瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 大虾们:怎么搞定http://168wz.net/这东东

12   1  /  2  页   跳转

大虾们:怎么搞定http://168wz.net/这东东

大虾们:怎么搞定http://168wz.net/这东东

我的机子现在用IE上网就自动打开http://168wz.net/这个网站
internet选项里的首页是空白的。
我尝试过用上网助手修复及瑞星来杀毒。
但还是不见效果,
谁能帮帮我。。。。。。
小弟感激不尽.......
最后编辑2005-09-19 01:23:00
分享到:
gototop
 

用hijackthis扫描后,把日志贴上来
gototop
 

日,骗点击率也不是这样吧
gototop
 

一入网站的那个窗口,点确定了吧~~~
好像只要不点确定都没有什么事·····

附件附件:

下载次数:0
文件类型:image/pjpeg
文件大小:
上传时间:2005-9-18 9:11:43
描述:



gototop
 



各位大虾:

感谢您关注我的这份报告,小菜鸟急需您的帮助!
本扫描/诊断报告由 雅虎助手IE修复专家 生成

操作系统: Windows 98SE
IE版本号: 5.00.2614.3500

===============================================================

以下是我的扫描报告正文:

*** 扫描项列表 ***

下列条目被IE修复专家判断为危险:


下列条目被IE修复专家判断为有风险:

1.R01 - IE起始页的默认页 - http://168wz.net,,
内容:http://168wz.net
安全等级:有风险

2.R01 - IE优先主页 - http://168wz.net,,
内容:http://168wz.net
安全等级:有风险

3.R01 - IE优先主页 - http://168wz.net,,
内容:http://168wz.net
安全等级:有风险

4.R01 - IE用户指定空白页 - http://168wz.net,,
内容:http://168wz.net
安全等级:有风险

5.R01 - IE用户指定空白页 - http://168wz.net,,
内容:http://168wz.net
安全等级:有风险

6.O01 - 域名解析文件(HOSTS) - 218.85.139.122 minisite.qq.com,,
相关文件:C:\WINDOWS\hosts
内容:218.85.139.122 minisite.qq.com
安全等级:有风险

7.O01 - 域名解析文件(HOSTS) - 218.85.139.122 www.minisite.qq.com,,
相关文件:C:\WINDOWS\hosts
内容:218.85.139.122 www.minisite.qq.com
安全等级:有风险

8.O01 - 域名解析文件(HOSTS) - 218.85.139.122 cnww.net,,
相关文件:C:\WINDOWS\hosts
内容:218.85.139.122 cnww.net
安全等级:有风险

9.O01 - 域名解析文件(HOSTS) - 218.85.139.122 www.cnww.net,,
相关文件:C:\WINDOWS\hosts
内容:218.85.139.122 www.cnww.net
安全等级:有风险

10.O01 - 域名解析文件(HOSTS) - 218.85.139.122 zhao123.com,,
相关文件:C:\WINDOWS\hosts
内容:218.85.139.122 zhao123.com
安全等级:有风险

11.O01 - 域名解析文件(HOSTS) - 218.85.139.122 www.zhao123.com,,
相关文件:C:\WINDOWS\hosts
内容:218.85.139.122 www.zhao123.com
安全等级:有风险

12.O01 - 域名解析文件(HOSTS) - 218.85.139.122 4399.com,,
相关文件:C:\WINDOWS\hosts
内容:218.85.139.122 4399.com
安全等级:有风险

13.O01 - 域名解析文件(HOSTS) - 218.85.139.122 www.4399.com,,
相关文件:C:\WINDOWS\hosts
内容:218.85.139.122 www.4399.com
安全等级:有风险

14.O01 - 域名解析文件(HOSTS) - 218.85.139.122 chinagames.net,,
相关文件:C:\WINDOWS\hosts
内容:218.85.139.122 chinagames.net
安全等级:有风险

15.O01 - 域名解析文件(HOSTS) - 218.85.139.122 www.chinagames.net,,
相关文件:C:\WINDOWS\hosts
内容:218.85.139.122 www.chinagames.net
安全等级:有风险

16.O01 - 域名解析文件(HOSTS) - 218.85.139.122... 等 2046 项相似内容,,
相关文件:C:\WINDOWS\hosts
安全等级:有风险


下列条目被IE修复专家判断为未知:

17.O04 - 当前用户自启动目录 - usb.exe,,
相关文件:(隐藏)(系统)C:\WINDOWS\Start Menu\Programs\启动\usb.exe
安全等级:未知

18.O04 - 自动运行项(Run) - usb,,
相关文件:C:\WINDOWS\SYSTEM\usb.exe
内容:C:\WINDOWS\SYSTEM\usb.exe
安全等级:未知

19.O17 - 本机网络设置 NameServer - 202.96.128.86,202.96.128.166,,
内容:202.96.128.86,202.96.128.166
安全等级:未知


下列条目被IE修复专家判断为安全:

20.R03 - 搜索挂接 - 雅虎助手,雅虎助手,等等



每次修复出来的结果都一样...
面且现在就是打开网站都自动链接到www.tu51.com
还自动弹出3楼的菜单.........

gototop
 

到这个帖上参考并下载HijackThis软件
http://forum.ikaka.com/topic.asp?board=67&artid=3926957
gototop
 

给你介绍一个软件,Spybot-S&D,很不错的一个绿色软件,可以免费升级,可以锁定IE,并对一些恶意网站进行屏蔽,他还有很多其它功能,祥情请参考下面的帖子
http://community.rising.com.cn/Forum/msg_read.asp?FmID=28&SubjectID=3862834&page=1
gototop
 

1-17修复
gototop
 

楼上朋友说的什么意思?
gototop
 

以下是hijackthis日志:
请高手指点......


Logfile of HijackThis v1.99.1
Scan saved at 16:23:10, on 05-9-18
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\PROGRAM FILES\瑞星杀毒\RAV\RAVTIMER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\FLASHGET\FLASHGET.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE

R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL
O1 - Hosts: 218.85.139.122 minisite.qq.com
O1 - Hosts: 218.85.139.122 www.minisite.qq.com
O1 - Hosts: 218.85.139.122 cnww.net
O1 - Hosts: 218.85.139.122 www.cnww.net
O1 - Hosts: 218.85.139.122 zhao123.com
O1 - Hosts: 218.85.139.122 www.zhao123.com
O1 - Hosts: 218.85.139.122 4399.com
O1 - Hosts: 218.85.139.122 www.4399.com
O1 - Hosts: 218.85.139.122 chinagames.net
O1 - Hosts: 218.85.139.122 www.chinagames.net
O1 - Hosts: 218.85.139.122 tiexue.net
O1 - Hosts: 218.85.139.122 www.tiexue.net
O1 - Hosts: 218.85.139.122 qq163.com
O1 - Hosts: 218.85.139.122 www.qq163.com
O1 - Hosts: 218.85.139.122 tt67.com
O1 - Hosts: 218.85.139.122 www.tt67.com
O1 - Hosts: 218.85.139.122 chinamp3.com
O1 - Hosts: 218.85.139.122 www.chinamp3.com
O1 - Hosts: 218.85.139.122 pg168.com
O1 - Hosts: 218.85.139.122 www.pg168.com
O1 - Hosts: 218.85.139.122 yymp3.com
O1 - Hosts: 218.85.139.122 www.yymp3.com
O1 - Hosts: 218.85.139.122 yy138.com
O1 - Hosts: 218.85.139.122 www.yy138.com
O1 - Hosts: 218.85.139.122 dj99.com
O1 - Hosts: 218.85.139.122 www.dj99.com
O1 - Hosts: 218.85.139.122 sogua.com
O1 - Hosts: 218.85.139.122 www.sogua.com
O1 - Hosts: 218.85.139.122 snsn.net
O1 - Hosts: 218.85.139.122 www.snsn.net
O1 - Hosts: 218.85.139.122 flash8.net
O1 - Hosts: 218.85.139.122 www.flash8.net
O1 - Hosts: 218.85.139.122 mop.com
O1 - Hosts: 218.85.139.122 www.mop.com
O1 - Hosts: 218.85.139.122 tianyaclub.com
O1 - Hosts: 218.85.139.122 www.tianyaclub.com
O1 - Hosts: 218.85.139.122 xici.net
O1 - Hosts: 218.85.139.122 www.xici.net
O1 - Hosts: 218.85.139.122 ucanlove.com
O1 - Hosts: 218.85.139.122 www.ucanlove.com
O1 - Hosts: 218.85.139.122 cmfu.com
O1 - Hosts: 218.85.139.122 www.cmfu.com
O1 - Hosts: 218.85.139.122 21red.net
O1 - Hosts: 218.85.139.122 www.21red.net
O1 - Hosts: 218.85.139.122 pconline.com.cn
O1 - Hosts: 218.85.139.122 www.pconline.com.cn
O1 - Hosts: 218.85.139.122 donews.com
O1 - Hosts: 218.85.139.122 www.donews.com
O1 - Hosts: 218.85.139.122 pcauto.com.cn
O1 - Hosts: 218.85.139.122 www.pcauto.com.cn
O1 - Hosts: 218.85.139.122 wo99.com
O1 - Hosts: 218.85.139.122 www.wo99.com
O1 - Hosts: 218.85.139.122 flashempire.com
O1 - Hosts: 218.85.139.122 www.flashempire.com
O1 - Hosts: 218.85.139.122 showgood.tv
O1 - Hosts: 218.85.139.122 www.showgood.tv
O1 - Hosts: 218.85.139.122 flashfan.net
O1 - Hosts: 218.85.139.122 www.flashfan.net
O1 - Hosts: 218.85.139.122 long21.net
O1 - Hosts: 218.85.139.122 www.long21.net
O1 - Hosts: 218.85.139.122 socom
O1 - Hosts: 218.85.139.122 www.socom
O1 - Hosts: 218.85.139.122 flashhome.net
O1 - Hosts: 218.85.139.122 www.flashhome.net
O1 - Hosts: 218.85.139.122 cnflash.net
O1 - Hosts: 218.85.139.122 www.cnflash.net
O1 - Hosts: 218.85.139.122 flashsky.com
O1 - Hosts: 218.85.139.122 www.flashsky.com
O1 - Hosts: 218.85.139.122 hunansky.com
O1 - Hosts: 218.85.139.122 www.hunansky.com
O1 - Hosts: 218.85.139.122 52flash.net
O1 - Hosts: 218.85.139.122 www.52flash.net
O1 - Hosts: 218.85.139.122 flashh.com
O1 - Hosts: 218.85.139.122 www.flashh.com
O1 - Hosts: 218.85.139.122 flashsun.com
O1 - Hosts: 218.85.139.122 www.flashsun.com
O1 - Hosts: 218.85.139.122 7k7k.com
O1 - Hosts: 218.85.139.122 www.7k7k.com
O1 - Hosts: 218.85.139.122 xuanxuan.com
O1 - Hosts: 218.85.139.122 www.xuanxuan.com
O1 - Hosts: 218.85.139.122 flash88.net
O1 - Hosts: 218.85.139.122 www.flash88.net
O1 - Hosts: 218.85.139.122 91flash.com
O1 - Hosts: 218.85.139.122 www.91flash.com
O1 - Hosts: 218.85.139.122 doingflash.com
O1 - Hosts: 218.85.139.122 www.doingflash.com
O1 - Hosts: 218.85.139.122 skyhits.com
O1 - Hosts: 218.85.139.122 www.skyhits.com
O1 - Hosts: 218.85.139.122 ting78.com
O1 - Hosts: 218.85.139.122 www.ting78.com
O1 - Hosts: 218.85.139.122 91.com
O1 - Hosts: 218.85.139.122 www.91.com
O1 - Hosts: 218.85.139.122 flashchina.net
O1 - Hosts: 218.85.139.122 www.flashchina.net
O1 - Hosts: 218.85.139.122 flash8.com.cn
O1 - Hosts: 218.85.139.122 www.flash8.com.cn
O1 - Hosts: 218.85.139.122 f130.net
O1 - Hosts: 218.85.139.122 www.f130.net
O1 - Hosts: 218.85.139.122 chinanim.com
O1 - Hosts: 218.85.139.122 www.chinanim.com
O1 - Hosts: 218.85.139.122 comicer.com
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRAM FILES\FLASHGET\JCCATCH.DLL
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\YAHOO!\ASSIST~1\ASSIST\YDRAGS~1.DLL
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRAM FILES\FLASHGET\FGIEBAR.DLL
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\DOWNLO~1\CNSMIN.DLL,Rundll32
O4 - HKLM\..\Run: [RavTimer] C:\PROGRA~1\瑞星杀毒\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [usb] C:\WINDOWS\SYSTEM\usb.exe
O4 - Startup: usb.exe
O8 - Extra context menu item: 使用网际快车下载 - C:\PROGRAM FILES\FLASHGET\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\PROGRAM FILES\FLASHGET\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\PROGRAM FILES\TENCENT\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\PROGRAM FILES\TENCENT\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\PROGRAM FILES\TENCENT\QQ\SendMMS.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O11 - Options group: [!CNS]  上网助手-地址栏搜索
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 202.96.128.86,202.96.128.166
O18 - Protocol: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\SYSTEM\urlmon.dll
O18 - Protocol: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\SYSTEM\urlmon.dll
O18 - Protocol: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\SYSTEM\urlmon.dll
O18 - Protocol: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\SYSTEM\urlmon.dll
O18 - Protocol: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\SYSTEM\urlmon.dll
O18 - Protocol: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\SYSTEM\urlmon.dll
O18 - Protocol: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\SYSTEM\urlmon.dll
O18 - Protocol: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\WINDOWS\SYSTEM\urlmon.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM\MSHTML.DLL
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM\MSHTML.DLL
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM\MSHTML.DLL
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM\MSHTML.DLL
O18 - Protocol: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SYSTEM\MSHTML.DLL
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\SYSTEM\MSHTML.DLL
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\SYSTEM\ITSS.DLL
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\SYSTEM\ITSS.DLL
O18 - Protocol: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\WINDOWS\SYSTEM\INETCOMM.DLL
O18 - Protocol: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: ipp - (no CLSID) - (no file)

gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT