瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 中了熊猫烧香之后,杀了三次毒还没好,我要疯掉了,来人帮帮忙吧
yimiao11 - 2007-1-22 12:56:00
已经用专杀杀了两次了,应该没有熊猫了,但是瑞星还不能用,开机扫描时也杀不到毒
Logfile of HijackThis v1.99.1
Scan saved at 12:39:53, on 2007-1-22
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rainbow Technologies\SPN Combo Installer\1.0.2\Server\WinNT\spnsrvnt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\92710EAC.exe
C:\program files\internet explorer\iexplore.exe
C:\Program Files\Rising\Rfw\RfwMain.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\windown2\OKADS024.exe
C:\DOCUME~1\liugy\LOCALS~1\Temp\7.exe
C:\SysA\svchost.exe
C:\SysB\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Progra~1\Eset\rund1132.exe
C:\WINDOWS\system.exe
C:\WINDOWS\winlog0n.exe
C:\Program Files\Maxthon\Maxthon.exe
F:\tool\杀毒软件\06 瑞星杀毒\HijackThis.exe

R3 - URLSearchHook: Tencent SearchHook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program

Files\TENCENT\Adplus\SSAddr.dll
F2 - REG:system.ini: UserInit=userinit.exe,rundll32.exe C:\WINDOWS\system32\winsys16_070118.dll start
O2 - BHO: Tencent Browser Helper - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\Program

Files\TENCENT\Adplus\SSAddr.dll
O2 - BHO: Info cache - {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} - C:\Documents and Settings\All

Users\Application Data\Microsoft\PCTools\pctools.dll
O2 - BHO: (no name) - {52CFADF9-6DBD-8C06-8452-21AEFBF10D93} - C:\WINDOWS\system32

\ftmsdtcu.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1

\FLASHGET\jccatch.dll
O2 - BHO: Shell name - {D682D42E-BE2C-4758-AB18-926D2E7553B8} - C:\WINDOWS\system32

\vmmreg32.dll (file missing)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1

\FLASHGET\fgiebar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program

Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32

\KakaTool.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef

/Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE

/Preload
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [OKADS024.exe] C:\WINDOWS\windown2\OKADS024.exe Auto
O4 - HKLM\..\Run: [RavHelp] C:\DOCUME~1\liugy\LOCALS~1\Temp\7.exe
O4 - HKLM\..\Run: [upxdn] C:\DOCUME~1\liugy\LOCALS~1\Temp\1.exe
O4 - HKLM\..\Run: [cmdbcs] C:\WINDOWS\cmdbcs.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [bgswitch] C:\WINDOWS\system32\bgswitch.exe
O4 - HKCU\..\Run: [RealUpdate] C:\WINDOWS\system32\update/Update.exe
O4 - HKCU\..\Run: [ravtask] C:\Progra~1\Eset\rund1132.exe
O4 - HKCU\..\Run: [zcweehuv0] C:\WINDOWS\system.exe
O4 - HKCU\..\Run: [uj7h2wwg] C:\WINDOWS\iexpl0re.exe
O4 - HKCU\..\Run: [9uxrj] C:\WINDOWS\winlog0n.exe
O4 - HKCU\..\Run: [svc] C:\DOCUME~1\liugy\LOCALS~1\Temp\logsony.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\qq\SendMMS.htm
O8 - Extra context menu item: 转换为 Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0

\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program

Files\Tencent\qq\QQ.EXE (file missing)
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program

Files\Tencent\qq\QQ.EXE (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1

\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1

\FLASHGET\flashget.exe
O11 - Options group: [TBH] 中文搜搜
O14 - IERESET.INF: START_PAGE_URL=http://www.tomatolei.com
O15 - Trusted Zone: http://www.icbc.com.cn
O16 - DPF: {F2EB8999-766E-4BF6-AAAD-188D398C0D0B} (PBActiveX40 Control) -

http://szdl.cmbchina.com/download/PB/pb50.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1

\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1

\MSGRAP~1.DLL
O20 - AppInit_DLLs: 235780M.BMP
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common

Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - D:\Program Files\MATLAB704

\webserver\bin\win32\matlabserver.exe
O23 - Service: Network Logon (NetWorkLogons) - Unknown owner - rundll32.exe (file missing)
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program

files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. -

C:\Program Files\Rising\Rfw\rfwsrv.exe
O23 - Service: Security Info (secinfo) - Unknown owner - C:\WINDOWS\security.exe
O23 - Service: SuperProServer - Unknown owner - C:\Program Files\Rainbow Technologies\SPN Combo

Installer\1.0.2\Server\WinNT\spnsrvnt.exe

1
查看完整版本: 中了熊猫烧香之后,杀了三次毒还没好,我要疯掉了,来人帮帮忙吧