瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 SOS:网页不定期弹出(139,tv mofile,ibm1860,5617,9158...)

12   1  /  2  页   跳转

SOS:网页不定期弹出(139,tv mofile,ibm1860,5617,9158...)

SOS:网页不定期弹出(139,tv mofile,ibm1860,5617,9158...)

139,tv mofile,ibm1860,5617,9158,winopen,survey88,ohoad
这些网页都曾以各种形式弹出过,扫描如下:

Logfile of HijackThis v1.99.1
Scan saved at 15:00:00, on 2006-08-13
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
d:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
D:\Program Files\D-Tools\daemon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\kingsoft\iciba\Iciba.exe
D:\Program Files\拼音加加\jj4\jjsvr4.exe
d:\program files\rising\rfw\RfwMain.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
D:\Downloads\RogueCleaner\RogueCleaner.exe
D:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Rising\Rav\Rav.exe
C:\Program Files\Kingsoft\WPS Office 2005 PersonalTrial\office6\wps.exe
D:\Downloads\恶意网页清理\ha_hijackthis_1991\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283}? - (no file)
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [DAEMON Tools-2052] "D:\Program Files\D-Tools\daemon.exe"  -lang 2052
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunOnce: [RavStub] "C:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [词霸Online自启动] D:\Program Files\kingsoft\iciba\Iciba.exe
O4 - HKCU\..\Run: [pyjj] D:\Program Files\拼音加加\jj4\jjsvr4.exe
O8 - Extra context menu item: &使用迅雷下载 - d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - d:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - d:\Program Files\Thunder Network\Thunder\Thunder.exe
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\cdnns.dll' missing
O16 - DPF: {18F57D30-EF36-4C0E-9343-7BFA6DF79B4A} -
O16 - DPF: {52DF16E3-6C4F-4B22-8BAF-09263E463B48} - http://zs.kingsoft.com/KOSInit.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155025051203
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9AEE2B9D-9A6B-4AB6-9772-0B0C66F9A8A3}: NameServer = 202.102.154.3 202.102.152.3
O20 - AppInit_DLLs: APIHookDll.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe

请大侠帮忙给看一下!小女子感激不尽!

另外:用恶意软件清理助手清理,每次清理完毕下次开机再检测总会又发现一两个“发现残余项目”,如:3721上网助手,CNIC中文上网,NB46工具栏,ADplus/MSplus病毒
最后编辑2006-08-13 19:20:26
分享到:
gototop
 

O16 - DPF: {18F57D30-EF36-4C0E-9343-7BFA6DF79B4A} -

你先删除这一项。

然后,用正版瑞星扫描一遍电脑杀毒。

最后用超级兔子卸载流氓程序。

清理完毕后,反馈有关情况给我。
gototop
 

谢谢!超级兔子好用吗?我有一次下的兔子被捆了东西,再不敢用了。
gototop
 

按你说的做完了,
用魔法兔子卸载了ADplus,联众,新浪点点通,
正版瑞星一如既往地没有发现病毒,
关机重启的时候出现问题:
sw:AcroRd32.exe-应用程序错误
“Ox5adc1531”指令引用的“0x00000014"内存,该内存不能为“read”
sw:AcroRd32.exe-应用程序错误
“Ox24002bcb”指令引用的“Ox24002bcb"内存,该内存不能为“read”

刚刚在此发帖的同时,瑞星检测到有网站试图把自己设为电脑主页,被我拒绝。

以下是我的诊断报告:
Logfile of HijackThis v1.99.1
Scan saved at 16:02:33, on 2006-08-13
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
d:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
d:\program files\rising\rfw\RfwMain.exe
C:\Program Files\Rising\Rav\RavTask.exe
D:\Program Files\D-Tools\daemon.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\kingsoft\iciba\Iciba.exe
D:\Program Files\拼音加加\jj4\jjsvr4.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Downloads\恶意网页清理\ha_hijackthis_1991\HijackThis.exe

R3 - Default URLSearchHook is missing
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [DAEMON Tools-2052] "D:\Program Files\D-Tools\daemon.exe"  -lang 2052
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [词霸Online自启动] D:\Program Files\kingsoft\iciba\Iciba.exe
O4 - HKCU\..\Run: [pyjj] D:\Program Files\拼音加加\jj4\jjsvr4.exe
O8 - Extra context menu item: &使用迅雷下载 - d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - d:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - d:\Program Files\Thunder Network\Thunder\Thunder.exe
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\cdnns.dll' missing
O16 - DPF: {52DF16E3-6C4F-4B22-8BAF-09263E463B48} - http://zs.kingsoft.com/KOSInit.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155025051203
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9AEE2B9D-9A6B-4AB6-9772-0B0C66F9A8A3}: NameServer = 202.102.154.3 202.102.152.3
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe

拜托啦!!!
gototop
 

运行Hijackthis,扫描结束后在下列选项前打上勾,然后选"修复
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\cdnns.dll' missing
O16 - DPF: {52DF16E3-6C4F-4B22-8BAF-09263E463B48} - http://zs.kingsoft.com/KOSInit.cab
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab

重启后删除
c:\windows\system32\cdnns.dll
gototop
 

R3 - Default URLSearchHook is missing
gototop
 

我没有发现有什么可疑程序。你是否可以重新启动一下电脑,再用hijackhis扫描一遍日志上来。
gototop
 

关机重启的时候出现问题:
sw:AcroRd32.exe-应用程序错误
“Ox5adc1531”指令引用的“0x00000014"内存,该内存不能为“read”
sw:AcroRd32.exe-应用程序错误
“Ox24002bcb”指令引用的“Ox24002bcb"内存,该内存不能为“read”

把Adobe卸载重新安装其它盘
gototop
 

谢谢楼上各位!
但兔子下载以后,主页被自动修改成了“好看123网址大全”
另外,瑞星接二连三监控到:修改<Start Page>值为<http://jjol.cn/?a=70796668616f6b616e>,我每次都拒绝了,但不知怎样从根本上解决。是不是兔子也被污染了?
gototop
 

应该是兔子的问题

IE--属性---常规---更改主页

你先把ADOBE的问题解决后,再扫描上来
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT