瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 怀疑中了病毒,麻烦高手看下hijackthis.log,thanks

1   1  /  1  页   跳转

怀疑中了病毒,麻烦高手看下hijackthis.log,thanks

怀疑中了病毒,麻烦高手看下hijackthis.log,thanks

另外在开IE的时候自动弹出新页面,打开www.98so.com.
thanks

HijackThis_815汉化版扫描日志 V1.99.1
保存于      14:09:38, 日期 2005-9-13
操作系统:  Windows 2000 SP4 (WinNT 5.00.2195)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\Documents and Settings\Administrator\桌面\HijackThis1991zww.exe

O2 - BHO: Target Class - {002AF282-E42D-4B51-9F70-F1570C02FAAD} - C:\Progra~1\NetMeting\Target\0.9.0.5\Target.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - 启动项HKLM\\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - 启动项HKLM\\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - 启动项HKLM\\Run: [hp 1000 firmware] C:\Program Files\hp LaserJet 1000\fwdl.exe
O4 - 启动项HKLM\\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - 启动项HKLM\\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - 启动项HKLM\\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: autoprint.bat
O16 - DPF: {073EE0EE-2F56-4A8A-9C1E-4B0A6C9D1C03} (LKSWebTools Control) - http://koa.sf-express.com/lks/koa/lkswebtools.ocx
O16 - DPF: {3F166327-8030-4881-8BD2-EA25350E574A} (CellWeb5 Control) - http://192.168.32.76/Client/CellWeb5.cab
O16 - DPF: {9E9ED017-71D7-4ED3-884E-0ACD92163EE9} (nc Class) - http://210.75.21.216/Client/NC_Client_131.exe
O18 - 列举现有的协议: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - C:\PROGRA~1\Kingsoft\POWERW~1\XDictExB.dll
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: McAfee Framework 服务 (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - NT 服务: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - NT 服务: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - NT 服务: Remote Administrator Service (r_server) - Unknown owner - C:\WINNT\system32\r_server.exe" /service (file missing)

最后编辑2005-09-13 15:49:02
分享到:
gototop
 

O4 - Startup: autoprint.bat  这个是打印机共享的:登陆对方机器.
016那三项都是正常的插件
另外那个www.98so.com的问题怎么解决?
多谢独孤豪侠
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT