各位老大好,我刚吃完了饭,我忘了告诉你们,我是装了双系统的,我刚在98那边升级了杀毒软件,将它更新为熊猫钛金2005,再用它扫描了全机,结果发现了两个病毒,一个是QQPass、还有一个是间谍软件,之后我再重启回到XP,我在开机的时候用HijackThis1991扫描了一个Logo,然后又在上网时扫了一个Logo,我等会再发给老大研究。之后我的这个熊猫又自动升级,但是还是无法开启自动保护,之后我的机子就发现一个病毒Exploit/Lsass它正想入侵我的机子,这是熊猫刚发的提示!现在呈上Logo两份,请帮忙分析,好象有变化哦!Logo如下:
2005-11-16(刚开机):
This_815汉化版扫描日志 V1.99.1
保存于 20:12:51, 日期 2005-11-16
操作系统: Windows XP (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP1 (6.00.2600.0000)
当前运行的进程:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Panda Software\熊猫卫士钛金版2004\PavFnSvr.exe
D:\Program Files\Panda Software\熊猫卫士钛金版2004\pavprot.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
D:\Program Files\Panda Software\熊猫卫士钛金版2004\Prevsrv.exe
D:\Program Files\Panda Software\熊猫卫士钛金版2004\PsImSvc.exe
D:\WINDOWS\System32\wdfmgr.exe
D:\Program Files\Panda Software\熊猫卫士钛金版2004\APVXDWIN.EXE
D:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Panda Software\熊猫卫士钛金版2004\WebProxy.exe
F:\应用程序\HijachThis V1.99.2汉化版\HijackThis1991zww.exe
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - D:\PROGRA~1\baidu\bar\baidubar.dll (file missing)
O3 - IE工具栏增项: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - D:\PROGRA~1\baidu\bar\baidubar.dll (file missing)
O4 - 启动项HKLM\\Run: [APVXDWIN] "D:\Program Files\Panda Software\熊猫卫士钛金版2004\APVXDWIN.EXE" /s
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\System32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O10 - Broken Internet access because of LSP provider 'd:\program files\panda software\
O16 - DPF: {371B29D9-4563-4E7F-B93D-F85ED5682ABC} (CoRaise Player
Object) - http://202.104.212.55/tsplay/tsplay.cab
O20 - AppInit_DLLs: PAVWAIT.DLL
O23 - NT 服务: Panda PAVFNSVR (PAVFNSVR) - Panda Software - D:\Program Files\Panda Software\熊猫卫士钛金版2004\PavFnSvr.exe
O23 - NT 服务: Panda PAVPROT (PAVPROT) - Panda Software - D:\Program Files\Panda Software\熊猫卫士钛金版2004\pavprot.exe
O23 - NT 服务: Panda Process Protection Service (PavPrSrv) - Panda Software - D:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - NT 服务: Panda anti-virus service (PAVSRV) - Panda Software - D:\Program Files\Panda Software\熊猫卫士钛金版2004\pavsrv51.exe
O23 - NT 服务: Panda Preventium+ Service (PREVSRV) - Panda Software - D:\Program Files\Panda Software\熊猫卫士钛金版2004\Prevsrv.exe
O23 - NT 服务: Panda IManager Service (PSIMSVC) - Panda Software Internacional - D:\Program Files\Panda Software\熊猫卫士钛金版2004\PsImSvc.exe
-----------------------------------------------------------
2005-11-16(上网后):
HijackThis_815汉化版扫描日志 V1.99.1
保存于 20:20:14, 日期 2005-11-16
操作系统: Windows XP (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP1 (6.00.2600.0000)
当前运行的进程:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Panda Software\熊猫卫士钛金版2004\PavFnSvr.exe
D:\Program Files\Panda Software\熊猫卫士钛金版2004\pavprot.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
D:\Program Files\Panda Software\熊猫卫士钛金版2004\Prevsrv.exe
D:\Program Files\Panda Software\熊猫卫士钛金版2004\PsImSvc.exe
D:\WINDOWS\System32\wdfmgr.exe
D:\Program Files\Panda Software\熊猫卫士钛金版2004\APVXDWIN.EXE
D:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Panda Software\熊猫卫士钛金版2004\WebProxy.exe
D:\Program Files\VnetClient1.6\VnetClient.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\system32\cmd.exe
D:\WINDOWS\System32\csrssv.exe
D:\Program Files\Panda Software\熊猫卫士钛金版2004\pavsrv51.exe
D:\Program Files\Panda Software\熊猫卫士钛金版2004\AVENGINE.EXE
F:\应用程序\HijachThis V1.99.2汉化版\HijackThis1991zww.exe
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - D:\PROGRA~1\baidu\bar\baidubar.dll (file missing)
O3 - IE工具栏增项: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - D:\PROGRA~1\baidu\bar\baidubar.dll (file missing)
O4 - 启动项HKLM\\Run: [APVXDWIN] "D:\Program Files\Panda Software\熊猫卫士钛金版2004\APVXDWIN.EXE" /s
O4 - 启动项HKLM\\Run: [Microsoft DLL Verifier] csrssv.exe
O4 - 启动项HKLM\\RunServices: [Microsoft DLL Verifier] csrssv.exe
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\System32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O10 - Broken Internet access because of LSP provider 'd:\program files\panda software\
O16 - DPF: {371B29D9-4563-4E7F-B93D-F85ED5682ABC} (CoRaise Player
Object) - http://202.104.212.55/tsplay/tsplay.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3A5220D4-E0CA-4A7C-810F-455C11C140B3}: NameServer = 202.96.128.86 202.96.128.166
O20 - AppInit_DLLs: PAVWAIT.DLL
O23 - NT 服务: Panda PAVFNSVR (PAVFNSVR) - Panda Software - D:\Program Files\Panda Software\熊猫卫士钛金版2004\PavFnSvr.exe
O23 - NT 服务: Panda PAVPROT (PAVPROT) - Panda Software - D:\Program Files\Panda Software\熊猫卫士钛金版2004\pavprot.exe
O23 - NT 服务: Panda Process Protection Service (PavPrSrv) - Panda Software - D:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - NT 服务: Panda anti-virus service (PAVSRV) - Panda Software - D:\Program Files\Panda Software\熊猫卫士钛金版2004\pavsrv51.exe
O23 - NT 服务: Panda Preventium+ Service (PREVSRV) - Panda Software - D:\Program Files\Panda Software\熊猫卫士钛金版2004\Prevsrv.exe
O23 - NT 服务: Panda IManager Service (PSIMSVC) - Panda Software Internacional - D:\Program Files\Panda Software\熊猫卫士钛金版2004\PsImSvc.exe
-----------------------------------------------------------
请高手们详细分析,请[font_color=#FF0000
]“救救小弟,Please!Helep Me!SOS”[/font]