瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 老是弹出http:// 540.filost.com网页,请各位大虾帮忙

1   1  /  1  页   跳转

老是弹出http:// 540.filost.com网页,请各位大虾帮忙

老是弹出http:// 540.filost.com网页,请各位大虾帮忙

下面是扫描后的系统日志:
Logfile of HijackThis v1.99.1
Scan saved at 00:36:11 上午, on 2006-4-16
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\Explorer.EXE
e:\program files\rising\rfw\rfwsrv.exe
E:\WINDOWS\System32\firewall.exe
E:\WINDOWS\System32\explorer.exe
E:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\WINDOWS\System32\SERVlCE.EXE
E:\Program Files\Rising\Rfw\rfwmain.exe
E:\WINDOWS\System32\ctfmon.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\conime.exe
E:\Documents and Settings\Victory\桌面\hj\ha_hijackthis_1991\HijackThis.exe

R3 - Default URLSearchHook is missing
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - E:\WINDOWS\System32\kakatool.dll
O4 - HKLM\..\Run: [Windows Network Firewall] E:\WINDOWS\System32\firewall.exe
O4 - HKLM\..\Run: [Windows Explorer] E:\WINDOWS\System32\explorer.exe
O4 - HKLM\..\Run: [TkBellExe] "E:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Spooler SubSystem App] E:\WINDOWS\System32\spoolsvc.exe
O4 - HKLM\..\Run: [SERVlCE] SERVlCE.EXE
O4 - HKLM\..\Run: [RfwMain] "E:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [Microsoft Internet Explorer] E:\WINDOWS\System32\iexplore.exe
O4 - HKLM\..\Run: [IMSCMig] E:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [Application Layer Gateway Service] E:\WINDOWS\System32\algs.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunServices: [SERVlCE] SERVlCE.EXE
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\System32\ctfmon.exe
O4 - Startup: 迅雷4.lnk = F:\Program Files\Thunder\Thunder.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - E:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - E:\WINDOWS\web\related.htm
O10 - Unknown file in Winsock LSP: e:\windows\system32\cdnns.dll
O11 - Options group: [CDNCLIENT]  中文上网
O16 - DPF: PresenceControl - http://www.catv.net/download/presencecontrol.cab
O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1108126243284
O16 - DPF: {64311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - http://bar.baidu.com/update/IESearch.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{53B4DB6A-F5BC-4C04-8A72-CB453F624D0B}: NameServer = 202.106.46.151 202.106.0.20
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - E:\WINDOWS\System32\vbsys2.dll
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - e:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - e:\program files\rising\rfw\rfwsrv.exe
O23 - Service: System Startup Service  (SvcProc) - Unknown owner - E:\WINDOWS\svcproc.exe (file missing)

最后编辑2006-04-16 14:50:24
分享到:
gototop
 

O4 - HKLM\..\Run: [Windows Network Firewall] E:\WINDOWS\System32\firewall.exe
O4 - HKLM\..\Run: [Windows Explorer] E:\WINDOWS\System32\explorer.exe
O4 - HKLM\..\Run: [Spooler SubSystem App] E:\WINDOWS\System32\spoolsvc.exe
O4 - HKLM\..\Run: [SERVlCE] SERVlCE.EXE
O4 - HKLM\..\Run: [Microsoft Internet Explorer] E:\WINDOWS\System32\iexplore.exe
O10 - Unknown file in Winsock LSP: e:\windows\system32\cdnns.dll
O11 - Options group: [CDNCLIENT] 中文上网
O16 - DPF: PresenceControl - http://www.catv.net/download/presencecontrol.cab
O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O16 - DPF: {64311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - E:\WINDOWS\System32\vbsys2.dll




O23 - Service: System Startup Service (SvcProc) - Unknown owner - E:\WINDOWS\svcproc.exe (file missing)

gototop
 

你中了木马,小心你的邮箱QQ游戏等账号的密码,建议先到另一台正常的系统上修改你的密码。
修复以上的选项
打开我的电脑,工具,查看,选中“显示所有文件和文件夹”还有清除勾选的“隐藏系统文件”这两个选项了
删除
E:\WINDOWS\System32\firewall.exe
E:\WINDOWS\System32\explorer.exe
E:\WINDOWS\System32\spoolsvc.exe
E:\WINDOWS\System32\iexplore.exe
E:\WINDOWS\System32\vbsys2.dll
E:\WINDOWS\svcproc.exe
注意看准目录,不要删除错了。
搜索SERVlCE.EXE(不是很确定,如果你也不知道,建议删除,删除前可以用RAR打包备份一下)找到后删除它。


gototop
 

另,装个杀毒软件,更新你的病毒库,这些病毒应该还有帮凶。
http://www.downxia.com/downinfo/89.html
下载卡巴斯基,在更新完病毒库后,再完整扫描C盘。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT