瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 老大真厉害,再帮我看看这个机子~

1   1  /  1  页   跳转

老大真厉害,再帮我看看这个机子~

老大真厉害,再帮我看看这个机子~

Logfile of HijackThis v1.99.1
Scan saved at 13:31:52, on 06-4-10
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\PTSNOOP.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\WINDOWS\IRXFER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\UPENGINE.EXE
C:\JCB_ZSZQVIP\TDXW.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\EXCEL.EXE
A:\系统\HIJACKTHIS.EXE

R3 - URLSearchHook: CnsHook Class - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSHOOK.DLL
F1 - win.ini: load=ptsnoop.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMMON\YCOMP5_1_3_0.DLL (file missing)
O2 - BHO: 3721中文邮 - {6231D512-E4A4-4DF2-BE62-5B8F0EE348EF} - C:\PROGRAM FILES\3721\CES\CESWEB.DLL (file missing)
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: 金山毒霸 - {A9BE2902-C447-420A-BB7F-A5DE921E6138} - C:\KAV2003\KAIEPLUS.DLL (file missing)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMMON\YCOMP5_1_3_0.DLL (file missing)
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [iDuba Personal FireWall] C:\KAVPFW\KAVPFW.EXE
O4 - HKCU\..\Run: [WrCtrl] "C:\Program Files\WinRoute Pro\wrctrl.exe"
O4 - HKCU\..\Run: [MsnMsgr] "c:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\QQ\QQ.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WINZIP\WZQKPICK.EXE
O8 - Extra context menu item: 超级解霸实时播放 - C:\HERO2000\URLGET.HTM
O8 - Extra context menu item: 播放或下载所有连接 - C:\HERO2000\GETALL.HTM
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: 豪杰 - {6c45dd20-3e0a-11d4-8c74-5254ab163ead} - http://202.108.223.44/ (file missing)
O9 - Extra 'Tools' menuitem: 豪杰公司站点 - {6c45dd20-3e0a-11d4-8c74-5254ab163ead} - http://202.108.223.44/ (file missing)
O9 - Extra button: 解霸 - {b5047660-3b09-11d4-8c74-5254ab163ead} - C:\HERO2000\STHSVCD.EXE (file missing)
O9 - Extra 'Tools' menuitem: 超级解霸2000 - {b5047660-3b09-11d4-8c74-5254ab163ead} - C:\HERO2000\STHSVCD.EXE (file missing)
O9 - Extra button: 音频 - {ba601560-3b18-11d4-8c74-5254ab163ead} - C:\HERO2000\MMXADO.EXE (file missing)
O9 - Extra 'Tools' menuitem: 超级音频解霸2000 - {ba601560-3b18-11d4-8c74-5254ab163ead} - C:\HERO2000\MMXADO.EXE (file missing)
O9 - Extra button: 速载 - {a0651e80-3d70-11d4-8c74-5254ab163ead} - C:\HERO2000\HTTPDOWN.EXE (file missing)
O9 - Extra 'Tools' menuitem: 快速HTTP下载器 - {a0651e80-3d70-11d4-8c74-5254ab163ead} - C:\HERO2000\HTTPDOWN.EXE (file missing)
O9 - Extra button: 金山卓越 - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - url:http://www.joyo.com (file missing)
O9 - Extra button: 卓越 - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - C:\PROGRA~1\KINGSOFT\XDICT\IEPLUGIN.DLL (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: 金山毒霸网站 - {1ff190e7-38ab-423e-b59c-4d166c2ea5f1} - url:http://www.duba.net (file missing)
O9 - Extra button: 在线查毒 IE版 - {f58d36c3-40be-4418-a786-d8fbe3eb3554} - C:\KAV2003\KAVIE.htm (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0411.DLL (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0411.DLL (file missing)
O9 - Extra button: 3721中文邮 - {5D73EE86-05F1-49ed-B850-E423120EC329} - http://cmail.3721.com?fb=client (file missing)
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao (file missing)
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O11 - Options group: [!CNS]  网络实名
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {0236C312-C64E-4BBA-A898-EAB33D124674} (DDown Class) - http://download.3721.com/download/DirectDown.cab
O16 - DPF: {19AD95AB-B73F-11D3-9AD8-00A0B9002EBE} (PBActiveX Control) - http://njcmbchina.nj-enterprise.com/PB.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll

摆脱了~
最后编辑2006-04-10 16:29:45
分享到:
gototop
 

【回复“酒醉的小强”的帖子】
机器有什么问题
gototop
 

怕是有病毒了~我也不知道~呵呵~这个是老板的机子~
gototop
 

【回复“酒醉的小强”的帖子】
日志没有问题
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT