瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求助!!!!!!怎么瑞星会自动关闭!(在线等~~)

1   1  /  1  页   跳转

求助!!!!!!怎么瑞星会自动关闭!(在线等~~)

求助!!!!!!怎么瑞星会自动关闭!(在线等~~)

不知道中了什么毒,用瑞星杀毒,就出现错误,自动关闭。同时也打不开,超级兔子和那360安全卫士,那专杀工具也杀到一般就跳掉了,重复几次也一样,进安全模式用瑞星,没毒,也打得开超级兔子和那360安全卫士。。。。
希望知道的帮帮我,万分感激!!!!
本人是2000的系统!!



Logfile of HijackThis v1.99.1
Scan saved at 11:32:08, on 2006-12-14
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
C:\PROGRA~1\MICROS~3\MSSQL\binn\sqlservr.exe
C:\Program Files\PeanutHull3\PhCore.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
D:\GRASP2~1\scktsrvr.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\Program Files\PeanutHull3\Phmain.exe
G:\123\winpip.exe
C:\Program Files\ChinaNet\VnetClient.exe
C:\Program Files\Tencent\TT\TCPlus.exe
D:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\桌面\ha_hijackthis_1991\HijackThis.exe

O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3}? - (no file)
O3 - Toolbar: (no name) - {406F94F0-504F-4a40-8DFD-58B0666ABEBD}? - (no file)
O3 - Toolbar: (no name) - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C}? - (no file)
O4 - HKLM\..\Run: [NopoosPad] C:\Program Files\NopoosPad\NopoosPen.exe
O4 - HKLM\..\Run: [SocketServer] D:\GRASP2~1\scktsrvr.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\RunOnce: [KKDelay] C:\Program Files\Rising\KakaToolBar\RunOnce.exe
O4 - HKLM\..\RunOnce: [Super Rabbit SRCK] "D:\Program Files\Super Rabbit\MagicSet\SRCK.exe" /autokill:14
O4 - HKCU\..\Run: [PhMain] C:\Program Files\PeanutHull3\Phmain.exe
O4 - Startup: 快捷方式 winpip.lnk = G:\123\winpip.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &使用迅雷下载 - D:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O9 - Extra button: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}? - D:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}? - D:\Program Files\Tencent\QQ\QQ.EXE
O16 - DPF: {1E0DFFCF-27FF-4574-849B-55007349FEDA} (iTrusPTA Class) - http://211.140.10.27:8081/commons/include/iTrusPta.cab
O16 - DPF: {52DF16E3-6C4F-4B22-8BAF-09263E463B48} - http://www.duba.net/cab/KOSInit.cab
O16 - DPF: {6DBB2904-082D-4DB0-944A-21C22BA121F4} (CCtInf Class) - http://www.95599.cn/perbank/BankControl.cab
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {C09B522F-8AED-4E21-A65C-DC1AB652BAEE} (Tencent Safety Online Base Module) - http://safe.qq.com/cgi-bin/tso/TSOBase.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{FD0061FB-581C-4437-96AA-26219DEA8AEC}: NameServer = 202.96.104.26 202.96.104.16
O18 - Protocol hijack: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300}?
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: PeanuthullCore - 广东网域 - C:\Program Files\PeanutHull3\PhCore.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: SentinelProtectionServer - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

附件附件:

下载次数:235
文件类型:image/pjpeg
文件大小:
上传时间:2006-12-14 11:01:50
描述:
预览信息:EXIF信息



最后编辑2006-12-14 15:13:57.090000000
分享到:
gototop
 

贴日志上来
gototop
 

如何上传日志,参看置顶贴
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 11:32:08, on 2006-12-14
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
C:\PROGRA~1\MICROS~3\MSSQL\binn\sqlservr.exe
C:\Program Files\PeanutHull3\PhCore.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
D:\GRASP2~1\scktsrvr.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\Program Files\PeanutHull3\Phmain.exe
G:\123\winpip.exe
C:\Program Files\ChinaNet\VnetClient.exe
C:\Program Files\Tencent\TT\TCPlus.exe
D:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\桌面\ha_hijackthis_1991\HijackThis.exe

O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3}? - (no file)
O3 - Toolbar: (no name) - {406F94F0-504F-4a40-8DFD-58B0666ABEBD}? - (no file)
O3 - Toolbar: (no name) - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C}? - (no file)
O4 - HKLM\..\Run: [NopoosPad] C:\Program Files\NopoosPad\NopoosPen.exe
O4 - HKLM\..\Run: [SocketServer] D:\GRASP2~1\scktsrvr.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\RunOnce: [KKDelay] C:\Program Files\Rising\KakaToolBar\RunOnce.exe
O4 - HKLM\..\RunOnce: [Super Rabbit SRCK] "D:\Program Files\Super Rabbit\MagicSet\SRCK.exe" /autokill:14
O4 - HKCU\..\Run: [PhMain] C:\Program Files\PeanutHull3\Phmain.exe
O4 - Startup: 快捷方式 winpip.lnk = G:\123\winpip.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &使用迅雷下载 - D:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O9 - Extra button: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}? - D:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}? - D:\Program Files\Tencent\QQ\QQ.EXE
O16 - DPF: {1E0DFFCF-27FF-4574-849B-55007349FEDA} (iTrusPTA Class) - http://211.140.10.27:8081/commons/include/iTrusPta.cab
O16 - DPF: {52DF16E3-6C4F-4B22-8BAF-09263E463B48} - http://www.duba.net/cab/KOSInit.cab
O16 - DPF: {6DBB2904-082D-4DB0-944A-21C22BA121F4} (CCtInf Class) - http://www.95599.cn/perbank/BankControl.cab
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {C09B522F-8AED-4E21-A65C-DC1AB652BAEE} (Tencent Safety Online Base Module) - http://safe.qq.com/cgi-bin/tso/TSOBase.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{FD0061FB-581C-4437-96AA-26219DEA8AEC}: NameServer = 202.96.104.26 202.96.104.16
O18 - Protocol hijack: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300}?
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: PeanuthullCore - 广东网域 - C:\Program Files\PeanutHull3\PhCore.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: SentinelProtectionServer - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

gototop
 

大家谁知道呀,帮我看看呀。本人很急呀,谢谢!!!!!!!
gototop
 

你把瑞星升到最新 进安全模式就可以把  这个免杀  搞了
gototop
 

急呀,瑞星升到最新了,进安全模式也查不出毒呀,有时突然变蓝屏,郁闷了。。。。。。。
希望各位高手帮帮我了呀。。。万分感激。。。。
gototop
 

和我一样的情况 我也等待解决方法
gototop
 

晕了,搞了一天了。也没弄好。。。。现在连QQ都被盗了。。。
各位大虾快帮帮我呀。。。。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT