瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 电脑中了病毒呀,老是有tdll.dll、msd2.dll 、msd2.exe ,瑞星杀不到

1   1  /  1  页   跳转

电脑中了病毒呀,老是有tdll.dll、msd2.dll 、msd2.exe ,瑞星杀不到

电脑中了病毒呀,老是有tdll.dll、msd2.dll 、msd2.exe ,瑞星杀不到

Logfile of HijackThis v1.99.1
Scan saved at 11:14:13, on 2006-12-14
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\Program Files\Rising\Rav\CCenter.exe
D:\Program Files\Rising\Rav\Ravmond.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\msdtc.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\System32\llssrv.exe
D:\WINNT\System32\mgabg.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\Program Files\Rising\Rav\RavStub.exe
D:\WINNT\system32\WFXSVC.EXE
D:\Program Files\Symantec\WinFax\WFXMOD32.EXE
D:\WINNT\system32\CAP2RSK.EXE
D:\WINNT\Explorer.EXE
D:\WINNT\system32\taskmgr.exe
D:\WINNT\SOUNDMAN.EXE
D:\WINNT\system32\wfxsnt40.exe
D:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
D:\Program Files\Rising\Rav\RavTask.exe
D:\Program Files\Rising\Rav\Ravmon.exe
D:\Program Files\Microsoft\svhost32.exe
D:\WINNT\Config\svhost32.exe
D:\WINNT\Microsoft\rundll32.exe
D:\WINNT\system32\internat.exe
D:\WINNT\system32\spool\drivers\w32x86\3\CAP2LAK.EXE
D:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP2SWK.EXE
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
D:\WINNT\system32\svchost.exe
D:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
D:\WINNT\down\rundll32.exe
D:\WINNT\system32\Dfssvc.exe
D:\WINNT\System32\inetsrv\inetinfo.exe
D:\WINNT\System32\svchost.exe
D:\Program Files\SkyNet\FireWall\PFW.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Documents and Settings\patent02\桌面\hijackthis\HijackThis.exe

R3 - URLSearchHook: (no name) - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - f:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - Toolbar: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - D:\PROGRA~1\Kingsoft\FASTAI~1\IEBand.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - D:\WINNT\system32\KakaTool.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [assistse] "D:\PROGRA~1\3721\assistse.exe"
O4 - HKLM\..\Run: [OrderReminder] D:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [FinePrint 分配器 v5] "D:\WINNT\system32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" /runonce
O4 - HKLM\..\Run: [RavTask] "D:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RavScanBD] "D:\Program Files\Rising\Rav\ScanBD.exe" /INST
O4 - HKLM\..\Run: [load] D:\WINNT\uninstall\rundl132.exe
O4 - HKLM\..\Run: [ms] D:\Program Files\Microsoft\svhost32.exe
O4 - HKLM\..\Run: [fzg] D:\WINNT\Config\svhost32.exe
O4 - HKLM\..\Run: [Micro] D:\WINNT\Microsoft\rundll32.exe
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - Global Startup: Canon LASER SHOT LBP-1210 状态窗口.LNK = D:\WINNT\system32\spool\drivers\w32x86\3\CAP2LAK.EXE
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Picture Package VCD Maker.lnk = D:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
O4 - Global Startup: Picture Package Menu.lnk = D:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: 上传到QQ网络硬盘 - G:\prog\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用网际快车下载 - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - G:\prog\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - G:\prog\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - G:\prog\QQ\SendMMS.htm
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: 金山词霸 - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - D:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - G:\prog\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - G:\prog\QQ\QQ.EXE
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - f:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - f:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {A3CD7F74-93C9-4BC4-B892-CCDF1514F714} (Submit Class) - https://pbank.95559.com.cn/personbank/ocx/safe.cab
O16 - DPF: {DDA166FA-B3EA-4A3B-8EE2-4F552CDEEE81} (KATScan Control) - http://ol.db.kingsoft.com/antitrojan/setup/KATScan.CAB
O16 - DPF: {E4CF9B52-A94E-4A27-AD90-904A81D0643A} (QPicControl Control) - http://my.paipai.com/activex/qpic.cab
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl Object) - https://www.tenpay.com/download/qqedit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9AF702E7-C91D-49BF-B8B3-0D4E47652DAB}: NameServer = 202.96.128.86,202.96.128.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{9AF702E7-C91D-49BF-B8B3-0D4E47652DAB}: NameServer = 202.96.128.86,202.96.128.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{9AF702E7-C91D-49BF-B8B3-0D4E47652DAB}: NameServer = 202.96.128.86,202.96.128.68
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: Intel PDS - Unknown owner - D:\WINNT\system32\cba\pds.exe (file missing)
O23 - Service: Macromedia Licensing Service - Unknown owner - D:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - D:\WINNT\System32\mgabg.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - D:\WINNT\system32\WFXSVC.EXE
最后编辑2006-12-14 11:20:44
分享到:
gototop
 

baohe大侠能不能帮忙看下日志呀
gototop
 

baohe、小聪大侠在不?帮忙看看吧
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT