瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 宽带不停下线,不能正常上网,也安装不了杀毒软件(附日志)

123   2  /  3  页   跳转

宽带不停下线,不能正常上网,也安装不了杀毒软件(附日志)

[C:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\rfwctrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [C:\Program Files\Rising\Rav\RsPPsys.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\Rav\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [C:\Program Files\Rising\Rav\HOOKSYS.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
    [C:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
    [C:\Program Files\Rising\Rav\libload.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
    [C:\Program Files\Rising\Rav\VirusLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [C:\Program Files\Rising\Rav\regmon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
    [C:\Program Files\Rising\Rav\HookWeb.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
    [C:\Program Files\Rising\Rav\MemMon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
    [C:\Program Files\Rising\Rav\expscan.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Rising\Rav\mPorts.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
    [C:\Program Files\Rising\Rav\HookCont.dll]  [Rising, 19, 0, 0, 0]
    [C:\Program Files\Rising\Rav\SpamEng.dll]  [N/A, 18, 0, 0, 6]
    [C:\Program Files\Rising\Rav\engine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
    [C:\Program Files\Rising\Rav\PostTrt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
    [C:\Program Files\Rising\Rav\UnExe.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\Program Files\Rising\Rav\ScanExec.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
    [C:\Program Files\Rising\Rav\ScanEx.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 23]
    [C:\Program Files\Rising\Rav\ExtFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 21]
    [C:\Program Files\Rising\Rav\NvFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
    [C:\Program Files\Rising\Rav\ScanMac.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
    [C:\Program Files\Rising\Rav\ScanSct.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
    [C:\Program Files\Rising\Rav\Unpacker.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
    [C:\Program Files\Rising\Rav\ScanPack.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
    [C:\Program Files\Rising\Rav\RsVM.dll]  [N/A, 19, 0, 0, 8]
    [C:\Program Files\Rising\Rav\Uscript.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
    [C:\Program Files\Rising\Rav\Uroutine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
[PID: 1196][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\Direcfor.dll]  [N/A, 1.0.0.1]
    [C:\WINDOWS\TEMP\temper\yesty.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\bomok.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\alxklt.dll]  [, 1, 0, 0, 0]
    [C:\WINDOWS\system32\ppgaxea.dll]  [, 1, 0, 0, 0]
    [C:\WINDOWS\system32\ccpgen.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\wpsont.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\sutxre.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\ex\Dhcom.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\ex\kerdpm.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\ex\Pac.dll]  [, 1, 0, 0, 1]
[PID: 1300][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1440][C:\WINDOWS\system32\Svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [c:\windows\system32\msservices\svchost.dll]  [N/A, N/A]
    [c:\windows\system32\msservices\MsService.dll]  [Microsoft Corporation All rights reserved, 1, 0, 0, 1]
    [c:\windows\system32\msservices\unreg1.dll]  [N/A, N/A]
    [c:\windows\system32\msservices\OldUnReg.dll]  [N/A, N/A]
[PID: 1472][C:\WINDOWS\system32\BaEncsx.exe]  [N/A, N/A]
[PID: 1504][C:\Program Files\Rising\Rav\RavStub.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 224][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1040][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1916][C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE]  [Nokia, 6, 81, 61, 4]
    [C:\WINDOWS\system32\ConnAPI.DLL]  [Nokia., 6, 81, 62, 0]
    [C:\PROGRA~1\Nokia\NOKIAP~1\PCSCM.dll]  [Nokia, 6, 81, 68, 0]
    [C:\Program Files\Common Files\PCSuite\ConfServer\ConfServer.dll]  [Nokia, 6, 81, 26, 0]
    [C:\PROGRA~1\Nokia\NOKIAP~1\Lang\LaunchApplication_chi-sc.NLR]  [Nokia, 6, 81, 60, 0]
[PID: 1160][C:\Program Files\Rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
[PID: 1008][C:\Program Files\Rising\Rav\Ravmon.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
    [C:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [C:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 2044][C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe]  [Time Information Services Ltd., 2.00 (506)]
    [C:\Program Files\Nokia\Nokia PC Suite 6\PCSCM.dll]  [Nokia, 6, 81, 68, 0]
    [C:\WINDOWS\system32\ConnAPI.DLL]  [Nokia., 6, 81, 62, 0]
    [C:\Program Files\Nokia\Nokia PC Suite 6\PCSL.dll]  [Nokia, 6, 81, 7, 0]
    [C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\Lang\PcSync2_chi-sc.nlr]  [Time Information Services Ltd., 9.00 (506)]
    [C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\Resource\PcSync2_Nokia.ngr]  [Time Information Services Ltd., 9.00 (506)]
gototop
 

[C:\Program Files\Common Files\Nokia\Adapters\NclSet.dll]  [Nokia, 6.81.9.0]
    [C:\Program Files\Common Files\Nokia\Adapters\Nclaeo.dsc]  [Nokia Mobile Phones Ltd., 4.00.008]
    [C:\Program Files\Common Files\Nokia\MPAPI\MPAPIps.dll]  [Nokia Corporation, 6.81.73.0]
    [C:\Program Files\Common Files\PCSuite\ConfServer\ConfServer.dll]  [Nokia, 6, 81, 26, 0]
    [C:\Program Files\Nokia\Nokia PC Suite 6\CommonSelectDevice.dll]  [Nokia, 6, 81, 73, 0]
[PID: 2108][C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe]  [Nokia Corporation, 6.81.161.1]
    [C:\Program Files\Common Files\Nokia\MPAPI\MPAPIps.dll]  [Nokia Corporation, 6.81.73.0]
[PID: 2112][C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe]  [Nokia., 6, 81, 60, 0]
    [C:\WINDOWS\system32\NclTools.dll]  [Nokia., 6, 81, 21, 1]
    [C:\Program Files\Common Files\PCSuite\Services\NclDS.dll]  [Nokia, 6, 81, 14, 0]
    [C:\Program Files\Common Files\PCSuite\Transports\NCLIrDAMM.dll]  [Nokia Corp., 6, 81, 27, 0]
    [C:\Program Files\Common Files\PCSuite\Transports\NCLRSMM.dll]  [Nokia, 6, 81, 34, 1]
    [C:\Program Files\Common Files\PCSuite\Transports\NCLUSBMM.dll]  [Nokia, 6, 81, 39, 1]
    [C:\Program Files\Common Files\PCSuite\Transports\NclMSBTMM.dll]  [Nokia., 6, 81, 40, 2]
[PID: 2184][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 2428][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1880][C:\Program Files\racer-henan-cnc\racer.exe]  [Putian Runway, 2, 0, 51, 92]
    [C:\Program Files\racer-henan-cnc\rwxre.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\nspr4.dll]  [Netscape Communications Corporation, 4.5 Beta]
    [C:\Program Files\racer-henan-cnc\xpcom.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\nss3.dll]  [Netscape Communications Corporation, 3.9.1]
    [C:\Program Files\racer-henan-cnc\softokn3.dll]  [Netscape Communications Corporation, 3.9.1]
    [C:\Program Files\racer-henan-cnc\gkgfx.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\js3250.dll]  [Netscape Communications Corporation, 4.0]
    [C:\Program Files\racer-henan-cnc\components\racer_base_comp.dll]  [Putian Runway, 2,0,47,87]
    [C:\Program Files\racer-henan-cnc\xpcom_compat.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\racer_base.dll]  [Putian Runway, 2,0,47,87]
    [C:\Program Files\racer-henan-cnc\components\pipnss.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\components\gklayout.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\components\jar50.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\components\xpcom_compat_c.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\components\racer_ad_comp.dll]  [Putian Runway, 2,0,47,87]
    [C:\Program Files\racer-henan-cnc\components\racer_access_dhcpplus.dll]  [Putian Runway, 2,0,47,87]
    [C:\Program Files\racer-henan-cnc\dhcpplus.dll]  [北京润汇科技有限公司, 0, 13, 21, 45]
    [C:\Program Files\racer-henan-cnc\components\racer_nss4_comp.dll]  [Putian Runway, 2,0,47,87]
    [C:\Program Files\racer-henan-cnc\nss4.dll]  [北京普天润汇科技有限公司, 1, 0, 0, 3]
    [C:\Program Files\racer-henan-cnc\wpcap.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\Program Files\racer-henan-cnc\pthreadVC.dll]  [N/A, N/A]
    [C:\Program Files\racer-henan-cnc\packet.dll]  [Politecnico di Torino, 3, 0, 0, 18]
[PID: 1004][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\macromed\flash\Flash.ocx]  [Macromedia, Inc., 7,0,19,0]
[PID: 4012][D:\TDDOWNLOAD\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1    www.ccnnic.com
127.0.0.1    www.ccnnlc.com
127.0.0.1    www.bodoto.com
127.0.0.1    bj.bodoto.com
127.0.0.1    nb.bodoto.com
127.0.0.1    hangzhou.bodoto.com
127.0.0.1    jh.bodoto.com
127.0.0.1    shangh.bodoto.com
127.0.0.1    my.bodoto.com
127.0.0.1    mail.bodoto.com
127.0.0.1    www.bodoto.net
127.0.0.1    www.bodoto.cn
127.0.0.1    www.bodoto.com.cn
127.0.0.1    www.bodoto.net.cn
127.0.0.1    www.bodoto.org
127.0.0.1    www.edmchina.com
127.0.0.1    www.edmchina.net
127.0.0.1    www.edmchina.cn
127.0.0.1    www.edmchina.com.cn
127.0.0.1    ad.edmchina.com
127.0.0.1    agent.edmchina.com
127.0.0.1    sales.edmchina.com
127.0.0.1    mail.edmchina.com
127.0.0.1    edmchina.com
127.0.0.1    edmchina.net
127.0.0.1    edmchina.cn
127.0.0.1    edmchina.com.cn
127.0.0.1    www.pk265.com
127.0.0.1    pk265.com
127.0.0.1    www.qqbao.com
127.0.0.1    www.qqbao.net
127.0.0.1    www.qqbao.cn
127.0.0.1    www.qqbao.com.cn
127.0.0.1    qqbao.com
127.0.0.1    qqbao.cn
127.0.0.1    qqbao.com.cn

==================================
gototop
 

C:\WINDOWS\system32\BaEncsx.exe
找到这个文件用winrar压缩发到我的邮箱mizukiuka@163.com
gototop
 

是河南网通宽带吧~ 是一种漏洞攻击 ~  这个漏洞只针对ADSL攻击后 会频繁掉线 ~  瑞星官网上好象有吧 ~好象是什么MS06-040之类的你去看下~
gototop
 

现在主要是我不能进入安全模式,所以可能杀不干净这些乱七八糟的东西
gototop
 

对了,忘了说,开机的时候总是弹出对话框说:加载进程出错,C:\WINDOW\system32\npoqjz07.dll这个文件
gototop
 

为什么没有人帮我啊,我好痛苦的,上来问人也要一会儿一下,帮忙啊,救命啊...............
gototop
 

各位哥哥,帮忙拉,很痛苦啊
gototop
 

引用:
【小小妖儿的贴子】各位哥哥,帮忙拉,很痛苦啊

………………

流氓软件多,下载36安全卫士来清除
gototop
 

引用:
【小小妖儿的贴子】对了,忘了说,开机的时候总是弹出对话框说:加载进程出错,C:\WINDOW\system32\npoqjz07.dll这个文件
………………

运行注册表搜索npoqjz07.dll删除
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT