恳请看被4199改主页后的日志.谢谢

我的情况是用超级兔子,木马杀客,瑞星杀毒后,清理了一些木马和病毒,重起电脑ie暂时恢复,等到第二天启动ie,今天是想打开QQ,发现瑞星的注册表更改提示又出来(一个叫run**.exe的运行文件),拒绝更改也没用,主页又是www.4199.com.用超级兔子的ie修复,找到:
在硬盘中找到以下可疑程序:
C:\WINDOWS\system32\USER.DLL.谢谢你们热心的,无私的为我们解决问题.因为有了你们,我们的电脑才能干净,心情才能舒畅.再次谢谢.

Logfile of HijackThis v1.99.1
Scan saved at 20:50:16, on 2006-9-21
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
D:\瑞星\rav\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\瑞星\rav\Rav\Ravmond.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\瑞星\rav\Rav\RavTask.exe
D:\新木马杀\mmsk\mmsk.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE
D:\瑞星\rav\Rav\Ravmon.exe
C:\WINDOWS\system32\spoolsv.exe
D:\瑞星\rav\Rav\RavStub.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\瑞星\rav\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
D:\迅雷\anzhuang\Program\Thunder5.exe
D:\HijackThis\HijackThis.exe

R3 - URLSearchHook: (no name) - {6D53ADB7-6AD5-4A59-BFE4-

7B57D2F4AA89} - (no file)
O1 - Hosts: 125.91.1.20 localhost
O1 - Hosts: 125.91.1.20 www.7939.com
O1 - Hosts: 125.91.1.20 www.hao123.com
O1 - Hosts: 125.91.1.20 www.9991.com
O1 - Hosts: 125.91.1.20 www.5566.net
O1 - Hosts: 125.91.1.20 www.gjj.cc
O1 - Hosts: 125.91.1.20 www.265.com
O1 - Hosts: 125.91.1.20 www.v111.com
O1 - Hosts: 125.91.1.20 www.7322.com
O2 - BHO: 超级兔子上网精灵 - {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} -

C:\PROGRA~1\SUPERR~1\MAGICSET\haokanbar.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\迅

雷\anzhuang\ComDlls\XunLeiBHO_002.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} -

C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-

90B976C2707C} - C:\WINDOWS\System32\KakaTool.dll
O3 - Toolbar: 超级兔子上网精灵 - {43869BB3-22FD-4F15-9B46-

238106BA2F4E} - C:\PROGRA~1\SUPERR~1\MAGICSET\haokanbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE"

/Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] ; C:\WINDOWS\System32

\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\System32

\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\System32

\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SysExplr] ; C:\Herosoft\HeroV8\SYSEXPLR.EXE
O4 - HKLM\..\Run: [IMSCMig] ; C:\PROGRA~1\COMMON~1\MICROS~1

\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common

Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [YDTMain.exe] ; C:\PROGRA~1\YDT\YDTMain.exe
O4 - HKLM\..\Run: [RavTask] "D:\瑞星\rav\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0

-k
O4 - HKLM\..\Run: [mmsk] D:\新木马杀\mmsk\mmsk.exe
O4 - HKLM\..\Run: [rundll] rundll32 user.dll s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN

Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Super Rabbit IEPro] C:\Program Files\Super

Rabbit\MagicSet\SRIECLI.EXE /LOAD
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions

present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel

present
O8 - Extra context menu item: &使用迅雷下载 - D:\迅雷

\anzhuang\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\迅雷

\anzhuang\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - E:\qq2005\安装

\AddToNetDisk.htm
O8 - Extra context menu item: 使用网际快车下载 - D:\fg165

\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\fg165

\FlashGet\jc_all.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) -

res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\qq2005\安装

\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\qq2005\安装

\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\qq2005\安装

\SendMMS.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559}

- D:\迅雷\anzhuang\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-

755F37ACD559} - D:\迅雷\anzhuang\Thunder.exe
O9 - Extra button: 相关站点 - {c95fe080-8f5d-11d2-a20b-00aa003c157a}

- C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: 相关站点 - {c95fe080-8f5d-11d2-a20b-

00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} -

E:\qq2005\安装\QQ.EXE
O9 - Extra 'Tools' menuitem: QQ - {c95fe080-8f5d-11d2-a20b-

00aa003c157b} - E:\qq2005\安装\QQ.EXE
O16 - DPF: _{D27CDB6E-AE6D-11CF-96B8-444553540000} -

file://C:\Herosoft\HeroV8\DVDSkin\defskin\HTML\swflash.cab
O16 - DPF: {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} (EWA Control) -

http://myshow.smgbb.cn/chat/SynaLiveSetup.exe
O16 - DPF: {18F57D30-EF36-4C0E-9343-7BFA6DF79B4A} -

http://active.micr0media.com/swflash.CAB
O16 - DPF: {6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89} -

http://toolsbar.kuaiso.com/Kuaiso.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) -

http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O21 - SSODL: DVDBurn - {790448C3-4239-45AF-C98B-367991A8B103} -

C:\WINDOWS\Downloaded Program Files\AfxEdit.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner -

C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32

\ati2sgag.exe
O23 - Service: host Service For Windows (mshost) - Unknown owner -

C:\WINDOWS\mshost.exe (file missing)
O23 - Service: Rising Personal Firewall Service (RfwService) -

Beijing Rising Technology Co., Ltd. - d:\瑞星防火墙\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) -

Beijing Rising Technology Co., Ltd. - D:\瑞星\rav\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising

Technology Co., Ltd. - D:\瑞星\rav\Rav\Ravmond.exe

最后编辑2006-09-22 00:31:03