瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】好心哥哥姐姐来救救我!附日志

1   1  /  1  页   跳转

【求助】好心哥哥姐姐来救救我!附日志

【求助】好心哥哥姐姐来救救我!附日志

Logfile of HijackThis v1.99.1
Scan saved at 22:27:26, on 2005-7-8
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ZAccess\AccessLinker ADSL\CnxDslTb.exe
C:\Program Files\Maxthon\Thundermini\ThunderMini.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\KV2005\KVMonXP.kxp
C:\Program Files\Thunder Network\Thunder\Thunder.exe
C:\Program Files\KV2005\TrojDie.kxp
C:\Program Files\KV2005\KRegEx.exe
C:\Program Files\Thunder Network\Thunder\MediaIssue\Issue.exe
C:\WINDOWS\system32\DllHost.exe
C:\Program Files\Maxthon\Maxthon.exe
C:\Program Files\KV2005\KvXP.kxp
C:\WINDOWS\system32\DllHost.exe
C:\Program Files\KV2005\KvXP.kxp
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.360\HijackThis.exe

O1 - Hosts: 66.102.7.104 publish.it168.com
O1 - Hosts: 66.102.7.104 it168.com
O1 - Hosts: 66.102.7.104 www.it168.com
O1 - Hosts: 66.102.7.104 www.zsyyy.com
O1 - Hosts: 66.102.7.104 zsyyy.com
O1 - Hosts: 66.102.7.104 news.xinhuanet.com
O1 - Hosts: 66.102.7.104 xinhuanet.com
O1 - Hosts: 66.102.7.104 www.xinhuanet.com
O1 - Hosts: 66.102.7.104 www.chinaren.com
O1 - Hosts: 66.102.7.104 chinaren.com
O1 - Hosts: 66.102.7.104 hackbase.com
O1 - Hosts: 66.102.7.104 www.hackbase.com
O1 - Hosts: 66.102.7.104 bbs.hackbase.com
O1 - Hosts: 66.102.7.104 www.cnredhacker.net
O1 - Hosts: 66.102.7.104 cnredhacker.net
O1 - Hosts: 66.102.7.104 bbs.cnredhacker.net
O1 - Hosts: 66.102.7.104 www.redhacker.cn
O1 - Hosts: 66.102.7.104 redhacker.cn
O1 - Hosts: 66.102.7.104 www.tt67.com
O1 - Hosts: 66.102.7.104 tt67.com
O1 - Hosts: 66.102.7.104 www.peacehall.com
O1 - Hosts: 66.102.7.104 peacehall.com
O1 - Hosts: 66.102.7.104 www.zaobao.com
O1 - Hosts: 66.102.7.104 zaobao.com
O1 - Hosts: 66.102.7.104 www.frhlm.com
O1 - Hosts: 66.102.7.104 frhlm.com
O1 - Hosts: 66.102.7.104 www.japanpig.com
O1 - Hosts: 66.102.7.104 japanpig.com
O1 - Hosts: 66.102.7.104 bbs.china918.net
O1 - Hosts: 66.102.7.104 china918.net
O1 - Hosts: 66.102.7.104 www.china918.net
O1 - Hosts: 66.102.7.104 bbs.hackbase.com
O1 - Hosts: 66.102.7.104 hackbase.com
O1 - Hosts: 66.102.7.104 www.hackbase.com
O1 - Hosts: 66.102.7.104 www.cnhonker.com.cn
O1 - Hosts: 66.102.7.104 cnhonker.com.cn
O1 - Hosts: 66.102.7.104 www.cnhonker.net
O1 - Hosts: 66.102.7.104 cnhonker.net
O1 - Hosts: 66.102.7.104 forum.chinahonker.com
O1 - Hosts: 66.102.7.104 www.zg77hk.com
O1 - Hosts: 66.102.7.104 zg77hk.com
O1 - Hosts: 66.102.7.104 chinahacker.com
O1 - Hosts: 66.102.7.104 www.chinahacker.com
O1 - Hosts: 66.102.7.104 hackerchina.com
O1 - Hosts: 66.102.7.104 www.hackerchina.com
O1 - Hosts: 66.102.7.104 hackercn.com
O1 - Hosts: 66.102.7.104 www.hackercn.com
O1 - Hosts: 66.102.7.104 cnhack.com
O1 - Hosts: 66.102.7.104 www.cnhack.com
O1 - Hosts: 66.102.7.104 hackchina.com
O1 - Hosts: 66.102.7.104 www.hackchina.com
O1 - Hosts: 66.102.7.104 asiahacker.com
O1 - Hosts: 66.102.7.104 www.asiahacker.com
O1 - Hosts: 66.102.7.104 hackerasia.com
O1 - Hosts: 66.102.7.104 www.hackerasia.com
O1 - Hosts: 66.102.7.104 54hacker.com
O1 - Hosts: 66.102.7.104 www.54hacker.com
O1 - Hosts: 66.102.7.104 e110.com
O1 - Hosts: 66.102.7.104 www.e110.com
O1 - Hosts: 66.102.7.104 www.300000.org
O1 - Hosts: 66.102.7.104 300000.org
O1 - Hosts: 66.102.7.104 dbkl.china1840-1949.net.cn
O1 - Hosts: 66.102.7.104 china1840-1949.net.cn
O1 - Hosts: 66.102.7.104 www.china1840-1949.net.cn
O1 - Hosts: 66.102.7.104 www.luobinghui.com
O1 - Hosts: 66.102.7.104 luobinghui.com
O1 - Hosts: 66.102.7.104 kryl.chinaspirit.net.cn
O1 - Hosts: 66.102.7.104 chinaspirit.net.cn
O1 - Hosts: 66.102.7.104 www.chinaspirit.net.cn
O1 - Hosts: 66.102.7.104 www.china.org.cn
O1 - Hosts: 66.102.7.104 china.org.cn
O1 - Hosts: 66.102.7.104 www.chinawill.com
O1 - Hosts: 66.102.7.104 chinawill.com
O1 - Hosts: 66.102.7.104 union.zhongsou.com
O1 - Hosts: 66.102.7.104 zhongsou.com
O1 - Hosts: 66.102.7.104 www.zhongsou.com
O1 - Hosts: 66.102.7.104 www.ad163.com
O1 - Hosts: 66.102.7.104 ad163.com
O1 - Hosts: 66.102.7.104 www.mypm.net
O1 - Hosts: 66.102.7.104 mypm.net
O1 - Hosts: 66.102.7.104 www.aspsun.com
O1 - Hosts: 66.102.7.104 aspsun.com
O1 - Hosts: 66.102.7.104 www.phpx.com
O1 - Hosts: 66.102.7.104 phpx.com
O1 - Hosts: 66.102.7.104 search.btchina.net
O1 - Hosts: 66.102.7.104 btchina.net
O1 - Hosts: 66.102.7.104 www.btchina.net
O1 - Hosts: 66.102.7.104 www.chinakrlm.com
O1 - Hosts: 66.102.7.104 chinakrlm.com
O1 - Hosts: 66.102.7.104 blog.hexun.com
O1 - Hosts: 66.102.7.104 hexun.com
O1 - Hosts: 66.102.7.104 www.hexun.com
O1 - Hosts: 66.102.7.104 thysea.com
O1 - Hosts: 66.102.7.104 www.thysea.com
O1 - Hosts: 66.102.7.104 goneianne.512j.com
O1 - Hosts: 66.102.7.104 512j.com
O1 - Hosts: 66.102.7.104 www.512j.com
O1 - Hosts: 66.102.7.104 3421-2.clubsky.net
O1 - Hosts: 66.102.7.104 www.clubsky.net
O1 - Hosts: 66.102.7.104 clubsky.net
O1 - Hosts: 66.102.7.104 www.ywkr.com
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: MEobjectSDT - {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} - C:\WINDOWS\System32\aclayer.dll
O2 - BHO: BrowseHelper Class - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} - C:\Program Files\KV2005\KvShell_1.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\system32\qylhelper.dll (file missing)
O3 - Toolbar: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\BitComet\BitCometBar\BitCometBar0.1.dll
O3 - Toolbar: 江民杀毒工具栏 - {B5A34A93-D538-43A7-8371-864CB6148D12} - C:\Program Files\KV2005\KvShell_1.dll
O4 - HKLM\..\Run: [CnxDslTaskBar] C:\Program Files\ZAccess\AccessLinker ADSL\CnxDslTb.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [thunder_mini] C:\Program Files\Maxthon\Thundermini\ThunderMini.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [KvMonXP] C:\Program Files\KV2005\KVMonXP.kxp /auto
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\system32\msconfig.exe /auto
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - Startup: 迅雷4.lnk = C:\Program Files\Thunder Network\Thunder\Thunder.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getAllurl.htm
O8 - Extra context menu item: &使用迷你迅雷下载 - C:\Program Files\Maxthon\Thundermini\geturl.htm
O8 - Extra context menu item: mxie 档案搜索 - C:\Program Files\mxie\Config\protocol.htm
O8 - Extra context menu item: 使用 IDM 下载 - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: 使用 IDM 下载所有链接 - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: 使用Kugoo下载 - C:\PROGRA~1\KUGOO2\KugooDownX.htm
O8 - Extra context menu item: 使用影音传送带下载 - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\qq\SendMMS.htm
O9 - Extra button: 网址大全 - {1FBA04EE-3024-11D2-8F1F-0000F87ABD18} - http://www.coc.cc (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\kvwspxp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\kvwspxp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\kvwspxp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\spi50.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\spi50.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1119596026471
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1119752428359
O17 - HKLM\System\CCS\Services\Tcpip\..\{580DBEB4-70FD-452D-93F9-B1BCFD7C5632}: NameServer = 202.99.192.68,202.99.162.6
O17 - HKLM\System\CCS\Services\Tcpip\..\{E4312C12-D971-42AB-98BC-29CDFD2911D8}: NameServer = 202.99.192.66 202.99.192.68
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\system32\mbprot.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: KVWSC - Jiangmin Co.Ltd - C:\Program Files\KV2005\kvwsc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

最后编辑2005-07-08 23:38:19
分享到:
gototop
 

【回复“乔☆畅”的帖子】
重新启动到安全模式(进入安全模式的方法:重新启动电脑, 开机自动检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式(Safe Mode)进入Windows。)

请关闭所有IE界面,重新使用HijackThis扫描一次,选中下面建议修复的项目,让HijackThis修复,修复前请允许HijackThis保留备份。(如果楼主知道是安全的可以不必勾选)
所有01项
O2 - BHO: MEobjectSDT - {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} - C:\WINDOWS\System32\aclayer.dll
O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\system32\qylhelper.dll (file missing)
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: 网址大全 - {1FBA04EE-3024-11D2-8F1F-0000F87ABD18} - http://www.coc.cc (file missing)
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\system32\mbprot.dll

然后打开我的电脑。。再点工具。。打开文件夹选项。。。查看。。。把隐藏受保护的系统文件(推荐)和隐藏已知文件类型的扩展名的勾去掉。再显示所有文件。 用WINDOWS的查找功能进行查找并删除:
C:\WINDOWS\System32\aclayer.dll
C:\WINDOWS\system32\qylhelper.dll
C:\WINDOWS\system32\mbprot.dll


gototop
 

补充:在地址栏输入www.163.com  www.qq.com  www.hackbase.com
等等网站后,打开的全部是google。不能用百度。不能用百度搜索。如果用,网页会出现google的not found。。。
哥哥姐姐们帮助我
gototop
 

【回复“乔☆畅”的帖子】
请先按一楼的回复进行修复
gototop
 

完成了,但是2楼我叙述的问题依旧
gototop
 

01项修复了吗?

问题仍在的话,请再用最新版Hijackthis1.99.1扫描一个log贴上来。
gototop
 

我发现01什么HOSTS 后面的网站都打不开。然后删除了一个,发现所对应的能打开了。。谢了这是………………
能全部删除吗??小弟谢谢刚才那位哥哥飞跃迷离了。
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 23:37:35, on 2005-7-8
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ZAccess\AccessLinker ADSL\CnxDslTb.exe
C:\Program Files\Maxthon\Thundermini\ThunderMini.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\KV2005\KVMonXP.kxp
C:\Program Files\KV2005\TrojDie.kxp
C:\Program Files\KV2005\KRegEx.exe
C:\WINDOWS\system32\DllHost.exe
C:\Program Files\Maxthon\Maxthon.exe
F:\fq\bingdu\工具\hijackthis\248783200522382732\HijackThis.exe

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: BrowseHelper Class - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} - C:\Program Files\KV2005\KvShell_1.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O3 - Toolbar: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\BitComet\BitCometBar\BitCometBar0.1.dll
O3 - Toolbar: 江民杀毒工具栏 - {B5A34A93-D538-43A7-8371-864CB6148D12} - C:\Program Files\KV2005\KvShell_1.dll
O4 - HKLM\..\Run: [CnxDslTaskBar] C:\Program Files\ZAccess\AccessLinker ADSL\CnxDslTb.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [thunder_mini] C:\Program Files\Maxthon\Thundermini\ThunderMini.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [KvMonXP] C:\Program Files\KV2005\KVMonXP.kxp /auto
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\system32\msconfig.exe /auto
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - Startup: 迅雷4.lnk = C:\Program Files\Thunder Network\Thunder\Thunder.exe
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getAllurl.htm
O8 - Extra context menu item: &使用迷你迅雷下载 - C:\Program Files\Maxthon\Thundermini\geturl.htm
O8 - Extra context menu item: mxie 档案搜索 - C:\Program Files\mxie\Config\protocol.htm
O8 - Extra context menu item: 使用 IDM 下载 - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: 使用 IDM 下载所有链接 - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: 使用Kugoo下载 - C:\PROGRA~1\KUGOO2\KugooDownX.htm
O8 - Extra context menu item: 使用影音传送带下载 - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\qq\SendMMS.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\kvwspxp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\kvwspxp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\kvwspxp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\spi50.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\spi50.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1119596026471
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1119752428359
O17 - HKLM\System\CCS\Services\Tcpip\..\{580DBEB4-70FD-452D-93F9-B1BCFD7C5632}: NameServer = 202.99.192.68,202.99.162.6
O17 - HKLM\System\CCS\Services\Tcpip\..\{E4312C12-D971-42AB-98BC-29CDFD2911D8}: NameServer = 202.99.192.66 202.99.192.68
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: KVWSC - Jiangmin Co.Ltd - C:\Program Files\KV2005\kvwsc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

现在好了
我把那个全删了
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT