瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 不行啊,我的问题还是没解决,大家帮忙看看啊

1   1  /  1  页   跳转

不行啊,我的问题还是没解决,大家帮忙看看啊

不行啊,我的问题还是没解决,大家帮忙看看啊

C:\\WINDOWS\\System32\\smss.exe
C:\\WINDOWS\\system32\\winlogon.exe
C:\\WINDOWS\\system32\\services.exe
C:\\WINDOWS\\system32\\lsass.exe
C:\\WINDOWS\\system32\\svchost.exe
C:\\WINDOWS\\System32\\svchost.exe
C:\\WINDOWS\\system32\\spoolsv.exe
C:\\WINDOWS\\Explorer.EXE
C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe
C:\\Program Files\\iCompanion\\ic.exe
C:\\Program Files\\Java\\j2re1.4.2_04\\bin\\jusched.exe
C:\\Program Files\\D-Tools\\daemon.exe
C:\\WINDOWS\\SOUNDMAN.EXE
C:\\Program Files\\WinPoET Broadband Connection\\winpppoverethernet.exe
C:\\WINDOWS\\system32\\ctfmon.exe
C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe
C:\\Program Files\\Maxthon\\Maxthon.exe
C:\\Program Files\\Symantec_Client_Security\\Symantec AntiVirus\\DefWatch.exe
C:\\Program Files\\Symantec_Client_Security\\Symantec AntiVirus\\Rtvscan.exe
C:\\WINDOWS\\System32\\svchost.exe
C:\\Program Files\\WinPoET Broadband Connection\\WrOS.EXE
C:\\Program Files\\BitComet\\BitComet.exe
C:\\Program Files\\FlashGet\\flashget.exe
C:\\DOCUME~1\\seanshen\\LOCALS~1\\Temp\\Rar$EX00.125\\HijackThis.exe

O2 - BHO: (no name) - {04DCC17E-35E1-417A-ABCF-41623FA2ACE7} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\\PROGRA~1\\SPYBOT~1\\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\\PROGRA~1\\FlashGet\\jccatch.dll
O2 - BHO: (no name) - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - (no file)
O3 - Toolbar: (no name) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - (no file)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\\PROGRA~1\\FlashGet\\fgiebar.dll
O3 - Toolbar: CyberArticle Express - {769A6A36-ED24-4376-BC7C-80225BF35698} - C:\\Program Files\\CyberArticle\\CAExp.dll
O4 - HKLM\\..\\Run: [IMJPMIG8.1] \"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32
O4 - HKLM\\..\\Run: [PHIME2002ASync] ; C:\\WINDOWS\\System32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC
O4 - HKLM\\..\\Run: [PHIME2002A] ; C:\\WINDOWS\\System32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName
O4 - HKLM\\..\\Run: [vptray] C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe
O4 - HKLM\\..\\Run: [netmon.exe] C:\\Program Files\\iCompanion\\ic.exe
O4 - HKLM\\..\\Run: [SunJavaUpdateSched] C:\\Program Files\\Java\\j2re1.4.2_04\\bin\\jusched.exe
O4 - HKLM\\..\\Run: [DAEMON Tools-1033] \"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033
O4 - HKLM\\..\\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\\..\\Run: [a-winpoet-service] \"C:\\Program Files\\WinPoET Broadband Connection\\winpppoverethernet.exe\"
O4 - HKLM\\..\\Run: [Super Rabbit SRRestore] ; C:\\PROGRA~1\\SUPERR~1\\MagicSet\\SRRest.exe /autosave
O4 - HKLM\\..\\Run: [KernelFaultCheck] ; %systemroot%\\system32\\dumprep 0 -k
O4 - HKLM\\..\\Run: [TkBellExe] \"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot
O4 - HKCU\\..\\Run: [ctfmon.exe] C:\\WINDOWS\\system32\\ctfmon.exe
O4 - HKCU\\..\\Run: [MsnMsgr] \"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background
O4 - HKCU\\..\\Run: [SpybotSD TeaTimer] C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe
O8 - Extra context menu item: 使用网际快车下载 - C:\\Program Files\\FlashGet\\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\\Program Files\\FlashGet\\jc_all.htm
O9 - Extra button: 金山词霸 - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - C:\\WINDOWS\\System32\\shdocvw.dll
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {991481A7-4669-4E15-8C24-100404E1F5CB} - http://www.bluesky.cn/download/blueskyvoice_60.cab
O16 - DPF: {F2EB8999-766E-4BF6-AAAD-188D398C0D0B} - http://www4.cmbchina.com/download/pb45.cab
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\..\\{75DC4427-90F7-42D1-8872-0A237D1867DE}: NameServer = 202.96.209.6 202.96.209.133
O20 - Winlogon Notify: NavLogon - C:\\WINDOWS\\System32\\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\\Program Files\\Symantec_Client_Security\\Symantec AntiVirus\\DefWatch.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\\Program Files\\Symantec_Client_Security\\Symantec AntiVirus\\Rtvscan.exe
O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\\Program Files\\WinPoET Broadband Connection\\WrOS.EXE


已经在安全模式下在未打开IE的情况下删除
O2 - BHO: (no name) - {04DCC17E-35E1-417A-ABCF-41623FA2ACE7} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - (no file)
三键,IE也清空

可重起后,还是存在这三键。
广告继续弹出。
这三键在注册表里是browse OBJECT
依然没有解决问题。

求大家再帮忙仔细看看。

现像。一开始弹出多多宽频的窗口,后来就是不同网址的什么手机铃声什么的。

本人是XP,MAXTHON
已用过 SPY SBOT 和 清理过IE 插件了。
最后编辑2005-09-03 10:44:34
分享到:
gototop
 

HijackThis_815汉化版扫描日志 V1.99.1
保存于      9:55:38, 日期 2005-9-3
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\iCompanion\ic.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\D-Tools\daemon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\WinPoET Broadband Connection\winpppoverethernet.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WinPoET Broadband Connection\WrOS.EXE
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\GreenMPC\GreenMPC.exe
C:\Documents and Settings\seanshen\桌面\4842302005817230232\HijackThis1991zww.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - IE工具栏增项: CyberArticle Express - {769A6A36-ED24-4376-BC7C-80225BF35698} - C:\Program Files\CyberArticle\CAExp.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - 启动项HKLM\\Run: [netmon.exe] C:\Program Files\iCompanion\ic.exe
O4 - 启动项HKLM\\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - 启动项HKLM\\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [a-winpoet-service] "C:\Program Files\WinPoET Broadband Connection\winpppoverethernet.exe"
O4 - 启动项HKLM\\Run: [Super Rabbit SRRestore] ; C:\PROGRA~1\SUPERR~1\MagicSet\SRRest.exe /autosave
O4 - 启动项HKLM\\Run: [KernelFaultCheck] ; %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] ; C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O9 - 浏览器额外的按钮: 金山词霸 - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - C:\WINDOWS\System32\shdocvw.dll
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} -
O16 - DPF: {991481A7-4669-4E15-8C24-100404E1F5CB} -
O16 - DPF: {F2EB8999-766E-4BF6-AAAD-188D398C0D0B} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{75DC4427-90F7-42D1-8872-0A237D1867DE}: NameServer = 202.96.209.6 202.96.209.133
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - NT 服务: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - NT 服务: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - NT 服务: WinPPPoverEthernet - iVasion, a Routerware Company - C:\Program Files\WinPoET Broadband Connection\WrOS.EXE

现在的情况,可是还是没有能阻止那个广告的弹出,受不了了
gototop
 

那个网络伴侣我用了很久了。
前面我删掉了
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll

三键,可还是没用。我的天啊。
什么毒啊。
gototop
 

不是,开机约10分钟左右,弹出一个IE窗口,主页是多多宽频
然后再过10分钟左右,又弹出一个,http://e.x365.cn/index.asp?id=10961,是这个网址
然后再10分钟左右,再弹出COOL DOG的网址

每次网址变化都不一样。

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT