瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 大家好,我的浏览器被动持了,请各位高手帮分折

1   1  /  1  页   跳转

大家好,我的浏览器被动持了,请各位高手帮分折

大家好,我的浏览器被动持了,请各位高手帮分折

cat > /etc/hosts << "EOF"
# Begin /etc/hosts (no network card version)

127.0.0.1 www.mydomain.com <value of HOSTNAME> localhost

# End /etc/hosts (no network card version)
EOF
HijackThis_815汉化版扫描日志 V1.99.1
保存于      17:21:51, 日期 2006-1-4
操作系统:  Windows XP  (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 (6.00.2600.0000)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\InterBase Corp\InterBase\bin\ibguard.exe
C:\Program Files\P4P\p2psvr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\InterBase Corp\InterBase\bin\ibserver.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
C:\WINDOWS\MSMNSGER.EXE
C:\WINDOWS\System32\RNUDLL32.EXE
C:\WINDOWS\System32\CTFMON.EXE
C:\WINDOWS\MSMNSGER.EXE
D:\Foxmail\HijackThis1991汉化版\HijackThis1991zww.exe

R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O1 - Hosts: 218.5.76.198 www.hk999.net
O1 - Hosts: 218.5.76.198 hk999.net
O1 - Hosts: 218.5.76.198 www.688899.com
O1 - Hosts: 218.5.76.198 688899.com
O1 - Hosts: 218.5.76.198 1.2233.cc
O1 - Hosts: 218.5.76.198 1.tk111.net
O1 - Hosts: 218.5.76.198 123.tk6666.com
O1 - Hosts: 218.5.76.198 2.166366.com
O1 - Hosts: 218.5.76.198 333.hk9688.com
O1 - Hosts: 218.5.76.198 3d.com.ru
O1 - Hosts: 218.5.76.198 6.139tk.com
O1 - Hosts: 218.5.76.198 88.tk121.com
O1 - Hosts: 218.5.76.198 a2afa.sz0808.com
O1 - Hosts: 218.5.76.198 asp.161.cc
O1 - Hosts: 218.5.76.198 b4c43.1986836.com
O1 - Hosts: 218.5.76.198 bbs.261.cc
O1 - Hosts: 218.5.76.198 bbs.3k4k.com
O1 - Hosts: 218.5.76.198 bbs.62788.com
O1 - Hosts: 218.5.76.198 bbs.hk6.cn
O1 - Hosts: 218.5.76.198 bbs.tu6.cn
O1 - Hosts: 218.5.76.198 bm.ok55555.com
O1 - Hosts: 218.5.76.198 brinkzs.nease.net
O1 - Hosts: 218.5.76.198 dns.hk5.net
O1 - Hosts: 218.5.76.198 dw2w6.1986836.com
O1 - Hosts: 218.5.76.198 ewqhu.1986836.com
O1 - Hosts: 218.5.76.198 edf1w.sz0808.com
O1 - Hosts: 218.5.76.198 gd1.ichat.net.cn
O1 - Hosts: 218.5.76.198 gd.ichat.net.cn
O1 - Hosts: 218.5.76.198 gd2.ichat.net.cn
O1 - Hosts: 218.5.76.198 gd3.ichat.net.cn
O1 - Hosts: 218.5.76.198 gd4.ichat.net.cn
O1 - Hosts: 218.5.76.198 gd7.ichat.net.cn
O1 - Hosts: 218.5.76.198 gd5.ichat.net.cn
O1 - Hosts: 218.5.76.198 gh.22336688.com
O1 - Hosts: 218.5.76.198 hk.hongkongtk.com
O1 - Hosts: 218.5.76.198 hkjc.27h.com
O1 - Hosts: 218.5.76.198 hknotow.51.net
O1 - Hosts: 218.5.76.198 hui.tk111.net
O1 - Hosts: 218.5.76.198 jpg.98tk.net
O1 - Hosts: 218.5.76.198 jpg.a3tk.com
O1 - Hosts: 218.5.76.198 jpg.yptbbs.cn
O1 - Hosts: 218.5.76.198 jpg.zqzw.com
O1 - Hosts: 218.5.76.198 liuhecai.wagoo.com
O1 - Hosts: 218.5.76.198 kj.a3tb.net
O1 - Hosts: 218.5.76.198 macboy.com.ru
O1 - Hosts: 218.5.76.198 rjzs.79788.com
O1 - Hosts: 218.5.76.198 sixmark.zh77.net
O1 - Hosts: 218.5.76.198 tif.168tk.net
O1 - Hosts: 218.5.76.198 tif.a3tb.net
O1 - Hosts: 218.5.76.198 tif.okiii.com
O1 - Hosts: 218.5.76.198 tif.yptbbs.cn
O1 - Hosts: 218.5.76.198 tk.2233.cc
O1 - Hosts: 218.5.76.198 tk.22518.com
O1 - Hosts: 218.5.76.198 tk.228tk.com
O1 - Hosts: 218.5.76.198 tk.66wo.com
O1 - Hosts: 218.5.76.198 tk.6844.com
O1 - Hosts: 218.5.76.198 tk.851212.org
O1 - Hosts: 218.5.76.198 tk.a3tk.com
O1 - Hosts: 218.5.76.198 tk.cx008.net
O1 - Hosts: 218.5.76.198 tk.liuhecainews.com
O1 - Hosts: 218.5.76.198 tk.yptbbs.cn
O1 - Hosts: 218.5.76.198 tk19.tk19.com
O1 - Hosts: 218.5.76.198 tlf.a3tb.net
O1 - Hosts: 218.5.76.198 tu.3k34k.com
O1 - Hosts: 218.5.76.198 tu.3k4k.com
O1 - Hosts: 218.5.76.198 tu.555uuu.com
O1 - Hosts: 218.5.76.198 tu.k689.net
O1 - Hosts: 218.5.76.198 tu.cx008.net
O1 - Hosts: 218.5.76.198 tu.lhctz.com
O1 - Hosts: 218.5.76.198 tu.wxtk.net
O1 - Hosts: 218.5.76.198 tuku.121310.com
O1 - Hosts: 218.5.76.198 tuku.121310.net
O1 - Hosts: 218.5.76.198 tuku.138tk.com
O1 - Hosts: 218.5.76.198 tuku.vk33.com
O1 - Hosts: 218.5.76.198 uu.uutk.com
O1 - Hosts: 218.5.76.198 vip.tttuuu.com
O1 - Hosts: 218.5.76.198 vip.wotk.com
O1 - Hosts: 218.5.76.198 vip.wotk.net
O1 - Hosts: 218.5.76.198 w.xg77.com
O1 - Hosts: 218.5.76.198 w1ww1.sz0808.com
O1 - Hosts: 218.5.76.198 w222w.1986836.com
O1 - Hosts: 218.5.76.198 w2w1w.1986836.com
O1 - Hosts: 218.5.76.198 wdww.1986836.com
O1 - Hosts: 218.5.76.198 wew33.1986836.com
O1 - Hosts: 218.5.76.198 wjww.1986836.com
O1 - Hosts: 218.5.76.198 wqa3aa.sz0808.com
O1 - Hosts: 218.5.76.198 wvvw.tu06.com
O1 - Hosts: 218.5.76.198 ww.166366.com
O1 - Hosts: 218.5.76.198 ww.475767.com
O1 - Hosts: 218.5.76.198 ww.tk1000.com
O1 - Hosts: 218.5.76.198 ww55ww.1986836.com
O1 - Hosts: 218.5.76.198 www.hk8123.com
O1 - Hosts: 218.5.76.198 hk8123.com
O1 - Hosts: 218.5.76.198 www.001tk.com
O1 - Hosts: 218.5.76.198 001tk.com
O1 - Hosts: 218.5.76.198 www.00211.com
O1 - Hosts: 218.5.76.198 00211.com
O1 - Hosts: 218.5.76.198 www.002tk.com
O1 - Hosts: 218.5.76.198 002tk.com
O1 - Hosts: 218.5.76.198 www.003tk.com
O1 - Hosts: 218.5.76.198 003tk.com
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O2 - BHO: apronA Class - {557B9038-FC87-453C-8B08-32D85F46EAC4} - C:\WINDOWS\REALON~2.DLL
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O4 - 启动项HKLM\\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - 启动项HKLM\\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - 启动项HKLM\\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - 启动项HKLM\\Run: [3721] C:\WINDOWS\MSMNSGER.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - IE右键菜单中的新增项目: 雅虎搜索 - res://C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll/246
O17 - HKLM\System\CCS\Services\Tcpip\..\{140FC346-DC00-49CB-99A5-2AD2E447B3CF}: NameServer = 202.103.224.68,202.103.225.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{2E67E627-6BEE-4F85-9D53-72E3E81A109E}: NameServer = 202.103.224.68,202.103.225.68
O23 - NT 服务: AVP-SE - Unknown owner - (no file)
O23 - NT 服务: InterBase Guardian (InterBaseGuardian) - InterBase Software Corp. - C:\Program Files\InterBase Corp\InterBase\bin\ibguard.exe
O23 - NT 服务: InterBase Server (InterBaseServer) - InterBase Software Corp. - C:\Program Files\InterBase Corp\InterBase\bin\ibserver.exe
O23 - NT 服务: P4P Service - Sohu.com Inc. - C:\Program Files\P4P\p2psvr.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - C:\Program Files\Rising\Rfw\rfwsrv.exe

最后编辑2006-01-08 22:33:50
分享到:
gototop
 

楼上谢谢你!我按你的方法去做了,结果还是一样。下一步怎么做呢?
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
C:\Program Files\InterBase Corp\InterBase\bin\ibguard.exe
C:\WINDOWS\System32\RNUDLL32.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\MSMNSGER.EXE
C:\Program Files\P4P\p2psvr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\InterBase Corp\InterBase\bin\ibserver.exe
C:\WINDOWS\System32\NOTEPAD.EXE
D:\Foxmail\HijackThis1991汉化版\HijackThis1991zww.exe

O1 - Hosts: 218.5.76.198 www.hk999.net
O1 - Hosts: 218.5.76.198 hk999.net
O1 - Hosts: 218.5.76.198 www.688899.com
O1 - Hosts: 218.5.76.198 688899.com
O1 - Hosts: 218.5.76.198 1.2233.cc
O1 - Hosts: 218.5.76.198 1.tk111.net
O1 - Hosts: 218.5.76.198 123.tk6666.com
O1 - Hosts: 218.5.76.198 2.166366.com
O1 - Hosts: 218.5.76.198 333.hk9688.com
O1 - Hosts: 218.5.76.198 3d.com.ru
O1 - Hosts: 218.5.76.198 6.139tk.com
O1 - Hosts: 218.5.76.198 88.tk121.com
O1 - Hosts: 218.5.76.198 a2afa.sz0808.com
O1 - Hosts: 218.5.76.198 asp.161.cc
O1 - Hosts: 218.5.76.198 b4c43.1986836.com
O1 - Hosts: 218.5.76.198 bbs.261.cc
O1 - Hosts: 218.5.76.198 bbs.3k4k.com
O1 - Hosts: 218.5.76.198 bbs.62788.com
O1 - Hosts: 218.5.76.198 bbs.hk6.cn
O1 - Hosts: 218.5.76.198 bbs.tu6.cn
O1 - Hosts: 218.5.76.198 bm.ok55555.com
O1 - Hosts: 218.5.76.198 brinkzs.nease.net
O1 - Hosts: 218.5.76.198 dns.hk5.net
O1 - Hosts: 218.5.76.198 dw2w6.1986836.com
O1 - Hosts: 218.5.76.198 ewqhu.1986836.com
O1 - Hosts: 218.5.76.198 edf1w.sz0808.com
O1 - Hosts: 218.5.76.198 gd1.ichat.net.cn
O1 - Hosts: 218.5.76.198 gd.ichat.net.cn
O1 - Hosts: 218.5.76.198 gd2.ichat.net.cn
O1 - Hosts: 218.5.76.198 gd3.ichat.net.cn
O1 - Hosts: 218.5.76.198 gd4.ichat.net.cn
O1 - Hosts: 218.5.76.198 gd7.ichat.net.cn
O1 - Hosts: 218.5.76.198 gd5.ichat.net.cn
O1 - Hosts: 218.5.76.198 gh.22336688.com
O1 - Hosts: 218.5.76.198 hk.hongkongtk.com
O1 - Hosts: 218.5.76.198 hkjc.27h.com
O1 - Hosts: 218.5.76.198 hknotow.51.net
O1 - Hosts: 218.5.76.198 hui.tk111.net
O1 - Hosts: 218.5.76.198 jpg.98tk.net
O1 - Hosts: 218.5.76.198 jpg.a3tk.com
O1 - Hosts: 218.5.76.198 jpg.yptbbs.cn
O1 - Hosts: 218.5.76.198 jpg.zqzw.com
O1 - Hosts: 218.5.76.198 liuhecai.wagoo.com
O1 - Hosts: 218.5.76.198 kj.a3tb.net
O1 - Hosts: 218.5.76.198 macboy.com.ru
O1 - Hosts: 218.5.76.198 rjzs.79788.com
O1 - Hosts: 218.5.76.198 sixmark.zh77.net
O1 - Hosts: 218.5.76.198 tif.168tk.net
O1 - Hosts: 218.5.76.198 tif.a3tb.net
O1 - Hosts: 218.5.76.198 tif.okiii.com
O1 - Hosts: 218.5.76.198 tif.yptbbs.cn
O1 - Hosts: 218.5.76.198 tk.2233.cc
O1 - Hosts: 218.5.76.198 tk.22518.com
O1 - Hosts: 218.5.76.198 tk.228tk.com
O1 - Hosts: 218.5.76.198 tk.66wo.com
O1 - Hosts: 218.5.76.198 tk.6844.com
O1 - Hosts: 218.5.76.198 tk.851212.org
O1 - Hosts: 218.5.76.198 tk.a3tk.com
O1 - Hosts: 218.5.76.198 tk.cx008.net
O1 - Hosts: 218.5.76.198 tk.liuhecainews.com
O1 - Hosts: 218.5.76.198 tk.yptbbs.cn
O1 - Hosts: 218.5.76.198 tk19.tk19.com
O1 - Hosts: 218.5.76.198 tlf.a3tb.net
O1 - Hosts: 218.5.76.198 tu.3k34k.com
O1 - Hosts: 218.5.76.198 tu.3k4k.com
O1 - Hosts: 218.5.76.198 tu.555uuu.com
O1 - Hosts: 218.5.76.198 tu.k689.net
O1 - Hosts: 218.5.76.198 tu.cx008.net
O1 - Hosts: 218.5.76.198 tu.lhctz.com
O1 - Hosts: 218.5.76.198 tu.wxtk.net
O1 - Hosts: 218.5.76.198 tuku.121310.com
O1 - Hosts: 218.5.76.198 tuku.121310.net
O1 - Hosts: 218.5.76.198 tuku.138tk.com
O1 - Hosts: 218.5.76.198 tuku.vk33.com
O1 - Hosts: 218.5.76.198 uu.uutk.com
O1 - Hosts: 218.5.76.198 vip.tttuuu.com
O1 - Hosts: 218.5.76.198 vip.wotk.com
O1 - Hosts: 218.5.76.198 vip.wotk.net
O1 - Hosts: 218.5.76.198 w.xg77.com
O1 - Hosts: 218.5.76.198 w1ww1.sz0808.com
O1 - Hosts: 218.5.76.198 w222w.1986836.com
O1 - Hosts: 218.5.76.198 w2w1w.1986836.com
O1 - Hosts: 218.5.76.198 wdww.1986836.com
O1 - Hosts: 218.5.76.198 wew33.1986836.com
O1 - Hosts: 218.5.76.198 wjww.1986836.com
O1 - Hosts: 218.5.76.198 wqa3aa.sz0808.com
O1 - Hosts: 218.5.76.198 wvvw.tu06.com
O1 - Hosts: 218.5.76.198 ww.166366.com
O1 - Hosts: 218.5.76.198 ww.475767.com
O1 - Hosts: 218.5.76.198 ww.tk1000.com
O1 - Hosts: 218.5.76.198 ww55ww.1986836.com
O1 - Hosts: 218.5.76.198 www.hk8123.com
O1 - Hosts: 218.5.76.198 hk8123.com
O1 - Hosts: 218.5.76.198 www.001tk.com
O1 - Hosts: 218.5.76.198 001tk.com
O1 - Hosts: 218.5.76.198 www.00211.com
O1 - Hosts: 218.5.76.198 00211.com
O1 - Hosts: 218.5.76.198 www.002tk.com
O1 - Hosts: 218.5.76.198 002tk.com
O1 - Hosts: 218.5.76.198 www.003tk.com
O1 - Hosts: 218.5.76.198 003tk.com
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O2 - BHO: apronA Class - {557B9038-FC87-453C-8B08-32D85F46EAC4} - C:\WINDOWS\REALON~2.DLL
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O4 - 启动项HKLM\\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - 启动项HKLM\\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - 启动项HKLM\\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - 启动项HKLM\\Run: [3721] C:\WINDOWS\MSMNSGER.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - IE右键菜单中的新增项目: 雅虎搜索 - res://C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll/246
O17 - HKLM\System\CCS\Services\Tcpip\..\{140FC346-DC00-49CB-99A5-2AD2E447B3CF}: NameServer = 202.103.224.68,202.103.225.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{2E67E627-6BEE-4F85-9D53-72E3E81A109E}: NameServer = 202.103.224.68,202.103.225.68
O23 - NT 服务: AVP-SE - Unknown owner - (no file)
O23 - NT 服务: InterBase Guardian (InterBaseGuardian) - InterBase Software Corp. - C:\Program Files\InterBase Corp\InterBase\bin\ibguard.exe
O23 - NT 服务: InterBase Server (InterBaseServer) - InterBase Software Corp. - C:\Program Files\InterBase Corp\InterBase\bin\ibserver.exe
O23 - NT 服务: P4P Service - Sohu.com Inc. - C:\Program Files\P4P\p2psvr.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - C:\Program Files\Rising\Rfw\rfwsrv.exe

gototop
 

楼上,你好!我按你的方法做了,但是修复后再扫描还是原来的样子,修复不了,MSMNSGER文件依然存在,删后重启后它又再生,请问怎么做才行,好烦啊
gototop
 

主要是这个文件MSMNSGER删了以后再生,在安全模式下把它删了,可是重新启动后又看到它在原来的地方。怎么办呢?
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT