瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 帮我也看看扫描报告,谢谢!(主页被恶意修改)

1   1  /  1  页   跳转

帮我也看看扫描报告,谢谢!(主页被恶意修改)

帮我也看看扫描报告,谢谢!(主页被恶意修改)

我刚装的系统, 不知道怎么又中招了,现在主页会连接到www.okww.net(以前我设置的是空白页),同时中了backdoor病毒,我用KV在安全模式下杀掉了这个病毒,这是杀毒后的扫描报告,总是不放心,请高手帮我看看是不是还有什么问题没有彻底解决?


HijackThis_815汉化版扫描日志 V1.99.1
保存于      16:49:22, 日期 2005-8-24
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
D:\kv2004\KV2004\KVMonXP.kxp
C:\WINDOWS\system32\ctfmon.exe
D:\kv2004\KV2004\KVSrvXp_1.exe
D:\kv2004\KV2004\KVwsc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\racer-henan-cnc\racer.exe
C:\Program Files\racer-henan-cnc\RacerKp.exe
D:\hijackthis1.99.1\HijackThis1991zww.exe

F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: 202.103.67.180 auto.search.msn.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1.4\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O4 - 启动项HKLM\\Run: [KvMonXP] D:\kv2004\KV2004\KVMonXP.kxp /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O14 - IERESET.INF: START_PAGE_URL=about:blank
O14 - IERESET.INF: MS_START_PAGE_URL=about:blank
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/aliedit.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1123844080846
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - NT 服务: KVSrvXp_1 - JiangMin Ltd. - D:\kv2004\KV2004\KVSrvXp_1.exe
O23 - NT 服务: KVWSC - Jiangmin Co - D:\kv2004\KV2004\KVwsc.exe
最后编辑2005-08-24 21:34:42
分享到:
gototop
 

【回复“hailang110”的帖子】

修复;
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: 202.103.67.180 auto.search.msn.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1.4\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O14 - IERESET.INF: START_PAGE_URL=about:blank
O14 - IERESET.INF: MS_START_PAGE_URL=about:blank

为系统打全补丁.
gototop
 

谢谢老大!我的问题解决了,现在是我处理好后的扫描报告

HijackThis_815汉化版扫描日志 V1.99.1
保存于      21:30:50, 日期 2005-8-24
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\kv2004\KV2004\KVMonXP.kxp
C:\WINDOWS\system32\ctfmon.exe
D:\kv2004\KV2004\KVSrvXp_1.exe
D:\kv2004\KV2004\KVwsc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\racer-henan-cnc\racer.exe
C:\Program Files\racer-henan-cnc\RacerKp.exe
D:\旺旺\淘宝旺旺\WangWang.exe
D:\popo\新建文件夹\popo2004\popo.exe
E:\联众外挂\LZCards.exe
C:\Program Files\Globallink\Game\share\GLWorld.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\hijackthis1.99.1\HijackThis1991zww.exe

O4 - 启动项HKLM\\Run: [KvMonXP] D:\kv2004\KV2004\KVMonXP.kxp /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/aliedit.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1123844080846
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - NT 服务: KVSrvXp_1 - JiangMin Ltd. - D:\kv2004\KV2004\KVSrvXp_1.exe
O23 - NT 服务: KVWSC - Jiangmin Co - D:\kv2004\KV2004\KVwsc.exe
gototop
 

log没问题了。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT