12   1  /  2  页   跳转

救命啊,郁闷了!弹垃圾网页!

救命啊,郁闷了!弹垃圾网页!

不知道在哪里中了招,开始是瑞星的全部监控系统被自动关闭,防火墙打不开,杀毒杀了N次,杀掉100多个病毒,然后我恢复了瑞星!然后又是IE打不开了,我就直接把桌面的IE删了,从"C:\Program Files\Internet Explorer"创建了一个快捷方程到桌面,这下可好,鼠标右键点就是跟普通文件一样的了,没有原来的那些:使用空白页面呀,什么的了!但是点这个快捷还是能打开网页的,但是就是老弹垃圾网站出来,郁闷死了,请帮帮忙呀,我应该怎么办?不好意思,本人电脑白痴一个,请斑竹详细解说!谢谢!
最后编辑2006-08-25 19:55:46
分享到:
gototop
 

下载黄山IE,或超级兔子,IE修复

请下载hijackthis1.99.1汉化版扫描将日志粘贴上来

http://free5.ys168.com/?ufwihgu168
gototop
 

超级兔子在哪里下啊?
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 13:58:12, on 2006-8-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\瑞星\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\瑞星\Rav\Ravmond.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\瑞星\Rav\RavStub.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\瑞星\Rav\RavTask.exe
C:\Program Files\瑞星\Rav\Ravmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\瑞星\Rav\RsAgent.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\瑞星\Rfw\rfwmain.exe
c:\program files\瑞星\rfw\rfwsrv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\BT\HijackThis V1[1].99.1汉化版\HijackThis.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mouser.exe
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4683.dll
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O2 - BHO: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: isObject Class - {BE0B5843-553A-48C2-9A42-258A1D791AFC} - C:\PROGRA~1\pcast\hbcast.dll
O2 - BHO: OsbornTech Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\WINDOWS\system32\msobhp.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\KakaTool.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\瑞星\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Telnet] C:\WINDOWS\system32\Telnet.exe
O4 - HKLM\..\Run: [spoolsv] C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer
O4 - HKLM\..\Run: [svc] C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [RichMedia] C:\WINDOWS\system32\Rundll32.exe  "C:\PROGRA~1\pcast\hbcast.dll",WaitWindows
O4 - HKLM\..\RunOnce: [RavStub] "C:\Program Files\瑞星\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [boot-hf] c:\windows\BOOT-hf.exe
O4 - HKCU\..\Run: [msnnt] C:\WINDOWS\winampa.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\quartz32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\quartz32.dll
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AXSafeControls.cab
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl Object) - https://www.tenpay.com/download/qqedit.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\瑞星\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\瑞星\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\瑞星\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\瑞星\Rav\Ravmond.exe
gototop
 

还有一个Trojan.PSW.QQGame.v每次开机扫描都有这个病毒,但是每次提示成功删除,但是开机还是有!
gototop
 

还有就是请问我的IE,我把原来桌面的删除了,从C:\Program Files\Internet Explorer"创建了一个快捷方程到桌面,但是点右键就是普通的文件形式了,就是右键点开就只有:常规,快阶方程式,兼容性!没有以前的那些什么:安全,使用空白网页,清空历史记录了!
我想恢复到以前的那种IE应该怎么弄啊?
gototop
 

C:\WINDOWS\system32\rundll32.exe
CmdLine=C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\MMSASS~1\MMSSVER.DLL,Service
刚刚又试图连接这个东西!
gototop
 

死人了死人了,又弹出这个网站
http://www.bdvod.com/mov/y/5233.php?a=5&b=538937&c=1240&d=1477&e=30&g=&k=null&exs_1=&x=&d=1477&c=1240&g=&a=5&e=30&n2=
gototop
 

唉,郁闷了,从新做系统得了,唉!苯人用的简单方法~
gototop
 

运行Hijackthis,把下面的选中打上钩,修复
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mouser.exe
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4683.dll
O2 - BHO: isObject Class - {BE0B5843-553A-48C2-9A42-258A1D791AFC} - C:\PROGRA~1\pcast\hbcast.dll
O2 - BHO: OsbornTech Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\WINDOWS\system32\msobhp.dll
O4 - HKCU\..\Run: [boot-hf] c:\windows\BOOT-hf.exe
O4 - HKLM\..\Run: [svc] C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [Telnet] C:\WINDOWS\system32\Telnet.exe
O4 - HKLM\..\Run: [spoolsv] C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT