瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 请高手帮忙分析一下日志,有广告自动弹出

1   1  /  1  页   跳转

请高手帮忙分析一下日志,有广告自动弹出

请高手帮忙分析一下日志,有广告自动弹出

可能是什么流氓软件,打开IE会从右下角出来一些广告,以前也遇到过,弄得电脑很慢
请高手看看哪些需要修复,谢谢先

Logfile of HijackThis v1.99.1
Scan saved at 19:12:54, on 2005-12-7
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINNT\system32\svchost.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\DK\1753\qq\QQ.exe
D:\DK\1753\qq\TIMPlatform.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\HijackThis.exe

O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Super Rabbit SRRestore] C:\Program Files\Super Rabbit\MagicSet\srrest.exe /autosave
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Startup: E话通.lnk = D:\eph.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: 写作之星.lnk = ?
O4 - Global Startup: 桌面传媒.lnk = C:\WINNT\system32\rundll32.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\DK\1753\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\DK\1753\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\DK\1753\qq\SendMMS.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{040A3D2E-BA61-4A8E-83A2-512B12A82A32}: NameServer = 69.50.184.85,195.225.176.31
O17 - HKLM\System\CCS\Services\Tcpip\..\{9DDF6525-CB53-4DB5-984A-920DD81B69C2}: NameServer = 69.50.184.85,195.225.176.31
O17 - HKLM\System\CCS\Services\Tcpip\..\{A102EA63-0548-48F7-8FE2-0CA2CF2F1D65}: NameServer = 202.106.46.151,202.106.0.20
O17 - HKLM\System\CS1\Services\VxD\MSTCP: NameServer = 69.50.184.85,195.225.176.31
O17 - HKLM\System\CS1\Services\Tcpip\..\{040A3D2E-BA61-4A8E-83A2-512B12A82A32}: NameServer = 69.50.184.85,195.225.176.31
O17 - HKLM\System\CS2\Services\Tcpip\..\{040A3D2E-BA61-4A8E-83A2-512B12A82A32}: NameServer = 202.106.127.1,202.99.8.1
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.50.184.85,195.225.176.31
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINNT\system32\mbprot.dll
O20 - AppInit_DLLs: APIHookDll.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: WindowsServer - Sygate Technologies, Inc. - (no file)
最后编辑2005-12-07 20:15:35
分享到:
gototop
 

重新启动到安全模式(进入安全模式的方法:重新启动电脑, 开机自动检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式(Safe Mode)进入Windows。)

请关闭所有IE界面,重新使用HijackThis扫描一次,选中下面建议修复的项目,让HijackThis修复,修复前请允许HijackThis保留备份。(如果楼主知道是安全的可以不必勾选)
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O4 - Global Startup: 桌面传媒.lnk = C:\WINNT\system32\rundll32.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINNT\system32\mbprot.dll

然后打开我的电脑→再点工具→打开文件夹选项→查看→把隐藏受保护的系统文件(推荐)和隐藏已知文件类型的扩展名的勾去掉→再显示所有文件→找到以下文件并删除:(如果有的话)
C:\WINNT\system32\mbprot.dll

桌面传媒您可以直接到C:\PROGRAM FILES\Desktop Media\目录下卸载

问题仍在请用System Repair Engineer扫个日志上来

下载地址见置顶贴
[必读]本版说明及常用小软件下载
http://forum.ikaka.com/topic.asp?board=67&artid=5188931

gototop
 

【回复“飞跃迷离”的帖子】
谢谢斑竹,我已经按照您提示的步骤完成了
把隐藏受保护的系统文件(推荐)——去掉这一项前面的√时,它提示有什么危险,现在已经删除mbprot.dll这个文件
是否可以再把它勾上——√把隐藏受保护的系统文件(推荐)?
gototop
 

可以呀
gototop
 

真是感谢您的热心
“)
祝你开心
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT