重大发现,卡卡上网助手等自动被删除!
无意中看了一个网页,瑞星提示有毒,我随手点击卡卡上网助手,可是当场被删除,并且计算自动关闭.
后来发现,安全模式也进不去了,下载"360安全卫士"同上面一样,立即被删除,并且机器关机,其它软件没事,就是部分小型杀毒软件有事.
用瑞星杀毒了,没有发现病毒!
以下是当时打开网页,被瑞星拦住的病毒:
Trojan.DL.Small.sdd 删除成功 2007-03-01 02:26 文件监控 C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\8TWPM3CT downloader[1].exe>>pe_patch(18)>>UPX
Trojan.DL.Small.sdd 删除成功 2007-03-01 02:26 文件监控 C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp downloader.exe>>pe_patch(18)>>UPX
Trojan.Clicker.VB.aiu 删除成功 2007-03-01 02:26 文件监控 C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\PWG7D5O1 theopen[1].exe>>UPX
Trojan.Clicker.VB.aiu 删除成功 2007-03-01 02:26 文件监控 C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp theopen.exe>>UPX
Trojan.DL.VBS.Agent.chu 删除成功 2007-03-01 02:26 文件监控 C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\GDMBOHMN bind_50077[1].htm
Trojan.DL.VBS.Agent.cfo 删除成功 2007-03-01 02:26 文件监控 C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\ADKNITI5 counter[1].htm
Trojan.DL.VBS.Agent.chu 跳过脚本 2007-03-01 02:26 网页/脚本监控 C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp 371646807264.tmp
Trojan.DL.VBS.Agent.cfo 跳过脚本 2007-03-01 02:27 网页/脚本监控 C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp 371646807264.tmp
C:\WINDOWS\Explorer.EXE HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN Start Page http://web.new114.com.cn 2007-03-01 02:23 修改 拒绝修改
C:\WINDOWS\Explorer.EXE HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN Start Page http://web.new114.com.cn 2007-03-01 02:23 修改 拒绝修改
C:\WINDOWS\ctfmonsys.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN ctfmonsys C:\WINDOWS\ctfmonsys.exe 2007-03-01 02:23 修改 拒绝修改
C:\WINDOWS\mppds.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN mppds C:\WINDOWS\mppds.exe 2007-03-01 02:23 修改 拒绝修改
C:\WINDOWS\msccrt.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN msccrt C:\WINDOWS\msccrt.exe 2007-03-01 02:23 修改 拒绝修改
C:\WINDOWS\system32\rundll32.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN A C:\WINDOWS\system32\rundll32.exe 1.1 s 2007-03-01 02:27 修改 拒绝修改
C:\WINDOWS\ctfmonsys.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN ctfmonsys C:\WINDOWS\ctfmonsys.exe 2007-03-01 02:33 修改 同意修改
C:\WINDOWS\mppds.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN mppds C:\WINDOWS\mppds.exe 2007-03-01 02:33 修改 同意修改
C:\WINDOWS\msccrt.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN msccrt C:\WINDOWS\msccrt.exe 2007-03-01 02:33 修改 同意修改
D:\Program Files\Wom\Womcc.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN ctfmonsys 2007-03-01 03:07 删除 同意修改
D:\Program Files\Wom\Womcc.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN mppds 2007-03-01 03:07 删除 同意修改
D:\Program Files\Wom\Womcc.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN msccrt 2007-03-01 03:07 删除 同意修改
D:\Program Files\Iparmor\Iparmor.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNSERVICES default 2007-03-01 03:17 添加 同意修改
D:\Program Files\Iparmor\Iparmor.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH SearchAssistant 2007-03-01 03:18 删除 同意修改
D:\Program Files\Iparmor\Iparmor.exe HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH CustomizeSearch 2007-03-01 03:18 删除 同意修改