1   1  /  1  页   跳转

【求助】请高手来看看...

【求助】请高手来看看...

无缘无故 弹乱七八糟的网是怎么会事
最后编辑2006-08-26 18:15:31
分享到:
gototop
 

这个是SREngLOG 的扫描日记
2006-08-26,17:50:49

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
    <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>  [Microsoft Corporation]
    <Realplayer.exe><C:\WINDOWS\system32\Realplayer.exe>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <CdnCtr><C:\Program Files\CNNIC\Cdn\cdnup.exe>  []
    <Torjan Program><C:\WINDOWS\WINLOGON.EXE>  [cE4zuDBQ9jPL0ldamHSG]
    <RavScanBD><"G:\Tools\ScanBD.exe" /INST>  []
    <ToP><C:\WINDOWS\LSASS.exe>  [nYVmLJNNBoK0PT1Uvl2f]
    <TProgram><C:\WINDOWS\SMSS.EXE>  [Xs5kzBEUMw1vRVHCJxSh]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  []
    <Realplayer.exe><C:\WINDOWS\system32\Realplayer.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <mosbhlp><rundll32.exe C:\WINDOWS\system32\oobe\msobsys.dll,_S1>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe 1>  []
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
    <{F3D0D422-CE6D-47B3-9CE6-C54DD63F1ADB}><C:\Program Files\Internet Explorer\PLUGINS\new123.sys>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <DelayRun><C:\WINDOWS\system\31adf460.dll>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
    <WinlogonNotify: AtiExtEvent><Ati2evxx.dll>  [ATI Technologies Inc.]

==================================
启动文件夹
服务
[Ati HotKey Poller / Ati HotKey Poller]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart]
  <C:\WINDOWS\system32\ati2sgag.exe><>
[Distributed Link Tracking Clienteers / dltcedrs]
  <c:\windows\system32\wdfmrg.exe><N/A>
[Distributed Link Tracking Clienter / HService2]
  <c:\windows\system32\SVCH0ST.EXE><>
[Rising Personal Firewall Service / RfwService]
  <f:\新建文件夹\rising\rising\rfw\rfwsrv.exe><N/A>
[Rising Process Communication Center / RsCCenter]
  <"F:\新建文件夹\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"F:\新建文件夹\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Volume Shadow Copyre / ServiceCopyre]
  <c:\windows\system32\servicers.exe><>
[Network Location Awareness (NAL) / ServiceNAL]
  <c:\windows\system32\kav.exe><>
[XDownloadService / XDownloadService]
  <C:\WINDOWS\system32\Rundll32.exe "C:\WINDOWS\Downloader.dll",Run><N/A>
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 17:59:37, on 2006-8-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\WINLOGON.EXE
C:\WINDOWS\system32\ctfmon.exe
D:\HijackThis.exe

F2 - REG:system.ini: Shell=Explorer.exe 1
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\IEHelper\IEHelper_5002.dll
O2 - BHO: (no name) - {16B770A0-0E87-4278-B748-2460D64A8386}? - (no file)
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O2 - BHO: (no name) - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108}? - (no file)
O2 - BHO: OsbornTech Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\WINDOWS\system32\msobhp.dll
O3 - Toolbar: 实用搜索工具条V2.0 - {75D82598-4A3C-419e-99D2-3EB56D09CFD0} - C:\Program Files\UtilToolBar\utilbar.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
O4 - HKLM\..\Run: [RavScanBD] "G:\Tools\ScanBD.exe" /INST
O4 - HKLM\..\Run: [ToP] C:\WINDOWS\LSASS.exe
O4 - HKLM\..\Run: [TProgram] C:\WINDOWS\SMSS.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Realplayer.exe] C:\WINDOWS\system32\Realplayer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Realplayer.exe] C:\WINDOWS\system32\Realplayer.exe
O8 - Extra context menu item: &使用迅雷下载 - D:\新建文件夹\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\新建文件夹\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - F:\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\QQ\SendMMS.htm
O8 - Extra context menu item: 访问通用网址 - C:\Program Files\CNNIC\Cdn\cnnic.htm
O9 - Extra button: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra button: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} - http://www.rising.com.cn/?u=RSTB (file missing)
O9 - Extra button: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com/?u=RSTB (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\wshcon32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wshcon32.dll
O11 - Options group: [CDNCLIENT]  中文上网
O21 - SSODL: DelayRun - {5A6F2F95-3191-433B-8533-EB0B596A7BAC} - C:\WINDOWS\system\31adf460.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Distributed Link Tracking Clienteers (dltcedrs) - Unknown owner - c:\windows\system32\wdfmrg.exe (file missing)
O23 - Service: Distributed Link Tracking Clienter (HService2) - Unknown owner - c:\windows\system32\SVCH0ST.EXE
O23 - Service: Rising Personal Firewall Service (RfwService) - Unknown owner - f:\新建文件夹\rising\rising\rfw\rfwsrv.exe
O23 - Service: Volume Shadow Copyre (ServiceCopyre) - Unknown owner - c:\windows\system32\servicers.exe
O23 - Service: Network Location Awareness (NAL) (ServiceNAL) - Unknown owner - c:\windows\system32\kav.exe

这个是HIJACKTHIS 的..还有..如果不是.安全模式不让我开HIJACKTHIS 和防火墙
gototop
 

O23 - Service: Distributed Link Tracking Clienteers (dltcedrs) - Unknown owner - c:\windows\system32\wdfmrg.exe (file missing)
O23 - Service: Distributed Link Tracking Clienter (HService2) - Unknown owner - c:\windows\system32\SVCH0ST.EXE
O23 - Service: Volume Shadow Copyre (ServiceCopyre) - Unknown owner - c:\windows\system32\servicers.exe
O23 - Service: Network Location Awareness (NAL) (ServiceNAL) - Unknown owner - c:\windows\system32\kav.exe
这几个是不是要修复的???我是菜鸟不太懂..以前有事都是重装.但结果还是..一样
gototop
 

c:\windows\system32\SVCH0ST.EXE
c:\windows\system32\servicers.exe
c:\windows\system32\kav.exe
这个是不是在.文件里删..
还有..7939 被劫...按照他们的方式搞过后..结果还是被默认了主页
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT