瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求助:我中了Trojan.PSW.QQPass.pxx,可是运行不了System Repair Engineer

12   1  /  2  页   跳转

求助:我中了Trojan.PSW.QQPass.pxx,可是运行不了System Repair Engineer

求助:我中了Trojan.PSW.QQPass.pxx,可是运行不了System Repair Engineer

我中了Trojan.PSW.QQPass.pxx,想按照论坛的解决方法删除,可是System Repair Engineer无论是扫描还是启动,都会发送错误报告(详情附图),然后System Repair Engineer就不能运行,要关闭了!
    我已经尝试过下载很多不同版本的System Repair Engineer,可是结果都是一样!
    谁可以帮帮我消除病毒或者解决System Repair Engineer的问题啊!
    麻烦各位了!谢谢!

附件附件:

下载次数:309
文件类型:image/pjpeg
文件大小:
上传时间:2006-10-6 23:47:07
描述:
预览信息:EXIF信息



最后编辑2006-10-13 21:44:37
分享到:
gototop
 

引用:
【网络一兵的贴子】这问题最近比较普遍,干脆完全格式化后重装系统最省心。这样都解决了。
………………


  谢谢您!除了重装,还有别的办法吗?因为我电脑装了很多东西,重装真的很痛苦啊!!
gototop
 

引用:
【xp123的贴子】看http://forum.ikaka.com/topic.asp?board=28&artid=8182259
………………


谢谢!可是这个方法是不行的,因为我看到论坛有也有中Trojan.PSW.QQPass.pxx的人已经试过!这个带"pxx"的已属于变种了!


我看到这个:http://forum.ikaka.com/topic.asp?board=28&artid=8185040&page=1
44楼的无邪哥哥已经给了解法,可是每个人的具体情况是不一样的,现在最惨的的关键是我用不了System Repair Engineer,所以连试一下去解决也不行!!!可怜啊!!!!!
gototop
 

【回复“yan121”的帖子】

顶一下,哪位高手能帮帮忙啊!!!不胜感激!!!
gototop
 

【回复“我无邪”的帖子】
刚刚试了,还是一样!
真的一定要重装吗?可是我又太多东西,例如扫描仪,打印机之类,重装真的很痛苦啊!

刚刚用扫了日志:

Logfile of Kaka v2. 0. 0. 9 Scan Module v2. 0. 0. 1
Scan saved at 12:21:12, on 2006-10-07
Platform: Microsoft Windows XP Professional Service Pack 1 (Build 2600)
MSIE: Internet Explorer v6.00 SP1;Q837009;Q832894;Q831167;Q823353;Q867801; (6.00.2800.1106 (xpsp1.020828-1920))


Running processes:
[smss.exe]
CommandLine =

[csrss.exe]
CommandLine = C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

[winlogon.exe]
CommandLine = winlogon.exe

[services.exe]
CommandLine = C:\WINDOWS\system32\services.exe

[lsass.exe]
CommandLine = C:\WINDOWS\system32\lsass.exe

[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss

[CCenter.exe]
CommandLine = "C:\Program Files\Rising\Rav\CCenter.exe"

[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs

[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k NetworkService

[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k LocalService

[rfwsrv.exe]
CommandLine = "c:\program files\rising\rfw\rfwsrv.exe"

[explorer.exe]
CommandLine = C:\WINDOWS\Explorer.EXE

[spoolsv.exe]
CommandLine = C:\WINDOWS\system32\spoolsv.exe

[rfwmain.exe]
CommandLine =  -StartUp

[RavStub.exe]
CommandLine = "C:\Program Files\Rising\Rav\RavStub.exe" /RAVMOND

[rundll32.exe]
CommandLine = Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32

[alg.exe]
CommandLine = C:\WINDOWS\System32\alg.exe

[HPConfig.exe]
CommandLine = C:\WINDOWS\system32\HPConfig.exe

[HPWirelessMgr.exe]
CommandLine = "C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe"

[mdm.exe]
CommandLine = "C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"

[sqlservr.exe]
CommandLine = "C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER

[realsched.exe]
CommandLine = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot

[RavTask.exe]
CommandLine = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM

[update.exe]
CommandLine = "C:\Program Files\Common Files\UPDATE2\Update.exe"

[RavMon.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmon.exe" -SYSTEM

[rundll32.exe]
CommandLine = "C:\WINDOWS\Intel\rundll32.exe"

[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k imgsvc

[wdfmgr.exe]
CommandLine = C:\WINDOWS\System32\wdfmgr.exe

[wdfmgr32.exe]
CommandLine = "C:\WINDOWS\System32\wdfmgr32.exe"

[rundll32.exe]
CommandLine = "C:\WINDOWS\System32\rundll32.exe" "C:\Program Files\DeskAdTop\Run.dll" ,Rundll

[WebThunder.exe]
CommandLine = "C:\Program Files\Thunder Network\WebThunder\WebThunder.exe"

[ctfmon.exe]
CommandLine = "C:\WINDOWS\System32\ctfmon.exe"

[wuauclt.exe]
CommandLine = "C:\WINDOWS\System32\wuauclt.exe" /RunStoreAsComServer Local\[45c]SUSDSe0a026c274ae8240a5c78e5d0ae055d6

[wuauclt.exe]
CommandLine = "C:\WINDOWS\System32\wuauclt.exe"

[IEXPLORE.EXE]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe" -nohome

[KkScan.exe]
CommandLine = "C:\Program Files\Rising\KakaToolBar\KkScan.exe"

[KkScan.exe]
CommandLine = "C:\Program Files\Rising\KakaToolBar\KkScan.exe"

[svchost.exe]
CommandLine = "C:\WINDOWS\System32\svchost.exe"

[Rsaupd.exe]
CommandLine = "C:\Program Files\Rising\KakaToolBar\Rsaupd.exe"
gototop
 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://seek.3721.com/srchasst.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://www.yahoo.com.cn
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://toolsbar.kuaiso.com/index.htm
R3 - Default URLSearchHook is missing
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: WebThunder Browser Helper - {00000AAA-A363-466E-BEF5-9BB68697AA7F} - C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_013.dll
O2 - BHO: IExpress - {27E96DE0-8211-42CF-9A1E-FA6246A95B77} - C:\WINDOWS\System32\iexpress.dll (file missing)
O2 - BHO: QQBrowserHelperObject Class - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\QQ\QQIEHelper.dll
O2 - BHO: Thunder Browser Helper - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll
O2 - BHO:  - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - D:\KuGoo3\KuGoo3DownXControl.ocx
O2 - BHO: CnsHook Class - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\CnsHook.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\PROGRA~1\FlashGet\getflash.dll (file missing)
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\kakatool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [KuGoo3] rem "D:\KuGoo3\KuGoo.exe"
O4 - HKCU\..\Run: [Realplayer.exe] rem C:\WINDOWS\System32\Realplayer.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] rem "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATIPTA] rem C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Display Settings] rem C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [SynTPLpr] rem C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] rem C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] rem Ati2mdxx.exe
O4 - HKLM\..\Run: [MMTray] rem C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [Cpqset] rem C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] rem "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QT4HPOT] rem C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [NMGameX_AutoRun] rem C:\WINDOWS\System32\Rundll32.exe NMGameX.dll,LiveProcess /aa
O4 - HKLM\..\Run: [Microsoft Update] rem snlogsvc.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Easy-PrintToolBox] rem C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [ExFilter] Rundll32.exe "C:\PROGRA~1\CNNIC\Cdn\cdnspie.dll,ExecFilter solo"
O4 - HKLM\..\Run: [KuGoo3] rem D:\KuGoo3\KuGoo.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDATE2\Update.exe
O4 - HKLM\..\Run: [zt] C:\WINDOWS\Intel\rundll32.exe
O4 - HKLM\..\Run: [wdfmgr32] C:\WINDOWS\System32\wdfmgr32.exe
O4 - HKLM\..\Run: [SOUNDM] winsmd.exe
O4 - HKLM\..\Run: [Desktop] C:\WINDOWS\System32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll
O4 - HKLM\..\Run: [WebThunder] C:\Program Files\Thunder Network\WebThunder\WebThunder.exe
O4 - HKLM\..\RunServices: [Microsoft Update] snlogsvc.exe
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 使用Web迅雷下载 - C:\Program Files\Thunder Network\WebThunder\GetUrl.htm
O8 - Extra context menu item: 使用Web迅雷下载全部链接 - C:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm
O8 - Extra context menu item: 使用网际快车下载 - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ表情 - D:\qq\AddEmotion.htm
O9 - Extra Button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra Button: 启动Web迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)
O9 - Extra 'Tools' menuitem: 启动Web迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra Button: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} - http://www.rising.com.cn/?u=RSTB (file missing)
O9 - Extra Button: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com/?u=RSTB (file missing)
O11 - Options group: [!CNS]  中文上网
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O16 - DPF: DirectAnimation Java Classes - file://C:\WINDOWS\Java\classes\dajava.cab
O16 - DPF: {36CB6B28-FC08-4373-8F54-1A02E3C15B7D} (WebDownLoad Control) - http://61.172.200.234:8000/mp444/WebDownLoadProj1.ocx
O16 - DPF: {3D8F74EE-8692-4F8F-A8D2-7522B732519E} (WebActivater Control) - http://game.qq.com/QQGame.cab
O16 - DPF: {448A5F6B-8C03-4B54-A338-F00237C508AD} (WEBChatRoomOCX Control) - http://www.51uc.com/cab/WEBChatRoom_1_46.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com/PhotoUpload/MsnPUpld.cab?10,0,910,0
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/2486869e78f024c3f804/netzip/RdxIE601_cn.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/ravkill/rsonline.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{200CA515-49E5-4E50-A149-8A087DA7C069}: NameServer = 202.96.128.86 202.96.128.166
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\System32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\System32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\System32\msdxm.ocx
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\System32\wiascr.dll
O21 - SSODL: DVDBurn - {790448C3-4239-45AF-C98B-367991A8B103} - C:\WINDOWS\Downloaded Program Files\AfxEdit.dll
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\System32\hpconfig.exe
O23 - Service: HPWirelessMgr (HPWirelessMgr) - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: Network Logon (NetWorkLogon) -  - rundll32.exe KB896495.log,start
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\Rising\Rav\CCenter.exe"
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\Rising\Rav\Ravmond.exe"
O23 - Service: telnets (telnets) -  - C:\WINDOWS\wondowws.exe
gototop
 

【回复“我无邪”的帖子】
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ AdaptecDirectCD找不到文件:rem

+ ATIModeChange找不到文件:rem

+ ATIPTA找不到文件:rem

+ Cpqset找不到文件:rem

+ Display Settings找不到文件:rem

+ Easy-PrintToolBox找不到文件:rem

+ IMJPMIG8.1找不到文件:rem

+ KuGoo3找不到文件:rem

+ QT4HPOT找不到文件:rem

+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe

+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwmain.exe

+ SynTPEnh找不到文件:rem

+ SynTPLpr找不到文件:rem

+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe

+ WebThunderWeb 迅雷深圳市迅雷网络技术有限公司c:\program files\thunder network\webthunder\webthunder.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

+ RavStubRising RavStubBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravstub.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

+ KuGoo3找不到文件:rem

HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components

+ 0找不到文件:About:Home

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components

+ n/a找不到文件:C:\Program Files\Messenger\msgsc.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

+ DVDBurn找不到文件:CLSID\{790448C3-4239-45AF-C98B-367991A8B103}\InprocServer32

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ cnshook.dll3721 CNS Module北京三七二一科技有限公司c:\windows\downloaded program files\cnshook.dll

+ InprocServer32找不到文件:CLSID\{06A48AD9-FF57-4E73-937B-B493E72F4226}\InprocServer32

+ InprocServer32找不到文件:CLSID\{08315C1A-9BA9-4B7C-A432-26885F78DF28}\InprocServer32

+ InprocServer32找不到文件:CLSID\{E568441B-9EF3-49F8-9A67-4141AC41ADD4}\InprocServer32

+ Rising Execute File Exts hookRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ sysldr.dllc:\windows\system32\sysldr.dll

+ yclickon.dllClickOn ModuleYAHOO Corporation Limitedc:\program files\yahoo!\assistant\yclickon.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Adaptec DirectCD Shell ExtensionDirectCD Shell Extention DLLRoxioc:\program files\roxio\easy cd creator 5\directcd\shellex.dll

+ Display Panning CPL Extension找不到文件:deskpan.dll

+ HyperTerminal Icon Ext找不到文件:CLSID\{88895560-9AA2-1069-930E-00AA0030EBC8}\InprocServer32

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ ScriptDropShellExtRoboEnhancer ScriptDropShellExt Modulec:\program files\acd systems\roboenhancer\scriptdropshellext.dll

+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realone player\rpshell.dll

+ WinRAR shell extensionc:\program files\winrar\rarext.dll

+ WinZipWinZip Shell Extension DLLWinZip Computing, Inc.c:\program files\winzip\wzshlstb.dll

+ WinZipWinZip Shell Extension DLLWinZip Computing, Inc.c:\program files\winzip\wzshlstb.dll

+ WinZipWinZip Shell Extension DLLWinZip Computing, Inc.c:\program files\winzip\wzshlstb.dll

+ WinZipWinZip Shell Extension DLLWinZip Computing, Inc.c:\program files\winzip\wzshlstb.dll

+ 粉碎文件找不到文件:CLSID\{C14F7681-33D8-11D3-A09B-00500402F30B}\InprocServer32

+ 我的手机File Manager interfaceTeleca Software Solutions ABc:\program files\sony ericsson\mobile\file manager\fmgrgui.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ CnsHook Class3721 CNS Module北京三七二一科技有限公司c:\windows\downloaded program files\cnshook.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ kakatool.dllBeijing Rising Technology Co., Ltd.c:\windows\system32\kakatool.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ @shdoclc.dll,-864c:\windows\web\related.htm

+ 访问卡卡社区找不到文件:http://www.ikaka.com/?u=RSTB

+ 访问瑞星网站找不到文件:http://www.rising.com.cn/?u=RSTB

+ 启动Web迅雷找不到文件:http://my.xunlei.com

+ 启动迅雷Thunder Networking Technologies,LTDc:\program files\thunder network\thunder\thunder.exe

计划任务

+ Symantec NetDetect.jobSymantec NetDetectSymantec Corporationc:\program files\symantec\liveupdate\ndetect.exe

HKLM\System\CurrentControlSet\Services

+ HPConfigHPConfig ModuleHewlett-Packardc:\windows\system32\hpconfig.exe

+ HPWirelessMgrHPWirelessMgr ModuleHewlett-Packard Co.c:\program files\hpq\notebook utilities\hpwirelessmgr.exe

+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwsrv.exe

+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe

+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe

HKLM\System\CurrentControlSet\Services

+ aliadwdmALi Audio Accelerator WDM DriverAcer Laboratories Inc.c:\windows\system32\drivers\ac97ali.sys

+ AliIdeALi mini IDE DriverAcer Laboratories Inc.c:\windows\system32\drivers\aliide.sys

+ ALiIRDAALi Fast Infrared DriverAcer Laboratories Inc.c:\windows\system32\drivers\aliirda.sys

+ ati2mtagATI Radeon Miniport DriverATI Technologies Inc.c:\windows\system32\drivers\ati2mtag.sys

+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\windows\system32\drivers\basetdi.sys

+ caboagpATI AGP driverATI Technologies Inc.c:\windows\system32\drivers\atisgkaf.sys

+ CALIAUDConexant WDM AC97 Audio DriverConexant Systems Inc.c:\windows\system32\drivers\caliaud.sys

+ CALIHALAConexant AmcHal DriverConexant Systems Inc.c:\windows\system32\drivers\calihal.sys

+ DKbFltrDritek Keyboard Filter DriverDritek System Inc.c:\windows\system32\drivers\dkbfltr.sys

+ DP83815National Semiconductor Corp. DP83815/816 10/100 MacPhyter NDIS 5.0 Miniport DriverNational Semiconductor Corp.c:\windows\system32\drivers\dp83815.sys

+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys

+ FA312NETGEAR FA312 Fast Ethernet NDIS 5.0 Miniport DriverNETGEAR Corp.c:\windows\system32\drivers\fa312nd5.sys

+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys

+ HookRegc:\program files\rising\rav\hookreg.sys

+ HookSysHooksysRisingc:\program files\rising\rav\hooksys.sys

+ HookUrlHookUrlBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\hookurl.sys

+ HPCIHP Configuration Interface DriverHewlett-Packardc:\windows\system32\drivers\hpci.sys

+ kmsinputc:\windows\system32\drivers\kmsinput.sys

+ MEMSCANMemScan Driver瑞星软件有限公司c:\program files\rising\rav\memscan.sys

+ mProcRsRising Personal FireWall  mprocrs.sysBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\mprocrs.sys

+ New0c:\windows\system32\new.sys

+ npkcrypt找不到文件:D:\qq\npkcrypt.sys

+ npkcusbnProtect KeyCrypt DriverINCA Internet Co., Ltd.d:\qq\npkcusb.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys

+ RsFwDrvnt_fwdrvBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rsfwdrv.sys

+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys

+ Sense3SENSE3 Driver for NTBeijing Senselockc:\windows\system32\drivers\sense3.sys

+ SVKPSVKP driver for NTAntiCrackingc:\windows\system32\svkp.sys

+ SymEventSymantec Event LibrarySymantec Corporationc:\program files\symantec\symevent.sys

+ SynTPSynaptics Touchpad DriverSynaptics, Inc.c:\windows\system32\drivers\syntp.sys

+ vcddevVirtual Native Network DriverVNN B.J.c:\windows\system32\drivers\vcdvnic.sys

HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute

+ ckc:\windows\system32\ck.exe

HKCU\Control Panel\Desktop\Scrnsave.exe

+ C:\WINDOWS\卡通动~1.SCRc:\windows\卡通动物 屏幕保护程序.scr

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors

+ Canon BJ Language Monitor PIXMA iP1000BJ Language MonitorCANON INC.c:\windows\system32\cnmlm6e.dll

gototop
 

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      14:19:31, 日期 2006-10-7
操作系统:  Windows XP SP1 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\System32\Rundll32.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Thunder Network\WebThunder\WebThunder.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\zh\桌面\HijackThis1[1].99.1\HijackThis1991zww.exe
gototop
 

R3 - 默认的URLSearchHook丢失。用HijackThis修复
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\CnsHook.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\kakatool.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] rem "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [ATIPTA] rem C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - 启动项HKLM\\Run: [Display Settings] rem C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - 启动项HKLM\\Run: [SynTPLpr] rem C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - 启动项HKLM\\Run: [SynTPEnh] rem C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - 启动项HKLM\\Run: [ATIModeChange] rem Ati2mdxx.exe
O4 - 启动项HKLM\\Run: [Cpqset] rem C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - 启动项HKLM\\Run: [AdaptecDirectCD] rem "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - 启动项HKLM\\Run: [QT4HPOT] rem C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [Easy-PrintToolBox] rem C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - 启动项HKLM\\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [KuGoo3] rem D:\KuGoo3\KuGoo.exe
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [WebThunder] C:\Program Files\Thunder Network\WebThunder\WebThunder.exe
O4 - 启动项HKLM\\RunOnce: [RavStub] "C:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [KuGoo3] rem "D:\KuGoo3\KuGoo.exe"
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - IE右键菜单中的新增项目: 使用Web迅雷下载 - C:\Program Files\Thunder Network\WebThunder\GetUrl.htm
O8 - IE右键菜单中的新增项目: 使用Web迅雷下载全部链接 - C:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\qq\AddEmotion.htm
O9 - 浏览器额外的按钮: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - 浏览器额外的“工具”菜单项: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - 浏览器额外的按钮: 启动Web迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)
O9 - 浏览器额外的“工具”菜单项: 启动Web迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\WINDOWS\System32\shdocvw.dll
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\WINDOWS\System32\shdocvw.dll
O9 - 浏览器额外的按钮: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} - http://www.rising.com.cn/?u=RSTB (file missing)
O9 - 浏览器额外的按钮: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com/?u=RSTB (file missing)
O11 - Options group: [!CNS]  中文上网
O16 - DPF: {36CB6B28-FC08-4373-8F54-1A02E3C15B7D} (WebDownLoad Control) - http://61.172.200.234:8000/mp444/WebDownLoadProj1.ocx
O16 - DPF: {3D8F74EE-8692-4F8F-A8D2-7522B732519E} (WebActivater Control) - http://game.qq.com/QQGame.cab
O16 - DPF: {448A5F6B-8C03-4B54-A338-F00237C508AD} (WEBChatRoomOCX Control) - http://www.51uc.com/cab/WEBChatRoom_1_46.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com/PhotoUpload/MsnPUpld.cab?10,0,910,0
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/2486869e78f024c3f804/netzip/RdxIE601_cn.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/ravkill/rsonline.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{200CA515-49E5-4E50-A149-8A087DA7C069}: NameServer = 202.96.128.86 202.96.128.166
O17 - HKLM\System\CS1\Services\Tcpip\..\{200CA515-49E5-4E50-A149-8A087DA7C069}: NameServer = 202.96.128.86 202.96.128.166
O21 - SSODL: DVDBurn - {790448C3-4239-45AF-C98B-367991A8B103} - (no file)
O23 - NT 服务: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - NT 服务: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - NT 服务: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe

gototop
 

看到:
HijackThis_zww汉化版扫描日志 V1.99.1:R3 - 默认的URLSearchHook丢失。用HijackThis修复

HijackThis_zww可能修复了SREng,SREng好像也可以用了!
这样有没有帮助啊?

补充一点,现在重启后用瑞星18.47.40扫内存,已经不会像之前那样会有二十多个Trojan.PSW.QQPass.pxx,现在扫内存,瑞星是显示没有病毒的!
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT