1   1  /  1  页   跳转

怪事!!!我的QQ号

怪事!!!我的QQ号

怪事,我的QQ号聊天记录全无,从4月7日到现在没有任何聊天记录。同部机器,3个QQ号同时上网,而独我的QQ号聊天记录没有,我没有删除聊天记录,也是在普通模式下上的网,我的另外2个QQ号有聊天记录,恳请高手们指点迷津,因为这个QQ是群聊号,含有技术性的东西,有时关闭某个群聊号,再打开里面什么也没有,烦人啊!!高手帮帮我啊!!
再有一个,以前网页打开很慢,后来经“不言放弃”“ZQ77”两位热心高手的指点下,查找病毒处理后网速极快!感谢两位!!不过我错删了rundll32.文件,再也打不开控制面板了和其他的东西, 是否有关联?
  现附上日志,看看是否还有病毒?
Logfile of Kaka v2. 0. 0. 8 Scan Module v2. 0. 0. 1
Scan saved at 20:18:11, on 2006-05-05
Platform: Microsoft Windows XP Professional Service Pack 2 (Build 2600)
MSIE: Internet Explorer v6.00 SP2; (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))


Running processes:
[SMSS.EXE]
CommandLine =

[CSRSS.EXE]
CommandLine = C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

[WINLOGON.EXE]
CommandLine = winlogon.exe

[SERVICES.EXE]
CommandLine = C:\WINDOWS\system32\services.exe

[LSASS.EXE]
CommandLine = C:\WINDOWS\system32\lsass.exe

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss

[CCenter.exe]
CommandLine = "C:\Program Files\Rising\Rav\CCenter.exe"

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost.exe -k NetworkService

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost.exe -k LocalService

[RavMonD.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmond.exe"

[EXPLORER.EXE]
CommandLine = C:\WINDOWS\Explorer.EXE

[SPOOLSV.EXE]
CommandLine = C:\WINDOWS\system32\spoolsv.exe

[RavStub.exe]
CommandLine = "C:\Program Files\Rising\Rav\RavStub.exe" /RAVMOND

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost.exe -k imgsvc

[RavTask.exe]
CommandLine = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM

[RavMon.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmon.exe" -SYSTEM

[realsched.exe]
CommandLine = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[ctfmon.exe]
CommandLine = "C:\WINDOWS\system32\ctfmon.exe"

[QQ.exe]
CommandLine = "F:\Program Files\Tencent\QQ\QQ.exe"

[alg.exe]
CommandLine = C:\WINDOWS\System32\alg.exe

[TIMPlatform.exe]
CommandLine = "F:\Program Files\Tencent\QQ\TIMPlatform.exe" -Embedding

[wuauclt.exe]
CommandLine = "C:\WINDOWS\system32\wuauclt.exe" /RunStoreAsComServer Local\[360]SUSDSb0d565312dbd614aa2d9ba1ebd9094aa

[RisingMain.exe]
CommandLine = "C:\Program Files\瑞星专家服务系统-标准版\RisingMain.exe"

[wuauclt.exe]
CommandLine = "C:\WINDOWS\system32\wuauclt.exe"

[KkScan.exe]
CommandLine = "C:\Program Files\Rising\KakaToolBar\KkScan.exe"

R3 - Default URLSearchHook is missing
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [stup.exe] C:\PROGRA~1\TENCENT\Adplus\stup.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [RavStub] "C:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE
O4 - Startup: 腾讯QQ.lnk = F:\Program Files\Tencent\QQ\QQ.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - F:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\Program Files\Tencent\QQ\SendMMS.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O16 - DPF: {52DF16E3-6C4F-4B22-8BAF-09263E463B48} - http://218.30.82.36/md5/YahooOnlineScanTest/KOSInit.cab
O16 - DPF: {DD473D47-C45E-427D-87C5-D6DEFBF8AB42} (WacosPrinterCtrlX Control) - http://192.130.1.74/Share/ActiveX/WacosPrinterCtrl.inf
O17 - HKLM\System\CCS\Services\Tcpip\..\{A9F5D855-0DFD-4666-B6FA-4E31A7A429A3}: NameServer = 61.187.98.3 202.103.96.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{F7146792-D1B1-4892-9B04-E2C3F0E6622D}: NameServer = 193.130.0.9
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O21 - SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll
O23 - Service: Print Manager (BKMARKS) -  - C:\WINDOWS\system32\rundll32.exe c:\windows\system32\wbem\irjit.dll,export 1087
O23 - Service: Indexing Manager (Hardware) -  - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Human Interface Device Access (HidServ) -  - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\Rising\Rav\CCenter.exe"
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\Rising\Rav\Ravmond.exe"
O23 - Service: SDAgent Service (SDAgentService) -  - C:\Program Files\Common Files\smartde\sde.exe
O23 - Service: StdService (StdService) -  - C:\WINDOWS\system32\rundll32.exe c:\windows\system32\stdsver.dll,service
最后编辑2006-05-06 18:07:50
分享到:
gototop
 

下载HijackThisV1.99.1并用它修复以下

http://forum.ikaka.com/topic.asp?board=67&artid=5188931

结束进程
C:\WINDOWS\system32\rundll32.exe
---------------------------------
修复:
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [stup.exe] C:\PROGRA~1\TENCENT\Adplus\stup.exe
O23 - Service: SDAgent Service (SDAgentService) - - C:\Program Files\Common Files\smartde\sde.exe
O23 - Service: StdService (StdService) - - C:\WINDOWS\system32\rundll32.exe c:\windows\system32\stdsver.dll,service
控制面板-性能与维护-管理工具-服务,找到SDAgent Service和StdService→双击→启动类型→禁止→停止→应用→确定。
终止SDAgent Service和StdService这个服务。
然后在注册表中展开
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
删除SDAgentService项目

然后找到如下文件并删除(如果有的话)

C:\WINDOWS\SYSTEM32\stdup.dll

C:\WINDOWS\system32\STDSVER.DLL

C:\WINDOWS\system32\stdcache\

C:\Program Files\Common Files\smartde\

C:\Program Files\TENCENT\Adplus\
gototop
 

为了保险,你可以在聊天结束后,直接手动保存QQ的聊天记录。
gototop
 

2116bromgamed2m 大侠:你好!我依照你的指点,差不多处理完,但是这个我弄不明白,如何去找到它或打开它,“然后在注册表中展开
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
删除SDAgentService项目”
gototop
 

【回复“心仪所向”的帖子】

打开注册表编辑器的方法:

开始->运行...

输入:

regedit

点“确定”按钮。

修改注册表后,一般按F5键刷新生效。如果不行,重新启动系统看看。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT