瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 请高手帮忙看看啊
海之龙啸 - 2005-7-21 23:13:00
我的注册表里有这么一项,怎么删都删不了。
advapi32    RUNDLL32 C:\WINNT\Downlo~1\_IS_ISC.DLL,isc
的病的时候就是这样:
advapi32    RUNDLL32 C:\WINNT\Downlo~1\_IS_ISC.DLL,isc
我上网前将任务管理器的RUNDLL32.exe强行关毕
用windows木马清道夫是查在这个位置
C:\WINNT\Downloaded Program Files\_IS_IDrv.exe---------------这个目录下找不到这些文件!!
C:\WINNT\Downloaded Program Files\_IS_KWRD.ini
C:\WINNT\Downloaded Program Files\_IS_BSYS.ini
C:\WINNT\Downloaded Program Files\_IS_7ZD.DLL
C:\WINNT\Downloaded Program Files\_IS_BSYS.DLL
C:\WINNT\Downloaded Program Files\_IS_IEBR.dll
C:\WINNT\Downloaded Program Files\_IS_ISC.DLL
C:\WINNT\Downloaded Program Files\_IS_LNBK.dll
C:\WINNT\Downloaded Program Files\_IS_LOIE.dll
C:\WINNT\Downloaded Program Files\_IS_MABR.dll
C:\WINNT\Downloaded Program Files\_IS_UPD.DLL
C:\WINNT\Downloaded Program Files\_IS_WEBH.dll
C:\WINNT\Downloaded Program Files\_IS_BAR.ini
C:\WINNT\Downloaded Program Files\_IS_BHO.ini
C:\WINNT\Downloaded Program Files\_IS_Site.ini
C:\WINNT\Downloaded Program Files\_IS_ml.dat
C:\WINNT\Downloaded Program Files\_IS_KWRD.ini.cpz
C:\WINNT\Downloaded Program Files\_IS_BSYS.ini.cpz

C:\WINNT\BACKUP\_IS_UPD.dll---我用启动光盘进纯DOS用del命令删除这些文件,重起后又还原!!
C:\WINNT\BACKUP\_IS_BSYS.DLL
C:\WINNT\BACKUP\_IS_LOIE.dll
C:\WINNT\BACKUP\_IS_LNBK.dll
C:\WINNT\BACKUP\_IS_MABR.DLL
C:\WINNT\BACKUP\_IS_IEBR.DLL
C:\WINNT\BACKUP\_IS_WEBH.DLL
C:\WINNT\BACKUP\_IS_7ZD.DLL
C:\WINNT\BACKUP\_IS_IDrv.exe
C:\WINNT\BACKUP\_IS_Site.ini
C:\WINNT\BACKUP\_IS_BAR.ini
C:\WINNT\BACKUP\_IS_BHO.INI
C:\WINNT\BACKUP\_IS_KWRD.ini
这些文件长期驻留内存。随系统启动!!
它的文件夹删了。可是过了一段时间注册表又出现了
advapi32    RUNDLL32 C:\WINNT\Downlo~1\_IS_0518\_IS_ISC.DLL,isc
不过没有发病。这是怎么回事啊!会不会又要发了啊!请高手帮忙看看啊。
郁闷!!!!!!!!!!

附件: 5458332005721231357.BMP
lxw850610 - 2005-7-22 0:06:00
SF......
不言放弃 - 2005-7-22 1:39:00
引用:
【海之龙啸的贴子】我的注册表里有这么一项,怎么删都删不了。
advapi32    RUNDLL32 C:\WINNT\Downlo~1\_IS_ISC.DLL,isc
的病的时候就是这样:
advapi32    RUNDLL32 C:\WINNT\Downlo~1\_IS_ISC.DLL,isc
我上网前将任务管理器的RUNDLL32.exe强行关毕
用windows木马清道夫是查在这个位置
C:\WINNT\Downloaded Program Files\_IS_IDrv.exe---------------这个目录下找不到这些文件!!
C:\WINNT\Downloaded Program Files\_IS_KWRD.ini
C:\WINNT\Downloaded Program Files\_IS_BSYS.ini
C:\WINNT\Downloaded Program Files\_IS_7ZD.DLL
C:\WINNT\Downloaded Program Files\_IS_BSYS.DLL
C:\WINNT\Downloaded Program Files\_IS_IEBR.dll
C:\WINNT\Downloaded Program Files\_IS_ISC.DLL
C:\WINNT\Downloaded Program Files\_IS_LNBK.dll
C:\WINNT\Downloaded Program Files\_IS_LOIE.dll
C:\WINNT\Downloaded Program Files\_IS_MABR.dll
C:\WINNT\Downloaded Program Files\_IS_UPD.DLL
C:\WINNT\Downloaded Program Files\_IS_WEBH.dll
C:\WINNT\Downloaded Program Files\_IS_BAR.ini
C:\WINNT\Downloaded Program Files\_IS_BHO.ini
C:\WINNT\Downloaded Program Files\_IS_Site.ini
C:\WINNT\Downloaded Program Files\_IS_ml.dat
C:\WINNT\Downloaded Program Files\_IS_KWRD.ini.cpz
C:\WINNT\Downloaded Program Files\_IS_BSYS.ini.cpz

C:\WINNT\BACKUP\_IS_UPD.dll---我用启动光盘进纯DOS用del命令删除这些文件,重起后又还原!!
C:\WINNT\BACKUP\_IS_BSYS.DLL
C:\WINNT\BACKUP\_IS_LOIE.dll
C:\WINNT\BACKUP\_IS_LNBK.dll
C:\WINNT\BACKUP\_IS_MABR.DLL
C:\WINNT\BACKUP\_IS_IEBR.DLL
C:\WINNT\BACKUP\_IS_WEBH.DLL
C:\WINNT\BACKUP\_IS_7ZD.DLL
C:\WINNT\BACKUP\_IS_IDrv.exe
C:\WINNT\BACKUP\_IS_Site.ini
C:\WINNT\BACKUP\_IS_BAR.ini
C:\WINNT\BACKUP\_IS_BHO.INI
C:\WINNT\BACKUP\_IS_KWRD.ini
这些文件长期驻留内存。随系统启动!!
它的文件夹删了。可是过了一段时间注册表又出现了
advapi32    RUNDLL32 C:\WINNT\Downlo~1\_IS_0518\_IS_ISC.DLL,isc
不过没有发病。这是怎么回事啊!会不会又要发了啊!请高手帮忙看看啊。
郁闷!!!!!!!!!!
...........................


C:\WINNT\Downloaded Program Files\_IS_ISC.DLL是病毒根源
用这个工具删除
双击打开后
在文件名框中输入C:\WINNT\Downloaded Program Files\_IS_ISC.DLL
然后按清除按纽

附件: 364052200572213925.zip
1
查看完整版本: 请高手帮忙看看啊