瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 大大,看看我的,有无中木马或灰鸽子

1   1  /  1  页   跳转

大大,看看我的,有无中木马或灰鸽子

大大,看看我的,有无中木马或灰鸽子

D:\WINDOWS\SYSTEM.EXE
木马克星说这会自动启动,是木马,各位大大,看看是不是,我用搜索,查不到这文件。
下面是我的hijackthis.log日记
Logfile of HijackThis v1.99.1
Scan saved at 17:49:53, on 2006-4-27
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Rising\Rav\CCenter.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Rising\Rav\Ravmond.exe
d:\program files\rising\rfw\rfwsrv.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Rising\Rav\RavStub.exe
D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
D:\Program Files\Common Files\Ulead

Systems\DVD\ULCDRSvr.exe
D:\WINDOWS\System32\wdfmgr.exe
D:\WINDOWS\Explorer.EXE
d:\program files\rising\rfw\RfwMain.exe
D:\WINDOWS\System32\Rundll32.exe
D:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Ringz Studio\Storm

Downloader\StormDownloader.exe
D:\Program Files\CNNIC\Cdn\cdnup.exe
D:\Program Files\Common

Files\Real\Update_OB\realsched.exe
D:\Program Files\Iparmor\Iparmor.exe
D:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Rising\Rav\Ravmon.exe
D:\WINDOWS\System32\conime.exe
D:\WINDOWS\System32\regsvr32.exe
D:\WINDOWS\System32\regsvr32.exe
D:\WINDOWS\System32\regsvr32.exe
D:\WINDOWS\System32\regsvr32.exe
D:\WINDOWS\System32\regsvr32.exe
D:\WINDOWS\System32\regsvr32.exe
D:\WINDOWS\NOTEPAD.EXE
F:\其它\木马克星\查杀木马\hi\HijackThis.exe

R3 - URLSearchHook: VeryCD Search Class -

{88351CEF-BAC0-4A9B-8380-31A173E2926F} -

D:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll
O2 - BHO: AcroIEHlprObj Class -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program

Files\Adobe\Acrobat

5.0\Reader\ActiveX\AcroIEHelper.ocx (file missing)
O2 - BHO: 雅虎助手 -

{406F94F0-504F-4a40-8DFD-58B0666ABEBD} -

D:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O2 - BHO: VeryCD超级搜索 -

{75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688} -

D:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll
O2 - BHO: BandIE Class -

{77FEF28E-EB96-44FF-B511-3185DEA48697} -

D:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: Google Toolbar Helper -

{AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program

files\google\googletoolbar2.dll
O3 - Toolbar: 金山快译(&K) -

{6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} -

D:\PROGRA~1\Kingsoft\FastAIT\IEBand.dll
O3 - Toolbar: 卡卡上网安全助手 -

{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} -

D:\WINDOWS\System32\kakatool.dll
O3 - Toolbar: 百纳搜索 -

{BA440AED-8A58-46A3-B8E5-6AEE4D03A7D8} - D:\Program

Files\BiGet\bigetband.dll
O3 - Toolbar: 雅虎助手 -

{406F94F0-504F-4a40-8DFD-58B0666ABEBD} -

D:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O3 - Toolbar: &Radio -

{8E718888-423F-11D2-876E-00A0C9082467} -

D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: VeryCD超级搜索 -

{F869BB38-FFEF-4589-B986-610B7AD0ADA2} -

D:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll
O3 - Toolbar: 百度超级搜霸 -

{B580CF65-E151-49C3-B73F-70B13FCA8E86} -

D:\PROGRA~1\baidu\bar\baidubar.dll
O3 - Toolbar: &Google -

{2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program

files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] ;

D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef

/Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] ;

D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] ;

D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE

/IMEName
O4 - HKLM\..\Run: [helper.dll] ;

D:\WINDOWS\system32\rundll32.exe

D:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [CnsMin] rem Rundll32.exe

D:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [RfwMain] "D:\Program

Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "D:\Program

Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [StormCodec_Helper] ; "c:\Program

Files\Ringz Studio\Storm Codec\StormSet.exe" /S

/opti
O4 - HKLM\..\Run: [MINI_BFYY] C:\Program Files\Ringz

Studio\Storm Downloader\StormDownloader.exe
O4 - HKLM\..\Run: [Super Rabbit SRRestore]

D:\Program Files\Super Rabbit\MagicSet\SRRest.exe

/autosave
O4 - HKLM\..\Run: [Super Rabbit Safe Folder] ;

D:\Program Files\Super Rabbit\MagicSet\SRFC.EXE

/Load
O4 - HKLM\..\Run: [YOKAssiant] Rundll32.exe

D:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll,YOK

Assiant
O4 - HKLM\..\Run: [YLive.exe] ;

D:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [yassistse] ;

"D:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - HKLM\..\Run: [Skype] c:\Program

Files\skype\Phone\Skype.exe
O4 - HKLM\..\Run: [CdnCtr] D:\Program

Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program

Files\Common Files\Real\Update_OB\realsched.exe" 

-osboot
O4 - HKLM\..\Run: [RavScanBD] "D:\Program

Files\Rising\Rav\ScanBD.exe" /INST
O4 - HKLM\..\Run: [iparmor] D:\Program

Files\Iparmor\Iparmor.exe mini
O4 - HKCU\..\Run: [ctfmon.exe]

D:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] ; "D:\Program

Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: &Download by NetAnts -

D:\PROGRA~1\NETANTS\NAGet.htm
O8 - Extra context menu item: &使用暴风下载器下载 -

C:\Program Files\Ringz Studio\Storm

Downloader\geturl.htm
O8 - Extra context menu item: &使用迅雷下载 -

C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接

- C:\Program Files\Thunder

Network\Thunder\getAllurl.htm
O8 - Extra context menu item: Download &All by

NetAnts - D:\PROGRA~1\NETANTS\NAGetAll.htm
O8 - Extra context menu item: Google 搜索(&G) -

res://d:\program

files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: VeryCD超级搜索 -

D:\PROGRA~1\YOK.com\SUPERS~1\yoksch.htm
O8 - Extra context menu item: 使用BiGet下载 -

res://D:\Program

Files\BiGet\bigetcatch.dll/bigethttp.html
O8 - Extra context menu item: 反向链接 -

res://d:\program

files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: 导出到 Microsoft

Excel(&x) -

res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 百度--MP3搜索 -

RES://D:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUMP3.HT

M
O8 - Extra context menu item: 百度--图片搜索 -

RES://D:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUIMG.HT

M
O8 - Extra context menu item: 百度--地图搜索 -

RES://D:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_MAP.H

TM
O8 - Extra context menu item: 百度--新闻搜索 -

RES://D:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUNEWS.H

TM
O8 - Extra context menu item: 百度--歌词搜索 -

RES://D:\PROGRA~1\baidu\bar\baidubar.dll/BAIDULYRIC.

HTM
O8 - Extra context menu item: 百度--知道搜索 -

RES://D:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_ZHIDA

O.HTM
O8 - Extra context menu item: 百度--硬盘搜索 -

RES://D:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_DISK.

HTM
O8 - Extra context menu item: 百度--站内搜索 -

RES://D:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_SITE.

HTM
O8 - Extra context menu item: 百度--网页搜索 -

RES://D:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUSEARCH

.HTM
O8 - Extra context menu item: 百度--词典搜索 -

RES://D:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_DIC.H

TM
O8 - Extra context menu item: 百度--贴吧搜索 -

RES://D:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUPOST.H

TM
O8 - Extra context menu item: 类似网页 -

res://d:\program

files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: 缓存的网页快照 -

res://d:\program

files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: 翻译英文字词(&T) -

res://d:\program

files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: 访问通用网址 -

D:\Program Files\CNNIC\Cdn\cnnic.htm
O9 - Extra button: BiGet -

{2B6B63F1-28C9-4005-A035-E3DCAF723342} - D:\Program

Files\BiGet\bigetloader.exe
O9 - Extra 'Tools' menuitem: BiGet -

{2B6B63F1-28C9-4005-A035-E3DCAF723342} - D:\Program

Files\BiGet\bigetloader.exe
O9 - Extra button: Yahoo 1G电邮 -

{507F9113-CD77-4866-BA92-0E86DA3D0B97} -

http://cn.zs.yahoo.com/cnsbutton.htm?

source=cns&btn=yahoomail (file missing)
O9 - Extra button: 寻宝乐趣多 -

{59BC54A2-56B3-44a0-93E5-432D58746E26} -

http://cn.zs.yahoo.com/cnsbutton.htm?

source=cns&btn=taobao (file missing)
O9 - Extra button: 雅虎助手 -

{5D73EE86-05F1-49ed-B850-E423120EC338} -

http://cn.zs.yahoo.com/cnsbutton.htm?

source=cns&btn=yassist (file missing)
O9 - Extra button: 行情 -

{92FB5B81-2C77-11D4-A66A-0040055E7174} -

http://www.gfhfzq.com.cn/activehq/ (file missing)
O9 - Extra 'Tools' menuitem: 行情 -

{92FB5B81-2C77-11D4-A66A-0040055E7174} -

http://www.gfhfzq.com.cn/activehq/ (file missing)
O9 - Extra button: 情景聊天 -

{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -

http://cn.zs.yahoo.com/cnsbutton.htm?

source=cns&btn=yahoomsg (file missing)
O9 - Extra button: (no name) -

{ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} -

http://cn.zs.yahoo.com/cnsbutton.htm?

source=cns&btn=repair (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 -

{ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} -

http://cn.zs.yahoo.com/cnsbutton.htm?

source=cns&btn=repair (file missing)
O9 - Extra button: (no name) -

{FD00D911-7529-4084-9946-A29F1BDF4FE5} -

http://cn.zs.yahoo.com/cnsbutton.htm?

source=cns&btn=clean (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 -

{FD00D911-7529-4084-9946-A29F1BDF4FE5} -

http://cn.zs.yahoo.com/cnsbutton.htm?

source=cns&btn=clean (file missing)
O10 - Unknown file in Winsock LSP:

d:\windows\system32\cdnns.dll
O11 - Options group: [!CNS]  上网助手-地址栏搜索
O11 - Options group: [CDNCLIENT]  中文上网
O11 - Options group: [TBH]  搜搜地址栏搜索
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}

(WUWebControl Class) -

http://update.microsoft.com/windowsupdate/v6/V5Contr

ols/en/x86/client/wuweb_site.cab?1143370140201
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD}

(AxInputControl Class) -

https://mybank.icbc.com.cn/icbc/perbank/AXSafeContro

ls.cab
O16 - DPF: {DFA15943-AE06-11D3-951F-0000E821282D}

(HexinCtrl Class) -

http://www.hfzq.com.cn/activehq/HexinATL.cab
O20 - AppInit_DLLs: APIHookDll.dll
O23 - Service: Rising Proxy  Service (RfwProxySrv) -

Beijing Rising Technology Co., Ltd. - d:\program

files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service

(RfwService) - Beijing Rising Technology Co., Ltd. -

d:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center

(RsCCenter) - Beijing Rising Technology Co., Ltd. -

D:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing

Rising Technology Co., Ltd. - D:\Program

Files\Rising\Rav\Ravmond.exe
O23 - Service: SoundMAX Agent Service (SoundMAX

Agent Service (default)) - Analog Devices, Inc. -

D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: System.exe (System.exer) - Unknown

owner - D:\WINDOWS\System.exe (file missing)
O23 - Service: Ulead Burning Helper

(UleadBurningHelper) - Ulead Systems, Inc. -

D:\Program Files\Common Files\Ulead

Systems\DVD\ULCDRSvr.exe

最后编辑2006-04-28 15:30:16
分享到:
gototop
 

O23 - Service: System.exe (System.exer) - Unknown owner - D:\WINDOWS\System.exe (file missing)
这项先修复一下.
gototop
 

开始→控制面板→性能和维护→管理工具→服务→查找System.exe →右击→属性→启动

类型→禁止→应用→停止→确定。
关闭所有浏览窗口以及一些不必要的程序
运行Hijackthis,扫描结束后在下列选项前打上勾,然后选修复“Fix Checked
O23 - Service: System.exe (System.exer) - Unknown owner - D:\WINDOWS\System.exe
双击我的电脑--工具---文件夹选项--查看选项卡--单击选取"显示隐藏文件或文件夹"--

清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示您确定更改时,单击“是”
然后找到如下文件并删除D:\WINDOWS\System.exe

gototop
 

无邪,谢谢,可惜我要去找却没了,
Logfile of HijackThis v1.99.1
Scan saved at 8:23:31, on 2006-4-28
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Rising\Rav\CCenter.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Rising\Rav\Ravmond.exe
d:\program files\rising\rfw\rfwsrv.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Rising\Rav\RavStub.exe
D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
D:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
D:\WINDOWS\System32\wdfmgr.exe
D:\WINDOWS\Explorer.EXE
d:\program files\rising\rfw\RfwMain.exe
D:\WINDOWS\System32\Rundll32.exe
D:\Program Files\Rising\Rav\RavTask.exe
D:\Program Files\Rising\Rav\Ravmon.exe
D:\WINDOWS\System32\ctfmon.exe
D:\WINDOWS\System32\NOTEPAD.EXE
F:\其它\木马克星\查杀木马\hi\HijackThis.exe

R3 - URLSearchHook: VeryCD Search Class - {88351CEF-BAC0-4A9B-8380-31A173E2926F} - D:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx (file missing)
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - D:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O2 - BHO: VeryCD超级搜索 - {75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688} - D:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - D:\PROGRA~1\baidu\bar\baidubar.dll
O3 - Toolbar: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - D:\PROGRA~1\Kingsoft\FastAIT\IEBand.dll
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - D:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O3 - Toolbar: VeryCD超级搜索 - {F869BB38-FFEF-4589-B986-610B7AD0ADA2} - D:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - D:\PROGRA~1\baidu\bar\baidubar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] ; D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] ; D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] ; D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [helper.dll] ; D:\WINDOWS\system32\rundll32.exe D:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [CnsMin] rem Rundll32.exe D:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [RfwMain] "D:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "D:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [Super Rabbit SRRestore] D:\Program Files\Super Rabbit\MagicSet\SRRest.exe /autosave
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] ; "D:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: &Download by NetAnts - D:\PROGRA~1\NETANTS\NAGet.htm
O8 - Extra context menu item: &使用暴风下载器下载 - C:\Program Files\Ringz Studio\Storm Downloader\geturl.htm
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O10 - Unknown file in Winsock LSP: d:\windows\system32\cdnns.dll
O11 - Options group: [!CNS]  上网助手-地址栏搜索
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1143370140201
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AXSafeControls.cab
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - D:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
我是按照你说的操作
开始→控制面板→性能和维护→管理工具→服务→查找System.exe →右击→属性→启动

类型→禁止→应用→停止→确定。
关闭所有浏览窗口以及一些不必要的程序
运行日志后却找不到那023了,呵呵,不过有个程序不知是什么?帮我看看,就是我桌面上多了是个IE图标,颜色比原来IE深,是深蓝色,点它属性,是"C:\Program Files\Internet Explorer\IEXPLORE.EXE" www.37021.net  我系统盘是D:,这是不是那www.37021.net  恶意网站的?是按这路径删除就可以了吗?

那O4 - HKLM\..\Run: [RavTask] "D:\Program Files\Rising\Rav\RavTask.exe" -system是不是那木马啊?
  O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx (file missing)这02项是什么呢?
我是菜鸟,盼答复?

gototop
 

3楼日志没问题  一切都正常
gototop
 

O4 - HKLM\..\Run: [RavTask] "D:\Program Files\Rising\Rav\RavTask.exe" -system是不是那木马啊?
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\e\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx (file missing)这02项是什么呢?
这两项一个是瑞星,一个是Adobe,都是好东东。
你的机子如果没有什么反常,可以说没有问题了。
gototop
 

呵呵,谢谢,谢谢!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT