瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我是你们的正版用户,帮忙啊,我关不了机

12   1  /  2  页   跳转

我是你们的正版用户,帮忙啊,我关不了机

我是你们的正版用户,帮忙啊,我关不了机

我是你们的正版用户,帮忙啊,不能正常关机,瑞星监控不停的监控到这个病毒 Trojan.PSW.LMir.atc  .我该怎么办啊.这是我的LOG,求你们帮忙啊.
这是我的LOG
Logfile of HijackThis v1.99.1
Scan saved at 16:52:50, on 2006-09-01
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\System32\svchost.exe
c:\windows\system32\inetsrv\csrss.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Rising\hijackthis\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Sun Java2 - {C61A70F3-505E-4B90-916F-627A8706B4BC} - c:\WINDOWS\system32\COMBoHEvent.dll
O3 - Toolbar: 宏网超级搜霸 - {2E7D3330-EB94-4518-B0FE-E05379A5C1DA} - C:\PROGRA~1\234567\ZGHWBAR.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O16 - DPF: {045ADB92-9635-45CE-B25B-F19F825B0E39} (MSTPlayerInstaller Control) - http://211.151.89.101/MSTPlayer/CHS/MSTPlayerInstaller.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1122554443184
O16 - DPF: {88734439-46D0-42C0-A13F-7E881EE550CF} (Filetran Control) - http://www.bluesky.cn/download/filetran.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{64937428-B9E4-4194-826C-206B66238EF7}: NameServer = 202.103.96.112,202.103.96.68
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\System32\mbprot.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe

最后编辑2006-09-04 08:58:55
分享到:
gototop
 

题外话。。。拔电源 =。=
gototop
 

还可以按住机箱电源键四秒钟...................
gototop
 

善意提醒 这些斑竹能杀毒也能防毒 你在他的坛子里灌水 小心你的机器也要拔电源或按住机箱电源键四秒钟...................
gototop
 

还是不能正常关机啊
gototop
 

帮忙啊~~,高手们帮我看看啊,好麻烦的啊。。
gototop
 

关闭IE窗口~
修复F2,02,03项~
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\System32\mbprot.dll (file missing)

另,病毒文件名和路径是?
gototop
 

我修复了,还是不行啊.以前一直是可以很正常关机的,昨天电脑中了病毒,然后就就不能关机了,在"开始"按钮中选"关闭计算机"然后弹出对话框,点"关闭"没有一点反应,点"重新启动"也没反应啊.
这是监控的病毒.
Trojan.PSW.LMir.atc删除成功2006-09-01 15:04文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 15:04文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin149.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 15:05文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin14B.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 15:06文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 15:10文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 15:10文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin14C.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 15:10文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 15:10文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin151.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 15:12文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 15:12文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin152.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 15:12文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 15:12文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin154.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 15:13文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 15:13文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin155.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 15:14文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 15:14文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin157.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 15:15文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin158.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 15:16文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.ZhengTu.hz删除成功2006-09-01 15:45文件监控C:\WINDOWS\System32ztdll.dll
Trojan.PSW.Lmir.lby删除成功2006-09-01 15:47文件监控C:\WINDOWS\System32Ravdm.exe>>FSG2.0
gototop
 

还有
病毒名称处理结果发现日期扫描方式路径文件
Trojan.PSW.LMir.atc删除成功2006-09-01 14:33文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin122.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:34文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:34文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin123.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:35文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:35文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:35文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin124.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:36文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin125.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:37文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:37文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin127.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:38文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:38文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:38文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin128.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:39文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:39文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin129.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:40文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:40文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin12B.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:41文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin12C.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:42文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:42文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:42文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin12E.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:43文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin12F.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:44文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:44文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin130.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:45文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:45文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:45文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin131.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:46文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:46文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin132.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:47文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:47文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin134.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:49文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:49文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin136.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:49文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin138.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:50文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:50文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:50文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin139.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:52文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:52文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin13C.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:53文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:53文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin13D.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:54文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:54文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin13E.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:55文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:55文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin13F.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:56文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:56文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin140.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:57文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:57文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin141.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:58文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:58文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 14:58文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin142.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 14:59文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin143.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 15:00文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 15:00文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin144.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 15:01文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 15:01文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 15:01文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin145.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 15:02文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin146.exe
Trojan.PSW.LMir.atc删除成功2006-09-01 15:03文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMNc[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 15:03文件监控C:\Documents and Settings\FengZheng\Local Settings\Temporary Internet Files\Content.IE5\107AYCR1c[1].gif
Trojan.PSW.LMir.atc删除成功2006-09-01 15:03文件监控C:\DOCUME~1\FENGZH~1\LOCALS~1\TempWin148.exe
gototop
 

求你们帮忙看一下啊,谢谢,
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT