123   3  /  3  页   跳转

比较严重的中毒事件--求助

我前面关于Autoruns回复的很清楚了

你现在贴上的图片,只能说明现象,又不能让大家帮助你找到问题的所在啊
gototop
 

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ CdnCtrLiveUpdate Modulec:\program files\cnnic\cdn\cdnup.exe

+ IMJPMIG8.1File not found: ;

+ KernelFaultCheckFile not found: ;

+ microsft UpdatesFile not found: ;

+ MSPY2002File not found: ;

+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.d:\program files\rising\rav\ravmon.exe

+ RavTimerRavTimerBeijing Rising Technology Co., Ltd.d:\program files\rising\rav\ravtimer.exe

+ Super Rabbit SRRestoreSuper Rabbit System RestoreSuper Rabbit Softe:\超级兔子\magicset\srrest.exe

+ SysExplrFile not found: ;

+ Systemc:\windows\system32\kernels32.exe

+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe

+ WindowsUpdateNTc:\windows\system\svwhost.exe

+ xv_crtlFile not found: ;

C:\Documents and Settings\All Users\「开始」菜单\程序\启动

+ Adobe Gamma Loader.lnkAdobe Gamma LoaderAdobe Systems, Inc.c:\program files\common files\adobe\calibration\adobe gamma loader.exe

C:\Documents and Settings\11\「开始」菜单\程序\启动

+ 腾讯QQ.lnkQQTENCENTe:\qq\新建文件夹\qq\qq.exe

+ 腾讯TM.lnkTMShell Microsoft 基础类应用程序e:\qq\新建文件夹\qq\tmshell.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

+ MsnMsgrFile not found: ;

+ Windows installerc:\winstall.exe

+ WindowsUpdateNTFile not found: C

HKLM\System\CurrentControlSet\Services

+ cmdServicec:\windows\sw1hz2u\command.exe

+ RsCCenterCCenterrisingd:\program files\rising\rav\ccenter.exe

+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.d:\program files\rising\rav\ravmond.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler

+ DDEFile not found: C:\WINDOWS\System32\birdihuy32.dll

+ ModuleFile not found: C:\WINDOWS\System32\chp.dll

+ st3c:\windows\system32\st3.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

+ EIFBHFCDFile not found: C:\WINDOWS\System32\Bimbckei.dll

+ mtkleFile not found: C:\WINDOWS\System32\iatjw32.dll

+ SysTray.ExshFile not found: C:\WINDOWS\System32\qnlhmlgp.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ cqedui.dllFile not found: C:\WINDOWS\system32\cqedui.dll

+ Display Panning CPL ExtensionFile not found: deskpan.dll

+ dyrawex.dllFile not found: C:\WINDOWS\system32\dyrawex.dll

+ guard.tmpFile not found: C:\WINDOWS\system32\guard.tmp

+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\windows\system32\hticons.dll

+ imsutil.dllFile not found: C:\WINDOWS\system32\imsutil.dll

+ InprocServer32File not found: CLSID\{87627F8E-5144-4161-BB31-3608E45C01F7}\InprocServer32

+ ioxpromn.dllFile not found: C:\WINDOWS\system32\ioxpromn.dll

+ kqdhu1.dllFile not found: C:\WINDOWS\system32\kqdhu1.dll

+ mEg_hook.dllFile not found: C:\WINDOWS\system32\mEg_hook.dll

+ mjgentr.dllFile not found: C:\WINDOWS\system32\mjgentr.dll

+ mmimsg.dllc:\windows\system32\mmimsg.dll

+ mthtml.dllFile not found: C:\WINDOWS\system32\mthtml.dll

+ obbccp32.dllFile not found: C:\WINDOWS\system32\obbccp32.dll

+ otbcp32r.dllFile not found: C:\WINDOWS\system32\otbcp32r.dll

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

+ Shell Extensions for RealOne PlayerRealOne Player Shell ExtensionsRealNetworksc:\program files\real\realone player\rpshellext.dll

+ ssnsapi.dllFile not found: C:\WINDOWS\system32\ssnsapi.dll

+ swcur32.dllc:\windows\system32\swcur32.dll

+ tjappcmp.dllFile not found: C:\WINDOWS\system32\tjappcmp.dll

+ uqildll.dllFile not found: C:\WINDOWS\system32\uqildll.dll

+ wjwfax.dllFile not found: C:\WINDOWS\system32\wjwfax.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ C:\WINDOWS\adsldpbd.dllc:\windows\adsldpbd.dll

+ CNNIC_IDNCndnIEHelper Modulec:\program files\cnnic\cdn\cdniehlp.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ FlashGet BarFlashGet IE BarAmaze Softc:\program files\flashget\fgiebar.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ @shdoclc.dll,-864c:\windows\web\related.htm

+ 腾讯QQQQTENCENTe:\qq\新建文件夹\qq\qq.exe

Task Scheduler

+ DDD_Install_Program.jobFile not found: C:\DOCUME~1\11\LOCALS~1\Temp\remotesetup.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ gggggc:\windows\adsldpbd.dll

+ ShellCompatibilityc:\windows\system32\lvns0957e.dll

+ st3c:\windows\system32\st3.dll

gototop
 

是这个吗?
gototop
 

比较多

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ Systemc:\windows\system32\kernels32.exe
+ WindowsUpdateNTc:\windows\system\svwhost.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
+ Windows installerc:\winstall.exe
HKLM\System\CurrentControlSet\Services
+ cmdServicec:\windows\sw1hz2u\command.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
+ st3c:\windows\system32\st3.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ mtkleFile not found: C:\WINDOWS\System32\iatjw32.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ imsutil.dllFile not found: C:\WINDOWS\system32\imsutil.dll
+ mmimsg.dllc:\windows\system32\mmimsg.dll
+ swcur32.dllc:\windows\system32\swcur32.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ C:\WINDOWS\adsldpbd.dllc:\windows\adsldpbd.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
HKLM\Software\Microsoft\Internet Explorer\Extensions
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
+ gggggc:\windows\adsldpbd.dll
+ ShellCompatibilityc:\windows\system32\lvns0957e.dll
+ st3c:\windows\system32\st3.dll

先用Autoruns禁用启动项,还有那些 not find,
重启,再删除相应的文件

工具的具体细节看Autoruns的帖子
gototop
 
123   3  /  3  页   跳转
页面顶部
Powered by Discuz!NT