瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 偷上黄网,中了灰鸽子,后悔莫及!请高手帮助!

12   2  /  2  页   跳转

偷上黄网,中了灰鸽子,后悔莫及!请高手帮助!

谢谢!我去试试手动查杀!
gototop
 

不行啊~~是变种的!检测不到文件名字!
gototop
 

自找的!
gototop
 

看了下启动项目:
服务里第1个:

[cress / cress][Stopped/Auto Start]
<C:\WINDOWS\cress.exe><N/A>
gototop
 

引用:
【帮帮我ya的贴子】[C:\Program Files\WinPoET Broadband Connection\WrOSControl.dll] [N/A, N/A]
[C:\Program Files\WinPoET Broadband Connection\WrFCUtil.dll] [N/A, N/A]
[C:\Program Files\WinPoET Broadband Connection\WrEventLog.dll] [N/A, N/A]
[C:\Program Files\WinPoET Broadband Connection\WrRTUtil.dll] [N/A, N/A]
[C:\Program Files\WinPoET Broadband Connection\WrInterfaceManager.dll] [N/A, N/A]
[C:\Program Files\WinPoET Broadband Connection\WrConfig.dll] [N/A, N/A]
[C:\Program Files\WinPoET Broadband Connection\WrNetworkDriver.dll] [N/A, N/A]
[C:\Program Files\WinPoET Broadband Connection\Wr_Mac_Frames.DLL] [N/A, N/A]
[C:\Program Files\WinPoET Broadband Connection\WrPoetDriver.DLL] [N/A, N/A]
[C:\Program Files\WinPoET Broadband Connection\WrPacketSock.dll] [N/A, N/A]
[PID: 624][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]

………………

没有问题
gototop
 

安全模式下
打开sreng (就是你扫日志的软件)“启动项目”-“服务”-“Win32服务应用程序”中点“隐藏经认证的微软项目”,
选中以下项目,点“删除服务”,再点“设置”,在弹出的框中点“否”:
cress / cress
PrTgressep / PrTgressep
重启计算机 安全模 式
双击我的电脑-工具-文件夹选项-查看-显示所有文件和文件夹,把“隐藏受保护的系统文件”的勾去掉。
然后删除C:\WINDOWS\cress.exe
C:\WINDOWS\system32\srvany.exe
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT