12   1  /  2  页   跳转

【求助】急!!! 这个是不是病毒!!!

【求助】急!!! 这个是不是病毒!!!

用终截者扫出来的!!!


#O4  危险    自启动:[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks\[Empty]]-c:\windows\system32\jhlog1.dll

可是我找了根本没有这个啊!!!


麻烦帮看下,奇怪为什么我每次查分数都不同?!!!

#T0 SecAnalyst 分析报告 版本:0, 4, 0, 47
#操作系统 : Microsoft Windows XP Professional Service Pack 2 (Build 2600) (CHS)
#系统目录 : C:\WINDOWS\system32
#浏览器  : Internet Explorer C:\WINDOWS\system32
#生成时间 : 2006-8-13 17:25:6

#T2 请把报告贴到安全救援中心bbs.s-sos.net,我们的专家会为你做出诊断,另外,报告中的安全风险值仅仅表示可疑程度。
#Q1 (请在此输入你的电脑遇到的问题和异常情况..)


#O4  危险    自启动:[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks\[Empty]]-c:\windows\system32\jhlog1.dll
#O4  警告    自启动:[hkey_local_machine\software\microsoft\windows\currentversion\shell extensions\approved\Shell Extension for CDRW]-d:\program files\ahead\incd\incdshx.dll
#O4  警告    自启动:[hkey_local_machine\software\microsoft\windows\currentversion\shell extensions\approved\RISING]-c:\windows\system32\ravext.dll
#O4  警告    自启动:[hkey_local_machine\software\microsoft\windows\currentversion\shell extensions\approved\Shell Extensions for RealOne Player]-c:\program files\real\realone player\rpshell.dll
#O4  警告    自启动:[hkey_local_machine\software\microsoft\windows\currentversion\runonce\RavStub]-"d:\program files\rising\rav\ravstub.exe" /runonce
#O4  警告    自启动:[hkey_local_machine\software\microsoft\windows\currentversion\run\BigDogPath]-c:\windows\vm_sti.exe usb pc camera 301p
#O4  低风险  自启动:[hkey_local_machine\software\microsoft\windows\currentversion\shell extensions\approved\WinRAR shell extension]-c:\program files\winrar\rarext.dll
#O4  低风险  自启动:[hkey_local_machine\software\microsoft\windows\currentversion\run\RfwMain]-"d:\program files\rising\rfw\rfwmain.exe" -startup
#O4  低风险  自启动:[hkey_local_machine\software\microsoft\windows\currentversion\shell extensions\approved\PowerConverter]-d:\program files\power mp3 wma converter 2006\shellext.dll
#O4  低风险  自启动:[hkey_local_machine\software\microsoft\windows\currentversion\shell extensions\approved\Display Panning CPL Extension]-deskpan.dll [file not found]
#O4  低风险  自启动:[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks\[Empty]]-c:\windows\system32\z.dll [file not found]
#O4  低风险  自启动:[hkey_local_machine\software\microsoft\windows\currentversion\run\Adobe Photo Downloader]-"d:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe" [file not found]
#O4  低风险  自启动:[hkey_local_machine\software\microsoft\windows\currentversion\shell extensions\approved\nView Desktop Context Menu]-c:\windows\system32\nvshell.dll
#O4  低风险  自启动:[hkey_local_machine\software\microsoft\windows\currentversion\shell extensions\approved\Desktop Explorer Menu]-c:\windows\system32\nvshell.dll
#O4  低风险  自启动:[hkey_local_machine\software\microsoft\windows\currentversion\shell extensions\approved\Desktop Explorer]-c:\windows\system32\nvshell.dll
#O4  低风险  自启动:[hkey_local_machine\software\microsoft\windows\currentversion\run\InCD]-d:\program files\ahead\incd\incd.exe


#D0  低风险  驱动: C:\WINDOWS\system32\Drivers\xBlock3.sys
#D0  低风险  驱动: D:\Program Files\Rising\Rav\ExpScan.sys
#D0  低风险  驱动: D:\Program Files\Rising\Rav\HOOKAPI.SYS
#D0  低风险  驱动: D:\Program Files\Rising\Rav\hookbase.sys
#D0  低风险  驱动: d:\program files\rising\rfw\RfwBase.sys
#D0  低风险  驱动: C:\WINDOWS\system32\Drivers\xFileMgr.sys
#D0  低风险  驱动: C:\WINDOWS\System32\Drivers\sunkfilt.sys
#D0  低风险  驱动: C:\WINDOWS\system32\Drivers\xProc.sys
#D0  低风险  驱动: C:\WINDOWS\system32\drivers\Oreans.sys
#D0  低风险  驱动: C:\WINDOWS\System32\Drivers\InCDfs.SYS
#D0  低风险  驱动: C:\WINDOWS\System32\Drivers\InCDrec.SYS
#D0  低风险  驱动: C:\WINDOWS\System32\DRIVERS\InCDPass.sys
#D0  低风险  驱动: C:\WINDOWS\System32\Drivers\incdrm.SYS

#R1  警告    SearchAssistant: about:blank - HKLM\Software\Microsoft\Internet Explorer\Main, SearchAssistant
#R1  警告    SearchAssistant: about:blank - HKCU\Software\Microsoft\Internet Explorer\Main, SearchAssistant

#O3  低风险  Toolbar: {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - NetXfer - D:\Program Files\Xi\NetXfer\NXToolBar.dll

#M0  危险    DLL:C:\WINDOWS\system32\jhlog1.dll
#M0  危险    DLL:C:\WINDOWS\system32\NVRSZHC.DLL
#M0  警告    DLL:D:\Program Files\Ahead\InCD\incdshx.dll
#M0  低风险  DLL:D:\Program Files\Rising\Rav\RSCOMMON.DLL
#M0  低风险  DLL:C:\WINDOWS\system32\nvshell.dll

#P0  危险    进程:d:\program files\rising\rfw\rfwsrv.exe
#P0  危险    进程:d:\program files\rising\rav\ravmond.exe
#P0  警告    进程:d:\program files\rising\rav\ravstub.exe
#P0  警告    进程:c:\windows\vm_sti.exe
#P0  低风险  进程:d:\program files\ahead\incd\incdsrv.exe
#P0  低风险  进程:d:\program files\rising\rfw\rfwmain.exe
#P0  低风险  进程:d:\program files\ahead\incd\incd.exe

#S0  危险    NT 服务: RfwService - 启动方式: 自动 - 当前状态: 已启动 - d:\program files\rising\rfw\rfwsrv.exe
#S0  危险    NT 服务: RsRavMon - 启动方式: 自动 - 当前状态: 已启动 - "D:\Program Files\Rising\Rav\Ravmond.exe"
#S0  警告    NT 服务: Adobe LM Service - 启动方式: 手动 - 当前状态: 已停止 - "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"
#S0  低风险  NT 服务: InCDsrv - 启动方式: 自动 - 当前状态: 已启动 - D:\Program Files\Ahead\InCD\InCDsrv.exe
#S0  低风险  NT 服务: InCDsrvR - 启动方式: 自动 - 当前状态: 已停止 - C:\Program Files\Ahead\InCD\InCDsrv.exe -r
#S0  低风险  NT 服务: HidServ - ServiceDll - C:\WINDOWS\System32\hidserv.dll - [file not found]
#S0  低风险  NT 服务: UMWdf - 启动方式: 自动 - 当前状态: 已停止 -  - [file not found]


#O18 低风险  Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL

您的电脑整体安全风险为高(113分),可能已经被破坏,请尽快处理!
最后编辑2006-08-13 20:52:51
分享到:
gototop
 

hijackthis 贴上来
http://forum.ikaka.com/topic.asp?board=67&artid=5188931 6楼
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 20:00:00, on 2006-8-13
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\Rising\Rav\Ravmond.exe
d:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Rising\Rav\RavTask.exe
D:\Program Files\Rising\Rfw\rfwmain.exe
C:\WINDOWS\VM_STI.EXE
D:\Program Files\Rising\Rav\Ravmon.exe
D:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\fscagent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\软件\ha_hijackthis_1991\HijackThis.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=userinit.exe,
O3 - Toolbar: NetXfer - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - D:\Program Files\Xi\NetXfer\NXToolBar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [RavTask] "D:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "D:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE USB PC Camera 301P
O4 - HKLM\..\Run: [InCD] D:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "D:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\RunOnce: [RavStub] "D:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: 腾讯QQ.lnk = D:\Program Files\Tencent\QQ\QQ.exe
O4 - Global Startup: microsoft office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &使用迅雷下载 - D:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\cdnns.dll' missing
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {6A2E758A-028B-46BB-A11D-0608AB5A4ED3} (DaumBGMCtrl Class) - http://listen.daum.net/52st/bgmplayer/Daum52stBGMPlayer.cab
O16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} (Cdmcco Class) - http://cafeimg.hanmail.net/cab9_1/dmcc2.cab?Version=1,0,0,10
O16 - DPF: {9AEBAA67-8B4D-4884-9EB7-8C6BEA20CE5C} (FileManager Control) - http://www.jype.com/cab/NetEditor.cab
O16 - DPF: {CACFD501-1157-442B-9D0E-3E0BC34FC4A9} (CYTWInst Class) - http://tw.cyworld.com/common/activex/cytwinst.cab
O16 - DPF: {EDEDED2E-A0A6-4085-BC52-A95255A96DBD} (CyImgChinaCtl Class) - http://fs1.cyworld.com.cn/common/activex/CyImgChina.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1EE27B82-2CAC-4332-8273-91FA1E114969}: NameServer = 202.101.172.46 202.101.172.47
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - D:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\Program Files\Rising\Rav\Ravmond.exe
gototop
 

请修复:
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=userinit.exe,
O3 - Toolbar: NetXfer - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - D:\Program Files\Xi\NetXfer\NXToolBar.dll
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
删除:
D:\Program Files\Xi\NetXfer\NXToolBar.dll
gototop
 

谢谢,不过请问怎么修复呢?

gototop
 





麻烦帮我看看这些进程正常吗?

附件附件:

下载次数:263
文件类型:image/pjpeg
文件大小:
上传时间:2006-8-13 20:19:41
描述:



gototop
 





麻烦帮我看看这些进程正常吗?

附件附件:

下载次数:244
文件类型:image/pjpeg
文件大小:
上传时间:2006-8-13 20:19:51
描述:



gototop
 

用你扫日志的软件在要修复的选项前打勾,按修复...
gototop
 

修复
R3 - Default URLSearchHook is missing
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)

另外: NXToolBar.dll是影音传送带没必要修复和删除
gototop
 

恩,楼上的说得对,我看错了...
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT