1234   4  /  4  页   跳转

病毒autorun.inf.....



    [C:\windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Alwil Software\Avast4\aswCmnOS.dll]  [ALWIL Software, 4, 7, 824, 0]
    [C:\Program Files\Alwil Software\Avast4\aswCmnB.dll]  [ALWIL Software, 4, 7, 824, 0]
    [C:\Program Files\Alwil Software\Avast4\aswCmnS.dll]  [ALWIL Software, 4, 7, 800, 0]
    [C:\Program Files\Alwil Software\Avast4\Aavm4h.dll]  [ALWIL Software, 4, 7, 844, 0]
    [C:\Program Files\Alwil Software\Avast4\ashTask.dll]  [ALWIL Software, 4, 7, 844, 0]
    [C:\Program Files\Alwil Software\Avast4\aswAux.dll]  [ALWIL Software, 4, 6, 763, 0]
    [C:\Program Files\Alwil Software\Avast4\ChineseS\Base.dll]  [ALWIL Software, 4, 7, 800, 0]
    [C:\windows\system32\GameLink.dll]  [www.Easy2Game.com, 17, 2, 6, 8]
    [C:\Program Files\Alwil Software\Avast4\ashWsFtr.dll]  [ALWIL Software, 4, 7, 835, 0]
    [C:\Program Files\Alwil Software\Avast4\aswScan.dll]  [ALWIL Software, 4, 7, 835, 0]
    [C:\PROGRA~1\Alwil Software\Avast4\AhResWs.dll]  [ALWIL Software, 4, 7, 844, 0]
    [C:\Program Files\Alwil Software\Avast4\aswEngin.dll]  [ALWIL Software, 4, 7, 844, 0]
[PID: 596 / Administrator][F:\千千静听\TTPlayer.exe]  [Alen Soft, 5, 0, 1, 0]
    [F:\千千静听\ttpcomm.dll]  [N/A, ]
    [C:\windows\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
    [C:\Program Files\Unlocker\UnlockerHook.dll]  [N/A, ]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\CDD70814.dll]  [N/A, ]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 6, 763, 0]
    [F:\千千静听\ttpres.dll]  [Alen Soft, 5, 0, 1, 0]
    [F:\千千静听\msdmo.dll]  [Microsoft Corporation, 6.03.01.0400]
    [F:\千千静听\AddIn\ttp_asf.dll]  [N/A, ]
    [F:\千千静听\AddIn\ttp_aac.dll]  [N/A, ]
    [F:\千千静听\AddIn\ttp_ac3dts.dll]  [N/A, ]
    [F:\千千静听\wmadmod.dll]  [Microsoft Corporation, 10.00.00.3646]
    [C:\windows\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [F:\千千静听\AddIn\ttp_lrcsh.dll]  [N/A, ]
    [C:\windows\system32\GameLink.dll]  [www.Easy2Game.com, 17, 2, 6, 8]
[PID: 244 / Administrator][C:\windows\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\windows\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
    [C:\Program Files\Unlocker\UnlockerHook.dll]  [N/A, ]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\CDD70814.dll]  [N/A, ]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 6, 763, 0]
[PID: 924 / Administrator][C:\windows\system32\dwwin.exe]  [Microsoft Corporation, 10.0.5815]
    [C:\windows\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
    [C:\Program Files\Unlocker\UnlockerHook.dll]  [N/A, ]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\CDD70814.dll]  [N/A, ]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 6, 763, 0]
[PID: 752 / Administrator][F:\上网\tt\TTraveler.exe]  [Tencent, 3, 5, 299, 201]
    [C:\Program Files\Unlocker\UnlockerHook.dll]  [N/A, ]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\CDD70814.dll]  [N/A, ]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 6, 763, 0]
    [C:\windows\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
    [F:\上网\tt\Plugins\TWeather\TWeather.dll]  [, 1, 0, 0, 3]
    [F:\上网\tt\TTNetFavor.dll]  [N/A, ]
    [C:\windows\system32\GameLink.dll]  [www.Easy2Game.com, 17, 2, 6, 8]
    [C:\Program Files\Alwil Software\Avast4\AhAScr.dll]  [ALWIL Software, 4, 7, 844, 0]
    [C:\PROGRA~1\Alwil Software\Avast4\Aavm4h.dll]  [ALWIL Software, 4, 7, 844, 0]
    [C:\PROGRA~1\Alwil Software\Avast4\ashBase.dll]  [ALWIL Software, 4, 7, 844, 0]
    [C:\windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\PROGRA~1\Alwil Software\Avast4\aswCmnOS.dll]  [ALWIL Software, 4, 7, 824, 0]
    [C:\PROGRA~1\Alwil Software\Avast4\aswCmnB.dll]  [ALWIL Software, 4, 7, 824, 0]
    [C:\PROGRA~1\Alwil Software\Avast4\aswCmnS.dll]  [ALWIL Software, 4, 7, 800, 0]
    [C:\PROGRA~1\Alwil Software\Avast4\ashTask.dll]  [ALWIL Software, 4, 7, 844, 0]
    [C:\PROGRA~1\Alwil Software\Avast4\aswAux.dll]  [ALWIL Software, 4, 6, 763, 0]
    [C:\windows\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\windows\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\windows\system32\SOGOUPY.IME]  [Sohu.com Inc., 3, 0, 0, 0]
    [D:\搜狐拼音\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
[PID: 1832 / Administrator][C:\WINDOWS\123.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\CDD70814.dll]  [N/A, ]
    [C:\Program Files\Unlocker\UnlockerHook.dll]  [N/A, ]
    [C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll]  [ALWIL Software, 4, 6, 763, 0]
    [C:\windows\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2523 (xpsp.040919-1030)]
    [C:\WINDOWS\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
    [C:\windows\system32\GameLink.dll]  [www.Easy2Game.com, 17, 2, 6, 8]

==================================
文件关联
.TXT  Error. [C:\windows\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [C:\windows\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
Easy2Game-TCPChain
    C:\windows\system32\GameLink.dll(www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-UDPChain
    C:\windows\system32\GameLink.dll(www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-UDPChain
    C:\windows\system32\GameLink.dll(www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-TCPChain
    C:\windows\system32\GameLink.dll(www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-TCPFilter
    C:\windows\system32\GameLink.dll(www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-UDPFilter
    C:\windows\system32\GameLink.dll(www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-UDPFilter
    C:\windows\system32\GameLink.dll(www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-TCPFilter
    C:\windows\system32\GameLink.dll(www.Easy2Game.com, Easy2Game Service Provider)

==================================
Autorun.inf
[D:\]
[AutoRun]
open=CDD70814.exe
shell\open=打开(&O)
shell\open\Command=CDD70814.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=CDD70814.exe

==================================
HOSTS 文件
N/A

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 200, C:\PROGRAM FILES\UNLOCKER\UNLOCKERASSISTANT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 596, F:\千千静听\TTPLAYER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 752, F:\上网\TT\TTRAVELER.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

感觉主要还是这里把
Autorun.inf
[D:\]
[AutoRun]
open=CDD70814.exe
shell\open=打开(&O)
shell\open\Command=CDD70814.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=CDD70814.exe
gototop
 

感觉主要还是这里


Autorun.inf
[D:\]
[AutoRun]
open=CDD70814.exe
shell\open=打开(&O)
shell\open\Command=CDD70814.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=CDD70814.exe
gototop
 


删除下面的驱动(运行SRENG--->启动项目--->服务--->驱动程序--->选择要删除的驱动--->选择删除服务--->点击设置--->出现提示里选择否,确认删除。)
[mashqfsd / mashqfsd][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\mashqfsd.sys><N/A>
[CnsStd / CnsStd][Running/Auto Start]
<\SystemRoot\System32\drivers\CnsStd.sys><北京三七二一科技有限公司>

下载冰刃删除以下文件
http://www.ttian.net/website/2005/0829/391.html
Autorun.inf
D:\CDD70814.exe
D:\Autorun.inf
C:\windows\system32\drivers\mashqfsd.sys
C:\windows\system32\drivers\CnsStd.sys
C:\Program Files\Common Files\Microsoft Shared\MSINFO\CDD70814.dat

然后在我网盘里下载(szzl.ys168.com)
IFEO映像挟持修复工具

下载arswp(Windows清理助手)清理下
http://www.arswp.com/download/arswp/arswp.rar

然后再扫个日志上来。
gototop
 


删除下面的驱动(运行SRENG--->启动项目--->服务--->驱动程序--->选择要删除的驱动--->选择删除服务--->点击设置--->出现提示里选择否,确认删除。)
[mashqfsd / mashqfsd][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\mashqfsd.sys><N/A>
[CnsStd / CnsStd][Running/Auto Start]
<\SystemRoot\System32\drivers\CnsStd.sys><北京三七二一科技有限公司>

下载冰刃删除以下文件
http://www.ttian.net/website/2005/0829/391.html
Autorun.inf
D:\CDD70814.exe
D:\Autorun.inf
C:\windows\system32\drivers\mashqfsd.sys
C:\windows\system32\drivers\CnsStd.sys
C:\Program Files\Common Files\Microsoft Shared\MSINFO\CDD70814.dat

然后在我网盘里下载(szzl.ys168.com)
IFEO映像挟持修复工具

下载arswp(Windows清理助手)清理下
http://www.arswp.com/download/arswp/arswp.rar

然后再扫个日志上来。
gototop
 

运行SRENG  运行后  提示:没发现这个目录  也就是进不去


最新的扫描报告

附件附件:

下载次数:92
文件类型:application/octet-stream
文件大小:
上传时间:2007-7-27 17:27:12
描述:

gototop
 

你们的上传功能有问题把  我上传了
但是打不开  别的地方都可以
我在这里的15楼上传了  去下把
gototop
 

我听人说  试试usbcleaner最新的。。。好像有点作用  现在瑞星可以开启了  我现在生完级  正在杀毒
好像杀掉了:lol
有点正常的样子  我现在用最新的瑞星在杀一遍看看
在重启  上帝保有
gototop
 

我最擅长删这种病毒:
1、用记事本方式打开INF文件。
2、找来一本计算机语言辞典。
3、找到大意为“不准进入安全模式。” “不准用带有杀毒二字的软件或网页。” “不准格式化。”“不准删除。”和“和病毒主体互相保护。”这几句话,删掉它们,加入“删掉它自己和病毒主体”这个语句。(要用英文打,为保证不打错,最好参照计算机语言词典)(找不到病毒主体?看看它有没有指向哪个莫名其妙的程序,把那个程序的名称带它的后缀名复制过来就性行了。)
4、直接删掉这个INF文件和病毒主体就行了(不行的话就格盘,再不行的话就只能重装系统了)
5、删完后用杀软杀掉剩余病毒就行了。
gototop
 

用U盘病毒专杀工具,我告诉你网址要吗????????/
gototop
 
1234   4  /  4  页   跳转
页面顶部
Powered by Discuz!NT