1   1  /  1  页   跳转

求助!!!谢谢各位大哥.

求助!!!谢谢各位大哥.

HijackThis_815汉化版扫描日志 V1.99.1
保存于      21:49:28, 日期 2005-11-9
操作系统:  Windows XP SP1 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\conime.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE
C:\Program Files\FBNClient\FBNClient\fbnClient.exe
C:\Program Files\Tencent\TT\TTraveler.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Zhang Xihong\桌面\4842302005817230232\HijackThis1991zww.exe

R3 - URLSearchHook: (no name) - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll
O1 - Hosts: 218.85.133.109www.vodfans.com
O1 - Hosts: 218.85.133.109vodfans.com
O1 - Hosts: 218.85.133.109www.k234.com
O1 - Hosts: 218.85.133.109k234.com
O1 - Hosts: 218.85.133.109www.goodwww.com
O1 - Hosts: 218.85.133.109goodwww.com
O1 - Hosts: 218.85.133.109www.tv66.org
O1 - Hosts: 218.85.133.109tv66.org
O1 - Hosts: 218.85.133.109www.w555.com
O1 - Hosts: 218.85.133.109w555.com
O1 - Hosts: 218.85.133.109www.tkfilm.com
O1 - Hosts: 218.85.133.109tkfilm.com
O1 - Hosts: 218.85.133.109www.163.zhao117.com
O1 - Hosts: 218.85.133.109163.zhao117.com
O1 - Hosts: 218.85.133.109www.v.wg818.com
O1 - Hosts: 218.85.133.109v.wg818.com
O1 - Hosts: 218.85.133.109www.7122.com
O1 - Hosts: 218.85.133.1097122.com
O1 - Hosts: 218.85.133.109www.v.wg818.com
O1 - Hosts: 218.85.133.109v.wg818.com
O1 - Hosts: 218.85.133.109www.hot.3721.com
O1 - Hosts: 218.85.133.109hot.3721.com
O1 - Hosts: 218.85.133.109www.99770.com
O1 - Hosts: 218.85.133.10999770.com
O1 - Hosts: 218.85.133.109www.kk369.net
O1 - Hosts: 218.85.133.109kk369.net
O1 - Hosts: 218.85.133.109www.xunlei.com
O1 - Hosts: 218.85.133.109xunlei.com
O1 - Hosts: 218.85.133.109www.92bt.com
O1 - Hosts: 218.85.133.10992bt.com
O1 - Hosts: 218.85.133.109www.search.onlinedown.net
O1 - Hosts: 218.85.133.109search.onlinedown.net
O1 - Hosts: 218.85.133.109www.ent.da163.net
O1 - Hosts: 218.85.133.109ent.da163.net
O1 - Hosts: 218.85.133.109www.lbxx.net
O1 - Hosts: 218.85.133.109lbxx.net
O1 - Hosts: 218.85.133.109www.44489.com
O1 - Hosts: 218.85.133.10944489.com
O1 - Hosts: 218.85.133.109www.avvip.com
O1 - Hosts: 218.85.133.109avvip.com
O1 - Hosts: 218.85.133.109www.film21cn.com
O1 - Hosts: 218.85.133.109film21cn.com
O1 - Hosts: 218.85.133.109www.y256.com
O1 - Hosts: 218.85.133.109y256.com
O1 - Hosts: 218.85.133.109www.newsw.net
O1 - Hosts: 218.85.133.109newsw.net
O1 - Hosts: 218.85.133.109www.vod99.com
O1 - Hosts: 218.85.133.109vod99.com
O1 - Hosts: 218.85.133.109www.80666666.com
O1 - Hosts: 218.85.133.10980666666.com
O1 - Hosts: 218.85.133.109www.88ty.com
O1 - Hosts: 218.85.133.10988ty.com
O1 - Hosts: 218.85.133.109www.xinglove.com
O1 - Hosts: 218.85.133.109xinglove.com
O1 - Hosts: 218.85.133.109www.99755.com
O1 - Hosts: 218.85.133.10999755.com
O1 - Hosts: 218.85.133.109www.loveba.com
O1 - Hosts: 218.85.133.109loveba.com
O1 - Hosts: 218.85.133.109www.fx120.net
O1 - Hosts: 218.85.133.109fx120.net
O1 - Hosts: 218.85.133.109www.feifanyu.com
O1 - Hosts: 218.85.133.109feifanyu.com
O1 - Hosts: 218.85.133.109www.wg818.com
O1 - Hosts: 218.85.133.109wg818.com
O1 - Hosts: 218.85.133.109www.shan-hua.com.cn
O1 - Hosts: 218.85.133.109shan-hua.com.cn
O1 - Hosts: 218.85.133.109www.7122.com
O1 - Hosts: 218.85.133.1097122.com
O1 - Hosts: 218.85.133.109www.pic21.net
O1 - Hosts: 218.85.133.109pic21.net
O1 - Hosts: 218.85.133.109www.9see.com
O1 - Hosts: 218.85.133.1099see.com
O1 - Hosts: 218.85.133.109www.pztu.com
O1 - Hosts: 218.85.133.109pztu.com
O1 - Hosts: 218.85.133.109www.xunlei.com
O1 - Hosts: 218.85.133.109xunlei.com
O1 - Hosts: 218.85.133.109www.image.yisou.com
O1 - Hosts: 218.85.133.109image.yisou.com
O1 - Hosts: 218.85.133.109www.yes358.com
O1 - Hosts: 218.85.133.109yes358.com
O1 - Hosts: 218.85.133.109www.supsky.com
O1 - Hosts: 218.85.133.109supsky.com
O1 - Hosts: 218.85.133.109www.7c8.com
O1 - Hosts: 218.85.133.1097c8.com
O1 - Hosts: 218.85.133.109www.ccliao.com
O1 - Hosts: 218.85.133.109ccliao.com
O1 - Hosts: 218.85.133.109www.tvliao.com
O1 - Hosts: 218.85.133.109tvliao.com
O1 - Hosts: 218.85.133.109www.dreamdate.com
O1 - Hosts: 218.85.133.109dreamdate.com
O1 - Hosts: 218.85.133.109www.dreamdate.com
O1 - Hosts: 218.85.133.109dreamdate.com
O1 - Hosts: 218.85.133.109www.readnovel.com
O1 - Hosts: 218.85.133.109readnovel.com
O1 - Hosts: 218.85.133.109www.3tom.com
O1 - Hosts: 218.85.133.1093tom.com
O1 - Hosts: 218.85.133.109www.126ww.com
O1 - Hosts: 218.85.133.109126ww.com
O1 - Hosts: 218.85.133.109www.fa123.net
O1 - Hosts: 218.85.133.109fa123.net
O1 - Hosts: 218.85.133.109www.kk119.com
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll
O2 - BHO: QQBrowserHelperObject Class - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ydragsearch.dll
O2 - BHO: 超级兔子上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - C:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~1.DLL
O3 - IE工具栏增项: 超级兔子上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - C:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~1.DLL
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll
O4 - 启动项HKLM\\Run: [Super Rabbit SRRestore] ; C:\Program Files\Super Rabbit\MagicSet\srrest.exe /autosave
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - 启动项HKLM\\Run: [3721] C:\$NtUninstallQ5926809$\3721.bat
O4 - 启动项HKLM\\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - 启动项HKLM\\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - 启动项HKLM\\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Super Rabbit IEPro] C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD
O4 - HKCU\..\Run: [IEXPLORE.EXE] IEXPLORE.EXE http://www.333tu.com
O4 - HKCU\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - HKCU\..\Run: [3721] C:\$NtUninstallQ5926809$\3721.bat
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\QQ\QQ.exe
O4 - Global Startup: 方正宽带客户端.lnk = C:\Program Files\FBNClient\FBNClient\fbnClient.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - IE右键菜单中的新增项目: !搜一搜 - res://C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll/246
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - IE右键菜单中的新增项目: 用比特精灵下载(&B) - C:\Program Files\BitSpirit\bsurl.htm
O9 - 浏览器额外的按钮: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm?pid=65226_1006 (file missing)
O11 - Options group: [!CNS]  上网助手-地址栏搜索
O17 - HKLM\System\CCS\Services\Tcpip\..\{CD331757-08E8-46DB-B9D9-A104AA589BAD}: NameServer = 219.141.140.10,219.232.48.61
O23 - NT 服务: Autodesk Licensing Service - Unknown owner - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - NT 服务: Windows Audio Services (winAudSer) - Unknown owner - C:\WINDOWS\System32\Winms.exe (file missing)

最后编辑2005-11-09 21:56:50
分享到:
gototop
 

重新启动到安全模式(进入安全模式的方法:重新启动电脑, 开机自动检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式(Safe Mode)进入Windows。)

请关闭所有IE界面,重新使用HijackThis扫描一次,选中下面建议修复的项目,让HijackThis修复,修复前请允许HijackThis保留备份。(如果楼主知道是安全的可以不必勾选)
R3 - URLSearchHook: (no name) - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)

所有01项
O4 - 启动项HKLM\\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - 启动项HKLM\\Run: [3721] C:\$NtUninstallQ5926809$\3721.bat
O4 - HKCU\..\Run: [IEXPLORE.EXE] IEXPLORE.EXE http://www.333tu.com
O4 - HKCU\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - HKCU\..\Run: [3721] C:\$NtUninstallQ5926809$\3721.bat
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
然后打开我的电脑→再点工具→打开文件夹选项→查看→把隐藏受保护的系统文件(推荐)和隐藏已知文件类型的扩展名的勾去掉→再显示所有文件→找到以下文件并删除:(如果有的话)
删除文件夹C:\$NtUninstallQ5926809$

O23 - NT 服务: Windows Audio Services (winAudSer) - Unknown owner - C:\WINDOWS\System32\Winms.exe (file missing)

请参考:http://forum.ikaka.com/topic.asp?board=67&artid=7300311
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT