瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 救命啊`~各位高手~~小弟先拜下了~~

1   1  /  1  页   跳转

救命啊`~各位高手~~小弟先拜下了~~

救命啊`~各位高手~~小弟先拜下了~~

昨日上网时突然出现个什么16位程序,自动安装了几个CNNIC之类的软件.后系统崩溃...
进去把能删的都删了后,还有几个删不掉.TEMP文件里出现了几个在安全模式也删不了的文件.还有几个DOS的批处理文件..
进程中比平时多了2个SVCHOST,有2个CSRSS.EXE进程.还有个WNGJLFJAOI.COM进程.都不能结束 .之前还有提示自动关机,后来装了个补丁就好象没了,请各位大哥帮帮我吧.感激不尽!
Logfile of HijackThis v1.99.1
Scan saved at 21:56:17, on 2006-9-16
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\crypserv.exe
D:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\windows\system32\inetsrv\csrss.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\temp\wngjlfjaoi.Com
D:\Program Files\Winamp\Winamp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\My Documents\Huawei\PortalServer\202.109.117.146\PortalClient.exe
D:\Program Files\shadu\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Macromedia. Flash8 Object - {C61A70F3-505E-4B90-916F-627A8706B4BC} - c:\WINDOWS\system32\FlashPlayer8OCX.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\QQ\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用迅雷下载 - D:\Program Files\Thunder\geturl.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\QQ\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\QQ\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\QQ\QQ\SendMMS.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - D:\Program Files\BitSpirit\bsurl.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\quartz32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\quartz32.dll
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {414E7D87-8073-4EFB-9E4B-C8DF04C979EE} (PortalCom AAA 1.0) - http://202.109.117.146/PortalAX02.cab
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AXSafeControls.cab
O20 - Winlogon Notify: Group Policy - C:\WINDOWS\system32\irlol5331.dll
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Diskeeper - Diskeeper Corporation - D:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Network Logon (NetWorkLogon) - Unknown owner - rundll32.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
最后编辑2006-09-16 22:17:44
分享到:
gototop
 

http://forum.ikaka.com/topic.asp?board=28&artid=8171746
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT