12   1  /  2  页   跳转

求助!!!一定看看啊啊

求助!!!一定看看啊啊

我的电脑中招了,好象是因为进了不健康的网站,这几天每次开机都会发现病毒的,好象是木马啊,哪位高手帮帮忙啊!!
这是日志:
HijackThis@Qoo的扫描日志  V1.97.7
Scan saved at 6:45:50, on 2005-9-17
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
E:\PROGRAM FILES\RISING\RAV\Ravmond.exe
E:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\P4P\p2psvr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\rundll32.exe
E:\Program Files\Winamp\winampa.exe
E:\PROGRA~1\Maxthon\THUNDE~1\ThunderMini.exe
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\system32\BCUP.exe
E:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
E:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\WINDOWS\etb\pokapoka67.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
E:\Program Files\Skype\Phone\Skype.exe
E:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\Program Files\DuDu\DDDClient\dudupros.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\China.exe
C:\WINDOWS\China.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\RUNDLL32.exe
E:\PROGRA~1\RISING\RAV\Rav.exe
E:\Program Files\Tencent\TT\TTraveler.exe
C:\Program Files\WinRAR\WinRAR.exe
e:\PROGRA~1\Tencent\TT\TCPlus.exe
C:\Program Files\BitComet\BitComet.exe
C:\DOCUME~1\a\LOCALS~1\Temp\Rar$EX04.062\HijackThis.exe
C:\Program Files\WinRAR\WinRAR.exe

R3 - URLSearchHook: MyURLSearchHook Class - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - C:\PROGRA~1\P4P\Toolbar.dll
O2 - BHO: (no name) - {002AF282-E42D-4B51-9F70-F1570C02FAAD} - C:\Progra~1\NetMeting\Target\0.9.0.5\Target.dll
O2 - BHO: (no name) - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\WINDOWS\Downloaded Program Files\TBHMain.dll
O2 - BHO: (no name) - {6BDE1669-B490-48E3-B668-456314F2D6C3} - C:\Program Files\DuDu\DddClient\dddiemon.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\CnsHook.dll
O3 - Toolbar: ????? - {DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} - C:\PROGRA~1\P4P\Toolbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [MoveSearch] C:\PROGRA~1\wsearch\Search.exe
O4 - HKLM\..\Run: [WinampAgent] e:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [thunder_mini] E:\PROGRA~1\Maxthon\THUNDE~1\ThunderMini.exe
O4 - HKLM\..\Run: [迅雷4] C:\Program Files\Sandai Technologies Inc\Thunder\thunder.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [YDTMain.exe] C:\PROGRA~1\YDT\YDTMain.exe
O4 - HKLM\..\Run: [BCUpdate] C:\WINDOWS\system32\BCUP.exe
O4 - HKLM\..\Run: [RavTimer] E:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] E:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [SysExplr] e:\Herosoft\HeroV9\SYSEXPLR.EXE
O4 - HKLM\..\Run: [System service67] C:\WINDOWS\etb\pokapoka67.exe
O4 - HKLM\..\Run: [System service66] C:\WINDOWS\etb\pokapoka66.exe
O4 - HKLM\..\Run: [KsgUpdateRun] C:\Program Files\Common Files\kingsoft\KSG\client.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfnom.exe] C:\WINDOWS\SVOHOST.exe
O4 - HKCU\..\Run: [KavPFW] "E:\Temp\KavPFW.exe"
O4 - HKCU\..\Run: [Skype] "E:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: NTUSER.DAT
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Startup: regproduct.ini
O4 - Global Startup: ntuser.dat
O4 - Global Startup: ntuser.dat.LOG
O8 - Extra context menu item: &使用迷你迅雷下载 - E:\PROGRA~1\Maxthon\THUNDE~1\geturl.htm
O8 - Extra context menu item: 使用搜狗直通车下载 - C:\PROGRA~1\P4P\dl.htm
O8 - Extra context menu item: 使用超级解霸播放 - e:\Herosoft\HeroV9\MPURLGET.HTM
O8 - Extra context menu item: 发送图片到手机 - C:\PROGRA~1\P4P\cx.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\Program Files\Tencent\qq\SendMMS.htm
O9 - Extra button: SoQ (HKLM)
O11 - Options group: [!CNS] 
O11 - Options group: [!MySearch]
O11 - Options group: [TBH] QQ
O16 - DPF: v3cab - http://searchmiracle.com/cab/13.cab
O16 - DPF: {31DDC1FD-CEA3-4837-A6DC-87E67015ADC9} - http://akamai.downloadv3.com/binaries/IA/svcsysnet32_EN_XP.cab
O16 - DPF: {32505657-9980-0010-8000-00AA00389B71} - http://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} - http://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {BA0F088C-72C1-475A-92F8-42391DEF6961} - http://www.bliao.com/download/blueskyvoice_27.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O16 - DPF: {F138084D-84D7-48CD-BEA8-04772457516E} (VqqSpeedDlProxy Class) - http://218.85.138.27/vqqsdl1009.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} (pCastPanel Class) - http://pcastdl.dudu.com/files/pCastCtl.cab

最后编辑2005-09-18 13:18:45
分享到:
gototop
 

日志太旧,用1.99.1在扫描下

照你现在的log,因为你没说病毒路径,只能猜了
O2 - BHO: (no name) - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\WINDOWS\Downloaded Program Files\TBHMain.dll

O4 - HKLM\..\Run: [MoveSearch] C:\PROGRA~1\wsearch\Search.exe
O4 - HKLM\..\Run: [YDTMain.exe] C:\PROGRA~1\YDT\YDTMain.exe
O4 - HKLM\..\Run: [System service67] C:\WINDOWS\etb\pokapoka67.exe
O4 - HKLM\..\Run: [System service66] C:\WINDOWS\etb\pokapoka66.exe
O4 - HKCU\..\Run: [ctfnom.exe] C:\WINDOWS\SVOHOST.exe
修复上面
删除

先结束conime.exe 进程

C:\WINDOWS\Downloaded Program Files\TBHMain.dll

C:\PROGRA~1\wsearch
C:\PROGRA~1\YDT
C:\WINDOWS\etb
C:\WINDOWS\SVOHOST.exe


在你的log里还看到了BCUP.exe
关闭所有IE。

.使用任务管理器删除BCUP.exe进程。

.打开运行,执行regsvr32 -u c:\系统目录\BoCaiToolBar.dll

.进入系统目录。
(winxp:\\WINDOWS\system32)
(win2000:\\winnt\system32)
(win98:\\windows\system)
.删除BCUP.exe,删除BoCaiToolBall.DLL

.打开注册表编辑器

删除HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BCUpdate

.删除HKEY_LOCAL_MACHINE\SOFTWARE\BlogChina\BC]

PS:记住要关闭所有的IE浏览器,不然无效,记不住复制在记事本里


自己卸载3721以及dudu
gototop
 

偶怕麻烦,看你那日志。呵呵
不过,普通木马病毒清除也就那么几个套路:
1 检查启动项
  把杀毒软件 防火墙 ctfmon 保留,其他统统干掉
2 检查系统自启动服务
  注意:只有看那些启动类型为自动的,逐一检查,宿主程序一看就知道。可疑的停掉,改为手动或者禁用(建议先改手动,以防万一)
3 以上还不能搞定的话,那大多是比较阴险的后门了。什么插入系统进程,隐藏服务,驱动加载啦。不用担心,用icesworld检查一下,红色显示的注意喽(瑞星,卡巴,3721在里面也显示红色,别误删!)

以上是手工查杀,如果你想靠杀毒软件自动来,我没什么好说,只有几个经验。(很多时候靠软件是不能根除的,软件再厉害能比人聪明?放着你那小脑袋瓜不用不是极大的浪费嘛!)
a 安全模式下杀毒 (对付驱动加载没用)
b 正常模式下,断网,用任务管理器结束一切可能的进程,包括explorer.exe(windows外壳程序),再杀。
c 有些删不掉的,可以在命令提示符下删除,或者用killbox删除。(对于任何删除操作请确认你有足够把握,否则先备份)


末了再让我来说说conime.exe这个进程到底是怎么回事吧."邪恶八进制安全团队"有专门讨论过这个进程。此进程跟输入法是有关的,它是在你使用命令行下切换输入法后才出现的。有兴趣的可自己测试。属于系统正常进程。(病毒破坏除外)
gototop
 

谢谢两位了,命运里の金色!不好意思,你写了那么多,我还是不知道怎么弄啊,我把信息弄的详细一点,帮忙在看看啊.感激ing……
病毒路径:
病毒名称处理结果发现日期扫描方式路径文件病毒来源
Trojan.Dialer.l删除成功05-09-18 10:40手动扫描C:\WINDOWSChina.exe本机
Trojan.Dialer.l删除成功05-09-18 10:42手动扫描C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\QLMZIHSTChina[2].exe本机
Trojan.Dialer.l删除成功05-09-18 10:42手动扫描C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\6X2H07IVChina[1].exe本机
Trojan.Dialer.l删除成功05-09-18 10:43手动扫描C:\Documents and Settings\a\Local Settings\Temporary Internet Files\Content.IE5\770J2YWUChina[1].exe本机
Trojan.Dialer.l删除成功05-09-18 10:50手动扫描C:\System Volume Information\_restore{9EC06397-E6CE-4CE5-9F4A-B40014241767}\RP74A0043074.exe本机
Backdoor.Gpigeon.pi清除成功05-09-18 11:58手动扫描C:\Program Files\Internet Explorer\IEXPLORE.EXEIEXPLORE.EXE>>C:\Program Files\Internet Explorer\IEXPLORE.EXE本机
gototop
 

引用:
【卡不基诺的贴子】谢谢两位了,命运里の金色!不好意思,你写了那么多,我还是不知道怎么弄啊,我把信息弄的详细一点,帮忙在看看啊.感激ing……
病毒路径:
病毒名称处理结果发现日期扫描方式路径文件病毒来源
Trojan.Dialer.l删除成功05-09-18 10:40手动扫描C:\WINDOWSChina.exe本机
Trojan.Dialer.l删除成功05-09-18 10:42手动扫描C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\QLMZIHSTChina[2].exe本机
Trojan.Dialer.l删除成功05-09-18 10:42手动扫描C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\6X2H07IVChina[1].exe本机
Trojan.Dialer.l删除成功05-09-18 10:43手动扫描C:\Documents and Settings\a\Local Settings\Temporary Internet Files\Content.IE5\770J2YWUChina[1].exe本机
Trojan.Dialer.l删除成功05-09-18 10:50手动扫描C:\System Volume Information\_restore{9EC06397-E6CE-4CE5-9F4A-B40014241767}\RP74A0043074.exe本机
Backdoor.Gpigeon.pi清除成功05-09-18 11:58手动扫描C:\Program Files\Internet Explorer\IEXPLORE.EXEIEXPLORE.EXE>>C:\Program Files\Internet Explorer\IEXPLORE.EXE本机

...........................
你中了灰鸽子的变种,请用hijackthis1.99.1扫描下电脑,把日志贴上来

C:\Documents and Settings\a\Local Settings\Temporary Internet Files\Content.IE5这个下面的毒照图的做,就可以删除

附件附件:

下载次数:0
文件类型:image/pjpeg
文件大小:
上传时间:2005-9-18 12:45:01
描述:



gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 12:29:08, on 2005-9-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
E:\PROGRAM FILES\RISING\RAV\Ravmond.exe
E:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\P4P\p2psvr.exe
E:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\wsearch\Search.exe
E:\PROGRA~1\Maxthon\THUNDE~1\ThunderMini.exe
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\system32\BCUP.exe
E:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
E:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\WINDOWS\etb\pokapoka68.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
E:\Program Files\Tencent\TT\TTraveler.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Microsoft Office\Office\EXCEL.EXE
C:\Program Files\Qyule\Qyule.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\a\LOCALS~1\Temp\Rar$EX00.094\HijackThis.exe
C:\WINDOWS\notepad.exe

R3 - URLSearchHook: MyURLSearchHook Class - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - C:\PROGRA~1\P4P\Toolbar.dll
F2 - REG:system.ini: Shell=Explorer.exe commamd.exe
O2 - BHO: Target Class - {002AF282-E42D-4B51-9F70-F1570C02FAAD} - C:\Progra~1\NetMeting\Target\0.9.0.5\Target.dll
O2 - BHO: Tencent Browser Helper - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\WINDOWS\Downloaded Program Files\TBHMain.dll
O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\system32\qylhelper.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\CnsHook.dll
O2 - BHO: InsIII - {DDDE2452-AF9E-4577-AE6C-465DBCB54D49} - C:\WINDOWS\system32\rtsapi16.dll
O3 - Toolbar: 捜狗直通车 - {DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} - C:\PROGRA~1\P4P\Toolbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [MoveSearch] C:\PROGRA~1\wsearch\Search.exe
O4 - HKLM\..\Run: [WinampAgent] e:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [thunder_mini] E:\PROGRA~1\Maxthon\THUNDE~1\ThunderMini.exe
O4 - HKLM\..\Run: [迅雷4] C:\Program Files\Sandai Technologies Inc\Thunder\thunder.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [YDTMain.exe] C:\PROGRA~1\YDT\YDTMain.exe
O4 - HKLM\..\Run: [BCUpdate] C:\WINDOWS\system32\BCUP.exe
O4 - HKLM\..\Run: [RavTimer] E:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] E:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [System service67] C:\WINDOWS\etb\pokapoka68.exe
O4 - HKLM\..\Run: [System service66] C:\WINDOWS\etb\pokapoka66.exe
O4 - HKLM\..\Run: [System service68] C:\WINDOWS\etb\pokapoka68.exe
O4 - HKLM\..\Run: [KsgUpdateRun] C:\Program Files\Common Files\kingsoft\KSG\client.exe
O4 - HKLM\..\Run: [ClientQyule] C:\Program Files\Qyule\Qyule.exe
O4 - HKLM\..\RunOnce: [ClientQyule] C:\Program Files\Qyule\qyule.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfnom.exe] C:\WINDOWS\SVOHOST.exe
O4 - HKCU\..\Run: [KavPFW] "E:\Temp\KavPFW.exe"
O4 - HKCU\..\Run: [Skype] "E:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ClientQyule] C:\Program Files\Qyule\Qyule.exe
O4 - HKCU\..\RunOnce: [ClientQyule] C:\Program Files\Qyule\qyule.exe
O4 - Startup: 青娱乐.lnk = C:\Program Files\Qyule\Qyule.exe
O4 - Global Startup: 青娱乐.lnk = C:\Program Files\Qyule\Qyule.exe
O8 - Extra context menu item: &使用迷你迅雷下载 - E:\PROGRA~1\Maxthon\THUNDE~1\geturl.htm
O8 - Extra context menu item: 使用搜狗直通车下载 - C:\PROGRA~1\P4P\dl.htm
O8 - Extra context menu item: 使用超级解霸播放 - e:\Herosoft\HeroV9\MPURLGET.HTM
O8 - Extra context menu item: 发送图片到手机 - C:\PROGRA~1\P4P\cx.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\Program Files\Tencent\qq\SendMMS.htm


gototop
 

O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm?pid=U_flashget_62580 (file missing)
O9 - Extra button: 豪杰超级解霸V9 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - e:\Herosoft\HeroV9\STHSDVD.EXE
O9 - Extra 'Tools' menuitem: 豪杰超级解霸V9 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - e:\Herosoft\HeroV9\STHSDVD.EXE
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: SoQ - {8F67DCF3-B1DF-4A39-A787-3775784BF737} - http://www.soq.com (file missing)
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - e:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - e:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O11 - Options group: [!CNS]  网络实名
O11 - Options group: [!MySearch] 搜索助手(MySearch)
O11 - Options group: [TBH] QQ地址栏搜索
O16 - DPF: v3cab - http://searchmiracle.com/cab/13.cab
O16 - DPF: {31DDC1FD-CEA3-4837-A6DC-87E67015ADC9} - http://akamai.downloadv3.com/binaries/IA/svcsysnet32_EN_XP.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {BA0F088C-72C1-475A-92F8-42391DEF6961} - http://www.bliao.com/download/blueskyvoice_27.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O16 - DPF: {F138084D-84D7-48CD-BEA8-04772457516E} (VqqSpeedDlProxy Class) - http://218.85.138.27/vqqsdl1009.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} (pCastPanel Class) - http://pcastdl.dudu.com/files/pCastCtl.cab
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\system32\mbprot.dll
O18 - Protocol: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll
O18 - Protocol: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\System32\wiascr.dll
O18 - Filter: text/html - {65CBAF77-19CA-4B81-86D5-7835D59BEA85} - C:\WINDOWS\System32\SoMP3.dll
O20 - AppInit_DLLs: C:\WINDOWS\System32\SoDAHK.DLL
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: P4P Service - Sohu.com Inc. - C:\Program Files\P4P\p2psvr.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - E:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - Service: 日志自动生成器2.0 - Unknown owner - C:\WINDOWS\G_Server2.0.exe
gototop
 

O23 - Service: 日志自动生成器2.0 - Unknown owner - C:\WINDOWS\G_Server2.0.exe
灰鸽子的说
请参考http://forum.ikaka.com/topic.asp?board=28&artid=6202404
gototop
 

另外,每次开机都会出现提示找不到command.exe文件的对话框,
gototop
 

手工清除:
1、开始-->运行-->cmd(打开命令提示符)
2、dir autorun.inf /a (没有参数a是看不到的,a是显示所有的意思),此时你会发现一个autorun.inf文件,约49字节。
3、attrib autorun.inf -s -h -r 去掉autorun.inf文件的系统、只读、隐藏属性,否则无法删除。
4、del autorun.inf
到这里还没完,因为你双击了D盘盘符没有打开却得到一个错误。要求定位command.exe,这个时候自动运行的信息已经加入注册表了。
5、清除注册表中
(1)开始-->运行-->regedit-->编辑-->查找-->command.exe
找到的第一个就是C盘的自动运行,删除整个shell子键
(2)F3,重复操作,处理其他盘符
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT