瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 再三救次我吧,又中了!浏览器IT没办法更改的,HJ日志导出

1   1  /  1  页   跳转

再三救次我吧,又中了!浏览器IT没办法更改的,HJ日志导出

再三救次我吧,又中了!浏览器IT没办法更改的,HJ日志导出

Logfile of HijackThis v1.99.1
Scan saved at 19:46:44, on 2006-1-15
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\qq\Setup_w0011\IExplorer.exe
C:\anzhuang3\vrvmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
D:\2号程序\mytool\C\popo.exe
D:\2号程序\mytool\C\popo.exe
C:\安装二号传输工具\Tencent\qq\QQ.exe
C:\安装二号传输工具\Tencent\qq\TIMPlatform.exe
C:\WINDOWS\system32\svchost.exe
D:\原程序\杀毒\HijackThis.exe

O1 - Hosts: y苠鶴0挔羳僻躪?穑@警?棫5唿Z∈6?5R€<漃n幝薬漫太d澒?3怊P@?)!:z擜8?巵U€T湣垇A?
O1 - Hosts: ?璟??M6Z?肂?`谽|茼す
O1 - Hosts: o{紞鋺C?c?dY龈Cげ4瓳R,]BU鸯+鐷蠕谽Lya霅EZ?嬾u${s荘;偳奰芽瓾)?{u赾肌$Z?w喣?EG诡{c?^鞴马1癄\5A}噏M*T弑].ITa!綅I?t5糗??孺老mYC腬^邾8?"?鑐,紿A}Q?e巏△稄瑡?鰑&鱡坹偬r?诱*膐辺?FT?」(J卜燱?'n鑚P?襬?賫B:D姿裀??7?蹁iX??wOjf>鼭?硒?0韞k<5蛚o#
O1 - Hosts: y苠鶴0挔羳僻躪?穑@警?棫5唿Z∈6?5R€<漃n幝薬漫太d澒?3怊P@?)!:z擜8?巵U€T湣垇A?
O1 - Hosts: ?璟??M6Z?肂?`谽|茼す
O1 - Hosts: o{紞鋺C?c?dY龈Cげ4瓳R,]BU鸯+鐷蠕谽Lya霅EZ?嬾u${s荘;偳奰芽瓾)?{u赾肌$Z?w喣?EG诡{c?^鞴马1癄\5A}噏M*T弑].ITa!綅I?t5糗??孺老mYC腬^邾8?"?鑐,紿A}Q?e巏△稄瑡?鰑&鱡坹偬r?诱*膐辺?FT?」(J卜燱?'n鑚P?襬?賫B:D姿裀??7?蹁iX??wOjf>鼭?硒?0韞k<5蛚o#
O1 - Hosts: U猺?◢傚80(4燍?
O1 - Hosts: 4t4
O1 - Hosts: w}當0?宬応籹~壚毤戧痔A<??纼H,o+_瑛z^?跪1??楚adx陟 聕鏑?焘{葰Хar︸桄禾?}褜?x韋yX?祣u+Tq??j搿W攎/`礧?HZ鬶D晳霧?胰咂jV嫙R尙?胛捩I+憕ts渿?F柔a塒?e?Ed纑s ?
O1 - Hosts: 鼔P鬃dt?`酰> 崌ajцH?7B&覞廃p 葀┺? 獈仕[畆\G_峧懌絩N呂D>计?5|?"?┼q徂??稠蕭?雒咣淕U廳夳%:d>D?嘀P啇?€}鲡I}k}>袻l]??欽鷎_褠~茼?S冴Z??蝝盩p5紜?眱?鰰$忌鮌~?桧1R#赜??錙~霎筼埆
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\安装2号Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll (file missing)
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: MacroMediapd - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} - C:\WINDOWS\system32\microapmddt.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\安沧装岸二号臷\Xi\NetTransport 2\NTIEHelper.dll (file missing)
O4 - HKLM\..\Run: [Super Rabbit SRRestore] C:\anzhuang3\Super Rabbit\MagicSet\srrest.exe /autosave
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera 301x
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RavTimer] D:\原程序\杀毒\RAV2003注册版\RAV2003\RAV2003\RavTimer.exe
O4 - HKLM\..\Run: [IMJPMIG8.2] C:\Program Files\qq\Setup_w0011\IExplorer.exe
O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDATE\Update.exe
O4 - HKLM\..\Run: [xysecond] C:\anzhuang3\vrvmon.exe
O4 - HKLM\..\Run: [res] C:\WINDOWS\system32\bsd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item:  >> 彩信发送 << - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\安装二号传输工具\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\安装二号传输工具\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\安装二号传输工具\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\安装二号传输工具\Tencent\qq\SendMMS.htm
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll (file missing)
O9 - Extra 'Tools' menuitem: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll (file missing)
O9 - Extra button: 卓越 - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - C:\WINDOWS\system32\IEPlugin.dll
O9 - Extra button: ZDNet - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - C:\WINDOWS\system32\IEPlugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{931B79DD-74D6-410B-BA2B-C6E33456EA32}: NameServer = 211.98.4.1 211.98.127.101
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

最后编辑2006-01-16 01:41:05
分享到:
gototop
 

【回复“kikimomol”的帖子】
问题多多!
C:\Program Files\qq\Setup_w0011\IExplorer.exe
这个文件有问题。请打包发到:baohelin@yahoo.com.cn。

————————
修復所有O1項。

————————

O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: MacroMediapd - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} - C:\WINDOWS\system32\microapmddt.dll

修復這兩項。

————————
O4 - HKLM\..\Run: [res] C:\WINDOWS\system32\bsd.exe

什麽東西?
gototop
 

修复hosts文件.
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT