现象,1>桌面每次开机自动生成三个网页2>自动弹IE出现免费点歌等网页3>自动弹出C:\Documents and Settings\Administrator并且里面生成ntuser.dat.LOG和NTUSER.DAT
log如下
Logfile of HijackThis v1.99.1
Scan saved at 16:03:58, on 2006-10-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\taskswitch.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\CNNIC\Cdn\cdnup.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
D:\setup\hijackthis\HijackThis.exe
R3 - URLSearchHook: (no name) - {BD328E49-38AB-42CB-8EEA-73AA4CD2A6FD} - (no file)
R3 - URLSearchHook: SrchHook Class - {EED92A43-CFCE-4548-BD73-B0A405470ED5} - C:\PROGRA~1\CNNIC\Cdn\iesrch.dll
O1 - Hosts: 222.189.228.4 www.hao123.com
O1 - Hosts: 222.189.228.4 www.7b.com.cn
O1 - Hosts: 222.189.228.4 www.7939.com
O1 - Hosts: 222.189.228.4 www.360safe.com
O1 - Hosts: 222.189.228.4 360safe.com
O1 - Hosts: 222.189.228.4 update.360safe.com
O1 - Hosts: 222.189.228.4 dl.360safe.com
O1 - Hosts: 222.189.228.4 bbs.360safe.com
O1 - Hosts: 222.189.228.4 count16.51yes.com
O1 - Hosts: 222.189.228.4 count18.51yes.com
O1 - Hosts: 222.189.228.4 count20.51yes.com
O1 - Hosts: 222.189.228.4 www.btbaicai.com
O1 - Hosts: 222.189.228.4 btbaicai.com
O1 - Hosts: 222.189.228.4 www.pctutu.com
O1 - Hosts: 222.189.228.4 www.7322.com
O1 - Hosts: 222.189.228.4 www.5566.net
O1 - Hosts: 222.189.228.4 www.9991.com
O1 - Hosts: 222.189.228.4 forum.ikaka.com
O1 - Hosts: 222.189.228.4 www.ikaka.com
O1 - Hosts: 222.189.228.4 www.piaoxue.com
O1 - Hosts: 222.189.228.4 forum.jiangmin.com
O1 - Hosts: 222.189.228.4 update.jiangmin.com
O1 - Hosts: 222.189.228.4 post.baidu.com
O1 - Hosts: 222.189.228.4 zhidao.baidu.com
O1 - Hosts: 222.189.228.4 update.rising.com.cn
O1 - Hosts: 222.189.228.4 online.rising.com.cn
O1 - Hosts: 222.189.228.4 dl.pconline.com.cn
O1 - Hosts: 222.189.228.4 space.uwants.com
O1 - Hosts: 222.189.228.4 www.pcav.cn
O1 - Hosts: 222.189.228.4 mopery.hits.io
O1 - Hosts: 222.189.228.4 www.goodmv.cn
O1 - Hosts: 222.189.228.4 www.5566.net
O1 - Hosts: 222.189.228.4 www.piaoxue.com
O1 - Hosts: 222.189.228.4 www.luosoft.com
O1 - Hosts: 222.189.228.4 luosoft.com
O1 - Hosts: 222.189.228.4 www.7255.com
O1 - Hosts: 222.189.228.4 dl.pconline.com.cn
O1 - Hosts: 222.189.228.4 www.spjoy.com
O1 - Hosts: 222.189.228.4 c01.caishow.com
O1 - Hosts: 222.189.228.4 c02.caishow.com
O1 - Hosts: 222.189.228.4 c03.caishow.com
O1 - Hosts: 222.189.228.4 c04.caishow.com
O1 - Hosts: 222.189.228.4 www.caishow.com
O1 - Hosts: 222.189.228.4 union.caishow.com
O1 - Hosts: 222.189.228.4 ad01.a8.com
O1 - Hosts: 222.189.228.4 ad02.a8.com
O1 - Hosts: 222.189.228.4 sg.a8.com
O1 - Hosts: 222.189.228.4 www.adanywhere.cn
O1 - Hosts: 222.189.228.4 ip.adanywhere.cn
O1 - Hosts: 222.189.228.4 ip1.adanywhere.cn
O1 - Hosts: 222.189.228.4 ip2.adanywhere.cn
O1 - Hosts: 222.189.228.4 www.bannerbox.cn
O1 - Hosts: 222.189.228.4 www.caiqiyue.com
O1 - Hosts: 222.189.228.4 toolsbar.kuaiso.com
O1 - Hosts: 222.189.228.4 www.kuaiso.com
O1 - Hosts: 222.189.228.4 www.2t2t.cn
O1 - Hosts: 222.189.228.4 3.a.kal.cn
O1 - Hosts: 222.189.228.4 ip.alexaanywhere.com
O1 - Hosts: 222.189.228.4 go.ipcenter.cn
O1 - Hosts: 222.189.228.4 www.2yin.cn
O1 - Hosts: 222.189.228.4 wwww.systeel.com.cn
O1 - Hosts: 222.189.228.4 go.baibaoxiang.cn
O1 - Hosts: 222.189.228.4 www.gao58.com
O1 - Hosts: 222.189.228.4 www.2tu.cn
O1 - Hosts: 222.189.228.4 www.91tu.cn
O1 - Hosts: 222.189.228.4 www.haotop.com
O1 - Hosts: 222.189.228.4 news01.virussky.com
O1 - Hosts: 222.189.228.4 news02.virussky.com
O1 - Hosts: 222.189.228.4 news03.virussky.com
O1 - Hosts: 222.189.228.4 news04.virussky.com
O1 - Hosts: 222.189.228.4 news40.virussky.com
O1 - Hosts: 222.189.228.4 news41.virussky.com
O1 - Hosts: 222.189.228.4 news42.virussky.com
O1 - Hosts: 222.189.228.4 www.an85.com
O1 - Hosts: 222.189.228.4 an85.com
O1 - Hosts: 222.189.228.4 www.ycdy.com
O1 - Hosts: 222.189.228.4 ycdy.com
O1 - Hosts: 222.189.228.4 down.virussky.com
O1 - Hosts: 222.189.228.4 update.virussky.com
O1 - Hosts: 222.189.228.4 www.maipao.com
O1 - Hosts: 222.189.228.4 www.sina-baidu.com
O1 - Hosts: 222.189.228.4 www.maohehe.com
O1 - Hosts: 222.189.228.4 www.1717kan.cn
O1 - Hosts: 222.189.228.4 www.feixue.net
O1 - Hosts: 222.189.228.4 www.xingkongitv.com
O1 - Hosts: 222.189.228.4 about-blank.cc
O1 - Hosts: 222.189.228.4 www.xfkz.com
O1 - Hosts: 222.189.228.4 xfkz.com
O1 - Hosts: 222.189.228.4 www.365tan.com
O1 - Hosts: 222.189.228.4 cg.9e3.com
O1 - Hosts: 222.189.228.4 www.qqplayer.net
O1 - Hosts: 222.189.228.4 www.sosok.com
O1 - Hosts: 222.189.228.4 img.zhangxiu.com
O1 - Hosts: 222.189.228.4 www.okeaa.com
O1 - Hosts: 222.189.228.4 www.winopen.cn
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v14.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\qq\QQIEHelper.dll
O2 - BHO: XBTP03129 - {71E000D6-C63D-4d95-85A0-76DF890982A3} - C:\PROGRA~1\SEARCH~1\SEARCH~1.DLL (file missing)
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll
O2 - BHO: (no name) - {AF3876B1-7D5F-4F0F-BECA-A6324D125A48} - C:\WINDOWS\system32\ATIDEMGREDEM.dll
O2 - BHO: IEHlprObj Class - {EAACBF9E-4B91-45FF-93ED-B297093951EA} - C:\Program Files\Internet Explorer\PLUGINS\Flash_Player.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [A] C:\WINDOWS\system32\rundll32.exe mont.dll s
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [DAEMON Tools-2052] ; "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [e-Border Credential] ; C:\Program Files\Permeo\e-Border Driver\s5credmgr.exe
O4 - HKLM\..\Run: [SoundMan] ; SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\qq\AddEmotion.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://tomatolei.com (file missing)
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\qq\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\qq\QQIEHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files\permeo\e-border driver\s5spi.dll
O10 - Unknown file in Winsock LSP: c:\program files\permeo\e-border driver\s5spi.dll
O10 - Unknown file in Winsock LSP: c:\program files\permeo\e-border driver\s5spi.dll
O10 - Unknown file in Winsock LSP: c:\program files\permeo\e-border driver\s5spi.dll
O10 - Unknown file in Winsock LSP: c:\program files\permeo\e-border driver\s5spi.dll
O10 - Unknown file in Winsock LSP: c:\program files\permeo\e-border driver\s5spi.dll
O11 - Options group: [CDNCLIENT] 中文上网
O14 - IERESET.INF: START_PAGE_URL=http://tomatolei.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{2AF2D889-F0C3-48B1-AF3A-F9903A7BC46E}: NameServer = 202.112.14.151,202.112.14.161
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: SVCHOST - Unknown owner - C:\WINDOWS\SVCHOST.EXE (file missing)