瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 电脑中了病毒,杀毒软件开不了,杀毒网页上不了,求救

12   2  /  2  页   跳转

电脑中了病毒,杀毒软件开不了,杀毒网页上不了,求救

列举下载的程序文件:                       

[CKAVWebScan Object]
InProcServer32 = C:\WINNT\system32\Kaspersky Lab\Kaspersky Online Scanner Pro\kavwebscan.dll
CODEBASE = http://www.kaspersky.com.cn/webscanner/kavwebscan_unicode.cab

[InstaFred]
InProcServer32 = C:\WINNT\DOWNLO~1\InstFred.ocx
CODEBASE = file://F:\Program Files\AutoCAD 2002\InstFred.ocx

[PowerList Control]
InProcServer32 = C:\DOCUME~1\aa\APPLIC~1\ppStream\100~1.139\POWERL~1.OCX
CODEBASE = http://www.ppstream.com/bin/powerplayer.cab

[WebActivater Control]
InProcServer32 = C:\WINNT\system32\WEBACT~1.OCX
CODEBASE = http://game.qq.com/QQGame2.cab

[MSN Photo Upload Tool]
InProcServer32 = C:\WINNT\Downloaded Program Files\MsnPUpld.dll
CODEBASE = http://spaces.msn.com//PhotoUpload/MsnPUpld.cab

[AcDcToday 控件]
InProcServer32 = C:\WINNT\DOWNLO~1\ACDCTO~1.OCX
CODEBASE = file://F:\Program Files\AutoCAD 2002\AcDcToday.ocx

[SysMonOCX Control]
InProcServer32 = C:\WINNT\DOWNLO~1\SYSMON~1.OCX
CODEBASE = http://www.ahn.com.cn/aspservice/plugin/myfirewall20.cab

[photo_uploader Control]
InProcServer32 = C:\PROGRA~1\PHOTO_~1\PHOTO_~1.OCX
CODEBASE = http://upload.photo.163.com/photoup.cab

[NOXLATE-BANR]
InProcServer32 = C:\WINNT\DOWNLO~1\InstBanr.ocx
CODEBASE = file://F:\Program Files\AutoCAD 2002\InstBanr.ocx

[Shockwave Flash Object]
InProcServer32 = C:\WINNT\system32\Macromed\Flash\Flash8b.ocx
CODEBASE = http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

[vc Control]
InProcServer32 = C:\WINNT\DOWNLO~1\vco.ocx
CODEBASE = http://update.viruschina.com/wmsj/vco.cab

[VqqSpeedDlProxy Class]
InProcServer32 = C:\WINNT\vqqsdl.dll
CODEBASE = http://218.85.138.27/vqqsdl1009.cab

[AcPreview 控件]
InProcServer32 = C:\WINNT\DOWNLO~1\ACPREV~1.OCX
CODEBASE = file://F:\Program Files\AutoCAD 2002\AcPreview.ocx

--------------------------------------------------

列举 ShellServiceObjectDelayLoad 项目:           

Network.ConnectionTray: C:\WINNT\system32\NETSHELL.dll
WebCheck: C:\WINNT\System32\webcheck.dll
SysTray: stobject.dll

--------------------------------------------------
报告完毕,共 7,358 字节         
报告生成用时:0.047秒     

Command line options:
  /verbose  - to add additional info on each section
  /complete - to include empty sections and unsuspicious data
  /full    - to include several rarely-important sections
  /force9x  - to include Win9x-only startups even if running on WinNT
  /forcent  - to include WinNT-only startups even if running on Win9x
  /forceall - to include all Win9x and WinNT startups, regardless of platform
  /history  - to list version history only
gototop
 

O23 - NT 服务: System Event - Unknown owner - C:\WINNT\SVCH0ST.exe (file missing)
打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索 System Event 删除...

修复
O2 - BHO: perfdp - {995FF616-7583-4D6B-9675-EED24EDC93BB} - C:\WINNT\system32\perfiup.dll
O2 - BHO: tkuid Class - {A2DBE85F-37BF-488F-9B0C-AE21AE05658A} - C:\WINNT\system32\contwin.dll (file missing)
O2 - BHO: DDOC - {A64E86D2-203D-4145-AA9B-2425BAF568E9} - C:\WINNT\system32\henroer.dll
O4 - 启动项HKLM\\Run: [Tray] C:\WINNT\command\rundll32.exe
O4 - 启动项HKLM\\Run: [Synchronization] rundll32.exe C:\WINNT\system32\MSCOMCT32.dll,DllUnregisterServer
删除
C:\WINNT\system32\perfiup.dll
C:\WINNT\system32\henroer.dll
C:\WINNT\command\rundll32.exe
C:\WINNT\system32\MSCOMCT32.dll

http://download5.pctutu.com/soft/winspeed782.zip
用超级兔子清理王在安全模式下卸载流氓软件...
gototop
 

开始-所有程序-瑞星杀毒软件-添加删除组件-修复
gototop
 

我的运行HijackThis.exe单机"扫描日志并保存日志"后日志只有上面的部分
gototop
 

好的
谢谢
我试试
gototop
 

不行
程序被自动关闭
gototop
 

不用试了,我中的是和你一样的病毒,用瑞星2007查都查不出来.卡巴也没用,格式化也不行,估计得用低格了.....
gototop
 


夸张!!
真的没有任何别的办法了啊????
跪求高手啊  硬盘里面的资料还很多 啊
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT