HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
中加了
AddrPlus3 c:\program files\tencent\addrplus\runner1.exe
删他自动恢复
C:\Program Files\TENCENT\AddrPlus下有以下文件
2006-01-13 23:02 348,672 Idlvy.dll
2006-01-16 16:50 93,696 IEHelp1.dll
2006-01-13 23:02 51,712 QAHook.dll
2006-01-16 16:50 53,248 QAHook2.dll
2006-01-16 16:50 93,696 Qpubf.dll
2006-01-13 22:34 12,800 Runner.exe
2006-01-16 16:50 9,728 Runner1.exe
2006-01-16 21:01 569 Stdtbh.dat
2006-01-16 16:50 51,200 TCtrl.dll
想办法删了以后重起自动恢复
IE地址栏又边写着“输入关键字,直接搜索”
跳转到腾讯的SOSO网站
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 17:43:26, 日期 2006-01-17
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kav.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kavmm.exe
D:\Program Files\Tencent\QQ\QQ.exe
D:\Program Files\Tencent\QQ\TIMPlatform.exe
D:\Program Files\Maxthon\Maxthon.exe
D:\Program Files\BitComet\BitComet.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\HijackThis V1.99.1\HijackThis1991zww.exe
R3 - URLSearchHook: QQ Search Hook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\AddrPlus\IEHelp1.dll
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v8.dll
O2 - BHO: Tencent Browser Helper - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\Program Files\TENCENT\AddrPlus\IEHelp1.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\Program Files\Flashget\jccatch.dll
O4 - 启动项HKLM\\Run: [KAV50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kav.exe" -run -n PersonalPro -v 5.0.0.0 -chkss
O4 - 启动项HKLM\\Run: [AddrPlus3] C:\PROGRA~1\TENCENT\AddrPlus\Runner1.exe C:\PROGRA~1\TENCENT\AddrPlus\QAHook2.dll Rundll32
O4 - 启动项HKCU\\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - D:\Program Files\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - D:\Program Files\Thunder\getallurl.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - D:\Program Files\Flashget\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - D:\Program Files\Flashget\jc_all.htm
O16 - DPF: {00001022-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter22 Class) - http://download.netmarble.com/web/nmstarter/NMStarter22.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl
Object) - https://img.alipay.com/download/aliedit.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1122374682029
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0A016929-8065-4F6D-B75F-0EFA424988DE}: NameServer = 202.96.69.38 218.83.153.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{D869DA43-296F-4678-8240-6BC81B138E93}: NameServer = 202.96.209.5
O23 - NT 服务: Apache - Unknown owner - z:\usr\local\apache\Apache.exe" --ntservice (file missing)
O23 - NT 服务: 卡巴斯基反病毒服务 (KLBLMain) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kavmm.exe" -run bl -n PersonalPro -v 5.0.0.0 -ttsr 10000000 (file missing)
O23 - NT 服务: MySQL - Unknown owner - z:\usr\local\mysql\bin\mysqld-nt.exe
O23 - NT 服务: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - NT 服务: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
HijackThis扫描结果如上 有几条异常 但删了重起还会有
平时我很注意系统的 垃圾软件什么的一发现利马清除
可腾讯的这个我不知道什么时候装上的 缺怎么也删不掉
哪位高手能帮我想想办法?
后来我下载了SOSO工具条装上 发现跟这几个文件不一样~
要知道是怎么装上的也许能完全删掉 可怎么装上的我都不知道~