12   1  /  2  页   跳转

X97M/Generic 病毒

X97M/Generic 病毒

发邮件的时候,系统回复说我的附件里面有X97M/Generic 病毒 ,邮件退回。怎么去掉这东东啊????////

快快帮帮我啊!!
最后编辑2006-04-06 11:04:27
分享到:
gototop
 

发邮件的时候。2000的系统。瑞星查也也不出来。没有POP
gototop
 

我没有
现在我该怎么做呢?
gototop
 

大哥,教教我啊!
谢了先!
gototop
 

您发送的邮件中带有 X97M/Generic 病毒, 系统拒绝投递.

//----------------------------------------------------------


注意:附件后缀为"bat、cmd、com、exe、pif、scr"的邮件,本邮件系统将拒绝接收与投递。
Received: from [218.90.16.41]; Tue, 4 Apr 2006 17:11:25 +0800
Message-ID: <006201c657c8$4ee7fd20$2203a8c0@sjw>
From: =b2312?B?y++/oc6i?=sjw@si-power.com>
To: "=b2312?B?1dQgzsTl2g==<wxz@si-power.com>
Cc: "=b2312?B?tqEgufq7qg==<dgh@si-power.com>
Subject: =b2312?B?y8TUwrfduaTX97zGu64o1srBv7K/KS54bHM=
Date: Tue, 4 Apr 2006 17:15:24 +0800
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary=---=extPart_000_005E_01C6580B.5C53D400"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1409
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1409

This is a multi-part message in MIME format.

------=extPart_000_005E_01C6580B.5C53D400
Content-Type: multipart/alternative;
boundary=---=extPart_001_005F_01C6580B.5C555AA0"


------=extPart_001_005F_01C6580B.5C555AA0
Content-Type: text/plain;
charset=b2312"
Content-Transfer-Encoding: base64

DQoNCiDLxNTCt925pNf3vMa7rijWysG/sr8pLnhscw=

------=extPart_001_005F_01C6580B.5C555AA0
Content-Type: text/html;
charset=b2312"
Content-Transfer-Encoding: base64

PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9XM0MvL0RURCBIVE1MIDQuMCBUcmFuc2l0aW9uYWwv
L0VOIj4NCjxIVE1MPjxIRUFEPg0KPE1FVEEgaHR0cC1lcXVpdj1Db250ZW50LVR5cGUgY29udGVu
dD0idGV4dC9odG1sOyBjaGFyc2V0PWdiMjMxMiI+DQo8TUVUQSBjb250ZW50PSJNU0hUTUwgNi4w
MC4yODAwLjE0OTgiIG5hbWU9R0VORVJBVE9SPg0KPFNUWUxFPjwvU1RZTEU+DQo8L0hFQUQ+DQo8
Qk9EWSBiZ0NvbG9yPSNmZmZmZmY+DQo8RElWPiZuYnNwOzwvRElWPjxCUj4mbmJzcDvLxNTCt925
pNf3vMa7rijWysG/sr8pLnhsczwvQk9EWT48L0hUTUw+DQo
------=extPart_001_005F_01C6580B.5C555AA0--

------=extPart_000_005E_01C6580B.5C53D400
Content-Type: application/vnd.ms-excel;
name=?gb2312?B?y8TUwrfduaTX97zGu64o1srBv7K/KS54bHM="
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename=?gb2312?B?y8TUwrfduaTX97zGu64o1srBv7K/KS54bHM="

0M8R4KGxGuEAAAAAAAAAAAAAAAAAAAAAPgADAP7/CQAGAAAAAAAAAAAAAAABAAAAAQAAAAAAAAAA
EAAAKAAAAAEAAAD+////AAAAAAAAAAD/////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
///////////////////////////////////////////////////////////////////////////9
////JwAAAAMAAAAEAAAABQAAAAYAAAAHAAAACAAAAAkAAAAKAAAACwAAAAwAAAANAAAADgAAAA8A
AAAQAAAAEQAAABIAAAATAAAAFAAAABUAAAAWAAAAFwAAABgAAAAZAAAAGgAAABsAAAAcAAAAHQAA
AB4AAAAfAAAAIAAAACEAAAAiAAAAIwAAACQAAAAlAAAAJgAAAP7///8zAAAA/v///yoAAAArAAAA
LAAAAC0AAAAuAAAALwAAADAAAAAxAAAAMgAAADQAAAA2AAAANQAAAP7////+////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
/////////////////////////////////////////////////////////////////////////1IA
bwBvAHQAIABFAG4AdAByAHkAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAWAAUA//////////8CAAAAIAgCAAAAAADAAAAAAAAARgAAAAAAprnAv1fGAfBGBaLAV8YB
KQAAAIAXAAAAAAAAVwBvAHIAawBiAG8AbwBrAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAABIAAgEMAAAA//////////8AAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAACAAAAC0kAAAAAAABfAFYAQgBBAF8AUABSAE8ASgBFAEMAVABfAEMAVQBS
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIgABAQEAAAAKAAAACQAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAcMLmocBXxgHwRgWiwFfGAQAAAAAAAAAAAAAAAFYAQgBBAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIAAEA////////
//8FAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABwwuahwFfGAdCl/aHAV8YBAAAAAAAAAAAAAAAACQgQ
AAAGBQAXGc0HyUAAAAYBAADhAAIAsATBAAIAAADiAAAAXABwAAMAAHNqdyAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBCAAIAsARhAQIAAADAAQAAPQECAAQA
0wAAAL0BAAC6AQ8ADAAAVGhpc1dvcmtib29rnAACAA4AGQACAAAAEgACAAAAEwACAAAArwECAAAA
vAECAAAAPQASAOABeAA5IbIROAAAAAAAAQBYAkAAAgAAAI0AAgAAACIAAgAAAA4AAgABALcBAgAA
ANoAAgAAADEAFADwAAAA/3+QAQAAAACGAAIBi1tTTzEAFADwAAAA/3+QAQAAAACGAAIBi1tTTzEA
FADwAAAA/3+QAQAAAACGAAIBi1tTTzEAFADwAAAA/3+QAQAAAACGAAIBi1tTTzEAFAC0AAAA/3+Q
AQAAAACGAAIBi1tTTzEAFADwAAAA/3+QAQAAAACGAAIBi1tTTzEAFADwAAQADACQAQAAAQCGAAIB
i1tTTzEAFADwAAQAJACQAQAAAQCGAAIBi1tTTzEALgDwAAAA/3+QAQAAAAEAAA8BVABpAG0AZQBz
ACAATgBlAHcAIABSAG8AbQBhAG4AMQAUAEABAAD/f5ABAAAAAIYAAgGLW1NPMQAuAEABAAD/f5AB
AAAAAQAADwFUAGkAbQBlAHMAIABOAGUAdwAgAFIAbwBtAGEAbgAxABQA8AABAP9/vAIAAAAAhgAC
AYtbU08xAC4A8AABAP9/vAIAAAABAAAPAVQAaQBtAGUAcwAgAE4AZQB3ACAAUgBvAG0AYQBuAB4E
KwAFABMAASIA5f8iACMALAAjACMAMAA7AFwALQAiAOX/IgAjACwAIwAjADAAHgQ1AAYAGAABIgDl
/yIAIwAsACMAIwAwADsAWwBSAGUAZABdAFwALQAiAOX/IgAjACwAIwAjADAAHgQ3AAcAGQABIgDl
/yIAIwAsACMAIwAwAC4AMAAwADsAXAAtACIA5f8iACMALAAjACMAMAAuADAAMAAeBEEACAAeAAEi
AOX/IgAjACwAIwAjADAALgAwADAAOwBbAFIAZQBkAF0AXAAtACIA5f8iACMALAAjACMAMAAuADAA
MAAeBGUAKgAwAAFfAC0AIgDl/yIAKgAgACMALAAjACMAMABfAC0AOwBcAC0AIgDl/yIAKgAgACMA
LAAjACMAMABfAC0AOwBfAC0AIgDl/yIAKgAgACIALQAiAF8ALQA7AF8ALQBAAF8ALQAeBCwAKQAn
AABfLSogIywjIzBfLTtcLSogIywjIzBfLTtfLSogIi0iXy07Xy1AXy0eBHUALAA4AAFfAC0AIgDl
/yIAKgAgACMALAAjACMAMAAuADAAMABfAC0AOwBcAC0AIgDl/yIAKgAgACMALAAjACMAMAAuADAA
MABfAC0AOwBfAC0AIgDl/yIAKgAgACIALQAiAD8APwBfAC0AOwBfAC0AQABfAC0AHgQ0ACsALwAA
Xy0qICMsIyMwLjAwXy07XC0qICMsIyMwLjAwXy07Xy0qICItIj8/Xy07Xy1AXy0eBBoAFwAVAABc
JCMsIyMwXyk7XChcJCMsIyMwXCkeBB8AGAAaAABcJCMsIyMwXyk7W1JlZF1cKFwkIywjIzBcKR4E
IAAZABsAAFwkIywjIzAuMDBfKTtcKFwkIywjIzAuMDBcKR4EJQAaACAAAFwkIywjIzAuMDBfKTtb
gototop
 

我不怎么懂
gototop
 

HijackThis1.99.1哪里有啊?
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 9:13:34, on 2006-4-6
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ServeHost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\SearchNet\SearchNet.exe
C:\WINNT\system32\ScsiAccess.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINNT\system32\internat.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Thunder Network\Thunder\Thunder.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\notepad.exe
E:\软件\hijackthis\HijackThis.exe

O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINNT\system32\xunleibho_v14.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MonitorURL Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\PROGRA~1\DESKAD~1\deskipn.dll (file missing)
O2 - BHO: 上网助手 - {1B0E7716-898E-48cc-9690-4E338E8DE1D3} - (no file)
O2 - BHO: Yahoo!Photo - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll
O2 - BHO: AntiFish Class - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yangling.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: DragSearch BHO - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL
O2 - BHO: (no name) - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: bho Class - {ED8DFC5C-10EF-45AB-9DC2-0639AFF5A270} - C:\PROGRA~1\COMMON~1\Wnwb\wnwbio.dll
O2 - BHO: 超级兔子上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - C:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~1.DLL (file missing)
O3 - Toolbar: 上网助手 - {1B0E7716-898E-48cc-9690-4E338E8DE1D3} - (no file)
O3 - Toolbar: CopySo拷贝搜 - {40987A5C-6AB8-4977-8BE9-A8889DE2EDCC} - C:\Program Files\Copyso\CopysoIE.dll
O3 - Toolbar: (no name) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - (no file)
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O3 - Toolbar: 超级兔子上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - C:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~1.DLL (file missing)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AddrPlus2] RUNDLL32.EXE C:\PROGRA~1\TENCENT\AddrPlus\QAHook1.dll,Rundll32
O4 - HKLM\..\Run: [AddrPlus] RUNDLL32.EXE C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll,Rundll32
O4 - HKLM\..\Run: [Thunder] "C:\Program Files\Thunder Network\Thunder\ThunderShell.exe" /s
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [MoveSearch] C:\Program Files\HuaCi\huaci\zsearch.exe
O4 - HKLM\..\Run: [Desktop] C:\WINNT\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: !CopySo拷贝搜 - res://C:\Program Files\Copyso\CopysoIE.dll/copyso.htm
O8 - Extra context menu item: !全球排名 - res://C:\Program Files\Copyso\CopysoIE.dll/tops.htm
O8 - Extra context menu item: !反向链接 - res://C:\Program Files\Copyso\CopysoIE.dll/snapshot.htm
O8 - Extra context menu item: !网页快照 - res://C:\Program Files\Copyso\CopysoIE.dll/similar.htm
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 添加到雅虎订阅(&Y) - res://C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yrss.dll/YRSSMENUEXT
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 雅虎搜索 - res://C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll/246
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm (file missing)
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=?allyesPara=816 (file missing)
O9 - Extra button: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/?source=Cns (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O11 - Options group: [!CNS]  网络实名
O16 - DPF: {1F831FA1-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday 控件) - file://C:\Program Files\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {9242BB35-0DB0-43AC-8DFC-8EA07E63B92A} - http://dl_dir.qq.com/qqtv/QQLiveOcxSetup.exe
O16 - DPF: {AE563722-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview 控件) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{2C728A52-A7BF-47BF-A1CE-8C4FBAE93CC6}: NameServer = 221.228.255.1
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ptssvc - Parallel Technologies, Inc. - (no file)
O23 - Service: Remote Log - 北京中搜在线软件有限公司 - C:\WINNT\system32\ServeHost.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINNT\system32\ScsiAccess.EXE

gototop
 

快帮帮我大侠!
我急死了!
gototop
 

没有安装
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT