1   1  /  1  页   跳转

HijackThis_zww 报告~~~~~~~~~~ 救救~!

HijackThis_zww 报告~~~~~~~~~~ 救救~!

(版主:我已经是第三次上来帮忙了.每次都按照你们的指导清除了,但过一天后,这些东东又会弹出来,不知道是为什么哦!~    顺便提一下,当这些东东出来后,我第一时间用卡卡上网助手彻底修复了一下~!)



HijackThis_zww汉化版扫描日志 V1.99.1
保存于      15:41:01, 日期 2005-12-11
操作系统:  Windows XP SP1 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
C:\PROGRA~1\SKYNET\FIREWALL\pfw.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CNNIC\Cdn\cdnup.exe
C:\WINDOWS\System32\mshta.exe
D:\HB\HijackThis1991汉化版\HijackThis1991zww.exe

O1 - Hosts: 61.129.15.77 popme.163.com
O1 - Hosts: 61.129.15.77 www.xk99.com
O1 - Hosts: 61.129.15.77 www.006.net
O1 - Hosts: 61.129.15.77 006.net
O1 - Hosts: 61.129.15.77 www.cmfu.com
O1 - Hosts: 61.129.15.77 www.free120.com
O1 - Hosts: 61.129.15.77 www.4577.com
O1 - Hosts: 61.129.15.77 www.9617.com
O1 - Hosts: 61.129.15.77 www.fjwz.com
O1 - Hosts: 61.129.15.77 partner.cpc.sohu.com
O1 - Hosts: 61.129.15.77 ad4.sina.com.cn
O1 - Hosts: 61.129.15.77 music.17o8.comer.cpc.sohu.com
O1 - Hosts: 61.129.15.77 ad.tom.com
O1 - Hosts: 61.129.15.77 search.union.3721.com
O1 - Hosts: 61.129.15.77 post.baidu.com
O1 - Hosts: 61.129.15.77 mp3.baidu.com
O1 - Hosts: 61.129.15.77 image.baidu.com
O1 - Hosts: 61.129.15.77 site.google.com
O1 - Hosts: 61.129.15.77 flash.baidu.com
O1 - Hosts: 61.129.15.77 assistant.3721.com
O1 - Hosts: 61.129.15.77 pfp.sina.com.cn
O1 - Hosts: 61.129.15.77 cn.websearch.yahoo.com
O1 - Hosts: 61.129.15.77 sms.qq.com
O1 - Hosts: 61.129.15.77 www.qq.com
O1 - Hosts: 61.129.15.77 partner.lead2.com.cn
O1 - Hosts: 61.129.15.77 ad.cn.doubleclick.net
O1 - Hosts: 61.129.15.77 auto.search.msn.com
O1 - Hosts: 61.129.15.77 www.ourgame.com
O1 - Hosts: 61.129.15.77 www.the9.com
O1 - Hosts: 61.129.15.77 www.flashempire.com
O1 - Hosts: 61.129.15.77 www.qq163.com
O1 - Hosts: 61.129.15.77 www.9sky.com
O1 - Hosts: 61.129.15.77 www.tom-1.com
O1 - Hosts: 61.129.15.77 www.17173.com
O1 - Hosts: 61.129.15.77 www.yaotou.com
O1 - Hosts: 61.129.15.77 union.3721.com
O1 - Hosts: 61.129.15.77 music.feifa.com
O1 - Hosts: 61.129.15.77 www.vodfans.com
O1 - Hosts: 61.129.15.77 www.sogua.com
O1 - Hosts: 61.129.15.77 fm974.tom.com
O1 - Hosts: 61.129.15.77 ent.tom.com
O1 - Hosts: 61.129.15.77 music.tyfo.com
O1 - Hosts: 61.129.15.77 www.wanwa.com
O1 - Hosts: 61.129.15.77 www.guang.org
O1 - Hosts: 61.129.15.77 www.wz.zj.cn
O1 - Hosts: 61.129.15.77 www.3189.net
O1 - Hosts: 61.129.15.77 music.17o8.com
O1 - Hosts: 61.129.15.77 www.99music.net
O1 - Hosts: 61.129.15.77 www.cococ.com
O1 - Hosts: 61.129.15.77 www.qqqq.cn
O1 - Hosts: 61.129.15.77 www.bnb.com.cn
O1 - Hosts: 61.129.15.77 www.z163.com
O1 - Hosts: 61.129.15.77 game.163.com
O1 - Hosts: 61.129.15.77 games.sina.com.cn
O1 - Hosts: 61.129.15.77 www.v111.com
O1 - Hosts: 61.129.15.77 music.v111.com
O1 - Hosts: 61.129.15.77 www.3tom.com
O1 - Hosts: 61.129.15.77 www.xkqq.com
O1 - Hosts: 61.129.15.77 www.verymp3.com
O1 - Hosts: 61.129.15.77 www.91look.com
O1 - Hosts: 61.129.15.77 www.168101.com
O1 - Hosts: 61.129.15.77 www.cmfu.com
O1 - Hosts: 61.129.15.77 www.woogood.com
O1 - Hosts: 61.129.15.77 www.haodx.com
O1 - Hosts: 61.129.15.77 www.yingku.com
O1 - Hosts: 61.129.15.77 www.flash51.com
O1 - Hosts: 61.129.15.77 www.17haha.com
O1 - Hosts: 61.129.15.77 www.432.cn
O1 - Hosts: 61.129.15.77 www.cnxp.com
O1 - Hosts: 61.129.15.77 www.hjsm.net
O1 - Hosts: 61.129.15.77 music.8wa.com
O1 - Hosts: 61.129.15.77 www.66vv.com
O1 - Hosts: 61.129.15.77 www.musicfbi.com
O1 - Hosts: 61.129.15.77 www.vv66.com
O1 - Hosts: 61.129.15.77 www.139mm.com
O1 - Hosts: 61.129.15.77 www.130wg.com
O1 - Hosts: 61.129.15.77 www.flashsea.com
O1 - Hosts: 61.129.15.77 movie.59178.com
O1 - Hosts: 61.129.15.77 www.wo123.com
O1 - Hosts: 61.129.15.77 www.1ya.cn
O1 - Hosts: 61.129.15.77 www.happy8.cn
O1 - Hosts: 61.129.15.77 www.s6.cn
O1 - Hosts: 61.129.15.77 www.hao123.com
O1 - Hosts: 61.129.15.77 www.qqee.com
O1 - Hosts: 61.129.15.77 imgu.21cn.com
O1 - Hosts: 61.129.15.77 www.sohu123.com
O1 - Hosts: 61.129.15.77 www.chinamp3.com
O1 - Hosts: 61.129.15.77 www.18z.net
O1 - Hosts: 61.129.15.77 www.ssxs.com
O1 - Hosts: 61.129.15.77 www.fjwz.net
O1 - Hosts: 61.129.15.77 www.wo365.com
O1 - Hosts: 61.129.15.77 www.zhao99.com
O1 - Hosts: 61.129.15.77 www.cn808.net
O1 - Hosts: 61.129.15.77 www.tt55.net
O1 - Hosts: 61.129.15.77 www.mp3tt.com
O1 - Hosts: 61.129.15.77 www.yi5.com
O1 - Hosts: 61.129.15.77 www.haozs.com
O1 - Hosts: 61.129.15.77 www.77ttt.com
O1 - Hosts: 61.129.15.77 www.77xi.com
O1 - Hosts: 61.129.15.77 13258.com
O1 - Hosts: 61.129.15.77 www.13258.com
O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - 启动项HKLM\\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - 启动项HKLM\\Run: [SKYNET Personal FireWall] C:\PROGRA~1\SKYNET\FIREWALL\pfw.exe
O4 - 启动项HKLM\\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - 启动项HKLM\\Run: [internet.exe] C:/WINDOWS/system.hta
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [IEXPLORE.EXE] IEXPLORE.EXE http://vod.soucn.net
O4 - Startup: desktop.ini
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\QQ\QQ.exe
O4 - Global Startup: desktop.ini
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - IE右键菜单中的新增项目: 访问通用网址 - C:\Program Files\CNNIC\Cdn\cnnic.htm
O9 - 浏览器额外的按钮: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - 浏览器额外的“工具”菜单项: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O11 - Options group: [CDNCLIENT]  中文上网
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O18 - 列举现有的协议: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\System32\mbprot.dll (file missing)
O23 - NT 服务: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - NT 服务: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
最后编辑2005-12-11 15:54:53
分享到:
gototop
 

重新启动到安全模式(进入安全模式的方法:重新启动电脑, 开机自动检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式(Safe Mode)进入Windows。)

请关闭所有IE界面,重新使用HijackThis扫描一次,选中下面建议修复的项目,让HijackThis修复,修复前请允许HijackThis保留备份。(如果楼主知道是安全的可以不必勾选)

所有01项

O4 - 启动项HKLM\\Run: [internet.exe] C:/WINDOWS/system.hta
O4 - HKCU\..\Run: [IEXPLORE.EXE] IEXPLORE.EXE http://vod.soucn.net
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

然后打开我的电脑→再点工具→打开文件夹选项→查看→把隐藏受保护的系统文件(推荐)和隐藏已知文件类型的扩展名的勾去掉→再显示所有文件→找到以下文件并删除:(如果有的话)
C:/WINDOWS/system.hta
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT