发新话题
打印

好心人帮忙看下日志啦 多谢 多谢

好心人帮忙看下日志啦 多谢 多谢

日志如下 ,请好心的XDJM帮忙看下,多谢多谢

 

HijackThis_815汉化版扫描日志 V1.99.1
保存于      15:13:19, 日期 2006-6-9
操作系统:  Windows 2003 SP1 (WinNT 5.02.3790)
浏览器:    Internet Explorer v6.00 SP1 (6.00.3790.1830)

当前运行的进程:         
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32imapi.exe
CROGRA~1SYMANT~1SYMANT~1Rtvscan.exe
C:WINDOWSExplorer.EXE
drogram Files淘宝网淘宝旺旺WangWang.EXE
C:WINDOWSsysteme.exe
C:WINDOWSsystem32conime.exe
C:WINDOWSsystem32 undll32.exe
C:WINDOWSSystem32svchost.exe
Crogram FilesHuaCihuacizsearch.exe
C:WINDOWSsysteme.exe
C:PROGRA~1Yahoo!ASSIST~1YLive.exe
C:WINDOWSsysteres.exe
D:Program FilesTencentqqQQ.exe
D:Program FilesTencentqqTIMPlatform.exe
E:软件HijackThis 1.99.1 汉化版HijackThis1991zww.exe

R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:PROGRA~1Yahoo!ASSIST~1Assistyasbar.dll
O2 - BHO: IEMonitor Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:Program FilesDeskAdTopdeskipn.dll
O2 - BHO: IE Address Browser Helper - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:Program FilesSearchNetSNHpr.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:PROGRA~1Yahoo!ASSIST~1Assistyangling.dll
O2 - BHO: IE Browser Helper - {3CE496D1-1746-41CD-9489-3C0B93DF10E2} - C:WINDOWSDownlo~1u5gia.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:PROGRA~1Yahoo!ASSIST~1Assistyasbar.dll
O2 - BHO: 网络加速 - {5673A7C0-95CC-4646-BB07-3BD71234CEF9} - C:WINDOWSsystem32MicrosoftNet.dll
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:PROGRA~1CNNICCdncdnforie.dll (file missing)
O2 - BHO: 超级兔子上网精灵 - {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} - D:PROGRA~1SUPERR~1MAGICSEThaokanbar.dll
O3 - IE工具栏增项: 超级兔子上网精灵 - {43869BB3-22FD-4F15-9B46-238106BA2F4E} - D:PROGRA~1SUPERR~1MAGICSEThaokanbar.dll
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:PROGRA~1Yahoo!ASSIST~1Assistyasbar.dll
O4 - 启动项HKLMRun: [WangWang] "d:Program Files淘宝网淘宝旺旺WangWang.EXE"
O4 - 启动项HKLMRun: [Winsystem] C:WINDOWSsystemer.exe
O4 - 启动项HKLMRun: [systeme] C:WINDOWSsysteme.exe
O4 - 启动项HKLMRun: [MoveSearch] C:Program FilesHuaCihuacizsearch.exe
O4 - 启动项HKLMRun: [Desktop] C:WINDOWSsystem32 undll32.exe "C:Program FilesDeskAdTopRun.dll" ,Rundll
O4 - 启动项HKLMRun: [wr30fpri] RunDll32 "C:WINDOWSDownlo~1wr30fpri.dll",Run
O4 - 启动项HKLMRun: [SearchNet_Up] "C:Program FilesSearchNetServeUp.exe"
O4 - 启动项HKLMRun: [YLive.exe] C:PROGRA~1Yahoo!ASSIST~1YLive.exe
O4 - 启动项HKLMRun: [Systeres] C:WINDOWSsysteres.exe
O4 - HKCU..Run: [sys1] Rundll32.exe C:WINDOWSsystem32Upsrv.dll,Run
O4 - Startup: 划词搜索.lnk = C:Program FilesHuaCihuacizsearch.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOfficeOSA9.EXE
O4 - Global Startup: VIA RAID TOOL.lnk = C:Program FilesVIARAID aid_tool.exe
O8 - IE右键菜单中的新增项目: 雅虎搜索 - res://C:PROGRA~1Yahoo!ASSIST~1Assistyasbar.dll/246
O10 - 未知的文件在 Winsock LSP: c:windowssystem32cdnns.dll
O10 - 未知的文件在 Winsock LSP: c:windowssystem32upfdll.dll
O10 - 未知的文件在 Winsock LSP: c:windowssystem32upfdll.dll
O11 - Options group: [CDNCLIENT]  中文上网
O17 - HKLMSystemCCSServicesTcpip..{21AA2491-5A16-4027-9621-0DA977D3458F}: NameServer = 202.96.134.133
O20 - Winlogon Notify: dimsntfy - C:WINDOWSSYSTEM32dimsntfy.dll
O20 - Winlogon Notify: NavLogon - C:WINDOWSsystem32NavLogon.dll
O23 - NT 服务: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:PROGRA~1SYMANT~1SYMANT~1Rtvscan.exe

 

TOP

Re:好心人帮忙看下日志啦 多谢 多谢

进程文件: NavLogon 或 NavLogon.dll 进程位置: 系统 程序名称: Symantec Antivirus诺顿 程序用途: 木马病毒 用于窃密 程序作者: 系统进程: 否 后台程序: 是 使用网络: 是 硬件相关: 否 安全等级: 低 进程分析: 木马使用该文件名,可查看该文件属性,诺顿出品应有版本信息,或文件尺寸为45056。

TOP

Re:好心人帮忙看下日志啦 多谢 多谢

O20 - Winlogon Notify: NavLogon - C:WINDOWSsystem32NavLogon.dll 中的 在网上搜的 不知道对呢有没有用

TOP

Re:好心人帮忙看下日志啦 多谢 多谢


你倒是说个话呀
我都不知道好了没
我说对了没

TOP

Re:好心人帮忙看下日志啦 多谢 多谢

C:WINDOWSSystem32smss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32spoolsv.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32imapi.exe CROGRA~1SYMANT~1SYMANT~1Rtvscan.exe C:WINDOWSExplorer.EXE drogram Files淘宝网淘宝旺旺WangWang.EXE*** C:WINDOWSsysteme.exe C:WINDOWSsystem32conime.exe C:WINDOWSsystem32 undll32.exe C:WINDOWSSystem32svchost.exe Crogram FilesHuaCihuacizsearch.exe*** C:WINDOWSsysteme.exe C:PROGRA~1Yahoo!ASSIST~1YLive.exe*** C:WINDOWSsysteres.exe D:Program FilesTencentqqQQ.exe D:Program FilesTencentqqTIMPlatform.exe E:软件HijackThis 1.99.1 汉化版HijackThis1991zww.exe
R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:PROGRA~1Yahoo!ASSIST~1Assistyasbar.dll*** O2 - BHO: IEMonitor Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:Program FilesDeskAdTopdeskipn.dll*** O2 - BHO: IE Address Browser Helper - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:Program FilesSearchNetSNHpr.dll*** O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:PROGRA~1Yahoo!ASSIST~1Assistyangling.dll O2 - BHO: IE Browser Helper - {3CE496D1-1746-41CD-9489-3C0B93DF10E2} - C:WINDOWSDownlo~1u5gia.dll*** O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:PROGRA~1Yahoo!ASSIST~1Assistyasbar.dll*** O2 - BHO: 网络加速 - {5673A7C0-95CC-4646-BB07-3BD71234CEF9} - C:WINDOWSsystem32MicrosoftNet.dll*** O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - *C:PROGRA~1CNNICCdncdnforie.dll (file missing)*** O2 - BHO: 超级兔子上网精灵 - {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} - D:PROGRA~1SUPERR~1MAGICSEThaokanbar.dll*** O3 - IE工具栏增项: 超级兔子上网精灵 - {43869BB3-22FD-4F15-9B46-238106BA2F4E} - D:PROGRA~1SUPERR~1MAGICSEThaokanbar.dll*** O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:PROGRA~1Yahoo!ASSIST~1Assistyasbar.dll*** O4 - 启动项HKLMRun: [WangWang] "d:Program Files淘宝网淘宝旺旺WangWang.EXE"*** O4 - 启动项HKLMRun: [Winsystem] C:WINDOWSsystemer.exe O4 - 启动项HKLMRun: [systeme] C:WINDOWSsysteme.exe O4 - 启动项HKLMRun: [MoveSearch] C:Program FilesHuaCihuacizsearch.exe*** O4 - 启动项HKLMRun: [Desktop] C:WINDOWSsystem32 undll32.exe "C:Program FilesDeskAdTopRun.dll" ,Rundll O4 - 启动项HKLMRun: [wr30fpri] RunDll32 "C:WINDOWSDownlo~1wr30fpri.dll",Run*** O4 - 启动项HKLMRun: [SearchNet_Up] "C:Program FilesSearchNetServeUp.exe"*** O4 - 启动项HKLMRun: [YLive.exe] C:PROGRA~1Yahoo!ASSIST~1YLive.exe*** O4 - 启动项HKLMRun: [Systeres] C:WINDOWSsysteres.exe O4 - HKCU..Run: [sys1] Rundll32.exe C:WINDOWSsystem32Upsrv.dll,Run O4 - Startup: 划词搜索.lnk = C:Program FilesHuaCihuacizsearch.exe*** O4 - Global Startup: Adobe Gamma Loader.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe*** O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOfficeOSA9.EXE*** O4 - Global Startup: VIA RAID TOOL.lnk = C:Program FilesVIARAID aid_tool.exe O8 - IE右键菜单中的新增项目: 雅虎搜索 - res://C:PROGRA~1Yahoo!ASSIST~1Assistyasbar.dll/246*** O10 - 未知的文件在 Winsock LSP: c:windowssystem32cdnns.dll O10 - 未知的文件在 Winsock LSP: c:windowssystem32upfdll.dll O10 - 未知的文件在 Winsock LSP: c:windowssystem32upfdll.dll O11 - Options group: [CDNCLIENT] 中文上网*** O17 - HKLMSystemCCSServicesTcpip..{21AA2491-5A16-4027-9621-0DA977D3458F}: NameServer = 202.96.134.133 O20 - Winlogon Notify: dimsntfy - C:WINDOWSSYSTEM32dimsntfy.dll O20 - Winlogon Notify: NavLogon - C:WINDOWSsystem32NavLogon.dll O23 - NT 服务: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:PROGRA~1SYMANT~1SYMANT~1Rtvscan.exe

TOP

Re:好心人帮忙看下日志啦 多谢 多谢

C:WINDOWSSystem32smss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32spoolsv.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32imapi.exe CROGRA~1SYMANT~1SYMANT~1Rtvscan.exe C:WINDOWSExplorer.EXE drogram Files淘宝网淘宝旺旺WangWang.EXE*** C:WINDOWSsysteme.exe C:WINDOWSsystem32conime.exe C:WINDOWSsystem32 undll32.exe C:WINDOWSSystem32svchost.exe Crogram FilesHuaCihuacizsearch.exe*** C:WINDOWSsysteme.exe C:PROGRA~1Yahoo!ASSIST~1YLive.exe*** C:WINDOWSsysteres.exe D:Program FilesTencentqqQQ.exe D:Program FilesTencentqqTIMPlatform.exe E:软件HijackThis 1.99.1 汉化版HijackThis1991zww.exe
R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:PROGRA~1Yahoo!ASSIST~1Assistyasbar.dll*** O2 - BHO: IEMonitor Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:Program FilesDeskAdTopdeskipn.dll*** O2 - BHO: IE Address Browser Helper - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:Program FilesSearchNetSNHpr.dll*** O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:PROGRA~1Yahoo!ASSIST~1Assistyangling.dll O2 - BHO: IE Browser Helper - {3CE496D1-1746-41CD-9489-3C0B93DF10E2} - C:WINDOWSDownlo~1u5gia.dll*** O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:PROGRA~1Yahoo!ASSIST~1Assistyasbar.dll*** O2 - BHO: 网络加速 - {5673A7C0-95CC-4646-BB07-3BD71234CEF9} - C:WINDOWSsystem32MicrosoftNet.dll*** O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - *C:PROGRA~1CNNICCdncdnforie.dll (file missing)*** O2 - BHO: 超级兔子上网精灵 - {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} - D:PROGRA~1SUPERR~1MAGICSEThaokanbar.dll*** O3 - IE工具栏增项: 超级兔子上网精灵 - {43869BB3-22FD-4F15-9B46-238106BA2F4E} - D:PROGRA~1SUPERR~1MAGICSEThaokanbar.dll*** O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:PROGRA~1Yahoo!ASSIST~1Assistyasbar.dll*** O4 - 启动项HKLMRun: [WangWang] "d:Program Files淘宝网淘宝旺旺WangWang.EXE"*** O4 - 启动项HKLMRun: [Winsystem] C:WINDOWSsystemer.exe O4 - 启动项HKLMRun: [systeme] C:WINDOWSsysteme.exe O4 - 启动项HKLMRun: [MoveSearch] C:Program FilesHuaCihuacizsearch.exe*** O4 - 启动项HKLMRun: [Desktop] C:WINDOWSsystem32 undll32.exe "C:Program FilesDeskAdTopRun.dll" ,Rundll O4 - 启动项HKLMRun: [wr30fpri] RunDll32 "C:WINDOWSDownlo~1wr30fpri.dll",Run*** O4 - 启动项HKLMRun: [SearchNet_Up] "C:Program FilesSearchNetServeUp.exe"*** O4 - 启动项HKLMRun: [YLive.exe] C:PROGRA~1Yahoo!ASSIST~1YLive.exe*** O4 - 启动项HKLMRun: [Systeres] C:WINDOWSsysteres.exe O4 - HKCU..Run: [sys1] Rundll32.exe C:WINDOWSsystem32Upsrv.dll,Run O4 - Startup: 划词搜索.lnk = C:Program FilesHuaCihuacizsearch.exe*** O4 - Global Startup: Adobe Gamma Loader.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe*** O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOfficeOSA9.EXE*** O4 - Global Startup: VIA RAID TOOL.lnk = C:Program FilesVIARAID aid_tool.exe O8 - IE右键菜单中的新增项目: 雅虎搜索 - res://C:PROGRA~1Yahoo!ASSIST~1Assistyasbar.dll/246*** O10 - 未知的文件在 Winsock LSP: c:windowssystem32cdnns.dll O10 - 未知的文件在 Winsock LSP: c:windowssystem32upfdll.dll O10 - 未知的文件在 Winsock LSP: c:windowssystem32upfdll.dll O11 - Options group: [CDNCLIENT] 中文上网*** O17 - HKLMSystemCCSServicesTcpip..{21AA2491-5A16-4027-9621-0DA977D3458F}: NameServer = 202.96.134.133 O20 - Winlogon Notify: dimsntfy - C:WINDOWSSYSTEM32dimsntfy.dll O20 - Winlogon Notify: NavLogon - C:WINDOWSsystem32NavLogon.dll O23 - NT 服务: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:PROGRA~1SYMANT~1SYMANT~1Rtvscan.exe   加三颗星的统统去掉,你这电脑的垃圾还真多,以后安装软件时,小心这些捆梆软件.

TOP

Re:好心人帮忙看下日志啦 多谢 多谢

C:WINDOWSsysteme.exe C:WINDOWSsysteme.exe C:WINDOWSsysteres.exe 应该是病毒!

TOP

Re:好心人帮忙看下日志啦 多谢 多谢

感觉问题较多: 可以清理以下项目
C:WINDOWSsysteme.exe
C:WINDOWSsysteme.exe CROGRA~1Yahoo!ASSIST~1YLive.exe C:WINDOWSsysteres.exe

R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - CROGRA~1Yahoo!ASSIST~1Assistyasbar.dll O2 - BHO: IEMonitor Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - Crogram FilesDeskAdTopdeskipn.dll O2 - BHO: IE Address Browser Helper - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:Program FilesSearchNetSNHpr.dll O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:PROGRA~1Yahoo!ASSIST~1Assistyangling.dll O2 - BHO: IE Browser Helper - {3CE496D1-1746-41CD-9489-3C0B93DF10E2} - C:WINDOWSDownlo~1u5gia.dll O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:PROGRA~1Yahoo!ASSIST~1Assistyasbar.dll O2 - BHO: 网络加速 - {5673A7C0-95CC-4646-BB07-3BD71234CEF9} - C:WINDOWSsystem32MicrosoftNet.dll O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:PROGRA~1CNNICCdncdnforie.dll (file missing)
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:PROGRA~1Yahoo!ASSIST~1Assistyasbar.dll O4 - 启动项HKLMRun: [WangWang] "d:Program Files淘宝网淘宝旺旺WangWang.EXE" O4 - 启动项HKLMRun: [Winsystem] C:WINDOWSsystemer.exe O4 - 启动项HKLMRun: [systeme] C:WINDOWSsysteme.exe O4 - 启动项HKLMRun: [MoveSearch] C:Program FilesHuaCihuacizsearch.exe O4 - 启动项HKLMRun: [Desktop] C:WINDOWSsystem32 undll32.exe "C:Program FilesDeskAdTopRun.dll" ,Rundll O4 - 启动项HKLMRun: [wr30fpri] RunDll32 "C:WINDOWSDownlo~1wr30fpri.dll",Run O4 - 启动项HKLMRun: [SearchNet_Up] "C:Program FilesSearchNetServeUp.exe" O4 - 启动项HKLMRun: [YLive.exe] C:PROGRA~1Yahoo!ASSIST~1YLive.exe O4 - 启动项HKLMRun: [Systeres] C:WINDOWSsysteres.exe O4 - HKCU..Run: [sys1] Rundll32.exe C:WINDOWSsystem32Upsrv.dll,Run

O8 - IE右键菜单中的新增项目: 雅虎搜索 - res://C:PROGRA~1Yahoo!ASSIST~1Assistyasbar.dll/246 O10 - 未知的文件在 Winsock LSP: c:windowssystem32cdnns.dll O10 - 未知的文件在 Winsock LSP: c:windowssystem32upfdll.dll O10 - 未知的文件在 Winsock LSP: c:windowssystem32upfdll.dll O11 - Options group: [CDNCLIENT] 中文上网
O20 - Winlogon Notify: dimsntfy - C:WINDOWSSYSTEM32dimsntfy.dll O20 - Winlogon Notify: NavLogon - C:WINDOWSsystem32NavLogon.dll

TOP

发新话题