123   1  /  3  页   跳转

求救!~~~~~~~~~~~~~~~~~~~~~~~

求救!~~~~~~~~~~~~~~~~~~~~~~~

我的电脑感染了desktop这个病毒,用"威金蠕虫"专杀工具和新欢乐时光变种专杀杀毒都杀不掉,不知道这是什么病毒,每次启动电脑的时候都会出现这个病毒!~请问该怎么解决!~谢谢!~~~~
名字是:desktop.ini 是记事本
里面的代码是:
[.ShellClassInfo]
LocalizedResourceName=@shell32.dll,-21774
最后编辑2006-10-22 00:38:36
分享到:
gototop
 

下载hijackthis扫描系统,把日志贴上来。
gototop
 

*----> 模块清单 <----*
(0000000000400000 - 0000000000419000: C:\Program Files\Internet Explorer\iexplore.exe
(0000000000f30000 - 0000000000fac000: C:\WINDOWS\system32\shdoclc.dll
(0000000001130000 - 000000000113c000: C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll
(0000000001590000 - 00000000015a9000: D:\Rising\Rav\RavScrCh.dll
(00000000019f0000 - 0000000001f39000: C:\WINDOWS\system32\xpsp2res.dll
(0000000003640000 - 0000000003676000: C:\WINDOWS\system32\CHENHU4.IME
(0000000005cd0000 - 0000000005e5d000: C:\WINDOWS\system32\macromed\flash\flash.ocx
(0000000006240000 - 0000000006244000: C:\Program Files\Common Files\System\msadc\msadcor.dll
(000000000ffd0000 - 000000000fff8000: C:\WINDOWS\system32\rsaenh.dll
(0000000010000000 - 0000000010040000: C:\WINDOWS\system32\alitb1\bar.dll
(0000000020000000 - 000000002000f000: C:\WINDOWS\system32\browselc.dll
(000000004a3e0000 - 000000004a405000: C:\WINDOWS\system32\winabc.ime
(000000004a410000 - 000000004a468000: C:\WINDOWS\system32\WINHTTP.dll
(000000004d0b0000 - 000000004d0d3000: C:\Program Files\Common Files\System\msadc\msadco.dll
(000000005adc0000 - 000000005adf7000: C:\WINDOWS\system32\uxtheme.dll
(000000005d170000 - 000000005d207000: C:\WINDOWS\system32\comctl32.dll
(000000005fdd0000 - 000000005fe24000: C:\WINDOWS\system32\NETAPI32.dll
(0000000060fd0000 - 0000000061025000: C:\WINDOWS\system32\hnetcfg.dll
(0000000061be0000 - 0000000061bed000: C:\WINDOWS\system32\MFC42LOC.DLL
(0000000062c20000 - 0000000062c29000: C:\WINDOWS\system32\LPK.DLL
(000000006c140000 - 000000006c175000: C:\WINDOWS\system32\dxtrans.dll
(000000006c180000 - 000000006c1da000: C:\WINDOWS\system32\dxtmsft.dll
(000000006cfd0000 - 000000006cfdb000: C:\WINDOWS\system32\dispex.dll
(000000006d7c0000 - 000000006d7ca000: C:\WINDOWS\system32\ddrawex.dll
(000000006e830000 - 000000006e83c000: C:\WINDOWS\system32\corpol.dll
(00000000719c0000 - 00000000719fe000: C:\WINDOWS\system32\mswsock.dll
(0000000071a00000 - 0000000071a08000: C:\WINDOWS\System32\wshtcpip.dll
(0000000071a10000 - 0000000071a18000: C:\WINDOWS\system32\WS2HELP.dll
(0000000071a20000 - 0000000071a37000: C:\WINDOWS\system32\WS2_32.dll
(0000000071a40000 - 0000000071a4b000: C:\WINDOWS\system32\wsock32.dll
(0000000071cc0000 - 0000000071cdc000: C:\WINDOWS\system32\actxprxy.dll
(0000000072240000 - 0000000072245000: C:\WINDOWS\system32\sensapi.dll
(0000000072a90000 - 0000000072aa8000: C:\WINDOWS\system32\plugin.ocx
(0000000072c80000 - 0000000072c88000: C:\WINDOWS\system32\msacm32.drv
(0000000072c90000 - 0000000072c99000: C:\WINDOWS\system32\wdmaud.drv
(0000000073270000 - 00000000732d7000: C:\WINDOWS\system32\vbscript.dll
(0000000073510000 - 0000000073535000: C:\WINDOWS\system32\scrrun.dll
(0000000073640000 - 000000007366e000: C:\WINDOWS\system32\msctfime.ime
(00000000736d0000 - 0000000073719000: C:\WINDOWS\system32\DDRAW.dll
(0000000073900000 - 000000007392d000: C:\WINDOWS\system32\WINWB.IME
(0000000073b30000 - 0000000073b36000: C:\WINDOWS\system32\DCIMAN32.dll
(0000000073d30000 - 0000000073e2e000: C:\WINDOWS\system32\MFC42.DLL
(0000000073fa0000 - 000000007400b000: C:\WINDOWS\system32\USP10.dll
(0000000074620000 - 0000000074647000: C:\WINDOWS\system32\msls31.dll
(0000000074650000 - 000000007467a000: C:\WINDOWS\system32\msimtf.dll
(0000000074680000 - 00000000746cb000: C:\WINDOWS\system32\MSCTF.dll
(0000000074cf0000 - 0000000074d81000: C:\WINDOWS\system32\mlang.dll
(00000000753b0000 - 0000000075421000: C:\WINDOWS\system32\mshtmled.dll
(0000000075430000 - 00000000754a1000: C:\WINDOWS\system32\CRYPTUI.dll
(00000000757d0000 - 00000000757e3000: C:\WINDOWS\system32\cryptnet.dll
(00000000759d0000 - 0000000075a7e000: C:\WINDOWS\system32\USERENV.dll
(0000000075b50000 - 0000000075b75000: C:\WINDOWS\system32\MSDART.DLL
(0000000075bc0000 - 0000000075c2e000: C:\WINDOWS\system32\jscript.dll
(0000000075c60000 - 0000000075cfb000: C:\WINDOWS\system32\urlmon.dll
(0000000075e00000 - 0000000075eae000: C:\WINDOWS\system32\SXS.DLL
(0000000075ef0000 - 0000000075fec000: C:\WINDOWS\system32\BROWSEUI.dll
(0000000075ff0000 - 0000000076055000: C:\WINDOWS\system32\MSVCP60.dll
(0000000076060000 - 00000000761b6000: C:\WINDOWS\system32\SETUPAPI.dll
(0000000076300000 - 000000007631d000: C:\WINDOWS\system32\IMM32.DLL
(0000000076320000 - 0000000076367000: C:\WINDOWS\system32\comdlg32.dll
(0000000076370000 - 00000000764dc000: C:\WINDOWS\system32\SHDOCVW.dll
(00000000765e0000 - 0000000076672000: C:\WINDOWS\system32\CRYPT32.dll
(0000000076680000 - 0000000076722000: C:\WINDOWS\system32\WININET.dll
(0000000076990000 - 0000000076acd000: C:\WINDOWS\system32\ole32.dll
(0000000076af0000 - 0000000076b01000: C:\WINDOWS\system32\ATL.DLL
(0000000076b10000 - 0000000076b3a000: C:\WINDOWS\system32\WINMM.dll
(0000000076c00000 - 0000000076c2e000: C:\WINDOWS\system32\WINTRUST.dll
(0000000076c60000 - 0000000076c88000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076d30000 - 0000000076d48000: C:\WINDOWS\system32\iphlpapi.dll
(0000000076d70000 - 0000000076d92000: C:\WINDOWS\system32\appHelp.dll
(0000000076db0000 - 0000000076dc2000: C:\WINDOWS\system32\MSASN1.dll
(0000000076e50000 - 0000000076e5e000: C:\WINDOWS\system32\rtutils.dll
(0000000076e60000 - 0000000076e72000: C:\WINDOWS\system32\rasman.dll
(0000000076e80000 - 0000000076eaf000: C:\WINDOWS\system32\TAPI32.dll
(0000000076eb0000 - 0000000076eec000: C:\WINDOWS\system32\RASAPI32.DLL
(0000000076ef0000 - 0000000076f17000: C:\WINDOWS\system32\DNSAPI.dll
(0000000076f30000 - 0000000076f5c000: C:\WINDOWS\system32\WLDAP32.dll
(0000000076f90000 - 0000000076f96000: C:\WINDOWS\system32\rasadhlp.dll
(0000000076fa0000 - 000000007701f000: C:\WINDOWS\system32\CLBCATQ.DLL
(0000000077020000 - 00000000770ba000: C:\WINDOWS\system32\COMRes.dll
(00000000770f0000 - 000000007717c000: C:\WINDOWS\system32\OLEAUT32.dll
(0000000077180000 - 0000000077282000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
(0000000077ba0000 - 0000000077ba7000: C:\WINDOWS\system32\midimap.dll
(0000000077bb0000 - 0000000077bc5000: C:\WINDOWS\system32\MSACM32.dll
(0000000077bd0000 - 0000000077bd8000: C:\WINDOWS\system32\VERSION.dll
(0000000077be0000 - 0000000077c38000: C:\WINDOWS\system32\msvcrt.dll
(0000000077c40000 - 0000000077c63000: C:\WINDOWS\system32\msv1_0.dll
(0000000077d10000 - 0000000077d9f000: C:\WINDOWS\system32\USER32.dll
(0000000077da0000 - 0000000077e49000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e50000 - 0000000077ee1000: C:\WINDOWS\system32\RPCRT4.dll
(0000000077ef0000 - 0000000077f37000: C:\WINDOWS\system32\GDI32.dll
(0000000077f40000 - 0000000077fb6000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000077fc0000 - 0000000077fd1000: C:\WINDOWS\system32\Secur32.dll
(000000007c800000 - 000000007c91c000: C:\WINDOWS\system32\kernel32.dll
(000000007c920000 - 000000007c9b4000: C:\WINDOWS\system32\ntdll.dll
(000000007cc80000 - 000000007cf62000: C:\WINDOWS\system32\mshtml.dll
(000000007d590000 - 000000007dd82000: C:\WINDOWS\system32\SHELL32.dll
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 22:34:28, on 2006-10-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\Rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
d:\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Rising\Rav\RavStub.exe
d:\rising\rfw\RfwMain.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Rising\Rav\RavTask.exe
D:\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\racer-henan-cnc\racer.exe
C:\Program Files\racer-henan-cnc\RacerKp.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\Documents and Settings\fan\My Documents\ha_hijackthis_1991\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Microsoft Internet Explorer Customization Dll - {3D898C55-78CC-5B7C-B5F2-45613F358288} - C:\WINDOWS\system32\iedksvr32.dll
O2 - BHO: ShowBarObject Class - {850B69E4-90DB-4F45-8621-891BF35A5B53} - C:\WINDOWS\system32\alitb1\bar.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RavTask] "D:\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "D:\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [rzt] C:\WINDOWS\Intel\rundll32.exe
O4 - HKLM\..\RunOnce: [RavStub] "D:\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: 进入征途传世.lnk = ?
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: 商机直通车 - {13b0c05c-ef05-4bf6-b0ea-f6111af25544} - C:\WINDOWS\system32\alitb1\bar.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'tcpcsapi.dll' missing
O15 - Trusted Zone: easyabc.95599.cn
O15 - Trusted Zone: www.95599.cn
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\Rising\Rav\Ravmond.exe
O23 - Service: systemm (systembar) - Unknown owner - C:\Program Files\baiodu\baidu.exe

gototop
 

下载sreng,重启电脑,进入安全模式后运行。
1.在“启动项目——注册表”里找到
[rzt] C:\WINDOWS\Intel\rundll32.exe
把它删掉,并删除文件
C:\WINDOWS\Intel\rundll32.exe
2.在“启动项目——服务——win32服务应用程序”中,钩选“隐藏已认证的微软项目”,找到 systemm (systembar),依次选“删除服务——设置——否”,然后找到文件
C:\Program Files\baiodu\baidu.exe
删除掉
gototop
 

另外看看015项的网址,如果陌生的话就用hijackthis修复掉
gototop
 

修复
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Microsoft Internet Explorer Customization Dll - {3D898C55-78CC-5B7C-B5F2-45613F358288} - C:\WINDOWS\system32\iedksvr32.dll
O4 - HKLM\..\Run: [rzt] C:\WINDOWS\Intel\rundll32.exe
O23 - Service: systemm (systembar) - Unknown owner - C:\Program Files\baiodu\baidu.exe

删除
C:\WINDOWS\Intel\rundll32.exe
C:\Program Files\baiodu\baidu.exe
gototop
 

不行啊!~还是会启动出来那几个病毒,不过我的机子速度好像快了好多!~~~
gototop
 

你是按照谁的方法做的??
gototop
 

再扫个日志
gototop
 
123   1  /  3  页   跳转
页面顶部
Powered by Discuz!NT