瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 我才买的盒装2007瑞星 就这样被栓掉了....?
lh22397908 - 2007-2-5 9:24:00
前几天才去新华书店花188元买的瑞星  就这样的效果...?
  昨天有个顾客拿个U盘来烤文件  U盘一插进去 瑞星右下角提示了一下病毒后
马上就自动出现卸载瑞星杀毒软件自己就被卸载了 在C盘的Rav里面就空了
仿火墙正常的都是好的...杀毒的不能用了监控中心也不在了
每次重启动后大概3分种以内就会自动重新启动  重起的时候不会出现任何提示...
我就是不愿意重装系统很麻烦的
有什么打印机 路由器 扫描仪 很多很多软件~!还需要装驱动什么的~!
有什么办法可以解决我的问题啊`!
我马上去把日志传上来
因为正常启动只有不到3分钟时间就会重启动  我在安全模式下打开注册表...点2下注册表就闪一下  点一下闪一下就是打不开  怎么办啊

附件: 63948120072595225.jpg
lh22397908 - 2007-2-5 9:37:00
Logfile of HijackThis v1.99.1
Scan saved at 9:16:25, on 2007-2-5
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\gmm_my.exe
C:\WINDOWS\system32\drivers\spoclsv.exe
C:\WINDOWS\iexpl0re.exe
C:\WINDOWS\system.exe
C:\WINDOWS\winlog0n.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\conime.exe
c:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\system32\rundll32.exe
D:\LiDong\iNet Protector\IProtectorService.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\桌面\HijackThis.exe

R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
O2 - BHO: AssistHelper - {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} - C:\Program Files\Yahoo!\Assistant\Assist\yassist.dll
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4A40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MyIE2] C:\WINDOWS\my.exe
O4 - HKLM\..\Run: [CONFIG] C:\WINDOWS\gmm_my.exe
O4 - HKLM\..\Run: [IEXPlORER] C:\WINDOWS\goodrack.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [load] C:\WINDOWS\uninstall\rundl132.exe
O4 - HKCU\..\Run: [svcshare] C:\WINDOWS\system32\drivers\spoclsv.exe
O4 - HKCU\..\Run: [w] C:\WINDOWS\iexpl0re.exe
O4 - HKCU\..\Run: [7h5yx3zce] C:\WINDOWS\system.exe
O4 - HKCU\..\Run: [wj12ulsx1v] C:\WINDOWS\winlog0n.exe
O4 - HKCU\..\Run: [wj12ulsx1v] C:\WINDOWS\winlog0n.exe
O8 - Extra context menu item: &使用迅雷下载 - d:\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\QQ\AddEmotion.htm
O8 - Extra context menu item: 添加到雅虎订阅(&Y) - res://C:\Program Files\Yahoo!\Assistant\Assist\yrss.dll/YRSSMENUEXT
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\QQ\SendMMS.htm
O8 - Extra context menu item: 雅虎搜索 - res://C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll/203
O9 - Extra button: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/start.htm?source=yzs_icon&btn=yassistnew (file missing)
O16 - DPF: {E847C78C-C210-4195-8799-FBF3BF89797D} (金山毒霸在线产品升级) - http://www.duba.net/cab/KOSInit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0038B4BA-9281-4B04-B278-5DE5AF75287A}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{89070DFC-B5F9-4619-8FE1-535705060A7E}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{0038B4BA-9281-4B04-B278-5DE5AF75287A}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{0038B4BA-9281-4B04-B278-5DE5AF75287A}: NameServer = 61.128.128.68,61.128.192.68
O23 - Service: Internet Protector System Service (InternetProtectorService) - Unknown owner - D:\LiDong\iNet Protector\IProtectorService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

水树雨下 - 2007-2-5 9:42:00
O4 - HKLM\..\Run: [load] C:\WINDOWS\uninstall\rundl132.exe
O4 - HKCU\..\Run: [svcshare] C:\WINDOWS\system32\drivers\spoclsv.exe
威金加熊猫,你还真够衰的, mizuki.ys168.com专杀,先更新,杀完重装瑞星,升到最高杀毒去
bettertiger - 2007-2-5 9:45:00
iexpl0re.exe
这个好像不是什么正常的东西。结束该进程。从启动项里清理,并进入注册表查找删除相关的键值。然后重新安装瑞星。扫描全盘。
Ahtiman - 2007-2-5 9:46:00
我觉得以下的有问题,先别乱删,有可能我搞错~
O4 - HKLM\..\Run: [MyIE2] C:\WINDOWS\my.exe
O4 - HKLM\..\Run: [CONFIG] C:\WINDOWS\gmm_my.exe
O4 - HKCU\..\Run: [svcshare] C:\WINDOWS\system32\drivers\spoclsv.exe
O4 - HKCU\..\Run: [wj12ulsx1v] C:\WINDOWS\winlog0n.exe
O4 - HKCU\..\Run: [wj12ulsx1v] C:\WINDOWS\winlog0n.exe
O4 - HKCU\..\Run: [w] C:\WINDOWS\iexpl0re.exe
lh22397908 - 2007-2-5 9:50:00
【回复“lh22397908”的帖子】
我下载的
1农夫山泉有点甜威金专杀.zip
2可以清除熊猫释放的垃圾,能修复仿威金感染的文件.rar
杀毒对不对啊
水树雨下 - 2007-2-5 9:52:00
1农夫山泉有点甜威金专杀.zip
2农夫山泉有点甜熊猫专杀
阿杜特洛夫斯基 - 2007-2-5 10:01:00
引用:
【Ahtiman的贴子】我觉得以下的有问题,先别乱删,有可能我搞错~
O4 - HKLM\..\Run: [MyIE2] C:\WINDOWS\my.exe
O4 - HKLM\..\Run: [CONFIG] C:\WINDOWS\gmm_my.exe
O4 - HKCU\..\Run: [svcshare] C:\WINDOWS\system32\drivers\spoclsv.exe
O4 - HKCU\..\Run: [wj12ulsx1v] C:\WINDOWS\winlog0n.exe
O4 - HKCU\..\Run: [wj12ulsx1v] C:\WINDOWS\winlog0n.exe
O4 - HKCU\..\Run: [w] C:\WINDOWS\iexpl0re.exe
………………


如果有打印机O4 - HKCU\..\Run: [svcshare] C:\WINDOWS\system32\drivers\spoclsv.exe
这个可以先不忙删除,其他的应该立即结束进程、删除,明显的路径不正确。


lh22397908 - 2007-2-5 10:05:00
【回复“水树雨下”的帖子】



lh22397908 - 2007-2-5 10:06:00
【回复“lh22397908”的帖子】
哪个拒绝访问的是什么东西  是不是不能撤除啊
lh22397908 - 2007-2-5 10:31:00
Logfile of HijackThis v1.99.1
Scan saved at 10:12:01, on 2007-2-5
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Administrator\桌面\HijackThis.exe

R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
O2 - BHO: AssistHelper - {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} - C:\Program Files\Yahoo!\Assistant\Assist\yassist.dll
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4A40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MyIE2] C:\WINDOWS\my.exe
O4 - HKLM\..\Run: [CONFIG] C:\WINDOWS\gmm_my.exe
O4 - HKLM\..\Run: [IEXPlORER] C:\WINDOWS\goodrack.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [w] C:\WINDOWS\iexpl0re.exe
O4 - HKCU\..\Run: [7h5yx3zce] C:\WINDOWS\system.exe
O4 - HKCU\..\Run: [svc] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\kwatlog.exe
O4 - HKCU\..\Run: [wj12ulsx1v] C:\WINDOWS\winlog0n.exe
O4 - HKCU\..\Run: [svcshare] C:\WINDOWS\system32\drivers\spoclsv.exe
O8 - Extra context menu item: &使用迅雷下载 - d:\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\QQ\AddEmotion.htm
O8 - Extra context menu item: 添加到雅虎订阅(&Y) - res://C:\Program Files\Yahoo!\Assistant\Assist\yrss.dll/YRSSMENUEXT
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\QQ\SendMMS.htm
O8 - Extra context menu item: 雅虎搜索 - res://C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll/203
O9 - Extra button: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/start.htm?source=yzs_icon&btn=yassistnew (file missing)
O16 - DPF: {E847C78C-C210-4195-8799-FBF3BF89797D} (金山毒霸在线产品升级) - http://www.duba.net/cab/KOSInit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0038B4BA-9281-4B04-B278-5DE5AF75287A}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{89070DFC-B5F9-4619-8FE1-535705060A7E}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{0038B4BA-9281-4B04-B278-5DE5AF75287A}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{0038B4BA-9281-4B04-B278-5DE5AF75287A}: NameServer = 61.128.128.68,61.128.192.68
O23 - Service: Internet Protector System Service (InternetProtectorService) - Unknown owner - D:\LiDong\iNet Protector\IProtectorService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe



附件: 639481200725102151.jpg
水树雨下 - 2007-2-5 10:35:00
引用:
【lh22397908的贴子】【回复“lh22397908”的帖子】
哪个拒绝访问的是什么东西  是不是不能撤除啊
………………

自己看说明,用
1农夫山泉有点甜威金专杀.zip
2农夫山泉有点甜熊猫专杀

lh22397908 - 2007-2-5 10:38:00
我现在已经杀完了 为什么还是自己不段的重新启动啊`!
开机就自己重启动了`!
lh22397908 - 2007-2-5 11:01:00
我重装的瑞星升级了 在杀毒 杀半又自动消失了
点不点不开了`!!我现在正在重新启动试下~!
lh22397908 - 2007-2-5 13:08:00
我进入带网络的安全模式下
就没有iexpl0re.exe
mopery - 2007-2-5 13:17:00
O4 - HKCU\..\Run: [svcshare] C:\WINDOWS\system32\drivers\spoclsv.exe
O4 - HKLM\..\Run: [load] C:\WINDOWS\uninstall\rundl132.exe

这俩文件还在的话 发送 bin59420@yahoo.com.cn

修复
O4 - HKLM\..\Run: [MyIE2] C:\WINDOWS\my.exe
O4 - HKLM\..\Run: [CONFIG] C:\WINDOWS\gmm_my.exe
O4 - HKLM\..\Run: [IEXPlORER] C:\WINDOWS\goodrack.exe
O4 - HKCU\..\Run: [w] C:\WINDOWS\iexpl0re.exe
O4 - HKCU\..\Run: [7h5yx3zce] C:\WINDOWS\system.exe
O4 - HKCU\..\Run: [wj12ulsx1v] C:\WINDOWS\winlog0n.exe
O4 - HKCU\..\Run: [wj12ulsx1v] C:\WINDOWS\winlog0n.exe
删除以上文件..
lh22397908 - 2007-2-5 14:52:00
【回复“mopery”的帖子】
我把我不认识的全部栓出了  现在不重起了比较正常了
---------------------------------现在扫出来的
Logfile of HijackThis v1.99.1
Scan saved at 14:39:41, on 2007-2-5
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
D:\360safe\safemon\360tray.exe
C:\WINDOWS\System32\alg.exe
D:\LiDong\iNet Protector\IProtectorService.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
d:\Rising\Rav\CCenter.exe
d:\Rising\Rav\RAVTASK.EXE
D:\Rising\Rav\Ravmond.exe
D:\Rising\Rav\RavStub.exe
D:\Rising\Rav\RavMon.exe
C:\Documents and Settings\Administrator\桌面\HijackThis.exe

O1 - Hosts: 221.231.140.199 www.781999.com
O2 - BHO: NavigatMon Class - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} - D:\360safe\safemon\safemon.dll
O4 - HKLM\..\Run: [360Safetray] D:\360safe\safemon\360tray.exe
O4 - HKLM\..\Run: [RavTask] "d:\Rising\Rav\RavTask.exe" -system
O8 - Extra context menu item: &使用迅雷下载 - d:\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Thunder\Program\GetAllUrl.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{0038B4BA-9281-4B04-B278-5DE5AF75287A}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{89070DFC-B5F9-4619-8FE1-535705060A7E}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{0038B4BA-9281-4B04-B278-5DE5AF75287A}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{0038B4BA-9281-4B04-B278-5DE5AF75287A}: NameServer = 61.128.128.68,61.128.192.68
O23 - Service: Internet Protector System Service (InternetProtectorService) - Unknown owner - D:\LiDong\iNet Protector\IProtectorService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - d:\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\Rising\Rav\Ravmond.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

lh22397908 - 2007-2-5 14:56:00
不好意思我全部撤除了`!
我想问一下我进呈里面有个---(iprotectorservice.EXE)
这个怎么卸载  有这个进程我就上不去网  无法打开网络~!
在带网络的安全模式下才可以上网
正常登陆上不起
sanjingshou - 2007-2-5 15:56:00
修复:O1 - Hosts: 221.231.140.199 www.781999.com
O23 - Service: Internet Protector System Service (InternetProtectorService) - Unknown owner - D:\LiDong\iNet Protector\IProtectorService.exe
删除文件: D:\LiDong\iNet Protector\IProtectorService.exe
1
查看完整版本: 我才买的盒装2007瑞星 就这样被栓掉了....?