瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】偶的 IE被劫持了!求大家帮忙!

12   1  /  2  页   跳转

【求助】偶的 IE被劫持了!求大家帮忙!

【求助】偶的 IE被劫持了!求大家帮忙!

我家的电脑会不时的自动弹http://www.my168.net/这个网站!很烦人这个~!
怎样才可以让它不弹出这个网站!
最后编辑2005-09-16 09:22:54
分享到:
gototop
 

【回复“菜鸟狂人”的帖子】您好,为了方便帮您解决问题,请您使用hijackthis把扫描的日志贴到贴子上来。

运行HijackThis,先点[扫描系统并保存日志]或[Do a system scan and save a logfile]按钮,扫描完成后,LOG将会在自动弹出的记事本中
显示,再从记事本里复制/粘贴到贴子里。如果LOG比较长,一贴发不完,你可以分成几个部分发在回贴里。
gototop
 

【回复“菜鸟狂人”的帖子】
请您先点击这里http://www.spywareinfo.com/~merijn/files/hijackthis.zip下载HijackThis1.99.1(它是免费的),将它解压到一个非临时性的文件夹(比如C:\Program Files\HijackThis\HijackThis.exe)。然后双击HijackThis.exe图标,选择Do a system scan and save a logfile,将产生的文本文件中的日志帖上来。如果一个帖子贴不下,可以将剩余的部分另开一帖。
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 23:39:46, on 2005-9-15
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
E:\rixing专用\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
e:\rixing专用\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Maxthon\Thundermini\ThunderMini.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CNNIC\Cdn\cdnup.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\cisvc.exe
E:\rixing专用\Rising\Rav\Ravmond.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
gototop
 

E:\rixing专用\Rising\Rfw\rfwmain.exe
F:\网络游戏\lala\QQ.exe
F:\网络游戏\lala\TIMPlatform.exe
F:\网络游戏\lala\qqpet\qqpet.exe
F:\网络游戏\lala\QQexternal.exe
F:\网络游戏\TT\TTraveler.exe
F:\HijackThis.exe

O1 - Hosts: 61.177.56.251 popme.163.com
O1 - Hosts: 61.177.56.251 www.xk99.com
O1 - Hosts: 61.177.56.251 www.006.net
O1 - Hosts: 61.177.56.251 006.net
O1 - Hosts: 61.177.56.251 www.cmfu.com
O1 - Hosts: 61.177.56.251 www.free120.com
O1 - Hosts: 61.177.56.251 www.4577.com
O1 - Hosts: 61.177.56.251 www.9617.com
O1 - Hosts: 61.177.56.251 www.fjwz.com
O1 - Hosts: 61.177.56.251 partner.cpc.sohu.com
O1 - Hosts: 61.177.56.251 ad4.sina.com.cn
O1 - Hosts: 61.177.56.251 music.17o8.comer.cpc.sohu.com
O1 - Hosts: 61.177.56.251 ad.tom.com
O1 - Hosts: 61.177.56.251 search.union.3721,com
O1 - Hosts: 61.177.56.251 post.baidu.com
O1 - Hosts: 61.177.56.251 mp3.baidu.com
O1 - Hosts: 61.177.56.251 image.baidu.com
O1 - Hosts: 61.177.56.251 site.google.com
O1 - Hosts: 61.177.56.251 flash.baidu.com
O1 - Hosts: 61.177.56.251 assistant.3721,com
O1 - Hosts: 61.177.56.251 pfp.sina.com.cn
O1 - Hosts: 61.177.56.251 cn.websearch.yahoo.com
O1 - Hosts: 61.177.56.251 sms.qq.com
O1 - Hosts: 61.177.56.251 www.qq.com
O1 - Hosts: 61.177.56.251 partner.lead2.com.cn
O1 - Hosts: 61.177.56.251 ad.cn.doubleclick.net
O1 - Hosts: 61.177.56.251 auto.search.msn.com
O1 - Hosts: 61.177.56.251 www.ourgame.com
O1 - Hosts: 61.177.56.251 www.the9.com
O1 - Hosts: 61.177.56.251 www.flashempire.com
O1 - Hosts: 61.177.56.251 www.qq163.com
O1 - Hosts: 61.177.56.251 www.9sky.com
O1 - Hosts: 61.177.56.251 www.tom-1.com
O1 - Hosts: 61.177.56.251 www.17173.com
O1 - Hosts: 61.177.56.251 www.yaotou.com
O1 - Hosts: 61.177.56.251 union.3721,com
O1 - Hosts: 61.177.56.251 music.feifa.com
O1 - Hosts: 61.177.56.251 www.vodfans.com
O1 - Hosts: 61.177.56.251 www.sogua.com
O1 - Hosts: 61.177.56.251 fm974.tom.com
O1 - Hosts: 61.177.56.251 ent.tom.com
O1 - Hosts: 61.177.56.251 music.tyfo.com
O1 - Hosts: 61.177.56.251 www.wanwa.com
O1 - Hosts: 61.177.56.251 www.guang.org
O1 - Hosts: 61.177.56.251 www.wz.zj.cn
O1 - Hosts: 61.177.56.251 www.3189.net
O1 - Hosts: 61.177.56.251 music.17o8.com
O1 - Hosts: 61.177.56.251 www.99music.net
O1 - Hosts: 61.177.56.251 www.cococ.com
O1 - Hosts: 61.177.56.251 www.qqqq.cn
O1 - Hosts: 61.177.56.251 www.bnb.com.cn
O1 - Hosts: 61.177.56.251 www.z163.com
O1 - Hosts: 61.177.56.251 game.163.com
O1 - Hosts: 61.177.56.251 games.sina.com.cn
O1 - Hosts: 61.177.56.251 www.v111.com
O1 - Hosts: 61.177.56.251 music.v111.com
O1 - Hosts: 61.177.56.251 www.3tom.com
O1 - Hosts: 61.177.56.251 www.xkqq.com
O1 - Hosts: 61.177.56.251 www.verymp3.com
O1 - Hosts: 61.177.56.251 www.91look.com
O1 - Hosts: 61.177.56.251 www.168101.com
O1 - Hosts: 61.177.56.251 www.cmfu.com
O1 - Hosts: 61.177.56.251 www.woogood.com
O1 - Hosts: 61.177.56.251 www.haodx.com
O1 - Hosts: 61.177.56.251 www.yingku.com
O1 - Hosts: 61.177.56.251 www.flash51.com
O1 - Hosts: 61.177.56.251 www.17haha.com
O1 - Hosts: 61.177.56.251 www.432.cn
O1 - Hosts: 61.177.56.251 www.cnxp.com
O1 - Hosts: 61.177.56.251 www.hjsm.net
O1 - Hosts: 61.177.56.251 music.8wa.com
O1 - Hosts: 61.177.56.251 www.66vv.com
O1 - Hosts: 61.177.56.251 www.musicfbi.com
O1 - Hosts: 61.177.56.251 www.vv66.com
O1 - Hosts: 61.177.56.251 www.139mm.com
O1 - Hosts: 61.177.56.251 www.130wg.com
O1 - Hosts: 61.177.56.251 www.flashsea.com
O1 - Hosts: 61.177.56.251 movie.59178.com
O1 - Hosts: 61.177.56.251 www.wo123.com
O1 - Hosts: 61.177.56.251 www.1ya.cn
O1 - Hosts: 61.177.56.251 www.happy8.cn
O1 - Hosts: 61.177.56.251 www.s6.cn
O1 - Hosts: 61.177.56.251 www.hao123.com
O1 - Hosts: 61.177.56.251 www.qqee.com
O1 - Hosts: 61.177.56.251 imgu.21cn.com
O1 - Hosts: 61.177.56.251 www.sohu123.com
O1 - Hosts: 61.177.56.251 www.chinamp3.com
O1 - Hosts: 61.177.56.251 www.18z.net
O1 - Hosts: 61.177.56.251 www.ssxs.com
O1 - Hosts: 61.177.56.251 www.fjwz.net
O1 - Hosts: 61.177.56.251 www.wo365.com
O1 - Hosts: 61.177.56.251 www.zhao99.com
O1 - Hosts: 61.177.56.251 www.cn808.net
O1 - Hosts: 61.177.56.251 www.tt55.net
O1 - Hosts: 61.177.56.251 www.mp3tt.com
O1 - Hosts: 61.177.56.251 www.yi5.com
O1 - Hosts: 61.177.56.251 www.haozs.com
O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O2 - BHO: IEMenu Class - {5D8B0CBC-6A8F-4495-96F0-631BAEEC93A6} - C:\WINDOWS\System32\hookie.dll
O2 - BHO: AssistII - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRA~1\3721\Assist\asbar.dll
O2 - BHO: InsIII - {DDDE2452-AF9E-4577-AE6C-465DBCB54D49} - C:\WINDOWS\System32\brinsthd.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 东方卫士 - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EF} - C:\PROGRA~1\DFVSIE~1\DFVSIEBR.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3}? - (no file)
O3 - Toolbar: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86}? - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [dddclient] "C:\Program Files\DuDu\DddClient\DuDuAcc.exe"  /m0
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [thunder_mini] C:\Program Files\Maxthon\Thundermini\ThunderMini.exe
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [internet.exe] C:/WINDOWS/systems.hta
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [renewup] C:\Program Files\CNNIC\Cdn\cdnrenew.exe
O4 - HKLM\..\Run: [MoveSearch] C:\Program Files\网络猪\Search.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] F:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [KvXP] C:\Program Files\KV2005\KvXP.kxp /ScanBoot /ScanSys
gototop
 

O4 - Startup: 腾讯QQ.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &使用迅雷下载 - F:\网络游戏\新建文件夹\pp2005\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - F:\网络游戏\新建文件夹\pp2005\getAllurl.htm
O8 - Extra context menu item: &使用迷你迅雷下载 - C:\Program Files\Maxthon\Thundermini\geturl.htm
O8 - Extra context menu item: 1.秀字转换 - res://C:\WINDOWS\System32\esagent.dll/open.html
O8 - Extra context menu item: 2.表情插入 - res://C:\WINDOWS\System32\esagent.dll/emot.html
O8 - Extra context menu item: 3.插入QQ表情 - res://C:\WINDOWS\System32\esagent.dll/openqqemot.html
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\网络游戏\lala\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\网络游戏\lala\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\网络游戏\lala\SendMMS.htm
O8 - Extra context menu item: 百度-搜索MP3 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUMP3.HTM
O8 - Extra context menu item: 百度-搜索图片 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUIMG.HTM
O8 - Extra context menu item: 百度-搜索新闻 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUNEWS.HTM
O8 - Extra context menu item: 百度-搜索歌词 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDULYRIC.HTM
O8 - Extra context menu item: 百度-搜索网页 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUSEARCH.HTM
O8 - Extra context menu item: 百度-搜索贴吧 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUPOST.HTM
O8 - Extra context menu item: 百度-词典搜索 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDU_DIC.HTM
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm?pid=U_3721_assist (file missing)
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - C:\Program Files\HOLDFAST\GameClient.exe
O9 - Extra button: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: 东方卫士 - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CE} - C:\PROGRA~1\DFVSIE~1\DFVSIEBR.dll
O9 - Extra 'Tools' menuitem: 东方卫士工具条 - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CE} - C:\PROGRA~1\DFVSIE~1\DFVSIEBR.dll
O9 - Extra button: 东方卫士2005下载版 - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9EE} - D:\杀毒专用\DFVSX\DFVSX.exe (file missing)
O9 - Extra 'Tools' menuitem: 东方卫士 - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9EE} - D:\杀毒专用\DFVSX\DFVSX.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-195?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O9 - Extra 'Tools' menuitem: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-195?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdnns.dll
O11 - Options group: [!CNS]  网络实名
O11 - Options group: [CDNCLIENT]  中文上网
O11 - Options group: [TBH] QQ地址栏搜索
O16 - DPF: {1C960AA3-FAEE-11D0-9262-00A0243D2412} (TegoSoft SmartLoader ActiveX Control) - http://web.cy07.com/ActiveX/TegoLoad.cab
O16 - DPF: {40CF48AF-E75D-4B5E-97A7-A37D1F9110F0} - http://file1.hawa.cn/icuavchat.cab
O16 - DPF: {52DF16E3-6C4F-4B22-8BAF-09263E463B48} - http://zs.kingsoft.com/KOSInit.cab
O16 - DPF: {5DD731E6-D4F0-11D3-BE3F-00105A6FDA50} (V3ProX Control) - http://origin-www.ahn.com.cn/aspservice/plugin/myv3.cab
O16 - DPF: {6BB0C189-3676-4711-AA75-E2801D6B0E27} (AvlFTP Control) - http://benchmark.avl.com.cn/cab/avlFtp.cab
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {9BBD100C-E820-4930-9937-E8F3AA40E584} (DFVSScanFile Control) - http://antivirus3.sunv.com/dfvsolDown/dfvsol.cab
O16 - DPF: {ACFE8232-03C5-4AEC-AF5E-42B806724096} (KSHScan Control) - http://scan.kingsoft.com/scan/fangyi/KAllScan.CAB
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O16 - DPF: {DDA166FA-B3EA-4A3B-8EE2-4F552CDEEE81} (KATScan Control) - http://211.152.52.102/duba/antitrojan/update/OCX/KATScan.CAB
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O16 - DPF: {F138084D-84D7-48CD-BEA8-04772457516E} (VqqSpeedDlProxy Class) - http://218.85.138.27/vqqsdl1006.cab
O16 - DPF: {FC1DF328-F720-4FD3-98A4-2595A7356D7F} - http://219.133.38.112/toolbar/qq_sst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{09DFCAA9-91B2-4259-8BB3-4DD9A6EF46F8}: NameServer = 61.234.254.5,211.98.2.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ACD30AD-B019-40D7-801F-8863E9463B0A}: NameServer = 202.103.96.87 211.98.2.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{09DFCAA9-91B2-4259-8BB3-4DD9A6EF46F8}: NameServer = 61.234.254.5,211.98.2.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{09DFCAA9-91B2-4259-8BB3-4DD9A6EF46F8}: NameServer = 61.234.254.5,211.98.2.4
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\System32\mbprot.dll
O18 - Protocol: mbox - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\System32\mbprot.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - e:\rixing专用\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - E:\rixing专用\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\rixing专用\Rising\Rav\Ravmond.exe
gototop
 

谢谢帮我看一下!
gototop
 

【回复“天使之剑”的帖子】Logfile of HijackThis v1.99.1
Scan saved at 23:39:46, on 2005-9-15
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
E:\rixing专用\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
e:\rixing专用\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Maxthon\Thundermini\ThunderMini.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CNNIC\Cdn\cdnup.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\cisvc.exe
E:\rixing专用\Rising\Rav\Ravmond.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
E:\rixing专用\Rising\Rfw\rfwmain.exe
F:\网络游戏\lala\QQ.exe
F:\网络游戏\lala\TIMPlatform.exe
F:\网络游戏\lala\qqpet\qqpet.exe
F:\网络游戏\lala\QQexternal.exe
F:\网络游戏\TT\TTraveler.exe
F:\HijackThis.exe

O1 - Hosts: 61.177.56.251 popme.163.com
O1 - Hosts: 61.177.56.251 www.xk99.com
O1 - Hosts: 61.177.56.251 www.006.net
O1 - Hosts: 61.177.56.251 006.net
O1 - Hosts: 61.177.56.251 www.cmfu.com
O1 - Hosts: 61.177.56.251 www.free120.com
O1 - Hosts: 61.177.56.251 www.4577.com
O1 - Hosts: 61.177.56.251 www.9617.com
O1 - Hosts: 61.177.56.251 www.fjwz.com
O1 - Hosts: 61.177.56.251 partner.cpc.sohu.com
O1 - Hosts: 61.177.56.251 ad4.sina.com.cn
O1 - Hosts: 61.177.56.251 music.17o8.comer.cpc.sohu.com
O1 - Hosts: 61.177.56.251 ad.tom.com
O1 - Hosts: 61.177.56.251 search.union.3721,com
O1 - Hosts: 61.177.56.251 post.baidu.com
O1 - Hosts: 61.177.56.251 mp3.baidu.com
O1 - Hosts: 61.177.56.251 image.baidu.com
O1 - Hosts: 61.177.56.251 site.google.com
O1 - Hosts: 61.177.56.251 flash.baidu.com
O1 - Hosts: 61.177.56.251 assistant.3721,com
O1 - Hosts: 61.177.56.251 pfp.sina.com.cn
O1 - Hosts: 61.177.56.251 cn.websearch.yahoo.com
O1 - Hosts: 61.177.56.251 sms.qq.com
O1 - Hosts: 61.177.56.251 www.qq.com
O1 - Hosts: 61.177.56.251 partner.lead2.com.cn
O1 - Hosts: 61.177.56.251 ad.cn.doubleclick.net
O1 - Hosts: 61.177.56.251 auto.search.msn.com
O1 - Hosts: 61.177.56.251 www.ourgame.com
O1 - Hosts: 61.177.56.251 www.the9.com
O1 - Hosts: 61.177.56.251 www.flashempire.com
O1 - Hosts: 61.177.56.251 www.qq163.com
O1 - Hosts: 61.177.56.251 www.9sky.com
O1 - Hosts: 61.177.56.251 www.tom-1.com
O1 - Hosts: 61.177.56.251 www.17173.com
O1 - Hosts: 61.177.56.251 www.yaotou.com
O1 - Hosts: 61.177.56.251 union.3721,com
O1 - Hosts: 61.177.56.251 music.feifa.com
O1 - Hosts: 61.177.56.251 www.vodfans.com
O1 - Hosts: 61.177.56.251 www.sogua.com
O1 - Hosts: 61.177.56.251 fm974.tom.com
O1 - Hosts: 61.177.56.251 ent.tom.com
O1 - Hosts: 61.177.56.251 music.tyfo.com
O1 - Hosts: 61.177.56.251 www.wanwa.com
O1 - Hosts: 61.177.56.251 www.guang.org
O1 - Hosts: 61.177.56.251 www.wz.zj.cn
O1 - Hosts: 61.177.56.251 www.3189.net
O1 - Hosts: 61.177.56.251 music.17o8.com
O1 - Hosts: 61.177.56.251 www.99music.net
O1 - Hosts: 61.177.56.251 www.cococ.com
O1 - Hosts: 61.177.56.251 www.qqqq.cn
O1 - Hosts: 61.177.56.251 www.bnb.com.cn
O1 - Hosts: 61.177.56.251 www.z163.com
O1 - Hosts: 61.177.56.251 game.163.com
O1 - Hosts: 61.177.56.251 games.sina.com.cn
O1 - Hosts: 61.177.56.251 www.v111.com
O1 - Hosts: 61.177.56.251 music.v111.com
O1 - Hosts: 61.177.56.251 www.3tom.com
O1 - Hosts: 61.177.56.251 www.xkqq.com
O1 - Hosts: 61.177.56.251 www.verymp3.com
O1 - Hosts: 61.177.56.251 www.91look.com
O1 - Hosts: 61.177.56.251 www.168101.com
O1 - Hosts: 61.177.56.251 www.cmfu.com
O1 - Hosts: 61.177.56.251 www.woogood.com
O1 - Hosts: 61.177.56.251 www.haodx.com
O1 - Hosts: 61.177.56.251 www.yingku.com
O1 - Hosts: 61.177.56.251 www.flash51.com
O1 - Hosts: 61.177.56.251 www.17haha.com
O1 - Hosts: 61.177.56.251 www.432.cn
O1 - Hosts: 61.177.56.251 www.cnxp.com
O1 - Hosts: 61.177.56.251 www.hjsm.net
O1 - Hosts: 61.177.56.251 music.8wa.com
O1 - Hosts: 61.177.56.251 www.66vv.com
O1 - Hosts: 61.177.56.251 www.musicfbi.com
O1 - Hosts: 61.177.56.251 www.vv66.com
O1 - Hosts: 61.177.56.251 www.139mm.com
O1 - Hosts: 61.177.56.251 www.130wg.com
O1 - Hosts: 61.177.56.251 www.flashsea.com
O1 - Hosts: 61.177.56.251 movie.59178.com
O1 - Hosts: 61.177.56.251 www.wo123.com
O1 - Hosts: 61.177.56.251 www.1ya.cn
O1 - Hosts: 61.177.56.251 www.happy8.cn
O1 - Hosts: 61.177.56.251 www.s6.cn
O1 - Hosts: 61.177.56.251 www.hao123.com
O1 - Hosts: 61.177.56.251 www.qqee.com
O1 - Hosts: 61.177.56.251 imgu.21cn.com
O1 - Hosts: 61.177.56.251 www.sohu123.com
O1 - Hosts: 61.177.56.251 www.chinamp3.com
O1 - Hosts: 61.177.56.251 www.18z.net
O1 - Hosts: 61.177.56.251 www.ssxs.com
O1 - Hosts: 61.177.56.251 www.fjwz.net
O1 - Hosts: 61.177.56.251 www.wo365.com
O1 - Hosts: 61.177.56.251 www.zhao99.com
O1 - Hosts: 61.177.56.251 www.cn808.net
O1 - Hosts: 61.177.56.251 www.tt55.net
O1 - Hosts: 61.177.56.251 www.mp3tt.com
O1 - Hosts: 61.177.56.251 www.yi5.com
O1 - Hosts: 61.177.56.251 www.haozs.com
O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O2 - BHO: IEMenu Class - {5D8B0CBC-6A8F-4495-96F0-631BAEEC93A6} - C:\WINDOWS\System32\hookie.dll
O2 - BHO: AssistII - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRA~1\3721\Assist\asbar.dll
O2 - BHO: InsIII - {DDDE2452-AF9E-4577-AE6C-465DBCB54D49} - C:\WINDOWS\System32\brinsthd.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 东方卫士 - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EF} - C:\PROGRA~1\DFVSIE~1\DFVSIEBR.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3}? - (no file)
O3 - Toolbar: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86}? - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [dddclient] "C:\Program Files\DuDu\DddClient\DuDuAcc.exe"  /m0
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [thunder_mini] C:\Program Files\Maxthon\Thundermini\ThunderMini.exe
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [internet.exe] C:/WINDOWS/systems.hta
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [renewup] C:\Program Files\CNNIC\Cdn\cdnrenew.exe
O4 - HKLM\..\Run: [MoveSearch] C:\Program Files\网络猪\Search.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] F:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [KvXP] C:\Program Files\KV2005\KvXP.kxp /ScanBoot /ScanSys
O4 - Startup: 腾讯QQ.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &使用迅雷下载 - F:\网络游戏\新建文件夹\pp2005\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - F:\网络游戏\新建文件夹\pp2005\getAllurl.htm
O8 - Extra context menu item: &使用迷你迅雷下载 - C:\Program Files\Maxthon\Thundermini\geturl.htm
O8 - Extra context menu item: 1.秀字转换 - res://C:\WINDOWS\System32\esagent.dll/open.html
O8 - Extra context menu item: 2.表情插入 - res://C:\WINDOWS\System32\esagent.dll/emot.html
O8 - Extra context menu item: 3.插入QQ表情 - res://C:\WINDOWS\System32\esagent.dll/openqqemot.html
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\网络游戏\lala\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\网络游戏\lala\AddEmotion.htm
gototop
 

【回复“天使之剑”的帖子】O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\网络游戏\lala\SendMMS.htm
O8 - Extra context menu item: 百度-搜索MP3 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUMP3.HTM
O8 - Extra context menu item: 百度-搜索图片 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUIMG.HTM
O8 - Extra context menu item: 百度-搜索新闻 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUNEWS.HTM
O8 - Extra context menu item: 百度-搜索歌词 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDULYRIC.HTM
O8 - Extra context menu item: 百度-搜索网页 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUSEARCH.HTM
O8 - Extra context menu item: 百度-搜索贴吧 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDUPOST.HTM
O8 - Extra context menu item: 百度-词典搜索 - res://C:\Program Files\BaiDu\bar\BaiduBar.dll/BAIDU_DIC.HTM
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm?pid=U_3721_assist (file missing)
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - C:\Program Files\HOLDFAST\GameClient.exe
O9 - Extra button: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: 东方卫士 - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CE} - C:\PROGRA~1\DFVSIE~1\DFVSIEBR.dll
O9 - Extra 'Tools' menuitem: 东方卫士工具条 - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CE} - C:\PROGRA~1\DFVSIE~1\DFVSIEBR.dll
O9 - Extra button: 东方卫士2005下载版 - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9EE} - D:\杀毒专用\DFVSX\DFVSX.exe (file missing)
O9 - Extra 'Tools' menuitem: 东方卫士 - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9EE} - D:\杀毒专用\DFVSX\DFVSX.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-195?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O9 - Extra 'Tools' menuitem: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-195?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdnns.dll
O11 - Options group: [!CNS]  网络实名
O11 - Options group: [CDNCLIENT]  中文上网
O11 - Options group: [TBH] QQ地址栏搜索
O16 - DPF: {1C960AA3-FAEE-11D0-9262-00A0243D2412} (TegoSoft SmartLoader ActiveX Control) - http://web.cy07.com/ActiveX/TegoLoad.cab
O16 - DPF: {40CF48AF-E75D-4B5E-97A7-A37D1F9110F0} - http://file1.hawa.cn/icuavchat.cab
O16 - DPF: {52DF16E3-6C4F-4B22-8BAF-09263E463B48} - http://zs.kingsoft.com/KOSInit.cab
O16 - DPF: {5DD731E6-D4F0-11D3-BE3F-00105A6FDA50} (V3ProX Control) - http://origin-www.ahn.com.cn/aspservice/plugin/myv3.cab
O16 - DPF: {6BB0C189-3676-4711-AA75-E2801D6B0E27} (AvlFTP Control) - http://benchmark.avl.com.cn/cab/avlFtp.cab
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {9BBD100C-E820-4930-9937-E8F3AA40E584} (DFVSScanFile Control) - http://antivirus3.sunv.com/dfvsolDown/dfvsol.cab
O16 - DPF: {ACFE8232-03C5-4AEC-AF5E-42B806724096} (KSHScan Control) - http://scan.kingsoft.com/scan/fangyi/KAllScan.CAB
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O16 - DPF: {DDA166FA-B3EA-4A3B-8EE2-4F552CDEEE81} (KATScan Control) - http://211.152.52.102/duba/antitrojan/update/OCX/KATScan.CAB
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O16 - DPF: {F138084D-84D7-48CD-BEA8-04772457516E} (VqqSpeedDlProxy Class) - http://218.85.138.27/vqqsdl1006.cab
O16 - DPF: {FC1DF328-F720-4FD3-98A4-2595A7356D7F} - http://219.133.38.112/toolbar/qq_sst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{09DFCAA9-91B2-4259-8BB3-4DD9A6EF46F8}: NameServer = 61.234.254.5,211.98.2.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ACD30AD-B019-40D7-801F-8863E9463B0A}: NameServer = 202.103.96.87 211.98.2.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{09DFCAA9-91B2-4259-8BB3-4DD9A6EF46F8}: NameServer = 61.234.254.5,211.98.2.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{09DFCAA9-91B2-4259-8BB3-4DD9A6EF46F8}: NameServer = 61.234.254.5,211.98.2.4
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\System32\mbprot.dll
O18 - Protocol: mbox - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\System32\mbprot.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - e:\rixing专用\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - E:\rixing专用\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\rixing专用\Rising\Rav\Ravmond.exe
gototop
 

建议卸载网络猪

运行Hijackthis,扫描结束后在下列选项前打上勾,然后选修复“Fix Checked”:

所有01项
O2 - BHO: IEMenu Class - {5D8B0CBC-6A8F-4495-96F0-631BAEEC93A6} - C:\WINDOWS\System32\hookie.dll
O2 - BHO: InsIII - {DDDE2452-AF9E-4577-AE6C-465DBCB54D49} - C:\WINDOWS\System32\brinsthd.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3}? - (no file)
O3 - Toolbar: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86}? - (no file)
O4 - HKLM\..\Run: [internet.exe] C:/WINDOWS/systems.hta
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {1C960AA3-FAEE-11D0-9262-00A0243D2412} (TegoSoft SmartLoader ActiveX Control) - http://web.cy07.com/ActiveX/TegoLoad.cab

显示隐藏文件

双击我的电脑--工具---文件夹选项--查看选项卡--单击选取"显示隐藏文件或文件夹"--清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示您确定更改时,单击“是”--单击“确定”。

然后找到如下文件并删除(如果有的话)。

C:\WINDOWS\System32\hookie.dll
C:\WINDOWS\System32\brinsthd.dll
C:/WINDOWS/systems.hta
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT