我昨天中了QQ尾巴病毒 后来上网按照网上的手动清除方法做 不知道自己事真的清除了没有 本人事菜鸟啊 昨天还要好笑 居然在这个论坛发帖子和回复都不行 点最后的发表没反映 只能看潜水,刚才重新装了下瑞星 结果帖子好发了 可是在主程序上点查毒马上跳出来查毒结束的窗口 根本救没有杀毒 不知道是什么原因啊
Logfile of HijackThis v1.99.1
Scan saved at 16:29:16, on 2005-07-11
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\联想\联想键盘驱动\Ps2Kbdriver.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\联想\联想键盘驱动\fastkey.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\IInfo\InfoNet.exe
C:\WINDOWS\system32\conime.exe
D:\新建文件夹 (2)\Rising\Rav\RavTimer.exe
D:\新建文件夹 (2)\RISING\RAV\CCENTER.EXE
D:\HijackThis\HijackThis.exe
O1 - Hosts: 207.46.249.190 www.microsoft.com
O1 - Hosts: 207.46.249.190 www.microsoft.com
O1 - Hosts: 211.100.15.60 www.pcsight.com
O1 - Hosts: 210.15.51.58 www.jicn.com
O1 - Hosts: 61.151.248.50 www.salala.com
O1 - Hosts: 211.147.60.72 www.chinamp3.com.
O1 - Hosts: 210.15.51.24 bbs.huyuonline.com
O1 - Hosts: 202.102.4.36 www.alone-city.com
O1 - Hosts: 61.129.70.69 tv.xicu.com
O1 - Hosts: 61.152.251.84 soft.winzheng.com
O1 - Hosts: 218.5.77.248 www.cnvp.com
O1 - Hosts: 61.243.189.16 bbs.xicu.com
O1 - Hosts: 61.135.137.51 www.joypark.com.cn
O1 - Hosts: 202.108.250.214 mp3.baidu.com
O1 - Hosts: 61.145.116.135 www.bluedon.com
O1 - Hosts: 211.154.171.139 www.netfriends.com.cn
O1 - Hosts: 207.46.249.190 www.microsoft.com
O1 - Hosts: 202.108.36.156 www.163.com
O1 - Hosts: 61.135.136.3 www.e-office.com.cn
O1 - Hosts: 61.135.135.18 www.it141.com
O1 - Hosts: 211.157.220.11 www.legend.com
O1 - Hosts: 202.108.32.200 www.fm365.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\新建文~2\SPYBOT~1\SDHelper.dll
O2 - BHO: DownloadValue Class - {616D4040-5712-4F0F-BCF1-5C6420A99E14} - C:\WINDOWS\system32\winhtp.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\Program Files\FlashGet\downbest.net-flashget\downbest.net-flashget\jccatch.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - H:\Norton\NavShExt.dll (file missing)
O3 - Toolbar: 博采 - {4DA2EE61-6399-4C39-AEB9-0D990E610D29} - C:\WINDOWS\system32\BOCAIT~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HuaShanTGEKBDPS2] C:\Program Files\联想\联想键盘驱动\Ps2Kbdriver.exe
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [TanLinkb] C:\Program Files\Legend\联想键盘驱动\Ps2Kbdriver.exe
O4 - HKLM\..\Run: [ExFilter] Rundll32.exe "C:\PROGRA~1\CNNIC\Cdn\cdnspie.dll,ExecFilter solo"
O4 - HKLM\..\Run: [RavTimer] D:\新建文~2\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] D:\新建文~2\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: 使用网际快车下载 - D:\Program Files\FlashGet\downbest.net-flashget\downbest.net-flashget\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\Program Files\FlashGet\downbest.net-flashget\downbest.net-flashget\jc_all.htm
O9 - Extra button: (no name) - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - c:\HAPPYH~1\XDict\IEPlugin.dll (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Program Files\FlashGet\downbest.net-flashget\downbest.net-flashget\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Program Files\FlashGet\downbest.net-flashget\downbest.net-flashget\flashget.exe
O9 - Extra button: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-195?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O9 - Extra 'Tools' menuitem: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-195?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.fm365.com
O16 - DPF: {098A3F72-3110-4004-B954-2F9DC44934B4} (AddSHCARoot Control) - http://www.sheca.com/AddSHCARootCert.cab
O16 - DPF: {14DD0EC3-98B0-48F2-84BB-09B8403C7C71} (TrainerOCX Control) - http://www.lenovohelp.com/ccversions/8/install/installer.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/095b450022e909bbda05/netzip/RdxIE601_cn.cab
O16 - DPF: {58CDB34C-B4D7-418B-A0FB-C4C8A01C2F0E} - http://diy.51.net/download/diybar.cab
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {7FC22A16-79E6-4787-9C96-B6359BB1106D} (DigitalTrafic Control) - http://www.jt.sh.cn/trafficmap/jtj.cab
O16 - DPF: {9BBD100C-E820-4930-9937-E8F3AA40E584} (DFVSScanFile Control) - http://antivirus3.sunv.com/dfvsolDown/dfvsol.cab
O16 - DPF: {CDC9134A-ABEB-4611-947D-E4DEC7EBD83E} (QDiagLEUpdateObj Class) - http://www.lenovohelp.com/html/qdiagle.cab
O16 - DPF: {D8B23265-10CA-4844-B2E3-E2840DF7EEF3} (WebRun Control) - http://www.59ie.com/online/webrun.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan
Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D550508A-C35E-4ED5-AA3B-56B6C18C9038}: NameServer = 202.96.209.6 202.96.209.133
O20 - AppInit_DLLs: APIHookDll.dll
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: QQ - Unknown owner - C:\WINDOWS\system32\H_Server.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - D:\新建文件夹 (2)\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Unknown owner - H:\新建文件夹 (2)\RAV-2005.V17.07.40\RISING\RAV\Ravmond.exe (file missing)