瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 有没有人知道怎么彻底删除“播霸”啊?

1   1  /  1  页   跳转

有没有人知道怎么彻底删除“播霸”啊?

有没有人知道怎么彻底删除“播霸”啊?

唉,中了这么个破玩意,烦死人了
自动安装,自动搜台·~
让人有种被强奸的感觉
实在是搞不定它了
来这里请教下高手看能不能指点几招
最后编辑2006-04-17 16:02:09
分享到:
gototop
 

引用:
【不言放弃的贴子】【回复“天牙海脚”的帖子】
先卸载
然后删除相关安装文件夹
最后清理注册表
...........................

你说的我都作过了
这流氓文件夹名字叫pcast,另外还有msibm、bakcfs、update的文件夹也应该是跟它有关的
另外还有个Wbem文件夹里面有些可疑的log:
(Sat Apr 15 21:59:13 2006) : Core physically unloaded!
(Sat Apr 15 22:10:55 2006) : Core physically unloaded!
(Sat Apr 15 22:17:43 2006) : Core physically unloaded!
(Sun Apr 16 09:19:08 2006) : Core physically unloaded!
(Sun Apr 16 09:35:06 2006) : Core physically unloaded!
(Sun Apr 16 09:53:34 2006) : Core physically unloaded!
(Sun Apr 16 09:54:11 2006) : Core physically unloaded!
(Sun Apr 16 10:10:10 2006) : Core physically unloaded!
(Sun Apr 16 10:35:38 2006) : Core physically unloaded!
(Sun Apr 16 10:49:49 2006) : Core physically unloaded!
(Sun Apr 16 10:50:14 2006) : Core physically unloaded!



Error loading module {F7CE2E13-8C90-11D1-9E7B-00C04FC324A8}, return code is 0x8007045b(Sun Apr 16 10:12:09 2006) :
NTLMLogin resulted in hr = 0x8004100e(Sun Apr 16 10:12:09 2006) :
Error loading module {F7CE2E13-8C90-11D1-9E7B-00C04FC324A8}, return code is 0x8004100e(Sun Apr 16 10:37:24 2006) :
NTLMLogin resulted in hr = 0x8004100e(Sun Apr 16 10:37:24 2006) :
Error loading module {F7CE2E13-8C90-11D1-9E7B-00C04FC324A8}, return code is 0x8004100e
===========================
看了下时间,都是播霸自动弹出来的时候,应该跟播霸有关
我进安全模式下,删除了播霸,删了文件、注册表之后重启还是没用
应该在某处还有备份的文件
这几天被它烦死了,什么东西都用过了
木马杀客、EWIDO、AN-admire,upiea、卡巴、瑞星、流氓软件清理助手,优化大师、兔子、完美卸载、HJ、SRE……
全都没用,而且大部分时间还是在安全模式下查的
gototop
 

如果置顶贴说的有用我早就解决了……
照着置顶贴说的作了还是无效,所以我到处搜索解决方法
gototop
 

HijackThis@Qoo的扫描日志  V1.97.7
Scan saved at 14:46:13, on 2006-4-17
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
D:\VStart50\VStart.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Maxthon\Maxthon.exe
C:\Program Files\QQ\QQ.exe
C:\Program Files\Tencent\TIMPlatform.exe
C:\WINNT\system32\conime.exe
C:\Program Files\QQ\qqpet\qqpet.exe
E:\QQ\QQPetNurse0409(2.1SP5)\QQPetNurse.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\Thunder Network\Thunder\Thunder.exe
C:\WINNT\system32\taskmgr.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\Documents and Settings\Administrator\桌面\hijackthis1.97_qoo\HijackThis.exe

O2 - BHO: (no name) - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINNT\system32\xunleibho_v8.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [VStart5.0] D:\VStart50\VStart.exe
O4 - HKLM\..\Run: [IMSCMig] ; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RavTask] "D:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [JeticoPFStartup] "C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: NTUSER.DAT
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Startup: PUTTY.RND
O4 - Global Startup: ntuser.dat
O4 - Global Startup: ntuser.dat.LOG
O4 - Global Startup: ntuser.pol
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: 使用KuGoo3下载(&K) - C:\Program Files\KuGoo3\KuGoo3DownX.htm
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Web Anti-Virus (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: QQ (HKLM)
O9 - Extra button: FlashGet (HKLM)
O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc3.cab
O16 - DPF: {BD540752-A141-4AB7-8A6C-4EB19A7E11A9} - http://vod.ecjtu.jx.cn/vod/manager/ocx/upload.CAB
O16 - DPF: {C661F36D-DF85-4EF4-83C7-E107B83D04B1} (WebActivater Control) - http://dl_dir.qq.com/3dshow/3DShowVM.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8DA58ECD-A2E3-414D-BBF5-C780C9B0F4BF}: NameServer = 202.101.208.3,202.101.224.68,202.101.208.4,202.101.226.68
gototop
 

现在的日志看不出来什么
因为我昨天又排查了一次
从今天早上到现在还没发现它弹出来
但是文件夹还在,删了也没用
懒的删了,先放那,找到方法也好拿它开刀
gototop
 

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      15:06:20, 日期 2006-4-17
操作系统:  Windows 2000 SP4 (WinNT 5.00.2195)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
D:\VStart50\VStart.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Maxthon\Maxthon.exe
C:\Program Files\QQ\QQ.exe
C:\Program Files\Tencent\TIMPlatform.exe
C:\WINNT\system32\conime.exe
C:\Program Files\QQ\qqpet\qqpet.exe
E:\QQ\QQPetNurse0409(2.1SP5)\QQPetNurse.exe
C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe
C:\Program Files\Thunder Network\Thunder\Thunder.exe
C:\WINNT\system32\taskmgr.exe
C:\Documents and

Settings\Administrator\桌面\2535952005811174944\HijackThis1991zww.exe

O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} -

C:\WINNT\system32\xunleibho_v8.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} -

C:\PROGRA~1\FlashGet\jccatch.dll
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} -

C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - 启动项HKLM\\Run: [VStart5.0] D:\VStart50\VStart.exe
O4 - 启动项HKLM\\Run: [IMSCMig] ;

C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
04 - 启动项HKLM\\Run: [RavTask] "D:\Program Files\Rising\Rav\RavTask.exe"

-system
O4 - 启动项HKLM\\Run: [JeticoPFStartup] "C:\Program Files\Jetico\Jetico

Personal Firewall\fwsrv.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - C:\Program Files\Thunder

Network\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - C:\Program Files\Thunder

Network\Thunder\getallurl.htm
O8 - IE右键菜单中的新增项目: 使用KuGoo3下载(&K) - C:\Program

Files\KuGoo3\KuGoo3DownX.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - C:\Program

Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - C:\Program

Files\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) -

res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - 浏览器额外的按钮: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - 浏览器额外的“工具”菜单项: Sun Java 控制台 -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - 浏览器额外的按钮: Web Anti-Virus -

{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky

Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - 浏览器额外的按钮: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -

C:\WINNT\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links -

{c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - (no

file)
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ -

{c95fe080-8f5d-11d2-a20b-00aa003c157b} - (no file)
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} -

C:\PROGRA~1\FlashGet\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet -

{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage

Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {BD540752-A141-4AB7-8A6C-4EB19A7E11A9} -

http://vod.ecjtu.jx.cn/vod/manager/ocx/upload.CAB
O16 - DPF: {C661F36D-DF85-4EF4-83C7-E107B83D04B1} (WebActivater Control) -

http://dl_dir.qq.com/3dshow/3DShowVM.cab
O17 -

HKLM\System\CCS\Services\Tcpip\..\{8DA58ECD-A2E3-414D-BBF5-C780C9B0F4BF}:

NameServer = 202.101.208.3,202.101.224.68,202.101.208.4,202.101.226.68
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: klogon - C:\WINNT\system32\klogon.dll
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) -

VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: ewido security suite control - ewido networks - C:\Program

Files\ewido anti-malware\ewidoctrl.exe
O23 - NT 服务: ewido security suite guard - ewido networks - C:\Program

Files\ewido anti-malware\ewidoguard.exe
O23 - NT 服务: Macromedia Licensing Service - Unknown owner - C:\Program

Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - NT 服务: ManageEngine OpManager (OpManager) - Unknown owner -

C:\Program Files\AdventNet\ME\OpManager\wrapper.exe" -s .\conf\wrapper.conf

(file missing)
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing

Rising Technology Co., Ltd. - D:\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co.,

Ltd. - D:\Rising\Rav\Ravmond.exe
O23 - NT 服务: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) -

Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f

"%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

gototop
 

O23 - NT 服务: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) -

Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f

"%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

这个是安装网络执法官的时候提示安装的
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT