瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我的电脑有个spooler.exe文件,奇占CPU!!几乎打不开网页!

12   1  /  2  页   跳转

我的电脑有个spooler.exe文件,奇占CPU!!几乎打不开网页!

我的电脑有个spooler.exe文件,奇占CPU!!几乎打不开网页!

我的是瑞星正版!并下载了最新版,都无法将他删除!我该怎么办??
最后编辑2005-09-07 12:02:45
分享到:
gototop
 

要在任务管理器不停地结束spooler.exe的进程,才可以打开网页!!惨!!!求救!!!
gototop
 

贴上HijackThis1.99.1版的日志吧,没有去找一下,网上很多!卡卡论坛也有的
gototop
 

我们公司也出现这个问题.到现在瑞星还杀不掉这个东西.也检测不到..诺顿可以检测到.可以隔离.不能杀..这种病毒会出现倒计时关机和经常死机.有时候打开一些文档也会出错..
请问这个病毒该怎么解决?
谢谢
gototop
 

引用:
【ChinaFree的贴子】我们公司也出现这个问题.到现在瑞星还杀不掉这个东西.也检测不到..诺顿可以检测到.可以隔离.不能杀..这种病毒会出现倒计时关机和经常死机.有时候打开一些文档也会出错..
请问这个病毒该怎么解决?
谢谢
...........................

请把诺顿杀毒软件的日志贴上来。
请下载并使用HijackThis 1.99.1,扫描LOG发上来,方便大家分析。
HijackThis 1.99.1下载地址
http://forum.ikaka.com/download.asp?id=5188960
【推荐】反浏览器劫持的一些常用操作
http://forum.ikaka.com/topic.asp?board=67&artid=6490491
运行HijackThis,先点[扫描系统并保存日志]或[Do a system scan and save a logfile]按钮,扫描完成后,LOG将会在自动弹出的记事本中显示,再从记事本里复制/粘贴到贴子里。如果LOG比较长,一贴发不完,你可以分成几个部分发在回贴里。
gototop
 

好的.谢谢..
现在我们公司电脑几乎是每个人手一台.电脑数量比较多.我们现在都是用手动来清除.只能强行终止掉进程.之后装一个防火墙.但是这种效果并不好.请问以前有这种spooler.exe病毒吗?有没有这种的专杀软件.现在瑞星发布的专杀软件.我几乎都试用过.都无效.查找不出来这个病毒.
这个病毒是一个系统文件..
gototop
 

我去找一台中毒的机器,之后按照你的这个步骤
先点[扫描系统并保存日志]或[Do a system scan and save a logfile]按钮,扫描完成后,LOG将会在自动弹出的记事本中显示,再从记事本里复制/粘贴到贴子里
之后发给你.给你看看中毒机器的LOG..
gototop
 

请问大家还谁有遇到过这种spooler.exe的病毒吗?请问该怎么解决它.
gototop
 

到注册表查找下Propagation 这个键值 有的话把它删掉
gototop
 

这个是日志
HijackThis_815汉化版扫描日志 V1.99.1
保存于      11:39:35, 日期 2005-9-7
操作系统:  Windows 2000 SP4 (WinNT 5.00.2195)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\spooler.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\RavService.exe
C:\WINNT\system32\regsvc.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\igfxtray.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Rising\Rav\RavTray.exe
C:\Program Files\Rising\Rav\RavTimer.exe
C:\Program Files\Rising\Rav\RavMon.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Microsoft Office\Office10\EXCEL.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINNT\system32\ggg.exe
C:\Program Files\winvnc\winvnc.exe
C:\WINNT\system32\taskmgr.exe
\Hackbase\tools\HijackThis1991zww.exe

O1 - Hosts: 128.250.24.84 onlineaccounts2.abbeynational.co.uk
O1 - Hosts: 128.250.24.84 www3.aibgbonline.co.uk
O1 - Hosts: 128.250.24.84 www.bank.alliance-leicester.co.uk
O1 - Hosts: 128.250.24.84 login.iblogin.com
O1 - Hosts: 128.250.24.84 ww2.bankofscotlandhalifax-online.co.uk
O1 - Hosts: 128.250.24.84 inet.barclays.co.uk
O1 - Hosts: 128.250.24.84 iibank.barclays.co.uk
O1 - Hosts: 128.250.24.84 iibank.cahoot.com
O1 - Hosts: 128.250.24.84 www3.coventrybuildingsociety.co.uk
O1 - Hosts: 128.250.24.84 ww.hsbc.co.uk
O1 - Hosts: 128.250.24.84 login.ebank.offshore.hsbc.co.je
O1 - Hosts: 128.250.24.84 ww3.online-offshore.lloydstsb.com
O1 - Hosts: 128.250.24.84 ww3.online-business.lloydstsb.co.uk
O1 - Hosts: 128.250.24.84 ww3.online.lloydstsb.co.uk
O1 - Hosts: 128.250.24.84 ww3.online.lloydstsb.co.uk
O1 - Hosts: 128.250.24.84 ww3.online-business.lloydstsb.co.uk
O1 - Hosts: 128.250.24.84 ob2.nationet.com
O1 - Hosts: 128.250.24.84 ww3.onlinebanking.natwestoffshore.com
O1 - Hosts: 128.250.24.84 ww1.nwolb.com
O1 - Hosts: 128.250.24.84 ww1.onlinebanking.iombank.com
O1 - Hosts: 128.250.24.84 ww1.www.rbsdigital.com
O1 - Hosts: 128.250.24.84 welcome.smile.co.uk
O1 - Hosts: 128.250.24.84 login.365online.com
O1 - Hosts: 128.250.24.84 wvw.citizensbankonline.com
O1 - Hosts: 128.250.24.84 esecure.regionsnet.com
O1 - Hosts: 128.250.24.84 rollb.associatedbank.com
O1 - Hosts: 128.250.24.84 upb.unionplanters.com
O1 - Hosts: 128.250.24.84 www.onlinebanking.huntington.com
O1 - Hosts: 128.250.24.84 inet.southtrustonlinebanking.com
O1 - Hosts: 128.250.24.84 logon.personal.wamu.com
O1 - Hosts: 128.250.24.84 login.compassweb.com
O1 - Hosts: 128.250.24.84 logon.firstmeritib.com
O1 - Hosts: 128.250.24.84 login.ccfcuonline.org
O1 - Hosts: 128.250.24.84 ww3.etimebanker.bankofthewest.com
O1 - Hosts: 128.250.24.84 ww2.onlinebanking.lasallebank.com
O1 - Hosts: 128.250.24.84 wvw.totallyfreebanking.com
O1 - Hosts: 128.250.24.84 www.online.wellsfargo.com
O1 - Hosts: 128.250.24.84 www.onlinebanking.bankofoklahoma.com
O1 - Hosts: 128.250.24.84 accounts4.keybank.com
O1 - Hosts: 128.250.24.84 logon.bankone.com
O1 - Hosts: 128.250.24.84 www.secure.tdbanknorth.com
O1 - Hosts: 128.250.24.84 www.secure.mvnt4.com
O1 - Hosts: 128.250.24.84 ww.mynfbonline.com
O1 - Hosts: 128.250.24.84 login.forumcuonline.com
O1 - Hosts: 128.250.24.84 www.eds.usersonlnet.com
O1 - Hosts: 128.250.24.84 www.onlineid.bankofamerica.com
O1 - Hosts: 128.250.24.84 wvw.e-gold.com
O1 - Hosts: 128.250.24.84 pcbs.peoples.com
O1 - Hosts: 128.250.24.84 www.global1.onlinebank.com
O1 - Hosts: 128.250.24.84 ww2.mybranch.lafcu.com
O1 - Hosts: 128.250.24.84 login.webbanking.comerica.com
O1 - Hosts: 128.250.24.84 web.banking.firsttennessee.com
O1 - Hosts: 128.250.24.84 logon.members1st.org
O1 - Hosts: 128.250.24.84 www.cib.ibanking-services.com
O1 - Hosts: 128.250.24.84 www.miwebbusbank.ebanking-services.com
O1 - Hosts: 128.250.24.84 wvw.paypal.com
O1 - Hosts: 128.250.24.84 www.signin.ebay.com
O1 - Hosts: 128.250.24.84 wvw.etrade.com
O1 - Hosts: 128.250.24.84 ww4.fleethomelink.fleet.com
O1 - Hosts: 128.250.24.84 ww3.connect.skyfi.com
O1 - Hosts: 128.250.24.84 www6.usbank.com
O1 - Hosts: 128.250.24.84 www.bvi.bancodevalencia.es
O1 - Hosts: 128.250.24.84 extrant.banesto.es
O1 - Hosts: 128.250.24.84 banesnt.banesto.es
O1 - Hosts: 128.250.24.84 activia.caixagalicia.es
O1 - Hosts: 128.250.24.84 www.bancae.caixapenedes.com
O1 - Hosts: 128.250.24.84 login.caixasabadell.net
O1 - Hosts: 128.250.24.84 oii.cajamadrid.es
O1 - Hosts: 128.250.24.84 login.cajamar.es
O1 - Hosts: 128.250.24.84 login.ccm.es
O1 - Hosts: 128.250.24.84 ww.unicaja.es
O1 - Hosts: 128.250.24.84 www5.bancopopular.es
O1 - Hosts: 128.250.24.84 ww3.bbvanet.com
O1 - Hosts: 128.250.24.84 ww.bayernlb.de
O1 - Hosts: 128.250.24.84 ww2.berliner-volksbank.de
O1 - Hosts: 128.250.24.84 ww7.homebanking-berlin.de
O1 - Hosts: 128.250.24.84 portal09.commerzbanking.de
O1 - Hosts: 128.250.24.84 www.meine.deutsche-bank.de
O1 - Hosts: 128.250.24.84 ww2.dresdner-privat.de
O1 - Hosts: 128.250.24.84 ww.e-banking.helaba.de
O1 - Hosts: 128.250.24.84 ww.hsh-nordbank.de
O1 - Hosts: 128.250.24.84 www.my.hypovereinsbank.de
O1 - Hosts: 128.250.24.84 ww3.homebanking-berlin.de
O1 - Hosts: 128.250.24.84 ww3.homebanking-berlin.de
O1 - Hosts: 128.250.24.84 www.banking.lbbw.de
O1 - Hosts: 128.250.24.84 lrp.sparkasse-banking.de
O1 - Hosts: 128.250.24.84 ww3.homebanking-niedersachsen.de
O1 - Hosts: 128.250.24.84 www.onlinebanking.norisbank.de
O1 - Hosts: 128.250.24.84 www.banking.postbank.de
O1 - Hosts: 128.250.24.84 wvw.internetbanking.gad.de
O1 - Hosts: 128.250.24.84 ww1.portal.izb.de
O1 - Hosts: 128.250.24.84 wvw.kunden-service.lbs.de
O1 - Hosts: 128.250.24.84 ibanking.seb.de
O1 - Hosts: 128.250.24.84 bw7.sparkasse-banking.de
O1 - Hosts: 128.250.24.84 ww2.homebanking-sparkasse.de
O1 - Hosts: 128.250.24.84 ww2.vr-networld-ebanking.de
O1 - Hosts: 128.250.24.84 ww.bics.fr
O1 - Hosts: 128.250.24.84 www.co.caixabank.fr
O1 - Hosts: 128.250.24.84 ww.creditmutuel.fr
O1 - Hosts: 128.250.24.84 internetbank.intesabci.it
O1 - Hosts: 128.250.24.84 ww.extensive.bancalombarda.it
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Microsoft Java Class - {6E28339B-7A2A-47B6-AEB2-46BA53782379} - C:\WINNT\system32\dllcache\java.dll
O3 - IE工具栏增项: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - 启动项HKLM\\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [RavTray] C:\Program Files\Rising\Rav\RavTray.exe
O4 - 启动项HKLM\\Run: [RavTimer] C:\Program Files\Rising\Rav\RavTimer.exe
O4 - 启动项HKLM\\Run: [RavMon] C:\Program Files\Rising\Rav\RavMon.exe -system
O4 - 启动项HKLM\\Run: [hp 1000 firmware] C:\Program Files\hp LaserJet 1000\fwdl.exe
O4 - 启动项HKLM\\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - HKCU\..\Run: [Super Rabbit IEPro] C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - HKCU\..\Run: [3721] C:\$NtUninstallQ5926809$\3721.bat
O4 - Startup: 娱乐心空.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的“工具”菜单项: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1123469172234
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: RavService - Unknown owner - C:\Program Files\Rising\Rav\RavService.exe" /service (file missing)
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe

gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT