Casky - 2007-6-24 22:46:00
如题!跪谢!!!!
IBM①5 - 2007-6-24 22:49:00
下载 System Repair Engineer,
http://www.kztechs.com/sreng/download.html
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
如果下载后不能运行请删除已下载的,然后重新下载.下载后首先不要运行先将下载的SREng.exe重命名为SREng.com(SREng.scr\SREng.bat\SREng.pif)或者abc.exe运行.
日志一次发不完,请分次发上来
Casky - 2007-6-24 23:00:00
坍塌....
右键没有"重命名".......
Casky - 2007-6-24 23:09:00
[CODE]
2007-06-24,22:59:54
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
Casky - 2007-6-24 23:09:00
==================================
启动文件夹
N/A
==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[MPSVC Service / MPSVCService][Running/Auto Start]
<C:\Program Files\Micropoint\MPSVC.exe><Micropoint Corporation>
==================================
驱动程序
[mp110001 / mp110001][Running/Auto Start]
<system32\drivers\mp110001.sys><MicroPoint Corporation>
[mp110002 / mp110002][Running/Auto Start]
<system32\drivers\mp110002.sys><Micropoint Corporation>
[mp110003 / mp110003][Running/Boot Start]
<\SystemRoot\system32\drivers\mp110003.sys><Micropoint Corporation>
[mp110004 / mp110004][Running/Auto Start]
<system32\drivers\mp110004.sys><Micropoint Corporation>
[mp110005 / mp110005][Running/Manual Start]
<system32\drivers\mp110005.sys><Micropoint Corporation>
[mp110006 / mp110006][Running/System Start]
<system32\drivers\mp110006.sys><Micropoint Corporation>
[mp110007 / mp110007][Running/System Start]
<system32\drivers\mp110007.sys><Micropoint Corporation>
[mp110008 / mp110008][Running/Auto Start]
<system32\drivers\mp110008.sys><Micropoint Corporation>
[mp110009 / mp110009][Running/System Start]
<system32\drivers\mp110009.sys><Micropoint Corporation>
[mp110010 / mp110010][Running/Boot Start]
<\SystemRoot\system32\drivers\mp110010.sys><Micropoint Corporation>
[mp110011 / mp110011][Running/System Start]
<system32\drivers\mp110011.sys><Micropoint Corporation>
[mp110012 / mp110012][Stopped/Manual Start]
<system32\drivers\mp110012.sys><Micropoint Corporation>
[mp110013 / mp110013][Running/Boot Start]
<\SystemRoot\system32\drivers\mp110013.sys><Micropoint Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[AVG Anti-Spyware Clean Driver / AvgAsCln][Stopped/System Start]
<System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
Casky - 2007-6-24 23:10:00
==================================
浏览器加载项
[CBrowseStakeout Class]
{55302805-482E-470E-8A57-6795A1487F90} <D:\kav2005\KAVAFish.dll, Kingsoft Corporation>
[CBrowseStakeout Class]
{55302805-482E-470E-8A57-6795A1487F90} <D:\kav2005\KAVAFish.dll, Kingsoft Corporation>
[金山毒霸反钓鱼...]
<D:\kav2005\KAF\ShowSet.htm, N/A>
==================================
正在运行的进程
[PID: 452][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 500][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 524][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10034]
[PID: 568][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10034]
[PID: 580][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10034]
[PID: 736][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10034]
[PID: 1520][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10034]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[E:\豪杰译霸\tronline\GUIDLLNT.dll] [N/A, ]
[PID: 1904][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[E:\豪杰译霸\tronline\GUIDLLNT.dll] [N/A, ]
[PID: 964][E:\豪杰译霸\tronline\tronline2k.exe] [China National Computer Software & Technolgy Service Corp., 4, 0, 0, 0]
[E:\豪杰译霸\tronline\GUIDLLNT.dll] [N/A, ]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2024][E:\Maxthon\Maxthon.exe] [Maxthon International Ltd., 1, 5, 6, 39]
[E:\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10034]
[C:\WINDOWS\system32\odbcbcp.dll] [Microsoft Corporation, 2000.085.1117.00 (xpsp_sp2_rtm.040803-2158)]
[E:\豪杰译霸\tronline\GUIDLLNT.dll] [N/A, ]
[E:\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\Macromed\Flash\flash.ocx] [Adobe Systems, Inc., 9,0,16,0]
[PID: 1016][E:\AVG Anti-Spyware 7.5\avgas.exe] [Anti-Malware Development a.s., 7, 5, 0, 50]
[E:\AVG Anti-Spyware 7.5\engine.dll] [Anti-Malware Development a.s., 4, 2, 0, 15]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10034]
[E:\豪杰译霸\tronline\GUIDLLNT.dll] [N/A, ]
[PID: 1700][D:\kav2005\KAVLog2.EXE] [Kingsoft Corporation, 2007.2.2.45]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\kav2005\KAConfig.DLL] [Kingsoft Corporation, 2007, 1, 11, 41]
[E:\豪杰译霸\tronline\GUIDLLNT.dll] [N/A, ]
[PID: 2732][C:\Documents and Settings\Casky\桌面\sreng2\SREng.com.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[E:\豪杰译霸\tronline\GUIDLLNT.dll] [N/A, ]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10034]
Casky - 2007-6-25 10:02:00
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
[D:\]
[AutoRun]
open=tel.xls.exe
shellexecute=tel.xls.exe
shell\Auto\command=tel.xls.exe
shell=Auto
[VVflagRun]
aabb=kdkfjdkf
[E:\]
[AutoRun]
open=tel.xls.exe
shellexecute=tel.xls.exe
shell\Auto\command=tel.xls.exe
shell=Auto
[VVflagRun]
aabb=kdkfjdkf
[F:\]
[AutoRun]
open=tel.xls.exe
shellexecute=tel.xls.exe
shell\Auto\command=tel.xls.exe
shell=Auto
[VVflagRun]
aabb=kdkfjdkf
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
Casky - 2007-6-25 10:04:00
就是以上这些了.麻烦高人指点啊....
Casky - 2007-6-25 10:05:00
补充下。是中了中国黑客2,后来杀掉了但是那些exe还有什么htm之类的都损坏.....怎么办....哭啊
HOSTのS - 2007-6-25 10:08:00
驱动感觉很奇怪 不敢下结论
删除每个盘下的Autorun.inf
孤独更可靠 - 2007-6-25 10:15:00
| 引用: |
【Casky的贴子】补充下。是中了中国黑客2,后来杀掉了但是那些exe还有什么htm之类的都损坏.....怎么办....哭啊 ……………… |
不会是指这个吧?!:
=tel.xls.exe
Casky - 2007-6-25 10:15:00
显卡驱动和声卡驱动都没装.
因为没有驱动盘,是在网上下载的驱动.但是中毒后貌似损坏了不能用
Casky - 2007-6-25 10:19:00
杀毒后重装了系统.但是发现所有其他盘里的的基本所有exe的文件都损坏了.有没有什么可以修复的方法呢?
春天的小水竹 - 2007-6-25 10:37:00
tel.xls.exe那么怪的名字,看来非善类,删了吧,另外把D,E,F盘下的autorun.inf删了吧
Casky - 2007-6-25 10:52:00
删不掉.....
HOSTのS - 2007-6-25 10:56:00
autorun.inf删不掉? 用冰刃
langzi1314 - 2007-6-25 11:03:00
有auto专杀的
专门针对这样的顽固病毒
Casky - 2007-6-25 11:11:00
那个我对付过,没问题。可是现在就是比较郁闷的是所有的exe都损坏掉了不知道哪位大侠有修复的方法啊
春天的小水竹 - 2007-6-25 11:46:00
exe文件坏了的话貌似只有重装那些EXE文件,另一个是系统还原,但系统还原以后是不是有病毒不能保证
北纬37℃ - 2007-6-25 12:12:00
1.进入安全模式把病毒清理干净
2.运行"SFC\SCANNOW'.在光驱中放如系统光盘进行系统修复安装
Casky - 2007-6-25 12:57:00
谢谢各位高人啊
系统文件都没什么问题的,主要是安装的其他程序还有很多重要的电子书等等都不能用了。看来只好一个一个重新下载了~唉.
© 2000 - 2026 Rising Corp. Ltd.