各位大哥:
我用卡卡听诊器查出计算机中存在“模块覆盖型”的灰鸽子病毒,用瑞星的专杀工具无法将文件提取,清除后重启进程中就又有了。
用手工清除的办法,用在安全模式下搜索_hook.dll也只有两个mag_hook.dll,而且这两个好像是系统自带的,用regedit.exe查不出什么问题。
我该怎么办?诸位大哥帮帮我吧!怎么才能够清除干净?
我用瑞星助手查了一下进程:
[IEXPLORE.EXE]
PID = 0x2ec
CommandLine = "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
IEXPLORE.EXE
0x400000
C:\Program Files\Internet Explorer\IEXPLORE.EXE
6.00.2800.1106
Microsoft Corporation
Internet Explorer
2002-08-29 09:32:08
ntdll.dll
0x77f80000
C:\WINNT\system32\NTDLL.DLL
5.00.2195.7006
Microsoft Corporation
NT Layer DLL
2005-08-16 18:56:12
kernel32.dll
0x77e60000
C:\WINNT\system32\KERNEL32.DLL
5.00.2195.7099
Microsoft Corporation
Windows NT BASE API Client DLL
2006-06-21 14:51:46
user32.dll
0x77df0000
C:\WINNT\system32\USER32.DLL
5.00.2195.7032
Microsoft Corporation
Windows 2000 USER API Client DLL
2005-06-03 22:18:06
GDI32.dll
0x77f40000
C:\WINNT\system32\GDI32.DLL
5.00.2195.7073
Microsoft Corporation
GDI Client DLL
2005-12-30 08:15:30
advapi32.dll
0x796d0000
C:\WINNT\system32\ADVAPI32.DLL
5.00.2195.7038
Microsoft Corporation
Advanced Windows 32 Base API
2005-06-03 22:18:06
RPCRT4.dll
0x786f0000
C:\WINNT\system32\rpcrt4.dll
5.00.2195.7085
Microsoft Corporation
Remote Procedure Call Runtime
2006-04-13 10:46:40
oleaut32.dll
0x77990000
C:\WINNT\system32\OLEAUT32.DLL
2.40.4522
Microsoft Corporation
2003-06-20 03:05:04
ole32.dll
0x7cf00000
C:\WINNT\system32\OLE32.DLL
5.00.2195.7059
Microsoft Corporation
Microsoft OLE for Windows
2005-09-05 13:47:36
mpr.dll
0x79b20000
C:\WINNT\system32\mpr.dll
5.00.2195.6824
Microsoft Corporation
Multiple Provider Router DLL
2006-06-21 14:51:46
version.dll
0x777e0000
C:\WINNT\system32\version.dll
5.00.2195.6623
Microsoft Corporation
Version Checking and File Installation Libraries
2003-06-20 03:05:04
LZ32.DLL
0x75950000
C:\WINNT\system32\lz32.dll
5.00.2195.6611
Microsoft Corporation
LZ Expand/Compress API DLL
2003-06-20 03:05:04
comctl32.dll
0x71710000
C:\WINNT\system32\comctl32.dll
5.81
Microsoft Corporation
Common Controls Library
2006-08-28 16:44:10
shell32.dll
0x78f90000
C:\WINNT\system32\SHELL32.DLL
5.00.3900.7105
Microsoft Corporation
Windows Shell Common Dll
2006-07-13 15:08:54
SHLWAPI.dll
0x70a70000
C:\WINNT\system32\SHLWAPI.DLL
6.00.2800.1896 (xpsp2.061023-0947)
Microsoft Corporation
Shell Light-weight Utility Library
2006-10-23 10:06:00
msvcrt.dll
0x78000000
C:\WINNT\system32\msvcrt.dll
6.10.9844.0
Microsoft Corporation
Microsoft (R) C Runtime Library
2003-06-20 03:05:04
wininet.dll
0x63000000
C:\WINNT\system32\WININET.DLL
6.00.2800.1586
Microsoft Corporation
Internet Extensions for Win32
2006-10-23 10:06:02
CRYPT32.dll
0x79c40000
C:\WINNT\system32\CRYPT32.DLL
5.131.2195.6926
Microsoft Corporation
Crypto API32
2005-06-03 22:18:08
MSASN1.dll
0x773f0000
C:\WINNT\system32\msasn1.dll
5.00.2195.6905
Microsoft Corporation
ASN.1 Runtime APIs
2005-06-03 22:18:08
wsock32.dll
0x74fd0000
C:\WINNT\system32\wsock32.dll
5.00.2195.6603
Microsoft Corporation
Windows Socket 32-Bit DLL
2003-06-20 03:05:04
WS2_32.DLL
0x74fb0000
C:\WINNT\system32\ws2_32.dll
5.00.2195.6601
Microsoft Corporation
Windows Socket 2.0 32-Bit DLL
2003-06-20 03:05:04
WS2HELP.DLL
0x74fa0000
C:\WINNT\system32\ws2help.dll
5.00.2134.1
Microsoft Corporation
Windows Socket 2.0 Helper for Windows NT
2002-08-15 12:00:00
IMAGEHLP.DLL
0x77900000
C:\WINNT\system32\IMAGEHLP.DLL
5.00.2195.6613
Microsoft Corporation
Windows NT Image Helper
2003-06-20 03:05:04
winmm.dll
0x77530000
C:\WINNT\system32\winmm.dll
5.00.2161.1
Microsoft Corporation
MCI API DLL
2002-08-15 12:00:00
AVICAP32.dll
0x74810000
C:\WINNT\system32\avicap32.dll
5.00.2134.1
Microsoft Corporation
AVI Capture window class
2002-08-15 12:00:00
MSVFW32.dll
0x6a1a0000
C:\WINNT\system32\msvfw32.dll
5.00.2195.6612
Microsoft Corporation
Microsoft Video for Windows DLL
2003-06-20 03:05:04
msacm32.dll
0x773d0000
C:\WINNT\system32\msacm32.dll
5.00.2134.1
Microsoft Corporation
Microsoft ACM Audio Filter
2002-08-15 12:00:00
IMM32.DLL
0x75e00000
C:\WINNT\system32\imm32.dll
5.00.2195.6655
Microsoft Corporation
Windows 2000 IMM32 API Client DLL
2003-06-20 03:05:04
LPK.DLL
0x6c330000
C:\WINNT\system32\lpk.dll
5.00.2195.6692
Microsoft Corporation
Language Pack
2003-06-20 03:05:04
USP10.dll
0x65d20000
C:\WINNT\system32\usp10.dll
1.0325.2195.6692
Microsoft Corporation
Uniscribe Unicode script processor
2003-06-20 03:05:04
JBQGIZ.DAT
0x1180000
C:\WINNT\JBQGIZ.DAT
2007-01-31 21:48:04
msafd.dll
0x74f50000
C:\WINNT\system32\msafd.dll
5.00.2195.6602
Microsoft Corporation
Microsoft Windows Sockets 2.0 Service Provider
2003-06-20 03:05:04
wshtcpip.dll
0x74f90000
C:\WINNT\system32\wshtcpip.dll
5.00.2195.6601
Microsoft Corporation
Windows Sockets Helper DLL
2003-06-20 03:05:04
rnr20.dll
0x77800000
C:\WINNT\system32\RNR20.DLL
5.00.2195.6603
Microsoft Corporation
Windows Socket2 NameSpace DLL
2003-06-20 03:05:04
DNSAPI.DLL
0x77960000
C:\WINNT\system32\dnsapi.dll
5.00.2195.7100
Microsoft Corporation
DNS Client API DLL
2006-07-06 19:45:02
iphlpapi.dll
0x77300000
C:\WINNT\system32\IPHLPAPI.DLL
5.00.2195.7097
Microsoft Corporation
IP Helper API
2006-05-19 17:17:56
ICMP.dll
0x774e0000
C:\WINNT\system32\icmp.dll
5.00.2134.1
Microsoft Corporation
ICMP DLL
2002-08-15 12:00:00
MPRAPI.dll
0x772e0000
C:\WINNT\system32\mprapi.dll
5.00.2181.1
Microsoft Corporation
Windows NT MP Router Administration DLL
2002-08-15 12:00:00
SAMLIB.DLL
0x750e0000
C:\WINNT\system32\samlib.dll
5.00.2195.6944
Microsoft Corporation
SAM Library DLL
2005-06-03 22:18:24
NETAPI32.DLL
0x7cea0000
C:\WINNT\system32\NETAPI32.DLL
5.00.2195.7108
Microsoft Corporation
Net Win32 API DLL
2006-08-17 18:44:10
Secur32.dll
0x797b0000
C:\WINNT\system32\secur32.dll
5.00.2195.6695
Microsoft Corporation
Security Support Provider Interface
2003-06-20 03:05:04
NTDSAPI.dll
0x77bd0000
C:\WINNT\system32\ntdsapi.dll
5.00.2195.6666
Microsoft Corporation
NT5DS
2003-06-20 03:05:04
WLDAP32.DLL
0x77930000
C:\WINNT\system32\WLDAP32.DLL
5.00.2195.7017
Microsoft Corporation
Win32 LDAP API DLL
2005-06-03 22:18:08
NETRAP.dll
0x75150000
C:\WINNT\system32\netrap.dll
5.00.2134.1
Microsoft Corporation
Net Remote Admin Protocol DLL
2002-08-15 12:00:00
ACTIVEDS.DLL
0x77370000
C:\WINNT\system32\activeds.dll
5.00.2195.6601
Microsoft Corporation
ADs Router Layer DLL
2003-06-20 03:05:04
ADSLDPC.DLL
0x77340000
C:\WINNT\system32\adsldpc.dll
5.00.2195.6993
Microsoft Corporation
ADs LDAP Provider C DLL
2005-06-03 22:18:08
RTUTILS.DLL
0x777f0000
C:\WINNT\system32\rtutils.dll
5.00.2168.1
Microsoft Corporation
Routing Utilities
2002-08-15 12:00:00
SETUPAPI.DLL
0x6d990000
C:\WINNT\system32\SETUPAPI.DLL
5.00.2195.6622
Microsoft Corporation
Windows Setup API
2003-06-20 03:05:04
USERENV.DLL
0x794d0000
C:\WINNT\system32\USERENV.DLL
5.00.2195.7002
Microsoft Corporation
Userenv
2005-06-03 22:18:06
RASAPI32.dll
0x774a0000
C:\WINNT\system32\RASAPI32.DLL
5.00.2195.6920
Microsoft Corporation
Remote Access API
2005-06-03 22:18:08
rasman.dll
0x77480000
C:\WINNT\system32\RASMAN.DLL
5.00.2195.6824
Microsoft Corporation
Remote Access Connection Manager
2005-06-03 22:18:08
TAPI32.dll
0x774f0000
C:\WINNT\system32\TAPI32.DLL
5.00.2195.6664
Microsoft Corporation
Microsoft? Windows(TM) Telephony API Client DLL
2003-06-20 03:05:04
DHCPCSVC.DLL
0x77320000
C:\WINNT\system32\DHCPCSVC.DLL
5.00.2195.7085
Microsoft Corporation
DHCP Client Service
2006-05-19 17:17:56
winrnr.dll
0x777a0000
C:\WINNT\system32\winrnr.dll
5.00.2160.1
Microsoft Corporation
LDAP RnR Provider DLL
2002-08-15 12:00:00
rasadhlp.dll
0x777b0000
C:\WINNT\system32\rasadhlp.dll
5.00.2195.7098
Microsoft Corporation
Remote Access AutoDial Helper
2006-07-06 19:45:0