瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » IE首页被锁定为7939.com/7b.com.cn的问题和修复(更新)
mopery - 2006-9-3 17:09:00
引用:
【西门修罗的贴子】斑竹为什么不提前几天发!我的电脑25号中招!还的我重做系统!
………………





这个有点难了...就前俩天开始才多起来...专杀我也是在别人那知道的..
zxcve - 2006-9-3 17:44:00
谢谢啦~~~已经OK了
但是  反而我觉得瑞星(花几百元买回来的)一点用都没有
什么作用也没起  按了等于没按
是不是瑞星的开发部已经换人了还是堕落了啊!!
我想瑞星要改进改进  不然~~~
ceoht - 2006-9-3 17:50:00
http://free.ys168.com/?mopery
这个下载不了啊,总是显示流量满了,试了半个多小时了还是不行,哪位高手指点一下
mopery - 2006-9-3 17:57:00
等一个多小时吧  2小时才 20M 流量...你也可以到分流的那个 网盘下载..
小小摩羯 - 2006-9-3 18:13:00
还是不行  每次开机都会出现
希望明天升级瑞星后有对策
最好杀毒后能并屏蔽有关此毒的来源
我们低手只能靠你们正版杀毒了 希望不要让大家失望
tkabc - 2006-9-3 22:47:00
引用:
【ceoht的贴子】http://free.ys168.com/?mopery
这个下载不了啊,总是显示流量满了,试了半个多小时了还是不行,哪位高手指点一下
………………


試試這個連接....我上傳到我的blog....
http://space.uwants.com/batch.download.php?aid=86320
mopery - 2006-9-3 23:12:00
abc 都来了...- -...
ajwcj - 2006-9-3 23:14:00
谢谢 !!!
tkabc - 2006-9-4 0:28:00
引用:
【mopery的贴子】abc 都来了...- -...

………………

路過一下.....
LANHUA - 2006-9-4 9:09:00
感谢楼主呀!
我被这个坏东东害了一天,电脑还中了木马.终于在这找到了解决的方法!
气的我就想,法律怎么没有可以投诉这些恶网的呢?
随风流转不是云 - 2006-9-4 10:24:00
我有个cmd.exe占cpu内存,我还有俩winlogen,怎么办?
哈哈镜hahajing - 2006-9-4 11:03:00
支持
pxzx1119 - 2006-9-4 11:58:00
急切期待瑞星更新!!
aikakaka - 2006-9-4 13:21:00
谢谢搂住为人民服务……
大力支持你
xwee - 2006-9-4 13:21:00
主页是改回来了,可是总是弹出乱七八糟的网站,这个怎么处理啊??
    http://www.maohehe.com/web/28.html
    http://show.googleadsenseagent.com/show/?VER=02&AdID=1003878&UID=00-50-70-A2-4A-35&SURL=http%3A%2F%2Falert%2Erising%2Ecom%2Ecn%2Fvirus%2Fvirusmonitor%2Easp&Host=alert.rising.com.cn&ConditionID=999
    http://show.googleadsenseagent.com/show/?VER=02&AdID=1003808&UID=00-50-70-A2-4A-35&SURL=http%3A%2F%2Fwww%2Ezhcw%2Ecom%2F&Host=www.zhcw.com&ConditionID=999
   
         
这些只是一部分,还有很多
abao315 - 2006-9-4 14:07:00
跪谢啊,再生父母!~
xiaoxiao26 - 2006-9-4 16:22:00
(1)我的电脑  按ctrl+alt+del之后 弹出的windows任务管理器  怎么只有任务和状态

其他上面的操作窗口(题目)怎么都没有了???只显示当前存在的任务和状态,进程根

本就看不到了~~~~~这是怎么回事??

(2)还有就是瑞星个人防火墙也不能用了!!

(3)雅虎助手中的IE修复---一键修复和高级修复根本不能用,点一下之后自动关闭。

(4)主页可以修改回来,但是过一会或者重起之后又恢复了~~很郁闷

俺是菜鸟,问问各位大侠到底该咋办啊~~~~~~~~痛苦

fengxing - 2006-9-4 17:07:00
前几步先按楼主说的做,然后去瑞星主页上下个"橙色八月专杀"杀一下电脑,然后再升级瑞星查杀一下
草原之夜啊 - 2006-9-4 17:36:00
第4步没有进行,其他都做了,但,还提示病毒在第6步路径那里,再怎么做呀?
没有酒量 - 2006-9-4 19:16:00
用黄山IE修复工具就可以了。
没有酒量 - 2006-9-4 19:17:00
用黄山IE修复工具就可以了。
蓉儿1981 - 2006-9-4 19:33:00
我的电脑里没有C:\WINDOWS\system32\brlmon.dll 或者C:\WINDOWS\System32\RavMon.dll或者C:\WINDOWS\system32\Rsvtub.dll怎么办呀
蓉儿1981 - 2006-9-4 19:40:00
好不容易找到了C:\WINDOWS\System32\RavMon.dll

可是这两个步骤不会,我太笨了,大伙教教

4.然后 用hijackthis修复
O4 - HKCU\..\Run: [Realplayer.exe] C:\WINDOWS\system32\Realplayer.exe
O4 - 启动项HKLM\\Run: [Realplayer.exe] C:\WINDOWS\system32\Realplayer.exe
这两项
5.修复注册表
开始 运行 输入regedit 删除HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft NT
和HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RunDown
HKLM\SOFTWARE\Microsoft\Baidu
蓉儿1981 - 2006-9-4 19:42:00
瑞星网站说升级最新版本可以杀死这个病毒,可我都杀三遍了,都没杀死,瑞星骗人的吧
newcenturymoon - 2006-9-4 19:52:00
手工最好  如果发现置顶贴子解决不了的话  请扫描个sreng 日志 上来
僞你訫酸 - 2006-9-4 20:46:00
支持一下,问一下有一种系统自带的网页怎么删啊,我用雅虎助手不管用!
零点起飞 - 2006-9-4 21:47:00
杀完后我IE不行了,请问一下是怎么回事?
一双击IE说"拒绝访问“,请问一下是怎么回事
零点起飞 - 2006-9-4 22:14:00
Logfile of HijackThis v1.99.1
Scan saved at 22:03:52, on 2006-9-4
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\PeanutHull3\PhCore.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\gogo\watchgo.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PeanutHull3\Phmain.exe
C:\Program Files\meibuddns70\meibu\meibuddns7.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Rav.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\new\LOCALS~1\Temp\Rar$EX00.469\HijackThis.exe

F3 - REG:win.ini: load=?粓??
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O1 - Hosts: 59.34.197.239 www.baidu.com
O1 - Hosts: 59.34.197.239 baidu.com
O1 - Hosts: 59.34.197.239 www.sohu.com
O1 - Hosts: 59.34.197.239 sohu.com
O1 - Hosts: 59.34.197.239 www.sina.com
O1 - Hosts: 59.34.197.239 sina.com
O1 - Hosts: 59.34.197.239 www.sina.com.cn
O1 - Hosts: 59.34.197.239 sina.com.cn
O1 - Hosts: 59.34.197.239 www.163.com
O1 - Hosts: 59.34.197.239 163.com
O1 - Hosts: 59.34.197.239 www.google.com
O1 - Hosts: 59.34.197.239 google.com
O1 - Hosts: 59.34.197.239 www.qq.com
O1 - Hosts: 59.34.197.239 qq.com
O1 - Hosts: 59.34.197.239 www.hao123.com
O1 - Hosts: 59.34.197.239 hao123.com
O1 - Hosts: 59.34.197.239 ttlttt.com
O1 - Hosts: 59.34.197.239 about:blank
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\Program Files\QQ2005\QQIEHelper.dll
O2 - BHO: (no name) - {72A79ABD-79BA-5D87-6B73-6837DB85DAC9} - C:\WINDOWS\system32\gogo.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: BitComet工具栏 - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\BitComet\BitCometBar\BitCometBar0.5.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [gogo] c:\Program Files\gogo\watchgo.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [NetRobocop] C:\Program Files\Robocop\Robocop.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhMain] C:\Program Files\PeanutHull3\Phmain.exe
O4 - Startup: KC2005.lnk = C:\Program Files\KC\KC2005.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: meibuddns7.lnk = C:\Program Files\meibuddns70\meibu\meibuddns7.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?SystemRoot%\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\QQ2005\AddToNetDisk.htm
O8 - Extra context menu item: 使用影音传送带下载 - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\QQ2005\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\QQ2005\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\QQ2005\SendMMS.htm
O9 - Extra button: 微软 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.microsoft.com/china/index.htm (file missing)
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\QQ2005\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\QQ2005\QQ.EXE
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\QQ2005\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\QQ2005\QQIEHelper.dll
O9 - Extra button: 访问加速 - {0713E8D2-850A-101B-AFC0-4210102A8DA7} - http://www.1-n.cn/fwjskt.asp (file missing) (HKCU)
O16 - DPF: {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} (photo_uploader Control) - http://upload.photo.163.com/photoup.cab
O16 - DPF: {A996E48C-D3DC-4244-89F7-AFA33EC60679} (Settings Class) - https://eces.foxconn.com/main/capicom.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{73B91F9D-6D98-449A-8250-87520385246E}: NameServer = 192.168.1.1
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PeanuthullCore - 广东网域 - C:\Program Files\PeanutHull3\PhCore.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

零点起飞 - 2006-9-4 22:16:00
请版主看看有没有问题
一人独处 - 2006-9-4 22:20:00
可是桌面上的IE还是打不开,是什么原因呢?
«23456789»
查看完整版本: IE首页被锁定为7939.com/7b.com.cn的问题和修复(更新)