1   1  /  1  页   跳转

请高手帮忙看看日志

请高手帮忙看看日志

Logfile of HijackThis v1.99.1
Scan saved at 16:10:38, on 2006-8-12
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\winmer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\NTdhcp.exe
C:\Program Files\explore.exe
C:\WINDOWS\system32\Intercpu.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\「开始」菜单\程序\启动\suanging.exe
C:\Program Files\VnetClient1.6\VnetClient.exe
C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\ingzshi421.exe
E:\TTPlayer\TTPlayer.exe
F:\Tencent\TT\TTraveler.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\explorer.exe
F:\Tencent\QQ\QQ.exe
F:\Tencent\QQ\TIMPlatfrom.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\LSASS.exe
F:\Tencent\QQ\QQ.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX01.562\HijackThis.exe
最后编辑2006-08-12 17:54:32
分享到:
gototop
 

3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
R3 - URLSearchHook: (no name) - {9CFBD10E-40E6-4315-8916-4693F2E3BD2F} - C:\WINDOWS\system32\Tjwm.dll (file missing)
R3 - URLSearchHook: (no name) - {854FCC22-49BA-4F05-AE76-3F24A13EA025} - C:\WINDOWS\system32\Byib.dll (file missing)
R3 - URLSearchHook: (no name) - {2575F9FA-229C-47C8-BE57-CF5485B5D3D0} - C:\WINDOWS\system32\Kbfl.dll (file missing)
R3 - URLSearchHook: (no name) - {73FFA181-14D0-42B6-8361-FC7538C6EA75} - C:\WINDOWS\system32\Toglac.dll (file missing)
R3 - URLSearchHook: (no name) - {8DD0AFEF-46F3-4681-B9A6-7503146C9A8E} - C:\WINDOWS\system32\Jbgc.dll (file missing)
R3 - URLSearchHook: (no name) - {014E9E84-84F6-4528-A41B-99F5B61DE075} - C:\WINDOWS\system32\Jvug.dll (file missing)
R3 - URLSearchHook: (no name) - {89927760-B83F-46EA-B927-72AE8B075D2C} - C:\WINDOWS\system32\Ccllha.dll (file missing)
R3 - URLSearchHook: (no name) - {431162A7-4E14-47E1-ADE4-A71581AB28F7} - C:\WINDOWS\system32\Xzvnrc.dll (file missing)
R3 - URLSearchHook: (no name) - {9572665A-28DB-4C48-9C21-E14F9278D3F7} - C:\WINDOWS\system32\Ikxhvt.dll (file missing)
R3 - URLSearchHook: (no name) - {9241EF1C-EE0C-4804-A028-E600BE6DA86D} - C:\WINDOWS\system32\Bvaqee.dll (file missing)
R3 - URLSearchHook: (no name) - {9CD3B660-809A-424E-8C7E-F3C83A70F6A6} - C:\WINDOWS\system32\Lifiry.dll (file missing)
R3 - URLSearchHook: (no name) - {6BA7EDA2-67F1-4247-B23A-594790E4A8FC} - C:\WINDOWS\system32\Ixxhwc.dll (file missing)
R3 - URLSearchHook: (no name) - {C1051928-52B6-405E-83E3-B92E705ABC07} - C:\WINDOWS\system32\Fvzber.dll (file missing)
R3 - URLSearchHook: (no name) - {1B4F3F4C-672F-4796-9A49-68F43AB9B073} - C:\WINDOWS\system32\Jivu.dll (file missing)
R3 - URLSearchHook: (no name) - {7F3CCF46-F162-4C69-B61E-A64EE5715488} - C:\WINDOWS\system32\Xcxb.dll (file missing)
R3 - URLSearchHook: (no name) - {25339CD5-7782-47FB-9E18-C7BD7AE3728A} - C:\WINDOWS\system32\Vkpr.dll (file missing)
R3 - URLSearchHook: (no name) - {F0E02445-B710-403B-98D3-AAFF3F9B4382} - C:\WINDOWS\system32\Ufqh.dll (file missing)
R3 - URLSearchHook: (no name) - {4C15D32E-0E67-4DBF-AFEC-69FB1371063B} - C:\WINDOWS\system32\Xibvb.dll (file missing)
R3 - URLSearchHook: (no name) - {D74605F2-5D7E-408C-904C-F85D7EC60CC6} - C:\WINDOWS\system32\Scfev.dll
R3 - URLSearchHook: Tencent SearchHook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\Adplus\SSAddr.dll
F3 - REG:win.ini: run=C:\WINDOWS\services.exe
O1 - Hosts: 61.129.75.124 mir.100888290cs.com
O1 - Hosts: 61.129.75.124 woool.100888290cs.com
O1 - Hosts: 61.129.75.124 www.mir5173.com
O1 - Hosts: 61.129.75.124 ert0003.e76.163ns.com
O1 - Hosts: 222.73.4.246 www.chenshijituan.com
O1 - Hosts: 59.36.96.132 qq.etsoft.com.cn
O1 - Hosts: 61.129.75.124 www.wg581.com
O2 - BHO: (no name) - {014E9E84-84F6-4528-A41B-99F5B61DE075} - C:\WINDOWS\system32\Jvug.dll (file missing)
O2 - BHO: (no name) - {1B4F3F4C-672F-4796-9A49-68F43AB9B073} - C:\WINDOWS\system32\Jivu.dll (file missing)
O2 - BHO: (no name) - {25339CD5-7782-47FB-9E18-C7BD7AE3728A} - C:\WINDOWS\system32\Vkpr.dll (file missing)
O2 - BHO: (no name) - {2575F9FA-229C-47C8-BE57-CF5485B5D3D0} - C:\WINDOWS\system32\Kbfl.dll (file missing)
O2 - BHO: wmicsmgr - {333872C4-92D6-4396-8542-64AB96518950} - C:\WINDOWS\system32\wmicsmgr.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll
O2 - BHO: FiltrateWebObj Class - {42AFACEE-2A77-41EB-9EE2-D9F8AF827F90} - C:\Program Files\KV2006\KVBHO.dll
O2 - BHO: (no name) - {431162A7-4E14-47E1-ADE4-A71581AB28F7} - C:\WINDOWS\system32\Xzvnrc.dll (file missing)
O2 - BHO: (no name) - {4C15D32E-0E67-4DBF-AFEC-69FB1371063B} - C:\WINDOWS\system32\Xibvb.dll (file missing)
O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\VNETCL~1.6\VNETTR~1.DLL
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - F:\Tencent\QQ\QQIEHelper.dll
O2 - BHO: DragSearch BHO - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
O2 - BHO: (no name) - {669751ED-D558-49AE-B01A-3B374CC7910E} - C:\WINDOWS\system32\ssup.dll
O2 - BHO: (no name) - {6BA7EDA2-67F1-4247-B23A-594790E4A8FC} - C:\WINDOWS\system32\Ixxhwc.dll (file missing)
O2 - BHO: (no name) - {73FFA181-14D0-42B6-8361-FC7538C6EA75} - C:\WINDOWS\system32\Toglac.dll (file missing)
O2 - BHO: (no name) - {7F3CCF46-F162-4C69-B61E-A64EE5715488} - C:\WINDOWS\system32\Xcxb.dll (file missing)
O2 - BHO: BrowseHelper Class - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} - C:\Program Files\KV2006\KvShell.dll
O2 - BHO: (no name) - {854FCC22-49BA-4F05-AE76-3F24A13EA025} - C:\WINDOWS\system32\Byib.dll (file missing)
O2 - BHO: (no name) - {89927760-B83F-46EA-B927-72AE8B075D2C} - C:\WINDOWS\system32\Ccllha.dll (file missing)
O2 - BHO: at - {8B316DA1-9950-4926-B9EA-1AEC124AFA45} - C:\WINDOWS\system32\sscli.dll
O2 - BHO: (no name) - {8DD0AFEF-46F3-4681-B9A6-7503146C9A8E} - C:\WINDOWS\system32\Jbgc.dll (file missing)
O2 - BHO: (no name) - {9241EF1C-EE0C-4804-A028-E600BE6DA86D} - C:\WINDOWS\system32\Bvaqee.dll (file missing)
O2 - BHO: (no name) - {9572665A-28DB-4C48-9C21-E14F9278D3F7} - C:\WINDOWS\system32\Ikxhvt.dll (file missing)
O2 - BHO: (no name) - {9CD3B660-809A-424E-8C7E-F3C83A70F6A6} - C:\WINDOWS\system32\Lifiry.dll (file missing)
O2 - BHO: (no name) - {9CFBD10E-40E6-4315-8916-4693F2E3BD2F} - C:\WINDOWS\system32\Tjwm.dll (file missing)
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - E:\KuGoo3\KuGoo3DownXControl.ocx
O2 - BHO: (no name) - {C1051928-52B6-405E-83E3-B92E705ABC07} - C:\WINDOWS\system32\Fvzber.dll (file missing)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLO~1\CnsHook.dll
O2 - BHO: (no name) - {D74605F2-5D7E-408C-904C-F85D7EC60CC6} - C:\WINDOWS\system32\Scfev.dll
O2 - BHO: (no name) - {F0E02445-B710-403B-98D3-AAFF3F9B4382} - C:\WINDOWS\system32\Ufqh.dll (file missing)
gototop
 

O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O3 - Toolbar: 江民杀毒工具栏 - {B5A34A93-D538-43A7-8371-864CB6148D12} - C:\Program Files\KV2006\KvShell.dll
O4 - HKLM\..\Run: [SKYNET Personal FireWall] C:\PROGRA~1\SKYNET\FIREWALL\pfw.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Thunder] "C:\Program Files\Thunder Network\Thunder\ThunderShell.exe" /s
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [stup.exe] C:\PROGRA~1\TENCENT\Adplus\stup.exe
O4 - HKLM\..\Run: [wmicsmgr] rundll32 C:\WINDOWS\system32\wmicsmgr.dll,Initialize
O4 - HKLM\..\Run: [res] C:\WINDOWS\system32\res.exe
O4 - HKLM\..\Run: [NTdhcp] C:\WINDOWS\system32\NTdhcp.exe
O4 - HKLM\..\Run: [explore.exe] C:\Program Files\explore.exe
O4 - HKLM\..\Run: [ToP] C:\WINDOWS\LSASS.exe
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [svchost] C:\Program Files\Common Files\System\svchost.exe
O4 - HKLM\..\Run: [Internet] C:\WINDOWS\system32\Intercpu.exe
O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKLM\..\RunServices: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ScanRegistry] C:\Program Files\Common Files\update\update.exe
O4 - HKCU\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\RunServices: [services] C:\WINDOWS\services.exe
O4 - Startup: 网络快车.lnk = C:\Program Files\VnetClient1.6\VnetClient.exe
O4 - Startup: 架设奇迹,版本购买,服务器租用.lnk = ?
O4 - Startup: 最稳定最精彩的老牌奇迹--130SF.lnk = ?
O4 - Startup: ingzshi421.exe
O4 - Global Startup: suanging.exe
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: >>彩信发送<< - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - F:\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用KuGoo3下载(&K) - E:\KuGoo3\KuGoo3DownX.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 添加到雅虎订阅(&Y) - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 雅虎搜索 - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - D:\新建文件夹 (2)\浩方对战平台\GameClient.exe
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao (file missing)
O9 - Extra button: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O11 - Options group: [!CNS] 网络实名
O11 - Options group: [TBH] 搜搜地址栏搜索
O16 - DPF: {5932517A-3326-4439-A708-1C98EDB5C549} (Downloader Class) - file://C:\Documents and Settings\All Users\Application Data\Share Helper\Cast\GGS\d21675f518b\js\iMopDl.cab
O16 - DPF: {ACFE8232-03C5-4AEC-AF5E-42B806724096} (KSHScan Control) - http://safe.qq.com/scan/KAllScan.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{2EBD88B4-AA2C-4AF0-9205-2D16C9A363EC}: NameServer = 202.96.128.166 61.144.56.101
O17 - HKLM\System\CS1\Services\Tcpip\..\{2EBD88B4-AA2C-4AF0-9205-2D16C9A363EC}: NameServer = 202.96.128.166 61.144.56.101
O21 - SSODL: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll (file missing)
O23 - Service: Network Logon (NetWorkLogon) - Unknown owner - rundll32.exe (file missing)
O23 - Service: New work (New Coections) - Unknown owner - C:\WINDOWS\system\svchost.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Network System (Universal Disk Manager) - Unknown owner - C:\Program Files\Common Files\COMM\Network.exe (file missing)
O23 - Service: GrayPigefsdfonServer (vbfsdfd) - Unknown owner - C:\WINDOWS\G_Server2006.exe

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT