12   2  /  2  页   跳转

【求助】一開電腦又重生毒

File Associations
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
N/A

==================================
gototop
 

06-12-01 21:38SYSTEM248Sign of "Win32:Agent-CSB [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\novel.exe\[UPX]" file. 
06-12-01 21:38SYSTEM248Sign of "Win32:Adware-gen. [Adw]" has been found in "C:\DOCUME~1\Pat\LOCALS~1\Temp\1\setup.exe" file. 
06-12-01 21:38SYSTEM248Sign of "Win32:Agent-CYK [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\winampr.exe\[UPX]" file. 
06-12-01 21:39SYSTEM248Sign of "Win32:Agent-CYK [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\realupdate.exe\[UPX]" file. 
06-12-01 21:39SYSTEM248Sign of "Win32:Dialer-359 [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\POPNTR.DLL\[UPX]" file. 
06-12-01 22:09Pat200Sign of "Win32:Agent-CSB [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\novel.exe\[UPX]" file. 
06-12-01 22:10Pat200Sign of "Win32:Adware-gen. [Adw]" has been found in "C:\DOCUME~1\Pat\LOCALS~1\Temp\6\setup.exe" file. 
06-12-01 22:10Pat200Sign of "Win32:Agent-CYK [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\winampr.exe\[UPX]" file. 
06-12-01 22:10Pat200Sign of "Win32:Agent-CYK [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\realupdate.exe\[UPX]" file. 
06-12-01 22:10Pat200Sign of "Win32:Dialer-359 [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\POPNTR.DLL\[UPX]" file. 
06-12-01 23:36SYSTEM220Sign of "Win32:Agent-CSB [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\novel.exe\[UPX]" file. 
06-12-01 23:37SYSTEM220Sign of "Win32:Adware-gen. [Adw]" has been found in "C:\DOCUME~1\Pat\LOCALS~1\Temp\2\setup.exe" file. 
06-12-01 23:37SYSTEM220Sign of "Win32:Agent-CYK [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\winampr.exe\[UPX]" file. 
06-12-01 23:37SYSTEM220Sign of "Win32:Adware-gen. [Adw]" has been found in "C:\DOCUME~1\Pat\LOCALS~1\Temp\2\setup.exe" file. 
06-12-02 04:01Pat212Sign of "Win32:Agent-CSB [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\novel.exe\[UPX]" file. 
06-12-02 04:02Pat212Sign of "Win32:Adware-gen. [Adw]" has been found in "C:\DOCUME~1\Pat\LOCALS~1\Temp\1\setup.exe" file. 
06-12-02 04:02Pat212Sign of "Win32:Agent-CYK [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\winampr.exe\[UPX]" file. 
06-12-02 04:02Pat212Sign of "Win32:Agent-CYK [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\realupdate.exe\[UPX]" file. 
06-12-02 04:03Pat212Sign of "Win32:Dialer-359 [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\POPNTR.DLL\[UPX]" file. 
06-12-02 04:16Pat228Sign of "Win32:Agent-CSB [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\novel.exe\[UPX]" file. 
06-12-02 04:17Pat228Sign of "Win32:Adware-gen. [Adw]" has been found in "C:\DOCUME~1\Pat\LOCALS~1\Temp\1\setup.exe" file. 
06-12-02 04:17Pat228Sign of "Win32:Agent-CYK [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\winampr.exe\[UPX]" file. 
06-12-02 04:17Pat228Sign of "Win32:Agent-CYK [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\realupdate.exe\[UPX]" file. 
06-12-02 04:17Pat228Sign of "Win32:Dialer-359 [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\POPNTR.DLL\[UPX]" file. 
06-12-02 04:27Pat200Sign of "Win32:Agent-CSB [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\novel.exe\[UPX]" file. 
06-12-02 04:28Pat200Sign of "Win32:Adware-gen. [Adw]" has been found in "C:\DOCUME~1\Pat\LOCALS~1\Temp\1\setup.exe" file. 
06-12-02 04:43Pat212Sign of "Win32:Agent-CSB [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\novel.exe\[UPX]" file. 
06-12-02 04:44Pat212Sign of "Win32:Adware-gen. [Adw]" has been found in "C:\DOCUME~1\Pat\LOCALS~1\Temp\1\setup.exe" file. 
06-12-02 04:56Pat232Sign of "Win32:Agent-CSB [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\novel.exe\[UPX]" file. 
06-12-02 05:00Pat232Sign of "Win32:Adware-gen. [Adw]" has been found in "C:\DOCUME~1\Pat\LOCALS~1\Temp\1\setup.exe" file. 
06-12-02 05:00Pat232Sign of "Win32:Agent-CYK [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\winampr.exe\[UPX]" file. 
06-12-02 05:00Pat232Sign of "Win32:Agent-CYK [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\realupdate.exe\[UPX]" file. 
06-12-02 05:00Pat232Sign of "Win32:Dialer-359 [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\POPNTR.DLL\[UPX]" file. 
06-12-02 18:03Pat224Sign of "Win32:Agent-CSB [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\novel.exe\[UPX]" file. 
06-12-02 18:03Pat224Sign of "Win32:Agent-CYK [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\winampr.exe\[UPX]" file. 
06-12-02 18:03Pat224Sign of "Win32:Agent-CYK [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\realupdate.exe\[UPX]" file. 
06-12-02 18:03Pat224Sign of "Win32:Dialer-359 [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\POPNTR.DLL\[UPX]" file. 
06-12-02 18:03Pat224Sign of "Win32:Adware-gen. [Adw]" has been found in "C:\DOCUME~1\Pat\LOCALS~1\Temp\6\setup.exe" file. 
06-12-02 18:22Pat204Sign of "Win32:Agent-CSB [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\novel.exe\[UPX]" file. 
06-12-02 18:22Pat204Sign of "Win32:Agent-CYK [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\winampr.exe\[UPX]" file. 
06-12-02 18:22Pat204Sign of "Win32:Adware-gen. [Adw]" has been found in "C:\DOCUME~1\Pat\LOCALS~1\Temp\2\setup.exe" file. 
06-12-02 18:22Pat204Sign of "Win32:Agent-CYK [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\realupdate.exe\[UPX]" file. 
06-12-02 18:22Pat204Sign of "Win32:Dialer-359 [Trj]" has been found in "C:\WINDOWS\system32\{pchome}\.setupd\POPNTR.DLL\[UPX]" file. 
gototop
 

上面的上這幾天的找到的
我發現了我一連線上網
一會兒在WINDOWS工作管理員就看到1033跟一個SETUP173的東東
自己開動
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT