瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】高手们在吗???帮帮我,要被病毒搞疯了5555555

123   2  /  3  页   跳转

【求助】高手们在吗???帮帮我,要被病毒搞疯了5555555

5555555555555555555555555555555555555555我的电脑到底怎么了啊?游戏上去不到3分钟就毫无反应了,只能看见别人动.都10天了555555555555555555555系统装了N遍55555555555555555开始是中木马病毒了,什么灰鸽子,特洛伊乱七八糟的,现在已经查不到毒了,怎么还这样啊5555555555555555555
gototop
 

55555555555555555555我就是看猫扑看的,都是看八卦新闻看的55555555555555555555.我以后再也不看了5555555555555555555555,我现在好后悔啊555555555555555555以前电脑什么杀软都没装2年了都没中过毒的啊55555555555555555怪不得人家说猫是因为好奇死掉的555555555555555555我现在就快死了55555555555555555555
gototop
 

Logfile of Kaka v2. 0. 0. 8 Scan Module v2. 0. 0. 1
Scan saved at 07:56:31, on 2006-03-27
Platform: Microsoft Windows XP Professional Service Pack 2 (Build 2600)
MSIE: Internet Explorer v6.00 SP2; (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))


Running processes:
[smss.exe]
CommandLine =

[csrss.exe]
CommandLine = C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

[winlogon.exe]
CommandLine = winlogon.exe

[services.exe]
CommandLine = C:\WINDOWS\system32\services.exe

[lsass.exe]
CommandLine = C:\WINDOWS\system32\lsass.exe

[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch

[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss

[CCenter.exe]
CommandLine = "d:\Program Files\Rising\Rav\CCenter.exe"

[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs

[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k NetworkService

[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k LocalService

[RavMonD.exe]
CommandLine = "d:\Program Files\Rising\Rav\Ravmond.exe"

[rfwsrv.exe]
CommandLine = "g:\Program Files\Rising\Rfw\rfwsrv.exe"

[spoolsv.exe]
CommandLine = C:\WINDOWS\system32\spoolsv.exe

[alg.exe]
CommandLine = C:\WINDOWS\System32\alg.exe

[RavStub.exe]
CommandLine = "d:\Program Files\Rising\Rav\RavStub.exe" /RAVMOND

[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k HTTPFilter

[explorer.exe]
CommandLine = C:\WINDOWS\Explorer.EXE

[rfwmain.exe]
CommandLine =  -StartUp

[wscntfy.exe]
CommandLine = C:\WINDOWS\system32\wscntfy.exe

[ADeck.exe]
CommandLine = "C:\Program Files\VIAudioi\SBADeck\ADeck.exe" 1

[RavTask.exe]
CommandLine = "D:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM

[ctfmon.exe]
CommandLine = "C:\WINDOWS\system32\ctfmon.exe"

[RavMon.exe]
CommandLine = "D:\Program Files\Rising\Rav\Ravmon.exe" -SYSTEM

[Dot1XClient.exe]
CommandLine = "C:\Program Files\Huawei-3Com\H3C 802.1X 客户端\Dot1XClient.exe"

[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k imgsvc

[RsAgent.exe]
CommandLine = "d:\Program Files\Rising\Rav\RsAgent.exe"

[agentsvr.exe]
CommandLine = C:\WINDOWS\msagent\AgentSvr.exe -Embedding

[Maxthon.exe]
CommandLine = "G:\Program Files\Maxthon\Maxthon.exe"

[notepad.exe]
CommandLine = "C:\WINDOWS\system32\NOTEPAD.EXE" C:\Documents and Settings\li\My Documents\KakaProcList.txt

[KkScan.exe]
CommandLine = "D:\Program Files\Rising\KakaToolBar\KkScan.exe"

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: QQBrowserHelperObject Class - {54EBD53A-9BC1-480B-966A-843A333CA162} - g:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\PROGRA~1\FLASHGET\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\fgiebar.dll (file missing)
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RfwMain] "g:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [RavTask] "d:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O8 - Extra context menu item: 使用网际快车下载 - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\Program Files\FlashGet\jc_all.htm
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\flashget.exe (file missing)
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\flashget.exe (file missing)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra Button: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} - http://www.rising.com.cn/?u=RSTB (file missing)
O9 - Extra Button: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com/?u=RSTB (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AXSafeControls.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C1A56C6C-454B-4786-9B58-32FE6381DD3A}: NameServer = 202.103.96.112,202.103.96.68
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O23 - Service: Human Interface Device Access (HidServ) -  - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - g:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - g:\Program Files\Rising\Rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - "d:\Program Files\Rising\Rav\CCenter.exe"
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - "d:\Program Files\Rising\Rav\Ravmond.exe"
gototop
 

拜托那位高手能在帮我看看好吗?我的电脑到底出什么问题了?上跑跑卡丁车也掉线,大话西游更不用说了,上去用不了几分钟就什么也操作不了了,但是也不掉线,就那么挂在那里......是不是中了病毒啊,瑞星也没查出来5555555
gototop
 

KakaProcList.txt这个不是卡卡上网助手吗???我刚下的哦 难道是病毒~~~
gototop
 

哦,我知道了:)是刚才导出的进程日志,呵呵,想发上来让大家看看,可是太大了好象,发不上来
gototop
 

啊,那怎么办啊?我用的是校园网哦,不用这个上不了网的啊.我之前用校园网一个多月了都没有事情,10天前开始倒霉的555555.查出来好多病毒,灰鸽子,特洛伊好有好多没记着名字55555还有以前用卡巴斯基,老发现有同校园网的IP攻击我的电脑55555我恨死他们了555555我的游戏帐号还被盗了一次,我正上着画面消失,然后出现一小对话框,写着:木马已清楚,请即使修改密码55555传了身份证帐号才要回来555555
gototop
 

还有每次删掉Prefetch文件夹下的那个PF文件,重启后瑞星总是有问题.第一次是提示我瑞星出现致命错误,无法运行.第二次是内存监控被禁止,怎么也启动不了...刚我又把哪个SVCHOST.EXE-3530F672.pf文件删了,不知道再重启的话瑞星又会怎样......
gototop
 

谁来帮我看看我的电脑到底怎么了
gototop
 

附上我的进程表:高手帮看看有问题不?
agentsvr.exe li
RsAgent.exe  li
taskmgr.exe  li
svchost.exe  SYSTEM
Dot1XClient.exe li
esplorer.exe li
ADeck.exe    li
notepad.exe  li
spoolsv.exe  SYSTEM
Maxthon.exe  li
rfwsrv.exe  SYSTEM
RavMonD.exe  SYSTEM
svchost.exe  LOCAL SERVICE
svchost.exe  NETWORK SERVICE
svchost.exe  SYSTEM
CCenter.exe  SYSTEM
Ravmon.exe  li
ctfmon.exe  li
Ravtask.exe  li
svchost.exe  NETWORK SERVICE
svchost.exe  SYSTEM
lsass.exe    SYSTEM
services.exe SYSTEM
winlogon.exe SYSTEM
csrss.exe    SYSTEM
svchost.exe  SYSTEM
smss.exe    SYSTEM
wscntfy.exe  li
RavStub.exe  li
rfwmain.exe  li
alg.exe      LOCAL SERVICE
System      SYSTEM
System Idle Process SYSTEM
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT