瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 同志们帮我看看!我真要去自杀了!

1   1  /  1  页   跳转

同志们帮我看看!我真要去自杀了!

同志们帮我看看!我真要去自杀了!

开一次浏览器就跳一个垃圾网站.一到节假日就开始跳了。 节假日过了就稍微好点了.查也查不出什么.
都是这些网站 另外我重装瑞星以后防火墙却没安装上。不知道什么原因!

http://luoqi.tiancity.com/homepage/event/2years/
http://magazine.zcom.com/kuaiche/2c6s7d8y9u3w0g6t7m2i5t7d0a7w9g6hVtCeYrBhZlf5d1Q2E4d7g9q0Y7D5C6C7Z9M7U5R6Y8U6g8d7o9e8d5a2z5g4a8v9h3e0c6j4w001.html
http://www.2cdma.cn/bf/
http://www.2cdma.cn/js/s.htm?bf
http://www.2cdma.cn/v.htm?tuitan2cdma
http://x.99jk.com/chengren/aobo/index2.htm
http://www.163888.net/pp/
http://u.7town.com/Pub/mms/3/index.html?uid=90291&a=&b=&c=&d=&e=&f=
http://comic.btbbt.com/
还有很多.我一次打不完.就先写几个.希望高手能帮帮我


有性药网页,有游戏网页,视频网页.烦死人了.

卡卡也查不出什么

瑞星也查不出 下面是我的日志
Logfile of Kaka v2. 0. 3. 0 Scan Module v1. 0. 6. 1
Scan saved at 01:07:20, on 2007-06-01
Platform: Microsoft Windows XP Personal Service Pack 2 (Build 2600)
MSIE: Internet Explorer v6.00 SP2; (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\system32\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://seek.3721.com/srchasst.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://www.yahoo.com.cn
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://fo.qq.com/index.shtml
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,default_page_url=http://www.foundertech.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm
R3 - URLSearchHook: Tencent SearchHook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\Adplus\SSAddr.dll
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: Tencent Browser Helper - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\Program Files\TENCENT\Adplus\SSAddr.dll
O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\chinanet\VNETTR~1.DLL
O2 - BHO: QQBrowserHelperObject Class - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: lutv - {5ED9F836-7487-4AB6-9124-9DDC1796B82E} - C:\PROGRA~1\uase\vedi.dll
O2 - BHO:  - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\uase\.dll (file missing)
O2 - BHO: - {669751ED-D558-49AE-B01A-3B374CC7910E} - C:\WINDOWS\system32\ssup.dll
O2 - BHO: Thunder Browser Helper - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\迅雷\ComDlls\XunLeiBHO_007.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: CnsHook Class - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLO~1\CnsHook.dll
O3 - Toolbar: (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\RunOnce: [KKDelay] C:\Program Files\Rising\KakaToolBar\RunOnce.exe
O4 - Startup: desktop.ini =
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\QQ\QQ.exe
O4 - Global Startup: desktop.ini =
O4 - Global Startup: Windows Update SP5.lnk = C:\Program Files\Common Files\xp5update.exe
O8 - Extra context menu item: &使用超级旋风下载 - C:\Program Files\Tencent\QQDownload\geturl.htm
O8 - Extra context menu item: &使用超级旋风下载全部链接 - C:\Program Files\Tencent\QQDownload\getAllurl.htm
O8 - Extra context menu item: &使用迅雷下载 - D:\迅雷\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\迅雷\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用Web迅雷下载 - D:\迅雷\GetUrl.htm
O8 - Extra context menu item: 使用Web迅雷下载全部链接 - D:\迅雷\GetAllUrl.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra Button: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\迅雷\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\迅雷\Thunder.exe
O9 - Extra Button: Yahoo 3.5G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - Extra Button: 名品折扣 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/mall/pro.php?allyesPara=816 (file missing)
O9 - Extra Button: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - Extra Button: 雅虎WIDGET - {6354ABE6-05F1-49ed-B850-E423120EC338} - http://cn.widget.yahoo.com/index.htm?source=Cns (file missing)
O9 - Extra Button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra Button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra Button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg (file missing)
O9 - Extra Button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra Button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O11 - Options group: [!CNS] 中文上网
O11 - Options group: [TBH] 中文搜搜
O14 - IERESET.INF: START_PAGE_URL=http://www.foundertech.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{8AD0BC6A-A2D2-4D7C-93C1-F47C1A4790DE}: NameServer = 202.100.64.68 61.178.0.93
O17 - HKLM\System\CCS\Services\Tcpip\..\{C8C714A2-F62D-4E2A-B83C-AA87781A0A0C}: NameServer = 202.100.64.68
O18 - Filter : application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\system32\mscoree.dll
O18 - Filter : application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\system32\mscoree.dll
O18 - Filter : application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\system32\mscoree.dll
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O21 - SSODL: dmlq - {F3D08A11-8F41-4B40-95D4-8EF2C8B01EBF} - C:\PROGRA~1\clkp\dmlq.dll
O21 - SSODL: wbwk - {12311512-2C1D-44b2-A044-872AD2AD5A61} - C:\PROGRA~1\clkp\dmlq.dll
O23 - Service: Application Management (AppMgmt) - - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: CoolWare (CoolWare) - - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Windows fons RunThem (fons) - - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Gentad (Gentad) - - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Human Interface Device Access (HidServ) - - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: ijkzdr (ijkzdr) - - C:\WINDOWS\system32\rundll32.exe c:\progra~1\common~1\vjkzjr\vjkzjr.dll,service -s
O23 - Service: Navoct (Navoct) - - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Vsn oxwy Service (oxwy) - - C:\WINDOWS\system32\rundll32.exe c:\progra~1\uase\yhgl.dll,service
O23 - Service: P4P Service (P4P Service) - Sohu.com Inc. - C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\Rising\Rav\CCenter.exe"
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - "C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"
O23 - Service: User Privilege Service (usprserv) - Microsoft Corporation - C:\WINDOWS\system32\svchost.exe -k netsvcs
最后编辑2007-06-02 23:14:19
分享到:
gototop
 

...额  不懂.


我也正郁闷着呢``
gototop
 

我原来也是这样,后来我自己搞定了,再也没有发生这种问题,我的经验是:1重新装系统,紧接着装瑞星,包括卡卡,2:上网升级瑞星及卡卡,给系统打补丁。3:断开网络,点运行,输入services.msc,把remote registry 改成禁用,一定要该啊。点运行,输入regedit ,检查注册表,没问题就备份。运行卡卡,点插件免疫,把插件免疫了。打开internet选项,点隐私,设置弹出为高,再点内容,把自动完成选项取消,4,这样就可以用了,(active插件一般要拦截下载啊),不知对你有没有用,这是我的经验,呵呵呵
gototop
 

我原来也是这样,后来我自己搞定了,再也没有发生这种问题,我的经验是:1重新装系统,紧接着装瑞星,包括卡卡,2:上网升级瑞星及卡卡,给系统打补丁。3:断开网络,点运行,输入services.msc,把remote registry 改成禁用,一定要该啊。点运行,输入regedit ,检查注册表,没问题就备份。运行卡卡,点插件免疫,把插件免疫了。打开internet选项,点隐私,设置弹出为高,再点内容,把自动完成选项取消,4,这样就可以用了,(active插件一般要拦截下载啊),不知对你有没有用,这是我的经验,呵呵呵
gototop
 

用瑞星杀毒软件对C盘全盘扫描,找到病毒根源在哪,再用卡卡查流氓,文件删不掉时找一张带预装系统PE的光盘,用光盘启动,不用硬盘任何文件,任何文件都可删除.不要老想着重做系统,太累.
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT