害怕毒啊 - 2006-5-11 10:16:00
我是用正版的瑞星杀毒软件,天天升级,
我进天极网摘,,不知道怎么, 瑞星就提示这些病毒..
瑞星.提示毒已经杀掉了..但我这时候CPU 占.100% 是不是瑞星提示错误了.电脑很卡.
病毒我发大家看下. 我要怎么完全杀掉这个毒
其中进程有个..mshta.exe 占99%
病毒名称 处理结果 发现日期 扫描方式 路径 文件
Trojan.DL.Agent.hrr 忽略 2006-05-11 01:25 文件监控 C:\Documents and Settings\yibaiwan\Local Settings\Temporary Internet Files\Content.IE5\G3K7G9C9 young[1].css
Trojan.DL.Agent.hrr 删除成功 2006-05-11 01:25 文件监控 C:\Documents and Settings\yibaiwan\Local Settings\Temporary Internet Files\Content.IE5\D48RD545 young[1].css
Trojan.JS.Psyme.d 删除成功 2006-05-11 01:25 文件监控 C: boot.hta
Trojan.DL.Agent.hrr 删除成功 2006-05-11 01:29 文件监控 C:\Documents and Settings\yibaiwan\Local Settings\Temporary Internet Files\Content.IE5\E3AV2N01 young[1].css
Trojan.JS.Psyme.d 删除成功 2006-05-11 01:29 文件监控 C: boot.hta
Trojan.DL.Agent.hrx 删除成功 2006-05-11 09:57 文件监控 C:\Documents and Settings\yibaiwan\Local Settings\Temporary Internet Files\Content.IE5\K9AHULEX young[1].css
Trojan.JS.Psyme.d 清除成功 2006-05-11 09:57 文件监控 C: boot.hta
害怕毒啊 - 2006-5-11 10:20:00
Logfile of HijackThis v1.99.1
Scan saved at 10:19:15, on 2006-5-11
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
c:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Netease\popo2004\popo.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\mshta.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Rising\Rav\Rav.exe
C:\Program Files\Rising\Rav\RsLogVw.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\yibaiwan\桌面\hijackthis\HijackThis.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\qq\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\qq\SendMMS.htm
O9 - Extra button: 联想 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.lenovo.com (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com.cn/webscanner/kavwebscan_unicode.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
害怕毒啊 - 2006-5-11 10:21:00
大家帮忙点啊. 我真的不懂.太怕了
不言放弃 - 2006-5-11 10:32:00
【回复“害怕毒啊”的帖子】
mshta.exe是微软Windows操作系统相关程序,用于执行.HTA文件
对于个人电脑用户来说
是没有什么用处的进程
结束mshta.exe进程
清空IE临时文件夹
安全模式下断网查杀
害怕毒啊 - 2006-5-11 10:45:00
能再具体点吗,我很菜,,我用瑞星杀了,好几次都没办法杀掉.
© 2000 - 2026 Rising Corp. Ltd.