瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】svhost32.exe,rundll32.exe,msime.exe问题..被无限烦恼中

1   1  /  1  页   跳转

【求助】svhost32.exe,rundll32.exe,msime.exe问题..被无限烦恼中

【求助】svhost32.exe,rundll32.exe,msime.exe问题..被无限烦恼中

(日志在4楼)
本人使用2003DE系统..杀毒软件瑞星2007测试版..
系统不时多出schost32.exe  rundll32.exe  msime.exe 但是瑞星都检测不了...我是用safe360扫描到的..
rundll32.exe常使我cpu保持100%
这些东西找到地方删除了...注册表里也删除了...但是就是又会出现....请大家告诉我解决的方法...谢谢
schost32.exe  C:\Program Files\microsoft\schost32.exe
rundll32.exe  c:\program files\rundll32.exe
rundll32.exe  c:\windows\comand\rundll32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN
rundll32.exe  c:\windows\Inter\rundll32.exe
  HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN
2个是  Tray 和 zt

msime.exe      c:\windows\msime.exe
    对应出来的东西使 ms

中毒后在 HKEY_current_user\SOFTWARE\MICROSOFT\WINDOWS nt\CURRENTVERSION\windows
里多了个  LOAD  指向 svhost32.exe


我怎么杀也杀不干净...请大家指教....
顺便问问这个东西是怎么感染来的..谢谢
最后编辑2006-09-05 11:04:39
分享到:
gototop
 

【回复“白河小鸟”的帖子】
顺便说声...中病毒后我声卡好像出现冲突了...寒...要每次重新启动才有声音...一重新中毒...继续没声音
gototop
 

【回复“轩辕小聪”的帖子】
Logfile of HijackThis v1.99.1
Scan saved at 11:00:43, on 2006-9-5
Platform: Windows 2003 SP1 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 SP1 (6.00.3790.1830)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\PeanutHull3\PhCore.exe
C:\Program Files\RhinoSoft.com\Serv-U\ServUDaemon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\soundman.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\RhinoSoft.com\Serv-U\ServUTray.exe
C:\Program Files\PeanutHull3\Phmain.exe
F:\Program Files\Tencent\qq\QQ.exe
F:\Program Files\Tencent\qq\TIMPlatform.exe
C:\WINDOWS\system32\conime.exe
F:\Program Files\BitComet\BitComet.exe
C:\Program Files\360safe\360Safe.exe
C:\Program Files\Rising\Rav\Rav.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\Documents and Settings\Administrator\桌面\HijackThis.exe

O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ServUTrayIcon] C:\Program Files\RhinoSoft.com\Serv-U\ServUTray.exe
O4 - HKCU\..\Run: [PhMain] C:\Program Files\PeanutHull3\Phmain.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - F:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\Program Files\Tencent\qq\SendMMS.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{1F08BE6C-7585-49DE-9271-F02E3D3D3709}: NameServer = 218.76.64.138 202.103.96.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{A1B77E6D-C839-41BA-BB12-68697226B71F}: NameServer = 211.91.216.129
O20 - Winlogon Notify: dimsntfy - C:\WINDOWS\SYSTEM32\dimsntfy.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PeanuthullCore - 广东网域 - C:\Program Files\PeanutHull3\PhCore.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Serv-U FTP 服务器 (Serv-U) - Rhino Software, Inc. +1(262) 560-9627 - C:\Program Files\RhinoSoft.com\Serv-U\ServUDaemon.exe

我清理后的日志,但是绝对没有清理干净...5555
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT