12   1  /  2  页   跳转

中毒了,求助

中毒了,求助

文件名:test.exe
文件路径:test.exe>c:\program files\internet explorer\test.exe
病毒名:Trojan.PSW.Misc.w

请问该如何清除,多谢!
最后编辑2006-03-02 11:12:41
分享到:
gototop
 

结束c:\program files\internet explorer\test.exe进程

进入注册表
搜索test.exe
找到后删除
注意路径是c:\program files\internet explorer\test.exe

删除
c:\program files\internet explorer\test.exe
gototop
 

请问“结束c:\program files\internet explorer\test.exe进程”
如何操作,
又是如何进入注册表呢?谢谢!
gototop
 

【回复“bbnhn”的帖子】
按CTRL+ALT+DEL组合键
调出任务管理器
在test.exe进程名称上右击--结束

开始--运行
输入regedit
确定
进入注册表
点击菜单栏中的编辑--查找 
输入test.exe
进行查找
gototop
 

我在任务管理器没有发现test.exe进程,后面按照你所说的步骤进行了,可是重新启动后还是在那里发现了同样的病毒,怎么办啊?
gototop
 

Autoruns保存一个日志发上来
日志保存方法:选择File->Save菜单项保存日志时注意选择Options->Hide Microsoft Entries菜单项(设置了这项后点工具栏的刷新按钮)

工具的下载、使用参考http://forum.ikaka.com/topic.asp?board=28&artid=7318038
gototop
 

反复操作了几次,这次启动后终于没有发现了,看看明天怎么样,如果还是有问题,我再发日志,第一次上这个论坛,感觉大家很热心,谢谢啊!
gototop
 

还是有毒啊
gototop
 

请看日志:
ProcessPIDCPUDescriptionCompany Name
System Idle Process095.38
Interruptsn/aHardware Interrupts
DPCsn/a1.54Deferred Procedure Calls
System4
  SMSS.EXE536Windows NT Session ManagerMicrosoft Corporation
  CSRSS.EXE604Client Server Runtime ProcessMicrosoft Corporation
  WINLOGON.EXE628Windows NT Logon ApplicationMicrosoft Corporation
    SERVICES.EXE6721.54Services and Controller appMicrosoft Corporation
    SVCHOST.EXE856Generic Host Process for Win32 ServicesMicrosoft Corporation
    CCenter.exe956CCenterBeijing Rising Technology Co., Ltd.
    SVCHOST.EXE972Generic Host Process for Win32 ServicesMicrosoft Corporation
      wuauclt.exe420Automatic UpdatesMicrosoft Corporation
    SVCHOST.EXE11281.54Generic Host Process for Win32 ServicesMicrosoft Corporation
    SVCHOST.EXE1140Generic Host Process for Win32 ServicesMicrosoft Corporation
    RavMonD.exe1160RavMondBeijing Rising Technology Co., Ltd.
      RavStub.exe1456Rising RavStubBeijing Rising Technology Co., Ltd.
    SPOOLSV.EXE1372Spooler SubSystem AppMicrosoft Corporation
    CDANTSRV.EXE1856C-Dilla RTS ServiceC-Dilla Ltd
    MDM.EXE1920Machine Debug ManagerMicrosoft Corporation
    NVSVC32.EXE1960NVIDIA Driver Helper Service, Version 56.72NVIDIA Corporation
    LSASS.EXE684LSA Shell (Export Version)Microsoft Corporation
EXPLORER.EXE1708Windows ExplorerMicrosoft Corporation
RUNDLL32.EXE312Run a DLL as an AppMicrosoft Corporation
realsched.exe432RealNetworks SchedulerRealNetworks, Inc.
Rfw.exe440Rising Personal FireWall Main ProgramBeijing Rising Technology Corporation Limited
RavTask.exe448RavTimerBeijing Rising Technology Co., Ltd.
  RavMon.exe688RavMonBeijing Rising Technology Co., Ltd.
RUNDLL32.EXE496Run a DLL as an AppMicrosoft Corporation
RUNDLL32.EXE508Run a DLL as an AppMicrosoft Corporation
qttask.exe516Apple Computer, Inc.
ctfmon.exe584CTF LoaderMicrosoft Corporation
LFMonitor.exe600SendFaxMonitor Microsoft 基础类应用程序
LFClient.exe588LANFax Suite客户端程序北京华录北方电子有限责任公司
acad.exe728AutoCAD ApplicationAutodesk, Inc.
TBrowser.exe416Tencent ExplorerTencent
autoruns.exe2504Autostart program viewerSysinternals - www.sysinternals.com
NOTEPAD.EXE3536记事本Microsoft Corporation
procexp.exe748Sysinternals Process ExplorerSysinternals
conime.exe3128Console IMEMicrosoft Corporation
gototop
 

我是用ProcessExplorer导出的,可以吗?
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT