瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】这个病毒怎么杀啊...高手请帮帮忙...

12   2  /  2  页   跳转

【求助】这个病毒怎么杀啊...高手请帮帮忙...

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\RISING\RAV\CCENTER.EXE
d:\Rising\Rav\Ravmond.exe
d:\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
d:\Rising\Rav\RavStub.exe
d:\rising\rfw\RfwMain.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Rising\Rav\RavTask.exe
D:\Rising\Rav\Ravmon.exe
D:\Ringz Studio\Storm Downloader\StormDownloader.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\ChinaNetSn\bin\Dialterminal.exe
d:\WinRAR\WinRAR.exe
D:\Tencent\TT\TTraveler.exe
C:\WINDOWS\system32\msiexec.exe
C:\DOCUME~1\shenjw\LOCALS~1\Temp\Rar$EX15.031\HijackThis1991zww.exe

R3 - URLSearchHook: (no name) - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - (no file)
R3 - URLSearchHook: (no name) - {0A430548-60B0-4DAF-8852-8F2DED69179D} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\FLASHGET\fgiebar.dll
O3 - IE工具栏增项: (no name) - {F43BD772-ABDD-43b7-A96A-3E9E61946EC0} - (no file)
O3 - IE工具栏增项: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - d:\BitComet\BitCometBar\BitCometBar0.3.dll
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - 启动项HKLM\\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - 启动项HKLM\\Run: [RfwMain] "d:\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [StormCodec_Helper] "d:\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - 启动项HKLM\\Run: [RavTask] "d:\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [stup.exe] C:\PROGRA~1\TENCENT\Adplus\stup.exe
O4 - 启动项HKLM\\RunOnce: [Super Rabbit Winspeed] "D:\Super Rabbit\MagicSet\winspeed.exe" /autokill:98,96,88,81,78,68,61,52,48,43,35,32,31,28,23,19,18,10,6,127,126,125,124,123,122,121,120,119,118,117,116,115,114,113,112,111,110,109,108,107,106,105,104,103,102,101,100,99,97,95,94,93,92,91,90,89,87,86,85,84,83,82,80,79,77,76,75,74,73,72,71,70,69,67,66,65,64,63,62,60,59,58,57,56,55,54,53,51,50,49,47,46,45,44,42,41,40,39,38,37,36,34,33,30,29,27,26,25,24,22,21,20,17,16,15,14,13,12,11,9,8,7,5,4,3,2,1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: 腾讯QQ.lnk = D:\Tencent\QQ\QQ.exe
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - D:\Thunder Network\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - D:\Thunder Network\Thunder\getallurl.htm
O8 - IE右键菜单中的新增项目: Google 搜索(&G) - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - D:\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - D:\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - D:\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://D:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\Tencent\QQ\SendMMS.htm
O9 - 浏览器额外的按钮: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm?pid=U_liwei9981_101827 (file missing)
O9 - 浏览器额外的按钮: 词霸 - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - g:\KINGSOFT\XDICT\ieplugin.DLL (file missing)
O9 - 浏览器额外的按钮: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - 浏览器额外的按钮: 卓越 - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - g:\KINGSOFT\XDICT\ieplugin.DLL (file missing)
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\FLASHGET\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\FLASHGET\flashget.exe
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {0400AC1C-EEF0-4638-A501-31D5A0DC2002} (VTPlug3 Class) - http://61.129.90.99:1995/VTrans.cab
O16 - DPF: {1DCEAEFB-ABD9-490F-894B-E7A99103CD06} (Echat2 Class) - http://chat.showbar.cn/cab/showbar_chat.cab
O16 - DPF: {5EC7C511-CD0F-42E6-830C-1BD9882F3458} - http://www.ppstream.com/bin/pp21cn.cab
O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) - http://61.129.90.99:1995/talk.cab
O16 - DPF: {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} (photo_uploader Control) - http://upload.photo.163.com/photoup.cab
O16 - DPF: {D57A1919-CB3C-461C-8F34-A87A1CD9127E} (My99Launch Control) - http://www.99lover.com/launcher/99launch_1000.cab
O16 - DPF: {DE3496D2-AFB9-47EB-A8C2-C3B330222513} (PhotoUpload Control) - http://www.photo.163.com/PhotoUpload.cab
O16 - DPF: {F138084D-84D7-48CD-BEA8-04772457516E} (VqqSpeedDlProxy Class) - http://218.85.138.27/vqqsdl1009.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} - http://ps.itv.mop.com/dn/files/pCastCtl_1.0.0.85_20060518.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6110962A-6657-45DB-A2C5-D33D0079A779}: NameServer = 61.134.35.20
O17 - HKLM\System\CCS\Services\Tcpip\..\{ECD413A3-7AB2-4AB0-BCBB-E990111301B8}: NameServer = 61.134.1.4 218.30.19.40
O23 - NT 服务: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - NT 服务: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - NT 服务: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - NT 服务: iPodService - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - NT 服务: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\rising\rfw\rfwproxy.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - d:\Rising\Rav\Ravmond.exe

gototop
 

进入控制面版的添加删除程序中卸载,搜搜地址栏搜索(QQ搜索小助手)
重启后删除
C:\PROGRA~1\TENCENT\Adplus
gototop
 

以上是按照无邪大人的指示操作后的日志...
不知道是不是这样就行了...
还有,大人让删的C:\Program Files\HuaCi怎么也删不了,安全状态下也删不掉...这是怎么回事呢
gototop
 

C:\PROGRA~1\TENCENT\Adplus
这个已经删掉了啊....
控制面版的添加删除程序中没有搜搜地址栏搜索(QQ搜索小助手)这个程序啊...
gototop
 

这是流氓软件,你用兔子再去卸载,一定要卸载成功后,才能删除
实在不行,可以试着到安全模式卸载。
gototop
 

哪个是流氓软件啊...是搜搜地址栏搜索(QQ搜索小助手)吗
gototop
 

如果有问题,再扫份日志粘上来。
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT