1   1  /  1  页   跳转

怎么也杀不掉,高手帮帮忙

怎么也杀不掉,高手帮帮忙

用卡帕在安全模式可以杀,但是一旦进入正常模式就又会有,卡帕上的名字是backdoor.win32.aimbot.af.病毒文件是rofl.sys.那位高手知道怎么杀啊
我扫描的日志
HijackThis@Qoo的扫描日志  V1.97.7
Scan saved at 17:40:32, on 2005-11-14
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\gcxsrvc.exe
D:\Downloads\hijackthis1.97_qoo\HijackThis.exe

O2 - BHO: (no name) - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\Program Files\TENCENT\AddrPlus\IEHelp1.dll
O2 - BHO: (no name) - {2E7D3330-EB94-4518-B0FE-E05379A5C1DA} - C:\PROGRA~1\iBar\10002\iBar.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll (file missing)
O2 - BHO: (no name) - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O2 - BHO: (no name) - {42AFACEE-2A77-41EB-9EE2-D9F8AF827F90} - C:\Program Files\KV2006\KVBHO.dll (file missing)
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - d:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL (file missing)
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O2 - BHO: (no name) - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\System32\stdup.dll
O2 - BHO: (no name) - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {AEF6F648-78D8-4456-BEE7-5ADE23D209FD} - C:\Program Files\HBClient\hapast.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: (no name) - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll
O3 - Toolbar: ????? - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll
O3 - Toolbar: ????? - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: ????? - {2E7D3330-EB94-4518-B0FE-E05379A5C1DA} - C:\PROGRA~1\iBar\10002\iBar.dll
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: NTUSER.DAT
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O8 - Extra context menu item:  >> 彩信发送 << - res://C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL/mms.htm
O8 - Extra context menu item: !搜一搜 - res://C:\WINDOWS\downlo~1\CnsMinEx.dll/1003
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用网际快车下载 - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 反向链接 - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://D:\office\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 百度-搜索MP3 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUMP3.HTM
O8 - Extra context menu item: 百度-搜索图片 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUIMG.HTM
O8 - Extra context menu item: 百度-搜索新闻 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUNEWS.HTM
O8 - Extra context menu item: 百度-搜索歌词 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDULYRIC.HTM
O8 - Extra context menu item: 百度-搜索网页 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUSEARCH.HTM
O8 - Extra context menu item: 百度-搜索贴吧 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUPOST.HTM
O8 - Extra context menu item: 百度-词典搜索 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_DIC.HTM
O8 - Extra context menu item: 类似网页 - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: 缓存的网页快照 - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: 访问通用网址 - C:\Program Files\CNNIC\Cdn\cnnic.htm
O9 - Extra button: Script Checker (HKLM)
O9 - Extra button: QQ (HKLM)
O9 - Extra button: FlashGet (HKLM)
O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdnns.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdog0.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdog0.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdog0.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdogr0.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdogr0.dll
O11 - Options group: [CDNCLIENT] 
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{65E734A3-D2B6-4C3F-BC3C-EFE62BB63B4C}: NameServer = 202.202.0.33,61.128.128.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{65E734A3-D2B6-4C3F-BC3C-EFE62BB63B4C}: NameServer = 202.202.0.33,61.128.128.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{65E734A3-D2B6-4C3F-BC3C-EFE62BB63B4C}: NameServer = 202.202.0.33,61.128.128.68

最后编辑2005-11-15 12:32:33
分享到:
gototop
 

扫描工具太老

用Autoruns保存一个日志发上来
日志保存方法:选择File->Save菜单项
保存日志时注意选择Options->Hide Microsoft Entries菜单项(设置了这项后点工具栏的刷新按钮)

工具使用参考http://forum.ikaka.com/topic.asp?board=28&artid=7318038第14楼
gototop
 

用autoruns又扫了遍,大侠们看看啊
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run           

+ KAVPersonal50    Kaspersky Anti-Virus GUI Part    Kaspersky Lab    c:\program files\kaspersky lab\kaspersky anti-virus personal\kav.exe

+ SoundMan    Realtek Sound Manager    Realtek Semiconductor Corp.    c:\windows\soundman.exe

HKLM\System\CurrentControlSet\Services           

+ AIM    AOL Instant Messanger        File not found: C:\WINDOWS\aim.exe

+ Ati HotKey Poller    ATI External Event Utility EXE Module    ATI Technologies Inc.    c:\windows\system32\ati2evxx.exe

+ ATI Smart    ATI Smart        c:\windows\system32\ati2sgag.exe

+ C-DillaCdaC11BA    Macrovision RTS Service    Macrovision    c:\windows\system32\drivers\cdac11ba.exe

+ kavsvc    Kaspersky Anti-Virus Service    Kaspersky Lab    c:\program files\kaspersky lab\kaspersky anti-virus personal\kavsvc.exe

+ lsass    Microsoft Path Finder Service Displays Internet Routing Paths.        File not found: C:\WINDOWS\lsass.exe

+ SavRoam    Symantec AntiVirus 漫游服务        File not found: C:\Program Files\Symantec AntiVirus\SavRoam.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks           

+ Cq.dll            File not found: C:\WINDOWS\System32\Cq.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved           

+ AlcoholShellEx            \

+ AutoCAD 数字签名图标覆盖处理程序    AcSignIcon Module    Autodesk    c:\windows\system32\acsignicon.dll

+ Autodesk Drawing Preview    AcThumbnail Module    Autodesk    c:\program files\common files\autodesk shared\thumbnail\acthumbnail16.dll

+ Display Panning CPL Extension            File not found: deskpan.dll

+ HyperTerminal Icon Ext    HyperTerminal Applet Library    Hilgraeve, Inc.    c:\windows\system32\hticons.dll

+ LDVP Shell Extensions    Symantec AntiVirus    Symantec Corporation    c:\program files\common files\symantec shared\ssc\vpshell2.dll

+ QQ Search Hook        Tencent    c:\program files\tencent\addrplus\iehelp1.dll

+ QQAddrBar Drop Target        Tencent    c:\program files\tencent\addrplus\iehelp1.dll

+ Script Checker    Script Monitor Internet Explorer plugin    Kaspersky Lab    c:\program files\kaspersky lab\avp6\scieplugin.dll

+ Shell extensions for file compression            \

+ Tencent Browser Helper        Tencent    c:\program files\tencent\addrplus\iehelp1.dll

+ TrojanHunter Menu Shell Extension            \

+ WinRAR shell extension            c:\program files\winrar\rarext.dll

+ Yahoo!Photo            File not found: C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll

+ 粉碎文件            File not found: C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ywiper.dll

+ 加密上下文菜单            \

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects           

+ BandIE Class    BaiduBar Module    Baidu.com, Inc.    c:\program files\baidu\bar\baidubar.dll

+ BrowserHAP Class    Hapbast Module    Shanghai Henbang Technology Co., Ltd    c:\program files\hbclient\hapast.dll

+ CNNIC_IDN    CndnIEHelper Module        c:\program files\cnnic\cdn\cdniehlp.dll

+ DragSearch BHO            File not found: C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL

+ FiltrateWebObj Class            File not found: C:\Program Files\KV2006\KVBHO.dll

+ Google Toolbar Helper    Google IE Client Toolbar    Google Inc.    c:\program files\google\googletoolbar1.dll

+ i&Bar搜索引擎            c:\program files\ibar\10002\ibar.dll

+ IeCatch2 Class    jccatch Module    Amaze Soft    d:\program files\flashget\jccatch.dll

+ MMSAssist BHO    MMSAssist        c:\program files\mmsassist\mmsassist.dll

+ QQBrowserHelperObject Class    QQIEHelper Module    深圳市腾讯计算机系统有限公司    d:\program files\tencent\qq\qqiehelper.dll

+ std software        AOL Corp.    c:\windows\system32\stdup.dll

+ Tencent Browser Helper        Tencent    c:\program files\tencent\addrplus\iehelp1.dll

+ WMHlprObj Class    WMHlpr Module        c:\program files\cnnic\cdn\wmhlpr.dll

+ Yahoo!Photo            File not found: C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar           

+ FlashGet Bar    FlashGet IE Bar    Amaze Soft    d:\program files\flashget\fgiebar.dll

+ ibar.dll            c:\program files\ibar\10002\ibar.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions           

+ &FlashGet    FlashGet    Amaze Soft    d:\program files\flashget\flashget.exe

+ Yahoo 1G电邮            File not found: http://cn.mail.yahoo.com/promo/rd1

+ 浩方对战平台    浩方对战平台    上海浩方在线信息技术有限公司    d:\program files\浩方对战平台\gameclient.exe

+ 清理上网记录            File not found: http://assistant.3721.com/clean1.htm?fb=Cns

+ 情景聊天            File not found: http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/

+ 腾讯QQ    QQ    TENCENT    d:\program files\tencent\qq\qq.exe

+ 修复浏览器            File not found: http://assistant.3721.com/security1.htm?fb=Cns

+ 雅虎助手            File not found: http://cn.zs.yahoo.com/?source=Cns

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify           

+ AtiExtEvent    ATI External Event Utility DLL Module    ATI Technologies Inc.    c:\windows\system32\ati2evxx.dll

HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9           

+ MSAFD Tcpip [RAW/IP]            c:\windows\system32\tcpipdog0.dll

+ MSAFD Tcpip [TCP/IP]            c:\windows\system32\tcpipdog0.dll

+ MSAFD Tcpip [UDP/IP]            c:\windows\system32\tcpipdog0.dll

+ RSVP TCP Service Provider            c:\windows\system32\tcpipdogr0.dll

+ RSVP UDP Service Provider            c:\windows\system32\tcpipdogr0.dll

gototop
 

啊,大家帮帮忙啊,大哥们!
gototop
 

怎么都没人理偶啊,高手们说句话
gototop
 

55555555,都没人管我啊,真可怜
gototop
 

HKLM\System\CurrentControlSet\Services
+ AIM AOL Instant Messanger File not found: C:\WINDOWS\aim.exe
+ lsass Microsoft Path Finder Service Displays Internet Routing Paths. File not found: C:\WINDOWS\lsass.exe

+ std software AOL Corp. c:\windows\system32\stdup.dll

HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9

+ MSAFD Tcpip [RAW/IP] c:\windows\system32\tcpipdog0.dll

+ MSAFD Tcpip [TCP/IP] c:\windows\system32\tcpipdog0.dll

+ MSAFD Tcpip [UDP/IP] c:\windows\system32\tcpipdog0.dll

+ RSVP TCP Service Provider c:\windows\system32\tcpipdogr0.dll

+ RSVP UDP Service Provider c:\windows\system32\tcpipdogr0.dll

删除启动项
重启
删除相应的文件
注意操作步骤

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT