我电脑里有个进程IEXPLORER.exe,我用木马克星,瑞星和卡巴斯基都干不掉它,我把进程扫描出来,请高手指点!
操作系统: Windows 2003 SP1 (WinNT 5.02.3790)
浏览器: Internet Explorer v6.00 SP1 (6.00.3790.1830)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpm.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
d:\PROGRA~1\MICROS~2\MSSQL\binn\sqlservr.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Iparmor\Iparmor.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe
C:\WINDOWS\explorer.exe
D:\Program Files\Tencent\QQ\QQ.exe
D:\Program Files\Tencent\QQ\TIMPlatform.exe
D:\Program Files\Tencent\TT\TTraveler.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.500\HijackThis1991zww.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\inituser.exe,C:\WINDOWS\system32\netsend.exe
O1 - Hosts: 172.25.16.16 jhoa.ylc.com.cn
O4 - 启动项HKLM\\Run: [AVPCC> "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe" /wait
O4 - 启动项HKLM\\Run: [rundll31> C:\WINDOWS\system32\IEXPLORER.exe
O4 - 启动项HKLM\\Run: [MSConfig> "C:\WINDOWS\ServicePackFiles\i386\msconfig.exe" /auto
O4 - 启动项HKLM\\RunOnce: [ANetFox ADClean> "C:\PROGRA~1\WI0C91~1\clean.exe" /autokill:127,119,115,111,107,106,99,90,87,81,75,61,56,32,24,126,125,124,123,122,121,120,118,117,116,114,113,112,110,109,108,105,104,103,102,101,100,98,97,96,95,94,93,92,91,89,88,86,85,84,83,82,80,79,78,77,76,74,73,72,71,70,69,68,67,66,65,64,63,62,60,59,58,57,55,54,53,52,51,50,49,48,47,46,45,44,43,42,41,40,39,38,37,36,35,34,33,31,30,29,28,27,26,25,23,22,21,20,19,18,17,16,15,13,12,11,10,9,8,7,6,5,4,3,2,1
O4 - HKCU\..\Run: [ctfmon.exe> C:\WINDOWS\system32\ctfmon.exe
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 使用影音传送带下载 - D:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - IE右键菜单中的新增项目: 使用影音传送带下载全部链接 - D:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - d:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - d:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\espi11.dll
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\espi11.dll
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\espi11.dll
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\espi11.dll
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\espi11.dll
O16 - DPF: {012F24D4-35B0-11D0-BF2D-0000E8D0D146} (AtlCam Class) -
O16 - DPF: {08BCD971-A13B-4D6E-A2A5-E9B2324FC00D} (ClientEXE Class) -
O16 - DPF: {26514F45-355A-11D6-8BFA-00106075BD36} (OaActiveFormX Control) - 共享资源/公用WebDesignerActiveXControl/$File/webdesigneractivex.cab
O16 - DPF: {317642DD-AF52-11D4-BC2A-0050DA8AEE6F} (FileMng Control) -
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) -
O16 - DPF: {5EC7C511-CD0F-42E6-830C-1BD9882F3458} -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {88734439-46D0-42C0-A13F-7E881EE550CF} (Filetran Control) -
O16 - DPF: {B41EEC1E-B17D-4746-84F9-FE5C8E538561} (RPCControl Class) - 共享资源/公用RPCActiveXControl/$File/RPCactivex.cab
O16 - DPF: {C4D88B8E-352B-11D6-BF77-0080C740A177} (Setup Class) -
O16 - DPF: {D0A29C6C-AA71-4423-8C4A-5998B774C448} -
O16 - DPF: {D57A1919-CB3C-461C-8F34-A87A1CD9127E} (My99Launch Control) -
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) -
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl Object) -
O16 - DPF: {E87A4CD6-BA5F-4552-BC4F-8EC240A2755C} (WebRecClient Control) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{507E3B14-FE4C-4EBE-8A42-3415FC2FD8CE}: NameServer = 172.30.16.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{508B3D53-7323-4BAE-A39E-65C7203567D2}: NameServer = 172.30.16.4,61.166.150.101
O17 - HKLM\System\CS2\Services\Tcpip\..\{507E3B14-FE4C-4EBE-8A42-3415FC2FD8CE}: NameServer = 172.30.16.4
O17 - HKLM\System\CS3\Services\Tcpip\..\{507E3B14-FE4C-4EBE-8A42-3415FC2FD8CE}: NameServer = 172.30.16.4
O18 - 列举现有的协议: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: dimsntfy - C:\WINDOWS\SYSTEM32\dimsntfy.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - NT 服务: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - NT 服务: AVP Control Centre Service (AVPCC) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe" /service (file missing)
O23 - NT 服务: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - NT 服务: ewido security suite guard - Unknown owner - F:\Ewido Security Suite Plus\ewidoguard.exe (file missing)
O23 - NT 服务: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - NT 服务: KAV Monitor Service (KAVMonitorService) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpm.exe" /service (file missing)
O23 - NT 服务: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - NT 服务: McAfee Framework 服务 (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - NT 服务: [Sentry5>Monitor Web-Activities (Sentry5AgentA) - Unknown owner - C:\Program Files\softbar.com\Sentry5\SentryAgentA.exe (file missing)
O23 - NT 服务: [Sentry5>Monitor Web-Files (Sentry5AgentB) - Unknown owner - C:\Program Files\softbar.com\Sentry5\SentryAgentB.exe (file missing)
O23 - NT 服务: [Sentry5>Data Communication (Sentry5AgentC) - Unknown owner - C:\Program Files\softbar.com\Sentry5\SentryAgentC.exe (file missing)
O23 - NT 服务: [Sentry5>Monitor SentryServices (Sentry5Dog) - Unknown owner - C:\Program Files\softbar.com\Sentry5\SentryDog.exe
O23 - NT 服务: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - NT 服务: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O4 - 启动项HKLM\\RunOnce: [ANetFox ADClean> "C:\PROGRA~1\WI0C91~1\clean.exe" /autokill:127,119,115,111,107,106,99,90,87,81,75,61,56,32,24,126,125,124,123,122,121,120,118,117,116,114,113,112,110,109,108,105,104,103,102,101,100,98,97,96,95,94,93,92,91,89,88,86,85,84,83,82,80,79,78,77,76,74,73,72,71,70,69,68,67,66,65,64,63,62,60,59,58,57,55,54,53,52,51,50,49,48,47,46,45,44,43,42,41,40,39,38,37,36,35,34,33,31,30,29,28,27,26,25,23,22,21,20,19,18,17,16,15,13,12,11,10,9,8,7,6,5,4,3,2,1
这个什么东东啊????
问题:
O4 - 启动项HKLM\\Run: [rundll31> C:\WINDOWS\system32\IEXPLORER.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\inituser.exe,C:\WINDOWS\system32\netsend.exe
修复后,删除“C:\WINDOWS\system32\IEXPLORER.exe”“C:\WINDOWS\system32\inituser.exe”“C:\WINDOWS\system32\netsend.exe”
再修复一下(file missing)的项吧,文件已丢失。。。
俺补充一下:
01 - Hosts: 172.25.16.16 jhoa.ylc.com.cn
直接修复
我也中了这个毒,,
杀不掉
原帖由 花花无缺 于 2006-7-2 04:07 发表
我也中了这个毒,,
杀不掉
:(:'( |
|