1   1  /  1  页   跳转

我被FREEPROD TOOLBAR 搞晕了

我被FREEPROD TOOLBAR 搞晕了

HijackThis_815汉化版扫描日志 V1.99.1
保存于      9:57:04, 日期 2006-2-6
操作系统:  Windows XP SP1 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\rundll32.exe
C:\WINDOWS\system32\inetdns.exe
C:\windows\System32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\windows\Explorer.EXE
C:\Program Files\rising\rfw\Rfw.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\windows\System32\ctfmon.exe
C:\windows\System32\conime.exe
D:\Program Files\HijackThis1991汉化版\HijackThis1991zww.exe

R3 - 默认的URLSearchHook丢失。用HijackThis修复
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: MFCOptimizeClass Object - {A6CEA0E7-6B4D-4CD9-9932-D85705CBC1A9} - C:\windows\System32\jkhhe.dll (file missing)
O2 - BHO: (no name) - {EA32FB3B-21C9-42cc-B8EF-01A9B28EDB0D} - C:\windows\System32\awtqp.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - IE工具栏增项: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\FLASHG~1\fgiebar.dll
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O4 - 启动项HKLM\\Run: [KAVPersonal50] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe /minimize
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [rfw] C:\Program Files\rising\rfw\Rfw.exe
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - 启动项HKLM\\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\System32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - D:\FlashGet@arong\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - D:\FlashGet@arong\jc_all.htm
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O17 - HKLM\System\CCS\Services\Tcpip\..\{36DD9A1C-92BB-41A3-B1F1-27C250E741A0}: NameServer = 218.74.122.74,218.74.122.75
O20 - Winlogon Notify: awtqp - C:\windows\SYSTEM32\awtqp.dll
O20 - Winlogon Notify: Dynamic Directory - C:\WINDOWS\system32\h8j4li1q18.dll
O20 - Winlogon Notify: jkhhe - C:\windows\System32\jkhhe.dll (file missing)
O20 - Winlogon Notify: pmnll - pmnll.dll (file missing)
O23 - NT 服务: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
这是日志请大侠帮我看看
现在不管我怎么杀重启后都会弹出FREEPROD 的安装程序MC-110-12-0000244.exe
最后编辑2006-02-06 13:38:12
分享到:
gototop
 

请帮我看看呀,急
gototop
 

结束C:\WINDOWS\system32\inetdns.exe进程

修复
R3 - 默认的URLSearchHook丢失。用HijackThis修复
O2 - BHO: (no name) - {EA32FB3B-21C9-42cc-B8EF-01A9B28EDB0D} - C:\windows\System32\awtqp.dll
O2 - BHO: MFCOptimizeClass Object - {A6CEA0E7-6B4D-4CD9-9932-D85705CBC1A9} - C:\windows\System32\jkhhe.dll (file missing)
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O20 - Winlogon Notify: awtqp - C:\windows\SYSTEM32\awtqp.dll
O20 - Winlogon Notify: Dynamic Directory - C:\WINDOWS\system32\h8j4li1q18.dll
O20 - Winlogon Notify: jkhhe - C:\windows\System32\jkhhe.dll (file missing)
O20 - Winlogon Notify: pmnll - pmnll.dll (file missing)

进入注册表
依次搜索jkhhe.dll和pmnll.dll
找到后全部删除

删除C:\WINDOWS\system32\inetdns.exe

以C:\windows\SYSTEM32\awtqp.dll为例:
http://www.atribune.org/downloads/VundoFix.exe
下载VundoFix.exe

双击VundoFix.exe,产生一个VundoFix文件夹

开机时按F8,可以停地按动F8,选择“safe mode”或“安全模式”进入

双击VundoFix文件夹中的KillVundo.bat,出现命令行提示窗口

按ENTER键

输入C:\windows\SYSTEM32\awtqp.dll

按ENTER键

输入C:\WINDOWS\SYSTEM32\pqtwa.*
<注意pqtwa拼写方向与awtqp相反>

按ENTER键

然后再用HIJACKTHIS修复
O20 - Winlogon Notify: awtqp - C:\windows\SYSTEM32\awtqp.dll

重启

<O20 - Winlogon Notify: Dynamic Directory - C:\WINDOWS\system32\h8j4li1q18.dll的操作类似>
gototop
 

谢谢指教,我试 试
gototop
 

行不行我现在还没有试,因为同事出去了,无法验证,不过我想知道怎样防止再次被劫持,另外还有两台也出现这种情况,不是因为去浏览了什么网页,而是通过网络传播过来的。
gototop
 

试试这几个工具:
http://forum.ikaka.com/topic.asp?board=67&artid=7485296  【推荐】Symantec的Trojan.Vundo Removal Tool
http://forum.ikaka.com/topic.asp?board=67&artid=7358637  【推荐】VundoFix简介
http://forum.ikaka.com/topic.asp?board=67&artid=7440953
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT