
我的电脑经常重启,查杀病毒,可每次上机继续出现!!病毒名字:Win32.Troj.Look2Me.g.237191还有个Win32.Hack.IRCBot.cy.8224
而且还经常弹出一些网页,及两个小窗口,桌面上也莫名其妙出现一些图标,如图:
下面是扫描的日志:
2006-07-31,18:06:09
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Internat.exe><internat.exe> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Synchronization Manager><mobsync.exe /logon> [Microsoft Corporation]
<NvCplDaemon><RUNDLL32.EXE NvQTwk,NvCplDaemon initialize> []
<defender><C:\\dfndrfg_7.exe> [&%&%&%&%%&%&%%&%]
<keyboard><C:\\kybrdfg_7.exe> [#$*&$*&$&*$&*$&*#$&*]
<SKYNET Personal FireWall><D:\PROGRA~1\SKYNET\FIREWALL\pfw.exe> [广州众达天网技术有限公司]
<newname><C:\\nwnmfg_7.exe> [&*&$*#&*$&*#&$*&*&$***]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINNT\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><NVDESK32.DLL> [NVIDIA Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}><C:\WINNT\system32\ljjihfd.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\CSCSettings]
<WinlogonNotify: CSCSettings><C:\WINNT\system32\p6n80g5ue6.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\IntlRun]
<WinlogonNotify: IntlRun><C:\WINNT\system32\UBERENV.DLL> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\IPConfTSP]
<WinlogonNotify: IPConfTSP><C:\WINNT\system32\mvafd.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\khfgdda]
<WinlogonNotify: khfgdda><khfgdda.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ljjihfd]
<WinlogonNotify: ljjihfd><ljjihfd.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ModuleUsage]
<WinlogonNotify: ModuleUsage><C:\WINNT\system32\mvafd.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rqrsrro]
<WinlogonNotify: rqrsrro><rqrsrro.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Shell Extensions]
<WinlogonNotify: Shell Extensions><C:\WINNT\system32\rjsutils.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellScrap]
<WinlogonNotify: ShellScrap><C:\WINNT\system32\rjsutils.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sstro]
<WinlogonNotify: sstro><C:\WINNT\system32\sstro.dll> []
==================================
附件:
7202322006731201215.bmp