瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 紧急求助
v异彩e - 2006-12-2 18:44:00
我的电脑中D盘怎么也打不开,而且瑞星监控中心和防火墙都打不开,杀毒也不管用,这是怎么回事啊?谁能帮帮我,郁闷死我了
水树雨下 - 2006-12-2 18:48:00
d盘怎么打不开?
v异彩e - 2006-12-2 18:51:00
就是得右键才可以。刚才检测有一个木马,叫Torjan Program,但是杀不了 我该怎么办呢?
水树雨下 - 2006-12-2 18:54:00
izuki.ys168.com下载System Repair Engineer扫个日志上来,一次贴不完分次贴,不要修改
v异彩e - 2006-12-2 19:02:00
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <KuGoo3><"E:\PROGRA~1\KUGOO3\KUGOO.EXE">  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [N/A]
    <systme32.exe><C:\WINDOWS\System32\systme32.exe>  [N/A]
    <KuGoo3><E:\PROGRA~1\KUGOO3\KUGOO.EXE>  [N/A]
    <r><C:\WINDOWS\down\rundll32.exe>  [N/A]
    <xy><C:\WINDOWS\Download\svhost32.exe>  [N/A]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <mhsystem><C:\DOCUME~1\User\LOCALS~1\Temp\2.exe>  [N/A]
    <stup.exe><C:\PROGRA~1\TENCENT\Adplus\stup.exe>  [Tencent]
    <Thunder><"F:\迅雷\ThunderShell.exe" /s>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <360Safe><Rundll32.exe E:\360safe\AntiAdwa.dll,KillAdware>  [360Safe.com]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
    <{1A404685-7563-4d02-B0F6-58B308A406A9}><f:\迅雷\ymyrmwrs.dll>  []
    <{729B6C61-BDC5-4C09-A1DE-A296BA0B89EC}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp>  [N/A]

==================================
启动文件夹
[腾讯QQ]
  <C:\Documents and Settings\User\「开始」菜单\程序\启动\腾讯QQ.lnk --> E:\QQ\QQ.exe [TENCENT]><N>

==================================
服务
[Application Management / AppMgmt]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[Ati HotKey Poller / Ati HotKey Poller]
  <C:\WINDOWS\System32\Ati2evxx.exe><N/A>
[ATI Smart / ATI Smart]
  <C:\WINDOWS\system32\ati2sgag.exe><>
[Human Interface Device Access / HidServ]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[RestoreService / RestoreService]
  <C:\WINDOWS\System32\Svchost.exe -k RestoreService-->C:\WINDOWS\System32\drivers\service.dll><N/A>
[Rising Proxy  Service / RfwProxySrv]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
  <c:\program files\rising\rfw\rfwsrv.exe><N/A>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Portable Media Serial Number Service / WmdmPmSN]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\System32\mspmsnsv.dll><Microsoft Corporation>
v异彩e - 2006-12-2 19:03:00
驱动程序
[ADProt / ADProt]
  <\SystemRoot\system32\drivers\ADProt.sys><腾讯科技(深圳)有限公司>
[Service for WDM 3D Audio Driver / ALCXSENS]
  <system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[ati2mtag / ati2mtag]
  <System32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Rising TDI Base Driver / BaseTDI]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[basic2 / basic2]
  <System32\DRIVERS\HSF_BSC2.sys><Conexant>
[Intel(R) PRO Adapter Driver / E100B]
  <System32\DRIVERS\e100b325.sys><Intel Corporation>
[ExpScaner / ExpScaner]
  <\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[Fallback / Fallback]
  <System32\DRIVERS\HSF_FALL.sys><Conexant>
[Fsks / Fsks]
  <System32\DRIVERS\HSF_FSKS.sys><Conexant>
[ghdaihdc / ghdaihdc]
  <\SystemRoot\system32\drivers\ghdaihdc.sys><中国互联网络信息中心(CNNIC)>
[HookCont / HookCont]
  <\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg]
  <\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
  <\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl]
  <\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[hsf_msft / hsf_msft]
  <System32\DRIVERS\HSF_MSFT.sys><Conexant>
[K56 / K56]
  <System32\DRIVERS\HSF_K56K.sys><Conexant>
[MEMSCAN / MEMSCAN]
  <\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs]
  <\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[nfutfkpj / nfutfkpj]
  <\SystemRoot\System32\drivers\nfutfkpj.sys><>
[Netgroup Packet Filter / NPF]
  <System32\DRIVERS\npf.sys><CACE Technologies>
[npkcrypt / npkcrypt]
  <\??\E:\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Rksample / Rksample]
  <System32\DRIVERS\HSF_SAMP.sys><Conexant>
[RsAntiSpyware / RsAntiSpyware]
  <\SystemRoot\System32\drivers\RsBoot.sys><Beijing Rising>
[RsFwDrv / RsFwDrv]
  <\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS]
  <\??\C:\PROGRAM FILES\RISING\RAV\RSPPSYS.sys><Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
  <System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv]
  <System32\DRIVERS\secdrv.sys><N/A>
[SoftFax / SoftFax]
  <System32\DRIVERS\HSF_FAXX.sys><Conexant>
[Tones / Tones]
  <System32\DRIVERS\HSF_TONE.sys><Conexant>

==================================
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\System32\xunleibho_v8.dll, >
[Tencent Browser Helper]
  {0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\Adplus\SSAddr.dll, Tencent>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <E:\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[]
  {669751ED-D558-49AE-B01A-3B374CC7910E} <C:\WINDOWS\System32\ssup.dll, N/A>
[]
  {A9930D97-9CF0-42A0-A10D-4F28836579D5} <E:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[CibaCtrl Class]
  {8DE0FCD4-5EB5-11D3-AD25-00002100131B} <C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <E:\office\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[JoyoCtrl Class]
  {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} <C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <E:\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <E:\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[金山快译(&K)]
  {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <C:\PROGRA~1\Kingsoft\FastAIT\IEBand.dll, >
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\System32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[PhotoUploadCtrl Control]
  {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} <E:\QQ\QZone\PHOTOU~1.OCX, tencent>
[photo_uploader Control]
  {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <C:\WINDOWS\DOWNLO~1\PHOTO_~1.OCX, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[&使用迅雷下载]
  <F:\迅雷\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <F:\迅雷\getallurl.htm, N/A>
[上传到QQ网络硬盘]
  <E:\QQ\AddToNetDisk.htm, N/A>
[使用KuGoo3下载(&K)]
  <E:\Program Files\KuGoo3\KuGoo3DownX.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://E:\office\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <E:\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <E:\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <E:\QQ\SendMMS.htm, N/A>
v异彩e - 2006-12-2 19:03:00
正在运行的进程
[PID: 548][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 612][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 640][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\Ati2evxx.dll]  [N/A, N/A]
    [f:\迅雷\ymyrmwrs.dll]  [, 1, 0, 0, 11]
[PID: 684][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 696][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 860][C:\WINDOWS\System32\Ati2evxx.exe]  [N/A, N/A]
[PID: 900][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 944][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1052][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1076][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1240][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 1512][C:\WINDOWS\system32\Ati2evxx.exe]  [N/A, N/A]
    [C:\WINDOWS\tdll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\wldll.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp]  [N/A, N/A]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 3, 6, 60]
[PID: 1560][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
    [C:\WINDOWS\tdll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\wldll.dll]  [N/A, N/A]
    [C:\DOCUME~1\User\LOCALS~1\Temp\mhsystem.dll]  [N/A, N/A]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 3, 6, 60]
    [C:\WINDOWS\RichDll.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp]  [N/A, N/A]
    [f:\迅雷\ymyrmwrs.dll]  [, 1, 0, 0, 11]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 1672][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3536]
    [C:\WINDOWS\tdll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\wldll.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp]  [N/A, N/A]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 3, 6, 60]
[PID: 1692][C:\Program Files\Rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 22]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\WINDOWS\tdll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\wldll.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp]  [N/A, N/A]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 3, 6, 60]
[PID: 1716][C:\WINDOWS\down\rundll32.exe]  [N/A, N/A]
    [C:\WINDOWS\tdll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\wldll.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp]  [N/A, N/A]
[PID: 1724][C:\WINDOWS\Download\svhost32.exe]  [N/A, N/A]
    [C:\WINDOWS\System32\wldll.dll]  [N/A, N/A]
    [C:\WINDOWS\tdll.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp]  [N/A, N/A]
[PID: 1788][C:\DOCUME~1\User\LOCALS~1\Temp\2.exe]  [N/A, N/A]
    [C:\DOCUME~1\User\LOCALS~1\Temp\mhsystem.dll]  [N/A, N/A]
[PID: 1796][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1912][C:\WINDOWS\System32\Svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [c:\windows\system32\drivers\service.dll]  [N/A, N/A]
    [c:\windows\system32\drivers\ms_restore.dll]  [Microsoft Corporation All rights reserved, 1, 0, 0, 1]
    [c:\windows\system32\drivers\Old_service.dll]  [N/A, N/A]
[PID: 116][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\tdll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\wldll.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp]  [N/A, N/A]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 3, 6, 60]
[PID: 144][C:\WINDOWS\System32\conime.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 3, 6, 60]
    [C:\WINDOWS\tdll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\wldll.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp]  [N/A, N/A]
[PID: 536][F:\迅雷\Thunder.exe]  [Thunder Networking Technologies,LTD, 5.0.3.86]
    [F:\迅雷\UpdateDownload.dll]  [N/A, N/A]
    [F:\迅雷\download_interface.dll]  [N/A, N/A]
    [F:\迅雷\log4cplus.dll]  [N/A, N/A]
    [F:\迅雷\stlport_vc646.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
    [F:\迅雷\historyinfo_manage.dll]  [N/A, N/A]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 3, 6, 60]
    [F:\迅雷\iThunder.dll]  [迅雷网络, 1, 0, 0, 30]
    [F:\迅雷\RegisterDll.dll]  [N/A, N/A]
    [C:\WINDOWS\tdll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\wldll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\DOCUME~1\User\LOCALS~1\Temp\mhsystem.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp]  [N/A, N/A]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
    [f:\迅雷\ymyrmwrs.dll]  [, 1, 0, 0, 11]
[PID: 1432][C:\WINDOWS\SERVICES.EXE]  [China, 0.00.0182]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 3, 6, 60]
    [C:\WINDOWS\tdll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\wldll.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp]  [N/A, N/A]
    [C:\DOCUME~1\User\LOCALS~1\Temp\mhsystem.dll]  [N/A, N/A]
[PID: 3080][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 3, 6, 60]
    [C:\Program Files\TENCENT\Adplus\SSAddr.dll]  [Tencent, 4, 3, 6, 60]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp]  [N/A, N/A]
    [C:\WINDOWS\System32\KakaTool.dll]  [Beijing Rising Technology Co., Ltd., 2, 0, 2, 4]
    [C:\WINDOWS\System32\xunleibho_v8.dll]  [, 4, 5, 1, 33]
    [E:\QQ\QQIEHelper.dll]  [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
    [E:\PROGRA~1\KuGoo3\KUGOO3~1.OCX]  [N/A, N/A]
    [C:\WINDOWS\tdll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\wldll.dll]  [N/A, N/A]
    [C:\DOCUME~1\User\LOCALS~1\Temp\mhsystem.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
[PID: 3560][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 3, 6, 60]
    [C:\Program Files\TENCENT\Adplus\SSAddr.dll]  [Tencent, 4, 3, 6, 60]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp]  [N/A, N/A]
    [C:\WINDOWS\System32\KakaTool.dll]  [Beijing Rising Technology Co., Ltd., 2, 0, 2, 4]
    [C:\WINDOWS\System32\xunleibho_v8.dll]  [, 4, 5, 1, 33]
    [E:\QQ\QQIEHelper.dll]  [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
    [E:\PROGRA~1\KuGoo3\KUGOO3~1.OCX]  [N/A, N/A]
    [C:\WINDOWS\tdll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\wldll.dll]  [N/A, N/A]
    [C:\DOCUME~1\User\LOCALS~1\Temp\mhsystem.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
[PID: 2252][C:\Program Files\Rising\Rav\RsAgent.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 3, 6, 60]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp]  [N/A, N/A]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\WINDOWS\tdll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\wldll.dll]  [N/A, N/A]
[PID: 2204][C:\WINDOWS\msagent\AgentSvr.exe]  [Microsoft Corporation, 2.00.0.3422]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 3, 6, 60]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp]  [N/A, N/A]
    [C:\WINDOWS\tdll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\wldll.dll]  [N/A, N/A]
[PID: 2440][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, N/A]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 3, 6, 60]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp]  [N/A, N/A]
    [C:\WINDOWS\tdll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\wldll.dll]  [N/A, N/A]
    [C:\DOCUME~1\User\LOCALS~1\Temp\mhsystem.dll]  [N/A, N/A]
[PID: 3664][C:\DOCUME~1\User\LOCALS~1\Temp\Rar$EX00.703\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
    [C:\Program Files\TENCENT\Adplus\Adplus.dll]  [Tencent, 4, 3, 6, 60]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp]  [N/A, N/A]
    [C:\WINDOWS\tdll.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\wldll.dll]  [N/A, N/A]
    [C:\DOCUME~1\User\LOCALS~1\Temp\mhsystem.dll]  [N/A, N/A]
v异彩e - 2006-12-2 19:04:00
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
[D:\]
[autorun]
OPEN=D:\pagefile.pif

==================================
HOSTS 文件
127.0.0.1      localhost
v异彩e - 2006-12-2 19:04:00
弄完了 ,是这样弄吗?
水树雨下 - 2006-12-2 19:12:00
运行System Repair Engineer 启动项目,注册表删除
<systme32.exe><C:\WINDOWS\System32\systme32.exe> [N/A]
<r><C:\WINDOWS\down\rundll32.exe> [N/A]
<xy><C:\WINDOWS\Download\svhost32.exe> [N/A]
<mhsystem><C:\DOCUME~1\User\LOCALS~1\Temp\2.exe> [N/A]
安全模式下打开我的电脑,工具,文件夹选项,查看,显示所有文件和文件夹,把“隐藏受保护的系统文件”的勾去掉删除
C:\WINDOWS\System32\systme32.exe
C:\WINDOWS\down\rundll32.exe
C:\WINDOWS\tdll.dll
C:\WINDOWS\System32\wldll.dll
C:\WINDOWS\Download\svhost32.exe
这个文件夹所有文件C:\DOCUME~1\User\LOCALS~1\Temp
右键打开d盘删除Autorun.inf,pagefile.pif
v异彩e - 2006-12-2 20:10:00
我弄了一遍了,可是那个木马还是有  急死我了
v异彩e - 2006-12-2 20:13:00
是不是需要再弄一遍呢?
水树雨下 - 2006-12-2 20:16:00
报的那个病毒文件名,路径
v异彩e - 2006-12-2 20:19:00
Torjan Program

C:\PROGRA~1\COMMON~1\iexplore.pif
水树雨下 - 2006-12-2 20:20:00
根据路径找到手动删除……
v异彩e - 2006-12-2 20:21:00
怎么手动删除阿?对不起 我比较笨
mold - 2006-12-2 20:24:00
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 19:39:59, 日期 2006-12-2
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\VM303_STI.EXE
C:\Program Files\95599 Certificate Tools\CIDC\RegCertTool.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
E:\Program Files\阿里巴巴\贸易通\AliTalk.exe
D:\下载\新建文件夹\HijackThis1991zww\HijackThis1991zww.exe

O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\KakaTool.dll
O4 - 启动项HKLM\\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - 启动项HKLM\\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - 启动项HKLM\\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - 启动项HKLM\\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - 启动项HKLM\\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - 启动项HKLM\\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - 启动项HKLM\\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - 启动项HKLM\\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - 启动项HKLM\\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - 启动项HKLM\\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - 启动项HKLM\\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - 启动项HKLM\\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
O4 - 启动项HKLM\\Run: [CnsMin] Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
O4 - 启动项HKLM\\Run: [HDCSP RegCertTool] C:\Program Files\95599 Certificate Tools\CIDC\RegCertTool.exe
O4 - 启动项HKLM\\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - 启动项HKLM\\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的按钮: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} - http://www.rising.com.cn/?u=RSTB (file missing)
O9 - 浏览器额外的按钮: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com/?u=RSTB (file missing)
O15 - “受信任的站点”中添加项: easyabc.95599.cn
O15 - “受信任的站点”中添加项: www.95599.cn
O16 - DPF: {59CCB4A0-727D-11CF-AC36-00AA00A47DD2} (Timer Object) - http://movie.yzvod.com/player/tools/ietimer.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{67178F3E-DB8C-47D2-95F4-B12F3A3074B4}: NameServer = 61.147.37.1 61.177.7.1
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - NT 服务: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - NT 服务: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - NT 服务: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - NT 服务: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - NT 服务: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - NT 服务: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
怎么办
帮忙看看我的
v异彩e - 2006-12-2 20:38:00
请告诉我一下 我该怎么办好吗?
用不用再扫一下日志?谢谢啦
mold - 2006-12-2 20:39:00
360安全卫士清理恶意软件官方下载页面下载软件网址:
http://www.360safe.com/download.html
v异彩e - 2006-12-2 20:55:00
谢谢你们啊~我现在弄完之后,用卡卡或者安全卫士查时,那个东西已经没有了,但是监控中心和防火墙还是打不开,该怎么办呢?
怀安LEDA電腦 - 2006-12-2 21:11:00
你好像是中西游木马了,
v异彩e - 2006-12-2 21:57:00
那是什么阿?我不怎么玩游戏阿` 该怎么办呢
1
查看完整版本: 紧急求助