瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求助:中毒重装系统后仍有许多病毒,而且会弹出许多莫明其妙的网页(附日志)

1   1  /  1  页   跳转

求助:中毒重装系统后仍有许多病毒,而且会弹出许多莫明其妙的网页(附日志)

求助:中毒重装系统后仍有许多病毒,而且会弹出许多莫明其妙的网页(附日志)

请高手帮忙看下日志,电脑先是中了毒,反复杀了很多次,每次杀毒都会显示已删除,但重新开机后仍然还有,重装系统后情况仍然存在,而且不管开不开IE,都会弹出什么关于脚本或者关于ACTIVEX控件的警告,还会弹出各种网页.请大家帮帮忙了,日志附后:
Logfile of HijackThis v1.99.1
Scan saved at 10:01:04, on 2006-10-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Samsung\SmarThru\PORTCTRL.EXE
C:\WINDOWS\command\rundll32.exe
C:\WINDOWS\Intel\rundll32.exe
C:\Program Files\Common Files\updat\Update.exe
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\PRINTV~1\pvmodule.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\WINDOWS\inf\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\Download\svhost32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\RUN32.EXE
C:\WINDOWS\system32\Svchost.exe
c:\program files\internet explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\00jx.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\svch0st.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\wuauclt.exe
c:\Program Files\Rising\Rav\CCenter.exe
c:\Program Files\Rising\Rav\RavTray.exe
c:\Program Files\Rising\Rav\RavTask.exe
c:\Program Files\Rising\Rav\RavService.exe
c:\Program Files\Rising\Rav\RsAgent.exe
C:\WINDOWS\Msagent\AGENTSVR.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Rising\Rav\Rav.exe
D:\Program Files\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.438\HijackThis.exe

O2 - BHO: (no name) - {049BE237-FC5F-4A1A-A667-92BAB5607D1E} - C:\WINDOWS\system32\addhelper.dll
O2 - BHO: AdPopup - {11F09AFD-75AD-4E51-AB43-E09E9351CE16} - C:\Program Files\Common Files\CPUSH\cpush.dll
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5156.dll (file missing)
O2 - BHO: raObject Class - {46F194EB-B7DB-4B7A-BD42-5FF39FD17664} - C:\PROGRA~1\pcast\hbcast.dll
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O2 - BHO: IEObject Class - {5F5422F7-7159-4CB6-BE7D-2C7EED492762} - C:\PROGRA~1\COMMON~1\yehoo\yehoo.dll
O2 - BHO: Spoolsv Class - {9C363D55-07D7-433d-A13E-D9C105202F6F} - C:\WINDOWS\system32\drivers\spoolsv.dll
O2 - BHO: XBTP03129 - {B07D1F6B-6B8C-4904-8EE8-5E5A2B4624B3} - C:\PROGRA~1\MICRSO~1\SEARCH~1.DLL (file missing)
O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~1\PRINTV~1\PRINTH~1.DLL
O2 - BHO: Windows Media Player - {FFFFFFFF-EEEE-EEEE-849E-8DF86E037512} - C:\WINDOWS\WinIEHelper.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [GW Port Controller] C:\Program Files\Samsung\SmarThru\PORTCTRL.EXE
O4 - HKLM\..\Run: [Tray] C:\WINDOWS\command\rundll32.exe
O4 - HKLM\..\Run: [rzt] C:\WINDOWS\Intel\rundll32.exe
O4 - HKLM\..\Run: [UpdateRun] C:\Program Files\Common Files\updat\Update.exe
O4 - HKLM\..\Run: [QuickSearch] C:\WINDOWS\system32\Rundll32.exe  "C:\PROGRA~1\COMMON~1\yehoo\yehoo.dll",WaitWindows
O4 - HKLM\..\Run: [PVModule] C:\PROGRA~1\PRINTV~1\pvmodule.exe
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [Ljx] C:\WINDOWS\inf\rundll32.exe
O4 - HKLM\..\Run: [RichMedia] C:\WINDOWS\system32\Rundll32.exe  "C:\PROGRA~1\pcast\hbcast.dll",WaitWindows
O4 - HKLM\..\Run: [xy] C:\WINDOWS\Download\svhost32.exe
O4 - HKLM\..\Run: [RavTray] "c:\Program Files\Rising\Rav\RavTray.exe"
O4 - HKLM\..\Run: [RavTask] "c:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SaveMail] C:\WINDOWS\system32\MSSOFT\\winampe.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O11 - Options group: [CDNCLIENT]  中文上网
O17 - HKLM\System\CCS\Services\Tcpip\..\{75FEDA13-EDEE-4863-9D4E-47847FE29955}: NameServer = 61.139.2.69
O20 - AppInit_DLLs: 608769M.BMP
O20 - Winlogon Notify: Control Panel - C:\WINDOWS\system32\bntsprx2.dll (file missing)
O23 - Service: Network Logons (NetWorkLogons) - Unknown owner - rundll32.exe (file missing)
O23 - Service: RavService - Unknown owner - c:\Program Files\Rising\Rav\RavService.exe" /service (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - c:\Program Files\Rising\Rav\CCenter.exe

最后编辑2006-10-23 11:07:08
分享到:
gototop
 

自己顶上去,高手帮忙看看吧,反正我自己都看到有些东西不正常,不过不晓得咋过删呀
gototop
 

C:\WINDOWS\inf\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\Download\svhost32.exe
C:\WINDOWS\SYSTEM32\RUN32.EXE
C:\WINDOWS\system32\Svchost.exe
O4 - HKCU\..\Run: [SaveMail] C:\WINDOWS\system32\MSSOFT\\winampe.exe
O4 - HKLM\..\Run: [Ljx] C:\WINDOWS\inf\rundll32.exe
O20 - AppInit_DLLs: 608769M.BMP
太多了……
gototop
 

这个手工可以删吗?还是怎么办?
gototop
 

C:\Program Files\Internet Explorer\00jx.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\svch0st.exe

漏了俩,先把这些搞掉,用超级兔子清理完注册表在扫个日志上来,建议直接格了算了……
gototop
 

格过了呀,重装了两遍了
gototop
 

那个该怎么删了,直接删不了,因为好像都是启动了的
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT