瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 Explorer.EXE和Trojan.DL.Agent.lag 杀不掉.(日志)

1   1  /  1  页   跳转

Explorer.EXE和Trojan.DL.Agent.lag 杀不掉.(日志)

Explorer.EXE和Trojan.DL.Agent.lag 杀不掉.(日志)

Ps:安全模式下杀过N次了

Trojan.DL.Agent.lag 刚查到的病毒.杀不掉 还有其他大概8种病毒 名字差不多好象
(历史记录打不开 所以忘记了)

Explorer.EXE iexplore.exe 不懂哪个是病毒? 两个进程同时都在的.
目录如下
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
还有wuauclt.exe 进程有两个.. 郁闷..
C:\WINDOWS\system32\wdfmgr.exe 名字好怪. 是什么?
C:\WINDOWS\system32\svchost.exe 这个进程我有 8个啊. 正常么?/

日志如下:

HijackThis@Qoo的扫描日志  V1.97.7
Scan saved at 13:04:48, on 2006-8-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\rising\Rav\RavTask.exe
D:\Program Files\rising\Rav\RavStub.exe
D:\Program Files\rising\Rav\Ravmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\rising\Rfw\Rfw.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
D:\Program Files\rising\Rav\Rav.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX00.690\HijackThis.exe
最后编辑2006-08-28 10:56:54
分享到:
gototop
 

R3 - URLSearchHook: (no name) - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - (no file)
O2 - BHO: (no name) - {14A21378-5BB1-4BC4-95D5-5D3F51527F6F} - C:\WINDOWS\system32\smflash.ocx
O2 - BHO: (no name) - {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} - E:\Program Files\Super Rabbit\MagicSet\haokanbar.dll
O3 - Toolbar: (no name) - {F43BD772-ABDD-43b7-A96A-3E9E61946EC0} - (no file)
O3 - Toolbar: NB46 - {56E88004-7AF8-474C-BB30-76E0B7B2B003} - C:\PROGRA~1\nb46.com\NB46TO~1.DLL
O3 - Toolbar: ????? - {43869BB3-22FD-4F15-9B46-238106BA2F4E} - E:\Program Files\Super Rabbit\MagicSet\haokanbar.dll
O4 - HKLM\..\Run: [RavTask] "D:\Program Files\rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [rfw] d:\Program Files\rising\Rfw\Rfw.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: NTUSER.DAT
O4 - Startup: 桌面.lnk
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Global Startup: ntuser.dat
O4 - Global Startup: ntuser.dat.LOG
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &使用迅雷下载 - D:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\qq\SendMMS.htm
O9 - Extra button: QQ (HKLM)
O9 - Extra 'Tools' menuitem: QQ (HKLM)
O10 - Unknown file in Winsock LSP: c:\windows\system32\wshcon32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wshcon32.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O16 - DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} (MMCPlayer Class) - http://p3p.sogou.com/MMCShell.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{05AAF654-DC3B-4B7F-B1E9-1E0B6B8955BE}: NameServer = 219.150.32.132 211.98.2.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{05AAF654-DC3B-4B7F-B1E9-1E0B6B8955BE}: NameServer = 219.150.32.132 211.98.2.4
O17 - HKLM\System\CS3\Services\Tcpip\..\{05AAF654-DC3B-4B7F-B1E9-1E0B6B8955BE}: NameServer = 219.150.32.132 211.98.2.4
gototop
 

瑞星杀不掉啊..

安全模式下也一样.. 防火墙 闪个不停...IP地址都不一样.

我晕..

下载软件都被弄坏了..  卡巴下载不了..

我晕.. 怎么办?
gototop
 

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT