瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 在线请教高手!_desktop病毒怎么杀?

12   1  /  2  页   跳转

在线请教高手!_desktop病毒怎么杀?

在线请教高手!_desktop病毒怎么杀?

我电脑不知道什么时候中了病毒,每个文件夹下生成了文本文件_desktop.ini物理删除无效,请高手指点!!!
Logfile of HijackThis v1.99.1
Scan saved at 19:15:48, on 2006-8-9
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe
C:\Program Files\Rising\Rav\RavService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\WINLOGON.EXE
C:\Program Files\Rising\Rav\RavTray.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\system32\rundll32.exe
F:\BitSpirit\BitSpirit.exe
C:\Program Files\Rising\Rav\Rav.exe
C:\DOCUME~1\cwk\LOCALS~1\Temp\Win20AE.exe
C:\DOCUME~1\cwk\LOCALS~1\Temp\Win20AF.exe
C:\Documents and Settings\cwk\桌面\ha_hijackthis_1991\HijackThis.exe

F2 - REG:system.ini: Shell=Explorer.exe 1
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v9.dll
O2 - BHO: NetXfer - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - e:\Program Files\NetXfer\NXIEHelper.dll
O2 - BHO: BHelper Class - {F2E37336-BFDB-409B-8D0E-6F013C438B20} - C:\WINDOWS\system32\caboa1c1.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [RavTray] "C:\Program Files\Rising\Rav\RavTray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [MSConfig] ; C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
O4 - HKLM\..\RunServices: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: IE-Bar.lnk = C:\Program Files\Common Files\IE-Bar\iebar.exe
O4 - Global Startup: 服务管理器.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - F:\BitSpirit\bsurl.htm
O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.co.kr/neo.fld/NowStarter.cab
O16 - DPF: {0A43613C-9F79-4E96-BEED-799045B3B753} (YGCWBG Control) - file://C:\Inetpub\wwwroot\YGBGClt20.inf
O16 - DPF: {20C2C286-BDE8-441B-B73D-AFA22D914DA5} (PowerList Control) - http://www.ppstream.com/bin/powerplayer.cab
O16 - DPF: {228CAD06-0A4A-11D5-B58B-0080C8D36FF1} (远光财务2.0-系统管理) - http://10.229.234.172/YGXTClt20.inf
O16 - DPF: {29AE8351-3844-11D2-8278-001088016936} (远光财务20-工资核算) - http://10.229.234.172/YGGZClt20.inf
O16 - DPF: {498BC605-8894-11D2-A1C0-0888C84BCE44} (远光财务20 -- 文件信息) - http://10.229.234.172/YGWJClt20.inf
O16 - DPF: {646976A9-28C4-11D2-8C62-0080C843C179} (远光财务20-帐务处理) - http://10.229.234.204/YGZWClt20.inf
O16 - DPF: {6AE02E1C-8859-4F57-9097-5A55A56A4CAF} - http://images.5460.net/toolbar/webinstall/5460.cab
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} (MediaGatewayX) - http://static.zangocash.com/cab/Seekmo/ie/bridge-c15.cab
O16 - DPF: {C1AF8F7B-5E5E-11D1-AE9E-44455354000F} (远光财务2.0--集团报表2.1) - file://C:\Inetpub\wwwroot\YGBBCLT20.inf
O16 - DPF: {E51C4AE5-2C78-11D2-A159-0080C843C4B3} (远光财务20-固定资产) - http://10.229.234.172/YGGDClt20.inf
O17 - HKLM\System\CCS\Services\Tcpip\..\{6ACBF356-D717-4A66-8924-D89925C397B3}: NameServer = 10.229.234.2
O20 - AppInit_DLLs: KB215366M.LOG
O21 - SSODL: DelayRun - {5A6F2F95-3191-433B-8533-EB0B596A7BAC} - C:\WINDOWS\system32\cabda1c0.dll
O23 - Service: Pigeon_Server (PigeonServer) - Unknown owner - C:\Program Files\HgzServer\G_Server2.03.exe (file missing)
O23 - Service: RavService - Unknown owner - C:\Program Files\Rising\Rav\RavService.exe" /service (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe

这是我的扫描日志,谢谢
最后编辑2006-08-11 10:22:40
分享到:
gototop
 

C:\WINDOWS\WINLOGON.EXE用专杀K掉
修复
O2 - BHO: BHelper Class - {F2E37336-BFDB-409B-8D0E-6F013C438B20} - C:\WINDOWS\system32\caboa1c1.dll
O20 - AppInit_DLLs: KB215366M.LOG
O21 - SSODL: DelayRun - {5A6F2F95-3191-433B-8533-EB0B596A7BAC} - C:\WINDOWS\system32\cabda1c0.dll
O23 - Service: Pigeon_Server (PigeonServer) - Unknown owner - C:\Program Files\HgzServer\G_Server2.03.exe (file missing)
O23 - Service: RavService - Unknown owner - C:\Program Files\Rising\Rav\RavService.exe" /service (file missing)
删除
C:\WINDOWS\system32\caboa1c1.dll
C:\WINDOWS\KB215366M.LOG
gototop
 

KB215366M.log删不掉,还有那个专杀在哪里下载呀,刚又扫描了一遍
Logfile of HijackThis v1.99.1
Scan saved at 10:03:58, on 2006-8-10
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
d:\PROGRA~1\YGCWWI~1\YGZWSV~1.EXE
d:\PROGRA~1\YGCWWI~1\YGXTSV~1.EXE
C:\WINDOWS\system32\conime.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\cwk\桌面\ha_hijackthis_1991\HijackThis.exe

F2 - REG:system.ini: Shell=Explorer.exe 1
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v9.dll
O2 - BHO: NetXfer - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - e:\Program Files\NetXfer\NXIEHelper.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [RavTray] "C:\Program Files\Rising\Rav\RavTray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [MSConfig] ; C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunServices: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: 服务管理器.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - F:\BitSpirit\bsurl.htm
O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.co.kr/neo.fld/NowStarter.cab
O16 - DPF: {0A43613C-9F79-4E96-BEED-799045B3B753} (YGCWBG Control) - file://C:\Inetpub\wwwroot\YGBGClt20.inf
O16 - DPF: {20C2C286-BDE8-441B-B73D-AFA22D914DA5} (PowerList Control) - http://www.ppstream.com/bin/powerplayer.cab
O16 - DPF: {228CAD06-0A4A-11D5-B58B-0080C8D36FF1} (远光财务2.0-系统管理) - http://10.229.234.172/YGXTClt20.inf
O16 - DPF: {29AE8351-3844-11D2-8278-001088016936} (远光财务20-工资核算) - http://10.229.234.172/YGGZClt20.inf
O16 - DPF: {498BC605-8894-11D2-A1C0-0888C84BCE44} (远光财务20 -- 文件信息) - http://10.229.234.172/YGWJClt20.inf
O16 - DPF: {646976A9-28C4-11D2-8C62-0080C843C179} (远光财务20-帐务处理) - http://10.229.234.204/YGZWClt20.inf
O16 - DPF: {6AE02E1C-8859-4F57-9097-5A55A56A4CAF} - http://images.5460.net/toolbar/webinstall/5460.cab
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} (MediaGatewayX) - http://static.zangocash.com/cab/Seekmo/ie/bridge-c15.cab
O16 - DPF: {C1AF8F7B-5E5E-11D1-AE9E-44455354000F} (远光财务2.0--集团报表2.1) - file://C:\Inetpub\wwwroot\YGBBCLT20.inf
O16 - DPF: {E51C4AE5-2C78-11D2-A159-0080C843C4B3} (远光财务20-固定资产) - http://10.229.234.172/YGGDClt20.inf
O17 - HKLM\System\CCS\Services\Tcpip\..\{6ACBF356-D717-4A66-8924-D89925C397B3}: NameServer = 10.229.234.2
O23 - Service: Pigeon_Server (PigeonServer) - Unknown owner - C:\Program Files\HgzServer\G_Server2.03.exe (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe

gototop
 

参考资料:"新欢乐时光"病毒分析及删除
http://www.pcav.cn/Article/aqzx/200608/6473.html
gototop
 

请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改。谢谢...
gototop
 

请修复:
F2 - REG:system.ini: Shell=Explorer.exe 1
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
gototop
 

专杀貌似在置顶有`
gototop
 

你可以来这个网站上下载超级兔子 然后用清理王 上网精灵 IE修复专家 来解决 http://www.pctutu.com/
gototop
 

O20 - AppInit_DLLs: KB215366M.LOG
gototop
 

O23 - Service: Pigeon_Server (PigeonServer) - Unknown owner - C:\Program Files\HgzServer\G_Server2
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT