瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 偶中招了,高手进来帮忙啊, 扫描结果已经贴上。

123   1  /  3  页   跳转

偶中招了,高手进来帮忙啊, 扫描结果已经贴上。

偶中招了,高手进来帮忙啊, 扫描结果已经贴上。


偶的windows xp的设备管理器能打开,但是打开后显示一片空白,什么设备也显示不了。
电脑右下角的网卡的标志,声卡的小喇叭都不见了,播放mp3没有声音了,但是还能上网。

这是中了什么病毒了啊?大家帮帮偶吧,先谢过了。
最后编辑2006-07-23 17:01:31
分享到:
gototop
 

我用瑞星杀毒软件查过一遍系统盘,显示有这么几个病毒,并都杀毒成功了:
Trojan.DL.Inject.fe删除成功2006-07-19 21:07文件监控C:\WINDOWS\system32pyjjkdll.dll
Trojan.DL.Inject.fe删除成功2006-07-19 22:21文件监控C:\WINDOWS\system32pyjjkdll.dll
Trojan.DL.Inject.fe删除成功2006-07-22 14:40文件监控C:\WINDOWS\system32pyjjkdll.dll
Trojan.DL.Inject.fe删除成功2006-07-23 12:55文件监控C:\WINDOWS\system32pyjjkdll.dll
Trojan.DL.Inject.fe删除成功2006-07-23 13:56文件监控C:\WINDOWS\system32pyjjkdll.dll
Trojan.Crypt.fy删除成功2006-07-23 10:17文件监控C:\System Volume Information\_restore{CEFC8F05-3799-4A97-83F4-F8C831295D77}\RP2A0006115.exe
Rootkit.Vanti.js删除成功2006-07-23 09:17文件监控C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp7gcs.dll
Rootkit.Vanti.js删除成功2006-07-23 09:34文件监控C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp7gcs.dll
Rootkit.Vanti.js删除成功2006-07-23 09:47文件监控C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp7gcs.dll
Rootkit.Vanti.js删除成功2006-07-23 10:19文件监控C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp7gcs.dll
Rootkit.Vanti.js删除成功2006-07-23 10:34文件监控C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp7gcs.dll
Rootkit.Vanti.js删除成功2006-07-23 11:08文件监控C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp7gcs.dll
Rootkit.Vanti.js删除成功2006-07-23 11:53文件监控C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp7gcs.dll
gototop
 

用System Repair Engineer扫分日志 贴上来
高手帮你看
gototop
 

http://www.kztechs.com/sreng/sreng2.zip
下载地址
gototop
 

http://forum.ikaka.com/topic.asp?board=28&artid=8105899
下载HijackThis...把日志帖上来..
gototop
 

zhangyouyou,
  谢谢你的回复
  System Repair Engineer 怎么扫描啊?不好意思,我是新手。
gototop
 

双击System Repair Engineer
然后 点击 “智能扫描” 然后 点击 右下角 “扫描”
扫描完后 点击“保存报告” 就好了
然后一部分一部分 贴上来
高后会帮你看得
gototop
 

好的,谢谢,我正在扫描,再现等待中 ... ...
gototop
 

2006-07-23,14:47:43

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <vptray><C:\PROGRA~1\SYMANT~1\VPTray.exe>  []
    <StormCodec_Helper><"D:\SoftWare\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  []
    <Samsung Taskbar Utility><C:\WINDOWS\system32\spool\drivers\w32x86\3\smstsb09.exe>  []
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <LoadFujitsuQuickTouch><C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe>  [FUJITSU LIMITED]
    <LoadBtnHnd><C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe>  [FUJITSU LIMITED]
    <IMJPMIG8.1><C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe">  []
    <BigDogPath><C:\WINDOWS\VM_STI.EXE AVSTAR PC Camera>  []
    <BATTERYAID><C:\Program Files\Fujitsu\BATTERYAID\BATTERYAID.exe>  [FUJITSU LIMITED]
    <auto><c:\Program Files\Internet Explorer\acslq.exe>  []
    <ATIPTA><C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>  [ATI Technologies, Inc.]
    <ATIModeChange><Ati2mdxx.exe>  [ATI Technologies, Inc.]
    <Apoint><C:\Program Files\Apoint2K\Apoint.exe>  [Alps Electric Co., Ltd.]
    <AGRSMMSG><AGRSMMSG.exe>  [Agere Systems]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <CheckFaultKernel><C:\WINDOWS\system32\mswdm.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\空中美语.scr>  []

==================================
启动文件夹
服务
[Ati HotKey Poller / Ati HotKey Poller]
  <C:\WINDOWS\system32\Ati2evxx.exe><N/A>
[OracleMTSRecoveryService / OracleMTSRecoveryService]
  <D:\SoftWare\oracle\ora92\bin\omtsreco.exe "OracleMTSRecoveryService"><Oracle Corporation>
[OracleOraHome92ClientCache / OracleOraHome92ClientCache]
  <D:\SoftWare\oracle\ora92\BIN\ONRSD.EXE><N/A>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
gototop
 

==================================
浏览器加载项
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\SoftWare\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <D:\SoftWare\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <D:\SoftWare\FlashGet\jccatch.dll, Amaze Soft>
[Google Toolbar Helper]
  {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[Java Plug-in 1.5.0_05]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll, Sun Microsystems, Inc.>
[CibaCtrl Class]
  {8DE0FCD4-5EB5-11D3-AD25-00002100131B} <D:\SoftWare\Kingsoft\XDict\IEPlugin.dll, >
[JoyoCtrl Class]
  {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} <D:\SoftWare\Kingsoft\XDict\IEPlugin.dll, >
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\SoftWare\Tencent\QQ\QQ.EXE, TENCENT>
[FlashGet]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <D:\SoftWare\FlashGet\flashget.exe, Amaze Soft>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\SoftWare\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <D:\SoftWare\FlashGet\fgiebar.dll, Amaze Soft>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[Java Plug-in 1.5.0_05]
  {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll, Sun Microsystems, Inc.>
[Google Script Object]
  {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\SoftWare\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Windows Genuine Advantage Validation Tool]
  {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
  {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\System32\mshtml.dll, N/A>
[HHCtrl Object]
  {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <D:\SoftWare\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\System32\shdocvw.dll, N/A>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\System32\shdocvw.dll, Microsoft Corporation>
[CibaCtrl Class]
  {8DE0FCD4-5EB5-11D3-AD25-00002100131B} <D:\SoftWare\Kingsoft\XDict\IEPlugin.dll, >
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <D:\SoftWare\FlashGet\jccatch.dll, Amaze Soft>
[Qzone Media Tools]
  {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} <D:\SoftWare\Tencent\QQ\QZone\QZONEM~1.OCX, Tencent Technology (Shenzhen) Company Limited>
[Google Toolbar Helper]
  {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\System32\shdocvw.dll, N/A>
[JoyoCtrl Class]
  {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} <D:\SoftWare\Kingsoft\XDict\IEPlugin.dll, >
[AUDIO__X_MS_WMA Moniker Class]
  {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8a.ocx, Macromedia, Inc.>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <D:\SoftWare\FlashGet\fgiebar.dll, Amaze Soft>
[E&xport to Microsoft Excel]
  <res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000, N/A>
[Google 搜索(&G)]
  <res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html, N/A>
[上传到QQ网络硬盘]
  <D:\SoftWare\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <D:\SoftWare\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <D:\SoftWare\FlashGet\jc_all.htm, N/A>
[反向链接]
  <res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html, N/A>
[添加到QQ自定义面板]
  <D:\SoftWare\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\SoftWare\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\SoftWare\Tencent\QQ\SendMMS.htm, N/A>
[类似网页]
  <res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html, N/A>
[缓存的网页快照]
  <res://c:\program files\google\GoogleToolbar2.dll/cmcache.html, N/A>
[翻译英文字词(&T)]
  <res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html, N/A>
gototop
 
123   1  /  3  页   跳转
页面顶部
Powered by Discuz!NT