瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】我的IE出老弹出奇虎网页呀?帮帮我吧。我没招了。

12   1  /  2  页   跳转

【求助】我的IE出老弹出奇虎网页呀?帮帮我吧。我没招了。

【求助】我的IE出老弹出奇虎网页呀?帮帮我吧。我没招了。

求求各位高手吧,我的电脑一打开IE浏览网页就会自动带出一个奇虎的网页(www.qihoo.com)而且打开的时间速度比以前慢一半,CPU使用记录一下就是100%我安装了卡卡助手也没招,用升级最新版的瑞星也没杀出病毒。有谁可以帮我吗?和我QQ373625970联系好吧?
  ~~~~~~~汗汗汗~~~~~~~[img][/img]
最后编辑2006-04-17 23:38:55
分享到:
gototop
 

发个扫描的日志上来啊!^
gototop
 

这个扫描日志我怎么发也发不上来呀,我太笨。。汗~~~
现在我重置了一个IE浏览器,这两个小时好像没有弹出来了,可是每打开一次网页,瑞星监控就会提示下面三个注册表项要改删除默认,我都选择拒绝修改。删除默认----我把这三个注册表项复复制下了来,帮我看看吧是不是这里出了问题,谢谢。
HKEY_CLASSES_ROOT\.HTM\OPENWITHLIST\MICROSOFT OFFICE WORD\SHELL\EDIT
 
HKEY_CLASSES_ROOT\.HTM\OPENWITHLIST\MICROSOFT OFFICE WORD\SHELL
 
HKEY_CLASSES_ROOT\.HTM\OPENWITHLIST\MICROSOFT OFFICE WORD
 
gototop
 

【回复“我是电脑新手呀”的帖子】
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
下载HIJACKTHIS
导出全部日志
gototop
 

* HijackThis v1.99.1 *
程序设计: Merijn - merijn@spywareinfo.com   
http://www.merijn.org/files/hijackthis.zip
http://www.merijn.org/index.html

汉化:zww3008 zww3008@yahoo.com.cn

HijcakThis日志中的每一行以一个分类名称开始。                                                                   
要查看主窗口扫结果列表中的某个项目类别的更多详细信息,请选定该项目所在行使其高亮显示,然后点击“关于该项目的信息...”按钮即可弹出该项目类别的详细信息说明。                                                                                               

R - 默认起始主页或默认搜索页注册表键值的改变,或新建的可能导致其改变的注册表键值
    R0 - 注册表中IE主页/搜索页默认键值的改变 
    R1 - 新建的注册表键值(V)         
    R1 - 新建的注册表键值(K)       
    R3 - 在本应只有一个键值的地方新建的额外键值 
F - ini文件中的启动项或映射到注册表中的键值       
    F0 - System.ini中的启动项改变值 
    F1 - Win.ini中的启动项新建值     
    F2 - 注册表中System.ini映射区中的启动项或UserInit项后面启动的其他程序
    F3 - 注册表中Win.ini文件映射区中的启动项                   
N - Netscape、Mozilla浏览器的默认起始主页和默认搜索页的改变。       
    N1 - Netscape 4.x中,prefs.js的改变       
    N2 - Netscape 6中,prefs.js的改变       
    N3 - Netscape 7中,prefs.js的改变       
    N4 - Mozilla中,prefs.js的改变       
O - 其它类,包含很多方面,下面一一详述                     
    O1 - 在Host文件中添加的IP地址域名解析映射
    O2 - IE浏览器辅助对象(BHO模块)                 
    O3 - IE工具栏                               
    O4 - 随系统加载的自启动顶         
    O5 - 使控制面板中隐去Internet选项 
    O6 - 禁用Internet选项     
    O7 - 禁用注册表编辑器                         
    O8 - IE的右键菜单中的新增项目               
    O9 - 额外的IE“工具”菜单项目及工具栏按钮               
    O10 - Winsock LSP浏览器劫持     
    O11 - IE“高级选项”中的新项目         
    O12 - IE插件     
    O13 - 对IE默认的URL前缀的修改               
    O14 - IERESET.INF文件中的改变     
    O15 - “受信任的站点”中的不速之客     
    O16 - 下载的程序文件,即下载程序目录下的ActiveX对象
    O17 - 域劫持/DNS服务器 
    O18 - 额外协议和协议劫持程序     
    O19 - 用户样式表劫持             
    O20 - 注册表键值AppInit_DLLs处的自启动项               
    O21 - 注册表键 ShellServiceObjectDelayLoad (SSODL)处的自启动项         
    O22 - 注册表键 SharedTaskScheduler 处的自启动项       

    O23 - 列举 NT 服务                 

HijackThis命令行方式       
* /autolog - 随系统启动运行HijackThis扫描,并生成和打开扫描日志 
* /ihatewhitelists - 忽略所有的内部空白列表                 
* /uninstall - 删除HijackThis的注册表信息,备份后退出                               

* 版本更新历史 *       

[v1.99.1]
* Added Winlogon Notify keys to O20 listing
* Fixed crashing bug on certain Win2000 and WinXP systems at O23 listing
* Fixed lots and lots of 'unexpected error' bugs
* Fixed lots of inproper functioning bugs (i.e. stuff that didn't work)
* Added 'Delete NT Service' function in Misc Tools section
* Added ProtocolDefaults to O15 listing
* Fixed MD5 hashing not working
* Fixed 'ISTSVC' autorun entries with garbage data not being fixed
* Fixed HijackThis uninstall entry not being updated/created on new versions
* Added Uninstall Manager in Misc Tools to manage 'Add/Remove Software' list
* Added option to scan the system at startup, then show results or quit if nothing found
[v1.99]
* Added O23 (NT Services) in light of newer trojans
* Integrated ADS Spy into Misc Tools section
* Added 'Action taken' to info in 'More info on this item'
[v1.98]
* Definitive support for Japanese/Chinese/Korean systems
* Added O20 (AppInit_DLLs) in light of newer trojans
* Added O21 (ShellServiceObjectDelayLoad, SSODL) in light of newer trojans
* Added O22 (SharedTaskScheduler) in light of newer trojans
* Backups of fixed items are now saved in separate folder
* HijackThis now checks if it was started from a temp folder
* Added a small process manager (Misc Tools section)
[v1.96]
* Lots of bugfixes and small enhancements! Among others:
* Fix for Japanese IE toolbars
* Fix for searchwww.com fake CLSID trick in IE toolbars and BHO's
* Attributes on Hosts file will now be restored when scanning/fixing/restoring it.
* Added several files to the LSP whitelist
* Fixed some issues with incorrectly re-encrypting data, making R0/R1 go undetected until a restart
* All sites in the Trusted Zone are now shown, with the exception of those on the nonstandard but safe domain list
[v1.95]
* Added a new regval to check for from Whazit hijack (Start Page_bak).
* Excluded IE logo change tweak from toolbar detection (BrandBitmap and SmBrandBitmap).
* New in logfile: Running processes at time of scan.
* Checkmarks for running StartupList with /full and /complete in HijackThis UI.
* New O19 method to check for Datanotary hijack of user stylesheet.
* Google.com IP added to whitelist for Hosts file check.
[v1.94]
* Fixed a bug in the Check for Updates function that could cause corrupt downloads on certain systems.
* Fixed a bug in enumeration of toolbars (Lop toolbars are now listed!).
* Added imon.dll, drwhook.dll and wspirda.dll to LSP safelist.
* Fixed a bug where DPF could not be deleted.
* Fixed a stupid bug in enumeration of autostarting shortcuts.
* Fixed info on Netscape 6/7 and Mozilla saying '%shitbrowser%' (oops).
* Fixed bug where logfile would not auto-open on systems that don't have .log filetype registered.
* Added support for backing up F0 and F1 items (d'oh!).
[v1.93]
* Added mclsp.dll (McAfee), WPS.DLL (Sygate Firewall), zklspr.dll (Zero Knowledge) and mxavlsp.dll (OnTrack) to LSP safelist.
* Fixed a bug in LSP routine for Win95.
* Made taborder nicer.
* Fixed a bug in backup/restore of IE plugins.
* Added UltimateSearch hijack in O17 method (I think).
* Fixed a bug with detecting/removing BHO's disabled by BHODemon.
* Also fixed a bug in StartupList (now version 1.52.1).
[v1.92]
* Fixed two stupid bugs in backup restore function.
* Added DiamondCS file to LSP files safelist.
* Added a few more items to the protocol safelist.
* Log is now opened immediately after saving.
* Removed rd.yahoo.com from NSBSD list (spammers are starting to use this, no doubt spyware authors will follow).
* Updated integrated StartupList to v1.52.
* In light of SpywareNuker/BPS Spyware Remover, any strings relevant to reverse-engineers are now encrypted.
* Rudimentary proxy support for the Check for Updates function.
[v1.91]
* Added rd.yahoo.com to the Nonstandard But Safe Domains list.
* Added 8 new protocols to the protocol check safelist, as well as showing the file that handles the protocol in the log (O18).
* Added listing of programs/links in Startup folders (O4).
* Fixed 'Check for Update' not detecting new versions.
[v1.9]
* Added check for Lop.com 'Domain' hijack (O17).
* Bugfix in URLSearchHook (R3) fix.
* Improved O1 (Hosts file) check.
* Rewrote code to delete BHO's, fixing a really nasty bug with orphaned BHO keys.
* Added AutoConfigURL and proxyserver checks (R1).
* IE Extensions (Button/Tools menuitem) in HKEY_CURRENT_USER are now also detected.
* Added check for extra protocols (O18).
[v1.81]
* Added 'ignore non-standard but safe domains' option.
* Improved Winsock LSP hijackers detection.
* Integrated StartupList updated to v1.4.
[v1.8]
* Fixed a few bugs.
* Adds detecting of free.aol.com in Trusted Zone.
* Adds checking of URLSearchHooks key, which should have only one value.
* Adds listing/deleting of Download Program Files.
* Integrated StartupList into the new 'Misc Tools' section of the Config screen!
[v1.71]
* Improves detecting of O6.
* Some internal changes/improvements.
[v1.7]
* Adds backup function! Yay!
* Added check for default URL prefix
* Added check for changing of IERESET.INF
* Added check for changing of Netscape/Mozilla homepage and default search engine.
[v1.61]
* Fixes Runtime Error when Hosts file is empty.
[v1.6]
* Added enumerating of MSIE plugins
* Added check for extra options in 'Advanced' tab of 'Internet Options'.
[v1.5]
* Adds 'Uninstall & Exit' and 'Check for update online' functions.
* Expands enumeration of autoloading Registry entries (now also scans for .vbs, .js, .dll, rundll32 and service)
[v1.4]
* Adds repairing of broken Internet access (aka Winsock or LSP fix) by New.Net/WebHancer
* A few bugfixes/enhancements
[v1.3]
* Adds detecting of extra MSIE context menu items
* Added detecting of extra 'Tools' menu items and extra buttons
* Added 'Confirm deleting/ignoring items' checkbox
[v1.2]
* Adds 'Ignorelist' and 'Info' functions
[v1.1]
* Supports BHO's, some default URL changes
[v1.0]
* Original release
再帮我看看吧。是哪个地方的问题哈/非常感激。。。。
gototop
 

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      20:17:32, 日期 2006-4-13
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\瑞星杀毒下载版安装文件\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\瑞星杀毒下载版安装文件\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
D:\瑞星杀毒下载版安装文件\Rising\Rav\RavStub.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\Explorer.EXE
D:\瑞星杀毒下载版安装文件\Rising\Rav\RavTask.exe
D:\瑞星杀毒下载版安装文件\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Phone\Skype.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\mqsvc.exe
C:\WINDOWS\System32\mqtgsvc.exe
D:\qq20006b1\QQ.exe
D:\qq20006b1\TIMPlatform.exe
D:\qq20006b1\QQ.exe
D:\qq20006b1\QQ.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\李晓清\LOCALS~1\Temp\Rar$EX06.350\HijackThis1991zww.exe

R3 - 默认的URLSearchHook丢失。用HijackThis修复
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - 启动项HKLM\\Run: [RavTask] "D:\瑞星杀毒下载版安装文件\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - D:\qq20006b1\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\qq20006b1\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\qq20006b1\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\qq20006b1\SendMMS.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1118765364316
O16 - DPF: {AC3A36A8-9BFF-410A-A33D-2279FFEB69D2} (Qzone Media Tools) - http://imgcache.qq.com/music/QQMusicSetup.exe
O16 - DPF: {C661F36D-DF85-4EF4-83C7-E107B83D04B1} (WebActivater Control) - http://dl_dir.qq.com/3dshow/3DShowVM.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl Object) - https://www.tenpay.com/download/qqedit.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - NT 服务: P4P Service - Unknown owner - D:\P4P\p2psvr.exe (file missing)
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\瑞星杀毒下载版安装文件\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\瑞星杀毒下载版安装文件\Rising\Rav\Ravmond.exe

帮帮我看看吧!!!谢谢你们了呀!!!
gototop
 

修复:
R3 - 默认的URLSearchHook丢失。用HijackThis修复
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
删除文件
C:\WINDOWS\SYSTEM32\stdup.dll
gototop
 

我修复了R3 - 默认的URLSearchHook

O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll

这个也修复了,但是当时再扫描没了,可是重启系统又有这项了,再次弹出那个网页。

还有删除文件C:\WINDOWS\SYSTEM32\stdup.dll也不成功,提示说"...文件未写保护或正被使用...."这类似的,我要怎么办呀?在帮我吧,谢谢了啦!!!
gototop
 

开始→控制面板→性能和维护→管理工具→服务→查找到StdService

所以如果用户遇到stdup.dll反复出现、无法删除的情况
请按以下步骤操作

1、开始→控制面板→性能和维护→管理工具→服务→查找StdService→右击→属性→启动类型→禁止→应用→停止→确定。

2、重新启动电脑, 开机检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式进入Windows
运行Hijackthis,扫描结束后在下列选项前打上勾,然后选修复“Fix Checked”:
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll

3、显示隐藏文件
双击我的电脑--工具---文件夹选项--查看选项卡--单击选取"显示隐藏文件或文件夹"--清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示您确定更改时,单击“是”--单击“确定”。
然后找到如下文件并删除
C:\WINDOWS\SYSTEM32\stdup.dll
C:\WINDOWS\system32\STDSVER.DLL
C:\WINDOWS\system32\stdcache\整个目录
gototop
 

有效吗?我也是遇到这个问题,但是,现在弹出的网页出现了类似“变种”的现象,弹出的网页出现了多样化,即打开随便什么网站时同时自动弹出的是A网站,第二次打开就出现B网站的页面……,没有重复,这怎么办呢?
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT