瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【讨论】下午出现的病毒【求助】

1   1  /  1  页   跳转

【讨论】下午出现的病毒【求助】

【讨论】下午出现的病毒【求助】

下午有一个QQ号里面有木马病毒.是被盗在找回来的.用QQ医生检查没问题. 刚一登上,QQ就消失在屏幕上.怎么也找不到,我想在登一次说已经重复.我就用瑞星杀毒,杀到一半全部停了.然后就什么也动不了,关机也不行. 从主机上也关不掉,过半小时以后自己又恢复正常.我也没点关机,就自己重启.刚才在杀毒出像一个日志,请问是什么?
Logfile of Kaka v2. 0. 3. 0 Scan Module v1. 0. 6. 1
Scan saved at 18:49:00, on 2007-06-30
Platform: Personal  (Build 6000)
MSIE: Internet Explorer v7.00 0 (7.00.6000.16386 (vista_rtm.061101-2205))


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\Windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,default_page_url=http://www.lenovo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page=http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page=http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: CBrowseStakeout Class - {55302805-482E-470E-8A57-6795A1487F90} - C:\kav2007\KAVAFish.DLL
O2 - BHO: Thunder Browser Helper - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Unattend0000000001{05ADE364-9E15-4DB1-9C53-3D8681E83E4C}] C:\Windows\test.bat
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SkDaemond] C:\Program Files\联想\联想标准键盘驱动\SkDaemond.exe
O4 - HKLM\..\Run: [autotask] C:\ProgramData\Lenovo\nsp\bin\autotask.exe
O4 - HKLM\..\Run: [LiveUpdate_uiServier] C:\Program Files\Lenovo\LiveUpdate\UiServer.exe
O4 - HKLM\..\Run: [KavStart] "C:\kav2007\KAVStart.exe" -startup
O4 - HKLM\..\Run: [EagleEye] C:\Program Files\lenovo\tuEagles\EagleSvr.exe
O4 - HKLM\..\Run: [runeip] C:\Program Files\Rising\AntiSpyware\runiep.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: &使用迅雷下载 - D:\Program Files\Thunder Network\Thunder\Program\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\Program Files\Thunder Network\Thunder\Program\getallurl.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ表情 - D:\QQ2007\AddEmotion.htm
O8 - Extra context menu item: 豪杰超级解霸V8实时播放 - C:\Herosoft\HeroV8\MPURLGET.HTM
O9 - Extra Button: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra Button: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra 'Tools' menuitem: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra Button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -  (file missing)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: *.127.0.0.1 (HKLM)
O15 - Trusted Zone: *.zcom.com (HKLM)
O18 - Filter : application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll
O18 - Filter : application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll
O18 - Filter : application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll
O18 - Filter : text/html - {F79B2338-A6E7-46D4-9201-422AA6E74F43} - C:\Windows\EagleFlt.dll
O18 - Filter : text/html - {F79B2338-A6E7-46D4-9201-422AA6E74F43} - C:\Windows\EagleFlt.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - (no file)
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - (no file)
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - (no file)
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - (no file)
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - (no file)
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - (no file)
最后编辑2007-07-01 00:03:20
分享到:
gototop
 

我可怜的电脑啊!

你可以用系统盘启动到WINDOWS故障恢复台进行修复操作了
gototop
 

用SReng扫描吧
gototop
 

O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - (no file)
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - (no file)
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - (no file)
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - (no file)
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - (no file)
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - (no file)
O18 - Protocol: msdaipp - (no CLSID) - (no file)
好多协议都被破坏了
gototop
 

下载 System Repair Engineer系统扫描工具软件,下载地址如下:
http://www.kztechs.com/sreng/download.html
扫描和上传日志的方法:
1、解压缩所下载的sreng2.zip压缩包;
2、打开已经解压缩的SRENG文件夹,双击运行其中的SREng.exe(如果不能运行,请删除已经解压的SRENG文件夹和其包含的所有文件,重新下载新的压缩包或用已下载的压缩包重新解压,解压时请将解压后的文件夹名改为111,解压后,进入111文件夹,不要运行其中的SREng.exe这个可执行文件,先将其直接改名为111.bat、111.scr、111.com或111.pif,或者改为111.exe,然后再双击运行);
3、依次按“智能扫描”、“扫描”、“保存报告”,将日志保存到硬盘上;
4、找到并打开日志,把日志中的内容用“复制”--“粘贴”命令拷贝到帖子上,不要修改地传上来(日志很长,一个帖子搞不完,请手动将全部内容分多个回复帖子传上来)。
友情提示:
扫描日志前关闭所有手工打开的软件和窗口。
注意在没有进一步提示前,请勿用SRENG工具胡乱修复,否则系统可能变的情况更糟。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT