12   2  /  2  页   跳转

【求助】狂跳网页,电脑要死了

Logfile of HijackThis v1.99.1
Scan saved at 1:03:48, on 2006-9-21
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\csrss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\Ati2evxx.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\Ati2evxx.exe
H:\WINDOWS\Explorer.EXE
H:\KAV2006\KWatch.EXE
H:\WINDOWS\system32\spoolsv.exe
H:\program files\锐捷网络\ruijie supplicant\8021x.exe
H:\KAV2006\KAVStart.exe
H:\Program Files\Common Files\Real\Update_OB\realsched.exe
H:\KAV2006\KPFW32.EXE
H:\KAV2006\KMailMon.EXE
D:\Program Files\Tencent\QQ\TIMPlatform.exe
H:\WINDOWS\system32\msdtc.exe
H:\WINDOWS\system32\cisvc.exe
H:\WINDOWS\system32\inetsrv\inetinfo.exe
H:\KAV2006\KPfwSvc.EXE
H:\WINDOWS\System32\snmp.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\mqsvc.exe
D:\Program Files\Tencent\QQ\QQ.exe
H:\WINDOWS\system32\mqtgsvc.exe
H:\WINDOWS\System32\alg.exe
H:\WINDOWS\system32\conime.exe
H:\Program Files\Internet Explorer\iexplore.exe
H:\WINDOWS\system32\cidaemon.exe
H:\WINDOWS\system32\cidaemon.exe
D:\Program Files\Tencent\TT\TTraveler.exe
D:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe
D:\应用软件\安全类\金山毒霸\kav2006\DubaTool_QQTail.EXE
D:\Program Files\HijackThis\HijackThis.exe

O1 - Hosts: 218.93.205.170 www.cncrk.com
O2 - BHO: TuoTuHelper.LDown - {0BECAB3A-E1F8-45E6-8332-38DD750EBA01} - D:\Program Files\Tuotu\TuoTuHelper.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - H:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - H:\PROGRA~1\Yahoo!\ASSIST~1\assist\yangling.dll
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - H:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - H:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - h:\program files\google\googletoolbar1.dll
O2 - BHO: OsbornTech Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - H:\WINDOWS\system32\ms.dll
O2 - BHO: WMHlprObj Class - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - H:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll
O2 - BHO: AssistHelper - {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} - H:\PROGRA~1\Yahoo!\ASSIST~1\assist\yassist.dll
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4A40-8DFD-58B0666ABEBD} - H:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - h:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "H:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [Supplicant] h:\program files\锐捷网络\ruijie supplicant\8021x.exe
O4 - HKLM\..\Run: [KavStart] "H:\KAV2006\KAVStart.exe" -startup
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [TkBellExe] "H:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Thunder] D:\Program Files\Thunder Network\Thunder\Thunder.exe /s
O4 - HKCU\..\Run: [KavPFW] "H:\KAV2006\KPFW32.EXE"
O4 - Global Startup: Ruijie Supplicant.lnk = ?
O8 - Extra context menu item: &使用迅雷下载 - D:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: Google 搜索(&G) - res://H:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用KuGoo3下载(&K) - H:\Program Files\KuGoo3\KuGoo3DownX.htm
O8 - Extra context menu item: 反向链接 - res://H:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://H:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 添加到雅虎订阅(&Y) - res://H:\PROGRA~1\Yahoo!\ASSIST~1\assist\yrss.dll/YRSSMENUEXT
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - D:\Program Files\BitSpirit\bsurl.htm
O8 - Extra context menu item: 类似网页 - res://H:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: 缓存的网页快照 - res://H:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: 翻译英文字词(&T) - res://H:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: 访问通用网址 - H:\Program Files\CNNIC\Cdn\cnnic.htm
O8 - Extra context menu item: 雅虎搜索 - res://H:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll/203
O9 - Extra button: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - H:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - H:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: 词霸 - {9A687CA6-D585-4947-9ED9-BE96071F5CD9} - H:\Program Files\Kingsoft\Powerword 2003\XDictExB.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'h:\windows\system32\cdnns.dll' missing
O11 - Options group: [CDNCLIENT]  中文上网
O18 - Protocol: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - H:\Program Files\Kingsoft\Powerword 2003\XDictExB.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - H:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - H:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kingsoft Personal Firewall Service (KPfwSvc) - キングソフト株式会社 - H:\KAV2006\KPfwSvc.EXE
O23 - Service: Kingsoft Antivirus KWatch Service (KWatchSvc) - Kingsoft Corporation - H:\KAV2006\KWatch.EXE

gototop
 

请高手看看啊,狂跳网页
gototop
 

【回复“600000”的帖子】
建议你下载超级兔子。
http://www.pctutu.com/srmsdown.asp
安装好后,打开“超级兔子优化王”“专业卸载,卸载所有提示的垃圾软件,卸载是不要打开任何浏览窗口。卸载不了可以重启后再去卸载。
卸载不了,一会在安全模式再卸载。

请到www.27814939.ys168.com,点“我的软件”下载KillBox.exe
重新启动电脑, 开机检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式进入Windows
双击打开KillBox.exe,分别删除
C:\WINDOWS\realupdate.exe
C:\WINDOWS\winampa.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\command\rundll32.exe
C:\WINDOWS\system32\sysmini.exe
C:\WINDOWS\system32\intenat.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\system32\alxklt.dll
C:\WINDOWS\system32\ppgaxea.dll
C:\WINDOWS\system32\adocbc.exe
C:\WINDOWS\system32\KB896475.log
C:\WINDOWS\system32\tdll.dll
C:\WINDOWS\system32\ontwps.dll
C:\WINDOWS\system32\genccp.dll
(删除时勾选“删除前先结束Explorer.EXE进程”不行再试着勾选"删除DLL文件前反注册此文件"
给菜鸟的东东—KillBox的使用技巧
http://forum.ikaka.com/topic.asp?board=28&artid=8160799

打开System Repair Engineer(也就是你的扫描日志软件SREng.exe),使用“启动项目,注册表”选中要修复的项
C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\adocbc.exe
,点“编辑”在“值”里删除C:\WINDOWS\system32\adocbc.exe

打开System Repair Engineer(也就是你的扫描日志软件SREng.exe),使用“启动项目,注册表”来删除以下选项。
C:\WINDOWS\realupdate.exe
C:\WINDOWS\winampa.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\command\rundll32.exe
C:\WINDOWS\system32\sysmini.exe
C:\WINDOWS\system32\intenat.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\system32\alxklt.dll
C:\WINDOWS\system32\ppgaxea.dll

完后重启,再扫个日志粘上来。
gototop
 

无邪大侠,请再帮看看,还有网页跳出,少了很多。日志呈上:
Logfile of HijackThis v1.99.1
Scan saved at 19:56:10, on 2006-9-22
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CNNIC\Cdn\cdnup.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\TEMP\setup.exe
C:\WINDOWS\Intel\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\ChinaNet\VnetClient.exe
c:\windows\system32\inetsrv\csrss.exe
C:\WINDOWS\system32\repair\IECWM\nerochk.exe
C:\WINDOWS\system32\repair\IECWM\nerochk.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\Logo1_.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\conime.exe
D:\9999\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\RunDll32.exe

F3 - REG:win.ini: load=C:\WINDOWS\rundl132.exe
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_5104.dll
O2 - BHO: (no name) - {3D898C55-74CC-4B7C-B5F1-45913F368388} - C:\PROGRA~1\SYSTEM~1\SYSTEM~1.DLL
O2 - BHO: MsXmlExObj Class - {449840D6-2E92-47B5-AED3-B03A41CE9CE4} - C:\WINDOWS\system32\MSXMLR~1.DLL
O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\chinanet\VNETTR~1.DLL
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O2 - BHO: DabObj Class - {70D509DD-32A5-4E11-B9C1-865433C8443C} - C:\WINDOWS\system32\dabapi.dll
O2 - BHO: Spoolsv Class - {9C363D55-07D7-433d-A13E-D9C105202F6F} - C:\WINDOWS\system32\drivers\spoolsv.dll
O2 - BHO: DDOC - {A64E86D2-203D-4145-AA9B-2425BAF568E9} - C:\WINDOWS\system32\henroer.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Macromedia. Flash8 Object - {C61A70F3-505E-4B90-916F-627A8706B4BC} - c:\WINDOWS\system32\FlashPlayer8OCX.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: bbmao Toolbar - {6AE02E1C-8859-4F57-9097-5A55A56A4CAF} - C:\Program Files\bbmao toolbar\bbmao_tb_v1_0_pd1002.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [YDTMain.exe] ; C:\PROGRA~1\YDT\YDTMain.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Mysee Alert] ; "C:\Program Files\GAOV\Mysee Alert\Mysee Alert.exe" -notray
O4 - HKLM\..\Run: [qt5axa] ; RunDll32 "C:\WINDOWS\Downlo~1\qt5axa.dll",Run
O4 - HKLM\..\Run: [NMGameX_AutoRun] C:\WINDOWS\system32\Rundll32.exe NMGameX.dll,LiveProcess /aa
O4 - HKLM\..\Run: [DesktopMemo] ; "C:\Program Files\DeskMemo\Deskmemo.exe"
O4 - HKLM\..\Run: [SrvNet32] ; RunDll32 "C:\Program Files\SearchNet\SrvNet32.dll",Run
O4 - HKLM\..\Run: [Kaspersky Anti-Hacker] ; D:\卡巴斯基防火墙\Kaspersky Anti-Hacker\kavpf.exe /silence
O4 - HKLM\..\Run: [System] C:\WINDOWS\TEMP\\setup.exe
O4 - HKLM\..\Run: [zt] C:\WINDOWS\Intel\rundll32.exe
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [dabrun] rundll32.exe "C:\WINDOWS\system32\dabapi.dll",Rundll32
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Desktop Search] ; "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [Super Rabbit Desktop Search] ; D:\Program Files\Super Rabbit\MagicSet(兔子)\SRSearch.exe
O4 - HKCU\..\Run: [daemon] C:\WINDOWS\daemon.exe
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\QQ\qq.exe
O4 - Global Startup: IE-Bar.lnk = C:\Program Files\Common Files\IE-Bar\iebar.exe
O8 - Extra context menu item: Google 搜索(&G) - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用超级解霸播放 - C:\Program Files\Herosoft\Hero 9\MPURLGET.HTM
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: 新浪UC - {2253922F-1B26-4C74-8B57-E3AEE748DBB8} - C:\Program Files\sina\UC\uc.exe
O9 - Extra button: 豪杰超级解霸9 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Program Files\Herosoft\Hero 9\STHSDVD.EXE
O9 - Extra 'Tools' menuitem: 豪杰超级解霸9 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Program Files\Herosoft\Hero 9\STHSDVD.EXE
O9 - Extra button: Yahoo 3.5G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - Extra button: 名品折扣 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/mall/pro.php?allyesPara=816 (file missing)
O9 - Extra button: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra button: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - Extra button: 雅虎WIDGET - {6354ABE6-05F1-49ed-B850-E423120EC338} - http://cn.widget.yahoo.com/index.htm?source=Cns (file missing)
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\cdnns.dll' missing
O11 - Options group: [CDNCLIENT]  中文上网
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{801F4DE8-CCEA-4D12-A1A8-0E73CFDA2073}: NameServer = 218.2.135.1 61.147.37.1
O17 - HKLM\System\CS3\Services\Tcpip\..\{801F4DE8-CCEA-4D12-A1A8-0E73CFDA2073}: NameServer = 218.2.135.1 61.147.37.1
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

gototop
 

2006-09-22,19:56:51

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
    <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>  [Microsoft Corporation]
    <Google Desktop Search><; "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup>  []
    <Super Rabbit Desktop Search><; D:\Program Files\Super Rabbit\MagicSet(兔子)\SRSearch.exe>  []
    <daemon><C:\WINDOWS\daemon.exe>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><C:\WINDOWS\rundl132.exe>  []
    <run><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <SoundMan><SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
    <IgfxTray><C:\WINDOWS\system32\igfxtray.exe>  [Intel Corporation]
    <HotKeysCmds><C:\WINDOWS\system32\hkcmd.exe>  [Intel Corporation]
    <YDTMain.exe><; C:\PROGRA~1\YDT\YDTMain.exe>  []
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <Mysee Alert><; "C:\Program Files\GAOV\Mysee Alert\Mysee Alert.exe" -notray>  []
    <qt5axa><; RunDll32 "C:\WINDOWS\Downlo~1\qt5axa.dll",Run>  [Microsoft Corporation]
    <NMGameX_AutoRun><C:\WINDOWS\system32\Rundll32.exe NMGameX.dll,LiveProcess /aa>  [NMGameX]
    <DesktopMemo><; "C:\Program Files\DeskMemo\Deskmemo.exe">  []
    <SrvNet32><; RunDll32 "C:\Program Files\SearchNet\SrvNet32.dll",Run>  []
    <Kaspersky Anti-Hacker><; D:\卡巴斯基防火墙\Kaspersky Anti-Hacker\kavpf.exe /silence>  []
    <System><C:\WINDOWS\TEMP\\setup.exe>  []
    <zt><C:\WINDOWS\Intel\rundll32.exe>  []
    <CdnCtr><C:\Program Files\CNNIC\Cdn\cdnup.exe>  []
    <dabrun><rundll32.exe "C:\WINDOWS\system32\dabapi.dll",Rundll32>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\Program Files\Herosoft\Hero 9\解霸屏保.SCR>  []

==================================
启动文件夹
[IE-Bar]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\IE-Bar.lnk><N>
[腾讯QQ]
  <C:\Documents and Settings\homeuser\「开始」菜单\程序\启动\腾讯QQ.lnk><N>

==================================
服务
[Microsoft Update Service / MouTALS]
  <C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\SMTPCONFS.DLL,Export 1087><N/A>
[SymWMI Service / SymWSC]
  <"C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe"><Symantec Corporation>

==================================
浏览器加载项
[MyIEHelper Class]
  {16B770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_5104.dll, Microsoft Corporation>
[]
  {3D898C55-74CC-4B7C-B5F1-45913F368388} <C:\PROGRA~1\SYSTEM~1\SYSTEM~1.DLL, N/A>
[MsXmlExObj Class]
  {449840D6-2E92-47B5-AED3-B03A41CE9CE4} <C:\WINDOWS\system32\MSXMLR~1.DLL, >
[VnetCookie Class]
  {4E83D567-4697-4F7B-B1F0-A513B01DB89A} <c:\PROGRA~1\chinanet\VNETTR~1.DLL, >
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[CdnForIE Class]
  {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[DabObj Class]
  {70D509DD-32A5-4E11-B9C1-865433C8443C} <C:\WINDOWS\system32\dabapi.dll, >
[Spoolsv Class]
  {9C363D55-07D7-433d-A13E-D9C105202F6F} <C:\WINDOWS\system32\drivers\spoolsv.dll, >
[DDOC]
  {A64E86D2-203D-4145-AA9B-2425BAF568E9} <C:\WINDOWS\system32\henroer.dll, N/A>
[Google Toolbar Helper]
gototop
 

{AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[Macromedia. Flash8 Object]
  {C61A70F3-505E-4B90-916F-627A8706B4BC} <c:\WINDOWS\system32\FlashPlayer8OCX.dll, N/A>
[新浪UC]
  {2253922F-1B26-4C74-8B57-E3AEE748DBB8} <C:\Program Files\sina\UC\uc.exe, N/A>
[豪杰超级解霸9]
  {367E0A21-8601-4986-9C9A-153BF5ACA118} <C:\Program Files\Herosoft\Hero 9\STHSDVD.EXE, N/A>
[Yahoo 3.5G电邮]
  {507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A>
[名品折扣]
  {59BC54A2-56B3-44a0-93E5-432D58746E26} <http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/mall/pro.php?allyesPara=816, N/A>
[CdnForIE Class]
  {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[雅虎助手]
  {5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A>
[雅虎WIDGET]
  {6354ABE6-05F1-49ed-B850-E423120EC338} <http://cn.widget.yahoo.com/index.htm?source=Cns, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[情景聊天]
  {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg, N/A>
[]
  {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[]
  {FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[bbmao Toolbar]
  {6AE02E1C-8859-4F57-9097-5A55A56A4CAF} <C:\Program Files\bbmao toolbar\bbmao_tb_v1_0_pd1002.dll, IE Toolbar>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[Google Script Object]
  {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[ActiveMovieControl Object]
  {05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[CAdLogic Object]
  {11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\CPUSH\cpush.dll, N/A>
[MyIEHelper Class]
  {16B770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_5104.dll, Microsoft Corporation>
[CNav Class]
  {1954558D-BD14-420A-BC38-7F41F7A1DDBB} <C:\WINDOWS\system32\NAVIGA~1.DLL, N/A>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
  {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
  {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[Tabular Data Control]
  {333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
[IE Browser Helper]
  {3CE496D1-1746-41CD-9489-3C0B93DF10E2} <, N/A>
[]
  {3D898C55-74CC-4B7C-B5F1-45913F368388} <C:\PROGRA~1\SYSTEM~1\SYSTEM~1.DLL, N/A>
[HHCtrl Object]
  {41B23C28-488E-4E5C-ACE2-BB0BBABE99E8} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[MsXmlExObj Class]
  {449840D6-2E92-47B5-AED3-B03A41CE9CE4} <C:\WINDOWS\system32\MSXMLR~1.DLL, >
[raObject Class]
  {46F194EB-B7DB-4B7A-BD42-5FF39FD17664} <C:\PROGRA~1\pcast\hbcast.dll, N/A>
[XML Document]
  {48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, N/A>
[VnetCookie Class]
  {4E83D567-4697-4F7B-B1F0-A513B01DB89A} <c:\PROGRA~1\chinanet\VNETTR~1.DLL, >
[HHCtrl Object]
  {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[CMCBooter Object]
  {53AF6E02-F18F-4228-AC13-3E79773FBE50} <C:\WINDOWS\system32\Booter.ocx, 北京高维视讯科技有限公司>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[CdnForIE Class]
  {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[bbmao Toolbar]
  {6AE02E1C-8859-4F57-9097-5A55A56A4CAF} <C:\Program Files\bbmao toolbar\bbmao_tb_v1_0_pd1002.dll, IE Toolbar>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[DabObj Class]
  {70D509DD-32A5-4E11-B9C1-865433C8443C} <C:\WINDOWS\system32\dabapi.dll, >
[Active Desktop Mover]
  {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[XBTP05676 Class]
  {72BA415A-AE03-4279-ACAB-39A3DF73FD4E} <C:\PROGRA~1\BBMAOT~1\BBMAO_~1.DLL, IE Toolbar>
[BROWSERToUC Class]
  {77AE4780-75E0-4CB0-A162-D1BBE3D50384} <C:\PROGRA~1\sina\UC\ActiveX\BROWSE~1.DLL, 北京新浪信息技术有限公司>
[]
  {8532B305-4486-4388-939F-341C0430CDFC} <C:\WINDOWS\system32\DxBho.dll, N/A>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Schedule Class]
  {8B316DA1-9950-4926-B9EA-1AEC124AFA45} <C:\WINDOWS\system32\sscli.dll, >
[Spoolsv Class]
  {9C363D55-07D7-433D-A13E-D9C105202F6F} <C:\WINDOWS\system32\drivers\spoolsv.dll, >
[DDOC]
  {A64E86D2-203D-4145-AA9B-2425BAF568E9} <C:\WINDOWS\system32\henroer.dll, N/A>
[PhotoUploadCtrl Control]
  {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} <C:\PROGRA~1\Tencent\QQ\QZone\PHOTOU~1.OCX, tencent>
[RMGetLicense Class]
  {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation>
[Google Toolbar Helper]
  {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
gototop
 

[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Microsoft DirectAnimation Control]
  {B6FFC24C-7E13-11D0-9B47-00C04FC2F51D} <C:\WINDOWS\system32\danim.dll, Microsoft Corporation>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Macromedia. Flash8 Object]
  {C61A70F3-505E-4B90-916F-627A8706B4BC} <c:\WINDOWS\system32\FlashPlayer8OCX.dll, N/A>
[CIEHelper Object]
  {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} <C:\WINDOWS\system32\ms.dll, N/A>
[NMGameX Class]
  {CD1A82F2-3770-4509-8355-0D2F45158F21} <C:\WINDOWS\system32\NMGameX.dll, NMGameX>
[AUDIO__MP3 Moniker Class]
  {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AUDIO__X_MS_WMA Moniker Class]
  {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_ASF Moniker Class]
  {CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
  {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[IEDown Class]
  {D0A29C6C-AA71-4423-8C4A-5998B774C448} <C:\WINDOWS\system32\GLIEDown2.dll, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[TencentVmpCtl Class]
  {D9819BD5-422B-4281-8523-726466ED692B} <C:\Program Files\Tencent\Viewpoint Media Player\AxMetaStream.dll, Viewpoint Corporation>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[Google 搜索(&G)]
  <res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html, N/A>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用超级解霸播放]
  <C:\Program Files\Herosoft\Hero 9\MPURLGET.HTM, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 480][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 536][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 560][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 604][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 616][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 760][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 808][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 876][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 952][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1096][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1220][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
    [C:\PROGRA~1\SYSTEM~1\SYSTEM~1.DLL]  <N/A><N/A>
    [C:\WINDOWS\system32\MSXMLR~1.DLL]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\dabapi.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\drivers\spoolsv.dll]  <><1, 0, 1, 1>
[PID: 1284][C:\Program Files\CNNIC\Cdn\cdnup.exe]  <><2, 4, 0, 8>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
[PID: 1360][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 1472][C:\WINDOWS\SOUNDMAN.EXE]  <Realtek Semiconductor Corp.><5.1.02>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
[PID: 1480][C:\WINDOWS\system32\igfxtray.exe]  <Intel Corporation><3,0,0,2104>
    [C:\WINDOWS\system32\hccutils.DLL]  <Intel Corporation><3,0,0,2104>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\WINDOWS\system32\igfxdev.dll]  <Intel Corporation><3,0,0,2104>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\igfxsrvc.dll]  <Intel Corporation><3,0,0,2104>
    [C:\WINDOWS\system32\igfxres.dll]  <Intel Corporation><3,0,0,2104>
    [C:\WINDOWS\system32\igfxress.dll]  <Intel Corporation><3,0,0,2104>
[PID: 1512][C:\WINDOWS\system32\hkcmd.exe]  <Intel Corporation><3,0,0,2104>
    [C:\WINDOWS\system32\hccutils.DLL]  <Intel Corporation><3,0,0,2104>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\WINDOWS\system32\igfxdev.dll]  <Intel Corporation><3,0,0,2104>
    [C:\WINDOWS\system32\igfxsrvc.dll]  <Intel Corporation><3,0,0,2104>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\igfxhk.dll]  <Intel Corporation><3,0,0,2104>
    [C:\WINDOWS\system32\igfxres.dll]  <Intel Corporation><3,0,0,2104>
gototop
 

[PID: 1524][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3510>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
[PID: 1664][C:\WINDOWS\TEMP\setup.exe]  <><1, 0, 0, 1>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
[PID: 1676][C:\WINDOWS\Intel\rundll32.exe]  <N/A><N/A>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
[PID: 1696][C:\WINDOWS\system32\rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\dabapi.dll]  <><1, 0, 0, 1>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\MSXMLR~1.DLL]  <><1, 0, 0, 1>
[PID: 1704][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
[PID: 1712][C:\Program Files\Messenger\msmsgs.exe]  <Microsoft Corporation><4.7.3001>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
[PID: 1928][C:\WINDOWS\system32\rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\DOCUME~1\homeuser\TEMPLA~1\ce65bdf\1.dll]  <千橡互联><3, 0, 2, 0>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\DOCUME~1\homeuser\TEMPLA~1\ce65bdf\3.dll]  <千橡互联><3, 0, 2, 8>
    [C:\DOCUME~1\homeuser\TEMPLA~1\ce65bdf\4.dll]  <千橡互联><3, 0, 2, 8>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
[PID: 508][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 532][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 792][C:\WINDOWS\SYSTEM32\RUNDLL32.EXE]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 320][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1160][C:\Program Files\ChinaNet\VnetClient.exe]  <><2005, 10, 8, 1>
    [C:\Program Files\ChinaNet\Communicate.dll]  <0><2005, 3, 3, 1>
    [C:\Program Files\ChinaNet\DialModule.dll]  <><2005, 3, 22, 1>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\PROGRA~1\ChinaNet\CLIENT~1.DLL]  <><2004, 2, 28, 1>
    [C:\PROGRA~1\ChinaNet\PLUGIN~1.OCX]  <><2005, 7, 27, 1>
    [C:\PROGRA~1\ChinaNet\sign.dll]  <0><2004, 12, 1, 1>
    [C:\PROGRA~1\ChinaNet\WEBPLU~1.DLL]  <><2005, 8, 18, 1>
    [C:\PROGRA~1\ChinaNet\PostPlug.dll]  <><2004, 12, 16, 2>
    [C:\PROGRA~1\ChinaNet\ADVERT~1.OCX]  <><2005, 10, 13, 1>
    [C:\PROGRA~1\ChinaNet\Gif89a.dll]  <><2005, 6, 21, 1>
    [C:\PROGRA~1\ChinaNet\VnetBs.ocx]  <><2004, 11, 18, 1>
    [C:\PROGRA~1\ChinaNet\ACCOUN~2.DLL]  <><2005, 8, 11, 1>
    [C:\PROGRA~1\ChinaNet\AccountMgr.dll]  <><2005, 8, 16, 1>
    [C:\PROGRA~1\ChinaNet\VnetSkin.ocx]  <GDDC><1, 0, 0, 1>
    [C:\PROGRA~1\ChinaNet\DialogStyle.dll]  <><1, 0, 0, 1>
    [C:\PROGRA~1\ChinaNet\Timer.ocx]  <><2005, 10, 9, 14>
    [C:\PROGRA~1\ChinaNet\PLUGIN~2.OCX]  <><2005, 2, 24, 1>
    [C:\PROGRA~1\ChinaNet\NEWMES~1.DLL]  <><2005, 8, 26, 1>
    [C:\PROGRA~1\ChinaNet\PassCtrl.dll]  <><1, 0, 0, 1>
    [C:\PROGRA~1\ChinaNet\PlugPush.dll]  <><2004, 12, 21, 1>
    [C:\PROGRA~1\ChinaNet\ALLINT~1.DLL]  <><2004, 11, 23, 1>
    [C:\PROGRA~1\ChinaNet\VNetLog.ocx]  <><2005, 10, 9, 1>
    [C:\PROGRA~1\ChinaNet\StatNum.dll]  <><2004, 11, 18, 1>
    [C:\PROGRA~1\ChinaNet\VNETON~1.OCX]  <><2005, 3, 2, 1>
    [C:\PROGRA~1\ChinaNet\ALLFUN~1.DLL]  <GDCN><2005, 10, 9, 1>
    [C:\PROGRA~1\ChinaNet\VnetOptLog.dll]  <><2005, 9, 13, 9>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
    [C:\PROGRA~1\ChinaNet\DlgSkin.ocx]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 2152][c:\windows\system32\inetsrv\csrss.exe]  <Microsoft><1.0.0.0>
[PID: 3572][C:\WINDOWS\system32\cmd.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3596][C:\WINDOWS\Logo1_.exe]  <N/A><N/A>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
[PID: 3608][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\PROGRA~1\Google\GOOGLE~1\GOOGLE~2.DLL]  <N/A><N/A>
    [C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopAPI2.dll]  <N/A><N/A>
    [C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopResources_zh_cn.dll]  <N/A><N/A>
    [c:\program files\google\googletoolbar2.dll]  <Google Inc.><3, 0, 131, 0>
    [C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_5104.dll]  <Microsoft Corporation><1, 3, 5, 0>
    [C:\PROGRA~1\SYSTEM~1\SYSTEM~1.DLL]  <N/A><N/A>
    [C:\WINDOWS\system32\MSXMLR~1.DLL]  <><1, 0, 0, 1>
    [c:\PROGRA~1\chinanet\VNETTR~1.DLL]  <><2005, 4, 6, 1>
    [c:\PROGRA~1\chinanet\Communicate.dll]  <0><2005, 3, 3, 1>
    [C:\PROGRA~1\ChinaNet\CLIENT~1.DLL]  <><2004, 2, 28, 1>
    [C:\WINDOWS\vDll.dll]  <N/A><N/A>
    [C:\Program Files\Tencent\QQ\QQIEHelper.dll]  <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
    [C:\WINDOWS\system32\dabapi.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\drivers\spoolsv.dll]  <><1, 0, 1, 1>
    [c:\WINDOWS\system32\FlashPlayer8OCX.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
    [c:\WINDOWS\system32\urlmons32.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 3648][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
[PID: 3684][D:\9999\HijackThis.exe]  <Soeperman Enterprises Ltd.><1.99.0001>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
[PID: 3892][C:\WINDOWS\system32\wuauclt.exe]  <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[PID: 296][C:\WINDOWS\system32\NOTEPAD.EXE]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
[PID: 3516][D:\sreng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 6>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 3>
    [C:\WINDOWS\system32\ztdll.dll]  <N/A><N/A>
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  Error. [超级解霸3000]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 

注意,你中了木马下载器,在修复未完前,最好不要连接网络。
建议你下载超级兔子。
http://www.pctutu.com/srmsdown.asp
安装好后,打开“超级兔子优化王”“专业卸载,卸载所有提示的垃圾软件,卸载是不要打开任何浏览窗口。卸载不了可以重启后再去卸载。
卸载完后

关闭所有浏览窗口以及一些不必要的程序
打开System Repair Engineer(也就是你的扫描日志软件SREng.exe),使用“系统修复,浏览器加载项”来删除以下选项。
C:\WINDOWS\system32\dabapi.dll
C:\WINDOWS\system32\drivers\spoolsv.dll
C:\WINDOWS\system32\henroer.dll
C:\WINDOWS\system32\DxBho.dll
C:\WINDOWS\system32\sscli.dll

请到www.27814939.ys168.com,点“我的软件”下载KillBox.exe
重新启动电脑, 开机检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式进入Windows
双击打开KillBox.exe,分别删除
C:\WINDOWS\system32\ztdll.dll
c:\WINDOWS\system32\urlmons32.dll
C:\WINDOWS\vDll.dll
c:\WINDOWS\system32\FlashPlayer8OCX.dll
c:\windows\system32\inetsrv\csrss.exe
C:\WINDOWS\system32\drivers\spoolsv.dll
C:\WINDOWS\Logo1_.exe
C:\WINDOWS\system32\rundll32.exe
:\WINDOWS\Intel\rundll32.exe
C:\WINDOWS\daemon.exe
C:\WINDOWS\rundl132.exe
C:\WINDOWS\TEMP\\setup.exe
C:\WINDOWS\Intel\rundll32.e
C:\WINDOWS\system32\dabapi.dll
(删除时勾选“删除前先结束Explorer.EXE进程”不行再试着勾选"删除DLL文件前反注册此文件"
给菜鸟的东东—KillBox的使用技巧
http://forum.ikaka.com/topic.asp?board=28&artid=8160799

打开System Repair Engineer(也就是你的扫描日志软件SREng.exe),使用“启动项目,注册表”来删除以下选项
C:\WINDOWS\system32\rundll32.exe
:\WINDOWS\Intel\rundll32.exe
C:\WINDOWS\daemon.exe
C:\WINDOWS\rundl132.exe
C:\WINDOWS\TEMP\\setup.exe
C:\WINDOWS\Intel\rundll32.exe

这两项应该有关系的。c:\WINDOWS\system32\FlashPlayer8OCX.dll
c:\windows\system32\inetsrv\csrss.exe建议你参考以下帖子的思路去解决问题
http://forum.ikaka.com/topic.asp?board=28&artid=8171746

以上方法解决你在安全模式上修复,完后重启,再进安全模式再修复一次。最后重启,再扫个日志粘上来。
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT