1   1  /  1  页   跳转

高手来看看(日志)

高手来看看(日志)

1.电脑 点一个文件 再点另一个文件  两个都会被选中
2.好几种病毒 都记不清了 大概10多种. 不同的.. (杀了N次 还剩几个)
3. 任务管理器 里显示的 PF使用率  250多MB哇!  慢死了 以前90多MB的 (我没安什么软件  就是瑞星杀毒)






HijackThis@Qoo的扫描日志  V1.97.7
Scan saved at 21:16:53, on 2006-8-3
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\wdfmgr.exe
D:\Program Files\rising\Rfw\Rfw.exe
D:\Program Files\rising\Rav\RavTask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe
D:\Program Files\rising\Rav\Ravmond.exe
D:\Program Files\rising\Rav\RAVMON.EXE
D:\Program Files\rising\Rav\RavStub.exe
D:\Program Files\rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\WINDOWS\system32\conime.exe
D:\qq\QQ.exe
D:\qq\TIMPlatform.exe
D:\qq\QQexternal.exe
C:\WINDOWS\system32\RunDll32.exe
C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX00.291\HijackThis.exe

R3 - URLSearchHook: (no name) - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - (no file)
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v14.dll
O2 - BHO: (no name) - {14A21378-5BB1-4BC4-95D5-5D3F51527F6F} - C:\WINDOWS\system32\smflash.ocx
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\qq\QQIEHelper.dll (file missing)
O2 - BHO: (no name) - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\Progra~1\Baidu\bar\BaiDuBar.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll
O2 - BHO: (no name) - {999ADFA2-8AD1-47ff-97FC-69FB847458F4} - C:\Progra~1\NetMeeting\nmview.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {F43BD772-ABDD-43b7-A96A-3E9E61946EC0} - (no file)
O3 - Toolbar: ????? - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\Progra~1\Baidu\bar\BaiDuBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: NB46 - {56E88004-7AF8-474C-BB30-76E0B7B2B003} - C:\PROGRA~1\nb46.com\NB46TO~1.DLL
O4 - HKLM\..\Run: [rfw] d:\Program Files\rising\Rfw\Rfw.exe
O4 - HKLM\..\Run: [RavTask] "D:\Program Files\rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [Thunder] "D:\Program Files\Thunder Network\Thunder\ThunderShell.exe" /s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: NTUSER.DAT
O4 - Startup: 桌面.lnk
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Global Startup: ntuser.dat
O4 - Global Startup: ntuser.dat.LOG
O8 - Extra context menu item: &使用迅雷下载 - D:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: Google 搜索(&G) - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\qq\SendMMS.htm
O9 - Extra button: QQ (HKLM)
O10 - Unknown file in Winsock LSP: c:\windows\system32\quartz32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\quartz32.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O16 - DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} (MMCPlayer Class) - http://p3p.sogou.com/MMCShell.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{05AAF654-DC3B-4B7F-B1E9-1E0B6B8955BE}: NameServer = 219.150.32.132 211.98.2.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{05AAF654-DC3B-4B7F-B1E9-1E0B6B8955BE}: NameServer = 219.150.32.132 211.98.2.4
O17 - HKLM\System\CS3\Services\Tcpip\..\{05AAF654-DC3B-4B7F-B1E9-1E0B6B8955BE}: NameServer = 219.150.32.132 211.98.2.4
O17 - HKLM\System\CS4\Services\Tcpip\..\{05AAF654-DC3B-4B7F-B1E9-1E0B6B8955BE}: NameServer = 219.150.32.132 211.98.2.4

最后编辑2006-08-03 22:54:39
分享到:
gototop
 

C:\WINDOWS\system32\svchost.exe

这个有8个哇!! 郁闷死  谁救救我哇``
电脑好慢哇`
gototop
 

天!你还来个" V1.97.7"的都已经"v1.99.1"了!!!

http://www.skycn.com/soft/15753.html
gototop
 

先清理流氓吧!
将你的搜狗和百度搜索都删掉.最好用超级兔子系列软件删除,然后将你的rising病毒库升级后全盘杀一下毒.
gototop
 

晕``杀了 一直还有啊 `` 郁闷 

日志有没问题???
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT