瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我才买的盒装2007瑞星 就这样被栓掉了....?

12   2  /  2  页   跳转

我才买的盒装2007瑞星 就这样被栓掉了....?

Logfile of HijackThis v1.99.1
Scan saved at 10:12:01, on 2007-2-5
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Administrator\桌面\HijackThis.exe

R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
O2 - BHO: AssistHelper - {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} - C:\Program Files\Yahoo!\Assistant\Assist\yassist.dll
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4A40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MyIE2] C:\WINDOWS\my.exe
O4 - HKLM\..\Run: [CONFIG] C:\WINDOWS\gmm_my.exe
O4 - HKLM\..\Run: [IEXPlORER] C:\WINDOWS\goodrack.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [w] C:\WINDOWS\iexpl0re.exe
O4 - HKCU\..\Run: [7h5yx3zce] C:\WINDOWS\system.exe
O4 - HKCU\..\Run: [svc] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\kwatlog.exe
O4 - HKCU\..\Run: [wj12ulsx1v] C:\WINDOWS\winlog0n.exe
O4 - HKCU\..\Run: [svcshare] C:\WINDOWS\system32\drivers\spoclsv.exe
O8 - Extra context menu item: &使用迅雷下载 - d:\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\QQ\AddEmotion.htm
O8 - Extra context menu item: 添加到雅虎订阅(&Y) - res://C:\Program Files\Yahoo!\Assistant\Assist\yrss.dll/YRSSMENUEXT
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\QQ\SendMMS.htm
O8 - Extra context menu item: 雅虎搜索 - res://C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll/203
O9 - Extra button: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/start.htm?source=yzs_icon&btn=yassistnew (file missing)
O16 - DPF: {E847C78C-C210-4195-8799-FBF3BF89797D} (金山毒霸在线产品升级) - http://www.duba.net/cab/KOSInit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0038B4BA-9281-4B04-B278-5DE5AF75287A}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{89070DFC-B5F9-4619-8FE1-535705060A7E}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{0038B4BA-9281-4B04-B278-5DE5AF75287A}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{0038B4BA-9281-4B04-B278-5DE5AF75287A}: NameServer = 61.128.128.68,61.128.192.68
O23 - Service: Internet Protector System Service (InternetProtectorService) - Unknown owner - D:\LiDong\iNet Protector\IProtectorService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

附件附件:

下载次数:162
文件类型:image/pjpeg
文件大小:
上传时间:2007-2-5 10:31:10
描述:
预览信息:EXIF信息



gototop
 

引用:
【lh22397908的贴子】【回复“lh22397908”的帖子】
哪个拒绝访问的是什么东西  是不是不能撤除啊
………………

自己看说明,用
1农夫山泉有点甜威金专杀.zip
2农夫山泉有点甜熊猫专杀

gototop
 

我现在已经杀完了 为什么还是自己不段的重新启动啊`!
开机就自己重启动了`!
gototop
 

我重装的瑞星升级了 在杀毒 杀半又自动消失了
点不点不开了`!!我现在正在重新启动试下~!
gototop
 

我进入带网络的安全模式下
就没有iexpl0re.exe
gototop
 

O4 - HKCU\..\Run: [svcshare] C:\WINDOWS\system32\drivers\spoclsv.exe
O4 - HKLM\..\Run: [load] C:\WINDOWS\uninstall\rundl132.exe

这俩文件还在的话 发送 bin59420@yahoo.com.cn

修复
O4 - HKLM\..\Run: [MyIE2] C:\WINDOWS\my.exe
O4 - HKLM\..\Run: [CONFIG] C:\WINDOWS\gmm_my.exe
O4 - HKLM\..\Run: [IEXPlORER] C:\WINDOWS\goodrack.exe
O4 - HKCU\..\Run: [w] C:\WINDOWS\iexpl0re.exe
O4 - HKCU\..\Run: [7h5yx3zce] C:\WINDOWS\system.exe
O4 - HKCU\..\Run: [wj12ulsx1v] C:\WINDOWS\winlog0n.exe
O4 - HKCU\..\Run: [wj12ulsx1v] C:\WINDOWS\winlog0n.exe
删除以上文件..
gototop
 

【回复“mopery”的帖子】
我把我不认识的全部栓出了  现在不重起了比较正常了
---------------------------------现在扫出来的
Logfile of HijackThis v1.99.1
Scan saved at 14:39:41, on 2007-2-5
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
D:\360safe\safemon\360tray.exe
C:\WINDOWS\System32\alg.exe
D:\LiDong\iNet Protector\IProtectorService.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
d:\Rising\Rav\CCenter.exe
d:\Rising\Rav\RAVTASK.EXE
D:\Rising\Rav\Ravmond.exe
D:\Rising\Rav\RavStub.exe
D:\Rising\Rav\RavMon.exe
C:\Documents and Settings\Administrator\桌面\HijackThis.exe

O1 - Hosts: 221.231.140.199 www.781999.com
O2 - BHO: NavigatMon Class - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} - D:\360safe\safemon\safemon.dll
O4 - HKLM\..\Run: [360Safetray] D:\360safe\safemon\360tray.exe
O4 - HKLM\..\Run: [RavTask] "d:\Rising\Rav\RavTask.exe" -system
O8 - Extra context menu item: &使用迅雷下载 - d:\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Thunder\Program\GetAllUrl.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{0038B4BA-9281-4B04-B278-5DE5AF75287A}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{89070DFC-B5F9-4619-8FE1-535705060A7E}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{0038B4BA-9281-4B04-B278-5DE5AF75287A}: NameServer = 61.128.128.68,61.128.192.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{0038B4BA-9281-4B04-B278-5DE5AF75287A}: NameServer = 61.128.128.68,61.128.192.68
O23 - Service: Internet Protector System Service (InternetProtectorService) - Unknown owner - D:\LiDong\iNet Protector\IProtectorService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - d:\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\Rising\Rav\Ravmond.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

gototop
 

不好意思我全部撤除了`!
我想问一下我进呈里面有个---(iprotectorservice.EXE)
这个怎么卸载  有这个进程我就上不去网  无法打开网络~!
在带网络的安全模式下才可以上网
正常登陆上不起
gototop
 

修复:O1 - Hosts: 221.231.140.199 www.781999.com
O23 - Service: Internet Protector System Service (InternetProtectorService) - Unknown owner - D:\LiDong\iNet Protector\IProtectorService.exe
删除文件: D:\LiDong\iNet Protector\IProtectorService.exe
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT