瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 高手帮我看看日志,开机时瑞星监控开不了

1   1  /  1  页   跳转

高手帮我看看日志,开机时瑞星监控开不了

高手帮我看看日志,开机时瑞星监控开不了

Logfile of HijackThis v1.99.1
Scan saved at 18:17:26, on 2007-4-1
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\MINIUS~1\SrtWatch.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Rising\Rav\RavTask.exe
D:\Temp\1632.exe
C:\WINDOWS\system32\ctfmon.exe
D:\小软件\日志工具\HijackThis.exe

O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - D:\小软件\网际快车\SubDirectory\jccatch.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - D:\小软件\网际快车\SubDirectory\getflash.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [SrtWatch] C:\PROGRA~1\MINIUS~1\SrtWatch.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [ROST] D:\Temp\1632.exe
O4 - HKLM\..\Run: [winform] C:\WINDOWS\winform.exe
O4 - HKCU\..\Run: [bgswitch] C:\WINDOWS\system32\bgswitch.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [g56m5ww4] d:\Temp\rundl132.exe
O8 - Extra context menu item: &使用快车(FlashGet)下载 - D:\小软件\网际快车\SubDirectory\jc_link.htm
O8 - Extra context menu item: &使用快车(FlashGet)下载全部链接 - D:\小软件\网际快车\SubDirectory\jc_all.htm
O9 - Extra button: 快车 - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\小软件\网际快车\SubDirectory\FlashGet.exe
O9 - Extra 'Tools' menuitem: 快车(FlashGet) - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\小软件\网际快车\SubDirectory\FlashGet.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{CA4635A7-CD46-4E0F-A516-283186B09E1C}: NameServer = 202.88.168.77,202.88.166.5
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
最后编辑2007-04-01 18:38:32
分享到:
gototop
 

O4 - HKLM\..\Run: [ROST] D:\Temp\1632.exe
O4 - HKCU\..\Run: [g56m5ww4] d:\Temp\rundl132.exe
O4 - HKLM\..\Run: [winform] C:\WINDOWS\winform.exe

修复诸上,删除如下:
C:\WINDOWS\winform.exe
d:\Temp\rundl132.exe
D:\Temp\1632.exe
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT