瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 急救!浏览器主页被修改为www.1633.cn

1   1  /  1  页   跳转

急救!浏览器主页被修改为www.1633.cn

急救!浏览器主页被修改为www.1633.cn

我的浏览器被劫持了,主页总是指向www.1633.cn/有时还回弹出广告窗口,系统进程里多了两个进程RNUDLL32.EXE,MSMNSGER.EXE无法杀死,头都搞大了。救救我的浏览器救救我
HijackThis日志如下:
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
C:\Program Files\AMD\Cool'n'Quiet\gemback.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\联想\模式转换\QuakeII.exe
C:\WINDOWS\LHotkey.exe
C:\Program Files\Lenovo\联想键盘驱动\LCC.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe
C:\Documents and Settings\Administrator\桌面\梦工厂脱机v1.63测试版\CMir2.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
D:\4F脱机外挂\传奇脱机发言外挂\MirSay.exe
D:\4F脱机外挂\传奇脱机发言外挂\MirSay.exe
D:\Iparmor\Iparmor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
D:\浏览器强力修复\HijackThis1991zww.exe

O1 - Hosts: 202.103.67.180 auto.search.msn.com
O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1

\chinanet\VNETTR~1.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton

AntiVirus\NavShExt.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} -

D:\NetTransport\NTIEHelper.dll
O3 - IE工具栏增项: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program

Files\Norton AntiVirus\NavShExt.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] rem rem "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil

/RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] rem rem C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE

/SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] rem rem C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE

/IMEName
O4 - 启动项HKLM\\Run: [NvCplDaemon] rem rem RUNDLL32.EXE C:\WINDOWS\system32

\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [nwiz] rem rem nwiz.exe /install
O4 - 启动项HKLM\\Run: [NvMediaCenter] rem rem RUNDLL32.EXE C:\WINDOWS\system32

\NvMcTray.dll,NvTaskbarInit
O4 - 启动项HKLM\\Run: [SoundMan] rem rem SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [helper.dll] rem rem C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1

\3721\helper.dll,Rundll32
O4 - 启动项HKLM\\Run: [advapi32] RUNDLL32 C:\WINDOWS\Downlo~1\_IS_0518\_IS_ISC.DLL,isc
O4 - 启动项HKLM\\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - 启动项HKLM\\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe

/GUID NAV /CMDLINE "REBOOT"
O4 - 启动项HKLM\\Run: [模式转换] C:\Program Files\联想\模式转换\QuakeII.exe
O4 - 启动项HKLM\\Run: [LHotkey] LHotkey.exe
O4 - 启动项HKLM\\Run: [Lcc] C:\Program Files\Lenovo\联想键盘驱动\LCC.exe
O4 - 启动项HKLM\\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec

Shared\Security Center\UsrPrmpt.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: 卡巴斯基反黑客.lnk = C:\Program Files\Kaspersky Lab\Kaspersky Anti-

Hacker\KAVPF.exe
O8 - IE右键菜单中的新增项目: 使用影音传送带下载 - D:\NetTransport\NTAddLink.html
O8 - IE右键菜单中的新增项目: 使用影音传送带下载全部链接 - D:\NetTransport\NTAddList.html
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O17 - HKLM\System\CCS\Services\Tcpip\..\{15D97105-4D43-4763-9965-A3784BFCDA58}: NameServer =

61.177.7.1 221.228.225.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{15D97105-4D43-4763-9965-A3784BFCDA58}: NameServer =

61.177.7.1 221.228.225.1
O23 - NT 服务: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - NT 服务: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - NT 服务: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - NT 服务: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - NT 服务: AMD PowerNow! (tm) Technology Service (GemServ) - Advanced Micro Devices -

C:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
O23 - NT 服务: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation -

C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\system32\nvsvc32.exe
O23 - NT 服务: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - NT 服务: SAVScan - Symantec Corporation - C:\Program Files\Norton

AntiVirus\SAVScan.exe
O23 - NT 服务: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1

\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - NT 服务: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - NT 服务: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common

Files\Symantec Shared\Security Center\SymWSC.exe
最后编辑2005-08-16 23:19:44
分享到:
gototop
 

【回复“Galy”的帖子】
您好,上次我介绍的方法您说清除不了,现在开来应该是您对IceSword不大了解.先搞清楚IS的用法吧.
gototop
 

请修复
O1 - Hosts: 202.103.67.180 auto.search.msn.com

您的问题很可能与传奇脱机发言外挂有关,建议暂停使用

关于
O4 - 启动项HKLM\\Run: [advapi32] RUNDLL32 C:\WINDOWS\Downlo~1\_IS_0518\_IS_ISC.DLL,isc

请参考

http://forum.ikaka.com/topic.asp?board=67&artid=6909890

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT