瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 各位大斑竹帮忙看一下,万分感谢!

1   1  /  1  页   跳转

各位大斑竹帮忙看一下,万分感谢!

各位大斑竹帮忙看一下,万分感谢!

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      13:29:09, 日期 2006-9-21
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\淘宝网\淘宝旺旺\WangWang.EXE
C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINPENJR\Win32\pphidpad.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\DrvMon.exe
C:\Program Files\Legend\HotKey\HotKeyB.exe
C:\HW99\HWVOICE\hwshell.exe
C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\zhanghao\LOCALS~1\Temp\Rar$EX00.531\HijackThis1991zww.exe

R3 - URLSearchHook: (no name) - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - (no file)
R3 - URLSearchHook: SgUrlSearHook Class - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - C:\WINDOWS\system32\socul.dll
R3 - URLSearchHook: VeryCD Search Class - {88351CEF-BAC0-4A9B-8380-31A173E2926F} - C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll (file missing)
R3 - URLSearchHook: (no name) - {306C835E-2318-49F0-9573-6AE858E90596} - (no file)
R3 - URLSearchHook: (no name) - {C492A2FC-0418-454B-9605-D5E9FAE2B877} - (no file)
R3 - URLSearchHook: (no name) - {5D6D38FD-4F27-413D-9AEB-175717E1E46E} - (no file)
R3 - URLSearchHook: (no name) - {0C2637B1-F436-44EE-9804-1CC9A73F8D3B} - (no file)
R3 - URLSearchHook: (no name) - {23AFE59E-885A-40A4-A3B9-C5D530B1BF7F} - (no file)
R3 - URLSearchHook: (no name) - {1214F728-3453-4803-B82B-E7FA72953590} - (no file)
R3 - URLSearchHook: (no name) - {5956FA0E-443A-4159-B262-295A1322DFB4} - (no file)
R3 - URLSearchHook: (no name) - {D6979BBC-3326-4EAE-AF2E-1BE12A93868A} - (no file)
R3 - URLSearchHook: (no name) - {A35BECCB-742C-4CA5-95EF-52E4655C0995} - (no file)
R3 - URLSearchHook: (no name) - {45A332A0-D2A2-432D-B66D-1D60562E2EE6} - (no file)
R3 - URLSearchHook: (no name) - {418EFBF4-A995-4718-8821-F23B5C3BD513} - (no file)
R3 - URLSearchHook: (no name) - {F861E69A-EC8D-47B1-882A-38C5FA1B7779} - (no file)
R3 - URLSearchHook: (no name) - {1E003EDA-1A37-46DA-8942-311BE24609CD} - (no file)
R3 - URLSearchHook: (no name) - {9AB61ACE-7220-49B3-AC29-B2E445E5C10B} - (no file)
R3 - URLSearchHook: (no name) - {F6CFDF56-9D0F-4681-B14B-F592FB70601A} - (no file)
R3 - URLSearchHook: (no name) - {B9600236-DC90-483A-84A8-178C92CD1D29} - (no file)
R3 - URLSearchHook: (no name) - {66F97C0B-0A66-411B-A6AE-FFB33EC02163} - (no file)
R3 - URLSearchHook: (no name) - {1F02DC4F-6076-46C1-BE31-BC664954CC51} - (no file)
R3 - URLSearchHook: (no name) - {37610A05-19CE-4DB0-94C8-08C8ABF7F4A3} - (no file)
R3 - URLSearchHook: (no name) - {C6673A6D-2848-4060-B6A2-03D88CDB85DD} - (no file)
R3 - URLSearchHook: (no name) - {63C02097-F5BB-4CE7-8667-D6C12DB07516} - (no file)
R3 - URLSearchHook: (no name) - {5BF354B0-8F5E-45AF-AC04-BFE033D24FC9} - (no file)
R3 - URLSearchHook: (no name) - {F61E5052-8BBF-40EC-8749-8A5431CDD564} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {0C2637B1-F436-44EE-9804-1CC9A73F8D3B} - (no file)
O2 - BHO: SohuDAIEHelper - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - (no file)
O2 - BHO: (no name) - {1214F728-3453-4803-B82B-E7FA72953590} - (no file)
O2 - BHO: (no name) - {1E003EDA-1A37-46DA-8942-311BE24609CD} - (no file)
O2 - BHO: (no name) - {1F02DC4F-6076-46C1-BE31-BC664954CC51} - (no file)
O2 - BHO: (no name) - {23AFE59E-885A-40A4-A3B9-C5D530B1BF7F} - (no file)
O2 - BHO: WinSearch - {27E96DE0-8211-42CF-9A1E-FA6246A95B77} - (no file)
O2 - BHO: (no name) - {306C835E-2318-49F0-9573-6AE858E90596} - (no file)
O2 - BHO: Yahoo!Photo - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - (no file)
O2 - BHO: (no name) - {37610A05-19CE-4DB0-94C8-08C8ABF7F4A3} - (no file)
O2 - BHO: AntiFish Class - {38928D50-8A48-44C2-945F-D2F23F771410} - (no file)
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - (no file)
O2 - BHO: (no name) - {418EFBF4-A995-4718-8821-F23B5C3BD513} - (no file)
O2 - BHO: (no name) - {45A332A0-D2A2-432D-B66D-1D60562E2EE6} - (no file)
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - (no file)
O2 - BHO: (no name) - {5956FA0E-443A-4159-B262-295A1322DFB4} - (no file)
O2 - BHO: (no name) - {5BF354B0-8F5E-45AF-AC04-BFE033D24FC9} - (no file)
O2 - BHO: (no name) - {5D6D38FD-4F27-413D-9AEB-175717E1E46E} - (no file)
O2 - BHO: DragSearch BHO - {62EED7C6-9F02-42f9-B634-98E2899E147B} - (no file)
O2 - BHO: (no name) - {63C02097-F5BB-4CE7-8667-D6C12DB07516} - (no file)
O2 - BHO: (no name) - {66F97C0B-0A66-411B-A6AE-FFB33EC02163} - (no file)
O2 - BHO: VeryCD超级搜索 - {75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688} - (no file)
O2 - BHO: (no name) - {9AB61ACE-7220-49B3-AC29-B2E445E5C10B} - (no file)
O2 - BHO: (no name) - {A35BECCB-742C-4CA5-95EF-52E4655C0995} - (no file)
O2 - BHO: (no name) - {B9600236-DC90-483A-84A8-178C92CD1D29} - (no file)
O2 - BHO: (no name) - {C492A2FC-0418-454B-9605-D5E9FAE2B877} - (no file)
O2 - BHO: (no name) - {C6673A6D-2848-4060-B6A2-03D88CDB85DD} - (no file)
O2 - BHO: (no name) - {D6979BBC-3326-4EAE-AF2E-1BE12A93868A} - (no file)
O2 - BHO: (no name) - {F61E5052-8BBF-40EC-8749-8A5431CDD564} - (no file)
O2 - BHO: (no name) - {F6CFDF56-9D0F-4681-B14B-F592FB70601A} - (no file)
O2 - BHO: (no name) - {F861E69A-EC8D-47B1-882A-38C5FA1B7779} - (no file)
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - (no file)
O3 - IE工具栏增项: VeryCD超级搜索 - {F869BB38-FFEF-4589-B986-610B7AD0ADA2} - C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll (file missing)
O3 - IE工具栏增项: 捜狗直通车 - {DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} - C:\Program Files\P4P\ToolBar.dll
O3 - IE工具栏增项: Yahoo! 导航条 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - 启动项HKLM\\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - 启动项HKLM\\Run: [WangWang] "C:\Program Files\淘宝网\淘宝旺旺\WangWang.EXE"
O4 - 启动项HKLM\\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - 启动项HKLM\\Run: [stup.exe] C:\PROGRA~1\TENCENT\Adplus\stup.exe
O4 - 启动项HKLM\\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - 启动项HKLM\\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - 启动项HKLM\\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - 启动项HKLM\\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - 启动项HKLM\\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - 启动项HKLM\\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - 启动项HKLM\\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - 启动项HKLM\\Run: [PPHIDPAD] C:\WINPENJR\Win32\pphidpad.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DrvMon.exe] C:\WINDOWS\system32\DrvMon.exe
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\QQ\QQ.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
最后编辑2006-09-21 14:57:46
分享到:
gototop
 

继续
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - IE右键菜单中的新增项目: VeryCD超级搜索 - C:\PROGRA~1\YOK.com\SUPERS~1\yoksch.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 使用搜狗直通车下载 - C:\Program Files\P4P\dl.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 发送图片到手机 - C:\Program Files\P4P\cx.htm
O8 - IE右键菜单中的新增项目: 在新的前台选项卡中打开 - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\zh-cn\msntabres.dll/230?86fe108fcd24ac7bdf49dc27a49642e
O8 - IE右键菜单中的新增项目: 在新的后台选项卡中打开 - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\zh-cn\msntabres.dll/229?86fe108fcd24ac7bdf49dc27a49642e
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 添加到“我的订阅” - C:\Program Files\P4P\rss.htm
O8 - IE右键菜单中的新增项目: 添加到雅虎订阅(&Y) - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - IE右键菜单中的新增项目: 雅虎搜索 - res://C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll/246
O9 - 浏览器额外的按钮: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - 浏览器额外的“工具”菜单项: Sun Java 控制台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - 浏览器额外的按钮: 联想 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.lenovo.com (file missing)
O9 - 浏览器额外的按钮: 我的订阅 - {8755CE6E-0BF7-4441-8751-FB728941B0B4} - C:\Program Files\P4P\rss.dll
O9 - 浏览器额外的按钮: 词霸 - {9A687CA6-D585-4947-9ED9-BE96071F5CD9} - C:\PROGRA~1\Kingsoft\POWERW~1\XDictExB.dll
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\cdnns.dll' missing
O11 - Options group: [CDNCLIENT]  中文上网
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com
O15 - “受信任的站点”中添加项: http://www.icbc.com.cn
O16 - DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} (MMCPlayer Class) - http://p3p.sogou.com/MMCShell.cab
O16 - DPF: {C37FBD87-3AA7-4640-9A8D-19AFC10B15B2} (Netease Chat Control) - http://room.chat.163.com/xchat/chat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C5E1F152-2DEF-4ADD-BA1E-E702FDA9B97A}: NameServer = 202.99.99.196
O18 - 列举现有的协议: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - C:\PROGRA~1\Kingsoft\POWERW~1\XDictExB.dll
O18 - Filter: text/html - {83DFBFF3-1455-4538-8036-39D2057787DF} - C:\WINDOWS\gsSecurity1.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\SoDAHK.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - NT 服务: P4P Service - Sohu.com Inc. - C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
O23 - NT 服务: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

gototop
 

我就不废话了,您各位给看一下,再帮忙教偶处理一下.
gototop
 

老大们都休息了吗,什么时候有时间啊?
gototop
 

斑竹是不是没有问题啊,我怎么可那我的日志这样乱啊,告诉我到底有没有问题啊
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT