1   1  /  1  页   跳转

baohe 哥哥你看日志!!!!

baohe 哥哥你看日志!!!!

Logfile of HijackThis v1.99.1
Scan saved at 21:37:48, on 2006-2-23
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\winnt\System32\smss.exe
C:\winnt\system32\csrss.exe
C:\winnt\system32\winlogon.exe
C:\winnt\system32\services.exe
C:\winnt\system32\lsass.exe
C:\winnt\system32\svchost.exe
C:\winnt\system32\spoolsv.exe
C:\winnt\System32\svchost.exe
C:\winnt\system32\nvsvc32.exe
C:\winnt\system32\MSTask.exe
C:\WINNT\SYSTEM32\RUNDLL32.EXE
C:\winnt\System32\WBEM\WinMgmt.exe
C:\winnt\system32\svchost.exe
C:\winnt\Explorer.EXE
C:\新建文件夹\CatchAll20050914\木马杀客\mmsk.exe
C:\winnt\CSRSS.EXE
C:\Program Files\ChinaNet\VnetClient.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\TIMPlatform.exe
E:\传神外挂\main.dat
E:\传神外挂\main.dat
E:\传神外挂\main.dat
E:\传神外挂\main.dat
E:\传神外挂\main.dat
C:\新建文件夹\CatchAll20050914\HijackThis\HijackThis.exe

O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\winnt\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [mmsk] C:\新建文件夹\CatchAll20050914\木马杀客\mmsk.exe
O4 - HKLM\..\Run: [Trojan Program] C:\winnt\CSRSS.EXE
O4 - HKLM\..\RunServices: [mmsk] C:\新建文件夹\CatchAll20050914\木马杀客\mmsk.exe
O4 - HKLM\..\RunServices: [Trojan Program] C:\winnt\CSRSS.EXE
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{10DC6A38-1B7C-4DB5-BBB1-DF4B15B2E013}: NameServer = 218.85.157.99 202.101.98.55
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\winnt\System32\dmadmin.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\winnt\system32\nvsvc32.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - C:\Program Files\Rising\Rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Network System (Universal Disk Manager) - Unknown owner - C:\Program Files\Common Files\COMM\Network.exe (file missing)
哎无奈了 注册表 用木马杀客杀了 但是 删不了注册表哇..
打开注册表 找到RUN 后 又边一片空白 没啥东西
还有msconfig打不开!!!!!!
最后编辑2006-02-23 22:02:25
分享到:
gototop
 

哥哥  我已经用木马杀客把他杀了 但是日志里还有为什么啊!!!!
5555555555怎么办
gototop
 

啊 那我还是从做系统吧 哎........
注册表删不得哎
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT