1   1  /  1  页   跳转

求救啊!!!

求救啊!!!

我绝对是个菜鸟,电脑种木马了用瑞星怎么也杀不掉,显示清除了在杀还有.
请各位高手帮帮我吧!小弟先在这里谢谢大家了.以下是杀毒的记录!
Backdoor.Gpigeon.2006.ug        清除成功        2006-11-30 23:48        手动扫描        Explorer.exe>>C:\WINDOWS\G_winraKey.DLL                本机
Backdoor.Gpigeon.2006.ug        清除成功        2006-11-30 23:48        手动扫描        RfwMain.exe>>C:\WINDOWS\G_winraKey.DLL                本机
Backdoor.Gpigeon.2006.ug        清除成功        2006-11-30 23:49        手动扫描        IEXPLORE.EXE>>C:\WINDOWS\G_winraKey.DLL                本机
Backdoor.Gpigeon.2006.ug        清除成功        2006-11-30 23:49        手动扫描        SOUNDMAN.EXE>>C:\WINDOWS\G_winraKey.DLL                本机
Backdoor.Gpigeon.2006.ug        清除成功        2006-11-30 23:49        手动扫描        SMax4PNP.exe>>C:\WINDOWS\G_winraKey.DLL                本机
Backdoor.Gpigeon.2006.ug        清除成功        2006-11-30 23:49        手动扫描        Smax4.exe>>C:\WINDOWS\G_winraKey.DLL                本机
Backdoor.Gpigeon.2006.ug        清除成功        2006-11-30 23:49        手动扫描        VM_STI.EXE>>C:\WINDOWS\G_winraKey.DLL                本机
Backdoor.Gpigeon.2006.ug        清除成功        2006-11-30 23:49        手动扫描        ctfmon.exe>>C:\WINDOWS\G_winraKey.DLL                本机

最后编辑2006-12-01 02:28:18
分享到:
gototop
 

请到我的网盘http://free5.ys168.com/?echowj下载Hijackthis
下载后运行HijackThis.rar,再运行HijackThis.exe
单击"扫描日志并保存日志"
把保存的日志复制粘贴上来. 日志一次粘不完,分次粘完,请不要修改.
查到病毒的,把病毒文件名和路径提供下。描述下故障现象
gototop
 

下面是我用1楼哪位大哥给的东西弄的日志.
Logfile of HijackThis v1.99.1
Scan saved at 1:50:32, on 2006-12-1
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
E:\瑞星\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
E:\瑞星\Rising\Rav\Ravmond.exe
e:\瑞星防火墙\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
E:\瑞星\Rising\Rav\RavStub.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\Explorer.exe
e:\瑞星防火墙\rising\rfw\RfwMain.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
E:\瑞星\Rising\Rav\RavTask.exe
E:\瑞星\Rising\Rav\Ravmon.exe
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\system32\ctfmon.exe
E:\瑞星\Rising\Rav\Rav.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\new\桌面\新建文件夹 (5)\HijackThis.exe

F2 - REG:system.ini: Shell=Explorer.exe ChangeDisplay.exe
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\QQ2005\QQIEHelper.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O3 - Toolbar: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - C:\DOCUME~1\new\桌烂面鎈\新陆建ㄎ文膥~3\IEBand.dll (file missing)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [RavTask] "E:\瑞星\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "E:\瑞星防火墙\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE USB PC Camera 301P
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [boot-hf] c:\windows\BOOT-hf.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\QQ2005\AddToNetDisk.htm
O8 - Extra context menu item: 使用影音传送带下载 - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\QQ2005\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\QQ2005\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\QQ2005\SendMMS.htm
O9 - Extra button: 微软 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.microsoft.com/china/index.htm (file missing)
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\QQ2005\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\QQ2005\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\QQ2005\QQIEHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{426F83EA-EA44-478B-AE0F-BF757E641560}: NameServer = 202.99.166.4 202.99.160.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{426F83EA-EA44-478B-AE0F-BF757E641560}: NameServer = 202.99.166.4 202.99.160.68
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - e:\瑞星防火墙\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - e:\瑞星防火墙\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - E:\瑞星\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\瑞星\Rising\Rav\Ravmond.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: interinat (spoolesv) - Unknown owner - C:\WINDOWS\G_winra.exe
O23 - Service: svchstt1 - Unknown owner - C:\WINDOWS\svchstt1.exe
O23 - Service: VPort2005_In_Lan (VPort2005_Lan) - Unknown owner - C:\WINDOWS\system32\VPort1.1.exe

gototop
 

哪位给看看啊.
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT