瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 本人中毒的经验已经不少,网上遍寻名医,就是没有良方!

1   1  /  1  页   跳转

本人中毒的经验已经不少,网上遍寻名医,就是没有良方!

本人中毒的经验已经不少,网上遍寻名医,就是没有良方!

本人中毒的经验已经不少,网上遍寻名医,就是没有良方!请各位高手救救在下!

病历如下:

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Corporation]
    <MSNShell><C:\Program Files\MSNShell\BIN\MSNShell.exe autorun>  [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <PHIME2002ASync><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <NvCplDaemon><; RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup>  [(Verified)NVIDIA Corporation]
    <nwiz><; nwiz.exe /install>  [NVIDIA Corporation]
    <NvMediaCenter><; RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit>  [(Verified)NVIDIA Corporation]
    <HP Component Manager><; "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe">  [Hewlett-Packard Company]
    <HPDJ Taskbar Utility><; C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe>  [(Verified)HP]
    <HP Software Update><; "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe">  [Hewlett-Packard Company]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\System32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]

==================================
启动文件夹
[Microsoft Office]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk --> C:\PROGRA~1\MICROS~2\Office\OSA9.EXE [Microsoft Corporation]><H>
[Controller]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Controller.LNK --> C:\PROGRA~1\Symantec\WinFax\WFXCTL32.EXE [N/A]><N>
[快捷方式 到 timeexesoft]
  <C:\Documents and Settings\andy_ho\「开始」菜单\程序\启动\快捷方式 到 timeexesoft.lnk --> D:\系统重装\TIMEEX~1.EXE [N/A]><N>

==================================
服务
[Human Interface Device Access / HidServ]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Network System / NetSystem]
  <C:\WINDOWS\System32\NetSystem.exe><Microsoft Corporation>
[NVIDIA Display Driver Service / NVSvc]
  <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[Rising Proxy  Service / RfwProxySrv]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[QoS / service]
  <C:\WINDOWS\service><N/A>
[system23 / system23]
  <C:\WINDOWS\system23.exe><N/A>
[WinFax PRO / wfxsvc]
  <C:\WINDOWS\System32\WFXSVC.EXE><Symantec Corporation>

==================================
驱动程序
[0000_sys.sys / ]
  <\SystemRoot\system32\drivers\0000_sys.sys><>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[ADProt / ADProt]
  <\SystemRoot\system32\drivers\ADProt.sys><腾讯科技(深圳)有限公司>
[Rising TDI Base Driver / BaseTDI]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[ExpScaner / ExpScaner]
  <\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[HCF_MSFT / HCF_MSFT]
  <System32\DRIVERS\HCF_MSFT.sys><Conexant>
[HookCont / HookCont]
  <\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg]
  <\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
  <\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl]
  <\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[kmsinput / kmsinput]
  <\??\C:\WINDOWS\System32\drivers\kmsinput.sys><N/A>
[MEMSCAN / MEMSCAN]
  <\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs]
  <\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[npkcrypt / npkcrypt]
  <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv]
  <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[PCTINDIS5 NDIS Protocol Driver / PCTINDIS5]
  <\??\C:\WINDOWS\System32\PCTINDIS5.SYS><PCTEL Inc.>
[Direct Parallel Link Driver / Ptilink]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsFwDrv / RsFwDrv]
  <\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
  <System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv]
  <System32\DRIVERS\secdrv.sys><N/A>
[Sony Ericsson W550 driver (WDM) / w550bus]
  <System32\DRIVERS\w550bus.sys><MCCI>
[Sony Ericsson W550 USB WMC Modem Filter / w550mdfl]
  <System32\DRIVERS\w550mdfl.sys><MCCI>
[Sony Ericsson W550 USB WMC Modem Drivers / w550mdm]
  <System32\DRIVERS\w550mdm.sys><MCCI>
[Sony Ericsson W550 USB WMC OBEX Interface Drivers / w550obex]
  <System32\DRIVERS\w550obex.sys><MCCI>

==================================
最后编辑2006-10-23 10:20:08
分享到:
gototop
 

高手们,不要见死不救呀!就是这个了  Backdoor.Gpigeon.iug
gototop
 

如果版主看见这贴了的话,请会一下,是否有办法请回复一下,如果确实不行还是老办法了,呵呵!
gototop
 

[QoS / service]
<C:\WINDOWS\service><N/A>
[system23 / system23]
<C:\WINDOWS\system23.exe><N/A>


上面这两个服务~

及下面这个驱动~
[0000_sys.sys / ]
<\SystemRoot\system32\drivers\0000_sys.sys><>

先停止 禁用它们,再重启后删除.
gototop
 

停止或禁用,可以试试下法~

在SREng中>启动项目>服务>win32服务应用程序>隐藏微软>找到这个服务>点修改启动类型>,将它的启动类型改为disabled或manual start>修改.

在SREng中>启动项目>服务>驱动>隐藏微软>查找这个驱动~(如果有点修改启动类型>,将它的启动类型改为disabled或manual start>修改.

修改成功后,重启系统,再到上面修改它们启动类型的地方删除它们,并打开文件夹,删除它们的文件.
gototop
 

谢谢影子大侠!!果然药到病除,这网站果然高手如云呀!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT