瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】电脑中毒,无法关机,长按电源也关不掉,特求拯救,望高人留步,谢谢

12   1  /  2  页   跳转

【求助】电脑中毒,无法关机,长按电源也关不掉,特求拯救,望高人留步,谢谢

【求助】电脑中毒,无法关机,长按电源也关不掉,特求拯救,望高人留步,谢谢

电脑中毒,无法关机,长按电源也关不掉,只能关掉总电源开关.我是12月15号中的毒,当时用瑞星杀掉2个,在关机的时候,电脑就出现重启,每一次都这样,搞的精疲力尽,没有效果.26号再次升级查杀,又找到2个,以为没有什么事情了,为安全起见,又在安全模式下再次查杀了一遍.但在关机的时候,在次重启.特请高人指教,不胜感谢.

附件附件:

下载次数:0
文件类型:application/octet-stream
文件大小:
上传时间:2005-12-28 16:29:19
描述:



最后编辑2005-12-29 09:51:48
分享到:
gototop
 

日志显示:
Logfile of Kaka v2. 0. 0. 3 Scan Module v2. 0. 0. 1
Scan saved at 16:31:53, on 2005-12-28
Platform: Microsoft Windows XP Professional Service Pack 2 (Build 2600)
MSIE: Internet Explorer v6.00 SP2; (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))


Running processes:
[SMSS.EXE]
CommandLine =

[csrss.exe]
CommandLine = C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

[winlogon.exe]
CommandLine = winlogon.exe

[services.exe]
CommandLine = C:\WINDOWS\system32\services.exe

[lsass.exe]
CommandLine = C:\WINDOWS\system32\lsass.exe

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k NetworkService

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k LocalService

[CCenter.exe]
CommandLine = "C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE"

[spoolsv.exe]
CommandLine = C:\WINDOWS\system32\spoolsv.exe

[UrlService.exe]
CommandLine = "C:\Program Files\zsxz\UrlService.exe"

[rundll32.exe]
CommandLine = C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\STDSVER.DLL,Service

[SOUNDMAN.EXE]
CommandLine = "C:\WINDOWS\SOUNDMAN.EXE"

[realsched.exe]
CommandLine = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot

[fpdisp5a.exe]
CommandLine = "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" /source=HKLM

[BCUP.exe]
CommandLine = "C:\WINDOWS\system32\BCUP.exe"

[poiap.exe]
CommandLine = "C:\WINDOWS\system32\poiap.exe"

[RavTask.exe]
CommandLine = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM

[PigDesktopFile.exe]
CommandLine = E:\百度下吧\网络猪\PigDesktopFile.exe

[sysdm.exe]
CommandLine = "C:\PROGRA~1\sysdm\sysdm.exe"

[IEUrldrive.exe]
CommandLine = "C:\Program Files\zsxz\IEUrldrive.exe"

[NetSpeeder.exe]
CommandLine = "C:\Program Files\Superhunter\NetSpeeder\NetSpeeder.exe" hide

[ctfmon.exe]
CommandLine = "C:\WINDOWS\system32\ctfmon.exe"

[ALG.EXE]
CommandLine = C:\WINDOWS\System32\alg.exe

[Mrup.exe]
CommandLine = "C:\Program Files\DeskAdTop\Mrup.exe"

[rundll32.exe]
CommandLine =  C:\WINDOWS\SYSTEM32\stdup.dll,Entry

[EXPLORER.EXE]
CommandLine = C:\WINDOWS\explorer.exe

[RavMonD.exe]
CommandLine = "C:\Program Files\rising\Rav\Ravmond.exe"

[RavMon.exe]
CommandLine = "C:\Program Files\rising\Rav\RAVMON.EXE"

[RavStub.exe]
CommandLine = "C:\Program Files\rising\Rav\RavStub.exe" /RAVMOND

[iexplore.exe]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe"  -nohome

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k imgsvc

[KkScan.exe]
CommandLine = "C:\Program Files\rising\KakaToolBar\KkScan.exe"

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.skycn.com/
R3 - Default URLSearchHook is missing
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: 210.22.13.11  www.china-ph.com  #0
O1 - Hosts: 210.51.26.221  www.easysea.com  #0
O1 - Hosts: 211.100.255.38  matrix.hongen.com  #0
O1 - Hosts: 218.30.110.222  www.livingwater4u.com  #0
O1 - Hosts: 61.152.238.70  jonahome.org  #0
O1 - Hosts: 72.14.203.104  www.google.com  #0
O1 - Hosts: 61.142.80.164  www.zhuye123.com  #0
O1 - Hosts: 222.73.0.209  www.chinaz.com  #0
O1 - Hosts: 61.135.132.168  dir.online.sh.cn  #0
O1 - Hosts: 220.166.64.219  www.einsun.net  #0
O1 - Hosts: 218.5.72.37  www.is777.com  #0
O1 - Hosts: 211.147.7.182  www2.beareyes.com.cn  #0
O1 - Hosts: 61.135.132.38  act.it.sohu.com  #0
O1 - Hosts: 218.5.74.144  www.pcchong.com  #0
O1 - Hosts: 61.175.209.181  www.jdjys.com  #0
O1 - Hosts: 202.101.6.75  www.kuanye.net  #0
O1 - Hosts: 61.153.11.133  bbs.gospelfilm.com  #0
O1 - Hosts: 65.61.198.163  www.goodnewscom.org  #0
O1 - Hosts: 202.101.62.197  www.god123.cn  #0
O1 - Hosts: 61.153.11.133  61.153.11.133  #0
O1 - Hosts: 219.153.10.168  www.chineseliterature.com.cn  #0
O1 - Hosts: 66.221.25.180  cclw.net  #0
O1 - Hosts: 61.172.200.217  www.fuyinchina.com  #0
O1 - Hosts: 210.51.25.140  www.fuyin.com  #0
O1 - Hosts: 202.108.35.191  chwmc.vip.sina.com  #0
O1 - Hosts: 205.178.132.155  www.afcinc.org  #0
O1 - Hosts: 66.78.27.6  cannan.lingliang.org  #0
O1 - Hosts: 221.238.194.33  www.zschurch.com  #0
O1 - Hosts: 202.64.132.117  old.ccfellow.org  #0
O1 - Hosts: 210.51.168.9  www.51wish.com  #0
O1 - Hosts: 129.174.41.95  www.peter-liu.net  #0
O1 - Hosts: 60.190.66.22  www.loves7.com  #0
O1 - Hosts: 218.5.76.70  www.gospelfilm.com  #0
O1 - Hosts: 219.239.88.110  www.yesky.com  #0
O1 - Hosts: 61.135.129.205  www.ciw.com.cn  #0
O1 - Hosts: 202.108.22.5  www.baidu.com  #0
O1 - Hosts: 61.152.167.123  bbs.cfanclub.net  #0
O1 - Hosts: 220.194.52.20  bbs.cfan.com.cn  #0
O1 - Hosts: 202.108.59.242  www.cfan.com.cn  #0
O1 - Hosts: 61.222.216.100  www.junyoung.com.tw  #0
O1 - Hosts: 61.147.119.206  www.bt2005.com  #0
O1 - Hosts: 61.129.117.111  www.pcbookcn.com  #0
O1 - Hosts: 218.201.39.98  www.cpcfan.com  #0
O1 - Hosts: 202.106.195.2  www.cngetit.com  #0
O1 - Hosts: 218.246.32.223  www.cz88.net  #0
O1 - Hosts: 221.192.132.171  www.52vcd.com  #0
O1 - Hosts: 219.239.89.47  bbs.enet.com.cn  #0
O1 - Hosts: 211.100.33.38  kuho.mop.com  #0
O1 - Hosts: 210.188.203.12  bbs.100free.net  #0
O1 - Hosts: 61.135.158.237  tech.tom.com  #0
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v5.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\adobe acrobat reader\新文件夹\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo!Photo - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll (file missing)
O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll (file missing)
O2 - BHO: DragSearch BHO - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL (file missing)
O2 - BHO: MMSAssist BHO - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: CBHelper Object - {8A4280AD-9B37-4922-A51D-73F3C3A32AF7} - C:\WINDOWS\system32\msibm\cfsbho.dll
O2 - BHO: IeControler Class - {9AFD91F9-6B03-4D22-A1E1-67D224CB7AB1} - C:\Program Files\Superhunter\NetSpeeder\IEMate.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\flashget\FLASHGET\jccatch.dll
O2 - BHO: BrowserHAP Class - {AEF6F648-78D8-4456-BEE7-5ADE23D209FD} - C:\Program Files\HBClient\hapast.dll (file missing)
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - F:\影坝印〈传送痛带鳿\NetTransport 2\NTIEHelper.dll (file missing)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: WMHlprObj Class - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll (file missing)
O3 - Toolbar: 博采 - {4DA2EE61-6399-4C39-AEB9-0D990E610D29} - C:\WINDOWS\system32\BOCAIT~1.DLL
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\flashget\FLASHGET\fgiebar.dll
O3 - Toolbar: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - D:\jinshan\IEBand.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-
gototop
 

Page\EPSON Web-To-Page.dll
O3 - Toolbar:  (file missing)
O3 - Toolbar: 完美网译通 - {F43BD772-ABDD-43b7-A96A-3E9E61946EC0} - C:\WINDOWS\WORLD2\TOOLBAR\hmtoolbar.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [PigLocalSearch] E:\百度下吧\网络猪\PigStart.exe
O4 - HKLM\..\Run: [FinePrint 分配器 v5] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" /source=HKLM
O4 - HKLM\..\Run: [BCUpdate] C:\WINDOWS\system32\BCUP.exe
O4 - HKLM\..\Run: [poiap] C:\WINDOWS\system32\poiap.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [sysser] C:\PROGRA~1\sysdm\sysdm.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NetSpeeder] "C:\Program Files\Superhunter\NetSpeeder\NetSpeeder.exe" hide
O4 - Startup: desktop.ini =
O4 - Startup: 桌面媒体.lnk = C:\WINDOWS\system32\rundll32.exe
O4 - Global Startup: desktop.ini =
O8 - Extra context menu item:  >> 彩信发送 << - res://C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL/mms.htm
O8 - Extra context menu item: &使用下载加速专家下载 -
O8 - Extra context menu item: (&D)用中搜视频下载下载 - E:\百度下吧\zhu vedio\PICUI\piclink.htm
O8 - Extra context menu item: 使用影音传送带下载 - F:\影印传送带\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - F:\影印传送带\NetTransport 2\NTAddList.html
O8 - Extra context menu item: 使用网际快车下载 - D:\flashget\FLASHGET\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\flashget\FLASHGET\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\QQ\SendMMS.htm
O8 - Extra context menu item: 百度-搜索MP3 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUMP3.HTM
O8 - Extra context menu item: 百度-搜索图片 -
res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUIMG.HTM
O8 - Extra context menu item: 百度-搜索新闻 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUNEWS.HTM
O8 - Extra context menu item: 百度-搜索歌词 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDULYRIC.HTM
O8 - Extra context menu item: 百度-搜索网页 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUSEARCH.HTM
O8 - Extra context menu item: 百度-搜索贴吧 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUPOST.HTM
O8 - Extra context menu item: 百度-词典搜索 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDU_DIC.HTM
O8 - Extra context menu item: 访问通用网址 -
O8 - Extra context menu item: 豪杰超级解霸V8实时播放 - C:\Herosoft\HeroV8\MPURLGET.HTM
O9 - Extra Button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289}? - http://sms.3721.com/ie/index.htm?pid=U_skycn_5409 (file missing)
O9 - Extra Button: 免费精彩视频超流畅在线观看 - {022C4009-5283-4365-97BF-144054B40E2E} - http://itv.mop.com (file missing)
O9 - Extra 'Tools' menuitem: 播霸电视 - {022C4009-5283-4365-97BF-144054B40E2E} - http://itv.mop.com (file missing)
O9 - Extra Button: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll (file missing)
O9 - Extra 'Tools' menuitem: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll (file missing)
O9 - Extra Button: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra 'Tools' menuitem: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra Button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97}? - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra Button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26}? - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - Extra Button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338}? - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra Button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O9 - Extra 'Tools' menuitem: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O9 - Extra Button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\flashget\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\flashget\FLASHGET\flashget.exe
O9 - Extra Button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [!ANetSpeeder]  NetSpeeder
O11 - Options group: [CDNCLIENT]  中文上网
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O16 - DPF: DirectAnimation Java Classes - file://C:\WINDOWS\Java\classes\dajava.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2EA6D939-4445-43F1-A12B-8CB3DDA8B855} (BlueskyVideo Control) - http://www.bluesky.cn/download/v2_60.cab
O16 - DPF: {991481A7-4669-4E15-8C24-100404E1F5CB} (Blueskyvoice Control) - http://www.bluesky.cn/download/blueskyvoice_60.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - file://C:\Herosoft\HeroV8\DVDSkin\defskin\HTML\swflash.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/ravkill/rsonline.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FA7A96DF-6ECE-49D2-B150-9F6068D063F8}: NameServer = 202.99.224.8 202.99.224.68
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - C:\WINDOWS\wc98pp.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\system32\mbprot.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\System32\wiascr.dll
O23 - Service: Download Service (Download Service) -  - C:\WINDOWS\system32\seedserv.exe
O23 - Service: Event Client (Event Client) -  - C:\Program Files\zsxz\UrlService.exe
O23 - Service: Human Interface Device Access (HidServ) -  - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Local Network Service (Local Network Service) -  - C:\WINDOWS\system32\urlsrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) -  - "C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\rising\Rav\Ravmond.exe"
O23 - Service: StdService (StdService) -  - C:\WINDOWS\system32\rundll32.exe c:\windows\system32\stdsver.dll,service
gototop
 

接第1张图后面的路径

附件附件:

下载次数:0
文件类型:application/octet-stream
文件大小:
上传时间:2005-12-28 17:09:36
描述:



gototop
 

问题还挺多的,,,用下面的工具再扫一个上来~~
HijackThis V1.99.1汉化版下载及英文原版下载地址(二楼)
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
gototop
 

HijackThis_815汉化版扫描日志 V1.99.1
保存于      17:58:27, 日期 2005-12-28
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\zsxz\UrlService.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\WINDOWS\system32\BCUP.exe
C:\Program Files\rising\Rav\RavTask.exe
E:\百度下吧\网络猪\PigDesktopFile.exe
C:\PROGRA~1\sysdm\sysdm.exe
C:\Program Files\zsxz\IEUrldrive.exe
C:\Program Files\Superhunter\NetSpeeder\NetSpeeder.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DeskAdTop\Mrup.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\rising\Rav\Ravmond.exe
C:\Program Files\rising\Rav\RAVMON.EXE
C:\Program Files\rising\Rav\RavStub.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\rising\Rav\Rav.exe
F:\hijackthis\4842302005817230232\HijackThis1991zww.exe

R3 - 默认的URLSearchHook丢失。用HijackThis修复
O1 - Hosts: 210.22.13.11 www.china-ph.com #0
O1 - Hosts: 210.51.26.221 www.easysea.com #0
O1 - Hosts: 211.100.255.38 matrix.hongen.com #0
O1 - Hosts: 218.30.110.222 www.livingwater4u.com #0
O1 - Hosts: 61.152.238.70 jonahome.org #0
O1 - Hosts: 72.14.203.104 www.google.com #0
O1 - Hosts: 61.142.80.164 www.zhuye123.com #0
O1 - Hosts: 222.73.0.209 www.chinaz.com #0
O1 - Hosts: 61.135.132.168 dir.online.sh.cn #0
O1 - Hosts: 220.166.64.219 www.einsun.net #0
O1 - Hosts: 218.5.72.37 www.is777.com #0
O1 - Hosts: 211.147.7.182 www2.beareyes.com.cn #0
O1 - Hosts: 61.135.132.38 act.it.sohu.com #0
O1 - Hosts: 218.5.74.144 www.pcchong.com #0
O1 - Hosts: 61.175.209.181 www.jdjys.com #0
O1 - Hosts: 202.101.6.75 www.kuanye.net #0
O1 - Hosts: 61.153.11.133 bbs.gospelfilm.com #0
O1 - Hosts: 65.61.198.163 www.goodnewscom.org #0
O1 - Hosts: 202.101.62.197 www.god123.cn #0
O1 - Hosts: 61.153.11.133 61.153.11.133 #0
O1 - Hosts: 219.153.10.168 www.chineseliterature.com.cn #0
O1 - Hosts: 66.221.25.180 cclw.net #0
O1 - Hosts: 61.172.200.217 www.fuyinchina.com #0
O1 - Hosts: 210.51.25.140 www.fuyin.com #0
O1 - Hosts: 202.108.35.191 chwmc.vip.sina.com #0
O1 - Hosts: 205.178.132.155 www.afcinc.org #0
O1 - Hosts: 66.78.27.6 cannan.lingliang.org #0
O1 - Hosts: 221.238.194.33 www.zschurch.com #0
O1 - Hosts: 202.64.132.117 old.ccfellow.org #0
O1 - Hosts: 210.51.168.9 www.51wish.com #0
O1 - Hosts: 129.174.41.95 www.peter-liu.net #0
O1 - Hosts: 60.190.66.22 www.loves7.com #0
O1 - Hosts: 218.5.76.70 www.gospelfilm.com #0
O1 - Hosts: 219.239.88.110 www.yesky.com #0
O1 - Hosts: 61.135.129.205 www.ciw.com.cn #0
O1 - Hosts: 202.108.22.5 www.baidu.com #0
O1 - Hosts: 61.152.167.123 bbs.cfanclub.net #0
O1 - Hosts: 220.194.52.20 bbs.cfan.com.cn #0
O1 - Hosts: 202.108.59.242 www.cfan.com.cn #0
O1 - Hosts: 61.222.216.100 www.junyoung.com.tw #0
O1 - Hosts: 61.147.119.206 www.bt2005.com #0
O1 - Hosts: 61.129.117.111 www.pcbookcn.com #0
O1 - Hosts: 218.201.39.98 www.cpcfan.com #0
O1 - Hosts: 202.106.195.2 www.cngetit.com #0
O1 - Hosts: 218.246.32.223 www.cz88.net #0
O1 - Hosts: 221.192.132.171 www.52vcd.com #0
O1 - Hosts: 219.239.89.47 bbs.enet.com.cn #0
O1 - Hosts: 211.100.33.38 kuho.mop.com #0
O1 - Hosts: 210.188.203.12 bbs.100free.net #0
O1 - Hosts: 61.135.158.237 tech.tom.com #0
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v5.dll
O2 - BHO: Target Class - {002AF282-E42D-4B51-9F70-F1570C02FAAD} - C:\Program Files\NetMeting\Target\Target.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\adobe acrobat reader\新文件夹\ActiveX\AcroIEHelper.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll (file missing)
O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll (file missing)
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL (file missing)
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: BHelper - {8A4280AD-9B37-4922-A51D-73F3C3A32AF7} - C:\WINDOWS\system32\msibm\cfsbho.dll
O2 - BHO: IeControler Class - {9AFD91F9-6B03-4D22-A1E1-67D224CB7AB1} - C:\Program Files\Superhunter\NetSpeeder\IEMate.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\flashget\FLASHGET\jccatch.dll
O2 - BHO: BrowserHAP Class - {AEF6F648-78D8-4456-BEE7-5ADE23D209FD} - C:\Program Files\HBClient\hapast.dll (file missing)
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - F:\影坝印〈传送痛带鳿\NetTransport 2\NTIEHelper.dll (file missing)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: WMHlprObj Class - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll (file missing)
O3 - IE工具栏增项: 博采 - {4DA2EE61-6399-4C39-AEB9-0D990E610D29} - C:\WINDOWS\system32\BOCAIT~1.DLL
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\flashget\FLASHGET\fgiebar.dll
O3 - IE工具栏增项: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - D:\jinshan\IEBand.dll
O3 - IE工具栏增项: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - IE工具栏增项: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
O3 - IE工具栏增项: 完美网译通 - {F43BD772-ABDD-43b7-A96A-3E9E61946EC0} - C:\WINDOWS\WORLD2\TOOLBAR\hmtoolbar.dll
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [PigLocalSearch] E:\百度下吧\网络猪\PigStart.exe
O4 - 启动项HKLM\\Run: [FinePrint 分配器 v5] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" /source=HKLM
O4 - 启动项HKLM\\Run: [BCUpdate] C:\WINDOWS\system32\BCUP.exe
O4 - 启动项HKLM\\Run: [poiap] C:\WINDOWS\system32\poiap.exe
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [sysser] C:\PROGRA~1\sysdm\sysdm.exe
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - 启动项HKLM\\Run: [NetSpeeder] "C:\Program Files\Superhunter\NetSpeeder\NetSpeeder.exe" hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: 桌面媒体.lnk = C:\WINDOWS\system32\rundll32.exe
O8 - IE右键菜单中的新增项目:  >> 彩信发送 << - res://C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL/mms.htm
O8 - IE右键菜单中的新增项目: (&D)用中搜视频下载下载 - E:\百度下吧\zhu vedio\PICUI\piclink.htm
O8 - IE右键菜单中的新增项目: 使用影音传送带下载 - F:\影印传送带\NetTransport 2\NTAddLink.html
O8 - IE右键菜单中的新增项目: 使用影音传送带下载全部链接 - F:\影印传送带\NetTransport 2\NTAddList.html
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - D:\flashget\FLASHGET\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - D:\flashget\FLASHGET\jc_all.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\QQ\SendMMS.htm
O8 - IE右键菜单中的新增项目: 百度-搜索MP3 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUMP3.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索图片 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUIMG.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索新闻 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUNEWS.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索歌词 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDULYRIC.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索网页 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUSEARCH.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索贴吧 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUPOST.HTM
O8 - IE右键菜单中的新增项目: 百度-词典搜索 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDU_DIC.HTM
O8 - IE右键菜单中的新增项目: 豪杰超级解霸V8实时播放 - C:\Herosoft\HeroV8\MPURLGET.HTM
gototop
 

HJ版本太旧了,http://forum.ikaka.com/topic.asp?board=28&artid=6979213去这个贴子一楼下最新的再扫~
gototop
 

C:\Program Files\zsxz\UrlService.exe
C:\WINDOWS\system32\BCUP.exe
C:\WINDOWS\system32\poiap.exe
E:\百度下吧\网络猪\PigDesktopFile.exe
C:\PROGRA~1\sysdm\sysdm.exe
C:\Program Files\zsxz\IEUrldrive.exe
C:\Program Files\DeskAdTop\Mrup.exe
C:\WINDOWS\SYSTEM32\stdup.dll,
这是你正运行中的能看到的有问题的进程~~~



所有的01项~~~
O2 - BHO: MMSAssist BHO - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: CBHelper Object - {8A4280AD-9B37-4922-A51D-73F3C3A32AF7} - C:\WINDOWS\system32\msibm\cfsbho.dll
O2 - BHO: IeControler Class - {9AFD91F9-6B03-4D22-A1E1-67D224CB7AB1} - C:\Program Files\Superhunter\NetSpeeder\IEMate.dll

O4 - HKLM\..\Run: [BCUpdate] C:\WINDOWS\system32\BCUP.exe
O4 - HKLM\..\Run: [poiap] C:\WINDOWS\system32\poiap.exe
O4 - HKLM\..\Run: [PigLocalSearch] E:\百度下吧\网络猪\PigStart.exe
O4 - HKLM\..\Run: [sysser] C:\PROGRA~1\sysdm\sysdm.exe

O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\system32\mbprot.dll

O23 - Service: Event Client (Event Client) - - C:\Program Files\zsxz\UrlService.exe
O23 - Service: Local Network Service (Local Network Service) - - C:\WINDOWS\system32\urlsrv.exe

O23 - Service: StdService (StdService) - - C:\WINDOWS\system32\rundll32.exe c:\windows\system32\stdsver.dll,service
以上的项都有问题~~~(先结束上面提到的运行中的进程)
再到HijackThis中修复,并删除所有的相关的文件~~
gototop
 

O9 - 浏览器额外的按钮: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289}? - http://sms.3721.com/ie/index.htm?pid=U_skycn_5409 (file missing)
O9 - 浏览器额外的按钮: 免费精彩视频超流畅在线观看 - {022C4009-5283-4365-97BF-144054B40E2E} - http://itv.mop.com (file missing)
O9 - 浏览器额外的“工具”菜单项: 播霸电视 - {022C4009-5283-4365-97BF-144054B40E2E} - http://itv.mop.com (file missing)
O9 - 浏览器额外的按钮: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll (file missing)
O9 - 浏览器额外的“工具”菜单项: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll (file missing)
O9 - 浏览器额外的按钮: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - 浏览器额外的“工具”菜单项: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - 浏览器额外的按钮: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97}? - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - 浏览器额外的按钮: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26}? - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - 浏览器额外的按钮: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338}? - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O9 - 浏览器额外的“工具”菜单项: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O9 - 浏览器额外的按钮: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\flashget\FLASHGET\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\flashget\FLASHGET\flashget.exe
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [!ANetSpeeder]  NetSpeeder
O11 - Options group: [CDNCLIENT]  中文上网
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2EA6D939-4445-43F1-A12B-8CB3DDA8B855} (BlueskyVideo Control) - http://www.bluesky.cn/download/v2_60.cab
O16 - DPF: {991481A7-4669-4E15-8C24-100404E1F5CB} (Blueskyvoice Control) - http://www.bluesky.cn/download/blueskyvoice_60.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - file://C:\Herosoft\HeroV8\DVDSkin\defskin\HTML\swflash.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/ravkill/rsonline.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FA7A96DF-6ECE-49D2-B150-9F6068D063F8}: NameServer = 202.99.224.8 202.99.224.68
O18 - 列举现有的协议: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\system32\mbprot.dll (file missing)
O18 - Filter: text/html - {65CBAF77-19CA-4B81-86D5-7835D59BEA85} - C:\WINDOWS\VIDEO.dll
O23 - NT 服务: Download Service - Unknown owner - C:\WINDOWS\system32\SeedServ.exe
O23 - NT 服务: Event Client - Unknown owner - C:\Program Files\zsxz\UrlService.exe
O23 - NT 服务: Local Network Service - Unknown owner - C:\WINDOWS\system32\URLSrv.exe
O23 - NT 服务: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\Ravmond.exe
已经发上hijackthis,烦劳您看看,在线等待,谢谢
也烦劳路过的GG JJM DD MM给予解答,不胜感谢
gototop
 

谢谢影子110,那我试试
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT