瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 是文件丢失还是灰鸽子作怪?kaka日志和hijackthis不同,以哪个为准?

1   1  /  1  页   跳转

是文件丢失还是灰鸽子作怪?kaka日志和hijackthis不同,以哪个为准?

是文件丢失还是灰鸽子作怪?kaka日志和hijackthis不同,以哪个为准?

斑竹、各位大哥大姐:这两天我的网络连接连图标都不见了;网络邻居拒绝操作;QQ关闭对话框时提示“库文件未注册”;控制面板的用户帐户无法进入,我用hijackthis和kaka助手扫描,结果不一样,kaka助手中扫描到的问题比较多,但是hijackthis没有显示,而且hijackthis中的018项无法修复,再次扫描的时候仍然存在;用优化大师扫描发现1027 Trjan.huigezi.e\1029 SubSARI的提示。这是文件丢失还是灰鸽子造成的?

拜托赐教!

这是KAKA日志
Logfile of Kaka v2. 0. 0. 5 Scan Module v2. 0. 0. 1
Scan saved at 21:26:19, on 2006-01-07
Platform: Microsoft Windows XP Professional Service Pack 1 (Build 2600)
MSIE: Internet Explorer v6.00 SP1; (6.00.2800.1106 (xpsp1.020828-1920))


Running processes:
[SMSS.EXE]
CommandLine =

[CSRSS.EXE]
CommandLine = C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

[WINLOGON.EXE]
CommandLine = winlogon.exe

[SERVICES.EXE]
CommandLine = C:\WINDOWS\system32\services.exe

[LSASS.EXE]
CommandLine = C:\WINDOWS\system32\lsass.exe

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss

[CCenter.exe]
CommandLine = "F:\ruixing\Rising\Rising\Rav\CCenter.exe"

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k NetworkService

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k LocalService

[RavMonD.exe]
CommandLine = "F:\ruixing\Rising\Rising\Rav\Ravmond.exe"

[rfwsrv.exe]
CommandLine = "f:\program files\rising\rfw\rfwsrv.exe"

[RavStub.exe]
CommandLine = F:\ruixing\Rising\Rising\Rav\RavStub.exe /RAVMOND

[spoolsv.exe]
CommandLine = C:\WINDOWS\system32\spoolsv.exe

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k imgsvc

[wdfmgr.exe]
CommandLine = C:\WINDOWS\System32\wdfmgr.exe

[Explorer.EXE]
CommandLine = C:\WINDOWS\Explorer.EXE

[RfwMain.exe]
CommandLine =  -StartUp

[RavTask.exe]
CommandLine = "F:\RUIXING\RISING\RISING\RAV\RAVTASK.EXE" -SYSTEM

[CTFMON.EXE]
CommandLine = "C:\WINDOWS\System32\ctfmon.exe"

[RavMon.exe]
CommandLine = "F:\ruixing\Rising\Rising\Rav\Ravmon.exe" -SYSTEM

[iexplore.exe]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe"

[KkScan.exe]
CommandLine = "F:\电脑清理\KAKA助手\KkScan.exe"

O1 - Hosts: 127.0.0.1 localhost
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\KakaTool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKLM\..\Run: [RavTask] "F:\ruixing\Rising\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "F:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\什么都有\QQ2005\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\什么都有\QQ2005\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\什么都有\QQ2005\qq\SendMMS.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O16 - DPF: DirectAnimation Java Classes - file://C:\WINDOWS\Java\classes\dajava.cab
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O23 - Service: Human Interface Device Access (HidServ) -  - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Microsoft MessangerServer (Microsoft MessangerServer) -  - C:\WINDOWS\Microsoft MessangerServer.exe
O23 - Service: nServer (nServer) -  - C:\WINDOWS\sgester.bat
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - f:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - "F:\ruixing\Rising\Rising\Rav\CCenter.exe"
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - "F:\ruixing\Rising\Rising\Rav\Ravmond.exe"

HijackThis_815汉化版扫描日志 V1.99.1
保存于      21:25:57, 日期 2006-1-7
操作系统:  Windows XP SP1 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
F:\ruixing\Rising\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
F:\ruixing\Rising\Rising\Rav\Ravmond.exe
f:\program files\rising\rfw\rfwsrv.exe
F:\ruixing\Rising\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
f:\program files\rising\rfw\RfwMain.exe
F:\ruixing\Rising\Rising\Rav\RavTask.exe
C:\WINDOWS\System32\ctfmon.exe
F:\ruixing\Rising\Rising\Rav\Ravmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\电脑清理\hijackthis\HijackThis1991汉化版\HijackThis1991zww.exe

O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\KakaTool.dll
O4 - 启动项HKLM\\Run: [RavTask] "F:\ruixing\Rising\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [RfwMain] "F:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - F:\什么都有\QQ2005\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - F:\什么都有\QQ2005\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - F:\什么都有\QQ2005\qq\SendMMS.htm
O18 - 列举现有的协议: ipp - (no CLSID) - (no file)
O18 - 列举现有的协议: msdaipp - (no CLSID) - (no file)
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - f:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - F:\ruixing\Rising\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - F:\ruixing\Rising\Rising\Rav\Ravmond.exe

最后编辑2006-01-10 12:31:06
分享到:
gototop
 

真得很抱歉,还没来得及把病毒打包发送,就已经被迫重装系统了。如果再发现类似情况我就知道先打包发送染病毒的文件给版主,多谢帮忙!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT