瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 Trojan.DL.Small.ibr 怎么RISING还杀不了呀

1   1  /  1  页   跳转

Trojan.DL.Small.ibr 怎么RISING还杀不了呀

Trojan.DL.Small.ibr 怎么RISING还杀不了呀

安全模式下杀了,到正常模式边杀边上网又有16个了,晕,快更新呀,怎么.exe的文件不能放上去吗,什么文件可以传上去呀

现在在用卡巴杀,多杀了一个木马?卡巴杀慢呀,不爽
提示c:\windows\system32\1116\ntjdo\mvq.fyf  是特洛伊木马Trojan-Spy.Win32.Agent.jo 对象无法清除,清除被延时

其他就是IE临时目录下的那个cf.scr木马了,也显示对象无法清除,清除被延时
最后编辑2006-04-05 11:39:26
分享到:
gototop
 

Autoruns保存一个日志发上来
日志保存方法:选择File->Save菜单项保存日志时注意选择Options->Hide Microsoft Entries菜单项(设置了这项后点工具栏的刷新按钮)

工具的下载、使用参考http://forum.ikaka.com/topic.asp?board=28&artid=7318038
gototop
 

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ ATIPTAATI Desktop Control PanelATI Technologies, Inc.c:\program files\ati technologies\ati control panel\atiptaxx.exe

+ CameraFixerCameraFixer MFC Applicationc:\windows\camerafixer.exe

+ Dell QuickSetQuickSet MFC Applicationc:\program files\dell\quickset\quickset.exe

+ IntelWirelessIntel Framework MFC ApplicationIntel Corporationc:\program files\intel\wireless\bin\ifrmewrk.exe

+ KAVPersonal50Kaspersky Anti-Virus GUI PartKaspersky Labc:\program files\kaspersky lab\kaspersky anti-virus personal\kav.exe

+ NeroFilterCheckNeroCheckAhead Software Gmbhc:\windows\system32\nerocheck.exe

+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe

+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwmain.exe

+ snpstd3CameraMonitor Applicationc:\windows\vsnpstd3.exe

+ spoolsv傲讯浏览器辅助工具广州傲讯信息科技有限公司c:\windows\system32\spoolsv\spoolsv.exe

HKLM\SOFTWARE\Classes\Protocols\Handler

+ ic32ppc:\windows\wc98pp.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ Rising Execute File Exts hookRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realplayer\rpshell.dll

+ WinRAR shell extensionc:\program files\winrar\rarext.dll

HKLM\Software\Classes\Folder\Shellex\ColumnHandlers

+ PDF Shell ExtensionPDF Shell ExtensionAdobe Systems, Inc.c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ Google Toolbar HelperGoogle IE 客户端工具栏Google Inc.c:\program files\google\googletoolbar1.dll

+ wmpdrm傲讯浏览器辅助工具Allsum Info. Tech. Ltd.c:\windows\system32\wmpdrm.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ googletoolbar1.dllGoogle IE 客户端工具栏Google Inc.c:\program files\google\googletoolbar1.dll

+ kakatool.dllBeijing Rising Technology Co., Ltd.c:\windows\system32\kakatool.dll

HKLM\System\CurrentControlSet\Services

+ Ati HotKey PollerATI External Event Utility EXE ModuleATI Technologies Inc.c:\windows\system32\ati2evxx.exe

+ C-DillaCdaC11BAMacrovision RTS ServiceMacrovisionc:\windows\system32\drivers\cdac11ba.exe

+ EvtEngIntel Event Trace ManagerIntel Corporationc:\program files\intel\wireless\bin\evteng.exe

+ kavsvcKaspersky Anti-Virus ServiceKaspersky Labc:\program files\kaspersky lab\kaspersky anti-virus personal\kavsvc.exe

+ NICCONFIGSVC配置内部网卡电源管理设置。Dell Inc.c:\program files\dell\nicconfigsvc\nicconfigsvc.exe

+ RegSrvcIntel Registry ServiceIntel Corporationc:\program files\intel\wireless\bin\regsrvc.exe

+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwsrv.exe

+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe

+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe

+ S24EventMonitorHandles the Spectrum24 NDIS TrafficIntel Corporation c:\program files\intel\wireless\bin\s24evmon.exe

+ WLANKEEPERProvides Profile Switching Service for SSO Feature SetIntel? Corporationc:\program files\intel\wireless\bin\wlkeeper.exe

HKLM\System\CurrentControlSet\Services

+ AegisPAEGIS Protocol (IEEE 802.1x) v3.1.0.1Meetinghouse Data Communicationsc:\windows\system32\drivers\aegisp.sys

+ APPDRVApp Support DriverDell Incc:\windows\system32\drivers\appdrv.sys

+ ati2mtagATI Radeon WindowsNT Miniport DriverATI Technologies Inc.c:\windows\system32\drivers\ati2mtag.sys

+ b57w2kBroadcom NetXtreme Gigabit Ethernet NDIS5.1 Driver.Broadcom Corporationc:\windows\system32\drivers\b57xp32.sys

+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\windows\system32\drivers\basetdi.sys

+ busenumVirtualcom Bus Enumeratorc:\windows\system32\drivers\busenum.sys

+ CdaC15BAMacrovision SECURITY DriverMacrovision Europe Ltdc:\windows\system32\drivers\cdac15ba.sys

+ EthComm2kc:\windows\system32\drivers\ethcomm2k.sys

+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys

+ giveioc:\windows\system32\giveio.sys

+ GTIPCI21Texas Instruments PCI GemCore IFD HandlerTexas Instrumentsc:\windows\system32\drivers\gtipci21.sys

+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys

+ HookRegc:\program files\rising\rav\hookreg.sys

+ HookSysHooksysRisingc:\program files\rising\rav\hooksys.sys

+ HookUrlHookUrlBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\hookurl.sys

+ HSF_DPHSF_DP driverConexant Systems, Inc.c:\windows\system32\drivers\hsf_dp.sys

+ HSF_DPVHSF_DP driverConexant Systems, Inc.c:\windows\system32\drivers\hsf_dpv.sys

+ HSFHWICHHSFHWICH WDM driverConexant Systems, Inc.c:\windows\system32\drivers\hsfhwich.sys

+ imagedrvNERO IMAGEDRIVE SCSI miniportAhead Software AGc:\windows\system32\drivers\imagedrv.sys

+ imagesrvNero Image ServerAhead Software AGc:\windows\system32\drivers\imagesrv.sys

+ io.sysc:\windows\system32\drivers\io.sys

+ IWCAIntel Wireless Connection AgentIntel Corporationc:\windows\system32\drivers\iwca.sys

+ Kl1Kaspersky Anti-Hacker Only DriverKaspersky Labc:\windows\system32\drivers\kl1.sys

+ Klifspuper-ptorKaspersky Labsc:\windows\system32\drivers\klif.sys

+ KlmcKaspersky Anti-Virus Mail Checker ProxyKaspersky Labc:\windows\system32\drivers\klmc.sys

+ kmsinputc:\windows\system32\drivers\kmsinput.sys

+ mdmxsdkDiagnostic Interface DRIVERConexantc:\windows\system32\drivers\mdmxsdk.sys

+ MEMSCANMemScan Driver瑞星软件有限公司c:\program files\rising\rav\memscan.sys

+ mProcRsRising Personal FireWall  mprocrs.sysBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\mprocrs.sys

+ NPFNPF Driver - TME extensionsPolitecnico di Torinoc:\windows\system32\drivers\npf.sys

+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.c:\program files\tencent\qq\npkcrypt.sys

+ OMCIOMCI Device DriverDell Computer Corporationc:\windows\system32\drivers\omci.sys

+ PortTalkPortTalk - Beyond Logic I/O Port DriverBeyond Logic http://www.beyondlogic.orgc:\windows\system32\drivers\porttalk.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys

+ PxHelp20Px Engine Device Driver for Windows 2000/XPSonic Solutionsc:\windows\system32\drivers\pxhelp20.sys

+ RsFwDrvnt_fwdrvBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rsfwdrv.sys

+ s24transWLAN TransportIntel Corporationc:\windows\system32\drivers\s24trans.sys

+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys

+ SentinelSentinel System Driver (NT Parallel driver)Rainbow Technologies, Inc.c:\windows\system32\drivers\sentinel.sys

+ Ser2plUSB-to-Serial Cable DriverProlific Technology Inc.c:\windows\system32\drivers\ser2pl.sys

+ SNPSTD3PC Camera driverc:\windows\system32\drivers\snpstd3.sys

+ STAC97SigmaTel Audio Driver (WDM)SigmaTel, Inc.c:\windows\system32\drivers\stac97.sys

+ UIUSysFile not found: system32\drivers\UIUSys.sys

+ w29n51Intel? Wireless LAN DriverIntel? Corporationc:\windows\system32\drivers\w29n51.sys

+ winachsfHSF_CNXT driverConexant Systems, Inc.c:\windows\system32\drivers\hsf_cnxt.sys

+ WinDriver6WinDriver Device Driver 6.02Jungoc:\windows\system32\drivers\windrvr6.sys

+ XELTEKXeusbanchor chipsc:\windows\system32\drivers\xeusb.sys

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ AtiExtEventATI External Event Utility DLL ModuleATI Technologies Inc.c:\windows\system32\ati2evxx.dll

+ IntelWirelessLogonNotify DLLIntel Corporationc:\program files\intel\wireless\bin\lgnotify.dll

gototop
 

电脑是DELL-D610  WINDOWS XP  SP2
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT