瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 電腦中毒症狀:WIN防火牆無法開啟/瑞星郵件監控自動禁用/無法上網等

1   1  /  1  页   跳转

電腦中毒症狀:WIN防火牆無法開啟/瑞星郵件監控自動禁用/無法上網等

電腦中毒症狀:WIN防火牆無法開啟/瑞星郵件監控自動禁用/無法上網等

如題,並且連局域網都無法訪問
這個病毒已經困繞我幾天了,有幾台電腦中這個毒
重裝系統作用不大,運行一段時間又出現

請問我該怎麽來殺掉它
最后编辑2008-03-15 14:16:39
分享到:
gototop
 

在線等....大哥救命啊
gototop
 

楼主用卡卡助手查杀一下看看有没有恶意程序!再用杀软在安全模式下查杀一遍!
gototop
 

windows清理助手/360安全卫士/卡卡助手/瑞星2008
安全模式下
全都试过,查不出任何东西出来..

gototop
 

进程信息:
ProcessPIDCPUDescriptionCompany Name
System Idle Process096.15
Interruptsn/aHardware Interrupts
DPCsn/aDeferred Procedure Calls
System40.77
  smss.exe368Windows NT Session ManagerMicrosoft Corporation
  csrss.exe424Client Server Runtime ProcessMicrosoft Corporation
  winlogon.exe452Windows NT Logon ApplicationMicrosoft Corporation
    services.exe5040.77Services and Controller appMicrosoft Corporation
    svchost.exe712Generic Host Process for Win32 ServicesMicrosoft Corporation
      wmiprvse.exe2064WMIMicrosoft Corporation
    svchost.exe784Generic Host Process for Win32 ServicesMicrosoft Corporation
    CCenter.exe820CCenterBeijing Rising Technology Co., Ltd.
    svchost.exe864Generic Host Process for Win32 ServicesMicrosoft Corporation
    svchost.exe904Generic Host Process for Win32 ServicesMicrosoft Corporation
    RavMonD.exe924RavMondBeijing Rising Technology Co., Ltd.
      RavStub.exe1112Rising RavStubBeijing Rising Technology Co., Ltd.
    svchost.exe952Generic Host Process for Win32 ServicesMicrosoft Corporation
    spoolsv.exe1220Spooler SubSystem AppMicrosoft Corporation
    msdtc.exe1296MS DTCconsole programMicrosoft Corporation
    cisvc.exe1416Content Index serviceMicrosoft Corporation
      cidaemon.exe3088Indexing Service filter daemonMicrosoft Corporation
      cidaemon.exe3112Indexing Service filter daemonMicrosoft Corporation
      cidaemon.exe3156Indexing Service filter daemonMicrosoft Corporation
    inetinfo.exe1496Internet Information ServicesMicrosoft Corporation
    sqlservr.exe1536SQL Server Windows NTMicrosoft Corporation
    sqlservr.exe1660SQL Server Windows NTMicrosoft Corporation
    sqlwriter.exe1776SQL Server VSS WriterMicrosoft Corporation
    vmware-authd.exe1968VMware Authorization ServiceVMware, Inc.
    vmount2.exe2024virtual disk mount serviceVMware, Inc.
    vmnat.exe276VMware NAT ServiceVMware, Inc.
    mssearch.exe656Microsoft PKM Search ServiceMicrosoft Corporation
    vmnetdhcp.exe272VMware VMnet DHCP serviceVMware, Inc.
    svchost.exe1184Generic Host Process for Win32 ServicesMicrosoft Corporation
    svchost.exe2828Generic Host Process for Win32 ServicesMicrosoft Corporation
    lsass.exe516LSA ShellMicrosoft Corporation
explorer.exe2552Windows ExplorerMicrosoft Corporation
RavTask.exe2672RavTimerBeijing Rising Technology Co., Ltd.
  RavMon.exe2704RavMonBeijing Rising Technology Co., Ltd.
stsystra.exe2732Sigmatel Audio system tray applicationSigmaTel, Inc.
ctfmon.exe2764CTF LoaderMicrosoft Corporation
3256优秀的系统自启动项目管理器Sysinternals - www.sysinternals.com
112.exe17202.31Sysinternals Process ExplorerSysinternals - www.sysinternals.com
iexplore.exe3508Internet ExplorerMicrosoft Corporation

gototop
 

自动运行项信息:
HKLM\System\CurrentControlSet\Services

+ MSSEARCH基于结构化和半结构化数据的内容以及属性生成全文索引,以便可以对数据进行快速的单词搜索(具体未经核实) Microsoft Corporationc:\program files\common files\system\mssearch\bin\mssearch.exe

+ MSSQLSERVERSQL Server Windows NT(具体未经核实) Microsoft Corporationc:\program files\microsoft sql server\mssql\binn\sqlservr.exe

+ MySQLc:\program files\mysql\mysql server 5.0\bin\mysqld-nt.exe

+ RsCCenterCCenter(具体未经核实) Beijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe

+ RsRavMonRavMond(具体未经核实) Beijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe

+ StarWindServiceEnables network access to local devices via iSCSI protocol.(具体未经核实) Rocket Division Softwared:\program files\alcohol soft\alcohol 120\starwind\starwindservice.exe

+ VMAuthdServiceAuthorization and authentication service for starting and accessing virtual machines(具体未经核实) VMware, Inc.d:\program files\vmware\vmware workstation\vmware-authd.exe

+ VMnetDHCPDHCP service for virtual networks(具体未经核实) VMware, Inc.c:\windows\system32\vmnetdhcp.exe

+ vmount2virtual disk mount service(具体未经核实) VMware, Inc.c:\program files\common files\vmware\vmware virtual image editing\vmount2.exe

+ VMware NAT ServiceNetwork address translation for virtual networks(具体未经核实) VMware, Inc.c:\windows\system32\vmnat.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ ATICCCCLI Application (Command Line Interface)(具体未经核实) ATI Technologies Inc.c:\program files\ati technologies\ati.ace\cli.exe

+ RavTaskRavTimer(具体未经核实) Beijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe

+ SigmatelSysTrayAppSigmatel Audio system tray application(具体未经核实) SigmaTel, Inc.c:\windows\stsystra.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ Rising Execute File Exts hookRising Shell Ext Module(具体未经核实) Beijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Autoplay for SlideShowC:\Program Files\SigmaTel\C-Major Audio\

+ Catalyst Context Menu extensionACE Context Menuc:\program files\ati technologies\ati.ace\atiacmxx.dll

+ Fusion CacheMicrosoft .NET Runtime Execution Engine(具体未经核实) Microsoft Corporationc:\windows\system32\mscoree.dll

+ HyperTerminal Icon Ext文件丢失: hticons.dll 。

+ LcdFriendlyLcdShell(具体未经核实) Space International, Inc.d:\program files\space international\cdspace 5\lcdshell.dll

+ Macromedia FlashPaper Context MenuFlashPaper ContextMenu Modulec:\program files\macromedia\flashpaper 2\flashpapercontextmenu.dll

+ RISINGRising Shell Ext Module(具体未经核实) Beijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ Shell extensions for file compressionC:\Program Files\SigmaTel\C-Major Audio\

+ Shell Extensions for RealOne Player文件丢失: C:\Program Files\Real\RealPlayer\rpshell.dll 。

+ Shell Icon Handler for Application ReferencesApplication Deployment Support Lib

大哥帮我看看
其中..112.exe进行程扫描器
gototop
 

贴出来的格式不清楚的话,我发了文件

附件附件:

下载次数:148
文件类型:application/octet-stream
文件大小:
上传时间:2008-3-15 10:49:57
描述:

gototop
 

SREng扫描的日志也一起发上来.,高手们醒醒

附件附件:

下载次数:113
文件类型:application/octet-stream
文件大小:
上传时间:2008-3-15 12:30:28
描述:

gototop
 

版主们,高手们
醒醒了
八百里加急!!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT