1   1  /  1  页   跳转

求助中毒了

求助中毒了

HijackThis_815汉化版扫描日志 V1.99.1
保存于 9:16:26, 日期 2005-10-15
操作系统: Windows XP SP1 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
D:\PROGRAM FILES\瑞星\杀毒\RAV\RAV\Ravmond.exe
d:\program files\瑞星\防火墙\新建文件夹\rising\rfw\rfwsrv.exe
D:\PROGRAM FILES\瑞星\杀毒\RAV\RAV\RavStub.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
D:\PROGRAM FILES\瑞星\杀毒\RAV\RAV\CCENTER.EXE
C:\WINDOWS.0\Explorer.EXE
d:\program files\瑞星\防火墙\新建文件夹\rising\rfw\RfwMain.exe
C:\WINDOWS.0\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
D:\PROGRA~1\瑞星\杀毒\RAV\RAV\RAVTIMER.EXE
D:\PROGRA~1\瑞星\杀毒\RAV\RAV\RAVMON.EXE
C:\WINDOWS.0\SOUNDMAN.EXE
C:\WINDOWS.0\System32\ctfmon.exe
D:\Program Files\download\kugoo\setup\KuGoo3\KuGoo.exe
C:\Program Files\DuDu\DddClient\dudupros.exe
C:\Program Files\DuDu\DddClient\DuDuAcc.exe
D:\Program Files\download\windows media p\computer\nt\NetTransport 2\NetTransport 2\NetTransport.exe
D:\Program Files\瑞星\hjk99\HijackThis 1.99.0\HijackThis1991zww.exe
D:\Program Files\瑞星\hjk99\HijackThis 1.99.0\HijackThis1991zww.exe

R3 - URLSearchHook: (no name) - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
O2 - BHO: EyeOnBrowser Class - {1272F701-349D-4DB3-BBCD-10CBDCD049FE} - C:\WINDOWS.0\Downlo~1\_IS_0518\_IS_WEBH.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\Program Files\download\QQGame\新建文件夹\新建文件夹\QQIEHelper.dll (file missing)
O2 - BHO: QQIEHelper - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS.0\system32\dla\tfswshx.dll
O2 - BHO: DuDu.com - {6BDE1669-B490-48E3-B668-456314F2D6C3} - C:\Program Files\DuDu\DddClient\dddiemon.dll
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - D:\PROGRA~1\download\kugoo\setup\KuGoo3\KUGOO3~1.OCX
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - D:\Program Files\download\windows media p\computer\nt\NetTransport 2\NetTransport 2\NTIEHelper.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS.0\System32\msdxm.ocx
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS.0\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS.0\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS.0\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [dla] C:\WINDOWS.0\system32\dla\tfswctrl.exe
O4 - 启动项HKLM\\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - 启动项HKLM\\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [RavTimer] D:\PROGRA~1\瑞星\杀毒\RAV\RAV\RAVTIMER.EXE
O4 - 启动项HKLM\\Run: [RavMon] D:\PROGRA~1\瑞星\杀毒\RAV\RAV\RAVMON.EXE -SYSTEM
O4 - 启动项HKLM\\Run: [RfwMain] "D:\Program Files\瑞星\防火墙\新建文件夹\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS.0\System32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Online Register.lnk = ?
O4 - Global Startup: DuDu下载加速器.lnk = C:\Program Files\DuDu\DDDClient\DuDuAcc.exe
O8 - IE右键菜单中的新增项目: 使用KuGoo3下载(&K) - D:\Program Files\download\kugoo\setup\KuGoo3\KuGoo3DownX.htm
O8 - IE右键菜单中的新增项目: 使用影音传送带下载 - D:\Program Files\download\windows media p\computer\nt\NetTransport 2\NetTransport 2\NTAddLink.html
O8 - IE右键菜单中的新增项目: 使用影音传送带下载全部链接 - D:\Program Files\download\windows media p\computer\nt\NetTransport 2\NetTransport 2\NTAddList.html
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\Program Files\download\QQGame\新建文件夹\新建文件夹\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\Program Files\download\QQGame\新建文件夹\新建文件夹\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\Program Files\download\QQGame\新建文件夹\新建文件夹\SendMMS.htm
O9 - 浏览器额外的按钮: 下载管理 - {3DB9F45E-AA74-4373-A466-C18A9F1C500D} - C:\Program Files\DuDu\DddClient\DuDuAcc.exe
O9 - 浏览器额外的“工具”菜单项: 下载管理 - {3DB9F45E-AA74-4373-A466-C18A9F1C500D} - C:\Program Files\DuDu\DddClient\DuDuAcc.exe
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS.0\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS.0\web\related.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\download\QQGame\新建文件夹\新建文件夹\QQ.EXE (file missing)
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\download\QQGame\新建文件夹\新建文件夹\QQ.EXE (file missing)
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\download\QQGame\新建文件夹\新建文件夹\QQIEHelper.dll (file missing)
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\download\QQGame\新建文件夹\新建文件夹\QQIEHelper.dll (file missing)
O18 - 列举现有的协议: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS.0\System32\mbprot.dll
O23 - NT 服务: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - d:\program files\瑞星\防火墙\新建文件夹\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - D:\PROGRAM FILES\瑞星\杀毒\RAV\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\PROGRAM FILES\瑞星\杀毒\RAV\RAV\Ravmond.exe





最后编辑2005-10-15 11:34:46
分享到:
gototop
 

修复:
R3 - URLSearchHook: (no name) - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)

O2 - BHO: EyeOnBrowser Class - {1272F701-349D-4DB3-BBCD-10CBDCD049FE} - C:\WINDOWS.0\Downlo~1\_IS_0518\_IS_WEBH.dll

02项请参考:
http://forum.ikaka.com/topic.asp?board=67&artid=6909890  【推荐】日志项中有_IS_ISC.dll的朋友来看看(反chaxun.com劫持)

还有楼主中的什么毒
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT