瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 落雪呀~~~~跪求高手~~帮看看~~ 有日志~~~

1   1  /  1  页   跳转

落雪呀~~~~跪求高手~~帮看看~~ 有日志~~~

落雪呀~~~~跪求高手~~帮看看~~ 有日志~~~

winlogon.exe 用户名Admin
WINLOGON.EXE .....SYSTEM  每次开机92.kun163.com/reg.htm 和www.kun163.com都会自动登陆 自动在桌面创快捷方式
日志扫描:\
Logfile of HijackThis v1.99.1
Scan saved at 15:43:28, on 2007-1-10
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\Media\winlogon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
E:\辅助工具1\日志扫描\HijackThis.exe

O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - E:\辅助工具1\新建文件夹 (3)\ComDlls\XunLeiBHO_002.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [RavStub] "C:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载 - E:\辅助工具1\新建文件夹 (3)\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - E:\辅助工具1\新建文件夹 (3)\Program\GetAllUrl.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{AD1D7969-BC0A-4CF1-99C6-74A56F787BA0}: NameServer = 202.102.154.3,202.102.152.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{C2757427-5809-41CD-B1F1-799710BA38FF}: NameServer = 202.102.152.3 202.102.154.3
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe

最后编辑2007-01-10 16:40:03
分享到:
gototop
 

winlogon.exe 用户名Admin
WINLOGON.EXE .....SYSTEM  每次开机92.kun163.com/reg.htm 和www.kun163.com都会自动登陆 自动在桌面创快捷方式
gototop
 

【回复“UFO不幸外人”的帖子】没装QQ呀~~ 怕老婆跟我抢机器 从开始就没装QQ~~见笑了~~
gototop
 

好象是解决了~谢谢 ~~~~那些东西没在出来~~~
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT