1   1  /  1  页   跳转

高手求俺 附日志

高手求俺 附日志

最近两天被病毒搞头晕了,下面是我的日志,望高手指点
  Logfile of HijackThis v1.99.1
Scan saved at 19:39:41, on 2007-1-11
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\瑞星杀毒\Rising\Rising\Rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
D:\瑞星杀毒\Rising\Rising\Rfw\RfwMain.exe
C:\Program Files\Rising\AntiSpyware\runiep.exe
C:\WINDOWS\winlog0n.exe
C:\WINDOWS\iexpiore.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\conime.exe
D:\解压winrar\WinRAR.exe
C:\DOCUME~1\du\LOCALS~1\Temp\Rar$EX00.164\HijackThis.exe

F2 - REG:system.ini: UserInit=userinit.exe,
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [runeip] C:\Program Files\Rising\AntiSpyware\runiep.exe
O4 - HKLM\..\Run: [zts2] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\zts2.exe
O4 - HKLM\..\Run: [1e8emu4cuimu1hg] C:\WINDOWS\winlog0n.exe
O4 - HKLM\..\Run: [hkyqu2u3ebiejfb] C:\WINDOWS\iexpiore.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=about:blank
O20 - AppInit_DLLs: 914847M.BMP
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - D:\瑞星杀毒\Rising\Rising\Rfw\rfwsrv.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\瑞星杀毒\Rising\Rav\Ravmond.exe

最后编辑2007-01-11 20:15:44
分享到:
gototop
 

C:\WINDOWS\winlog0n.exe
C:\WINDOWS\iexpiore.exe
C:\WINDOWS\System32\conime.exe
O4 - HKLM\..\Run: [zts2] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\zts2.exe
O4 - HKLM\..\Run: [1e8emu4cuimu1hg] C:\WINDOWS\winlog0n.exe
O4 - HKLM\..\Run: [hkyqu2u3ebiejfb] C:\WINDOWS\iexpiore.exe
删除,可能还有问题
gototop
 

勾选修复:

O4 - HKLM\..\Run: [zts2] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\zts2.exe
O4 - HKLM\..\Run: [1e8emu4cuimu1hg] C:\WINDOWS\winlog0n.exe
O4 - HKLM\..\Run: [hkyqu2u3ebiejfb] C:\WINDOWS\iexpiore.exe
O20 - AppInit_DLLs: 914847M.BMP

安全模式,用killbox删除:
C:\WINDOWS\914847M.BMP
C:\WINDOWS\winlog0n.exe
C:\WINDOWS\iexpiore.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp--清空这个文件夹

然后贴SR日志上来
gototop
 

C:\WINDOWS\System32\conime.exe
高歌猛进,这个是什么?
gototop
 

【回复“yqlikaka”的帖

输入法编辑器
gototop
 

O,学习ING
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT