瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 C:\WINDOWS\Temp\SafePage.htm是病毒吗?如何彻底的清除?

1   1  /  1  页   跳转

C:\WINDOWS\Temp\SafePage.htm是病毒吗?如何彻底的清除?

C:\WINDOWS\Temp\SafePage.htm是病毒吗?如何彻底的清除?

我每次打开IE后,每隔4---5分钟就弹出这样的提示,是因为有了瑞星卡卡的帮忙,而我每次从C盘里清除了这个文件后(C:\WINDOWS\Temp\SafePage.htm)可一会它又弹出来了,我用瑞星也杀不了,用木马杀客也没有效果,请问这是什么病毒?请高手给予帮忙,万分感谢!

附件附件:

下载次数:1839
文件类型:image/pjpeg
文件大小:
上传时间:2006-9-17 21:25:52
描述:



最后编辑2006-09-17 21:59:34
分享到:
gototop
 

请到http://forum.ikaka.com/topic.asp?board=28&artid=8105899
下载HijackThis
下载后运行HijackThis.rar,再运行HijackThis.exe
单机"扫描日志并保存日志"
把保存的日志复制粘贴上来.
gototop
 

从注册表清除
gototop
 

回复:C:\WINDOWS\Temp\SafePage.htm是病毒吗?如何彻底的清除?

Logfile of HijackThis v1.99.1
Scan saved at 9:17:27, on 2009-4-1
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Ris\CCENTER.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Ris\RavMonD.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\StormII\stormliv.exe
C:\Program Files\Rising\Ris\RavTask.exe
C:\Program Files\Rising\Ris\ScanFrm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Ris\rsnetsvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Rising\Ris\RSTRAY.EXE
D:\安装\卡卡\rstray.exe
D:\安装\360\360safe\safemon\360Tray.exe
C:\WINDOWS\system32\ctfmon.exe
D:\安装\阿里旺旺\aliim.exe
D:\安装\慧聪网\IM.exe
D:\安装\QQ\QQ.exe
D:\安装\迅雷\Program\Thunder5.exe
D:\安装\QQ\TXPlatform.exe
D:\安装\慧聪网\mmt.exe
D:\安装\QQ\QQ.exe
D:\安装\QQ\QQ.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX17.812\HijackThis.exe

O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - D:\安装\迅雷\ComDlls\TDAtOnce_Now.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\安装\迅雷\ComDlls\xunleiBHO_Now.dll
O2 - BHO: 卡卡上网安全助手 - {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} - C:\WINDOWS\system32\UrlFilter.dll
O2 - BHO: SafeMon Class - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} - D:\安装\360\360safe\safemon\safemon.dll
O4 - HKLM\..\Run: [Thunder] "D:\安装\迅雷\Thunder.exe" /s
O4 - HKLM\..\Run: [RisTray] "C:\Program Files\Rising\Ris\RsTray.exe" -system
O4 - HKLM\..\Run: [runeip] "D:\安装\卡卡\rstray.exe" /startup
O4 - HKLM\..\Run: [360Safetray] D:\安装\360\360safe\safemon\360Tray.exe /start
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [aliim] D:\安装\阿里旺旺\aliim.exe
O4 - Startup: 慧聪发发.lnk = ?
O4 - Startup: 腾讯QQ.lnk = ?
O8 - Extra context menu item: 使用迅雷下载 - D:\安装\迅雷\Program\GetUrl.htm
O8 - Extra context menu item: 使用迅雷下载全部链接 - D:\安装\迅雷\Program\GetAllUrl.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ表情 - D:\安装\AddEmotion.htm
O9 - Extra button: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\安装\迅雷\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\安装\迅雷\Thunder.exe
O9 - Extra button: 联想 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.lenovo.com (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O16 - DPF: {B2EC6023-6C00-49F9-A8BE-3AAC4E326BA4} - http://mimg.163.com/bin/NetEaseMailActiveX.cab
O20 - AppInit_DLLs: kmon.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Contrl Center of Storm Media (ccosm) - 北京暴风网际科技有限公司 - C:\Program Files\StormII\stormliv.exe
O23 - Service: Ris Process Communication Center (RisCCenter) - Beijing Rising Information Technology Co., Ltd. - C:\Program Files\Rising\Ris\CCENTER.EXE
O23 - Service: Rising RisTask Manager (RisTask) - Unknown owner - C:\Program Files\Rising\Ris\RavTask.exe" RisTask (file missing)
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Information Technology Co., Ltd. - C:\Program Files\Rising\Ris\RavMonD.exe
O23 - Service: Rising Scan Service (RsScanSrv) - Beijing Rising Information Technology Co., Ltd. - C:\Program Files\Rising\Ris\ScanFrm.exe
gototop
 

回复:C:\WINDOWS\Temp\SafePage.htm是病毒吗?如何彻底的清除?

我现在也出现这个问题,刚才和工程师聊了半天,也没弄掉,请求解决办法
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT