回复: adware.win32/rugo怎么杀?急!!!

c:\windows\system32\b5a3.dll分析结果:
反病毒引擎版本最后更新扫描结果
a-squared4.5.0.242009.07.28AdWare.Bdsearch!IK
AhnLab-V35.0.0.22009.07.28-
AntiVir7.9.0.2282009.07.28TR/Agent.49152
Antiy-AVL2.0.3.72009.07.28-
Authentium5.1.2.42009.07.28W32/AdAgent.I.gen!Eldorado
Avast4.8.1335.02009.07.27Win32:Agent-GRW
AVG8.5.0.3872009.07.28-
BitDefender7.22009.07.28Gen:Adware.Heur.Hu8@GmhJoiob
CAT-QuickHeal10.002009.07.28-
ClamAV0.94.12009.07.28-
Comodo17902009.07.28-
DrWeb5.0.0.121822009.07.28Trojan.DownLoader.origin
eSafe7.0.17.02009.07.27-
eTrust-Vet31.6.66432009.07.28-
F-Prot4.4.4.562009.07.28W32/AdAgent.I.gen!Eldorado
F-Secure8.0.14470.02009.07.28-
Fortinet3.120.0.02009.07.28-
GData192009.07.28Gen:Adware.Heur.Hu8@GmhJoiob
IkarusT3.1.1.64.02009.07.28AdWare.Bdsearch
Jiangmin11.0.8002009.07.28Heur:Adware/MsLock
K7AntiVirus7.10.8032009.07.27-
Kaspersky7.0.0.1252009.07.28-
McAfee56902009.07.27-
McAfee+Artemis56902009.07.27-
McAfee-GW-Edition6.8.52009.07.28Heuristic.LooksLike.Trojan.Agent.J
Microsoft1.49032009.07.28Adware:Win32/Rugo
NOD3242842009.07.28-
Norman
2009.07.28-
nProtect2009.1.8.02009.07.28-
Panda10.0.0.142009.07.28-
PCTools4.4.2.02009.07.28-
Prevx3.02009.07.28-
Rising21.40.13.002009.07.28-
Sophos4.44.02009.07.28Rugo
Sunbelt3.2.1858.22009.07.28AdWare.Win32.WSearch
Symantec1.4.4.122009.07.28-
TheHacker6.3.4.3.3752009.07.28-
TrendMicro8.950.0.10942009.07.28-
VBA323.12.10.92009.07.28-
ViRobot2009.7.28.18572009.07.28-
VirusBuster4.6.5.02009.07.27-
附加信息
File size: 548864 bytes
MD5  : ce4fc2ef676974113422feb7ce7abbf2
SHA1  : d6bcd97e4dccd327e852fa6014132b422fcfb26e
SHA256: f4754159614ae61f4a64a2217a7d733020ac9d99dbc08260164981e5ec53a02e
PEInfo: PE Structure information
       
        ( base data )
        entrypointaddress.: 0x3DD33
        timedatestamp.....: 0x4A6E4EFE (Tue Jul 28 03:06:06 2009)
        machinetype.......: 0x14C (Intel I386)
       
        ( 5 sections )
        name viradd virsiz rawdsiz ntrpy md5
        .text 0x1000 0x63966 0x64000 6.69 01dfb99cc9916195644974e70eecae5e
.rdata 0x65000 0xD8EA 0xE000 4.86 16faf3b10eb25f5d4077a8b2ba35e746
.data 0x73000 0x531CC 0x5000 5.39 0fd0b48c28b6a079a85330da810e360b
.rsrc 0xC7000 0x1288 0x2000 3.03 6967db2044f6677da6611f3ec1f19b0b
.reloc 0xC9000 0xB152 0xC000 5.66 b85c193034ec9ee805a6d8f918114913
       
        ( 10 imports )
       
>advapi32.dll: RegQueryValueExA, InitializeSecurityDescriptor,RegOpenKeyA, RegSetValueExA, RegCreateKeyA, GetUserNameA,RegCreateKeyExA, RegQueryValueA, RegSetValueA, RegDeleteKeyA,RegDeleteValueA, RegOpenKeyExA, RegQueryInfoKeyA, RegEnumKeyExA,SetSecurityDescriptorDacl, RegCloseKey
> gdi32.dll: DeleteObject,CreateRectRgn, GetPixel, GetTextExtentPoint32A, CreateSolidBrush,GetStockObject, GetObjectA, GetDeviceCaps, BitBlt,CreateCompatibleBitmap, DeleteDC, SelectObject, CreateCompatibleDC,SaveDC, RestoreDC, CombineRgn
> kernel32.dll:DeleteCriticalSection, GetLocalTime, CloseHandle, UnmapViewOfFile,MapViewOfFile, CreateFileMappingA, OpenFileMappingA, ReleaseMutex,FlushViewOfFile, WaitForSingleObject, CreateMutexA, FindClose,FindFirstFileA, GetLastError, GetSystemTimeAsFileTime, SetErrorMode,MultiByteToWideChar, GetShortPathNameA, GetTempFileNameA, GetTempPathA,Sleep, CopyFileA, SetFileAttributesA, GetWindowsDirectoryA,DeleteFileA, GetVolumeInformationA, GetSystemDirectoryA, lstrcmpA,FindNextFileA, lstrcatA, lstrcpyA, CreateDirectoryA, GetVersionExA,SetProcessWorkingSetSize, GetCurrentProcess, GetTickCount,InterlockedExchange, GetACP, GetLocaleInfoA, GetThreadLocale,EnterCriticalSection, LeaveCriticalSection, FlushInstructionCache,HeapFree, GetProcessHeap, HeapAlloc, WideCharToMultiByte,InterlockedDecrement, lstrlenA, GetCurrentThreadId, GlobalUnlock,GlobalLock, GlobalAlloc, lstrlenW, MulDiv, InterlockedIncrement,GetModuleFileNameA, GetModuleHandleA, FreeLibrary, SizeofResource,LoadResource, FindResourceA, InitializeCriticalSection, lstrcmpiA,lstrcpynA, IsDBCSLeadByte, GetProcAddress, LoadLibraryA, CreateThread,SetEvent, OpenEventA, CreateProcessA, WaitForMultipleObjects,CreateEventA, Module32Next, Module32First, CreateToolhelp32Snapshot,GetCurrentDirectoryA, Process32Next, Process32First, ReadFile,CreateFileA, TerminateProcess, DeviceIoControl, GetFileAttributesA,VirtualAlloc, VirtualFree, SetFilePointer, WriteFile, SetEndOfFile,GetStdHandle, QueryPerformanceCounter, SetUnhandledExceptionFilter,IsBadWritePtr, HeapCreate, HeapDestroy, TlsGetValue, RaiseException,TlsSetValue, TlsFree, SetLastError, TlsAlloc, GetOEMCP, GetCPInfo,LCMapStringW, LCMapStringA, RemoveDirectoryA, GetCommandLineA,HeapReAlloc, VirtualQuery, GetSystemInfo, VirtualProtect,GetDriveTypeA, FileTimeToLocalFileTime, FileTimeToSystemTime,ExitProcess, RtlUnwind, HeapSize, GetFullPathNameA, FlushFileBuffers,SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA,GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW,UnhandledExceptionFilter, GetTimeZoneInformation, GetStringTypeA,GetStringTypeW, GetUserDefaultLCID, EnumSystemLocalesA, IsValidLocale,IsValidCodePage, IsBadReadPtr, IsBadCodePtr, SetStdHandle,GetLocaleInfoW, CompareStringA, CompareStringW,SetEnvironmentVariableA, LocalFree, LoadLibraryExA, GetCurrentProcessId
>ole32.dll: CoTaskMemRealloc, CLSIDFromString, CLSIDFromProgID,CoGetClassObject, OleLockRunning, CoTaskMemAlloc, StringFromGUID2,OleUninitialize, OleInitialize, CreateStreamOnHGlobal,CoCreateInstance, CoUninitialize, CoInitialize, CoTaskMemFree
> oleaut32.dll: -, -, -, -, -, -, -, -, -, -, -, -
> shell32.dll: SHGetFolderPathA
> urlmon.dll: URLDownloadToFileA
>user32.dll: GetForegroundWindow, SetForegroundWindow,SystemParametersInfoA, MapWindowPoints, ShowWindow, UpdateWindow,PeekMessageA, GetMessageA, TranslateMessage, EnumWindows,AdjustWindowRectEx, FindWindowExA, PostMessageA,CreateAcceleratorTableA, CharNextA, GetParent, GetClassNameA,RedrawWindow, GetDlgItem, IsWindow, DestroyAcceleratorTable, GetFocus,DispatchMessageA, IsChild, GetWindow, SetFocus, BeginPaint, EndPaint,GetDesktopWindow, InvalidateRgn, InvalidateRect, FillRect, SetCapture,ReleaseCapture, GetSysColor, CreateWindowExA, CallWindowProcA,RegisterWindowMessageA, RegisterClassExA, GetWindowTextLengthA,GetWindowTextA, DefWindowProcA, SetActiveWindow, LoadCursorA,GetClassInfoExA, KillTimer, SetTimer, SetWindowPos, MoveWindow,SetWindowTextA, SendMessageA, GetWindowLongA, SetWindowLongA,DestroyWindow, PostQuitMessage, wsprintfA, SetWindowRgn, ReleaseDC,GetWindowRect, GetClientRect, GetSystemMetrics, LoadImageA,UnregisterClassA, GetDC
> wininet.dll: InternetReadFile,HttpSendRequestA, FindFirstUrlCacheEntryA, FindNextUrlCacheEntryA,GetUrlCacheEntryInfoA, InternetCrackUrlA, InternetOpenA,InternetConnectA, InternetCloseHandle, HttpOpenRequestA,DeleteUrlCacheEntry
> ws2_32.dll: -, -, -
       
        ( 1 exports )
       
> Always, DSDD_YUNJ_DOSS, GetPlayerVersion, playAdk
TrID  : File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
ssdeep: 12288:ddfAJ5ChL/XI1W5WRU04L15D4Q/CYz4hBV7j9H6d1fzaXIRpZ9InBJaol1UNFRR2:d9KChLACK+PD9/Urj96XaXIRpZ9InBJf
PEiD  : -
RDS  : NSRL Reference Data Set
-