瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 有截图,有日志,请帮助!来个专业的支援下啊!!!!!!!!!!!!!

1   1  /  1  页   跳转

有截图,有日志,请帮助!来个专业的支援下啊!!!!!!!!!!!!!

有截图,有日志,请帮助!来个专业的支援下啊!!!!!!!!!!!!!

特征:一打开IE,瑞星就提示杀毒,杀了毒后,再打开IE,仍然有,而且每开一个IE窗口,就提示杀了一次毒,不能彻底杀掉,怎么办啊~~~~~~~~~~~~~~~

在安全模式下用手动扫描,扫不出任何病毒。。。

有个兄弟说用“ewido anti-spyware ”,但是不知道为什么我的系统不能安装这个软件

二楼附日志

附件附件:

下载次数:138
文件类型:application/octet-stream
文件大小:
上传时间:2006-9-19 18:33:05
描述:



最后编辑2006-09-20 18:35:12
分享到:
gototop
 

2006-09-13,19:23:16

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows 98 SE -

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联


启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<internat.exe><internat.exe> [Microsoft Corporation]
<ScanRegistry><C:\WINDOWS\scanregw.exe /autorun> [Microsoft Corporation]
<TaskMonitor><C:\WINDOWS\taskmon.exe> [Microsoft Corporation]
<SystemTray><SysTray.Exe> [Microsoft Corporation]
<nwiz><nwiz.exe /install> [NVIDIA Corporation]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<NMGameX_AutoRun><C:\WINDOWS\Rundll32.exe NMGAMEX.DLL,LiveProcess /aa> []
<RavTask><"D:\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<RsCcenter><"D:\Rising\Rav\CCenter.exe"> [Beijing Rising Technology Co., Ltd.]
<RavMond><"D:\Rising\Rav\RavMond.exe"> [Beijing Rising Technology Co., Ltd.]
<RavMon><"D:\Rising\Rav\RavMon.exe" -system> [Beijing Rising Technology Co., Ltd.]

==================================
启动文件夹
服务

==================================
浏览器加载项
[DragSearch BHO]
{62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YDRAGS~1.DLL, N/A>
[MyIEHelper Class]
{16A770A0-0E87-4278-B748-2460D64A8386} <C:\WINDOWS\SYSTEM\IEHELPER_8888.DLL, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <D:\迅雷\迅雷\COMDLLS\XUNLEIBHO_002.DLL, Thunder Networking Technologies,LTD>
[WebThunder Browser Helper]
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <D:\迅雷\WEB迅雷\WEBTHUNDERBHO_013.DLL, Thunder Networking Technologies,LTD>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[启动迅雷]
{0062C9BD-B349-40DE-91A0-755F37ACD559} <D:\迅雷\迅雷\Thunder.exe, Thunder Networking Technologies,LTD>
[启动Web迅雷]
{962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH8B.OCX, Macromedia, Inc.>
[Update Class]
{9F1C11AA-197B-4942-BA54-47A8489BB47F} <C:\WINDOWS\SYSTEM\IUCTL.DLL, Microsoft Corporation>
[&使用迅雷下载]
<D:\迅雷\迅雷\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<D:\迅雷\迅雷\Program\GetAllUrl.htm, N/A>
[使用Web迅雷下载]
<D:\迅雷\WEB迅雷\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
<D:\迅雷\WEB迅雷\GetAllUrl.htm, N/A>
[添加到QQ自定义面板]
<F:\桌面\OICQ\AddPanel.htm, N/A>
[添加到QQ表情]
<F:\桌面\OICQ\AddEmotion.htm, N/A>
[上传到QQ网络硬盘]
<F:\桌面\OICQ\AddToNetDisk.htm, N/A>
[用QQ彩信发送该图片]
<F:\桌面\OICQ\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 4294923535][C:\WINDOWS\SYSTEM\MPREXE.EXE] <Microsoft Corporation><4.10.1998>
[PID: 4294931387][D:\RISING\RAV\CCENTER.EXE] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[D:\RISING\RAV\EXTOLE.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[D:\RISING\RAV\RSSTORE.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[D:\RISING\RAV\UNPACKER.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\RISING\RAV\SCANEXEC.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\RISING\RAV\SCANSCT.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[D:\RISING\RAV\SCANMAC.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[D:\RISING\RAV\NVFILE.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[D:\RISING\RAV\POSTTRT.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 15>
[D:\RISING\RAV\SCANEX.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
[D:\RISING\RAV\RSUNPACK.DLL] <Beijing Rising Technology Co., Ltd.><1, 0, 0, 13>
[D:\RISING\RAV\UNEXE.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\RISING\RAV\ENGINE.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 34>
[D:\RISING\RAV\SPAMENG.DLL] <N/A><18, 0, 0, 6>
[D:\RISING\RAV\MAILMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[D:\RISING\RAV\MEMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\RISING\RAV\HOOKWEB.DLL] <rising><18, 0, 0, 2>
[D:\RISING\RAV\REGMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[D:\RISING\RAV\VIRUSLIB.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
[D:\RISING\RAV\LIBLOAD.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[D:\RISING\RAV\SCANNER.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 32>
[D:\RISING\RAV\HOOKSYS.DLL] <Beijing Rising Technology Co., Ltd.><18, 1, 0, 11>
[D:\RISING\RAV\RSLOG.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
[D:\RISING\RAV\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\RISING\RAV\CFGDLL.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\RISING\RAV\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[D:\RISING\RAV\RSCOMMX.DLL] <rising><18, 0, 0, 1>
[PID: 4294929763][D:\RISING\RAV\RAVMOND.EXE] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 35>
[D:\RISING\RAV\BWLIST.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[D:\RISING\RAV\PNGDLL.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[D:\RISING\RAV\RSCOMMX.DLL] <rising><18, 0, 0, 1>
[D:\RISING\RAV\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\RISING\RAV\CFGDLL.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\RISING\RAV\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[PID: 4294888843][D:\RISING\RAV\RAVMON.EXE] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 33>
[D:\RISING\RAV\BWLIST.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[D:\RISING\RAV\RSGUILIB.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
gototop
 

[C:\PROGRAM FILES\WINRAR\RAREXT.DLL] <N/A><N/A>
[C:\WINDOWS\SYSTEM\RAVEXT.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[C:\WINDOWS\SYSTEM\NVCPL.DLL] <NVIDIA Corporation><4.14.10.6121>
[C:\WINDOWS\SYSTEM\OLEACC.DLL] <Microsoft Corporation><4.2.2209.0>
[C:\WINDOWS\SYSTEM\NVSHELL.DLL] <NVIDIA Corporation><4.14.10.6121>
[D:\RISING\RAV\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\迅雷\WEB迅雷\WEBTHUNDERBHO_013.DLL] <Thunder Networking Technologies,LTD><6, 0, 0, 4>
[D:\迅雷\迅雷\COMDLLS\XUNLEIBHO_002.DLL] <Thunder Networking Technologies,LTD><5, 0, 0, 2>
[C:\WINDOWS\SYSTEM\DHCPCSVC.DLL] <N/A><N/A>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4294802775][C:\WINDOWS\EXPLORER.EXE] <Microsoft Corporation><4.72.3110.1>
[PID: 4294799603][C:\WINDOWS\SYSTEM\RPCSS.EXE] <Microsoft Corporation><4.71.2900>
[PID: 4294718507][C:\WINDOWS\SYSTEM\INTERNAT.EXE] <Microsoft Corporation><4.10.2222>
[PID: 4294707979][C:\WINDOWS\TASKMON.EXE] <Microsoft Corporation><4.10.1998>
[PID: 4294716395][C:\WINDOWS\SYSTEM\SYSTRAY.EXE] <Microsoft Corporation><4.10.2222>
[D:\RISING\RAV\RSCOMMX.DLL] <rising><18, 0, 0, 1>
[D:\RISING\RAV\CFGDLL.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\RISING\RAV\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[D:\RISING\RAV\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 4294686699][D:\RISING\RAV\RAVTASK.EXE] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[PID: 4294622731][C:\WINDOWS\SYSTEM\WMIEXE.EXE] <Microsoft Corporation><5.00.1755.1>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\PROGRAM FILES\EFFICIENT NETWORKS\ENTERNET 300\APP\RESCHS.DLL] <Efficient Networks, Inc.><1, 5, 0, 18>
[PID: 4294579415][C:\PROGRAM FILES\EFFICIENT NETWORKS\ENTERNET 300\APP\ENTERNET.EXE] <N/A><N/A>
[C:\PROGRAM FILES\EFFICIENT NETWORKS\ENTERNET 300\APP\DSLAPI32.DLL] <Efficient Networks Inc.><1, 5, 0, 19>
[C:\PROGRAM FILES\EFFICIENT NETWORKS\ENTERNET 300\APP\PACKETLOG.DLL] <Efficient Networks, Inc.><1, 5, 0, 21>
[C:\PROGRAM FILES\EFFICIENT NETWORKS\ENTERNET 300\APP\RESMSGCHS.DLL] <Efficient Networks, Inc.><1, 5, 0, 18>
[C:\WINDOWS\SYSTEM\NVDD32.DLL] <NVidia Corporation><4.14.10.6121>
[C:\WINDOWS\SYSTEM\NVARCH32.DLL] <NVIDIA Corporation><4.14.10.6121>
[PID: 4294499395][C:\WINDOWS\SYSTEM\DDHELP.EXE] <Microsoft Corporation><4.09.00.0900>
[C:\WINDOWS\SYSTEM\RAVEXT.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[D:\迅雷\迅雷\COMDLLS\THUNDERAGENT_003.DLL] <Thunder Networking Technologies,LTD><1, 0, 0, 10>
[C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH8B.OCX] <Macromedia, Inc.><8,0,24,0>
[D:\RISING\RAV\RAVSCRCH.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\迅雷\WEB迅雷\WEBTHUNDERBHO_013.DLL] <Thunder Networking Technologies,LTD><6, 0, 0, 4>
[D:\迅雷\迅雷\COMDLLS\XUNLEIBHO_002.DLL] <Thunder Networking Technologies,LTD><5, 0, 0, 2>
[C:\WINDOWS\SYSTEM\IEHELPER_8888.DLL] <Microsoft Corporation><1, 2, 2, 0>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4294536127][C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE] <Microsoft Corporation><6.00.2800.1106>
[PID: 4294644191][C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE] <RealNetworks, Inc.><0.1.0.3510>
[D:\RISING\RAV\RAVSCRCH.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\迅雷\迅雷\PROGRAM\ITARGETAD.DLL] <Thunder Networking Technologies,LTD><1, 0, 1, 55>
[C:\WINDOWS\SYSTEM\RAVEXT.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[D:\迅雷\迅雷\COMPONENTS\P4PCLIENT\P4PCLIENT.DLL] <Thunder Networking Technologies,LTD><1, 0, 3, 8>
[D:\迅雷\迅雷\COMPONENTS\INMEDIA\IEMBED04.DLL] < ><2, 3, 0, 37>
[D:\迅雷\迅雷\COMPONENTS\INMEDIA\IEMBEDSHELL.DLL] < ><1, 0, 0, 11>
[D:\迅雷\迅雷\PROGRAM\FLOATBAR.DLL] <Thunder Networking Technologies,LTD><1, 0, 0, 2>
[D:\迅雷\迅雷\PROGRAM\REGISTERDLL.DLL] <Thunder Networking Technologies,LTD><2, 1, 0, 18>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4294375023][D:\迅雷\迅雷\PROGRAM\THUNDER5.EXE] <Thunder Networking Technologies,LTD><5.3.0.220>
[D:\迅雷\迅雷\PROGRAM\HISTORYINFO_MANAGE.DLL] <Thunder Networking Technologies,LTD><5, 2, 0, 148>
[D:\迅雷\迅雷\PROGRAM\MSGMANAGE.DLL] <Thunder Networking Technologies,LTD><1, 0, 0, 15>
[D:\迅雷\迅雷\PROGRAM\UPDATEDOWNLOAD.DLL] <Thunder Networking Technologies,LTD><1, 0, 1, 8>
[D:\迅雷\迅雷\PROGRAM\DOWNLOAD_INTERFACE.DLL] <Thunder Networking Technologies,LTD><1, 0, 4, 71>
[D:\迅雷\迅雷\PROGRAM\ASYN_DNS.DLL] <N/A><N/A>
[C:\WINDOWS\SYSTEM\DHCPCSVC.DLL] <N/A><N/A>
[D:\迅雷\迅雷\PROGRAM\LOG4CPLUS.DLL] < ><1, 0, 2, 1>
[D:\迅雷\迅雷\PROGRAM\STLPORT_VC646.DLL] <STLport Consulting, Inc.><4.6.2003.1031>
[PID: 4294452443][C:\WINDOWS\DESKTOP\新建文件夹\SRENG2\SRENG.EXE] <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [C:\WINDOWS\winhlp32.exe %1]
.INI OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS OK. [C:\WINDOWS\WScript.exe "%1" %*]
.JS OK. [C:\WINDOWS\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================

gototop
 

这么祥细都没人来分析下啊。。。。。
gototop
 

..............
gototop
 

搞不懂.
gototop
 

还是没反应。。。。。。。。。。。。。。。。
gototop
 

这里的贴怎么都是自己在顶...
gototop
 

我顶你个肺。。
gototop
 

参考一下本版的置顶贴,第2个关于IEhelp的
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT