1   1  /  1  页   跳转

[求助] 高人来看看我中什么毒了

高人来看看我中什么毒了

杀软打不开,一进安全模式就蓝屏,资源管理器和桌面上的程序都打不开,自动弹网页,自己开的网页也自动关闭,还自动断网!
这是我用HijackThis软件弄出来的,高手看看怎么解决啊!




Logfile of HijackThis v1.99.1
Scan saved at 3:06:11, on 2008-12-22
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Tudou\飞速Tudou\TudouVa.exe
C:\WINDOWS\waavafqzwga.exe
C:\WINDOWS\W8HVV.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Thunder\Program\Thunder5.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\TDDOWNLOAD\flashget_1301_1.exe
D:\TDDOWNLOAD\flashget_1301_1.exe
D:\TDDOWNLOAD\HijackThis.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\W8HVV.exe
C:\WINDOWS\W8HVV.exe
C:\WINDOWS\W8HVV.exe
O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll
O2 - BHO: ThunderOnce Class - {8A7553E5-5146-11D5-A672-00B0D022E945} - C:\WINDOWS\system32\numftrxm.dll
O2 - BHO: SafeMon Class - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} - D:\安装\360\360safe\safemon\safemon.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ctfmon] ctfmon.exe
O4 - HKCU\..\Run: [QQ2009] "D:\Program Files\Tencent\QQ2009\Bin\QQ.exe" /background
O4 - Startup: 启动飞速土豆.lnk = ?
O4 - Global Startup: mxspsippr.lnk = C:\WINDOWS\zazmrytuho.exe
O4 - Global Startup: gwarzfxtasqkf.lnk = C:\WINDOWS\laqoyuc.exe
O4 - Global Startup: kzxymbyi.lnk = C:\WINDOWS\xdeusqdnol.exe
O4 - Global Startup: jxlgcqmuyw.lnk = C:\WINDOWS\waavafqzwga.exe
O4 - Global Startup: fkvfzhjgi.lnk = C:\WINDOWS\knkuxwnlyh.exe
O4 - Global Startup: jkqbeed.lnk = C:\WINDOWS\wofydbis.exe
O8 - Extra context menu item: 使用迅雷下载 - C:\Program Files\Thunder\Program\geturl.htm
O8 - Extra context menu item: 使用迅雷下载全部链接 - C:\Program Files\Thunder\Program\getallurl.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O9 - Extra button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra 'Tools' menuitem: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (EditCtrl Class) - https://img.alipay.com/download/2121/aliedit.cab
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - Protocol: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: BoBoTurbo - Unknown owner - C:\WINDOWS\system32\BoBoTurbo\BoBoTurbo.exe (file missing)
O23 - Service: zfrfty (nrgmdtar) - Unknown owner - C:\WINDOWS\system32\nrgmdtar.exe
O23 - Service: krtthcpv (qeibjxlthk) - Unknown owner - C:\WINDOWS\system32\qeibjxlthk.exe (file missing)
O23 - Service: yoasfk (wofydbis) - Unknown owner - C:\WINDOWS\wofydbis.exe
O23 - Service: jtcylovm (zazmrytuho) - Unknown owner - C:\WINDOWS\zazmrytuho.exe (file missing)

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
分享到:
gototop
 

回复:高人来看看我中什么毒了

怎么没人来啊
gototop
 

回复:高人来看看我中什么毒了

一大堆毒

扫SRENG日志发这论坛来

下载最新版本的SRENG工具:http://www.kztechs.com/sreng/download.html
操作方法可以看这贴2楼:http://bbs.ikaka.com/showtopic-8442813.aspx

1 下载的是压缩包,必须解压缩后再运行。
2 运行SREng***.EXE
3 选择主界面左边的:智能扫描=》扫描=》保存报告
4 把报告保存后,将日志文件发这论坛来。

建议日志文件以附件形式发来
点击我这贴右下角的“引用”或最右下角的那个较大的“回复”然后就应该知道怎么发了。
请不要开新贴发日志,就原贴接贴发日志即可。
gototop
 

回复: 高人来看看我中什么毒了

报告

附件附件:

文件名:SREngLOG.log
下载次数:151
文件类型:application/octet-stream
文件大小:
上传时间:2008-12-22 20:09:31
描述:log

gototop
 

回复:高人来看看我中什么毒了

下载大蜘蛛
全盘查杀
ftp://ftp.drweb.com/pub/drweb/cureit/launch.exe
(慎重删除)

查完后再扫一份日志上来
gototop
 

回复:高人来看看我中什么毒了

大蜘蛛下下来以后说不是有效的应用程序,运行不了!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT