1   1  /  1  页   跳转

请教如何清除这个流氓插件

请教如何清除这个流氓插件

最近这几天在浏览网站时,总是自动弹出网页。大致就是这几个网站“http://61.129.102.144/xx/、http://www.ycdy.com/、http://www.vlog365.com/、http://www.vlog365.cn/”,并且自动在我的收藏夹中填加,使用瑞星卡卡上网助手修复时,提示有一个“未知,BHO插件,路径是C:\WINDOWS\system32\3721.5.dll”,使用瑞星卡卡禁止,可是机器一重启又有了。

附件附件:

下载次数:231
文件类型:image/pjpeg
文件大小:
上传时间:2006-10-19 23:46:49
描述:



最后编辑2006-10-20 16:19:46
分享到:
gototop
 

下面HijackThis v1.99.1日志
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
d:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
d:\Program Files\Rising\Rav\Ravmond.exe
d:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
d:\Program Files\Rising\Rav\RavStub.exe
d:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\mshosts.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
D:\Program Files\Rising\Rav\RavTask.exe
D:\Herosoft\HeroV8\SYSEXPLR.EXE
D:\Program Files\Rising\Rav\Ravmon.exe
D:\Program Files\Dr.COM\Dr.COM 宽带登录客户端\ishare_user.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Tencent\QQ\QQ.exe
d:\Program Files\Tencent\QQ\TMDlls\TIMPlatform.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\notepad.exe
E:\教程\瑞星2005\病毒专杀工具\ha_hijackthis_1991\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {69D23154-CA31-43E9-BEEB-F78E6D1642B3} - C:\WINDOWS\system32\3721.5.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RavTask] "d:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "d:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [SysExplr] d:\Herosoft\HeroV8\SYSEXPLR.EXE
O4 - HKLM\..\RunOnce: [RavStub] "d:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKLM\..\RunOnce: [WoptiClean] rundll32.exe "D:\Program Files\Wopti\WoptiCleanDll.dll",CleanNextBoot "D:\Program Files\Wopti\\WoptiClean"
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdog1.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdog1.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdog1.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdogr0.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdogr0.dll
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) -
gototop
 

http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{22C930E8-6969-48FE-9475-6D7DD9432EFD}: NameServer = 192.168.1.20
O17 - HKLM\System\CS1\Services\Tcpip\..\{22C930E8-6969-48FE-9475-6D7DD9432EFD}: NameServer = 192.168.1.20
O17 - HKLM\System\CS2\Services\Tcpip\..\{22C930E8-6969-48FE-9475-6D7DD9432EFD}: NameServer = 192.168.1.20
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: host Service For Windows (mshosts) - Unknown owner - C:\WINDOWS\mshosts.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - d:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - d:\Program Files\Rising\Rav\Ravmond.exe

手动删除那个3721.5.DLL也不行。请大家帮助解决一下。
gototop
 

晕,怎么没有人理我呀!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT