12345   1  /  5  页   跳转

小女急请各位大哥救命啊~

小女急请各位大哥救命啊~

我电脑中了病毒,现在换了好几个杀毒软件都不能启动了,连强大的瑞星也启动了,小女子听人说这是被病毒修改了电脑的什么设置所致,
是不是注册表阿,哪位大哥大姐救救我啊!我不想重装系统。。。5555555555。。。。。
最后编辑2007-05-24 13:05:53
分享到:
gototop
 

是不是我起得太早了,各位还没起床阿 呵呵
着急啊!
gototop
 

打个哈欠!!!看看
gototop
 

下载 System Repair Engineer,
http://www.kztechs.com/sreng/download.html
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
日志一次发不完,请分次发上来
gototop
 

引用:
【303266474的贴子】下载 System Repair Engineer,
http://www.kztechs.com/sreng/download.html
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
日志一次发不完,请分次发上来
………………


一直到上述照做了,运行软件,系统提示找不到该软件
和刚一安装杀软时候问题一样,之后怎么点击也没反应。。。怎么办?
gototop
 

这是昨晚上用avg查毒的报告,目前所有杀软都不能用


+ Scan result:       



H:\Documents and Settings\gtozhouhang\Local Settings\Temporary Internet Files\Content.IE5\NK7F034V\yieacore3[1].cab/yieacore.dll/cdnaux.dll -> Adware.Cdn : Cleaned.
H:\Documents and Settings\gtozhouhang\Local Settings\Temporary Internet Files\Content.IE5\JXRHUTFY\yalliveex3[1].cab/yalliveex.dll -> Adware.Cdnup : Cleaned.
HKU\S-1-5-21-602162358-2049760794-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{38928D50-8A48-44C2-945F-D2F23F771410} -> Adware.CnsMin : Cleaned.
HKU\S-1-5-21-602162358-2049760794-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6671A431-5C3D-463D-A7CF-5587F9B7E191} -> Adware.Generic : Cleaned.
H:\Documents and Settings\gtozhouhang\Local Settings\Temporary Internet Files\Content.IE5\XNK3SPQA\yaslive[1].cab/yalive.dll/Assist\yasbar.dll/sremove.exe -> Adware.Yassist : Cleaned.
F:\TK4\Taikou4.exe -> Backdoor.Agent.aas : Cleaned.
C:\Program Files\安装程序\XP_SP2_tcpPatch.exe -> Backdoor.Hupigon : Cleaned.
E:\Program Files\PPStream\xpsp2\XPSP2Patch.exe -> Backdoor.Hupigon : Cleaned.
E:\金山毒霸终身升级版\金山毒霸2006完美升级破解补丁[7月3日]\UpCrack.EXE -> Backdoor.Hupigon : Cleaned.
E:\Program Files\Super Rabbit\MagicSet\SRRest.exe -> Backdoor.Lot.ml : Cleaned.
H:\Documents and Settings\gtozhouhang\Local Settings\Temporary Internet Files\Content.IE5\0U2OOZX3\yaskeepmain3[1].cab/yasrdd.dll -> Downloader.Baido : Cleaned.
H:\Documents and Settings\gtozhouhang\Local Settings\Temporary Internet Files\Content.IE5\0U2OOZX3\yaskeepmain3[1].cab/yasrde.exe -> Downloader.Baido : Cleaned.
E:\Warcraft III\Tools\TFTkeygen.exe -> Dropper.PT : Cleaned.
H:\Documents and Settings\gtozhouhang\Cookies\gtozhouhang@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
H:\Documents and Settings\gtozhouhang\Cookies\gtozhouhang@entrepreneur.122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
H:\Documents and Settings\gtozhouhang\Cookies\gtozhouhang@3.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
H:\Documents and Settings\gtozhouhang\Cookies\gtozhouhang@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
H:\Documents and Settings\gtozhouhang\Cookies\gtozhouhang@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
H:\Documents and Settings\gtozhouhang\Cookies\gtozhouhang@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
H:\Documents and Settings\gtozhouhang\Cookies\gtozhouhang@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Cleaned.
H:\Documents and Settings\gtozhouhang\Cookies\gtozhouhang@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
H:\KAV2006.rar/KAV2006\Update.EXE -> Trojan.Agent.yy : Cleaned.
H:\KAV2006.rar/KAV2006\н¨Îļþ¼Ð\½ðɽ¶¾°Ô\Update.EXE -> Trojan.Agent.yy : Cleaned.
H:\Documents and Settings\gtozhouhang\Local Settings\Temp\16.exe -> Trojan.OnLineGames.qh : Cleaned.
H:\WINDOWS\system32\mh100.exe -> Trojan.OnLineGames.ue : Cleaned.
H:\WINDOWS\system32\nwizqjsj.exe -> Trojan.OnLineGames.ug : Cleaned.
H:\System Volume Information\_restore{9B17A8C5-1448-4E1B-863A-5B69F2B08FC7}\RP144\snapshot\MFEX-2.DAT -> Trojan.QQPass.pf : Cleaned.
H:\System Volume Information\_restore{9B17A8C5-1448-4E1B-863A-5B69F2B08FC7}\RP144\snapshot\MFEX-3.DAT -> Trojan.QQPass.pf : Cleaned.
H:\System Volume Information\_restore{9B17A8C5-1448-4E1B-863A-5B69F2B08FC7}\RP145\snapshot\MFEX-2.DAT -> Trojan.QQPass.pf : Cleaned.
H:\System Volume Information\_restore{9B17A8C5-1448-4E1B-863A-5B69F2B08FC7}\RP145\snapshot\MFEX-3.DAT -> Trojan.QQPass.pf : Cleaned.
H:\WINDOWS\system32\nwizAsktao.exe -> Trojan.WOW.qp : Cleaned.
H:\WINDOWS\system32\nwizwmsjs.exe -> Trojan.WOW.qp : Cleaned.
H:\Documents and Settings\gtozhouhang\Local Settings\Temporary Internet Files\Content.IE5\0U2OOZX3\menu[1].js -> Worm.Fujacks.k : Cleaned.
H:\Documents and Settings\gtozhouhang\Local Settings\Temporary Internet Files\Content.IE5\0U2OOZX3\wbk9E.tmp -> Worm.Fujacks.k : Cleaned.
H:\Documents and Settings\gtozhouhang\Local Settings\Temporary Internet Files\Content.IE5\F3R0R5CM\main[1].js -> Worm.Fujacks.k : Cleaned.
H:\Documents and Settings\gtozhouhang\Local Settings\Temporary Internet Files\Content.IE5\JXRHUTFY\wbk123.tmp -> Worm.Fujacks.k : Cleaned.
H:\Documents and Settings\gtozhouhang\Local Settings\Temporary Internet Files\Content.IE5\JXRHUTFY\wbk158.tmp -> Worm.Fujacks.k : Cleaned.
H:\Documents and Settings\gtozhouhang\Local Settings\Temporary Internet Files\Content.IE5\JXRHUTFY\wbk3B0.tmp -> Worm.Fujacks.k : Cleaned.
H:\Documents and Settings\gtozhouhang\Local Settings\Temporary Internet Files\Content.IE5\JXRHUTFY\wbk419.tmp -> Worm.Fujacks.k : Cleaned.
H:\Documents and Settings\gtozhouhang\Local Settings\Temporary Internet Files\Content.IE5\JXRHUTFY\wbk422.tmp -> Worm.Fujacks.k : Cleaned.
H:\Documents and Settings\gtozhouhang\Local Settings\Temporary Internet Files\Content.IE5\XNK3SPQA\menu[3].js -> Worm.Fujacks.k : Cleaned.


虽然提示清除  可是磁盘已就不能正常打开,杀阮也不能用
对了 我电脑中的是u盘传播的

连正规杀软都干不过的病毒
一个查木马的软件没抱太大希望。。。
gototop
 

开机按F8,进入安全模式下试试.能不能扫描.

只是怀疑,打开文件时不要双击,用右键打开.

SREng.exe改个名试试.改成3.com或6.bat.
gototop
 

你好强啊!
开始扫瞄了!
是不是杀软也能这么运行?
gototop
 

[CODE]

2007-05-24,09:45:43

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><H:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
    <usbmon><; F:\USBCleaner6.0\usbmon.exe>  [zju]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <ATICCC><"H:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe">  []
    <BaiduXUpdate><; "c:\Program Files\Baidu\BaiduX\MovieUpdate.exe" --Update>  [Baidu.com, Inc.]
    <cmdbcs><H:\WINDOWS\cmdbcs.exe>  []
    <mppds><H:\WINDOWS\mppds.exe>  []
    <upxdnd><H:\DOCUME~1\GTOZHO~1\LOCALS~1\Temp\upxdnd.exe>  [N/A]
    <!AVG Anti-Spyware><"H:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized>  [Anti-Malware Development a.s.]
    <rxmoefa><H:\WINDOWS\system32\shulbhs.exe>  [N/A]
    <ShStatEXE><"H:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE>  [Network Associates, Inc.]
    <McAfeeUpdaterUI><"H:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey>  [Network Associates, Inc.]
    <Network Associates Error Reporting Service><"H:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe">  [Network Associates, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><H:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <WPDShServiceObj><H:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
    <IE7 Uninstall Stub><H:\WINDOWS\system32\ieudinit.exe>  [(Verified)Microsoft Windows Component Publisher]
gototop
 

启动文件夹
[百度下吧]
  <H:\Documents and Settings\All Users\「开始」菜单\程序\启动\百度下吧.lnk --> C:\PROGRA~1\Baidu\BaiduX\BaiduX.exe [Baidu Corporation]><H>

==================================
服务
[Application Management / AppMgmt][Stopped/Manual Start]
  <H:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
  <H:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  <H:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
  <H:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe><Anti-Malware Development a.s.>
[Kingsoft Personal Firewall Service / KPfwSvc][Stopped/Auto Start]
  <"H:\KAV2006\KPfwSvc.EXE"><N/A>
[Kingsoft Antivirus KWatch Service / KWatchSvc][Stopped/Auto Start]
  <H:\KAV2006\KWatch.EXE><N/A>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd][Stopped/Manual Start]
  <"H:\Program Files\WinPcap\rpcapd.exe" -d -f "H:\Program Files\WinPcap\rpcapd.ini"><N/A>
[Rising Process Communication Center / RsCCenter][Stopped/Auto Start]
  <"H:\Program Files\Rising\Rav\CCenter.exe"><N/A>
[Dell Wireless WLAN Tray Service / wltrysvc][Running/Auto Start]
  <H:\WINDOWS\System32\WLTRYSVC.EXE H:\WINDOWS\System32\bcmwltry.exe><N/A>
[Network Associates Task Manager / McTaskManager][Running/Auto Start]
  <"H:\Program Files\Network Associates\VirusScan\VsTskMgr.exe"><Network Associates, Inc.>
[Network Associates McShield / McShield][Running/Auto Start]
  <"H:\Program Files\Network Associates\VirusScan\Mcshield.exe"><Network Associates, Inc.>
[McAfee Framework 服务 / McAfeeFramework][Running/Auto Start]
  <H:\Program Files\Network Associates\Common Framework\FrameworkService.exe /ServiceStart><Network Associates, Inc.>
gototop
 
12345   1  /  5  页   跳转
页面顶部
Powered by Discuz!NT