1   1  /  1  页   跳转

操,土匪D种来袭了

操,土匪D种来袭了

最近也不知道从哪染来了tufei.d病毒,用瑞星在DOS下也杀不掉,土匪进村子站住INTELNET不放了,真牛逼,谁给想个辄,感激不尽
最后编辑2005-11-01 18:49:41
分享到:
gototop
 

补充一下日志
ogfile of HijackThis v1.99.1
Scan saved at 23:58:33, on 2005-10-31
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Audio Deck\EnMixCPL.exe
D:\KILLVI~1\RAV\RAVTIMER.EXE
D:\KILLVI~1\RAV\RAVMON.EXE
C:\WINDOWS\system32\ctfmon.exe
D:\KILLVIRUS\RAV\CCENTER.EXE
D:\KILLVIRUS\RAV\Ravmond.exe
D:\KILLVIRUS\RAV\RavStub.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\jyb\桌面\HijackThis.exe

O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v5.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SKYNET Personal FireWall] D:\应用\FireWall\pfw.exe
O4 - HKLM\..\Run: [EnvyHFCPL] C:\Program Files\Audio Deck\EnMixCPL.exe
O4 - HKLM\..\Run: [RavTimer] D:\KILLVI~1\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] D:\KILLVI~1\RAV\RAVMON.EXE -SYSTEM
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{EAD8273F-5CA9-428D-BA80-28DB91C1AB06}: NameServer = 221.11.1.67 202.99.192.68
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - D:\KILLVIRUS\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\KILLVIRUS\RAV\Ravmond.exe

gototop
 

用此软件点扫描生成后的文挡就这些
gototop
 

用此软件点扫描生成后的文挡就这些
gototop
 

瑞星杀毒时它占着IE不走,DOS下也搞不掉,真烦人
gototop
 

名称explorer.exe
病毒tufei.d
gototop
 

快谁给想个辄
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT