瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 每次启动都可以杀出的内存病毒,为何…………

12   1  /  2  页   跳转

每次启动都可以杀出的内存病毒,为何…………

每次启动都可以杀出的内存病毒,为何…………

每次启动系统都可以杀出来一个内存病毒,但是全盘杀毒数次,都找不到病毒源,请问怎么解决?

附件附件:

下载次数:167
文件类型:application/octet-stream
文件大小:
上传时间:2006-11-5 16:35:20
描述:



最后编辑2006-11-08 09:09:30
分享到:
gototop
 

图片2

附件附件:

下载次数:164
文件类型:application/octet-stream
文件大小:
上传时间:2006-11-5 16:37:06
描述:



gototop
 

是灰鸽子...瑞星应该有专杀工具的......
gototop
 

...参考别人的帖子````上传个日志``
gototop
 

鸽子,扫个日志贴上来
gototop
 

请告知日志软件的下载方位 谢谢
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 10:39:37, on 2006-11-6
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
d:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
d:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
d:\Program Files\Rising\Rav\RavStub.exe
D:\Program Files\Rising\Rav\RavTask.exe
D:\Program Files\Rising\Rav\Ravmon.exe
C:\Program Files\R_server\R_server.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\nvsvc32.exe
c:\p2pplayer\pullservice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
d:\Program Files\Thunder Network\ThunderMini\program\ThunderMini.exe
D:\Program Files\dzh\internet\hypwise.exe
D:\Program Files\dzh\internet\hypmain.exe
d:\Program Files\Tencent\QQ\QQ.exe
E:\TDDownload\绿色免安装\QQ保姆\QQPetNurse.exe
d:\Program Files\Tencent\QQ\TIMPlatform.exe
d:\Program Files\Tencent\QQ\QQ.exe
d:\Program Files\Tencent\QQ\QQ.exe
d:\Program Files\Tencent\QQ\qqpet\qqpet.exe
d:\Program Files\Tencent\QQ\qqpet\qqpet.exe
d:\Program Files\Tencent\QQ\qqpet\qqpet.exe
d:\Program Files\Maxthon\Maxthon.exe
C:\Documents and Settings\Administrator\桌面\ha_hijackthis_1991(1)\HijackThis.exe

O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - d:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - d:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll
O2 - BHO: ThunderMiniBHO - {8E6C1C49-F9CE-4311-9FB4-D70E8B0AEAEB} - d:\Program Files\Thunder Network\ThunderMini\ComDlls\XunLeiMiniBHO_001.dll
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX
O4 - HKLM\..\Run: [RavTask] "d:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [远程协助] C:\Program Files\R_server\R_server.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\RunOnce: [RavStub] "d:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &使用迷你迅雷下载 - d:\Program Files\Thunder Network\ThunderMini\Program\GetUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用KuGoo3下载(&K) - D:\Program Files\KuGoo3\KuGoo3DownX.htm
O8 - Extra context menu item: 使用迅雷下载 - d:\Program Files\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: 使用迅雷下载全部链接 - d:\Program Files\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 把图片收藏到好网角 - C:\Program Files\wang1314\wang1314pic.html
O8 - Extra context menu item: 收藏此页到好网角收藏夹 - C:\Program Files\wang1314\wang1314.html
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 添加到广告杀手 - d:\Program Files\TweakAssist\AdKiller.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - D:\Program Files\BitSpirit\bsurl.htm
O9 - Extra button: JUJU猫 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.jujumao.com (file missing)
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - d:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - d:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: 时尚精品,体验快感 - {6E5EECAF-8879-4a75-8A88-B44B6382A763} - http://adfarm.mediaplex.com/ad/ck/4080-22910-9640-290?cn=chaoyue;site;hp&mpro=http://www.ebay.com.cn (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: 易趣购物 - {6E5EECAF-8879-4a75-8A88-B44B6382A763} - http://adfarm.mediaplex.com/ad/ck/4080-22910-9640-290?cn=chaoyue;site;hp&mpro=http://www.ebay.com.cn (file missing) (HKCU)
O17 - HKLM\System\CCS\Services\Tcpip\..\{6E87CFB7-0B19-4D94-A938-AB1E120A5C05}: NameServer = 219.150.150.150,219.150.32.132
O17 - HKLM\System\CS1\Services\Tcpip\..\{6E87CFB7-0B19-4D94-A938-AB1E120A5C05}: NameServer = 219.150.150.150,219.150.32.132
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PullService - Unknown owner - c:\p2pplayer\pullservice.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - d:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - d:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Network Management Center Time (W32Times) - Unknown owner - C:\WINDOWS\system32\timeman32.exe
gototop
 

安全模式下,检查系统漏洞,打上补丁,最后用杀毒软件杀毒,不行就用专杀。楼上说是鸽子病毒(本人没中过啊。。。。少有研究)那就试试吧。
gototop
 

用金山也杀了,杀不出病毒,,晕 

系统已经补丁打到顶勒
gototop
 

修复
O23 - Service: Network Management Center Time (W32Times) - Unknown owner - C:\WINDOWS\system32\timeman32.exe

删除C:\WINDOWS\system32\timeman32.exe
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT