瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 请大家访问防毒网论坛,申请斑竹

1   1  /  1  页   跳转

请大家访问防毒网论坛,申请斑竹

请大家访问防毒网论坛,申请斑竹

电脑防毒网:http://www.fangdu.net
电脑防毒网论坛: http://www.fangdu.net/bbs

现在接受斑竹申请当中。



------------
电脑安全吗?防毒网保护你。
http://www.fangdu.net
最后编辑2005-07-31 17:04:38
分享到:
gototop
 

可以吗。帮我看年无的日志。都有什么病毒这么杀死。

Logfile of HijackThis v1.99.1
Scan saved at 16:42:37, on 2005-7-31
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\NTdhcp.exe
C:\WINDOWS\system32\ctfmon.exe
G:\系统工具\瑞星\HijackThis.exe

O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v4.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - F:\网络游戏\QQ\QQ2005\QQIEHelper.dll
O2 - BHO: Router Layer - {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} - C:\WINDOWS\System32\aclayer.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SysExplr] rem G:\应用工具\播放器\豪杰超级解霸 3000 英雄版\豪杰3000\SYSEXPLR.EXE
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [NTdhcp] C:\WINDOWS\system32\NTdhcp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: 腾讯QQ.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: 反向链接 - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\网络游戏\QQ\QQ2005\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\网络游戏\QQ\QQ2005\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\网络游戏\QQ\QQ2005\SendMMS.htm
O8 - Extra context menu item: 类似网页 - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: 缓存的网页快照 - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\网络游戏\QQ\QQ2005\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\网络游戏\QQ\QQ2005\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - F:\网络游戏\QQ\QQ2005\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - F:\网络游戏\QQ\QQ2005\QQIEHelper.dll
O9 - Extra button: 易趣购物 - {EE60714F-AC19-427e-861A-FD60ABDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=1 (file missing)
O9 - Extra 'Tools' menuitem: 易趣购物 - {EE60714F-AC19-427e-861A-FD60ABDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=1 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Frank Server (Frank) - Unknown owner - C:\WINDOWS\Bin_Server.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

gototop
 

C:\WINDOWS\system32\NTdhcp.exe
O2 - BHO: Router Layer - {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} - C:\WINDOWS\System32\aclayer.dll
  O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
  O4 - HKLM\..\Run: [NTdhcp] C:\WINDOWS\system32\NTdhcp.exe 
O9 - Extra 'Tools' menuitem: 易趣购物 - {EE60714F-AC19-427e-861A-FD60ABDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=1 (file missing)
O23 - Service: Frank Server (Frank) - Unknown owner - C:\WINDOWS\Bin_Server.exe
建议在安全模式下修复以上,删除对应文件

NTdhcp.exe
这个是QQ木马.今天在论坛上拿到了这个样本,自己亲身感受了下,瑞星查不到.在注册表清理完后,在C:\!submit里面NTdhcp.exe删除他
不知道你有没有中灰鸽子.023项很可疑
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT