瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】小弟跪求高手了【求助】给小弟看看了,帮小弟条命!

1   1  /  1  页   跳转

【求助】小弟跪求高手了【求助】给小弟看看了,帮小弟条命!

【求助】小弟跪求高手了【求助】给小弟看看了,帮小弟条命!

小弟正版的瑞星,天天更新.前几天用BT下了个电影,RM格式,默认用REALPLAYER播放,一点开,这个电影文件自动叫REALPLAYER打开了N多个媒体连接,也就是网页只类,估计就中招了,然后瑞星时不时的就监控到有病毒,一个一个杀,然后打开瑞星从头到尾杀了个遍,没发现什么病毒,但是监控不停的监控到有病毒.病毒名称也就是后门啊木马啊QQGAME啊QQPASSWORD一类的,然后QQ被登陆,QQ被盗,郁闷~~大哥们大姐们,高手们,我的本本已经不能再承受重新安装XP之苦了,光区已经OVER了,你们救救我吧!我是瑞星好几年的忠实FANS啊!
附上扫描结果:
Logfile of HijackThis v1.99.1
Scan saved at 12:15:32 AM, on 8/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\ChinaNet\VnetClient.exe
C:\Program Files\Tencent\QQ\TIMPlatform.exe
C:\Program Files\GreenBrowser\GreenBrowser.exe
C:\Program Files\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\TTPlayer\TTPlayer.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Rising\Rav\Rav.exe
C:\Documents and Settings\Lemon\Desktop\HijackThis V1[1].99.1汉化版\HijackThis.exe

F2 - REG:system.ini: UserInit=userinit.exe,
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [SKYNET Personal FireWall] C:\PROGRA~1\SKYNET\FIREWALL\pfw.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [wdfmgr32] C:\WINDOWS\system32\wdfmgr32.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQì?2ê1¤??ì?éè?? - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wmpcd32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wmpcd32.dll
O15 - Trusted Zone: http://www.icbc.com.cn
O17 - HKLM\System\CCS\Services\Tcpip\..\{C228D59B-B568-41DE-8011-34EC18B1FA04}: NameServer = 222.88.88.88 219.150.150.150
O17 - HKLM\System\CCS\Services\Tcpip\..\{CCF8560C-374F-49FD-A39E-3F7CD3C0CAB0}: NameServer = 222.88.88.88
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Aication (tographicServices) - TENCENT - C:\Program Files\Common Files\Microsoft Shared\MSInfo\svchsot.exe

最后编辑2006-08-27 01:07:13
分享到:
gototop
 

还有,应该是我中招了以后,有一次我开机拨上了号,什么程序也没运行,但是我的MODEM的数据灯就闪个不停,我察看本地连接,然后发现发送的数据包有几十万个,而接受的就300多个.高手,小弟的命就靠你们了!
gototop
 

嗯,我新装的系统,没装什么程序,一个很干净的系统,高手们,拯救小弟的电脑啊.
gototop
 

3楼大哥,发给我的BAIDU说是NOKIA的问题,我这里有NOKIA的什么问题吗?
gototop
 

小弟用的英文版的XP,难怪扫描结果都是英文....
gototop
 

NOKIA的这个进程和小弟电脑中招有联系吗?HJ修复什么意思?小弟菜,多指教
gototop
 

我已经把O23 - Service: Aication (tographicServices) - TENCENT - C:\Program Files\Common Files\Microsoft Shared\MSInfo\svchsot.exe
修复了
然后呢?
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT