瑞星卡卡安全论坛技术交流区系统软件 机器总叫,是不是中毒了?【求助】

1   1  /  1  页   跳转

机器总叫,是不是中毒了?【求助】

机器总叫,是不是中毒了?【求助】

最近我的主机总是发出“嘟嘟”的叫声,网速有时也很慢,CPU占用率经常达到100%,此时电脑就根死机一样,不能进行操作,用瑞星杀毒还没有毒,只是经常出现下面两个本机病毒:地址:C:\DOCUME~1\Owner\LOCALS~1\Temp\6.exe
            C:\DOCUME~1\Owner\LOCALS~1\Temp\ck3.exe.exe>>Unpack
病毒名:Dropper.LMir.r
      Trojan.PSW.QQPass.pgo
但是按这个路径我找不到这个文件,瑞星能杀掉这两个病毒。
HijackThis v1.99.1扫描结果:
Logfile of HijackThis v1.99.1
Scan saved at 12:23:04, on 2006-6-20
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
D:\瑞星杀毒软件\RAV\CCENTER.EXE
D:\瑞星杀毒软件\Rav\Ravmond.exe
d:\瑞星杀毒软件\rfw\rfwsrv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\soundman.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
D:\瑞星杀毒软件\Rav\RavTask.exe
D:\瑞星杀毒软件\Rfw\rfwmain.exe
C:\WINDOWS\System32\ctfmon.exe
D:\瑞星杀毒软件\Rav\Ravmon.exe
C:\WINDOWS\system32\spoolsv.exe
D:\瑞星杀毒软件\Rav\RavStub.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\aua1\aua1.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Maxthon\Maxthon.exe
C:\WINDOWS\System32\ctfmon.exe
D:\瑞星杀毒软件\Rav\Rav.exe
D:\瑞星杀毒软件\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\WINDOWS\System32\PYINTAU.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
D:\WinRAR V3.42 汉化版\安装\WinRAR.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX00.706\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R3 - URLSearchHook: 虎翼DIY吧! - {0A00D11E-B1E7-44b5-AD88-C9190876AAC4} - C:\WINDOWS\System32\diybar2\diybar2.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: 59.36.99.231 www.mir5173.com
O1 - Hosts: 59.36.99.231 ert0003.e76.163ns.com
O1 - Hosts: 59.36.99.231 sky001.e11.163ns.com
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v13.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll (file missing)
O2 - BHO: URLMonitor Class - {3ED9FFDA-79DB-4B2D-99B7-16EA3C4A3A92} - C:\WINDOWS\System32\hap.dll
O2 - BHO: Link Filter - {4022F902-ABC7-4C79-924F-BB26F1D355A2} - C:\WINDOWS\System32\diybar2\diybar2.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\腾讯QQ 2005 SP1 简体中文正式版\QQIEHelper.dll
O2 - BHO: DownloadValue Class - {616D4040-5712-4F0F-BCF1-5C6420A99E14} - C:\WINDOWS\System32\winhtp.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL (file missing)
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - (no file)
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [RavTask] "D:\瑞星杀毒软件\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "D:\瑞星杀毒软件\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item:  >> 彩信发送 << - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\腾讯QQ 2005 SP1 简体中文正式版\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 导出当前页到超星阅览器(&A) - D:\SSReader 3.8简体中文增强版\SSREADER36\ss_all.htm
O8 - Extra context menu item: 导出选中部分到超星阅览器(&S) - D:\SSReader 3.8简体中文增强版\SSREADER36\ss_select.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\腾讯QQ 2005 SP1 简体中文正式版\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\腾讯QQ 2005 SP1 简体中文正式版\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\腾讯QQ 2005 SP1 简体中文正式版\SendMMS.htm
O9 - Extra button: (no name) - {3F686D91-4AFA-4ed1-B43F-F1DB46ED480C} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Link Filter - {3F686D91-4AFA-4ed1-B43F-F1DB46ED480C} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\腾讯QQ 2005 SP1 简体中文正式版\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\腾讯QQ 2005 SP1 简体中文正式版\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\腾讯QQ 2005 SP1 简体中文正式版\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\腾讯QQ 2005 SP1 简体中文正式版\QQIEHelper.dll
O16 - DPF: {28E0FA88-ABA8-4937-A247-3031F1A11165} (Installer Class) - http://dl.51.net/download/diybar2.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{45609A3D-0321-4866-B802-914A6A25701C}: NameServer = 85.255.116.105 85.255.112.63
O17 - HKLM\System\CCS\Services\Tcpip\..\{6A7C48A7-9BBE-4784-A1C7-7C23CE742360}: NameServer = 85.255.116.105,85.255.112.63
O17 - HKLM\System\CCS\Services\Tcpip\..\{843806D3-15B1-4ECE-97A5-1371A24ED6B8}: NameServer = 85.255.116.105,85.255.112.63
O17 - HKLM\System\CS1\Services\Tcpip\..\{45609A3D-0321-4866-B802-914A6A25701C}: NameServer = 85.255.116.105 85.255.112.63
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\瑞星杀毒软件\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\瑞星杀毒软件\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\瑞星杀毒软件\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\瑞星杀毒软件\Rav\Ravmond.exe
O23 - Service: winaua - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\aua1\aua1.exe

最后编辑2006-06-22 11:05:03.733000000
分享到:
gototop
 

问题依旧,还有了新问题在不进行任何操作的情况下,机器自己就发出“蹬蹬”的声音。“嘟嘟”的声音还是总响。
gototop
 

如何清理系统的自启动项目和注册表里所对应的东西?
gototop
 

将C盘格式化后,问题ok。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT