瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 地址栏搜索----中毒了(请高手指点)

1   1  /  1  页   跳转

地址栏搜索----中毒了(请高手指点)

地址栏搜索----中毒了(请高手指点)

输入什么内容进行搜索,都会自动弹出http://www.5533.com.cn的网页.

昨天用刚升过级的瑞星杀了两个病毒,但还没有杀干净,进行搜索时情况依然一样.

请高手帮忙解决,谢谢.

(附中毒界面)

附件附件:

下载次数:0
文件类型:image/pjpeg
文件大小:
上传时间:2005-7-30 9:38:12
描述:



最后编辑2005-07-30 14:35:10
分享到:
gototop
 

【回复“微言”的帖子】
建议你下载并使用HijackThis1.99.1
HijackThis下载地址请参考:
【必读】本版说明及常用小软件下载
http://forum.ikaka.com/topic.asp?board=67&artid=5188931

HijackThis的使用方法-----请参考--瑞星HijackThis专题
http://it.rising.com.cn/newSite/Channels/anti_virus/Antivirus_Faq/TopicExplorerPagePackage/hijackthis.htm
gototop
 

收到,谢谢.

不过我是菜鸟一个,还得慢慢研究.
gototop
 

扫描结果如下,请高手帮忙.

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      10:06:22, 日期 2005-7-30
操作系统:  Windows 2000 SP4 (WinNT 5.00.2195)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\Program Files\SkyNet\FireWall\PFW.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\WINNT\system32\ctfmon.exe
C:\Program Files\eMule\eMule.exe
C:\WINNT\system32\wuauclt.exe
C:\Documents and Settings\Administrator\桌面\临时文件\729\HijackThis1991zww.exe

O1 - Hosts: 218.85.132.177 zs.3721.com
O1 - Hosts: 218.85.132.177 seek.3721.com
O1 - Hosts: 218.85.132.177 auto.search.msn.com
O1 - Hosts: 218.85.132.177 dir.sina.com.cn
O1 - Hosts: 218.85.132.177 pic.sina.com.cn
O1 - Hosts: 218.85.132.177 search.sina.com.cn
O1 - Hosts: 218.85.132.177 dir.sohu.com
O1 - Hosts: 218.85.132.177 dir.sogou.com
O1 - Hosts: 218.85.132.177 dir.yahoo.com
O1 - Hosts: 218.85.132.177 popme.163.com
O1 - Hosts: 218.85.132.177 site.baidu.com
O1 - Hosts: 218.85.132.177 www.432.cn
O1 - Hosts: 218.85.132.177 x.baidu.com
O1 - Hosts: 218.85.132.177 assistant.3721.com
O1 - Hosts: 218.85.132.177 sms.3721.com
O1 - Hosts: 218.85.132.177 cnsmin.3721.com
O1 - Hosts: 218.85.132.177 hot.3721.com
O1 - Hosts: 218.85.132.177 3721.com
O1 - Hosts: 218.85.132.177 www.3721.com
O1 - Hosts: 218.85.132.177 dl.3721.com
O1 - Hosts: 218.85.132.177 www.skycn.com
O1 - Hosts: 218.85.132.177 skycn.com
O1 - Hosts: 218.85.132.177 nmsearch.3721.com
O1 - Hosts: 218.85.132.177 cmail.3721.com
O1 - Hosts: 218.85.132.177 corp.3721.com
O1 - Hosts: 218.85.132.177 download.3721.com
O1 - Hosts: 218.85.132.177 www.hao123.com
O1 - Hosts: 218.85.132.177 www.hao123.net
O1 - Hosts: 218.85.132.177 hao123.com
O1 - Hosts: 218.85.132.177 hao123.net
O1 - Hosts: 218.85.132.177 www.265.com
O1 - Hosts: 218.85.132.177 265.com
O1 - Hosts: 218.85.132.177 www.3tom.com
O1 - Hosts: 218.85.132.177 www.da123.com
O1 - Hosts: 218.85.132.177 www.ttjj.com
O1 - Hosts: 218.85.132.177 www.gjj.cc
O1 - Hosts: 218.85.132.177 www.516.com
O1 - Hosts: 218.85.132.177 union.265.com
O1 - Hosts: 218.85.132.177 wn.265.com
O1 - Hosts: 218.85.132.177 music.265.com
O1 - Hosts: 218.85.132.177 516.com
O1 - Hosts: 218.85.132.177 mp3.516.com
O1 - Hosts: 218.85.132.177 www.sowang.com
O1 - Hosts: 218.85.132.177 www.asiacool.com
O1 - Hosts: 218.85.132.177 www.haodx.com
O1 - Hosts: 218.85.132.177 www.365key.com
O1 - Hosts: 218.85.132.177 www.365key.com
O1 - Hosts: 218.85.132.177 www.5566.net
O1 - Hosts: 218.85.132.177 5566.net
O1 - Hosts: 218.85.132.177 www.v111.com
O1 - Hosts: 218.85.132.177 v111.com
O1 - Hosts: 218.85.132.177 www.tthao.com
O1 - Hosts: 218.85.132.177 www.51115.com
O1 - Hosts: 218.85.132.177 www.K369.com
O1 - Hosts: 218.85.132.177 www.37021.com
O1 - Hosts: 218.85.132.177 www.qqwz.com
O1 - Hosts: 218.85.132.177 www.haokan123.com
O1 - Hosts: 218.85.132.177 www.zhao99.com
O1 - Hosts: 218.85.132.177 www.vv11.com
O1 - Hosts: 218.85.132.177 www.114.com.cn
O1 - Hosts: 218.85.132.177 url.114.com.cn
O1 - Hosts: 218.85.132.177 www.34se.com
O1 - Hosts: 218.85.132.177 www.chinadmoz.net
O1 - Hosts: 218.85.132.177 webspacecn.com
O1 - Hosts: 218.85.132.177 www.seed.cn
O1 - Hosts: 218.85.132.177 www.56ds.com
O1 - Hosts: 218.85.132.177 dianying2009.com
O1 - Hosts: 218.85.132.177 vod.epac.to
O1 - Hosts: 218.85.132.177 www.zhaoshang.net.cn
O1 - Hosts: 218.85.132.177 www.282.com.cn
O1 - Hosts: 218.85.132.177 51.163.com
O1 - Hosts: 218.85.132.177 www.op99.com
O1 - Hosts: 218.85.132.177 op99.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: DownloadBHO T2BHO - {B1D147E7-873E-4909-8127-695D9BB78728} - C:\WINNT\Downloaded Program Files\barhelp22.0.dll
O3 - IE工具栏增项: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - 启动项HKLM\\Run: [SKYNET Personal FireWall] C:\Program Files\SkyNet\FireWall\PFW.exe
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - 启动项HKLM\\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - 启动项HKLM\\Run: [YDTMain.exe] C:\PROGRA~1\YDT\YDTMain.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\eMule.exe -AutoStart
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的按钮: 百万图库 - {6713E8D2-850A-101B-AFC0-4210102A8DA7} - http://www.26-3.com/p (file missing) (HKCU)
O9 - 浏览器额外的按钮: 铃声图片下载 - {7713E8D2-850A-101B-AFC0-4210102A8DA7} - http://www.26-3.com/sms/index.htm (file missing) (HKCU)
O16 - DPF: {2BFAA61B-5C83-4865-8281-D8BDBF863061} (PGEdit Class) - https://www.gnetpg.com/PG_ATL.cab
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/aliedit.cab
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} (天下搜索) - http://iebar.t2t2.com/iebar.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EEB72AEE-B2C1-4793-9FB2-26358FE8FD42}: NameServer = 202.96.128.143,202.96.128.68
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe

gototop
 

【回复“微言”的帖子】
请修复:
所有的O1项
O2 - BHO: DownloadBHO T2BHO - {B1D147E7-873E-4909-8127-695D9BB78728} - C:\WINNT\Downloaded Program Files\barhelp22.0.dll
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - 浏览器额外的按钮: 百万图库 - {6713E8D2-850A-101B-AFC0-4210102A8DA7} - http://www.26-3.com/p (file missing) (HKCU)
O9 - 浏览器额外的按钮: 铃声图片下载 - {7713E8D2-850A-101B-AFC0-4210102A8DA7} - http://www.26-3.com/sms/index.htm (file missing) (HKCU)
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} (天下搜索) - http://iebar.t2t2.com/iebar.cab
搜索并删除文件:
C:\WINNT\Downloaded Program Files\barhelp22.0.dll。


gototop
 

多谢sanadayukimura.

另:你的名字太长了.
gototop
 

引用:
【sanadayukimura的贴子】【回复“微言”的帖子】
请修复:
所有的O1项
搜索并删除文件:
C:\WINNT\Downloaded Program Files\barhelp22.0.dll。



...........................



找不到barhelp22.0.dll这个文件啊!!
gototop
 

第一次删时,由于看不仔细,01项没有删除,所以情况依然出现,又因为barhelp22.0.dll文件找不到,所以以为是sanadayukimura搞错了.

但我在回上贴时,才发现原来还要求我删除所有的01项.

立即删除后,再用就好了.再次对 sanadayukymura表示感谢.

附件附件:

下载次数:0
文件类型:image/pjpeg
文件大小:
上传时间:2005-7-30 14:27:41
描述:



gototop
 

【回复“微言”的帖子】
》》找不到barhelp22.0.dll这个文件啊!!

可能是HijackThis在修复的同时删除了
gototop
 

可能是.
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT