1   1  /  1  页   跳转

恶意广告!怎么处理啊【求助】

恶意广告!怎么处理啊【求助】

我发现每打开一张网页都一个广告!很贩人啊怎么能把它去掉啊谢谢

Logfile of HijackThis v1.99.1
Scan saved at 22:07:40, on 2005-12-6
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT.0\System32\smss.exe
C:\WINNT.0\system32\winlogon.exe
C:\WINNT.0\system32\services.exe
C:\WINNT.0\system32\lsass.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\Program Files\rising\Rav\Ravmond.exe
C:\Program Files\Rising\Rfw\rfwsrv.exe
C:\WINNT.0\system32\svchost.exe
C:\WINNT.0\system32\spoolsv.exe
C:\WINNT.0\system32\svchost.exe
C:\WINNT.0\system32\nvsvc32.exe
C:\Program Files\P4P\p2psvr.exe
C:\WINNT.0\system32\MSTask.exe
C:\Program Files\rising\Rav\RavStub.exe
C:\WINNT.0\system32\tcpsvcs.exe
C:\WINNT.0\System32\WBEM\WinMgmt.exe
C:\WINNT.0\system32\svchost.exe
C:\WINNT.0\Explorer.EXE
C:\Program Files\Rising\Rfw\RfwMain.exe
C:\Program Files\Media Gateway\MediaGateway.exe
C:\Program Files\HuaCi\huaci\zsearch.exe
C:\Program Files\rising\Rav\RavTask.exe
C:\WINNT.0\system32\ctfmon.exe
C:\Program Files\rising\Rav\Ravmon.exe
E:\千千静听\TTPlayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT.0\system32\NOTEPAD.EXE
E:\常用杀毒工具\155847200541134207\HijackThis.exe

R3 - URLSearchHook: MyURLSearchHook Class - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - C:\PROGRA~1\P4P\ToolBar.dll
O2 - BHO: Shockwave Flash BrowserHelpObject - {1002C84D-A326-2D3C-13F3-2C2474392A91} - C:\WINNT.0\system32\FlashHlp.dll
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O3 - Toolbar: CyberArticle Express - {769A6A36-ED24-4376-BC7C-80225BF35698} - C:\Program Files\CyberArticle\CAExp.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINNT.0\system32\KakaTool.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT.0\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Media Gateway] C:\Program Files\Media Gateway\MediaGateway.exe
O4 - HKLM\..\Run: [MoveSearch] C:\Program Files\HuaCi\huaci\zsearch.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [e2bf698e3dd45f5e44365f33f80239c8] "F:\qqspc\wpsdls.14520.10.exe" -t 14520.10
O8 - Extra context menu item:  >> 彩信发送 << - res://C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL/mms.htm
O8 - Extra context menu item: &使用迅雷下载 - E:\讯雷\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - E:\讯雷\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - E:\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 保存: 完整网页... - C:\Program Files\CyberArticle\script\Save.htm
O8 - Extra context menu item: 保存: 更多保存内容... - C:\Program Files\CyberArticle\script\SaveAuto.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\qq\SendMMS.htm
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - F:\浩方对战平台\GameClient.exe
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O9 - Extra 'Tools' menuitem: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O9 - Extra button: SoQ - {8F67DCF3-B1DF-4A39-A787-3775784BF737} - http://www.soq.com (file missing)
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/180solutions/ie/bridge-c24.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} (pCastPanel Class) - http://ps.itv.mop.com/dn/files/pCastCtl_1.0.0.76_20051110.cab
O20 - AppInit_DLLs: APIHookDll.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT.0\System32\dmadmin.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT.0\system32\nvsvc32.exe
O23 - Service: P4P Service - Sohu R&D - C:\Program Files\P4P\p2psvr.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - C:\Program Files\Rising\Rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\Ravmond.exe

最后编辑2005-12-06 22:45:40
分享到:
gototop
 

这个是木马杀克查出的
C:\WINNT.0\system32\winconfd.dll 怀疑为CNNIC广告
C:\WINNT.0\system32\ZUpdate\CdnIEHlp.dll_被屏蔽木马 怀疑为CNNIC广告
C:\WINNT.0\system32\ZUpdate\CdnIEHlp.dll_被屏蔽木马 发现广告程序:tro2005-7-10-adware-A0000032,81920
gototop
 

要沉自己顶
gototop
 

【回复“菜鸟的问题”的帖子】把“中文上网”卸喽!
gototop
 

我没有装中文上网,我的程序里面没有,我的添加程序里面就有一个划词搜索!我卸了,可有时打开网页还是有广告!
邮件我收到了谢谢baohe 版主对我的帮助!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT