电脑昨天晚上中了超级病毒了,瑞星都打不开,瑞星网页也打不开了,还有正在游戏的帐号也被盗了!本想电脑全部格式了,可电脑里有好多照片不舍得。昨天晚上搞到12点多电脑才好一点,现在搞了日志请高手帮帮忙看看病毒还有吗!谢谢大家了!Logfile of HijackThis v1.99.1
Scan saved at 17:49:27, on 2009-4-29
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
E:\Rising\Rav\CCENTER.EXE
C:\WINDOWS\System32\svchost.exe
E:\Rising\Rav\RavTask.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
e:\Rising\Rfw\rfwsrv.exe
e:\Rising\Rfw\rfwProxy.exe
e:\Rising\Rfw\rfwstub.exe
E:\Rising\Rav\rsnetsvr.exe
C:\Program Files\kingsoft\KSWebShieldSVC\KSWebShield.exe
e:\Rising\Rfw\RfwMain.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\Rising\Rav\rssafety.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\StormII\stormliv.exe
C:\Program Files\Tencent\QQSoftMgr\TencentUpdateSvc.exe
C:\WINDOWS\System32\alg.exe
D:\wow\World of Warcraft(3.0.5)\BigFoot.exe
E:\TheWorld 2.0\TheWorld.exe
E:\Rising\Rav\ScanFrm.exe
E:\杀\KSMSvc.exe
E:\RISING\RAV\RSTRAY.EXE
E:\RISING\RAV\RSMAIN.EXE
E:\Rising\Rav\RavMonD.exe
E:\日志查看器\HijackThis.exe
O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll
O2 - BHO: 卡卡上网安全助手 - {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} - C:\WINDOWS\system32\UrlFilter.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [RfwMain] "e:\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RavTray] "E:\Rising\Rav\RsTray.exe" -system
O4 - HKLM\..\Run: [safety3] "E:\Rising\Rav\rssafety.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: 使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\geturl.htm
O8 - Extra context menu item: 使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ表情 - E:\QQ\Bin\AddEmotion.htm
O9 - Extra button: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra 'Tools' menuitem: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O17 - HKLM\System\CCS\Services\Tcpip\..\{74204E81-BAEB-41E6-9F62-3D9603E1933A}: NameServer = 61.153.81.75 61.153.81.74
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O23 - Service: Contrl Center of Storm Media (ccosm) - 北京暴风网际科技有限公司 - C:\Program Files\StormII\stormliv.exe
O23 - Service: Kingsoft Antivirus WebShield Service - Kingsoft Corporation - C:\Program Files\kingsoft\KSWebShieldSVC\KSWebShield.exe
O23 - Service: Kingsoft Rescue Service - Unknown owner - E:\杀\KSMSvc.exe
O23 - Service: Rav Process Communication Center (RavCCenter) - Beijing Rising Information Technology Co., Ltd. - E:\Rising\Rav\CCENTER.EXE
O23 - Service: Rising RavTask Manager (RavTask) - Unknown owner - E:\Rising\Rav\RavTask.exe" RavTask (file missing)
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Information Technology Co., Ltd. - e:\Rising\Rfw\rfwProxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Information Technology Co., Ltd. - e:\Rising\Rfw\rfwsrv.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Information Technology Co., Ltd. - E:\Rising\Rav\RavMonD.exe
O23 - Service: Rising Scan Service (RsScanSrv) - Beijing Rising Information Technology Co., Ltd. - E:\Rising\Rav\ScanFrm.exe
O23 - Service: Tencent Software Update Service (TSUSVC) - Unknown owner - C:\Program Files\Tencent\QQSoftMgr\TencentUpdateSvc.exe" -run (file missing)
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; TheWorld)