12   1  /  2  页   跳转

哪位英雄愿意救美,求救心切!

哪位英雄愿意救美,求救心切!

嘻嘻,您好。大过我的叫GG、JJ,小过我的小DD、MM。我中毒,但查不出毒。只要一开机那个病毒网就会自动打开IE上他的网站,只是我ADSL不是设置自动连接的,但这样每次开机都会进他网站也挺讨厌的,怎么办呢?这病毒到底驻存在哪里呢?您知道可以帮下我吗?不胜感激

我又来找大家的麻烦啦,修来修去还是不行,那个恶意代码网站还是同样存在,连设置瑞星的开机扫描什么的都不工作啦,防火墙一直以来都要手工打开
就是这个网站:http://www.12388.hk      我试了好多次转向太快,看不到IP地址
高手们再帮帮我,我现在扫描一份贴上来您们帮我分析下,想试着删那个04项的,但删不了
[img][/img]
HijackThis_zww汉化版扫描日志 V1.99.1
保存于      9:52:42, 日期 2005-7-2
操作系统:  Windows XP  (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 (6.00.2600.0000)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\conime.exe
D:\rising\Rising\Rav\RavMon.exe
D:\RISING\RISING\RAV\CCENTER.EXE
D:\RISING\RISING\RAV\Ravmond.exe
C:\WINDOWS\System32\svchost.exe
D:\RISING\RISING\RAV\RavStub.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\HijackThis1991汉化版\HijackThis1991zww.exe
F:\IPQQ2005BETA1\Tencent\QQ.exe
F:\IPQQ2005BETA1\Tencent\TIMPlatform.exe
F:\IPQQ2005BETA1\Tencent\QQ.exe

R3 - URLSearchHook: (no name) - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - (no file)
O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O2 - BHO: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\Progra~1\Baidu\bar\BaiDuBar.dll
O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\System32\qylhelper.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - (no file)
O3 - IE工具栏增项: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\Progra~1\Baidu\bar\BaiDuBar.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKCU\\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - 启动项HKCU\\Run: [3721] C:\$NtUninstallQ5926809$\3721.BAT
O4 - 启动项HKCU\\Run: [cnmail] regedit -s C:\$NtUninstallQ5926809$\spcust0m.dll
O4 - 启动项HKCU\\Run: [services] http://www.12388.hk
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - F:\IPQQ2005BETA1\Tencent\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - F:\IPQQ2005BETA1\Tencent\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - F:\IPQQ2005BETA1\Tencent\SendMMS.htm
O8 - IE右键菜单中的新增项目: 百度-搜索MP3 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUMP3.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索图片 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUIMG.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索新闻 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUNEWS.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索歌词 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDULYRIC.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索网页 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUSEARCH.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索贴吧 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUPOST.HTM
O8 - IE右键菜单中的新增项目: 百度-词典搜索 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDU_DIC.HTM
O9 - 浏览器额外的按钮: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - 浏览器额外的“工具”菜单项: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - 浏览器额外的按钮: 百度搜索伴侣 - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - C:\WINDOWS\System32\shdocvw.dll
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\QQ\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\QQ\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\QQ\QQIEHelper.dll
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\cdnns.dll
O11 - Options group: [!IESearch] !IESearch
O11 - Options group: [CDNCLIENT]  中文上网
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O15 - “受信任的站点”中添加项: easyabc.95599.cn
O15 - “受信任的站点”中添加项: www.95599.cn
O16 - DPF: {8819C261-5B61-4628-908C-9BE795EABEC3} (IE Class) - https://www.95599.cn/platform/pub/cab/ABC.cab
O16 - DPF: {9A578C98-3C2F-4630-890B-FC04196EF420} (CNNIC_IDN) - http://client.jogo.cn/download/cnnic/cdn.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - http://bar.baidu.com/update/IESearch.cab
O16 - DPF: {F138084D-84D7-48CD-BEA8-04772457516E} (VqqSpeedDlProxy Class) - http://218.85.138.27/vqqsdl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{97138CEF-1B0C-4DBA-9AD1-CCD0AC2C906E}: NameServer = 61.144.56.101 202.96.128.68
O18 - 列举现有的协议: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - 列举现有的协议: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: ipp - (no CLSID) - (no file)
O18 - 列举现有的协议: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - 列举现有的协议: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - 列举现有的协议: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: msdaipp - (no CLSID) - (no file)
O18 - 列举现有的协议: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - 列举现有的协议: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll
O18 - 列举现有的协议: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - D:\RISING\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\RISING\RISING\RAV\Ravmond.exe

附件附件:

下载次数:0
文件类型:image/pjpeg
文件大小:
上传时间:2005-7-1 10:24:42
描述:



最后编辑2005-07-02 09:54:24
分享到:
gototop
 

应该是注册表被修改吧
gototop
 

【回复“thomas2004”的帖子】
注册表没修改,我也用了瑞星那个修复注册表的,扫描不到有被改过的IE,谢谢你的回复
gototop
 

那么.搜索下载 hijackthis 1.99.1 扫描一份log.贴上来吧
gototop
 

我说开机启动的注册表项目吖

不是ie的项目吖.瑞星当然查不出
gototop
 

【回复“thomas2004”的帖子】
好的我马上搜了上传上来
gototop
 

我扫了但上传出问题,说文件类型不对,那又是什么问题呀,传了几次传不上,但扫到有好多01开头的,我以前用过,有时候就算是删了01开头的也同样存在问题
HijackThis_zww汉化版扫描日志 V1.99.1
保存于      10:37:28, 日期 2005-7-1
操作系统:  Windows XP  (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 (6.00.2600.0000)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\RISING\RISING\RAV\RAVTIMER.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\conime.exe
D:\RISING\RISING\RAV\CCENTER.EXE
D:\RISING\RISING\RAV\Ravmond.exe
C:\WINDOWS\System32\svchost.exe
D:\RISING\RISING\RAV\RavStub.exe
D:\rising\Rising\Rav\RavMon.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\HijackThis1991汉化版\HijackThis1991zww.exe

R3 - URLSearchHook: (no name) - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - (no file)
O1 - Hosts: 210.17.251.234 bbbppp.com
O1 - Hosts: 210.17.251.234 www.bbbppp.com
O1 - Hosts: 210.17.251.234 666fff.com
O1 - Hosts: 210.17.251.234 www.666fff.com
O1 - Hosts: 210.17.251.234 ok0809.com
O1 - Hosts: 210.17.251.234 www.ok0809.com
O1 - Hosts: 210.17.251.234 qq558899.com
O1 - Hosts: 210.17.251.234 www.qq558899.com
O1 - Hosts: 210.17.251.234 hkqw.com
O1 - Hosts: 210.17.251.234 www.hkqw.com
O1 - Hosts: 210.17.251.234 65188.com
O1 - Hosts: 210.17.251.234 www.65188.com
O1 - Hosts: 210.17.251.234 665858.com
O1 - Hosts: 210.17.251.234 www.665858.com
O1 - Hosts: 210.17.251.234 tm5656.com
O1 - Hosts: 210.17.251.234 www.tm5656.com
O1 - Hosts: 210.17.251.234 88235.com
O1 - Hosts: 210.17.251.234 www.88235.com
O1 - Hosts: 210.17.251.234 k88688.com
O1 - Hosts: 210.17.251.234 www.k88688.com
O1 - Hosts: 210.17.251.234 22688.cn
O1 - Hosts: 210.17.251.234 www.22688.cn
O1 - Hosts: 210.17.251.234 30887.com
O1 - Hosts: 210.17.251.234 www.30887.com
O1 - Hosts: 210.17.251.234 331188.net
O1 - Hosts: 210.17.251.234 www.331188.net
O1 - Hosts: 210.17.251.234 50958.com
O1 - Hosts: 210.17.251.234 www.50958.com
O1 - Hosts: 210.17.251.234 518778.com
O1 - Hosts: 210.17.251.234 www.518778.com
O1 - Hosts: 210.17.251.234 hongkong3618.com
O1 - Hosts: 210.17.251.234 www.hongkong3618.com
O1 - Hosts: 210.17.251.234 kk4444.com
O1 - Hosts: 210.17.251.234 www.kk4444.com
O1 - Hosts: 210.17.251.234 xp668.com
O1 - Hosts: 210.17.251.234 www.xp668.com
O1 - Hosts: 210.17.251.234 iebar.t2t2.com
O1 - Hosts: 210.17.251.234 fh94.com
O1 - Hosts: 210.17.251.234 www.fh94.com
O1 - Hosts: 210.17.251.234 ww678.com
O1 - Hosts: 210.17.251.234 www.ww678.com
O1 - Hosts: 210.17.251.234 00559.com
O1 - Hosts: 210.17.251.234 www.00559.com
O1 - Hosts: 210.17.251.234 25889.com
O1 - Hosts: 210.17.251.234 www.25889.com
O1 - Hosts: 210.17.251.234 49558.com
O1 - Hosts: 210.17.251.234 www.49558.com
O1 - Hosts: 210.17.251.234 6868888.com
O1 - Hosts: 210.17.251.234 www.6868888.com
O1 - Hosts: 210.17.251.234 7575333.com
O1 - Hosts: 210.17.251.234 www.7575333.com
O1 - Hosts: 210.17.251.234 85599.com
O1 - Hosts: 210.17.251.234 www.85599.com
O1 - Hosts: 210.17.251.234 88993.com
O1 - Hosts: 210.17.251.234 www.88993.com
O1 - Hosts: 210.17.251.234 f689.com
O1 - Hosts: 210.17.251.234 www.f689.com
O1 - Hosts: 210.17.251.234 hk3728.com
O1 - Hosts: 210.17.251.234 www.hk3728.com
O1 - Hosts: 210.17.251.234 k3355.com
O1 - Hosts: 210.17.251.234 www.k3355.com
O1 - Hosts: 210.17.251.234 kk766.com
O1 - Hosts: 210.17.251.234 www.kk766.com
O1 - Hosts: 210.17.251.234 kkkiii.com
O1 - Hosts: 210.17.251.234 www.kkkiii.com
O1 - Hosts: 210.17.251.234 kkkjjj.com
O1 - Hosts: 210.17.251.234 www.kkkjjj.com
O1 - Hosts: 210.17.251.234 pp678.com
O1 - Hosts: 210.17.251.234 www.pp678.com
O1 - Hosts: 210.17.251.234 56598.com
O1 - Hosts: 210.17.251.234 www.56598.com
O1 - Hosts: 210.17.251.234 hk5868.com
O1 - Hosts: 210.17.251.234 hk5868.com
O1 - Hosts: 210.17.251.234 qq558899.com
O1 - Hosts: 210.17.251.234 www.qq558899.com
O1 - Hosts: 210.17.251.234 tm669.com
O1 - Hosts: 210.17.251.234 www.tm669.com
O1 - Hosts: 210.17.251.234 68599.com
O1 - Hosts: 210.17.251.234 www.68599.com
O1 - Hosts: 210.17.251.234 358619.com
O1 - Hosts: 210.17.251.234 www.358619.com
O1 - Hosts: 210.17.251.234 3c6.com
O1 - Hosts: 210.17.251.234 www.3c6.com
O1 - Hosts: 210.17.251.234 f888888.com
O1 - Hosts: 210.17.251.234 www.f888888.com
O1 - Hosts: 210.17.251.234 hh8hh.com
O1 - Hosts: 210.17.251.234 www.hh8hh.com
O1 - Hosts: 210.17.251.234 hongkong998.com
O1 - Hosts: 210.17.251.234 www.hongkong998.com
O1 - Hosts: 210.17.251.234 lh8688.com
O1 - Hosts: 210.17.251.234 www.lh8688.com
O1 - Hosts: 210.17.251.234 lh8688.net
O1 - Hosts: 210.17.251.234 www.lh8688.net
O1 - Hosts: 210.17.251.234 p888888.com
O1 - Hosts: 210.17.251.234 www.p888888.com
O1 - Hosts: 210.17.251.234 vv6888.com
O1 - Hosts: 210.17.251.234 www.vv6888.com
O1 - Hosts: 210.17.251.234 y8y88.com
O1 - Hosts: 210.17.251.234 www.y8y88.com
O1 - Hosts: 210.17.251.234 y8y88.net
O1 - Hosts: 210.17.251.234 www.y8y88.net
O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O2 - BHO: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\Progra~1\Baidu\bar\BaiDuBar.dll
O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\System32\qylhelper.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - (no file)
O3 - IE工具栏增项: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\Progra~1\Baidu\bar\BaiDuBar.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [internat.exe] internat.exe
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKCU\\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - 启动项HKCU\\Run: [3721] C:\$NtUninstallQ5926809$\3721.BAT
O4 - 启动项HKCU\\Run: [cnmail] regedit -s C:\$NtUninstallQ5926809$\spcust0m.dll
O4 - 启动项HKCU\\Run: [services] http://www.12388.hk
O4 - Global Startup: microsoft office.lnk = D:\New Folder\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - E:\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - E:\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - E:\QQ\SendMMS.htm
O8 - IE右键菜单中的新增项目: 百度-搜索MP3 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUMP3.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索图片 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUIMG.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索新闻 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUNEWS.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索歌词 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDULYRIC.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索网页 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUSEARCH.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索贴吧 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUPOST.HTM
O8 - IE右键菜单中的新增项目: 百度-词典搜索 - res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDU_DIC.HTM
O9 - 浏览器额外的按钮: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - 浏览器额外的“工具”菜单项: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - 浏览器额外的按钮: 百度搜索伴侣 - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - C:\WINDOWS\System32\shdocvw.dll
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\QQ\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\QQ\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\QQ\QQIEHelper.dll
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\cdnns.dll
O11 - Options group: [!IESearch] !IESearch
O11 - Options group: [CDNCLIENT]  中文上网
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O15 - “受信任的站点”中添加项: easyabc.95599.cn
O15 - “受信任的站点”中添加项: www.95599.cn
O16 - DPF: {8819C261-5B61-4628-908C-9BE795EABEC3} (IE Class) - https://www.95599.cn/platform/pub/cab/ABC.cab
O16 - DPF: {9A578C98-3C2F-4630-890B-FC04196EF420} (CNNIC_IDN) - http://client.jogo.cn/download/cnnic/cdn.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - http://bar.baidu.com/update/IESearch.cab
O16 - DPF: {F138084D-84D7-48CD-BEA8-04772457516E} (VqqSpeedDlProxy Class) - http://218.85.138.27/vqqsdl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{97138CEF-1B0C-4DBA-9AD1-CCD0AC2C906E}: NameServer = 61.144.56.101 202.96.128.68
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - D:\RISING\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\RISING\RISING\RAV\Ravmond.exe

gototop
 

【回复“碟儿”的帖子】
急急,在线等解决的办法呀,谁来帮我下呀,不胜感激呀。还是不行呀,就是这个恶意代码网:http://www.12388.hk
gototop
 

开始-附件-启动里面有没有东西加进去,有的话先删了
用上网助手试一下,不知道能不能修复http://assistant.3721.com/iefix01.htm
gototop
 

修复:
O1 - Hosts: 210.17.251.234 bbbppp.com
O1 - Hosts: 210.17.251.234 www.bbbppp.com
O1 - Hosts: 210.17.251.234 666fff.com
O1 - Hosts: 210.17.251.234 www.666fff.com
O1 - Hosts: 210.17.251.234 ok0809.com
O1 - Hosts: 210.17.251.234 www.ok0809.com
O1 - Hosts: 210.17.251.234 qq558899.com
O1 - Hosts: 210.17.251.234 www.qq558899.com
O1 - Hosts: 210.17.251.234 hkqw.com
O1 - Hosts: 210.17.251.234 www.hkqw.com
O1 - Hosts: 210.17.251.234 65188.com
O1 - Hosts: 210.17.251.234 www.65188.com
O1 - Hosts: 210.17.251.234 665858.com
O1 - Hosts: 210.17.251.234 www.665858.com
O1 - Hosts: 210.17.251.234 tm5656.com
O1 - Hosts: 210.17.251.234 www.tm5656.com
O1 - Hosts: 210.17.251.234 88235.com
O1 - Hosts: 210.17.251.234 www.88235.com
O1 - Hosts: 210.17.251.234 k88688.com
O1 - Hosts: 210.17.251.234 www.k88688.com
O1 - Hosts: 210.17.251.234 22688.cn
O1 - Hosts: 210.17.251.234 www.22688.cn
O1 - Hosts: 210.17.251.234 30887.com
O1 - Hosts: 210.17.251.234 www.30887.com
O1 - Hosts: 210.17.251.234 331188.net
O1 - Hosts: 210.17.251.234 www.331188.net
O1 - Hosts: 210.17.251.234 50958.com
O1 - Hosts: 210.17.251.234 www.50958.com
O1 - Hosts: 210.17.251.234 518778.com
O1 - Hosts: 210.17.251.234 www.518778.com
O1 - Hosts: 210.17.251.234 hongkong3618.com
O1 - Hosts: 210.17.251.234 www.hongkong3618.com
O1 - Hosts: 210.17.251.234 kk4444.com
O1 - Hosts: 210.17.251.234 www.kk4444.com
O1 - Hosts: 210.17.251.234 xp668.com
O1 - Hosts: 210.17.251.234 www.xp668.com
O1 - Hosts: 210.17.251.234 iebar.t2t2.com
O1 - Hosts: 210.17.251.234 fh94.com
O1 - Hosts: 210.17.251.234 www.fh94.com
O1 - Hosts: 210.17.251.234 ww678.com
O1 - Hosts: 210.17.251.234 www.ww678.com
O1 - Hosts: 210.17.251.234 00559.com
O1 - Hosts: 210.17.251.234 www.00559.com
O1 - Hosts: 210.17.251.234 25889.com
O1 - Hosts: 210.17.251.234 www.25889.com
O1 - Hosts: 210.17.251.234 49558.com
O1 - Hosts: 210.17.251.234 www.49558.com
O1 - Hosts: 210.17.251.234 6868888.com
O1 - Hosts: 210.17.251.234 www.6868888.com
O1 - Hosts: 210.17.251.234 7575333.com
O1 - Hosts: 210.17.251.234 www.7575333.com
O1 - Hosts: 210.17.251.234 85599.com
O1 - Hosts: 210.17.251.234 www.85599.com
O1 - Hosts: 210.17.251.234 88993.com
O1 - Hosts: 210.17.251.234 www.88993.com
O1 - Hosts: 210.17.251.234 f689.com
O1 - Hosts: 210.17.251.234 www.f689.com
O1 - Hosts: 210.17.251.234 hk3728.com
O1 - Hosts: 210.17.251.234 www.hk3728.com
O1 - Hosts: 210.17.251.234 k3355.com
O1 - Hosts: 210.17.251.234 www.k3355.com
O1 - Hosts: 210.17.251.234 kk766.com
O1 - Hosts: 210.17.251.234 www.kk766.com
O1 - Hosts: 210.17.251.234 kkkiii.com
O1 - Hosts: 210.17.251.234 www.kkkiii.com
O1 - Hosts: 210.17.251.234 kkkjjj.com
O1 - Hosts: 210.17.251.234 www.kkkjjj.com
O1 - Hosts: 210.17.251.234 pp678.com
O1 - Hosts: 210.17.251.234 www.pp678.com
O1 - Hosts: 210.17.251.234 56598.com
O1 - Hosts: 210.17.251.234 www.56598.com
O1 - Hosts: 210.17.251.234 hk5868.com
O1 - Hosts: 210.17.251.234 hk5868.com
O1 - Hosts: 210.17.251.234 qq558899.com
O1 - Hosts: 210.17.251.234 www.qq558899.com
O1 - Hosts: 210.17.251.234 tm669.com
O1 - Hosts: 210.17.251.234 www.tm669.com
O1 - Hosts: 210.17.251.234 68599.com
O1 - Hosts: 210.17.251.234 www.68599.com
O1 - Hosts: 210.17.251.234 358619.com
O1 - Hosts: 210.17.251.234 www.358619.com
O1 - Hosts: 210.17.251.234 3c6.com
O1 - Hosts: 210.17.251.234 www.3c6.com
O1 - Hosts: 210.17.251.234 f888888.com
O1 - Hosts: 210.17.251.234 www.f888888.com
O1 - Hosts: 210.17.251.234 hh8hh.com
O1 - Hosts: 210.17.251.234 www.hh8hh.com
O1 - Hosts: 210.17.251.234 hongkong998.com
O1 - Hosts: 210.17.251.234 www.hongkong998.com
O1 - Hosts: 210.17.251.234 lh8688.com
O1 - Hosts: 210.17.251.234 www.lh8688.com
O1 - Hosts: 210.17.251.234 lh8688.net
O1 - Hosts: 210.17.251.234 www.lh8688.net
O1 - Hosts: 210.17.251.234 p888888.com
O1 - Hosts: 210.17.251.234 www.p888888.com
O1 - Hosts: 210.17.251.234 vv6888.com
O1 - Hosts: 210.17.251.234 www.vv6888.com
O1 - Hosts: 210.17.251.234 y8y88.com
O1 - Hosts: 210.17.251.234 www.y8y88.com
O1 - Hosts: 210.17.251.234 y8y88.net
O1 - Hosts: 210.17.251.234 www.y8y88.net

O4 - 启动项HKCU\\Run: [services] http://www.12388.hk
这几个ip你知道么
218.85.138.27
如果知道
O16 - DPF: {F138084D-84D7-48CD-BEA8-04772457516E} (VqqSpeedDlProxy Class) - http://218.85.138.27/vqqsdl.cab这个可以不修复
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT