瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】最近开始乱弹网页了,并且被强制安装酷桌面

12   2  /  2  页   跳转

【求助】最近开始乱弹网页了,并且被强制安装酷桌面

正在运行的进程
[PID: 152][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.00.2195.6601>
[PID: 180][\??\C:\WINNT\system32\csrss.exe]  <Microsoft Corporation><5.00.2195.6601>
[PID: 200][\??\C:\WINNT\system32\winlogon.exe]  <Microsoft Corporation><5.00.2195.6970>
[PID: 228][C:\WINNT\system32\services.exe]  <Microsoft Corporation><5.00.2195.6700>
    [C:\WINNT\system32\dmserver.dll]  <VERITAS Software Corp.><2195.6605.297.3>
[PID: 240][C:\WINNT\system32\lsass.exe]  <Microsoft Corporation><5.00.2195.6902>
[PID: 420][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 444][C:\WINNT\system32\spoolsv.exe]  <Microsoft Corporation><5.00.2195.6659>
[PID: 472][C:\WINNT\system32\crypserv.exe]  <Kenonic Controls Ltd.><5.4.0>
[PID: 488][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 508][C:\Program Files\ewido anti-spyware 4.0\guard.exe]  <Anti-Malware Development a.s.><4, 0, 0, 172>
    [C:\Program Files\ewido anti-spyware 4.0\engine.dll]  <Anti-Malware Development a.s.><4, 0, 0, 172>
[PID: 552][C:\WINNT\system32\nvsvc32.exe]  <NVIDIA Corporation><6.14.10.5303>
[PID: 596][C:\WINNT\system32\MSTask.exe]  <Microsoft Corporation><4.71.2195.6920>
[PID: 620][C:\WINNT\system32\stisvc.exe]  <Microsoft Corporation><5.00.2195.6656>
[PID: 664][C:\WINNT\System32\WBEM\WinMgmt.exe]  <Microsoft Corporation><1.50.1085.0100>
[PID: 696][C:\WINNT\system32\mspmspsv.exe]  <Microsoft Corporation><7.10.00.3059>
[PID: 704][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 828][C:\WINNT\Explorer.EXE]  <Microsoft Corporation><5.00.3700.6690>
    [D:\多媒体\HappyPlayer\Codecs\mmfinfo.dll]  <N/A><N/A>
    [D:\多媒体\HappyPlayer\Codecs\mkunicode.dll]  <N/A><N/A>
    [C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll]  <Anti-Malware Development a.s.><4, 0, 0, 172>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
[PID: 952][C:\WINNT\system32\msime.exe]  <Microsoft Corporation><5.1.2600.2180>
[PID: 968][C:\WINNT\SOUNDMAN.EXE]  <Realtek Semiconductor Corp.><5.1.0.27>
[PID: 992][C:\Program Files\Super Rabbit\MagicSet\DS.EXE]  <Super Rabbit Software><1.50>
[PID: 1016][C:\WINNT\system32\Internat.exe]  <Microsoft Corporation><5.00.2920.0000>
[PID: 960][C:\WINNT\system32\rundll32.exe]  <Microsoft Corporation><5.00.2134.1>
    [C:\DOCUME~1\123\LOCALS~1\APPLIC~1\ae31945\1.dll]  <千橡互联><2, 2, 1, 0>
    [C:\DOCUME~1\123\LOCALS~1\APPLIC~1\ae31945\3.dll]  <千橡互联><3, 0, 0, 0>
    [C:\DOCUME~1\123\LOCALS~1\APPLIC~1\ae31945\4.dll]  <千橡互联><3, 0, 0, 0>
[PID: 788][C:\WINNT\NOTEPAD.EXE]  <Microsoft Corporation><5.00.2140.1>
[PID: 876][C:\Program Files\VnetClient1.6\VnetClient.exe]  <><2005, 11, 18, 1>
    [C:\Program Files\VnetClient1.6\Communicate.dll]  <GDCN><2005, 3, 3, 1>
    [C:\Program Files\VnetClient1.6\DialModule.dll]  <GDCN><2005, 9, 1, 1>
    [C:\PROGRA~1\VNETCL~1.6\CLIENT~1.DLL]  <><2004, 2, 28, 1>
    [C:\PROGRA~1\VNETCL~1.6\PLUGIN~1.OCX]  <><2005, 12, 20, 1>
    [C:\PROGRA~1\VNETCL~1.6\sign.dll]  <0><2004, 12, 1, 1>
    [C:\PROGRA~1\VNETCL~1.6\ADVERT~1.OCX]  <><2005, 10, 13, 1>
    [C:\PROGRA~1\VNETCL~1.6\Gif89a.dll]  <><2005, 6, 21, 1>
    [C:\PROGRA~1\VNETCL~1.6\VnetBs.ocx]  <><2004, 11, 18, 1>
    [C:\PROGRA~1\VNETCL~1.6\ACCOUN~2.DLL]  <><2005, 8, 11, 1>
    [C:\PROGRA~1\VNETCL~1.6\AccountMgr.dll]  <><2005, 8, 16, 1>
    [C:\PROGRA~1\VNETCL~1.6\VnetSkin.ocx]  <GDDC><2005, 12, 21, 1>
    [C:\PROGRA~1\VNETCL~1.6\DialogStyle.dll]  <><1, 0, 0, 1>
    [C:\PROGRA~1\VNETCL~1.6\BDSearch.ocx]  <gdcn><2005, 12, 22, 1>
    [C:\PROGRA~1\VNETCL~1.6\Timer.ocx]  <><2005, 10, 9, 14>
    [C:\PROGRA~1\VNETCL~1.6\PLUGIN~2.OCX]  <><2005, 2, 24, 1>
    [C:\PROGRA~1\VNETCL~1.6\NEWMES~1.DLL]  <><2005, 8, 26, 1>
    [C:\PROGRA~1\VNETCL~1.6\PassCtrl.dll]  <GDCN><2006, 1, 9, 10>
    [C:\WINNT\system32\wpcap.dll]  <Politecnico di Torino><3, 0, 0, 18>
    [C:\WINNT\system32\pthreadVC.dll]  <N/A><N/A>
    [C:\WINNT\system32\packet.dll]  <Politecnico di Torino><3, 0, 0, 18>
    [C:\PROGRA~1\VNETCL~1.6\PlugPush.dll]  <><2004, 12, 21, 1>
    [C:\PROGRA~1\VNETCL~1.6\ALLINT~1.DLL]  <><2004, 11, 23, 1>
    [C:\PROGRA~1\VNETCL~1.6\VNETLO~1.OCX]  <><2005, 4, 19, 1>
    [C:\PROGRA~1\VNETCL~1.6\StatNum.dll]  <><2004, 11, 18, 1>
    [C:\PROGRA~1\VNETCL~1.6\VNETON~1.OCX]  <><2005, 3, 2, 1>
    [C:\PROGRA~1\VNETCL~1.6\ALLFUN~1.DLL]  <GDCN><2006, 1, 13, 11>
    [C:\PROGRA~1\VNETCL~1.6\VnetOptLog.dll]  <><2005, 9, 13, 9>
    [C:\PROGRA~1\VNETCL~1.6\DlgSkin.ocx]  <><1, 0, 0, 1>
    [C:\WINNT\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
[PID: 1256][D:\TT\TTraveler.exe]  <腾讯公司><3.0.0.241>
    [D:\TT\Plugins\TWeather\TWeather.dll]  <><1, 0, 0, 1>
    [D:\TT\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
    [C:\WINNT\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
[PID: 1284][C:\Program Files\WinRAR\WinRAR.exe]  <N/A><N/A>
[PID: 1076][E:\TEMP\Rar$EX00.936\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
gototop
 

日志不粘全,只能猜猜了。
关闭所有浏览窗口以及一些不必要的程序
运行(双击)System Repair Engineer,使用“系统修复,浏览器加载项”来删除以下选项。
C:\WINNT\system\1a3oc1f0.dll
<C:\WINNT\system32\CoolBho.dll

ALT+CTRL+DELETE调出任务管理器,终止msime.exe,LetsCool.exe的进程
运行(双击)System Repair Engineer,使用“启动项目,注册表”来删除以下选项。
C:\Program Files\LetsCool\LetsCool.exe
C:\WINNT\system32\mswdm.exe
删除
C:\WINNT\system32\msime.exe(一定要找到删除)
C:\Program Files\LetsCool
C:\WINNT\system32\mswdm.exe
重启后删除
C:\WINNT\system\1a3oc1f0.dll
<C:\WINNT\system32\CoolBho.dll
请再扫份日志粘上来。
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT