瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【推荐】关于落雪系列木马专杀..以及“橙色八月”专杀

«910111213141516   16  /  16  页   跳转

【推荐】关于落雪系列木马专杀..以及“橙色八月”专杀

[c:\program files\rising\rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [c:\program files\rising\rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 3292][C:\Program Files\Rising\Rav\RavMon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 33>
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 2464][C:\Program Files\Maxthon\Maxthon.exe]  <Maxthon International Ltd.><1, 5, 6, 39>
    [C:\Program Files\Maxthon\maxzlib.dll]  < ><1, 0, 0, 2>
    [C:\Program Files\Maxthon\Services\RealTime\real_time.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
[PID: 3100][F:\QQ\QQ.exe]  <TENCENT><0, 0, 0, 0>
    [F:\QQ\CoralAssist.DLL]  <Coral Team><4.5.0 build 20060515>
    [F:\QQ\CoralQQ.DLL]  <Coral Team><4.5.2 Build 20060830>
    [F:\QQ\ipsearcher.dll]  <N/A><1.0.0.4>
    [F:\QQ\QQBaseClassInDll.dll]  <><1, 0, 0, 1>
    [F:\QQ\QQHelperDll.dll]  <><1, 0, 0, 1>
    [F:\QQ\BasicCtrlDll.dll]  <Tencent><5, 0, 200, 370>
    [F:\QQ\QQAPI.dll]  <><1, 0, 0, 1>
    [F:\QQ\TIMProxy.dll]  <tencent><0, 3, 2, 4>
    [F:\QQ\LoginCtrl.dll]  <><1, 0, 0, 1>
    [F:\QQ\npkcntc.dll]  <INCA Internet Co., Ltd.><2006, 6, 27, 1>
    [F:\QQ\npkpdb.dll]  <INCA Internet Co., Ltd.><2003, 10, 1, 1>
    [F:\QQ\QQRes.dll]  <tencent><1, 0, 0, 1>
    [F:\QQ\QQMainFrame.dll]  <N/A><N/A>
    [F:\QQ\CQQApplication.dll]  <N/A><N/A>
    [F:\QQ\NewSkin.dll]  <><1, 0, 0, 1>
    [F:\QQ\HostingMgr.dll]  <><1, 0, 0, 1>
    [F:\QQ\CameraDll.dll]  <><1, 0, 0, 1>
    [F:\QQ\MailSummary.dll]  <><1, 0, 0, 1>
    [F:\QQ\QQSpace.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [F:\QQ\QQGroupMng.dll]  <><1, 0, 0, 1>
    [F:\QQ\GroupLive.dll]  <N/A><N/A>
    [F:\QQ\UserDefinedHead.dll]  <><1, 0, 0, 1>
    [F:\QQ\QQPlugin.dll]  <N/A><N/A>
    [F:\QQ\QQConfigPlugin.dll]  <><1, 0, 0, 1>
    [F:\QQ\QRingMng.dll]  <N/A><N/A>
    [F:\QQ\PhoneAPI.dll]  <><1, 0, 0, 1>
    [F:\QQ\DialerAllinOne.dll]  <tencent><1, 4, 0, 0>
    [F:\QQ\VPortal.dll]  <><1, 0, 0, 4>
    [F:\QQ\QQAvatar.dll]  <N/A><N/A>
    [F:\QQ\FlashAvatarDll.dll]  <><1, 4, 0, 1>
    [F:\QQ\LongConnection.dll]  <tencent><5, 0, 200, 160>
    [F:\QQ\QQPet.dll]  <><1, 0, 0, 1>
    [F:\QQ\QQSysMsgMng.dll]  <N/A><N/A>
    [F:\QQ\BQQApplication.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [F:\QQ\CommercesMng.dll]  <><1, 0, 0, 1>
    [F:\QQ\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
    [F:\QQ\QQAddr.dll]  <深圳市腾讯计算机系统有限公司><5, 0, 101, 240>
    [F:\QQ\QQSceneMng.dll]  <N/A><N/A>
    [F:\QQ\QQPhoneHelper.dll]  <腾讯科技(深圳)有限公司><2, 0, 1, 10>
[PID: 3848][F:\QQ\TIMPlatform.exe]  <tencent><0, 3, 1, 8>
    [F:\QQ\TIMProxy.dll]  <tencent><0, 3, 2, 4>
[PID: 2212][C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe]  <Microsoft Corporation><2.0.50727.42 (RTM.050727-4200)>
[PID: 3112][C:\Program Files\TTPlayer\TTPlayer.exe]  <Alen Soft><4, 6, 8, 0>
    [C:\Program Files\TTPlayer\ttpcomm.dll]  <N/A><N/A>
    [C:\Program Files\TTPlayer\ttpres.dll]  <Alen Soft><4, 6, 8, 0>
    [C:\Program Files\TTPlayer\AddIn\ttp_lrcsh.dll]  <N/A><N/A>
[PID: 2688][C:\Program Files\FlashGet\flashget.exe]  <FlashGet.com><1, 7, 3, 0>
[PID: 1928][C:\Program Files\Rising\Rav\Rav.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 75>
    [C:\Program Files\Rising\Rav\PlugIn\RsPgScan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 17>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RavUI.Dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 65>
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
    [C:\Program Files\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 32>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\Rising\Rav\RavUIMsg.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
    [C:\Program Files\Rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
    [C:\Program Files\Rising\Rav\MVEngine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 15>
    [C:\Program Files\Rising\Rav\Engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 34>
    [C:\Program Files\Rising\Rav\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\Unpacker.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\Program Files\Rising\Rav\RSUnpack.dll]  <Beijing Rising Technology Co., Ltd.><1, 0, 0, 13>
    [C:\Program Files\Rising\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 15>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\ExtFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\Program Files\Rising\Rav\ScanNet.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 2408][C:\Program Files\WinRAR\WinRAR.exe]  <N/A><N/A>
[PID: 3076][C:\DOCUME~1\YLPMDMFG\LOCALS~1\Temp\Rar$EX00.703\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 

这里的工具我全下载用了。现在正常,但是我不敢重启机子,怕又不行了,怎么办啊
都重装四次机器了。本来正常了,可是我用了U盘里的东西又中招了。原来备份的资料,可能是U盘也有病毒吧。现在我把U盘格了。双击可以打开了。原来不能双击打开,只能用右键打开。
gototop
 

为什么我用迅雷下不了但是另存为就下得拉?用不用得啊?我中了Trojan.DL.Agent.lwz
,Trojan.DL.Agent.aoz
在C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\YDKFYBCX    engt32c[2].dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp    engt32c.dll
用落雪能不能杀啊?
[img][/img]
gototop
 

顺便说一句,好像我重装系统升级补丁以后就查出一堆的木马,删也删不掉,开机速度特别慢!出墙纸了还要等上一分多钟才有图标出来噢!我的可是新机噢!!!
gototop
 

好好学习.
gototop
 

版主得空回个信指导一下啊!
gototop
 

斑竹大哥,
麻烦你帮偶看看,这俩个病毒是不是你说的这些?

1:Trojan.DL.Delf.dry

2:Trojan.VBS.Agent.b

能用瑞星最新版杀掉吗?或者用什么办法?

前些天严重中毒,木马,浏览器被劫持...瑞星杀毒和防火墙全部挂掉..
刚重新装完俩三天,现在又提示有这个病毒..
可是偶刚用瑞星杀毒了,一个也没杀出来.是没有了?还是瑞星查不出来,也杀不掉呢?
好害怕.怕重新启动了瑞星又挂...
紧急求助斑竹大哥...感谢..
期待...

gototop
 
«910111213141516   16  /  16  页   跳转
页面顶部
Powered by Discuz!NT