瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 中毒了,反复查杀,反复出现,请帮忙解决.

1   1  /  1  页   跳转

中毒了,反复查杀,反复出现,请帮忙解决.

中毒了,反复查杀,反复出现,请帮忙解决.


中毒了,反复查杀,反复出现,而且出现死机样现象;请帮忙解决,谢谢了!
Logfile of HijackThis v1.99.1
Scan saved at 21:27:46, on 2006-7-13
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\winsvc.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\ChinaNet\VnetClient.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Downloads\426101200522225654\HijackThis.exe

F2 - REG:system.ini: Shell=Explorer.exe C:\WINNT\system32\atom.exe
O2 - BHO: WebThunderBHO - {00000AAA-A363-466E-BEF5-9BB68697AA7F} - C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_010.dll
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINNT\system32\xunleibho_v13.dll
O2 - BHO: MonitorURL Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\PROGRA~1\DESKAD~1\deskipn.dll
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINNT\system32\wmpdrm.dll
O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4708.dll
O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\chinanet\VNETTR~1.DLL
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O2 - BHO: IEYHlprObj Class - {5C761D09-377E-4EAC-ADA1-C9CDE39B5674} - C:\WINNT\IEYHelper.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll
O2 - BHO: NewWeb Controller - {9ACEEE31-1440-471B-AA46-72B061FE7D61} - C:\WINNT\system32\WinSC32.dll
O2 - BHO: estAliveObj Class - {A2B7A0F0-B697-4A71-8D91-43443F57D7BB} - C:\WINNT\estAlive.dll
O2 - BHO: Flash 8 ocx  - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} - C:\WINNT\system32\flash8.dll
O2 - BHO: TskUnfzt Class - {E1E6DEAE-FDAC-DF28-7AA4-BF4CE5C4BF85} - C:\WINNT\DOWNLO~1\kmruhbd.dll
O2 - BHO: Subconscious Intruder - {E2218499-2FD4-4EED-A94A-7F0B9C6E300E} - C:\WINNT\system32\Inte32.dll
O2 - BHO: Letscool System Helper - {F0C15012-7DBD-4068-95A2-0A82DB03AC35} - C:\WINNT\system32\CoolBho.dll
O2 - BHO: AlxTB BHO - {F1FABE79-25FC-46de-8C5A-2C6DB9D64333} - C:\WINNT\system32\AlxTB1.dll (file missing)
O2 - BHO: WMHlprObj Class - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll
O2 - BHO: google bar - {F651FCAA-F826-4922-8990-C6F99CC67AFC} - C:\WINNT\Win32ef.dll
O2 - BHO: google bar - {FAD11F89-F11E-4A15-92FB-6F0EDC4C8D59} - C:\WINNT\vwwreg.dll
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINNT\system32\KakaTool.dll
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Desktop] C:\WINNT\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll
O4 - HKLM\..\Run: [] C:\WINNT\system32\atom.exe
O4 - HKLM\..\Run: [spoolsv] C:\WINNT\system32\spoolsv\spoolsv.exe -printer
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: Google 搜索(&G) - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Mail to a Friend... - http://client.alexa.com/holiday/script/actions/mailto.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用Web迅雷下载 - C:\Program Files\Thunder Network\WebThunder\GetUrl.htm
O8 - Extra context menu item: 使用超级解霸播放 - C:\Program Files\Herosoft\Hero 9\MPURLGET.HTM
O8 - Extra context menu item: 反向链接 - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra button: 启动Web迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)
O9 - Extra 'Tools' menuitem: 启动Web迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O10 - Unknown file in Winsock LSP: c:\winnt\system32\cdnns.dll
O10 - Unknown file in Winsock LSP: c:\winnt\xboxcenter.dll
O10 - Unknown file in Winsock LSP: c:\winnt\xboxcenter.dll
O10 - Unknown file in Winsock LSP: c:\winnt\xboxcenter.dll
O10 - Unknown file in Winsock LSP: c:\winnt\xboxcenter.dll
O10 - Unknown file in Winsock LSP: c:\winnt\xboxcenter.dll
O11 - Options group: [CDNCLIENT]  中文上网
O16 - DPF: {7A97B026-F3BB-49F6-BEAC-75021AD45B4E} (SLAProbe Control) - http://xnjc.jsinfo.net:81/sla/SLAProbe/SLAProbe.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{7725B560-0D9B-4A42-A9CC-16D0A6A61D52}: NameServer = 61.147.37.1 61.177.7.1
O23 - Service: DeskService - Unknown owner - C:\WINNT\system32\winsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe

最后编辑2006-07-13 21:48:05
分享到:
gototop
 

修复
F2 - REG:system.ini: Shell=Explorer.exe C:\WINNT\system32\atom.exe
O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4708.dll
O2 - BHO: IEYHlprObj Class - {5C761D09-377E-4EAC-ADA1-C9CDE39B5674} - C:\WINNT\IEYHelper.dll
O2 - BHO: NewWeb Controller - {9ACEEE31-1440-471B-AA46-72B061FE7D61} - C:\WINNT\system32\WinSC32.dll
O2 - BHO: estAliveObj Class - {A2B7A0F0-B697-4A71-8D91-43443F57D7BB} - C:\WINNT\estAlive.dll
O2 - BHO: Subconscious Intruder - {E2218499-2FD4-4EED-A94A-7F0B9C6E300E} - C:\WINNT\system32\Inte32.dll
O2 - BHO: Letscool System Helper - {F0C15012-7DBD-4068-95A2-0A82DB03AC35} - C:\WINNT\system32\CoolBho.dll
O2 - BHO: AlxTB BHO - {F1FABE79-25FC-46de-8C5A-2C6DB9D64333} - C:\WINNT\system32\AlxTB1.dll (file missing)
O2 - BHO: google bar - {F651FCAA-F826-4922-8990-C6F99CC67AFC} - C:\WINNT\Win32ef.dll
O2 - BHO: google bar - {FAD11F89-F11E-4A15-92FB-6F0EDC4C8D59} - C:\WINNT\vwwreg.dll
O4 - HKLM\..\Run: [] C:\WINNT\system32\atom.exe
删除
C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4708.dll
C:\WINNT\IEYHelper.dll
C:\WINNT\system32\WinSC32.dll
C:\WINNT\estAlive.dll
C:\WINNT\system32\Inte32.dll
C:\WINNT\system32\CoolBho.dll
C:\WINNT\Win32ef.dll
C:\WINNT\vwwreg.dll
C:\WINNT\system32\atom.exe

O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINNT\system32\wmpdrm.dll
O4 - HKLM\..\Run: [spoolsv] C:\WINNT\system32\spoolsv\spoolsv.exe -printer
参考:http://forum.ikaka.com/topic.asp?board=28&artid=7948848

O23 - Service: DeskService - Unknown owner - C:\WINNT\system32\winsvc.exe
鸽子..安全模式...打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索DeskService删除...
删除
C:\WINNT\system32\winsvc.exe


O10 - Unknown file in Winsock LSP: c:\winnt\xboxcenter.dll
O10 - Unknown file in Winsock LSP: c:\winnt\xboxcenter.dll
O10 - Unknown file in Winsock LSP: c:\winnt\xboxcenter.dll
O10 - Unknown file in Winsock LSP: c:\winnt\xboxcenter.dll
O10 - Unknown file in Winsock LSP: c:\winnt\xboxcenter.dll
需要用LSPFix 来修复..
LSPFix(汉化版) 下载地址:http://forum.ikaka.com/topic.asp?board=67&artid=5188931
(8楼...)
同时下载WinsockXPFix.exe...(2楼...)
----------------------------------------------------------------
先运行LSPFix ... 勾上 我确定要进行修复操作 ...
然后将xboxcenter.dll移到右边...点下完成...
----------------------------------------------------------------
如果在操作之后不能上网...请用WinsockXPFix.exe 修复一下即可...安全模式下..

http://www.pctutu.com/srmsdown.asp
下载超级兔子..用超级兔子清理王卸载流氓软件...(安全模式...)
gototop
 

【回复“没事就乐”的帖子】
修复
F2 - REG:system.ini: Shell=Explorer.exe C:\WINNT\system32\atom.exe
O2 - BHO: MonitorURL Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\PROGRA~1\DESKAD~1\deskipn.dll
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINNT\system32\wmpdrm.dll
O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4708.dll
O2 - BHO: IEYHlprObj Class - {5C761D09-377E-4EAC-ADA1-C9CDE39B5674} - C:\WINNT\IEYHelper.dll
O2 - BHO: NewWeb Controller - {9ACEEE31-1440-471B-AA46-72B061FE7D61} - C:\WINNT\system32\WinSC32.dll
O2 - BHO: estAliveObj Class - {A2B7A0F0-B697-4A71-8D91-43443F57D7BB} - C:\WINNT\estAlive.dll
O2 - BHO: Flash 8 ocx - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} - C:\WINNT\system32\flash8.dll
O2 - BHO: TskUnfzt Class - {E1E6DEAE-FDAC-DF28-7AA4-BF4CE5C4BF85} - C:\WINNT\DOWNLO~1\kmruhbd.dll
O2 - BHO: Subconscious Intruder - {E2218499-2FD4-4EED-A94A-7F0B9C6E300E} - C:\WINNT\system32\Inte32.dll
O2 - BHO: Letscool System Helper - {F0C15012-7DBD-4068-95A2-0A82DB03AC35} - C:\WINNT\system32\CoolBho.dll
O2 - BHO: AlxTB BHO - {F1FABE79-25FC-46de-8C5A-2C6DB9D64333} - C:\WINNT\system32\AlxTB1.dll (file missing)
O2 - BHO: google bar - {F651FCAA-F826-4922-8990-C6F99CC67AFC} - C:\WINNT\Win32ef.dll
O2 - BHO: google bar - {FAD11F89-F11E-4A15-92FB-6F0EDC4C8D59} - C:\WINNT\vwwreg.dll
O4 - HKLM\..\Run: [Desktop] C:\WINNT\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll
O4 - HKLM\..\Run: [] C:\WINNT\system32\atom.exe
O4 - HKLM\..\Run: [spoolsv] C:\WINNT\system32\spoolsv\spoolsv.exe -printer
O23 - Service: DeskService - Unknown owner - C:\WINNT\system32\winsvc.exe

开始--控制面板--性能和维护--管理工具--服务
禁用DeskService服务

开始--运行
输入regedit
确定
进入注册表
依次展开
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Services](X代表1,2,3,4....)
找到后删除winsvc.exe所在的系统服务文件夹

卸载
C:\Program Files\DeskAdTop\

http://cexx.org/lspfix.htm
下载LSPFix.exe
修复c:\winnt\xboxcenter.dll
修复方法参考图片
注意这次应该选中xboxcenter.dll文件

删除
C:\Program Files\DeskAdTop\
C:\WINNT\system32\wmpdrm.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4708.dll
C:\WINNT\IEYHelper.dll
C:\WINNT\system32\WinSC32.dll
C:\WINNT\estAlive.dll
C:\WINNT\system32\flash8.dll
C:\WINNT\DOWNLO~1\kmruhbd.dll
C:\WINNT\system32\Inte32.dll
C:\WINNT\system32\CoolBho.dll
C:\WINNT\Win32ef.dll
C:\WINNT\vwwreg.dll
C:\WINNT\system32\atom.exe
C:\WINNT\system32\spoolsv\
C:\WINNT\system32\winsvc.exe

附件附件:

下载次数:272
文件类型:image/pjpeg
文件大小:
上传时间:2006-7-13 21:49:59
描述:



gototop
 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Services](X代表1,2,3,4....)


汗..........
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT