最近机器无故多了一个i.exe进程,hosts文件也反复被篡改,刚删除里面的内容,一会又出现了,多数是指向与瑞星有关的网页,所以卡卡出现升不了级,进不了瑞星网站,用瑞星2006(升级到18.53)、卡卡助手也(3.0.0.8)扫描不到有病毒,现将hosts和卡卡扫描出的i.exe的相关内容附在后面,请高手分手,并指出解决办法。
hosts文件内容如下:
125.91.14.230 www.kzdh.com
125.91.14.230 www.7255.com
125.91.14.230 www.7322.com
125.91.14.230 www.7939.com
125.91.14.230 www.piaoxue.com
125.91.14.230 www.feixu.net
125.91.14.230 www.6781.com
125.91.14.230 www.7b.com.cn
125.91.14.230 7b.com.cn
125.91.14.230 www.918188.com
125.91.14.230 hao.allxue.com
125.91.14.230 good.allxue.com
125.91.14.230 baby.allxue.com
125.91.14.230 www.allxue.com
125.91.14.230 about.lank.la
125.91.14.230 www.x114x.com
125.91.14.230 www.37ss.com
125.91.14.230 www.7k.cc
125.91.14.230 www.73ss.com
125.91.14.230 www.hao123.com
125.91.14.230 www.81915.com
125.91.14.230 222.88.90.22
125.91.14.230 www.9991.com
125.91.14.230 www.my123.com
125.91.14.230 www.haokan123.com
125.91.14.230 www.5566.net
125.91.14.230 www.gjj.cc
125.91.14.230 www.2345.com
125.91.14.230 dl.hao318.com
125.91.14.230 www.123wa.com
125.91.14.230 www.ku886.com
125.91.14.230 www.5icrack.com
125.91.14.230 www.jjol.cn
127.0.0.1 www.rising.com.cn
127.0.0.1 tool.ikaka.com
127.0.0.1 www.ikaka.com
127.0.0.1 update.rising.com.cn
127.0.0.1 online.rising.com.cn
127.0.0.1 up.rising.com.cn
127.0.0.1 go.rising.com.cn
127.0.0.1 it.rising.com.cn
127.0.0.1 rising.com.cn
127.0.0.1 ikaka.com
卡卡扫描i.exe进程的相关内容如下:
[i.exe]
PID = 0x484
CommandLine = "C:\program files\Rising\AntiSpyware\Ras.exe"
i.exe
0x1000000
C:\WINDOWS\system32\i.exe
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Run a DLL as an App
2002-10-07 12:00:00
ntdll.dll
0x77f50000
C:\WINDOWS\system32\ntdll.dll
5.1.2600.1217 (xpsp2.030429-2131)
Microsoft Corporation
NT Layer DLL
2003-05-01 16:57:50
kernel32.dll
0x77e40000
C:\WINDOWS\system32\kernel32.dll
5.1.2600.1560 (xpsp2_gdr.040517-1325)
Microsoft Corporation
Windows NT BASE API Client DLL
2004-06-18 02:31:30
msvcrt.dll
0x77be0000
C:\WINDOWS\system32\msvcrt.dll
7.0.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT CRT DLL
2002-10-07 12:00:00
GDI32.dll
0x7f000000
C:\WINDOWS\system32\gdi32.dll
5.1.2600.1789 (xpsp2.051228-1438)
Microsoft Corporation
GDI Client DLL
2006-01-03 06:38:18
ADVAPI32.dll
0x77da0000
C:\WINDOWS\system32\advapi32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Advanced Windows 32 Base API
2002-10-07 12:00:00
RPCRT4.dll
0x78000000
C:\WINDOWS\system32\rpcrt4.dll
5.1.2600.1361 (xpsp2.040109-1800)
Microsoft Corporation
Remote Procedure Call Runtime
2004-03-06 10:17:32
USER32.dll
0x77d10000
C:\WINDOWS\system32\user32.dll
5.1.2600.1634 (xpsp2.050301-1526)
Microsoft Corporation
Windows XP USER API Client DLL
2005-03-03 02:21:30
IMAGEHLP.dll
0x76c60000
C:\WINDOWS\system32\imagehlp.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows NT Image Helper
2002-10-07 12:00:00
IMM32.DLL
0x76300000
C:\WINDOWS\system32\imm32.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Windows XP IMM32 API Client DLL
2002-10-07 12:00:00
LPK.DLL
0x62c20000
C:\WINDOWS\system32\lpk.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Language Pack
2002-10-07 12:00:00
USP10.dll
0x72f10000
C:\WINDOWS\system32\usp10.dll
1.0409.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Uniscribe Unicode script processor
2002-10-07 12:00:00
6.sys
0x920000
C:\WINDOWS\system32\drivers\6.sys
2006-11-27 13:41:56
WSOCK32.DLL
0x71a40000
C:\WINDOWS\system32\wsock32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 32-Bit DLL
2002-10-07 12:00:00
WS2_32.dll
0x71a20000
C:\WINDOWS\system32\ws2_32.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 32-Bit DLL
2002-10-07 12:00:00
WS2HELP.dll
0x71a10000
C:\WINDOWS\system32\ws2help.dll
5.1.2600.0 (xpclient.010817-1148)
Microsoft Corporation
Windows Socket 2.0 Helper for Windows NT
2002-10-07 12:00:00
SHELL32.DLL
0x773a0000
C:\WINDOWS\system32\shell32.dll
6.00.2800.1816 (xpsp2.060316-1527)
Microsoft Corporation
Windows Shell Common Dll
2006-03-17 13:04:50
SHLWAPI.dll
0x772a0000
C:\WINDOWS\system32\SHLWAPI.DLL
6.00.2800.1740 (xpsp2.050831-1533)
Microsoft Corporation
Shell Light-weight Utility Library
2005-09-01 09:51:50
comctl32.dll
0x78090000
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.1816_x-ww_7d33ba0e\comctl32.dll
6.0 (xpsp2.060316-1527)
Microsoft Corporation
User Experience Controls Library
2006-03-16 22:04:46
comctl32.dll
0x77310000
C:\WINDOWS\system32\comctl32.dll
5.82 (xpsp1.020828-1920)
Microsoft Corporation
Common Controls Library
2002-10-07 12:00:00
uxtheme.dll
0x5adc0000
C:\WINDOWS\system32\uxtheme.dll
6.00.2800.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft UxTheme Library
2002-10-07 12:00:00
MSCTF.dll
0x74680000
C:\WINDOWS\system32\MSCTF.dll
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
MSCTF Server DLL
2002-10-07 12:00:00
vvvvv.dll
0xe40000
C:\WINDOWS\system32\vvvvv.dll
2006-11-27 13:41:56
msctfime.ime
0xea0000
C:\WINDOWS\system32\MSCTFIME.IME
5.1.2600.1106 (xpsp1.020828-1920)
Microsoft Corporation
Microsoft Text Frame Work Service IME
2002-10-07 12:00:00
ole32.dll
0x4fec0000
C:\WINDOWS\system32\ole32.dll
5.1.2600.1720 (xpsp2.050722-1526)
Microsoft Corporation
Microsoft OLE for Windows
2005-07-26 12:38:28