瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 高手,求助呀,好象是中了灰鸽子病毒了

1   1  /  1  页   跳转

高手,求助呀,好象是中了灰鸽子病毒了

高手,求助呀,好象是中了灰鸽子病毒了


   小弟是新手,今天启动机子怎么也启动不起来,一出现桌面就死机,现在还在安全模式里面上的,我用HijackThis1.99.1扫描注册表,可小弟看不懂,请高手帮帮忙

下面是我扫描的注册表
Logfile of HijackThis v1.99.1
Scan saved at 14:44:32, on 2005-9-26
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\ctfmon.exe
D:\WINDOWS\System32\Rundll32.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\WinRAR\WinRAR.exe
D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX21.422\HijackThis.exe

R3 - URLSearchHook: MyURLSearchHook Class - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - D:\PROGRA~1\P4P\Toolbar.dll
O1 - Hosts: 61.129.88.171 www.tom789.com
O1 - Hosts: 61.129.88.171 tom789.com
O1 - Hosts: 61.129.88.171 www.ok8080.comwww.15002.com
O1 - Hosts: 61.129.88.171 ok8080.comwww.15002.com
O1 - Hosts: 61.129.88.171 www.dy1861.com
O1 - Hosts: 61.129.88.171 dy1861.com
O1 - Hosts: 61.129.88.171 www.jqdy365.net
O1 - Hosts: 61.129.88.171 jqdy365.net
O1 - Hosts: 61.129.88.171 www.2000qq.com
O1 - Hosts: 61.129.88.171 2000qq.com
O1 - Hosts: 61.129.88.171 www.wz518.net
O1 - Hosts: 61.129.88.171 wz518.net
O1 - Hosts: 61.129.88.171 www.spliao8.com
O1 - Hosts: 61.129.88.171 spliao8.com
O1 - Hosts: 61.129.88.171 www.7t7t.com
O1 - Hosts: 61.129.88.171 7t7t.com
O1 - Hosts: 61.129.88.171 www.bfa.edu.cn
O1 - Hosts: 61.129.88.171 bfa.edu.cn
O1 - Hosts: 61.129.88.171 www.xiaobaidu.com
O1 - Hosts: 61.129.88.171 xiaobaidu.com
O1 - Hosts: 61.129.88.171 www.pvod.com
O1 - Hosts: 61.129.88.171 pvod.com
O1 - Hosts: 61.129.88.171 www.168111.com
O1 - Hosts: 61.129.88.171 168111.com
O1 - Hosts: 61.129.88.171 www.667ww.com
O1 - Hosts: 61.129.88.171 667ww.com
O1 - Hosts: 61.129.88.171 www.kk369.net
O1 - Hosts: 61.129.88.171 kk369.net
O1 - Hosts: 61.129.88.171 www.h123ok.com
O1 - Hosts: 61.129.88.171 h123ok.com
O1 - Hosts: 61.129.88.171 www.dy808.com
O1 - Hosts: 61.129.88.171 dy808.com
O1 - Hosts: 61.129.88.171 www.80066.com
O1 - Hosts: 61.129.88.171 80066.com
O1 - Hosts: 61.129.88.171 www.ziyue.com
O1 - Hosts: 61.129.88.171 ziyue.com
O1 - Hosts: 61.129.88.171 www.siff.com
O1 - Hosts: 61.129.88.171 siff.com
O1 - Hosts: 61.129.88.171 www.junwang-china.com
O1 - Hosts: 61.129.88.171 junwang-china.com
O1 - Hosts: 61.129.88.171 www.hengshui.com
O1 - Hosts: 61.129.88.171 hengshui.com
O1 - Hosts: 61.129.88.171 www.shoududianyingyuan.com.cn
O1 - Hosts: 61.129.88.171 shoududianyingyuan.com.cn
O1 - Hosts: 61.129.88.171 www.tvb.com.cn
O1 - Hosts: 61.129.88.171 tvb.com.cn
O1 - Hosts: 61.129.88.171 www.korea-av.com
O1 - Hosts: 61.129.88.171 korea-av.com
O1 - Hosts: 61.129.88.171 www.shanzei.com
O1 - Hosts: 61.129.88.171 shanzei.com
O1 - Hosts: 61.129.88.171 www.avqq.com
O1 - Hosts: 61.129.88.171 avqq.com
O1 - Hosts: 61.129.88.171 www.love.sokr.net
O1 - Hosts: 61.129.88.171 love.sokr.net
O1 - Hosts: 61.129.88.171 www.94tvb.com
O1 - Hosts: 61.129.88.171 94tvb.com
O1 - Hosts: 61.129.88.171 www.mfk8.com
O1 - Hosts: 61.129.88.171 mfk8.com
O1 - Hosts: 61.129.88.171 www.film21cn.com
O1 - Hosts: 61.129.88.171 film21cn.com
O1 - Hosts: 61.129.88.171 www.dvd.net.cn
O1 - Hosts: 61.129.88.171 dvd.net.cn
O1 - Hosts: 61.129.88.171 www.chinese-girl.net
O1 - Hosts: 61.129.88.171 chinese-girl.net
O1 - Hosts: 61.129.88.171 www.517tg.net
O1 - Hosts: 61.129.88.171 517tg.net
O1 - Hosts: 61.129.88.171 www.8848wg.com
O1 - Hosts: 61.129.88.171 8848wg.com
O1 - Hosts: 61.129.88.171 www.tomfilm.net
O1 - Hosts: 61.129.88.171 tomfilm.net
O1 - Hosts: 61.129.88.171 www.hot57.com
O1 - Hosts: 61.129.88.171 hot57.com
O1 - Hosts: 61.129.88.171 www.music9999.com
O1 - Hosts: 61.129.88.171 music9999.com
O1 - Hosts: 61.129.88.171 www.jx263.com
O1 - Hosts: 61.129.88.171 jx263.com
O1 - Hosts: 61.129.88.171 www.666ccc.com
O1 - Hosts: 61.129.88.171 666ccc.com
O1 - Hosts: 61.129.88.171 www.liu6.com
O1 - Hosts: 61.129.88.171 liu6.com
O1 - Hosts: 61.129.88.171 www.poptang.com
O1 - Hosts: 61.129.88.171 poptang.com
O1 - Hosts: 61.129.88.171 www.maoxiandao.com
O1 - Hosts: 61.129.88.171 maoxiandao.com
O1 - Hosts: 61.129.88.171 www.qq65.com
O1 - Hosts: 61.129.88.171 qq65.com
O1 - Hosts: 61.129.88.171 www.zhao123.com
O1 - Hosts: 61.129.88.171 zhao123.com
O1 - Hosts: 61.129.88.171 www.4399.com
O1 - Hosts: 61.129.88.171 4399.com
O1 - Hosts: 61.129.88.171 www.chinagames.net
O1 - Hosts: 61.129.88.171 chinagames.net
O1 - Hosts: 61.129.88.171 www.tiexue.net
O1 - Hosts: 61.129.88.171 tiexue.net
O1 - Hosts: 61.129.88.171 www.qq163.com
O1 - Hosts: 61.129.88.171 qq163.com
O1 - Hosts: 61.129.88.171 www.tt67.com
O1 - Hosts: 61.129.88.171 tt67.com
O1 - Hosts: 61.129.88.171 www.chinamp3.com
O1 - Hosts: 61.129.88.171 chinamp3.com
O1 - Hosts: 61.129.88.171 www.pg168.com
O2 - BHO: SohuDAIEHelper - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - D:\Program Files\P4P\sodaie.dll
O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - D:\WINDOWS\System32\CdnIEHlp.dll (file missing)
O2 - BHO: QQBrowserHelperObject Class - {54EBD53A-9BC1-480B-966A-843A333CA162} - E:\引玉资料\QQIEHelper.dll
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - (no file)
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - D:\WINDOWS\system32\stdup.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\zh-cn\msntb.dll
O2 - BHO: CnsHook Class - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: (no name) - {06ABAA2D-34AB-4902-A326-409BD9B9A7A5} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\zh-cn\msntb.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 虎翼DIY吧! - {0A00D11E-B1E7-44b5-AD88-C9190876AAC4} - D:\WINDOWS\System32\diybar2\diybar2.dll
O3 - Toolbar: 天下搜索 - {56A7DC70-E102-4408-A34A-AE06FEF01586} - D:\WINDOWS\Downloaded Program Files\CONFLICT.1\IEBar.dll
O3 - Toolbar: (no name) - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - (no file)
O3 - Toolbar: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - D:\Program Files\3721\Assist\asbar.dll
O3 - Toolbar: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - D:\PROGRA~1\Kingsoft\FASTAI~1\IEBand.dll
O3 - Toolbar: 新浪ViVi收藏夹 - {15DDE989-CD45-4561-BF99-D22C0D5C2B85} - D:\WINDOWS\Downlo~1\vivimin0.dll
O3 - Toolbar: 捜狗直通车 - {DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} - D:\PROGRA~1\P4P\Toolbar.dll
O3 - Toolbar: 金山毒霸 - {A9BE2902-C447-420A-BB7F-A5DE921E6138} - D:\KAV6\KAIEPlus.DLL
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [CApp] D:\WINDOWS\System32\capp.exe
O4 - HKLM\..\Run: [NMGameX_AutoRun] D:\WINDOWS\System32\Rundll32.exe NMGameX.dll,LiveProcess /aa
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [360Main.exe] D:\PROGRA~1\360so\360Main.exe
O4 - HKLM\..\Run: [3721] C:\$NtUninstallQ5926809$\3721.bat
O4 - HKLM\..\Run: [KAVRun] D:\KAV6\KAVRun.EXE
O4 - HKLM\..\Run: [Kulansyn] D:\KAV6\Kulansyn.EXE
O4 - HKLM\..\Run: [KpopMon] D:\KAV6\KpopMon.EXE
O4 - HKLM\..\Run: [RavTimer] D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] D:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [cnyisou_com] http://www.hen30.com
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [WinsSystem] C:\Program Files\Internet Explorer\syssmss.exe
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item:  >> 彩信发送 << - res://D:\PROGRA~1\MMSASS~1\MMSASS~1.DLL/mms.htm
O8 - Extra context menu item: &使用迅雷下载 - D:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\Program Files\Thunder Network\Thunder\getAllurl.htm
O8 - Extra context menu item: 使用搜狗直通车下载 - D:\PROGRA~1\P4P\dl.htm
O8 - Extra context menu item: 使用网际快车下载 - D:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: 发送图片到手机 - D:\PROGRA~1\P4P\cx.htm
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 收藏此页到新浪ViVi - http://vivi.sina.com.cn/collect/click.php?agent=viviband
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\引玉资料\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\引玉资料\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\引玉资料\SendMMS.htm
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm (file missing)
O9 - Extra button: 中文域名 - {35980F6E-A137-4E50-953D-813BB8556899} - D:\WINDOWS\System32\CdnIEHlp.dll (file missing)
O9 - Extra 'Tools' menuitem: 中文域名 - {35980F6E-A137-4E50-953D-813BB8556899} - D:\WINDOWS\System32\CdnIEHlp.dll (file missing)
O9 - Extra button: (no name) - {3F686D91-4AFA-4ed1-B43F-F1DB46ED480C} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Link Filter - {3F686D91-4AFA-4ed1-B43F-F1DB46ED480C} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
最后编辑2005-09-26 17:00:13
分享到:
gototop
 

O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: 金山卓越 - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - url:http://www.joyo.com (file missing)
O9 - Extra button: SoQ - {8F67DCF3-B1DF-4A39-A787-3775784BF737} - http://www.soq.com (file missing)
O9 - Extra button: 百度搜索伴侣 - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - D:\WINDOWS\DOWNLO~1\BDSrHook.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\引玉资料\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\引玉资料\QQ.EXE
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-219?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O9 - Extra 'Tools' menuitem: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-219?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\引玉资料\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\引玉资料\QQIEHelper.dll
O9 - Extra button: 金山毒霸网站 - {e1fc9760-7b95-49cd-80b9-8c9e41017b93} - url:http://www.duba.net (file missing)
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: 在线查毒 - {f58d36c3-40be-4418-a786-d8fbe3eb3554} - D:\KAV6\kavie.HTM
O9 - Extra button: Start spyware remover - {BF69DF00-2734-477F-8257-27CD04F88779} - D:\Program Files\WareOut\WareOut.exe (HKCU)
O9 - Extra 'Tools' menuitem: Start spyware remover - {BF69DF00-2734-477F-8257-27CD04F88779} - D:\Program Files\WareOut\WareOut.exe (HKCU)
O11 - Options group: [!CNS]  上网助手-地址栏搜索
O11 - Options group: [!IESearch] !IESearch
O11 - Options group: [!MySearch] 搜索助手(MySearch)
O15 - Trusted Zone: http://*.63.219.181.7
O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d:oo.mht!http://195.95.218.83/users/sale/web/axe/x.chm::/update.exe
O16 - DPF: {15DDE989-CD45-4561-BF99-D22C0D5C2B74} - http://image2.sina.com.cn/home/ddtsource/ddt.cab
O16 - DPF: {15DDE989-CD45-4561-BF99-D22C0D5C2B85} (新浪ViVi收藏夹) - http://image2.sina.com.cn/pfp/iweb/vivimin.cab
O16 - DPF: {28E0FA88-ABA8-4937-A247-3031F1A11165} (Installer Class) - http://dl.51.net/download/diybar2.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} (天下搜索) - http://iebar.t2t2.com/iebar.cab
O16 - DPF: {58CDB34C-B4D7-418B-A0FB-C4C8A01C2F0E} (DIYBAR) - http://dl.51.net/download/diybar.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1127361906734
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://map.tsinghua.edu.cn:8081/tsinghua/msxml4.cab
O16 - DPF: {98A62E3F-A8C5-4EF0-8A00-C70CF9D18A89} (LoaderCore Class) - http://tb.sogou.com/DLLoader.cab
O16 - DPF: {9A0527C1-4D5F-4E45-9D28-6257F75EDDB1} (IEBHOObj Class) - http://download.imuweb.com/client/chatatwill/ie/imuiepls.cab
O16 - DPF: {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} (BDSrchHook Class) - http://61.129.32.83/baidu/IESearch.cab
O16 - DPF: {C14D003A-DA41-4FEE-8204-62A94EAA29D1} (GLWebAvt Control) - http://bbs.ourgame.com/image/GLWebAvt.cab
O16 - DPF: {C22D6D40-47D8-40FE-825A-CC7F4D88B3B8} - http://download.3721.com/download/inst.ca_
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/ravkill/rsonline.cab
O16 - DPF: {F138084D-84D7-48CD-BEA8-04772457516E} (VqqSpeedDlProxy Class) - http://218.85.138.27/vqqsdl1009.cab
O16 - DPF: {FC87A650-207D-4392-A6A1-82ADBC56FA64} (MultiDist) - http://xbs.mtree.com/mt/dialers/fc/MultiDistFC.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{54513989-4BC1-4B73-9EE9-99C3F98F61BF}: NameServer = 69.50.176.196,195.225.176.110
O17 - HKLM\System\CCS\Services\Tcpip\..\{B5ED57CE-9FB6-4511-BB1D-6ADF88650E77}: NameServer = 69.50.176.196,195.225.176.110
O17 - HKLM\System\CS1\Services\Tcpip\..\{54513989-4BC1-4B73-9EE9-99C3F98F61BF}: NameServer = 69.50.176.156,195.225.176.31
O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer = 69.50.176.196,195.225.176.110
O17 - HKLM\System\CS2\Services\Tcpip\..\{54513989-4BC1-4B73-9EE9-99C3F98F61BF}: NameServer = 69.50.176.196,195.225.176.110
O17 - HKLM\System\CS3\Services\VxD\MSTCP: NameServer = 69.50.176.196,195.225.176.110
O17 - HKLM\System\CS3\Services\Tcpip\..\{54513989-4BC1-4B73-9EE9-99C3F98F61BF}: NameServer = 69.50.176.196,195.225.176.110
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.50.176.196,195.225.176.110
O18 - Protocol: mp3 - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - D:\WINDOWS\DOWNLO~1\BDSrHook.dll
O18 - Filter: text/html - {65CBAF77-19CA-4B81-86D5-7835D59BEA85} - D:\WINDOWS\System32\SoMP3.dll
O18 - Filter: text/plain - {0E055CD7-3823-489A-87F5-7D3027EFA525} - D:\WINDOWS\System32\mcicdb.dll
O20 - AppInit_DLLs: D:\WINDOWS\System32\SoDAHK.DLL
O20 - Winlogon Notify: igfxcui - D:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: C-DillaCdaC11BA - Macrovision - D:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Kingsoft AntiVirus Service (KAVSvc) - kingsoft Antivirus - D:\KAV6\KAVSvc.EXE
O23 - Service: P4P Service - Sohu.com Inc. - D:\Program Files\P4P\p2psvr.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - Service: svhost - Unknown owner - D:\WINDOWS\svhost.exe

  高手告诉我怎么杀呀,,,


gototop
 

是个是鸽子病毒呀
gototop
 

高手指教呀
急呀~~~~~~~~~~~~~~~~!
gototop
 

没人看懂吗???
急死小弟了
gototop
 

O23 - Service: svhost - Unknown owner - D:\WINDOWS\svhost.exe

把这个服务关掉。
gototop
 

O1 - Hosts: 61.129.88.171 www.tom789.com 这是你自己加的吗?如果不是把01项修复。
O4 - HKLM\..\Run: [cnyisou_com] http://www.hen30.com这个去掉
O23 - Service: svhost - Unknown owner - D:\WINDOWS\svhost.exe同5楼一样这个停了
水平有限,别的看不出,你先试试,另外瑞星和另的杀毒软件最好别同时装。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT