123   1  /  3  页   跳转

惊现Trojan.Agent.dln,付日志和SRE

惊现Trojan.Agent.dln,付日志和SRE

如题~!请帮下解决```谢谢
Logfile of HijackThis v1.99.1
Scan saved at 15:11:48, on 2006-10-9
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
E:\Rising\Rav\CCenter.exe
E:\Rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
E:\Rising\Rav\RavStub.exe
C:\WINNT\Explorer.EXE
C:\WINNT\SOUNDMAN.EXE
E:\Rising\Rav\RavTask.exe
E:\Rising\Rav\Ravmon.exe
C:\WINNT\system32\internat.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\WINNT\system32\NOTEPAD.EXE
E:\我的音乐\迅雷\VIPHy-Tata\TT\TTraveler.exe
E:\我的音乐\迅雷\Program\Thunder5.exe
E:\Rising\Rav\RsAgent.exe
C:\WINNT\msagent\AgentSvr.exe
E:\我的音乐\迅雷\VIPHy-Tata\qq\QQ.exe
E:\我的音乐\迅雷\VIPHy-Tata\qq\TIMPlatform.exe
E:\Downloads\ha_hijackthis_1991\HijackThis.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5034.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - E:\我的音乐\迅雷\VIPHy-Tata\qq\QQIEHelper.dll
O2 - BHO: DownloadBHO T2BHO - {B1D147E7-873E-4909-8127-695D9BB78728} - C:\WINNT\Downloaded Program Files\barhelp24.0.dll
O2 - BHO: 信息检索 - {CE7C3CF0-98A8-474D-B2B5-1ED7E2E3B004} - C:\WINNT\system32\IEHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O3 - Toolbar: 天下搜索 - {56A7DC70-E102-4408-A34A-AE06FEF01586} - C:\WINNT\Downloaded Program Files\iebar23.0.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RavTask] "E:\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &使用迅雷下载 - E:\我的音乐\迅雷\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - E:\我的音乐\迅雷\Program\GetAllUrl.htm
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: 上传到QQ网络硬盘 - E:\我的音乐\迅雷\VIPHy-Tata\qq\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\我的音乐\迅雷\VIPHy-Tata\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\我的音乐\迅雷\VIPHy-Tata\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\我的音乐\迅雷\VIPHy-Tata\qq\SendMMS.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - E:\我的音乐\迅雷\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - E:\我的音乐\迅雷\Thunder.exe
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\我的音乐\迅雷\VIPHy-Tata\qq\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\我的音乐\迅雷\VIPHy-Tata\qq\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\我的音乐\迅雷\VIPHy-Tata\qq\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\我的音乐\迅雷\VIPHy-Tata\qq\QQIEHelper.dll
O9 - Extra button: YOK超级搜索 - {F869BB38-FFEF-4589-B986-610B7AD0ADA2} - http://www.yok.com (file missing)
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O16 - DPF: {18F57D30-EF36-4C0E-9343-7BFA6DF79B4A} - http://active.micr0media.com/swflash.CAB
O16 - DPF: {285C55C4-B32C-4EC0-8539-BBCE97FDF380} (SuperStream Control) - http://listen.sdo.com/video_ddo/SuperRelease.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {43E839C5-E10F-443A-BC1F-F09CFD2ABC77} (updatePanelX Control) - http://www.uusee.com/player/updateC.cab
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/1007/aliedit.cab
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} (天下搜索) - http://iebar.t2t2.com/iebar.cab
O16 - DPF: {79312BD7-AB1A-4730-829F-F43C984D0A9D} (ACNSTAT Class) - http://www.ctsunion.com/CTS.CAB
O16 - DPF: {C661F36D-DF85-4EF4-83C7-E107B83D04B1} (WebActivater Control) - http://dl_dir.qq.com/3dshow/3DShowVM.cab
O16 - DPF: {DD713965-ECD7-407B-A886-FCF999BB6765} (SnSubmitControl Class) - http://jf.sdo.com/sndasec.cab
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl Object) - https://www.tenpay.com/download/qqedit.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} - http://ps.itv.mop.com/dn/files/pCastCtl-1.0.0.90-signed.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{BAD67DEA-CDD2-4EE2-9A59-455EF18348D9}: NameServer = 202.103.225.68 202.103.224.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{C56C25A2-9108-4615-B48C-F6C1CB428D52}: NameServer = 202.103.224.68,202.103.225.68
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Number of any portable media. - Unknown owner - C:\WINNT\system32\command.com
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Protected content might services - Unknown owner - C:\WINNT\system32\SVCH0ST.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - E:\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\Rising\Rav\Ravmond.exe

附件附件:

下载次数:249
文件类型:application/octet-stream
文件大小:
上传时间:2006-10-9 15:23:54
描述:



最后编辑2006-10-10 22:53:28
分享到:
gototop
 

顶~!
gototop
 

修复
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5034.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
去我的e盘mizuki.ys168.com下载LSPFix和WinsockxpFix
用LSPFix修复所有的010项,修复后如果不能上网就用WinsockxpFix修复
gototop
 

是去安全模式下修复么?
gototop
 

用LSPFix修复所有的010项
这个软件我有,但是进去没有010项``(你说的软件我都有)
具体怎么操作呢?
gototop
 

还有我SRE  少描的我该怎么修复呢?
gototop
 

ding
gototop
 

顶上去啊``
gototop
 

ding
gototop
 

请到www.27814939.ys168.com,点“我的软件”下载360LSPFix.exe,删除
请到http://forum.ikaka.com/topic.asp?board=67&artid=5188931,下载,LSPFix.exe,WinsockXPFix这两个软件
重新启动电脑, 开机检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式进入Windows

运行LSPFix.exe
删除
gdiplus32.dll
附说明一份
LSPFix.exe这个软件主要用来辅助修复HijackThis扫描发现的O10项。
使用时,请关闭所有IE界面和文件夹界面后运行LSPFix,运行后,把要修复的那一个O10项从左边转到右边,点“Finish”即可。(不过这之前,需要在“I know what I`m doing”前面打勾。)
双击我的电脑,工具,文件夹选项,查看,单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示确定更改时,单击“是”,清除“隐藏已知文件类型的扩展名
删除
c:\winnt\system32\gdiplus32.dll
修复后重启,如果无法上网,请运行WinsockXPFix,让它修复一下。
回到正常模式,请再扫日志粘上来。
如果总是无法修复
看以下的帖子
解决Winsock LSP“浏览器劫持”的一些方法
http://forum.ikaka.com/topic.asp?board=67&artid=8162074

还有不少病毒
请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改。
gototop
 
123   1  /  3  页   跳转
页面顶部
Powered by Discuz!NT