回复: Trojan,Win32.Nodef.DL中了这个病毒,求救
原帖由 baike1985 于 2009-2-22 19:11:00 发表
救助
请新开主题帖求助,你和楼主中毒情况不同,方法不能通用。
日志异常项如下(红色不确定):
=================================
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<bf3b><rundll32 "C:\WINDOWS\Downlo~1\bf3b.dll",Run> [Microsoft Corporation]
==================================
服务
[Display Mode Automation Regulate / DMAR][Stopped/Auto Start]
<C:\Program Files\Common Files\stiles\watose.exe><N/A>[PomedEr / PomedEr][Running/Auto Start]
<C:\WINDOWS\system32\db1d.exe><Microsoft Corporation>
[OSEvent / OSEvent][Running/Auto Start]
<C:\WINDOWS\system32\t.exe><Microsoft Corporation>==================================
驱动程序
[222421 / 222421][Stopped/Manual Start]
<2 - 系统找不到指定的文件。><N/A>
[2249156 / 2249156][Stopped/]
<2 - 系统找不到指定的文件。><N/A>
==================================
浏览器加载项
[ui Class]
{16DCA182-CFB2-4A4D-9E6A-6292559688CE} <C:\WINDOWS\system32\SPORD0R.dll, N/A>
[BlkHelper Class]
{7648AC4A-76F6-4D95-B2C4-F07004015DD5} <C:\WINDOWS\system32\swrhost.dll, N/A>
==================================
正在运行的进程
[PID: 2172 / yahoo][C:\Program Files\Common Files\stiles\ctafmon.exe] [N/A, ]
[C:\Program Files\Common Files\stiles\wutels\bsetas.dll] [N/A, ]
[C:\Program Files\Common Files\stiles\wutels\sosen.dll] [N/A, ]
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 2172, C:\PROGRAM FILES\COMMON FILES\STILES\CTAFMON.EXE]
==================================
计划任务
[已启用] bf3b.job
rundll32
[已启用] bf3ac.job
rundll32
==================================