1   1  /  1  页   跳转

救命!!

救命!!

瑞星病毒查杀结果报告
清除病毒种类列表:
病毒: RootKit.Win32.Mnless.jz 
未清除病毒种类列表:
病毒: 未知 Windows 病毒           
MAC 地址:00:30:18:A9:60:9D
用户来源:局域网
软件版本:20.41.30


RootKit.Win32.Mnless.jz

监控全关,开机就桌面全部还原

现附上SREng的扫描报告!

拜托高手帮忙!!小妹谢谢了!!

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)

附件附件:

文件名:SREngLOG.log
下载次数:75
文件类型:application/octet-stream
文件大小:
上传时间:2008-4-29 21:57:50
描述:log

分享到:
gototop
 

回复:救命!!

下个磁碟机专杀吧。然后重新启动后在扫描日志看看
gototop
 

回复:救命!!

好!!试试!!3Q~
gototop
 

回复:救命!!

下载XDelBox1.7)删除以下文件
http://www.dodudou.com/down/index.php

C:\WINDOWS\system32\mpwdbapi.dll
C:\WINDOWS\system32\ypcqbhlp.dll
C:\WINDOWS\system32\mpmycapi.dll
C:\WINDOWS\system32\dqNNBNNB1052.dll
C:\WINDOWS\system32\dqMHXMHX1035.dll
C:\WINDOWS\system32\dqKAFKAF1068.dll
C:\WINDOWS\system32\dqDXYDXY1009.dll
C:\WINDOWS\system32\dqSADSAD1042.dll
C:\WINDOWS\system32\jfrwdh.dll
C:\WINDOWS\system32\29xz.dll
C:\Program Files\Common Files\Microsoft Shared\MSINFO\System76.Ins
C:\WINDOWS\system32\frntrn.dll
C:\WINDOWS\system32\gjjte.dll
C:\WINDOWS\system32\fxgnfx.dll
C:\WINDOWS\system32\xdfntt.dll
C:\WINDOWS\system32\hfjg.dll
C:\WINDOWS\system32\ijatnaw.dll
C:\WINDOWS\system32\bjrvm.dll
C:\WINDOWS\system32\crugd.dll
C:\WINDOWS\system32\lariytrz.dll
C:\WINDOWS\system32\kduy.dll
C:\WINDOWS\system32\sperls.dll
C:\WINDOWS\system32\dqNNBNNB1052.dll
C:\WINDOWS\system32\dqMHXMHX1035.dll
C:\WINDOWS\system32\dqKAFKAF1068.dll
C:\WINDOWS\system32\dqDXYDXY1009.dll
C:\WINDOWS\system32\dqSADSAD1042.dll
C:\WINDOWS\system32\29xz.dll
C:\WINDOWS\system32\issms32.dll
C:\Program Files\Internet Explorer\PLUGINS\WinSys16.Sys
C:\Autorun.inf
C:\MSDOS.bat
C:\WINDOWS\system32\winini.exe
C:\WINDOWS\system32\drivers\WmKillDrv.sys
C:\WINDOWS\system32\ghjdtry.dll
C:\WINDOWS\system32\dgxsrr.dll
C:\WINDOWS\system32\fdght.dll
C:\WINDOWS\system32\rgghjj.dll
C:\WINDOWS\system32\sefawe.dll
C:\WINDOWS\system32\frntrn.dll
C:\WINDOWS\system32\qrhhb.dll
C:\WINDOWS\system32\drghszd.dll
C:\WINDOWS\system32\fngn.dll
C:\WINDOWS\system32\gjjte.dll
C:\WINDOWS\system32\xgnfn.dll
C:\WINDOWS\system32\xfgnhcgfm.dll
C:\WINDOWS\system32\serger.dll
C:\WINDOWS\system32\bnxnb.dll
C:\WINDOWS\system32\fxgnfx.dll
C:\WINDOWS\system32\jzijj.dll
C:\WINDOWS\system32\xfgnfx.dll
C:\WINDOWS\system32\serghjm.dll
C:\WINDOWS\system32\thsddh.dll
C:\WINDOWS\system32\xbcvxb.dll
C:\WINDOWS\system32\zfdzb.dll
C:\WINDOWS\system32\xdndn.dll
C:\WINDOWS\system32\xdfntt.dll
C:\WINDOWS\system32\hgfhk.dll
C:\WINDOWS\system32\dnteh.dll
C:\WINDOWS\system32\xfng.dll
C:\WINDOWS\system32\njritc.dll
C:\WINDOWS\system32\chmfcmh.dll
C:\WINDOWS\system32\jwlah.dll
C:\WINDOWS\system32\gmnait.dll
C:\WINDOWS\system32\hfjg.dll
C:\WINDOWS\system32\thurh.dll
C:\WINDOWS\system32\mgmgmm.dll
C:\WINDOWS\system32\oqrthc.dll
C:\WINDOWS\system32\hktrre.dll
C:\WINDOWS\system32\jyjlt.dll
C:\WINDOWS\system32\ijatnaw.dll
C:\WINDOWS\system32\sehhter.dll
C:\WINDOWS\system32\fhjfg.dll
C:\WINDOWS\system32\zdbdb.dll
C:\WINDOWS\system32\ydgn.dll
C:\WINDOWS\system32\dbfb.dll
C:\WINDOWS\system32\fjnbv.dll
C:\WINDOWS\system32\fghshj.dll
C:\WINDOWS\system32\setrhes.dll
C:\WINDOWS\system32\cdxbfxdb.dll
C:\WINDOWS\system32\xfgnxfn.dll
C:\WINDOWS\system32\gjkhj.dll
C:\WINDOWS\system32\xdhdg.dll
C:\WINDOWS\system32\rhs.dll
C:\WINDOWS\system32\mrjhtjd.dll
C:\WINDOWS\system32\zdbfbd.dll
C:\WINDOWS\system32\fjyjy.dll
C:\WINDOWS\system32\fxnfnh.dll
C:\WINDOWS\system32\bjrvm.dll
C:\WINDOWS\system32\ektvm.dll
C:\WINDOWS\system32\rdthr.dll
C:\WINDOWS\system32\rgfjj.dll
C:\WINDOWS\system32\dscef.dll
C:\WINDOWS\system32\crugd.dll
C:\WINDOWS\system32\lariytrz.dll
C:\WINDOWS\system32\hjaiq.dll
C:\WINDOWS\system32\kduy.dll
C:\WINDOWS\system32\hkfgh.dll
C:\WINDOWS\system32\awef.dll
C:\WINDOWS\system32\dfhsh.dll
C:\WINDOWS\system32\ethsh.dll
C:\WINDOWS\system32\stehs.dll
C:\WINDOWS\system32\sthth.dll
C:\WINDOWS\system32\wfhyt.dll
C:\WINDOWS\system32\sperls.dll



启动项目--注册表--删除
    <AppInit_DLLs><ghjdtry.dll,dgxsrr.dll,fdght.dll,rgghjj.dll,sefawe.dll,frntrn.dll,qrhhb.dll,drghszd.dll,fngn.dll,gjjte.dll,xgnfn.dll,xfgnhcgfm.dll,serger.dll,bnxnb.dll,fxgnfx.dll,jzijj.dll,xfgnfx.dll,serghjm.dll,thsddh.dll,xbcvxb.dll,zfdzb.dll,xdndn.dll,xdfntt.dll,hgfhk.dll,dnteh.dll,xfng.dll,njritc.dll,chmfcmh.dll,jwlah.dll,gmnait.dll,hfjg.dll,thurh.dll,mgmgmm.dll,oqrthc.dll,hktrre.dll,jyjlt.dll,ijatnaw.dll,sehhter.dll,fhjfg.dll,zdbdb.dll,ydgn.dll,dbfb.dll,fjnbv.dll,fghshj.dll,setrhes.dll,cdxbfxdb.dll,xfgnxfn.dll,gjkhj.dll,xdhdg.dll,rhs.dll,mrjhtjd.dll,zdbfbd.dll,fjyjy.dll,fxnfnh.dll,bjrvm.dll,ektvm.dll,rdthr.dll,rgfjj.dll,dscef.dll,crugd.dll,lariytrz.dll,hjaiq.dll,kduy.dll,hkfgh.dll,awef.dll,dfhsh.dll,ethsh.dll,stehs.dll,sthth.dll,wfhyt.dll,sperls.dll,>  [N/A]
    <{25694105-5108-9405-3695-954187462152}><C:\WINDOWS\system32\mpwdbapi.dll>  [N/A]
    <{30AF1289-F140-A140-D012-C1458759FC03}><C:\WINDOWS\system32\ypcqbhlp.dll>  [N/A]
    <{3629FF4F-ACDB-5C90-A098-FACB3456A263}><C:\WINDOWS\system32\mpmycapi.dll>  [N/A]
    <{ced40adf-ad8d-49c1-8c5c-14551ca6c591}><C:\WINDOWS\system32\dqNNBNNB1052.dll>  []
    <{8ccdf465-f6db-4ba5-b338-7cb13b339a0d}><C:\WINDOWS\system32\dqMHXMHX1035.dll>  []
    <{94761188-463c-4185-b647-5a25c5652e26}><C:\WINDOWS\system32\dqKAFKAF1068.dll>  []
    <{917238cc-685a-4bed-b840-8185e894ad0c}><C:\WINDOWS\system32\dqDXYDXY1009.dll>  []
    <{d70eb86c-312a-48d5-a89f-0c1f4b75cc72}><C:\WINDOWS\system32\dqSADSAD1042.dll>  []
    <{841529CB-7F77-4B99-A895-B5441E0D302F}><C:\WINDOWS\system32\jfrwdh.dll>  [N/A]
    <{00C61FBA-BC47-4525-9B7D-4D7FBE662D57}><C:\WINDOWS\system32\29xz.dll>  []
    <{A693A5AB-BDBA-4AE7-A1C8-E41FEE1C020B}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\System76.Ins>  [N/A]
==================================
删除服务
[COM+ Windows System / WinINI][Running/Auto Start]
  <C:\WINDOWS\system32\winini.exe><Microsoft Corporation>
==================================
删除驱动程序
[WmKillDrv / WmKillDrv][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\drivers\WmKillDrv.sys><N/A>

==================================
删除浏览器加载项
[]
  {1AB1F65A-964F-4AE7-B254-05146A0E602E} <C:\Program Files\Internet Explorer\PLUGINS\WinSys16.Sys, N/A>
[]
  {25694105-5108-9405-3695-954187462152} <C:\WINDOWS\system32\mpwdbapi.dll, N/A>
[]
  {30AF1289-F140-A140-D012-C1458759FC03} <C:\WINDOWS\system32\ypcqbhlp.dll, N/A>
[]
  {3629FF4F-ACDB-5C90-A098-FACB3456A263} <C:\WINDOWS\system32\mpmycapi.dll, N/A>
[]
  {A693A5AB-BDBA-4AE7-A1C8-E41FEE1C020B} <C:\Program Files\Common Files\Microsoft Shared\MSINFO\System76.Ins, N/A>
[SrchHook Class]
  {F08555B0-9CC3-11D2-AA8E-000000000000} <C:\WINDOWS\system32\IEBHO.dll, N/A>
[]
  {1AB1F65A-964F-4AE7-B254-05146A0E602E} <C:\Program Files\Internet Explorer\PLUGINS\WinSys16.Sys, N/A>
[]
  {25694105-5108-9405-3695-954187462152} <C:\WINDOWS\system32\mpwdbapi.dll, N/A>
[]
  {30AF1289-F140-A140-D012-C1458759FC03} <C:\WINDOWS\system32\ypcqbhlp.dll, N/A>
[]
  {3629FF4F-ACDB-5C90-A098-FACB3456A263} <C:\WINDOWS\system32\mpmycapi.dll, N/A>
[]
  {A693A5AB-BDBA-4AE7-A1C8-E41FEE1C020B} <C:\Program Files\Common Files\Microsoft Shared\MSINFO\System76.Ins, N/A>
==================================
下载windows清理助手清理下
http://www.arswp.com/download.html

还有问题,再扫个日志上来
最初的诞生,只为最后的永恒....


这年头 灌个水我容易吗?
gototop
 

回复:救命!!

这个是感染型病毒

按火影的处理以后,还要更新杀软全盘杀毒,修复被感染的文件
gototop
 

回复:救命!!

学习ing
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT