我一使用VAGAA的时候,就自动打开一个网页www.qqabc.com,而且一直处在选中状态!木马克星扫描结果是
c:\windows\downloaded program files\lianzhong_cns.exe 怀疑为3721广告.
c:\windows\system32\auto.exe 怀疑为灰鸽子木马2
c:\WINDOWS\system32\climn.exe 怀疑为baidu广告
c:\WINDOWS\system32\Clsmn.exe 文件被捆绑
c:\WINDOWS\system32\AutoLive.dll 怀疑为3721广告2
HACKTHIS结果Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\wxsyncli.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\killsex2.0\smss.exe
C:\WINDOWS\System32\Clsmn.exe
C:\WINDOWS\system32\internat.exe
D:\Vagaa\Vagaa.exe
C:\Program Files\Iparmor\Iparmor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\桌面\HijackThis.exe
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - Startup: INTERNAT.lnk = C:\WINDOWS\system32\internat.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java 控制台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - D:\Program\浩方对战平台\GameClient.exe
O16 - DPF: {D0A29C6C-AA71-4423-8C4A-5998B774C448} (IEDown Class) - http://download.ourgame.com/IEDown4.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8FA5A451-4BD6-4803-99C5-4FF5603E9F00}: NameServer = 218.2.135.1,202.102.24.35
O20 - Winlogon Notify: DfLogon - C:\WINDOWS\SYSTEM32\LogonDll.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sicent Network File Synchronization (sicentnetsync) - 成都吉胜科技有限公司 - C:\WINDOWS\System32\wxsyncli.exe