瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 请看看我的日志,帮帮我
yy1111yy - 2006-8-4 21:02:00

我现在用的是TT这个浏览器,没有用IE了,但是没有开IE的情况下每几分钟IE就跳出来登陆1个广告那样的网站(有几个不同的网站),我用卡卡助手,广告拦截,IE修复这些都没有用,请看看我的日志,帮帮我



Logfile of HijackThis v1.99.1
Scan saved at 20:48:03, on 2006-8-4
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\cmmon.exe
C:\windows\Explorer.EXE
C:\windows\system32\spoolsv.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\windows\system32\rundll32.exe
C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
C:\windows\system32\Client.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\windows\WINLOGON.EXE
C:\windows\system32\ctfmon.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\rundll32.exe
C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
C:\windows\System32\svchost.exe
C:\windows\system32\Rundll32.exe
C:\Program Files\Raxco\PerfectDisk\PDSched.exe
C:\Program Files\ADSL拨号王\HNMainUI.exe
C:\Program Files\Common Files\smartde\sde.exe
C:\Program Files\Tencent\TT\TTraveler.exe
C:\BT发片文档\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\windows\system32\userinit.exe,C:\windows\system32\cmmon.exe
O2 - BHO: Shockwave Flash Object - {14A21378-5BB1-4BC4-95D5-5D3F51527F6F} - C:\WINDOWS\system32\smflash.ocx
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O2 - BHO: MEobjectSDT - {D4D5C535-BA95-4327-870D-A33826FDD17A} - C:\windows\system32\obwbkya.dll
O2 - BHO: 1 - {E78F50F9-51CF-40EC-AE3F-4F802528150B} - C:\windows\Downloader.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\windows\system32\kakatool.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DAEMON Tools-2052] "C:\Program Files\D-Tools\daemon.exe"  -lang 2052
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\windows\DOWNLO~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [System] C:\windows\system32\Client.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [Torjan Program] C:\windows\WINLOGON.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: >>彩信发送<< - res://C:\PROGRA~1\MMSASS~1\mmsass~1.dll/mms.htm
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - Extra 'Tools' menuitem: 彩E精灵设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O11 - Options group: [CDNCLIENT]  中文上网
O17 - HKLM\System\CCS\Services\Tcpip\..\{C04B20E6-92B8-45EF-8AFF-5C5636E821D4}: NameServer = 61.128.128.68 61.128.192.68
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\windows\system32\mbprot.dll (file missing)
O23 - Service: .Net Boot Service - Unknown owner - C:\windows\system32\big5_gb2312.exe (file missing)
O23 - Service: Database information combine (DbooInfo) - 易易加速科技有限公司 - C:\windows\dbmsinfo.exe
O23 - Service: Local Network Service - Unknown owner - C:\windows\system32\SeedServ.exe
O23 - Service: P4P Service - Sohu.com Inc. - C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: Routing and Remote Manager (RemAccMan) - Unknown owner - C:\Program Files\Outlook Express\Operater.exe (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: SDAgent Service (SDAgentService) - 北京兴华基业软件技术有限公司 - C:\Program Files\Common Files\smartde\sde.exe
1
查看完整版本: 请看看我的日志,帮帮我