瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求教大家:看看我的桌面是怎么了?

12   2  /  2  页   跳转

求教大家:看看我的桌面是怎么了?

自启动项
HKEY_LOCAL_MACHINE Software\Microsoft\Windows\Currentversion\Run
IMJPMIG8.1 = ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
PHIME2002ASync = C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
SoundMan = soundman.exe
Super Rabbit SRRestore = D:\MAGICSET\SRRest.exe /autosave
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
helper.dll = C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
CnsMin = Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32
DAEMON Tools-1033 = "C:\Program Files\D-Tools\daemon.exe" -lang 1033
NMGameX_AutoRun = C:\WINDOWS\System32\Rundll32.exe NMGameX.dll,LiveProcess /aa
RavTimer = D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
RavMon = D:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
Fast Start = C:\WINDOWS\system32\svcnt.exe home

HKEY_CURRENT_USER Software\Microsoft\Windows\Currentversion\Run
ctfmon.exe = C:\WINDOWS\System32\ctfmon.exe
NVIEW = rundll32.exe nview.dll,nViewLoadHook
Fast Start = C:\WINDOWS\system32\svcnt.exe home

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
shell32.dll = C:\WINDOWS\system32\svcnt.exe home
C:\WINDOWS\DOWNLO~1\CnsHook.dll= C:\WINDOWS\system32\svcnt.exe home

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
PostBootReminder = %SystemRoot%\system32\SHELL32.dll
CDBurn = %SystemRoot%\system32\SHELL32.dll
WebCheck = %SystemRoot%\System32\webcheck.dll
SysTray = C:\WINDOWS\System32\stobject.dll

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
%SystemRoot%\System32\browseui.dll= Browseui 预加载程序
%SystemRoot%\System32\browseui.dll= 组件类别缓存程序
%SystemRoot%\System32\browseui.dll= OLE Module


SYSTEM.INI BOOT SHELL explorer.exe

gototop
 

其他相关项
HKEY_CURRENT_USER Software\Microsoft\Internet Explorer\Main start page ----> res://shdocsv.dll/blank.htm
HKEY_LOCAL_MACHINE Software\Microsoft\internet explorer\search searchassistant ----> res://shdocsv.dll/asst.htm
HKEY_LOCAL_MACHINE Software\Microsoft\Windows NT\CurrentVersion\Winlogon DefaultUserName ----> lee
HKEY_LOCAL_MACHINE Software\Microsoft\Windows NT\CurrentVersion\Winlogon AltDefaultUserName ----> lee
HKEY_LOCAL_MACHINE Software\Microsoft\Windows NT\CurrentVersion\Winlogon Userinit ----> userinit.exe


WININIT.INI
[rename]
C:\WINDOWS\System32\Image.exe=C:\WINDOWS\System32\EtImg.ocx

Hosts
# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

gototop
 

进程列表

[System Process]
System
C:\Program Files\D-Tools\daemon.exe (Made by DAEMON'S HOME)
C:\WINDOWS\system32\svcnt.exe

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
D:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Rundll32.exe
C:\WINDOWS\soundman.exe
C:\WINDOWS\system32\rundll32.exe
D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
D:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\nvsvc32.exe
D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
D:\Tencent\QQ.exe
D:\Tencent\TIMPlatform.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\download\RavDetect.exe
gototop
 

1、用杀毒软件杀一下毒,估计是病毒和恶意程序.2、或者用超级兔子修改墙纸,然后用它清理一下注册表.3、或者查看墙纸的文件名将他搜索出来看在什么目录下,将之删除
gototop
 

用最新的瑞星查不到病毒  用超级兔子改也没有用  我的墙纸被这个软件覆盖掉了
gototop
 

请用hijackthis扫描完整log
gototop
 

既然知道该墙纸被软件覆盖那何不试试:1、卸载该软件,如不能卸载可试用超级兔子或优化大师里的高级卸载工具来卸.2、如还不行看能不直接删除该文件夹,如不能可用优化大师里的文件夹粉碎机,或到命令提示符下用dos命令删除
gototop
 

估计是个恶意软件。警告你,说你的电脑有间谍软件或广告软件了,要你清理,而且给出了相关下载清理软件的地址。可以杀毒,另外关闭messeger看看管用不。在运行里输入net stop messenger即可。
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT