1   1  /  1  页   跳转

求助.斑竹过来看看【原创】

求助.斑竹过来看看【原创】

偶的浏览器不知道是怎么,一打开的时候地址上面是空白页
但是底下却出现了一个网页 而且是英文的  经常会自动弹出一些广告 浏览器不开也弹
偶先把日志发上来高手帮偶看看
Logfile of HijackThis v1.99.2
Scan saved at 23:10:55, on 2005-10-23
Platform: Windows 2000  (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\Mixer.exe
C:\WINNT\System32\rundll32.exe
C:\WINNT\System32\rundll32.exe
D:\QQ寵物\QQ\QQ.exe
D:\QQ寵物\QQ\TIMPlatform.exe
C:\Program Files\Tencent\TT\TTraveler.exe
C:\WINNT\System32\drwtsn32.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\HijackThis.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\HAP111Dist100214.exe
C:\WINNT\System32\Rundll32.exe

R3 - URLSearchHook: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRA~1\3721\Assist\asbar.dll
F3 - REG:win.ini: run=
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\QQ寵物\QQ\QQIEHelper.dll
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - (no file)
O2 - BHO: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINNT\system32\stdup.dll
O2 - BHO: ltmenu Class - {78C21EFD-53BA-406C-AF1A-33A38ABD3958} - C:\Program Files\LtUcx\1002\c0.dll
O2 - BHO: BrowserHAP Class - {AEF6F648-78D8-4456-BEE7-5ADE23D209FD} - C:\Program Files\HBClient\hapast.dll
O2 - BHO: AssistII - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRA~1\3721\Assist\asbar.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - D:\王踔志疚伟癨\NetTransport 2\NTIEHelper.dll (file missing)
O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\WINNT\System32\qylhelper.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINNT\downlo~1\CnsHook.dll
O2 - BHO: (no name) - {E4D18836-E514-4A63-BAA0-E875E83B06DF} - C:\WINNT\System32\cpkb.dll
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - C:\PROGRA~1\YiSou\yisoub.dll
O3 - Toolbar: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\Program Files\YiSou\yisou.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll,DllInstall
O4 - HKLM\..\Run: [helper.dll] C:\WINNT\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINNT\downlo~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ProxyThorn] C:\2222\ProxyThorn\ProxyThorn.exe
O4 - HKLM\..\Run: [hbpassport] C:\PROGRA~1\HBClient\hbast.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [Kugoo] C:\PROGRA~1\KuGoo2\KuGoo.exe
O4 - Startup: 腾讯QQ.lnk = ?
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\QQ寵物\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用Kugoo下载 - C:\PROGRA~1\KuGoo2\KugooDownX.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\QQ寵物\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\QQ寵物\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\QQ寵物\QQ\SendMMS.htm
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm (file missing)
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: 视频聊天 - {6924091F-CD97-41E1-B1D4-D9079409D413} - http://www.liantang.net (file missing)
O9 - Extra 'Tools' menuitem: 视频聊天 - {6924091F-CD97-41E1-B1D4-D9079409D413} - http://www.liantang.net (file missing)
O9 - Extra button: 寻论网--中学作业解答 - {6924091F-CD97-41E1-B1D4-D9079409D423} - http://www.xunlun.com (file missing)
O9 - Extra 'Tools' menuitem: 中学作业 - {6924091F-CD97-41E1-B1D4-D9079409D423} - http://www.xunlun.com (file missing)
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\QQ寵物\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\QQ寵物\QQ\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\QQ寵物\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\QQ寵物\QQ\QQIEHelper.dll
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O11 - Options group: [!CNS]  上网助手-地址栏搜索
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {0400AC1C-EEF0-4638-A501-31D5A0DC2002} (VTPlug3 Class) - http://61.129.90.93:1995/VTrans.cab
O16 - DPF: {5DD731E6-D4F0-11D3-BE3F-00105A6FDA50} ({5DD731E6-D4F0-11D3-BE3F-00105A6FDA50}) - http://www.jx163.com/jsp/zvconline/plugin/myv3na.cab
O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) - http://61.129.90.93:1995/talk.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{18B2432C-4920-4EB0-A5DC-407E94994E8D}: NameServer = 218.76.138.66,218.76.138.67
O17 - HKLM\System\CCS\Services\Tcpip\..\{572F4F87-AA07-4733-B71F-51FCBBA8779F}: NameServer = 218.76.138.66,218.76.138.90
O17 - HKLM\System\CS1\Services\Tcpip\..\{18B2432C-4920-4EB0-A5DC-407E94994E8D}: NameServer = 218.76.138.66,218.76.138.67
O17 - HKLM\System\CS2\Services\Tcpip\..\{18B2432C-4920-4EB0-A5DC-407E94994E8D}: NameServer = 218.76.138.66,218.76.138.67
O18 - Filter: text/html - {1BF19294-5F9A-43D7-AE02-F252D930DF5F} - C:\WINNT\System32\cpkb.dll
O18 - Filter: text/plain - {1BF19294-5F9A-43D7-AE02-F252D930DF5F} - C:\WINNT\System32\cpkb.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Windows Proxy Server (Windows Proxy ) - Unknown owner - C:\WINNT\C_Server1.2.exe


附件附件:

下载次数:0
文件类型:image/pjpeg
文件大小:
上传时间:2005-10-23 23:17:09
描述:



最后编辑2005-10-24 12:49:17
分享到:
gototop
 

在线等~... 谢谢高手帮忙
gototop
 

【回复“儛乖乖”的帖子】
修复;
O2 - BHO: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINNT\system32\stdup.dll
O2 - BHO: ltmenu Class - {78C21EFD-53BA-406C-AF1A-33A38ABD3958} - C:\Program Files\LtUcx\1002\c0.dll
O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\WINNT\System32\qylhelper.dll
O2 - BHO: (no name) - {E4D18836-E514-4A63-BAA0-E875E83B06DF} - C:\WINNT\System32\cpkb.dll
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O23 - Service: Windows Proxy Server (Windows Proxy ) - Unknown owner - C:\WINNT\C_Server1.2.exe

显示所有文件找到以下:(如果有的话)
C:\WINNT\system32\stdup.dll
C:\Program Files\LtUcx\目录
C:\WINNT\System32\qylhelper.dll
C:\WINNT\System32\cpkb.dll
C:\winstall.exe
C:\WINNT\C_Server1.2.exe
C:\WINNT\C_Server1.2.dll
C:\WINNT\C_Server1.2key.dll
C:\WINNT\C_Server1.2_Hook.dll

重新启动即可.



gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT