1   1  /  1  页   跳转

救命啊! 斑竹

救命啊! 斑竹

这几天一启动电脑进入桌面就询问是否要删除病毒  之后我就用瑞星查杀病毒老是杀到“WINDOWS下的PE病毒”的病毒
我已经用HijackThis扫描过了  由于过长 我分两次上传
Logfile of HijackThis v1.99.1
Scan saved at 10:44:39, on 2006-8-10
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\rising\rfw\rfwproxy.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\baigoo\bgoomain.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\wincup\wincup.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\RavMon.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\Rising\Rav\Rav.exe
C:\Program Files\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Maxthon\Maxthon.exe
D:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe
C:\检查电脑的\HijackThis.exe

R3 - URLSearchHook: YOK Search Class - {88351CEF-BAC0-4A9B-8380-31A173E2926F} - C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe,,C:\WINDOWS\system32\UserModer.exe,C:\WINDOWS\system32\internt.exe
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v14.dll
O2 - BHO: (no name) - {0606EB86-92D6-4414-B463-6A0944AC1A80} - C:\WINDOWS\system32\Zantp.dll (file missing)
O2 - BHO: IEMonitor Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\Program Files\DeskAdTop\deskipn.dll
O2 - BHO: (no name) - {13014582-E73D-4B6F-9F1F-7119C59BC2DE} - C:\WINDOWS\system32\Keobbx.dll
O2 - BHO: (no name) - {21DA8B3F-A664-4584-9D57-7EA6587B513F} - C:\WINDOWS\system32\Seca.dll
O2 - BHO: (no name) - {25E7FC8D-AA55-4B47-A098-D5D8BC4D5C91} - C:\WINDOWS\system32\Zoki.dll
O2 - BHO: WinSearch - {27E96DE0-8211-42CF-9A1E-FA6246A95B77} - C:\WINDOWS\system32\winsearch.dll
O2 - BHO: IE Address Browser Helper - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:\Program Files\SearchNet\SNHpr.dll (file missing)
O2 - BHO: (no name) - {2A763EE1-73D4-4A18-BD0E-D886C3BBF376} - C:\WINDOWS\system32\Gqrmev.dll
O2 - BHO: (no name) - {2B255223-11E9-4D61-9AB7-F6271C3C6B65} - C:\WINDOWS\system32\Cndi.dll (file missing)
O2 - BHO: (no name) - {2C14F701-0908-4FF6-95D5-2BA212961B28} - C:\WINDOWS\system32\Bqjvs.dll (file missing)
O2 - BHO: (no name) - {30035B63-04DF-419D-9EE7-D0B85FBF234A} - C:\WINDOWS\system32\Yjrci.dll
O2 - BHO: (no name) - {318DEC01-C3B5-4625-A9CD-30E3E18DBD5D} - C:\WINDOWS\system32\Csbmml.dll
O2 - BHO: (no name) - {31AB4C86-12FC-42E7-B213-B6266E586843} - C:\WINDOWS\system32\Hxijh.dll (file missing)
O2 - BHO: (no name) - {3B99FF35-E6AD-4302-9D29-D57059355BE6} - C:\WINDOWS\system32\Hbkyjn.dll
O2 - BHO: (no name) - {3BFD9E44-CCC0-47B1-B130-E4ED8E7ED7DF} - C:\WINDOWS\system32\Mghv.dll
O2 - BHO: IE Browser Helper - {3CE496D1-1746-41CD-9489-3C0B93DF10E2} - C:\WINDOWS\Downlo~1\e9o3g.dll
O2 - BHO: (no name) - {403EC0F0-3954-4783-B01D-56783AA71EF5} - C:\WINDOWS\system32\Lnpdyc.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O2 - BHO: (no name) - {419D4E5B-3F38-44D7-B0AE-FE6531C22094} - C:\WINDOWS\system32\Odpgh.dll (file missing)
O2 - BHO: (no name) - {43C5A803-34EE-47E1-8FB4-3C7577042EDB} - C:\WINDOWS\system32\Oodq.dll (file missing)
O2 - BHO: (no name) - {4451C1C2-BBED-44B1-8F21-61E3C43479AE} - C:\WINDOWS\system32\Tlqy.dll (file missing)
O2 - BHO: (no name) - {44AC9A57-A7A3-404E-B642-8011D9BBEA26} - C:\WINDOWS\system32\Ztrcd.dll
O2 - BHO: (no name) - {464B2CB7-23F8-4EE6-8F0F-2998E490DE5C} - C:\WINDOWS\system32\Bazri.dll
O2 - BHO: (no name) - {49BDE454-223E-4D22-BC8D-ADE4BFD08FAE} - C:\WINDOWS\system32\Mbusb.dll (file missing)
O2 - BHO: (no name) - {4E0BBDB5-ED95-412C-A13F-A4BD1D0CDDE7} - C:\WINDOWS\system32\Tkrvwr.dll
O2 - BHO: (no name) - {4F7891FB-BFF5-4AD3-A255-4F898A30E9FF} - C:\WINDOWS\system32\Ivvdnm.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: (no name) - {5C1C1F28-E0DA-491E-A642-3D0AA61F9F33} - C:\WINDOWS\system32\Nzqlh.dll
O2 - BHO: (no name) - {61F23B3D-B3C0-4AE0-9506-EDC091FB61E1} - C:\WINDOWS\system32\Rpbut.dll (file missing)
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL (file missing)
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O2 - BHO: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: (no name) - {736982C8-E07A-4AFD-B6BD-23EDF1DC6210} - C:\WINDOWS\system32\Jtptb.dll
O2 - BHO: 珊瑚虫工具栏 - {75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688} - C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll
O2 - BHO: (no name) - {77265D4B-8CD8-4FAB-94D8-EC098B456501} - C:\WINDOWS\system32\Gcvu.dll (file missing)
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: bg - {7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} - C:\Program Files\baigoo\BGooBHO.dll
O2 - BHO: (no name) - {865997BA-9E4D-45C6-B88C-AD106E54DF8F} - C:\WINDOWS\system32\Zhlwte.dll (file missing)
最后编辑2006-08-10 11:15:56
分享到:
gototop
 

O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll
O2 - BHO: (no name) - {8B7C4AAD-E960-4493-9268-E50443F9B8FC} - C:\WINDOWS\system32\Nisdom.dll
O2 - BHO: (no name) - {8C6870A8-CFD2-46F3-B4E3-A1FB6F1944FD} - C:\WINDOWS\system32\Jsoqvd.dll (file missing)
O2 - BHO: (no name) - {8DEB869C-C258-402D-B061-5BCF37F37CF3} - C:\WINDOWS\system32\Yykyic.dll (file missing)
O2 - BHO: (no name) - {A1D30A82-E8BA-492D-AB6E-75D204CBF72C} - C:\WINDOWS\system32\Ssgirr.dll (file missing)
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {B0588633-3E40-41CA-BAB7-45982F9A6F03} - C:\WINDOWS\system32\Mpuns.dll (file missing)
O2 - BHO: (no name) - {B3A4D461-B076-4158-BB19-521FEE029048} - C:\WINDOWS\system32\Eywsw.dll (file missing)
O2 - BHO: (no name) - {C1D88B37-516C-49CB-8F4C-5175A599D851} - C:\WINDOWS\system32\Zauy.dll
O2 - BHO: (no name) - {DE0717F0-61FF-4D39-A39C-D3FB40E2D19C} - C:\WINDOWS\system32\Qtzuzd.dll (file missing)
O2 - BHO: (no name) - {E33F5037-B189-4711-8FE3-0BEBBADCAE9D} - C:\WINDOWS\system32\Yrouff.dll (file missing)
O2 - BHO: (no name) - {E5FE633F-05F9-4696-919A-0093BE851D3E} - C:\WINDOWS\system32\Esnsjz.dll (file missing)
O2 - BHO: (no name) - {E85889F1-DE38-4777-8B02-AF2873D3E387} - C:\WINDOWS\system32\Wwcqex.dll (file missing)
O2 - BHO: (no name) - {EC5A217F-3995-42C6-8AD3-6937FC7CCA90} - C:\WINDOWS\system32\Wbdjph.dll (file missing)
O2 - BHO: (no name) - {F9DBE561-BEED-43C2-A96A-B0A6FF153248} - C:\WINDOWS\system32\Nflywb.dll (file missing)
O2 - BHO: (no name) - {FE3CC913-01B1-478D-8B9F-FA41D5373B52} - C:\WINDOWS\system32\Wnjqmf.dll (file missing)
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: 珊瑚虫工具栏 - {F869BB38-FFEF-4589-B986-610B7AD0ADA2} - C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll
O3 - Toolbar: (no name) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - (no file)
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Desktop] C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll
O4 - HKLM\..\Run: [hijskp9i] RunDll32 "C:\WINDOWS\Downlo~1\hijskp9i.dll",Run
O4 - HKLM\..\Run: [YOKAssiant] Rundll32.exe C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll,YOKAssiant
O4 - HKLM\..\Run: [Mysee Alert] "C:\Program Files\GAOV\Mysee Alert\Mysee Alert.exe" -notray
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [bgoomain.exe] C:\PROGRA~1\baigoo\bgoomain.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item:  >> 彩信发送 << - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
O8 - Extra context menu item: &使用迅雷下载 - D:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: >>彩信发送<< - res://C:\PROGRA~1\MMSASS~1\mmsass~1.dll/mms.htm
O8 - Extra context menu item: Google 搜索(&G) - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用KuGoo3下载(&K) - D:\Program Files\KuGoo3\KuGoo3DownX.htm
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\绿色软件\网际快车(FlashGet) v1.65 美化特别版\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\绿色软件\网际快车(FlashGet) v1.65 美化特别版\jc_all.htm
O8 - Extra context menu item: 反向链接 - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 珊瑚虫搜索 - C:\Program Files\YOK.com\SuperSearch\yoksch.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 类似网页 - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: 缓存的网页快照 - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: 翻译英文字词(&T) - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: 豪杰超级解霸V8实时播放 - C:\Herosoft\HeroV8\MPURLGET.HTM
O8 - Extra context menu item: 雅虎搜索 - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O9 - Extra button: 游一游 - {29269350-EC07-4274-821F-F2E0E2697149} - http://act.youyy.com/YoyyLink.html (file missing)
O9 - Extra button: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra 'Tools' menuitem: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra button: JUJU猫 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.jujumao.net (file missing)
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - Extra 'Tools' menuitem: 彩E精灵设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - Extra button: 酷热影音 - {7D73FF86-05F1-39ed-C850-A423120EC338} - www.kuree.com/index.htm?id=00011001 (file missing)
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F72C95B5-37EB-4687-BE7A-65E2E22FAEA0}: NameServer = 202.100.192.68
O21 - SSODL: SysTime - {724C75F1-B757-408D-A50A-4CF99DA35D73} - C:\PROGRA~1\WinKld\WinKld.dll
O23 - Service: Automatic_Updates (AppMgmt_) - Unknown owner - C:\WINDOWS\NeroCheck.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Routing and Remote SqlServer (Remote SQL) - Unknown owner - C:\WINDOWS\system32\su.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: WinWrCup - MsWinCup - C:\WINDOWS\wincup\wincup.exe
gototop
 

O4 - HKLM\..\Run: [hijskp9i] RunDll32 "C:\WINDOWS\Downlo~1\hijskp9i.dll",Run
O23 - Service: WinWrCup - MsWinCup - C:\WINDOWS\wincup\wincup.exe
清理流氓软件,你的系统垃圾太多,建议你重装,修复已经没有多大意义
gototop
 

建议你下载超级兔子。
http://www.pctutu.com/srmsdown.asp
病毒N多 能杀就杀 不能就按楼上的做 另外修复所有(file missing)
和(no name)项
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT