瑞星卡卡安全论坛
网游爱好者111 - 2006-1-21 20:22:00
本人今天不小心中了3个病毒,小弟弟想手动删除,请高手指导!
1。文件名:dll.exe
文件夹:C:\WINDOWS\system32
病毒名:Trojan.PSW.Lmir.jdl
2。文件名:update.exe
文件夹:C:\Program Files\Common Files\UPDATE
病毒名:Trojan.DL.QQhelper.h
3。文件名:Network.exe
文件夹:C:\Program Files\Common Files\SAND
病毒名:Adware.Clciker.YNYW.m
下面我把病毒发作的现象简单介绍下!
不知道是哪个病毒发作的时候,机器的显示器突然无视频信号。我这个时候想把机器重新启动,可是重起的按键也不好使,那个大的关机键长按10多秒中也关不了机器,我只有把电源跋掉。
小弟这个菜鸟现在在线等大虾指点!希望高手能给予出现这个现象的原理说明和详细的手动清除这3个病毒的方法。
........
网游爱好者111 - 2006-1-21 20:34:00
哪位大虾能帮帮小弟呀?
网游爱好者111 - 2006-1-21 21:24:00

哪位大哥能帮帮啊。
不言放弃 - 2006-1-21 21:30:00
操作参考:
结束下列文件的进程<若有的话>
C:\WINDOWS\system32\dll.exe
C:\Program Files\Common FilesUPDATE\update.exe
C:\Program Files\Common Files\SAND\Network.exe
进入注册表
依次搜索dll.exe,update.exe,Network.exe
找到后全部删除
<注意路径>
禁用相关服务
<注意路径>
删除
C:\WINDOWS\system32\dll.exe
C:\Program Files\Common FilesUPDATE
C:\Program Files\Common Files\SAND
网游爱好者111 - 2006-1-21 22:15:00
大虾我刚才在结束进程里没有发现,这个三个文件
不过我在注册表里发现了他们三个的踪影,都已经删除了。
可是在重起完机器后Torjan.PSW.Lmir.jdl还是没有删除,在次查毒的时候又出现了
。
请指教!
不言放弃 - 2006-1-21 22:22:00
用HIJACKTHIS导出日志
网游爱好者111 - 2006-1-21 22:23:00
能告诉我下下在那个东西的网只吗?
我是菜鸟啊,不晓得在哪下啊
不言放弃 - 2006-1-21 22:27:00
【回复“网游爱好者111”的帖子】
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
网游爱好者111 - 2006-1-21 22:38:00
浏览器加载项
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v9.dll, Thunder Networking Technologies,LTD>
[Tencent Browser Helper]
{0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\AddrPlus\IEHelp1.dll, Tencent>
[CNNIC_IDN]
{35980F6E-A137-4E50-953D-813BB8556899} <C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll, >
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[WMHlprObj Class]
{F5824EFB-728A-4726-A5A5-85A68B20EDC3} <C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll, >
[免费精彩视频超流畅在线观看]
{022C4009-5283-4365-97BF-144054B40E2E} <http://itv.mop.com, N/A>
[CNNIC_IDN]
{35980F6E-A137-4E50-953D-813BB8556899} <C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll, >
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[PortalCom Control 2.0]
{48038521-20FB-11D8-BC64-00B0D07A8A19} <C:\WINDOWS\DOWNLO~1\PORTAL~1.OCX, Huawei Co. Ltd.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v9.dll, Thunder Networking Technologies,LTD>
[Tencent Browser Helper]
{0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\AddrPlus\IEHelp1.dll, Tencent>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[CNNIC_IDN]
{35980F6E-A137-4E50-953D-813BB8556899} <C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll, >
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[WMHlprObj Class]
{F5824EFB-728A-4726-A5A5-85A68B20EDC3} <C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll, >
[&使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
<C:\Program Files\Thunder Network\Thunder\getallurl.htm, N/A>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
[访问通用网址]
<C:\Program Files\CNNIC\Cdn\cnnic.htm, N/A>
网游爱好者111 - 2006-1-21 22:41:00
正在运行的进程
[PID: 396][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 452][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 484][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 528][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 540][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 696][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 744][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 812][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 884][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1004][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1140][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 1376][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[PID: 1472][C:\Program Files\CNNIC\Cdn\cdnup.exe] <><2, 2, 0, 2>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[C:\Program Files\CNNIC\Cdn\cdntdns.dll] <CNNIC><2, 2, 0, 1>
[PID: 1484][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[PID: 1548][C:\WINDOWS\system32\conime.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[PID: 1760][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 456][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[C:\WINDOWS\system32\xunleibho_v9.dll] <Thunder Networking Technologies,LTD><4, 5, 1, 33>
[C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll] <><2, 1, 0, 2>
[C:\Program Files\Tencent\QQ\QQIEHelper.dll] <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
[C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll] <><1, 0, 0, 4>
[C:\WINDOWS\system32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[PID: 344][E:\waigua\Mir2Facility.exe] <><1, 0, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[C:\WINDOWS\system32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 352][E:\waigua\极限帐号管理器.exe] <><1, 0, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[PID: 1652][C:\Program Files\Internet Explorer\IEXPLORE.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[C:\WINDOWS\system32\xunleibho_v9.dll] <Thunder Networking Technologies,LTD><4, 5, 1, 33>
[C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll] <><2, 1, 0, 2>
[C:\Program Files\Tencent\QQ\QQIEHelper.dll] <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
[C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll] <><1, 0, 0, 4>
[C:\WINDOWS\system32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 840][C:\Program Files\Thunder Network\Thunder\Thunder.exe] <Thunder Networking Technologies,LTD><5.0.6.98>
[C:\Program Files\Thunder Network\Thunder\UpdateDownload.dll] <Thunder Networking Technologies,LTD><1, 0, 0, 1>
[C:\Program Files\Thunder Network\Thunder\download_interface.dll] <Thunder Networking Technologies,LTD><1, 0, 0, 1>
[C:\Program Files\Thunder Network\Thunder\log4cplus.dll] <><1, 0, 2, 1>
[C:\Program Files\Thunder Network\Thunder\stlport_vc646.dll] <STLport Consulting, Inc.><4.6.2003.1031>
[C:\Program Files\Thunder Network\Thunder\historyinfo_manage.dll] <Thunder Networking Technologies,LTD><5, 0, 0, 73>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[C:\Program Files\Thunder Network\Thunder\iThunder.dll] <Thunder Networking Technologies,LTD><1, 0, 0, 30>
[C:\Program Files\Thunder Network\Thunder\RegisterDll.dll] <Thunder Networking Technologies,LTD><1, 0, 1, 4>
[C:\WINDOWS\system32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[PID: 204][C:\Documents and Settings\user\桌面\SREng.exe] <Smallfrogs Studio><2.0.12.350>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[C:\WINDOWS\system32\cdnns.dll] <CNNIC><2, 0, 0, 0>
网游爱好者111 - 2006-1-21 22:42:00
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP Error. [winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
网游爱好者111 - 2006-1-21 22:42:00
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<KavPFW><; "C:\KAV2006\KPFW32.EXE">
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<CdnCtr><C:\Program Files\CNNIC\Cdn\cdnup.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<AddrPlus3><; C:\PROGRA~1\TENCENT\AddrPlus\Runner.exe C:\PROGRA~1\TENCENT\AddrPlus\QAHook1.dll Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<KavStart><; "C:\KAV2006\KAVStart.exe" -startup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Thunder><; "C:\Program Files\Thunder Network\Thunder\ThunderShell.exe" /s>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Update><; C:\Program Files\Common Files\UPDATE\Update.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
不言放弃 - 2006-1-21 22:47:00
进入注册表
删除
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Update><; C:\Program Files\Common Files\UPDATE\Update.exe>
退出注册表
删除C:\WINDOWS\system32\dll.exe
C:\Program Files\Common FilesUPDATE
C:\Program Files\Common Files\SAND
网游爱好者111 - 2006-1-21 22:54:00
能告诉我下下在那个东西的网只吗?
我是菜鸟啊,不晓得在哪下啊
网游爱好者111 - 2006-1-21 23:11:00
我如果在想给你,你能看出问题的东西,得给你发哪一块?
网游爱好者111 - 2006-1-21 23:51:00
完了你下了啊?
那我明天等你消息吧,谢谢了
不言放弃 - 2006-1-22 0:24:00
楼主还有什么问题啊
网游爱好者111 - 2006-1-22 7:52:00
我刚才把系统还原关了,在c盘就没有查到病毒,这样病毒就能够杀掉了吧!
还有就我的显示器,总是自己关闭,然后只能跋电源才能关机器!
这是否跟病毒有关系呢,还是机器本身什么问题,请指教!
网游爱好者111 - 2006-1-22 8:07:00
正在运行的进程
[PID: 396][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 460][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 484][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 528][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 540][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 696][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 756][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 840][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 924][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1004][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1140][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 1368][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[C:\WINDOWS\system32\xunleibho_v9.dll] <Thunder Networking Technologies,LTD><4, 5, 1, 33>
[PID: 1464][C:\Program Files\CNNIC\Cdn\cdnup.exe] <><2, 2, 0, 2>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[C:\Program Files\CNNIC\Cdn\cdntdns.dll] <CNNIC><2, 2, 0, 1>
[PID: 1472][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[PID: 1564][C:\WINDOWS\system32\conime.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[PID: 1192][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 996][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[C:\WINDOWS\system32\xunleibho_v9.dll] <Thunder Networking Technologies,LTD><4, 5, 1, 33>
[C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll] <><2, 1, 0, 2>
[C:\Program Files\Tencent\QQ\QQIEHelper.dll] <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
[C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll] <><1, 0, 0, 4>
[C:\WINDOWS\system32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[PID: 1220][E:\waigua\Mir2Facility.exe] <><1, 0, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[C:\WINDOWS\system32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 220][E:\waigua\极限帐号管理器.exe] <><1, 0, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[PID: 156][D:\gongju\SREng.exe] <Smallfrogs Studio><2.0.12.350>
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] <><2, 0, 0, 9>
[C:\Program Files\CNNIC\Cdn\imaoe.dll] <cnnic><2, 1, 0, 0>
[C:\Program Files\CNNIC\Cdn\cdndet.dll] <><2, 1, 0, 1>
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] <><2, 1, 0, 1>
[C:\WINDOWS\system32\cdnns.dll] <CNNIC><2, 0, 0, 0>
网游爱好者111 - 2006-1-22 8:09:00
这个是我今天早上扫描地,你看看呀,
网游爱好者111 - 2006-1-22 8:30:00
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 8:26:07, 日期 2006-1-22
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CNNIC\Cdn\cdnup.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\waigua\Mir2Facility.exe
E:\waigua\极限帐号管理器.exe
D:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\user\桌面\HijackThis1991zww.exe
R3 - URLSearchHook: (no name) - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - (no file)
R3 - URLSearchHook: (no name) - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - (no file)
R3 - URLSearchHook: QQ Search Hook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\AddrPlus\IEHelp1.dll
O1 - Hosts: 202.103.67.180 auto.search.msn.com
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v9.dll
O2 - BHO: Tencent Browser Helper - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\Program Files\TENCENT\AddrPlus\IEHelp1.dll
O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: WMHlprObj Class - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll
O3 - IE工具栏增项: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - 启动项HKCU\\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - IE右键菜单中的新增项目: 访问通用网址 - C:\Program Files\CNNIC\Cdn\cnnic.htm
O9 - 浏览器额外的按钮: 免费精彩视频超流畅在线观看 - {022C4009-5283-4365-97BF-144054B40E2E} - http://itv.mop.com (file missing)
O9 - 浏览器额外的“工具”菜单项: 播霸电视 - {022C4009-5283-4365-97BF-144054B40E2E} - http://itv.mop.com (file missing)
O9 - 浏览器额外的按钮: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - 浏览器额外的“工具”菜单项: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\cdnns.dll
O11 - Options group: [!CNS] 网络实名
O11 - Options group: [CDNCLIENT] 中文上网
O11 - Options group: [TBH] QQ地址栏搜索插件
O16 - DPF: {48038521-20FB-11D8-BC64-00B0D07A8A19} (PortalCom Control 2.0) - http://221.208.250.138/PortalAX02.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{40897A4C-1AAC-4911-BAEA-C48CBE8532DE}: NameServer = 202.97.224.69 202.97.224.68
O23 - NT 服务: ILAFY - Sysinternals - www.sysinternals.com - C:\DOCUME~1\user\LOCALS~1\Temp\ILAFY.exe
O23 - NT 服务: OAMKUUSRWCLQT - Sysinternals - www.sysinternals.com - C:\DOCUME~1\user\LOCALS~1\Temp\OAMKUUSRWCLQT.exe
O23 - NT 服务: Network System (Universal Disk Manager) - Unknown owner - C:\Program Files\Common Files\SAND\Network.exe (file missing)
O23 - NT 服务: WRYTKWVPHZOIVAP - Sysinternals - www.sysinternals.com - C:\DOCUME~1\user\LOCALS~1\Temp\WRYTKWVPHZOIVAP.exe
新城司令 - 2006-1-22 9:51:00
【回复“不言放弃”的帖子】
同意你的方法。
网游爱好者111 - 2006-1-22 11:24:00
我是个爱学习的人,我比较喜欢手动杀毒,
我想永不言放弃,是绝对乐意帮助喜欢学习的人地。
大家以后有什么问题就问他,他的解答很具体,而且他对别人提出的问题很负责,在这里我表示诚挚的谢意。
网游爱好者111 - 2006-1-22 11:25:00
我是个爱学习的人,我比较喜欢手动杀毒,
我想永不言放弃,是绝对乐意帮助喜欢学习的人地。
大家以后有什么问题就问他,他的解答很具体,而且他对别人提出的问题很负责,在这里我表示诚挚的谢意
邓尼茨 - 2006-1-22 12:02:00
http://www.hanzify.org/?Go=Show::List&ID=7439
这里有下载
网游爱好者111 - 2006-1-22 12:05:00
| 引用: |
【邓尼茨的贴子】http://www.hanzify.org/?Go=Show::List&ID=7439 这里有下载 ........................... |
您的网只是关于哪方面的?
谢谢!
1
© 2000 - 2026 Rising Corp. Ltd.