瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 老是弹出网页,卡卡也拦不住!!

1   1  /  1  页   跳转

老是弹出网页,卡卡也拦不住!!

老是弹出网页,卡卡也拦不住!!

现在我一开网页就弹出:古狗,百度,还有就是263的ET广告网页,卡卡也拦不住,我它们是网址都添到卡卡的拦截菜单也没用!怎么办啊?
最后编辑2006-03-06 10:44:17
分享到:
gototop
 

【回复“3325320”的帖子】
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
下载HIJACKTHIS
导出日志
gototop
 

Logfile of Kaka v2. 0. 0. 7 Scan Module v2. 0. 0. 1
Scan saved at 10:19:25, on 2006-03-06
Platform: Advanced Server  (Build 3790)
MSIE: Internet Explorer v6.00  (6.00.3790.0 (srv03_rtm.030324-2048))


Running processes:
[smss.exe]
CommandLine =

[csrss.exe]
CommandLine = C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

[winlogon.exe]
CommandLine = winlogon.exe

[services.exe]
CommandLine = C:\WINDOWS\system32\services.exe

[lsass.exe]
CommandLine = C:\WINDOWS\system32\lsass.exe

[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss

[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k termsvcs

[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k NetworkService

[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k LocalService

[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs

[ccSetMgr.exe]
CommandLine = "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"

[ccEvtMgr.exe]
CommandLine = "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"

[spoolsv.exe]
CommandLine = C:\WINDOWS\system32\spoolsv.exe

[msdtc.exe]
CommandLine = C:\WINDOWS\system32\msdtc.exe

[alg.exe]
CommandLine = C:\WINDOWS\System32\alg.exe

[DefWatch.exe]
CommandLine = "C:\Program Files\Symantec AntiVirus\DefWatch.exe"

[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k WinErr

[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k regsvc

[rzxsevce.exe]
CommandLine = d:\Net110\rzxsevce.exe

[Rtvscan.exe]
CommandLine = "C:\Program Files\Symantec AntiVirus\Rtvscan.exe"

[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k tapisrv

[dfssvc.exe]
CommandLine = C:\WINDOWS\system32\Dfssvc.exe

[wmiprvse.exe]
CommandLine = C:\WINDOWS\system32\wbem\wmiprvse.exe -Embedding

[explorer.exe]
CommandLine = C:\WINDOWS\Explorer.EXE

[CServer.exe]
CommandLine = "C:\PROGRA~1\LANSER~1\CServer.exe"

[RServer.exe]
CommandLine = "C:\Program Files\LANServer\RServer.exe"

[SOUNDMAN.EXE]
CommandLine = "C:\WINDOWS\SOUNDMAN.EXE"

[Server.exe]
CommandLine = "D:\Octopus\Server.exe"

[BkDb.exe]
CommandLine = "D:\Octopus\Bkdb.exe" -h

[ccApp.exe]
CommandLine = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

[VPTray.exe]
CommandLine = "C:\PROGRA~1\SYMANT~1\VPTray.exe"

[SysMon.exe]
CommandLine = "D:\Net110\SysMon.exe"

[svchost.exe]
CommandLine = "C:\WINDOWS\svchost.exe"

[internat.exe]
CommandLine = "C:\WINDOWS\system32\internat.exe"

[LSParser.exe]
CommandLine = D:\Net110\LSParser.exe

[LSUI.exe]
CommandLine = D:\Net110\Lsui.exe

[rzxsurename.exe]
CommandLine = D:\Octopus\rzxsurename.exe

[sde.exe]
CommandLine = "C:\Program Files\Common Files\smartde\sde.exe" -zkxf

[UPdate.exe]
CommandLine = "E:\下载区\UPdate.exe"

[IEXPLORE.EXE]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe"

[KkScan.exe]
CommandLine = "C:\Program Files\Rising\KakaToolBar\KkScan.exe"

[IEXPLORE.EXE]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe" www.baidu.com

R3 - Default URLSearchHook is missing
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Resume copy] copyfstq.exe /startup
O4 - HKLM\..\Run: [LANServer] C:\PROGRA~1\LANSER~1\CServer.exe
O4 - HKLM\..\Run: [RServer] C:\Program Files\LANServer\RServer.exe
O4 - HKLM\..\Run: [DLink Control Panel Silent] rundll32 dlnetcp.cpl,SilentCall
O4 - HKLM\..\Run: [DLink System Tray] C:\Program Files\D-Link\DGE-530T\dlnetst.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ssServ] D:\Octopus\Server.exe
O4 - HKLM\..\Run: [BackupDB] D:\Octopus\Bkdb.exe -h
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SYSMON] d:\Net110\SysMon.exe
O4 - HKLM\..\Run: [System Manager] C:\WINDOWS\svchost.exe
O4 - Startup: desktop.ini =
O4 - Startup: INTERNAT.lnk = C:\WINDOWS\system32\internat.exe
O4 - Global Startup: desktop.ini =
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\system32\shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab Class) - http://www.systemrequirementslab.com/sysreqlab.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4E7A1690-64C1-4C81-836D-A287B43D8228}: NameServer = 60.191.134.196,60.191.134.206
O17 - HKLM\System\CCS\Services\Tcpip\..\{E2A9EADD-049D-4C1E-80A3-210CDEC06016}: NameServer = 60.191.134.196,60.191.134.206
O18 - Filter : application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\system32\mscoree.dll
O18 - Filter : application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\system32\mscoree.dll
O18 - Filter : application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\system32\mscoree.dll
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O20 - Winlogon Notify: NavLogon
O23 - Service: Ati HotKey Poller (Ati HotKey Poller) -  - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: ATI Smart (ATI Smart) -  - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - "C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - "C:\Program Files\Symantec AntiVirus\DefWatch.exe"
O23 - Service: Human Interface Device Access (HidServ) -  - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) -  - "C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"
O23 - Service: RzxSevce (RzxSevce) - 深圳任子行网络技术有限公司 - d:\Net110\rzxsevce.exe
O23 - Service: SAVRoam (SavRoam) - symantec - "C:\Program Files\Symantec AntiVirus\SavRoam.exe"
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - "C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus (Symantec AntiVirus) - Symantec Corporation - "C:\Program Files\Symantec AntiVirus\Rtvscan.exe"
O23 - Service: SDAgent Service (SDAgentService) - 北京兴华基业软件技术有限公司 - C:\Program Files\Common Files\smartde\sde.exe
gototop
 

O23 - Service: SDAgent Service (SDAgentService) - 北京兴华基业软件技术有限公司 - C:\Program Files\Common Files\smartde\sde.exe
我怀疑是这个,但是删不掉!!
gototop
 

【回复“3325320”的帖子】
结束如下两个进程:
[svchost.exe]
CommandLine = "C:\WINDOWS\svchost.exe"

[UPdate.exe]
CommandLine = "E:\下载区\UPdate.exe"

用HIJACKTHIS修复
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [System Manager] C:\WINDOWS\svchost.exe
O23 - Service: SDAgent Service (SDAgentService) - 北京兴华基业软件技术有限公司 - C:\Program Files\Common Files\smartde\sde.exe

删除
C:\WINDOWS\svchost.exe
E:\下载区\UPdate.exe
C:\Program Files\Common Files\smartde\

另外最好进入注册表
清理上述文件在注册表中的相关信息
gototop
 

C:\WINDOWS\svchost.exe
C:\Program Files\Common Files\smartde\ 
这两个无法删除~
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT