1   1  /  1  页   跳转

请高手帮忙~

请高手帮忙~

最近中了病毒~什么realplay.exe启动项加载的那种~
搞了半天没搞定~又不想重装`
所以想找高手帮忙分析下报告~
Logfile of HijackThis v1.99.1
Scan saved at 17:36:19, on 2006-9-11
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINNT\Explorer.exe
C:\WINNT\WINLOGON.EXE
C:\WINNT\svchost.exe
C:\WINNT\system32\internat.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINNT\system32\NOTEPAD.EXE
H:\hijackthisv1.99.1\HijackThis.exe

F2 - REG:system.ini: Shell=Explorer.exe 1
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [svc] C:\WINNT\svchost.exe
O4 - HKLM\..\Run: [Torjan Program] C:\WINNT\WINLOGON.EXE
O4 - HKLM\..\RunServices: [Torjan Program] C:\WINNT\WINLOGON.EXE
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [DrvMon.exe] C:\WINNT\system32\DrvMon.exe
O4 - HKCU\..\Run: [svc] C:\WINNT\svchost.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O17 - HKLM\System\CCS\Services\Tcpip\..\{C2C7343C-F510-48B2-A14B-093831E90AAD}: NameServer = 61.177.7.1
O18 - Protocol: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - C:\PROGRA~1\Kingsoft\POWERW~1\XDictExB.dll
O21 - SSODL: SysTray.Exbr - {6368D1FC-6F5C-4f1b-B164-E67214F678E9} - C:\WINNT\system32\oaleekaj.dll (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe

最后编辑2006-09-27 17:11:41
分享到:
gototop
 

有没有专家帮忙啊?
gototop
 

继续顶高手帮我看看乃
gototop
 

【回复“网游游侠”的帖子】
最近病毒真是厉害
我的估计只能重装了~555555555
我没有你说的那些症状了~刚开始的时候好像也有
gototop
 

好了,但是重装的系统
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT