1   1  /  1  页   跳转

帮助!!!中毒了啊

帮助!!!中毒了啊

本人最近中了毒,具体情况是,杀完毒还是出现,只要一上网就出现病毒,在系统的安全模式下在查杀A0002835.exe时停止不动。具体日志如下


HijackThis_815汉化版扫描日志 V1.99.1
保存于      14:26:24, 日期 2006-7-24
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
E:\瑞星杀毒软件\CCenter.exe
C:\WINDOWS\System32\svchost.exe
E:\瑞星杀毒软件\Ravmond.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
E:\瑞星杀毒软件\RavStub.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\SOUNDMAN.EXE
E:\瑞星杀毒软件\RavTask.exe
E:\瑞星杀毒软件\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
E:\瑞星杀毒软件\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Ringz Studio\Storm Downloader\StormDownloader.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\讯雷5\Program\Thunder5.exe
C:\PROGRA~1\MINIPP~1\MINIPP~1.EXE
C:\Program Files\WinRAR\WinRAR.exe
E:\HijackThis1991zww.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe,C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\bjcmmc.exe
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v4.dll
O2 - BHO: internet explorer helper - {02C9B9AB-6372-46C5-B356-773FAF3B6B1E} - C:\WINDOWS\fonts\msshapi.dll
O2 - BHO: FltSetUp Class - {1D49D58D-5C84-4B50-8359-D9809BEB2B32} - C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll
O2 - BHO: Adobe-Plugins Manager - {2AFA7CEC-26D9-4256-AF57-497A13180BA5} - C:\WINDOWS\System32\Agm.dll
O2 - BHO: JyxBzkbh Class - {52BCB388-9D79-6013-7922-58EB952E8081} - (no file)
O2 - BHO: ActiveBHO Class - {63C55A7F-6E29-8D4F-5C76-4F850F28D13A} - C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O2 - BHO: BHOImp Class - {70AFF2CB-9DA2-499C-8D15-900729FCE83D} - C:\WINDOWS\system32\YHBO.dll (file missing)
O2 - BHO: MSHlper Class - {721E6521-4CAD-4A8D-A7F1-4E230B31EF19} - C:\WINDOWS\system32\MSHLP.DLL
O2 - BHO: bg - {7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} - C:\Program Files\baigoo\BGooBHO.dll (file missing)
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\讯雷5\ComDlls\XunLeiBHO_002.dll
O2 - BHO: ThunderMiniBHO - {8E6C1C49-F9CE-4311-9FB4-D70E8B0AEAEB} - C:\Program Files\Thunder Network\ThunderMini\ComDlls\XunLeiMiniBHO_002.dll
O2 - BHO: Mini PPGou BHO - {92FB5F8F-8254-4978-9C50-03D9B0405062} - C:\PROGRA~1\MINIPP~1\MINIPP~1.DLL
O2 - BHO: IEHlprObj Class - {999ADFA2-8AD1-47ff-97FC-69FB847458F4} - C:\Progra~1\NetMeeting\nmview.dll
O2 - BHO: Internet_Explorer_Service - {9E1E1371-9D8F-4421-81B9-F8D2E1773A59} - C:\WINDOWS\system32\HelperService.dll
O2 - BHO: iehelper - {C1DE9E98-839F-4055-AEDF-781852C25895} - C:\WINDOWS\system32\aperferer.dll
O2 - BHO: Yahoo Bar - {F60FAB6F-115D-4797-9ED1-89793B930876} - C:\WINDOWS\ODBINT.dll
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [RavTask] "E:\瑞星杀毒软件\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [sysmini] C:\WINDOWS\system32\sysmini.exe
O4 - 启动项HKLM\\Run: [svc] C:\WINDOWS\svchost.exe
O4 - 启动项HKLM\\Run: [m0c4gx] RunDll32 "C:\WINDOWS\Downlo~1\m0c4gx.dll",Run
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [MINI_BFYY] C:\Program Files\Ringz Studio\Storm Downloader\StormDownloader.exe
O4 - 启动项HKLM\\Run: [MINIPP~1.EXE] C:\PROGRA~1\MINIPP~1\MINIPP~1.EXE
O4 - 启动项HKLM\\RunOnce: [RavStub] "E:\瑞星杀毒软件\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [svc] C:\WINDOWS\svchost.exe
O8 - IE右键菜单中的新增项目: &使用暴风下载器下载 - C:\Program Files\Ringz Studio\Storm Downloader\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - C:\Program Files\讯雷5\Program\GetUrl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - C:\Program Files\讯雷5\Program\GetAllUrl.htm
O8 - IE右键菜单中的新增项目: &使用迷你屁屁狗[PPGou]加速下载 - C:\PROGRA~1\MINIPP~1\geturl.htm
O8 - IE右键菜单中的新增项目: >>彩信发送<< - res://C:\PROGRA~1\MMSASS~1\mmsass~1.dll/mms.htm
O8 - IE右键菜单中的新增项目: 用比特精灵下载(&B) - E:\BS下载软件\BitSpirit\bsurl.htm
O9 - 浏览器额外的按钮: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - D:\浩方对战平台\GameClient.exe
O9 - 浏览器额外的按钮: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - 浏览器额外的“工具”菜单项: 彩E精灵设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\cdnns.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{957F1D9E-C68C-4FFA-AD50-07E9C7ADE759}: NameServer = 202.109.14.5 202.96.209.5
O18 - Filter: text/html - {E7009873-0D40-45B1-8D59-5B9AE98C7D38} - C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll
O21 - SSODL: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - (no file)
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - E:\瑞星杀毒软件\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\瑞星杀毒软件\Ravmond.exe
最后编辑2006-07-24 14:46:23
分享到:
gototop
 

修复
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe,C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\bjcmmc.exe
O2 - BHO: internet explorer helper - {02C9B9AB-6372-46C5-B356-773FAF3B6B1E} - C:\WINDOWS\fonts\msshapi.dll
O2 - BHO: FltSetUp Class - {1D49D58D-5C84-4B50-8359-D9809BEB2B32} - C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll
O2 - BHO: Adobe-Plugins Manager - {2AFA7CEC-26D9-4256-AF57-497A13180BA5} - C:\WINDOWS\System32\Agm.dll
O2 - BHO: JyxBzkbh Class - {52BCB388-9D79-6013-7922-58EB952E8081} - (no file)
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O2 - BHO: BHOImp Class - {70AFF2CB-9DA2-499C-8D15-900729FCE83D} - C:\WINDOWS\system32\YHBO.dll (file missing)
O2 - BHO: MSHlper Class - {721E6521-4CAD-4A8D-A7F1-4E230B31EF19} - C:\WINDOWS\system32\MSHLP.DLL
O2 - BHO: bg - {7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} - C:\Program Files\baigoo\BGooBHO.dll (file missing)
O2 - BHO: IEHlprObj Class - {999ADFA2-8AD1-47ff-97FC-69FB847458F4} - C:\Progra~1\NetMeeting\nmview.dll
O2 - BHO: Internet_Explorer_Service - {9E1E1371-9D8F-4421-81B9-F8D2E1773A59} - C:\WINDOWS\system32\HelperService.dll
O2 - BHO: iehelper - {C1DE9E98-839F-4055-AEDF-781852C25895} - C:\WINDOWS\system32\aperferer.dll
O2 - BHO: Yahoo Bar - {F60FAB6F-115D-4797-9ED1-89793B930876} - C:\WINDOWS\ODBINT.dll
O4 - 启动项HKLM\\Run: [svc] C:\WINDOWS\svchost.exe
O4 - 启动项HKLM\\Run: [m0c4gx] RunDll32 "C:\WINDOWS\Downlo~1\m0c4gx.dll",Run
O4 - HKCU\..\Run: [svc] C:\WINDOWS\svchost.exe
O8 - IE右键菜单中的新增项目: >>彩信发送<< - res://C:\PROGRA~1\MMSASS~1\mmsass~1.dll/mms.htm
O9 - 浏览器额外的按钮: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - 浏览器额外的“工具”菜单项: 彩E精灵设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O18 - Filter: text/html - {E7009873-0D40-45B1-8D59-5B9AE98C7D38} - C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll
O21 - SSODL: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - (no file)

删除
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\bjcmmc.exe
C:\WINDOWS\fonts\msshapi.dll
C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll
C:\WINDOWS\System32\Agm.dll
C:\WINDOWS\system32\MSHLP.DLL
C:\Progra~1\NetMeeting\nmview.dll
C:\WINDOWS\system32\HelperService.dll
C:\WINDOWS\system32\aperferer.dll
C:\WINDOWS\ODBINT.dll
C:\WINDOWS\svchost.exe
C:\WINDOWS\Downlo~1\m0c4gx.dll


http://www.pctutu.com/srmsdown.asp
下载超级兔子..用超级兔子清理王卸载流氓软件...(安全模式...)

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\bjcmmc.exe
麻烦压缩发送到bin59420@yahoo.com.cn
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT