瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 高手进来看看!!!!!【求助】

1234   1  /  4  页   跳转

高手进来看看!!!!!【求助】

高手进来看看!!!!!【求助】

我不知道该怎么办,电脑里好象是进了病毒,我的瑞星被强行关闭,我再也打不开我的瑞星进行杀毒工作,我该怎么办?杀也杀不掉,我还能勉强上网,但是所有的密码我都不敢打入,这个是什么病毒啊!!杀都杀不掉?我该怎么办?是不是只能重装系统啊? 有人能告诉我办法吗!!!!!!快啊!  我好急的!
最后编辑2005-10-05 22:53:47
分享到:
gototop
 

【回复“救我!”的帖子】
    哇哇,怎么都没有人告诉我怎么办啊%
  我好惨啊 谁来告诉我我这个是怎么了啊?
    是不是中了“灰鸽子”啊~!!!!
我才14岁啊,小孩子不懂啊,求求你们啊,各位大哥大姐
  总该告诉我我这个是中的什么病毒吧?
gototop
 

小MM,先看看“金色”的帖子。
gototop
 

呵呵—谢谢啊……我在看啊
但愿我能静下心来——
555想到我的电脑是这样就想哭啊————
gototop
 

怎样强行关闭啊??开机有吗?
gototop
 

用hijackthis扫描后,把日志贴上来
gototop
 

谢谢你,我正在搞,等下我想,我就能知道是什么弄坏了我的电脑了!

擦干眼泪!加油!
gototop
 

这个是日志吗?哥哥姐姐门啊帮帮我……
我很感激!·!!!

Logfile of HijackThis v1.99.2
Scan saved at 13:19:14, on 2005-10-3
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CNNIC\Cdn\cdnup.exe
C:\WINNT\system32\internat.exe
C:\WINNT\system32\conime.exe
D:\TT\TTraveler.exe
C:\DOCUME~1\l\LOCALS~1\Temp\HijackThis.exe
C:\WINNT\system32\Rundll32.exe

O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O2 - BHO: (no name) - {35980F6E-A137-4E50-953D-813BB8556899}? - (no file)
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\QQ\QQIEHelper.dll
O2 - BHO: (no name) - {6E28339B-7A2A-47B6-AEB2-46BA53782373}? - (no file)
O2 - BHO: BrowserHAP Class - {AEF6F648-78D8-4456-BEE7-5ADE23D209FD} - C:\Program Files\HBClient\hapast.dll
O2 - BHO: (no name) - {CE7C3CF0-4B15-11D1-ABED-709549C10000}? - (no file)
O2 - BHO: (no name) - {D032570A-5F63-4812-A094-87D007C23012}? - (no file)
O2 - BHO: (no name) - {F5824EFB-728A-4726-A5A5-85A68B20EDC3}? - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\BitComet\BitCometBar\BitCometBar0.1.dll
O3 - Toolbar: 网络钓鱼克星 - {954F618B-0DEC-4D1A-9317-E0FC96F87865} - C:\WINNT\system32\MainIEBand.dll
O3 - Toolbar: 卡卡安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINNT\system32\kakatool.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [ClientQyule] C:\Program Files\Qyule\Qyule.exe
O4 - HKLM\..\Run: [usbn] C:\WINNT\system32\usbn.exe -go -c20 -w1
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - HKLM\..\Run: [NetUpdate] C:\WINNT\system32\NetUpdate.exe
O4 - HKLM\..\Run: [hbpassport] C:\PROGRA~1\HBCLIENT\hbast.exe
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [ClientQyule] C:\Program Files\Qyule\Qyule.exe
O4 - HKCU\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - HKCU\..\Run: [3721] C:\$NtUninstallQ5926809$\3721.bat
O4 - HKCU\..\Run: [Kugoo] F:\PROGRA~1\KUGOO2\kugoo.exe
O4 - Startup: 腾讯QQ.lnk = D:\QQ\QQ.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用Kugoo下载 - F:\PROGRA~1\KUGOO2\KugooDownX.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\QQ\SendMMS.htm
O8 - Extra context menu item: 访问通用网址 - C:\Program Files\CNNIC\Cdn\cnnic.htm
O9 - Extra button: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\QQ\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\QQ\QQIEHelper.dll
O9 - Extra button: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} - http://www.rising.com.cn (file missing)
O9 - Extra button: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com (file missing)
O11 - Options group: [CDNCLIENT]  中文上网
O11 - Options group: [TBH]  QQ地址栏搜索插件
O16 - DPF: {15DDE989-CD45-4561-BF99-D22C0D5C2B74} - http://image2.sina.com.cn/home/ddtsource/ddt.cab
O16 - DPF: {20C2C286-BDE8-441B-B73D-AFA22D914DA5} (PowerList Control) - http://www.ppstream.com/bin/powerplayer.cab
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {9A578C98-3C2F-4630-890B-FC04196EF420} (CNNIC_IDN) - http://client.jogo.cn/download/cnnic/cdn.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O16 - DPF: {F138084D-84D7-48CD-BEA8-04772457516E} (VqqSpeedDlProxy Class) - http://218.85.138.27/vqqsdl1009.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D79DBF06-3E37-4F33-A1D1-F5AC831084BC}: NameServer = 61.234.254.5,61.234.254.6
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINNT\system32\vbsys2.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: MSGSERVICE - Unknown owner - C:\WINNT\msgsrv.exe (file missing)
O23 - Service: Windows Installer help (MSIServerhelp) - Unknown owner - C:\WINNT\msiexechelp.exe
O23 - Service: nServer (Server) - Unknown owner - C:\WINNT\serset.exe

gototop
 

O23 - Service: nServer (Server) - Unknown owner - C:\WINNT\serset.exe
O23 - Service: Windows Installer help (MSIServerhelp) - Unknown owner - C:\WINNT\msiexechelp.exe
先把鸽子清掉
1.开始-运行输入regedit,打开注册表编辑器,定位到HKEY_LOCAL_MACHINE\ SYSTEM \ CURRENTCONTROLSET \ SERVICES分支,删除左栏中的病毒服务名nServer (Server)和Windows Installer help (MSIServerhelp)
2.重启系统,在“文件夹选项”的“查看”面板中勾选“显示系统文件”、“显示所有的文件和文件夹”两项,点击“确定”按钮。然后在%windows%下寻找病毒文件名 C:\WINNT\serset.exe, C:\WINNT\serset.dll, C:\WINNT\serset_Hook.dll, C:\WINNT\sersetkey.dll,C:\WINNT\msiexechelp.exe,C:\WINNT\msiexechelp.dll,C:\WINNT\msiexechelp_Hook.dll,C:\WINNT\msiexechelpkey.dll能找到的都删除
gototop
 

【回复“救我!”的帖子】
O4 - HKLM\..\Run: [usbn] C:\WINNT\system32\usbn.exe -go -c20 -w1
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - HKLM\..\Run: [NetUpdate] C:\WINNT\system32\NetUpdate.exe
O4 - HKLM\..\Run: [hbpassport] C:\PROGRA~1\HBCLIENT\hbast.exe

O4 - HKCU\..\Run: [ClientQyule] C:\Program Files\Qyule\Qyule.exe
O4 - HKCU\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - HKCU\..\Run: [3721] C:\$NtUninstallQ5926809$\3721.bat

一堆木马+流氓.

O23 - Service: MSGSERVICE - Unknown owner - C:\WINNT\msgsrv.exe (file missing)
O23 - Service: Windows Installer help (MSIServerhelp) - Unknown owner - C:\WINNT\msiexechelp.exe
O23 - Service: nServer (Server) - Unknown owner - C:\WINNT\serset.exe

三只木马

O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINNT\system32\vbsys2.dll

这项也有问题.

在安全模式下杀毒吧.

gototop
 
1234   1  /  4  页   跳转
页面顶部
Powered by Discuz!NT