您的位置:首页 > 运维架构 > 网站架构

运行QQ提示找不到SVHUVS.DLL?一些安全网站打不开?修复~

2008-10-19 11:21 369 查看
运行QQ提示找不到SVHUVS.DLL?一些安全网站打不开?修复~

 

endurer 原创
2008-10-19 第1版

 

前天,一位同事说他的电脑,在运行QQ时提示找不到文件SVHUVS.DLL,另外有网站打不开,进安全模式会蓝屏。请偶帮忙检修。

 



 

同事的电脑中装有瑞星和360卫士。先Google一下SVHUVS.DLL是什么东东,不料Google网站打不开。换sogou,可以正常打开,搜索得知SVHUVS.DLL是个恶意文件。

想下载金山清理专家可以修复安全模式(偶都在卡卡论坛提了几次了,可瑞星卡卡安全助手还是没有加入这个功能),不料打开金山毒霸的网站没打开,电脑却蓝屏了。

重启电脑,下载 pe_xscan 扫描 log并分析,发现如下可疑项:

pe_xscan 08-08-01 by Purple Endurer
2008-10-17 12:3:21
Windows XP Service Pack 2(5.1.2600)
MSIE:7.0.5730.13
管理员用户组
正常模式

O1 - Hosts: 219.235.3.16    search.114.vnet.cn
O1 - Hosts: 219.235.3.16    keyword.vnet.cn
O1 - Hosts: 219.235.3.16    auto.search.msn.com
O1 - Hosts: 219.235.3.16    search.msn.com
O1 - Hosts: 219.235.3.16    cnweb.search.live.com
O1 - Hosts: 219.235.3.16    www.k369.com
O1 - Hosts: 219.235.3.16    www.5566.net
O1 - Hosts: 219.235.3.16    360.cn
O1 - Hosts: 219.235.3.16    360.qihoo.com
O1 - Hosts: 219.235.3.16    360safe.qihoo.com
O1 - Hosts: 219.235.3.16    forum.ikaka.com
O1 - Hosts: 219.235.3.16    www.ikaka.com
O1 - Hosts: 202.165.102.243 update.ikaka.com
O1 - Hosts: 219.235.3.16    forum.jiangmin.com
O1 - Hosts: 202.165.102.243 update.jiangmin.com
O1 - Hosts: 219.235.3.16    tieba.baidu.com
O1 - Hosts: 219.235.3.16    post.baidu.com
O1 - Hosts: 219.235.3.16    zhidao.baidu.com
O1 - Hosts: 219.235.3.16    www.baidu.com
O1 - Hosts: 202.165.102.243 update.rising.com.cn
O1 - Hosts: 219.235.3.16    online.rising.com.cn
O1 - Hosts: 202.165.102.243 center.rising.com.cn
O1 - Hosts: 219.235.3.16    up.duba.net
O1 - Hosts: 219.235.3.16    vi.duba.net
O1 - Hosts: 219.235.3.16    shadu.baidu.com
O1 - Hosts: 219.235.3.16    du.baidu.com
O1 - Hosts: 219.235.3.16    security.symantec.com
O1 - Hosts: 219.235.3.16    shadu.duba.net
O1 - Hosts: 219.235.3.16    bbs.duba.net
O1 - Hosts: 219.235.3.16    online.jiangmin.com
O1 - Hosts: 219.235.3.16    cn.mcafee.com
O1 - Hosts: 219.235.3.16    www.ahn.com.cn
O1 - Hosts: 219.235.3.16    www.kaspersky.com.cn
O1 - Hosts: 219.235.3.16    www.pcav.cn
O1 - Hosts: 219.235.3.16    www.luosoft.com
O1 - Hosts: 219.235.3.16    www.im286.com
O1 - Hosts: 219.235.3.16    an.baidu.com
O1 - Hosts: 219.235.3.16    ma.baidu.com
O1 - Hosts: 219.235.3.16    bbs.htmlman.net
O1 - Hosts: 202.165.102.243 download.rising.com.cn
O1 - Hosts: 202.165.102.243 rsup08.rising.com.cn
O1 - Hosts: 219.235.3.16    10000.286er.com
O1 - Hosts: 219.235.3.16    im286.net
O1 - Hosts: 219.235.3.16    ju.qihoo.com
O1 - Hosts: 219.235.3.16    bbs.chinaz.com
O1 - Hosts: 219.235.3.16    www.qihoo.com
O1 - Hosts: 202.165.102.243 dnl-cn1.kaspersky-labs.com
O1 - Hosts: 202.165.102.243 dnl-cn2.kaspersky-labs.com
O1 - Hosts: 202.165.102.243 dnl-cn3.kaspersky-labs.com
O1 - Hosts: 202.165.102.243 dnl-cn4.kaspersky-labs.com
O1 - Hosts: 202.165.102.243 dnl-cn5.kaspersky-labs.com
O1 - Hosts: 202.165.102.243 dnl-cn6.kaspersky-labs.com
O1 - Hosts: 202.165.102.243 dnl-cn7.kaspersky-labs.com
O1 - Hosts: 202.165.102.243 dnl-cn8.kaspersky-labs.com
O1 - Hosts: 202.165.102.243 dnl-cn9.kaspersky-labs.com
O1 - Hosts: 202.165.102.243 dnl-cn10.kaspersky-labs.com
O1 - Hosts: 202.165.102.243 dnl-cn11.kaspersky-labs.com
O1 - Hosts: 202.165.102.243 dnl-cn12.kaspersky-labs.com
O1 - Hosts: 202.165.102.243 dnl-cn13.kaspersky-labs.com
O1 - Hosts: 202.165.102.243 dnl-cn14.kaspersky-labs.com
O1 - Hosts: 202.165.102.243 dnl-cn15.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-eu1.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-eu2.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-eu3.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-eu4.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-eu5.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-eu6.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-eu7.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-eu8.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-eu9.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-eu10.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-eu11.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-eu12.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-eu13.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-eu14.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-eu15.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-us1.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-us2.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-us3.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-us4.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-us5.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-us6.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-us7.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-us8.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-us9.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-us10.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-us11.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-us12.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-us13.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-us14.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-us15.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-ru1.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-ru2.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-ru3.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-ru4.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-ru5.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-ru6.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-ru7.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-ru8.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-ru9.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-ru10.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-ru11.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-ru12.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-ru13.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-ru14.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-ru15.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-jp1.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-jp2.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-jp3.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-jp4.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-jp5.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-jp6.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-jp7.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-jp8.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-jp9.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-jp10.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-jp11.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-jp12.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-jp13.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-jp14.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-jp15.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-kr1.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-kr2.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-kr3.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-kr4.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-kr5.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-kr6.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-kr7.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-kr8.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-kr9.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-kr10.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-kr11.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-kr12.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-kr13.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-kr14.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-kr15.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-cd1.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-cd2.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-cd3.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-cd4.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-cd5.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-cd6.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-cd7.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-cd8.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-cd9.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-cd10.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-cd11.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-cd12.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-cd13.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-cd14.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    dnl-cd15.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    downloads1.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    downloads2.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    downloads3.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    downloads4.kaspersky-labs.com
O1 - Hosts: 202.165.102.243    downloads5.kaspersky-labs.com
O1 - Hosts: 219.235.3.16       ishare.sina.com.cn
O1 - Hosts: 219.235.3.16       search.cn.yahoo.com
O1 - Hosts: 219.235.3.16       www.google.com
O1 - Hosts: 219.235.3.16       google.com
O1 - Hosts: 219.235.3.16       www.google.cn
O1 - Hosts: 219.235.3.16       www.yahoo.com.cn
O1 - Hosts: 219.235.3.16       cn.yahoo.com
O1 - Hosts: 219.235.3.16       search.tom.com
O1 - Hosts: 219.235.3.16       zhuansha.duba.net
O1 - Hosts: 219.235.3.16       buy.duba.net
O1 - Hosts: 219.235.3.16       client.download.duba.net
O1 - Hosts: 219.235.3.16       page.so.163.com
O1 - Hosts: 219.235.3.16       www.soso.com
O1 - Hosts: 219.235.3.16       sou.china.com
O1 - Hosts: 219.235.3.16       test.591jx.com
O1 - Hosts: 219.235.3.16       a.topxxxx.cn
O1 - Hosts: 219.235.3.16       picon.chinaren.com
O1 - Hosts: 219.235.3.16       www.5566.net

O21 - SSODL - qtfstqywi() - {ed5810ca-65d0-ba25-76e1-65d09842c225} = C:/WINDOWS/system32/loanoltrd.dll

 

原来恶意程序修改了hosts文件(HijackThis/pe_xscan log中的O1项)。

在其它电脑上下载了金山清理专家,用U盘拷过来,运行,先修复安全模式,然后检测恶意程序,检测出了2个,清理了;提示hosts被恶意修改,修复。检测到了HijackThis/pe_xscan log中的O21项可疑,却没法处理。

还是下载 HijackThis备用罢。

重启电脑到安全模式,这次没蓝屏,可以正常进入。运行HijackThis,修复O21项,却发现O1项并没有被金山清理专家修复,用HijackThis修复。

重启电脑测试,Google,瑞星等网站可以正常打开了~

重新下载安装QQ~
内容来自用户分享和网络整理,不保证内容的准确性,如有侵权内容,可联系管理员处理 点击这里给我发消息
相关文章推荐