高手您好!我已被一些莫名其妙的网站折腾了2个多月了,没办法,只有求助于你们了.
上个月电脑感染过什么"威金、橙色八月”都清除了,访问正常网站时被转向到恶意网页,
浏览器自动弹出来这些网站。要看网页里的内容点击后,新出来的窗口有时就会跳出这些网站。
(www.jiemeng8.com/hot.html www.8you.cn/show.asp)
www.dymore.cn/list1.html
www.jiemeng8.com/hot.html
www.8you.cn/show.asp
www.6dy.org/top100.html
http://links.is686.com/t3.html?keyrunf=jiemeng
http://www.jiemeng8.com/key/d0d4b0aea1a2d7f6b0aea1a2b4bac3ce1.html
www.8you.cn/gallery.asp
www.8you.cn/show.asp
www.dymore.cn/list2.html
www.6dy.org/top100.html
itv.mop.com/today/todaymop2.html
pop.9v.cn/code/showpop.asp
www.jiemeng8.com/list.html
itv.mop.com/today/todaymop1.html
www.6dy.org/list1.html
www6.itry.cn/ete.htm
itv.mop.com/today/todaymop1.html
www.myad.cn/code/vip.asp
www.jiemeng8.com/key/d0d4b0aea1a2d7f6b0aea1a2b4bac3ce1.html
link.is686.com/t3.html?keyrunf=jiemeng
www.jiemeng8.com/key/d0d4b0aea1a2d7f6b0aea1a2b4bac3ce1.html
www.jiemeng8.com/hot.html
shenzhen.vekee.com/hot/090504/tan_index.html
shenzhen.vekee.com/hot/091802/tan_index.html
www.8you.cn/show.asp
www.6dy.org/list1.html
itv.mop.com/today/todaymop1.html
www.jiemeng8.com/key/d0d4b0aea1a2d7f6b0aea1a2b4bac3ce1.html
www.dymore.cn/list2.html
auto.sohu.com/s2006/2006beijing/
www.jiemeng8.com/list.html
itv.mop.com/today/todaymop2.html
www.8you.cn/show.asp
www.dymore.cn/list1.html
itv.mop.com/today/todaymop2.html
www.6dy.org/top100.html
www.chinacars.com/index_new.htm
http://www.dymore.cn/list2.html
等。
我附了HijackThis_zww扫描日志和这些XXX的网站,等待您的回复,谢谢!!!
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 15:41:28, 日期 2006-11-16
操作系统: Windows 2000 SP4 (WinNT 5.00.2195)
浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)
当前运行的进程:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
d:\瑞星\rising\rfw\rfwsrv.exe
C:\WINNT\system32\svchost.exe
D:\瑞星\Rising\Rav\CCenter.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
d:\瑞星\rising\rfw\RfwMain.exe
D:\瑞星\Rising\Rav\RavTask.exe
C:\WINNT\system32\internat.exe
D:\瑞星\Rising\Rav\Ravmond.exe
D:\瑞星\Rising\Rav\RAVMON.EXE
C:\Program Files\Internet Explorer\iexplore.exe
F:\cx\应用软件\瑞星升级包\病毒专杀工具\HijackThis1991zww.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}? - (no file)
O2 - BHO: Baidu Search Bar - {0FB8C8ED-61A4-DD21-DBBC-9C11983DDB38} - C:\WINNT\system32\BAIDUB~2.DLL
O2 - BHO: (no name) - {54EBD53A-9BC1-480B-966A-843A333CA162}? - (no file)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\网际士快斐车礬\FLASHGET\jccatch.dll (file missing)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - IE工具栏增项: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\网际士快斐车礬\FLASHGET\fgiebar.dll (file missing)
O3 - IE工具栏增项: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINNT\system32\KakaTool.dll
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [nwiz] nwiz.exe /install
O4 - 启动项HKLM\\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - 启动项HKLM\\Run: [RavTask] "D:\瑞星\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [RfwMain] "D:\瑞星\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\RunOnce: [KKDelay] C:\Program Files\Rising\KakaToolBar\RunOnce.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O8 - IE右键菜单中的新增项目: Convert link target to Adobe PDF - res://D:\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - IE右键菜单中的新增项目: Convert link target to existing PDF - res://D:\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - IE右键菜单中的新增项目: Convert selected links to Adobe PDF - res://D:\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - IE右键菜单中的新增项目: Convert selected links to existing PDF - res://D:\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - IE右键菜单中的新增项目: Convert selection to Adobe PDF - res://D:\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - IE右键菜单中的新增项目: Convert selection to existing PDF - res://D:\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - IE右键菜单中的新增项目: Convert to Adobe PDF - res://D:\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - IE右键菜单中的新增项目: Convert to existing PDF - res://D:\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - D:\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - D:\网际快车\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - D:\网际快车\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\QQ\SendMMS.htm
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}? - D:\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}? - D:\QQ\QQ.EXE
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\网际快车\FLASHGET\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\网际快车\FLASHGET\flashget.exe
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6}? - C:\WINNT\system32\shdocvw.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6}? - C:\WINNT\system32\shdocvw.dll
O9 - 浏览器额外的按钮: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444}? - http://www.rising.com.cn (file missing)
O9 - 浏览器额外的按钮: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445}? - http://www.ikaka.com (file missing)
O16 - DPF: {001290E5-CD10-4957-9D2B-FD2B74990219} (GovTifActiveX Control) - http://211.157.104.94/sipo/zljs/GovActive/GovTifActiveX.ocx
O16 - DPF: {2354A44B-3CEB-4829-9940-545B03103538} (PowerPlr Control) - http://bb.wuhan.net.cn/plugin/PowerPlr.ocx
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl
Object) - https://img.alipay.com/download/1007/aliedit.cab
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/normalbank/AxSafeControls.cab
O16 - DPF: {F2EB8999-766E-4BF6-AAAD-188D398C0D0B} (PBActiveX40 Control) - http://szdl.cmbchina.com/download/PB/pb50.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4459E86A-5252-4CF2-B953-F49C665A5507}: NameServer = 202.103.24.68,202.103.0.117
O17 - HKLM\System\CS1\Services\Tcpip\..\{4459E86A-5252-4CF2-B953-F49C665A5507}: NameServer = 202.103.24.68,202.103.0.117
O17 - HKLM\System\CS2\Services\Tcpip\..\{4459E86A-5252-4CF2-B953-F49C665A5507}: NameServer = 202.103.24.68,202.103.0.117
O23 - NT 服务: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - NT 服务: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\瑞星\rising\rfw\rfwproxy.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\瑞星\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\瑞星\Rising\Rav\CCenter.exe
O23 - NT 服务: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\瑞星\Rising\Rav\Ravmond.exe