渭水 - 2008-7-10 23:06:00
开始发作是因为启动XP后,始终不显示桌面。可进入安全模式。反复使用瑞星和卡卡,无效。下载清理助手,清理出包括灰鸽子在内的众多病毒和木马。然后启动,能够进入桌面。但运行卡卡,发现有木马下载器和众多的“问道盗号木马”。用卡卡清除。然后扫了日志,请帮忙分析,还应该如何操作?谢谢。
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)附件:
SREngLOG.log
cckk1223 - 2008-7-11 10:24:00
你先加我QQ ;3067499863
QQ群:61505098 然后我来告诉你(在这里打字太多了不好)
bluebin - 2008-7-11 10:41:00
使用sreng最新版本清理一下几项:
启动项目注册表:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{4D698451-2015-6358-9871-2015987452D4}><C:\WINDOWS\system32\apzhdtde.dll> [File is missing]
<{30618412-C528-C784-C056-C164D1F7C503}><C:\WINDOWS\system32\detxciua.dll> [File is missing]
<{4372FE4D-E2C2-45FE-A893-E2B1691A7DD0}><> [N/A]
<{00080008-0008-0008-0008-00080008BB15}><C:\WINDOWS\system32\encapdh.dll> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<dpvvoxmh.dll><> [N/A]
<adsntzt.dll><> [N/A]
<rasdlgcq.dll><> [N/A]
<mstimewd.dll><> [N/A]
<cliconfgzx.dll><> [N/A]
<msobjstl.dll><> [N/A]
<ksuserfy.dll><> [N/A]
<bootvidgj.dll><> [N/A]
<tscfgwmijxsj.dll><> [N/A]
<dispexcb.dll><> [N/A]
<imgutilhx2.dll><> [N/A]
<encapdh.dll><C:\WINDOWS\system32\encapdh.dll> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<AVPSrv><; C:\WINDOWS\AVPSrv.exE> [File is missing]
<cmdbcs><; C:\WINDOWS\cmdbcs.exe> [File is missing]
<DbgHlp32><; C:\WINDOWS\DbgHlp32.exe> [File is missing]
<Kvsc3><; C:\WINDOWS\Kvsc3.exE> [File is missing]
<LotusHlp><; C:\WINDOWS\LotusHlp.exe> [File is missing]
<mppds><; C:\WINDOWS\mppds.exe> [File is missing]
<SSLDyn><; C:\WINDOWS\SSLDyn.exe> [File is missing]
<upxdnd><; C:\WINDOWS\upxdnd.exe> [File is missing]
<WinSysM><; C:\WINDOWS\215366M.exe> [File is missing]
<WinSysW><; C:\WINDOWS\215366L.exe> [File is missing]
<msccrt><; C:\WINDOWS\msccrt.exe> [File is missing]
<MsIMMs32><; C:\WINDOWS\MsIMMs32.exE> [File is missing]
<MsPrint32D><; C:\WINDOWS\MsPrint32D.exe> [File is missing]
修复文件关联:
TXT CHM INI
重启电脑 杀毒软件升级到最新版本,全盘查杀,无法删除的,可以上报瑞星。
© 2000 - 2026 Rising Corp. Ltd.