中毒了,请大家帮忙看看。
症状:进入正常模式会出现不断的重新启动,安全模式可以进入在控制面板中-管理工具中查看服务,很多都被关闭。下面是我用hijckthis扫描的结果:入,Logfile of HijackThis v1.99.1
Scan saved at 18:54:04, on 2006-7-18
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\userinit.exe
C:\WINNT\Explorer.EXE
C:\Documents and Settings\Administrator\桌面\HijackThis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SAV\vptray.exe
***O4 - HKLM\..\Run: [zskosyldgnr]x[_veponiwmdksz_] c:\winnt\system32\_zskdmwinopev_[x]rngdlyso.exe
***O4 - HKLM\..\Run: [SchedulingAgent] mstinit.exe /firstlogon
***O4 - HKLM\..\RunServices: [zskosyldgnr]x[_veponiwmdksz_] c:\winnt\system32\_zskdmwinopev_[x]rngdlyso.exe
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [vptray] C:\PROGRA~1\SAV\vptray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Program Files\Navnt\navapw32.exe
O4 - Global Startup: 服务管理器.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
**O16 - DPF: {52DF16E3-6C4F-4B22-8BAF-09263E463B48} (金山毒霸在线产品升级) - http://zs.kingsoft.com/KOSInit.cab
O16 - DPF: {94CB3591-FC13-11D3-9A7F-0080C8BA18B9} (w900c288 Control) - http://192.168.10.223/webShow/w900_realtime/w900c288Proj1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{94C65543-B281-4B02-9A69-219F0F29BAAE}: NameServer = 192.168.10.2
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\\NavLogon.dll
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINNT\system32\2236_27.dll
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SAV\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Intel Alert Handler - Intel? Corporation - C:\WINNT\system32\ams_ii\hndlrsvc.exe
O23 - Service: Intel Alert Originator - Intel? Corporation - C:\WINNT\system32\ams_ii\iao.exe
O23 - Service: Intel File Transfer - Intel? Corporation - C:\WINNT\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel? Corporation - C:\WINNT\system32\cba\pds.exe
O23 - Service: Symantec AntiVirus Server (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SAV\Rtvscan.exe
O23 - Service: Symantec System Center Discovery Service (NSCTOP) - Symantec Corporation - C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
O23 - Service: Serv-U FTP Server (Serv-U) - Unknown owner - E:\Serv-U\SERVUD~1.EXE