翻譯社O2 - BHO: (no name) - {67270207-b9ee-4d26-9270-860fdb060ca1} - C:\WINDOWS\system32\ixt0.dll
這是我抓到的毒
C:\WINDOWS\System32\svchost.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O17 - HKLM\System\CCS\Services\Tcpip\..\{C5544812-7CDF-4CEB-8D94-8C0F81C24507}: NameServer = 168.95.192.1 168.95.1.1
www.360safe.com
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
C:\Program Files\Eset od32kui.exe
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
天成翻譯社的symantc antivirus 也一直偵測到病毒翻譯社 但是氣人的是怎麼殺就是會再出現!!> <
C:\WINDOWS\system32\spoolsv.exe
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
C:\WINDOWS\system32\winlogon.exe

有問題的程式應當是issearch.exe吧!
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\Program Files\Eset od32krn.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\lsass.exe
我想必然是告白病毒! 但是為什麼防毒軟體都殺了有會依直泛起勒?
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
C:\WINDOWS\Explorer.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll翻譯社NvStartup
以下是我的log files 不知道有沒人能看出端倪...
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINDOWS\System32\smss.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKLM\..\RunOnce: [vsoupd.dll] rundll32.exe advpack.dll,RegisterOCX c:\PROGRA~1\mcafee.com\vso\vsoupd.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll

C:\Program Files\MSN Messenger\MsnMsgr.Exe
O8 - Extra context menu item: 匯出至 Microsoft Excel(&X) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
Logfile of HijackThis v1.99.1
請看
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset od32kui.exe" /WAITSERVICE
今天不知道中了什麼怪毒...
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O3 - Toolbar: Dr.eye WebPage Translation - {92B255FE-94E2-4BCA-958D-3926CE38913F} - C:\PROGRA~1\Inventec\Dreye\DreyeMT\DREYEI~1.DLL
O23 - Service: iPod Service - Apple Computer翻譯社 Inc. - C:\Program Files\iPod\bin\iPodService.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
Running processes:
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
天成翻譯社比來也遇過類似的工作,最後結論發現防毒軟體是防毒的,這類工作照舊要交給防木馬軟體或是防特務軟體來掃除才會乾淨,究竟各司其職!
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\QuickTime\qttask.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

天成翻譯社的媽阿 誰來救就我阿!!!! 感謝各位了
O20 - Winlogon Notify: winbjt32 - winbjt32.dll (file missing)

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O8 - Extra context menu item: 轉換成簡體中文(&S) - res://C:\WINDOWS\system32\tcscconv.dll/tosimp
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
一向跑出要天成翻譯社采辦防毒軟體的網頁
C:\WINDOWS\system32\conime.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
http://fileinfo.prevx.com/adware/qq215224914976-ISSE17080133/ISSEARCH.EXE.html

留言列表 留言列表

發表留言