瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 高手请进....我电脑中木马了...55555555....

1   1  /  1  页   跳转

高手请进....我电脑中木马了...55555555....

高手请进....我电脑中木马了...55555555....

现在上传不了东西..也下载不了东西``还有好多小问题存在...5555..救命呀..

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      0:21:43, 日期 1980-1-30
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\RpcS.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\新建文件夹\Program\Thunder5.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.8472\GoogleToolbarNotifier.exe
D:\电驴\eMule\emule.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\TIMPlatform.exe
C:\WINDOWS\system32\SysExp.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Tencent\QQGame\QQGame.exe
C:\Program Files\Tencent\QQGame\QQGameDl.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\桌面\HijackThis1991汉化版\HijackThis1991zww.exe

R3 - URLSearchHook: Tencent SearchHook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\Adplus\SSAddr.dll (file missing)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,c:\WINDOWS\1008.exe
O2 - BHO: IEMonitor Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\Program Files\DeskAdTop\deskipn.dll (file missing)
O2 - BHO: ThunderBHO - {0C7C23EE-A848-485B-873C-0ED954731014} - D:\新建文件夹\ComDlls\XunLeiBHO_007.dll
O2 - BHO: 搜搜地址栏搜索 - {0C7C23EF-A848-485B-873C-0ED954731014} - (no file)
O2 - BHO: AdPopup - {11F09AFD-75AD-4E51-AB43-E09E9351CE16} - C:\Program Files\Common Files\CPUSH\cpush.dll
O2 - BHO: (no name) - {13B80B13-6D02-424C-88E4-5EABF0883CA0} - C:\WINDOWS\system32\mfwfavksohbjv.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: XTTBPos00 - {BBBE1C1A-89F7-4AF6-ABD1-1A1DE1C6962A} - C:\PROGRA~1\SOFATO~1\sofa.dll
O3 - IE工具栏增项: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - IE工具栏增项: sofa - {B7D3E479-CC68-42B5-A338-B5A0E057163B} - C:\Program Files\SofaToolbar\sofa.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - 启动项HKLM\\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - 启动项HKLM\\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - 启动项HKLM\\Run: [RTHDCPL] RTHDCPL.EXE
O4 - 启动项HKLM\\Run: [Alcmtr] ALCMTR.EXE
O4 - 启动项HKLM\\Run: [Thunder] "D:\新建文件夹\Thunder.exe" /s
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [ltnward] C:\WINDOWS\system32\ltnward.exe
O4 - 启动项HKLM\\Run: [KuGoo3] C:\Program Files\KuGoo3\KuGoo.exe
O4 - 启动项HKLM\\Run: [Picasa Media Detector] C:\Documents and Settings\Administrator\桌面\Popkart\Picasa2\PicasaMediaDetector.exe
O4 - 启动项HKLM\\Run: [sdafdsafds] D;]XJOEPXT]ufnq]266/fyf
O4 - 启动项HKLM\\Run: [sysExp] C:\WINDOWS\system32\SysExp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [bgswitch] C:\WINDOWS\system32\bgswitch.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.8472\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [eMuleAutoStart] D:\电驴\eMule\emule.exe -AutoStart
O4 - Startup: desktop.ini
O4 - Startup: palmOne Registration.lnk = C:\Program Files\palmOne\register.exe
O4 - Startup: QQ游戏启动加速程序.lnk = C:\Program Files\Tencent\QQGame\Accel.exe
O4 - Global Startup: desktop.ini
O4 - Global Startup: HotSync 管理器.lnk = C:\Program Files\palmOne\Hotsync.exe
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - D:\新建文件夹\Program\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - D:\新建文件夹\Program\getallurl.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - 浏览器额外的按钮: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\新建文件夹\Thunder.exe
O9 - 浏览器额外的“工具”菜单项: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\新建文件夹\Thunder.exe
O9 - 浏览器额外的按钮: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.tomatolei.com (file missing)
O9 - 浏览器额外的“工具”菜单项: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.tomatolei.com (file missing)
O9 - 浏览器额外的按钮: sofa - {B7D3E479-CC68-42B5-A338-B5A0E057163B} - C:\Program Files\SofaToolbar\sofa.dll
O9 - 浏览器额外的“工具”菜单项: sofa - {B7D3E479-CC68-42B5-A338-B5A0E057163B} - C:\Program Files\SofaToolbar\sofa.dll
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.tomatolei.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{E00C5962-4699-4EED-A94D-32EAD2093623}: NameServer = 202.96.134.133,202.96.128.166
O18 - 列举现有的协议: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\PROGRA~1\KuGoo3\InExtend\KUGOO3~1.OCX
O20 - Winlogon Notify: cryptimg - C:\WINDOWS\SYSTEM32\cryptimg.dll
O23 - NT 服务: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - NT 服务: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - NT 服务: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - NT 服务: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - NT 服务: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - NT 服务: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - NT 服务: SysTem32(IIS) - Unknown owner - C:\WINDOWS\system8672.exe
O23 - NT 服务: Provisioning Transaction Service (ttt_13) - Unknown owner - C:\WINDOWS\system32\win.exe

最后编辑2007-01-30 01:19:06
分享到:
gototop
 

用HIJACKTHIS修复以下项:

O23 - NT 服务: SysTem32(IIS) - Unknown owner - C:\WINDOWS\system8672.exe
O23 - NT 服务: Provisioning Transaction Service (ttt_13) - Unknown owner - C:\WINDOWS\system32\win.exe
修复后请到安全模式下删除这些文件
gototop
 

问题有点多,我再看看
gototop
 

好的..谢谢..
gototop
 

修复以下项:C:\WINDOWS\system32\RpcS.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.8472\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe  此项为REAL的驻留程序,建议修复

R3 - URLSearchHook: Tencent SearchHook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\Adplus\SSAddr.dll (file missing)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,c:\WINDOWS\1008.exe  此项若无法修复,进入注册表将userinit.exe后面的删除即可
O2 - BHO: IEMonitor Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\Program Files\DeskAdTop\deskipn.dll (file missing)
O2 - BHO: 搜搜地址栏搜索 - {0C7C23EF-A848-485B-873C-0ED954731014} - (no file)
O2 - BHO: (no name) - {13B80B13-6D02-424C-88E4-5EABF0883CA0} - C:\WINDOWS\system32\mfwfavksohbjv.dll

O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: XTTBPos00 - {BBBE1C1A-89F7-4AF6-ABD1-1A1DE1C6962A} - C:\PROGRA~1\SOFATO~1\sofa.dll
O3 - IE工具栏增项: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - IE工具栏增项: sofa - {B7D3E479-CC68-42B5-A338-B5A0E057163B} - C:\Program Files\SofaToolbar\sofa.dll

O4 - 启动项HKLM\\Run: [ltnward] C:\WINDOWS\system32\ltnward.exe

O4 - 启动项HKLM\\Run: [sdafdsafds] D;]XJOEPXT]ufnq]266/fyf
O4 - 启动项HKLM\\Run: [sysExp] C:\WINDOWS\system32\SysExp.exe 
O4 - HKCU\..\Run: [bgswitch] C:\WINDOWS\system32\bgswitch.exe 
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.8472\GoogleToolbarNotifier.exe

O4 - Startup: desktop.ini

O9 - 浏览器额外的按钮: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.tomatolei.com (file missing)
O9 - 浏览器额外的“工具”菜单项: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.tomatolei.com (file missing)
O9 - 浏览器额外的按钮: sofa - {B7D3E479-CC68-42B5-A338-B5A0E057163B} - C:\Program Files\SofaToolbar\sofa.dll
O9 - 浏览器额外的“工具”菜单项: sofa - {B7D3E479-CC68-42B5-A338-B5A0E057163B} - C:\Program Files\SofaToolbar\sofa.dll

O14 - IERESET.INF: START_PAGE_URL=http://www.tomatolei.com

gototop
 

建议下个卡卡清除下插件,没用的插件太多了
gototop
 

刚才没注意,第一次的有几个误发了~~
现在已经更正~~
gototop
 

不是吧!!!..我都修复了..怎么半..
gototop
 

误修复的那几项请重新用安装程序修复下即可~~
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT