瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 吐血求助Trojan.PSW.ZhengTu.xl病毒怎么杀啊
玲珑无比 - 2006-12-13 20:59:00
我用瑞星杀软查出了C盘下的Trojan.PSW.ZhengTu.xl和Trojan.PSW.Lineage.mnt两个病毒总是提醒重启后删除,但是每次重启后再查互仍然在,它们所在的文件夹目录为C:\Documents and Settings\Administrator\Local Settings\Temp\zts2.dll

C:\WINDOWS\tdll.dll用手动去删也不能删掉,这两个毒弄得我的打印机老是发神经病用不了,各位能帮下忙吗?我已经尝试了好多方法,杀了几天了还是搞不定,请高人指教吧
找ZS论坛不言放弃 - 2006-12-13 21:01:00
去了360论坛了?恭喜你中了招.据说瑞星最新版本可以查杀
遇到病毒不开心 - 2006-12-13 21:04:00
吐血 真浪费 建议你去捐血去 不能浪费哦~~~~~~~~@_@>_<^_^
玲珑无比 - 2006-12-13 21:13:00
血我可是献过三次了,真的,小女子能如此大义凛然,各位大哥你们不能见死不救吧?我可是很乖的,不乱点网站的,只是我的同事乱来我就不知道了,唉!我要竭力顶上去啊,要不我的贴沉了的话何日才能再生啊~~~~~~
红夜鬼1 - 2006-12-13 21:14:00
:\Documents and Settings\Administrator\Local Settings\Temp\到安全模式下清空文件夹
到安全模式下删除
C:\WINDOWS\tdll.dll

不行扫描日志上来

请下载SREng2(最新版) ,使用“智能扫描”,按下“扫描”按钮进行扫描,
扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告
日志文件内容复制-粘贴上来,,日志一次粘不完,分次粘完,请不要修改。

下载地址
http://www.kztechs.com/sreng/sreng2.zip
玲珑无比 - 2006-12-13 21:17:00
楼上的,怎么我老是看见你这个贴的,是不是真的可以行啊?其实以前用瑞星的杀软都还行,就是升级了2007版的后就中毒就越来越深了,真是心寒啊~~~~~~我还是去试下你的方法吧,现在死马也要当成活马医了
遇到病毒不开心 - 2006-12-13 21:27:00
Trojan 为什么开头带这个的都杀不了啊 ~!!!!!!
遇到病毒不开心 - 2006-12-13 21:29:00
看来你身体很好哦 都捐3次了 我帮你顶啊~~~~!!!!!!!^_^>_<
玲珑无比 - 2006-12-14 12:15:00
自已再顶顶了,重新装了卡巴斯基来杀也不行,我快要崩溃了5555555555~~~~~~~~~~
flyfox516 - 2006-12-14 13:31:00
瑞醒2007可以杀
有你就好 - 2006-12-14 13:58:00
2006-12-14,13:53:45

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows 2000 Server Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>  [Microsoft Corporation]
    <Yahoo! Pager><"C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet>  [N/A]
    <ctfmon.exe><ctfmon.exe>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <SoundMan><SOUNDMAN.EXE>  [(Verified)Realtek Semiconductor Corp.]
    <NMGameX_AutoRun><C:\WINNT\system32\Rundll32.exe NMGameX.dll,LiveProcess /aa>  [NMGameX]
    <CnsMin><Rundll32.exe C:\WINNT\downlo~1\CnsMin.dll,Rundll32>  [北京三七二一科技有限公司]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <RavTray><"C:\Program Files\Rising\Rav\RavTray.exe">  [Rising]
    <SKYNET Personal FireWall><C:\Program Files\SkyNet\FireWall\PFW.exe>  [N/A]
    <NeroCheck><C:\WINNT\system32\NeroCheck.exe>  [Ahead Software Gmbh]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINNT\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINNT\downlo~1\CnsHook.dll>  [北京三七二一科技有限公司]
    <{E568441B-9EF3-49F8-9A67-4141AC41ADD4}><C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll>  [Yahoo! China]
    <{4BAB150F-DD97-476D-9C1E-41B6CDC0CA7A}><C:\PROGRA~1\Yahoo!\ASSIST~1\yclickon.dll>  [YAHOO Corporation Limited]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINNT\豪杰多~1.SCR>  [N/A]

==================================
启动文件夹
[Microtek 扫描仪探测器]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microtek 扫描仪探测器.lnk --> C:\PROGRA~1\Microtek\SCANWI~1\SCANNE~1.EXE []><N>
[Adobe Gamma Loader]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk --> C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE [Adobe Systems, Inc.]><N>
[腾讯QQ]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\PROGRA~1\Tencent\qq\QQ.exe [TENCENT]><N>

==================================
服务
[ASP.NET State Service / aspnet_state]
  <C:\WINNT\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Logical Disk Manager Administrative Service / dmadmin]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[P4P Service / P4P Service]
  <C:\Program Files\Common Files\Sogou PXP\p2psvr.exe><Sohu.com Inc.>
[Rav Net Agent / RavAgent]
  <C:\Program Files\Rising\Rav\RavAgent.exe><北京瑞星科技股份有限公司>
[Rav Net Alert / RavAlert]
  <C:\Program Files\Rising\Rav\RavAlert.exe><瑞星科技股份发展有限公司>
[RavService / RavService]
  <"C:\Program Files\Rising\Rav\RavService.exe" /service><Beijing Rising Technology Co., Ltd.>
[RavUpdate / RavUpdate]
  <"C:\Program Files\Rising\Rav\RavUpdate.exe" ><Beijing Rising Technology Co., Ltd.>
[Rising Proxy  Service / RfwProxySrv]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[RNReport / RNReport]
  <"C:\Program Files\Rising\Rav\RNReport.exe"><瑞星科技股份发展有限公司>
[Rising Process Communication Center / RsCCenter]
  <C:\Program Files\Rising\Rav\CCenter.exe><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>

==================================
驱动程序
[00 / 00]
  <\SystemRoot\\SystemRoot\System32\drivers\111312.sys><N/A>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[Rising TDI Base Driver / BaseTDI]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[Cdr4_2K / Cdr4_2K]
  <C:\WINNT\SYSTEM32\DRIVERS\Cdr4_2K.SYS><Roxio>
[Cdralw2k / Cdralw2k]
  <C:\WINNT\SYSTEM32\DRIVERS\Cdralw2k.SYS><Roxio>
[CnsMinKP / CnsMinKP]
  <\SystemRoot\system32\drivers\CnsMinKP.sys><Copyright (C) 3721 Corporation.>
[dmboot / dmboot]
  <System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio]
  <\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload]
  <\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[ExpScaner / ExpScaner]
  <\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[fkcssaxm / fkcssaxm]
  <2 - 系统找不到指定的文件。
><N/A>
[HookCont / HookCont]
  <\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg]
  <\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
  <\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl]
  <\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[Imagedrv / Imagedrv]
  <\SystemRoot\system32\DRIVERS\imagedrv.sys><Ahead Software AG and its licensors>
[VK USB Driver / ISP68X]
  <System32\Drivers\ISP68X.sys><Winbond Electronics Crop.>
[MEMSCAN / MEMSCAN]
  <\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs]
  <\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[New0 / New0]
  <\??\C:\WINNT\system32\new.sys><N/A>
[npkcrypt / npkcrypt]
  <\??\C:\Program Files\Tencent\qq\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv4 / nv4]
  <system32\DRIVERS\nv4.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20]
  <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[RsFwDrv / RsFwDrv]
  <\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[Realtek RTL8139-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[CP210x USB Composite Device driver (WDM) / slabbus]
  <system32\DRIVERS\slabbus.sys><MCCI>
[CP210x USB to UART Bridge Controller Drivers / slabser]
  <system32\DRIVERS\slabser.sys><MCCI>
[Sony Memory Stick Driver(SONYPVM1) / SONYPVM1]
  <\SystemRoot\system32\DRIVERS\SONYPVM1.SYS><Sony Corporation>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1]
  <system32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[Icatch(VII) Still Camera Device / USBCamera]
  <System32\Drivers\Bulk536.sys><USB BULK>
[WatchKey / WatchKey]
  <System32\Drivers\wdkey.sys><N/A>
[World Standard Teletext Codec / WSTCODEC]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[yaskp / yaskp]
  <\SystemRoot\system32\drivers\yaskp.sys><Copyright (C) yahoo Corporation.>
有你就好 - 2006-12-14 14:02:00
Trojan.Dailer.dty 这种病毒杀掉后,重启系统又出现啦,请高手帮忙!
1
查看完整版本: 吐血求助Trojan.PSW.ZhengTu.xl病毒怎么杀啊