瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 这个网站总要弹出来.......怎么办~

1   1  /  1  页   跳转

这个网站总要弹出来.......怎么办~

这个网站总要弹出来.......怎么办~

用了360 卡卡 兔子
最后重装系统还是不行~~~有人能帮帮忙没??
http://www.86dy.net/dy.htm
最后编辑2007-02-28 14:25:36
分享到:
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 11:59:00, on 2007-2-28
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
D:\qq\QQ.exe
C:\Documents and Settings\Administrator\桌面\新建文件夹\xmjjl.exe
E:\新建文件夹 (6)\魔界Online\gc.exe.bak
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\explorer.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.453\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v14.dll
O2 - BHO: Flash 9b - {492B8F66-B8CF-4F7A-B0EE-B7383B92F5BA} - C:\WINDOWS\system\IceHBO.dll
O4 - HKLM\..\RunOnce: [KKDelay] C:\Program Files\Rising\AntiSpyware\RunOnce.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: JUJU猫 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.jujumao.com (file missing)
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{7A0A7B03-FE5D-4530-B281-4E3691617332}: NameServer = 61.236.127.254 211.98.2.4
O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\system32\wdfmgr.exe (file missing)

这些就是扫描出来的,帮我看下哪个地方有错~
gototop
 

C:\Documents and Settings\Administrator\桌面\新建文件夹\xmjjl.exe 这个是新魔界的外挂~~
另一个就不知道了~~~用了N多软件都不行 这个垃圾网站总是弹出来~
O17 - HKLM\System\CCS\Services\Tcpip\..\{7A0A7B03-FE5D-4530-B281-4E3691617332}: NameServer = 61.236.127.254 211.98.2.4 这个也挺可疑
这个怎么删除了~
gototop
 

又扫描了一次 这次少点了~
Logfile of HijackThis v1.99.1
Scan saved at 12:48:21, on 2007-2-28
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
D:\qq\QQ.exe
C:\Documents and Settings\Administrator\桌面\新建文件夹\xmjjl.exe
E:\新建文件夹 (6)\魔界Online\gc.exe.bak
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Thunder Network\Thunder\Thunder.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.906\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v14.dll
O2 - BHO: Flash Object Class - {109B111C-371B-4267-AF19-BDEB6EDA0970} - C:\WINDOWS\Flash8.dll
O2 - BHO: Flash 9b - {492B8F66-B8CF-4F7A-B0EE-B7383B92F5BA} - C:\WINDOWS\system\IceHBO.dll
O2 - BHO: AdSwpr - {FCADDC14-BD46-408A-9842-CDBE1C6D37EB} - d:\PROGRA~1\IE修复~1\IERBar.dll
O3 - Toolbar: &IE修复专家 - {123249EB-F891-44C4-946F-450064F9080E} - d:\PROGRA~1\IE修复~1\IERBar.dll
O4 - HKLM\..\RunOnce: [KKDelay] C:\Program Files\Rising\AntiSpyware\RunOnce.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O17 - HKLM\System\CCS\Services\Tcpip\..\{7A0A7B03-FE5D-4530-B281-4E3691617332}: NameServer = 61.236.127.254 211.98.2.4
O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\system32\wdfmgr.exe (file missing)


C:\WINDOWS\explorer.exe
这个是不是正确的?好象EXPLORER不是这个目录~

gototop
 

谢谢emtry 和 oarbznd  问题好象解决了~~~不在弹出这个网站了~
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT