瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 最近我的电脑怎么总是中毒????

12   1  /  2  页   跳转

最近我的电脑怎么总是中毒????

最近我的电脑怎么总是中毒????

以前从没这样过,最近不知是我上网(包括下载)有问题啊还是就是病毒忒猖獗了(俺可不喜欢上什么不良网站,除非恶意链接的,只是喜欢下载东东试一试),瑞星接二连三的查出什么病毒啊木马什么的,我的XP是D版的,但瑞星是正版的啊,不至于大过年的这么让我紧张吧也不知道是不是真的杀干净了

看看查毒杀毒的日志文件:15日-今天的 前面很少

病毒名称               处理结果           发现日期       扫描方式    路径                           文件
Trojan.QqPassword.krnln27  删除成功    2006-01-15 19:18  文件监控    C:\DOCUME~1\TCL\LOCALS~1\Temp    krnln27.run
Trojan.QqPassword.krnln27  删除成功    2006-01-15 19:18  文件监控    C:\DOCUME~1\TCL\LOCALS~1\Temp    krnln27.run
Trojan.QqPassword.krnln27  删除成功    2006-01-15 19:21  文件监控    C:\DOCUME~1\TCL\LOCALS~1\Temp    krnln27.run
VBS.StartPage.d            跳过脚本    2006-01-16 23:35  网页/脚本监控  C:\DOCUME~1\TCL\LOCALS~1\Temp    49655142920.tmp
VBS.StartPage.d               跳过脚本    2006-01-16 23:35  网页/脚本监控  C:\DOCUME~1\TCL\LOCALS~1\Temp    49655142920.tmp
Exploit.HTML.Mht.cd       跳过脚本    2006-01-22 08:49  网页/脚本监控  C:\DOCUME~1\TCL\LOCALS~1\Temp    294067385056.tmp
Backdoor.Gpigeon.co(灰鸽子)删除成功    2006-01-22 10:55  文件监控  C:\Documents and Settings\TCL\Local Settings\Temporary Internet Files\Content.IE5\P4WNLPO9    Setup[1].exe>>VEUnpackFile
Exploit.HTML.Mht       删除成功    2006-01-22 10:55  文件监控  C:\Documents and Settings\TCL\Local Settings\Temporary Internet Files\Content.IE5\0LY3O5U7CATGEPT3.HTM
Js.hta.StartPage       忽略           2006-01-23 15:57  文件监控  C:\Documents and Settings\TCL\Local Settings\Temporary Internet Files\Content.IE5\CH27WPEJtest[1].hta
Js.hta.StartPage       删除成功    2006-01-23 15:57  文件监控  C:\Documents and Settings\TCL\Local Settings\Temporary Internet Files\Content.IE5\CHAVKPURtest[1].hta
Js.hta.StartPage       重新启动计算机后删除文件    2006-01-23 15:58  文件监控  C:\Documents and Settings\TCL\Local Settings\Temporary Internet Files\Content.IE5\SZBREWLXtest[1].hta
Js.hta.StartPage       跳过脚本    2006-01-23 15:58  网页/脚本监控  C:\DOCUME~1\TCL\LOCALS~1\Temp    314841694696.tmp
Trojan.PSW.LMir.aka       重新启动计算机后删除文件    2006-01-23 18:39  文件监控    C:\WINDOWS    KB2357801.LOG
Adware.Clicker.YNYW.m       删除成功    2006-01-22 11:20  定时扫描  C:\Program Files\Common Files\SAND    qqfaceclient.exe
Js.hta.StartPage       删除成功    2006-01-23 16:03  手动扫描  C:\Documents and Settings\TCL\Local Settings\Temporary Internet Files\Content.IE5\SZBREWLXtest[1].hta
Dropper.Delf.t               删除成功    2006-01-23 18:59  手动扫描  C:\WINDOWS\Downloaded Program Files    #.exe
最后编辑2006-01-23 21:24:31
分享到:
gototop
 

好多就在IE临时文件夹中
但还有其它的木马

建议
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
下载HIJACKTHIS导出日志
gototop
 

【回复“kim0217”的帖子】

HijackThis@Qoo的扫描日志  V1.97.7
Scan saved at 19:56:17, on 2006-01-23
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwproxy.exe
C:\Program Files\rising\Rfw\rfwsrv.exe
C:\Program Files\rising\Rav\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\rising\Rfw\RfwMain.exe
C:\Program Files\beelink\bverify\bverify.exe
C:\Program Files\rising\Rav\RavTask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\rising\Rav\Ravmon.exe
C:\Program Files\rising\Rfw\RfwCfg.exe
C:\Program Files\rising\Rfw\ScanBD.exe
d:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\TCL\LOCALS~1\Temp\Rar$EX04.843\HijackThis.exe

R3 - URLSearchHook: CnsHook Class - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: (no name) - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v8.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: TeachingHandler - {31EBA2E2-58B2-4980-9C41-F12F5F1422C5} - C:\Program Files\Common Files\Collegesoft\Share Components\TPHANDLE.dll
O2 - BHO: (no name) - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - (no file)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: (no name) - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - (no file)
O3 - Toolbar: ????? - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: ????? - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\kakatool.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [StormCodec_Helper] "d:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [AC] C:\Program Files\beelink\bverify\bverify.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: intlname.ols
O4 - Startup: NTUSER.DAT
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Startup: xxx
O8 - Extra context menu item: &使用迅雷下载 - d:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 火狐Flash保存 - D:\Program Files\FoxFlashplayer\PlugIns\GetFlash.htm
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: QQ (HKLM)
O11 - Options group: [!CNS] 
O16 - DPF: {52A05F4B-9F0C-4752-BB78-9B6DFD2DE9D5} (HdwCode Control) - http://www.chinaacc.com/plugin/HdwCode.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://219.133.46.45/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1104841741608
O16 - DPF: {D0A29C6C-AA71-4423-8C4A-5998B774C448} (IEDown Class) - http://download.ourgame.com/IEDown4.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E2247C7-9CB9-4EC9-91EC-70E3D180A3A3}: NameServer = 10.254.131.253
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E2247C7-9CB9-4EC9-91EC-70E3D180A3A3}: NameServer = 10.254.131.253
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E2247C7-9CB9-4EC9-91EC-70E3D180A3A3}: NameServer = 10.254.131.253
O17 - HKLM\System\CS3\Services\Tcpip\..\{1E2247C7-9CB9-4EC9-91EC-70E3D180A3A3}: NameServer = 10.254.131.253

谢谢!帮忙看看
gototop
 

抱歉!是不是这个好一点?


Logfile of HijackThis v1.99.0
Scan saved at 20:02:58, on 2006-01-23
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwproxy.exe
C:\Program Files\rising\Rfw\rfwsrv.exe
C:\Program Files\rising\Rav\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\rising\Rfw\RfwMain.exe
C:\Program Files\beelink\bverify\bverify.exe
C:\Program Files\rising\Rav\RavTask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\rising\Rav\Ravmon.exe
C:\Program Files\rising\Rfw\RfwCfg.exe
C:\Program Files\rising\Rfw\ScanBD.exe
D:\Program Files\SnowFox\DesktopSprite2\DesktopSprite.exe
E:\Downloads\进程监测\HijackThis.exe

R3 - URLSearchHook: CnsHook Class - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v8.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: TeachingHandler - {31EBA2E2-58B2-4980-9C41-F12F5F1422C5} - C:\Program Files\Common Files\Collegesoft\Share Components\TPHANDLE.dll
O2 - BHO: (no name) - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - (no file)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: DragSearch BHO - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - (no file)
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\kakatool.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [StormCodec_Helper] "d:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [AC] C:\Program Files\beelink\bverify\bverify.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 火狐Flash保存 - D:\Program Files\FoxFlashplayer\PlugIns\GetFlash.htm
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=1 (file missing)
O9 - Extra 'Tools' menuitem: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=1 (file missing)
O9 - Extra button: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} - http://www.rising.com.cn/?u=RSTB (file missing)
O9 - Extra button: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com/?u=RSTB (file missing)
O11 - Options group: [!CNS]  网络实名
O16 - DPF: {52A05F4B-9F0C-4752-BB78-9B6DFD2DE9D5} (HdwCode Control) - http://www.chinaacc.com/plugin/HdwCode.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://219.133.46.45/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1104841741608
O16 - DPF: {D0A29C6C-AA71-4423-8C4A-5998B774C448} (IEDown Class) - http://download.ourgame.com/IEDown4.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E2247C7-9CB9-4EC9-91EC-70E3D180A3A3}: NameServer = 10.254.131.253
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E2247C7-9CB9-4EC9-91EC-70E3D180A3A3}: NameServer = 10.254.131.253
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E2247C7-9CB9-4EC9-91EC-70E3D180A3A3}: NameServer = 10.254.131.253
O17 - HKLM\System\CS3\Services\Tcpip\..\{1E2247C7-9CB9-4EC9-91EC-70E3D180A3A3}: NameServer = 10.254.131.253
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\System32\mbprot.dll
O20 - AppInit_DLLs: KB2357801.LOG
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: NVIDIA Driver Helper Service - Unknown - C:\WINDOWS\System32\nvsvc32.exe (file missing)
O23 - Service: Rising Proxy  Service - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\Ravmond.exe
O23 - Service: 用友U8预警调度服务 - Unknown - C:\WINDOWS\System32\AlertService.exe
O23 - Service: U8管理软件 - Unknown - C:\WINDOWS\system32\ServerNT.EXE
gototop
 

【回复“kim0217”的帖子】
HIJACKTHIS版本太旧
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
下载HIJACKTHIS
导出日志
gototop
 

【回复“不言放弃”的帖子】

这个是不是可以?

Logfile of HijackThis v1.99.1
Scan saved at 20:26:39, on 2006-01-23
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwproxy.exe
C:\Program Files\rising\Rfw\rfwsrv.exe
C:\Program Files\rising\Rav\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\rising\Rfw\RfwMain.exe
C:\Program Files\beelink\bverify\bverify.exe
C:\Program Files\rising\Rav\RavTask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\rising\Rav\Ravmon.exe
C:\Program Files\rising\Rfw\RfwCfg.exe
C:\Program Files\rising\Rfw\ScanBD.exe
D:\Program Files\SnowFox\DesktopSprite2\DesktopSprite.exe
C:\Program Files\rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
d:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\TCL\LOCALS~1\Temp\Rar$EX00.187\HijackThis.exe

R3 - URLSearchHook: CnsHook Class - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v8.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: TeachingHandler - {31EBA2E2-58B2-4980-9C41-F12F5F1422C5} - C:\Program Files\Common Files\Collegesoft\Share Components\TPHANDLE.dll
O2 - BHO: (no name) - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - (no file)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: DragSearch BHO - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - (no file)
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\kakatool.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [StormCodec_Helper] "d:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [AC] C:\Program Files\beelink\bverify\bverify.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 火狐Flash保存 - D:\Program Files\FoxFlashplayer\PlugIns\GetFlash.htm
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=1 (file missing)
O9 - Extra 'Tools' menuitem: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=1 (file missing)
O9 - Extra button: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} - http://www.rising.com.cn/?u=RSTB (file missing)
O9 - Extra button: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com/?u=RSTB (file missing)
O11 - Options group: [!CNS]  网络实名
O16 - DPF: {52A05F4B-9F0C-4752-BB78-9B6DFD2DE9D5} (HdwCode Control) - http://www.chinaacc.com/plugin/HdwCode.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://219.133.46.45/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1104841741608
O16 - DPF: {D0A29C6C-AA71-4423-8C4A-5998B774C448} (IEDown Class) - http://download.ourgame.com/IEDown4.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E2247C7-9CB9-4EC9-91EC-70E3D180A3A3}: NameServer = 10.254.131.253
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E2247C7-9CB9-4EC9-91EC-70E3D180A3A3}: NameServer = 10.254.131.253
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E2247C7-9CB9-4EC9-91EC-70E3D180A3A3}: NameServer = 10.254.131.253
O17 - HKLM\System\CS3\Services\Tcpip\..\{1E2247C7-9CB9-4EC9-91EC-70E3D180A3A3}: NameServer = 10.254.131.253
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\System32\mbprot.dll
O20 - AppInit_DLLs: KB2357801.LOG
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\WINDOWS\System32\nvsvc32.exe (file missing)
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\Ravmond.exe
O23 - Service: 用友U8预警调度服务 (UFALERTSERVICE) - Unknown owner - C:\WINDOWS\System32\AlertService.exe
O23 - Service: U8管理软件 (UFNet) - Unknown owner - C:\WINDOWS\system32\ServerNT.EXE

gototop
 



操作参考:
修复
O20 - AppInit_DLLs: KB2357801.LOG

删除
C:\DOCUME~1\TCL\LOCALS~1\Temp 下的所有文件

C:\Documents and Settings\TCL\Local Settings\Temporary Internet Files下的所有文件

C:\Program Files\Common Files\SAND 文件夹

C:\WINDOWS\Downloaded Program Files下的所有文件

KB2357801.LOG


gototop
 

【回复“不言放弃”的帖子】

正在照着做,谢谢啦!
gototop
 

【回复“不言放弃”的帖子】

修复
O20 - AppInit_DLLs: KB2357801.LOG

还想问一下,我点了fix checked了,有点“是”然后弹出了一个大对话框,都是英文的没看懂(我英语很烂的)就关了,再扫描一遍就没有这项了,可是我去c:\window下也没找到啊?

还有就是这个文件不是瑞星给让删掉的吗?恢复不会又出来病毒吧?
gototop
 

【回复“kim0217”的帖子】
找不到文件请参考:

附件附件:

下载次数:428
文件类型:image/pjpeg
文件大小:
上传时间:2006-1-23 21:05:15
描述:



gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT