瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 那位高人帮帮我啊,我中了灰鸽子了,需要急救啊!!!这里有我的日志

1   1  /  1  页   跳转

那位高人帮帮我啊,我中了灰鸽子了,需要急救啊!!!这里有我的日志

那位高人帮帮我啊,我中了灰鸽子了,需要急救啊!!!这里有我的日志

这是我的日志,哪位高人能帮帮忙啊,我先谢了.帮帮忙吧!!!!



Logfile of HijackThis v1.99.1
Scan saved at 19:35:59, on 2005-11-5
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
E:\Thunder\Thunder.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\diskman.exe
E:\酷狗\KuGoo3\KuGoo.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\ZT\LOCALS~1\Temp\Rar$EX35.022\HijackThis.exe

O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v8.dll
O2 - BHO: BHO Class - {9A556B8F-FD02-420E-A1FD-9DB33808254E} - C:\WINDOWS\SePpBar\SeLineBar43505888.dll
O3 - Toolbar: 天天搜索(&T) - {102293E4-758B-4483-946B-714EBCEC91B8} - C:\WINDOWS\SePpBar\SeToolBar43505885.dll
O4 - HKLM\..\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [SeUpdateExe] C:\WINDOWS\SePpBar\SeUpdate4350588d.exe -sedutyvisit
O4 - HKLM\..\Run: [Update] C:\WINDOWS\system32\Update.exe
O4 - HKLM\..\Run: [Thunder] "E:\Thunder\ThunderShell.exe" /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [KuGoo3] "E:\酷狗\KuGoo3\KuGoo.exe"
O8 - Extra context menu item: &使用迅雷下载 - E:\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - E:\Thunder\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - E:\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\QQ\SendMMS.htm
O9 - Extra button: 天天搜索 - {102293E4-758B-4483-946B-714EBCEC91B8} - C:\WINDOWS\SePpBar\SeToolBar43505885.dll
O9 - Extra 'Tools' menuitem: 天天搜索 - {102293E4-758B-4483-946B-714EBCEC91B8} - C:\WINDOWS\SePpBar\SeToolBar43505885.dll
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E11EC2A6-F5D3-4D19-B8ED-FB060F6DD91A}: NameServer = 202.99.160.68 202.99.166.4
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - Service: Universal Disk Manager - Unknown owner - C:\WINDOWS\diskman.exe
最后编辑2005-11-07 17:59:24
分享到:
gototop
 

O23 - Service: Universal Disk Manager - Unknown owner - C:\WINDOWS\diskman.exe
鸽子
gototop
 

O23 - Service: Universal Disk Manager - Unknown owner - C:\WINDOWS\diskman.exe
1.开始-运行输入regedit,打开注册表编辑器,定位到HKEY_LOCAL_MACHINE\ SYSTEM \ CURRENTCONTROLSET \ SERVICES分支,删除左栏中的病毒服务名Universal Disk Manager
2.重启系统,在“文件夹选项”的“查看”面板中勾选“显示系统文件”、“显示所有的文件和文件夹”两项,点击“确定”按钮。然后在%windows%下寻找病毒文件名C:\WINDOWS\diskman.exe,C:\WINDOWS\diskman.dll,C:\WINDOWS\diskman_Hook.dll,C:\WINDOWS\diskmankey.dll,能找到的都删除
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT