瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 版主大人这是我的日志,麻烦你了

1234   4  /  4  页   跳转

版主大人这是我的日志,麻烦你了

O23 - Service: System Event - Unknown owner - C:\WINNT\SVCH0ST.exe
日.这鸽子终于出来啦
http://forum.ikaka.com/topic.asp?board=28&artid=7713905
按照这里说的来杀
gototop
 

老大~~~~~~~~~~~偶要哭类
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 13:35:22, on 2006-09-17
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
e:\program files\rising\rfw\rfwsrv.exe
C:\WINNT\system32\svchost.exe
E:\Program Files\Rising\Rav\CCenter.exe
E:\Program Files\Rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\system32\NMSSvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
E:\Program Files\Rising\Rav\RavStub.exe
C:\WINNT\SYSTEM32\RUNDLL32.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
e:\program files\rising\rfw\RfwMain.exe
E:\Program Files\Rising\Rav\RavTask.exe
C:\WINNT\system32\ctfmon.exe
E:\Program Files\Rising\Rav\Ravmon.exe
C:\Program Files\WESTEL\南京菲亚特4S经销商管理系统(C)\nanya.exe
E:\Program Files\Rising\Rav\Rav.exe
E:\Program Files\Rising\Rav\RsAgent.exe
C:\WINNT\msagent\AgentSvr.exe
E:\常用软件\ha_hijackthis_1991\HijackThis.exe

O2 - BHO: (no name) - {E730189A-9973-4121-B046-AD1C161EC3AF} - (no file)
O2 - BHO: update wnwb - {ED8DFC5C-10EF-45AB-9DC2-0639AFF5A270} - C:\PROGRA~1\COMMON~1\Wnwb\wnwbio.dll
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] rem C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] rem C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [StormCodec_Helper] rem "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [ETypeAssistant] C:\Program Files\英文打字助手\ETypeAssistant.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [RfwMain] "E:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "E:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [DesktopSprite] rem C:\Program Files\SnowFox\DesktopSprite2\DesktopSprite.exe
O4 - HKCU\..\Run: [MsnMsgr] rem "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: 南京菲亚特4S经销商管理系统.lnk = ?
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: _{488A4255-3236-44B3-8F27-FA1AECAA8844} - https://img.alipay.com/download/1007/aliedit.cab
O16 - DPF: _{73E4740C-08EB-4133-896B-8D0A7C9EE3CD} - https://mybank.icbc.com.cn/icbc/perbank/AXSafeControls.cab
O16 - DPF: _{8F00D534-4044-43E0-9B97-A60A8D17C4A9} - http://mail.yanghai.cn/CebcApi.cab
O16 - DPF: _{ACFE8232-03C5-4AEC-AF5E-42B806724096} - http://safe.qq.com/scan/KAllScan.CAB
O16 - DPF: {52DF16E3-6C4F-4B22-8BAF-09263E463B48} - http://zs.kingsoft.com/KOSInit.cab
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: System Safety Monitor - C:\WINNT\SYSTEM32\SSMWinlogonEx.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINNT\system32\NMSSvc.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - e:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - E:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: UF2000财务软件 (UFNet) - Unknown owner - C:\WINNT\system32\ServerNT.exe

gototop
 

我昨天想装SSM的,装不进不知道怎么了
gototop
 

啊,瑞星显示ha-hijackthis感染病毒了
gototop
 

引用:
【四月一日君寻的贴子】啊,瑞星显示ha-hijackthis感染病毒了
………………

gototop
 

偶现在是毒王
gototop
 

还有米有人撒~~~~~~~~~~~~~~~~~~~~``````
gototop
 
1234   4  /  4  页   跳转
页面顶部
Powered by Discuz!NT