瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 如何设置卡卡上网安全助手阻止划词猪【求助】

123   1  /  3  页   跳转

如何设置卡卡上网安全助手阻止划词猪【求助】

如何设置卡卡上网安全助手阻止划词猪【求助】


上网时在没有任何提示的情况下安装了(划词搜索中搜在线及MMSAssist)两个文
件请高手指点。谢谢!!!
最后编辑2006-01-05 09:10:15
分享到:
gototop
 

啊?看看插件管理,找到了就禁用
gototop
 

飘过...
gototop
 

在卡卡插件管理,已设禁用还是不知不觉的情况下安装了
gototop
 

在下不才,小问几句:
1.楼主用的操作系统是什么?
2.原有的猪猪是否已经杀了吃肉了。
3.猪猪插件是否屏蔽(或称免疫)?
4.你所谓的不知不觉安装是什么意思?是不是访问某个网站,没有任何提示就被装上了?卡卡没有提示,ie也没有提示?还是又安装了某些软件之后被强奸了?
5.是否把猪猪加进了卡卡的黑名单?
gototop
 

操作系统XP sp2
猪已经杀了吃肉了注册表已清理干净
猪猪插件免疫
所谓的不知不觉是正常上网,没有任何提示就被装上了?卡卡没有提示,ie也没有提示,在卡卡插件管理,已设禁用还是不知不觉的情况下安装了
用汉字把猪猪加进了卡卡的黑名单
gototop
 

那就很值得奇怪和可疑了,这样吧,你再卸载一次,卸载完马上用工具扫描个日志上来。如果这些工作都做了还被装上就是有问题了,可以骗过卡卡没应该没问题,因为卡卡还幼小,但是骗过ie就没道理了,底层监控都被骗就不大可能了。如果确定是没有提示就装上了,你就杀掉猪然后扫日志上来看看。
gototop
 

我发现卡卡的黑名单真幼稚,只是用文字识别?你可以试试别的工具加入黑名单试试,理论上说免疫以后就没问题,以后就不会提示和安装了。
gototop
 

Logfile of Kaka v2. 0. 0. 5 Scan Module v2. 0. 0. 1
Scan saved at 10:44:36, on 2006-01-03
Platform: Microsoft Windows XP Personal Service Pack 2 (Build 2600)
MSIE: Internet Explorer v6.00 SP2; (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))


Running processes:
[smss.exe]
CommandLine =

[csrss.exe]
CommandLine = C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

[winlogon.exe]
CommandLine = winlogon.exe

[SERVICES.EXE]
CommandLine = C:\WINDOWS\system32\services.exe

[LSASS.EXE]
CommandLine = C:\WINDOWS\system32\lsass.exe

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k NetworkService

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k LocalService

[LEXBCES.EXE]
CommandLine = C:\WINDOWS\system32\LEXBCES.EXE

[LEXPPS.EXE]
CommandLine = LEXPPS.EXE

[spoolsv.exe]
CommandLine = C:\WINDOWS\system32\spoolsv.exe

[EXPLORER.EXE]
CommandLine = C:\WINDOWS\Explorer.EXE

[ps2Kbdriver.exe]
CommandLine = "C:\Program Files\联想\联想键盘驱动\Ps2Kbdriver.exe"

[VM_STI.EXE]
CommandLine = "C:\WINDOWS\VM_STI.EXE" BigDogPath

[realsched.exe]
CommandLine = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot

[RdfSnap2005.exe]
CommandLine = "D:\Program Files\SuperSoft\RdfSnap2005\RdfSnap2005.EXE" /R

[KVMonXP_1.kxp]
CommandLine = "D:\Program Files\KV2006\KVMonXP_1.kxp" /auto

[CTFMON.EXE]
CommandLine = "C:\WINDOWS\system32\ctfmon.exe"

[fastkey.exe]
CommandLine = "C:\Program Files\联想\联想键盘驱动\fastkey.exe"

[KVSrvXP.exe]
CommandLine = "D:\Program Files\KV2006\KVSrvXP.exe" /Service

[kvwsc.exe]
CommandLine = "D:\Program Files\KV2006\kvwsc.exe"

[nvsvc32.exe]
CommandLine = C:\WINDOWS\System32\nvsvc32.exe

[TGESrvLogon.exe]
CommandLine = "C:\Program Files\联想\联想键盘驱动\TGESrvLogon.exe"

[wdfmgr.exe]
CommandLine = C:\WINDOWS\system32\wdfmgr.exe

[alg.exe]
CommandLine = C:\WINDOWS\System32\alg.exe

[TrojDie.kxp]
CommandLine = "D:\Program Files\KV2006\TrojDie.kxp" -enable-hide

[KRegEx.exe]
CommandLine = "D:\Program Files\KV2006\KRegEx.exe" 2052

[UIHost.exe]
CommandLine = "D:\Program Files\KV2006\UIHost.exe" -service -Embedding

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k imgsvc

[iexplore.exe]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe"

[KkScan.exe]
CommandLine = "d:\Program Files\Rising\KakaToolBar\KkScan.exe"

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.fm365.com/
R3 - Default URLSearchHook is missing
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: BrowseHelper Class - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} - D:\Program Files\KV2006\KvShell.dll
O2 - BHO:  (file missing)
O3 - Toolbar: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - D:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O3 - Toolbar: 江民杀毒工具栏 - {B5A34A93-D538-43A7-8371-864CB6148D12} - D:\Program Files\KV2006\KvShell.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] ; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] ; RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [HuaShanTGEKBDPS2] C:\Program Files\联想\联想键盘驱动\Ps2Kbdriver.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE USB PC Camera 301P
O4 - HKLM\..\Run: [Autop] ; D:\Program Files\!sunv\dfyd\AutoP.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] ; C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RdfSnap2005] "D:\Program Files\SuperSoft\RdfSnap2005\RdfSnap2005.EXE" /R
O4 - HKLM\..\Run: [KvMonXP] D:\Program Files\KV2006\KVMonXP_1.kxp /auto
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: 使用网际快车下载 - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\Program Files\FlashGet\jc_all.htm
O9 - Extra Button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191}? -  (file missing)
O9 - Extra 'Tools' menuitem: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191}? -  (file missing)
O10 - Unknown file in Winsock LSP: D:\Program Files\KV2006\KVSock_1.dll
O10 - Unknown file in Winsock LSP: D:\Program Files\KV2006\KVSock_1.dll
O10 - Unknown file in Winsock LSP: D:\Program Files\KV2006\KVSock_1.dll
O10 - Unknown file in Winsock LSP: D:\Program Files\KV2006\KVSock_1.dll
O10 - Unknown file in Winsock LSP: D:\Program Files\KV2006\KVSock_1.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.fm365.com
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E5DAA8F2-05F8-4785-9221-58408964E4B0}: NameServer = 202.97.227.138 202.97.224.69
O18 - Filter : application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\system32\mscoree.dll
O18 - Filter : application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\system32\mscoree.dll
O18 - Filter : application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\system32\mscoree.dll
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - C:\WINDOWS\wc98pp.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\System32\msvidctl.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\System32\wiascr.dll
O20 - AppInit_DLLs: NVDESK32.DLL
O20 - Winlogon Notify: ZGNotify
O23 - Service: Application Management (AppMgmt) -  - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Human Interface Device Access (HidServ) -  - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: KVSrvXP (KVSrvXP) - Jiangmin Co. Ltd - D:\Program Files\KV2006\KVSrvXP.exe /Service
O23 - Service: KVWSC (KVWSC) - Jiangmin Co.Ltd - "D:\Program Files\KV2006\kvwsc.exe"
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\lexbces.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TGE CardReader Mgr Host v2 (TGECardReaderMgrHost.2) -  - C:\Program Files\联想\联想键盘驱动\TGESrvLogon.exe
gototop
 

CommandLine = "C:\WINDOWS\VM_STI.EXE" BigDogPath这个是什么?
R3 - Default URLSearchHook is missing修复一下
O2 - BHO: (file missing)修复
O4 - HKLM\..\Run: [NvCplDaemon] ; RUNDLL32.EXE NvQTwk,NvCplDaemon initialize这个是什么?
O9 - Extra Button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191}? - (file missing)修复
O9 - Extra 'Tools' menuitem: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191}? - (file missing)修复
以上不能保证是猪猪的全部问题
需要修复的可以确定是猪猪的注册表残留,你所谓的安装,我怀疑是不是你还能在ie中看到按钮或菜单项什么的?
gototop
 
123   1  /  3  页   跳转
页面顶部
Powered by Discuz!NT