瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 请帮忙看看我的日志。。谢谢。。

1   1  /  1  页   跳转

请帮忙看看我的日志。。谢谢。。

请帮忙看看我的日志。。谢谢。。

不知道有什么问题,每隔一段时间,主机就会响一声,然后所有程序会暂停一秒钟。
请帮忙看看日志。
谢谢。

Logfile of HijackThis v1.99.0
Scan saved at 9:42:26, on 2005-12-7
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
D:\Program Files\Helexis\Drive Health\dhcore.exe
D:\Program Files\ewido\security suite\ewidoctrl.exe
D:\KAV6\KAVSvc.EXE
D:\KAV6\KAVPFW.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
D:\KAV6\KWatchUI.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\sistray.exe
D:\KAV6\MailMon.EXE
D:\KAV6\KAVPlus.EXE
C:\WINDOWS\system32\svchost.exe
D:\Program Files\eMule\eMule.exe
D:\Program Files\Tencent\qq\QQ.exe
D:\Program Files\Tencent\qq\TIMPlatform.exe
D:\Program Files\Tencent\TT\TTraveler.exe
C:\Documents and Settings\Administrator\桌面\工具\HijackThis\HijackThis.exe

O2 - BHO: Tencent Browser Helper - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\WINDOWS\Downloaded Program Files\Elcnqgb.dll (file missing)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\PROGRA~1\flashget\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\flashget\fgiebar.dll
O4 - HKLM\..\Run: [KAVRUN] D:\KAV6\KAVRUN.EXE
O4 - HKLM\..\Run: [iDuba Personal FireWall] D:\KAV6\KAVPFW.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [iDuba Personal FireWall] D:\KAV6\KAVPFW.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Use Yahoo Downloader - C:\Program Files\3721\Dlaccel\geturl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 使用网际快车下载 - D:\Program Files\flashget\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\Program Files\flashget\jc_all.htm
O8 - Extra context menu item: 使用超级解霸播放 - D:\Program Files\Herosoft\Hero 9\MPURLGET.HTM
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\qq\SendMMS.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - D:\BitSpirit\bsurl.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java 控制台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.tomatolei.com (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\flashget\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\flashget\flashget.exe
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - http://cn.download.yahoo.com/dl/install/yinst0401.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} - http://game.qq.com/QQGame2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125503927865
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {AC3A36A8-9BFF-410A-A33D-2279FFEB69D2} (QQPlayer Control) - http://219.133.62.236/QQPlayer.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: BlueSoleil Hid Service - Unknown - D:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: DriveHealth - Helexis Software Development - D:\Program Files\Helexis\Drive Health\dhcore.exe
O23 - Service: ewido security suite control - ewido networks - D:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: internew - Unknown - C:\WINDOWS\system32\system.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kingsoft AntiVirus Service - kingsoft Antivirus - D:\KAV6\KAVSvc.EXE
O23 - Service: System Safety Monitor - System Safety - D:\Program Files\System Safety Monitor\SSMService.exe
O23 - Service: StyleXPService - Unknown - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

最后编辑2005-12-07 14:15:11
分享到:
gototop
 

【回复“bbs136”的帖子】
O23 - Service: internew - Unknown - C:\WINDOWS\system32\system.exe
估计是个木马
用HijackThis修复这项。
请找到 C:\WINDOWS\system32\system.exe,打包,发到:baohelin@yahoo.com.cn
gototop
 

给你发了。谢谢你啊。。
我重起一下。
看还有不有。
gototop
 

另外请问一下
O23 - Service: InstallDriver Table Manager - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

这个是什么程序啊?
我以前都没看见过。
gototop
 

【回复“bbs136”的帖子】已经搞掂。查杀方法见:http://forum.ikaka.com/topic.asp?board=28&artid=7507990
gototop
 

O23 - Service: internew - Unknown - C:\WINDOWS\system32\system.exe进程有问题。
参看楼上斑竹的帖子吧
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT