瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 这个病毒太狠了,我实在是杀不掉,请高手指教?

1   1  /  1  页   跳转

这个病毒太狠了,我实在是杀不掉,请高手指教?

这个病毒太狠了,我实在是杀不掉,请高手指教?

我的机子在没有程序运行的情况下,在资源管理器里老是显示有网络活动,并且在启动是还自动想关我的防火强和杀毒软件,有时连资源管理器都打不开?

附件附件:

下载次数:0
文件类型:image/pjpeg
文件大小:
上传时间:2005-11-11 23:03:55
描述:



最后编辑2005-11-15 00:05:36
分享到:
gototop
 

我现在被逼的只有使用System Safety Monitor能暂时控制一下,但不是长久之计啊,请高手帮帮我吧!
还忘说了一点就是: 有时我的防火强安全级别被莫名奇妙篡改,可恶之极!!!
gototop
 

安全模式下也杀过,但提示无法处理!

Logfile of HijackThis v1.99.1
Scan saved at 10:21:22, on 2005-11-12
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\nvsvc32.exe
d:\System Safety Monitor\SSMService.exe
C:\WINDOWS\Explorer.EXE
d:\System Safety Monitor\sysSafe.exe
C:\WINDOWS\Mixer.exe
D:\SKYNET\FIREWALL\pfw.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Maxthon\Maxthon.exe
D:\HijackThis\HijackThis.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,C:\WINDOWS\easen\rundll.exe,
O1 - Hosts: 211.167.92.11 www.jrj.com.cn #0
O1 - Hosts: 61.136.162.4 www.checheng.net #0
O1 - Hosts: 211.160.73.26 www.btchina.net #0
O1 - Hosts: 218.5.79.59 www.okbt.com #0
O1 - Hosts: 70.85.48.252 70.85.48.252 #0
O1 - Hosts: 61.152.160.98 www.bt990.com #0
O1 - Hosts: 67.15.57.101 bbs.morok.net #0
O1 - Hosts: 210.22.13.173 www.emumax.com #0
O1 - Hosts: 61.129.85.214 emugif.emu-zone.org #0
O1 - Hosts: 61.145.112.78 j2c.emu-zone.org #0
O1 - Hosts: 61.145.112.78 www.emu-zone.org #0
O1 - Hosts: 218.16.124.114 www.romman.net #0
O1 - Hosts: 218.201.40.171 www.emusun.net #0
O1 - Hosts: 221.209.119.9 www.chinaemu.org #0
O1 - Hosts: 219.136.252.180 aier.6to23.com #0
O1 - Hosts: 64.193.110.132 www.freepgs.com #0
O1 - Hosts: 61.153.44.219 kofbobo.chinae3.com #0
O1 - Hosts: 202.109.114.134 www2.emu-zone.org #0
O1 - Hosts: 211.98.81.47 www.fireemblem.net #0
O1 - Hosts: 61.180.86.7 www.ppxbbs.com #0
O1 - Hosts: 218.57.135.54 www.egcg.net #0
O1 - Hosts: 219.142.91.11 www.icbc.com.cn #0
O1 - Hosts: 211.162.39.129 www.redfour.com.cn #0
O1 - Hosts: 202.101.43.39 www.163down.com #0
O1 - Hosts: 61.242.253.60 www.skycn.com #0
O1 - Hosts: 61.129.33.169 down.81000.net #0
O1 - Hosts: 61.139.126.27 www.cuiv.com #0
O1 - Hosts: 202.43.216.55 cn.yahoo.com #0
O1 - Hosts: 202.101.43.16 www.crsky.com #0
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v8.dll
O2 - BHO: Shockwave Flash BrowserHelpObject - {1002C84D-A326-2D3C-13F3-2C2474392A91} - C:\WINDOWS\System32\FlashHlp.dll
O2 - BHO: IeControler Class - {9AFD91F9-6B03-4D22-A1E1-67D224CB7AB1} - d:\NetSpeeder\IEMate.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\FlashGet\jccatch.dll
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - C:\PROGRA~1\YiSou\yisoub.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: 天下搜索 - {56A7DC70-E102-4408-A34A-AE06FEF01586} - C:\WINDOWS\Downloaded Program Files\iebar22.0.dll
O3 - Toolbar: (no name) - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - (no file)
O3 - Toolbar: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\Program Files\YiSou\yisou.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [KAVPersonal50] d:\Kasper\kav.exe /minimize
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MINI_BFYY] D:\Storm Downloader\StormDownloader.exe
O4 - HKLM\..\Run: [SKYNET Personal FireWall] D:\SKYNET\FIREWALL\pfw.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载 - D:\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\Thunder\getallurl.htm
O8 - Extra context menu item: 使用网际快车下载 - D:\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\FlashGet\jc_all.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\OFFICE\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\FlashGet\flashget.exe
O11 - Options group: [!ANetSpeeder]  NetSpeeder
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} (天下搜索) - http://iebar.t2t2.com/iebar.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131442180886
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{19829D6C-4EE0-4B2C-9C2C-519A3AAE9A03}: NameServer = 202.103.44.5 202.103.0.117
O17 - HKLM\System\CS2\Services\Tcpip\..\{19829D6C-4EE0-4B2C-9C2C-519A3AAE9A03}: NameServer = 202.103.44.5 202.103.0.117
O20 - AppInit_DLLs: APIHookDll.dll
O20 - Winlogon Notify: System Safety Monitor - C:\WINDOWS\SYSTEM32\SSMWinlogonEx.dll
O23 - Service: kavsvc - Kaspersky Lab - d:\Kasper\kavsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: System Safety Monitor (SSM) - System Safety - d:\System Safety Monitor\SSMService.exe

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT