一开始出现的是智联招聘广告 现在又变成其他广告的集合 郁闷
日志文件 Trend Micro HijackThis v 2.0.2
日志保存时间: 22:22:49,2011-6-5
操作系统: Windows XP SP3 (WinNT 5.01.2600)
IE版本: Internet Explorer v6.00 SP3 (6.00.2900.5512)
启动模式: 正常
正在运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Kingsoft\kiscommon\kxescore.exe
C:\Program Files\Common Files\Kingsoft\kiscommon\kxesapp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Kingsoft\kiscommon\upsvc.exe
C:\Program Files\Common Files\Kingsoft\kiscommon\kxetray.exe
C:\Program Files\360\360Safe\safemon\360Tray.exe
C:\WINDOWS\system32\ctfmon.exe
G:\KuGou2010\KuGoo.exe
G:\KuGou2010\kgdaemon.exe
E:\QQ\Bin\QQ.exe
E:\QQ\Bin\TXPlatform.exe
G:\platform 5.0\GameClient.exe
C:\Program Files\360\360se3\360se.exe
C:\Program Files\360\360se3\Extensions\SafeCentral\urlproc.exe
C:\Program Files\360\360se3\360se.exe
C:\Documents and Settings\Administrator\Application Data\360SE\extensions\ExtWebmail\360seNotify.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\360\360se3\360se.exe
G:\hijackthis.exe
D:\UserData\TEMP\nsc4F.tmp\hijackthis.exe
R3 - 默认 URLSearchHook 丢失
O4 - HKLM\..\Run: [kxesc] "C:\Program Files\Common Files\Kingsoft\kiscommon\kxetray.exe" -autorun
O4 - HKLM\..\Run: [360Safetray] "C:\Program Files\360\360Safe\safemon\360Tray.exe" /start
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\system32\msconfig.exe /auto
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] ctfmon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] ctfmon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - 扩展右键菜单项: 中国站长天空网页链接查看器(&L) -
http://www.zzsky.cn/tool/weblinkviewer/reshunter.htmlO8 - 扩展右键菜单项: 中国站长天空网页链接查看器__跟踪链接(&E) -
http://www.zzsky.cn/weblinkviewer/reshunter_link.htmlO8 - 扩展右键菜单项: 使用迅雷下载 - d:\Program Files\Thunder\BHO\geturl.htm
O8 - 扩展右键菜单项: 使用迅雷下载全部链接 - d:\Program Files\Thunder\BHO\GetAllUrl.htm
O9 - 额外的按钮: (未命名) - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - (没有文件)
O15 - Trusted Zone:
http://www.ccb.comO15 - Trusted Zone:
http://www.icbc.com.cnO15 - Trusted Zone: http://*.pps.tv
O15 - Trusted Zone: http://*.ppstream.com
O15 - Trusted Zone: http://*.webscache.com
O15 - ESC Trusted Zone: http://*.pps.tv
O15 - ESC Trusted Zone: http://*.ppstream.com
O15 - ESC Trusted Zone: http://*.webscache.com
O16 - DPF: {36C9539B-49D2-01C7-9C6D-10DACDFEA59C} (Axcleanctrl Class) -
https://b2c.icbc.com.cn/icbc/newperbank/icbcclean.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1296472515000O16 - DPF: {CFECDB64-2AF0-455E-8CD5-1641DBA26AA2} (cardnum Control) -
http://www.ewoka.com/lika/cardnumProj1.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{D2CD62B7-B528-4690-97D2-4E1B1EA00B23}: NameServer = 202.101.224.68,202.101.224.69
O18 - Protocol: KuGoo - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\WINDOWS\system32\KuGoo3DownXControl.ocx
O18 - Protocol: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\WINDOWS\system32\KuGoo3DownXControl.ocx
O23 - NT 服务: Google 更新服务 (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - NT 服务: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - NT 服务: Kingsoft Rescue Service - Unknown owner - C:\Program Files\kingsoft\KSM\ksmsvc.exe
O23 - NT 服务: KSafe service (KSafeSvc) - Kingsoft Corporation - C:\Program Files\KSafe\KSafeSvc.exe
O23 - NT 服务: Kingsoft Security App Service (kxesapp) - Kingsoft Corporation - C:\Program Files\Common Files\Kingsoft\kiscommon\kxesapp.exe
O23 - NT 服务: Kingsoft Core Service (kxescore) - Kingsoft Corporation - C:\Program Files\Common Files\Kingsoft\kiscommon\kxescore.exe
O23 - NT 服务: Kingsoft Antivirus Update Service (KxEUpSrv) - Kingsoft Corporation - C:\Program Files\Common Files\Kingsoft\kiscommon\upsvc.exe
O23 - NT 服务: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe(文件不存在)
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - NT 服务: Sandboxie Service (SbieSvc) - Unknown owner - C:\Program Files\360safe\Shield\SbieSvc.exe(文件不存在)
O23 - NT 服务: UPS - Unknown owner - C:\WINDOWS\System32\ups.exe(文件不存在)
O23 - NT 服务: XLDoctor Services - 深圳市迅雷网络技术有限公司 - d:\Program Files\Thunder\Program\DctSer.exe
O23 - NT 服务: 主动防御 (ZhuDongFangYu) - 360.cn - C:\Program Files\360\360Safe\deepscan\zhudongfangyu.exe
怎么解决?
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; GTB6.6; User-agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; http://bsalsa.com) ; .NET CLR 2.0.50727)