玲珑无比 - 2006-12-13 20:59:00
我用瑞星杀软查出了C盘下的Trojan.PSW.ZhengTu.xl和Trojan.PSW.Lineage.mnt两个病毒总是提醒重启后删除,但是每次重启后再查互仍然在,它们所在的文件夹目录为C:\Documents and Settings\Administrator\Local Settings\Temp\zts2.dll
和
C:\WINDOWS\tdll.dll用手动去删也不能删掉,这两个毒弄得我的打印机老是发神经病用不了,各位能帮下忙吗?我已经尝试了好多方法,杀了几天了还是搞不定,请高人指教吧
找ZS论坛不言放弃 - 2006-12-13 21:01:00
去了360论坛了?恭喜你中了招.据说瑞星最新版本可以查杀
遇到病毒不开心 - 2006-12-13 21:04:00
吐血 真浪费 建议你去捐血去 不能浪费哦~~~~~~~~@_@>_<^_^
玲珑无比 - 2006-12-13 21:13:00
血我可是献过三次了,真的,小女子能如此大义凛然,各位大哥你们不能见死不救吧?我可是很乖的,不乱点网站的,只是我的同事乱来我就不知道了,唉!我要竭力顶上去啊,要不我的贴沉了的话何日才能再生啊~~~~~~
红夜鬼1 - 2006-12-13 21:14:00
:\Documents and Settings\Administrator\Local Settings\Temp\到安全模式下清空文件夹
到安全模式下删除
C:\WINDOWS\tdll.dll
不行扫描日志上来
请下载SREng2(最新版) ,使用“智能扫描”,按下“扫描”按钮进行扫描,
扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告
日志文件内容复制-粘贴上来,,日志一次粘不完,分次粘完,请不要修改。
下载地址
http://www.kztechs.com/sreng/sreng2.zip
玲珑无比 - 2006-12-13 21:17:00
楼上的,怎么我老是看见你这个贴的,是不是真的可以行啊?其实以前用瑞星的杀软都还行,就是升级了2007版的后就中毒就越来越深了,真是心寒啊~~~~~~我还是去试下你的方法吧,现在死马也要当成活马医了
遇到病毒不开心 - 2006-12-13 21:27:00
Trojan 为什么开头带这个的都杀不了啊 ~!!!!!!
遇到病毒不开心 - 2006-12-13 21:29:00
看来你身体很好哦 都捐3次了 我帮你顶啊~~~~!!!!!!!^_^>_<
玲珑无比 - 2006-12-14 12:15:00
自已再顶顶了,重新装了卡巴斯基来杀也不行,我快要崩溃了5555555555~~~~~~~~~~
flyfox516 - 2006-12-14 13:31:00
瑞醒2007可以杀
有你就好 - 2006-12-14 13:58:00
2006-12-14,13:53:45
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows 2000 Server Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [Microsoft Corporation]
<Yahoo! Pager><"C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet> [N/A]
<ctfmon.exe><ctfmon.exe> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SoundMan><SOUNDMAN.EXE> [(Verified)Realtek Semiconductor Corp.]
<NMGameX_AutoRun><C:\WINNT\system32\Rundll32.exe NMGameX.dll,LiveProcess /aa> [NMGameX]
<CnsMin><Rundll32.exe C:\WINNT\downlo~1\CnsMin.dll,Rundll32> [北京三七二一科技有限公司]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<RavTray><"C:\Program Files\Rising\Rav\RavTray.exe"> [Rising]
<SKYNET Personal FireWall><C:\Program Files\SkyNet\FireWall\PFW.exe> [N/A]
<NeroCheck><C:\WINNT\system32\NeroCheck.exe> [Ahead Software Gmbh]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINNT\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINNT\downlo~1\CnsHook.dll> [北京三七二一科技有限公司]
<{E568441B-9EF3-49F8-9A67-4141AC41ADD4}><C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll> [Yahoo! China]
<{4BAB150F-DD97-476D-9C1E-41B6CDC0CA7A}><C:\PROGRA~1\Yahoo!\ASSIST~1\yclickon.dll> [YAHOO Corporation Limited]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><C:\WINNT\豪杰多~1.SCR> [N/A]
==================================
启动文件夹
[Microtek 扫描仪探测器]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microtek 扫描仪探测器.lnk --> C:\PROGRA~1\Microtek\SCANWI~1\SCANNE~1.EXE []><N>
[Adobe Gamma Loader]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk --> C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE [Adobe Systems, Inc.]><N>
[腾讯QQ]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\PROGRA~1\Tencent\qq\QQ.exe [TENCENT]><N>
==================================
服务
[ASP.NET State Service / aspnet_state]
<C:\WINNT\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Logical Disk Manager Administrative Service / dmadmin]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[P4P Service / P4P Service]
<C:\Program Files\Common Files\Sogou PXP\p2psvr.exe><Sohu.com Inc.>
[Rav Net Agent / RavAgent]
<C:\Program Files\Rising\Rav\RavAgent.exe><北京瑞星科技股份有限公司>
[Rav Net Alert / RavAlert]
<C:\Program Files\Rising\Rav\RavAlert.exe><瑞星科技股份发展有限公司>
[RavService / RavService]
<"C:\Program Files\Rising\Rav\RavService.exe" /service><Beijing Rising Technology Co., Ltd.>
[RavUpdate / RavUpdate]
<"C:\Program Files\Rising\Rav\RavUpdate.exe" ><Beijing Rising Technology Co., Ltd.>
[Rising Proxy Service / RfwProxySrv]
<c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[RNReport / RNReport]
<"C:\Program Files\Rising\Rav\RNReport.exe"><瑞星科技股份发展有限公司>
[Rising Process Communication Center / RsCCenter]
<C:\Program Files\Rising\Rav\CCenter.exe><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
==================================
驱动程序
[00 / 00]
<\SystemRoot\\SystemRoot\System32\drivers\111312.sys><N/A>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[Rising TDI Base Driver / BaseTDI]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[Cdr4_2K / Cdr4_2K]
<C:\WINNT\SYSTEM32\DRIVERS\Cdr4_2K.SYS><Roxio>
[Cdralw2k / Cdralw2k]
<C:\WINNT\SYSTEM32\DRIVERS\Cdralw2k.SYS><Roxio>
[CnsMinKP / CnsMinKP]
<\SystemRoot\system32\drivers\CnsMinKP.sys><Copyright (C) 3721 Corporation.>
[dmboot / dmboot]
<System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio]
<\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload]
<\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[ExpScaner / ExpScaner]
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[fkcssaxm / fkcssaxm]
<2 - 系统找不到指定的文件。
><N/A>
[HookCont / HookCont]
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg]
<\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
<\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl]
<\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[Imagedrv / Imagedrv]
<\SystemRoot\system32\DRIVERS\imagedrv.sys><Ahead Software AG and its licensors>
[VK USB Driver / ISP68X]
<System32\Drivers\ISP68X.sys><Winbond Electronics Crop.>
[MEMSCAN / MEMSCAN]
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs]
<\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[New0 / New0]
<\??\C:\WINNT\system32\new.sys><N/A>
[npkcrypt / npkcrypt]
<\??\C:\Program Files\Tencent\qq\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv4 / nv4]
<system32\DRIVERS\nv4.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[RsFwDrv / RsFwDrv]
<\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[Realtek RTL8139-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[CP210x USB Composite Device driver (WDM) / slabbus]
<system32\DRIVERS\slabbus.sys><MCCI>
[CP210x USB to UART Bridge Controller Drivers / slabser]
<system32\DRIVERS\slabser.sys><MCCI>
[Sony Memory Stick Driver(SONYPVM1) / SONYPVM1]
<\SystemRoot\system32\DRIVERS\SONYPVM1.SYS><Sony Corporation>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1]
<system32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[Icatch(VII) Still Camera Device / USBCamera]
<System32\Drivers\Bulk536.sys><USB BULK>
[WatchKey / WatchKey]
<System32\Drivers\wdkey.sys><N/A>
[World Standard Teletext Codec / WSTCODEC]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[yaskp / yaskp]
<\SystemRoot\system32\drivers\yaskp.sys><Copyright (C) yahoo Corporation.>
有你就好 - 2006-12-14 14:02:00
Trojan.Dailer.dty 这种病毒杀掉后,重启系统又出现啦,请高手帮忙!
© 2000 - 2026 Rising Corp. Ltd.