瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】卡卡、瑞星升级被劫持了

1   1  /  1  页   跳转

【求助】卡卡、瑞星升级被劫持了

【求助】卡卡、瑞星升级被劫持了

最近机器无故多了一个i.exe进程,hosts文件也反复被篡改,刚删除里面的内容,一会又出现了,多数是指向与瑞星有关的网页,所以卡卡出现升不了级,进不了瑞星网站,用瑞星2006(升级到18.53)、卡卡助手也(3.0.0.8)扫描不到有病毒,现将hosts和卡卡扫描出的i.exe的相关内容附在后面,请高手分手,并指出解决办法。
hosts文件内容如下:

125.91.14.230 www.kzdh.com
125.91.14.230 www.7255.com
125.91.14.230 www.7322.com
125.91.14.230 www.7939.com
125.91.14.230 www.piaoxue.com
125.91.14.230 www.feixu.net
125.91.14.230 www.6781.com
125.91.14.230 www.7b.com.cn
125.91.14.230 7b.com.cn
125.91.14.230 www.918188.com
125.91.14.230 hao.allxue.com
125.91.14.230 good.allxue.com
125.91.14.230 baby.allxue.com
125.91.14.230 www.allxue.com
125.91.14.230 about.lank.la
125.91.14.230 www.x114x.com
125.91.14.230 www.37ss.com
125.91.14.230 www.7k.cc
125.91.14.230 www.73ss.com
125.91.14.230 www.hao123.com
125.91.14.230 www.81915.com
125.91.14.230 222.88.90.22
125.91.14.230 www.9991.com
125.91.14.230 www.my123.com
125.91.14.230 www.haokan123.com
125.91.14.230 www.5566.net
125.91.14.230 www.gjj.cc
125.91.14.230 www.2345.com
125.91.14.230 dl.hao318.com
125.91.14.230 www.123wa.com
125.91.14.230 www.ku886.com
125.91.14.230 www.5icrack.com
125.91.14.230 www.jjol.cn
127.0.0.1 www.rising.com.cn
127.0.0.1 tool.ikaka.com
127.0.0.1 www.ikaka.com
127.0.0.1 update.rising.com.cn
127.0.0.1 online.rising.com.cn
127.0.0.1 up.rising.com.cn
127.0.0.1 go.rising.com.cn
127.0.0.1 it.rising.com.cn
127.0.0.1 rising.com.cn
127.0.0.1 ikaka.com



卡卡扫描i.exe进程的相关内容如下:
[i.exe]
PID = 0x484
CommandLine = "C:\program files\Rising\AntiSpyware\Ras.exe"
    i.exe
    0x1000000
    C:\WINDOWS\system32\i.exe
    5.1.2600.0 (xpclient.010817-1148)
    Microsoft Corporation
    Run a DLL as an App
    2002-10-07 12:00:00

    ntdll.dll
    0x77f50000
    C:\WINDOWS\system32\ntdll.dll
    5.1.2600.1217 (xpsp2.030429-2131)
    Microsoft Corporation
    NT Layer DLL
    2003-05-01 16:57:50

    kernel32.dll
    0x77e40000
    C:\WINDOWS\system32\kernel32.dll
    5.1.2600.1560 (xpsp2_gdr.040517-1325)
    Microsoft Corporation
    Windows NT BASE API Client DLL
    2004-06-18 02:31:30

    msvcrt.dll
    0x77be0000
    C:\WINDOWS\system32\msvcrt.dll
    7.0.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    Windows NT CRT DLL
    2002-10-07 12:00:00

    GDI32.dll
    0x7f000000
    C:\WINDOWS\system32\gdi32.dll
    5.1.2600.1789 (xpsp2.051228-1438)
    Microsoft Corporation
    GDI Client DLL
    2006-01-03 06:38:18

    ADVAPI32.dll
    0x77da0000
    C:\WINDOWS\system32\advapi32.dll
    5.1.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    Advanced Windows 32 Base API
    2002-10-07 12:00:00

    RPCRT4.dll
    0x78000000
    C:\WINDOWS\system32\rpcrt4.dll
    5.1.2600.1361 (xpsp2.040109-1800)
    Microsoft Corporation
    Remote Procedure Call Runtime
    2004-03-06 10:17:32

    USER32.dll
    0x77d10000
    C:\WINDOWS\system32\user32.dll
    5.1.2600.1634 (xpsp2.050301-1526)
    Microsoft Corporation
    Windows XP USER API Client DLL
    2005-03-03 02:21:30

    IMAGEHLP.dll
    0x76c60000
    C:\WINDOWS\system32\imagehlp.dll
    5.1.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    Windows NT Image Helper
    2002-10-07 12:00:00

    IMM32.DLL
    0x76300000
    C:\WINDOWS\system32\imm32.dll
    5.1.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    Windows XP IMM32 API Client DLL
    2002-10-07 12:00:00

    LPK.DLL
    0x62c20000
    C:\WINDOWS\system32\lpk.dll
    5.1.2600.0 (xpclient.010817-1148)
    Microsoft Corporation
    Language Pack
    2002-10-07 12:00:00

    USP10.dll
    0x72f10000
    C:\WINDOWS\system32\usp10.dll
    1.0409.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    Uniscribe Unicode script processor
    2002-10-07 12:00:00

    6.sys
    0x920000
    C:\WINDOWS\system32\drivers\6.sys
   
   
   
    2006-11-27 13:41:56

    WSOCK32.DLL
    0x71a40000
    C:\WINDOWS\system32\wsock32.dll
    5.1.2600.0 (xpclient.010817-1148)
    Microsoft Corporation
    Windows Socket 32-Bit DLL
    2002-10-07 12:00:00

    WS2_32.dll
    0x71a20000
    C:\WINDOWS\system32\ws2_32.dll
    5.1.2600.0 (xpclient.010817-1148)
    Microsoft Corporation
    Windows Socket 2.0 32-Bit DLL
    2002-10-07 12:00:00

    WS2HELP.dll
    0x71a10000
    C:\WINDOWS\system32\ws2help.dll
    5.1.2600.0 (xpclient.010817-1148)
    Microsoft Corporation
    Windows Socket 2.0 Helper for Windows NT
    2002-10-07 12:00:00

    SHELL32.DLL
    0x773a0000
    C:\WINDOWS\system32\shell32.dll
    6.00.2800.1816 (xpsp2.060316-1527)
    Microsoft Corporation
    Windows Shell Common Dll
    2006-03-17 13:04:50

    SHLWAPI.dll
    0x772a0000
    C:\WINDOWS\system32\SHLWAPI.DLL
    6.00.2800.1740 (xpsp2.050831-1533)
    Microsoft Corporation
    Shell Light-weight Utility Library
    2005-09-01 09:51:50

    comctl32.dll
    0x78090000
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.1816_x-ww_7d33ba0e\comctl32.dll
    6.0 (xpsp2.060316-1527)
    Microsoft Corporation
    User Experience Controls Library
    2006-03-16 22:04:46

    comctl32.dll
    0x77310000
    C:\WINDOWS\system32\comctl32.dll
    5.82 (xpsp1.020828-1920)
    Microsoft Corporation
    Common Controls Library
    2002-10-07 12:00:00

    uxtheme.dll
    0x5adc0000
    C:\WINDOWS\system32\uxtheme.dll
    6.00.2800.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    Microsoft UxTheme Library
    2002-10-07 12:00:00

    MSCTF.dll
    0x74680000
    C:\WINDOWS\system32\MSCTF.dll
    5.1.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    MSCTF Server DLL
    2002-10-07 12:00:00

    vvvvv.dll
    0xe40000
    C:\WINDOWS\system32\vvvvv.dll
   
   
   
    2006-11-27 13:41:56

    msctfime.ime
    0xea0000
    C:\WINDOWS\system32\MSCTFIME.IME
    5.1.2600.1106 (xpsp1.020828-1920)
    Microsoft Corporation
    Microsoft Text Frame Work Service IME
    2002-10-07 12:00:00

    ole32.dll
    0x4fec0000
    C:\WINDOWS\system32\ole32.dll
    5.1.2600.1720 (xpsp2.050722-1526)
    Microsoft Corporation
    Microsoft OLE for Windows
    2005-07-26 12:38:28
最后编辑2007-11-08 14:31:30
分享到:
gototop
 

问题已解决,非常感谢
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT