瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 想不通死了,第3次中同一种毒了,为什么啊?

12   1  /  2  页   跳转

想不通死了,第3次中同一种毒了,为什么啊?

想不通死了,第3次中同一种毒了,为什么啊?

又是一个什么赌博的网站,无限制的跳出来,看来今天又要贴日志了,为什么老是中毒啊?两个月不到,3次了,是我上的网站有问题,还是什么???
最后编辑2005-10-13 23:45:30
分享到:
gototop
 

【回复“NODODO”的帖子】
请用HijackThis1.99.1 扫个日志上来...

gototop
 

及时为您的系统打补丁

及时更新病毒库,升级防火墙

尽量少去一些垃圾网站
gototop
 

为了能去"垃圾"网站,我装瑞星,要完善瑞星的监控注册表功能 :)
gototop
 

【回复“缘来是你吗”的帖子】
如果不打补丁,它们可以轻易击穿IE……
gototop
 

你电脑太虚了吧,楼主
补补~  :D
gototop
 

第4次中毒了~~什么补丁啊?


HijackThis_zww汉化版扫描日志 V1.99.1
保存于      17:29:50, 日期 2002-9-11
操作系统:  Windows 2000 SP4 (WinNT 5.00.2195)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

gototop
 

【回复“NODODO”的帖子】
请您将日志贴全……
gototop
 

字太多了~不让我贴啊~

当前运行的进程:         
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\userinit.exe
C:\WINNT\Explorer.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.438\HijackThis1991zww.exe

O1 - Hosts: 219.153.13.45 www.53900.com
O1 - Hosts: 219.153.13.45 53900.com
O1 - Hosts: 219.153.13.45 tm286.com
O1 - Hosts: 219.153.13.45 www.tm286.com
O1 - Hosts: 219.153.13.45 99244.com
O1 - Hosts: 219.153.13.45 www.99244.com
O1 - Hosts: 219.153.13.45 55555555555.com
O1 - Hosts: 219.153.13.45 www.55555555555.com
O1 - Hosts: 219.153.13.45 www.hklacfour.org
O1 - Hosts: 219.153.13.45 hklacfour.org
O1 - Hosts: 219.153.13.45 www.85852.com
O1 - Hosts: 219.153.13.45 85852.com
O1 - Hosts: 219.153.13.45 www.goodsanya.com
O1 - Hosts: 219.153.13.45 goodsanya.com
O1 - Hosts: 219.153.13.45 www.8hk8.com
O1 - Hosts: 219.153.13.45 8hk8.com
O1 - Hosts: 219.153.13.45 69399.com
O1 - Hosts: 219.153.13.45 www.69399.com
O1 - Hosts: 219.153.13.45 www.xg2005.com
O1 - Hosts: 219.153.13.45 xg2005.com
O1 - Hosts: 219.153.13.45 www.777999.cn
O1 - Hosts: 219.153.13.45 777999.cn
O1 - Hosts: 219.153.13.45 www.hk5568.com
O1 - Hosts: 219.153.13.45 hk5568.com
O1 - Hosts: 219.153.13.45 www.k55669.com
O1 - Hosts: 219.153.13.45 k55669.com
O1 - Hosts: 219.153.13.45 www.hk9669.com
O1 - Hosts: 219.153.13.45 hk9669.com
O1 - Hosts: 219.153.13.45 www.99128.net
O1 - Hosts: 219.153.13.45 99128.net
O1 - Hosts: 219.153.13.45 www.001678.com
O1 - Hosts: 219.153.13.45 001678.com
O1 - Hosts: 219.153.13.45 www.tm533.com
O1 - Hosts: 219.153.13.45 tm533.com
O1 - Hosts: 219.153.13.45 www.xg833.com
O1 - Hosts: 219.153.13.45 xg833.com
O1 - Hosts: 219.153.13.45 www.55229.com
O1 - Hosts: 219.153.13.45 55229.com
O1 - Hosts: 219.153.13.45 542888.com
O1 - Hosts: 219.153.13.45 www.542888.com
O1 - Hosts: 219.153.13.45 www.5787.com
O1 - Hosts: 219.153.13.45 5787.com
O1 - Hosts: 219.153.13.45 www.bbs567.com
O1 - Hosts: 219.153.13.45 bbs567.com
O1 - Hosts: 219.153.13.45 www.994477.cn
O1 - Hosts: 219.153.13.45 994477.cn
O1 - Hosts: 219.153.13.45 www.12shengxiao.com
O1 - Hosts: 219.153.13.45 12shengxiao.com
O1 - Hosts: 219.153.13.45 www.71444.com
O1 - Hosts: 219.153.13.45 71444.com
O1 - Hosts: 219.153.13.45 www.88930.com
O1 - Hosts: 219.153.13.45 88930.com
O1 - Hosts: 219.153.13.45 fy-lou.com
O1 - Hosts: 219.153.13.45 www.fy-lou.com
O1 - Hosts: 219.153.13.45 zcp88.50m.org
O1 - Hosts: 219.153.13.45 www.zcp88.50m.org
O1 - Hosts: 219.153.13.45 tv188.com
O1 - Hosts: 219.153.13.45 www.tv188.com
O1 - Hosts: 219.153.13.45 7699.com
O1 - Hosts: 219.153.13.45 www.7699.com
O1 - Hosts: 219.153.13.45 hktrj.net
O1 - Hosts: 219.153.13.45 www.hktrj.net
O1 - Hosts: 219.153.13.45 htcsy.net
O1 - Hosts: 219.153.13.45 www.htcsy.net
O1 - Hosts: 219.153.13.45 cctv49.net
O1 - Hosts: 219.153.13.45 www.cctv49.net
O1 - Hosts: 219.153.13.45 bbs.0472.net
O1 - Hosts: 219.153.13.45 www.bbs.0472.net
O1 - Hosts: 219.153.13.45 lhkm.com
O1 - Hosts: 219.153.13.45 www.lhkm.com
O1 - Hosts: 219.153.13.45 tv666.net
O1 - Hosts: 219.153.13.45 www.tv666.net
O1 - Hosts: 219.153.13.45 68899.net
O1 - Hosts: 219.153.13.45 www.68899.net
O1 - Hosts: 219.153.13.45 hhj520.com
O1 - Hosts: 219.153.13.45 www.hhj520.com
O1 - Hosts: 219.153.13.45 yys888.net
O1 - Hosts: 219.153.13.45 www.yys888.net
O1 - Hosts: 219.153.13.45 yys888.net
O1 - Hosts: 219.153.13.45 www.yys888.net
O1 - Hosts: 219.153.13.45 slsjst.com
O1 - Hosts: 219.153.13.45 www.slsjst.com
O1 - Hosts: 219.153.13.45 m.xdd.cc
O1 - Hosts: 219.153.13.45 www.m.xdd.cc
O1 - Hosts: 219.153.13.45 hk.ft66.net
O1 - Hosts: 219.153.13.45 www.hk.ft66.net
O1 - Hosts: 219.153.13.45 hkjlf.com
O1 - Hosts: 219.153.13.45 www.hkjlf.com
O1 - Hosts: 219.153.13.45 1000000rmb.com
O1 - Hosts: 219.153.13.45 www.1000000rmb.com
O1 - Hosts: 219.153.13.45 xg789.126.com
O1 - Hosts: 219.153.13.45 www.xg789.126.com
O1 - Hosts: 219.153.13.45 2134.hkyes.com
O1 - Hosts: 219.153.13.45 www.2134.hkyes.com
O1 - Hosts: 219.153.13.45 www3.yc889.com
O1 - Hosts: 219.153.13.45 www.www3.yc889.com
O1 - Hosts: 219.153.13.45 4901.com
O1 - Hosts: 219.153.13.45 www.4901.com
O1 - Hosts: 219.153.13.45 qwmlt.com
O1 - Hosts: 219.153.13.45 www.qwmlt.com
O1 - Hosts: 219.153.13.45 vip06.com
gototop
 

O2 - BHO: apronA Class - {557B9038-FC87-453C-8B08-32D85F46EAC4} - C:\WINNT\RealPlay.Dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINNT\downlo~1\CnsHook.dll
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - IE工具栏增项: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.2001.0001\zh-cn\msntb.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - IE工具栏增项: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRA~1\3721\assist\asbar.dll
O3 - IE工具栏增项: 卡卡安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\Program Files\Rising\KaKaToolBar\kakatool.dll
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - 启动项HKLM\\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - 启动项HKLM\\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - 启动项HKLM\\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.0002.1001\zh-cn\msnappau.exe"
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [DAEMON Tools-2052] "C:\Program Files\D-Tools\daemon.exe"  -lang 2052
O4 - 启动项HKLM\\Run: [helper.dll] C:\WINNT\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - 启动项HKLM\\Run: [CnsMin] Rundll32.exe C:\WINNT\downlo~1\CnsMin.dll,Rundll32
O4 - 启动项HKLM\\Run: [assistse] "C:\PROGRA~1\3721\assistse.exe"
O4 - 启动项HKLM\\Run: [MS-4011 Memory Patch] D:\杀毒\RavSasser.exe -Patch
O4 - 启动项HKLM\\Run: [Services] C:\WINNT\system32\E.tmp
O4 - 启动项HKLM\\Run: [PNPSiteExec] PNPSiteExec.exe
O4 - 启动项HKLM\\RunServices: [PNPSiteExec] PNPSiteExec.exe
O4 - HKCU\..\Run: [Internat.exe] Internat.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [PNPSiteExec] PNPSiteExec.exe
O4 - 启动项HKCU\\RunServices: [PNPSiteExec] PNPSiteExec.exe
O4 - Startup: 腾讯QQ.lnk = G:\qq\QQ.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - IE右键菜单中的新增项目: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - IE右键菜单中的新增项目: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - IE右键菜单中的新增项目: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - IE右键菜单中的新增项目: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - IE右键菜单中的新增项目: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - IE右键菜单中的新增项目: 使用Kugoo下载 - C:\Program Files\KuGoo\KugooDownX.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - G:\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - G:\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - G:\qq\SendMMS.htm
O9 - 浏览器额外的按钮: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm?pid=13720_1006 (file missing)
O9 - 浏览器额外的按钮: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - 浏览器额外的按钮: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - 浏览器额外的按钮: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: kele8 - {84920E5F-3788-49cd-A274-E365578DF174} - http://www.kele8.com/ (file missing)
O9 - 浏览器额外的“工具”菜单项: kele8 - {84920E5F-3788-49cd-A274-E365578DF174} - http://www.kele8.com/ (file missing)
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - G:\qq\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - G:\qq\QQ.EXE
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - 浏览器额外的“工具”菜单项: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - 浏览器额外的“工具”菜单项: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} - http://www.rising.com.cn (file missing)
O9 - 浏览器额外的按钮: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com (file missing)
O11 - Options group: [!CNS]  上网助手-地址栏搜索
O16 - DPF: {5DD731E6-D4F0-11D3-BE3F-00105A6FDA50} ({5DD731E6-D4F0-11D3-BE3F-00105A6FDA50}) - http://218.108.248.143/zvc/plugin/myv3na.cab
O16 - DPF: {733652F9-53EF-4BF1-B391-375980675D6F} (V3PROXL Control) - http://download.3721.com/download/myv3/plugin/myv3light.cab
O16 - DPF: {ABA7CC7F-019D-47DB-A0D2-B3C2B3AC1B44} (Fc2Boot Class) - http://fun.kele8.com/fun/system/fc2boot.cab
O16 - DPF: {C8BD9ACB-F7EC-48E6-BB2F-DAADC6789E9A} (Kingsoft DUBA OnlineScan) - http://ol.db.kingsoft.com/antiscan/setup/KAVClean.CAB
O16 - DPF: {D7F0CC2E-FB09-4B38-B9A7-6807CBCD4859} (NMChatX Control) - http://image2.sina.com.cn/igame/cab/nmchatx.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/ravkill/rsonline.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: MSSQLSERVER - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe (file missing)
O23 - NT 服务: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINNT\system32\NMSSvc.exe
O23 - NT 服务: Microsoft SSL (ssl) - Unknown owner - C:\WINNT\system32\ssl.exe

gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT