12   1  /  2  页   跳转

帮我看看日志有问题吗?

帮我看看日志有问题吗?

Logfile of HijackThis v1.99.1
Scan saved at 23:40:30, on 2005-8-31
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\木马绝杀\killer.exe
C:\WINDOWS\System32\msupdate32.exe
C:\KAV6\KAVSVC.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\DFVSX\DFVSX.exe
C:\WINDOWS\mousesync.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\TIMPlatform.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\FlashGet\flashget.exe
C:\Program Files\shanda\泡泡堂\CA.exe
E:\HijackThis.exe

O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [木马绝杀] C:\Program Files\木马绝杀\killer.exe -min
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [microsft Updates] msupdate32.exe
O4 - HKLM\..\RunServices: [microsft Updates] msupdate32.exe
O8 - Extra context menu item: 使用网际快车下载 - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O11 - Options group: [!CNS]  网络实名
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125409128828
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2F10976-D985-4022-B388-8DFC9383E226}: NameServer = 202.96.104.16 202.96.104.26
O23 - Service: Kingsoft AntiVirus Service (KAVSvc) - kingsoft Antivirus - C:\KAV6\KAVSVC.EXE
O23 - Service: Microsoft Windows Service - Unknown owner - C:\WINDOWS\mousesync.exe
O23 - Service: Norton AntiVirus 自动防护服务 (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)

最后编辑2005-09-01 21:25:10
分享到:
gototop
 

【回复“luliang09”的帖子】
晚上好。
终止进程:
C:\WINDOWS\System32\msupdate32.exe
C:\WINDOWS\mousesync.exe
修复:
O4 - HKLM\..\Run: [microsft Updates] msupdate32.exe
O4 - HKLM\..\RunServices: [microsft Updates] msupdate32.exe
O23 - Service: Microsoft Windows Service - Unknown owner - C:\WINDOWS\mousesync.exe。
删除:
C:\WINDOWS\System32\msupdate32.exe
C:\WINDOWS\mousesync.exe。
gototop
 

谢谢啦,现在应该没问题了吧?

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\木马绝杀\killer.exe
C:\Program Files\DFVSX\DFVSX.exe
C:\WINDOWS\System32\mshost.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\KAV6\KAVSVC.EXE
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\TIMPlatform.exe
C:\WINDOWS\System32\wuauclt.exe
E:\HijackThis.exe

O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [木马绝杀] C:\Program Files\木马绝杀\killer.exe -min
O4 - HKLM\..\Run: [MS-4011 Memory Patch] C:\Downloads\RavSasser.exe -Patch
O4 - HKLM\..\Run: [dfvsx] "C:\Program Files\DFVSX\DFVSX.exe" -Min
O4 - HKLM\..\Run: [Microsoft Client] mshost.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunServices: [Microsoft Client] mshost.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [Microsoft Client] mshost.exe
O4 - HKCU\..\RunServices: [Microsoft Client] mshost.exe
O8 - Extra context menu item: 使用网际快车下载 - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O11 - Options group: [!CNS]  网络实名
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125409128828
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2F10976-D985-4022-B388-8DFC9383E226}: NameServer = 202.96.104.16 202.96.104.26
O23 - Service: Kingsoft AntiVirus Service (KAVSvc) - kingsoft Antivirus - C:\KAV6\KAVSVC.EXE
O23 - Service: Norton AntiVirus 自动防护服务 (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)

gototop
 

【回复“luliang09”的帖子】
修复:
O4 - HKLM\..\Run: [Microsoft Client] mshost.exe
O4 - HKLM\..\RunServices: [Microsoft Client] mshost.exe
O4 - HKCU\..\Run: [Microsoft Client] mshost.exe
O4 - HKCU\..\RunServices: [Microsoft Client] mshost.exe
利用Windows自带的搜索功能找到mshost.exe并删除。
gototop
 

谢谢!!!!!!!现在没问题了吧,为什么我总是中病毒啊?
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\KAV6\KAVSVC.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\木马绝杀\killer.exe
C:\Program Files\DFVSX\DFVSX.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\TIMPlatform.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\HijackThis.exe

O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [木马绝杀] C:\Program Files\木马绝杀\killer.exe -min
O4 - HKLM\..\Run: [MS-4011 Memory Patch] C:\Downloads\RavSasser.exe -Patch
O4 - HKLM\..\Run: [dfvsx] "C:\Program Files\DFVSX\DFVSX.exe" -Min
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O8 - Extra context menu item: 使用网际快车下载 - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O11 - Options group: [!CNS]  网络实名
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125409128828
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2F10976-D985-4022-B388-8DFC9383E226}: NameServer = 202.96.104.16 202.96.104.26
O23 - Service: Kingsoft AntiVirus Service (KAVSvc) - kingsoft Antivirus - C:\KAV6\KAVSVC.EXE
O23 - Service: Norton AntiVirus 自动防护服务 (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)

gototop
 

lsass.exe
是病毒吗?
gototop
 

?
gototop
 

wdfmgr.exe 是病毒吗?
gototop
 

lsass - lsass.exe - 进程信息
进程文件: lsass 或者 lsass.exe


进程名称: Local Security Authority Service
 
进程名称: lsass.exe是一个系统进程,用于微软Windows系统的安全机制。它用于本地安全和登陆策略。
-----------------------------------------------------------
wdfmgr - wdfmgr.exe - 进程信息
进程文件: wdfmgr 或者 wdfmgr.exe
进程名称: Windows Driver Foundation Manager
 
描述:
wdfmgr.exe是微软Microsoft Windows media player 10播放器的一部分。该进程用于减少兼容性问题。
gototop
 

谢谢,在问一下
WINLOGON。EXE
SMSS。EXE
TIMPLATFORM。EXE
SPOOLSV。EXE
CSRSS。EXE
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT