最新扫描的,大家帮我看看,这个恶意的网页。

HijackThis_815汉化版扫描日志 V1.99.1
保存于      18:07:58 上午, 日期 2005-12-25
操作系统:  Windows XP  (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 (6.00.2600.0000)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Tencent\qq\QQ.exe
d:\Program Files\Tencent\qq\TIMPlatform.exe
D:\Program Files\Maxthon\Maxthon.exe
C:\WINDOWS\System32\conime.exe
C:\WINDOWS\System32\taskmgr.exe
d:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\张伟健\LOCALS~1\Temp\Rar$EX00.805\HijackThis1991zww.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: 超级兔子上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\PROGRA~1\SUPERR~1\IEG\HAOKAN~2.DLL
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\KUAICH~1\fgiebar.dll
O3 - IE工具栏增项: Infofo 工具栏 - {D74EC18E-3DDD-4174-B1B1-949FE3B8366D} - C:\Program Files\Infofo Bar\infofobar.dll
O3 - IE工具栏增项: 超级兔子上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\PROGRA~1\SUPERR~1\IEG\HAOKAN~2.DLL
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
O4 - 启动项HKLM\\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Super Rabbit IEPro] D:\Program Files\Super Rabbit\IEG\SRIECLI.EXE /LOAD
O4 - Global Startup: Internet Explorer.URL
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - D:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - D:\Program Files\kuaiche9999\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - D:\Program Files\kuaiche9999\jc_all.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Excel(&x) - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\Program Files\Tencent\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\Program Files\Tencent\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\Program Files\Tencent\qq\SendMMS.htm
O9 - 浏览器额外的按钮: 江民在线杀毒 - {06926B30-424E-4f1c-8EE3-543CD96573DC} - http://online.jiangmin.com/online.asp (file missing)
O9 - 浏览器额外的按钮: (no name) - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - http://www32.websamba.com/ppmmpic/c/?a=&b=&c=rx&d=s30&e=&f=&i=&j=685451&t=12/23/2005&s=b (file missing)
O9 - 浏览器额外的按钮: (no name) - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://www32.websamba.com/ppmmpic/c/?a=&b=&c=rx&d=s30&e=&f=&i=&j=685451&t=12/23/2005&s=b (file missing)
O9 - 浏览器额外的按钮: 漂漂娱乐网 - {6713E8D2-850A-101B-AFC0-4210102A8DA7} - http://www32.websamba.com/ppmmpic/c/?a=&b=&c=rx&d=s30&e=&f=&i=&j=685451&t=12/23/2005&s=bm (file missing)
O9 - 浏览器额外的按钮: (no name) - {A23817F2-733B-4BC5-8DED-C1B9B4BBF93C} - (no file)
O9 - 浏览器额外的按钮: (no name) - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - http://www32.websamba.com/ppmmpic/c/?a=&b=&c=rx&d=s30&e=&f=&i=&j=685451&t=12/23/2005&s=b (file missing)
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://www32.websamba.com/ppmmpic/c/?a=&b=&c=rx&d=s30&e=&f=&i=&j=685451&t=12/23/2005&s=t1 (file missing)
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://www32.websamba.com/ppmmpic/c/?a=&b=&c=rx&d=s30&e=&f=&i=&j=685451&t=12/23/2005&s=t2 (file missing)
O9 - 浏览器额外的按钮: 漂漂娱乐网 - {6713E8D2-850A-101B-AFC0-4210102A8DA7} - http://www32.websamba.com/ppmmpic/c/?a=&b=&c=rx&d=s30&e=&f=&i=&j=685451&t=12/23/2005&s=bu (file missing) (HKCU)
O17 - HKLM\System\CCS\Services\Tcpip\..\{3D68680F-9A62-4E2B-87B2-B39406B57D76}: NameServer = 202.103.96.112,202.103.96.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{3D68680F-9A62-4E2B-87B2-B39406B57D76}: NameServer = 202.103.96.112,202.103.96.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{3D68680F-9A62-4E2B-87B2-B39406B57D76}: NameServer = 202.103.96.112,202.103.96.68
O23 - NT 服务: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - NT 服务: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - NT 服务: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe



说明一下
就是上面的那个
http://www32.websamba.com/ppmmpic/c/?a=&b=&c=rx&d=s30&e=&f=&i=&j=685451&t=12/23/2005&s=t1
这个网页真TM难搞
一开机就自动打开
而且自动下载木马

各路高手帮帮忙怎么搞定它
找了好久注册表都没有找到它
在启动项里去了之后一重启了它就又来了
最后编辑2005-12-25 18:43:06