瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 这些病毒要怎么杀
风铃草草 - 2007-9-24 17:06:00
以下是日志:
Logfile of HijackThis v1.99.1
Scan saved at 16:20:52, on 2007-9-24
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\Dell\OpenManage\dataeng\bin\dcevt32.exe
C:\Program Files\Dell\OpenManage\dataeng\bin\dcstor32.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\llssrv.exe
c:\Program Files\MSDE\MSSQL$RAVN\Binn\sqlservr.exe
C:\Program Files\Dell\OpenManage\oma\bin\omsad32.exe
C:\PROGRAM FILES\RISING\RAV\RavAgent.exe
C:\PROGRAM FILES\RISING\RAV\RavAlert.exe
C:\Program Files\Rising\Rav\RavService.exe
C:\PROGRAM FILES\RISING\RAV\RavUpdate.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Rising\Rav\RNReport.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Dell\OpenManage\iws\bin\win32\omaws32.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\system32\msdtc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\jj4\jjsvr4.exe
C:\Program Files\AntiARP Stand-alone Edition\AntiArp.exe
C:\Program Files\Rising\AntiSpyware\runiep.exe
C:\Program Files\Rising\Rav\RavTray.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINNT\system32\taskmgr.exe
C:\WINNT\explorer.exe
E:\病毒专杀工具\HijackThis\HijackThis.exe
C:\WINNT\system32\k11906219927.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe
O2 - BHO: (no name) - {C2626E66-D21B-E628-C1DF-1DACCFA36ED2} - C:\Program Files\Common Files\fjOs0r.dll (file missing)
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WangWang] "C:\Program Files\Alisoft\WangWang\WangWang.EXE"
O4 - HKLM\..\Run: [AntiARPStandalone] C:\Program Files\AntiARP Stand-alone Edition\AntiArp.exe
O4 - HKLM\..\Run: [runeip] "C:\Program Files\Rising\AntiSpyware\runiep.exe" /startup
O4 - HKLM\..\Run: [RavTray] "C:\Program Files\Rising\Rav\RavTray.exe"
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [DiskMan32] C:\WINNT\DiskMan32.exe
O4 - HKLM\..\Run: [WinSysM] C:\WINNT\IGM.exe
O4 - HKLM\..\Run: [Kvsc3] C:\WINNT\Kvsc3.exe
O4 - HKLM\..\Run: [mppds] C:\WINNT\mppds.exe
O4 - HKLM\..\Run: [MsIMMs32] C:\WINNT\MsIMMs32.exe
O4 - HKLM\..\Run: [AVPSrv] C:\WINNT\AVPSrv.exe
O4 - HKLM\..\Run: [cmdbcs] C:\WINNT\cmdbcs.exe
O4 - HKLM\..\Run: [upxdnd] C:\WINNT\upxdnd.exe
O4 - HKCU\..\Run: [pyjj] C:\Program Files\jj4\jjsvr4.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [KASStart] "E:\病毒专杀工具\流氓软件清理工具绿色版合集\金山毒霸系统清理专家\KASStart.EXE" -Startup
O4 - Startup: 腾讯QQ.lnk = D:\Program Files\Tencent\QQ\QQ.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {051A0549-A9CA-400C-87D6-6125D80F11F2} - http://61.154.11.148/jy/script/ScdReportP.ocx
O16 - DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} (MMCPlayer Class) - http://p3p.sogou.com/MMCShell.cab
O16 - DPF: {2375BEE5-F175-4F1C-81EC-8E4E2E72E2DD} (PhotoDraw Class) - http://qz-photo.qq.com/qzone_v4/QzoneMediaTools.cab
O16 - DPF: {3F166327-8030-4881-8BD2-EA25350E574A} ({3F166327-8030-4881-8BD2-EA25350E574A}) - http://www.cnisn.com.cn:8091/TSG_Report/comm/cellweb5.cab
O16 - DPF: {CECB54B6-2334-460A-9973-3C72029A31FE} - http://61.154.11.148/jy/script/VGImageProj.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{0E55D54A-A800-406E-98EE-0A75DE32957C}: NameServer = 202.101.98.55,202.101.107.55
O17 - HKLM\System\CS1\Services\Tcpip\..\{0E55D54A-A800-406E-98EE-0A75DE32957C}: NameServer = 202.101.98.55,202.101.107.55
O17 - HKLM\System\CS2\Services\Tcpip\..\{0E55D54A-A800-406E-98EE-0A75DE32957C}: NameServer = 202.101.98.55,202.101.107.55
O23 - Service: Systems Management Event Manager (dcevt32) - Dell Inc. - C:\Program Files\Dell\OpenManage\dataeng\bin\dcevt32.exe
O23 - Service: Systems Management Data Manager (dcstor32) - Dell Inc. - C:\Program Files\Dell\OpenManage\dataeng\bin\dcstor32.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: OM Common Services (omsad) - Dell Inc. - C:\Program Files\Dell\OpenManage\oma\bin\omsad32.exe
O23 - Service: Rav Net Agent (RavAgent) - 北京瑞星科技股份有限公司 - C:\PROGRAM FILES\RISING\RAV\RavAgent.exe
O23 - Service: Rav Net Alert (RavAlert) - 瑞星科技股份发展有限公司 - C:\PROGRAM FILES\RISING\RAV\RavAlert.exe
O23 - Service: RavService - Unknown owner - C:\Program Files\Rising\Rav\RavService.exe" /service (file missing)
O23 - Service: RavUpdate - Unknown owner - C:\PROGRAM FILES\RISING\RAV\RavUpdate.exe" (file missing)
O23 - Service: RNReport - 瑞星科技股份发展有限公司 - C:\Program Files\Rising\Rav\RNReport.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Secure Port Server (Server Administrator) - Unknown owner - %SystemDrive%\Program Files\Dell\OpenManage\iws\bin\win32\omaws32.exe (file missing)



[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; Mozilla/4.0(Compatible Mozilla/4.0(Compatible-EmbeddedWB 14.58 http://bsalsa.com/ EmbeddedWB- 14.58  from: http://bsalsa.com/ ; Mozilla/4.0(Compatible RogueCleanerEmbeddedWB- 14.58  from: http://bsalsa.com/ )
1
查看完整版本: 这些病毒要怎么杀