瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » Trojan.PSW.LMir.aik 怎么杀
rjw0602 - 2005-11-17 19:33:00
急!急!急
BlackStone - 2005-11-17 19:39:00
用Autoruns保存一个日志发上来
日志保存方法:选择File->Save菜单项
保存日志时注意选择Options->Hide Microsoft Entries菜单项(设置了这项后点工具栏的刷新按钮)

工具的下载、使用参考http://forum.ikaka.com/topic.asp?board=28&artid=7318038第14楼
rjw0602 - 2005-11-17 20:50:00
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ NvCplDaemonNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll

+ nwizNVIDIA nView Wizard, Version 53.03 NVIDIA Corporationc:\windows\system32\nwiz.exe

+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmon.exe

+ RavTimerRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtimer.exe

+ rxc:\windows\rundll32.exe

C:\Documents and Settings\←☆★§★☆→\「开始」菜单\程序\启动

+ Rainlendar精美日历.lnkc:\program files\rainlendar\rainlendar.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

+ NvMediaCenterNVIDIA Media Center LibraryNVIDIA Corporationc:\windows\system32\nvmctray.dll

+ SipodDDPhoneDDPhonee:\ddphone\ddphone.exe

HKLM\System\CurrentControlSet\Services

+ NVSvcProvides system and desktop level support to the NVIDIA display driverNVIDIA Corporationc:\windows\system32\nvsvc32.exe

+ RsCCenterCCenterrisingc:\program files\rising\rav\ccenter.exe

+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Desktop ExplorerNVIDIA Desktop Explorer, Version 53.03 NVIDIA Corporationc:\windows\system32\nvshell.dll

+ Desktop Explorer MenuNVIDIA Desktop Explorer, Version 53.03 NVIDIA Corporationc:\windows\system32\nvshell.dll

+ GMail DriveGMail File System Shell Namespace ExtensionBjarke Viksoec:\windows\system32\shellext\gmailfs.dll

+ GMailFS Context MenuGMail File System Shell Namespace ExtensionBjarke Viksoec:\windows\system32\shellext\gmailfs.dll

+ GMailFS Drop HandlerGMail File System Shell Namespace ExtensionBjarke Viksoec:\windows\system32\shellext\gmailfs.dll

+ GMailFS Property SheetGMail File System Shell Namespace ExtensionBjarke Viksoec:\windows\system32\shellext\gmailfs.dll

+ nView Desktop Context MenuNVIDIA Desktop Explorer, Version 53.03 NVIDIA Corporationc:\windows\system32\nvshell.dll

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ ThunderIEHelper Classxunleibho Modulec:\windows\system32\xunleibho_v5.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ 浩方对战平台浩方对战平台上海浩方在线信息技术有限公司e:\浩方对战平台\gameclient.exe

+ 易趣购物File not found: http://click2.ad4all.net/url2/urlmanage/url.asp?id=1

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls

+ APIHookDll.dllFile not found: APIHookDll.dll

BlackStone - 2005-11-17 20:53:00
+ rxc:\windows\rundll32.exe

用Autoruns删除启动像
重启
删除c:\windows\rundll32.exe
rjw0602 - 2005-11-17 21:20:00
还是不行啊 1按CTRL+ALT+DEL 那个rundll32.exe
又出来了
1
查看完整版本: Trojan.PSW.LMir.aik 怎么杀