瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我的电脑中了Backdoor.PcShare.f病毒,请帮我看一下我的日志,谢谢!

1   1  /  1  页   跳转

我的电脑中了Backdoor.PcShare.f病毒,请帮我看一下我的日志,谢谢!

我的电脑中了Backdoor.PcShare.f病毒,请帮我看一下我的日志,谢谢!

求助版主,我的电脑里现在再开机灰鸽子病毒是没有了,可是总有这两个病毒除不了.病毒名是:Backdoor.PcShare.f
这是什么病毒,我该怎么样扼杀它呢,盼回复!
谢谢!!
Logfile of HijackThis v1.99.1
Scan saved at 16:20:55, on 2005-09-15
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\3721\assistse.exe
C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\LLJAgent\KXAgentS.exe
C:\PROGRA~1\RISING\RAV\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Tencent\TT\TTraveler.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\888888\LOCALS~1\Temp\Rar$EX03.031\HijackThis.exe

R3 - URLSearchHook: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\Program Files\3721\Assist\asbar.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: 219.153.5.189www.zhao123.com
O1 - Hosts: 219.153.5.189zhao123.com
O1 - Hosts: 219.153.5.189www.4399.com
O1 - Hosts: 219.153.5.1894399.com
O1 - Hosts: 219.153.5.189www.chinagames.net
O1 - Hosts: 219.153.5.189chinagames.net
O1 - Hosts: 219.153.5.189www.tiexue.net
O1 - Hosts: 219.153.5.189tiexue.net
O1 - Hosts: 219.153.5.189www.qq163.com
O1 - Hosts: 219.153.5.189qq163.com
O1 - Hosts: 219.153.5.189www.tt67.com
O1 - Hosts: 219.153.5.189tt67.com
O1 - Hosts: 219.153.5.189www.chinamp3.com
O1 - Hosts: 219.153.5.189chinamp3.com
O1 - Hosts: 219.153.5.189www.pg168.com
O1 - Hosts: 219.153.5.189pg168.com
O1 - Hosts: 219.153.5.189www.yymp3.com
O1 - Hosts: 219.153.5.189yymp3.com
O1 - Hosts: 219.153.5.189www.yy138.com
O1 - Hosts: 219.153.5.189yy138.com
O1 - Hosts: 219.153.5.189www.dj99.com
O1 - Hosts: 219.153.5.189dj99.com
O1 - Hosts: 219.153.5.189www.sogua.com
O1 - Hosts: 219.153.5.189sogua.com
O1 - Hosts: 219.153.5.189www.snsn.net
O1 - Hosts: 219.153.5.189snsn.net
O1 - Hosts: 219.153.5.189www.flash8.net
O1 - Hosts: 219.153.5.189flash8.net
O1 - Hosts: 219.153.5.189www.mop.com
O1 - Hosts: 219.153.5.189mop.com
O1 - Hosts: 219.153.5.189www.tianyaclub.com
O1 - Hosts: 219.153.5.189tianyaclub.com
O1 - Hosts: 219.153.5.189www.xici.net
O1 - Hosts: 219.153.5.189xici.net
O1 - Hosts: 219.153.5.189www.ucanlove.com
O1 - Hosts: 219.153.5.189ucanlove.com
O1 - Hosts: 219.153.5.189www.cmfu.com
O1 - Hosts: 219.153.5.189cmfu.com
O1 - Hosts: 219.153.5.189www.21red.net
O1 - Hosts: 219.153.5.18921red.net
O1 - Hosts: 219.153.5.189www.pconline.com.cn
O1 - Hosts: 219.153.5.189pconline.com.cn
O1 - Hosts: 219.153.5.189www.donews.com
O1 - Hosts: 219.153.5.189donews.com
O1 - Hosts: 219.153.5.189www.pcauto.com.cn
O1 - Hosts: 219.153.5.189pcauto.com.cn
O1 - Hosts: 219.153.5.189www.265.com
O1 - Hosts: 219.153.5.189265.com
O1 - Hosts: 219.153.5.189www.wo99.com
O1 - Hosts: 219.153.5.189wo99.com
O1 - Hosts: 219.153.5.189www.familydoctor.com.cn
O1 - Hosts: 219.153.5.189familydoctor.com.cn
O1 - Hosts: 219.153.5.189www.flashempire.com
O1 - Hosts: 219.153.5.189flashempire.com
O1 - Hosts: 219.153.5.189www.showgood.tv
O1 - Hosts: 219.153.5.189showgood.tv
O1 - Hosts: 219.153.5.189www.flashfan.net
O1 - Hosts: 219.153.5.189flashfan.net
O1 - Hosts: 219.153.5.189www.long21.net
O1 - Hosts: 219.153.5.189long21.net
O1 - Hosts: 219.153.5.189www.sowww.com
O1 - Hosts: 219.153.5.189sowww.com
O1 - Hosts: 219.153.5.189www.flashhome.net
O1 - Hosts: 219.153.5.189flashhome.net
O1 - Hosts: 219.153.5.189www.cnflash.net
O1 - Hosts: 219.153.5.189cnflash.net
O1 - Hosts: 219.153.5.189www.flashsky.com
O1 - Hosts: 219.153.5.189flashsky.com
O1 - Hosts: 219.153.5.189www.hunansky.com
O1 - Hosts: 219.153.5.189hunansky.com
O1 - Hosts: 219.153.5.189www.52flash.net
O1 - Hosts: 219.153.5.18952flash.net
O1 - Hosts: 219.153.5.189www.flashh.com
O1 - Hosts: 219.153.5.189flashh.com
O1 - Hosts: 219.153.5.189www.flashsun.com
O1 - Hosts: 219.153.5.189flashsun.com
O1 - Hosts: 219.153.5.189www.7k7k.com
O1 - Hosts: 219.153.5.1897k7k.com
O1 - Hosts: 219.153.5.189www.xuanxuan.com
O1 - Hosts: 219.153.5.189xuanxuan.com
O1 - Hosts: 219.153.5.189www.91flash.com
O1 - Hosts: 219.153.5.18991flash.com
O1 - Hosts: 219.153.5.189www.doingflash.com
O1 - Hosts: 219.153.5.189doingflash.com
O1 - Hosts: 219.153.5.189www.5see.com
O1 - Hosts: 219.153.5.1895see.com
O1 - Hosts: 219.153.5.189www.skyhits.com
O1 - Hosts: 219.153.5.189skyhits.com
O1 - Hosts: 219.153.5.189www.ting78.com
O1 - Hosts: 219.153.5.189ting78.com
O1 - Hosts: 219.153.5.189www.91.com
O1 - Hosts: 219.153.5.18991.com
O1 - Hosts: 219.153.5.189www.flashchina.net
O1 - Hosts: 219.153.5.189flashchina.net
O1 - Hosts: 219.153.5.189www.flash8.com.cn
O1 - Hosts: 219.153.5.189flash8.com.cn
O1 - Hosts: 219.153.5.189www.f130.net
O1 - Hosts: 219.153.5.189f130.net
O1 - Hosts: 219.153.5.189www.chinanim.com
O1 - Hosts: 219.153.5.189chinanim.com
O1 - Hosts: 219.153.5.189www.comicer.com
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v5.dll
O2 - BHO: QQBrowserHelperObject Class - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\qq\QQIEHelper.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\Program Files\3721\Assist\asbar.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\CnsHook.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\Program Files\3721\Assist\asbar.dll
O3 - Toolbar: IE伴郎 - {B225B89D-5E95-4194-98E8-149993071B31} - C:\PROGRA~1\NETMEE~1\CALLCO~1.DLL
O3 - Toolbar: 完美网译通 - {F43BD772-ABDD-43b7-A96A-3E9E61946EC0} - C:\WINDOWS\WORLD2\TOOLBAR\hmtoolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] ; SOUNDMAN.EXE
O4 - HKLM\..\Run: [MyIMLite_UpDate] ; rundll32 C:\WINDOWS\System32\MyIMLite\Update.dll,UpdateFirst
O4 - HKLM\..\Run: [Super Rabbit SRRestore] ; C:\Program Files\Super Rabbit\MagicSet\srrest.exe /autosave
O4 - HKLM\..\Run: [SNPP202] ; C:\WINDOWS\vsnpp202.exe
O4 - HKLM\..\Run: [CnsMin] rem Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [assistse] "C:\PROGRA~1\3721\assistse.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] ; "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Super Rabbit CDNotify] ; C:\Program Files\Super Rabbit\MagicSet\srcdnoti.exe /LOAD
O4 - HKCU\..\Run: [msnmsgr] ; "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
最后编辑2005-09-16 17:52:09
分享到:
gototop
 

O8 - Extra context menu item: !搜一搜 - res://C:\WINDOWS\downlo~1\CnsMinEx.dll/1003
O8 - Extra context menu item: Google 搜索(&G) - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: 使用Kugoo下载 - C:\PROGRA~1\KUGOO2\KugooDownX.htm
O8 - Extra context menu item: 反向链接 - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: 类似网页 - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: 缓存的网页快照 - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: 翻译英文字词(&T) - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm?pid=U_superrsoft_62756 (file missing)
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-219?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O9 - Extra 'Tools' menuitem: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-219?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\qq\QQIEHelper.dll (file missing)
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\qq\QQIEHelper.dll (file missing)
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O11 - Options group: [!CNS]  网络实名
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com
O16 - DPF: {2EA6D939-4445-43F1-A12B-8CB3DDA8B855} (BlueskyVideo Control) - http://www.bluesky.cn/download/v2_60.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/06b4e00107027e653205/netzip/RdxIE601_cn.cab
O16 - DPF: {991481A7-4669-4E15-8C24-100404E1F5CB} (Blueskyvoice Control) - http://www.bluesky.cn/download/blueskyvoice_60.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {C14D003A-DA41-4FEE-8204-62A94EAA29D1} (GLWebAvt Control) - http://bbs.ourgame.com/image/GLWebAvt.cab
O16 - DPF: {CC4FE0DB-801C-4ACB-A17B-5D816C72000B} (SetupDrv Control) - http://www.hinovo.com:8080/autodrv/SetupDrvX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9433A8E5-8F8D-4D10-979F-F2D4FE5E81C2}: NameServer = 61.177.7.1 221.228.255.1
O23 - Service: KXAgent Service (KXAgentService) - SmartDove - C:\Program Files\LLJAgent\KXAgentS.exe

gototop
 

【回复“酸草莓”的帖子
首先打全您系统所需要的补丁.运行hijackthis修复:
所有01项,
O3 - Toolbar: 完美网译通 - {F43BD772-ABDD-43b7-A96A-3E9E61946EC0} - C:\WINDOWS\WORLD2\TOOLBAR\hmtoolbar.dll
O4 - HKLM\..\Run: [SNPP202] ; C:\WINDOWS\vsnpp202.exe

删除:
C:\WINDOWS\WORLD2\整个目录
C:\WINDOWS\vsnpp202.exe


gototop
 

请修复所有的01项先,别的可能还有问题,把C:\WINDOWS\vsnpp202.exe打包发到robinkillingvirus@yahoo.com.cn
gototop
 

晕死!!楼主的系统怎么老出问题?
如果我是你,干脆重装系统,打上所有补丁。然后,用GHOST做个系统备份。一旦再出问题,也不用这么累了。用GHOST备份恢复系统,只需要10来分钟。
gototop
 

嘻嘻,问题是我自己不会装啊,我得请人装,好象挺麻烦!
gototop
 

你们对电脑很精通,令人羡慕,唉,电脑出问题真是难倒我!
gototop
 

怎样删除Trojan.PSW.QQRobber.ay
gototop
 

多向别人请教,日积月累阿
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT