瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 千千静听中了downloader.delf.awm,高手请帮忙

1   1  /  1  页   跳转

千千静听中了downloader.delf.awm,高手请帮忙

千千静听中了downloader.delf.awm,高手请帮忙

运行千千静听后,AVG显示其中了downloader.delf.awm,隔离后重新安装千千静听,还是出现这个问题。
路径是c:\program files\TTPlayer\TTPlayer.exe

附上扫描日志,望高手早日帮忙,好让我重新用上静听


Logfile of HijackThis v1.99.1
Scan saved at 21:11:19, on 2006-12-30
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\MyIE\MyIE.exe
D:\程序\VIRUS\hijackthis_PConline\HijackThis.exe

R3 - Default URLSearchHook is missing
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} -

C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program

Files\BitComet\BitCometBar\BitCometBar0.1.dll
O3 - Toolbar: 超级兔子上网精灵 - {43869BB3-22FD-4F15-9B46-238106BA2F4E} -

C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] ; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil

/RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\System32

\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [StormCodec_Helper] ; "C:\Program Files\Ringz Studio\Storm

Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [ThunderMini] ; C:\Program Files\Thunder

Network\ThunderMini\ThunderMiniShell.exe
O4 - HKLM\..\Run: [WangWang] ; "C:\Program Files\淘宝网\淘宝旺旺\WangWang.EXE"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware

7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft

Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1

\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program

Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program

Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} -

C:\Program Files\Tencent\QQ\QQ.EXE
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -

http://forevermizu.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) -

http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2E44B653-A63B-4D2D-BAC0-E1F343EA4A3E}:

NameServer = 202.109.14.5 202.96.209.5
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1

\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1

\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: rpcc - C:\WINDOWS\System32\rpcc.dll
O23 - Service: 444444 (343243) -  - (no file)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. -

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky

Anti-Virus Personal Pro\kavsvc.exe
O23 - Service: Remote Map Manager - Unknown owner - C:\WINDOWS\system32\lssc.exe

(file missing)
O23 - Service: Remote Process Manager - Unknown owner - C:\WINDOWS\system32

\vcmon.exe (file missing)
最后编辑2006-12-31 18:15:48
分享到:
gototop
 

忘记说明一下,我用过千橡专杀工具扫描,显示无病毒。郁闷啊
gototop
 

你去千千官方再下载一个千千静听的软件 把原来的卸载 然后装新的 看还报不报 如果还报就是AVG误报
gototop
 

AVG误报严重
他在病毒裤上做了手脚
gototop
 

修复:
R3 - Default URLSearchHook is missing
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O23 - Service: 444444 (343243) - - (no file)
O23 - Service: Remote Map Manager - Unknown owner - C:\WINDOWS\system32\lssc.exe

(file missing)
O23 - Service: Remote Process Manager - Unknown owner - C:\WINDOWS\system32

\vcmon.exe (file missing)
最后2项 如果修复了还有的话  +我QQ51877638
gototop
 

去官方网站上下载了个新版的,安装后不报了。难道是我以前用千千静听的时候就已经中毒了,到现在才报吗?还是版本的问题?

修复那几项后再扫描就没有了,不知道那是什么东东.

谢谢大家!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT