瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 急求助啊,打开浏览器电脑右下老是弹出小广告窗口.

1   1  /  1  页   跳转

急求助啊,打开浏览器电脑右下老是弹出小广告窗口.

急求助啊,打开浏览器电脑右下老是弹出小广告窗口.

打开浏览器电脑右下老是弹出小广告窗口,就跟QQ广告窗口一样.并且有时候老自动弹出易趣的广告页面. 帮我看看怎么解决吧.. 我扫描过如下:

Logfile of HijackThis v1.99.1
Scan saved at 18:07:25, on 2006-10-31
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\安全软件\瑞星杀毒软件\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\安全软件\瑞星杀毒软件\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
D:\安全软件\瑞星杀毒软件\Rising\Rav\RavTask.exe
D:\安全软件\瑞星杀毒软件\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\clipsvr.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\wincup\wincup.exe
E:\宽带登陆\ishare_user.exe
C:\WINDOWS\system32\svchost.exe
c:\windows\powermsgr.exe
C:\WINDOWS\system32\NOTEPAD.EXE
D:\安全软件\注册表扫描.修复\HijackThis.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINDOWS\system32\wmpdrm.dll
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O2 - BHO: IEHlprObj Class - {EAACBF9E-4B91-45FF-93ED-B297093951EA} - C:\Program Files\Internet Explorer\PLUGINS\Flash_Player.dll
O2 - BHO: 超级兔子上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\超级兔~1.35\MagicSet\HAOKAN~1.DLL
O3 - Toolbar: IE标准栏 - {954F618B-0DEC-4D1A-9317-E0FC96F87865} - C:\WINDOWS\system32\amstreamxb1.dll
O3 - Toolbar: 超级兔子上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\超级兔~1.35\MagicSet\HAOKAN~1.DLL
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SKYNET Personal FireWall] D:\安全软件\天网防火墙\3.0\FireWall\PFW.exe
O4 - HKLM\..\Run: [RavTask] "D:\安全软件\瑞星杀毒软件\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [Cmaudio] ; RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [StormCodec_Helper] ; "D:\暴风影音\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [BigDogPath] ; C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [Super Rabbit Shutdown] ; D:\超级兔子魔法设置 v7.35\MagicSet\srshut.EXE /LOAD
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [YOKAssiant] ; Rundll32.exe C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll,YOKAssiant
O4 - HKLM\..\Run: [WebThunder] ; C:\Program Files\Thunder Network\WebThunder\WebThunder.exe
O4 - HKLM\..\Run: [spoolsv] ; C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] ; "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NetCounter] ; c:\Program Files\NetCounter\NetCount.exe
O4 - HKCU\..\Run: [svc] ; C:\WINDOWS\svchost.exe
O4 - HKCU\..\Run: [eMuleAutoStart] ; D:\eMule\eMule.exe -AutoStart
O4 - HKCU\..\Run: [Super Rabbit IEPro] ; D:\超级兔子魔法设置 v7.35\MagicSet\SRIECLI.EXE /LOAD
O4 - Startup: Reboot.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &使用迅雷下载 - D:\迅雷\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\迅雷\Program\GetAllUrl.htm
O8 - Extra context menu item: >>彩信发送<< - res://C:\PROGRA~1\MMSASS~1\mmsass~1.dll/mms.htm
O8 - Extra context menu item: >>粗陓楷冞<< - res://C:\PROGRA~1\MMSASS~1\mmsass~1.dll/mms.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - F:\游戏\qq\AddToNetDisk.htm
O8 - Extra context menu item: 使用Web迅雷下载 - C:\Program Files\Thunder Network\WebThunder\GetUrl.htm
O8 - Extra context menu item: 使用Web迅雷下载全部链接 - C:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\游戏\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\游戏\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\游戏\qq\SendMMS.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - D:\BT客户端v3.3\BitSpirit\bsurl.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - D:\迅雷\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - D:\迅雷\Thunder.exe
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - F:\游戏\浩方对战平台\Gameclient.exe
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - Extra 'Tools' menuitem: 彩E精灵设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - Extra button: 启动Web迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)
O9 - Extra 'Tools' menuitem: 启动Web迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\游戏\qq\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\游戏\qq\QQ.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdog1.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdog1.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdogr0.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdogr0.dll
O16 - DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} (MMCPlayer Class) - http://p3p.sogou.com/MMCShell.cab
O16 - DPF: {2931566C-B8A6-46C5-BF4D-E6AB9251E953} (Nexon Package Manager Control) - http://s.nx.com/activex/public_new/nxpm.cab
O16 - DPF: {32D72994-45B9-42B5-8980-FB561D1BE2D0} (nEdit Control) - https://ekey.163.com/nEdit.cab
O16 - DPF: {43E839C5-E10F-443A-BC1F-F09CFD2ABC77} (updatePanelX Control) - http://www.uusee.com/player/updateC.cab
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/1007/aliedit.cab
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AXSafeControls.cab
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: DelayRun - {5A6F2F95-3191-433B-8533-EB0B596A7BAC} - C:\WINDOWS\387d8700.dll (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\安全软件\瑞星杀毒软件\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\安全软件\瑞星杀毒软件\Rising\Rav\Ravmond.exe
O23 - Service: WinWrCup - MsWinCup - C:\WINDOWS\wincup\wincup.exe
最后编辑2006-10-31 20:53:17
分享到:
gototop
 

重新启动电脑,自动检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式(Safe Mode)进入Windows。)


控制面板--管理工具--服务--查找--WinWrCup--启动类型--设置为已禁止--服务类型--设置为停止

进入控制面版的添加删除程序中卸载,MMSASS~1彩信

关闭所有浏览窗口以及一些不必要的程序
运行Hijackthis,把下面的选中打上钩,修复
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINDOWS\system32\wmpdrm.dll
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O4 - HKLM\..\Run: [YOKAssiant] ; Rundll32.exe C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll,YOKAssiant
O4 - HKLM\..\Run: [spoolsv] ; C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer
O4 - HKCU\..\Run: [svc] ; C:\WINDOWS\svchost.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: >>彩信发送<< - res://C:\PROGRA~1\MMSASS~1\mmsass~1.dll/mms.htm
O8 - Extra context menu item: >>粗陓楷冞<< - res://C:\PROGRA~1\MMSASS~1\mmsass~1.dll/mms.htm
O21 - SSODL: DelayRun - {5A6F2F95-3191-433B-8533-EB0B596A7BAC} - C:\WINDOWS\387d8700.dll (file missing)
O23 - Service: WinWrCup - MsWinCup - C:\WINDOWS\wincup\wincup.exe



删除
C:\WINDOWS\wincup\文件夹
C:\WINDOWS\system32\spoolsv\文件夹
C:\WINDOWS\svchost.exe
C:\PROGRA~1\MMSASS~1
如果还是解决不了
下载超级兔子。
http://www.pctutu.com/srmsdown.asp
安装好后,打开“超级兔子清理王”“专业卸载,卸载所有提示的垃圾软件,
卸载是不要打开任何浏览窗口。卸载不了可以重启后再去卸载。

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT