瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 打开IE后过一会就跳出http://fetion.im这个网页 请各位帮帮我

12   2  /  2  页   跳转

打开IE后过一会就跳出http://fetion.im这个网页 请各位帮帮我

[PID: 996][D:\COMMON~1\naPrdMgr.exe]  [Network Associates, Inc., 3.5.0.412]
    [D:\COMMON~1\nailog.dll]  [Network Associates, Inc., 3.5.0.474]
    [D:\COMMON~1\naCmnLib.dll]  [Network Associates, Inc., 3.5.0.474]
    [D:\COMMON~1\naXML.dll]  [Network Associates, Inc., 3.5.0.474]
    [D:\COMMON~1\0804\AgentRes.dll]  [Network Associates, Inc., 3.5.0.412]
    [D:\McAfee-v8.0_chs\VsPlugin.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\WINDOWS\system32\EntApi.dll]  [Network Associates, Inc, 8.0.0.277]
[PID: 1120][D:\McAfee-v8.0_chs\VsTskMgr.exe]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\SHUTIL.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\naiwmain.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\naicondl.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\RES04\VsTskMgr.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\MIDUtil.Dll]  [McAfee, Inc., 8.0.0.152]
    [D:\McAfee-v8.0_chs\BBCpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\coptcpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\EmCfgCpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\RES04\SEmalRes.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\RES04\Product.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\nvpcpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\ftcfg.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\mytilus.dll]  [Network Associates, Inc., 8.0.0.251]
    [D:\McAfee-v8.0_chs\Res04\McShield.dll]  [Network Associates, Inc., 8.0.0.251]
    [D:\McAfee-v8.0_chs\OASCpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\vsodscpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\ftl.dll]  [Network Associates, Inc., 8.0.0.135]
    [D:\McAfee-v8.0_chs\vsupdcpl.dll]  [Network Associates, Inc., 8.0.0.912]
[PID: 1196][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  [Microsoft Corporation, 7.00.9466]
[PID: 1288][C:\WINDOWS\system32\Svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
    [c:\windows\system32\drivers\service.dll]  [N/A, N/A]
    [c:\windows\system32\drivers\ms_restore.dll]  [Microsoft Corporation All rights reserved, 1, 0, 0, 1]
    [c:\windows\system32\drivers\Old_service.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\EntApi.dll]  [Network Associates, Inc, 8.0.0.277]
[PID: 1360][c:\windows\system\micro\iexplorer.exe]  [, 1.0.0.0]
    [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
    [D:\McAfee-v8.0_chs\scriptproxy.dll]  [Network Associates, Inc., 8.0.0.955]
    [D:\McAfee-v8.0_chs\mytilus.dll]  [Network Associates, Inc., 8.0.0.251]
    [D:\McAfee-v8.0_chs\Res04\McShield.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Common Files\Network Associates\Engine\mcscan32.dll]  [McAfee, Inc., 5.1.00]
[PID: 1508][c:\windows\system\Microsoft\kav.exe]  [, 1.0.0.0]
    [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
    [D:\McAfee-v8.0_chs\scriptproxy.dll]  [Network Associates, Inc., 8.0.0.955]
    [D:\McAfee-v8.0_chs\mytilus.dll]  [Network Associates, Inc., 8.0.0.251]
    [D:\McAfee-v8.0_chs\Res04\McShield.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Common Files\Network Associates\Engine\mcscan32.dll]  [McAfee, Inc., 5.1.00]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
[PID: 1572][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe]  [Analog Devices, Inc., 3, 2, 6, 0]
[PID: 1592][C:\WINDOWS\system32\rundll32.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\vision\VISVER.DLL]  [, 1, 2, 0, 7]
    [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
[PID: 2180][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
[PID: 3108][C:\WINDOWS\system32\cidaemon.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
[PID: 3204][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\EntApi.dll]  [Network Associates, Inc, 8.0.0.277]
    [D:\讯雷WEB\WebThunderBHO_015.dll]  [Thunder Networking Technologies,LTD, 6, 0, 0, 5]
    [C:\WINDOWS\system32\xunleibho_v4.dll]  [, 4, 3, 2, 29]
    [D:\文件夹\QQIEHelper.dll]  [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
    [C:\PROGRA~1\vision\vision.dll]  [, 1, 2, 0, 7]
    [C:\PROGRA~1\vision\alvsn.dll]  [N/A, 1, 0, 0, 4]
    [D:\文件夹\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
    [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
    [D:\McAfee-v8.0_chs\scriptproxy.dll]  [Network Associates, Inc., 8.0.0.955]
    [D:\McAfee-v8.0_chs\mytilus.dll]  [Network Associates, Inc., 8.0.0.251]
    [D:\McAfee-v8.0_chs\Res04\McShield.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Common Files\Network Associates\Engine\mcscan32.dll]  [McAfee, Inc., 5.1.00]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
    [D:\讯雷WEB\MediaAddin10.dll]  [Thunder Networking Technologies,LTD, 3, 1, 0, 62]
[PID: 2996][D:\McAfee-v8.0_chs\scan32.exe]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\vsodscpl.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\naiwmain.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\ftcfg.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\mytilus.dll]  [Network Associates, Inc., 8.0.0.251]
    [D:\McAfee-v8.0_chs\SHUTIL.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\ftl.dll]  [Network Associates, Inc., 8.0.0.135]
    [D:\McAfee-v8.0_chs\Res04\McShield.dll]  [Network Associates, Inc., 8.0.0.251]
    [D:\McAfee-v8.0_chs\RES04\Product.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\RES04\Shutilrc.dll]  [Network Associates, Inc., 8.0.0.912]
    [D:\McAfee-v8.0_chs\Graphics.dll]  [Network Associates, Inc., 8.0.0.912]
    [C:\Program Files\Common Files\Network Associates\Engine\mcscan32.dll]  [McAfee, Inc., 5.1.00]
    [D:\Common Framework\GenEvtInf.dll]  [Network Associates, Inc., 3.5.0.412]
    [D:\McAfee-v8.0_chs\NaEventU.DLL]  [Network Associates, Inc., 8.0.0.342]
    [D:\McAfee-v8.0_chs\Res04\naEvtRes.dll]  [Network Associates, Inc., 8.0.0.342]
    [D:\Common Framework\SecureFrameworkFactory.dll]  [Network Associates, Inc., 3.5.0.412]
gototop
 

[PID: 3128][D:\文件夹\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [D:\文件夹\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [D:\文件夹\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [D:\文件夹\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 370]
    [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
    [D:\文件夹\QQAPI.dll]  [, 1, 0, 0, 1]
    [D:\文件夹\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [D:\文件夹\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [D:\文件夹\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [D:\文件夹\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [D:\文件夹\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [D:\文件夹\QQMainFrame.dll]  [N/A, N/A]
    [D:\文件夹\CQQApplication.dll]  [N/A, N/A]
    [D:\文件夹\NewSkin.dll]  [, 1, 0, 0, 1]
    [D:\文件夹\HostingMgr.dll]  [, 1, 0, 0, 1]
    [D:\文件夹\CameraDll.dll]  [, 1, 0, 0, 1]
    [D:\文件夹\MailSummary.dll]  [, 1, 0, 0, 1]
    [D:\文件夹\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
    [D:\文件夹\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [D:\文件夹\GroupLive.dll]  [N/A, N/A]
    [D:\文件夹\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [D:\文件夹\QQPlugin.dll]  [N/A, N/A]
    [D:\文件夹\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [D:\文件夹\QRingMng.dll]  [N/A, N/A]
    [D:\文件夹\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [D:\文件夹\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [D:\文件夹\VPortal.dll]  [, 1, 0, 0, 4]
    [D:\文件夹\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [D:\文件夹\QQAvatar.dll]  [N/A, N/A]
    [D:\文件夹\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [D:\文件夹\QQPet.dll]  [, 1, 0, 0, 1]
    [D:\文件夹\QQSysMsgMng.dll]  [N/A, N/A]
    [D:\文件夹\BQQApplication.dll]  [N/A, N/A]
    [D:\文件夹\QQAllInOne.dll]  [N/A, N/A]
    [D:\文件夹\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
    [D:\文件夹\QQCustomFace.dll]  [N/A, N/A]
    [D:\文件夹\CommercesMng.dll]  [, 1, 0, 0, 1]
    [D:\文件夹\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [D:\文件夹\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 240]
    [D:\文件夹\QQSceneMng.dll]  [N/A, N/A]
    [D:\文件夹\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 1, 11]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
    [D:\文件夹\QQMagicFace.dll]  [, 1, 0, 0, 1]
[PID: 3284][D:\文件夹\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [D:\文件夹\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 2156][D:\讯雷WEB\WebThunder.exe]  [深圳市迅雷网络技术有限公司, 1, 5, 0, 77]
    [D:\讯雷WEB\taskmanage.dll]  [Thunder Networking Technologies,LTD, 1, 5, 0, 77]
    [D:\讯雷WEB\download_interface.dll]  [Thunder Networking Technologies,LTD, 2, 11, 3, 22]
    [D:\讯雷WEB\asyn_dns.dll]  [Thunder Networking Technologies,LTD, 2, 11, 3, 22]
    [D:\讯雷WEB\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 2, 1, 39]
    [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
    [D:\讯雷WEB\historyinfo_manage.dll]  [Thunder Networking Technologies,LTD, 5, 3, 0, 228]
    [D:\讯雷WEB\UpdateDownload.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 8]
    [D:\讯雷WEB\UpdateExec.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 5]
    [D:\讯雷WEB\iEmbedShell.dll]  [ , 1, 0, 0, 14]
    [D:\讯雷WEB\iEmbed07.dll]  [ , 3, 1, 0, 58]
    [D:\McAfee-v8.0_chs\scriptproxy.dll]  [Network Associates, Inc., 8.0.0.955]
    [D:\McAfee-v8.0_chs\mytilus.dll]  [Network Associates, Inc., 8.0.0.251]
    [D:\McAfee-v8.0_chs\Res04\McShield.dll]  [Network Associates, Inc., 8.0.0.251]
    [C:\Program Files\Common Files\Network Associates\Engine\mcscan32.dll]  [McAfee, Inc., 5.1.00]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
[PID: 1040][D:\安装程序\sreng2\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
    [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
gototop
 

==================================
文件关联
.TXT  Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. [C:\WINDOWS\hh.exe %1]
.HLP  Error. [C:\WINDOWS\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF  Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1                    about-blank.cc
127.0.0.1                    hao.allxun.com
127.0.0.1                    kzxf.com
127.0.0.1                    vod.mmdy.org
127.0.0.1                    www.123wa.com
127.0.0.1                    www.4199.com
127.0.0.1                    www.71791.com
127.0.0.1                    www.7939.com
127.0.0.1                    www.9505.com
127.0.0.1                    www.feixue.net
127.0.0.1                    www.kzxf.com
127.0.0.1                    www.my123.com
127.0.0.1                    www.piaoxue.com
127.0.0.1                    www.xfkz.com
127.0.0.1                    xfkz.com

==================================
gototop
 

好了.谢谢帮我弄了弄 我看了个么是头就混了
gototop
 

哥哥还在吗 帮我看一下 谢谢
gototop
 

红夜鬼1哥哥你在哪里啊 快来看看我的日志呀
gototop
 

红夜鬼1哥哥你在哪里啊 快来看看我的日志呀
gototop
 

红夜鬼1哥哥你在哪里啊 快来看看我分析一下拉
gototop
 

怎么没人了 谁来帮我分析一下啊
gototop
 

运行SREng2,使用:系统修复--文件关联--全选--修复



重新启动电脑,自动检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式(Safe Mode)进入Windows。)


运行(双击)SRENG2,点“启动项目,服务,点“驱动程序”
勾选“隐藏已认证的微软项目”选中病毒服务00003cff选择“删除服务”
点“设置”选择“否”


运行(双击)SRENG2,点“启动项目,服务,点“Win32服务应用程序”
勾选“隐藏微软服务”选中病毒服务
RestoreService
Logical Disk Manager Amdinistrative Serviece5
VisionService
Voolume Shadow Copyre2
,选择“删除服务”
点“设置”选择“否”


显示隐藏文件
删除:
C:\WINDOWS\system32\drivers\service.dll
c:\windows\system\micro\iexplorer.exe
C:\PROGRA~1\vision\
c:\windows\system32\drivers\00003cff.SYS
c:\windows\system\Microsoft\kav.exe

把.EXE两个病毒压缩发给我,见签名
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT