1   1  /  1  页   跳转

浏览器主页被改

浏览器主页被改

把主页设为空白页和hosts清空后,如果电脑不重启一切正常,但只要重启后主页就又变成
http://www.5t1t.com,hosts的内容为:
218.5.76.71 1ting.com
218.5.76.71 www.1ting.com
218.5.76.71 yy138.com
218.5.76.71 www.yy138.com
218.5.76.71 dj99.com
218.5.76.71 www.dj99.com
218.5.76.71 520music.com
218.5.76.71 www.520music.com
218.5.76.71 vv66.com
218.5.76.71 www.vv66.com
218.5.76.71 666ccc.com
218.5.76.71 www.666ccc.com
218.5.76.71 666qqq.com
218.5.76.71 www.666qqq.com
218.5.76.71 100yy.com
218.5.76.71 www.100yy.com
218.5.76.71 006.net
218.5.76.71 www.006.net
218.5.76.71 2t.cn
218.5.76.71 www.2t.cn
218.5.76.71 cococ.com
218.5.76.71 www.cococ.com
218.5.76.71 ting.cococ.com
218.5.76.71 yymp3.com
218.5.76.71 www.yymp3.com
218.5.76.71 qq163.com
218.5.76.71 www.qq163.com
218.5.76.71 7760.com
218.5.76.71 www.7760.com
218.5.76.71 568.com
218.5.76.71 www.568.com
218.5.76.71 nowok.net
218.5.76.71 www.nowok.net
218.5.76.71 chinamp3.com
218.5.76.71 www.chinamp3.com
218.5.76.71 99music.net
218.5.76.71 www.99music.net
218.5.76.71 6621.com
218.5.76.71 www.6621.com
218.5.76.71 7t7t.com
218.5.76.71 www.7t7t.com
218.5.76.71 haoting.com
218.5.76.71 www.haoting.com
218.5.76.71 mtv110.com
218.5.76.71 www.mtv110.com
218.5.76.71 st020.com
218.5.76.71 www.st020.com
218.5.76.71 music.jschina.com.cn
218.5.76.71 real2000.org
218.5.76.71 www.real2000.org
218.5.76.71 6bb.com
218.5.76.71 www.6bb.com
218.5.76.71 5474.com
218.5.76.71 www.5474.com
218.5.76.71 qq163.com
218.5.76.71 www.qq163.com
218.5.76.71 ting88.com
218.5.76.71 www.ting88.com
218.5.76.71 tt78.com
218.5.76.71 www.tt78.com
218.5.76.71 8yh.com
218.5.76.71 mp3.8yh.com
218.5.76.71 ibmp3.com
218.5.76.71 www.ibmp3.com
218.5.76.71 feifa.com
218.5.76.71 www.feifa.com
218.5.76.71 music.feifa.com
218.5.76.71 91f.net
218.5.76.71 www.91f.net
218.5.76.71 6621.com
218.5.76.71 www.6621.com
218.5.76.71 ting163.com
218.5.76.71 www.ting163.com
218.5.76.71 99music.net
218.5.76.71 www.99music.net
218.5.76.71 wo99.com
218.5.76.71 www.wo99.com
218.5.76.71 jnnc.com
218.5.76.71 www.jnnc.com
218.5.76.71 mtv123.com
218.5.76.71 www.mtv123.com
218.5.76.71 dj520.com
218.5.76.71 www.dj520.com
218.5.76.71 7xi.net
218.5.76.71 www.7xi.net
218.5.76.71 mtv110.com
218.5.76.71 www.mtv110.com
218.5.76.71 mtvtop.net
218.5.76.71 www.mtvtop.net
218.5.76.71 mtvtop.com
218.5.76.71 www.mtvtop.com
218.5.76.71 xaonline.com
218.5.76.71 music.xaonline.com
218.5.76.71 musictea.com
218.5.76.71 www.musictea.com
218.5.76.71 tfol.com
218.5.76.71 www.tfol.com
218.5.76.71 yyue.com
218.5.76.71 www.yyue.com
218.5.76.71 yyue.net
218.5.76.71 www.yyue.net
218.5.76.71 qq150.com
218.5.76.71 www.qq150.com
218.5.76.71 517tg.com
218.5.76.71 www.517tg.com
218.5.76.71 souting.com
218.5.76.71 www.souting.com
218.5.76.71 tt67.com
218.5.76.71 www.tt67.com
218.5.76.71 tt78.com
218.5.76.71 www.tt78.com
218.5.76.71 funmtv.com
218.5.76.71 www.funmtv.com
218.5.76.71 gz163.cn
218.5.76.71 www.gz163.cn
218.5.76.71 51y.com
218.5.76.71 www.51y.com
218.5.76.71 tt90.com
218.5.76.71 www.tt90.com
218.5.76.71 cns.3721.com
218.5.76.71 assistant.3721.com
218.5.76.71 auto.search.msn.com
218.5.76.71 so.qq.com
218.5.76.71 4yt.net
218.5.76.71 www.4yt.net
218.5.76.71 qq533.net
218.5.76.71 www.qq533.net


有谁碰过,怎么解决,谢谢!
最后编辑2005-11-06 16:32:51
分享到:
gototop
 

HijackThis_815汉化版扫描日志 V1.99.1
保存于      9:01:30, 日期 2005-11-6
操作系统:  Windows 2000 SP4 (WinNT 5.00.2195)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpm.exe
C:\WINNT\System32\llssrv.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\WINNT\Explorer.EXE
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\system32\conime.exe
C:\Program Files\HijackThis1991汉化版\HijackThis1991zww.exe

F2 - REG:system.ini: UserInit=userinit,nddeagnt.exe
O1 - Hosts: 218.5.76.71 1ting.com
O1 - Hosts: 218.5.76.71 www.1ting.com
O1 - Hosts: 218.5.76.71 yy138.com
O1 - Hosts: 218.5.76.71 www.yy138.com
O1 - Hosts: 218.5.76.71 dj99.com
O1 - Hosts: 218.5.76.71 www.dj99.com
O1 - Hosts: 218.5.76.71 520music.com
O1 - Hosts: 218.5.76.71 www.520music.com
O1 - Hosts: 218.5.76.71 vv66.com
O1 - Hosts: 218.5.76.71 www.vv66.com
O1 - Hosts: 218.5.76.71 666ccc.com
O1 - Hosts: 218.5.76.71 www.666ccc.com
O1 - Hosts: 218.5.76.71 666qqq.com
O1 - Hosts: 218.5.76.71 www.666qqq.com
O1 - Hosts: 218.5.76.71 100yy.com
O1 - Hosts: 218.5.76.71 www.100yy.com
O1 - Hosts: 218.5.76.71 006.net
O1 - Hosts: 218.5.76.71 www.006.net
O1 - Hosts: 218.5.76.71 2t.cn
O1 - Hosts: 218.5.76.71 www.2t.cn
O1 - Hosts: 218.5.76.71 cococ.com
O1 - Hosts: 218.5.76.71 www.cococ.com
O1 - Hosts: 218.5.76.71 ting.cococ.com
O1 - Hosts: 218.5.76.71 yymp3.com
O1 - Hosts: 218.5.76.71 www.yymp3.com
O1 - Hosts: 218.5.76.71 qq163.com
O1 - Hosts: 218.5.76.71 www.qq163.com
O1 - Hosts: 218.5.76.71 7760.com
O1 - Hosts: 218.5.76.71 www.7760.com
O1 - Hosts: 218.5.76.71 568.com
O1 - Hosts: 218.5.76.71 www.568.com
O1 - Hosts: 218.5.76.71 nowok.net
O1 - Hosts: 218.5.76.71 www.nowok.net
O1 - Hosts: 218.5.76.71 chinamp3.com
O1 - Hosts: 218.5.76.71 www.chinamp3.com
O1 - Hosts: 218.5.76.71 99music.net
O1 - Hosts: 218.5.76.71 www.99music.net
O1 - Hosts: 218.5.76.71 6621.com
O1 - Hosts: 218.5.76.71 www.6621.com
O1 - Hosts: 218.5.76.71 7t7t.com
O1 - Hosts: 218.5.76.71 www.7t7t.com
O1 - Hosts: 218.5.76.71 haoting.com
O1 - Hosts: 218.5.76.71 www.haoting.com
O1 - Hosts: 218.5.76.71 mtv110.com
O1 - Hosts: 218.5.76.71 www.mtv110.com
O1 - Hosts: 218.5.76.71 st020.com
O1 - Hosts: 218.5.76.71 www.st020.com
O1 - Hosts: 218.5.76.71 music.jschina.com.cn
O1 - Hosts: 218.5.76.71 real2000.org
O1 - Hosts: 218.5.76.71 www.real2000.org
O1 - Hosts: 218.5.76.71 6bb.com
O1 - Hosts: 218.5.76.71 www.6bb.com
O1 - Hosts: 218.5.76.71 5474.com
O1 - Hosts: 218.5.76.71 www.5474.com
O1 - Hosts: 218.5.76.71 qq163.com
O1 - Hosts: 218.5.76.71 www.qq163.com
O1 - Hosts: 218.5.76.71 ting88.com
O1 - Hosts: 218.5.76.71 www.ting88.com
O1 - Hosts: 218.5.76.71 tt78.com
O1 - Hosts: 218.5.76.71 www.tt78.com
O1 - Hosts: 218.5.76.71 8yh.com
O1 - Hosts: 218.5.76.71 mp3.8yh.com
O1 - Hosts: 218.5.76.71 ibmp3.com
O1 - Hosts: 218.5.76.71 www.ibmp3.com
O1 - Hosts: 218.5.76.71 feifa.com
O1 - Hosts: 218.5.76.71 www.feifa.com
O1 - Hosts: 218.5.76.71 music.feifa.com
O1 - Hosts: 218.5.76.71 91f.net
O1 - Hosts: 218.5.76.71 www.91f.net
O1 - Hosts: 218.5.76.71 6621.com
O1 - Hosts: 218.5.76.71 www.6621.com
O1 - Hosts: 218.5.76.71 ting163.com
O1 - Hosts: 218.5.76.71 www.ting163.com
O1 - Hosts: 218.5.76.71 99music.net
O1 - Hosts: 218.5.76.71 www.99music.net
O1 - Hosts: 218.5.76.71 wo99.com
O1 - Hosts: 218.5.76.71 www.wo99.com
O1 - Hosts: 218.5.76.71 jnnc.com
O1 - Hosts: 218.5.76.71 www.jnnc.com
O1 - Hosts: 218.5.76.71 mtv123.com
O1 - Hosts: 218.5.76.71 www.mtv123.com
O1 - Hosts: 218.5.76.71 dj520.com
O1 - Hosts: 218.5.76.71 www.dj520.com
O1 - Hosts: 218.5.76.71 7xi.net
O1 - Hosts: 218.5.76.71 www.7xi.net
O1 - Hosts: 218.5.76.71 mtv110.com
O1 - Hosts: 218.5.76.71 www.mtv110.com
O1 - Hosts: 218.5.76.71 mtvtop.net
O1 - Hosts: 218.5.76.71 www.mtvtop.net
O1 - Hosts: 218.5.76.71 mtvtop.com
O1 - Hosts: 218.5.76.71 www.mtvtop.com
O1 - Hosts: 218.5.76.71 xaonline.com
O1 - Hosts: 218.5.76.71 music.xaonline.com
O1 - Hosts: 218.5.76.71 musictea.com
O1 - Hosts: 218.5.76.71 www.musictea.com
O1 - Hosts: 218.5.76.71 tfol.com
O1 - Hosts: 218.5.76.71 www.tfol.com
O1 - Hosts: 218.5.76.71 yyue.com
O1 - Hosts: 218.5.76.71 www.yyue.com
O1 - Hosts: 218.5.76.71 yyue.net
O1 - Hosts: 218.5.76.71 www.yyue.net
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\Net Transport\NTIEHelper.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O4 - 启动项HKLM\\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - 启动项HKLM\\Run: [SystemTray] SysTray.Exe
O4 - 启动项HKLM\\Run: [AxFilter] Rundll32.exe C:\WINNT\DOWNLO~1\AxFilter.dll,Rundll32
O4 - 启动项HKLM\\Run: [AVPCC] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe" /wait
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 使用影音传送带下载 - C:\PROGRA~1\Xi\NETTRA~1\NTAddLink.html
O8 - IE右键菜单中的新增项目: 使用影音传送带下载全部链接 - C:\PROGRA~1\Xi\NETTRA~1\NTAddList.html
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{C749AA47-7B3C-4A8D-8A26-8F7984E511C6}: NameServer = 202.101.103.55
O20 - Winlogon Notify: MetaFrame - ctxnotif.dll (file missing)
O23 - NT 服务: AVP Control Centre Service (AVPCC) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe" /service (file missing)
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: KAV Monitor Service (KAVMonitorService) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpm.exe" /service (file missing)

gototop
 

哈哈,可以了,太谢谢您了!
gototop
 

又出现了,看来还没彻底清除干净,再次贴上新的日记:

HijackThis_815汉化版扫描日志 V1.99.1
保存于      11:02:22, 日期 2005-11-6
操作系统:  Windows 2000 SP4 (WinNT 5.00.2195)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpm.exe
C:\WINNT\System32\llssrv.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\WINNT\Explorer.EXE
C:\Program Files\D-Tools\daemon.exe
C:\WINNT\system32\Rundll32.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe
C:\WINNT\system32\internat.exe
c:\!wnm\wnb.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\rundll32.exe
C:\Program Files\HijackThis1991汉化版\HijackThis1991zww.exe

F2 - REG:system.ini: UserInit=userinit,nddeagnt.exe
O1 - Hosts: 218.5.76.71 1ting.com
O1 - Hosts: 218.5.76.71 www.1ting.com
O1 - Hosts: 218.5.76.71 yy138.com
O1 - Hosts: 218.5.76.71 www.yy138.com
O1 - Hosts: 218.5.76.71 dj99.com
O1 - Hosts: 218.5.76.71 www.dj99.com
O1 - Hosts: 218.5.76.71 520music.com
O1 - Hosts: 218.5.76.71 www.520music.com
O1 - Hosts: 218.5.76.71 vv66.com
O1 - Hosts: 218.5.76.71 www.vv66.com
O1 - Hosts: 218.5.76.71 666ccc.com
O1 - Hosts: 218.5.76.71 www.666ccc.com
O1 - Hosts: 218.5.76.71 666qqq.com
O1 - Hosts: 218.5.76.71 www.666qqq.com
O1 - Hosts: 218.5.76.71 100yy.com
O1 - Hosts: 218.5.76.71 www.100yy.com
O1 - Hosts: 218.5.76.71 006.net
O1 - Hosts: 218.5.76.71 www.006.net
O1 - Hosts: 218.5.76.71 2t.cn
O1 - Hosts: 218.5.76.71 www.2t.cn
O1 - Hosts: 218.5.76.71 cococ.com
O1 - Hosts: 218.5.76.71 www.cococ.com
O1 - Hosts: 218.5.76.71 ting.cococ.com
O1 - Hosts: 218.5.76.71 yymp3.com
O1 - Hosts: 218.5.76.71 www.yymp3.com
O1 - Hosts: 218.5.76.71 qq163.com
O1 - Hosts: 218.5.76.71 www.qq163.com
O1 - Hosts: 218.5.76.71 7760.com
O1 - Hosts: 218.5.76.71 www.7760.com
O1 - Hosts: 218.5.76.71 568.com
O1 - Hosts: 218.5.76.71 www.568.com
O1 - Hosts: 218.5.76.71 nowok.net
O1 - Hosts: 218.5.76.71 www.nowok.net
O1 - Hosts: 218.5.76.71 chinamp3.com
O1 - Hosts: 218.5.76.71 www.chinamp3.com
O1 - Hosts: 218.5.76.71 99music.net
O1 - Hosts: 218.5.76.71 www.99music.net
O1 - Hosts: 218.5.76.71 6621.com
O1 - Hosts: 218.5.76.71 www.6621.com
O1 - Hosts: 218.5.76.71 7t7t.com
O1 - Hosts: 218.5.76.71 www.7t7t.com
O1 - Hosts: 218.5.76.71 haoting.com
O1 - Hosts: 218.5.76.71 www.haoting.com
O1 - Hosts: 218.5.76.71 mtv110.com
O1 - Hosts: 218.5.76.71 www.mtv110.com
O1 - Hosts: 218.5.76.71 st020.com
O1 - Hosts: 218.5.76.71 www.st020.com
O1 - Hosts: 218.5.76.71 music.jschina.com.cn
O1 - Hosts: 218.5.76.71 real2000.org
O1 - Hosts: 218.5.76.71 www.real2000.org
O1 - Hosts: 218.5.76.71 6bb.com
O1 - Hosts: 218.5.76.71 www.6bb.com
O1 - Hosts: 218.5.76.71 5474.com
O1 - Hosts: 218.5.76.71 www.5474.com
O1 - Hosts: 218.5.76.71 qq163.com
O1 - Hosts: 218.5.76.71 www.qq163.com
O1 - Hosts: 218.5.76.71 ting88.com
O1 - Hosts: 218.5.76.71 www.ting88.com
O1 - Hosts: 218.5.76.71 tt78.com
O1 - Hosts: 218.5.76.71 www.tt78.com
O1 - Hosts: 218.5.76.71 8yh.com
O1 - Hosts: 218.5.76.71 mp3.8yh.com
O1 - Hosts: 218.5.76.71 ibmp3.com
O1 - Hosts: 218.5.76.71 www.ibmp3.com
O1 - Hosts: 218.5.76.71 feifa.com
O1 - Hosts: 218.5.76.71 www.feifa.com
O1 - Hosts: 218.5.76.71 music.feifa.com
O1 - Hosts: 218.5.76.71 91f.net
O1 - Hosts: 218.5.76.71 www.91f.net
O1 - Hosts: 218.5.76.71 6621.com
O1 - Hosts: 218.5.76.71 www.6621.com
O1 - Hosts: 218.5.76.71 ting163.com
O1 - Hosts: 218.5.76.71 www.ting163.com
O1 - Hosts: 218.5.76.71 99music.net
O1 - Hosts: 218.5.76.71 www.99music.net
O1 - Hosts: 218.5.76.71 wo99.com
O1 - Hosts: 218.5.76.71 www.wo99.com
O1 - Hosts: 218.5.76.71 jnnc.com
O1 - Hosts: 218.5.76.71 www.jnnc.com
O1 - Hosts: 218.5.76.71 mtv123.com
O1 - Hosts: 218.5.76.71 www.mtv123.com
O1 - Hosts: 218.5.76.71 dj520.com
O1 - Hosts: 218.5.76.71 www.dj520.com
O1 - Hosts: 218.5.76.71 7xi.net
O1 - Hosts: 218.5.76.71 www.7xi.net
O1 - Hosts: 218.5.76.71 mtv110.com
O1 - Hosts: 218.5.76.71 www.mtv110.com
O1 - Hosts: 218.5.76.71 mtvtop.net
O1 - Hosts: 218.5.76.71 www.mtvtop.net
O1 - Hosts: 218.5.76.71 mtvtop.com
O1 - Hosts: 218.5.76.71 www.mtvtop.com
O1 - Hosts: 218.5.76.71 xaonline.com
O1 - Hosts: 218.5.76.71 music.xaonline.com
O1 - Hosts: 218.5.76.71 musictea.com
O1 - Hosts: 218.5.76.71 www.musictea.com
O1 - Hosts: 218.5.76.71 tfol.com
O1 - Hosts: 218.5.76.71 www.tfol.com
O1 - Hosts: 218.5.76.71 yyue.com
O1 - Hosts: 218.5.76.71 www.yyue.com
O1 - Hosts: 218.5.76.71 yyue.net
O1 - Hosts: 218.5.76.71 www.yyue.net
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\Net Transport\NTIEHelper.dll
O4 - 启动项HKLM\\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - 启动项HKLM\\Run: [SystemTray] SysTray.Exe
O4 - 启动项HKLM\\Run: [AxFilter] Rundll32.exe C:\WINNT\DOWNLO~1\AxFilter.dll,Rundll32
O4 - 启动项HKLM\\Run: [AVPCC] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe" /wait
O4 - 启动项HKLM\\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [internat.exe] internat.exe
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 使用影音传送带下载 - C:\PROGRA~1\Xi\NETTRA~1\NTAddLink.html
O8 - IE右键菜单中的新增项目: 使用影音传送带下载全部链接 - C:\PROGRA~1\Xi\NETTRA~1\NTAddList.html
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{C749AA47-7B3C-4A8D-8A26-8F7984E511C6}: NameServer = 202.101.103.55
O20 - Winlogon Notify: MetaFrame - ctxnotif.dll (file missing)
O23 - NT 服务: AVP Control Centre Service (AVPCC) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe" /service (file missing)
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: KAV Monitor Service (KAVMonitorService) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpm.exe" /service (file missing)

gototop
 

hosts文件我已清除过了,第一次按你的方法处理重启后正常了,但运行一段时间后就又出现主页和hosts被改,望版主再看看还有什么解决的方法,还需要提供什么资料吗?谢谢!
gototop
 

处理了,还是会的,两台都一样,一台是win2000 server,一台是win2003,连在局域网上,会不会是互相感染?
gototop
 

这下完完了,可能有木马了,系统进程中多了cmd.exe和ftp.exe两个进程,而且无法关闭进程,怎么办呢?
gototop
 

cmd.exe和ftp.exe这两个如果是正常的进程是可以结束进程树的,问题是现在不能关闭进程树就有点怪了,或是我判断错了。
gototop
 

我把win2003关机后,在win2000 server机子上进行如下处理:
1、设置ie主页为空白页;
2、删除cookies,删除脱机文件,清除历史记录;
3、清除hosts中的所有内容;
4、清除临时文件夹中的所有内容;
5、重启电脑;
现扫描后如下:

HijackThis_815汉化版扫描日志 V1.99.1
保存于      15:05:24, 日期 2005-11-6
操作系统:  Windows 2000 SP4 (WinNT 5.00.2195)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpm.exe
C:\WINNT\System32\llssrv.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\WINNT\Explorer.EXE
C:\Program Files\D-Tools\daemon.exe
C:\WINNT\system32\Rundll32.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe
C:\WINNT\system32\internat.exe
c:\!wnm\wnb.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\TIMPlatform.exe
C:\WINNT\system32\conime.exe
C:\Program Files\HijackThis1991汉化版\HijackThis1991zww.exe

F2 - REG:system.ini: UserInit=userinit,nddeagnt.exe
O1 - Hosts: 218.5.76.71 1ting.com
O1 - Hosts: 218.5.76.71 www.1ting.com
O1 - Hosts: 218.5.76.71 yy138.com
O1 - Hosts: 218.5.76.71 www.yy138.com
O1 - Hosts: 218.5.76.71 dj99.com
O1 - Hosts: 218.5.76.71 www.dj99.com
O1 - Hosts: 218.5.76.71 520music.com
O1 - Hosts: 218.5.76.71 www.520music.com
O1 - Hosts: 218.5.76.71 vv66.com
O1 - Hosts: 218.5.76.71 www.vv66.com
O1 - Hosts: 218.5.76.71 666ccc.com
O1 - Hosts: 218.5.76.71 www.666ccc.com
O1 - Hosts: 218.5.76.71 666qqq.com
O1 - Hosts: 218.5.76.71 www.666qqq.com
O1 - Hosts: 218.5.76.71 100yy.com
O1 - Hosts: 218.5.76.71 www.100yy.com
O1 - Hosts: 218.5.76.71 006.net
O1 - Hosts: 218.5.76.71 www.006.net
O1 - Hosts: 218.5.76.71 2t.cn
O1 - Hosts: 218.5.76.71 www.2t.cn
O1 - Hosts: 218.5.76.71 cococ.com
O1 - Hosts: 218.5.76.71 www.cococ.com
O1 - Hosts: 218.5.76.71 ting.cococ.com
O1 - Hosts: 218.5.76.71 yymp3.com
O1 - Hosts: 218.5.76.71 www.yymp3.com
O1 - Hosts: 218.5.76.71 qq163.com
O1 - Hosts: 218.5.76.71 www.qq163.com
O1 - Hosts: 218.5.76.71 7760.com
O1 - Hosts: 218.5.76.71 www.7760.com
O1 - Hosts: 218.5.76.71 568.com
O1 - Hosts: 218.5.76.71 www.568.com
O1 - Hosts: 218.5.76.71 nowok.net
O1 - Hosts: 218.5.76.71 www.nowok.net
O1 - Hosts: 218.5.76.71 chinamp3.com
O1 - Hosts: 218.5.76.71 www.chinamp3.com
O1 - Hosts: 218.5.76.71 99music.net
O1 - Hosts: 218.5.76.71 www.99music.net
O1 - Hosts: 218.5.76.71 6621.com
O1 - Hosts: 218.5.76.71 www.6621.com
O1 - Hosts: 218.5.76.71 7t7t.com
O1 - Hosts: 218.5.76.71 www.7t7t.com
O1 - Hosts: 218.5.76.71 haoting.com
O1 - Hosts: 218.5.76.71 www.haoting.com
O1 - Hosts: 218.5.76.71 mtv110.com
O1 - Hosts: 218.5.76.71 www.mtv110.com
O1 - Hosts: 218.5.76.71 st020.com
O1 - Hosts: 218.5.76.71 www.st020.com
O1 - Hosts: 218.5.76.71 music.jschina.com.cn
O1 - Hosts: 218.5.76.71 real2000.org
O1 - Hosts: 218.5.76.71 www.real2000.org
O1 - Hosts: 218.5.76.71 6bb.com
O1 - Hosts: 218.5.76.71 www.6bb.com
O1 - Hosts: 218.5.76.71 5474.com
O1 - Hosts: 218.5.76.71 www.5474.com
O1 - Hosts: 218.5.76.71 qq163.com
O1 - Hosts: 218.5.76.71 www.qq163.com
O1 - Hosts: 218.5.76.71 ting88.com
O1 - Hosts: 218.5.76.71 www.ting88.com
O1 - Hosts: 218.5.76.71 tt78.com
O1 - Hosts: 218.5.76.71 www.tt78.com
O1 - Hosts: 218.5.76.71 8yh.com
O1 - Hosts: 218.5.76.71 mp3.8yh.com
O1 - Hosts: 218.5.76.71 ibmp3.com
O1 - Hosts: 218.5.76.71 www.ibmp3.com
O1 - Hosts: 218.5.76.71 feifa.com
O1 - Hosts: 218.5.76.71 www.feifa.com
O1 - Hosts: 218.5.76.71 music.feifa.com
O1 - Hosts: 218.5.76.71 91f.net
O1 - Hosts: 218.5.76.71 www.91f.net
O1 - Hosts: 218.5.76.71 6621.com
O1 - Hosts: 218.5.76.71 www.6621.com
O1 - Hosts: 218.5.76.71 ting163.com
O1 - Hosts: 218.5.76.71 www.ting163.com
O1 - Hosts: 218.5.76.71 99music.net
O1 - Hosts: 218.5.76.71 www.99music.net
O1 - Hosts: 218.5.76.71 wo99.com
O1 - Hosts: 218.5.76.71 www.wo99.com
O1 - Hosts: 218.5.76.71 jnnc.com
O1 - Hosts: 218.5.76.71 www.jnnc.com
O1 - Hosts: 218.5.76.71 mtv123.com
O1 - Hosts: 218.5.76.71 www.mtv123.com
O1 - Hosts: 218.5.76.71 dj520.com
O1 - Hosts: 218.5.76.71 www.dj520.com
O1 - Hosts: 218.5.76.71 7xi.net
O1 - Hosts: 218.5.76.71 www.7xi.net
O1 - Hosts: 218.5.76.71 mtv110.com
O1 - Hosts: 218.5.76.71 www.mtv110.com
O1 - Hosts: 218.5.76.71 mtvtop.net
O1 - Hosts: 218.5.76.71 www.mtvtop.net
O1 - Hosts: 218.5.76.71 mtvtop.com
O1 - Hosts: 218.5.76.71 www.mtvtop.com
O1 - Hosts: 218.5.76.71 xaonline.com
O1 - Hosts: 218.5.76.71 music.xaonline.com
O1 - Hosts: 218.5.76.71 musictea.com
O1 - Hosts: 218.5.76.71 www.musictea.com
O1 - Hosts: 218.5.76.71 tfol.com
O1 - Hosts: 218.5.76.71 www.tfol.com
O1 - Hosts: 218.5.76.71 yyue.com
O1 - Hosts: 218.5.76.71 www.yyue.com
O1 - Hosts: 218.5.76.71 yyue.net
O1 - Hosts: 218.5.76.71 www.yyue.net
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\Net Transport\NTIEHelper.dll
O4 - 启动项HKLM\\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - 启动项HKLM\\Run: [SystemTray] SysTray.Exe
O4 - 启动项HKLM\\Run: [AxFilter] Rundll32.exe C:\WINNT\DOWNLO~1\AxFilter.dll,Rundll32
O4 - 启动项HKLM\\Run: [AVPCC] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe" /wait
O4 - HKCU\..\Run: [internat.exe] internat.exe
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 使用影音传送带下载 - C:\PROGRA~1\Xi\NETTRA~1\NTAddLink.html
O8 - IE右键菜单中的新增项目: 使用影音传送带下载全部链接 - C:\PROGRA~1\Xi\NETTRA~1\NTAddList.html
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{C749AA47-7B3C-4A8D-8A26-8F7984E511C6}: NameServer = 202.101.103.55
O20 - Winlogon Notify: MetaFrame - ctxnotif.dll (file missing)
O23 - NT 服务: AVP Control Centre Service (AVPCC) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpcc.exe" /service (file missing)
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: KAV Monitor Service (KAVMonitorService) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus for MS NT Server\avpm.exe" /service (file missing)

补充说明:
  原来清空hosts和设ie主页为空白页后重启电脑就又马上被改掉,现重启电脑后要过1分钟左右主页和hosts才会被改。
gototop
 

这次应改彻底解决了,开机好久了hosts文件和ie主页都正常,谢谢版主。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT