我的电脑怎么总是出现这个TROJAN.SPY.AGENT.XX毒,每次都是杀毒成功,但每次开机还有,请高手看看!怎么能杀掉啊,谢谢!
Logfile of HijackThis v1.99.1
Scan saved at 21:58:27, on 2006-2-23
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT.0\System32\smss.exe
C:\WINNT.0\system32\winlogon.exe
C:\WINNT.0\system32\services.exe
C:\WINNT.0\system32\lsass.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\Program Files\rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINNT.0\system32\svchost.exe
C:\WINNT.0\system32\spoolsv.exe
C:\WINNT.0\system32\svchost.exe
C:\WINNT.0\system32\nvsvc32.exe
C:\WINNT.0\system32\MSTask.exe
C:\WINNT.0\system32\tcpsvcs.exe
C:\WINNT.0\system32\stisvc.exe
C:\WINNT.0\System32\WBEM\WinMgmt.exe
C:\Program Files\rising\Rav\RavStub.exe
C:\WINNT.0\system32\svchost.exe
C:\WINNT.0\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\rising\Rav\RavTask.exe
C:\Program Files\rising\Rav\Ravmon.exe
E:\电影播放器\Storm Downloader\StormDownloader.exe
E:\Program Files\Super Rabbit\MagicSet\DS.EXE
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINNT.0\SOUNDMAN.EXE
C:\WINNT.0\system32\ctfmon.exe
E:\电影播放器\Storm Downloader\TDUpdate.exe
E:\千千静听\TTPlayer.exe
C:\WINNT.0\system32\conime.exe
E:\QQ\QQ.exe
E:\QQ\TIMPlatform.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\常用杀毒工具\155847200541134207\HijackThis.exe
O2 - BHO: Zhongsou Browser Helper - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:\PROGRA~1\SEARCH~1\SNHpr.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINNT.0\system32\KakaTool.dll
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [MINI_BFYY] E:\电影播放器\Storm Downloader\StormDownloader.exe
O4 - HKLM\..\Run: [Super Rabbit Desktop Set] E:\Program Files\Super Rabbit\MagicSet\DS.EXE /Load
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [SearchNet_Up] "C:\Program Files\SearchNet\ServeUp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT.0\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Desktop] C:\WINNT.0\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll
O4 - HKLM\..\Run: [CdnCtr] >x
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [e2bf698e3dd45f5e44365f33f80239c8] "F:\qqspc\wpsdls.14520.10.exe" -t 14520.10
O8 - Extra context menu item: &使用暴风下载器下载 - E:\电影播放器\Storm Downloader\geturl.htm
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Sandai Technologies Inc\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Sandai Technologies Inc\Thunder\getAllurl.htm
O8 - Extra context menu item: 保存: 完整网页... - C:\Program Files\CyberArticle\script\Save.htm
O8 - Extra context menu item: 保存: 更多保存内容... - C:\Program Files\CyberArticle\script\SaveAuto.htm
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - C:\WINNT.0\system32\shdocvw.dll
O9 - Extra button: 网址大全 - {1FBA04EE-3024-11D2-8F1F-0000F87ABD18} - http://www.coc.cc (file missing)
O16 - DPF: {448A5F6B-8C03-4B54-A338-F00237C508AD} (WEBChatRoomOCX Control) - http://www.51uc.com/cab/WEBChatRoom_1_39.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {7FC751A9-492D-41B1-9F8D-D2C8809D8907} (EmoWebInstallerCtl Class) - http://img.365ren.com/tv/cabs/EmoWebInstaller.cab
O16 - DPF: {9242BB35-0DB0-43AC-8DFC-8EA07E63B92A} (LiveMediaOcx Control) - http://bbmedia.qq.com/media/QQLiveSetup.exe
O16 - DPF: {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} (photo_uploader Control) - http://upload.photo.163.com/photoup.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan
Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl
Object) - https://www.tenpay.com/download/qqedit.cab
O16 - DPF: {F381FC65-D92D-4410-B865-E4E9713994E8} (Cytd Encipherment Memory) - http://202.99.42.177/sso/ccitpay.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{85501E4B-78DA-46DB-A6E2-181FC2AE16EE}: NameServer = 202.106.0.20 202.106.46.151
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT.0\System32\dmadmin.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Microstrat Offices - Unknown owner - C:\WINNT.0\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT.0\system32\nvsvc32.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\Ravmond.exe