12   1  /  2  页   跳转

灰鸽子 大侠帮帮忙 ` `急`````!

灰鸽子 大侠帮帮忙 ` `急`````!

最近寝食难安 中了灰鸽子``
`
`杀又杀不掉
~但是瑞星老弹出菜单     
`说有毒```
` ` `
哪位`大侠帮帮忙 `教教我怎么办````!??
`
附:



Logfile of HijackThis v1.99.1
Scan saved at 12:49:16, on 2005-11-15
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
E:\瑞星\RISING\RAV\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
E:\瑞星\RISING\RAV\CCENTER.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\TBPanel.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\瑞星\RISING\RAV\RAVTIMER.EXE
E:\瑞星\RISING\RAV\RAVMON.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\QQ\TIMPlatform.exe
E:\QQ\QQ.exe
C:\Program Files\Windows Media Player\wmplayer.exe
E:\瑞星\248783200522382732\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll (file missing)
O2 - BHO: FiltrateWebObj Class - {42AFACEE-2A77-41EB-9EE2-D9F8AF827F90} - E:\KV2006\KV2006\KVBHO.dll (file missing)
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - E:\QQ\QQIEHelper.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL (file missing)
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: 百度搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\WINDOWS\DOWNLO~1\BaiDuBar.dll
O3 - Toolbar: 百度搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\WINDOWS\DOWNLO~1\BaiDuBar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Gainward] C:\WINDOWS\TBPanel.exe /A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [KvMonXP] E:\KV2005\KV2005\KVMonXP.kxp /auto
O4 - HKLM\..\Run: [RavTimer] E:\瑞星\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] E:\瑞星\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = E:\office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: 使用网际快车下载 - E:\网际快车\cr-JetCar\cr-JetCar\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - E:\网际快车\cr-JetCar\cr-JetCar\jc_all.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\QQ\AddEmotion.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\QQ\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\QQ\QQIEHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5DD731E6-D4F0-11D3-BE3F-00105A6FDA50} (V3ProX Control) - http://origin-www.ahn.com.cn/aspservice/plugin/myv3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B651838D-9E67-40B6-8ECE-EB6C5281CFDD}: NameServer = 192.168.38.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{E029BEBC-1B49-4850-9850-434209CE5B70}: NameServer = 202.103.0.117 202.103.24.68
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - E:\瑞星\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\瑞星\RISING\RAV\Ravmond.exe
O23 - Service: Windows Audio0 - Unknown owner - C:\WINDOWS\G_Server.exe

最后编辑2005-11-15 14:17:41
分享到:
gototop
 

重新启动到安全模式(进入安全模式的方法:重新启动电脑, 开机自动检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式(Safe Mode)进入Windows。)

开始→控制面板→性能和维护→管理工具→服务→查找Windows Audio0→右击→属性→启动类型→禁止→应用→停止→确定。

请关闭所有IE界面,重新使用HijackThis扫描一次,选中下面建议修复的项目,让HijackThis修复,修复前请允许HijackThis保留备份。(如果楼主知道是安全的可以不必勾选)
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

然后打开我的电脑→再点工具→打开文件夹选项→查看→把隐藏受保护的系统文件(推荐)和隐藏已知文件类型的扩展名的勾去掉→再显示所有文件→找到以下文件并删除:(如果有的话)
C:\WINDOWS\G_Server.exe
C:\WINDOWS\G_Server.dll
C:\WINDOWS\G_Server_hook.dll
C:\WINDOWS\G_Serverkey.dll
gototop
 

谢谢高手帮忙`
我先试试`````````
gototop
 

http://forum.ikaka.com/topic.asp?board=3&artid=7412711
gototop
 

我的个别游戏不能正常进如~(MU和魔兽)MU是点了连接后就没有任何反映了~而魔兽就会弹出2个对话框~(附图)我怀疑是系统文件除了问题~~有办法解决吗?(我已装了DX9。0C)

附件附件:

下载次数:0
文件类型:application/octet-stream
文件大小:
上传时间:2005-11-15 13:08:08
描述:



gototop
 

2

附件附件:

下载次数:0
文件类型:application/octet-stream
文件大小:
上传时间:2005-11-15 13:08:36
描述:



gototop
 

【回复“wxtzxx”的帖子】
不好意思,刚才看错了作者。请参考这个帖子的回复!

http://forum.ikaka.com/topic.asp?board=67&artid=7412982
gototop
 

好的~
gototop
 

搞顶了`
谢谢飞跃迷离的帮忙`````~
`
``不过有个新问题`
`在c  盘\WINDOWS\里发现很多这样的文件夹
C:\WINDOWS\$hf_mig$
C:\WINDOWS\$MSI31Uninstall_KB893803v2$
是隐藏文件夹
字体颜色为兰色 ~
有27个之多`
请飞跃迷离帮忙看看是什么东东 ```是不是毒`````


如果图

附件附件:

下载次数:0
文件类型:image/pjpeg
文件大小:
上传时间:2005-11-15 13:56:20
描述:



gototop
 

这些文件夹是系统更新程序的临时保存目录,不是病毒。
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT