1   1  /  1  页   跳转

自动找开网页问题?

自动找开网页问题?

我的电脑老是自动找开网页.关过之后过一段时间又会自动找开.要是不关它还会找开别的页.我的计算机除查出一个木马外就没有什么病毒了?
是不是注册表里被恶意网页给更改了?

最后编辑2005-10-19 17:09:31
分享到:
gototop
 

--- Spybot - Search & Destroy version: 1.4  (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-10-19 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2005-05-31 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2005-05-31 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2005-10-14 Includes\Cookies.sbi
2005-10-14 Includes\Dialer.sbi
2005-10-14 Includes\Hijackers.sbi
2005-10-14 Includes\Keyloggers.sbi
2004-11-29 Includes\LSP.sbi
2005-10-14 Includes\Malware.sbi
2005-10-14 Includes\PUPS.sbi
2005-10-14 Includes\Revision.sbi
2005-10-14 Includes\Security.sbi
2005-10-14 Includes\Spybots.sbi
2005-02-17 Includes\Tracks.uti
2005-10-14 Includes\Trojans.sbi

Located: HK_LM:Run, hbpassport
command: C:\PROGRA~1\HBClient\hbast.exe
  file: C:\PROGRA~1\HBClient\hbast.exe
  size: 90112
    MD5: 6c6a3d2fe4905b2a502c01ff7cc7da7f

Located: HK_LM:Run, KAVPersonal50
command: C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe /minimize
  file:

Located: HK_CU:Run, internat.exe
command: internat.exe
  file: C:\WINNT\system32\internat.exe
  size: 21264
    MD5: 2061f6ff47f6938d95c18e3a1a8cf7e2

Located: HK_CU:Run, SpybotSD TeaTimer
command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
  file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
  size: 1415824
    MD5: 70496eee0ddbe485f658693826f44d38

Located: Startup (所有用户), 天网防火墙个人版 (2).lnk
command: C:\Program Files\SkyNet\FireWall\PFW.exe
  file: C:\Program Files\SkyNet\FireWall\PFW.exe
  size: 2783232
    MD5: 5c5a3bd6886faff04b48393e299a93ea

Located: WinLogon, crypt32chain
command: crypt32.dll
  file: crypt32.dll

Located: WinLogon, cryptnet
command: cryptnet.dll
  file: cryptnet.dll

Located: WinLogon, cscdll
command: cscdll.dll
  file: cscdll.dll

Located: WinLogon, NetCache
command: C:\WINNT\system32\gp6ql3j51.dll
  file: C:\WINNT\system32\gp6ql3j51.dll
  size: 0
    MD5: d41d8cd98f00b204e9800998ecf8427e ???

Located: WinLogon, sclgntfy
command: sclgntfy.dll
  file: sclgntfy.dll

Located: WinLogon, SensLogn
command: WlNotify.dll
  file: WlNotify.dll

Located: WinLogon, wzcnotif
command: wzcdlg.dll
  file: wzcdlg.dll

gototop
 

HijackThis_815汉化版扫描日志 V1.99.1
保存于      15:10:52, 日期 2005-10-19
操作系统:  Windows 2000 SP4 (WinNT 5.00.2195)
浏览器:    Unable to get Internet Explorer version!

当前运行的进程:         
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\QWRtaW5pc3RyYXRvcnhkbAAA\command.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\system32\locator.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\internat.exe
C:\WINNT\system32\Rundll32.exe
C:\Program Files\SkyNet\FireWall\PFW.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\conime.exe
F:\Program Files\幽灵盾\gshield\gshield.exe
F:\Program Files\Tencent\QQ\QQ.exe
F:\Program Files\Tencent\QQ\TIMPlatform.exe
F:\Program Files\Tencent\TT\TTraveler.exe
D:\Program Files\TTPlayer\TTPlayer.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINNT\notepad.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.422\HijackThis1991zww.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - IE工具栏增项: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - IE工具栏增项: 卡卡安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINNT\system32\kakatool.dll
O3 - IE工具栏增项: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - F:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll
O4 - 启动项HKLM\\Run: [KAVPersonal50] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe /minimize
O4 - 启动项HKLM\\Run: [hbpassport] C:\PROGRA~1\HBClient\hbast.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: 天网防火墙个人版 (2).lnk = C:\Program Files\SkyNet\FireWall\PFW.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - IE右键菜单中的新增项目: 用比特精灵下载(&B) - D:\Program Files\处理软件与网页素材\[游戏][图像处理][动画制作]\CS1.5中文硬盘版\CS1.5中文硬盘版\BitSpirit\bsurl.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{2F6F8F05-0813-4D40-9843-5CB462E28D24}: NameServer = 61.147.37.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{2F6F8F05-0813-4D40-9843-5CB462E28D24}: NameServer = 61.147.37.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{2F6F8F05-0813-4D40-9843-5CB462E28D24}: NameServer = 61.147.37.1
O20 - Winlogon Notify: NetCache - C:\WINNT\system32\gp6ql3j51.dll
O23 - NT 服务: Command Service (cmdService) - Unknown owner - C:\WINNT\QWRtaW5pc3RyYXRvcnhkbAAA\command.exe
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - NT 服务: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe

gototop
 

谢谢版主了!
gototop
 

删除C:\WINNT\QWRtaW5pc3RyYXRvcnhkbAAA\command.exe
删除这一项还得进安全模式!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT