瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 笔记本出现异常,浏览器自动关闭 附日志

1   1  /  1  页   跳转

[求助] 笔记本出现异常,浏览器自动关闭 附日志

笔记本出现异常,浏览器自动关闭 附日志

笔记本用    apple浏览器  上网,5分钟左右自动退出。用nod32全盘扫描,没有发现病毒。请各位朋友帮忙看看日志,是哪里出现问题了。  小弟在此谢过!


日志:
日志文件 Trend Micro HijackThis v 2.0.2
日志保存时间: 21:53:33,2009-2-5
操作系统: Windows XP SP2 (WinNT 5.01.2600)
IE版本: Internet Explorer v6.00 SP2 (6.00.2900.2180)
启动模式: 正常
正在运行的进程:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\360Safebox\safeboxTray.exe
D:\Program Files\360safe\safemon\360tray.exe
C:\Program Files\Rising\AntiSpyware\rstray.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\windows\system32\nvsvc32.exe
C:\WINDOWS\system32\shadow\ShadowService.exe
C:\windows\system32\svchost.exe
C:\Program Files\Rising\AntiSpyware\knownsvr.exe
C:\windows\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\葛文君\LOCALS~1\Temp\Rar$EX00.531\HijackThis.exe
O1 - Hosts: <html>
O1 - Hosts: <head>
O1 - Hosts: <script>
O1 - Hosts: $(document).ready(function(){
O1 - Hosts: if(point>0)
O1 - Hosts: aurl=location.href.substr(point+5,location.href.length);
O1 - Hosts: avurl=location.href;
O1 - Hosts: });
O1 - Hosts: {
O1 - Hosts: {
O1 - Hosts: alert("请输入要到达的网址。");
O1 - Hosts: return;
O1 - Hosts: }
O1 - Hosts: window.location.href=url;
O1 - Hosts: }
O1 - Hosts: {
O1 - Hosts: window.document.getElementById("count").src="http://218.57.242.44/adv/count/?type="+pram
O1 - Hosts: }
O1 - Hosts: </script>
O1 - Hosts: //
O1 - Hosts: //
O1 - Hosts: </script>
O1 - Hosts: try
O1 - Hosts: {
O1 - Hosts: if(parent.location.href)
O1 - Hosts: {
O1 - Hosts: }
O1 - Hosts: }
O1 - Hosts: catch(e)
O1 - Hosts: {
O1 - Hosts: //下面可以做相应的处理,如转向其他页面
O1 - Hosts: //alert("被人加载了");
O1 - Hosts: }
O1 - Hosts: </script>
O1 - Hosts: <title>抱歉,您输入的网页目前无法访问</title>
O1 - Hosts: </head>
O1 - Hosts: <body>
O1 - Hosts: <tr>
O1 - Hosts: <tr>
O1 - Hosts: {
O1 - Hosts: }
O1 - Hosts: document.write("无法显示该网页")
O1 - Hosts: }
O1 - Hosts: <tr>
O1 - Hosts: </tr>
O1 - Hosts: <tr>
O1 - Hosts: <tr>
O1 - Hosts: <tr>
O1 - Hosts: </input></td>
O1 - Hosts: </tr>
O1 - Hosts: </form>
O1 - Hosts: </table></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr>
O1 - Hosts: </form></td>
O1 - Hosts: </tr>
O1 - Hosts: </table></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr>
O1 - Hosts: </tr>
O1 - Hosts: <tr>
O1 - Hosts: </tr>
O1 - Hosts: </table></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: <tr>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </div>
O1 - Hosts: </div>
O1 - Hosts: </body>
O1 - Hosts: </html>
O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - F:\迅雷\ComDlls\TDAtOnce_Now.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - F:\迅雷\ComDlls\xunleiBHO_Now.dll
O2 - BHO: 卡卡上网安全助手 - {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} - C:\windows\system32\UrlFilter.dll
O2 - BHO: SafeMon Class - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} - D:\Program Files\360safe\safemon\safemon.dll
O4 - HKLM\..\Run: [360Safebox] "C:\Program Files\360Safebox\safeboxTray.exe" /r
O4 - HKLM\..\Run: [360Safetray] D:\Program Files\360safe\safemon\360tray.exe /start
O4 - HKLM\..\Run: [NvCplDaemon] ; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [hpWirelessAssistant] ; %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [NvMediaCenter] ; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] ; nwiz.exe /install
O4 - HKLM\..\Run: [runeip] "C:\Program Files\Rising\AntiSpyware\rstray.exe" /startup
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\EsetACT\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [bgswitch] C:\WINDOWS\system32\bgswitch.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [bgswitch] C:\WINDOWS\system32\bgswitch.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - 扩展右键菜单项: 使用迅雷下载 - F:\迅雷\Program\GetUrl.htm
O8 - 扩展右键菜单项: 使用迅雷下载全部链接 - F:\迅雷\Program\GetAllUrl.htm
O8 - 扩展右键菜单项: 导出到 Microsoft Excel(&X) - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - 扩展右键菜单项: 添加到QQ表情 - D:\Program Files\Tencent\AddEmotion.htm
O9 - 额外的按钮: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - F:\迅雷\Thunder.exe
O9 - 额外的“工具”菜单项目: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - F:\迅雷\Thunder.exe
O9 - 额外的按钮: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.tomatolei.com(文件不存在)
O9 - 额外的“工具”菜单项目: 番茄花园 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.tomatolei.com(文件不存在)
O9 - 额外的按钮: 鱼鱼软件 - {6096E38F-5AC3-4391-8EC4-75DFA92FB32F} - http://www.cfishsoft.com(文件不存在)
O9 - 额外的按钮: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - 额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 额外的“工具”菜单项目: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: kmon.dll
O20 - Winlogon Notify: PsNotify - PsNotify.dll(文件不存在)
O23 - NT 服务:  Bonjour 服务 (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - NT 服务:  Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - NT 服务:  Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - NT 服务:  FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - NT 服务:  NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - NT 服务:  Shadow System Service (ShadowSystemService) - Unknown owner - C:\WINDOWS\system32\shadow\ShadowService.exe
--
文件结束 - 6395 字节

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
分享到:
gototop
 

回复:笔记本出现异常,浏览器自动关闭 附日志

修复
O1 - Hosts: <html>
O1 - Hosts: <head>
O1 - Hosts: <script>
O1 - Hosts: $(document).ready(function(){
O1 - Hosts: if(point>0)
O1 - Hosts: aurl=location.href.substr(point+5,location.href.length);
O1 - Hosts: avurl=location.href;
O1 - Hosts: });
O1 - Hosts: {
O1 - Hosts: {
O1 - Hosts: alert("请输入要到达的网址。");
O1 - Hosts: return;
O1 - Hosts: }
O1 - Hosts: window.location.href=url;
O1 - Hosts: }
O1 - Hosts: {
O1 - Hosts: window.document.getElementById("count").src="http://218.57.242.44/adv/count/?type="+pram
O1 - Hosts: }
O1 - Hosts: </script>
O1 - Hosts: //
O1 - Hosts: //
O1 - Hosts: </script>
O1 - Hosts: try
O1 - Hosts: {
O1 - Hosts: if(parent.location.href)
O1 - Hosts: {
O1 - Hosts: }
O1 - Hosts: }
O1 - Hosts: catch(e)
O1 - Hosts: {
O1 - Hosts: //下面可以做相应的处理,如转向其他页面
O1 - Hosts: //alert("被人加载了");
O1 - Hosts: }
O1 - Hosts: </script>
O1 - Hosts: <title>抱歉,您输入的网页目前无法访问</title>
O1 - Hosts: </head>
O1 - Hosts: <body>
O1 - Hosts: <tr>
O1 - Hosts: <tr>
O1 - Hosts: {
O1 - Hosts: }
O1 - Hosts: document.write("无法显示该网页")
O1 - Hosts: }
O1 - Hosts: <tr>
O1 - Hosts: </tr>
O1 - Hosts: <tr>
O1 - Hosts: <tr>
O1 - Hosts: <tr>
O1 - Hosts: </input></td>
O1 - Hosts: </tr>
O1 - Hosts: </form>
O1 - Hosts: </table></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr>
O1 - Hosts: </form></td>
O1 - Hosts: </tr>
O1 - Hosts: </table></td>
O1 - Hosts: </tr>
O1 - Hosts: <tr>
O1 - Hosts: </tr>
O1 - Hosts: <tr>
O1 - Hosts: </tr>
O1 - Hosts: </table></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: <tr>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </div>
O1 - Hosts: </div>
O1 - Hosts: </body>
O1 - Hosts: </html>

对个人来讲,统计,仪器,高速的计算机可以让人们得到大量充裕的时间。
这个社会中,更不可缺的是具备现代化的管理经验。
gototop
 

回复:笔记本出现异常,浏览器自动关闭 附日志

谢谢 ,已按指点修复,试用下 看还有没有问题。
gototop
 

回复:笔记本出现异常,浏览器自动关闭 附日志


对个人来讲,统计,仪器,高速的计算机可以让人们得到大量充裕的时间。
这个社会中,更不可缺的是具备现代化的管理经验。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT