瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】请高手指导.这种病毒怎么清除?

123   1  /  3  页   跳转

【求助】请高手指导.这种病毒怎么清除?

【求助】请高手指导.这种病毒怎么清除?

这是什么病毒?这种病毒怎么清除?每次杀毒瑞星都说病毒已清除.杀了N次病毒都说病毒已清除.可每次都都在,怎么彻底?清除请高手指导.多谢啊.

病毒名称如下:
Trojan.DL.Agent.xjv
Trojan.DL.Agent.yoo

最后编辑2007-03-14 22:42:19.827000000
分享到:
gototop
 

引用:
【笨鸟学飞的贴子】这是什么病毒?这种病毒怎么清除?每次杀毒瑞星都说病毒已清除.杀了N次病毒都说病毒已清除.可每次都都在,怎么彻底?清除请高手指导.多谢啊.

病毒名称如下:
Trojan.DL.Agent.xjv
Trojan.DL.Agent.yoo


………………

请贴SRENG日志
gototop
 

升级你的杀毒软件.然后全盘扫描杀毒,应该会提示病毒文件位置的.
然后使用UNLOCKER删除病毒文件就OK了
gototop
 

给系统添加密码,关闭共享,关闭系统还原.及时更新系统补丁.清理系统各处的临时文件.这样子可以有效的抑制病毒的频繁发作
gototop
 

========Content========
这是什么SRENG日志,在哪里找呢?
gototop
 

【回复“姑苏残月”的帖子】
照您说的做了,重启再杀,又说清除了.我再关机开机再扫描,老地方又有啊,烦死了.
gototop
 

请高手指导一下,多谢啦!
gototop
 

【回复“baohe”的帖子】
[CODE]

2007-03-14,20:52:13

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
    <bgswitch><; C:\WINDOWS\system32\bgswitch.exe>  []
    <MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Windows XP Publisher]
    <Super Rabbit CDNotify><C:\Program Files\Super Rabbit\MagicSet\SRCDNoti.exe /LOAD>  [Super Rabbit Soft]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
gototop
 

【回复“baohe”的帖子】
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [N/A]
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <High Definition Audio Property Page Shortcut><; HDAShCut.exe>  [(Verified)Microsoft Windows XP Publisher]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <BigDog303><C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)>  [N/A]
    <NeroFilterCheck><; C:\WINDOWS\system32\NeroCheck.exe>  [Ahead Software Gmbh]
    <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <iTunesHelper><; "C:\Program Files\iTunes\iTunesHelper.exe">  [(Verified)"Apple Computer, Inc."]
    <NexusServer><; "C:\Program Files\Common Files\Canopus Shared\ProCoder 2\Kernel\PNXSERVR.exe" -SelfLaunch>  []
    <StormCodec_Helper><; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  []
    <SystemTray><systray.exe>  [(Verified)Microsoft Windows Publisher]
    <MemoryCardManager><; C:\Program Files\Lenovo\Lenovo Precision Photo\MemCard.exe -startup>  [Lexmark International, Inc.]
    <HjTools><; C:\Program Files\hjtools\upgrade.exe zhj5>  [N/A]
    <BluetoothAuthenticationAgent><; rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent>  [(Verified)Microsoft Windows Publisher]
    <KONICA MINOLTA PagePro 1350WStatusDisplay><; C:\WINDOWS\system32\MSTMON_Q.EXE>  [KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.]
    <MoveSearch><; C:\Program Files\HuaCi\huaci\zsearch.exe>  [中搜在线]
    <stup.exe><C:\PROGRA~1\TENCENT\Adplus\stup.exe>  [Tencent]
    <CdnCtr><; C:\Program Files\CNNIC\Cdn\cdnup.exe>  []
    <CnsM.dll><; Rundll32.exe C:\PROGRA~1\3721\CnsM.dll,Rundll32>  [北京三七二一科技有限公司]
    <helper.dll><C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>  []
    <CnsMHlp.exe><; C:\WINDOWS\Downloaded Program files\CnsMHlp.exe>  [3721.com]
    <CnsMin><Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32>  [北京三七二一科技有限公司]
    <IESAddr><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows XP Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]

==================================
启动文件夹
[Adobe Reader Speed Launch]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk --> C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [Adobe Systems Incorporated]><H>
[AutoCAD 启动加速器]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\AutoCAD 启动加速器.lnk --> C:\PROGRA~1\COMMON~1\AUTODE~1\ACSTAR~1.EXE [Autodesk, Inc]><N>
[Cyber-shot Viewer 媒体检查工具]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\Cyber-shot Viewer 媒体检查工具.lnk --> C:\PROGRA~1\Sony\SONYPI~1\VOLUME~1\SPUVOL~1.EXE [Sony Corporation]><H>
[PICA]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\PICA.lnk --> C:\PROGRA~1\PICA\Pica.exe []><H>
[腾讯QQ]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><H>

==================================
gototop
 

服务
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[Autodesk Licensing Service / Autodesk Licensing Service][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><Autodesk>
[BlueSoleil Hid Service / BlueSoleil Hid Service][Running/Auto Start]
  <C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe><N/A>
[Crypkey License / Crypkey License][Running/Auto Start]
  <crypserv.exe><Kenonic Controls Ltd.>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
  <"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[iPod Service / iPod Service][Stopped/Manual Start]
  <"C:\Program Files\iPod\bin\iPodService.exe"><Apple Computer, Inc.>
[LightScribeService Direct Disc Labeling Service / LightScribeService][Running/Auto Start]
  <"C:\Program Files\Common Files\LightScribe\LSSrvc.exe"><Hewlett-Packard Company>
[lvbs_device / lvbs_device][Stopped/Manual Start]
  <C:\WINDOWS\system32\lvbscoms.exe -service><Lenovo (Beijing) Ltd.>
[MySql / MySql][Stopped/Auto Start]
  <C:/MySql/bin/mysqld-nt.exe><N/A>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Ulead Burning Helper / UleadBurningHelper][Running/Auto Start]
  <C:\Program Files\common files\Ulead Systems\DVD\ULCDRSvr.exe><Ulead Systems, Inc.>
[Windows User Mode Driver Framework / UMWdf][Stopped/Auto Start]
  <><N/A>
gototop
 
123   1  /  3  页   跳转
页面顶部
Powered by Discuz!NT