瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 谁能帮帮我?好郁闷啊(有日志,谢谢啊)

1   1  /  1  页   跳转

谁能帮帮我?好郁闷啊(有日志,谢谢啊)

谁能帮帮我?好郁闷啊(有日志,谢谢啊)

Logfile of HijackThis v1.99.0
Scan saved at 19:54:13, on 2008-1-8
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\WINDOWS\System32\conime.exe
D:\QQ\TXPlatform.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
F:\HijackThis\HijackThis\HijackThis.exe

F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: QQCycloneHelper - {00000000-12C9-4305-82F9-43058F20E8D2} - (no file)
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] ;RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BeatTrojan] F:\Program Files\木马清除大师2008\BeatTrojanMon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &使用BitComet下载全部链接 - res://E:\BT\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &使用超级旋风下载 - F:\超级旋风\geturl.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\QQ\AddEmotion.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - D:\比特精灵\比特精灵\bsurl.htm
O8 - Extra context menu item: 设为 Messenger Live 头像 - F:\msnshell\Bin\SetMSNDP.htm
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvkoo.com/update/KooPlayer.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: 9E3D3248 - Unknown - C:\WINDOWS\System32\9E8F3418.EXE
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: 卡巴斯基反病毒6.0 - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: P4P Service - Sohu.com Inc. - C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
O23 - Service: Rising Proxy  Service - Unknown - c:\program files\rising\rfw\rfwproxy.exe (file missing)
O23 - Service: Rising Personal Firewall Service - Unknown - c:\program files\rising\rfw\rfwsrv.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) - Unknown - %ProgramFiles%\WinPcap\rpcapd.exe (file missing)
O23 - Service: Rising Process Communication Center - Unknown - C:\Program Files\rising\Rav\CCenter.exe (file missing)
O23 - Service: RsRavMon Service - Unknown - C:\Program Files\rising\Rav\Ravmond.exe (file missing)
O23 - Service: 木马清除大师实时监控 - Unknown - f:\Program Files\木马清除大师2008\BeatTrojanSvc.exe (file missing)



[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Poco 0.31; iebar; acc=baadshah; acc=none; TencentTraveler ; (R1 1.3); .NET CLR 1.1.4322)
最后编辑2008-01-09 15:47:16
分享到:
gototop
 

55555555
没人帮帮我吗 郁闷啊 郁闷啊
gototop
 

版主不要怪我灌水
gototop
 

O23 - Service: 9E3D3248 - Unknown - C:\WINDOWS\System32\9E8F3418.EXE

此项异常。用hijakthis修复后,重启电脑删除 C:\WINDOWS\System32\9E8F3418.EXE这个文件。
gototop
 

C:\WINDOWS\System32\ups.exe删
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT