瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 中了灰鸽子!实在找不到日志中的问题,请求帮忙!!!

12   2  /  2  页   跳转

中了灰鸽子!实在找不到日志中的问题,请求帮忙!!!

运行(双击)System Repair Engineer,使用“系统修复,文件关联,勾选“全选”点“修复”使所有扩展名都恢复正常。
运行(双击)System Repair Engineer,点“启动项目,服务,点“Win32服务应用程序”勾选“隐藏微软服务”选中病毒服务kv centro,vsw ,wint,WinWrCup选择“删除服务”点“设置”选择“否”最后重启。(每一个逗号隔开的就是一个病毒的服务,请逐一删除)

下载超级兔子。
http://www.pctutu.com/srmsdown.asp
安装好后,打开“超级兔子清理王”“专业卸载,卸载所有提示的垃圾软件,卸载是不要打开任何浏览窗口。卸载不了可以重启后再去卸载。
卸载完后,重启。
运行(双击)System Repair Engineer,使用“启动项目,注册表”来删除以下选项。
D:\Program Files\Internet Explorer\InfoMs.bin
D:\Program Files\Common Files\Microsoft Shared\MSINFO\_joice.vxd
删除
D:\Program Files\Internet Explorer\InfoMs.bin
D:\Program Files\Common Files\Microsoft Shared\MSINFO\_joice.vxd
D:\WINDOWS\wincup
D:\WINDOWS\System32\wint
D:\DOCUME~1\yy\LOCALS~1\Temp
D:\WINDOWS\hook.exe
修复后,重启,请再扫份日志粘上来。
gototop
 

使用“超级兔子清理王”“专业卸载时,无论重启多少次电脑都无法卸载“mmsassist彩信通”!
最后一步:运行(双击)System Repair Engineer,使用“启动项目,注册表”来删除以下选项时,在注册表处没有看到这六个选项D:\Program Files\Internet Explorer\InfoMs.bin
D:\Program Files\Common Files\Microsoft Shared\MSINFO\_joice.vxd
D:\WINDOWS\wincup
D:\WINDOWS\System32\wint
D:\DOCUME~1\yy\LOCALS~1\Temp
D:\WINDOWS\hook.exe
所以没有删除
gototop
 

2006-07-28,14:40:20

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional  (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><D:\WINDOWS\System32\ctfmon.exe>  [Microsoft Corporation]
    <iDuba Personal FireWall><D:\KAV6\Kavpfw.EXE>  [Kingsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <Load><rundll32 "D:\WINDOWS\Downloaded Program Files\NProtect.dll",NProtect>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
    <run><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <ISUSPM Startup><D:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup>  [InstallShield Software Corporation]
    <ISUSScheduler><"D:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start>  [InstallShield Software Corporation]
    <yahoo_mini><D:\Program Files\3721\Dlaccel\YDownloader.exe>  []
    <IMEKRMIG6.1><D:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE>  [Microsoft Corporation]
    <MSPY2002><D:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC>  []
    <RavTask><"D:\Program Files\rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <iDuba Personal FireWall><D:\KAV6\Kavpfw.EXE>  [Kingsoft Corporation]
    <KAVRUN><D:\KAV6\KAVRUN.EXE>  []
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  []
    <SoundMan><SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <Super Rabbit Winspeed><"F:\Program Files\Super Rabbit\MagicSet\winspeed.exe" /autokill:54>  [Super Rabbit Soft]
    <alsmt.exe><D:\WINDOWS\System32\alsmt.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><D:\WINDOWS\System32\Userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <SysTime><D:\PROGRA~1\WinKld\WinKld.dll>  [www.88dog.com]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><D:\KAV6\KaScrScn.scr>  []

==================================
gototop
 

启动文件夹
服务
[Ati HotKey Poller / Ati HotKey Poller]
  <D:\WINDOWS\System32\Ati2evxx.exe><N/A>
[ATI Smart / ATI Smart]
  <D:\WINDOWS\system32\ati2sgag.exe><>
[EPSON Printer Status Agent2 / EPSONStatusAgent2]
  <D:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe><SEIKO EPSON CORPORATION>
[IMAPI CD-Burning COM Service / ImapiService]
  <D:\WINDOWS\System32\imapi.exe><Microsoft Corporation>
[Kingsoft AntiVirus Service / KAVSvc]
  <D:\KAV6\KAVSvc.EXE><kingsoft Antivirus>
[Rising Process Communication Center / RsCCenter]
  <"D:\Program Files\rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"D:\Program Files\rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>

==================================
浏览器加载项
[Vision]
  {6671A431-5C3D-463d-A7CF-5587F9B7E191} <D:\PROGRA~1\MMSASS~1\mmsass~1.dll, >
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <D:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[V3ProX Control]
  {5DD731E6-D4F0-11D3-BE3F-00105A6FDA50} <D:\WINDOWS\DOWNLO~1\v3prox.ocx, Ahnlab, Inc.>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <D:\WINDOWS\System32\wuweb.dll, Microsoft Corporation>
[MUWebControl Class]
  {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <D:\WINDOWS\System32\muweb.dll, Microsoft Corporation>
[photo_uploader Control]
  {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <D:\WINDOWS\DOWNLO~1\PHOTO_~1.OCX, N/A>
[Kingsoft DUBA OnlineScan]
  {C8BD9ACB-F7EC-48E6-BB2F-DAADC6789E9A} <D:\WINDOWS\System32\kingsoft\ONLINE~1\kavclean.ocx, kingsoft>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <D:\WINDOWS\System32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[Ravonline]
  {DA984A6D-508E-11D6-AA49-0050FF3C628D} <D:\WINDOWS\Downloaded Program Files\RsOnline.dll, Beijing Rising Tech. Co., Ltd.>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <D:\WINDOWS\Downloaded Program Files\OL2005.dll, N/A>

==================================
gototop
 

正在运行的进程
[PID: 440][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 516][\??\D:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 540][\??\D:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 584][D:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 604][D:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 776][D:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 832][D:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 896][D:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 964][D:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1188][D:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2600.0000 (xpclient.010817-1148)>
    [D:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [D:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [D:\Program Files\rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1600][D:\WINDOWS\System32\conime.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1616][F:\Program Files\Super Rabbit\MagicSet\magicset.exe]  <Super Rabbit Soft><7.72>
[PID: 184][D:\Program Files\rising\Rav\RsAgent.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
    [D:\Program Files\rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
[PID: 196][D:\WINDOWS\msagent\AgentSvr.exe]  <Microsoft Corporation><2.00.0.3422>
[PID: 344][D:\Program Files\Microsoft Office\Office\WINWORD.EXE]  <Microsoft Corporation><9.0.2823>
    [D:\KAV6\MsPlugIn.DLL]  <Kingsoft Corp.><2003, 11, 25, 80>
    [D:\KAV6\KAVIPC.dll]  <Kingsoft Corp.><2002, 3, 29, 8>
    [D:\Program Files\rising\Rav\RsPlugIn.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [D:\Program Files\rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
    [D:\Program Files\rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 400][D:\Program Files\WinRAR\WinRAR.exe]  <N/A><N/A>
[PID: 892][D:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2600.0000 (xpclient.010817-1148)>
    [D:\WINDOWS\System32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 1068][D:\WINDOWS\System32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1140][D:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2600.0000 (xpclient.010817-1148)>
    [D:\WINDOWS\System32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 1440][D:\DOCUME~1\yy\LOCALS~1\Temp\Rar$EX75.078\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["D:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
gototop
 

我感觉删除“mmsassist彩信通”是关键!但是我看了兔子论坛都没有人能够回答这个问题,我直接在c盘中删除mmsassist文件夹都没有用,根本删除不了
gototop
 

再次麻烦我无邪啦!谢谢!!!
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT