瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】我的电脑怎么了,每次开机都说有木马,杀了还有?

1   1  /  1  页   跳转

【求助】我的电脑怎么了,每次开机都说有木马,杀了还有?

【求助】我的电脑怎么了,每次开机都说有木马,杀了还有?

我的电脑每次开机都绘显示说,我中了木马,已经清除,请看下面的日志
2006-06-04 09:22:21, IEXPLORE.EXE>>C:\Program Files\Internet Explorer\IEXPLORE.EXE ->未知病毒
2006-06-04 07:46:48, IEXPLORE.EXE>>C:\Program Files\Internet Explorer\IEXPLORE.EXE ->Backdoor.Gpigeon.uql
2006-06-03 22:26:09, IEXPLORE.EXE>>C:\Program Files\Internet Explorer\IEXPLORE.EXE ->Backdoor.Gpigeon.uql
2006-06-03 22:00:23, IEXPLORE.EXE>>C:\Program Files\Internet Explorer\IEXPLORE.EXE ->Backdoor.Gpigeon.uql
2006-06-03 21:00:39, IEXPLORE.EXE>>C:\Program Files\Internet
我用卡卡扫描的进程日志023项如下
O23 - Service: C-DillaSrv (C-DillaSrv) - C-Dilla Ltd - C:\WINNT\system32\drivers\cdantsrv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\system32\dmadmin.exe /com
O23 - Service: Macromedia Licensing Service (Macromedia Licensing Service) - - "C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - - "C:\Program Files\CyberLink\Shared Files\RichVideo.exe"
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\rising\Rav\Ravmond.exe"
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: windows (windows) - - C:\WINNT\cn.exe

请大家帮忙!
最后编辑2006-06-04 11:56:01
分享到:
gototop
 

O23 - Service: windows (windows) - - C:\WINNT\cn.exe
gototop
 

我又用hijackthis扫的数据,请高手指点该怎么办

NameServer = 211.91.120.129,211.94.33.193
O23 - NT 服务: C-DillaSrv - C-Dilla Ltd - C:\WINNT\system32\DRIVERS\CDANTSRV.EXE
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - NT 服务: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - NT 服务: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\Ravmond.exe
O23 - NT 服务: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - NT 服务: windows - Unknown owner - C:\WINNT\cn.exe
gototop
 

我按照
引用:
【baohe的贴子】

怎么确认鸽子的文件名?还是看HijackThis日志。Unknown owner - 后面的内容就是鸽子文件的所在位置及其文件名。本例是C:\WINDOWS\windr.exe)。

注意:除了可执行文件.exe外(本例是windr.exe),%WINDOWS%下可能还有包含可执行文件名的.dll文件(以本例为例,这些dll的文件名可能有windr.dll、windr_hook.dll、windrKey.dll),这些文件数目不定。只要有,也要删除。
...........................

去做,可是查不出来,问题还是没有解决。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT