瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 有个叫爆米花视频的网站每隔5分钟就自动出来!

1   1  /  1  页   跳转

有个叫爆米花视频的网站每隔5分钟就自动出来!

有个叫爆米花视频的网站每隔5分钟就自动出来!

有个叫爆米花视频的网站每隔5分钟就自动出来!我安装了卡卡也没有用,下面是我的日志扫描:
Logfile of Kaka v2. 0. 2. 6 Scan Module v1. 0. 4. 5
Scan saved at 00:42:34, on 2007-02-16
Platform: Microsoft Windows XP Personal Service Pack 2 (Build 2600)
MSIE: Internet Explorer v6.00 SP2; (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,default_page_url=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\system32\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.qq.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,default_page_url=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.qq.com/
F1 - win.ini: Run=C:\PROGRA~1\COMMON~1\ATi\aatievv.exe
O1 - Hosts: 127.0.0.1      localhost
O3 - Toolbar: 闪联任意通 - {0C9B3AB9-DEDF-11D8-A2D4-0050FC464B19} - C:\Program Files\Lenovo\IGRS EasyShare\IgrsAnywhere.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [EzButton] C:\Program Files\EzButton\EzButton.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\EnergyCut\utilty.exe
O4 - HKLM\..\Run: [EnergyCut] C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Lenovo\ShuttleCenter\PCMService.exe"
O4 - HKLM\..\Run: [IgrsPortal] "C:\Program Files\Lenovo\IGRS EasyShare\IgrsPortal.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [DAEMON Tools-2052] "D:\Program Files\D-Tools\daemon.exe"  -lang 2052
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [runeip] D:\Program Files\Rising\AntiSpyware\runiep.exe
O4 - HKLM\..\RunOnce: [KKDelay] D:\Program Files\Rising\AntiSpyware\RunOnce.exe
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getAllurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - D:\Program Files\BitSpirit\bsurl.htm
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\cdnns.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{350B9C14-C65E-433F-A4F9-600C27D75F1E}: NameServer = 202.97.224.69 202.97.224.68
O18 - Filter : application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\system32\mscoree.dll
O18 - Filter : application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\system32\mscoree.dll
O18 - Filter : application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\system32\mscoree.dll
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O23 - Service: Application Management (AppMgmt) -  - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Autodesk Licensing Service (Autodesk Licensing Service) - Autodesk - "C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - "C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) -  - "C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLCapSvc.exe"
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) -  - "C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLSched.exe"
O23 - Service: CyberLink Media Library Service (CyberLink Media Library Service) - Cyberlink - "C:\Program Files\Lenovo\ShuttleCenter\Kernel\CLML_NTService\CLMLServer.exe"
O23 - Service: General Updater/AutoUpdater Service (GUA) - lenovo - "C:\Program Files\lenovo\GUA\GUA.exe"
O23 - Service: IGRS (IGRS) - 联想集团有限公司 - C:\Program Files\Lenovo\IGRS\IGRS.exe
O23 - Service: IGRSFILE (IGRSFILE) - Lenovo Group Limited - C:\Program Files\lenovo\IGRS Profiles\File Profile\IgrsFile.exe
O23 - Service: IgrsFileShare (IgrsFileShare) - 联想集团有限公司 - "C:\Program Files\Lenovo\IGRS EasyShare\FileShare.exe"
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - "C:\Program Files\Norton AntiVirus\navapsvc.exe"
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) -  - "C:\Program Files\CyberLink\Shared Files\RichVideo.exe"
O23 - Service: SAVScan (SAVScan) - Symantec Corporation - "C:\Program Files\Norton AntiVirus\SAVScan.exe"
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - "C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"
O23 - Service: User Privilege Service (usprserv) - Microsoft Corporation - C:\WINDOWS\system32\svchost.exe -k netsvcs
最后编辑2007-02-19 23:32:31.250000000
分享到:
gototop
 

我的也中了这个东西烦死了  有高手来999999
gototop
 

O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\cdnns.dll
这个是什么?
gototop
 

我也中那个了system32~~
~删不掉的
卡卡也不行
gototop
 

偶中的也是一样的毒啊!!!5555
gototop
 

救命啊!就是这个东西,垃圾32,(C:\WINDOWS\system32\cdnns.dll
)要怎么杀啊???
gototop
 

cdnns.dll进程名称:cdnns描述:cdnns.dll是cnnic中文上网的文件,如果你不需要该软件,可以使用其自身的卸载程序或其它软件进行删除。进程名称cdnns.dll

<SCRIPT language=javascript src="http://js3.all4ad.net/html2js/display.aspx?unionid=haokan123&htmlid=html/flash/300x300.htm&val1=http://adfarm.mediaplex.com/ad/ck/4080-22903-9499-0?aid=haokan123;mtjsflash300x300;&val2=haokan123"><script>


出品者cnnic.cn属于cnnic.cn系统进程 后台进程 使用网络 硬件相关 常见错误 内存使用 安全等级 广告软件 间谍软件 病毒 木马 描述进程文件:cdnns.dll进程名称:cdnns描述:cdnns.dll是cnnic中文上网的文件,如果你不需要该软件,可以使用其自身的卸载程序或其它软件进行删除。
gototop
 

cdnns.dll进程名称:cdnns描述:cdnns.dll是cnnic中文上网的文件,如果你不需要该软件,可以使用其自身的卸载程序或其它软件进行删除。进程名称cdnns.dll

<SCRIPT language=javascript src="http://js3.all4ad.net/html2js/display.aspx?unionid=haokan123&htmlid=html/flash/300x300.htm&val1=http://adfarm.mediaplex.com/ad/ck/4080-22903-9499-0?aid=haokan123;mtjsflash300x300;&val2=haokan123"><script>


出品者cnnic.cn属于cnnic.cn系统进程 后台进程 使用网络 硬件相关 常见错误 内存使用 安全等级 广告软件 间谍软件 病毒 木马 描述进程文件:cdnns.dll进程名称:cdnns描述:cdnns.dll是cnnic中文上网的文件,如果你不需要该软件,可以使用其自身的卸载程序或其它软件进行删除。
gototop
 

我也一样 同病相连啊  你弄好了么 告诉我怎么弄的谢谢了
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT