1   1  /  1  页   跳转

啊【求助】

啊【求助】

Logfile of HijackThis v1.99.0
Scan saved at 0:25:27, on 2006-2-11
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\杀毒工具\瑞星杀毒\RISING\RAV\Ravmond.exe
D:\杀毒工具\瑞星杀毒\RISING\RAV\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\System32\nvsvc32.exe
D:\杀毒工具\瑞星杀毒\RISING\RAV\CCENTER.EXE
C:\Program Files\Common Files\COMM\Network.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\杀毒工具\瑞星杀毒\Rising\Rav\RavMon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\HijackThis\HijackThis.exe

R3 - URLSearchHook: MyURLSearchHook Class - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - C:\Program Files\P4P\ToolBar.dll
R3 - URLSearchHook: SgUrlSearHook Class - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - C:\WINDOWS\system32\socul.dll
R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v13.dll
O2 - BHO: Tencent Browser Helper - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\Program Files\TENCENT\AdPlus\IEHelp.dll
O2 - BHO: SohuDAIEHelper - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - C:\Program Files\P4P\sodaie.dll
O2 - BHO: QuickBtn - {1A199C20-DE2B-4838-AE3F-B5257ECE2B7E} - C:\Program Files\CoolWebsite\QuickLink.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll
O2 - BHO: Deliverer Class - {3E290290-1728-4C1E-863A-AA12526333F6} - C:\Program Files\CNet\ADDeliverer\ADDeliverer.dll
O2 - BHO: (no name) - {3E290290-1728-4C1E-863A-AA12526333F6}? - (no file)
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - F:\qq\QQIEHelper.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B}? - (no file)
O2 - BHO: Accoona Search Assistant - {944864A5-3916-46E2-96A9-A2E84F3F1208} - C:\Program Files\Accoona\ASearchAssist.dll
O2 - BHO: HBObject Class - {AE22AFE5-1EF4-4D25-9E23-D2825FB17DA1} - C:\PROGRA~1\HBClient\tbhelper.dll
O2 - BHO: DownloadBHO T2BHO - {B1D147E7-873E-4909-8127-695D9BB78728}? - (no file)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\CnsHook.dll
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O3 - Toolbar: Accoona - {364B6276-C6C1-40B6-A6D7-6C48871FD707} - C:\Program Files\Accoona\atoolbar.dll
O3 - Toolbar: 天下搜索 - {56A7DC70-E102-4408-A34A-AE06FEF01586} - C:\WINDOWS\Downloaded Program Files\CONFLICT.2\iebar23.0.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RichMedia] C:\WINDOWS\system32\Rundll32.exe  "C:\PROGRA~1\HBClient\tbhelper.dll",WaitWindows
O4 - HKLM\..\Run: [AddrPlus3] C:\PROGRA~1\TENCENT\AdPlus\Runner.exe C:\PROGRA~1\TENCENT\AdPlus\QAHook.dll Rundll32
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Thunder] "D:\辅助工具\Thunder\ThunderShell.exe" /s
O4 - HKLM\..\Run: [Skype] D:\游戏软件\skype\Phone\Skype.exe
O4 - HKLM\..\Run: [DAEMON Tools-2052] "D:\游戏软件\daemon.exe"  -lang 2052
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: 腾讯QQ.lnk
O8 - Extra context menu item: !搜一搜 - res://C:\Program Files\yisou\yisou.dll/232
O8 - Extra context menu item: &使用迅雷下载 - D:\辅助工具\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\辅助工具\Thunder\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - F:\qq\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\qq\SendMMS.htm
O8 - Extra context menu item: 雅虎搜索 - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm (file missing)
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289}? - http://sms.3721.com/ie/index.htm (file missing)
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - F:\浩方\浩方对战平台\浩方对战平台\GameClient.exe
O9 - Extra button: 实用网址导航 - {1D901067-2529-4A9B-9B6B-7A1DB3A44CB5} - C:\Program Files\CoolWebsite\QuickLink.dll
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\qq\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\qq\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6}? - F:\qq\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6}? - F:\qq\QQIEHelper.dll
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5}? - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5}? - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\hbmter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hbmter.dll
O11 - Options group: [!CNS]  网络实名
O16 - DPF: {52DF16E3-6C4F-4B22-8BAF-09263E463B48} (金山毒霸在线产品升级) - http://218.30.82.36/md5/YahooOnlineScanTest/KOSInit.cab
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} (天下搜索) - http://iebar.t2t2.com/iebar.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F9FA5B5B-9261-49B9-B432-B9DE10974FD9}: NameServer = 61.147.37.1 61.177.7.1
O23 - Service: Abidfac5f-r -  - (no file)
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Rising Process Communication Center - rising - D:\杀毒工具\瑞星杀毒\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service - Beijing Rising Technology Co., Ltd. - D:\杀毒工具\瑞星杀毒\RISING\RAV\Ravmond.exe
O23 - Service: Network System - COMENET TECHNOLOGY - C:\Program Files\Common Files\COMM\Network.exe

最后编辑2006-02-11 14:13:01
分享到:
gototop
 

【回复“天使之剑”的帖子】请问这2个扫描如何使用
全是英文看不懂请指导下
gototop
 

【回复“天使之剑”的帖子】
用http://www.virustotal.com/扫描的结果
Este es el resultado de analizar el archivo "QuickLink.dll" que VirusTotal ha procesado el dia 10/02/2006 a las 18:16:39 (CET).
Antivirus Version Actualización Resultado
AntiVir 6.33.0.81 10.02.2006 no ha encontrado virus
Avast 4.6.695.0 10.02.2006 no ha encontrado virus
AVG 718 10.02.2006 no ha encontrado virus
Avira 6.33.0.81 10.02.2006 no ha encontrado virus
BitDefender 7.2 10.02.2006 no ha encontrado virus
CAT-QuickHeal 8.00 10.02.2006 no ha encontrado virus
ClamAV devel-20060126 09.02.2006 no ha encontrado virus
DrWeb 4.33 10.02.2006 no ha encontrado virus
eTrust-InoculateIT 23.71.72 09.02.2006 no ha encontrado virus
eTrust-Vet 12.4.2074 10.02.2006 no ha encontrado virus
Ewido 3.5 10.02.2006 no ha encontrado virus
Fortinet 2.54.0.0 10.02.2006 no ha encontrado virus
F-Prot 3.16c 09.02.2006 no ha encontrado virus
Ikarus 0.2.59.0 10.02.2006 no ha encontrado virus
Kaspersky 4.0.2.24 10.02.2006 no ha encontrado virus
McAfee 4694 10.02.2006 no ha encontrado virus
NOD32v2 1.1402 09.02.2006 no ha encontrado virus
Norman 5.70.10 10.02.2006 no ha encontrado virus
Panda 9.0.0.4 10.02.2006 no ha encontrado virus
Sophos 4.02.0 10.02.2006 no ha encontrado virus
Symantec 8.0 10.02.2006 no ha encontrado virus
TheHacker 5.9.4.094 10.02.2006 no ha encontrado virus
UNA 1.83 09.02.2006 no ha encontrado virus
VBA32 3.10.5 10.02.2006 no ha encontrado virus



VirusTotal es un servicio gratuito ofrecido por Hispasec Sistemas, que no garantiza la disponibilidad y continuidad de funcionamiento de este. Pese a que el indice de detección ofrecido por el análisis simultaneo de múltiples motores antivirus es muy superior al de un solo producto, los resultados NO pueden garantizar la inocuidad de un archivo. No existe solución que pueda ofrecer un 100% de efectividad en el reconocimiento de virus y malware en general.
请帮忙看看
gototop
 

【回复“魔法学徒”的帖子】未能在控制面版下的管理工具的服务里面找到REMOTE LOG文件请问该怎么办?
gototop
 

【回复“天使之剑”的帖子】http://virusscan.jotti.org/扫描结果如下请帮忙看看
Scanner  Malware name 
AntiVir  Worm/Procil.a.1 
ArcaVir  Trojan.Spy.Sckeylog.Ac 
Avast  Win32:Keylog-016 
AVG Antivirus  PSW.Generic.U 
BitDefender  Trojan.SCKeyLog.20 
ClamAV  Trojan.SCKeylog-7 
Dr.Web  Trojan.SCKeyLog.45 
F-Prot Antivirus  W32/SCkeylogger.G@spy 
Fortinet  W32/Sckeylog.V-tr 
Kaspersky Anti-Virus  Trojan-Spy.Win32.SCKeyLog.ac 
NOD32  Win32/Spy.SCKeyLog 
Norman Virus Control  W32/SCKeylog.DR 
UNA  Trojan.Spy.Win32.SCKeyLog 
VBA32  Trojan-Spy.Win32.SCKeyLog.v 

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT