1234   1  /  4  页   跳转

[求助] 看下日志`中毒拉`

看下日志`中毒拉`

装了360也打开不了``不知道是中了什么病毒```请高手帮帮忙``
感激```

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)

附件附件:

文件名:SREngLOG.log
下载次数:183
文件类型:application/octet-stream
文件大小:
上传时间:2009-2-1 18:49:05
描述:log

分享到:
gototop
 

回复: 看下日志`中毒拉`

有猫癣下载器,QQPASS,GAMEOL
日志见以下异常:
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <bgswitch><C:\WINDOWS\system32\bgswitch.exe>  []   壁纸自动换软件的注册表启动项,非病毒添加
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><C:\windows\rundl132.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Startwd><rundll32.exe C:\windows\system32\wd0105.dll,Hook>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <Alcmtr><anymie360.exe>  []
    <qq><C:\windows\TEMP\428796.txt>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><fhofeodb.dll>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Windows Component Publisher]  这个可是正儿八经的正常注册表项啊
    <{3891567A-57D1-40E2-B080-F9C5E7ED4D86}><C:\windows\system32\jophlmna.dll>  []
    <{5A041F13-A111-12A4-B0CF-F99818AA68A5}><C:\windows\system32\ar12A401dll.dll>  []
    <{1566BA11-A899-408F-BFD3-0DFCAC9ADBCC}><C:\windows\system32\hlmmbahh.dll>  []
    <{97428C00-9F29-40F7-808A-B51CA06C0CBA}><C:\windows\system32\pnkiocgg.dll>  []
    <{A654F3CB-E34C-480B-835A-40804127320F}><C:\windows\system32\amlkfjcb.dll>  []
    <{26B77012-D930-431D-A2C6-C087B7647C88}><C:\windows\system32\imbnnghi.dll>  []
    <{16E23300-43C6-41CA-87DE-F271C3C082F1}><C:\windows\system32\hmeijjgg.dll>  []
    <{773A1048-341B-469C-9771-272B8EB32F7F}><C:\windows\system32\nnjahgko.dll>  []
    <{D09AC869-F932-46FA-89B1-7097D3983FE3}><C:\windows\system32\dgpacomp.dll>  []
    <{6538CD8F-076A-4196-BD52-CCBE203DA748}><C:\windows\system32\mljocdof.dll>  []
    <{D7CAEE38-D46E-4708-B4F5-FC570033D891}><C:\windows\system32\dncaeejo.dll>  []
    <{F18FE8DB-03DA-4BA9-9AEB-0DD2FD18FF2D}><C:\windows\system32\fhofeodb.dll>  []
    <{18BEC266-AFE9-4A43-8442-D842B1D8A2B1}><C:\windows\system32\hobecimm.dll>  []
    <{58180AAE-C86D-4FB5-8A9B-4F9F23A504C6}><C:\windows\system32\lohogaae.dll>  []
    <{E52BCE9B-21E4-4A94-8951-BEC498F831DE}><C:\windows\system32\elibcepb.dll>  []
    <{FE5DAB53-7D2A-4CC6-AE2E-F85DDB012430}><C:\windows\system32\feldablj.dll>  []
    <{D94B22C9-7CA6-4FC7-BE64-52B968F1B84F}><C:\Program Files\Internet Explorer\JoooNt8.Jzx>  []
    <{CE4C52D6-96D0-49FE-A071-24C8FC35B821}><C:\windows\system32\cekclidm.dll>  []
    <{478932A2-862F-4A34-A264-54A6EB998FDE}><C:\Program Files\Internet Explorer\PowerNt.Onz>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <3891567A><C:\windows\system32\jophlmna.dll>  []
    <1566BA11><C:\windows\system32\hlmmbahh.dll>  []
    <97428C00><C:\windows\system32\pnkiocgg.dll>  []
    <A654F3CB><C:\windows\system32\amlkfjcb.dll>  []
    <26B77012><C:\windows\system32\imbnnghi.dll>  []
    <16E23300><C:\windows\system32\hmeijjgg.dll>  []
    <773A1048><C:\windows\system32\nnjahgko.dll>  []
    <D09AC869><C:\windows\system32\dgpacomp.dll>  []
    <6538CD8F><C:\windows\system32\mljocdof.dll>  []
    <D7CAEE38><C:\windows\system32\dncaeejo.dll>  []
    <F18FE8DB><C:\windows\system32\fhofeodb.dll>  []
    <18BEC266><C:\windows\system32\hobecimm.dll>  []
    <58180AAE><C:\windows\system32\lohogaae.dll>  []
    <E52BCE9B><C:\windows\system32\elibcepb.dll>  []
    <FE5DAB53><C:\windows\system32\feldablj.dll>  []
    <CE4C52D6><C:\windows\system32\cekclidm.dll>  []
驱动程序

[Safe Mon 360 / SafeMon0][Running/System Start]
  <\??\C:\windows\system32\724A1196.dat><N/A>
运行的威胁
    [c:\windows\system32\rpcss.dll]  [N/A, ]
    [C:\windows\system32\anymie360.dll]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNt.Onz]  [N/A, ]
    [C:\Program Files\Internet Explorer\JoooNt8.Jzx]  [N/A, ]
    [C:\DOCUME~1\www\LOCALS~1\Temp\WowInitcode.dat]  [N/A, ]
建议看置顶帖
最后编辑超级游戏迷 最后编辑于 2009-02-01 19:19:06
gototop
 

回复:看下日志`中毒拉`

很急啊```各位同志们``麻烦你们了``````
gototop
 

回复: 看下日志`中毒拉`

中毒很深,发现:

1、存在威金病毒的注册表启动项;

2、APPINIT_DLLS、ShellExecuteHooks注册表项下有大量木马注册表启动项,怀疑与当前的ups10.dll病毒有关;有大量IFEO劫持项,安全工具和杀软等基本都被劫持了;

3、系统文件c:\windows\system32\rpcss.dll被病毒替换(复制粘贴应该挂掉了);

4、没安装杀毒软件和防火墙(360的防毒能力太弱,根本不能取代杀软和防火墙),否则根本不可能这么惨……
打酱油的……
gototop
 

回复: 看下日志`中毒拉`

补充2楼:

一、
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\windows\system32\ctfmon.exe>  [(Infected) Microsoft Corporation
系统输入法进程被病毒感染。
二、
服务
[Application Management / AppMgmt][Stopped/Manual Start]
  <C:\windows\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[DCOM Server Process Launcher / DcomLaunch][Running/Auto Start]
  <C:\windows\system32\svchost -k DcomLaunch-->%SystemRoot%\system32\rpcss.dll><N/A>
[Remote Procedure Call (RPC) / RpcSs][Running/Auto Start]
  <C:\windows\system32\svchost -k rpcss-->%SystemRoot%\system32\rpcss.dll><N/A>
[Task Scheduler / Schedule][Stopped/Disabled]
  <C:\windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\system32\schedsvc.dll><N/A>
[System Restore Service / srservice][Running/Auto Start]
  <C:\windows\system32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\srsvc.dll><N/A>
[Windows Image Acquisition (WIA) / stisvc][Stopped/Disabled]
  <C:\windows\system32\svchost.exe -k imgsvc-->%SystemRoot%\system32\wiaservc.dll><N/A>
[Windows Time / W32Time][Running/Auto Start]
  <C:\windows\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\w32time.dll><N/A>
以上系统服务进程对应的映像文件(dll文件)和服务注册表项可能均已被病毒替换。

三、
驱动程序
[NsDlRK250 / NsDlRK250][Running/Manual Start]
  <\??\C:\windows\system32\Nskhelper2.sys><N/A>
[NsPsDk00 / NsPsDk00][Running/Manual Start]
  <\??\C:\windows\system32\NsPass0.sys><N/A>
[NsPsDk01 / NsPsDk01][Running/Manual Start]
  <\??\C:\windows\system32\NsPass1.sys><N/A>
[NsPsDk02 / NsPsDk02][Running/Manual Start]
  <\??\C:\windows\system32\NsPass2.sys><N/A>
[NsPsDk04 / NsPsDk04][Running/Manual Start]
  <\??\C:\windows\system32\NsPass4.sys><N/A>
[Safe Mon 360 / SafeMon0][Running/System Start]
  <\??\C:\windows\system32\724A1196.dat><N/A>
[msiffei / msiffei][Stopped/Manual Start]
  <System32\Drivers\msiffei.sys><N/A>
[npkwy / npkwy][Running/Boot Start]
  <\SystemRoot\system32\drivers\aumlu.sys><N/A>
[acpidisk / acpidisk][Running/Auto Start]
  <\??\C:\windows\system32\drivers\acpidisk.sys><N/A>
[io / io][Running/]
  <2 - 系统找不到指定的文件。
><N/A>
一个感染性下载器病毒添加的多个驱动程序,还有还原SSDT表使杀软监控失效的NB病毒驱动,以及一些其它病毒驱动。

四、
浏览器加载项
[Info cache]
  {296AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\windows\Intel\baiduc.dll, Syons.Fae>
[]
  {478932A2-862F-4A34-A264-54A6EB998FDE} <C:\Program Files\Internet Explorer\PowerNt.Onz, N/A>
[]
  {5A041F13-A111-12A4-B0CF-F99818AA68A5} <C:\windows\system32\ar12A401dll.dll, N/A>
[]
  {D94B22C9-7CA6-4FC7-BE64-52B968F1B84F} <C:\Program Files\Internet Explorer\JoooNt8.Jzx, N/A>
[Info cache]
  {296AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\windows\Intel\baiduc.dll, Syons.Fae>
[]
  {478932A2-862F-4A34-A264-54A6EB998FDE} <C:\Program Files\Internet Explorer\PowerNt.Onz, N/A>
[]
  {5A041F13-A111-12A4-B0CF-F99818AA68A5} <C:\windows\system32\ar12A401dll.dll, N/A>
[]
  {D94B22C9-7CA6-4FC7-BE64-52B968F1B84F} <C:\Program Files\Internet Explorer\JoooNt8.Jzx, N/A>
病毒添加的BHO……

五、
正在运行的进程
[PID: 556 / SYSTEM][\??\C:\windows\system32\winlogon.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\windows\system32\winlib .dll]  [N/A, ]
[PID: 784 / SYSTEM][C:\windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [c:\windows\system32\rpcss.dll]  [N/A, ]
    [C:\windows\system32\anymie360.dll]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNt.Onz]  [N/A, ]
    [C:\Program Files\Internet Explorer\JoooNt8.Jzx]  [N/A, ]
    [C:\DOCUME~1\www\LOCALS~1\Temp\WowInitcode.dat]  [N/A, ]

[PID: 860 / NETWORK SERVICE][C:\windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [c:\windows\system32\rpcss.dll]  [N/A, ]
[PID: 904 / SYSTEM][C:\windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [c:\windows\system32\w32time.dll]  [N/A, ]
    [c:\windows\system32\srsvc.dll]  [N/A, ]

[PID: 1744 / www][C:\windows\system32\Ati2evxx.exe]  [, ]
    [C:\Program Files\Internet Explorer\JoooNt8.Jzx]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNt.Onz]  [N/A, ]
[PID: 436 / www][C:\windows\system32\Shadow\ShadowTip.exe]  [PowerShadow, 1, 0, 0, 1]
    [C:\Program Files\Internet Explorer\JoooNt8.Jzx]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNt.Onz]  [N/A, ]
    [C:\DOCUME~1\www\LOCALS~1\Temp\WowInitcode.dat]  [N/A, ]

[PID: 444 / www][C:\windows\system32\conime.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Internet Explorer\JoooNt8.Jzx]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNt.Onz]  [N/A, ]

[PID: 476 / www][C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe]  [ATI Technologies, Inc., 6.14.10.5113]
    [C:\Program Files\Internet Explorer\JoooNt8.Jzx]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNt.Onz]  [N/A, ]
    [C:\DOCUME~1\www\LOCALS~1\Temp\WowInitcode.dat]  [N/A, ]

[PID: 508 / www][C:\Program Files\D-Tools\daemon.exe]  [DAEMON'S HOME, 3.47.0.0]
    [C:\Program Files\Internet Explorer\JoooNt8.Jzx]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNt.Onz]  [N/A, ]
[PID: 512 / www][C:\windows\system32\ctfmon.exe]  [(Infected) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[PID: 2460 / www][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\windows\system32\cbhclajf.dll]  [N/A, ]
    [C:\windows\system32\jophlmna.dll]  [N/A, ]
    [C:\windows\system32\bnifahhi.dll]  [N/A, ]
    [C:\windows\system32\hlmmbahh.dll]  [N/A, ]
    [C:\windows\Intel\baiduc.dll]  [Syons.Fae, 2. 3, 0, 2]
    [C:\Program Files\Internet Explorer\JoooNt8.Jzx]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNt.Onz]  [N/A, ]
    [C:\windows\system32\cekclidm.dll]  [N/A, ]
    [C:\windows\system32\feldablj.dll]  [N/A, ]
    [C:\windows\system32\elibcepb.dll]  [N/A, ]
    [C:\windows\system32\lohogaae.dll]  [N/A, ]
    [C:\windows\system32\hobecimm.dll]  [N/A, ]
    [C:\windows\system32\fhofeodb.dll]  [N/A, ]
    [C:\windows\system32\dncaeejo.dll]  [N/A, ]
    [C:\windows\system32\mljocdof.dll]  [N/A, ]
    [C:\windows\system32\dgpacomp.dll]  [N/A, ]
    [C:\windows\system32\hmeijjgg.dll]  [N/A, ]
    [C:\windows\system32\imbnnghi.dll]  [N/A, ]
    [C:\windows\system32\amlkfjcb.dll]  [N/A, ]
    [C:\windows\system32\pnkiocgg.dll]  [N/A, ]
    [C:\DOCUME~1\www\LOCALS~1\Temp\WowInitcode.dat]  [N/A, ]
[PID: 672 / www][C:\windows\explorer.exe]  [(Verified) Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Internet Explorer\PowerNt.Onz]  [N/A, ]
    [C:\windows\system32\ar12A401dll.dll]  [N/A, ]
    [C:\Program Files\Internet Explorer\JoooNt8.Jzx]  [N/A, ]
    [C:\windows\system32\jophlmna.dll]  [N/A, ]
    [C:\windows\system32\hlmmbahh.dll]  [N/A, ]
    [C:\windows\system32\pnkiocgg.dll]  [N/A, ]
    [C:\windows\system32\amlkfjcb.dll]  [N/A, ]
    [C:\windows\system32\imbnnghi.dll]  [N/A, ]
    [C:\windows\system32\hmeijjgg.dll]  [N/A, ]
    [C:\windows\system32\nnjahgko.dll]  [N/A, ]
    [C:\windows\system32\dgpacomp.dll]  [N/A, ]
    [C:\windows\system32\mljocdof.dll]  [N/A, ]
    [C:\windows\system32\dncaeejo.dll]  [N/A, ]
    [C:\windows\system32\fhofeodb.dll]  [N/A, ]
    [C:\windows\system32\hobecimm.dll]  [N/A, ]
    [C:\windows\system32\lohogaae.dll]  [N/A, ]
    [C:\windows\system32\elibcepb.dll]  [N/A, ]
    [C:\windows\system32\feldablj.dll]  [N/A, ]
    [C:\windows\system32\cekclidm.dll]  [N/A, ]

[PID: 1880 / www][D:\Process Explorer\procexp.exe]  [汉化: 余飞雨, 10.2  汉化: 余飞雨]
    [D:\Process Explorer\USP10.dll]  [Microsoft Corporation, 1.0420.2600.5512 (xpsp.080413-2105)]
    [C:\windows\system32\fhofeodb.dll]  [N/A, ]

[PID: 2572 / www][C:\Program Files\Tencent\QQ\TXPlatform.exe]  [Tencent, 1, 0, 170, 0]
    [C:\Program Files\Tencent\QQ\PSAPI.DLL]  [N/A, ]
    [C:\windows\system32\fhofeodb.dll]  [N/A, ]
    [C:\Program Files\Internet Explorer\JoooNt8.Jzx]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNt.Onz]  [N/A, ]

[PID: 3204 / www][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\windows\system32\hlmmbahh.dll]  [N/A, ]
    [C:\Program Files\Internet Explorer\JoooNt8.Jzx]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNt.Onz]  [N/A, ]
    [C:\windows\Intel\baiduc.dll]  [Syons.Fae, 2. 3, 0, 2]
    [C:\windows\system32\cekclidm.dll]  [N/A, ]
    [C:\windows\system32\feldablj.dll]  [N/A, ]
    [C:\windows\system32\elibcepb.dll]  [N/A, ]
    [C:\windows\system32\lohogaae.dll]  [N/A, ]
    [C:\windows\system32\hobecimm.dll]  [N/A, ]
    [C:\windows\system32\fhofeodb.dll]  [N/A, ]
    [C:\windows\system32\dncaeejo.dll]  [N/A, ]
    [C:\windows\system32\mljocdof.dll]  [N/A, ]
    [C:\windows\system32\dgpacomp.dll]  [N/A, ]
    [C:\windows\system32\hmeijjgg.dll]  [N/A, ]
    [C:\windows\system32\imbnnghi.dll]  [N/A, ]
    [C:\windows\system32\amlkfjcb.dll]  [N/A, ]
    [C:\windows\system32\pnkiocgg.dll]  [N/A, ]
    [C:\windows\system32\jophlmna.dll]  [N/A, ]
    [C:\DOCUME~1\www\LOCALS~1\Temp\WowInitcode.dat]  [N/A, ]

[PID: 720 / www][F:\sreng2\SREngLdr.EXE]  [Smallfrogs Studio, 2.7.0.1210]
    [F:\sreng2\USP10.dll]  [Microsoft Corporation, 1.0420.2600.5512 (xpsp.080413-2105)]
[PID: 2476 / www][C:\DOCUME~1\www\LOCALS~1\Temp\742192]  [, 1, 0, 0, 1]
    [C:\windows\system32\hmeijjgg.dll]  [N/A, ]
    [C:\Program Files\Internet Explorer\JoooNt8.Jzx]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNt.Onz]  [N/A, ]
    [C:\DOCUME~1\www\LOCALS~1\Temp\WowInitcode.dat]  [N/A, ]

[PID: 3836 / www][F:\sreng2\SRE903a8a6a.EXE]  [Smallfrogs Studio, 2.7.0.1210]
    [F:\sreng2\USP10.dll]  [Microsoft Corporation, 1.0420.2600.5512 (xpsp.080413-2105)]
    [C:\windows\system32\hmeijjgg.dll]  [N/A, ]
    [C:\Program Files\Internet Explorer\JoooNt8.Jzx]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNt.Onz]  [N/A, ]
    [C:\windows\system32\cekclidm.dll]  [N/A, ]
    [C:\windows\system32\feldablj.dll]  [N/A, ]
    [C:\windows\system32\elibcepb.dll]  [N/A, ]
    [C:\windows\system32\lohogaae.dll]  [N/A, ]
    [C:\windows\system32\hobecimm.dll]  [N/A, ]
    [C:\windows\system32\fhofeodb.dll]  [N/A, ]
    [C:\windows\system32\dncaeejo.dll]  [N/A, ]
    [C:\windows\system32\mljocdof.dll]  [N/A, ]
    [C:\windows\system32\dgpacomp.dll]  [N/A, ]
    [C:\windows\system32\imbnnghi.dll]  [N/A, ]
    [C:\windows\system32\amlkfjcb.dll]  [N/A, ]
    [C:\windows\system32\pnkiocgg.dll]  [N/A, ]
    [C:\windows\system32\hlmmbahh.dll]  [N/A, ]
    [C:\windows\system32\jophlmna.dll]  [N/A, ]
    [C:\DOCUME~1\www\LOCALS~1\Temp\WowInitcode.dat]  [N/A, ]
一群病毒(红色)……

六、
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 2476, C:\DOCUME~1\WWW\LOCALS~1\TEMP\742192]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2476, C:\DOCUME~1\WWW\LOCALS~1\TEMP\742192]
以上两个病毒进程……
打酱油的……
gototop
 

回复:看下日志`中毒拉`

``````怎么个说法??怎样才能清楚掉??
gototop
 

回复: 看下日志`中毒拉`

建议用安装光盘启动电脑,将全盘格式化后重装系统(病毒可能感染了非系统分区的可执行文件,并在正常应用程序安装目录下释放DLL文件监视应用程序运行,手工清理实在太麻烦了)……
打酱油的……
gototop
 

回复:看下日志`中毒拉`

````全盘??我的天`````
求助 手工杀毒```大哥````帮帮我``   
多麻烦也不怕```
gototop
 

回复: 看下日志`中毒拉`



引用:
原帖由 youarepig 于 2009-2-1 19:52:00 发表
````全盘??我的天`````
求助 手工杀毒```大哥````帮帮我``   
多麻烦也不怕``` 
对以下感染型下载器病毒所造成的危害,可能导致除系统分区外所有分区下的应用程序的可执行文件都被感染,被感染的文件是否能恢复很难说,我没有一定能修复的把握。如果被感染的文件只能强制删除,那基本所有应用软件都要重装,和全盘格掉重装系统耗费的时间差不多,而且使用后者的话,比前者弄得更干净更保险……
[NsDlRK250 / NsDlRK250][Running/Manual Start]
  <\??\C:\windows\system32\Nskhelper2.sys><N/A>
[NsPsDk00 / NsPsDk00][Running/Manual Start]
  <\??\C:\windows\system32\NsPass0.sys><N/A>
[NsPsDk01 / NsPsDk01][Running/Manual Start]
  <\??\C:\windows\system32\NsPass1.sys><N/A>
[NsPsDk02 / NsPsDk02][Running/Manual Start]
  <\??\C:\windows\system32\NsPass2.sys><N/A>
[NsPsDk04 / NsPsDk04][Running/Manual Start]
  <\??\C:\windows\system32\NsPass4.sys><N/A>


可以等其他高手给出完全修复的步骤,我没有把握……

吃一堑长一智,以后别再用360取代杀软和防火墙了,会死人的……
最后编辑超级游戏迷 最后编辑于 2009-02-01 20:06:30
打酱油的……
gototop
 

回复:看下日志`中毒拉`

感染型病毒?LZ发个样本上来看下
gototop
 
1234   1  /  4  页   跳转
页面顶部
Powered by Discuz!NT