瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 帮帮小女子吧,已经被病毒折磨N天了(有日志)

12345   2  /  5  页   跳转

帮帮小女子吧,已经被病毒折磨N天了(有日志)

E:\SysAuto.exe这个不是系统文件吗?删了不会有危险吗?
gototop
 

是病毒!!
gototop
 

如果你能找到那个文件请发给我 谢谢 newcenturymoon1986@yahoo.com.cn
压缩加密123
gototop
 

这个文件上传不到我的邮箱里,说是附件不能是.exe文件
gototop
 

<svc><D:\DOCUME~1\dd\LOCALS~1\Temp\expseny.exe> [N/A]
<jwx078wu6wk3m7><D:\DOCUME~1\dd\LOCALS~1\Temp\iexplorer.exe> [N/A]
<wosa><D:\DOCUME~1\dd\LOCALS~1\Temp\woso.exe> [N/A]
<rxsa><D:\DOCUME~1\dd\LOCALS~1\Temp\rxso.exe> [N/A]
<wdsa><D:\DOCUME~1\dd\LOCALS~1\Temp\wdso.exe> [N/A]
<tlsa><D:\DOCUME~1\dd\LOCALS~1\Temp\tlso.exe> [N/A]
<dasa><D:\DOCUME~1\dd\LOCALS~1\Temp\daso.exe> [N/A]
]<Local Security Authority Service><D:\WINNT\System32\lssas.exe> [N/A]
<Advanced DHTML Enable><D:\WINNT\System32\vvbb.exe> [N/A]
<mhsa><D:\DOCUME~1\dd\LOCALS~1\Temp\mhso.exe> []
<fysa><D:\DOCUME~1\dd\LOCALS~1\Temp\fyso.exe> [N/A]
<jtsa><D:\DOCUME~1\dd\LOCALS~1\Temp\jtso.exe> [N/A]
<wlsa><D:\DOCUME~1\dd\LOCALS~1\Temp\wlso.exe> [N/A]
<wgsa><D:\DOCUME~1\dd\LOCALS~1\Temp\wgso.exe> [N/A]
<wmsa><D:\DOCUME~1\dd\LOCALS~1\Temp\wmso.exe> [N/A]
<qjsa><D:\DOCUME~1\dd\LOCALS~1\Temp\qjso.exe> [N/A]
<cmdbcs><D:\WINNT\cmdbcs.exe> []
<msccrt><D:\WINNT\msccrt.exe> []
<MSDEG32><LYLoader.exe> [N/A]
<MSDWG32><LYLoadbr.exe> [N/A]
<MSDCG32 ><LYLeador.exe> [N/A]
<MSDOG32><LYLoador.exe> [N/A]
<MSDSG32><LYLoadar.exe> [N/A]
<MSDMG32><LYLoadmr.exe> []
<MSDHG32><LYLoadhr.exe> [N/A]
<MSDQG32><LYLoadqr.exe> [N/A]
<visin><D:\WINNT\System32\visin.exe> [Microsoft Corporation]
<?{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><> [N/A]
<?{0CD68AC9-FF63-3E61-626B-B663E62F6236}><> [N/A]
<{A6011F8F-A7F8-49AA-9ADA-49127D43138F}><D:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.bmt> []
<{1496D5ED-7A09-46D0-8C92-B8E71A4304DF}><D:\WINNT\System32\msacn.dll> []
<{754FB7D8-B8FE-4810-B363-A788CD060F1F}><D:\Program Files\Internet Explorer\PLUGINS\System64.Sys> []


[Network DDC / Windowsdate][Stopped/Auto Start]
<D:\WINNT\System32\servex.exe><N/A>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
<D:\WINNT\System32\svchost.exe -k netsvcs-->D:\WINNT\System32\mspmsnsv.dll><Microsoft Corporation>
[Wireless Service / WZCSRVC][Stopped/Auto Start]
<D:\WINNT\System32\rundll32.exe netsrvcs.dll,input><Microsoft Corporation>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<D:\WINNT\System32\rundll32.exe windhcp.ocx,input><Microsoft Corporation>
[Remote Debug Service / RemoteDbg][Stopped/Auto Start]
<D:\WINNT\System32\rundll32.exe RemoteDbg.dll,input><Microsoft Corporation>
[Win32 Debug Service / MSDebugsvc][Stopped/Auto Start]
<D:\WINNT\System32\rundll32.exe msdebug.dll,input><Microsoft Corporation>


[D:\WINNT\System32\msport.dll] [N/A, ]
[D:\WINNT\System32\wscsv.dll] [N/A, ]
[D:\WINNT\System32\fksdy.dll] [N/A, ]
[D:\WINNT\System32\wgptl.dll] [N/A, ]
[D:\WINNT\System32\wtrmm.dll] [N/A, ]
[D:\WINNT\System32\hreax.dll] [N/A, ]
[D:\WINNT\System32\wfdrd.dll] [N/A, ]
[D:\WINNT\System32\zkjjx.dll] [N/A, ]
[D:\WINNT\System32\dh103.dll] [N/A, ]

这些全是病毒..
gototop
 

引用:
【大大的紫葡萄的贴子】这个文件上传不到我的邮箱里,说是附件不能是.exe文件
………………

右键 添加到压缩文件
gototop
 

唉,这么多病毒啊,看得头都晕了
gototop
 

发给你的文件是什么东西啊?
gototop
 

病毒丫
gototop
 

不是什么后门之类的吗?通过那个可以访问我电脑里的文件
gototop
 
12345   2  /  5  页   跳转
页面顶部
Powered by Discuz!NT