瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【紧急求助】请问各位电脑高手:“00025832.dll”是个什么病毒?

1   1  /  1  页   跳转

【紧急求助】请问各位电脑高手:“00025832.dll”是个什么病毒?

【紧急求助】请问各位电脑高手:“00025832.dll”是个什么病毒?

是用瑞星查到的,显示的病毒名为:“backdoor.win32.pcclient.ci”感染的是C:\WINDOWS\system32目录下的00025832.dll文件,把这个文件删除之后,下次开机时还会自动出来一个。

    要怎样才能彻底删除掉啊?向各位高手求助!

    下边是我用HijackThis扫描到的结果,请高手们帮忙看一下。

Logfile of HijackThis v1.99.1
Scan saved at 17:28:24, on 2005-9-2
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\svchost.exe
C:\Program Files\racer-henan-cnc\racer.exe
C:\Program Files\racer-henan-cnc\RacerKp.exe
C:\Program Files\Maxthon\Maxthon.exe
D:\下载\gg\hijackthis\HijackThis.exe

O3 - Toolbar: (no name) - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - (no file)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\绿躺色软砑件\网际士快靱~1.65\fgiebar.dll (file missing)
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\Windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\qq\SendMMS.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1122602867968
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1122603075609
O20 - Winlogon Notify: igfxcui - C:\Windows\SYSTEM32\igfxsrvc.dll
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: Messenger - Unknown owner - C:\Windows\system32\wow.exe (file missing)
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

最后编辑2005-09-02 18:18:21
分享到:
gototop
 

安全模式下杀毒看看
gototop
 

在安全模式下杀掉之后,再次开机病毒还是会出现
gototop
 

修复
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
gototop
 

偶去试试看
gototop
 

还是不行,请教超级专家来帮忙解决
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT