请高手帮忙看看这日志,我的电脑中毒了,但是杀了还有,
杀毒软件总是报有毒,汗~~~
谢谢先
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ BDAgent BDSwitch Application SOFTWIN S.R.L. c:\program files\softwin\bitdefender10\bdagent.exe
+ BDMCon BitDefender Management Console SOFTWIN S.R.L. c:\program files\softwin\bitdefender10\bdmcon.exe
这是病毒报表:C:\Program Files\Common Files\{406A1408-086E-2052-1110-040407040056}\Update.exe发现: Adware.ToolBar888.B
C:\Program Files\Common Files\{406A1408-086E-2052-1110-040407040056}\Update.exe杀毒失败
C:\Program Files\Common Files\{406A1408-086E-2052-1110-040407040056}\Update.exe移动
C:\Program Files\Common Files\{306A1408-086E-2052-1110-040407040056}\MyToolBar.dll发现: Adware.ToolBar888.B
C:\Program Files\Common Files\{306A1408-086E-2052-1110-040407040056}\MyToolBar.dll杀毒失败
C:\Program Files\Common Files\{306A1408-086E-2052-1110-040407040056}\MyToolBar.dll移动
C:\Program Files\Common Files\{306A1408-086E-2052-1110-040407040056}\Activate.exe发现: Adware.ToolBar888.B
C:\Program Files\Common Files\{306A1408-086E-2052-1110-040407040056}\Activate.exe杀毒失败
C:\Program Files\Common Files\{306A1408-086E-2052-1110-040407040056}\Activate.exe移动
C:\Program Files\Common Files\{306A1408-086E-2052-1110-040407040056}\Uninst.exe发现: Adware.ToolBar888.B
C:\Program Files\Common Files\{306A1408-086E-2052-1110-040407040056}\Uninst.exe杀毒失败
C:\Program Files\Common Files\{306A1408-086E-2052-1110-040407040056}\Uninst.exe移动
+ IMJPMIG8.1 File not found: ;
+ PHIME2002A File not found: ;
+ PHIME2002ASync File not found: ;
+ QuickTime Task File not found: ;
+ Skype File not found: ;
+ SoundMan Realtek Sound Manager Realtek Semiconductor Corp. c:\windows\soundman.exe
+ Thunder File not found: ;
+ TkBellExe File not found: ;
+ WebThunder File not found: ;
C:\Documents and Settings\All Users\「开始」菜单\程序\启动
+ AutoCAD 启动加速器.lnk AutoCAD Startup Accelerator Autodesk, Inc c:\program files\common files\autodesk shared\acstart17.exe
C:\Documents and Settings\Administrator\「开始」菜单\程序\启动
+ 腾讯QQ珊瑚虫版.lnk CoralQQ 加载程序 珊瑚虫工作室 d:\program files\tencent珊瑚虫\qq\coralqq.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
+ {406A1408-086E-2052-1110-040407040056} File not found: C:\Program Files\Common Files\{406A1408-086E-2052-1110-040407040056}\Update.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
+ eMuleAutoStart eMule http://www.emule.org.cn c:\program files\emule\emule.exe
+ kugoo File not found: ;
+ MSMSGS File not found: ;
+ updatereal File not found: C:\WINDOWS\realupdate.exe other
HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components
+ 0 File not found:
About:Home
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ AutoCAD 数字签名图标覆盖处理程序 AcSignIcon Module Autodesk c:\windows\system32\acsignicon.dll
+ Autodesk Drawing Preview AcThumbnail Module Autodesk c:\program files\common files\autodesk shared\thumbnail\acthumbnail16.dll
+ Display Panning CPL Extension File not found: deskpan.dll
+ HyperTerminal Icon Ext HyperTerminal Applet Library Hilgraeve, Inc. c:\windows\system32\hticons.dll
+ Shell Extensions for RealOne Player RealPlayer Shell Extensions RealNetworks, Inc. c:\program files\real\realplayer\rpshell.dll
+ WinRAR shell extension c:\program files\winrar\rarext.dll
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ Web 文件夹 c:\program files\common files\microsoft shared\web folders\msonsext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ ToolBar888 File not found: C:\Program Files\Common Files\{306A1408-086E-2052-1110-040407040056}\MyToolBar.dll
+ 超级兔子上网精灵 HaoKanBar Toolbar Module Xiang Feng Technology d:\program files\超级兔子\magicset\haokanbar.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ googletoolbar1.dll File not found: c:\program files\google\googletoolbar1.dll
+ MyToolBar.dll File not found: C:\Program Files\Common Files\{306A1408-086E-2052-1110-040407040056}\MyToolBar.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ 豪杰超级解霸V8 d:\herosoft\herov8\sthsdvd.exe
+ 启动Web迅雷 File not found: http://my.xunlei.com
+ 启动迅雷 Thunder Networking Technologies,LTD d:\program files\thunder network\thunder\thunder.exe
+ 腾讯QQ File not found: D:\Program Files\Tencent\QQ\QQ.EXE
HKLM\System\CurrentControlSet\Services
+ bdss Scans media for viruses and other security threats c:\program files\common files\softwin\bitdefender scan server\bdss.exe
+ C-DillaCdaC11BA Macrovision RTS Service Macrovision c:\windows\system32\drivers\cdac11ba.exe
+ C-DillaSrv C-Dilla RTS Service C-Dilla Ltd c:\windows\system32\drivers\cdantsrv.exe
+ LIVESRV Downloads BitDefender updates and new malware signatures from the Internet SOFTWIN S.R.L. c:\program files\common files\softwin\bitdefender update service\livesrv.exe
+ NetWorkLogons 支持网络上计算机远程登陆事件。如果此服务被停用,网络登陆将不可用。如果此服务被禁用,任何依赖它的服务将无法启动。 c:\windows\system32\kb27861012.log
+ Unigraphics License Server (uglmd) 为此 NX 产品准备许可证 Macrovision Corporation c:\program files\ugs\license servers\ugnxflexlm\lmgrd.exe
+ VSSERV Scans media for viruses and other security threats SOFTWIN S.R.L. c:\program files\softwin\bitdefender10\vsserv.exe
+ XCOMM Ensures proper communication between BitDefender components Softwin c:\program files\common files\softwin\bitdefender communicator\xcommsvr.exe
HKLM\System\CurrentControlSet\Services
+ ALCXSENS Sensaura WDM 3D Audio Driver Sensaura c:\windows\system32\drivers\alcxsens.sys
+ ALCXWDM Realtek AC'97 Audio Driver (WDM) Realtek Semiconductor Corp. c:\windows\system32\drivers\alcxwdm.sys
+ bdfdll c:\program files\softwin\bitdefender10\bdfdll.sys
+ BDFSDRV c:\program files\softwin\bitdefender10\bdfsdrv.sys
+ BDRSDRV c:\program files\softwin\bitdefender10\bdrsdrv.sys
+ C-Dilla C-Dilla Windows NT RTS Macrovision c:\windows\system32\drivers\cdant.sys
+ CdaC15BA Macrovision SECURITY Driver Macrovision Europe Ltd c:\windows\system32\drivers\cdac15ba.sys
+ DS1410D File not found: SYSTEM32\drivers\DS1410D.SYS
+ FETNDIS NDIS 5.0 miniport driver VIA Technologies, Inc. c:\windows\system32\drivers\fetnd5.sys
+ k750bus Sony Ericsson 750 Driver MCCI c:\windows\system32\drivers\k750bus.sys
+ k750mdfl Sony Ericsson 750 USB WMC Modem Filter MCCI c:\windows\system32\drivers\k750mdfl.sys
+ k750mdm Sony Ericsson 750 USB WMC Modem Drivers MCCI c:\windows\system32\drivers\k750mdm.sys
+ k750mgmt Sony Ericsson 750 USB WMC Device Management Drivers MCCI c:\windows\system32\drivers\k750mgmt.sys
+ k750obex Sony Ericsson 750 USB WMC OBEX Interface Drivers MCCI c:\windows\system32\drivers\k750obex.sys
+ kmsinput c:\windows\system32\drivers\kmsinput.sys
+ npkcrypt nProtect KeyCrypt Driver INCA Internet Co., Ltd. d:\program files\tencent\qq\npkcrypt.sys
+ nv NVIDIA Compatible Windows 2000 Miniport Driver, Version 56.73 NVIDIA Corporation c:\windows\system32\drivers\nv4_mini.sys
+ pfc Padus(R) ASPI Shell Padus, Inc. c:\windows\system32\drivers\pfc.sys
+ Ptilink Direct Parallel Link Driver Parallel Technologies, Inc. c:\windows\system32\drivers\ptilink.sys
+ Secdrv SafeDisc driver c:\windows\system32\drivers\secdrv.sys
+ SONYPVU1 Sony USB Lower Filter driver Sony Corporation c:\windows\system32\drivers\sonypvu1.sys
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls
+ sockspy.dll c:\windows\system32\sockspy.dll
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
+ EPSON V5 2KMonitor EPSON Bidirectional Monitor SEIKO EPSON CORPORATION c:\windows\system32\ebpmon2.dll
这是system扫描的日志
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [Microsoft Corporation]
<MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background> [Microsoft Corporation]
<kugoo><; C:\PROGRA~1\KUGOO2\KUGOO.EXE> []
<updatereal><C:\WINDOWS\realupdate.exe other> []
<eMuleAutoStart><C:\Program Files\eMule\eMule.exe -AutoStart> [http://www.emule.org.cn]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<SoundMan><SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<QuickTime Task><; "F:\qttask.exe" -atboottime> []
<Skype><; C:\Program Files\skype\Phone\Skype.exe> []
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<Thunder><; "D:\Program Files\Thunder Network\Thunder\ThunderShell.exe" /s> []
<Super Rabbit SafeEdit><D:\Program Files\超级兔子\MagicSet\SRFC.EXE /Load> [Super Rabbit Soft]
<SKYNET Personal FireWall><; D:\极品五笔\FIREWALL\pfw.exe> []
<BDMCon><"C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg> [SOFTWIN S.R.L.]
<BDAgent><"C:\Program Files\Softwin\BitDefender10\bdagent.exe"> [SOFTWIN S.R.L.]
<WebThunder><; C:\Program Files\Thunder Network\WebThunder\WebThunder.exe> [深圳市迅雷网络技术有限公司]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><sockspy.dll> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><LogonUI.EXE> [Microsoft Corporation]
==================================
启动文件夹
[Microsoft Office]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk><N>
[AutoCAD 启动加速器]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\AutoCAD 启动加速器.lnk><H>
[腾讯QQ珊瑚虫版]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ珊瑚虫版.lnk><H>
附件:
6207992006101095712.BMP