瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】系统濒临崩溃。。极限求助。。。。杀spyware

1   1  /  1  页   跳转

【求助】系统濒临崩溃。。极限求助。。。。杀spyware

【求助】系统濒临崩溃。。极限求助。。。。杀spyware

哪位知道spyware是怎样的病毒?我的机子快疯了。
桌面上面什么都没有了。。。
十万十万火急。。。
        。。谢。
最后编辑2005-11-15 11:53:41
分享到:
gototop
 

用Autoruns保存一个日志发上来
日志保存方法:选择File->Save菜单项
保存日志时注意选择Options->Hide Microsoft Entries菜单项(设置了这项后点工具栏的刷新按钮)

工具使用参考http://forum.ikaka.com/topic.asp?board=28&artid=7318038第14楼
gototop
 

天,但是怎么复制呢?
我复制的时候显示系统找不到指定的文件。
gototop
 

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ 8WLUA4c:\documents and settings\cic.a2\local settings\temp\cxtpls_loader.exe

+ AddrPlusFile not found: C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll

+ CdnCtrLiveUpdate Modulec:\program files\cnnic\cdn\cdnup.exe

+ Explorer32c:\winnt\system32\efsdfgxg.exe

+ HotKeysCmdshkcmd ModuleIntel Corporationc:\winnt\system32\hkcmd.exe

+ IgfxTrayigfxTray ModuleIntel Corporationc:\winnt\system32\igfxtray.exe

+ IST ServiceFile not found: C:\Program Files\ISTsvc\istsvc.exe

+ msresearchFile not found: c:\windows\msresearch.exe

+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmon.exe

+ RavTimerRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtimer.exe

+ SurfAccuracyFile not found: C:\Program Files\SurfAccuracy\SAcc.exe

+ SysExplre:\r\sysexplr.exe

+ Systemc:\winnt\system32\kernels32.exe

+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe

+ Updatec:\program files\common files\update\update.exe

+ YLive.exeFile not found: C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe

+ zangoFile not found: c:\program files\zangoclient\zango.exe

C:\Documents and Settings\All Users\「开始」菜单\程序\启动

+ DuDu加速器.lnkDuDuAcc ModuleDuDuc:\program files\dudu\dddclient\duduacc.exe

C:\Documents and Settings\cic.A2\「开始」菜单\程序\启动

+ F10·加加.lnkF10·加加加加在线c:\program files\jjol\ime\f10.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

+ Windows installerc:\winstall.exe

HKLM\System\CurrentControlSet\Services

+ PPPoEServicec:\program files\北京通信\宽带e线—adsl\app\pppoeservice.exe

+ RsCCenterCCenterrisingc:\program files\rising\rav\ccenter.exe

+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe

+ SoundMAX Agent Service (default)SoundMAX service agent componentAnalog Devices, Inc.c:\program files\analog devices\soundmax\smagent.exe

+ tcphost.exec:\winnt\tcphost.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ eb.dllc:\winnt\system32\eb.dll

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt\system32\ravext.dll

+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realone player\rpshell.dll

+ 粉碎文件File not found: C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ywiper.dll

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Web 文件夹c:\program files\common files\microsoft shared\web folders\msonsext.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ ibar.dllc:\program files\ibar\10002\ibar.dll

+ 一搜YiSou ToolBar 3721c:\program files\yisou\yisou.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ 豪杰超级解霸9Hero Super Player 9Herosofte:\r\sthsdvd.exe

+ 精彩图铃File not found: http://ad.imhero.com/ADShow.aspx?PlaceID=B2

+ 腾讯QQFile not found: C:\Program Files\Tencent\QQ\QQ.EXE

+ 网上购物File not found: http://ad.imhero.com/ADShow.aspx?PlaceID=B1

+ 下载管理DuDuAcc ModuleDuDuc:\program files\dudu\dddclient\duduacc.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls

+ APIHookDll.dllFile not found: APIHookDll.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ Internet Settingsc:\winnt\system32\k4lq0e35eh.dll

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors

+ EPSON V5 2KMonitorEPSON Bidirectional MonitorSEIKO EPSON CORPORATIONc:\winnt\system32\ebpmon2.dll

+ SSGR3 LangmonPrinter Language MonitorSamsung Electronics.c:\winnt\system32\ssgr3mk.dll

gototop
 

是这个么?但好像是程序啊?
gototop
 

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ 8WLUA4c:\documents and settings\cic.a2\local settings\temp\cxtpls_loader.exe
+ Explorer32c:\winnt\system32\efsdfgxg.exe
+ Updatec:\program files\common files\update\update.exe
+ tcphost.exec:\winnt\tcphost.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ eb.dllc:\winnt\system32\eb.dll
+ Internet Settingsc:\winnt\system32\k4lq0e35eh.dll

删除启动项
重启
删除相应的文件

还有那些not find 的垃圾项都可以删除
gototop
 

thank.thank..thanks....
gototop
 

我把这几个文件都删掉了,可是有几个,就这个还是有,而且还是看不到桌面,是不是必需重装了呢?
+ 8WLUA4c:\documents and settings\cic.a2\local settings\temp\cxtpls_loader.exe
gototop
 

再扫描一个日志上来
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT