瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】被恶意网站攻击,请求帮助

1   1  /  1  页   跳转

【求助】被恶意网站攻击,请求帮助

【求助】被恶意网站攻击,请求帮助

受到恶意网站www.5533.com的攻击,试了很多方法主页还是改不回来,甚至禁用了我的注册表。希望得到老大的帮助,用hijackthis 1.99扫描后的结果:

Logfile of HijackThis v1.99.1
Scan saved at 17:38:08, on 2003-7-15
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\D-Tools\daemon.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\ghost.exe
C:\WINDOWS\System32\mshta.exe
C:\Program Files\ZarvaSoft\Smart Update Utility\AhnSD.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\ZarvaSoft\ZVC\V3P3AT.exe
C:\Program Files\ZarvaSoft\Smart Update Utility\Ahnsdsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Roxio\Easy Media Creator 7\Home Page\HomePageApp.exe
C:\Program Files\Roxio\Easy Media Creator 7\Capture\RoxioCapture7.exe
C:\PROGRA~1\ZARVAS~1\ZVC\MonSvcNT.EXE
C:\Program Files\ZarvaSoft\ZVC\MonSysNT.exe
C:\Program Files\Roxio\Easy Media Creator 7\Media Manager\MediaManager7.exe
C:\Program Files\Roxio\Easy Media Creator 7\Creator Classic\Creator7.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Kingsoft\PowerWord 2005\XDICT.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Ivyhuang\LOCALS~1\Temp\Rar$EX00.594\HijackThis.exe

O1 - Hosts: 218.85.132.177 cns.3721.com
O1 - Hosts: 218.85.132.177 seek.3721.com
O1 - Hosts: 218.85.132.177 assistant.3721.com
O1 - Hosts: 218.85.132.177 sms.3721.com
O1 - Hosts: 218.85.132.177 cnsmin.3721.com
O1 - Hosts: 218.85.132.177 hot.3721.com
O1 - Hosts: 218.85.132.177 3721.com
O1 - Hosts: 218.85.132.177 www.3721.com
O1 - Hosts: 218.85.132.177 nmsearch.3721.com
O1 - Hosts: 218.85.132.177 cmail.3721.com
O1 - Hosts: 218.85.132.177 corp.3721.com
O1 - Hosts: 218.85.132.177 download.3721.com
O1 - Hosts: 218.85.132.177 www.hao123.com
O1 - Hosts: 218.85.132.177 www.265.com
O1 - Hosts: 218.85.132.177 hao123.com
O1 - Hosts: 218.85.132.177 265.com
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to

Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm

Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [ExFilter] Rundll32.exe C:\WINDOWS\System32\hookdll.dll,ExecFilter solo
O4 - HKLM\..\Run: [IMSCMIG40W] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40W\IMSCMIG.EXE

/SetPreload /Log
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft

Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PDF Converter Registry Controller] "C:\Program Files\ScanSoft\PDF

Converter 2.0\\RegistryController.exe"
O4 - HKLM\..\Run: [Sys_Run] C:\WINDOWS\ghost.exe
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\system32\helper.hta
O4 - HKLM\..\Run: [AHNSD] "C:\Program Files\ZarvaSoft\Smart Update Utility\AhnSD.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft

ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common

Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?SystemRoot%\Installer\{AC76BA86-

1033-0000-7760-000000000002}\SC_Acrobat.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program

Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program

Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program

Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program

Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program

Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program

Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat

7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat

7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Open PDF in Word (PDF Converter 2.0) - res://C:\Program

Files\ScanSoft\PDF Converter 2.0\IEShellExt.dll /100
O8 - Extra context menu item: 使用Kugoo下载 - C:\PROGRA~1\KUGOO2\KugooDownX.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -

C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -

C:\WINDOWS\web\related.htm
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) -

https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O18 - Protocol: mp3 - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe

Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ahnlab Task Scheduler - AhnLab, Inc. - C:\Program Files\ZarvaSoft\Smart

Update Utility\Ahnsdsv.exe
O23 - Service: MonSvcNT - Ahnlab, Inc. - C:\PROGRA~1\ZARVAS~1\ZVC\MonSvcNT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\System32\nvsvc32.exe

最后编辑2005-07-16 18:02:45
分享到:
gototop
 

【回复“diamond007”的帖子】
请关闭所有IE界面,重新使用HijackThis扫描一次,选中下面建议修复的项目,让HijackThis修复,修复前请允许HijackThis保留备份。(如果楼主知道是安全的可以不必勾选)
所有01项
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O18 - Protocol: mp3 - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - (no file)

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT