瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 请大虾们帮我分析一下这个日志,我一定是中马了,该怎么清除?在下不胜感激!

1   1  /  1  页   跳转

请大虾们帮我分析一下这个日志,我一定是中马了,该怎么清除?在下不胜感激!

请大虾们帮我分析一下这个日志,我一定是中马了,该怎么清除?在下不胜感激!

HijackThis_815汉化版扫描日志 V1.99.1
保存于      23:56:25, 日期 2006-4-17
操作系统:  Windows XP  (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 (6.00.2600.0000)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\star\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\star\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
D:\star\Rising\Rav\RavStub.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\Rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\3721\assistse.exe
C:\Program Files\QuickTime\qttask.exe
D:\star\Rising\Rav\RavTask.exe
D:\star\Rising\Rav\Ravmon.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
E:\UC\uc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\RUNDLL32.EXE
E:\HijackThis1991汉化版\HijackThis1991zww.exe

R3 - URLSearchHook: CnsHook Class - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLO~1\CnsHook.dll
F3 - REG:win.ini: run=C:\WINDOWS\services.exe
O1 - Hosts: 218.85.139.123 minisite.qq.com
O1 - Hosts: 218.85.139.123 www.minisite.qq.com
O1 - Hosts: 218.85.139.123 cnww.net
O1 - Hosts: 218.85.139.123 www.cnww.net
O1 - Hosts: 218.85.139.123 zhao123.com
O1 - Hosts: 218.85.139.123 www.zhao123.com
O1 - Hosts: 218.85.139.123 4399.com
O1 - Hosts: 218.85.139.123 www.4399.com
O1 - Hosts: 218.85.139.123 chinagames.net
O1 - Hosts: 218.85.139.123 www.chinagames.net
O1 - Hosts: 218.85.139.123 tiexue.net
O1 - Hosts: 218.85.139.123 www.tiexue.net
O1 - Hosts: 218.85.139.123 qq163.com
O1 - Hosts: 218.85.139.123 www.qq163.com
O1 - Hosts: 218.85.139.123 tt67.com
O1 - Hosts: 218.85.139.123 www.tt67.com
O1 - Hosts: 218.85.139.123 chinamp3.com
O1 - Hosts: 218.85.139.123 www.chinamp3.com
O1 - Hosts: 218.85.139.123 pg168.com
O1 - Hosts: 218.85.139.123 www.pg168.com
O1 - Hosts: 218.85.139.123 yymp3.com
O1 - Hosts: 218.85.139.123 www.yymp3.com
O1 - Hosts: 218.85.139.123 yy138.com
O1 - Hosts: 218.85.139.123 www.yy138.com
O1 - Hosts: 218.85.139.123 dj99.com
O1 - Hosts: 218.85.139.123 www.dj99.com
O1 - Hosts: 218.85.139.123 sogua.com
O1 - Hosts: 218.85.139.123 www.sogua.com
O1 - Hosts: 218.85.139.123 snsn.net
O1 - Hosts: 218.85.139.123 www.snsn.net
O1 - Hosts: 218.85.139.123 flash8.net
O1 - Hosts: 218.85.139.123 www.flash8.net
O1 - Hosts: 218.85.139.123 mop.com
O1 - Hosts: 218.85.139.123 www.mop.com
O1 - Hosts: 218.85.139.123 tianyaclub.com
O1 - Hosts: 218.85.139.123 www.tianyaclub.com
O1 - Hosts: 218.85.139.123 xici.net
O1 - Hosts: 218.85.139.123 www.xici.net
O1 - Hosts: 218.85.139.123 ucanlove.com
O1 - Hosts: 218.85.139.123 www.ucanlove.com
O1 - Hosts: 218.85.139.123 cmfu.com
O1 - Hosts: 218.85.139.123 www.cmfu.com
O1 - Hosts: 218.85.139.123 21red.net
O1 - Hosts: 218.85.139.123 www.21red.net
O1 - Hosts: 218.85.139.123 pconline.com.cn
O1 - Hosts: 218.85.139.123 www.pconline.com.cn
O1 - Hosts: 218.85.139.123 donews.com
O1 - Hosts: 218.85.139.123 www.donews.com
O1 - Hosts: 218.85.139.123 pcauto.com.cn
O1 - Hosts: 218.85.139.123 www.pcauto.com.cn
O1 - Hosts: 218.85.139.123 wo99.com
O1 - Hosts: 218.85.139.123 www.wo99.com
O1 - Hosts: 218.85.139.123 flashempire.com
O1 - Hosts: 218.85.139.123 www.flashempire.com
O1 - Hosts: 218.85.139.123 showgood.tv
O1 - Hosts: 218.85.139.123 www.showgood.tv
O1 - Hosts: 218.85.139.123 flashfan.net
O1 - Hosts: 218.85.139.123 www.flashfan.net
O1 - Hosts: 218.85.139.123 long21.net
O1 - Hosts: 218.85.139.123 www.long21.net
O1 - Hosts: 218.85.139.123 socom
O1 - Hosts: 218.85.139.123 www.socom
O1 - Hosts: 218.85.139.123 flashhome.net
O1 - Hosts: 218.85.139.123 www.flashhome.net
O1 - Hosts: 218.85.139.123 cnflash.net
O1 - Hosts: 218.85.139.123 www.cnflash.net
O1 - Hosts: 218.85.139.123 flashsky.com
O1 - Hosts: 218.85.139.123 www.flashsky.com
O1 - Hosts: 218.85.139.123 hunansky.com
O1 - Hosts: 218.85.139.123 www.hunansky.com
O1 - Hosts: 218.85.139.123 52flash.net
O1 - Hosts: 218.85.139.123 www.52flash.net
O1 - Hosts: 218.85.139.123 flashh.com
O1 - Hosts: 218.85.139.123 www.flashh.com
O1 - Hosts: 218.85.139.123 flashsun.com
O1 - Hosts: 218.85.139.123 www.flashsun.com
O1 - Hosts: 218.85.139.123 7k7k.com
O1 - Hosts: 218.85.139.123 www.7k7k.com
O1 - Hosts: 218.85.139.123 xuanxuan.com
O1 - Hosts: 218.85.139.123 www.xuanxuan.com
O1 - Hosts: 218.85.139.123 flash88.net
O1 - Hosts: 218.85.139.123 www.flash88.net
O1 - Hosts: 218.85.139.123 91flash.com
O1 - Hosts: 218.85.139.123 www.91flash.com
O1 - Hosts: 218.85.139.123 doingflash.com
O1 - Hosts: 218.85.139.123 www.doingflash.com
O1 - Hosts: 218.85.139.123 skyhits.com
O1 - Hosts: 218.85.139.123 www.skyhits.com
O1 - Hosts: 218.85.139.123 ting78.com
O1 - Hosts: 218.85.139.123 www.ting78.com
O1 - Hosts: 218.85.139.123 91.com
O1 - Hosts: 218.85.139.123 www.91.com
O1 - Hosts: 218.85.139.123 flashchina.net
O1 - Hosts: 218.85.139.123 www.flashchina.net
O1 - Hosts: 218.85.139.123 flash8.com.cn
O1 - Hosts: 218.85.139.123 www.flash8.com.cn
O1 - Hosts: 218.85.139.123 f130.net
O1 - Hosts: 218.85.139.123 www.f130.net
O1 - Hosts: 218.85.139.123 chinanim.com
O1 - Hosts: 218.85.139.123 www.chinanim.com
O1 - Hosts: 218.85.139.123 comicer.com
O2 - BHO: BdSearch - {02496EBD-8455-48db-B3C7-5DAC97D9F5A7} - C:\PROGRA~1\baidu\iexp\BDSrHook.dll
O2 - BHO: IDDTInitObj Class - {15DDE989-CD45-4561-BF99-D22C0D5C2B74} - C:\PROGRA~1\sina\UC\UCddt\ddtinit.dll
O2 - BHO: RawExecAction Object - {18898424-E3AB-4BA9-8E8D-5434B1CECA75} - C:\WINDOWS\System32\gebcd.dll
O2 - BHO: (no name) - {20D57A66-F7DF-467d-907B-9B7F4A118AB7} - C:\WINDOWS\System32\mllml.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\qq\QQIEHelper.dll
O2 - BHO: 3721中文邮 - {6231D512-E4A4-4DF2-BE62-5B8F0EE348EF} - C:\PROGRA~1\3721\Ces\cesweb.dll
O2 - BHO: KillObj Class - {66C28884-4E5D-494B-80C9-CAA27528FD6D} - C:\PROGRA~1\sina\UC\UCddt\ddtkillw.ocx
O2 - BHO: EyeOnIE Class - {6E28339B-7A2A-47B6-AEB2-46BA53782379} - C:\Program Files\IS\BhoPlugin.dll (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AssistII - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\Program Files\3721\Assist\asbar.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\zh-cn\msntb.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLO~1\CnsHook.dll
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - C:\PROGRA~1\yisou\yisoub.dll
O3 - IE工具栏增项: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - IE工具栏增项: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\zh-cn\msntb.dll
O3 - IE工具栏增项: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\Program Files\3721\Assist\asbar.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - IE工具栏增项: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\Program Files\yisou\yisou.dll
O3 - IE工具栏增项: 新浪点点通 - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - C:\PROGRA~1\sina\UC\UCddt\DDTONG~1.DLL
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [SoundMan] soundman.exe
O4 - 启动项HKLM\\Run: [Hide] C:\HWR\Hide.exe
O4 - 启动项HKLM\\Run: [CnsMin] Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32
O4 - 启动项HKLM\\Run: [cesmain.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\Ces\cmail.dll,Rundll32
O4 - 启动项HKLM\\Run: [internat.exe] internat.exe
O4 - 启动项HKLM\\Run: [YDTMain.exe] C:\PROGRA~1\YDT\YDTMain.exe
O4 - 启动项HKLM\\Run: [is] C:\Program Files\IS\is.exe
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [assistse] "C:\3721\assistse.exe"
O4 - 启动项HKLM\\Run: [KVCENTER] C:\KV2005\KVCenter.kxp
O4 - 启动项HKLM\\Run: [abaak] regedit -s c:\windows\system\winlog\WIN32log.cer
O4 - 启动项HKLM\\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - 启动项HKLM\\Run: [NMGameX_AutoRun] C:\WINDOWS\System32\Rundll32.exe NMGameX.dll,LiveProcess /aa
O4 - 启动项HKLM\\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - 启动项HKLM\\Run: [MS-4011 Memory Patch] C:\Documents and Settings\a\桌面\RavSasser.exe -Patch
O4 - 启动项HKLM\\Run: [KvMonXP] C:\KV2005\KVMonXP.kxp /auto
O4 - 启动项HKLM\\Run: [RavTask] "D:\star\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [AddrPlus3] C:\PROGRA~1\TENCENT\Adplus\stup.exe C:\PROGRA~1\TENCENT\Adplus\Adplus.dll Rundll32
O4 - HKCU\..\Run: [] regedit -s c:\windows\system\winlog\WIN32log.cer
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] D:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\Run: [KvXP] C:\KV2005\KvXP.kxp /ScanBoot /ScanSys
O4 - HKCU\..\RuunServices:[services] C:\WINDOWS\services.exe
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\qq\QQ.exe
O4 - Startup: 新浪UC.lnk = E:\UC\uc.exe
O4 - Global Startup: 服务管理器.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
最后编辑2006-04-18 01:13:07
分享到:
gototop
 

O8 - IE右键菜单中的新增项目: !搜一搜 - res://C:\Program Files\yisou\yisou.dll/232
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - C:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\qq\SendMMS.htm
O9 - 浏览器额外的按钮: (no name) - {02496EBD-8455-48db-B3C7-5DAC97D9F5A7} - http://baidu.com/index.php?tn=bainiudg (file missing)
O9 - 浏览器额外的按钮: 新浪UC - {2253922F-1B26-4C74-8B57-E3AEE748DBB8} - E:\UC\uc.exe
O9 - 浏览器额外的按钮: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - 浏览器额外的按钮: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao (file missing)
O9 - 浏览器额外的按钮: 3721中文邮 - {5D73EE86-05F1-49ed-B850-E423120EC329} - http://cmail.3721.com?fb=client (file missing)
O9 - 浏览器额外的按钮: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - 浏览器额外的按钮: kele8 - {84920E5F-3788-49cd-A274-E365578DF174} - http://www.kele8.com/ (file missing)
O9 - 浏览器额外的“工具”菜单项: kele8 - {84920E5F-3788-49cd-A274-E365578DF174} - http://www.kele8.com/ (file missing)
O9 - 浏览器额外的按钮: 卓越 - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - c:\HAPPYH~1\XDict\IEPlugin.dll
O9 - 浏览器额外的按钮: 易趣购物 - {BE9C13C3-9E46-4db1-BC05-BD8DA44599F2} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-195?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O9 - 浏览器额外的“工具”菜单项: 易趣购物 - {BE9C13C3-9E46-4db1-BC05-BD8DA44599F2} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-195?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O9 - 浏览器额外的按钮: 金山词霸 - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - c:\HAPPYH~1\XDict\IEPlugin.dll
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\qq\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\qq\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe (file missing)
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe (file missing)
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\qq\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\qq\QQIEHelper.dll
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - 浏览器额外的“工具”菜单项: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - 浏览器额外的按钮: 新浪点点通 - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - C:\PROGRA~1\sina\UC\UCddt\DDTONG~1.DLL
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - 浏览器额外的“工具”菜单项: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O11 - Options group: [!CNS]  网络实名
O11 - Options group: [!IESearch] !IESearch
O11 - Options group: [TBH]  搜搜地址栏搜索
O14 - IERESET.INF: START_PAGE_URL=http://www.legend.com
O16 - DPF: {2D4851FD-0BFE-11D4-9260-9AF666D52059} (GameX Class) - http://www1.kele8.com/game/system/activex/gamex.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {88734439-46D0-42C0-A13F-7E881EE550CF} (Filetran Control) - http://www.bluesky.cn/download/filetran.cab
O16 - DPF: {99888952-AC62-437C-AFC6-7B5CF05A7F2F} (IEDown Class) - http://www.ourgame.com/srvcenter/download/IEDown.cab
O16 - DPF: {9A578C98-3C2F-4630-890B-FC04196EF420} (CNNIC_IDN) - http://jump.cnnic.cn/stat/stat?sid=0008&debug=false&pid=c_95p&url=http://client.jogo.cn/download/cnnic/cdn.cab
O16 - DPF: {9b935470-ad4a-11d5-b63e-00c04faedb18} (Oracle JInitiator 1.1.8.16) - http://202.104.30.109/jinitiator/jinit11816.exe
O16 - DPF: {ABA7CC7F-019D-47DB-A0D2-B3C2B3AC1B44} (Fc2Boot Class) - http://www2.kele8.com/fun/system/fc2boot.cab
O16 - DPF: {C0C13879-6A17-429E-80F1-60B23FC1F720} (FcBoot Class) - http://www1.kele8.com/game/system/activex/fcboot.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O16 - DPF: {F138084D-84D7-48CD-BEA8-04772457516E} (VqqSpeedDlProxy Class) - http://218.85.138.27/vqqsdl1009.cab
O20 - AppInit_DLLs: KB2153662.LOG
O20 - Winlogon Notify: gebcd - C:\WINDOWS\System32\gebcd.dll
O20 - Winlogon Notify: mllml - C:\WINDOWS\SYSTEM32\mllml.dll
O20 - Winlogon Notify: TGENotify - C:\WINDOWS\SYSTEM32\TGENotify.dll
O21 - SSODL: 0IDBBJEI - {48EC6A5E-595C-1954-5DC8-41C6066F1877} - C:\WINDOWS\System32\Ncgnkbkd.dll (file missing)
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\star\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\star\Rising\Rav\Ravmond.exe
O23 - NT 服务: TGE CardReader Mgr Host v2 (TGECardReaderMgrHost.2) - Unknown owner - C:\Program Files\Legend\联想键盘驱动\TGESrvLogon.exe (file missing)
gototop
 

那个01项是怎么回事呢?
还有C:\HWR\Hide.exe
C:\Program Files\IS\is.exe
这两个我用KILLBOX都没有杀掉,现在QQ上不去,感觉是QQ木马,可是我杀不掉.
请大虾帮我看看,指点一下,该查哪个?在下不胜感激!

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT