瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】病毒Trojan.DL.Agent.jer怎么删也删不掉

1   1  /  1  页   跳转

【求助】病毒Trojan.DL.Agent.jer怎么删也删不掉

【求助】病毒Trojan.DL.Agent.jer怎么删也删不掉

这个病毒删一次过会又会出现...怎么删也删不掉...

最后编辑2006-06-24 13:30:49
分享到:
gototop
 

正在运行的进程
[PID: 480][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 544][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 568][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 612][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 624][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 788][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 836][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\cdnns.dll]  <N/A><N/A>
[PID: 900][D:\Rising\Rav\CCenter.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 916][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1216][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1272][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1288][D:\Rising\Rav\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 26>
    [D:\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [D:\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [D:\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [D:\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\Rising\Rav\RsLog.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
    [D:\Rising\Rav\HOOKSYS.dll]  <Rising><18, 1, 0, 9>
    [D:\Rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [D:\Rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\Rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\Rising\Rav\regmon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [D:\Rising\Rav\HookWeb.dll]  <rising><18, 0, 0, 1>
    [D:\Rising\Rav\MemMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [D:\Rising\Rav\expscan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\Rising\Rav\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
    [D:\Rising\Rav\MailMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [D:\Rising\Rav\SpamEng.dll]  <N/A><18, 0, 0, 6>
    [D:\Rising\Rav\engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [D:\Rising\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [D:\Rising\Rav\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [D:\Rising\Rav\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [D:\Rising\Rav\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [D:\Rising\Rav\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [D:\Rising\Rav\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
    [D:\Rising\Rav\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 15>
    [D:\Rising\Rav\Unpacker.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [D:\Rising\Rav\ExtOLE.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [D:\Rising\Rav\RsStore.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[PID: 1424][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\cdnns.dll]  <N/A><N/A>
[PID: 1716][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\WINDOWS\system32\Yeucn.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Okutrb.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Wtklxs.dll]  <N/A><N/A>
    [C:\WINDOWS\Downloaded Program Files\Vgixx.dll]  <Tencent><4, 0, 10, 100>
    [C:\WINDOWS\Downloaded Program Files\Bbkl.dll]  <Tencent><4, 0, 10, 100>
    [C:\WINDOWS\system32\Lbxrh.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Sklidg.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Ghxh.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Pfsesx.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Dqkeyp.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Ygekc.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Fvkwzy.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Ohqk.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Qaea.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Gfsn.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Icfxy.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Htteja.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Ppml.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Gktr.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Wdvihu.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Ovfu.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Sqmdl.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Jidnup.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Xylg.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Ximp.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Wjgh.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Svwk.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Yvmn.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Kayki.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Acgex.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Quvjqq.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Uvfpg.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Lezqhj.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Ynou.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Pftnt.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Spetsi.dll]  <N/A><N/A>
    [C:\PROGRA~1\winkld\Winkld.dat]  <www.88dog.com><2, 0, 0, 1>
    [C:\WINDOWS\system32\cdnns.dll]  <N/A><N/A>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\SystemToolbar.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\WinDefendor.dll]  <TODO: <公司名>><1.0.0.2>
gototop
 

[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll]  <Yahoo! China><1, 1, 2, 1034>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll]  <Yahoo!><2, 1, 8, 1048>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL]  <><1, 2, 7, 1006>
    [C:\PROGRA~1\baigoo\bgoobho.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\HelperService.dll]  <N/A><N/A>
    [C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX]  <N/A><N/A>
    [C:\Program Files\NetTransport 2\NTIEHelper.dll]  <Xi><1.91.12>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ywiper.dll]  <N/A><1, 0, 1, 1014>
    [D:\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1005>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\nvcpl.dll]  <NVIDIA Corporation><6.14.10.7801>
    [C:\WINDOWS\system32\NVRSZHC.DLL]  <NVIDIA Corporation><6.14.10.7801>
    [C:\WINDOWS\system32\nvshell.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\icm32.dll]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1776][D:\Rising\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [D:\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [D:\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 2004][C:\WINDOWS\system32\nvsvc32.exe]  <NVIDIA Corporation><6.14.10.7801>
[PID: 148][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1596][D:\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [D:\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [D:\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\WINDOWS\Downloaded Program Files\Vgixx.dll]  <Tencent><4, 0, 10, 100>
[PID: 2016][D:\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 26>
    [D:\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
    [D:\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [D:\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [D:\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [D:\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\WINDOWS\Downloaded Program Files\Vgixx.dll]  <Tencent><4, 0, 10, 100>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1005>
[PID: 1172][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3680][C:\WINDOWS\system32\CTFMON.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\Downloaded Program Files\Vgixx.dll]  <Tencent><4, 0, 10, 100>
[PID: 1316][C:\PROGRA~1\baigoo\bgoomain.exe]  <BGoo><1, 0, 0, 1005>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1005>
    [C:\WINDOWS\Downloaded Program Files\Vgixx.dll]  <Tencent><4, 0, 10, 100>
    [C:\PROGRA~1\baigoo\bgooex.dll]  <><1, 0, 0, 1007>
    [C:\WINDOWS\system32\cdnns.dll]  <N/A><N/A>
[PID: 3788][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3208>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1005>
    [C:\WINDOWS\Downloaded Program Files\Vgixx.dll]  <Tencent><4, 0, 10, 100>
[PID: 3072][C:\WINDOWS\system32\rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\IE-BAR\Cast\dmipn.dll]  <千橡互联><2, 2, 1, 0>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1005>
    [C:\WINDOWS\Downloaded Program Files\Vgixx.dll]  <Tencent><4, 0, 10, 100>
    [C:\PROGRA~1\IE-BAR\Cast\dmshell.dll]  <千橡互联><2, 2, 1, 0>
    [C:\Progra~1\IE-BAR\Cast\221~1.0\dmplayer.dll]  <千橡互联><2, 2, 1, 0>
    [C:\WINDOWS\system32\cdnns.dll]  <N/A><N/A>
[PID: 3204][C:\Program Files\Yayad\AdPop.Exe]  <CDM><1.0.0.1>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1005>
    [C:\WINDOWS\Downloaded Program Files\Vgixx.dll]  <Tencent><4, 0, 10, 100>
    [C:\Program Files\Yayad\autoupdate.dll]  <CDM><1.0.0.1>
    [C:\WINDOWS\system32\cdnns.dll]  <N/A><N/A>
[PID: 2248][D:\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1005>
    [C:\WINDOWS\Downloaded Program Files\Vgixx.dll]  <Tencent><4, 0, 10, 100>
    [D:\SREng2\Plugins\SREngPluginDemo.SRE]  <Smallfrogs Studio><1, 1, 1, 0>
    [C:\WINDOWS\system32\cdnns.dll]  <N/A><N/A>
[PID: 360][C:\Program Files\TENCENT\TT\TTraveler.exe]  <腾讯公司><3.0.0.246>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1005>
    [C:\WINDOWS\Downloaded Program Files\Vgixx.dll]  <Tencent><4, 0, 10, 100>
    [C:\Program Files\TENCENT\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll]  <腾讯公司><1, 1, 0, 5>
    [C:\Program Files\TENCENT\TT\Plugins\TWeather\TWeather.dll]  <><1, 0, 0, 3>
    [C:\WINDOWS\system32\cdnns.dll]  <N/A><N/A>
    [C:\Program Files\TENCENT\TT\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
    [D:\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

汗,问题多多
gototop
 

[C:\WINDOWS\system32\Yeucn.dll] <N/A><N/A>
[C:\WINDOWS\system32\Okutrb.dll] <N/A><N/A>
[C:\WINDOWS\system32\Wtklxs.dll] <N/A><N/A>
[C:\WINDOWS\Downloaded Program Files\Vgixx.dll] <Tencent><4, 0, 10, 100>
[C:\WINDOWS\Downloaded Program Files\Bbkl.dll] <Tencent><4, 0, 10, 100>
[C:\WINDOWS\system32\Lbxrh.dll] <N/A><N/A>
[C:\WINDOWS\system32\Sklidg.dll] <N/A><N/A>
[C:\WINDOWS\system32\Ghxh.dll] <N/A><N/A>
[C:\WINDOWS\system32\Pfsesx.dll] <N/A><N/A>
[C:\WINDOWS\system32\Dqkeyp.dll] <N/A><N/A>
[C:\WINDOWS\system32\Ygekc.dll] <N/A><N/A>
[C:\WINDOWS\system32\Fvkwzy.dll] <N/A><N/A>
[C:\WINDOWS\system32\Ohqk.dll] <N/A><N/A>
[C:\WINDOWS\system32\Qaea.dll] <N/A><N/A>
[C:\WINDOWS\system32\Gfsn.dll] <N/A><N/A>
[C:\WINDOWS\system32\Icfxy.dll] <N/A><N/A>
[C:\WINDOWS\system32\Htteja.dll] <N/A><N/A>
[C:\WINDOWS\system32\Ppml.dll] <N/A><N/A>
[C:\WINDOWS\system32\Gktr.dll] <N/A><N/A>
[C:\WINDOWS\system32\Wdvihu.dll] <N/A><N/A>
[C:\WINDOWS\system32\Ovfu.dll] <N/A><N/A>
[C:\WINDOWS\system32\Sqmdl.dll] <N/A><N/A>
[C:\WINDOWS\system32\Jidnup.dll] <N/A><N/A>
[C:\WINDOWS\system32\Xylg.dll] <N/A><N/A>
[C:\WINDOWS\system32\Ximp.dll] <N/A><N/A>
[C:\WINDOWS\system32\Wjgh.dll] <N/A><N/A>
[C:\WINDOWS\system32\Svwk.dll] <N/A><N/A>
[C:\WINDOWS\system32\Yvmn.dll] <N/A><N/A>
[C:\WINDOWS\system32\Kayki.dll] <N/A><N/A>
[C:\WINDOWS\system32\Acgex.dll] <N/A><N/A>
[C:\WINDOWS\system32\Quvjqq.dll] <N/A><N/A>
[C:\WINDOWS\system32\Uvfpg.dll] <N/A><N/A>
[C:\WINDOWS\system32\Lezqhj.dll] <N/A><N/A>
[C:\WINDOWS\system32\Ynou.dll] <N/A><N/A>
[C:\WINDOWS\system32\Pftnt.dll] <N/A><N/A>
[C:\WINDOWS\system32\Spetsi.dll] <N/A><N/A>
[C:\PROGRA~1\winkld\Winkld.dat] <www.88dog.com><2, 0, 0, 1>
[C:\WINDOWS\system32\cdnns.dll] <N/A><N/A>
[C:\PROGRA~1\baigoo\bgoohk.dll.....
建议先用超级兔子卸载流氓软件再扫日志,而且你的日志不全
gototop
 

http://www.crsky.com/soft/2924.html
下载超级兔子..用超级兔子清理王卸载流氓软件...

清干净垃圾 再扫上来...日志帖全...
gototop
 

HijackThis这个就可以了,把所有的都删除
gototop
 

HijackThis这个要怎么操作
gototop
 

请下载HijackThis.exe,扫描并保存报告帖上来。
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT