瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 跪求高手看一下我的日志,被劫持了!

1   1  /  1  页   跳转

跪求高手看一下我的日志,被劫持了!

跪求高手看一下我的日志,被劫持了!

Logfile of HijackThis v1.99.1
Scan saved at 17:26:11, on 2006-5-19
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\My Documents\新建文件夹 (2)\新建文件夹\HijackThis.exe

R3 - URLSearchHook: (no name) - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\新建文件夹\QQIEHelper.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - Startup: 腾讯QQ.LNK = ?
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\新建文件夹\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\新建文件夹\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\新建文件夹\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\新建文件夹\SendMMS.htm
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\cdnns.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O17 - HKLM\System\CCS\Services\Tcpip\..\{B01B1D3E-4C6B-4A20-A731-9DE437C4580F}: NameServer = 202.99.192.68,202.97.132.100
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Alerter - Unknown owner - C:\WINDOWS\System32\msnmsk.exe (file missing)
O23 - Service: ClipBook (ClipSrv) - Unknown owner - C:\WINDOWS\System32\winmsk.exe (file missing)
O23 - Service: vsw - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\vsy1\vsy1.exe (file missing)
O23 - Service: winmum - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mum1\mum1.exe (file missing)
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe (file missing)

最后编辑2006-05-19 19:36:29
分享到:
gototop
 

开始→运行→输入services.msc,打开“服务”→查找  Alerter,ClipBook (ClipSrv) ,vsw ,winmum→双击→启动类型→禁止→停止→应用→确定。禁止Alerter,ClipBook (ClipSrv) ,vsw ,winmum这4个服务
关闭所有浏览窗口以及一些不必要的程序
运行Hijackthis,扫描结束后在下列选项前打上勾,然后选"修复""
O23 - Service: Alerter - Unknown owner - C:\WINDOWS\System32\msnmsk.exe (file missing)
O23 - Service: ClipBook (ClipSrv) - Unknown owner - C:\WINDOWS\System32\winmsk.exe (file missing)
O23 - Service: vsw - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\vsy1\vsy1.exe (file missing)
O23 - Service: winmum - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mum1\mum1.exe (file missing)
双击我的电脑--工具---文件夹选项--查看--单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示您确定更改时,单击“是
删除

C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp文件夹里所有能删除的东东。
C:\WINDOWS\System32\msnmsk.exe
\WINDOWS\System32\winmsk.exe
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT