close

英語口譯價位語言翻譯公司C:\Program Files\Symantec AntiVirus\DefWatch.exe
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O8 - Extra context menu item: 匯出至 Microsoft Excel(&X) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll翻譯社NvStartup
C:\Program Files\Eset od32krn.exe

今天不知道中了什麼怪毒...
C:\Program Files\MSN Messenger\MsnMsgr.Exe
O2 - BHO: (no name) - {67270207-b9ee-4d26-9270-860fdb060ca1} - C:\WINDOWS\system32\ixt0.dll
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset od32krn.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
C:\WINDOWS\system32\svchost.exe
不只首頁被綁架了...就連左下角的對象列也一向泛起訊息說什麼天成翻譯社的電腦中毒要采辦他們的防毒軟體!!
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Eset od32kui.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u

PS:天成翻譯社遇到的失職軟體是趨勢的,只會一直叫有病毒,但是卻什麼事都不做!只問翻譯公司要不要切斷網路連線翻譯
翻譯社 on 2006/12/1
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
www.360safe.com
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
天成翻譯社想一定是告白病毒! 可是為什麼防毒軟體都殺了有會依直泛起勒?
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\spoolsv.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
Running processes:
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
天成翻譯社的媽阿 誰來救就天成翻譯社阿!!!! 謝謝列位了
O8 - Extra context menu item: 轉換成簡體中文(&S) - res://C:\WINDOWS\system32\tcscconv.dll/tosimp
C:\WINDOWS\Explorer.EXE
大要看了一下你的記載檔
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
我的首頁用regedit底下去改 開初是變回來了, 可是從頭開機後又回到了本來的告白首頁....
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O4 - HKLM\..\RunOnce: [mcvsescn.exe] c:\PROGRA~1\mcafee.com\vso\mcvsescn.exe -regserver
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe


Platform: Windows XP SP2 (WinNT 5.01.2600)
http://fileinfo.prevx.com/adware/qq215224914976-ISSE17080133/ISSEARCH.EXE.html
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O3 - Toolbar: Dr.eye WebPage Translation - {92B255FE-94E2-4BCA-958D-3926CE38913F} - C:\PROGRA~1\Inventec\Dreye\DreyeMT\DREYEI~1.DLL

Logfile of HijackThis v1.99.1
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
O8 - Extra context menu item: Foxy 下載 - res://C:\Program Files\Foxy\Foxy.exe/download.htm
C:\WINDOWS\System32\smss.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
C:\WINDOWS\system32\services.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32 vsvc32.exe
C:\WINDOWS\system32\ctfmon.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
以下是我的log files 不知道有沒人能看出眉目...
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
C:\WINDOWS\system32\issearch.exe
C:\WINDOWS\system32\svchost.exe
連我的symantc antivirus 也一向偵測到病毒翻譯社 可是氣人的是怎麼殺就是會再泛起!!> <
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
C:\Documents and Settings\Administrator\桌面\Tools\HijackThis.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
建議使用 360安全衛士
C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
我最近也遇過類似的事情,最後結論發現防毒軟體是防毒的,這種工作仍是要交給防木馬軟體或是防特務軟體來打掃才會乾淨,畢竟各司其職!
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
C:\Program Files\Windows Media Player\wmplayer.exe

O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [msci] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2006121215421_mcinfo.exe /insfin
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O14 - IERESET.INF: START_PAGE_URL=http://tw.yahoo.com
C:\WINDOWS\system32\lsass.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
也能夠進入平安模式 進行殺毒 (開機 BIOS自檢后按F8)
有問題的程式應當是issearch.exe吧!
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
這是我抓到的毒
一向跑出要天成翻譯社采辦防毒軟體的網頁
O4 - HKLM\..\RunOnce: [vsoupd.dll] rundll32.exe advpack.dll,RegisterOCX c:\PROGRA~1\mcafee.com\vso\vsoupd.dll

O23 - Service: HotKey Poller - Unknown owner - C:\WINDOWS\G_Server2006
請看
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{C5544812-7CDF-4CEB-8D94-8C0F81C24507}: NameServer = 168.95.192.1 168.95.1.1
C:\WINDOWS\system32\winlogon.exe
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll翻譯社NvTaskbarInit
翻譯公司的同時履行好多防毒軟體喔!他們不會打架嗎?
C:\Program Files\iPod\bin\iPodService.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O8 - Extra context menu item: Foxy 搜索 - res://C:\Program Files\Foxy\Foxy.exe/search.htm
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O20 - Winlogon Notify: winbjt32 - winbjt32.dll (file missing)
O8 - Extra context menu item: 轉換成繁體中文(&T) - res://C:\WINDOWS\system32\tcscconv.dll/totrad
O4 - HKLM\..\Run: [CleanUp] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2006121215422_mcappins.exe /v=3 /cleanup
c:\progra~1\mcafee.com\vso\mcvsescn.exe



本文出自: https://www.mobile01.com/topicdetail.php?f=174&t=243151有關翻譯的問題歡迎諮詢天成翻譯社

arrow
arrow
    創作者介紹
    創作者 rodriqpn8jb 的頭像
    rodriqpn8jb

    rodriqpn8jb@outlook.com

    rodriqpn8jb 發表在 痞客邦 留言(0) 人氣()


    留言列表 留言列表

    發表留言