查看: 900|回复: 2
|
Help me...<<< WIN.HTA >>>
[复制链接]
|
|
i kena this win.hta >>> my IE home page cant change...change liao...the web site address come again how ??? |
|
|
|
|
|
|
|
楼主 |
发表于 25-5-2004 08:21 PM
|
显示全部楼层
i use all spy software provide in here...but after scan liao....the web site still come out....i change the home page liao...then restart the pc....the home page set back the web site
http://www.babe4u.com
pls help me.....PPPPLLLLLLLSSSSSSSSSSSSSSSSSSSSSSSSSSSS |
|
|
|
|
|
|
|
楼主 |
发表于 26-5-2004 04:44 PM
|
显示全部楼层
please some body help me..i already hijack liao...but restart pc still come out
Logfile of HijackThis v1.97.7
Scan saved at 16:41:43, on 26/05/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\msconfig.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\New Folder\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.babe4us.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.babe4us.com
O1 - Hosts: 69.93.131.132 fadama.com
O1 - Hosts: 69.93.131.132 www.link8.com
O1 - Hosts: 69.93.131.132 www.avsex.tv
O1 - Hosts: 69.93.131.132 www.easypic2.com
O1 - Hosts: 69.93.131.132 www.rawpussy.com
O1 - Hosts: 69.93.131.132 www.sleazydream.com
O1 - Hosts: 69.93.131.132 www.freepicturepage.com
O1 - Hosts: 69.93.131.132 www.amsterdamsexxx.com
O1 - Hosts: 69.93.131.132 www.thumbco.com
O1 - Hosts: 69.93.131.132 www.cnstat.com
O1 - Hosts: 69.93.131.132 stat.t2t2.com
O1 - Hosts: 69.93.131.132 www.seetu.net
O1 - Hosts: 69.93.131.132 www.xfreehosting.com
O1 - Hosts: 69.93.131.132 www2.xfreehosting.com
O1 - Hosts: 69.93.131.132 www3.xfreehosting.com
O1 - Hosts: 69.93.131.132 www.sexushost.com
O1 - Hosts: 69.93.131.132 www.66036.com
O1 - Hosts: 69.93.131.132 www1.66036.com
O1 - Hosts: 69.93.131.132 www2.66036.com
O1 - Hosts: 69.93.131.132 www3.66036.com
O1 - Hosts: 69.93.131.132 www4.66036.com
O1 - Hosts: 69.93.131.132 www5.66036.com
O1 - Hosts: 69.93.131.132 www6.66036.com
O1 - Hosts: 69.93.131.132 www7.66036.com
O1 - Hosts: 69.93.131.132 www8.66036.com
O1 - Hosts: 69.93.131.132 www.topsex2k.com
O1 - Hosts: 69.93.131.132 www.upme.net
O1 - Hosts: 69.93.131.132 cnsmin.3721.com
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLO~1\CnsHook.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\Program Files\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [msconfig] C:\WINDOWS\System32\msconfig.exe
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msconfig] C:\WINDOWS\System32\msconfig.exe
O4 - HKCU\..\RunOnce: [ICQ] C:\Program Files\ICQ\ICQ.exe -trayboot
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Short Message (HKLM)
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Instant Messenger (HKLM)
O9 - Extra button: 3721 Assistant (HKLM)
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra 'Tools' menuitem: Repair Browser (HKLM)
O9 - Extra 'Tools' menuitem: Clean Internet access record (HKLM)
O10 - Unknown file in Winsock LSP: c:\progra~1\worm\imsf.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\worm\imsf.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\worm\imsf.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\worm\imsf.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\worm\imsf.dll
O11 - Options group: [!CNS] Chinese keywords
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/p ... s/flash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://utu.popcap.com/games/popcaploader_v5.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4E1B7113-6390-46DA-BCDD-ECE00F4A580C}: NameServer = 202.188.0.133 202.188.1.5
<B>
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.babe4us.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.babe4us.com</b>
this 2 i delete liao..but after restart still come out
O10 - Unknown file in Winsock LSP: c:\progra~1\worm\imsf.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\worm\imsf.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\worm\imsf.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\worm\imsf.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\worm\imsf.dll
and this come not delete leh
please help me...coz always come out the SEx web site...really "jialat" lah....cause got kids to online also |
|
|
|
|
|
|
| |
本周最热论坛帖子
|