瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 谁来帮帮我,谢谢各位大哥大姐了.

123   1  /  3  页   跳转

谁来帮帮我,谢谢各位大哥大姐了.

谁来帮帮我,谢谢各位大哥大姐了.

这两天电脑也不知道怎么了,特被的慢.毒我都杀了好多便了,可每次杀都有,还每次都会有新的病毒.我都快疯掉了.今天开机还是这样,我是真一点都不懂.大家帮我看看,谢谢各位了.对了,今天开机,音响还没有声了,是不是音频的驱动被感染了啊?

附件附件:

下载次数:330
文件类型:application/octet-stream
文件大小:
上传时间:2006-11-15 16:34:34
描述:



最后编辑2006-11-15 19:07:17
分享到:
gototop
 

咋没人回我贴呢,各位帮帮忙啦,兄弟这里先谢过了.
gototop
 

清空IE临时文件夹!就能删除需解压的病毒!
如果还不行就到http://free5.ys168.com/?jxsbb
下载HijackThis1[1].99.1.rar 0.2MB 系统扫描工具或sreng2.zip 0.4MB 系统扫描工具,解压,打开,运行,执行扫描,保存日志,将日志内容贴上来,注意不要改动,一次贴不完,分多次贴!
gototop
 

是不是有未知的病毒 或者 有个病原体
gototop
 

谢谢啦,俺这就去.
gototop
 

应该是某种病毒不能被彻底杀掉而感染的吧
gototop
 

没遇到过这样的
gototop
 

引用:
【上帝的笑的贴子】是不是有未知的病毒 或者 有个病原体
………………

生物?`````请上传日志``如果能找到病毒路径 解压后删除``````
gototop
 

2006-11-15,17:51:04

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <TOSCDSPD><C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe>  [TOSHIBA]
    <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <00THotkey><C:\WINDOWS\system32\00THotkey.exe>  [东芝公司]
    <000StTHK><000StTHK.exe>  [N/A]
    <IgfxTray><C:\WINDOWS\system32\igfxtray.exe>  [(Verified)Intel Corporation]
    <HotKeysCmds><C:\WINDOWS\system32\hkcmd.exe>  [(Verified)Intel Corporation]
    <SynTPLpr><C:\Program Files\Synaptics\SynTP\SynTPLpr.exe>  [(Verified)Synaptics, Inc.]
    <SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe>  [(Verified)Synaptics, Inc.]
    <TouchED><C:\Program Files\TOSHIBA\TouchED\TouchED.Exe>  [东芝公司]
    <TFNF5><TFNF5.exe>  [TOSHIBA Corp.]
    <TPSMain><TPSMain.exe>  [TOSHIBA Corporation]
    <TPSODDCtl><TPSODDCtl.exe>  [TOSHIBA Corporation]
    <TFncKy><TFncKy.exe>  [N/A]
    <TMESRV.EXE><C:\Program Files\TOSHIBA\TME3\TMESRV31.EXE /Logon>  [东芝]
    <TMERzCtl.EXE><C:\Program Files\TOSHIBA\TME3\TMERzCtl.EXE /Service>  [TOSHIBA]
    <SmoothView><C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe>  [TOSHIBA Corporation]
    <dla><C:\WINDOWS\system32\dla\tfswctrl.exe>  [Sonic Solutions]
    <TosHKCW.exe><"C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe">  [TOSHIBA CORPORATION]
    <NDSTray.exe><NDSTray.exe>  [N/A]
    <AGRSMMSG><AGRSMMSG.exe>  [Agere Systems]
    <ThpSrv><c:\WINDOWS\system32\thpsrv /logon>  [N/A]
    <IMEKRMIG6.1><C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE>  [(Verified)Microsoft Corporation]
    <MSPY2002><C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC>  [(Verified)N/A]
    <ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe">  [(Verified)Symantec Corporation]
    <DAEMON Tools-2052><"C:\Program Files\D-Tools\daemon.exe"  -lang 2052>  [DAEMON'S HOME]
    <stup.exe><C:\PROGRA~1\TENCENT\Adplus\stup.exe>  [Tencent]
    <YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>  [Yahoo! China]
    <yassistse><"C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">  [Yahoo! China]
    <CdnCtr><C:\Program Files\CNNIC\Cdn\cdnup.exe>  [N/A]
    <Thunder><"C:\Program Files\Thunder Network\Thunder\Thunder.exe" /s>  [Thunder Networking Technologies,LTD]
    <Symantec NetDriver Monitor><C:\PROGRA~1\SYMNET~1\SNDMon.exe>  [(Verified)Symantec Corporation]
    <CFSServ.exe><CFSServ.exe -NoClient>  [N/A]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  [N/A]
    <Desktop><C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <DTService><rundll32.exe C:\WINDOWS\system32\drivers\soundmix.dll,Load>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{E568441B-9EF3-49F8-9A67-4141AC41ADD4}><C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll>  [Yahoo! China]
    <{4BAB150F-DD97-476D-9C1E-41B6CDC0CA7A}><C:\PROGRA~1\Yahoo!\Assistant\yClickOn.dll>  [YAHOO Corporation Limited]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <webwork><C:\WINDOWS\webwork\webwork.dll>  [N/A]
gototop
 

==================================
启动文件夹
[RAMASST]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\RAMASST.lnk --> C:\WINDOWS\system32\RAMASST.exe [Matsushita Electric Industrial Co., Ltd.]><N>
[腾讯QQ]
  <C:\Documents and Settings\aa\「开始」菜单\程序\启动\腾讯QQ.lnk --> D:\QQ\QQ.exe [TENCENT]><N>

==================================
服务
[ASP.NET State Service / aspnet_state]
  <C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Symantec Event Manager / ccEvtMgr]
  <"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc]
  <"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr]
  <"C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[ConfigFree Service / CFSvcs]
  <C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe><TOSHIBA CORPORATION>
[DVD-RAM_Service / DVD-RAM_Service]
  <C:\WINDOWS\system32\DVDRAMSV.exe><Matsushita Electric Industrial Co., Ltd.>
[Human Interface Device Access / HidServ]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[JMediaService / JMediaService]
  <C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\MMSASS~1\MMSSVER.DLL,Service><Microsoft Corporation>
[KSD2Service / KSD2Service]
  <2 - 系统找不到指定的文件。
><N/A>
[Security Machine Manager / MOVEESS]
  <C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE C:\WINDOWS\SYSTEM32\WBEM\OGYYMQ00.DLL,Export 1087><Microsoft Corporation>
[Norton AntiVirus Auto Protect Service / navapsvc]
  <"C:\Program Files\Norton AntiVirus\navapsvc.exe"><Symantec Corporation>
[Indexing Manager / NtStub]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\afcjfz32.dll><Microsoft Corporation>
[PC Back Servers / PCBackServers]
  <C:\WINDOWS\system32\877232pro.exe><N/A>
[SAVScan / SAVScan]
  <"C:\Program Files\Norton AntiVirus\SAVScan.exe"><Symantec Corporation>
[ScriptBlocking Service / SBService]
  <C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe><Symantec Corporation>
[Servicel / Servicel]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\jetspeed.dll><>
[Symantec Network Drivers Service / SNDSrvc]
  <"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Standard Update Net Service / stdupnet]
  <C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\stdupnet.dll,Service -s><Microsoft Corporation>
[SymWMI Service / SymWSC]
  <"C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe"><Symantec Corporation>
[TOSHIBA HDD Protection  / Thpsrv]
  <C:\WINDOWS\system32\ThpSrv.exe><TOSHIBA Corporation>
[Tmesrv3 / Tmesrv]
  <"C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe" /Service><东芝>

==================================
驱动程序
[00001287 / 00001287]
  <\SystemRoot\system32\drivers\00001287.SYS><N/A>
[ADProt / ADProt]
  <\SystemRoot\system32\drivers\ADProt.sys><N/A>
[TOSHIBA V92 Software Modem / AgereSoftModem]
  <system32\DRIVERS\AGRSM.sys><Agere Systems>
[cdnprot / cdnprot]
  <\SystemRoot\system32\drivers\cdnprot.sys><中国互联网络信息中心(CNNIC)>
[cdntran / cdntran]
  <system32\drivers\cdntran.sys><CNNIC>
[d347bus / d347bus]
  <\SystemRoot\system32\DRIVERS\d347bus.sys><>
[d347prt / d347prt]
  <\SystemRoot\System32\Drivers\d347prt.sys><>
[drvmcdb / drvmcdb]
  <\SystemRoot\system32\drivers\drvmcdb.sys><Sonic Solutions>
[drvnddm / drvnddm]
  <system32\drivers\drvnddm.sys><Sonic Solutions>
[Intel(R) PRO Adapter Driver / E100B]
  <system32\DRIVERS\e100b325.sys><Intel Corporation>
[ialm / ialm]
  <system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[idajfbbg / idajfbbg]
  <\??\C:\WINDOWS\system32\drivers\idajfbbg.sys><中国互联网络信息中心(CNNIC)>
[meiudf / meiudf]
  <System32\Drivers\meiudf.sys><Matsushita Electric Industrial Co.,Ltd.>
[NAVENG / NAVENG]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061108.024\NAVENG.Sys><Symantec Corporation>
[NAVEX15 / NAVEX15]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061108.024\NavEx15.Sys><Symantec Corporation>
[TOSHIBA Network Device Usermode I/O Protocol / Netdevio]
  <system32\DRIVERS\netdevio.sys><TOSHIBA Corporation.>
[npkycryp / npkycryp]
  <\??\D:\QQ\npkycryp.sys><N/A>
[oreans32 / oreans32]
  <\??\C:\WINDOWS\system32\drivers\oreans32.sys><N/A>
[paraudio / paraudio]
  <2 - 系统找不到指定的文件。
><N/A>
[pneupbzr / pneupbzr]
  <\SystemRoot\system32\drivers\pneupbzr.sys><>
[StarForce Protection Environment Driver v6 / prodrv06]
  <\SystemRoot\System32\drivers\prodrv06.sys><Protection Technology>
[StarForce Protection Helper Driver v2 / prohlp02]
  <\SystemRoot\System32\drivers\prohlp02.sys><Protection Technology>
[StarForce Protection Synchronization Driver v1 / prosync1]
  <\SystemRoot\System32\drivers\prosync1.sys><Protection Technology>
[Direct Parallel Link Driver / Ptilink]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20]
  <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[SAVRT / SAVRT]
  <\??\C:\Program Files\Norton AntiVirus\SAVRT.SYS><Symantec Corporation>
[SAVRTPEL / SAVRTPEL]
  <\??\C:\Program Files\Norton AntiVirus\SAVRTPEL.SYS><Symantec Corporation>
[Secdrv / Secdrv]
  <system32\DRIVERS\secdrv.sys><N/A>
[StarForce Protection Helper Driver / sfhlp01]
  <\SystemRoot\System32\drivers\sfhlp01.sys><Protection Technology>
[SMC IrCC Miniport Device Driver / SMCIRDA]
  <system32\DRIVERS\smcirda.sys><SMC>
[sscdbhk5 / sscdbhk5]
  <system32\drivers\sscdbhk5.sys><Sonic Solutions>
[ssrtln / ssrtln]
  <system32\drivers\ssrtln.sys><Sonic Solutions>
[SigmaTel C-Major Audio / STAC97]
  <system32\drivers\STAC97.sys><SigmaTel, Inc.>
[SymEvent / SymEvent]
  <\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV]
  <\SystemRoot\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI]
  <\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[Synaptics TouchPad Driver / SynTP]
  <system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[szdwqa2 / szdwqa24]
  <\SystemRoot\System32\DRIVERS\szdwqa24.sys><N/A>
[TCP/IP Protocol Driver / Tcpip]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[tfsnboio / tfsnboio]
  <system32\dla\tfsnboio.sys><Sonic Solutions>
[tfsncofs / tfsncofs]
  <system32\dla\tfsncofs.sys><Sonic Solutions>
[tfsndrct / tfsndrct]
  <system32\dla\tfsndrct.sys><Sonic Solutions>
[tfsndres / tfsndres]
  <system32\dla\tfsndres.sys><Sonic Solutions>
[tfsnifs / tfsnifs]
  <system32\dla\tfsnifs.sys><Sonic Solutions>
[tfsnopio / tfsnopio]
  <system32\dla\tfsnopio.sys><Sonic Solutions>
[tfsnpool / tfsnpool]
  <system32\dla\tfsnpool.sys><Sonic Solutions>
[tfsnudf / tfsnudf]
  <system32\dla\tfsnudf.sys><Sonic Solutions>
[tfsnudfa / tfsnudfa]
  <system32\dla\tfsnudfa.sys><Sonic Solutions>
[TOSHIBA HDD Protection Driver / Thpdrv]
  <\SystemRoot\system32\DRIVERS\thpdrv.sys><TOSHIBA Corporation>
[TOSHIBA HDD Protection - Shock Sensor Driver / Thpevm]
  <\SystemRoot\system32\DRIVERS\Thpevm.SYS><TOSHIBA Corporation>
[TMEI3E / TMEI3E]
  <System32\Drivers\TMEI3E.SYS><Toshiba Corporation>
[Bluetooth ACPI from TOSHIBA / tosrfec]
  <system32\DRIVERS\tosrfec.sys><TOSHIBA Corporation>
[TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver / TVALZ]
  <\SystemRoot\system32\DRIVERS\TVALZ.SYS><TOSHIBA Corporation>
[vncs / vncsg]
  <\SystemRoot\System32\DRIVERS\vncsg.sys><N/A>
[用于 Windows XP 的英特尔(R) PRO/无线 2200BG 网络连接驱动程序 / w29n51]
  <system32\DRIVERS\w29n51.sys><Intel? Corporation>
gototop
 
123   1  /  3  页   跳转
页面顶部
Powered by Discuz!NT