esojob - 2006-12-8 12:35:00
我的firefox最近被劫持了,前几天不知在哪儿中毒了,导致firefox被劫持,出现如下症状:
1 在地址栏输入网址,就会被恶意转到一个叫××信息网,原网站根本上不了。
2 地址栏输入网址时一不小心输错,也会被转到该××信息网。
3 我的firefox自己设立的主页在打开firefox时,出不来而是也被转到××信息网
4 在搜索得到结果时,点击结果条目时,偶尔也会被转到××信息网。
我用杀毒软件和反木马软件查找,没有发现病毒,我再用超级兔子,在清除系统的垃圾文件和在删除firefox的上网记录和缓存后,劫持会短时间消除,当在浏览一段时间惑后,劫持又会出现,真是太头痛了,请高手和帮主帮忙解决以下。
还想知道:这个问题会不会使我的电脑信息和资料被泄漏?怎样彻底解决这个问题以防下次再被劫持?
那个垃圾××信息网叫新天通讯信息网,全家不得好死,宣传用这等下流方法!!!!
此方法试过,无效。
----------------------------------------------------------
最简单的修复方法:把那个xx站的域名打入另册,在
c:\windows\system32\drivers\etc\hosts
加入一行
127.0.0.1 xx的域名
-----------------------------------------------------
这是我的扫描日志,请高手帮忙一下
HijackThis@Qoo的扫描日志 V1.97.7
Scan saved at 12:21:09, on 2006-12-8
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\thtfpc\桌面\hijackthis1.97_qoo\HijackThis.exe
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [JeticoPFStartup] "C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: NTUSER.DAT
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Startup: NULL
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
esojob - 2006-12-8 12:55:00
2006-12-08,12:37:43
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<avgnt><"C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min> [Avira GmbH]
<JeticoPFStartup><"C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe"> [Jetico, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
<WinlogonNotify: igfxcui><igfxdev.dll> [(Verified)Intel Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<AGRSMMSG><; AGRSMMSG.exe> [Agere Systems]
<Alcmtr><; ALCMTR.EXE> [(Verified)Realtek Semiconductor Corp.]
<High Definition Audio Property Page Shortcut><; HDAShCut.exe> [(Verified)Windows (R) Server 2003 DDK provider]
<igfxhkcmd><; C:\WINDOWS\system32\hkcmd.exe> [(Verified)Intel Corporation]
<igfxpers><; C:\WINDOWS\system32\igfxpers.exe> [(Verified)Intel Corporation]
<igfxtray><; C:\WINDOWS\system32\igfxtray.exe> [(Verified)Intel Corporation]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<OfficeScanNT Monitor><; "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow> [N/A]
<RemoteControl><; "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"> [Cyberlink Corp.]
<RTHDCPL><; RTHDCPL.EXE> [(Verified)Realtek Semiconductor Corp.]
==================================
启动文件夹
N/A
==================================
服务
[AntiVir PersonalEdition Classic Scheduler / AntiVirScheduler]
<C:\Program Files\AntiVir PersonalEdition Classic\sched.exe><Avira GmbH>
[AntiVir PersonalEdition Classic Guard / AntiVirService]
<C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe><AVIRA GmbH>
[ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard]
<C:\Program Files\ewido anti-spyware 4.0\guard.exe><Anti-Malware Development a.s.>
[Human Interface Device Access / HidServ]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[OfficeScanNT 实时扫描 / ntrtscan]
<><N/A>
[OfficeScanNT 个人防火墙 / OfcPfwSvc]
<><N/A>
[OfficeScanNT 侦听程序 / tmlisten]
<><N/A>
==================================
驱动程序
[Agere Systems Soft Modem / AgereSoftModem]
<system32\DRIVERS\AGRSM.sys><Agere Systems>
[avgio / avgio]
<\??\C:\Program Files\AntiVir PersonalEdition Classic\avgio.sys><H+BEDV Datentechnik GmbH>
[avgntflt / avgntflt]
<\??\C:\Program Files\AntiVir PersonalEdition Classic\avgntflt.sys><AVIRA GmbH>
[bcftdi / bcftdi]
<C:\WINDOWS\SYSTEM32\DRIVERS\bcftdi.SYS><Jetico, Inc.>
[bc_filter / bc_filter]
<C:\WINDOWS\SYSTEM32\DRIVERS\bc_filter.SYS><Jetico, Inc.>
[BC_IP_Filter / bc_ip_f]
<C:\WINDOWS\SYSTEM32\DRIVERS\bc_ip_f.SYS><Jetico, Inc.>
[BC_Engine / bc_ngn]
<C:\WINDOWS\SYSTEM32\DRIVERS\bc_ngn.SYS><Jetico, Inc.>
[BC_PAT_Filter / bc_pat_f]
<C:\WINDOWS\SYSTEM32\DRIVERS\bc_pat_f.SYS><Jetico, Inc.>
[BC_Protocol_Filter / bc_prt_f]
<C:\WINDOWS\SYSTEM32\DRIVERS\bc_prt_f.SYS><Jetico, Inc.>
[BC_TDI_Filter / bc_tdi_f]
<C:\WINDOWS\SYSTEM32\DRIVERS\bc_tdi_f.SYS><Jetico, Inc.>
[ewido anti-spyware 4.0 driver / ewido anti-spyware 4.0 driver]
<\??\C:\Program Files\ewido anti-spyware 4.0\guard.sys><N/A>
[Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService]
<system32\drivers\HdAudio.sys><Windows (R) Server 2003 DDK provider>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[ialm / ialm]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService]
<system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp]
<system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv]
<system32\DRIVERS\secdrv.sys><N/A>
[tifm21 / tifm21]
<system32\drivers\tifm21.sys><Texas Instruments>
[Trend Micro Filter / TmFilter]
<\??\C:\Program Files\Trend Micro\OfficeScan Client\TmXPFlt.sys><N/A>
[Trend Micro PreFilter / TmPreFilter]
<\??\C:\Program Files\Trend Micro\OfficeScan Client\TmPreFlt.sys><N/A>
esojob - 2006-12-8 12:56:00
==================================
浏览器加载项
[Edit Class]
{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v5.dll, N/A>
[Edit Class]
{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\flash.ocx, Macromedia, Inc.>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<, N/A>
[添加到QQ表情]
<, N/A>
[用QQ彩信发送该图片]
<, N/A>
==================================
正在运行的进程
[PID: 600][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 664][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 688][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 736][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 748][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 908][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 972][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1076][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1132][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1204][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1592][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1688][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[C:\Program Files\ewido anti-spyware 4.0\context.dll] [Anti-Malware Development a.s., 4, 0, 0, 172]
[C:\Program Files\AntiVir PersonalEdition Classic\shlext.dll] [H+BEDV Datentechnik GmbH, 7.00.00.04]
[PID: 1852][C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe] [Avira GmbH, 7.00.00.18]
[C:\Program Files\AntiVir PersonalEdition Classic\avgcmxp.dll] [Avira GmbH, 7.00.00.16]
[PID: 1860][C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe] [Jetico, Inc., 1.0.1.61]
[C:\Program Files\Jetico\Jetico Personal Firewall\Modules\ip_filter.dll] [Jetico, Inc., 1.0.1.20]
[C:\Program Files\Jetico\Jetico Personal Firewall\Modules\proto_filter.dll] [Jetico, Inc., 1.0.0.27]
[C:\Program Files\Jetico\Jetico Personal Firewall\Modules\tdi_filter.dll] [Jetico, Inc., 1.0.0.59]
[C:\Program Files\Jetico\Jetico Personal Firewall\Modules\pat_filter.dll] [Jetico, Inc., 1.0.0.20]
[C:\Program Files\Jetico\Jetico Personal Firewall\bcflogtb.dll] [Jetico, Inc., 1.0.1.8]
[C:\Program Files\Jetico\Jetico Personal Firewall\bcfgenv.dll] [Jetico, Inc., 1.0.0.26]
[C:\Program Files\Jetico\Jetico Personal Firewall\fwui.dll] [Jetico, Inc., 1.0.1.86]
[PID: 1868][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1176][C:\Program Files\AntiVir PersonalEdition Classic\sched.exe] [Avira GmbH, 7.00.00.27]
[C:\Program Files\AntiVir PersonalEdition Classic\schedr.dll] [ Avira GmbH, 7.00.00.09]
[PID: 1196][C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe] [AVIRA GmbH, 7.00.00.35]
[C:\Program Files\AntiVir PersonalEdition Classic\GUARDMSG.DLL] [Avira GmbH, 7.00.00.12]
[C:\Program Files\AntiVir PersonalEdition Classic\AVPREF.DLL] [Avira GmbH, 7.00.00.02]
[C:\Program Files\AntiVir PersonalEdition Classic\SMTPLIB.DLL] [Avira GmbH, 1.02.00.08]
[C:\Program Files\AntiVir PersonalEdition Classic\AVEWIN32.DLL] [Avira GmbH, 7.2.0.49]
[PID: 1312][C:\Program Files\ewido anti-spyware 4.0\guard.exe] [Anti-Malware Development a.s., 4, 0, 0, 172]
[C:\Program Files\ewido anti-spyware 4.0\engine.dll] [Anti-Malware Development a.s., 4, 0, 0, 172]
[PID: 380][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1372][C:\WINDOWS\system32\NOTEPAD.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1880][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\macromed\flash\flash.ocx] [Macromedia, Inc., 6,0,79,0]
[PID: 244][C:\Program Files\Mozilla Firefox\firefox.exe] [Mozilla Corporation, 1.8.1: 2006101023]
[C:\Program Files\Mozilla Firefox\js3250.dll] [Netscape Communications Corporation, 4.0]
[C:\Program Files\Mozilla Firefox\nspr4.dll] [Netscape Communications Corporation, 4.6.3]
[C:\Program Files\Mozilla Firefox\xpcom_core.dll] [Mozilla Foundation, 1.8.1: 2006101023]
[C:\Program Files\Mozilla Firefox\plc4.dll] [Netscape Communications Corporation, 4.6.3]
[C:\Program Files\Mozilla Firefox\plds4.dll] [Netscape Communications Corporation, 4.6.3]
[C:\Program Files\Mozilla Firefox\smime3.dll] [Mozilla Foundation, 3.11.3 Basic ECC]
[C:\Program Files\Mozilla Firefox\nss3.dll] [Mozilla Foundation, 3.11.3 Basic ECC]
[C:\Program Files\Mozilla Firefox\softokn3.dll] [Mozilla Foundation, 3.11.3 Basic ECC]
[C:\Program Files\Mozilla Firefox\ssl3.dll] [Mozilla Foundation, 3.11.3 Basic ECC]
[C:\Program Files\Mozilla Firefox\xpcom_compat.dll] [Mozilla Foundation, 1.8.1: 2006101023]
[C:\Program Files\Mozilla Firefox\components\myspell.dll] [Mozilla Foundation, 1.8.1: 2006101023]
[C:\Program Files\Mozilla Firefox\components\jar50.dll] [Mozilla Foundation, 1.8.1: 2006101023]
[C:\Program Files\Mozilla Firefox\components\spellchk.dll] [Mozilla Foundation, 1.8.1: 2006101023]
[C:\Program Files\Mozilla Firefox\freebl3.dll] [Mozilla Foundation, 3.11.3 Basic ECC]
[C:\Program Files\Mozilla Firefox\nssckbi.dll] [Mozilla Foundation, 1.62]
[PID: 1432][C:\Documents and Settings\csl\桌面\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 www.tongxunqicai.cn
==================================
红夜鬼1 - 2006-12-8 12:58:00
运行SREng2,使用“系统修复”--浏览器加载项--删除
[Edit Class]
{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
显示隐藏文件
删除:
C:\WINDOWS\system32\CMBEdit.dll
行SREng2,使用:系统修复--文件关联--全选--修复
© 2000 - 2026 Rising Corp. Ltd.