瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】隔几分钟就弹一些乱78糟的网站,什么网站都有.搞死人了.!

1   1  /  1  页   跳转

【求助】隔几分钟就弹一些乱78糟的网站,什么网站都有.搞死人了.!

【求助】隔几分钟就弹一些乱78糟的网站,什么网站都有.搞死人了.!

先头是中了Trojan.DL.HTML.Spreader.a的木马,
弄也弄不掉,杀也杀不完,只好把电脑全格了.
但是开机后发现隔段时间还是弹网站,什么网站都有 .
用正版瑞星也查不出来.!    T_T...55555.. 搞死了..




Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
D:\Rising\Rav\RavTask.exe
C:\WINDOWS\VM_STI.EXE
D:\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
D:\QQ\QQ.exe
D:\QQ\TIMPlatform.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ChinaNet\VnetClient.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Rising\Rav\Rav.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.390\HijackThis.exe

O2 - BHO: (no name) - {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} - C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll
O2 - BHO: (no name) - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\chinanet\VNETTR~1.DLL
O2 - BHO: (no name) - {96FC3938-C6CA-475D-8D3B-45F323A6B62B} - C:\Documents and Settings\All Users\Application Data\Microsoft\Office\NAVDATA\webnav_2016.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RavTask] "D:\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE ZSMC USB PC Camera
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [bgswitch] C:\WINDOWS\system32\bgswitch.exe
O4 - Startup: NTUSER.DAT
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Global Startup: ntuser.dat
O4 - Global Startup: ntuser.dat.LOG
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\QQ\SendMMS.htm
O9 - Extra button: QQ (HKLM)
O17 - HKLM\System\CCS\Services\Tcpip\..\{D63BC130-C60B-4175-9BE5-49F7F1C6E0E7}: NameServer = 202.103.44.150 202.103.24.68
最后编辑2007-01-07 18:20:53.170000000
分享到:
gototop
 

运行Hijackthis,把下面的选中打上钩,修复
O2 - BHO: (no name) - {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} - C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll
O2 - BHO: (no name) - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\chinanet\VNETTR~1.DLL
O2 - BHO: (no name) - {96FC3938-C6CA-475D-8D3B-45F323A6B62B} - C:\Documents and Settings\All Users\Application Data\Microsoft\Office\NAVDATA\webnav_2016.dll

重启按F8进入安全模式下
显示隐藏文件
删除:
c:\PROGRA~1\chinanet\VNETTR~1.DLL
C:\Documents and Settings\All Users\Application Data\Microsoft\Office\NAVDATA\webnav_2016.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT