瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 浏览器自动打开www.kan4.com/index2.htm?k1

1234   2  /  4  页   跳转

浏览器自动打开www.kan4.com/index2.htm?k1

[PID: 236][C:\WINDOWS\SOUNDMAN.EXE]  <Realtek Semiconductor Corp.><5, 1, 0, 48>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\WINDOWS\system32\tdll.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
[PID: 244][C:\Program Files\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\WINDOWS\system32\tdll.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
[PID: 336][C:\Program Files\Logitech\MouseWare\system\em_exec.exe]  <Logitech Inc.><9.79.027>
    [C:\Program Files\Logitech\MouseWare\system\EVENTEX.dll]  <Logitech Inc.><9.79.027>
    [C:\WINDOWS\system32\COMNCTR.dll]  <Logitech Inc.><9.79.027>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\Program Files\Logitech\MouseWare\system\ccresrce.dll]  <Logitech Inc.><9.79.027>
    [C:\Program Files\Logitech\MouseWare\system\GlbResLt.dll]  <Logitech Inc.><9.79.027>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\Logitech\MouseWare\System\devices.dll]  <Logitech Inc.><9.79.027>
    [C:\Program Files\Logitech\MouseWare\system\ccstmglb.dll]  <Logitech Inc.><9.79.027>
    [C:\Program Files\Logitech\MouseWare\system\ccustom.dll]  <Logitech Inc.><9.79.027>
    [C:\Program Files\Logitech\MouseWare\system\ccmsghk.dll]  <Logitech Inc.><9.79.027>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.027>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
    [C:\WINDOWS\system32\tdll.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
[PID: 364][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3536>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\WINDOWS\system32\tdll.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
gototop
 

[PID: 380][C:\WINDOWS\command\rundll32.exe]  <N/A><N/A>
    [C:\WINDOWS\system32\tdll.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
[PID: 436][C:\WINDOWS\Intel\rundll32.exe]  <N/A><N/A>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\tdll.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
[PID: 488][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.027>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\tdll.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
[PID: 584][C:\Program Files\Antiy Labs\Alive\AliveCenter_.exe]  <安天信息技术有限公司><2, 1, 1, 0>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.027>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\tdll.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
[PID: 764][C:\Program Files\Antiy Labs\AGuard\AGuard_.exe]  <安天信息技术有限公司><2, 3, 5, 1>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.027>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\Program Files\Common Files\Antiy Labs\Base\AVLeachSDK.dll]  <Antiy Labs><2, 0, 3, 0>
    [C:\Program Files\Common Files\Antiy Labs\Base\Module\AExploit.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Common Files\Antiy Labs\Base\Module\APack.dll]  <Antiy Labs><1, 0, 1, 1>
    [C:\Program Files\Common Files\Antiy Labs\Base\Module\ATrojan.dll]  <Antiy Labs><1, 0, 12, 0>
    [C:\Program Files\Common Files\Antiy Labs\Base\Module\KillTrojan.dll]  <Antiy Labs><1, 0, 0, 3>
    [C:\Program Files\Common Files\Antiy Labs\Base\Module\MiscFix.dll]  <Antiy Labs><1, 0, 1, 0>
    [C:\Program Files\Common Files\Antiy Labs\Base\Module\ScanReg.dll]  <><1, 0, 0, 3>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\tdll.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
gototop
 

[PID: 1232][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 2648][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2324][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.027>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\WINDOWS\system32\KakaTool.dll]  <Beijing Rising Technology Co., Ltd.><2, 0, 0, 9>
    [c:\program files\google\googletoolbar1.dll]  <Google Inc.><3, 0, 131, 0>
    [f:\QQ\QQIEHelper.dll]  <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
    [d:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll]  <Thunder Networking Technologies,LTD><5, 0, 0, 2>
    [C:\PROGRA~1\COMMON~1\Wnwb\wnwbio.dll]  <深圳世强软件开发部><2005, 8, 30, 1>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\tdll.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
    [C:\WINDOWS\system32\mscore.dll]  <N/A><N/A>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
    [C:\WINDOWS\system32\JPWB.IME]  <常诚研制><4.00.950>
[PID: 3876][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1972][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\KakaTool.dll]  <Beijing Rising Technology Co., Ltd.><2, 0, 0, 9>
    [c:\program files\google\googletoolbar1.dll]  <Google Inc.><3, 0, 131, 0>
    [f:\QQ\QQIEHelper.dll]  <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
    [d:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll]  <Thunder Networking Technologies,LTD><5, 0, 0, 2>
    [C:\PROGRA~1\COMMON~1\Wnwb\wnwbio.dll]  <深圳世强软件开发部><2005, 8, 30, 1>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
[PID: 1064][D:\Program Files\Thunder\Program\Thunder5.exe]  <Thunder Networking Technologies,LTD><5.4.0.226>
    [D:\Program Files\Thunder\Program\UpdateDownload.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 8>
    [D:\Program Files\Thunder\Program\download_interface.dll]  <Thunder Networking Technologies,LTD><2, 0, 0, 1>
    [D:\Program Files\Thunder\Program\stlport_vc646.dll]  <STLport Consulting, Inc.><4.6.2003.1031>
    [D:\Program Files\Thunder\Program\log4cplus.dll]  <><1, 0, 2, 1>
    [D:\Program Files\Thunder\Program\asyn_dns.dll]  <N/A><N/A>
    [D:\Program Files\Thunder\Program\msgmanage.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 15>
    [D:\Program Files\Thunder\Program\historyinfo_manage.dll]  <Thunder Networking Technologies,LTD><5, 2, 0, 148>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.027>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [D:\Program Files\Thunder\Program\RegisterDll.dll]  <Thunder Networking Technologies,LTD><2, 1, 0, 18>
    [D:\Program Files\Thunder\Program\FloatBar.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 2>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\tdll.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
    [D:\Program Files\Thunder\Components\InMedia\iEmbedShell.dll]  < ><1, 0, 0, 11>
    [d:\Program Files\Thunder\Components\InMedia\iEmbed04.dll]  < ><2, 3, 0, 37>
    [D:\Program Files\Thunder\Components\P4PClient\P4PClient.dll]  <Thunder Networking Technologies,LTD><1, 0, 4, 10>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\WINDOWS\system32\mscore.dll]  <N/A><N/A>
    [D:\Program Files\Thunder\Program\iTargetAd.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 59>
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
gototop
 

[PID: 2620][C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX00.453\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.027>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\tdll.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\Internet Explorer\IEXPLORE.Dat]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\IEXPLORE.Sys]  <N/A><N/A>
    [C:\WINDOWS\system32\mscore.dll]  <N/A><N/A>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 

日志就全在这里了,这是我第一次发日志,发的不好,请多原凉
gototop
 

你的问题不一般,试试吧
请到www.27814939.ys168.com,点“我的软件”下载KillBox.exe
重新启动电脑, 开机检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式进入Windows
双击打开KillBox.exe,分别删除
C:\WINDOWS\command\rundll32.exe
C:\WINDOWS\Intel\rundll32.exe
C:\Program Files\Internet Explorer\PLUGINS\system.sys
C:\Program Files\Internet Explorer\IEXPLORE.Sys
C:\Program Files\Internet Explorer\IEXPLORE.D
C:\WINDOWS\system32\DLMain.dll
C:\WINDOWS\system32\tdll.dll
C:\WINDOWS\system32\ztdll.dll
C:\WINDOWS\system32\mscore.dll
(删除时勾选“删除前先结束Explorer.EXE进程”不行再试着勾选"删除DLL文件前反注册此文件"
给菜鸟的东东—KillBox的使用技巧
http://forum.ikaka.com/topic.asp?board=28&artid=8160799

打开System Repair Engineer(也就是你的扫描日志软件SREng.exe),使用“启动项目,注册表”来删除以下选项
Start.exe
C:\WINDOWS\command\rundll32.exe
Start.exe
C:\WINDOWS\Intel\rundll32.exe
C:\Program Files\Internet Explorer\PLUGINS\system.sys
C:\Program Files\Internet Explorer\IEXPLORE.Sys
C:\Program Files\Internet Explorer\IEXPLORE.D
C:\WINDOWS\system32\DLMain.dll



打开System Repair Engineer(也就是你的扫描日志软件SREng.exe),使用“启动项目,注册表”选中要修复的项
Explorer.exe ntio.exe
,点“编辑”在“值”里删除ntio.exe

手动搜索
Start.exe
ntio.exe如果能找到在删除前发到twtxk@126.com
完后重启
再扫个日志粘上来。
gototop
 

不好意思,是不是以上的工作都要做的。
gototop
 

不好意思,是不是以上的程序都要做的
gototop
 

是的,一定要做,完后,不管结果如果,都应重启,再扫个日志粘上来。
gototop
 

我去做了,不管怎么,先谢谢你了!!
gototop
 
1234   2  /  4  页   跳转
页面顶部
Powered by Discuz!NT