瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】病毒Trojan.PSW.Misc.kiv 怎么杀不掉呢?

123   2  /  3  页   跳转

【求助】病毒Trojan.PSW.Misc.kiv 怎么杀不掉呢?

[C:\Program Files\航天信息\防伪开票\BIN\NetReport.bpl]  [, 1.0.0.0]
    [C:\Program Files\航天信息\防伪开票\BIN\SB_ValAddedTax.bpl]  [, 1.0.0.0]
    [C:\Program Files\航天信息\防伪开票\BIN\SBDataInOut.bpl]  [, 1.0.0.0]
    [C:\Program Files\航天信息\防伪开票\BIN\RZUTIL.DLL]  [, 1.0.0.5]
    [C:\Program Files\航天信息\防伪开票\BIN\SysInfoSet.bpl]  [, 1.0.0.0]
    [C:\Program Files\航天信息\防伪开票\BIN\Daodsp.bpl]  [, 1.0.0.0]
    [C:\Program Files\航天信息\防伪开票\BIN\TeleCommData.bpl]  [, 1.0.0.0]
    [C:\Program Files\航天信息\防伪开票\BIN\webdsnap60.bpl]  [Borland Software Corporation, 6.0.6.240]
    [C:\Program Files\航天信息\防伪开票\BIN\inet60.bpl]  [Borland Software Corporation, 6.0.6.240]
    [C:\Program Files\航天信息\防伪开票\BIN\inetdb60.bpl]  [Borland Software Corporation, 6.0.6.163]
    [C:\Program Files\航天信息\防伪开票\BIN\nmfast60.bpl]  [NetMasters, 6.0.6.163]
    [C:\Program Files\航天信息\防伪开票\BIN\dxBarC6.bpl]  [Developer Express Inc., 4.2.0.0]
    [C:\Program Files\航天信息\防伪开票\BIN\dxComnC6.bpl]  [Developer Express Inc., 1.2.1.0]
    [C:\Program Files\航天信息\防伪开票\BIN\dxPageControlC6.bpl]  [Developer Express Inc., 1.0.1.0]
    [C:\Program Files\航天信息\防伪开票\BIN\RzScanPckg.bpl]  [, 1.0.0.0]
    [C:\Program Files\航天信息\防伪开票\BIN\EhLib.bpl]  [, 1.0.0.0]
    [C:\Program Files\航天信息\防伪开票\BIN\EZTW32.DLL]  [N/A, N/A]
    [C:\Program Files\航天信息\防伪开票\BIN\SCANRECO.DLL]  [N/A, N/A]
    [C:\Program Files\航天信息\防伪开票\BIN\fpcheck.dll]  [N/A, N/A]
    [C:\Program Files\航天信息\防伪开票\BIN\twrece.dll]  [N/A, N/A]
    [C:\Program Files\航天信息\防伪开票\BIN\twscan.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\航天信息\防伪开票\BIN\recocore.dll]  [N/A, N/A]
    [C:\Program Files\航天信息\防伪开票\BIN\form.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\航天信息\防伪开票\BIN\ZIP.DLL]  [N/A, N/A]
    [C:\Program Files\航天信息\防伪开票\BIN\NetRenZ.bpl]  [, 1.0.0.0]
    [C:\Program Files\航天信息\防伪开票\BIN\InvBook.bpl]  [, 1.0.0.0]
    [C:\Program Files\航天信息\防伪开票\BIN\DeclareDuti.bpl]  [, 1.0.0.0]
    [C:\Program Files\航天信息\防伪开票\BIN\CInvManage.bpl]  [, 1.0.0.0]
    [C:\Program Files\航天信息\防伪开票\BIN\InvBook2.bpl]  [, 1.0.0.0]
    [C:\Program Files\航天信息\防伪开票\BIN\JSPCIDLL.dll]  [N/A, N/A]
    [C:\Program Files\航天信息\防伪开票\BIN\twtiff32.dll]  [N/A, N/A]
    [C:\Program Files\航天信息\防伪开票\BIN\twbmp32.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Borland Shared\BDE\IDAPI32.DLL]  [N/A, N/A]
    [C:\Program Files\航天信息\防伪开票\BIN\ImageResource.dll]  [N/A, N/A]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\Program Files\Common Files\Borland Shared\BDE\idsql32.DLL]  [N/A, N/A]
    [C:\DOCUME~1\wxb\LOCALS~1\Temp\Tmp7.tmp]  [N/A, N/A]
    [C:\Program Files\Common Files\Borland Shared\BDE\IDR20009.DLL]  [N/A, N/A]
gototop
 

[C:\Program Files\Common Files\Borland Shared\BDE\BANTAM.DLL]  [N/A, N/A]
    [C:\Program Files\Common Files\Borland Shared\BDE\IDPDX32.DLL]  [N/A, N/A]
    [C:\Program Files\Common Files\Borland Shared\BDE\idbat32.DLL]  [N/A, N/A]
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\epepcres.dll]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 2992][D:\qick\qq.exe]  [TENCENT, 0, 0, 0, 0]
    [D:\qick\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [D:\qick\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [D:\qick\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 14]
    [D:\qick\QQAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [D:\qick\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [D:\qick\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [D:\qick\npkcntc.dll]  [INCA Internet Co., Ltd., 2005, 9, 1, 1]
    [D:\qick\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [D:\qick\QQTM.dll]  [N/A, N/A]
    [D:\qick\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [D:\qick\QQMainFrame.dll]  [N/A, N/A]
    [D:\qick\CQQApplication.dll]  [N/A, N/A]
    [D:\qick\NewSkin.dll]  [, 1, 0, 0, 1]
    [D:\qick\HostingMgr.dll]  [, 1, 0, 0, 1]
    [D:\qick\CameraDll.dll]  [, 1, 0, 0, 1]
    [D:\qick\MailSummary.dll]  [, 1, 0, 0, 1]
    [D:\qick\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\System32\msdmo.dll]  [N/A, N/A]
    [D:\qick\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [D:\qick\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [D:\qick\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [D:\qick\QRingMng.dll]  [N/A, N/A]
    [D:\qick\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [D:\qick\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [D:\qick\QQSysMsgMng.dll]  [N/A, N/A]
    [D:\qick\LongConnection.dll]  [tencent, 0, 3, 3, 8]
    [D:\qick\QQPet.dll]  [, 1, 0, 0, 1]
    [D:\qick\QQAvatar.dll]  [N/A, N/A]
    [D:\qick\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [D:\qick\BQQApplication.dll]  [N/A, N/A]
    [D:\qick\QQPlugin.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
    [D:\qick\CommercesMng.dll]  [, 1, 0, 0, 1]
    [D:\qick\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [D:\qick\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 141]
    [D:\qick\QQSceneMng.dll]  [N/A, N/A]
    [D:\qick\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 2, 23]
    [D:\qick\QQAllInOne.dll]  [N/A, N/A]
    [D:\qick\SCCore.dll]  [N/A, N/A]
    [D:\qick\QQCustomFace.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [D:\qick\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [D:\qick\GroupConnection.dll]  [Tencent, 5, 0, 202, 30]
[PID: 3028][D:\qick\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [D:\qick\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 3032][C:\WINDOWS\System32\conime.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[PID: 1964][D:\Program files\Rising\Rav\RsAgent.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\WINDOWS\235780M.BMP]  [N/A, N/A]
    [D:\Program files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[PID: 2640][C:\WINDOWS\msagent\AgentSvr.exe]  [Microsoft Corporation, 2.00.0.3422]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[PID: 2668][C:\Program Files\Rising\AntiSpyware\Ras.exe]  [Beijing Rising Technology Co., Ltd., 1, 0, 3, 9]
    [C:\Program Files\Rising\AntiSpyware\RasGui.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 19]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [D:\Program files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 3956][C:\Program Files\Windows NT\Accessories\wordpad.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
gototop
 

[C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\epepcres.dll]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 3136][D:\Program files\Rising\Rav\Rav.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
    [C:\WINDOWS\235780M.BMP]  [N/A, N/A]
    [D:\Program files\Rising\Rav\PlugIn\RsPgScan.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 17]
    [D:\Program files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [D:\Program files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [D:\Program files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [D:\Program files\Rising\Rav\RavUI.Dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 30]
    [D:\Program files\Rising\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
    [D:\Program files\Rising\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [D:\Program files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [D:\Program files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
    [D:\Program files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
    [D:\Program files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [D:\Program files\Rising\Rav\RavQu.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [D:\Program files\Rising\Rav\RsStore.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [D:\Program files\Rising\Rav\libload.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [D:\Program files\Rising\Rav\VirusLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [D:\Program files\Rising\Rav\engine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
    [D:\Program files\Rising\Rav\UnExe.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [D:\Program files\Rising\Rav\ExtFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 23]
    [D:\Program files\Rising\Rav\ScanEx.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 32]
    [D:\Program files\Rising\Rav\PostTrt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
    [D:\Program files\Rising\Rav\NvFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
    [D:\Program files\Rising\Rav\ScanMac.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
    [D:\Program files\Rising\Rav\ScanSct.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [D:\Program files\Rising\Rav\ScanExec.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
    [D:\Program files\Rising\Rav\ExtOLE.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
    [D:\Program files\Rising\Rav\Unpacker.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
    [D:\Program files\Rising\Rav\ScanPack.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 18]
    [D:\Program files\Rising\Rav\RsVM.dll]  [N/A, 19, 0, 0, 13]
    [D:\Program files\Rising\Rav\Uroutine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [D:\Program files\Rising\Rav\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [D:\Program files\Rising\Rav\ExtMail.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
    [D:\Program files\Rising\Rav\ScanNet.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [D:\Program files\Rising\Rav\Uscript.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
    [D:\Program files\Rising\Rav\ScanElf.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
gototop
 

[PID: 3460][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\235780M.BMP]  [N/A, N/A]
    [c:\program files\google\googletoolbar2.dll]  [Google Inc., 4, 0, 1020, 3054]
    [C:\WINDOWS\System32\kakatool.dll]  [Beijing Rising Technology Co., Ltd., 2, 0, 2, 6]
    [D:\CK\WebThunderBHO_015.dll]  [Thunder Networking Technologies,LTD, 6, 0, 0, 5]
    [D:\qick\QQIEHelper.dll]  [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [D:\Program files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\System32\msdmo.dll]  [N/A, N/A]
    [D:\CK\Kuree\Codec\VSFilter.dll]  [Gabest, 1, 0, 1, 3]
    [D:\CK\Kuree\Codec\empgdmx.ax]  [Elecard Ltd., 1, 0, 19, 51017]
    [C:\Program Files\WaVideo\VDecoder.ax]  [N/A, 1, 0, 1, 1]
    [D:\CK\Kuree\Codec\ffdshow.ax]  [N/A, 1.0.2.1997]
[PID: 2256][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [c:\program files\google\googletoolbar2.dll]  [Google Inc., 4, 0, 1020, 3054]
    [C:\WINDOWS\System32\kakatool.dll]  [Beijing Rising Technology Co., Ltd., 2, 0, 2, 6]
    [D:\CK\WebThunderBHO_015.dll]  [Thunder Networking Technologies,LTD, 6, 0, 0, 5]
    [D:\qick\QQIEHelper.dll]  [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
    [D:\Program files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
[PID: 1272][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, N/A]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[PID: 2704][C:\DOCUME~1\wxb\LOCALS~1\Temp\Rar$EX03.267\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
gototop
 

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
N/A

==================================


[/CODE]
gototop
 

怎么没有回音呢?
gototop
 

我点了系统修复提示:
警告!注册表值AppInit-DLLs被修改为非正常值(默认值是空)。请检查你的系统中可能存在的计算机病毒。
gototop
 

开始,运行,regedit展开注册表,把这项编辑为空,AppInit_DLLs
重启后删除235780M.BMP
gototop
 

可是没有找到这个235780M.BMP 文件呀-好象是隐藏的.
gototop
 

重启后能找到文件,但是不能删除235780M.BMP 文件,提示被写保护或者正在使用!
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT