瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】请帮我检查日志,谢谢!

1   1  /  1  页   跳转

【求助】请帮我检查日志,谢谢!

【求助】请帮我检查日志,谢谢!

我的进程总是有IEXPLORE.EXE这个进程,已经按照网友的操作删除注册表的病毒进程,但是再次启动电脑依然存在这个进程,请大虾们帮我看看我的日志,由于我是第一次用HijackThis v1.99.1软件,不知道是不是正确,如真有病毒,请详细教我杀毒办法,本人电脑白痴,谢谢指教!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
d:\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
D:\rising\Rav\RavStub.exe
d:\rising\rfw\RfwMain.exe
D:\rising\Rav\RavTask.exe
D:\rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
D:\bitcomet\BitComet.exe
D:\tt\TTraveler.exe
D:\office 2003\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\conime.exe
D:\rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
F:\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: 超级兔子上网精灵 - {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} - D:\magicset\haokanbar.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\flashget\fgiebar.dll
O3 - Toolbar: BitComet工具栏 - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - d:\bitcomet\BitCometBar\BitCometBar0.6.dll
O3 - Toolbar: 超级兔子上网精灵 - {43869BB3-22FD-4F15-9B46-238106BA2F4E} - D:\magicset\haokanbar.dll
O4 - HKLM\..\Run: [RavTask] "D:\rising\Rav\RavTask.exe" -system
O4 - HKLM\..\RunOnce: [RavStub] "D:\rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: 使用网际快车下载 - D:\flashget\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\flashget\jc_all.htm
O16 - DPF: {20C2C286-BDE8-441B-B73D-AFA22D914DA5} (PowerList Control) - http://download.ppstream.com/bin/powerplayer.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1152360731109
O16 - DPF: {EF6205C1-3F17-4829-BCB5-1336ED89E356} (KvScanOnline Control) - http://online.jiangmin.com/KvDown.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} - http://cache10.itv.mop.com/pCastCtl-1.0.0.88_signed.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{662B6C90-02E9-42B3-9E33-02916BC6521A}: NameServer = 202.106.46.151 202.106.0.20
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: 卡巴斯基反病毒软件6.0 (AVP) - Unknown owner - D:\kaspersky\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\rising\Rav\Ravmond.exe
O23 - Service: Windows XP Vista        - Unknown owner - C:\WINDOWS\Hacker.com.cn.ini
最后编辑2006-08-01 09:17:55
分享到:
gototop
 

开始 运行 输入 services.msc 找到Windows XP Vista 双击 停止并且将启动类型改为 已禁用
开始 运行 输入regedit 分别定位到HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Services
查找Windows XP Vista  目录,查到的清删除整个目录
重启计算机
显示所有文件并且显示隐藏的系统文件
删除如下文件C:\WINDOWS\Hacker.com.cn.ini
gototop
 

O23 - Service: Windows XP Vista - Unknown owner - C:\WINDOWS\Hacker.com.cn.ini
灰鸽子
gototop
 

谢谢两位大虾的帮忙,非常感激,希望此贴对朋友们有帮助!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT