瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 已经解决--灰鸽子病毒不能清除--瑞星误报

12   2  /  2  页   跳转

已经解决--灰鸽子病毒不能清除--瑞星误报

==================================
正在运行的进程
[PID: 324][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 508][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 532][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 576][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 588][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 740][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 784][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 844][C:\Program Files\Rising\Rav\CCenter.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 864][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 904][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 968][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1016][C:\Program Files\Rising\Rav\Ravmond.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 43]
    [C:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\rfwctrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [C:\Program Files\Rising\Rav\RsPPsys.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\Rav\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [C:\Program Files\Rising\Rav\HOOKSYS.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
    [C:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
    [C:\Program Files\Rising\Rav\libload.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [C:\Program Files\Rising\Rav\VirusLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [C:\Program Files\Rising\Rav\regmon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
    [C:\Program Files\Rising\Rav\HookWeb.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
    [C:\Program Files\Rising\Rav\MemMon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
    [C:\Program Files\Rising\Rav\expscan.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Rising\Rav\mPorts.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
    [C:\Program Files\Rising\Rav\HookCont.dll]  [Rising, 19, 0, 0, 0]
    [C:\Program Files\Rising\Rav\SpamEng.dll]  [N/A, 18, 0, 0, 6]
    [C:\Program Files\Rising\Rav\engine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
    [C:\Program Files\Rising\Rav\PostTrt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
    [C:\Program Files\Rising\Rav\UnExe.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\Program Files\Rising\Rav\ScanExec.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
    [C:\Program Files\Rising\Rav\ScanEx.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 32]
    [C:\Program Files\Rising\Rav\ExtFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 23]
    [C:\Program Files\Rising\Rav\NvFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
    [C:\Program Files\Rising\Rav\ScanMac.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
    [C:\Program Files\Rising\Rav\ScanSct.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [C:\Program Files\Rising\Rav\Unpacker.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
    [C:\Program Files\Rising\Rav\ScanPack.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 18]
    [C:\Program Files\Rising\Rav\RsVM.dll]  [N/A, 19, 0, 0, 13]
    [C:\Program Files\Rising\Rav\Uroutine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [C:\Program Files\Rising\Rav\Uscript.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
    [C:\Program Files\Rising\Rav\ScanNet.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 1220][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
    [C:\WINDOWS\system32\SSGH1LMK.DLL]  [Samsung Electronics., 1.0.0.0]
[PID: 1412][C:\Program Files\AhnLab\Smart Update Utility\AhnSDsv.exe]  [AhnLab, Inc., 5, 5, 0, 1]
    [C:\Program Files\AhnLab\Smart Update Utility\NLS\ASD0804.nls]  [AhnLab, Inc., 5, 0, 0, 5]
[PID: 1588][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1616][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1196 built by: dnsrv(bld4act)]
[PID: 1880][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 284][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
    [C:\Program Files\Winrar\rarext.dll]  [N/A, N/A]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\PROGRA~1\ESTsoft\ALZip\AZCTM.dll]  [ESTsoft, 6.1.13.56]
    [C:\KAV2006\KASocket.dll]  [Kingsoft Corporation, 2005, 2, 22, 233]
    [C:\KAV2006\KAVEXT.DLL]  [Kingsoft Corporation, 2005, 8, 5, 16]
gototop
 

[PID: 896][C:\Program Files\Rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\KAV2006\KASocket.dll]  [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 980][C:\Program Files\AhnLab\Smart Update Utility\AhnSD.exe]  [AhnLab, Inc., 5, 5, 0, 1]
    [C:\Program Files\AhnLab\Smart Update Utility\NLS\ASD0804.nls]  [AhnLab, Inc., 5, 0, 0, 5]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\KAV2006\KASocket.dll]  [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 1048][C:\Program Files\Rising\Rav\Ravmon.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
    [C:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [C:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\KAV2006\KASocket.dll]  [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 1356][C:\Program Files\Rising\AntiSpyware\runiep.exe]  [Beijing Rising Technology Co., Ltd., 1, 0, 1, 3]
    [C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\KAV2006\KASocket.dll]  [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 1312][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\KAV2006\KASocket.dll]  [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 3956][C:\Program Files\AhnLab\AhnLab SpyZero 2.0\AszMon.exe]  [AhnLab, Inc., 2, 0, 0, 71]
    [C:\Program Files\AhnLab\AhnLab SpyZero 2.0\AszLog.dll]  [AhnLab, Inc., 2, 0, 0, 41]
    [C:\Program Files\AhnLab\AhnLab SpyZero 2.0\ACALogE.dll]  [AhnLab, Inc., 1, 0, 0, 18]
    [C:\Program Files\AhnLab\AhnLab SpyZero 2.0\ahni18n2.dll]  [AhnLab, Inc., 6, 1, 0, 4]
    [C:\Program Files\AhnLab\AhnLab SpyZero 2.0\aszctrl.dll]  [AhnLab, Inc., 2, 0, 0, 93]
    [C:\Program Files\AhnLab\AhnLab SpyZero 2.0\AhnInst.dll]  [AhnLab, Inc., 6, 0, 0, 54]
    [C:\Program Files\AhnLab\AhnLab SpyZero 2.0\ASZFlt.dll]  [AhnLab, Inc, 2, 2, 0, 1]
    [C:\Program Files\AhnLab\AhnLab SpyZero 2.0\AhnCtlKD.dll]  [AhnLab, Inc., 1, 0, 1, 7]
    [C:\Program Files\AhnLab\AhnLab SpyZero 2.0\AszWL.dll]  [AhnLab, Inc., 2, 0, 0, 21]
    [C:\Program Files\AhnLab\AhnLab SpyZero 2.0\AszEnc.dll]  [AhnLab, Inc., 2, 0, 0, 11]
    [C:\Program Files\AhnLab\AhnLab SpyZero 2.0\AszDMZ.dll]  [AhnLab, Inc., 2, 0, 0, 17]
    [C:\Program Files\AhnLab\AhnLab SpyZero 2.0\Nls\ASZL0804.nls]  [AhnLab, Inc., 2, 0, 0, 19]
    [C:\Program Files\AhnLab\AhnLab SpyZero 2.0\Driver\ACALogDF.drv]  [AhnLab, Inc., 1, 0, 0, 13]
    [C:\Program Files\AhnLab\AhnLab SpyZero 2.0\system\62\AhnSZE.dll]  [AhnLab, Inc., 3, 0, 2, 11]
[PID: 2376][C:\Program Files\SAP\FrontEnd\Sapgui\saplogon.exe]  [SAP AG, Walldorf, 6402.2.3.978]
    [C:\Program Files\SAP\FrontEnd\Sapgui\saplgnui.dll]  [SAP AG, Walldorf, 6402.2.3.5]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sappctxt.dll]  [SAP AG, Walldorf, 6400.2.0.19]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapfewtr.dll]  [SAP AG, Walldorf, 6402.2.3.222]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapfewut.dll]  [SAP AG, Walldorf, 6402.2.3.258]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapthmcust.dll]  [SAP AG, Walldorf, 6402.2.3.1011]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapfewrm.dll]  [SAP AG, Walldorf, 6402.2.3.332]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapfewcx.dll]  [SAP AG, Walldorf, 6400.2.0.208]
    [C:\Program Files\SAP\FrontEnd\Sapgui\saplgdll.dll]  [SAP AG, Walldorf, 6402.2.3.964]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapdpams.dll]  [SAP AG, Walldorf, 6400.2.0.0815]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapshlib.dll]  [SAP AG, Walldorf, 6402.2.3.43]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapguilib.dll]  [SAP AG, Walldorf, 6402.2.3.8966]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapfront.dll]  [SAP AG, Walldorf, 6402.2.3.2923]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapfewed.dll]  [SAP AG, Walldorf, 6400.2.0.9]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapfewcls.dll]  [SAP AG, Walldorf, 6402.2.3.004]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapfewnls.dll]  [SAP AG, Walldorf, 6402.2.3.016]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapfewdr.dll]  [SAP AG, Walldorf, 6402.2.3.214]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapfdraw.dll]  [SAP AG, Walldorf, 6402.2.3.252]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapthmdrw.dll]  [SAP AG, Walldorf, 6402.2.3.102]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapfewdp.dll]  [SAP AG, Walldorf, 6402.2.3.68]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapawrfc.dll]  [SAP AG, Walldorf, 6402.2.3.238]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapawole.dll]  [SAP AG, Walldorf, 6402.2.3.223]
    [C:\WINDOWS\system32\LIBRFC32.dll]  [SAP AG, 6402, 2, 35, 4454]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapfewcb.dll]  [SAP AG, Walldorf, 6402.2.3.212]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapfewui.dll]  [SAP AG, Walldorf, 6402.2.3.344]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapfctrl.dll]  [SAP AG, Walldorf, 6402.2.3.283]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapapihk.dll]  [SAP AG, 1, 0, 0, 5]
    [C:\Program Files\SAP\FrontEnd\Sapgui\gngmb.dll]  [SAP AG, Walldorf, 6402.2.3.1007]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapfhook.dll]  [SAP AG, Walldorf, 6402.2.3.206]
    [C:\Program Files\SAP\FrontEnd\Sapgui\sapcpp45.dll]  [SAP AG, 6400, 17, 0, 30013]
    [c:\program files\sap\frontend\sapgui\sapdatap.ocx]  [SAP AG, Walldorf, 6402.2.3.238]
    [C:\Program Files\SAP\FrontEnd\SapGui\sapguisv.ocx]  [SAP AG, Walldorf, 6400.2.0.236]
    [C:\WINDOWS\system32\sapbtmp.dll]  [SAP AG, Walldorf, 6402.2.3.1309]
    [C:\Program Files\SAP\FrontEnd\Sapgui\guixt.dll]  [Synactive GmbH  www.synactive.com, 2004.2.1]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [c:\program files\sap\frontend\sapgui\sapguirm.ocx]  [SAP AG, Walldorf, 6402.2.3.210]
    [C:\Program Files\SAP\FrontEnd\SapGui\saptabcn.ocx]  [SAP AG, Walldorf, 6400.2.0.223]
    [C:\KAV2006\KASocket.dll]  [Kingsoft Corporation, 2005, 2, 22, 233]
    [C:\Program Files\SAP\FrontEnd\SapGui\sapcltfc.ocx]  [SAP AG, Walldorf, 6400.2.0.101]
gototop
 

[PID: 1952][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\KAV2006\KASocket.dll]  [Kingsoft Corporation, 2005, 2, 22, 233]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[PID: 4032][C:\KAV2006\KWatch.EXE]  [Kingsoft Corporation, 2005, 9, 27, 51]
    [C:\KAV2006\KAVIPC2.DLL]  [Kingsoft Corporation, 2004, 12, 28, 20]
    [C:\KAV2006\KAEPlat.DLL]  [Kingsoft Corp., 2004, 11, 26, 53]
    [C:\KAV2006\KAEMem.DAT]  [Kingsoft, 2004, 11, 9, 11]
[PID: 3932][C:\KAV2006\KPfwSvc.EXE]  [Kingsoft Corporation, 2005, 9, 5, 28]
[PID: 2272][C:\KAV2006\KMailMon.EXE]  [Kingsoft Corporation, 2005, 10, 8, 85]
    [C:\KAV2006\KAntiSpm.dll]  [N/A, 1, 0, 0, 2]
    [C:\KAV2006\KAVIPC2.DLL]  [Kingsoft Corporation, 2004, 12, 28, 20]
    [C:\KAV2006\KAECall2.DLL]  [Kingsoft Corporation, 2004, 12, 28, 7]
    [C:\KAV2006\KAEPlat.DLL]  [Kingsoft Corp., 2004, 11, 26, 53]
    [C:\KAV2006\KAEMem.DAT]  [Kingsoft, 2004, 11, 9, 11]
    [C:\KAV2006\KAConfig.DLL]  [Kingsoft Corporation, 2005, 3, 23, 30]
    [C:\KAV2006\KASocket.dll]  [Kingsoft Corporation, 2005, 2, 22, 233]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[PID: 2404][C:\KAV2006\KPFW32.EXE]  [Kingsoft Corporation, 2005, 11, 22, 606]
    [C:\KAV2006\KASocket.dll]  [Kingsoft Corporation, 2005, 2, 22, 233]
    [C:\KAV2006\KAVIPC2.DLL]  [Kingsoft Corporation, 2004, 12, 28, 20]
    [C:\KAV2006\KAConfig.DLL]  [Kingsoft Corporation, 2005, 3, 23, 30]
    [C:\KAV2006\FiltList.dll]  [N/A, N/A]
    [C:\KAV2006\KAVPassp.DLL]  [Kingsoft Corporation, 2005, 11, 22, 221]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\KAV2006\KAEPlat.DLL]  [Kingsoft Corp., 2004, 11, 26, 53]
    [C:\KAV2006\KAEMem.DAT]  [Kingsoft, 2004, 11, 9, 11]
[PID: 2836][C:\KAV2006\KAV32.exe]  [Kingsoft Corporation, 2005, 11, 24, 2008]
    [C:\KAV2006\KASocket.dll]  [Kingsoft Corporation, 2005, 2, 22, 233]
    [C:\KAV2006\KAV32Res.dll]  [Kingsoft Corporation, 2005, 11, 22, 22]
    [C:\KAV2006\KAEPlat.DLL]  [Kingsoft Corp., 2004, 11, 26, 53]
    [C:\KAV2006\KAEMem.DAT]  [Kingsoft, 2004, 11, 9, 11]
    [C:\KAV2006\KAConfig.DLL]  [Kingsoft Corporation, 2005, 3, 23, 30]
    [C:\KAV2006\KAVIPC2.DLL]  [Kingsoft Corporation, 2004, 12, 28, 20]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\KAV2006\KAVPassp.DLL]  [Kingsoft Corporation, 2005, 11, 22, 221]
    [C:\KAV2006\DBAgent.DLL]  [Kingsoft Corporation, 2005, 10, 27, 9]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 3464][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\KAV2006\KASocket.dll]  [Kingsoft Corporation, 2005, 2, 22, 233]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\KAV2006\KAVAFish.DLL]  [Kingsoft Corporation, 2006, 10, 25, 27]
[PID: 2816][C:\KAV2006\KAVStart.EXE]  [Kingsoft Corporation, 2006, 11, 10, 212]
    [C:\KAV2006\KASocket.dll]  [Kingsoft Corporation, 2005, 2, 22, 233]
    [C:\KAV2006\KAVIPC2.DLL]  [Kingsoft Corporation, 2004, 12, 28, 20]
    [C:\KAV2006\SvcTimer.DLL]  [Kingsoft Corporation, 2006.12.22.84]
    [C:\KAV2006\PopSprt3.dll]  [Kingsoft Corporation, 2006, 9, 26, 38]
    [C:\KAV2006\KAVPassp.dll]  [Kingsoft Corporation, 2005, 11, 22, 221]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[PID: 2088][E:\software\灰鸽子木马专杀\HijackThis 1.99.0\HijackThis1991汉化版\HijackThis1991zww.exe]  [Soeperman Enterprises Ltd., 1.99.0001]
    [C:\KAV2006\KASocket.dll]  [Kingsoft Corporation, 2005, 2, 22, 233]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[PID: 3512][C:\WINDOWS\system32\msiexec.exe]  [Microsoft Corporation, 3.1.4000.1823]
[PID: 2964][C:\Downloads\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [C:\KAV2006\KASocket.dll]  [Kingsoft Corporation, 2005, 2, 22, 233]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
109.10.1.17    bjdccs
127.0.0.1      localhost

==================================
API HOOK
警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
入口点错误:LoadLibraryExW

==================================


[/CODE]
gototop
 

引用:
【花花公子与小赖虫的贴子】  最近我公司的好多电脑也中了此病毒,我用瑞星升级到最新版终于把它给杀掉了,但查杀时间比较长,所以我就从网上找了手动查杀的方法。据瑞星报的是灰鸽子,我不知道是不是误报,我把我找的手动查杀资料发出来,肯定可以解决此问题。


IEXPLORE.EXE可以进程的最终解决方案!
该病毒感染的迹象:
1,在启动到桌面的时候以system为用户名建立iexplore.exe或是IEXPLORE.EXE进程,不仅占用大量内存,而且每过几秒种就自动复制一个!
2,具有很深的隐藏性,不容易被用户所发现。通过定位该进程始终指向正常的C:\Program Files\Internet Explorer\IEXPLORE.EXE
经过确认其实这个进程是和twunk32.exe  有着某种的关系。
手工查杀twunk32.exe:
1、点击:“开始”、“运行”。键入regedit,按回车。清理注册表:
(1)展开:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
删除:"load"=""  这项中招主要表现为图片
(2)展开:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
删除:"twin"="c:\\windows\\system32\\twunk32.exe"
2、重启。显示隐藏文件。
3、删除c:\windows\system32\twunk32.exe。
4、卸载QQ。重新安装。因为QQ文件夹中的TIMPlatform.exe已被病毒覆盖,或是删除TIMPlatform.exe也行,这点很重要!

    为什么要这样做呢?原因是该病毒监控并修改注册表,还把自己设置为启动加载项,其他木马杀客 恶意软件清理 360安全 黄山等都不能彻底的杀掉。此病毒寄存在腾讯公司的聊天软件QQ里面,就算你重装或还原了系统,如果没有删除QQ,是没用的。因为病毒在QQ里头,有个隐藏文件,一运行QQ就感染。重装QQ也是无效的,必须将整个QQ目录包全部删了。所以:步骤如下:
    1、重装或还原系统,
    2、直接删除整个QQ目录包,
    还原后再重新安装无毒的QQ原程序,OK。



………………

非常感谢!!你的东西我记下了。不过还好我可能中的和你不同。所以没有发现
现在可以说可能是瑞星的一个BUG,12月29日升级前的误报,目前升级到1月4日就不再有了
非常感谢
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT