木马克星提示:
C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx文件被系统注入: C:\Program Files\Internet Explorer\iexplore.exe 程序
新建文件: C:\WINDOWS\Downloaded Program Files\swflash.inf 2006-8-3 18:52:55
瑞星防火墙提示如图片:
提示
详细内容2006-08-03 17:21:48, 系统禁止本地explorer.exe连接网络的请求,地址为:TCP, 0.0.0.0:2389 => 218.97.193.104:80[WEB网页]程序名称为:C:\WINDOWS\explorer.exe
详细内容2006-08-03 15:13:36, 系统禁止本地explorer.exe连接网络的请求,地址为:TCP, 0.0.0.0:1455 => 218.97.193.104:80[WEB网页]程序名称为:C:\WINDOWS\explorer.exe
......
详细内容2006-08-03 16:47:29, 系统禁止本地explorer.exe连接网络的请求,地址为:TCP, 0.0.0.0:2002[
TransScout/恶鹰木马] => 218.97.193.104:80[WEB网页]程序名称为:C:\WINDOWS\explorer.exe
但是瑞星杀毒最新的一点反应都没有!!
应该怎么办,才能让这个东西不在我打开文件夹的时候访问网页,就是说怎么去删掉它HijackThis日志:
Logfile of HijackThis v1.99.1
Scan saved at 20:29:40, on 2006-8-3
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\racer\racer.exe
C:\Program Files\racer\RacerKp.exe
D:\Program Files\Iparmor\Iparmor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\regedit.exe
F:\download\HijackThis.exe
O2 - BHO: Shockwave Flash
Object - {14A21378-5BB1-4BC4-95D5-5D3F51527F6F} - C:\WINDOWS\system32\smflash.ocx
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: 网通宽带用户客户端.lnk = C:\Program Files\racer\racer.exe
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - D:\Program Files\浩方对战平台\GameClient.exe
O20 - AppInit_DLLs: APIHookDll.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe