1   1  /  1  页   跳转

老弹出黄色网站 谁能帮帮忙 3Q

老弹出黄色网站 谁能帮帮忙 3Q

老自动弹出黄色网站 弹出来以后就很卡 

下面是小弟用HijackThis扫描出来的  教我该在办  谢谢了  在线等的

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Download\svhost32.exe
C:\WINDOWS\system32\ctfmon.exe
E:\MpSoft\VOD\mpvod.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mcrar.exe
C:\WINDOWS\system32\Dfssvc.exe
E:\MpSoft\VOD\VODServer.exe
C:\WINDOWS\system32\conime.exe
E:\ppdvdhscar\Client.exe
E:\BitSpirit\BitSpirit\BitSpirit.exe
C:\WINDOWS\system32\ntesersv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Thunder\Program\Thunder5.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\新建文件夹\HijackThis.exe

R3 - URLSearchHook: Tencent SearchHook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\Adplus\SSAddr.dll
O2 - BHO: 中文搜搜 - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\Program Files\TENCENT\Adplus\SSAddr.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [StormCodec_Helper] "e:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [xy] C:\WINDOWS\Download\svhost32.exe
O4 - HKLM\..\Run: [stup.exe] C:\PROGRA~1\TENCENT\Adplus\stup.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [mpvod] E:\MpSoft\VOD\mpvod.exe /autorun
O4 - HKCU\..\Run: [svchost] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mcrar.exe
O4 - Global Startup: Microsoft Office.lnk = D:\program\office2k\Office\OSA9.EXE
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - E:\BitSpirit\BitSpirit\bsurl.htm
O9 - Extra button: 网址大全 - {C18CB140-0BBB-11D4-8FE8-0088CC102438} - http://www.k369.com (file missing)
O9 - Extra 'Tools' menuitem: 网址大全 - {C18CB140-0BBB-11D4-8FE8-0088CC102438} - http://www.k369.com (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\wsd_sock32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wsd_sock32.dll
O11 - Options group: [TBH] 中文搜搜
O17 - HKLM\System\CCS\Services\Tcpip\..\{1D44C27D-DCC4-4BB5-9ACB-9F842ED97230}: NameServer = 220.170.64.68,220.170.64.96
O17 - HKLM\System\CCS\Services\Tcpip\..\{8BD6A937-A180-47BC-8FB7-747AA079DC2A}: NameServer = 220.170.64.68,220.170.64.96
O17 - HKLM\System\CCS\Services\Tcpip\..\{B145E85F-F27E-4AB4-8790-520BC9B09EEE}: NameServer = 220.170.64.68,220.170.64.96
O23 - Service: Network Connection4005381 (Service4005381) - Unknown owner - C:\WINDOWS\system32\ntesersv.exe
最后编辑2006-11-10 19:29:37
分享到:
gototop
 

O4 - HKLM\..\Run: [xy] C:\WINDOWS\Download\svhost32.exe
O4 - HKCU\..\Run: [svchost] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mcrar.exe
修复
删除C:\WINDOWS\Download\svhost32.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mcrar.exe


O23 - Service: Network Connection4005381 (Service4005381) - Unknown owner - C:\WINDOWS\system32\ntesersv.exe
进入注册表查找删除ntesersv.exe(有好几个)
重起删除C:\WINDOWS\system32\ntesersv.exe

O10 - Unknown file in Winsock LSP: c:\windows\system32\wsd_sock32.dll
Winsock修复  看清楚用法

http://forum.ikaka.com/topic.asp?board=28&artid=7259392


倒  裸奔的~~~~~~~~~~
gototop
 

O4 - HKLM\..\Run: [xy] C:\WINDOWS\Download\svhost32.exe
O4 - HKCU\..\Run: [svchost] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mcrar.exe修复了 

C:\WINDOWS\Download\svhost32.exe这个也删了  谢谢了

但是C:\WINDOWS\system32\ntesersv.exe重起后删不掉

那网站图片也不显示看不到
麻烦再帮帮我好吗
gototop
 

使用IceSword杀毒的一些基本操作:

http://forum.ikaka.com/topic.asp?board=28&artid=7168178
gototop
 

修复

C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mcrar.exe
C:\WINDOWS\system32\Dfssvc.exe
E:\MpSoft\VOD\VODServer.exe
C:\WINDOWS\system32\conime.exe
E:\ppdvdhscar\Client.exe
E:\MpSoft\VOD\mpvod.exe
    红色部分为正常
C:\WINDOWS\system32\ntesersv.exe


O4 - HKLM\..\Run: [xy] C:\WINDOWS\Download\svhost32.exe
O4 - HKLM\..\Run: [stup.exe] C:\PROGRA~1\TENCENT\Adplus\stup.exe

O4 - HKCU\..\Run: [svchost] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mcrar.exe
O4 - Global Startup: Microsoft Office.lnk = D:\program\office2k\Office\OSA9.EXE
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - E:\BitSpirit\BitSpirit\bsurl.htm
O9 - Extra button: 网址大全 - {C18CB140-0BBB-11D4-8FE8-0088CC102438} - http://www.k369.com (file missing)
O9 - Extra 'Tools' menuitem: 网址大全 - {C18CB140-0BBB-11D4-8FE8-0088CC102438} - http://www.k369.com (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\wsd_sock32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wsd_sock32.dll
O11 - Options group: [TBH] 中文搜搜
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT