瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我的firefox最近被劫持:请高手帮忙

1   1  /  1  页   跳转

我的firefox最近被劫持:请高手帮忙

我的firefox最近被劫持:请高手帮忙

我的firefox最近被劫持了,前几天不知在哪儿中毒了,导致firefox被劫持,出现如下症状:
1 在地址栏输入网址,就会被恶意转到一个叫××信息网,原网站根本上不了。
2 地址栏输入网址时一不小心输错,也会被转到该××信息网。
3 我的firefox自己设立的主页在打开firefox时,出不来而是也被转到××信息网
4 在搜索得到结果时,点击结果条目时,偶尔也会被转到××信息网。
我用杀毒软件和反木马软件查找,没有发现病毒,我再用超级兔子,在清除系统的垃圾文件和在删除firefox的上网记录和缓存后,劫持会短时间消除,当在浏览一段时间惑后,劫持又会出现,真是太头痛了,请高手和帮主帮忙解决以下。
还想知道:这个问题会不会使我的电脑信息和资料被泄漏?怎样彻底解决这个问题以防下次再被劫持?


那个垃圾××信息网叫新天通讯信息网,全家不得好死,宣传用这等下流方法!!!!

此方法试过,无效。
----------------------------------------------------------
最简单的修复方法:把那个xx站的域名打入另册,在

c:\windows\system32\drivers\etc\hosts

加入一行

127.0.0.1 xx的域名
-----------------------------------------------------
这是我的扫描日志,请高手帮忙一下
HijackThis@Qoo的扫描日志  V1.97.7
Scan saved at 12:21:09, on 2006-12-8
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\thtfpc\桌面\hijackthis1.97_qoo\HijackThis.exe

O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [JeticoPFStartup] "C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: NTUSER.DAT
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Startup: NULL
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
最后编辑2006-12-08 12:49:57
分享到:
gototop
 

2006-12-08,12:37:43

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <avgnt><"C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min>  [Avira GmbH]
    <JeticoPFStartup><"C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe">  [Jetico, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
    <WinlogonNotify: igfxcui><igfxdev.dll>  [(Verified)Intel Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <AGRSMMSG><; AGRSMMSG.exe>  [Agere Systems]
    <Alcmtr><; ALCMTR.EXE>  [(Verified)Realtek Semiconductor Corp.]
    <High Definition Audio Property Page Shortcut><; HDAShCut.exe>  [(Verified)Windows (R) Server 2003 DDK provider]
    <igfxhkcmd><; C:\WINDOWS\system32\hkcmd.exe>  [(Verified)Intel Corporation]
    <igfxpers><; C:\WINDOWS\system32\igfxpers.exe>  [(Verified)Intel Corporation]
    <igfxtray><; C:\WINDOWS\system32\igfxtray.exe>  [(Verified)Intel Corporation]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <OfficeScanNT Monitor><; "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow>  [N/A]
    <RemoteControl><; "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe">  [Cyberlink Corp.]
    <RTHDCPL><; RTHDCPL.EXE>  [(Verified)Realtek Semiconductor Corp.]

==================================
启动文件夹
N/A

==================================
服务
[AntiVir PersonalEdition Classic Scheduler / AntiVirScheduler]
  <C:\Program Files\AntiVir PersonalEdition Classic\sched.exe><Avira GmbH>
[AntiVir PersonalEdition Classic Guard / AntiVirService]
  <C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe><AVIRA GmbH>
[ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard]
  <C:\Program Files\ewido anti-spyware 4.0\guard.exe><Anti-Malware Development a.s.>
[Human Interface Device Access / HidServ]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[OfficeScanNT 实时扫描 / ntrtscan]
  <><N/A>
[OfficeScanNT 个人防火墙 / OfcPfwSvc]
  <><N/A>
[OfficeScanNT 侦听程序 / tmlisten]
  <><N/A>

==================================
驱动程序
[Agere Systems Soft Modem / AgereSoftModem]
  <system32\DRIVERS\AGRSM.sys><Agere Systems>
[avgio / avgio]
  <\??\C:\Program Files\AntiVir PersonalEdition Classic\avgio.sys><H+BEDV Datentechnik GmbH>
[avgntflt / avgntflt]
  <\??\C:\Program Files\AntiVir PersonalEdition Classic\avgntflt.sys><AVIRA GmbH>
[bcftdi / bcftdi]
  <C:\WINDOWS\SYSTEM32\DRIVERS\bcftdi.SYS><Jetico, Inc.>
[bc_filter / bc_filter]
  <C:\WINDOWS\SYSTEM32\DRIVERS\bc_filter.SYS><Jetico, Inc.>
[BC_IP_Filter / bc_ip_f]
  <C:\WINDOWS\SYSTEM32\DRIVERS\bc_ip_f.SYS><Jetico, Inc.>
[BC_Engine / bc_ngn]
  <C:\WINDOWS\SYSTEM32\DRIVERS\bc_ngn.SYS><Jetico, Inc.>
[BC_PAT_Filter / bc_pat_f]
  <C:\WINDOWS\SYSTEM32\DRIVERS\bc_pat_f.SYS><Jetico, Inc.>
[BC_Protocol_Filter / bc_prt_f]
  <C:\WINDOWS\SYSTEM32\DRIVERS\bc_prt_f.SYS><Jetico, Inc.>
[BC_TDI_Filter / bc_tdi_f]
  <C:\WINDOWS\SYSTEM32\DRIVERS\bc_tdi_f.SYS><Jetico, Inc.>
[ewido anti-spyware 4.0 driver / ewido anti-spyware 4.0 driver]
  <\??\C:\Program Files\ewido anti-spyware 4.0\guard.sys><N/A>
[Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService]
  <system32\drivers\HdAudio.sys><Windows (R) Server 2003 DDK provider>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus]
  <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[ialm / ialm]
  <system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService]
  <system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
[Direct Parallel Link Driver / Ptilink]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp]
  <system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv]
  <system32\DRIVERS\secdrv.sys><N/A>
[tifm21 / tifm21]
  <system32\drivers\tifm21.sys><Texas Instruments>
[Trend Micro Filter / TmFilter]
  <\??\C:\Program Files\Trend Micro\OfficeScan Client\TmXPFlt.sys><N/A>
[Trend Micro PreFilter / TmPreFilter]
  <\??\C:\Program Files\Trend Micro\OfficeScan Client\TmPreFlt.sys><N/A>
gototop
 

==================================
浏览器加载项
[Edit Class]
  {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v5.dll, N/A>
[Edit Class]
  {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\flash.ocx, Macromedia, Inc.>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <, N/A>
[添加到QQ表情]
  <, N/A>
[用QQ彩信发送该图片]
  <, N/A>

==================================
正在运行的进程
[PID: 600][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 664][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 688][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 736][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 748][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 908][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 972][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1076][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1132][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1204][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1592][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1688][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [C:\Program Files\ewido anti-spyware 4.0\context.dll]  [Anti-Malware Development a.s., 4, 0, 0, 172]
    [C:\Program Files\AntiVir PersonalEdition Classic\shlext.dll]  [H+BEDV Datentechnik GmbH, 7.00.00.04]
[PID: 1852][C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe]  [Avira GmbH, 7.00.00.18]
    [C:\Program Files\AntiVir PersonalEdition Classic\avgcmxp.dll]  [Avira GmbH, 7.00.00.16]
[PID: 1860][C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe]  [Jetico, Inc., 1.0.1.61]
    [C:\Program Files\Jetico\Jetico Personal Firewall\Modules\ip_filter.dll]  [Jetico, Inc., 1.0.1.20]
    [C:\Program Files\Jetico\Jetico Personal Firewall\Modules\proto_filter.dll]  [Jetico, Inc., 1.0.0.27]
    [C:\Program Files\Jetico\Jetico Personal Firewall\Modules\tdi_filter.dll]  [Jetico, Inc., 1.0.0.59]
    [C:\Program Files\Jetico\Jetico Personal Firewall\Modules\pat_filter.dll]  [Jetico, Inc., 1.0.0.20]
    [C:\Program Files\Jetico\Jetico Personal Firewall\bcflogtb.dll]  [Jetico, Inc., 1.0.1.8]
    [C:\Program Files\Jetico\Jetico Personal Firewall\bcfgenv.dll]  [Jetico, Inc., 1.0.0.26]
    [C:\Program Files\Jetico\Jetico Personal Firewall\fwui.dll]  [Jetico, Inc., 1.0.1.86]
[PID: 1868][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1176][C:\Program Files\AntiVir PersonalEdition Classic\sched.exe]  [Avira GmbH, 7.00.00.27]
    [C:\Program Files\AntiVir PersonalEdition Classic\schedr.dll]  [ Avira GmbH, 7.00.00.09]
[PID: 1196][C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe]  [AVIRA GmbH, 7.00.00.35]
    [C:\Program Files\AntiVir PersonalEdition Classic\GUARDMSG.DLL]  [Avira GmbH, 7.00.00.12]
    [C:\Program Files\AntiVir PersonalEdition Classic\AVPREF.DLL]  [Avira GmbH, 7.00.00.02]
    [C:\Program Files\AntiVir PersonalEdition Classic\SMTPLIB.DLL]  [Avira GmbH, 1.02.00.08]
    [C:\Program Files\AntiVir PersonalEdition Classic\AVEWIN32.DLL]  [Avira GmbH, 7.2.0.49]
[PID: 1312][C:\Program Files\ewido anti-spyware 4.0\guard.exe]  [Anti-Malware Development a.s., 4, 0, 0, 172]
    [C:\Program Files\ewido anti-spyware 4.0\engine.dll]  [Anti-Malware Development a.s., 4, 0, 0, 172]
[PID: 380][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1372][C:\WINDOWS\system32\NOTEPAD.EXE]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1880][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\macromed\flash\flash.ocx]  [Macromedia, Inc., 6,0,79,0]
[PID: 244][C:\Program Files\Mozilla Firefox\firefox.exe]  [Mozilla Corporation, 1.8.1: 2006101023]
    [C:\Program Files\Mozilla Firefox\js3250.dll]  [Netscape Communications Corporation, 4.0]
    [C:\Program Files\Mozilla Firefox\nspr4.dll]  [Netscape Communications Corporation, 4.6.3]
    [C:\Program Files\Mozilla Firefox\xpcom_core.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [C:\Program Files\Mozilla Firefox\plc4.dll]  [Netscape Communications Corporation, 4.6.3]
    [C:\Program Files\Mozilla Firefox\plds4.dll]  [Netscape Communications Corporation, 4.6.3]
    [C:\Program Files\Mozilla Firefox\smime3.dll]  [Mozilla Foundation, 3.11.3 Basic ECC]
    [C:\Program Files\Mozilla Firefox\nss3.dll]  [Mozilla Foundation, 3.11.3 Basic ECC]
    [C:\Program Files\Mozilla Firefox\softokn3.dll]  [Mozilla Foundation, 3.11.3 Basic ECC]
    [C:\Program Files\Mozilla Firefox\ssl3.dll]  [Mozilla Foundation, 3.11.3 Basic ECC]
    [C:\Program Files\Mozilla Firefox\xpcom_compat.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [C:\Program Files\Mozilla Firefox\components\myspell.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [C:\Program Files\Mozilla Firefox\components\jar50.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [C:\Program Files\Mozilla Firefox\components\spellchk.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [C:\Program Files\Mozilla Firefox\freebl3.dll]  [Mozilla Foundation, 3.11.3 Basic ECC]
    [C:\Program Files\Mozilla Firefox\nssckbi.dll]  [Mozilla Foundation, 1.62]
[PID: 1432][C:\Documents and Settings\csl\桌面\sreng2\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost
127.0.0.1 www.tongxunqicai.cn

==================================
gototop
 


运行SREng2,使用“系统修复”--浏览器加载项--删除
[Edit Class]
{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
显示隐藏文件
删除: 
C:\WINDOWS\system32\CMBEdit.dll

行SREng2,使用:系统修复--文件关联--全选--修复
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT