1   1  /  1  页   跳转

谁来帮我分析一下啊

谁来帮我分析一下啊

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\HEROSOFT\Hero3000\SysExplr.EXE
C:\WINDOWS\system32\rundll32.exe
C:\KAV6\Kulansyn.EXE
C:\WINDOWS\System32\interserv.exe
C:\Program Files\WeirdOnTheWeb\WeirdOnTheWeb.exe
C:\WINDOWS\System32\msxct.exe
C:\program files\internet explorer\iexplore.exe
C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe
C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\KAV6\KPopMon.exe
C:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\PowerInfo\DreamPlayer\DreamPlayer.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\TIMPlatform.exe
C:\Program Files\BullsEye Network\bin\bargains.exe
C:\Program Files\rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\hijackthisV1.99.1.exe
C:\HijackThis1991汉化版\HijackThis1991zww.exe

R3 - URLSearchHook: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\Program Files\3721\Assist\asbar.dll
O1 - Hosts: 216.138.184.21 onlineaccounts2.abbeynational.co.uk
O1 - Hosts: 216.138.184.21 www3.aibgbonline.co.uk
O1 - Hosts: 216.138.184.21 www.bank.alliance-leicester.co.uk
O1 - Hosts: 216.138.184.21 login.iblogin.com
O1 - Hosts: 216.138.184.21 ww2.bankofscotlandhalifax-online.co.uk
O1 - Hosts: 216.138.184.21 inet.barclays.co.uk
O1 - Hosts: 216.138.184.21 iibank.barclays.co.uk
O1 - Hosts: 216.138.184.21 iibank.cahoot.com
O1 - Hosts: 216.138.184.21 www3.coventrybuildingsociety.co.uk
O1 - Hosts: 216.138.184.21 ww.hsbc.co.uk
O1 - Hosts: 216.138.184.21 login.ebank.offshore.hsbc.co.je
O1 - Hosts: 216.138.184.21 ww3.online-offshore.lloydstsb.com
O1 - Hosts: 216.138.184.21 ww3.online-business.lloydstsb.co.uk
O1 - Hosts: 216.138.184.21 ww3.online.lloydstsb.co.uk
O1 - Hosts: 216.138.184.21 ww3.online.lloydstsb.co.uk
O1 - Hosts: 216.138.184.21 ww3.online-business.lloydstsb.co.uk
O1 - Hosts: 216.138.184.21 ob2.nationet.com
O1 - Hosts: 216.138.184.21 ww3.onlinebanking.natwestoffshore.com
O1 - Hosts: 216.138.184.21 ww1.nwolb.com
O1 - Hosts: 216.138.184.21 ww1.onlinebanking.iombank.com
O1 - Hosts: 216.138.184.21 ww1.www.rbsdigital.com
O1 - Hosts: 216.138.184.21 welcome.smile.co.uk
O1 - Hosts: 216.138.184.21 login.365online.com
O1 - Hosts: 216.138.184.21 wvw.citizensbankonline.com
O1 - Hosts: 216.138.184.21 esecure.regionsnet.com
O1 - Hosts: 216.138.184.21 rollb.associatedbank.com
O1 - Hosts: 216.138.184.21 upb.unionplanters.com
O1 - Hosts: 216.138.184.21 www.onlinebanking.huntington.com
O1 - Hosts: 216.138.184.21 inet.southtrustonlinebanking.com
O1 - Hosts: 216.138.184.21 logon.personal.wamu.com
O1 - Hosts: 216.138.184.21 login.compassweb.com
O1 - Hosts: 216.138.184.21 logon.firstmeritib.com
O1 - Hosts: 216.138.184.21 login.ccfcuonline.org
O1 - Hosts: 216.138.184.21 ww3.etimebanker.bankofthewest.com
O1 - Hosts: 216.138.184.21 ww2.onlinebanking.lasallebank.com
O1 - Hosts: 216.138.184.21 wvw.totallyfreebanking.com
O1 - Hosts: 216.138.184.21 www.online.wellsfargo.com
O1 - Hosts: 216.138.184.21 www.onlinebanking.bankofoklahoma.com
O1 - Hosts: 216.138.184.21 accounts4.keybank.com
O1 - Hosts: 216.138.184.21 logon.bankone.com
O1 - Hosts: 216.138.184.21 www.secure.tdbanknorth.com
O1 - Hosts: 216.138.184.21 www.secure.mvnt4.com
O1 - Hosts: 216.138.184.21 ww.mynfbonline.com
O1 - Hosts: 216.138.184.21 login.forumcuonline.com
O1 - Hosts: 216.138.184.21 www.eds.usersonlnet.com
O1 - Hosts: 216.138.184.21 www.onlineid.bankofamerica.com
O1 - Hosts: 216.138.184.21 wvw.e-gold.com
O1 - Hosts: 216.138.184.21 pcbs.peoples.com
O1 - Hosts: 216.138.184.21 www.global1.onlinebank.com
O1 - Hosts: 216.138.184.21 ww2.mybranch.lafcu.com
O1 - Hosts: 216.138.184.21 login.webbanking.comerica.com
O1 - Hosts: 216.138.184.21 web.banking.firsttennessee.com
O1 - Hosts: 216.138.184.21 logon.members1st.org
O1 - Hosts: 216.138.184.21 www.cib.ibanking-services.com
O1 - Hosts: 216.138.184.21 www.miwebbusbank.ebanking-services.com
O1 - Hosts: 216.138.184.21 wvw.paypal.com
O1 - Hosts: 216.138.184.21 www.signin.ebay.com
O1 - Hosts: 216.138.184.21 wvw.etrade.com
O1 - Hosts: 216.138.184.21 ww4.fleethomelink.fleet.com
O1 - Hosts: 216.138.184.21 ww3.connect.skyfi.com
O1 - Hosts: 216.138.184.21 www6.usbank.com
O1 - Hosts: 216.138.184.21 www.bvi.bancodevalencia.es
O1 - Hosts: 216.138.184.21 extrant.banesto.es
O1 - Hosts: 216.138.184.21 banesnt.banesto.es
O1 - Hosts: 216.138.184.21 activia.caixagalicia.es
O1 - Hosts: 216.138.184.21 www.bancae.caixapenedes.com
O1 - Hosts: 216.138.184.21 login.caixasabadell.net
O1 - Hosts: 216.138.184.21 oii.cajamadrid.es
O1 - Hosts: 216.138.184.21 login.cajamar.es
O1 - Hosts: 216.138.184.21 login.ccm.es
O1 - Hosts: 216.138.184.21 ww.unicaja.es
O1 - Hosts: 216.138.184.21 www5.bancopopular.es
O1 - Hosts: 216.138.184.21 ww3.bbvanet.com
O1 - Hosts: 216.138.184.21 ww.bayernlb.de
O1 - Hosts: 216.138.184.21 ww2.berliner-volksbank.de
O1 - Hosts: 216.138.184.21 ww7.homebanking-berlin.de
O1 - Hosts: 216.138.184.21 portal09.commerzbanking.de
O1 - Hosts: 216.138.184.21 www.meine.deutsche-bank.de
O1 - Hosts: 216.138.184.21 ww2.dresdner-privat.de
O1 - Hosts: 216.138.184.21 ww.e-banking.helaba.de
O1 - Hosts: 216.138.184.21 ww.hsh-nordbank.de
O1 - Hosts: 216.138.184.21 www.my.hypovereinsbank.de
O1 - Hosts: 216.138.184.21 ww3.homebanking-berlin.de
O1 - Hosts: 216.138.184.21 ww3.homebanking-berlin.de
O1 - Hosts: 216.138.184.21 www.banking.lbbw.de
O1 - Hosts: 216.138.184.21 lrp.sparkasse-banking.de
O1 - Hosts: 216.138.184.21 ww3.homebanking-niedersachsen.de
O1 - Hosts: 216.138.184.21 www.onlinebanking.norisbank.de
O1 - Hosts: 216.138.184.21 www.banking.postbank.de
O1 - Hosts: 216.138.184.21 wvw.internetbanking.gad.de
O1 - Hosts: 216.138.184.21 ww1.portal.izb.de
O1 - Hosts: 216.138.184.21 wvw.kunden-service.lbs.de
O1 - Hosts: 216.138.184.21 ibanking.seb.de
O1 - Hosts: 216.138.184.21 bw7.sparkasse-banking.de
O1 - Hosts: 216.138.184.21 ww2.homebanking-sparkasse.de
O1 - Hosts: 216.138.184.21 ww2.vr-networld-ebanking.de
O1 - Hosts: 216.138.184.21 ww.bics.fr
O1 - Hosts: 216.138.184.21 www.co.caixabank.fr
O1 - Hosts: 216.138.184.21 ww.creditmutuel.fr
O1 - Hosts: 216.138.184.21 internetbank.intesabci.it
O1 - Hosts: 216.138.184.21 ww.extensive.bancalombarda.it
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll (file missing)
O2 - BHO: Target Class - {002AF282-E42D-4B51-9F70-F1570C02FAAD} - C:\Progra~1\NetMeting\Target\0.9.0.3\Target.dll
O2 - BHO: IDDTInitObj Class - {15DDE989-CD45-4561-BF99-D22C0D5C2B74} - C:\WINDOWS\Downlo~1\ddtinit.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\PROGRA~1\3721\Assist\Angling.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: Router Layer - {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} - C:\WINDOWS\System32\aclayer.dll
O2 - BHO: Msxml32DOMDocument Class - {6E28339B-7A2A-47B6-AEB2-46BA53782379} - C:\WINDOWS\System32\dllcache\msxml32.dll
O2 - BHO: AssistII - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\Program Files\3721\Assist\asbar.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLO~1\CnsHook.dll
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - C:\PROGRA~1\yisou\yisoub.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - IE工具栏增项: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll
O3 - IE工具栏增项: 卡卡安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\Program Files\Rising\KaKaToolBar\kakatool.dll
O3 - IE工具栏增项: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - IE工具栏增项: (no name) - {A9BE2902-C447-420A-BB7F-A5DE921E6138}? - (no file)
O3 - IE工具栏增项: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\Program Files\3721\Assist\asbar.dll
O3 - IE工具栏增项: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\Program Files\yisou\yisou.dll
最后编辑2005-07-22 18:25:48
分享到:
gototop
 

O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [SysExplr] C:\HEROSOFT\Hero3000\SysExplr.EXE
O4 - 启动项HKLM\\Run: [SCDEPLOY] C:\DOCUME~1\zsc\LOCALS~1\Temp\ScDeploy\ScDeploy.exe -install
O4 - 启动项HKLM\\Run: [MS04_028 Memory Patch] C:\Documents and Settings\zsc\Local Settings\Temporary Internet Files\Content.IE5\MT892FML\RavJPG[1].exe -Patch
O4 - 启动项HKLM\\Run: [MS-4011 Memory Patch] C:\Documents and Settings\zsc\Local Settings\Temporary Internet Files\Content.IE5\G1C12RMT\RavSasser[1].exe -Patch
O4 - 启动项HKLM\\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - 启动项HKLM\\Run: [NMGameX_AutoRun] C:\WINDOWS\System32\Rundll32.exe NMGameX.dll,LiveProcess /aa
O4 - 启动项HKLM\\Run: [CnsMin] Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32
O4 - 启动项HKLM\\Run: [SYSTRAY] C:\UNMT.EXE
O4 - 启动项HKLM\\Run: [Microsoft SpA Service] winsys.exe
O4 - 启动项HKLM\\Run: [Windows Firewall Log] winlog.exe
O4 - 启动项HKLM\\Run: [KAVRun] C:\KAV6\KAVRun.EXE
O4 - 启动项HKLM\\Run: [Kulansyn] C:\KAV6\Kulansyn.EXE
O4 - 启动项HKLM\\Run: [Internet Services] interserv.exe
O4 - 启动项HKLM\\Run: [WeirdOnTheWeb] "C:\Program Files\WeirdOnTheWeb\WeirdOnTheWeb.exe"
O4 - 启动项HKLM\\Run: [j1o0gneo] C:\WINDOWS\System32\j1o0gneo.exe
O4 - 启动项HKLM\\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - 启动项HKLM\\Run: [msxct] msxct.exe
O4 - 启动项HKLM\\Run: [KvMonXP] C:\PROGRA~1\KV2005\KVMonXP.kxp /auto
O4 - 启动项HKLM\\Run: [MS Remote Procedure Call Service] MSRPC32.exe
O4 - 启动项HKLM\\Run: [CnxDslTaskBar] "C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe"
O4 - 启动项HKLM\\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - 启动项HKLM\\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - 启动项HKLM\\Run: [Microsoft Machine] WinJava.exe
O4 - 启动项HKLM\\RunServices: [Microsoft SpA Service] winsys.exe
O4 - 启动项HKLM\\RunServices: [Windows Firewall Log] winlog.exe
O4 - 启动项HKLM\\RunServices: [Internet Services] interserv.exe
O4 - 启动项HKLM\\RunServices: [win1ogon] win1ogon.exe
O4 - 启动项HKLM\\RunServices: [CPU Buffer] CPUBuffer.exe
O4 - 启动项HKLM\\RunServices: [MS Remote Procedure Call Service] MSRPC32.exe
O4 - 启动项HKLM\\RunServices: [Microsoft Machine] WinJava.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft SpA Service] winsys.exe
O4 - HKCU\..\Run: [Internet Services] interserv.exe
O4 - HKCU\..\Run: [win1ogon] win1ogon.exe
O4 - HKCU\..\Run: [CPU Buffer] CPUBuffer.exe
O4 - HKCU\..\Run: [DreamPlayer] "C:\Program Files\PowerInfo\DreamPlayer\DreamPlayer.exe" /i
O4 - 启动项HKCU\\RunServices: [Internet Services] interserv.exe
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\QQ\QQ.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - IE右键菜单中的新增项目: !搜一搜 - res://C:\WINDOWS\DOWNLO~1\CnsMinEx.dll/1003
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
gototop
 

O9 - 浏览器额外的按钮: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm?pid=U_eaini_5398 (file missing)
O9 - 浏览器额外的按钮: 江民在线杀毒 - {06926B30-424E-4f1c-8EE3-543CD96573DC} - http://club.jiangmin.com/kvscan/KvOnline.asp (file missing)
O9 - 浏览器额外的按钮: 江民在线杀毒 - {06926B30-424E-4f1c-8EE3-543CD96573DC}? - http://club.jiangmin.com/kvscan/KvOnline.asp (file missing)
O9 - 浏览器额外的按钮: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - C:\Program Files\浩方对战平台\GameClient.exe (file missing)
O9 - 浏览器额外的按钮: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - 浏览器额外的按钮: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - 浏览器额外的按钮: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338}? - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: 金山卓越 - {8DE0FCD4-5EB5-11D3-AD25-00002100131B}? - url:http://www.joyo.com (file missing)
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的按钮: 金山毒霸网站 - {e1fc9760-7b95-49cd-80b9-8c9e41017b93}? - url:http://www.duba.net (file missing)
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - 浏览器额外的“工具”菜单项: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: 在线查毒 - {f58d36c3-40be-4418-a786-d8fbe3eb3554} - C:\KAV6\kavie.htm
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - 浏览器额外的“工具”菜单项: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} - http://www.rising.com.cn (file missing)
O9 - 浏览器额外的按钮: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com (file missing)
O11 - Options group: [!CNS]  网络实名
O11 - Options group: [!MySearch] 搜索助手(MySearch)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAccessVerisign/ie/Bridge-c139.cab
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-622221193458} - file://c:\ex.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/aliedit.cab
O16 - DPF: {52DF16E3-6C4F-4B22-8BAF-09263E463B48} (金山毒霸安全助手) - http://zs.kingsoft.com/KOSInit.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1111820287046
O16 - DPF: {86BC8440-8693-4076-A144-6BAF942B40B0} (RegMore Class) - http://mysearch.8848.com/mysearch/MySearch.CAB
O16 - DPF: {C8BD9ACB-F7EC-48E6-BB2F-DAADC6789E9A} (Kingsoft DUBA OnlineScan) - http://ol.db.kingsoft.com/antiscan/setup/KAVClean.CAB
O16 - DPF: {D0A29C6C-AA71-4423-8C4A-5998B774C448} (IEDown Class) - http://download.ourgame.com/IEDown4.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O16 - DPF: {EF6205C1-3F17-4829-BCB5-1336ED89E356} - http://club.jiangmin.com/kvscan/KvDown.cab
O16 - DPF: {F553811C-C2CE-4A33-90B4-A6D333FDF794} (DreamSetup Control) - http://61.156.12.91/ddvod/user/help/player/DreamPlayer/DreamSetup.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4630C27A-8629-4337-9963-D0B9D29EBE49}: NameServer = 202.102.128.68 202.102.152.3
O18 - 列举现有的协议: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - 列举现有的协议: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - 列举现有的协议: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\System32\msvidctl.dll
O18 - 列举现有的协议: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: ipp - (no CLSID) - (no file)
O18 - 列举现有的协议: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - 列举现有的协议: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - 列举现有的协议: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - 列举现有的协议: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll
O18 - 列举现有的协议: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - 列举现有的协议: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - 列举现有的协议: msdaipp - (no CLSID) - (no file)
O18 - 列举现有的协议: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
O18 - 列举现有的协议: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - 列举现有的协议: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll
O18 - 列举现有的协议: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\System32\msvidctl.dll
O18 - 列举现有的协议: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - 列举现有的协议: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\System32\msdxm.ocx
O18 - 列举现有的协议: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\System32\wiascr.dll
O18 - Filter: text/html - {65CBAF77-19CA-4B81-86D5-7835D59BEA85} - C:\WINDOWS\System32\SoMP3.dll
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll
O23 - NT 服务: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - NT 服务: Externtelecom - Unknown owner - C:\WINDOWS\extel.exe (file missing)
O23 - NT 服务: WIN32 (image) - Unknown owner - C:\WINDOWS\image.exe (file missing)
O23 - NT 服务: Net Functions Library (Netlib) - Unknown owner - C:\WINDOWS\System32\wkssmd.exe
O23 - NT 服务: Remote Procedure Call (RPC) Helper - Unknown owner - MSRPC32.exe (file missing)
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - NT 服务: winfws - Unknown owner - C:\WINDOWS\winfws.exe (file missing)

gototop
 

先发这些,晚上继续发后面的,都是要修复的
所有01项
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll (file missing)
O2 - BHO: Router Layer - {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} - C:\WINDOWS\System32\aclayer.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
O4 - 启动项HKLM\\Run: [SCDEPLOY] C:\DOCUME~1\zsc\LOCALS~1\Temp\ScDeploy\ScDeploy.exe -install
O4 - 启动项HKLM\\Run: [MS04_028 Memory Patch] C:\Documents and Settings\zsc\Local Settings\Temporary Internet Files\Content.IE5\MT892FML\RavJPG[1].exe -Patch
O4 - 启动项HKLM\\Run: [MS-4011 Memory Patch] C:\Documents and Settings\zsc\Local Settings\Temporary Internet Files\Content.IE5\G1C12RMT\RavSasser[1].exe -Patch
O4 - 启动项HKLM\\Run: [SYSTRAY] C:\UNMT.EXE
O4 - 启动项HKLM\\Run: [Microsoft SpA Service] winsys.exe
O4 - 启动项HKLM\\Run: [Windows Firewall Log] winlog.exe
O4 - 启动项HKLM\\Run: [Internet Services] interserv.exe
O4 - 启动项HKLM\\Run: [WeirdOnTheWeb] "C:\Program Files\WeirdOnTheWeb\WeirdOnTheWeb.exe"
O4 - 启动项HKLM\\Run: [j1o0gneo] C:\WINDOWS\System32\j1o0gneo.exe
O4 - 启动项HKLM\\Run: [msxct] msxct.exe
O4 - 启动项HKLM\\Run: [MS Remote Procedure Call Service] MSRPC32.exe
O4 - 启动项HKLM\\Run: [Microsoft Machine] WinJava.exe
O4 - 启动项HKLM\\RunServices: [Microsoft SpA Service] winsys.exe
O4 - 启动项HKLM\\RunServices: [Windows Firewall Log] winlog.exe
O4 - 启动项HKLM\\RunServices: [Internet Services] interserv.exe
O4 - 启动项HKLM\\RunServices: [win1ogon] win1ogon.exe
O4 - 启动项HKLM\\RunServices: [CPU Buffer] CPUBuffer.exe
O4 - 启动项HKLM\\RunServices: [MS Remote Procedure Call Service] MSRPC32.exe
O4 - 启动项HKLM\\RunServices: [Microsoft Machine] WinJava.exe
O4 - HKCU\..\Run: [Microsoft SpA Service] winsys.exe
O4 - HKCU\..\Run: [Internet Services] interserv.exe
O4 - HKCU\..\Run: [win1ogon] win1ogon.exe
O4 - HKCU\..\Run: [CPU Buffer] CPUBuffer.exe
O4 - 启动项HKCU\\RunServices: [Internet Services] interserv.exe
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAccessVerisign/ie/Bridge-c139.cab
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-622221193458} - file://c:\ex.cab
gototop
 

O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll
O23 - NT 服务: Externtelecom - Unknown owner - C:\WINDOWS\extel.exe (file missing)
O23 - NT 服务: WIN32 (image) - Unknown owner - C:\WINDOWS\image.exe (file missing)
O23 - NT 服务: Remote Procedure Call (RPC) Helper - Unknown owner - MSRPC32.exe (file missing)
O23 - NT 服务: winfws - Unknown owner - C:\WINDOWS\winfws.exe (file missing)
O23 - NT 服务: Net Functions Library (Netlib) - Unknown owner - C:\WINDOWS\System32\wkssmd.exe

建议修复(如果楼主认为安全可以不选)

重起进安全模式,关闭系统还原
管理工具--服务--停止并禁用
Externtelecom
WIN32 (image)
Remote Procedure Call (RPC)
winfws
Net Functions Library (Netlib)
我的电脑--工具--文件夹选项--查看--显示所有文件(如图,或参考本版基本操作说明http://forum.ikaka.com/topic.asp?board=67&artid=6789825)
查找并删除相关文件(就是修复项后面的路径文件

请您清空IE缓存
开始--控制面版--internet选项--删除文件--删除所有脱机内容

附件附件:

下载次数:0
文件类型:image/pjpeg
文件大小:
上传时间:2005-7-22 17:52:35
描述:



gototop
 

最后
运行--regedit--HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\run和runservices里面查找相关文件的键值
如果有,请删除!(如果不确定,请压缩备份后再进行修改)
如果不知道怎么改,请进入上面的路径,截个图发上来
gototop
 

清理一下注册表垃圾:修复所有(file missing)的项
O9 - 浏览器额外的按钮: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm?pid=U_eaini_5398 (file missing)
O9 - 浏览器额外的按钮: 江民在线杀毒 - {06926B30-424E-4f1c-8EE3-543CD96573DC} - http://club.jiangmin.com/kvscan/KvOnline.asp (file missing)
O9 - 浏览器额外的按钮: 江民在线杀毒 - {06926B30-424E-4f1c-8EE3-543CD96573DC}? - http://club.jiangmin.com/kvscan/KvOnline.asp (file missing)
O9 - 浏览器额外的按钮: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - C:\Program Files\浩方对战平台\GameClient.exe (file missing)
O9 - 浏览器额外的按钮: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - 浏览器额外的按钮: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - 浏览器额外的按钮: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338}? - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: 金山卓越 - {8DE0FCD4-5EB5-11D3-AD25-00002100131B}? - url:http://www.joyo.com (file missing)

O9 - 浏览器额外的按钮: 金山毒霸网站 - {e1fc9760-7b95-49cd-80b9-8c9e41017b93}? - url:http://www.duba.net (file missing)
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - 浏览器额外的“工具”菜单项: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: 在线查毒 - {f58d36c3-40be-4418-a786-d8fbe3eb3554} - C:\KAV6\kavie.htm
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - 浏览器额外的“工具”菜单项: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} - http://www.rising.com.cn (file missing)
O9 - 浏览器额外的按钮: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com (file missing)
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT