1   1  /  1  页   跳转

每次开机的时候都有这个病毒.

每次开机的时候都有这个病毒.

我的电脑每次开机以后瑞星都会杀掉Trojan.DL.Agent.zlo这个病毒.个位高手都来帮忙看看啊.
最后编辑2006-11-28 14:15:00
分享到:
gototop
 

请到我的网盘http://free5.ys168.com/?echowj下载Hijackthis
下载后运行HijackThis.rar,再运行HijackThis.exe
单击"扫描日志并保存日志"
把保存的日志复制粘贴上来. 日志一次粘不完,分次粘完,请不要修改.
查到病毒的,把病毒文件名和路径提供下。描述下故障现象
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 12:36:50, on 2006-11-28
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\Rising\Rav\Ravmond.exe
d:\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
D:\Rising\Rav\RavStub.exe
d:\rising\rfw\RfwMain.exe
F:\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
c:\windows\system\m6\iexplorer.exe
D:\Rising\Rav\RavTask.exe
D:\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
D:\神州数码\DigitalChinaSupplicant.exe
C:\WINDOWS\system32\conime.exe
E:\360safe\360Safe.exe
C:\Program Files\QQ2006\QQ.exe
C:\Program Files\QQ2006\TIMPlatform.exe
E:\卡卡助手\Ras.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
E:\Hijackthis\HijackThis.exe

O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RavTask] "D:\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "D:\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\bind_40254.exe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\bind_40254.exe
O4 - HKLM\..\Run: [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\iis.exe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\iis.exe
O4 - HKLM\..\Run: [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\seveneleven.exe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\seveneleven.exe
O4 - HKLM\..\Run: [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dodolook029.exe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dodolook029.exe
O4 - HKLM\..\Run: [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\setup133.exe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\setup133.exe
O4 - HKLM\..\Run: [sdmmrnm] C:\WINDOWS\temp\sd151.exe
O4 - HKLM\..\Run: [Alcmtr] ; ALCMTR.EXE
O4 - HKLM\..\Run: [hxgame-update] ; C:\Program Files\hxupdate\hxgame-update.exe
O4 - HKLM\..\Run: [nwiz] ; nwiz.exe /install
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [RTHDCPL] ; RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] ; SkyTel.EXE
O4 - HKLM\..\Run: [wallpaper] ; c:\windows\system32\壁纸自动换.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: AutoCAD 启动加速器.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - F:\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\Rising\Rav\Ravmond.exe
O23 - Service: Logical Disk Manager Amdindistrative Service6 (S8696666) - Unknown owner - c:\windows\system\m6\iexplorer.exe

gototop
 

高手快来帮忙啊.谢谢了
gototop
 

修复:
O4 - HKLM\..\Run: [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\bind_40254.exe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\bind_40254.exe
O4 - HKLM\..\Run: [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\iis.exe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\iis.exe
O4 - HKLM\..\Run: [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\seveneleven.exe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\seveneleven.exe
O4 - HKLM\..\Run: [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dodolook029.exe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dodolook029.exe
O4 - HKLM\..\Run: [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\setup133.exe] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\setup133.exe
O4 - HKLM\..\Run: [sdmmrnm] C:\WINDOWS\temp\sd151.exe
O23 - Service: Logical Disk Manager Amdindistrative Service6 (S8696666) - Unknown owner - c:\windows\system\m6\iexplorer.exe

重新启动,进入安全模式,显示隐藏文件.删除以下文件.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\bind_40254.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\iis.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\seveneleven.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dodolook029.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\setup133.exe
C:\WINDOWS\temp\sd151.exe
c:\windows\system\m6\iexplorer.exe


gototop
 

进入安全模式以后怎么显示隐藏文件?
gototop
 


我的电脑---文件夹选项----查看----隐藏已知受系统保护的文件勾去掉,显示所有文件勾上,隐藏已知文件类型的扩展名这个勾去掉
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT