瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】电脑中木马,这是今天扫的日志

12   2  /  2  页   跳转

【求助】电脑中木马,这是今天扫的日志

删除启动项:
<winform><C:\WINDOWS\winform.exe> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<testrun><C:\WINDOWS\testexe.exe> []
<upxdnd><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.exe> []
删除服务:
[3B7D8D8E / 3B7D8D8E][Stopped/Auto Start]
<C:\WINDOWS\system32\54FE265B.EXE -k><Microsoft Corporation>
删除驱动:
[Netgroup Packet Filter / NPF][Stopped/System Start]
<2 - 系统找不到指定的文件。
><N/A>
删除文件:
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\testdll.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\6A168E6E.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\system32\nwizAsktao.dll] [N/A, ]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\WINDOWS\system32\xunleibho_v8.dll] [, 4, 5, 1, 33]
[C:\WINDOWS\system32\6A168E6E.DLL] [Microsoft Corporation, ]
删除Autorun.inf
[C:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe
[D:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe
[E:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe
gototop
 

引用:
【姑苏残月的贴子】删除启动项:
<winform><C:\WINDOWS\winform.exe> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<testrun><C:\WINDOWS\testexe.exe> []
<upxdnd><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.exe> []
删除服务:
[3B7D8D8E / 3B7D8D8E][Stopped/Auto Start]
<C:\WINDOWS\system32\54FE265B.EXE -k><Microsoft Corporation>
删除驱动:
[Netgroup Packet Filter / NPF][Stopped/System Start]
<2 - 系统找不到指定的文件。
><N/A>
删除文件:
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\testdll.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\6A168E6E.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\system32\nwizAsktao.dll] [N/A, ]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\WINDOWS\system32\xunleibho_v8.dll] [, 4, 5, 1, 33]
[C:\WINDOWS\system32\6A168E6E.DLL] [Microsoft Corporation, ]
删除Autorun.inf
[C:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe
[D:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe
[E:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe

………………


最后删除  的那个 双击 打开硬盘去删除 有问题吗?
gototop
 

【回复“菜菜瓜瓜”的帖子】><N/A>
删除文件:
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\testdll.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\6A168E6E.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\system32\nwizAsktao.dll] [N/A, ]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\WINDOWS\system32\xunleibho_v8.dll] [, 4, 5, 1, 33]
[C:\WINDOWS\system32\6A168E6E.DLL] [Microsoft Corporation, ]
删除Autorun.inf
[C:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe
[D:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe
[E:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe

这几个文件我怎么找都找不到
gototop
 

引用:
【叹息之影的贴子】【回复“菜菜瓜瓜”的帖子】><N/A>
删除文件:
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\testdll.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\6A168E6E.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\system32\nwizAsktao.dll] [N/A, ]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\WINDOWS\system32\xunleibho_v8.dll] [, 4, 5, 1, 33]
[C:\WINDOWS\system32\6A168E6E.DLL] [Microsoft Corporation, ]
用xdelbox(http://www.i170.com/Attach/51FD704F-C0BD-41E7-B0E9-60673A888FD6 下载)删除以上文件:
使用说明:删除时复制所有要删除文件的路径,选中抑制再生,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。

删除Autorun.inf
[C:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe
[D:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe
[E:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe

先显示隐藏文件 在

用WINRAR  删除rising.exe还有Autorun.inf   
这几个文件我怎么找都找不到

………………



gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT