1234   3  /  4  页   跳转

如何杀Trojan.DL.Agent.dtp病毒.

找着那个htpatch了,图标象是条码,是那个吗
mstask的后缀还是dll,不是exe
gototop
 

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ BigDog303VimicroVimicroc:\windows\vm303_sti.exe

+ ExFiltercdnspiec:\program files\cnnic\cdn\cdnspie.dll

+ LenSoftFlyShuttle Microsoft 基础类应用程序c:\program files\lenovo\幸福一键通\flyshuttle.exe

+ Lskbdrvc:\program files\lenovo\幸福一键通\kbdriver.exe

+ NvCplDaemonNVIDIA Taskbar Utility LibraryNVIDIA Corporationc:\windows\system32\nvqtwk.dll

+ nwizNVIDIA nView Control Panel, Version 28.32 NVIDIA Corporationc:\windows\system32\nwiz.exe

+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmon.exe

+ RavTimerRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtimer.exe

+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwmain.exe

+ SoundManRealtek Sound ManagerRealtek Semiconductor Corp.C:\WINDOWS\soundman.exe

+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe

C:\Documents and Settings\All Users\「开始」菜单\程序\启动

+ InterVideo WinCinema Manager.lnkWinCinema Managerc:\program files\intervideo\common\bin\wincinemamgr.exe

C:\Documents and Settings\Owner\「开始」菜单\程序\启动

+ 腾讯QQ.lnkd:\program files\新建文件夹\qq.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realplayer\rpshell.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ NTIECatcher ClassNet Transport IE Helper ModuleXid:\program files\xi\nettransport 2\ntiehelper.dll

+ QQBrowserHelperObject ClassQQIEHelper Module深圳市腾讯计算机系统有限公司c:\program files\tencent\qq\qqiehelper.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ 联想File not found: http://www.legend.com

+ 腾讯QQd:\program files\新建文件夹\qq.exe

HKLM\System\CurrentControlSet\Services

+ NtFrs32c:\windows\system32\ntfrs32.exe

+ NVSvcNVIDIA Driver Helper Service, Version 28.32NVIDIA Corporationc:\windows\system32\nvsvc32.exe

+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwsrv.exe

+ RsCCenterCCenterrisingc:\program files\rising\rav\ccenter.exe

+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe

HKLM\System\CurrentControlSet\Services

+ ALCXWDMRealtek AC'97 Audio Driver (WDM)Realtek Semiconductor Corp.c:\windows\system32\drivers\alcxwdm.sys

+ BaseTDIbasetdiRisingc:\windows\system32\drivers\basetdi.sys

+ basic2NTRksample driverConexantc:\windows\system32\drivers\hsf_bsc2.sys

+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys

+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys

+ HookRegc:\program files\rising\rav\hookreg.sys

+ HookSys瑞星c:\program files\rising\rav\hooksys.sys

+ HSF_DPHSF_DP driverConexant Systemsc:\windows\system32\drivers\hsf_dp.sys

+ hsf_msftWinACHSF driverConexantc:\windows\system32\drivers\hsf_msft.sys

+ HSFHWBS2HSF_HWB2 WDM driverConexant Systemsc:\windows\system32\drivers\hsfhwbs2.sys

+ kmsinputc:\windows\system32\drivers\kmsinput.sys

+ mdmxsdkDiagnostic Interface DRIVERConexantc:\windows\system32\drivers\mdmxsdk.sys

+ MSJDrvrc:\windows\system32\drivers\msjdrvr.sys

+ New0c:\windows\system32\new.sys

+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.c:\program files\tencent\qq\npkcrypt.sys

+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 28.32 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys

+ RksampleRksample WDM driverConexantc:\windows\system32\drivers\hsf_samp.sys

+ RsFwDrvnt_fwdrvRisingc:\program files\rising\rfw\rsfwdrv.sys

+ rtl8139NDIS 5.0 driver                                                                  Realtek Semiconductor Corporation                                                c:\windows\system32\drivers\rtl8139.sys

+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys

+ sisagpSiS NT AGP FilterSilicon Integrated Systems Corporationc:\windows\system32\drivers\sisagpx.sys

+ SiSideSiS PCI Mini IDE DriverSilicon Integrated Systems Corp.c:\windows\system32\drivers\siside.sys

+ sisperfSiS Filter DriverSilicon Integrated Systems Corp.c:\windows\system32\drivers\sisperf.sys

+ UIUSysDiagnostic Interface DRIVERConexantc:\windows\system32\drivers\uiusys.sys

+ winachsfWinACHSF driverConexant Systemsc:\windows\system32\drivers\hsf_cnxt.sys

+ ZSMC303Video streaming and Capture Device DriverVMc:\windows\system32\drivers\usbvm303.sys

gototop
 

O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [mstasks.exe] C:\WINDOWS\System32\mstasks.exe

修复
重启
删除C:\WINDOWS\System32\mstasks.exe;C:\WINDOWS\htpatch.exe试试

我按照这个方法修复了,但是因为我不知道找到的是不是就是你说 的那个,所以我还没删除了
gototop
 

我看了一下mstasks.dll的属性,它的创建时间是我组装电脑的时间,能删除吗?
gototop
 

按照方法删除启动项,重起后只找着c:\windows\system32\drivers\msjdrvr.sys,删除了,其他两个地址c:\windows\system32\ntfrs32.exe;
c:\windows\system32\new.sys;根本没有,是不是删除启动项以后没有的,因为删除之前我还找着了,可是删除以后,重起电脑就没有了,这样就好了吗?这次重起电脑到是没有黄页出现了.
gototop
 

你说的那个方法O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [mstasks.exe] C:\WINDOWS\System32\mstasks.exe

修复
重启
删除C:\WINDOWS\System32\mstasks.exe;C:\WINDOWS\htpatch.exe试试
我也做了,把那两项也修复重起了,但是没有删除,用还原不用,修复以后没事吧.还有现在电脑速度快多了,谢谢
gototop
 

好象不行,我杀毒时,又出现了那个病毒,但是地址变了
文件名分别是suflsd  NtFrs3  nsdff.dll 文件路径都是c;\windows\system32 病毒名还是那个,是怎么回事啊
gototop
 

而且c:\ststem volume information\_restore这里也有
gototop
 

杀完毒发现病毒后的日志
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ BigDog303VimicroVimicroc:\windows\vm303_sti.exe

+ ExFiltercdnspiec:\program files\cnnic\cdn\cdnspie.dll

+ LenSoftFlyShuttle Microsoft 基础类应用程序c:\program files\lenovo\幸福一键通\flyshuttle.exe

+ Lskbdrvc:\program files\lenovo\幸福一键通\kbdriver.exe

+ NvCplDaemonNVIDIA Taskbar Utility LibraryNVIDIA Corporationc:\windows\system32\nvqtwk.dll

+ nwizNVIDIA nView Control Panel, Version 28.32 NVIDIA Corporationc:\windows\system32\nwiz.exe

+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmon.exe

+ RavTimerRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtimer.exe

+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwmain.exe

+ SoundManRealtek Sound ManagerRealtek Semiconductor Corp.C:\WINDOWS\soundman.exe

+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe

C:\Documents and Settings\All Users\「开始」菜单\程序\启动

+ InterVideo WinCinema Manager.lnkWinCinema Managerc:\program files\intervideo\common\bin\wincinemamgr.exe

C:\Documents and Settings\Owner\「开始」菜单\程序\启动

+ 腾讯QQ.lnkd:\program files\新建文件夹\qq.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realplayer\rpshell.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ NTIECatcher ClassNet Transport IE Helper ModuleXid:\program files\xi\nettransport 2\ntiehelper.dll

+ QQBrowserHelperObject ClassQQIEHelper Module深圳市腾讯计算机系统有限公司c:\program files\tencent\qq\qqiehelper.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ 联想File not found: http://www.legend.com

+ 腾讯QQd:\program files\新建文件夹\qq.exe

HKLM\System\CurrentControlSet\Services

+ NVSvcNVIDIA Driver Helper Service, Version 28.32NVIDIA Corporationc:\windows\system32\nvsvc32.exe

+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\rfwsrv.exe

+ RsCCenterCCenterrisingc:\program files\rising\rav\ccenter.exe

+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe

HKLM\System\CurrentControlSet\Services

+ ALCXWDMRealtek AC'97 Audio Driver (WDM)Realtek Semiconductor Corp.c:\windows\system32\drivers\alcxwdm.sys

+ BaseTDIbasetdiRisingc:\windows\system32\drivers\basetdi.sys

+ basic2NTRksample driverConexantc:\windows\system32\drivers\hsf_bsc2.sys

+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys

+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys

+ HookRegc:\program files\rising\rav\hookreg.sys

+ HookSys瑞星c:\program files\rising\rav\hooksys.sys

+ HSF_DPHSF_DP driverConexant Systemsc:\windows\system32\drivers\hsf_dp.sys

+ hsf_msftWinACHSF driverConexantc:\windows\system32\drivers\hsf_msft.sys

+ HSFHWBS2HSF_HWB2 WDM driverConexant Systemsc:\windows\system32\drivers\hsfhwbs2.sys

+ kmsinputc:\windows\system32\drivers\kmsinput.sys

+ mdmxsdkDiagnostic Interface DRIVERConexantc:\windows\system32\drivers\mdmxsdk.sys

+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.c:\program files\tencent\qq\npkcrypt.sys

+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 28.32 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys

+ RksampleRksample WDM driverConexantc:\windows\system32\drivers\hsf_samp.sys

+ RsFwDrvnt_fwdrvRisingc:\program files\rising\rfw\rsfwdrv.sys

+ rtl8139NDIS 5.0 driver                                                                  Realtek Semiconductor Corporation                                                c:\windows\system32\drivers\rtl8139.sys

+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys

+ sisagpSiS NT AGP FilterSilicon Integrated Systems Corporationc:\windows\system32\drivers\sisagpx.sys

+ SiSideSiS PCI Mini IDE DriverSilicon Integrated Systems Corp.c:\windows\system32\drivers\siside.sys

+ sisperfSiS Filter DriverSilicon Integrated Systems Corp.c:\windows\system32\drivers\sisperf.sys

+ UIUSysDiagnostic Interface DRIVERConexantc:\windows\system32\drivers\uiusys.sys

+ winachsfWinACHSF driverConexant Systemsc:\windows\system32\drivers\hsf_cnxt.sys

+ ZSMC303Video streaming and Capture Device DriverVMc:\windows\system32\drivers\usbvm303.sys

gototop
 

病毒是没有再出现,可是网速特别慢,跟没杀病毒时一样慢,再帮我看看日志吧,是不是病毒没有删除.
gototop
 
1234   3  /  4  页   跳转
页面顶部
Powered by Discuz!NT