1   1  /  1  页   跳转

瑞星的监控打不开,可能中了病毒

瑞星的监控打不开,可能中了病毒

Logfile of HijackThis v1.99.1
Scan saved at 11:08:14, on 2006-8-7
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Common Files\GoldenSoft\ChannelRg.exe
C:\Documents and Settings\scar\桌面\新建文件夹\新建文件夹\guard.exe
C:\Program Files\腾讯 QQ & TM Q哥Q妹版\qq.exe
C:\Program Files\腾讯 QQ & TM Q哥Q妹版\TIMPlatform.exe
C:\Program Files\腾讯 QQ & TM Q哥Q妹版\qqpet\qqpet.exe
C:\DOCUME~1\scar\LOCALS~1\Temp\Rar$EX00.275\HijackThis.exe

R3 - URLSearchHook: (no name) - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: (no name) - _{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} - (no file)
O2 - BHO: (no name) - _{27E96DE0-8211-42CF-9A1E-FA6246A95B77} - (no file)
O2 - BHO: yPhtb - _{33BBE430-0E42-4f12-B075-8D21ACB10DCB} - (no file)
O2 - BHO: Anti Fish - _{38928D50-8A48-44C2-945F-D2F23F771410} - (no file)
O2 - BHO: (no name) - _{3CE496D1-1746-41CD-9489-3C0B93DF10E2} - (no file)
O2 - BHO: YDragSearch - _{62EED7C6-9F02-42f9-B634-98E2899E147B} - (no file)
O2 - BHO: NewWeb Controller - _{9ACEEE31-1440-471B-AA46-72B061FE7D61} - (no file)
O2 - BHO: (no name) - _{A697BC46-BC93-4833-93F5-1E365011E88A} - (no file)
O2 - BHO: (no name) - _{B3122598-CA4A-E1E2-BF30-7BC7B77A098C} - (no file)
O2 - BHO: Letscool System Helper - _{F0C15012-7DBD-4068-95A2-0A82DB03AC35} - (no file)
O2 - BHO: (no name) - _{F651FCAA-F826-4922-8990-C6F99CC67AFC} - (no file)
O2 - BHO: (no name) - _{FAD11F89-F11E-4A15-92FB-6F0EDC4C8D59} - (no file)
O2 - BHO: AssistHelper - _{FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} - (no file)
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - (no file)
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hxgame-update] C:\Program Files\hxupdate\hxgame-update.exe
O4 - HKLM\..\Run: [YOKAssiant] Rundll32.exe C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll,YOKAssiant uninstall
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [pbmini] "C:\Program Files\pcast\PodcastbarMini\PodcastBarMini.exe" -hide
O4 - HKLM\..\Run: [WingKav] C:\DOCUME~1\scar\LOCALS~1\Temp\Rar$EX01.635\WingKav2006.exe
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Xplus_spy] "D:\新建文件夹 (2)\xvcclip.exe" /min
O8 - Extra context menu item: !搜一搜(&S) - res://C:\Program Files\YiSou\yisou.dll/232
O8 - Extra context menu item: &使用DuDu下载 - res://C:\Program Files\DuDu\Speed\dddmext.dll/202
O8 - Extra context menu item: &使用DuDu下载全部链接 - res://C:\Program Files\DuDu\Speed\dddmext.dll/203
O8 - Extra context menu item: &使用DuDu下载选择链接 - res://C:\Program Files\DuDu\Speed\dddmext.dll/204
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\腾讯 QQ & TM Q哥Q妹版\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\腾讯 QQ & TM Q哥Q妹版\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\腾讯 QQ & TM Q哥Q妹版\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\腾讯 QQ & TM Q哥Q妹版\SendMMS.htm
O8 - Extra context menu item: 百度--MP3搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUMP3.HTM
O8 - Extra context menu item: 百度--图片搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUIMG.HTM
O8 - Extra context menu item: 百度--地图搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_MAP.HTM
O8 - Extra context menu item: 百度--新闻搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUNEWS.HTM
O8 - Extra context menu item: 百度--歌词搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDULYRIC.HTM
O8 - Extra context menu item: 百度--知道搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_ZHIDAO.HTM
O8 - Extra context menu item: 百度--硬盘搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_DISK.HTM
O8 - Extra context menu item: 百度--站内搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_SITE.HTM
O8 - Extra context menu item: 百度--网页搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUSEARCH.HTM
O8 - Extra context menu item: 百度--词典搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_DIC.HTM
O8 - Extra context menu item: 百度--贴吧搜索 - RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUPOST.HTM
O9 - Extra button: kele8 - {84920E5F-3788-49cd-A274-E365578DF174} - http://www.kele8.com/ (file missing)
O9 - Extra 'Tools' menuitem: kele8 - {84920E5F-3788-49cd-A274-E365578DF174} - http://www.kele8.com/ (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: YOK超级搜索 - {F869BB38-FFEF-4589-B986-610B7AD0ADA2} - http://www.yok.com (file missing)
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\cdnns.dll' missing
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EDCF1014-D7CA-48BF-B996-385B8C8779C8}: NameServer = 202.102.154.3 202.102.152.3
O18 - Filter: text/html - {1BC02872-BC5E-46BE-BA76-6B0170FE6BFE} - C:\WINDOWS\System32\Navsmall.dll
O21 - SSODL: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - (no file)
O23 - Service: ChannelRg - Unknown owner - C:\Program Files\Common Files\GoldenSoft\ChannelRg.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Documents and Settings\scar\桌面\新建文件夹\新建文件夹\guard.exe
O23 - Service: GrayPigeon - Unknown owner - C:\WINDOWS\Hacker.com.cn.exe (file missing)
O23 - Service: Kaspersky Anti-Virus Service (kavsvc) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe

最后编辑2006-08-07 11:31:05
分享到:
gototop
 

不是可能中毒了,是肯定中毒了.我前几天也中了这毒,GHOST还原都不行.后来发现在D盘还有病毒,这可能就是导致还原也没有用的原因.我先把D盘的毒干掉后,再还原才解决的问题.你自己看着办吧.我干掉的病毒是传奇烙血.
gototop
 

O4 - HKCU\..\Run: [Xplus_spy] "D:\新建文件夹 (2)\xvcclip.exe" /min
这个可疑

O23 - Service: GrayPigeon - Unknown owner - C:\WINDOWS\Hacker.com.cn.exe (file missing)
这个是灰鸽子,在论坛搜下有解决方法,BAOHE写的.
不过估计还有别的病毒.
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT