前段时间台式机遭病毒侵犯中毒太深不得已重新系统并查杀,累及笔记本也出现病毒症状,老弹出广告窗口,系统缓慢。后分别用木马克星、完美卸载、卡巴斯基及360安全卫士查杀,部分病毒被消除,但只要打开TM/IE/FF,完美卸载的防火墙提示有病毒,而且在系统盘的临时文件夹的确就动态随机出现一些文件,比如C:\WINDOWS\Temp\cch~38844b2a0.htp等,这些引起报警。。
现将用SREng2扫描的结果贴上来,希望有高手指点下我该如何动作下一步:
2006-08-12,04:57:44
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<My Helper><D:\GreenSoft\Myhelper\Helper.EXE> [助手工作室]
<LiveUpatePower><D:\Program Files\完美卸载V2006\MyUpdate.exe -PowerOn> []
<RegFireWall><D:\Program Files\完美卸载V2006\WmSysPro.exe -PowerOn> []
<kav><"D:\Program Files\Kaspersky Anti-Virus 6.0\avp.exe"> [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
==================================
启动文件夹
[清华紫光CDMA无线上网卡]
<C:\Documents and Settings\张四宇\「开始」菜单\程序\启动\清华紫光CDMA无线上网卡.lnk><N>
==================================
服务
[卡巴斯基反病毒软件6.0 / AVP]
<"D:\Program Files\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
[IBM PM Service / IBMPMSVC]
<C:\WINDOWS\System32\ibmpmsvc.exe><N/A>
==================================
浏览器加载项
[CWebToolsBHO Class]
{C49A89A1-D366-4151-904C-16F69B1C444E} <D:\GreenSoft\IE6多窗口插件\WebTools.dll, Microgarden LLC>
[Pluck]
{053017A8-53F7-4EA3-AA38-A4CCAAF1F9E7} <D:\Program Files\Pluck Corporation\Pluck\PluckExplorerBar.dll, N/A>
[Web Browser Applet Control]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\WINDOWS\System32\msjava.dll, Microsoft Corporation>
[Web反病毒保护]
{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <D:\Program Files\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
[e起摘]
{36A2003E-700F-4a3f-B25E-3ABBAB7E36A2} <, N/A>
[Save To Palm]
{6C8741AB-53B4-476e-BE7C-F519AD8A6494} <, N/A>
[NetCollect]
{7051B514-71B7-41B1-88ED-DDF0FAAA3115} <D:\GreenSoft\NetCollect\netcollect.exe, N/A>
[Microgarden WebTools]
{E929661E-3728-4E52-BCCB-AE4058F75466} <D:\GreenSoft\IE6多窗口插件\WebTools.dll, Microgarden LLC>
[Microsoft Office Template and Media Control]
{02BCC737-B171-4746-94C9-0D8A0B2C0089} <C:\WINDOWS\Downloaded Program Files\IEAWSDC.DLL, N/A>
[XLink Class]
{18F57D30-EF36-4C0E-9343-7BFA6DF79B4A} <C:\WINDOWS\System32\wmpcd32.dll, N/A>
[Java Plug-in 1.4.2_04]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll, JavaSoft / Sun Microsystems, Inc.>
[Java Plug-in 1.4.2_04]
{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} <C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll, JavaSoft / Sun Microsystems, Inc.>
[Shockwave Flash
Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\flash\flash8.ocx, Macromedia, Inc.>
[CPasswordEditCtrl
Object]
{E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\System32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
[&Save To Palm]
<D:\Program Files\palmOne\HandStoryME.htm, N/A>
[&使用迅雷下载]
<D:\Program Files\Thunder\Program\GetUrl.htm, N/A>
[360doc个人图书馆]
<http://www.360doc.com/rightClick.aspx, N/A>
[C&lip To Palm]
<D:\Program Files\palmOne\HandStoryMEC.htm, N/A>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用网际快车下载]
<D:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<D:\Program Files\FlashGet\jc_all.htm, N/A>
[加入天天网摘]
<http://www.365key.com/include/rightClick.aspx, N/A>
[添加到e起摘]
<C:\WINDOWS\system\enetiebutton\enetiebutton.html, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[采集源代码]
<D:\GreenSoft\NetCollect\NcActive\NcSourceCode.htm, N/A>
[采集网页]
<D:\GreenSoft\NetCollect\NcActive\NcWebPage.htm, N/A>
[采集网页的选定部分]
<D:\GreenSoft\NetCollect\NcActive\NcselWebPage.htm, N/A>
[采集选定部分的源代码]
<D:\GreenSoft\NetCollect\NcActive\NcselSourceCode.htm, N/A>
==================================
附件:
727455200681251222.JPG