1   1  /  1  页   跳转

请帮我看看我的日志,谢谢

请帮我看看我的日志,谢谢

Logfile of HijackThis v1.99.1
Scan saved at 11:38:04, on 2005-11-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\SOUNDMAN.EXE
D:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\SKYNET\FIREWALL\pfw.exe
D:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Baidu\Disk Search\BaiduDiskSearch.exe
D:\WINDOWS\system32\svchost.exe
C:\Program Files\Baidu\Disk Search\BaiduCrawl.exe
D:\WINDOWS\System32\svchost.exe
C:\Program Files\Maxthon\Maxthon.exe
D:\WINDOWS\system32\rundll32.exe
C:\Program Files\Iparmor\Iparmor.exe
C:\Program Files\hijackthis\HijackThis.exe

O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - D:\WINDOWS\system32\xunleibho_v4.dll
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: MmsSend Class - {43A8AFD1-5C9C-4ADB-BABB-407254BC0F34} - D:\WINDOWS\DOWNLO~1\SENSKY~1.DLL
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - D:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O2 - BHO: IeCapture Class - {67B6599D-1ACF-4EA9-9EAB-578DF0FE6F78} - D:\Program Files\Common Files\Baidu\Disk Search\dsie.dll
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - D:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - D:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: T2BHO Class - {B1D147E7-873E-4909-8127-695D9BB78728} - D:\WINDOWS\Downloaded Program Files\barhelp22.0.dll
O2 - BHO: (no name) - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - (no file)
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - D:\PROGRA~1\baidu\bar\baidubar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [KAVPersonal50] "c:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
O4 - HKLM\..\Run: [SKYNET Personal FireWall] C:\PROGRA~1\SKYNET\FIREWALL\pfw.exe
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RegBar] regsvr32.exe /u D:\progra~1\blogmark\bocaitoolbar.dll /s /i /n
O4 - HKCU\..\Run: [BaiduDS] c:\Program Files\Baidu\Disk Search\BaiduDiskSearch.exe -NoOpen
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item:  >> 彩信发送 << - res://D:\PROGRA~1\MMSASS~1\MMSASS~1.DLL/mms.htm
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - D:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O9 - Extra 'Tools' menuitem: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - D:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O10 - Unknown file in Winsock LSP: c:\program files\baidu\disk search\disksearchservicestub.dll
O10 - Unknown file in Winsock LSP: c:\program files\baidu\disk search\disksearchservicestub.dll
O10 - Unknown file in Winsock LSP: c:\program files\baidu\disk search\disksearchservicestub.dll
O14 - IERESET.INF: START_PAGE_URL=about:blank
O17 - HKLM\System\CCS\Services\Tcpip\..\{896D2F94-E4E9-4ED9-A83B-6242FB137C37}: NameServer = 202.120.2.101,202.120.2.100
O17 - HKLM\System\CS1\Services\Tcpip\..\{896D2F94-E4E9-4ED9-A83B-6242FB137C37}: NameServer = 202.120.2.101,202.120.2.100
O17 - HKLM\System\CS2\Services\Tcpip\..\{896D2F94-E4E9-4ED9-A83B-6242FB137C37}: NameServer = 202.120.2.101,202.120.2.100
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - D:\WINDOWS\system32\mbprot.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "D:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: APIHookDll.dll
O20 - Winlogon Notify: igfxcui - D:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: kavsvc - Kaspersky Lab - c:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe

最后编辑2005-11-26 12:41:48
分享到:
gototop
 

【回复“fttd”的帖子】



请楼主先参考:
【讨论】关于stdup.dll反复出现、无法删除的解决办法

http://forum.ikaka.com/topic.asp?board=67&artid=7423269



使用下面的两个多引擎扫描器扫描下列文件:
C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
D:\WINDOWS\DOWNLO~1\SENSKY~1.DLL
多引擎扫描之Virustotal:

http://www.virustotal.com/
多引擎扫描之Jotti:

http://virusscan.jotti.org/


请务必将报告贴全。
gototop
 

This is a report processed by VirusTotal on 11/26/2005 at 05:16:12 (CET) after scanning the file "SnagItBHO.dll" file.
Antivirus Version Update Result
AntiVir 6.32.0.6 11.25.2005 no virus found
Avast 4.6.695.0 11.26.2005 no virus found
AVG 718 11.25.2005 no virus found
Avira 6.32.0.6 11.25.2005 no virus found
BitDefender 7.2 11.26.2005 no virus found
CAT-QuickHeal 8.00 11.25.2005 no virus found
ClamAV devel-20051108 11.25.2005 no virus found
DrWeb 4.33 11.25.2005 no virus found
eTrust-Iris 7.1.194.0 11.24.2005 no virus found
eTrust-Vet 11.9.1.0 11.25.2005 no virus found
Fortinet 2.48.0.0 11.25.2005 no virus found
F-Prot 3.16c 11.24.2005 no virus found
Ikarus 0.2.59.0 11.26.2005 no virus found
Kaspersky 4.0.2.24 11.26.2005 no virus found
McAfee 4637 11.25.2005 no virus found
NOD32v2 1.1305 11.25.2005 no virus found
Norman 5.70.10 11.25.2005 no virus found
Panda 8.02.00 11.25.2005 no virus found
Sophos 3.99.0 11.26.2005 no virus found
Symantec 8.0 11.26.2005 no virus found
TheHacker 5.9.1.044 11.24.2005 no virus found
VBA32 3.10.5 11.26.2005 no virus found



VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.> Go to: Home Contact En español
--------------------------------------------------------------------------------
www.virustotal.com :: ©Hispasec Sistemas 2004,05 :: e-mail info@virustotal.com
gototop
 

This is a report processed by VirusTotal on 11/26/2005 at 05:31:36 (CET) after scanning the file "SENSKY_1.DLL" file.
Antivirus Version Update Result
AntiVir 6.32.0.6 11.25.2005 no virus found
Avast 4.6.695.0 11.26.2005 no virus found
AVG 718 11.25.2005 no virus found
Avira 6.32.0.6 11.25.2005 no virus found
BitDefender 7.2 11.26.2005 no virus found
CAT-QuickHeal 8.00 11.25.2005 no virus found
ClamAV devel-20051108 11.25.2005 no virus found
DrWeb 4.33 11.25.2005 no virus found
eTrust-Iris 7.1.194.0 11.24.2005 no virus found
eTrust-Vet 11.9.1.0 11.25.2005 no virus found
Fortinet 2.48.0.0 11.25.2005 no virus found
F-Prot 3.16c 11.24.2005 no virus found
Ikarus 0.2.59.0 11.26.2005 no virus found
Kaspersky 4.0.2.24 11.26.2005 no virus found
McAfee 4637 11.25.2005 no virus found
NOD32v2 1.1305 11.25.2005 no virus found
Norman 5.70.10 11.25.2005 no virus found
Panda 8.02.00 11.25.2005 no virus found
Sophos 3.99.0 11.26.2005 no virus found
Symantec 8.0 11.26.2005 no virus found
TheHacker 5.9.1.044 11.24.2005 no virus found
VBA32 3.10.5 11.26.2005 no virus found



VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.> Go to: Home Contact En español
--------------------------------------------------------------------------------
www.virustotal.com :: ©Hispasec Sistemas 2004,05 :: e-mail info@virustotal.com
gototop
 

Service load:  0%        100% 

File:  SnagItBHO.dll 
Status:  OK 
MD5  38a0edab4ca5f91812e5f99995b1c583 
Packers detected:  -
Scanner results 
AntiVir  Found nothing
ArcaVir  Found nothing
Avast  Found nothing
AVG Antivirus  Found nothing
BitDefender  Found nothing
ClamAV  Found nothing
Dr.Web  Found nothing
F-Prot Antivirus  Found nothing
Fortinet  Found nothing
Kaspersky Anti-Virus  Found nothing
NOD32  Found nothing
Norman Virus Control  Found nothing
UNA  Found nothing
VBA32  Found nothing
gototop
 

File:  SENSKY~1.DLL 
Status:  OK 
MD5  1571d4aa1471ac0ba00059c8e6fb1ebd 
Packers detected:  -
Scanner results 
AntiVir  Found nothing
ArcaVir  Found nothing
Avast  Found nothing
AVG Antivirus  Found nothing
BitDefender  Found nothing
ClamAV  Found nothing
Dr.Web  Found nothing
F-Prot Antivirus  Found nothing
Fortinet  Found nothing
Kaspersky Anti-Virus  Found nothing
NOD32  Found nothing
Norman Virus Control  Found nothing
UNA  Found nothing
VBA32  Found nothing
gototop
 

【回复“fttd”的帖子】



嗯,好的。那两个文件没问题。
请参考第一楼给出的那个帖子。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT