ζζζ酷魚☆★☆ - 2006-7-23 17:42:00
我的QQ突然需要激活才能使用了然后查了一下毒,发现这个发现病毒种类列表:
病毒: Backdoor.Agent.ddb 次数: 2
病毒: Trojan.DL.Small.ibr 次数: 1
然后我把日志扫描了一个给大家看看,请大家帮帮我```
HijackThis_815汉化版扫描日志 V1.99.1
保存于 17:32:50, 日期 2006-7-23
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Unable to get Internet Explorer version!
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
E:\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
E:\Rising\Rav\Ravmond.exe
e:\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
E:\Rising\Rav\RavStub.exe
e:\rising\rfw\RfwMain.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\alg.exe
E:\Rising\Rav\RavTask.exe
E:\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\UberIcon\UberIcon Manager.exe
E:\遨游\Maxthon\Max.exe
E:\Rising\Rav\RsLogVw.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\wb\LOCALS~1\Temp\Rar$EX00.516\HijackThis1991zww.exe
F2 - REG:system.ini: UserInit=userinit.exe,C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\emje.exe
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v13.dll
O2 - BHO: FltSetUp Class - {1D49D58D-5C84-4B50-8359-D9809BEB2B32} - C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll
O2 - BHO: IEHlprObj Class - {999ADFA2-8AD1-47ff-97FC-69FB847458F4} - C:\Progra~1\NetMeeting\nmview.dll
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - E:\KuGoo3\KuGoo3DownXControl.ocx
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [ATIPTA] ; "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - 启动项HKLM\\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - 启动项HKLM\\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - 启动项HKLM\\Run: [RfwMain] "E:\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [RavTask] "E:\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [System Files Updater] ; C:\WINDOWS\FlyakiteOSX\Tools\System Files Updater.exe /S
O4 - 启动项HKLM\\RunOnce: [RavStub] "E:\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] ; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [RK Launcher] ; C:\Program Files\RK Launcher\RKLauncher.exe
O4 - HKCU\..\Run: [Alt+Q Hotkey Tool] ; C:\WINDOWS\Alt+Q Hotkey.exe
O4 - HKCU\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe"
O4 - HKCU\..\Run: [WinRoll] ; C:\Program Files\WinRoll\winroll.exe
O4 - HKCU\..\Run: [Yz Shadow] ; C:\Program Files\YzShadow\YzShadow.exe
O4 - Startup: 新浪UC.lnk = E:\UCSetup_2005III\UC\uc.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - E:\讯雷\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - E:\讯雷\getallurl.htm
O8 - IE右键菜单中的新增项目: 使用KuGoo3下载(&K) - E:\KuGoo3\KuGoo3DownX.htm
O9 - 浏览器额外的按钮: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - F:\cs1.5\浩方对战平台\GameClient.exe
O9 - 浏览器额外的按钮: 新浪UC - {2253922F-1B26-4C74-8B57-E3AEE748DBB8} - E:\UCSetup_2005III\UC\uc.exe
O9 - 浏览器额外的按钮: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.tomatolei.com (file missing)
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\quartz32.dll
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\quartz32.dll
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {2354A44B-3CEB-4829-9940-545B03103538} (PowerPlr Control) - http://movie.sun116.com/plugin/PowerPlr.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{22EEEDE8-4680-4526-960C-0ED96101AD2C}: NameServer = 221.5.203.98 221.5.203.99
O17 - HKLM\System\CS1\Services\Tcpip\..\{22EEEDE8-4680-4526-960C-0ED96101AD2C}: NameServer = 221.5.203.98 221.5.203.99
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: text/html - {E7009873-0D40-45B1-8D59-5B9AE98C7D38} - C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll
O21 - SSODL: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - (no file)
O23 - NT 服务: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - NT 服务: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - NT 服务: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - e:\rising\rfw\rfwproxy.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - e:\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - E:\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\Rising\Rav\Ravmond.exe
710207 - 2006-7-23 17:44:00
Trojan.DL.Small.ibr参考http://forum.ikaka.com/topic.asp?board=28&artid=7948848
ζζζ酷魚☆★☆ - 2006-7-23 17:48:00
就只有这一个问题吗?
mopery - 2006-7-23 17:50:00
修复
F2 - REG:system.ini: UserInit=userinit.exe,C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\emje.exe
O2 - BHO: FltSetUp Class - {1D49D58D-5C84-4B50-8359-D9809BEB2B32} - C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll
O2 - BHO: IEHlprObj Class - {999ADFA2-8AD1-47ff-97FC-69FB847458F4} - C:\Progra~1\NetMeeting\nmview.dll
O4 - 启动项HKLM\\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKCU\..\Run: [Alt+Q Hotkey Tool] ; C:\WINDOWS\Alt+Q Hotkey.exe
O21 - SSODL: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - (no file)
删除
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\emje.exe
C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll
C:\Progra~1\NetMeeting\nmview.dll
C:\WINDOWS\system32\ps2.exe
C:\WINDOWS\Alt+Q Hotkey.exe
http://www.pctutu.com/srmsdown.asp
下载超级兔子..用超级兔子清理王卸载流氓软件...(安全模式...)
ζζζ酷魚☆★☆ - 2006-7-23 21:03:00
我在安全模式下杀了毒了~~~请大侠看看有什么问题没有
HijackThis_815汉化版扫描日志 V1.99.1
保存于 20:47:22, 日期 2006-7-23
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Unable to get Internet Explorer version!
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\conime.exe
E:\Rising\Rav\RavMon.exe
D:\专杀木马\HijackThis1991zww.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\difd.exe
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v13.dll
O2 - BHO: (no name) - {999ADFA2-8AD1-47ff-97FC-69FB847458F4} - (no file)
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - E:\KuGoo3\KuGoo3DownXControl.ocx
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [ATIPTA] ; "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - 启动项HKLM\\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - 启动项HKLM\\Run: [RfwMain] "E:\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [RavTask] "E:\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [System Files Updater] ; C:\WINDOWS\FlyakiteOSX\Tools\System Files Updater.exe /S
O4 - 启动项HKLM\\RunOnce: [RavStub] "E:\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] ; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [RK Launcher] ; C:\Program Files\RK Launcher\RKLauncher.exe
O4 - HKCU\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe"
O4 - HKCU\..\Run: [WinRoll] ; C:\Program Files\WinRoll\winroll.exe
O4 - HKCU\..\Run: [Yz Shadow] ; C:\Program Files\YzShadow\YzShadow.exe
O4 - Startup: 新浪UC.lnk = E:\UCSetup_2005III\UC\uc.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - E:\讯雷\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - E:\讯雷\getallurl.htm
O8 - IE右键菜单中的新增项目: 使用KuGoo3下载(&K) - E:\KuGoo3\KuGoo3DownX.htm
O9 - 浏览器额外的按钮: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - F:\cs1.5\浩方对战平台\GameClient.exe
O9 - 浏览器额外的按钮: 新浪UC - {2253922F-1B26-4C74-8B57-E3AEE748DBB8} - E:\UCSetup_2005III\UC\uc.exe
O9 - 浏览器额外的按钮: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.tomatolei.com (file missing)
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\quartz32.dll
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\quartz32.dll
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {2354A44B-3CEB-4829-9940-545B03103538} (PowerPlr Control) - http://movie.sun116.com/plugin/PowerPlr.ocx
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: text/html - {E7009873-0D40-45B1-8D59-5B9AE98C7D38} - C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll
O23 - NT 服务: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - NT 服务: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - NT 服务: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - e:\rising\rfw\rfwproxy.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - e:\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - E:\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\Rising\Rav\Ravmond.exe
ζζζ酷魚☆★☆ - 2006-7-23 21:35:00
米有人知道吗??大侠们帮我看看呀!
ζζζ酷魚☆★☆ - 2006-7-23 21:36:00
米有人知道吗??大侠们帮我看看呀!
ζζζ酷魚☆★☆ - 2006-7-24 0:04:00
老大们~~好与不好上来给我说说好不?
ζζζ酷魚☆★☆ - 2006-7-24 0:46:00
老大们~~好与不好上来给我说说好不?
ζζζ酷魚☆★☆ - 2006-7-24 0:47:00
老大们~~好与不好上来给我说说好不?
不言放弃 - 2006-7-24 1:03:00
【回复“ζζζ酷魚☆★☆”的帖子】
修复
O18 - Filter: text/html - {E7009873-0D40-45B1-8D59-5B9AE98C7D38} - C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll
删除
C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll
================
http://cexx.org/lspfix.htm
下载LSPFix.exe
修复010项中的c:\windows\system32\quartz32.dll
修复方法参考图片
注意这次应该选中quartz32.dll文件
若用LSPFix.exe修复后还是不能上网
建议用WinsockFix修复注册表
WinsockFix下载:
http://www.winsockfix.nl/
==================
开始--运行
输入regedit
确定
进入注册表
修改
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\difd.exe
>
为
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
================
删除
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\difd.exe
=================
晕倒
竟然不能上传图片了
参考下面贴子中的图片吧
http://forum.ikaka.com/topic.asp?board=28&artid=7795226
© 2000 - 2026 Rising Corp. Ltd.