C7F84D0447D8} - D:\Program Files\迅雷\ComDlls\XunLeiBHO_006.dll
O2 - BHO: CNNIC 网络工具Drag - {352E3B3A-CAB5-4DBC-B940-C7F84D0447D8} - (no file)
O2 - BHO: Cdn Class - {471A662A-4030-42BC-B632-758700A64DB9} - C:\PROGRA~1\cdnpack\cdncn.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O2 - BHO: KillObj Class - {66C28884-4E5D-494B-80C9-CAA27528FD6D} - C:\PROGRA~1\Sina\ddt\ddtkillw.ocx
O2 - BHO: 超级兔子上网精灵 - {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} - C:\PROGRA~1\SUPERR~1\MAGICSET\haokanbar.dll
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (file missing)
O3 - Toolbar: 超级兔子上网精灵 - {43869BB3-22FD-4F15-9B46-238106BA2F4E} - C:\PROGRA~1\SUPERR~1\MAGICSET\haokanbar.dll
O3 - Toolbar: 新浪点点通 - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - C:\PROGRA~1\Sina\ddt\DDTONG~1.DLL
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Windows木马防火墙] E:\杀毒\windows木马清道夫注册机版\ftcsetup\Windows木马清道夫 8.8上网必备绿色注册可升级版\ftcsetup\Trojanwall.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [263 SuperMail] C:\Program Files\263 SuperMail\263 SuperMail.exe /run
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [NMGameX_AutoRun] C:\WINNT\system32\Rundll32.exe nmgamex.dll,LiveProcess /aa
O4 - HKLM\..\RunOnce: [DDTRestartRun] rundll32.exe C:\PROGRA~1\Sina\ddt\DDTInit.dll,RestartRun
O4 - HKCU\..\Run: [Super Rabbit IEPro] C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [MsnMsgr] ; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: 新浪点点通.lnk = C:\Program Files\sina\ddt\DDTDesk.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item:  添加到新浪点点通阅读器 - res://C:\PROGRA~1\Sina\ddt\RssReader.exe/RSSFEED.js
O8 - Extra context menu item: &使用迅雷下载 - D:\Program Files\迅雷\Program\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\Program Files\迅雷\Program\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用彩信超级自写发送到手机 - http://mms.sina.com.cn/mmsnews.html
O8 - Extra context menu item: 使用新浪下载助手下载 - C:\PROGRA~1\Sina\ddt\sinadl.htm
O8 - Extra context menu item: 发送图片到手机(&M) - http://sms.sina.com.cn/diy/send.html?from=467
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 收藏此页到新浪ViVi - http://vivi.sina.com.cn/collect/click.php?agent=ddt
O8 - Extra context menu item: 新浪搜索 - http://cha.sina.com.cn/ddt.html
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\Program Files\迅雷\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\Program Files\迅雷\Thunder.exe
O9 - Extra button: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra button: 新浪点点通 - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - C:\PROGRA~1\Sina\ddt\DDTONG~1.DLL
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O9 - Extra button: (no name) - {974AD624-EA50-4831-A6C0-3040F6665396} - C:\PROGRA~1\Sina\ddt\rssband.dll (HKCU)
O9 - Extra 'Tools' menuitem: 新浪点点通阅读器 - {974AD624-EA50-4831-A6C0-3040F6665396} - C:\PROGRA~1\Sina\ddt\rssband.dll (HKCU)
O9 - Extra button: 新浪点点通阅读器 - {F0646DC8-58CD-4C64-8F6B-525043914685} - C:\PROGRA~1\Sina\ddt\rssband.dll (HKCU)

附件附件:

下载次数:738
文件类型:image/pjpeg
文件大小:
上传时间:2006-12-13 11:30:12
描述:
预览信息:EXIF信息



最后编辑2006-12-13 14:46:12
分享到:
gototop
 

续扫描日志:
O10 - Broken Internet access because of LSP provider 'c:\winnt\system32\cdnns.dll' missing
O11 - Options group: [CDNCLIENT]  中文上网
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1130508648453
O17 - HKLM\System\CCS\Services\Tcpip\..\{792BCA0C-0D6F-4C0D-93E2-B79EA8453364}: NameServer = 211.97.64.129
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O21 - SSODL: MediaCheck - {D1F73845-4BAB-4061-A46B-FCF7ECC19217} - C:\PROGRA~1\Kuree\MService.dll (file missing)
O23 - Service: 00115 - Unknown owner - \\192.168.97.67\Admin$\eraseme_62675.exe (file missing)
O23 - Service: 01105 - Unknown owner - \\192.168.97.67\Admin$\eraseme_18161.exe (file missing)
O23 - Service: 02225 - Unknown owner - \\192.168.97.67\Admin$\eraseme_28406.exe (file missing)
O23 - Service: 06770 - Unknown owner - \\192.168.97.67\Admin$\eraseme_70801.exe (file missing)
O23 - Service: 08037 - Unknown owner - \\192.168.97.67\Admin$\eraseme_34403.exe (file missing)
O23 - Service: 10116 - Unknown owner - \\192.168.97.67\Admin$\eraseme_51625.exe (file missing)
O23 - Service: 10302 - Unknown owner - \\192.168.97.67\Admin$\eraseme_88052.exe (file missing)
O23 - Service: 11268 - Unknown owner - \\192.168.97.67\Admin$\eraseme_88825.exe (file missing)
O23 - Service: 11384 - Unknown owner - \\192.168.97.67\Admin$\eraseme_51164.exe (file missing)
O23 - Service: 11626 - Unknown owner - \\192.168.97.67\Admin$\eraseme_58871.exe (file missing)
O23 - Service: 11876 - Unknown owner - \\192.168.97.67\Admin$\eraseme_42812.exe (file missing)
O23 - Service: 12250 - Unknown owner - \\192.168.97.67\Admin$\eraseme_62618.exe (file missing)
O23 - Service: 12807 - Unknown owner - \\192.168.97.67\Admin$\eraseme_45374.exe (file missing)
O23 - Service: 15452 - Unknown owner - \\192.168.97.67\Admin$\eraseme_71873.exe (file missing)
O23 - Service: 16767 - Unknown owner - \\192.168.97.67\Admin$\eraseme_85476.exe (file missing)
O23 - Service: 16772 - Unknown owner - \\192.168.97.67\Admin$\eraseme_38328.exe (file missing)
O23 - Service: 17112 - Unknown owner - \\192.168.97.67\Admin$\eraseme_36680.exe (file missing)
O23 - Service: 20513 - Unknown owner - \\192.168.97.67\Admin$\eraseme_43062.exe (file missing)
O23 - Service: 21068 - Unknown owner - \\192.168.97.67\Admin$\eraseme_67704.exe (file missing)
O23 - Service: 21487 - Unknown owner - \\192.168.97.67\Admin$\eraseme_23225.exe (file missing)
O23 - Service: 21606 - Unknown owner - \\192.168.97.67\Admin$\eraseme_54082.exe (file missing)
O23 - Service: 23740 - Unknown owner - \\192.168.97.67\Admin$\eraseme_26152.exe (file missing)
O23 - Service: 26262 - Unknown owner - \\192.168.97.67\Admin$\eraseme_28411.exe (file missing)
O23 - Service: 26372 - Unknown owner - \\192.168.97.67\Admin$\eraseme_62726.exe (file missing)
O23 - Service: 32003 - Unknown owner - \\192.168.97.67\Admin$\eraseme_06851.exe (file missing)
O23 - Service: 33673 - Unknown owner - \\192.168.97.67\Admin$\eraseme_60201.exe (file missing)
O23 - Service: 33811 - Unknown owner - \\192.168.97.67\Admin$\eraseme_87715.exe (file missing)
O23 - Service: 34227 - Unknown owner - \\192.168.97.67\Admin$\eraseme_04355.exe (file missing)
O23 - Service: 34605 - Unknown owner - \\192.168.97.67\Admin$\eraseme_71825.exe (file missing)
O23 - Service: 35873 - Unknown owner - \\192.168.97.67\Admin$\eraseme_61377.exe (file missing)
O23 - Service: 37216 - Unknown owner - \\192.168.97.67\Admin$\eraseme_43330.exe (file missing)
O23 - Service: 37836 - Unknown owner - \\192.168.97.67\Admin$\eraseme_41278.exe (file missing)
O23 - Service: 40024 - Unknown owner - \\192.168.97.67\Admin$\eraseme_33535.exe (file missing)
O23 - Service: 40364 - Unknown owner - \\192.168.97.67\Admin$\eraseme_60520.exe (file missing)
O23 - Service: 41244 - Unknown owner - \\192.168.97.67\Admin$\eraseme_32305.exe (file missing)
O23 - Service: 43254 - Unknown owner - \\192.168.97.67\Admin$\eraseme_85767.exe (file missing)
O23 - Service: 45837 - Unknown owner - \\192.168.97.67\Admin$\eraseme_56721.exe (file missing)
O23 - Service: 50271 - Unknown owner - \\192.168.97.67\Admin$\eraseme_25510.exe (file missing)
O23 - Service: 50544 - Unknown owner - \\192.168.97.67\Admin$\eraseme_75461.exe (file missing)
O23 - Service: 50716 - Unknown owner - \\192.168.97.67\Admin$\eraseme_28362.exe (file missing)
O23 - Service: 51415 - Unknown owner - \\192.168.97.67\Admin$\eraseme_22271.exe (file missing)
O23 - Service: 52836 - Unknown owner - \\192.168.97.67\Admin$\eraseme_10258.exe (file missing)
O23 - Service: 56766 - Unknown owner - \\192.168.97.67\Admin$\eraseme_86324.exe (file missing)
O23 - Service: 58552 - Unknown owner - \\192.168.97.67\Admin$\eraseme_14041.exe (file missing)
O23 - Service: 61063 - Unknown owner - \\192.168.97.67\Admin$\eraseme_88016.exe (file missing)
O23 - Service: 61205 - Unknown owner - \\192.168.97.67\Admin$\eraseme_01374.exe (file missing)
O23 - Service: 61653 - Unknown owner - \\192.168.97.67\Admin$\eraseme_76880.exe (file missing)
O23 - Service: 62564 - Unknown owner - \\192.168.97.67\Admin$\eraseme_78781.exe (file missing)
O23 - Service: 63635 - Unknown owner - \\192.168.97.67\Admin$\eraseme_47840.exe (file missing)
O23 - Service: 64405 - Unknown owner - \\192.168.97.67\Admin$\eraseme_23614.exe (file missing)
O23 - Service: 64653 - Unknown owner - \\192.168.97.67\Admin$\eraseme_64052.exe (file missing)
O23 - Service: 65564 - Unknown owner - \\192.168.97.67\Admin$\eraseme_58341.exe (file missing)
O23 - Service: 66177 - Unknown owner - \\192.168.97.67\Admin$\eraseme_83500.exe (file missing)
O23 - Service: 68238 - Unknown owner - \\192.168.97.67\Admin$\eraseme_38046.exe (file missing)
O23 - Service: 70606 - Unknown owner - \\192.168.97.67\Admin$\eraseme_63456.exe (file missing)
O23 - Service: 74115 - Unknown owner - \\192.168.97.67\Admin$\eraseme_13677.exe (file missing)
O23 - Service: 76637 - Unknown owner - \\192.168.97.67\Admin$\eraseme_30530.exe (file missing)
O23 - Service: 77254 - Unknown owner - \\192.168.97.67\Admin$\eraseme_16807.exe (file missing)
O23 - Service: 77324 - Unknown owner - \\192.168.97.67\Admin$\eraseme_07564.exe (file missing)
O23 - Service: 80133 - Unknown owner - \\192.168.97.67\Admin$\eraseme_60208.exe (file missing)
O23 - Service: 80474 - Unknown owner - \\192.168.97.67\Admin$\eraseme_38426.exe (file missing)
O23 - Service: 80612 - Unknown owner - \\192.168.97.67\Admin$\eraseme_41145.exe (file missing)
O23 - Service: 81683 - Unknown owner - \\192.168.97.67\Admin$\eraseme_70425.exe (file missing)
O23 - Service: 82636 - Unknown owner - \\192.168.97.67\Admin$\eraseme_30540.exe (file missing)
O23 - Service: 83005 - Unknown owner - \\192.168.97.67\Admin$\eraseme_64757.exe (file missing)
O23 - Service: 83316 - Unknown owner - \\192.168.97.67\Admin$\eraseme_71285.exe (file missing)
O23 - Service: 83378 - Unknown owner - \\192.168.97.67\Admin$\eraseme_71178.exe (file missing)
O23 - Service: 84464 - Unknown owner - \\192.168.97.67\Admin$\eraseme_45127.exe (file missing)
O23 - Service: 85237 - Unknown owner - \\192.168.97.67\Admin$\eraseme_48184.exe (file missing)
O23 - Service: 87481 - Unknown owner - \\192.168.97.67\Admin$\eraseme_14648.exe (file missing)
O23 - Service: 88142 - Unknown owner - \\192.168.97.67\Admin$\eraseme_73611.exe (file missing)
O23 - Service: 88206 - Unknown owner - \\192.168.97.67\Admin$\eraseme_63744.exe (file missing)
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: McAfee Framework 服务 (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe

gototop
 

谁能指点指点啊!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT