瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 帮我看下日志,有没有病毒啊,我是网吧的,怎么号老被盗啊

1   1  /  1  页   跳转

帮我看下日志,有没有病毒啊,我是网吧的,怎么号老被盗啊

帮我看下日志,有没有病毒啊,我是网吧的,怎么号老被盗啊

Logfile of HijackThis v1.99.1
Scan saved at 13:01:56, on 2006-9-1
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\Program Files\HC\HCard\smss.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hc\HCard\RunMe.exe
C:\Program Files\Hc\HCard\System.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Hc\HCard\services.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\中顺技术\桌面\HijackThis.exe

O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [RunStar] C:\Program Files\HC\HCard\smss.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [MyApp] C:\Program Files\Hc\HCard\RunMe.exe
O4 - HKLM\..\Run: [MyApp2] C:\Program Files\Hc\HCard\System.exe
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &使用迅雷下载 - d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{AD2DEF45-F568-4B64-919E-F1A6832AC5FB}: NameServer = 61.147.37.1,61.177.7.1
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

最后编辑2006-09-01 13:24:58
分享到:
gototop
 

网吧不是有还原么?

日志正常..
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT