瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】今天早上开始访问网络就会有异常连接!但是我查不出来!

12   1  /  2  页   跳转

【求助】今天早上开始访问网络就会有异常连接!但是我查不出来!

【求助】今天早上开始访问网络就会有异常连接!但是我查不出来!

今天早上用Maxthon浏览网页,每启动一个页面就会拦截数个连接,可是我查不出来任何病毒或木马!请大家帮帮忙!

附件附件:

下载次数:0
文件类型:image/pjpeg
文件大小:
上传时间:2005-9-21 15:22:20
描述:



最后编辑2005-09-22 20:29:35
分享到:
gototop
 

后来我尝试努力查找,让这个连接通过,结果是连接到一个木马网页,但是为何本机查不出来有任何异常的进程或程序?

附件附件:

下载次数:0
文件类型:image/pjpeg
文件大小:
上传时间:2005-9-21 15:24:55
描述:



gototop
 

斑竹请帮忙啊!我实在没办法了!
gototop
 

【回复“Biosea”的帖子】
先用HijackThis1.99.1扫个日志贴上来吧。或许能发现有用线索。
gototop
 

引用:
【Biosea的贴子】斑竹请帮忙啊!我实在没办法了!
...........................
那个是IE的地址!很正常!
gototop
 

那第2张图的连接怎么解释?原来不会这样的啊.....
gototop
 

引用:
【baohe的贴子】【回复“Biosea”的帖子】
先用HijackThis1.99.1扫个日志贴上来吧。或许能发现有用线索。
...........................


斑竹,这是扫描的结果,请帮我看看吧!

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      20:19:42, 日期 2005-9-21
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\RISING\RAV\Ravmond.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
D:\RISING\RAV\RavStub.exe
d:\rising\rfw\rfwsrv.exe
D:\cFosSpeed\spd.exe
d:\CPUCooL\CooLSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\RISING\RAV\CCENTER.EXE
C:\WINDOWS\system32\svchost.exe
D:\RISING\RAV\RAVTIMER.EXE
D:\RISING\RAV\RAVMON.EXE
D:\cFosSpeed\cFosSpeed.exe
C:\WINDOWS\vsnppro.exe
D:\Radeon Omega Drivers\v2.6.53\ATI Tray Tools\atitray.exe
C:\WINDOWS\system32\ctfmon.exe
d:\rising\rfw\RfwMain.exe
D:\CPUCooL\CPUCooL.exe
D:\Maxthon\Maxthon.exe
D:\FlashGet\flashget.exe
H:\Downloads\2535952005811174944\HijackThis1991zww.exe

O1 - Hosts: 202.115.160.7 www.swust.edu.cn
O1 - Hosts: 61.155.39.170 www.verycd.com
O1 - Hosts: 218.206.122.42 www.onlinedown.net
O1 - Hosts: 219.146.240.243 www3.skycn.com
O1 - Hosts: 218.5.72.119 bbs6.cnxp.com
O1 - Hosts: 61.172.200.244 www.169s.com
O1 - Hosts: 218.104.136.227 www.fangdown.com
O1 - Hosts: 222.174.146.188 down.cn366.com
O1 - Hosts: 202.101.43.16 www.crsky.com
O1 - Hosts: 61.139.77.115 www.rc114.com
O1 - Hosts: 61.129.48.158 www.51job.com
O1 - Hosts: 61.145.112.78 www.emu-zone.org
O1 - Hosts: 222.77.177.58 www.17173.com
O1 - Hosts: 222.77.177.57 lineage2.17173.com
O1 - Hosts: 218.30.66.62 www.lineage2.com.cn
O1 - Hosts: 219.136.244.111 www.pcgames.com.cn
O1 - Hosts: 210.51.189.54 www.sunnyinteractive.com.cn
O1 - Hosts: 61.129.55.238 patch.ali213.net
O1 - Hosts: 220.164.140.213 www.plro.net
O1 - Hosts: 222.77.177.58 wow.17173.com
O1 - Hosts: 218.30.21.161 www.comicer.com
O1 - Hosts: 219.129.149.166 comic.hyd8.com
O1 - Hosts: 218.30.100.115 www.jojohot.com
O1 - Hosts: 220.181.26.209 alumni.chinaren.com
O1 - Hosts: 218.201.41.22 www.cniti.com
O1 - Hosts: 219.239.94.166 www.zol.com.cn
O1 - Hosts: 202.205.10.1 www.edu.cn
O1 - Hosts: 61.183.15.95 www.mop.com
O1 - Hosts: 219.238.233.202 www.rising.com.cn
O1 - Hosts: 202.102.249.40 www.mydrivers.com
O1 - Hosts: 192.67.198.6 bbs.tt1069.com
O1 - Hosts: 61.129.72.113 www.luosoft.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\FlashGet\jccatch.dll
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\FlashGet\fgiebar.dll
O3 - IE工具栏增项: 卡卡安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - 启动项HKLM\\Run: [RavTimer] D:\RISING\RAV\RAVTIMER.EXE
O4 - 启动项HKLM\\Run: [RavMon] D:\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - 启动项HKLM\\Run: [RfwMain] "D:\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [QuickTime Task] "D:\QuickTime\qttask.exe" -atboottime
O4 - 启动项HKLM\\Run: [cFosSpeed] D:\cFosSpeed\cFosSpeed.exe
O4 - 启动项HKLM\\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - 启动项HKLM\\Run: [snppro] C:\WINDOWS\vsnppro.exe
O4 - 启动项HKLM\\RunOnce: [RavStub] "D:\RISING\RAV\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [AtiTrayTools] "D:\Radeon Omega Drivers\v2.6.53\ATI Tray Tools\atitray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: CPUCooL.lnk = D:\CPUCooL\CPUCooL.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - D:\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - D:\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://D:\Microsoft Office\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\Tencent\AddEmotion.htm
O9 - 浏览器额外的按钮: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_08\bin\npjpi142_08.dll
O9 - 浏览器额外的“工具”菜单项: Sun Java 控制台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_08\bin\npjpi142_08.dll
O9 - 浏览器额外的按钮: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Microsoft Office\OFFICE11\REFIEBAR.DLL
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\FlashGet\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\FlashGet\flashget.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{9BB21ECF-902A-4079-AD06-0E495C55A04D}: NameServer = 61.139.2.69 202.98.96.68
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSN Messenger\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: APIHookDll.dll
O23 - NT 服务: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - NT 服务: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - NT 服务: cFosSpeed System Service (cFosSpeedS) - Unknown owner - D:\cFosSpeed\spd.exe" -service (file missing)
O23 - NT 服务: CPUCooLServer Service (CPUCooLServer) - Unknown owner - d:\CPUCooL\CooLSrv.exe
O23 - NT 服务: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - NT 服务: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - d:\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - D:\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\RISING\RAV\Ravmond.exe
gototop
 

顶,斑竹麻烦看看吧,不行了...
gototop
 

终止进程:
C:\WINDOWS\vsnppro.exe

修复:
O1 - Hosts: 202.115.160.7 www.swust.edu.cn
O1 - Hosts: 61.155.39.170 www.verycd.com
O1 - Hosts: 218.206.122.42 www.onlinedown.net
O1 - Hosts: 219.146.240.243 www3.skycn.com
O1 - Hosts: 218.5.72.119 bbs6.cnxp.com
O1 - Hosts: 61.172.200.244 www.169s.com
O1 - Hosts: 218.104.136.227 www.fangdown.com
O1 - Hosts: 222.174.146.188 down.cn366.com
O1 - Hosts: 202.101.43.16 www.crsky.com
O1 - Hosts: 61.139.77.115 www.rc114.com
O1 - Hosts: 61.129.48.158 www.51job.com
O1 - Hosts: 61.145.112.78 www.emu-zone.org
O1 - Hosts: 222.77.177.58 www.17173.com
O1 - Hosts: 222.77.177.57 lineage2.17173.com
O1 - Hosts: 218.30.66.62 www.lineage2.com.cn
O1 - Hosts: 219.136.244.111 www.pcgames.com.cn
O1 - Hosts: 210.51.189.54 www.sunnyinteractive.com.cn
O1 - Hosts: 61.129.55.238 patch.ali213.net
O1 - Hosts: 220.164.140.213 www.plro.net
O1 - Hosts: 222.77.177.58 wow.17173.com
O1 - Hosts: 218.30.21.161 www.comicer.com
O1 - Hosts: 219.129.149.166 comic.hyd8.com
O1 - Hosts: 218.30.100.115 www.jojohot.com
O1 - Hosts: 220.181.26.209 alumni.chinaren.com
O1 - Hosts: 218.201.41.22 www.cniti.com
O1 - Hosts: 219.239.94.166 www.zol.com.cn
O1 - Hosts: 202.205.10.1 www.edu.cn
O1 - Hosts: 61.183.15.95 www.mop.com
O1 - Hosts: 219.238.233.202 www.rising.com.cn
O1 - Hosts: 202.102.249.40 www.mydrivers.com
O1 - Hosts: 192.67.198.6 bbs.tt1069.com
O1 - Hosts: 61.129.72.113 www.luosoft.com
O4 - 启动项HKLM\\Run: [snppro] C:\WINDOWS\vsnppro.exe

然后删除C:\WINDOWS\vsnppro.exe
gototop
 

vsnppro.exe是我的摄像头的驱动的自启动项.....

我重装后没装它还是一样...我怀疑是ADSL Modem出问题了?有可能吗?我格式化重装后按原有的步骤安装基本的补丁和驱动,然后装瑞星上网,结果一样.....期间不可能中病毒啊!
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT