123   3  /  3  页   跳转

浏览器被劫持了(在线等)

[PID: 1352][C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe]  <Network Associates, Inc.><2.0.275.0>
[PID: 1360][D:\KAVPFW.EXE]  <Kingsoft Corporation><2004, 8, 16, 295>
    [D:\KAVMLM.DLL]  <Kingsoft Corporation><2003.11.12.10>
    [D:\PFWScanC.dll]  <KingSoft><2002, 4, 12, 3>
    [D:\KAMsgBox.dll]  <><2002.9.27.30>
    [D:\NetShare.dll]  <Kingsoft Antivirus><2004, 2, 20, 67>
    [D:\KAEPlat.DLL]  <Kingsoft Corp.><2005, 12, 29, 56>
    [D:\KAEMem.DAT]  <Kingsoft><2006, 4, 12, 13>
    [D:\KAEUnpack.DAT]  <Kingsoft Corp.><2006, 6, 15, 44>
    [D:\KAEQSCAN.DLL]  <Kingsoft Corp><2004, 3, 26, 69>
    [D:\KAVLogFn.dll]  <N/A><2003, 11, 26, 16>
[PID: 1376][C:\WINNT\system32\Internat.exe]  <Microsoft Corporation><5.00.2920.0000>
[PID: 1328][C:\Program Files\MSN Messenger\msnmsgr.exe]  <Microsoft Corporation><7.0.0816>
    [C:\WINNT\system32\msdmo.dll]  <N/A><N/A>
[PID: 1508][C:\WINNT\system32\drivers\mcq\adout.exe]  <><1, 0, 0, 8>
[PID: 408][C:\WINNT\system32\wuauclt.exe]  <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
    [C:\WINNT\system32\EntApi.dll]  <Network Associates, Inc><8.0.0.240>
[PID: 1544][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2800.1106>
    [C:\WINNT\system32\EntApi.dll]  <Network Associates, Inc><8.0.0.240>
    [C:\WINNT\system32\kakatool.dll]  <Beijing Rising Technology Co., Ltd.><2, 0, 0, 9>
    [C:\PROGRA~1\MMSASS~1\mmsass~1.dll]  <><1, 2, 0, 5>
    [C:\Program Files\Network Associates\VirusScan\scriptproxy.dll]  <Network Associates, Inc.><8.0.0.912>
    [C:\Program Files\Network Associates\VirusScan\mytilus.dll]  <Network Associates, Inc.><8.0.0.251>
    [C:\Program Files\Network Associates\VirusScan\Res04\McShield.dll]  <Network Associates, Inc.><8.0.0.251>
    [C:\Program Files\Common Files\Network Associates\Engine\mcscan32.dll]  <McAfee, Inc.><4.4.00>
    [C:\WINNT\system32\macromed\flash\Flash.ocx]  <Macromedia, Inc.><7,0,19,0>
[PID: 980][E:\Program Files\Tencent\QQ\QQ.exe]  <TENCENT><0, 0, 0, 0>
    [E:\Program Files\Tencent\QQ\QQBaseClassInDll.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\QQHelperDll.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\BasicCtrlDll.dll]  <Tencent><5, 0, 200, 160>
    [E:\Program Files\Tencent\QQ\QQAPI.dll]  <><1, 0, 0, 1>
    [e:\Program Files\Tencent\QQ\TIMProxy.dll]  <tencent><0, 3, 2, 4>
    [E:\Program Files\Tencent\QQ\LoginCtrl.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\npkcntc.dll]  <INCA Internet Co., Ltd.><2006, 3, 2, 1>
    [E:\Program Files\Tencent\QQ\npkpdb.dll]  <INCA Internet Co., Ltd.><2003, 10, 1, 1>
    [E:\Program Files\Tencent\QQ\QQRes.dll]  <tencent><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\QQMainFrame.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\CQQApplication.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\NewSkin.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\HostingMgr.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\CameraDll.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\MailSummary.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\QQSpace.dll]  <><1, 0, 0, 1>
    [C:\WINNT\system32\msdmo.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\QQGroupMng.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\GroupLive.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\QQSysMsgMng.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\BQQApplication.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\UserDefinedHead.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\QQPlugin.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\LongConnection.dll]  <tencent><5, 0, 200, 160>
    [E:\Program Files\Tencent\QQ\QRingMng.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\PhoneAPI.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\DialerAllinOne.dll]  <tencent><1, 4, 0, 0>
    [E:\Program Files\Tencent\QQ\QQPet.dll]  <><1, 0, 0, 1>
    [E:\Program Files\Tencent\QQ\QQAvatar.dll]  <N/A><N/A>
    [E:\Program Files\Tencent\QQ\FlashAvatarDll.dll]  <><1, 4, 0, 1>
[PID: 1580][E:\Program Files\Tencent\QQ\TIMPlatform.exe]  <tencent><0, 3, 1, 8>
    [e:\Program Files\Tencent\QQ\TIMProxy.dll]  <tencent><0, 3, 2, 4>
[PID: 1480][E:\Program Files\sre\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINNT\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 

MMSS彩信依然无法卸载,还有其他的卸载工具吗?
Ie插件无法卸载。我都试了几回了。
总是弹出网页跟这个卸载关系大吗?
是不是别的原因啊,是不是浏览器没有设置好?
gototop
 

关闭所有浏览窗口以及一些不必要的程序
运行(双击)System Repair Engineer,使用“系统修复,浏览器加载项”来删除以下选项。
C:\PROGRA~1\MMSASS~1\mmsass~1.dll
运行(双击)System Repair Engineer,点“启动项目,服务,点“Win32服务应用程序”勾选“隐藏微软服务”选中病毒服务JMediaService,Network Connection选择“删除服务”点“设置”选择“否”最后重启。(每一个逗号隔开的就是一个病毒的服务,请逐一删除)
重启后删除
C:\windows\system32\Netserv.exe
C:\PROGRA~1\MMSASS~1
靖再扫份日志粘上来。
gototop
 
123   3  /  3  页   跳转
页面顶部
Powered by Discuz!NT