瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】机子很慢 高手帮忙看下 附上日志

12   1  /  2  页   跳转

【求助】机子很慢 高手帮忙看下 附上日志

【求助】机子很慢 高手帮忙看下 附上日志

Logfile of HijackThis v1.99.1
Scan saved at 21:27:24, on 2006-11-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\WINLOGON.EXE
C:\WINDOWS\SOUNDMAN.EXE
D:\PROGRA~1\FIREWALL\pfw.exe
C:\KAV6\Kulansyn.EXE
C:\KAV6\KWatchUI.EXE
E:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\IGMP.exe
C:\WINDOWS\1explore.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\新文件夹\XDICT.EXE
C:\KAV6\KAVSvc.EXE
C:\WINDOWS\system32\sessmgr.exe
C:\KAV6\MailMon.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\KAV6\KAVPlus.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Program Files\bitcomet\BitComet.exe
D:\Program Files\Downloads\HijackThis.exe

F2 - REG:system.ini: Shell=Explorer.exe 1
O1 - Hosts: 221.231.138.113 wooll.host7.tfidc.com
O1 - Hosts: 221.231.138.113 www.work009.com
O1 - Hosts: 221.231.138.113 my.m365m.com
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\QQ2005\QQIEHelper.dll
O2 - BHO: HSProgSDT - {5D15CEAC-3B27-4863-AAEA-93A4C8A6C57D} - C:\WINDOWS\system32\hssdtobm.dll
O3 - Toolbar: 金山毒霸 - {A9BE2902-C447-420A-BB7F-A5DE921E6138} - C:\KAV6\KAIEPlus.DLL
O3 - Toolbar: BitComet工具栏 - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - E:\Program Files\BitComet\BitCometBar\BitCometBar0.6.dll
O4 - HKLM\..\Run: [KAVRUN] C:\KAV6\KAVRun.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SKYNET Personal FireWall] D:\PROGRA~1\FIREWALL\pfw.exe
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Kulansyn] C:\KAV6\Kulansyn.EXE
O4 - HKLM\..\Run: [KpopMon] C:\KAV6\KpopMon.EXE
O4 - HKLM\..\Run: [DAEMON Tools] "E:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
O4 - HKLM\..\Run: [IGMP] C:\WINDOWS\system32\IGMP.exe
O4 - HKLM\..\Run: [Alert] ; C:\Program Files\Starsoftcomm\StarCenter\alert.exe
O4 - HKLM\..\Run: [AutoUpd] ; C:\Program Files\Starsoftcomm\StarCenter\UpdTray.exe
O4 - HKLM\..\Run: [hxgame-update] ; C:\Program Files\hxupdate\hxgame-update.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [ISUSPM Startup] ; C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] ; "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [KernelFaultCheck] ; %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [KvMonXP] ;
O4 - HKLM\..\Run: [StarCenter] ; C:\Program Files\Starsoftcomm\StarCenter\StarCenter.exe
O4 - HKLM\..\Run: [StormCodec_Helper] ; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ravshell] C:\WINDOWS\1explore.exe
O4 - HKCU\..\Run: [eMuleAutoStart] ; D:\Program Files\eMule\eMule.exe -AutoStart
O4 - HKCU\..\Run: [Super Rabbit Desktop Search] ;
O4 - Startup: 金山词霸 2006.lnk = ?
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\QQ2005\AddToNetDisk.htm
O8 - Extra context menu item: 使用影音传送带下载 - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\QQ2005\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\QQ2005\AddEmotion.htm
O8 - Extra context menu item: 添加到雅虎订阅(&Y) - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\QQ2005\SendMMS.htm
O9 - Extra button: (no name) - {0062C9BD-B349-40DE-91A0-755F37ACD559} - (no file)
O9 - Extra button: 微软 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.microsoft.com/china/index.htm (file missing)
O9 - Extra button: 金山卓越 - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - url:http://www.joyo.com (file missing)
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\QQ2005\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\QQ2005\QQIEHelper.dll
O9 - Extra button: 金山毒霸网站 - {e1fc9760-7b95-49cd-80b9-8c9e41017b93} - url:http://www.duba.net (file missing)
O9 - Extra button: 在线查毒 - {f58d36c3-40be-4418-a786-d8fbe3eb3554} - C:\KAV6\kavie.HTM
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Database information combine (DbooInfo) - 易易加速科技有限公司 - C:\WINDOWS\dbmsinfo.exe
O23 - Service: Kingsoft AntiVirus Service (KAVSvc) - kingsoft Antivirus - C:\KAV6\KAVSvc.EXE
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exe

有时候cpu100%
最后编辑2006-11-26 23:27:42
分享到:
gototop
 

你中的毒可真不少
C:\WINDOWS\system32\IGMP.exe
C:\WINDOWS\1explore.exe
C:\WINDOWS\winlogon.exe
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exe

O4 - HKLM\..\Run: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
O4 - HKLM\..\Run: [IGMP] C:\WINDOWS\system32\IGMP.exe
O4 - HKLM\..\Run: [Alert] ; C:\Program Files\Starsoftcomm\StarCenter\alert.exe
O4 - HKLM\..\Run: [AutoUpd] ; C:\Program Files\Starsoftcomm\StarCenter\UpdTray.exe
O4 - HKLM\..\Run: [hxgame-update] ; C:\Program Files\hxupdate\hxgame-update.exe
gototop
 

怎么办呢?高手说明啊
gototop
 

1explore.exe是 Trojan.dl.agent.znb木马下载器
直接删除启动项结束进程
gototop
 

winlogon啊
原来微软的杀毒软件就可以把你干了呀
查杀结果:
Antivirus Version Update Result
AntiVir 7.2.0.46 11.25.2006  no virus found
Authentium 4.93.8 11.24.2006 Possibly a new variant of W32/Suspicious:VisualBasicMalware!Maximus
Avast 4.7.892.0 11.23.2006  no virus found
AVG 386 11.26.2006  no virus found
BitDefender 7.2 11.26.2006  no virus found
CAT-QuickHeal 8.00 11.25.2006 (Suspicious) - DNAScan
ClamAV devel-20060426 11.25.2006  no virus found
DrWeb 4.33 11.26.2006 BackDoor.Generic.1471
eSafe 7.0.14.0 11.26.2006 suspicious Trojan/Worm
eTrust-InoculateIT 23.73.67 11.25.2006 Win32/Bopninja.5cr!Trojan
eTrust-Vet 30.3.3211 11.24.2006  no virus found
Ewido 4.0 11.25.2006  no virus found
Fortinet 2.82.0.0 11.26.2006 suspicious
F-Prot 3.16f 11.24.2006 Possibly a new variant of W32/Suspicious:VisualBasicMalware!Maximus
F-Prot4 4.2.1.29 11.24.2006 W32/Suspicious:VisualBasicMalware!Maximus
Ikarus 0.2.65.0 11.24.2006 Backdoor.Win32.PcClient.GV
Kaspersky 4.0.2.24 11.26.2006  no virus found
McAfee 4904 11.24.2006  no virus found
Microsoft 1.1804 11.26.2006 PWS:Win32/Wowsteal.gen!A
NOD32v2 1882 11.24.2006 a variant of Win32/PSW.Legendmir
Norman 5.80.02 11.24.2006  no virus found
Panda 9.0.0.4 11.26.2006 Suspicious file
Prevx1 V2 11.26.2006 Polynomial.Code.Exploit
gototop
 

去微软网站下载杀毒软件 把WINLOGON干了
gototop
 

微软那个杀毒软件叫啥名字?
gototop
 

去搜下
gototop
 


微软OneCare杀毒软件

gototop
 

找到一个免费下载.但是他说只支持英文.不支持中文.无语~~~
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT