瑞星卡卡安全论坛

首页 » 技术交流区 » 系统软件 » 请高手帮我看看,我是菜鸟不会呀!!!!
叶子鸟 - 2006-6-9 19:25:00
我是电脑菜鸟,才学的,家里买了个电脑上网,可是这几天我实在没办法了,只要我用Internet Explorer上网站的话机子就会重起,玩其他的一点事也没有,还有我用腾讯TT上网站的话也没事,我估计可能是中木马了,可是我删不了,这是有人教我用SREng.exe扫描出来的日志报告,请高手帮我看看,发现木马,病毒请教我怎么样弄成吗?我可是个菜鸟,2006-06-09,19:10:10

System Repair Engineer 2.0.12.350 (2.0 RC 1)
    Windows XP Professional Service Pack 1 - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <load><>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <run><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <CnsMin><Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <SoundMan><rem SOUNDMAN.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <YDTMain.exe><C:\PROGRA~1\YDT\YDTMain.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <shell><EXPLORER.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <AppInit_DLLs><>

==================================
启动文件夹
服务
[Rising Proxy  Service / RfwProxySrv]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[winaua / winaua]
  <C:\DOCUME~1\BLUEWA~1\LOCALS~1\Temp\aua1\aua1.exe -R><N/A>

==================================
叶子鸟 - 2006-6-9 19:25:00
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\System32\xunleibho_v8.dll, >
[VnetCookie Class]
  {4E83D567-4697-4F7B-B1F0-A513B01DB89A} <c:\PROGRA~1\chinanet\VNETTR~1.DLL, >
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <E:\联众\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Google Toolbar Helper]
  {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar.dll, N/A>
[CnsHook Class]
  {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\downlo~1\CnsHook.dll, 北京三七二一科技有限公司>
[DragSearch BHO]
  {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} <C:\PROGRA~1\yisou\yisoub.dll, >
[Yahoo 1G电邮]
  {507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A>
[寻宝乐趣多]
  {59BC54A2-56B3-44a0-93E5-432D58746E26} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao, N/A>
[雅虎助手]
  {5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <E:\联众\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <E:\联众\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[情景聊天]
  {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg, N/A>
[]
  {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A>
[]
  {FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar.dll, N/A>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\fgiebar.dll, Amaze Soft>
[一搜工具条]
  {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} <C:\Program Files\yisou\yisou.dll, 3721>
[PowerPlr Control]
  {2354A44B-3CEB-4829-9940-545B03103538} <C:\WINDOWS\DOWNLO~1\PowerPlr.ocx, Powerise Digital>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\System32\wuweb.dll, Microsoft Corporation>
[Filetran Control]
  {88734439-46D0-42C0-A13F-7E881EE550CF} <C:\PROGRA~1\Bluesky\BLUESK~1\filetran.ocx, N/A>
[LoaderCore Class]
  {98A62E3F-A8C5-4EF0-8A00-C70CF9D18A89} <C:\WINDOWS\Downloaded Program Files\DLLoader.dll, sohu.com>
[Kingsoft DUBA OnlineScan]
  {C8BD9ACB-F7EC-48E6-BB2F-DAADC6789E9A} <C:\WINDOWS\System32\kingsoft\ONLINE~1\kavclean.ocx, kingsoft>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\flash.ocx, Macromedia, Inc.>
[VqqSpeedDlProxy Class]
  {F138084D-84D7-48CD-BEA8-04772457516E} <C:\WINDOWS\vqqsdl.dll, Tencent>
[!搜一搜]
  <res://C:\Program Files\yisou\yisou.dll/232, N/A>
[&Google Search]
  <res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html, N/A>
[&使用迅雷下载]
  <C:\Program Files\Sandai Technologies Inc\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <C:\Program Files\Sandai Technologies Inc\Thunder\getallurl.htm, N/A>
[上传到QQ网络硬盘]
  <E:\联众\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <E:\联众\AddPanel.htm, N/A>
[添加到QQ表情]
  <E:\联众\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <E:\联众\SendMMS.htm, N/A>
叶子鸟 - 2006-6-9 19:26:00
==================================
正在运行的进程
[PID: 432][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 484][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 516][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.1557 (xpsp2_gdr.040517-1325)>
    [C:\WINDOWS\System32\CHENHU4.IME]  <chenhu><5.5>
[PID: 560][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 572][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 712][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 780][C:\Program Files\Rising\Rav\CCenter.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 796][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 904][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 932][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 952][C:\Program Files\Rising\Rav\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 22>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsLog.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
    [C:\Program Files\Rising\Rav\HOOKSYS.dll]  <Rising><18, 1, 0, 9>
    [C:\Program Files\Rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [C:\Program Files\Rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\regmon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\HookWeb.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\MemMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\expscan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
    [C:\Program Files\Rising\Rav\MailMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Rising\Rav\SpamEng.dll]  <N/A><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
    [C:\Program Files\Rising\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 15>
    [C:\Program Files\Rising\Rav\Unpacker.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[PID: 1060][c:\program files\rising\rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 32>
    [c:\program files\rising\rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
    [c:\program files\rising\rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [c:\program files\rising\rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
    [c:\program files\rising\rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [c:\program files\rising\rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[PID: 1160][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.1699 (xpsp2.050610-1533)>
[PID: 1236][C:\Program Files\Rising\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1524][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\System32\CHENHU4.IME]  <chenhu><5.5>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\WINDOWS\downlo~1\CnsHook.dll]  <北京三七二一科技有限公司><1, 0, 2, 4>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [D:\新建文件夹\ske\contmenu.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\xunleibho_v8.dll]  <><4, 5, 1, 33>
    [C:\PROGRA~1\yisou\yisoub.dll]  <><1, 1, 2, 4>
[PID: 1740][c:\program files\rising\rfw\RfwMain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 51>
    [c:\program files\rising\rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [c:\program files\rising\rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [c:\program files\rising\rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\WINDOWS\System32\CHENHU4.IME]  <chenhu><5.5>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
[PID: 1900][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1920][C:\WINDOWS\system32\cisvc.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1988][C:\DOCUME~1\BLUEWA~1\LOCALS~1\Temp\aua1\aua1.exe]  <N/A><N/A>
[PID: 640][C:\WINDOWS\System32\wuauclt.exe]  <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[PID: 856][C:\WINDOWS\System32\Rundll32.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\WINDOWS\System32\CHENHU4.IME]  <chenhu><5.5>
[PID: 1332][C:\Program Files\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\WINDOWS\System32\CHENHU4.IME]  <chenhu><5.5>
[PID: 1368][C:\WINDOWS\System32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\WINDOWS\System32\CHENHU4.IME]  <chenhu><5.5>
[PID: 1404][C:\Program Files\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 19>
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\WINDOWS\System32\CHENHU4.IME]  <chenhu><5.5>
叶子鸟 - 2006-6-9 19:27:00
[PID: 1676][C:\Program Files\Rising\Rav\RsAgent.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\WINDOWS\System32\CHENHU4.IME]  <chenhu><5.5>
[PID: 1344][C:\WINDOWS\msagent\AgentSvr.exe]  <Microsoft Corporation><2.00.0.3422>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\WINDOWS\System32\CHENHU4.IME]  <chenhu><5.5>
[PID: 316][C:\Program Files\Chinanet\VnetClient.exe]  <><2005, 11, 14, 1>
    [C:\Program Files\Chinanet\Communicate.dll]  <0><2005, 3, 3, 1>
    [C:\Program Files\Chinanet\DialModule.dll]  <GDCN><2005, 11, 15, 1>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\PROGRA~1\Chinanet\CLIENT~1.DLL]  <><2004, 2, 28, 1>
    [C:\WINDOWS\System32\CHENHU4.IME]  <chenhu><5.5>
    [C:\PROGRA~1\Chinanet\PLUGIN~1.OCX]  <><2005, 7, 27, 1>
    [C:\PROGRA~1\Chinanet\sign.dll]  <0><2004, 12, 1, 1>
    [C:\PROGRA~1\Chinanet\WEBPLU~1.DLL]  <><2005, 8, 18, 1>
    [C:\PROGRA~1\Chinanet\PostPlug.dll]  <><2004, 12, 16, 2>
    [C:\PROGRA~1\Chinanet\ADVERT~1.OCX]  <><2005, 10, 13, 1>
    [C:\PROGRA~1\Chinanet\Gif89a.dll]  <><2005, 6, 21, 1>
    [C:\PROGRA~1\Chinanet\VnetBs.ocx]  <><2004, 11, 18, 1>
    [C:\PROGRA~1\Chinanet\ACCOUN~2.DLL]  <><2005, 11, 14, 1>
    [C:\PROGRA~1\Chinanet\AccountMgr.dll]  <><2005, 11, 14, 17>
    [C:\PROGRA~1\Chinanet\VnetSkin.ocx]  <GDDC><2005, 11, 14, 1>
    [C:\PROGRA~1\Chinanet\DialogStyle.dll]  <><1, 0, 0, 1>
    [C:\PROGRA~1\Chinanet\Timer.ocx]  <><2005, 10, 9, 14>
    [C:\PROGRA~1\Chinanet\PLUGIN~2.OCX]  <><2005, 2, 24, 1>
    [C:\PROGRA~1\Chinanet\NEWMES~1.DLL]  <><2005, 8, 26, 1>
    [C:\PROGRA~1\Chinanet\PassCtrl.dll]  <><1, 0, 0, 1>
    [C:\PROGRA~1\Chinanet\PlugPush.dll]  <><2004, 12, 21, 1>
    [C:\PROGRA~1\Chinanet\ALLINT~1.DLL]  <><2004, 11, 23, 1>
    [C:\PROGRA~1\Chinanet\VNetLog.ocx]  <><2005, 10, 9, 1>
    [C:\PROGRA~1\Chinanet\StatNum.dll]  <><2004, 11, 18, 1>
    [C:\PROGRA~1\Chinanet\VNETON~1.OCX]  <><2005, 3, 2, 1>
    [C:\PROGRA~1\Chinanet\ALLFUN~1.DLL]  <GDCN><2005, 10, 9, 1>
    [C:\PROGRA~1\Chinanet\VnetOptLog.dll]  <><2005, 9, 13, 9>
    [C:\PROGRA~1\Chinanet\DlgSkin.ocx]  <><2005, 11, 14, 1>
    [C:\WINDOWS\flash.ocx]  <Macromedia, Inc.><7,0,19,0>
[PID: 776][C:\Program Files\Tencent\TT\TTraveler.exe]  <深圳市腾讯计算机系统有限公司><1. 6. 8. 157>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\WINDOWS\System32\CHENHU4.IME]  <chenhu><5.5>
    [C:\WINDOWS\downlo~1\CnsHook.dll]  <北京三七二一科技有限公司><1, 0, 2, 4>
    [C:\Program Files\Tencent\TT\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
    [C:\WINDOWS\flash.ocx]  <Macromedia, Inc.><7,0,19,0>
[PID: 2152][C:\新建文件夹\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\WINDOWS\System32\CHENHU4.IME]  <chenhu><5.5>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
叶·幽思 - 2006-6-9 19:49:00
你在安全模式下那些文件也删不掉吗?
叶子鸟 - 2006-6-9 19:54:00
是呀,我实在没办法了
叶·幽思 - 2006-6-9 20:00:00
这个软件我用的次数不多,先看看.呆会给你答案.
叶·幽思 - 2006-6-9 20:05:00
你先看一下那篇帖子,试着删除流氓软件~
叶子鸟 - 2006-6-9 20:24:00
我用了,删了些软件了,可是我用Internet Explorer上网页还是会重起,这是什么原因呀????


叶·幽思 - 2006-6-9 20:35:00
那些病毒你删了没啊?
叶·幽思 - 2006-6-9 20:43:00
结束以下进程:

[PID: 1420][C:\WINDOWS\System32\rundll32.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>

[C:\WINDOWS\System32\STDSVER.DLL] <><3, 2, 1, 6>
[C:\WINDOWS\System32\CHENHU4.IME] <chenhu><5.5>

[PID: 1524][C:\DOCUME~1\BLUEWA~1\LOCALS~1\Temp\aua1\aua1.exe] <N/A><N/A>

结束不了用Icesword ,http://forum.ikaka.com/topic.asp?board=28&artid=6979213  2楼

删除文件用:killbox,http://forum.ikaka.com/topic.asp?board=28&artid=6979213  3楼

服务里禁用:

QoS Service / BNESS
StdService
winaua

删除:

C:\DOCUME~1\BLUEWA~1\LOCALS~1\Temp\aua1\aua1.exe
C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\STDSVER.DLL
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL
C:\Program Files\CoolWebsite\QuickLink.dll

yaoshihai ..............
我无邪 - 2006-6-9 21:26:00
建议你下载超级兔子。
http://www.pctutu.com/srmsdown.asp
安装好后,打开“超级兔子优化王”“专业卸载,卸载所有提示的垃圾软件。
双击我的电脑,工具,文件夹选项,查看,单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示确定更改时,单击“是”,清除“隐藏已知文件类型的扩展名

运行System Repair Engineer,点“启动项目,服务,勾选“隐藏微软服务”选中病毒服务winaua,选择“删除所选服务”“否”最后重启
删除
C:\DOCUME~1\BLUEWA~1\LOCALS~1\Temp删除这个文件夹中所有能删除的东东
C:\PROGRA~1\YDT
C:\PROGRA~1\yisou
C:\WINDOWS\downlo~1\CnsMin.dll
先这样试,看能不能解决你的问题。
叶·幽思 - 2006-6-9 21:44:00
学习了!以后要虚心点了~可能要我真的遇到了问题才知道怎么做~
汇汇 - 2006-6-9 21:57:00
IE重新安装一下
叶·幽思 - 2006-6-9 21:58:00
【回复“汇汇”的帖子】主要是楼主的机子里有木马病毒.
ADL - 2006-6-9 22:23:00
先清理流氓!禁用不必要的启动及服务项!

-----------------------------
3721

CnsMin

YDTMain.exe


aua1.exe(病毒!)

一搜

雅虎助手

搜一搜

-------------------------
----------------希望对你有帮助----------------
原创】Windows XP鲜为人知的70招 天剑星
http://forum.ikaka.com/topic.asp?board=3&artid=6926728

安装好Windows系统后必须做的10件事 kjb
http://forum.ikaka.com/topic.asp?board=3&artid=6926997

详解Windows系统中如何释放C盘空间 £光芒£
http://forum.ikaka.com/topic.asp?board=3&artid=6979849

Windows XP系统中可以被禁用的服务对照表
http://forum.ikaka.com/topic.asp?board=3&artid=6990365


ADL - 2006-6-9 22:26:00
恶意软件清理助手
http://www.skycn.com/soft/24604.html
现在网上的流氓软件越来越多,前些日子网络行业协会点名了十大流氓软件,这些软件的特点大多时强制安装,而且不容易卸载。
本软件即是针对这种情况编写的,软件目前可以清理下列流氓软件:
1.一搜工具条
2.完美网译通
3.CNIC中文上网
4.博采网摘
5.百度搜霸
6.3721上网助手
7.360搜
8.Dudu下载加速器
9.很棒小秘书
10.网络猪
11.划词搜索
...................
--------------------------------
下载后解压缩!
解压后直接运行RogueCleaner.exe
在线升级到最版本!
然后进"安全模式"杀流氓!

-----------------------
IE插件管理专家(upiea)
http://www.skycn.com/soft/21205.html
IE插件屏蔽突破了传统的插件屏蔽软件思维模式,插件屏蔽软件不仅仅能屏蔽插件!还可以识别当前已安装的插件!并可卸载插件! IE插件屏蔽在除了屏蔽插件的基本功能之外,更有令人侧目的创新!99.99%模拟Windows XP SP2的IE加载项功能,使2000以上Windows系统也可以具有Windows XP SP2的IE加载项功能,显示当前已安装的插件并可卸载插件这是目前任何一款插件屏蔽软件所不具备的,作者希望通过自己不懈的努力,让大家在上网的同时抢先享受无忧的乐趣!
Upiea 2005 SP1 发布增加:
扩容插件免疫定义库,可免疫659个插件
扩容隐私清理定义库,可清理58项
插件管理增加插件类型显示
IE设置-常规设置,搜索设置均增加选择引擎功能
IE设置-右键菜单,新建增加网摘类右键菜单选择
系统工具去除定时工具,增加2个系统工具
修正:
更新DUDU、3721、Yahoo助手插件卸载
IE设置-选项,修正部分工具栏按钮显示不正常
IE设置-菜单设置,修正无法保存修改
系统修复-系统文件备份修正备份文件存放目录。
1
查看完整版本: 请高手帮我看看,我是菜鸟不会呀!!!!