瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我中了我见过最讨厌的病毒,高手快来帮下忙!!!!!!!!!!!!

1   1  /  1  页   跳转

我中了我见过最讨厌的病毒,高手快来帮下忙!!!!!!!!!!!!

我中了我见过最讨厌的病毒,高手快来帮下忙!!!!!!!!!!!!

最开始的症状是自动弹出网页,IE被改得一塌糊涂,注册表编辑器被禁用.通过IE修复软件后也没什么效果,就系统还原(我以为这招就必杀了吧).没想到啊没想到一个最严重的问题还留着,在浏览器中凡www开头的网址打开几乎都会被转换到www.top22.cn的这个病毒网址(严重鄙视这个网站).请教高手怎么解决这个问题??包括什么杀毒软件可以搞定,如果要自己动手恢复要怎么搞定?

    先表示感谢下.
最后编辑2005-07-08 10:03:01
分享到:
gototop
 

HijackThis下载地址请参考:
【必读】本版说明及常用小软件下载
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
请扫描后,把日志贴上来,这个应该属于浏览器劫持,随便你贴在哪里了
gototop
 


谢谢指点,我第一次用这软件,是记事本这个吧,看不懂,望高人指点:)

Logfile of HijackThis v1.99.1
Scan saved at 8:23:53, on 2005-7-8
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\FLASHGET\flashget.exe
C:\Downloads\HijackThis.exe

R3 - Default URLSearchHook is missing
O1 - Hosts: ----------------音乐网站----------------
O1 - Hosts: 222.77.178.52 dj99.com
O1 - Hosts: 222.77.178.52 dj99.net
O1 - Hosts: 222.77.178.52 1ting.com
O1 - Hosts: 222.77.178.52 www.1ting.com
O1 - Hosts: 222.77.178.52 www.dj99.com
O1 - Hosts: 222.77.178.52 www.dj99.net
O1 - Hosts: 222.77.178.52 qq163.com
O1 - Hosts: 222.77.178.52 www.qq163.com
O1 - Hosts: 219.129.216.89 qq163.net
O1 - Hosts: 219.129.216.89 www.qq163.net
O1 - Hosts: 222.77.178.52 qq520.com
O1 - Hosts: 222.77.178.52 www.qq520.com
O1 - Hosts: 222.77.178.52 qq520.net
O1 - Hosts: 222.77.178.52 www.qq520.net
O1 - Hosts: 222.77.178.52 cococ.com
O1 - Hosts: 222.77.178.52 www.cococ.com
O1 - Hosts: 222.77.178.52 ting.cococ.com
O1 - Hosts: 222.77.178.52 www.chinamp3.com
O1 - Hosts: 222.77.178.52 tfol.com
O1 - Hosts: 222.77.178.52 music.tfol.com
O1 - Hosts: 219.129.216.89 ting98.com
O1 - Hosts: 222.77.178.52 www.ting98.com
O1 - Hosts: 222.77.178.52 ting99.com
O1 - Hosts: 222.77.178.52 www.ting99.com
O1 - Hosts: 219.129.216.89 yyue.com
O1 - Hosts: 219.129.216.89 www.yyue.com
O1 - Hosts: 219.129.216.89 yyue.net
O1 - Hosts: 219.129.216.89 www.yyue.net
O1 - Hosts: 222.77.178.52 qq530.com
O1 - Hosts: 222.77.178.52 www.qq530.com
O1 - Hosts: 219.129.216.89 552211.com
O1 - Hosts: 219.129.216.89 www.552211.com
O1 - Hosts: 219.129.216.89 sg12.com
O1 - Hosts: 219.129.216.89 www.sg12.com
O1 - Hosts: 222.77.178.52 0ting.com
O1 - Hosts: 222.77.178.52 www.0ting.com
O1 - Hosts: 222.77.178.52 772.cn
O1 - Hosts: 222.77.178.52 www.772.cn
O1 - Hosts: 219.129.216.89 qq150.com
O1 - Hosts: 219.129.216.89 www.qq150.com
O1 - Hosts: 222.77.178.52 yy265.com
O1 - Hosts: 222.77.178.52 www.yy265.com
O1 - Hosts: 219.129.216.89 www.517tg.com
O1 - Hosts: 219.129.216.89 517tg.com
O1 - Hosts: 219.129.216.89 www.klkb.com
O1 - Hosts: 219.129.216.89 klkb.com
O1 - Hosts: 219.129.216.89 qq250.com
O1 - Hosts: 219.129.216.89 www.qq250.com
O1 - Hosts: 222.77.178.52 666ccc.com
O1 - Hosts: 222.77.178.52 www.666ccc.com
O1 - Hosts: 222.77.178.52 7t7t.com
O1 - Hosts: 222.77.178.52 www.7t7t.com
O1 - Hosts: ----------------著名网址----------------
O1 - Hosts: 222.77.178.52 hao123.com
O1 - Hosts: 222.77.178.52 hao123.net
O1 - Hosts: 222.77.178.52 hao222.com
O1 - Hosts: 222.77.178.52 hao222.net
O1 - Hosts: 222.77.178.52 www.hao123.com
O1 - Hosts: 222.77.178.52 www.hao123.net
O1 - Hosts: 222.77.178.52 www.hao222.com
O1 - Hosts: 222.77.178.52 www.hao222.net
O1 - Hosts: 222.77.178.52 265.com
O1 - Hosts: 222.77.178.52 www.265.com
O1 - Hosts: 222.77.178.52 516.com
O1 - Hosts: 222.77.178.52 www.516.com
O1 - Hosts: 219.129.216.89 da123.com
O1 - Hosts: 219.129.216.89 www.da123.com
O1 - Hosts: 219.129.216.89 wu123.com
O1 - Hosts: 219.129.216.89 www.wu123.com
O1 - Hosts: ----------------杀毒网站----------------
O1 - Hosts: 222.77.178.52 www.rising.com.cn
O1 - Hosts: 222.77.178.52 dl.jiangmin.com
O1 - Hosts: 222.77.178.52 it.rising.com.cn
O1 - Hosts: 222.77.178.52 online.rising.com.cn
O1 - Hosts: 222.77.178.52 go.rising.com.cn
O1 - Hosts: 222.77.178.52 db.kingsoft.com
O1 - Hosts: 222.77.178.52 kingsoft.com
O1 - Hosts: 222.77.178.52 www.jiangmin.com
O1 - Hosts: 222.77.178.52 jiangmin.com
O1 - Hosts: 222.77.178.52 online.jiangmin.com
O1 - Hosts: 222.77.178.52 assistant.3721.com
O1 - Hosts: ----------------搜索网站----------------
O1 - Hosts: 222.77.178.52 baidu.com
O1 - Hosts: 222.77.178.52 www.baidu.com
O1 - Hosts: 222.77.178.52 mp3.baidu.com
O1 - Hosts: 222.77.178.52 google.com
O1 - Hosts: 222.77.178.52 www.google.com
O1 - Hosts: 222.77.178.52 yisou.com
O1 - Hosts: 222.77.178.52 www.yisou.com
O1 - Hosts: 222.77.178.52 music.yisou.com
O1 - Hosts: 222.77.178.52 search.sohu.com
O1 - Hosts: 222.77.178.52 auto.search.msn.com
O1 - Hosts: 222.77.178.52 search.sina.com.cn
O1 - Hosts: 222.77.178.52 so.163.com
O1 - Hosts: 222.77.178.52 cha.so.163.com
O1 - Hosts: 222.77.178.52 search.tom.com
O1 - Hosts: 222.77.178.52 cns.3721.com
O1 - Hosts: 222.77.178.52 so.qq.com
O1 - Hosts: ----------------门户网站----------------
O1 - Hosts: 222.77.178.52 163.com
O2 - BHO: QQBrowserHelperObject Class - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: 使用网际快车下载 - C:\PROGRA~1\FLASHGET\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\PROGRA~1\FLASHGET\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D8B47D5-1367-45D1-9A80-6654BEAB85DE}: NameServer = 202.101.112.55 202.101.98.55
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

gototop
 

修复所有01项
R3 - Default URLSearchHook is missing
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present\
gototop
 

好象解决了噎~~~~~~~~~~~~~~~

真是太神奇鸟,有问题偶在来,再次表示感谢
gototop
 

不客气
gototop
 

不错的东西啊,
先自各看看,学习学习。
谢谢了!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT