无情狂人 - 2006-7-30 21:06:00
http://www.cd321.com http://www.677977.com这两个网站
这是我的进程
Logfile of HijackThis v1.99.1
Scan saved at 20:53:10, on 2006-7-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\SVOHOST.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\JJOL\IME\JJSvr.EXE
C:\Program Files\Internet Explorer\iexplore.exe
D:\浩方对战平台\HFGameOPT\GameClient.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
G:\HijackThis.exe
R3 - Default URLSearchHook is missing
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [SoundMam] C:\WINDOWS\system32\SVOHOST.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O17 - HKLM\System\CCS\Services\Tcpip\..\{C7A66580-AED0-4A46-8F44-300B66CB3AC4}: NameServer = 61.128.128.68 61.128.192.68
O23 - Service: Media Number Service - Unknown owner - C:\WINDOWS\w32dsm.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: ELSA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
无情狂人 - 2006-7-30 23:15:00
麻烦那个高手帮我看看啊!!!!!!!!!!!
无情狂人 - 2006-7-31 18:02:00
请高手看看啊!!
万分感谢了!!
ogim - 2006-7-31 22:07:00
看不出太大的问题!
不过你可以这样!
X:\WINNT\system32\drivers\etc\hosts x是你的系统盘
用记事本打开hosts
在下面写上这个
127.0.0.1 www.cd321.com
127.0.0.1 www.677977.com
ogim - 2006-7-31 22:18:00
建议System Repair Engineer 2.0.21.505 (2.0 RC 2)
把日志放上!
chuangzhao - 2006-8-1 0:48:00
X:\WINNT\system32\drivers\etc\hosts x是你的系统盘
用记事本打开hosts
在下面写上这个
127.0.0.1 www.cd321.com
127.0.0.1 www.677977.com
我试了没有用啊!!!!
无情狂人 - 2006-8-1 11:10:00
这是我的日志请高手看看
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SoundMam><C:\WINDOWS\system32\SVOHOST.exe> []
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> []
<jiahu><C:\WINDOWS\system32\svchqst.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<KernelCheck><C:\WINDOWS\system32\winine.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{08315C1A-9BA9-4B7C-A432-26885F78DF28}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\rejoi.vxd> []
==================================
启动文件夹
服务
[Media Number Service / Media Number Service]
<C:\WINDOWS\w32dsm.exe><N/A>
[MSCSPTISRV / MSCSPTISRV]
<"C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe"><Sony Corporation>
[ELSA Display Driver Service / NVSvc]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[PACSPTISVR / PACSPTISVR]
<"C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe"><Sony Corporation>
[Sony SPTI Service / SPTISRV]
<"C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe"><Sony Corporation>
[SonicStage SCSI Service / SSScsiSV]
<C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe><Sony Corporation>
==================================
浏览器加载项
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, N/A>
[internet explorer helper]
{02C9B9AB-6372-46C5-B356-773FAF3B6B1E} <C:\WINDOWS\fonts\msshapi.dll, >
[wmpdrm]
{0E674588-66B7-4E19-9D0E-2053B800F69F} <C:\WINDOWS\system32\wmpdrm.dll, N/A>
[实用搜索]
{15ADF205-4C54-4CFE-AC88-1EA0BA6D06A0} <C:\Program Files\ScanToolbar\ScanBar.dll, N/A>
[MyIEHelper Class]
{16A770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4573.dll, N/A>
[KAVIEHelper Class]
{1B2F92A1-CDAF-4511-9382-91E3F5CE0880} <C:\PROGRA~1\KOS\KOSIEBar.dll, 金山软件股份有限公司>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[YrrCwduj Class]
{2D7D043B-104C-0B25-7AD4-4EB5AD4C85A5} <C:\WINDOWS\DOWNLO~1\yjzvd.dll, upsrhsoft>
[CaiShowBH Class]
{3AF40CB8-B3BA-4E2D-8968-4BF8DB172997} <C:\Program Files\CaiShow Tech\CaiShow\BrowerHelper.dll, N/A>
[]
{3D898C55-74CC-4B7C-B5F1-45913F368388} <C:\WINDOWS\system32\bdhelper.dll, N/A>
[Deliverer Class]
{3E290290-1728-4C1E-863A-AA12526333F6} <C:\Program Files\CNet\ADDeliverer\ADDeliverer.dll, N/A>
[金山毒霸在线产品升级]
{52DF16E3-6C4F-4B22-8BAF-09263E463B48} <C:\PROGRA~1\KOS\KOSInit.ocx, 金山软件股份有限公司>
[NetAccelerate Class]
{5673A7C0-95CC-4646-BB07-3BD71234CEF9} <C:\WINDOWS\system32\wuwebex.dll, N/A>
[金山毒霸在线杀毒]
{577A1997-6FD0-4972-B234-885DA583F9CE} <C:\PROGRA~1\KOS\KOSClean.ocx, 金山软件股份有限公司>
[ActiveBHO Class]
{63C55A7F-6E29-8D4F-5C76-4F850F28D13A} <C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll, N/A>
[MMSAssist BHO]
{6671A431-5C3D-463D-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[MSHlper Class]
{721E6521-4CAD-4A8D-A7F1-4E230B31EF19} <C:\WINDOWS\system32\mshlp.dll, N/A>
[CpapView Class]
{77962960-536E-47EC-9DDB-52651519705F} <C:\WINDOWS\system32\Rundll32.dll, >
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[IEHlprObj Class]
{999ADFA2-8AD1-47FF-97FC-69FB847458F4} <C:\Progra~1\NetMeeting\nmview.dll, N/A>
[HBObject Class]
{AE22AFE5-1EF4-4D25-9E23-D2825FB17DA1} <C:\PROGRA~1\HBClient\tbhelper.dll, N/A>
[
无情狂人 - 2006-8-1 11:10:00
卡卡上网安全助手]
{AFF6E516-CBE5-4F8A-9C2F-38A68013E766} <C:\WINDOWS\system32\kakatool.dll, N/A>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[VIDEO__X_MS_WMV Moniker Class]
{CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\System32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[珊瑚虫 工具栏]
{D74EC18E-3DDD-4174-B1B1-949FE3B8366D} <C:\Program Files\Infofo Bar\infofobar.dll, 珊瑚虫工作室 泰格工作室>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, N/A>
[FlashGet Bar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\fgiebar.dll, Amaze Soft>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[上传到QQ网络硬盘]
<G:\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<G:\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<G:\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<G:\QQ\SendMMS.htm, N/A>
正在运行的进程
[PID: 588][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 656][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 680][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 724][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 736][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 896][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 956][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1072][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1112][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1140][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1376][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\winscok.dll] <N/A><N/A>
[D:\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[PID: 1424][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 1556][C:\WINDOWS\system32\SVOHOST.exe] <N/A><N/A>
[C:\WINDOWS\system32\winscok.dll] <N/A><N/A>
[PID: 1572][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\winscok.dll] <N/A><N/A>
[PID: 2004][C:\WINDOWS\system32\conime.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\winscok.dll] <N/A><N/A>
[PID: 412][C:\WINDOWS\system32\nvsvc32.exe] <NVIDIA Corporation><6.14.10.7181>
[PID: 520][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 580][C:\WINDOWS\system32\wdfmgr.exe] <Microsoft Corporation><5.1.2600.2180 (private/xpsp_mce.040810-0205)>
[PID: 276][G:\QQ\QQ.exe] <TENCENT><0, 0, 0, 0>
[G:\QQ\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[G:\QQ\QQHelperDll.dll] <><1, 0, 0, 1>
[G:\QQ\BasicCtrlDll.dll] <Tencent><5, 0, 200, 160>
[C:\WINDOWS\system32\winscok.dll] <N/A><N/A>
[G:\QQ\LoginCtrl.dll] <><1, 0, 0, 1>
[G:\QQ\npkcntc.dll] <INCA Internet Co., Ltd.><2006, 3, 2, 1>
[G:\QQ\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[G:\QQ\QQAPI.dll] <><1, 0, 0, 1>
[G:\QQ\TIMProxy.dll] <tencent><0, 3, 2, 4>
[G:\QQ\QQRes.dll] <tencent><1, 0, 0, 1>
[G:\QQ\QQMainFrame.dll] <N/A><N/A>
[G:\QQ\CQQApplication.dll] <N/A><N/A>
[G:\QQ\NewSkin.dll] <><1, 0, 0, 1>
[G:\QQ\HostingMgr.dll] <><1, 0, 0, 1>
[G:\QQ\CameraDll.dll] <><1, 0, 0, 1>
[G:\QQ\MailSummary.dll] <><1, 0, 0, 1>
[G:\QQ\QQSpace.dll] <><1, 0, 0, 1>
[C:\WINDOWS\system32\msdmo.dll] <N/A><N/A>
[G:\QQ\QQGroupMng.dll] <><1, 0, 0, 1>
[G:\QQ\GroupLive.dll] <N/A><N/A>
[G:\QQ\QQSysMsgMng.dll] <N/A><N/A>
[G:\QQ\UserDefinedHead.dll] <><1, 0, 0, 1>
[G:\QQ\QQPlugin.dll] <N/A><N/A>
[G:\QQ\QQConfigPlugin.dll] <><1, 0, 0, 1>
[G:\QQ\QQAvatar.dll] <N/A><N/A>
[G:\QQ\FlashAvatarDll.dll] <><1, 4, 0, 1>
[G:\QQ\QRingMng.dll] <N/A><N/A>
[G:\QQ\PhoneAPI.dll] <><1, 0, 0, 1>
[G:\QQ\DialerAllinOne.dll] <tencent><1, 4, 0, 0>
[G:\QQ\QQAllInOne.dll] <N/A><N/A>
[G:\QQ\SCCore.dll] <N/A><N/A>
[G:\QQ\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 200>
[G:\QQ\LongConnection.dll] <tencent><5, 0, 200, 160>
[G:\QQ\QQPet.dll] <><1, 0, 0, 1>
[G:\QQ\BQQApplication.dll] <N/A><N/A>
[G:\QQ\CommercesMng.dll] <><1, 0, 0, 1>
[G:\QQ\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[G:\QQ\QQUdpGetFileLib.dll] <tencent><0, 2, 2, 3>
[G:\QQ\QQSceneMng.dll] <N/A><N/A>
[G:\QQ\QQPhoneHelper.dll] <腾讯科技(深圳)有限公司><2, 0, 5, 50>
[G:\QQ\QQSettingCtrl.dll] <><1, 0, 0, 1>
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[G:\QQ\videodevice.dll] <Tencent><1.5.0.0>
[G:\QQ\inplus.dll] <Tencent><1.5.0.0>
[C:\WINDOWS\system32\l3codeca.acm] <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
[PID: 1844][G:\QQ\TIMPlatform.exe] <tencent><0, 3, 1, 8>
[C:\WINDOWS\system32\winscok.dll] <N/A><N/A>
[G:\QQ\TIMProxy.dll] <tencent><0, 3, 2, 4>
[PID: 372][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\winscok.dll] <N/A><N/A>
[PID: 612][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\winscok.dll] <N/A><N/A>
[C:\WINDOWS\system32\FOURIER_M1.IME] <北京紫光华宇软件股份有限公司><4.0.0.5001>
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[PID: 156][C:\WINDOWS\system32\winine.exe] <Microsoft Corporation><5.1.2600.0>
[PID: 852][c:\windows\system32\svchqst.exe] <N/A><N/A>
[C:\WINDOWS\system32\winscok.dll] <N/A><N/A>
[PID: 616][G:\sreng2021505\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\WINDOWS\system32\winscok.dll] <N/A><N/A>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
© 2000 - 2026 Rising Corp. Ltd.