瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 经常弹出无地址的IE网页,请帮忙看一下日志,我是WIN2000

1   1  /  1  页   跳转

经常弹出无地址的IE网页,请帮忙看一下日志,我是WIN2000

经常弹出无地址的IE网页,请帮忙看一下日志,我是WIN2000

Logfile of HijackThis v1.99.1
Scan saved at 15:14:52, on 2006-4-19
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\system32\mspmspsv.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\Explorer.EXE
D:\WINNT\system32\Rundll32.exe
D:\WINNT\System32\igfxtray.exe
D:\WINNT\system32\spool\drivers\w32x86\3\hpztsb09.exe
D:\Program Files\HP\hpcoretech\hpcmpmgr.exe
D:\WINNT\system32\internat.exe
D:\WINNT\system32\rundll32.exe
D:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
D:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Files\Outlook Express\msimn.exe
D:\Program Files\Kingsoft\Powerword 2003\XDICT.EXE
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\The Cleaner\cleaner.exe
D:\WINNT\system32\conime.exe
D:\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: Tencent Browser Helper - {0C7C23EF-A848-485B-873C-0ED954731014} - D:\Program Files\TENCENT\Adplus\SSAddr.dll
O2 - BHO: BDIcp Class - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - D:\WINNT\DOWNLO~1\BDPlugin.dll
O2 - BHO: BDHlprObj Class - {CA92B524-BC8A-4610-BD2C-6BD3E28155D0} - D:\WINNT\DOWNLO~1\BDHelper.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3}? - (no file)
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - D:\WINNT\system32\kakatool.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] D:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] ; D:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] ; SOUNDMAN.EXE
O4 - HKLM\..\Run: [LoadQM] ; loadqm.exe
O4 - HKLM\..\Run: [TkBellExe] ; "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NMGameX_AutoRun] D:\WINNT\system32\Rundll32.exe NMGameX.dll,LiveProcess /aa
O4 - HKLM\..\Run: [KAVPersonal50] "c:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [BIE] Rundll32 D:\WINNT\DOWNLO~1\BDPlugin.dll,Rundll32
O4 - HKLM\..\Run: [supdate2.dll] RUNDLL32.EXE D:\WINNT\system32\supdate2.dll,Run
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] D:\WINNT\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Component Manager] "D:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [stup.exe] D:\PROGRA~1\TENCENT\Adplus\stup.exe
O4 - HKCU\..\Run: [MsnMsgr] ; "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Startup: 腾讯QQ.lnk = ?
O4 - Global Startup: 金山词霸 2003.lnk = D:\Program Files\Kingsoft\Powerword 2003\XDICT.EXE
O4 - Global Startup: IE-BAR.lnk = D:\WINNT\system32\rundll32.exe
O8 - Extra context menu item: &使用迅雷下载 - F:\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - F:\Thunder\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - E:\d\我的文档\chen.d.qq\AddToNetDisk.htm
O8 - Extra context menu item: 使用搜狗直通车下载 - D:\Program Files\P4P\dl.htm
O8 - Extra context menu item: 使用网际快车下载 - D:\PROGRA~1\FLASHGET\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\PROGRA~1\FLASHGET\jc_all.htm
O8 - Extra context menu item: 使用迅雷下载 - i:\thunder\geturl.htm
O8 - Extra context menu item: 使用迅雷全部链接 - i:\thunder\getallurl.htm
O8 - Extra context menu item: 发送图片到手机 - D:\Program Files\P4P\cx.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 导出当前页到超星阅览器(&A) - D:\Program Files\SSREADER36\ss_all.htm
O8 - Extra context menu item: 导出选中部分到超星阅览器(&S) - D:\Program Files\SSREADER36\ss_select.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\d\我的文档\chen.d.qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\d\我的文档\chen.d.qq\AddEmotion.htm
O8 - Extra context menu item: 添加到“我的订阅” - D:\Program Files\P4P\rss.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\d\我的文档\chen.d.qq\SendMMS.htm
O9 - Extra button: 词霸 - {9A687CA6-D585-4947-9ED9-BE96071F5CD9} - D:\Program Files\Kingsoft\Powerword 2003\XDictExB.dll
O9 - Extra button: 百度搜索伴侣 - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - D:\WINNT\DOWNLO~1\BDPlugin.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\D\我的文档\chen.d.qq\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\D\我的文档\chen.d.qq\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\D\我的文档\chen.d.qq\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\D\我的文档\chen.d.qq\QQIEHelper.dll
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} - http://www.rising.com.cn/?u=RSTB (file missing)
O9 - Extra button: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com/?u=RSTB (file missing)
O11 - Options group: [TBH]  搜搜地址栏搜索
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} (BDIcp Class) - http://bar.baidu.com/update/IESearch.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O16 - DPF: {F2EB8999-766E-4BF6-AAAD-188D398C0D0B} (PBActiveX40 Control) - http://www4.cmbchina.com/download/pb45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C8FC1532-DB29-4325-8576-C0102AE81DFB}: NameServer = 192.168.16.100,202.96.209.5
O18 - Protocol: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - D:\Program Files\Kingsoft\Powerword 2003\XDictExB.dll
O18 - Protocol: mp3 - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - D:\WINNT\DOWNLO~1\BDPlugin.dll
O20 - Winlogon Notify: igfxcui - D:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: hpdj - HP - D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hpdj.exe
O23 - Service: kavsvc - Kaspersky Lab - c:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe

最后编辑2006-04-22 02:07:22
分享到:
gototop
 

拜托啦!怎么没有人帮我啊?小弟很苦恼!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT