12   2  /  2  页   跳转

中毒了请高手帮忙

本人是菜鸟,用瑞星杀出两个病毒提示重起计算机后删除,但是重起后还是有病毒。
gototop
 

重新扫描了一遍注册表启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
    <Super Rabbit IEPro><F:\soft\MagicSet\SRIECLI.EXE /LOAD>  [Super Rabbit Soft]
    <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <SoundMan><; SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
    <StormCodec_Helper><; "F:\soft\Storm Codec\StormSet.exe" /S /opti>  []
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  [N/A]
    <runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe>  [Beijing Rising Technology Co., Ltd.]
    <sdafdsafds><D;]XJOEPXT]ufnq]te264/fyf>  [N/A]
    <RavTask><"F:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <miniqqlive><"C:\Program Files\Tencent\QQLive\MiniQQLive.exe">  [Tencent]
    <WangWang><"F:\Program Files\淘宝网\淘宝旺旺\WangWang.EXE">  [淘宝(中国)软件有限公司]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <RavStub><"F:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
gototop
 

请高手点拨
gototop
 

请高手指点
gototop
 

安全模式下
删除服务项:
  [Distributed Console Manager / Framework][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\szdj.dll><N/A>
[Routing Protect Access / NHLscA][Stopped/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\SMTPCONFS.DLL,Export 1087><N/A>

删除驱动:
[fwpgnt8 / fwpgnt89][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\fwpgnt89.sys><N/A>
[hbwanl3 / hbwanl30][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\hbwanl30.sys><N/A>
[msqmx / msqmx][Running/Boot Start]
<\SystemRoot\system32\drivers\msqmx.sys><N/A>
[rlwd / rlwdk][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\rlwdk.sys><N/A>
删除相关文件
gototop
 

高手现身啊
gototop
 

能详细说一下吗,本人是菜鸟。
gototop
 

请详细说明如何删除本人是菜鸟
gototop
 

服务和驱动借助sreng删除,文件尝试安全模式下手动删除,不行下载冰刃进行强制删除
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT