12   1  /  2  页   跳转

【求助】瑞星清除后又有的病毒

【求助】瑞星清除后又有的病毒

最近有这样2种病毒Backdoor.Gpigeon.wvw  另外是Backdoor.pigeon.wfv 。用瑞星杀拉好几回还是有,不知道该如何处理。请教高手。
最后编辑2006-08-28 13:18:19
分享到:
gototop
 

这是鸽子,扫一个日子上来.
gototop
 

【回复“myoperator”的帖子】
怎么扫日记
gototop
 

http://forum.ikaka.com/topic.asp?board=28&artid=6979213一楼下载附件扫描日志上来
gototop
 

请到http://www.spywareinfo.com/~merijn/files/hijackthis.zip 下载Hijackthis,贴个log上来
gototop
 

【回复“myoperator”的帖子】
Backdoor.ASP.Ace.tq
Backdoor.Ciadoor.ew
Backdoor.Ciadoor.ex
Backdoor.Ciadoor.ey
Backdoor.Ciadoor.ez
Backdoor.Ciadoor.fa
Backdoor.Codbot.ld
Backdoor.Codbot.le
Backdoor.Codbot.lf
Backdoor.Codbot.lg
Backdoor.Codbot.lh
Backdoor.Codbot.li
Backdoor.Codbot.lk
Backdoor.Codbot.ll
Backdoor.Codbot.lm
Backdoor.Codbot.lp
Backdoor.Codbot.lr
Backdoor.Codbot.ls
Backdoor.Codbot.lt
Backdoor.Codbot.lu
Backdoor.Codbot.lv
Backdoor.Codbot.lw
Backdoor.Codbot.lx
Backdoor.Codbot.ma
Backdoor.Codbot.mb
Backdoor.Codbot.mc
Backdoor.Codbot.md
Backdoor.Codbot.me
Backdoor.Codbot.mf
Backdoor.Codbot.mg
Backdoor.Codbot.mh
Backdoor.Codbot.mi
Backdoor.Codbot.mj
Backdoor.Codbot.mk
Backdoor.Delf.uet
Backdoor.Delf.ueu
Backdoor.Delf.uev
Backdoor.Delf.uew
Backdoor.Delf.uex
Backdoor.Delf.uey
Backdoor.Delf.uez
Backdoor.Delf.ufa
Backdoor.Delf.ufb
Backdoor.Delf.ufc
Backdoor.Delf.ufd
Backdoor.Delf.ufe
Backdoor.Delf.uff
Backdoor.Delf.ufg
Backdoor.Delf.ufh
Backdoor.Delf.ugi
Backdoor.Delf.ugj
Backdoor.Delf.ugk
Backdoor.Delf.ujd
Backdoor.Delf.uje
Backdoor.Delf.ujf
Backdoor.FireFly.ah
Backdoor.Gpigeon.xge
Backdoor.Gpigeon.xgg
Backdoor.Gpigeon.xgh
Backdoor.Haxdoor.rl
Backdoor.Haxdoor.rm
Backdoor.Haxdoor.rn
Backdoor.Haxdoor.ro
Backdoor.Haxdoor.rp
Backdoor.Haxdoor.rq
Backdoor.Haxdoor.rr
Backdoor.IRCBot.csf
Backdoor.IRCBot.csg
Backdoor.IRCBot.csh
Backdoor.IRCBot.csi
Backdoor.IRCBot.csj
Backdoor.IRCBot.csk
Backdoor.Medbot.al
Backdoor.Medbot.am
Backdoor.Mybot.dop
Backdoor.Mybot.doq
Backdoor.Mybot.dor
Backdoor.Mybot.dos
Backdoor.Mybot.dot
Backdoor.Mybot.dou
Backdoor.Mybot.dov
Backdoor.NCPH.g
Backdoor.PcClient.jap
Backdoor.PcClient.jaq
Backdoor.Rohbot.a
Backdoor.SdBot.qbe
Dropper.LMir.r
Hack.Flooder.SYN.t
Trojan.DL.Delf.btb
Trojan.DL.QQHelper.dvn
Trojan.DL.QQHelper.dvo
Trojan.DL.QQHelper.dvp
Trojan.DL.QQHelper.dvq
Trojan.PSW.Lmir.keu
Trojan.PSW.WoWar.db
Trojan.PSW.ZhengTu.aj
Worm.IM.Guap.m
Worm.IM.Lewor.bk
Worm.IM.Lewor.bl
Worm.IM.Opanki.cf
Worm.IM.Opanki.cg
Worm.IM.Small.f
Worm.IM.Small.g
Worm.IM.VB.ab
Worm.IM.VB.ac
Worm.Kidala.k
Worm.Kidala.l
Worm.Kidala.m
Worm.Lightmoon.a
Worm.Mail.Bagle.qp
Worm.Mail.Bagle.qq
Worm.Mail.Bagle.qr
Worm.Mail.Bagle.qs
Worm.Mail.Bagle.qt
Worm.Mail.Bagle.qu
Worm.Mail.Bagle.qv
Worm.Mail.Bagle.qw
Worm.Mail.Bagle.qx
Worm.Mail.Bagle.qy
Worm.Mail.Bagle.qz
Worm.Mail.Bagle.ra
Worm.Mail.Bagle.rb
Worm.Mail.Bagle.rc
Worm.Mail.Bagle.rd
Worm.Mail.Bagle.re
Worm.Mail.Bagle.rf
Worm.Mail.Bagle.rg
Worm.Mail.Bagle.rh
Worm.Mail.Bagle.ri
Worm.Mail.Bagle.rj
Worm.Mail.Bagle.rk
Worm.Mail.Bagle.rl
Worm.Mail.Bagle.rm
Worm.Mail.Bagz.ac
Worm.Mail.Banwarum.h
Worm.Mail.Brontok.gk
Worm.Mail.Brontok.gl
Worm.Mail.Brontok.gm
Worm.Mail.Brontok.gn
Worm.Mail.Brontok.go
Worm.Mail.Brontok.gp
Worm.Mail.Brontok.gq
Worm.Mail.Brontok.gs
Worm.Mail.Brontok.gt
Worm.Mail.Calgary.bd
Worm.Mail.Centar.l
Worm.Mail.Combra.aw
Worm.Mail.Combra.ax
Worm.Mail.Combra.ay
Worm.Mail.Combra.az
Worm.Mail.Combra.ba
Worm.Mail.Doombot.k
Worm.Mail.Fable.a
Worm.Mail.Fable.b
Worm.Mail.Generic.cj
Worm.Mail.Generic.ck
Worm.Mail.Generic.cl
Worm.Mail.Generic.cm
Worm.Mail.Kebede.h
Worm.Mail.Locksky.jw
Worm.Mail.Locksky.jx
Worm.Mail.Locksky.jy
Worm.Mail.Locksky.jz
Worm.Mail.Locksky.ka
Worm.Mail.LoveLetter.f
Worm.Mail.Scano.af
Worm.Mail.Scano.ag
Worm.Mail.Scano.ah
Worm.Mail.Scano.ai
Worm.Mail.Scano.aj
Worm.Mail.Scano.ak
Worm.Mail.Skowor.o
Worm.Mail.Skowor.p
Worm.Mail.Sober.ac
Worm.Mail.VB.cj
Worm.Mail.VB.ck
Worm.Mail.VB.cl
Worm.Mytob.nfd
Worm.Mytob.nfe
Worm.Mytob.nff
Worm.Mytob.nfg
Worm.Mytob.nfh
Worm.Mytob.nfi
Worm.Nanspy.q
Worm.P2P.Agent.o
Worm.P2P.Agent.p
Worm.P2P.SpyBot.azn
Worm.P2P.SpyBot.azo
Worm.P2P.SpyBot.azp
Worm.P2P.SpyBot.azq
Worm.P2P.SpyBot.azr
Worm.P2P.SpyBot.azs
Worm.P2P.SpyBot.azt
Worm.P2P.SpyBot.azu
Worm.P2P.SpyBot.azv
Worm.P2P.SpyBot.azw
Worm.P2P.SpyBot.azx
Worm.P2P.SpyBot.azy
Worm.P2P.SpyBot.azz
Worm.P2P.SpyBot.baa
Worm.P2P.SpyBot.bab
Worm.P2P.SpyBot.bac
Worm.P2P.SpyBot.bae
Worm.P2P.VB.aal
Worm.P2P.VB.aam
Worm.P2P.VB.aan
Worm.P2P.VB.aao
Worm.Protoride.eg
Worm.Salia.a
Worm.Small.aa
Worm.Smalldoor.a
Worm.Spybot.ain
Worm.Spybot.aio
Worm.Spybot.aip
Worm.Spybot.aiq
Worm.Spybot.air
Worm.Spybot.ais
Worm.Spybot.ait
Worm.Spybot.aiu
Worm.Spybot.aiv
Worm.Spybot.aiw
Worm.Spybot.aix
Worm.Spybot.aiy
Worm.Spybot.aiz
Worm.Spybot.aja
Worm.Spybot.ajb
Worm.Spybot.ajc
Worm.Spybot.ajd
Worm.Spybot.aje
Worm.Spybot.ajf
Worm.Spybot.ajg
Worm.Spybot.ajh
Worm.Spybot.aji
Worm.Spybot.ajj
Worm.Spybot.ajk
Worm.Spybot.ajl
Worm.Spybot.ajm
Worm.Spybot.ajn
Worm.Spybot.ajo
Worm.Spybot.ajp
Worm.Spybot.ajq
Worm.Spybot.ajr
Worm.Spybot.ajs
Worm.Spybot.ajt
Worm.Spybot.aju
Worm.Spybot.ajv
Worm.Spybot.ajw
Worm.Spybot.ajx
Worm.Spybot.ajy
Worm.Spybot.ajz
Worm.Spybot.aka
Worm.Spybot.akb
Worm.Spybot.akc
Worm.Spybot.akd
Worm.Spybot.ake
Worm.Spybot.akf
Worm.Spybot.akg
Worm.Spybot.akh
Worm.Spybot.aki
Worm.Spybot.akj
Worm.Spybot.akk
Worm.Spybot.akl
Worm.Spybot.akm
Worm.Spybot.akn
Worm.Spybot.ako
Worm.Spybot.akp
Worm.Spybot.akq
Worm.Spybot.akr
Worm.Spybot.aks
Worm.Spybot.akt
Worm.Spybot.aku
Worm.Spybot.akv
Worm.Spybot.akw
Worm.Spybot.akx
Worm.Spybot.aky
Worm.Spybot.akz
Worm.Spybot.ala
Worm.Spybot.alb
Worm.Spybot.alc
Worm.Spybot.ald
Worm.Spybot.ale
Worm.Spybot.alf
Worm.Spybot.alg
Worm.Spybot.alh
Worm.Spybot.ali
Worm.Spybot.alj
Worm.Spybot.alk
Worm.Spybot.all
Worm.Spybot.alm
Worm.Spybot.aln
Worm.Spybot.alo
Worm.Spybot.alp
Worm.Spybot.alq
Worm.Spybot.alr
Worm.Spybot.als
Worm.Spybot.alt
Worm.Spybot.alu
Worm.Spybot.alv
Worm.Spybot.alw
Worm.Spybot.alx
Worm.Spybot.aly
Worm.Spybot.alz
Worm.Spybot.ama
Worm.Spybot.amb
Worm.Spybot.amc
Worm.Spybot.amd
Worm.Spybot.ame
Worm.Spybot.amf
Worm.Spybot.amg
Worm.Spybot.amh
Worm.Spybot.ami
Worm.Spybot.amj
Worm.Spybot.amk
Worm.Spybot.aml
Worm.Spybot.amm
Worm.Spybot.amn
Worm.Spybot.amo
Worm.Spybot.amp
Worm.Spybot.amq
Worm.Spybot.amr
Worm.Spybot.ams
Worm.Spybot.amt
Worm.Spybot.amu
Worm.Spybot.amv
Worm.Spybot.amw
Worm.Spybot.amx
Worm.Spybot.amy
Worm.Spybot.amz
Worm.Spybot.ana
Worm.Spybot.anb
Worm.Spybot.anc
Worm.Spybot.and
Worm.Spybot.ane
Worm.Spybot.anf
Worm.Spybot.ang
Worm.Spybot.anh
Worm.Spybot.ani
Worm.Spybot.anj
Worm.Spybot.ank
Worm.Spybot.anl
Worm.Spybot.anm
Worm.Spybot.ann
Worm.Spybot.ano
Worm.Spybot.anp
Worm.Spybot.anq
Worm.Spybot.anr
Worm.Spybot.ans
Worm.Spybot.ant
Worm.Spybot.anu
Worm.Spybot.anv
Worm.Spybot.anw
Worm.Spybot.anx
Worm.Spybot.any
Worm.Spybot.anz
Worm.Spybot.aoa
Worm.Spybot.aob
Worm.Spybot.aoc
Worm.Spybot.aod
Worm.Spybot.aoe
Worm.Spybot.aof
Worm.Spybot.aog
Worm.Spybot.aoh
Worm.Spybot.aoi
Worm.Spybot.aoj
Worm.Spybot.aok
Worm.Spybot.aol
Worm.Spybot.aom
Worm.Spybot.aon
Worm.Spybot.aoo
Worm.Spybot.aop
Worm.Spybot.aoq
Worm.Spybot.aor
Worm.Spybot.aos
Worm.Spybot.aot
Worm.Spybot.aou
Worm.Spybot.aow
Worm.Spybot.aox
Worm.Spybot.aoy
Worm.Spybot.aoz
Worm.Spybot.apa
Worm.Spybot.apb
Worm.Spybot.apc
Worm.Spybot.ape
Worm.Spybot.apf
Worm.Spybot.apg
Worm.Spybot.aph
Worm.Spybot.api
Worm.Spybot.apj
Worm.Spybot.apk
Worm.Spybot.apl
Worm.Spybot.apm
Worm.Spybot.apn
Worm.Spybot.apo
Worm.Spybot.app
Worm.Spybot.apq
Worm.Spybot.apr
Worm.Spybot.aps
Worm.Spybot.apt
Worm.Spybot.apu
Worm.Spybot.apv
Worm.Spybot.apw
Worm.Spybot.apx
Worm.SymbOS.Flexispy.a
Worm.SymbOS.StopUp.a
Worm.SymbOS.StopUp.b
Worm.Vasor.a
Worm.Vasor.b
Worm.Vasor.c
Worm.Vasor.d
Worm.VB.ep
Worm.VB.eq
Worm.VB.er
Worm.VB.es
Worm.VB.et
Worm.VB.eu
Worm.VB.ev
Worm.VB.ew
Worm.VB.ex
Worm.VB.ey
Worm.VB.ez
gototop
 

我给你们一个病毒的截图把,你们看以下请各位帮忙

附件附件:

下载次数:3539
文件类型:application/octet-stream
文件大小:
上传时间:2006-6-6 11:25:10
描述:



gototop
 

引用:
【myoperator的贴子】这是鸽子,扫一个日子上来.
...........................


我已经把截图的图片给你,请指教。先谢拉
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 11:21:37, on 2006-6-6
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Rundll32.exe
D:\Program Files\Rising\Rav\RavStub.exe
c:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
D:\Program Files\Rising\Rav\RavTask.exe
D:\Program Files\Rising\Rav\Ravmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\AOL\1146398089\ee\AOLSoftware.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ProcessTamer\ProcessTamerTray.exe
D:\Program Files\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe
D:\Program Files\Rising\Rav\Rav.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\我的下载\HijackThis.exe

R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
R3 - URLSearchHook: SrchHook Class - {EED92A43-CFCE-4548-BD73-B0A405470ED5} - C:\PROGRA~1\CNNIC\Cdn\iesrch.dll
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v14.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\导出邮件\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo!Photo - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll
O2 - BHO: AntiFish Class - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yangling.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O2 - BHO: QQBrowserHelperObject Class - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\QQ2005\QQIEHelper.dll
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - E:\新建文件夹\ComDlls\XunLeiBHO_001.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: HBObject Class - {AE22AFE5-1EF4-4D25-9E23-D2825FB17DA1} - C:\PROGRA~1\HBClient\tbhelper.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\CnsHook.dll
O2 - BHO: (no name) - {FEDF637B-F631-4583-A210-33CC828D42DB}? - (no file)
O3 - Toolbar: (no name) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - (no file)
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: (no name) - {FEDF637B-F631-4583-A210-33CC828D42DB}? - (no file)
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [RavTask] "D:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1146398089\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [RichMedia] C:\WINDOWS\system32\Rundll32.exe  "C:\PROGRA~1\HBClient\tbhelper.dll",WaitWindows
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [RavStub] "D:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ProcessTamer.lnk = C:\Program Files\ProcessTamer\ProcessTamerTray.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: &使用迅雷下载 - E:\新建文件夹\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - E:\新建文件夹\Program\GetAllUrl.htm
O8 - Extra context menu item: Google 搜索(&G) - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\QQ2005\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\QQ2005\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\QQ2005\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\QQ2005\SendMMS.htm
O8 - Extra context menu item: 百度--MP3搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUMP3.HTM
O8 - Extra context menu item: 百度--图片搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUIMG.HTM
O8 - Extra context menu item: 百度--新闻搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUNEWS.HTM
O8 - Extra context menu item: 百度--歌词搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDULYRIC.HTM
O8 - Extra context menu item: 百度--网页搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUSEARCH.HTM
O8 - Extra context menu item: 百度--词典搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_DIC.HTM
O8 - Extra context menu item: 百度--贴吧搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUPOST.HTM
O8 - Extra context menu item: 雅虎搜索 - res://C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll/246
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97}? - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26}? - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao (file missing)
O9 - Extra button: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - Extra button: 微软 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.microsoft.com/china/index.htm (file missing)
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra button: 易趣购物 - {DE607144-AC19-424e-868A-8D70ABDF119A}? - http://click2.ad4all.net/url2/urlmanage/url.asp?id=5 (file missing)
O9 - Extra 'Tools' menuitem: 易趣购物 - {DE607144-AC19-424e-868A-8D70ABDF119A}? - http://click2.ad4all.net/url2/urlmanage/url.asp?id=5 (file missing)
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6}? - C:\Program Files\QQ2005\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6}? - C:\Program Files\QQ2005\QQIEHelper.dll
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg (file missing)
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}? - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - Extra button: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} - http://www.rising.com.cn/?u=RSTB (file missing)
O9 - Extra button: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com/?u=RSTB (file missing)
O10 - Unknown file in Winsock LSP: c:\progra~1\hbclient\hplus.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\hbclient\hplus.dll
O11 - Options group: [!CNS]  网络实名
O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.tvkoo.com/update/KooPlayer.ocx
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6F66139C-5ECB-4366-AE19-FD6C6C038469}: NameServer = 202.96.128.166 202.96.134.133
O17 - HKLM\System\CCS\Services\Tcpip\..\{B37236C6-7452-42EA-BAFD-BD7105DB60AE}: NameServer = 202.96.134.133,202.96.128.68
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: lsass8030 - Unknown owner - C:\WINDOWS\lsass8030.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Systen - Unknown owner - C:\WINDOWS\Systen.exe

附件附件:

下载次数:3516
文件类型:application/octet-stream
文件大小:
上传时间:2006-6-6 11:31:47
描述:



gototop
 

请到http://www.spywareinfo.com/~merijn/files/hijackthis.zip 下载Hijackthis,贴个log上来

方法:
运行hijackthis-》选“Do a system scan and save a logfile"-》将记事本中的内容贴上来
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT