请问,用正版瑞星不行,杀毒软件安装出错,即出错从新启动,防火墙可以安装。
每次启动防火墙都有报木马被发现,被删除。
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 4:01:08, 日期 2002-1-1
操作系统: Windows XP SP1 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Rising\Rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\hpdriver.exe
D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\System32\r_server.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\soundman.exe
C:\windows\system\xpsp2.exe
C:\WINDOWS\System32\steam.exe
C:\WINDOWS\System32\msupdate32.exe
C:\program files\180searchassistant\salm.exe
C:\Program Files\Media Gateway\MediaGateway.exe
C:\WINDOWS\System32\msnmsrg.exe
C:\WINDOWS\System32\coderxt.exe
D:\Program Files\Rising\Rfw\RfwMain.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\osww\msuo.exe
C:\Program Files\ChinaNet\VnetClient.exe
D:\hijackthis 1.99.1 汉化第二版\hijackthisV1.99.1.exe
D:\Program Files\HijackThis1991汉化版\HijackThis1991zww.exe
O1 - Hosts: 127.0.0.0 localhost
O1 - Hosts: 134.103.64.153 aix_svr
O2 - BHO: SABHO - {21B4ACC4-8874-4AEC-AEAC-F567A249B4D4} - c:\program files\180searchassistant\salmhook.dll
O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\chinanet\VNETTR~1.DLL
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [Task service] taskmgs.exe
O4 - 启动项HKLM\\Run: [C-Media Speaker Configuration] C:\Documents and Settings\Administrator\桌面\Win2k_xp-cmi\WIN2K_XP\Setup.exe /SPEAKER
O4 - 启动项HKLM\\Run: [SoundMan] soundman.exe
O4 - 启动项HKLM\\Run: [Anti-Virus Update Scheduler] C:\windows\system\xpsp2.exe
O4 - 启动项HKLM\\Run: [System Update] C:\WINDOWS\System32\pdtwud.exe
O4 - 启动项HKLM\\Run: [steam] steam.exe
O4 - 启动项HKLM\\Run: [Network Access] winssh.exe
O4 - 启动项HKLM\\Run: [microsft Updates] msupdate32.exe
O4 - 启动项HKLM\\Run: [salm] c:\program files\180searchassistant\salm.exe
O4 - 启动项HKLM\\Run: [SAHBundle] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\BUNDLE~1.EXE run
O4 - 启动项HKLM\\Run: [Media Gateway] C:\Program Files\Media Gateway\MediaGateway.exe
O4 - 启动项HKLM\\Run: [gpwr] C:\WINDOWS\gpwr.exe
O4 - 启动项HKLM\\Run: [winnt DNS ident] msnmsrg.exe
O4 - 启动项HKLM\\Run: [System Service] coderxt.exe
O4 - 启动项HKLM\\Run: [RfwMain] "d:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [RavTimer] d:\Program Files\Rising\Rav\RavTimer.exe
O4 - 启动项HKLM\\Run: [RavMon] d:\Program Files\Rising\Rav\RavMon.exe -system
O4 - 启动项HKLM\\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - 启动项HKLM\\RunServices: [Task service] taskmgs.exe
O4 - 启动项HKLM\\RunServices: [Network Access] winssh.exe
O4 - 启动项HKLM\\RunServices: [Microsoft Update] wuamk032.exe
O4 - 启动项HKLM\\RunServices: [steam] steam.exe
O4 - 启动项HKLM\\RunServices: [microsft Updates] msupdate32.exe
O4 - 启动项HKLM\\RunServices: [winnt DNS ident] msnmsrg.exe
O4 - 启动项HKLM\\RunServices: [System Service] coderxt.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Task service] taskmgs.exe
O4 - HKCU\..\Run: [Sore] C:\Program Files\osww\msuo.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {7BD7A34E-F3EE-44B1-95A7-E04C2B7FB90C} (IDFlowViewX Control) - http://zjod.zjtelecom.cn/csscfg.nsf/AttachFile/IDFlowView/$FILE/IDFlowView.cab
O16 - DPF: {99410CDE-6F16-42ce-9D49-3807F78F0287} (ClientInstaller Class) - http://www.180searchassistant.com/180saax.cab
O16 - DPF: {AB70C611-DE79-4DB5-B637-CCA50876E4D8} (passport.File
ObjectCtrl) - http://zjod.zjtelecom.cn/csscfg.nsf/AttachFile/passport/$FILE/passport.CAB
O16 - DPF: {D4C3A8C0-2098-4ECA-B77D-AF04D3836E22} (Jkflcx Control) - http://134.103.69.225/jkflcx/JkflcxProj1.inf
O17 - HKLM\System\CCS\Services\Tcpip\..\{FA2D913F-DCA3-4A7F-B3C7-F23CE831448F}: NameServer = 134.96.32.26
O21 - SSODL: FICBEA0F - {6EDF5FEC-1C08-1AA2-23F6-5EBE37892971} - C:\WINDOWS\System32\Lcibap32.dll (file missing)
O21 - SSODL: mtkle - {A40A0E29-3BAA-4D84-509C-E8CBD59BD7EE} - C:\WINDOWS\System32\veixhj32.dll (file missing)
O21 - SSODL: mtklefap - {A85D2547-8A68-4FC1-12B0-9F8BF209251C} - C:\WINDOWS\System32\oiisye32.dll (file missing)
O23 - NT 服务: hpdriver - Unknown owner - C:\WINDOWS\hpdriver.exe
O23 - NT 服务: OracleClientCache80 - Unknown owner - C:\orant\BIN\ONRSD80.EXE
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - D:\Program Files\Rising\Rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Unknown owner - D:\PROGRAM FILES\RISING\RAV\Ravmond.exe (file missing)
O23 - NT 服务: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\System32\r_server.exe" /service (file missing)