Board logo

标题: 第一次发现装了微点无法启动. [打印本页]

作者: avc345     时间: 2007-3-7 22:25    标题: 第一次发现装了微点无法启动.

东芝笔记电脑中了Worm.Brontok.c病毒,
用江民3.7日的病毒库,杀了后,重启出现C:\WINDOWS\BerasJatah.exe
然后进入安装模式下,安装3.7下载的最新的东方微点,重启后,发现一向最快显示出来的微点竟然没有显示,后发现微点没有启动,点击后发现以下错误提示:
附件 1: asdasd.jpg (2007-3-7 22:25, 23.47 K,下载次数: 55)



作者: avc345     时间: 2007-3-7 22:27
江民杀毒后,在C盘留下BootScan.log中显示:

2007-03-07 20:16:33  Jiangmin BootScan   1.0.6.720
2007-03-07 20:16:33  Start scanning with options: (0x2, 0x241)
2007-03-07 20:16:33  User Interface: (1, 0x804)
2007-03-07 20:16:43  Found virus "I-Worm/Brontok.c" in C:\WINDOWS\BerasJatah.exe, Deleted, result code is 5
2007-03-07 20:17:26  Found virus "TrojanClicker.Agent.sr" in C:\WINDOWS\system32\iexpress.dll, Deleted, result code is 5
2007-03-07 20:17:29  Found virus "I-Worm/Brontok.c" in C:\WINDOWS\system32\Administrator's Setting.scr, Deleted, result code is 5
2007-03-07 20:19:32  Found virus "I-Worm/Brontok.c" in C:\WINDOWS\pss\Empty.pifStartup, Deleted, result code is 5
2007-03-07 20:19:58  Found virus "I-Worm/Brontok.c" in C:\WINDOWS\ShellNew\sempalong.exe, Deleted, result code is 5
2007-03-07 20:21:15  Found virus "I-Worm/Brontok.c" in C:\Documents and Settings\Administrator\Local Settings\Application Data\smss.exe, Deleted, result code is 5
2007-03-07 20:21:16  Found virus "I-Worm/Brontok.c" in C:\Documents and Settings\Administrator\Local Settings\Application Data\services.exe, Deleted, result code is 5
2007-03-07 20:21:16  Found virus "I-Worm/Brontok.c" in C:\Documents and Settings\Administrator\Local Settings\Application Data\lsass.exe, Deleted, result code is 5
2007-03-07 20:21:16  Found virus "I-Worm/Brontok.c" in C:\Documents and Settings\Administrator\Local Settings\Application Data\winlogon.exe, Deleted, result code is 5
2007-03-07 20:21:16  Found virus "I-Worm/Brontok.c" in C:\Documents and Settings\Administrator\Local Settings\Application Data\inetinfo.exe, Deleted, result code is 5
2007-03-07 20:21:16  Found virus "I-Worm/Brontok.c" in C:\Documents and Settings\Administrator\Local Settings\Application Data\csrss.exe, Deleted, result code is 5
2007-03-07 20:21:17  Found virus "I-Worm/Brontok.c" in C:\Documents and Settings\Administrator\Templates\Brengkolang.com, Deleted, result code is 5
2007-03-07 20:21:18  Found virus "I-Worm/Brontok.c" in C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\Empty.pif, Deleted, result code is 5
2007-03-07 20:27:11  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\文档的备份(全部).exe, Deleted, result code is 5
2007-03-07 20:27:13  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\《圆明园》与龚半伦_黄炳元的个人空间_杭州博客网 - powered by X-Space.files\《圆明园》与龚半伦_黄炳元的个人空间_杭州博客网 - powered by X-Space.files`.exe, Deleted, result code is 5
2007-03-07 20:27:13  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\《圆明园》与龚半伦_黄炳元的个人空间_杭州博客网 - powered by X-Space.files\batch.toolbar.files\batch.toolbar.files`.exe, Deleted, result code is 5
2007-03-07 20:27:13  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\姚氏族谱\姚氏族谱.exe, Deleted, result code is 5
2007-03-07 20:27:14  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\官话、简历\官话、简历.exe, Deleted, result code is 5
2007-03-07 20:27:14  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\我接收到的文件\我接收到的文件.exe, Deleted, result code is 5
2007-03-07 20:27:15  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\教子无方的龚自珍- 好好她爸 - 新浪BLOG.files\教子无方的龚自珍- 好好她爸 - 新浪BLOG.files`.exe, Deleted, result code is 5
2007-03-07 20:27:15  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\明星档案\唐国强\唐国强.exe, Deleted, result code is 5
2007-03-07 20:27:15  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\明星档案\孙俪\孙俪.exe, Deleted, result code is 5
2007-03-07 20:27:15  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\明星档案\巫刚\巫刚.exe, Deleted, result code is 5
2007-03-07 20:27:15  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\明星档案\张丰毅\张丰毅.exe, Deleted, result code is 5
2007-03-07 20:27:16  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\明星档案\林熙蕾\林熙蕾.exe, Deleted, result code is 5
2007-03-07 20:27:16  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\明星档案\桥本丽香\桥本丽香.exe, Deleted, result code is 5
2007-03-07 20:27:16  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\明星档案\范冰冰\范冰冰.exe, Deleted, result code is 5
2007-03-07 20:27:16  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\明星档案\蒋勤勤\蒋勤勤.exe, Deleted, result code is 5
2007-03-07 20:27:16  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\明星档案\陈好\陈好.exe, Deleted, result code is 5
2007-03-07 20:27:17  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\明星档案\陶泽如\陶泽如.exe, Deleted, result code is 5
2007-03-07 20:27:17  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\西洋风情城图片\西洋风情城图片.exe, Deleted, result code is 5
2007-03-07 20:27:18  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\论文夹\论文夹.exe, Deleted, result code is 5
2007-03-07 20:27:18  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\论文夹\1421\1421.exe, Deleted, result code is 5
2007-03-07 20:27:19  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\论文夹\北京宝船中心文件\北京宝船中心文件.exe, Deleted, result code is 5
2007-03-07 20:27:19  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\论文夹\天妃圣迹图\天妃圣迹图.exe, Deleted, result code is 5
2007-03-07 20:27:19  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\论文夹\明永乐太监外交与天妃崇拜\明永乐太监外交与天妃崇拜.exe, Deleted, result code is 5
2007-03-07 20:27:20  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\资料相片\资料相片.exe, Deleted, result code is 5
2007-03-07 20:27:20  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\郑和下西洋\郑和下西洋.exe, Deleted, result code is 5
2007-03-07 20:27:23  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\郑和像集\郑和像集.exe, Deleted, result code is 5
2007-03-07 20:27:26  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\郑和航海图集\郑和航海图集.exe, Deleted, result code is 5
2007-03-07 20:27:26  Found virus "I-Worm/Brontok.c" in D:\文档的备份(全部)\黄花岗烈士名单[麻辣社区].files\黄花岗烈士名单[麻辣社区].files`.exe, Deleted, result code is 5
2007-03-07 20:29:13  Finished, Files: 39195, Viruses: 41, Killed: 0, Deleted: 41

2007-03-07 20:35:27  Jiangmin BootScan   1.0.6.720
2007-03-07 20:35:27  Start scanning with options: (0x2, 0x241)
2007-03-07 20:35:27  User Interface: (1, 0x804)
2007-03-07 20:47:40  Finished, Files: 39167, Viruses: 0, Killed: 0, Deleted: 0

2007-03-07 20:51:08  SafeBoot mode, skip virus scanning

2007-03-07 21:08:05  SafeBoot mode, skip virus scanning
作者: avc345     时间: 2007-3-7 22:29
难道这个去年4月份就发现的病毒有这么厉害啊,可以让微点无法启动啊,太晕了吧.

春节期间的微点又和跑跑卡丁车起冲突了,关了微点也玩不了跑跑卡丁车,最后只好卸掉了才能玩跑跑卡丁车,真晕.
作者: Legend     时间: 2007-3-7 22:31
请把此样本压缩发送至 virus@micropoint.com.cn
作者: michael     时间: 2007-3-8 07:17
慢慢来哦
作者: 100000     时间: 2007-3-8 09:31
LZ怎么不在正常模式安装试下呢
作者: avc345     时间: 2007-3-9 14:05
要什么样本啊?是朋友的机器,后来重装了系统,明天就还给她了.

楼上的,正常模式下,什么病毒也都正常运行啊,我当然是进入安全模式安装才安全啊.

微点是7号那天在你们网站上下载的啊,好象显示是2.11的

没法启动,也法升级了
作者: Legend     时间: 2007-3-9 14:15
楼主的情况并非病毒导致,可能是您的具体环境引起,如果您再遇到这种问题,请及时联系论坛版主或加入微点的技术交流群:16998902管理员帮您具体分析解决。
作者: ogo     时间: 2007-3-11 13:50
卡丁车启动时候貌似要写不少东西?




欢迎光临 微点交流论坛 (http://bbs.micropoint.com.cn/) bbs.micropoint.com.cn