瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求救ING,中了Trojan.PSW.Lineage.ns病毒,怎么也杀不掉啊!!

12   1  /  2  页   跳转

求救ING,中了Trojan.PSW.Lineage.ns病毒,怎么也杀不掉啊!!

求救ING,中了Trojan.PSW.Lineage.ns病毒,怎么也杀不掉啊!!

酒鬼中了这个麻烦的病毒的说,现在瑞星也不能用,Internat.exe,Explover.exe和MSN都感染了,就是杀不掉的说,哪位大爷可以拉小弟一把的说!!
最后编辑2005-09-27 22:35:02
分享到:
gototop
 

汗,菜鸟一只的说
从来没碰到过咧
怎么弄的说,哭求ING
gototop
 

【回复“網事如夢”的帖子】
收到,立刻去试一下,汗,谢谢大爷的说!!
gototop
 

酒鬼试过了,不能进安全模式啊,哭,怎么办怎么办,原地打转!!
gototop
 

文件名      文件路径                                 
RAVMON.EXE  RAVMON.EXE>>C:\WINDOWS\SYSTEM\RXDLL.DLL 
病毒名                  状态
Trojan.PSW.Lineage.ns  清除失败
gototop
 

还有EXPLORER.EXE,RUNDLL32.EXE,MSNMSGR.EXE,同样的路径,同样的病毒,同样的清除失败!!哭啊
gototop
 

日志是吧,酒鬼利马贴上来,亲!
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 21:04:37, on 05-9-27
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\PROGRAM FILES\RISING\RAV\RAVMOND.EXE
C:\PROGRAM FILES\RISING\RAV\RAVMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\RUNDLL32.EXE
C:\PROGRAM FILES\RUNDLL32.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\INTERNAT.EXE
C:\WINDOWS\SYSTEM\W98EJECT.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
E:\PROGRAM FILES\TENCENT\TT\TTRAVELER.EXE
C:\MY DOCUMENTS\HUAWEI\PORTALSERVER\202.109.117.146\PORTALCLIENT.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
G:\HIJACKTHIS1.99.1\HIJACKTHIS.EXE
gototop
 

R3 - URLSearchHook: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRAM FILES\3721\ASSIST\ASBAR.DLL
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - E:\网际士快斐车礬\FLASHGET\JCCATCH.DLL (file missing)
O2 - BHO: 3721中文邮 - {6231D512-E4A4-4DF2-BE62-5B8F0EE348EF} - C:\PROGRAM FILES\3721\CES\CESWEB.DLL
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSHOOK.DLL
O2 - BHO: HBO Class - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - C:\WINDOWS\SYSTEM\services\2.01.00.dll (file missing)
O2 - BHO: IDDTInitObj Class - {15DDE989-CD45-4561-BF99-D22C0D5C2B74} - C:\WINDOWS\DOWNLO~1\DDTINIT.DLL
O2 - BHO: ShowBarObject Class - {850B69E4-90DB-4F45-8621-891BF35A5B53} - C:\WINDOWS\SYSTEM\ALITB3\__NEW\BAR.DLL
O2 - BHO: KillObj Class - {66C28884-4E5D-494B-80C9-CAA27528FD6D} - C:\WINDOWS\DOWNLO~1\DDTKILLW.OCX
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - E:\PROGRAM FILES\XI\NETTRANSPORT 2\NTIEHELPER.DLL
O2 - BHO: AssistII - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRAM FILES\3721\ASSIST\ASBAR.DLL
O2 - BHO: DownloadBHO T2BHO - {B1D147E7-873E-4909-8127-695D9BB78728} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\BARHELP22.0.DLL
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - C:\PROGRA~1\YISOU\YISOUB.DLL
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - E:\网际士快斐车礬\FLASHGET\FGIEBAR.DLL (file missing)
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: 新浪点点通 - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - C:\WINDOWS\DOWNLO~1\DDTONG~1.DLL
O3 - Toolbar: 虎翼DIY吧! - {0A00D11E-B1E7-44b5-AD88-C9190876AAC4} - C:\WINDOWS\SYSTEM\51.NET\DIYBAR\DIYBAR.DLL
O3 - Toolbar: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRAM FILES\3721\ASSIST\ASBAR.DLL
gototop
 

O3 - Toolbar: 天下搜索 - {56A7DC70-E102-4408-A34A-AE06FEF01586} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.1\IEBAR22.0.DLL
O3 - Toolbar: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\PROGRAM FILES\YISOU\YISOU.DLL
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\DOWNLO~1\CNSMIN.DLL,Rundll32
O4 - HKLM\..\Run: [ccenter] C:\Program Files\rising\Rav\CCenter.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [RavTimer] E:\瑞星杀毒\RAV\RavTimer.exe
O4 - HKLM\..\Run: [popproxy] C:\PROGRAM FILES\RISING\RAV\RavProxy.exe
O4 - HKLM\..\Run: [NMGameX_AutoRun] C:\WINDOWS\Rundll32.exe NMGAMEX.DLL,LiveProcess /aa
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\RunServices: [RNBOStart] C:\WINDOWS\SYSTEM\RNBOSENT\SENTSTRT.EXE
O4 - HKLM\..\RunServices: [ccenter] C:\Program Files\rising\Rav\CCenter.exe
O4 - HKLM\..\RunServices: [RsCcenter] C:\PROGRA~1\RISING\RAV\CCENTER.EXE
O4 - HKLM\..\RunServices: [RavMond] C:\PROGRA~1\RISING\RAV\RAVMOND.EXE
O4 - HKLM\..\RunServices: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: w98Eject.lnk = C:\WINDOWS\System\w98eject.exe
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: 使用网际快车下载 - E:\网际快车\FLASHGET\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - E:\网际快车\FLASHGET\jc_all.htm
O8 - Extra context menu item: 解霸实时播放 - F:\win3 播放器\解霸英雄\MPURLGET.HTM
O8 - Extra context menu item: ▼使用旋风下载 - E:\Program Files\Tencent\TT\cg_link.htm
O8 - Extra context menu item: 发送图片到手机(&M) - http://sms.sina.com.cn/diy/send.html?from=467
O8 - Extra context menu item: 使用彩信超级自写发送到手机 - http://mms.sina.com.cn/mmsnews.html
O8 - Extra context menu item: 使用影音传送带下载 - E:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - E:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: 使用Kugoo下载 - E:\PROGRAM FILES\KUGOO\KugooDownX.htm
O8 - Extra context menu item: 收藏此页到ViVi - http://vivi.sina.com.cn/collect/click.php?agent=ddt
O8 - Extra context menu item: 新浪搜索 - http://cha.sina.com.cn/ddt.html
O8 - Extra context menu item: 使用新浪下载助手下载 - C:\WINDOWS\DOWNLO~1\sinadl.htm
O8 - Extra context menu item: 收藏此页到新浪ViVi - http://vivi.sina.com.cn/collect/click.php?agent=ddt
O8 - Extra context menu item: 添加QQ网络收藏夹 - E:\PROGRAM FILES\TENCENT\TT\NAF.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - E:\PROGRA~1\KINGSOFT\FASTAIT\IEPLUGIN.DLL
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT