[注意]电脑中毒了,5555……怎么办!
偶的电脑中毒了,就是这个文件mspcidrv.sys,中了木马了。偶在网上查了很久,有时注册表,又是虾米的,偶看不懂!怎么办啊!555
谁教我个简单好用的方法,谢谢了。
SRENG的官方下载地址:<P>http://www.kztechs.com/sreng/download.html</P><P>下载后选~第四选项-智能扫描-选上检查进程模块的数字签名-扫描后保存报告~把内容粘上来,一次粘不完分几次粘,中间不要修改~..</P>
<P>..这个是驱动级的病毒,使用Rootkit技术..</P><p><P>你可以先试下用:</P><p><P>强制删除工具 PowerRMV
下载地址: http://ishare.sina.com.cn/cgi-bin/fileid.cgi?fileid=1020456
填入要杀灭文件(包括完整的路径) ~勾选“抑止杀灭对象再次生成”,点杀灭,有找不到提示的请忽略 ~</P><p><P>填入:</P><P>C:\WINDOWS\system32\NTDLL32.dll
</P> <P>这个也是从网上看到的,不知道能不能有用</P> 人在江湖漂,能有不中招 <B>以下是引用<I>dukhilu</I>在2007-3-10 12:52:30的发言:</B>
SRENG的官方下载地址:
<P>http://www.kztechs.com/sreng/download.html</P>
<P>下载后选~第四选项-智能扫描-选上检查进程模块的数字签名-扫描后保存报告~把内容粘上来,一次粘不完分几次粘,中间不要修改~..</P>
<P>..这个是驱动级的病毒,使用Rootkit技术..</P>
<P>
<P>你可以先试下用:</P>
<P>
<P>强制删除工具 PowerRMV
下载地址: http://ishare.sina.com.cn/cgi-bin/fileid.cgi?fileid=1020456
填入要杀灭文件(包括完整的路径) ~勾选“抑止杀灭对象再次生成”,点杀灭,有找不到提示的请忽略 ~</P>
<P>
<P>填入:</P>
<P>C:\WINDOWS\system32\NTDLL32.dll
</P>
谢谢,偶先试一下。 <P>Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能</P><P>以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件</P><P>
启动项目
注册表
<MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background> [(Verified)Microsoft Windows XP Publisher]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
<load><>
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<nwiz><nwiz.exe /install>
<SoundMan><SOUNDMAN.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<CnxDslTaskBar><"c:\program files\usb modem\accessrunner adsl usb\CnxDslTb.exe" "USB Modem\AccessRunner ADSL USB">
<THTF><C:\Program Files\THTF\THTF键盘驱动程序安装\skdaemon.exe> []
<NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<Mysee Alert><"C:\Program Files\GAOV\Mysee Alert\Mysee Alert.exe" -notray>
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [(Verified)"RealNetworks, Inc."]
<DesktopMemo><"C:\Program Files\DeskMemo\Deskmemo.exe"> []
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>
<WebThunder><E:\崇\WebThunder.exe> [深圳市迅雷网络技术有限公司]
<StormCodec_Helper><"D:\Storm Codec\StormSet.exe" /S /opti> []
<Internet><"C:\WINDOWS\system32\internet.exe">
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>
<RavStub><"C:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE>
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Component Publisher]
<AppInit_DLLs><C:\WINDOWS\system32\NTDLL32.dll>
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> </P><P>==================================</P> <P>启动文件夹
[腾讯QQ]
<C:\Documents and Settings\zhou\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\PROGRA~1\Tencent\QQ\QQ.exe ><N></P><P>==================================
服务
<"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
<"C:\WINDOWS\system32\internet.exe"><Microsoft Corporation>
<C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.></P><P>==================================
驱动程序
<\SystemRoot\system32\drivers\ADProt.sys><腾讯科技(深圳)有限公司>
<system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
<System32\DRIVERS\HSF_BSC2.sys><Conexant>
<System32\DRIVERS\CnxEtP.sys><Conexant Systems, Inc.>
<System32\DRIVERS\CnxEtU.sys><Conexant Systems, Inc.>
<System32\DRIVERS\CnxTgNL.sys><Conexant Systems, Inc.>
<\??\C:\WINDOWS\system32\drivers\dump_wmimmc.sys><N/A>
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
<System32\DRIVERS\HSF_FALL.sys><Conexant>
<System32\DRIVERS\HSF_FSKS.sys><Conexant>
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
<\??\C:\Program Files\Rising\Rav\HookReg.sys><>
<\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
<System32\DRIVERS\HSFBS2S2.sys><Conexant Systems, Inc.>
<System32\DRIVERS\HSFDPSP2.sys><Conexant Systems, Inc.>
<System32\DRIVERS\HSF_MSFT.sys><Conexant>
<System32\DRIVERS\HSF_K56K.sys><Conexant>
<\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
<\SystemRoot\system32\drivers\kxkbxgc.sys><>
<\SystemRoot\\SystemRoot\System32\drivers\lcjbkej.sys><N/A>
<System32\DRIVERS\mdmxsdk.sys><Conexant>
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
<system32\DRIVERS\mspcidrv.sys><N/A>
<\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
<System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
<System32\DRIVERS\HSF_SAMP.sys><Conexant>
<\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
<\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
<System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
<System32\DRIVERS\secdrv.sys><N/A>
<System32\DRIVERS\Skkbdf.sys><Silitek Corp.>
<System32\DRIVERS\HSF_FAXX.sys><Conexant>
<System32\DRIVERS\HSF_TONE.sys><Conexant>
<System32\DRIVERS\HSF_V124.sys><Conexant>
<\SystemRoot\System32\DRIVERS\vdigewwp.sys><Yahoo! China Corporation>
<\SystemRoot\System32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
<\SystemRoot\System32\DRIVERS\viaide.sys><Microsoft Corporation>
<System32\DRIVERS\HSFCXTS2.sys><Conexant Systems, Inc.>
<System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation></P><P>==================================</P> 浏览器加载项
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <E:\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
{8E25AC4A-B129-451B-BEE2-3B510BB751DA} <C:\WINDOWS\system32\NTDLL32.dll, Microsoft Corporation>
{AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
{D0903A3B-F0EA-434a-9742-98C5335C7946} <C:\WINDOWS\system32\IEHelper.dll, Mass Effect Network>
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <E:\迅雷\Thunder.exe, Thunder Networking Technologies,LTD>
[启动Web迅雷]
{962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <, N/A>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <E:\崇\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
{08A312BA-5409-49FC-9347-54BB7D069AC6} <, N/A>
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\System32\mshtml.dll, N/A>
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
{3CEFF6CD-6F08-4E4D-BCCD-FF7415288C3B} <C:\WINDOWS\system32\SHDOCVW.DLL, Microsoft Corporation>
{52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
{54EBD53A-9BC1-480B-966A-843A333CA162} <, N/A>
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\System32\shdocvw.dll, N/A>
[]
{669751ED-D558-49AE-B01A-3B374CC7910E} <C:\WINDOWS\system32\ssup.dll, TENCENT>
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
{7670648D-461B-42AF-BDFE-46D26AF5EFF2} <E:\崇\MediaAddin10.dll, Thunder Networking Technologies,LTD>
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\System32\shdocvw.dll, Microsoft Corporation>
{889D2FEB-5411-4565-8998-1DD2C5261283} <, N/A>
{8E25AC4A-B129-451B-BEE2-3B510BB751DA} <C:\WINDOWS\system32\NTDLL32.dll, Microsoft Corporation>
{AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
{AA899B43-24BD-4B6B-BBD0-45557D8D11E0} <C:\PROGRA~1\VIEWGOOD\WEBPLA~1\VGPlayer.dll, >
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\System32\mshtml.dll, Microsoft Corporation>
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\System32\shdocvw.dll, N/A>
[]
{B69003B3-C55E-4B48-836C-BC5946FC3B28} <C:\Program Files\Messenger\msgsc.dll, Microsoft Corporation>
{B6FFC24C-7E13-11D0-9B47-00C04FC2F51D} <C:\WINDOWS\System32\danim.dll, Microsoft Corporation>
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
{CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
{CD3AFA7B-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
{CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
{CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
{CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\System32\rmoc3260.dll, RealNetworks, Inc.>
{D0903A3B-F0EA-434A-9742-98C5335C7946} <C:\WINDOWS\system32\IEHelper.dll, Mass Effect Network>
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
{F917534D-535B-416B-8E8F-0C04756C31A8} <C:\WINDOWS\system32\GLIEDown2.dll, 联众公司>
[&使用迅雷下载]
<E\迅雷\Program\geturl.htm, N/A>
[&使用迅雷下载全部链接]
<E:\迅雷\Program\getallurl.htm, N/A> <P>[上传到QQ网络硬盘]
<C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用Web迅雷下载]
<E:\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
<E:\GetAllUrl.htm, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm, N/A></P><P>==================================
正在运行的进程
[\SystemRoot\System32\smss.exe]
[\??\C:\WINDOWS\system32\csrss.exe]
[, 18, 0, 0, 6]
[, 1, 0, 0, 1]
[, 1, 0, 0, 1]
[深圳市迅雷网络技术有限公司, 1, 6, 0, 87]
[ , 1, 0, 0, 14]
[ , 3, 1, 0, 58]
</P>
[腾讯公司, 3.2.200.275]
[腾讯公司, 1, 1, 0, 5]
[, 1, 0, 0, 3]
[深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 4]
[, ]
<P>==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK.
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]</P><P>==================================
Winsock 提供者
N/A</P><P>==================================
Autorun.inf
N/A</P><P>==================================
HOSTS 文件
127.0.0.1 localhost</P><P>==================================
API HOOK N/A</P><P>==================================
隐藏进程 N/A</P><P>=================================</P><P>这么长,怎么办</P>