瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】我是菜鸟大侠们快来帮我!

1   1  /  1  页   跳转

【求助】我是菜鸟大侠们快来帮我!

【求助】我是菜鸟大侠们快来帮我!

这是我的日志,开机总是弹出网页!
HijackThis@Qoo的扫描日志  V1.97.7
Scan saved at 8:04:50, on 2006-9-17
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\CNNIC\Cdn\cdnup.exe
C:\WINDOWS\WINLOGON.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\SVOHOST.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\ntkrnl.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.016\HijackThis.exe

O2 - BHO: (no name) - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\Program Files\DeskAdTop\deskipn.dll
O2 - BHO: (no name) - {08A312BB-5409-49FC-9347-54BB7D069AC6}? - (no file)
O2 - BHO: (no name) - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_5007.dll
O2 - BHO: (no name) - {16B770A0-0E87-4278-B748-2460D64A8386}? - (no file)
O2 - BHO: (no name) - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O2 - BHO: (no name) - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108}? - (no file)
O3 - Toolbar: ????? - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll (file missing)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Desktop] C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll
O4 - HKLM\..\Run: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
O4 - HKLM\..\Run: [SoundMam] C:\WINDOWS\system32\SVOHOST.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: dmshell.dll
O4 - Startup: nk1.exe
O4 - Startup: NTUSER.DAT
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Startup: RavMonLog
O4 - Startup: tcmd.exe
O4 - Global Startup: ntuser.dat
O4 - Global Startup: ntuser.dat.LOG
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdnns.dll
O10 - Unknown file in Winsock LSP: c:\program files\kv2006\kvsock.dll
O10 - Unknown file in Winsock LSP: c:\program files\kv2006\kvsock.dll
O10 - Unknown file in Winsock LSP: c:\program files\kv2006\kvsock.dll
O10 - Unknown file in Winsock LSP: c:\program files\kv2006\kvsock.dll
O10 - Unknown file in Winsock LSP: c:\program files\kv2006\kvsock.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{CB8A79A1-4460-457E-B27C-A6D6E313C273}: NameServer = 202.102.154.3 202.102.152.3
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - %SystemRoot%\system32\mshtml.dll

最后编辑2006-09-17 08:26:11
分享到:
gototop
 

O2 - BHO: (no name) - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_5007.dll
参考:http://csc.rising.com.cn/KnowledgeBase/detailInfo.aspx?Action=ViewInfo&InfoID=718&Channel=RSV


O4 - HKLM\..\Run: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
下载专杀查杀.下载地址:http://mopery.hits.io/狮子落雪系列专杀.zip

修复
O2 - BHO: (no name) - {08A312BB-5409-49FC-9347-54BB7D069AC6}? - (no file)
O2 - BHO: (no name) - {16B770A0-0E87-4278-B748-2460D64A8386}? - (no file)
O2 - BHO: (no name) - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108}? - (no file)
O4 - HKLM\..\Run: [SoundMam] C:\WINDOWS\system32\SVOHOST.exe
O4 - Startup: dmshell.dll
O4 - Startup: nk1.exe
O4 - Startup: NTUSER.DAT
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Startup: RavMonLog
O4 - Startup: tcmd.exe
O4 - Global Startup: ntuser.dat
O4 - Global Startup: ntuser.dat.LOG
删除
C:\WINDOWS\system32\SVOHOST.exe

右键-打开
除C盘以外的盘..
删除
Autorun.inf和sxs.exe

处理完..
http://mopery.hits.io/sreng2.zip 下载System Repair Engineer
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT