IE总是一会就弹出这个域名下的网站,什么http://www.71791.com/sp/,http://www.71791.com/mm.啊,用kaka,兔子,黄山,重装IE也没办法,高手请解决下哦!先谢谢了!我已经被困绕3天了!!
系统活动进程
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\WINDOWS\SYSTEM32\NOTEPAD.EXE
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_002.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\INK\PENCHS.DLL
D:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\WINDOWS\SYSTEM32\WINWB98.IME
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9.OCX
D:\PROGRAM FILES\ADOBE\ACROBAT 7.0\ACTIVEX\PDFSHELL.CHS
C:\WINDOWS\SYSTEM32\KAKATOOL.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
D:\PROGRAM FILES\RISING\RFW\RFWSRV.EXE
D:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL
D:\PROGRAM FILES\RISING\RFW\RFWLOG.DLL
D:\PROGRAM FILES\RISING\RFW\RFWDRV.DLL
D:\PROGRAM FILES\RISING\RFW\PSAPI.DLL
D:\PROGRAM FILES\RISING\RFW\MONDRV.DLL
D:\PROGRAM FILES\RISING\RFW\PROCLIB.DLL
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\PROGRAM FILES\ADOBE\ACROBAT 7.0\ACTIVEX\PDFSHELL.DLL
D:\PROGRAM FILES\ADOBE\ACROBAT 7.0\ACTIVEX\PDFSHELL.CHS
C:\WINDOWS\SYSTEM32\NVCPL.DLL
C:\WINDOWS\SYSTEM32\NVSHELL.DLL
D:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
D:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
D:\PROGRAM FILES\ADOBE\ACROBAT 7.0\ACROBAT ELEMENTS\CONTEXTMENU.DLL
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\MFC71CHS.DLL
D:\PROGRAM FILES\ADOBE\ACROBAT 7.0\ACROBAT ELEMENTS\CONTEXTMENU.CHS
C:\PROGRAM FILES\MSN MESSENGER\FSSHEXT.8.0.0792.00.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_002.DLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\ADOBEPDF.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
D:\PROGRAM FILES\ADOBE\ACROBAT 7.0\DISTILLR\ADISTRES.CHS
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
D:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE
D:\PROGRAM FILES\RISING\RFW\RSGUILIB.DLL
D:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL
D:\PROGRAM FILES\RISING\RFW\PNGDLL.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\2052\MDMUI.DLL
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\THUNDER5.EXE
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\UPDATEDOWNLOAD.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\DOWNLOAD_INTERFACE.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\LOG4CPLUS.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\STLPORT_VC646.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\ASYN_DNS.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\MSGMANAGE.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\HISTORYINFO_MANAGE.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\REGISTERDLL.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\FLOATBAR.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\INMEDIA\IEMBEDSHELL.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\INMEDIA\IEMBED.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\P4PCLIENT\P4PCLIENT.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\ITARGETAD.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\INK\PENCHS.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
D:\PROGRAM FILES\TENCENT\QQ\QQ.EXE
D:\PROGRAM FILES\TENCENT\QQ\CQQ45RC\CORALASSIST.DLL
D:\PROGRAM FILES\TENCENT\QQ\CQQ45RC\CORALQQ.DLL
D:\PROGRAM FILES\TENCENT\QQ\CQQ45RC\IPSEARCHER.DLL
D:\PROGRAM FILES\TENCENT\QQ\MFC42.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQBASECLASSINDLL.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQHELPERDLL.DLL
D:\PROGRAM FILES\TENCENT\QQ\BASICCTRLDLL.DLL
D:\PROGRAM FILES\TENCENT\QQ\RICHED32.DLL
D:\PROGRAM FILES\TENCENT\QQ\RICHED20.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQAPI.DLL
D:\PROGRAM FILES\TENCENT\QQ\TIMPROXY.DLL
D:\PROGRAM FILES\TENCENT\QQ\LOGINCTRL.DLL
D:\PROGRAM FILES\TENCENT\QQ\NPKCNTC.DLL
D:\PROGRAM FILES\TENCENT\QQ\NPKPDB.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQRES.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQMAINFRAME.DLL
D:\PROGRAM FILES\TENCENT\QQ\CQQAPPLICATION.DLL
D:\PROGRAM FILES\TENCENT\QQ\NEWSKIN.DLL
D:\PROGRAM FILES\TENCENT\QQ\HOSTINGMGR.DLL
D:\PROGRAM FILES\TENCENT\QQ\CAMERADLL.DLL
D:\PROGRAM FILES\TENCENT\QQ\MAILSUMMARY.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQSPACE.DLL
D:\PROGRAM FILES\TENCENT\QQ\VBSCRIPT.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQGROUPMNG.DLL
D:\PROGRAM FILES\TENCENT\QQ\GROUPLIVE.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQSYSMSGMNG.DLL
D:\PROGRAM FILES\TENCENT\QQ\USERDEFINEDHEAD.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQPLUGIN.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQCONFIGPLUGIN.DLL
D:\PROGRAM FILES\TENCENT\QQ\QRINGMNG.DLL
D:\PROGRAM FILES\TENCENT\QQ\PHONEAPI.DLL
D:\PROGRAM FILES\TENCENT\QQ\DIALERALLINONE.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\PROGRAM FILES\TENCENT\QQ\QQAVATAR.DLL
D:\PROGRAM FILES\TENCENT\QQ\FLASHAVATARDLL.DLL
D:\PROGRAM FILES\TENCENT\QQ\LONGCONNECTION.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQPET.DLL
D:\PROGRAM FILES\TENCENT\QQ\BQQAPPLICATION.DLL
D:\PROGRAM FILES\TENCENT\QQ\COMMERCESMNG.DLL
D:\PROGRAM FILES\TENCENT\QQ\PERSONALDESKTOP.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQADDR.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQSCENEMNG.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQPHONEHELPER.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_002.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\INK\PENCHS.DLL
D:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\WINDOWS\SYSTEM32\WINWB98.IME
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\KAKATOOL.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\THUNDERAGENT_002.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM32\KAKATOOL.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_002.DLL
D:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\DOCUMENTS AND SETTINGS\YANG\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\B04QXYKI\RSDETECT[1].EXE
D:\PROGRAM FILES\TENCENT\QQ\QQ.EXE
D:\PROGRAM FILES\TENCENT\QQ\CQQ45RC\CORALASSIST.DLL
D:\PROGRAM FILES\TENCENT\QQ\CQQ45RC\CORALQQ.DLL
D:\PROGRAM FILES\TENCENT\QQ\CQQ45RC\IPSEARCHER.DLL
D:\PROGRAM FILES\TENCENT\QQ\MFC42.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQBASECLASSINDLL.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQHELPERDLL.DLL
D:\PROGRAM FILES\TENCENT\QQ\BASICCTRLDLL.DLL
D:\PROGRAM FILES\TENCENT\QQ\RICHED32.DLL
D:\PROGRAM FILES\TENCENT\QQ\RICHED20.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQAPI.DLL
D:\PROGRAM FILES\TENCENT\QQ\TIMPROXY.DLL
D:\PROGRAM FILES\TENCENT\QQ\LOGINCTRL.DLL
D:\PROGRAM FILES\TENCENT\QQ\NPKCNTC.DLL
D:\PROGRAM FILES\TENCENT\QQ\NPKPDB.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQRES.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQMAINFRAME.DLL
D:\PROGRAM FILES\TENCENT\QQ\CQQAPPLICATION.DLL
D:\PROGRAM FILES\TENCENT\QQ\NEWSKIN.DLL
D:\PROGRAM FILES\TENCENT\QQ\HOSTINGMGR.DLL
D:\PROGRAM FILES\TENCENT\QQ\CAMERADLL.DLL
D:\PROGRAM FILES\TENCENT\QQ\MAILSUMMARY.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQSPACE.DLL
D:\PROGRAM FILES\TENCENT\QQ\VBSCRIPT.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQGROUPMNG.DLL
D:\PROGRAM FILES\TENCENT\QQ\GROUPLIVE.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQSETTINGCTRL.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQSYSMSGMNG.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQAVATAR.DLL
D:\PROGRAM FILES\TENCENT\QQ\FLASHAVATARDLL.DLL
D:\PROGRAM FILES\TENCENT\QQ\USERDEFINEDHEAD.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQPLUGIN.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQCONFIGPLUGIN.DLL
D:\PROGRAM FILES\TENCENT\QQ\QRINGMNG.DLL
D:\PROGRAM FILES\TENCENT\QQ\PHONEAPI.DLL
D:\PROGRAM FILES\TENCENT\QQ\DIALERALLINONE.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\PROGRAM FILES\TENCENT\QQ\LONGCONNECTION.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQPET.DLL
D:\PROGRAM FILES\TENCENT\QQ\BQQAPPLICATION.DLL
D:\PROGRAM FILES\TENCENT\QQ\COMMERCESMNG.DLL
D:\PROGRAM FILES\TENCENT\QQ\PERSONALDESKTOP.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQADDR.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQSCENEMNG.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQPHONEHELPER.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9.OCX
D:\PROGRAM FILES\TENCENT\QQ\QQALLINONE.DLL
D:\PROGRAM FILES\TENCENT\QQ\SCCORE.DLL
D:\PROGRAM FILES\TENCENT\QQ\GDIPLUS.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQCUSTOMFACE.DLL
C:\WINDOWS\SYSTEM32\IMSC40A.IME
D:\PROGRAM FILES\TENCENT\QQ\SHAREFILES.DLL
D:\PROGRAM FILES\TENCENT\QQ\QQMAGICFACE.DLL
D:\PROGRAM FILES\TENCENT\QQ\TIMPLATFORM.EXE
D:\PROGRAM FILES\TENCENT\QQ\TIMPROXY.DLL
C:\WINDOWS\SYSTEM32\CONIME.EXE
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
RavTask = "D:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
RfwMain = "D:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE" -STARTUP
webService = SYSTEMS.EXE
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\SYSTEM32\NVCPL.DLL,NVSTARTUP
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "D:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde
其它启动项
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
SCRNSAVE.EXE = C:\WINDOWS\System32\logon.scr
Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
ScCertProp = WLNOTIFY.DLL
Schedule = WLNOTIFY.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
termsrv = WLNOTIFY.DLL
wlballoon = WLNOTIFY.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = USERINIT.EXE,
shell = EXPLORER.EXE
IE - BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{889D2FEB-5411-4565-8998-1DD2C5261283} = D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll