瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】昨天ie被此网站劫持并杀出很多蠕虫病毒

1   1  /  1  页   跳转

【求助】昨天ie被此网站劫持并杀出很多蠕虫病毒

【求助】昨天ie被此网站劫持并杀出很多蠕虫病毒

使用瑞星无效,卡卡上网助手无法安装,很多程序无法安装!求助,日志如下,[R]那个启动项删不掉!
Logfile of Kaka v2. 0. 0. 9 Scan Module v2. 0. 0. 1
Scan saved at 13:52:48, on 2006-10-10
Platform: Microsoft Windows XP Professional  (Build 2600)
MSIE: Internet Explorer v6.00  (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))


O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Super Rabbit Start Button] E:\Program Files\Super Rabbit\MagicSet\SRSB.EXE /Load
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [PCSuiteTrayApplication] ; D:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
O4 - HKLM\..\Run: [RavScanBD] "C:\Program Files\Rising\Rfw\ScanBD.exe" /INST
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [WebThunder] d:\Program Files\Thunder Network\WebThunder\WebThunder.exe
O4 - HKLM\..\Run: [R] C:\WINDOWS\System32\rundll32.exe msprt.dll s
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O16 - DPF: {2354A44B-3CEB-4829-9940-545B03103538} (PowerPlr Control) - http://vnet.wuhan.net.cn/plugin/PowerPlr.ocx
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/1007/aliedit.cab
O16 - DPF: {5467862B-C477-437F-886E-EC5006B37DCA} (PwdEdit Control) - https://ebank.cmbc.com.cn/PwdEdit.cab
O16 - DPF: {85599589-00AA-11D7-A7D0-00E04C3F6D70} (SecClient Control) - https://ebank.cmbc.com.cn/secClientOcx.cab
O16 - DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} () - file://I:\程序\程序已备份\媒体中心\会声会影\会声会影9中文版\setup.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{057B1A11-07CE-48B1-BC06-437F58804B5E}: NameServer = 210.52.149.2,210.52.207.2
O18 - Filter : text/x-mrml - {C51721BE-858B-4A66-A8BF-D2882FF49820} - d:\Program Files\YAMAHA\MidRadio Player\midradio.ocx
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\System32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\System32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\System32\msvidctl.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\System32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\System32\msdxm.ocx
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\System32\wiascr.dll
O20 - Winlogon Notify: WgaLogon
O23 - Service: Adobe LM Service (Adobe LM Service) - Adobe Systems - "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"
O23 - Service: Event Service (Framework) -  - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Human Interface Device Access (HidServ) -  - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: System Event Logger (NHLscA) -  - C:\WINDOWS\System32\rundll.exe c:\windows\system32\wbem\smtpconfs.dll,export 1087
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rfw\rfwsrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) -  - "C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\Rising\Rav\CCenter.exe"
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\Rising\Rav\Ravmond.exe"
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

附件附件:

下载次数:171
文件类型:application/octet-stream
文件大小:
上传时间:2006-10-10 14:23:30
描述:



最后编辑2006-10-10 23:00:52
分享到:
gototop
 

控制面板--管理工具--服务--查找--Remote Packet Capture Protocol v.0 ,,,System Event Logger (--启动类型--设置为已禁止--服务类型--设置为停止

运行Hijackthis,把下面的选中打上钩,修复
O23 - Service: System Event Logger (NHLscA) - - C:\WINDOWS\System32\rundll.exe c:\windows\system32\wbem\smtpconfs.dll,export 1087
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - - "C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"

删除
C:\Program Files\WinPcap\文件夹
c:\windows\system32\wbem\smtpconfs.dll

O4 - HKLM\..\Run: [R] C:\WINDOWS\System32\rundll32.exe msprt.dll s
看一下链接
http://forum.ikaka.com/topic.asp?board=67&artid=8188842
gototop
 

修复后,重启,还存在异常,请下载SREng2 ,使用“智能扫描”,按下“扫描”按钮进行扫描,
扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告
日志文件内容复制-粘贴上来,,日志一次粘不完,分次粘完,请不要修改。

下载地址
http://free5.ys168.com/?ufwihgu168
gototop
 

非常感谢你秋日里的蓝天,主要问题已经解决,只是现在仍然有一个问题存在,就是使用QQ宠物时,一开任何位养宠物的页面就弹出脚本页面错误的提示,以至于无法进行喂养!!图我会发新的主体附上!!谢谢
gototop
 

呵呵,我也不知道这个,你试着下载个新版的QQ,看能不能解决喂养的问题。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT