查看: 3898|回复: 1
收起左侧

请高手们帮忙看看我的日志,要删除哪些?

[复制链接]
柠柠儿
发表于 2006-11-30 10:02:43 | 显示全部楼层 |阅读模式
最近一开机就显示iexplorer.exe占CPU的100%,但用什么杀毒软件及木马软件都查不出毒。
后来看了那个‘灰鸽子手工查杀’的贴子后,用里面的方法,终于可以查到了。也删除了后来出现的几个文件。

之后也用hijack扫描了日记,可是我不会看,不知道应该要删除哪些?

还有,虽然删除了出现的几个文件后,开机时,进程里不再有iexplorer.exe,但卡巴还是经常显示有“进程 C:\Program Files\Internet Explorer\iexplore.exe (PID: 3508): 试图 执行可疑操作 被拒绝.”

应该是还是没杀完吧。





Logfile of HijackThis v1.99.1
Scan saved at 3:11:46, on 2006-11-28
Platform: Windows XP SP2, v.2096 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2096)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\bb\LOCALS~1\Temp\Rar$EX00.860\HijackThis.exe
O1 - Hosts: 202.75.218.253 www.hao123.com
O1 - Hosts: 202.75.218.253 www.7b.com.cn
O1 - Hosts: 202.75.218.253 www.7939.com
O1 - Hosts: 202.75.218.253 www.360safe.com
O1 - Hosts: 202.75.218.253 360safe.com
O1 - Hosts: 202.75.218.253 update.360safe.com
O1 - Hosts: 202.75.218.253 dl.360safe.com
O1 - Hosts: 202.75.218.253 bbs.360safe.com
O1 - Hosts: 202.75.218.253 count16.51yes.com
O1 - Hosts: 202.75.218.253 count18.51yes.com
O1 - Hosts: 202.75.218.253 count20.51yes.com
O1 - Hosts: 202.75.218.253 www.btbaicai.com
O1 - Hosts: 202.75.218.253 btbaicai.com
O1 - Hosts: 202.75.218.253 www.pctutu.com
O1 - Hosts: 202.75.218.253 www.7322.com
O1 - Hosts: 202.75.218.253 www.5566.net
O1 - Hosts: 202.75.218.253 www.9991.com
O1 - Hosts: 202.75.218.253 forum.ikaka.com
O1 - Hosts: 202.75.218.253 www.ikaka.com
O1 - Hosts: 202.75.218.253 update.ikaka.com
O1 - Hosts: 202.75.218.253 www.piaoxue.com
O1 - Hosts: 202.75.218.253 forum.jiangmin.com
O1 - Hosts: 202.75.218.253 update.jiangmin.com
O1 - Hosts: 202.75.218.253 post.baidu.com
O1 - Hosts: 202.75.218.253 zhidao.baidu.com
O1 - Hosts: 202.75.218.253 update.rising.com.cn
O1 - Hosts: 202.75.218.253 online.rising.com.cn
O1 - Hosts: 202.75.218.253 dl.pconline.com.cn
O1 - Hosts: 202.75.218.253 space.uwants.com
O1 - Hosts: 202.75.218.253 www.pcav.cn
O1 - Hosts: 202.75.218.253 mopery.hits.io
O1 - Hosts: 202.75.218.253 www.goodmv.cn
O1 - Hosts: 202.75.218.253 www.5566.net
O1 - Hosts: 202.75.218.253 www.piaoxue.com
O1 - Hosts: 202.75.218.253 www.luosoft.com
O1 - Hosts: 202.75.218.253 luosoft.com
O1 - Hosts: 202.75.218.253 www.7255.com
O1 - Hosts: 202.75.218.253 dl.pconline.com.cn
O1 - Hosts: 202.75.218.253 www.spjoy.com
O1 - Hosts: 202.75.218.253 c01.caishow.com
O1 - Hosts: 202.75.218.253 c02.caishow.com
O1 - Hosts: 202.75.218.253 c03.caishow.com
O1 - Hosts: 202.75.218.253 c04.caishow.com
O1 - Hosts: 202.75.218.253 www.caishow.com
O1 - Hosts: 202.75.218.253 union.caishow.com
O1 - Hosts: 202.75.218.253 ad01.a8.com
O1 - Hosts: 202.75.218.253 ad02.a8.com
O1 - Hosts: 202.75.218.253 sg.a8.com
O1 - Hosts: 202.75.218.253 www.adanywhere.cn
O1 - Hosts: 202.75.218.253 ip.adanywhere.cn
O1 - Hosts: 202.75.218.253 ip1.adanywhere.cn
O1 - Hosts: 202.75.218.253 ip2.adanywhere.cn
O1 - Hosts: 202.75.218.253 www.bannerbox.cn
O1 - Hosts: 202.75.218.253 www.caiqiyue.com
O1 - Hosts: 202.75.218.253 www.2t2t.cn
O1 - Hosts: 202.75.218.253 3.a.kal.cn
O1 - Hosts: 202.75.218.253 ip.alexaanywhere.com
O1 - Hosts: 202.75.218.253 go.ipcenter.cn
O1 - Hosts: 202.75.218.253 www.2yin.cn
O1 - Hosts: 202.75.218.253 wwww.systeel.com.cn
O1 - Hosts: 202.75.218.253 go.baibaoxiang.cn
O1 - Hosts: 202.75.218.253 www.gao58.com
O1 - Hosts: 202.75.218.253 www.2tu.cn
O1 - Hosts: 202.75.218.253 www.91tu.cn
O1 - Hosts: 202.75.218.253 www.haotop.com
O1 - Hosts: 202.75.218.253 news01.virussky.com
O1 - Hosts: 202.75.218.253 news02.virussky.com
O1 - Hosts: 202.75.218.253 news03.virussky.com
O1 - Hosts: 202.75.218.253 news04.virussky.com
O1 - Hosts: 202.75.218.253 news40.virussky.com
O1 - Hosts: 202.75.218.253 news41.virussky.com
O1 - Hosts: 202.75.218.253 news42.virussky.com
O1 - Hosts: 202.75.218.253 www.an85.com
O1 - Hosts: 202.75.218.253 an85.com
O1 - Hosts: 202.75.218.253 www.ycdy.com
O1 - Hosts: 202.75.218.253 ycdy.com
O1 - Hosts: 202.75.218.253 down.virussky.com
O1 - Hosts: 202.75.218.253 update.virussky.com
O1 - Hosts: 202.75.218.253 www.maipao.com
O1 - Hosts: 202.75.218.253 www.sina-baidu.com
O1 - Hosts: 202.75.218.253 www.maohehe.com
O1 - Hosts: 202.75.218.253 www.1717kan.cn
O1 - Hosts: 202.75.218.253 www.feixue.net
O1 - Hosts: 202.75.218.253 www.xingkongitv.com
O1 - Hosts: 202.75.218.253 about-blank.cc
O1 - Hosts: 202.75.218.253 www.xfkz.com
O1 - Hosts: 202.75.218.253 xfkz.com
O1 - Hosts: 202.75.218.253 www.365tan.com
O1 - Hosts: 202.75.218.253 cg.9e3.com
O1 - Hosts: 202.75.218.253 www.qqplayer.net
O1 - Hosts: 202.75.218.253 www.sosok.com
O1 - Hosts: 202.75.218.253 img.zhangxiu.com
O1 - Hosts: 202.75.218.253 www.okeaa.com
O1 - Hosts: 202.75.218.253 www.winopen.cn
O1 - Hosts: 202.75.218.253 dnl-eu1.kaspersky-labs.com
O1 - Hosts: 202.75.218.253 dnl-eu2.kaspersky-labs.com
O1 - Hosts: 202.75.218.253 dnl-eu3.kaspersky-labs.com
O1 - Hosts: 202.75.218.253 dnl-eu4.kaspersky-labs.com
O1 - Hosts: 202.75.218.253 dnl-eu5.kaspersky-labs.com
O1 - Hosts: 202.75.218.253 dnl-us1.kaspersky-labs.com
O1 - Hosts: 202.75.218.253 dnl-us2.kaspersky-labs.com
O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\chinanet\VNETTR~1.DLL
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [kis] "D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [UnlockerAssistant] "D:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [StormCodec_Helper] "D:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [WangWang] "D:\Program Files\淘宝网\淘宝旺旺\WangWang.EXE"
O4 - HKLM\..\Run: [Alitalk] D:\PROGRA~1\阿里巴巴\贸易通\AliTalk.EXE
O4 - HKLM\..\Run: [A] C:\WINDOWS\system32\rundll32.exe q.dll s
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: 星空极速.lnk = C:\Program Files\ChinaNet\VnetClient.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: 使用迅雷下载 - D:\Program Files\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: 使用迅雷下载全部链接 - D:\Program Files\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: Web反病毒保护 - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O20 - AppInit_DLLs: D:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: 卡巴斯基互联网安全套装 6.0 (AVP) - Unknown owner - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
xiaowangzi
发表于 2006-11-30 12:59:03 | 显示全部楼层
O1项一般可以全删;
O4 - HKLM\..\Run: [StormCodec_Helper] "D:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti,如果使用暴风影音的话,点击开始--运行,输入msconfig,点启动,不选里面这一项,不让它开机启动
O4 - HKLM\..\Run: [WangWang] "D:\Program Files\淘宝网\淘宝旺旺\WangWang.EXE"
O4 - HKLM\..\Run: [Alitalk] D:\PROGRA~1\阿里巴巴\贸易通\AliTalk.EXE
O4 - Global Startup: 星空极速.lnk = C:\Program Files\ChinaNet\VnetClient.exe
这三项如果用的话也按暴风影音那一项在mcsconfig里做同样的处理
O18项不太清楚,比较可疑,可能你的电脑里有间谍软件
       建议你下个兔子,用兔子整理一下,把插件一般都去了就行,最好也用超级兔子优化一下系统。另外再问一下高手吧,我是个菜鸟级的,呵呵。

评分

参与人数 1经验 +3 收起 理由
navigateqd + 3 感谢解答: )

查看全部评分

您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-22 11:11 , Processed in 0.132677 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表