1   1  /  1  页   跳转

我看到日志了 帮我看看IE 谢谢拉

我看到日志了 帮我看看IE 谢谢拉

我挑出一些可疑的 帮我看看 谢谢
2006-05-04 15:03:04, 系统禁止本地rundll32.exe连接网络的请求,地址为:TCP, 0.0.0.0:2049[NFS服务器] => 211.100.33.75:80[WEB网页]程序名称为:C:\WINDOWS\system32\rundll32.exe
2006-05-04 13:44:03, 系统禁止本地rundll32.exe连接网络的请求,地址为:TCP, 0.0.0.0:1813[Radius评估] => 220.163.176.236:80[WEB网页]程序名称为:C:\WINDOWS\system32\rundll32.exe
2006-05-04 13:44:00, 系统禁止本地rundll32.exe连接网络的请求,地址为:TCP, 0.0.0.0:1812[Radius认证] => 220.163.176.236:80[WEB网页]程序名称为:C:\WINDOWS\system32\rundll32.exe
2006-05-04 13:43:57, 系统禁止本地rundll32.exe连接网络的请求,地址为:TCP, 0.0.0.0:1808 => 220.163.176.236:80[WEB网页]程序名称为:C:\WINDOWS\system32\rundll32.exe
2006-05-04 13:43:54, 系统禁止本地rundll32.exe连接网络的请求,地址为:TCP, 0.0.0.0:1807[SpySender木马] => 220.163.176.236:80[WEB网页]程序名称为:C:\WINDOWS\system32\rundll32.exe
2006-05-04 13:41:18, 系统禁止本地rundll32.exe连接网络的请求,地址为:TCP, 0.0.0.0:1755[流媒体服务] => 220.163.176.236:80[WEB网页]程序名称为:C:\WINDOWS\system32\rundll32.exe
2006-05-04 13:40:06, 系统禁止本地rundll32.exe连接网络的请求,地址为:TCP, 0.0.0.0:1731[Netmeeting] => 218.61.36.241:80[WEB网页]程序名称为:C:\WINDOWS\system32\rundll32.exe
2006-05-04 13:39:42, 系统禁止本地rundll32.exe连接网络的请求,地址为:TCP, 0.0.0.0:1723[PPTP(虚拟专用网)] => 218.61.36.241:80[WEB网页]程序名称为:C:\WINDOWS\system32\rundll32.exe
最后编辑2006-05-05 22:13:34
分享到:
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 0:17:40, on 2006-5-5
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
D:\应用程序\3D MAX\mentalray\satellite\raysat_3dsmax8server.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Rising\Rfw\rfwmain.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe
D:\应用程序\RealPlayer\RealPlay.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\下载文件\HijackThis.exe
D:\应用程序\金山快译\FastAIT.exe

R3 - URLSearchHook: (no name) - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINDOWS\system32\wmpdrm.dll
O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper200653_8029.dll
O2 - BHO: Zhongsou Browser Helper - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:\Program Files\SearchNet\SNHpr.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: DTSvc Class - {6B280AC7-8B18-46A4-BF70-FC579A1B2F76} - C:\Program Files\DTSVC\DTS\DTS.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\应τ用贸程绦序騖\FlashGet\jccatch.dll (file missing)
O2 - BHO: HBObject Class - {AE22AFE5-1EF4-4D25-9E23-D2825FB17DA1} - C:\PROGRA~1\HBClient\hbhelper.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\CnsHook.dll
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - C:\PROGRA~1\yisou\yisoub.dll
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O3 - Toolbar: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\Program Files\yisou\yisou.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ASUS Probe] rem C:\Program Files\ASUS\Asus Probe\AsusProb.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [helper.dll] rem C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [YLive.exe] rem C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [yassistse] rem "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [RichMedia] C:\WINDOWS\system32\Rundll32.exe  "C:\PROGRA~1\HBClient\hbhelper.dll",WaitWindows
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: eBay易趣--全球商品一网打尽.lnk = C:\Program Files\EbayShop\EbayShop.exe
O8 - Extra context menu item: !搜一搜 - res://C:\Program Files\yisou\yisou.dll/232
O8 - Extra context menu item: 使用网际快车下载 - D:\应用程序\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\应用程序\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\应用程序\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\应用程序\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\应用程序\qq\SendMMS.htm
O8 - Extra context menu item: 翻译英文字词(&T) - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao (file missing)
O9 - Extra button: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O11 - Options group: [!CNS]  网络实名
O17 - HKLM\System\CCS\Services\Tcpip\..\{1C5D9C3A-D334-4A34-889F-0CD4DC133EF6}: NameServer = 61.177.7.1 221.228.255.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{C01A30E2-B359-49C7-A28E-FC04A2D8131A}: NameServer = 61.177.7.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1C5D9C3A-D334-4A34-889F-0CD4DC133EF6}: NameServer = 61.177.7.1 221.228.255.1
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - D:\应用程序\3D MAX\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
gototop
 

它还会自己给我安装eBay易趣 郁闷啊
被我删除好几次 了这次又来了
gototop
 

我这个能解决吗
gototop
 

感谢8楼 我问题解决了
不过有点疑问
我昨天把系统还原了一下
结果还是一样
我来看了帖子才解决了问题
不过有几项的后缀不样 我不干删除
C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper200653_8029.dll
现在文件名叫:wd2_051117_WIS190_mini.exe
C:\WINDOWS\SYSTEM32\stdup.dll
现在文件名叫:stdup.uni
C:\PROGRA~1\HBClient
C盘里没C:\PROGRA~1
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT