瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 也是qq病毒,一直搞不定了,请来帮忙~

1   1  /  1  页   跳转

也是qq病毒,一直搞不定了,请来帮忙~

也是qq病毒,一直搞不定了,请来帮忙~

我最近和别人聊天时,过段时间就给别人发消息

我刚刚给你点了一首好听的歌放在手机信箱里你用手机拨 1②590556226就可以听了,听完后有我留言

怎么用qq病毒专杀什么的都搞不定呢,谢谢~
最后编辑2006-11-09 14:05:29
分享到:
gototop
 

QQ尾巴,应该可以杀的....
gototop
 

已经下过了那个qq专杀,杀过了总是不行

有没有别的手动的办法?
谢谢
gototop
 

已经下过了那个qq专杀,杀过了总是不行

有没有别的手动的办法?
谢谢
gototop
 

我也是,重裝繫統后就中毒暸,不仅试qq中毒,连淘宝旺旺叶中毒了
gototop
 

发日志。。
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 9:33:43, on 2006-11-9
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
D:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
d:\Program Files\AVG Anti-Spyware 7.5\guard.exe
D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
D:\花生壳\PeanutHull3\PhCore.exe
C:\PROGRA~1\EFFICI~1\ENTERN~1\app\pppoeservice.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Maxthon\Maxthon.exe
D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Program Files\SuperProxy代理服务器\SuperProxy.exe
D:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe
E:\wl\qqkav_skycn.exe
D:\Program Files\Tencent\QQ\QQ.exe
E:\wl\工具软件\HijackThis.com

R3 - Default URLSearchHook is missing
O3 - Toolbar: (no name) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - (no file)
O4 - HKLM\..\Run: [kav] "D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [Thunder] "D:\Program Files\Thunder Network\Thunder\Thunder.exe" /s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\Ctfmon.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &使用迅雷下载 - d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: Web反病毒保护 - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{12855C3D-0B46-460D-901A-7D795ECD2536}: NameServer = 202.102.134.68,202.102.128.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{E67E4A37-C182-4901-9EB9-42453F4F8441}: NameServer = 202.102.154.3 202.102.128.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{12855C3D-0B46-460D-901A-7D795ECD2536}: NameServer = 202.102.134.68,202.102.128.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{12855C3D-0B46-460D-901A-7D795ECD2536}: NameServer = 202.102.134.68,202.102.128.68
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - d:\Program Files\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: 卡巴斯基反病毒软件6.0 (AVP) - Unknown owner - D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Kingsoft Personal Firewall Service (KPfwSvc) - Unknown owner - (no file)
O23 - Service: DNS Cache (NHLscA) - Unknown owner - C:\WINDOWS\SYSTEM32\RUN32.EXE (file missing)
O23 - Service: Windows Desktop Multimedia (ntkrnl) - Unknown owner - ntkrnl.exe (file missing)
O23 - Service: PeanuthullCore - 广东网域 - D:\花生壳\PeanutHull3\PhCore.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\PROGRA~1\EFFICI~1\ENTERN~1\app\pppoeservice.exe
O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\WINDOWS\system32\spoolsv.exe (file missing)

gototop
 

O10 - Unknown file in Winsock LSP: c:\windows\system32\cn_api60.dll
需要用LSPFix 来修复..
LSPFix(汉化版) 下载地址:http://mopery.hits.io/LSPFix.zip
同时下载:http://mopery.hits.io/WinsockXPFix.zip
----------------------------------------------------------------
先运行LSPFix ... 勾上 我确定要进行修复操作 ...
然后将cn_api60.dll移到右边...点下完成...
----------------------------------------------------------------
如果在操作之后不能上网...请用WinsockXPFix.exe 修复一下即可...安全模式下..

gototop
 

O23 - Service: Windows Desktop Multimedia (ntkrnl) - Unknown owner - ntkrnl.exe (file missing) 这个是什么啊?`` R3 - Default URLSearchHook is missing 还有这个```
gototop
 

谢谢楼上,我在进程里面并没有发现那个进程啊?
最新扫描的如下:
Logfile of HijackThis v1.99.1
Scan saved at 14:03:07, on 2006-11-9
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
D:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
d:\Program Files\AVG Anti-Spyware 7.5\guard.exe
D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
D:\花生壳\PeanutHull3\PhCore.exe
C:\PROGRA~1\EFFICI~1\ENTERN~1\app\pppoeservice.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SuperProxy代理服务器\SuperProxy.exe
D:\Program Files\Maxthon\Maxthon.exe
C:\WINDOWS\regedit.exe
D:\Program Files\Tencent\QQ\QQ.exe
D:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe
C:\WINDOWS\system32\NOTEPAD.EXE
E:\wl\工具软件\HijackThis.com

O4 - HKLM\..\Run: [kav] "D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [Thunder] "D:\Program Files\Thunder Network\Thunder\Thunder.exe" /s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &使用迅雷下载 - d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: Web反病毒保护 - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{12855C3D-0B46-460D-901A-7D795ECD2536}: NameServer = 202.102.134.68,202.102.128.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{E67E4A37-C182-4901-9EB9-42453F4F8441}: NameServer = 202.102.154.3 202.102.128.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{12855C3D-0B46-460D-901A-7D795ECD2536}: NameServer = 202.102.134.68,202.102.128.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{12855C3D-0B46-460D-901A-7D795ECD2536}: NameServer = 202.102.134.68,202.102.128.68
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - d:\Program Files\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: 卡巴斯基反病毒软件6.0 (AVP) - Unknown owner - D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Kingsoft Personal Firewall Service (KPfwSvc) - Unknown owner - (no file)
O23 - Service: DNS Cache (NHLscA) - Unknown owner - C:\WINDOWS\SYSTEM32\RUN32.EXE (file missing)
O23 - Service: Windows Desktop Multimedia (ntkrnl) - Unknown owner - (no file)
O23 - Service: PeanuthullCore - 广东网域 - D:\花生壳\PeanutHull3\PhCore.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\PROGRA~1\EFFICI~1\ENTERN~1\app\pppoeservice.exe
O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\WINDOWS\system32\spoolsv.exe (file missing)

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT