瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 讨厌的病毒又来啦~~~~高手帮忙看看扫描结果!!!

123   3  /  3  页   跳转

讨厌的病毒又来啦~~~~高手帮忙看看扫描结果!!!

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1648, C:\WINDOWS\SYSTEM32\SPOOLSV.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 204, D:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 688, C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 708, D:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 780, D:\PROGRAM FILES\RISING\RAV\RAVMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 944, E:\PROGRAM FILES\TENCENT\QQDOWNLOAD\QQDOWNLOAD.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

奇怪?进程好多,我扫描时只开了浏览器而已~
这么长,又要麻烦人了~~~我几乎每天都升级瑞星,上网时也开防火墙,下载的东西也要拿瑞星扫描以后才用,为什么我的电脑还会中病毒呢?
高手帮帮忙吧!不知道该怎么办了~~~~~~~
gototop
 

沉了^顶一下!
gototop
 

沉了^顶一下!
gototop
 

版主帮帮忙吧!!!!
gototop
 

日志除了下面服务外,其它的并没异常哦,“...病毒又来了.......”楼主说说你系统的异常...
下载冰刃http://www.skycn.com/soft/37828.html#download,解压,打开冰刃主界面,在服务,按以下的路径和服务名中找到以下项:
下面的这些服务都不是很正常,这么多建议楼主先把它们都禁用后看看情况怎样。。要是系统正常了,就直接把它们删除好了...
[DCOM Server Process Launcher / DcomLaunch][Running/Auto Start]
<C:\WINDOWS\system32\svchost -k DcomLaunch-->%SystemRoot%\system32

\rpcss.dll>
DHCP Client / Dhcp][Running/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\dhcpcsvc.dll
COM+ Event System / EventSystem][Running/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\es.dll
Fast User Switching Compatibility / FastUserSwitchingCompatibility]

[Stopped/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\shsvcs.dll
[Server / lanmanserver][Running/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\srvsvc.dll
Workstation / lanmanworkstation][Running/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\wkssvc.dll
Network Connections / Netman][Running/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\netman.dll
Remote Access Connection Manager / RasMan][Running/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\rasmans.dll
Remote Procedure Call (RPC) / RpcSs][Running/Auto Start]
<C:\WINDOWS\system32\svchost -k rpcss-->%SystemRoot%\system32\rpcss.dll
Shell Hardware Detection / ShellHWDetection][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\shsvcs.dll
Windows Image Acquisition (WIA) / stisvc][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k imgsvc-->%SystemRoot%\system32

\wiaservc.dll
Telephony / TapiSrv][Running/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\tapisrv.dll
Themes / Themes][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\shsvcs.dll
Universal Plug and Play Device Host / upnphost][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k LocalService-->%SystemRoot%\System32

\upnphost.dll
WebClient / WebClient][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k LocalService-->%SystemRoot%\System32

\webclnt.dll
gototop
 



删除服务
[Windows Explorer / Windows Explorer][Stopped/Auto Start]
<C:\WINDOWS\Windows Corporation.exe><N/A>
删除C:\WINDOWS\Windows Corporation.exe

请说明问题...
gototop
 

引用:
【读毒的贴子】日志除了下面服务外,其它的并没异常哦,“...病毒又来了.......”楼主说说你系统的异常...
下载冰刃http://www.skycn.com/soft/37828.html#download,解压,打开冰刃主界面,在服务,按以下的路径和服务名中找到以下项:
下面的这些服务都不是很正常,这么多建议楼主先把它们都禁用后看看情况怎样。。要是系统正常了,就直接把它们删除好了...
[DCOM Server Process Launcher / DcomLaunch][Running/Auto Start]
<C:\WINDOWS\system32\svchost -k DcomLaunch-->%SystemRoot%\system32

\rpcss.dll>
DHCP Client / Dhcp][Running/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\dhcpcsvc.dll
COM+ Event System / EventSystem][Running/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\es.dll
Fast User Switching Compatibility / FastUserSwitchingCompatibility]

[Stopped/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\shsvcs.dll
[Server / lanmanserver][Running/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\srvsvc.dll
Workstation / lanmanworkstation][Running/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\wkssvc.dll
Network Connections / Netman][Running/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\netman.dll
Remote Access Connection Manager / RasMan][Running/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\rasmans.dll
Remote Procedure Call (RPC) / RpcSs][Running/Auto Start]
<C:\WINDOWS\system32\svchost -k rpcss-->%SystemRoot%\system32\rpcss.dll
Shell Hardware Detection / ShellHWDetection][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\shsvcs.dll
Windows Image Acquisition (WIA) / stisvc][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k imgsvc-->%SystemRoot%\system32

\wiaservc.dll
Telephony / TapiSrv][Running/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\tapisrv.dll
Themes / Themes][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32

\shsvcs.dll
Universal Plug and Play Device Host / upnphost][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k LocalService-->%SystemRoot%\System32

\upnphost.dll
WebClient / WebClient][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k LocalService-->%SystemRoot%\System32

\webclnt.dll

………………

不建议楼主按此操作
gototop
 

我机子中毒的情况,呵呵,看这里,有图
http://forum.ikaka.com/topic.asp?board=28&artid=8372789
gototop
 
123   3  /  3  页   跳转
页面顶部
Powered by Discuz!NT