12   1  /  2  页   跳转

请问高手W32.Netsky.P@mm是什么病毒?

请问高手W32.Netsky.P@mm是什么病毒?

我的机器在运行一段时间后,反应特慢,C、D、E、F盘都被共享了。我也知道这是网络天空病毒,可是没有针对这个的杀毒软件。我该怎么办呀,请高手不吝赐教!!!
最后编辑2005-08-09 09:09:29
分享到:
gototop
 

你好,我能找到网络天空的杀毒软件并下载运行,但这个病毒没有和网上一模一样的,下载别的都不管用,这该怎么办呀??
gototop
 

是瑞星在线查毒时,我的诺盾就提示出“发现病毒W32.Netsky.P@mm”,但它只是隔离并显示成功,但下次又出来了。不用瑞星查毒,诺盾也不显示有病毒。我现在正在用瑞星在线查毒,还没有提示有病毒。
gototop
 

实在不好意思,我的水平太差,不知道如何扫日志和打安全补丁。还请几位大侠不吝相告。隔离后没几天又一样了。
gototop
 

子阳老兄,我用的是2000系统,是否也一样?还有日志如何扫呢?
gototop
 

好的,已经找到网址了。我估计琢磨到下午了,谢谢,下午见。祝你们中午有个好胃口!
gototop
 

好了,请几位高手帮忙给分析一下:
Logfile of HijackThis v1.99.1
Scan saved at 11:31:51, on 2005-8-8
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\msdtc.exe
C:\WINNT\system32\cisvc.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINNT\system32\svchost.exe
C:\KOAL\HSCAS\RESIN\bin\httpd.exe
C:\WINNT\System32\llssrv.exe
C:\KOAL\HSCAS\JDK\bin\java.exe
C:\KOAL\HSCAS\MSDE\MSSQL\Binn\sqlservr.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Foxmail\Foxmail.exe
C:\WINNT\system32\cidaemon.exe
D:\程序\TT\TTraveler.exe
C:\WINNT\regedit.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
D:\程序\Hijackthis\HijackThis.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\\WINNT\\system32\\userinit.exe,C:\WINNT\system32\spdwinw2k.exe
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\程序\QQ\QQIEHelper.dll (file missing)
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [spdwinw2k] C:\WINNT\system32\spdwinw2k.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: !搜一搜(&S) - res://C:\WINNT\DOWNLO~1\CnsMinEx.dll/1003
O8 - Extra context menu item: 使用搜狗直通车下载 - D:\程序\TSCC Codec编码器 V2.0\P4P\dl.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\程序\98\新建文件夹\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\程序\98\新建文件夹\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\程序\98\新建文件夹\SendMMS.htm
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm?pid=U_mynest_56115 (file missing)
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\程序\QQ\QQ.EXE (file missing)
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\程序\QQ\QQ.EXE (file missing)
O9 - Extra button: 搜索引擎 - {c95fe080-8f5d-11d2-a20b-00aa003c157c} - http://a.zhaol.com (file missing)
O9 - Extra 'Tools' menuitem: 搜索引擎 - {c95fe080-8f5d-11d2-a20b-00aa003c157c} - http://a.zhaol.com (file missing)
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\程序\QQ\QQIEHelper.dll (file missing)
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\程序\QQ\QQIEHelper.dll (file missing)
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: 铃声图片下载 - {6713E8D2-850A-101B-AFC0-4210102A8DA7} - http://sms.ufo2008.com (file missing) (HKCU)
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/077d9868ba7ff94f3902/netzip/RdxIE601_cn.cab
O16 - DPF: {B83FC273-3522-4CC6-92EC-75CC86678DA4} - http://download.3721.com/download/CnsMin.cab
O16 - DPF: {D0A29C6C-AA71-4423-8C4A-5998B774C448} (IEDown Class) - http://download.ourgame.com/IEDown3.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Hscas Web Server (HSCAS) - Unknown owner - C:\KOAL\HSCAS\RESIN\bin\httpd.exe" -service  "-conf"  "conf\resin.conf (file missing)
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe

gototop
 

请高手教教我
gototop
 

日志已经扫好了,请高手帮我看看,如何杀毒?非常谢谢!
gototop
 

不知道呀,是它吗,把它删掉可以吗
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT