1   1  /  1  页   跳转

求助高手,有日志

求助高手,有日志

电脑中毒了,会弹出像中了冲击波一样的窗口然后自动关机
Logfile of HijackThis v1.99.1
Scan saved at 13:07:08, on 2006-9-9
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\RocketDock\RocketDock.exe
C:\WINNT\system32\conime.exe
D:\PrcMgr\PrcMgr.exe
C:\Program Files\XTZJQQ\QQ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\mmc.exe
C:\WINNT\regedit.exe
D:\HijackThis.exe

O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ms] C:\Program Files\Microsoft\svhost32.exe
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - C:\Program Files\BitSpirit\bsurl.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1154734667458
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1154734105540
O17 - HKLM\System\CCS\Services\Tcpip\..\{4C7DFEB9-BDDF-4E19-A107-30137E8B76B4}: NameServer = 202.96.104.65
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

最后编辑2006-09-10 15:57:07
分享到:
gototop
 

O4 - HKLM\..\Run: [ms] C:\Program Files\Microsoft\svhost32.exe
非常可疑,我怀疑木马
gototop
 

关闭所有浏览窗口以及一些不必要的程序
运行Hijackthis,扫描结束后在下列选项前打上勾,然后选"修复
O4 - HKLM\..\Run: [ms] C:\Program Files\Microsoft\svhost32.exe
删除
O4 - HKLM\..\Run: [ms] C:\Program Files\Microsoft\svhost32.exe
重启
请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改。
gototop
 

2006-09-09,13:34:19

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <RocketDock><"C:\Program Files\RocketDock\RocketDock.exe">  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <Synchronization Manager><mobsync.exe /logon>  [Microsoft Corporation]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <SoundMan><SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINNT\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{6E44887F-5214-41F2-AB46-4728735C4CC6}><C:\Program Files\Internet Explorer\PLUGINS\system.sys>  []

==================================
启动文件夹
服务
[Logical Disk Manager Administrative Service / dmadmin]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Rising Personal Firewall Service / RfwService]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd]
  <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><N/A>

==================================
浏览器加载项
[IeCatch5 Class]
  {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <C:\Program Files\FlashGet\jccatch.dll, FlashGet>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, N/A>
[FlashGet]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\Program Files\FlashGet\flashget.exe, >
[@msdxmLC.dll,-1@2052,电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINNT\system32\wuweb.dll, Microsoft Corporation>
[MUWebControl Class]
  {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINNT\system32\muweb.dll, Microsoft Corporation>
[&使用迅雷下载]
gototop
 

<C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
  <D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
[用比特精灵下载(&B)]
  <C:\Program Files\BitSpirit\bsurl.htm, N/A>

==================================
正在运行的进程
[PID: 140][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.00.2195.6601>
[PID: 164][\??\C:\WINNT\system32\csrss.exe]  <Microsoft Corporation><5.00.2195.6601>
[PID: 160][\??\C:\WINNT\system32\winlogon.exe]  <Microsoft Corporation><5.00.2195.6970>
[PID: 212][C:\WINNT\system32\services.exe]  <Microsoft Corporation><5.00.2195.6700>
    [C:\WINNT\system32\dmserver.dll]  <VERITAS Software Corp.><2195.6605.297.3>
[PID: 224][C:\WINNT\system32\lsass.exe]  <Microsoft Corporation><5.00.2195.6902>
[PID: 380][c:\program files\rising\rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 32>
    [c:\program files\rising\rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
    [c:\program files\rising\rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [c:\program files\rising\rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
    [c:\program files\rising\rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [c:\program files\rising\rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[PID: 468][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 492][C:\WINNT\system32\spoolsv.exe]  <Microsoft Corporation><5.00.2195.7059>
    [C:\WINNT\system32\CNMLM6e.DLL]  <CANON INC.><1.80.2.50>
    [C:\WINNT\system32\ZLHP2600.DLL]  <Zenographics, Inc.><5, 53, 2611, 0>
    [C:\WINNT\system32\ZLM.dll]  <Zenographics, Inc.><5, 50, 1416, 0>
    [C:\WINNT\system32\hptcpmon.dll]  <Hewlett Packard><2.52.01.002>
    [C:\WINNT\system32\hpzjrd01.dll]  <Hewlett Packard><1.00.01.006>
    [C:\WINNT\system32\HPZJSN01.dll]  <Hewlett Packard Company><1, 0, 0, 3>
    [C:\WINNT\system32\HPTcpMUI.dll]  <Microsoft Corporation><2.52.01.002>
    [C:\WINNT\system32\hptcpmib.dll]  <Hewlett Packard><2.52.01.002>
    [C:\WINNT\system32\spool\PRTPROCS\W32X86\CNMPD6e.DLL]  <CANON INC.><1.80.2.50>
    [C:\WINNT\system32\spool\PRTPROCS\W32X86\IMFPrint.DLL]  <Zenographics, Inc.><5, 54, 330, 0>
    [C:\WINNT\system32\Imf32.dll]  <Zenographics, Inc.><5, 60, 1204, 0>
    [C:\WINNT\system32\ZTAG32.dll]  <Zenographics, Inc.><5, 60, 1210, 0>
    [C:\WINNT\system32\ZSPOOL.dll]  <Zenographics, Inc.><5, 51, 709, 0>
[PID: 524][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 568][C:\WINNT\system32\regsvc.exe]  <Microsoft Corporation><5.00.2195.6701>
[PID: 596][C:\WINNT\system32\MSTask.exe]  <Microsoft Corporation><4.71.2195.6920>
[PID: 636][C:\WINNT\System32\WBEM\WinMgmt.exe]  <Microsoft Corporation><1.50.1085.0100>
[PID: 668][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 700][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 1080][C:\WINNT\Explorer.EXE]  <Microsoft Corporation><5.00.3700.6690>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\Program Files\RocketDock\MouseHook2.dll]  <N/A><N/A>
    [C:\Program Files\FlashGet\jccatch.dll]  <FlashGet><1, 1, 5, 0>
    [C:\Program Files\Thunder
gototop
 

Network\Thunder\ComDlls\XunLeiBHO_002.dll]  <Thunder Networking Technologies,LTD><5, 0, 0, 2>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
[PID: 1100][c:\program files\rising\rfw\RfwMain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 51>
    [c:\program files\rising\rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [c:\program files\rising\rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [c:\program files\rising\rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\Program Files\RocketDock\MouseHook2.dll]  <N/A><N/A>
[PID: 860][C:\WINNT\SOUNDMAN.EXE]  <Realtek Semiconductor Corp.><5.1.05>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
[PID: 892][C:\Program Files\RocketDock\RocketDock.exe]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\Program Files\RocketDock\MouseHook2.dll]  <N/A><N/A>
[PID: 1208][C:\WINNT\system32\conime.exe]  <Microsoft Corporation><5.00.2195.6655>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
[PID: 1220][D:\PrcMgr\PrcMgr.exe]  <www.jpexe.com><4.00>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\Program Files\RocketDock\MouseHook2.dll]  <N/A><N/A>
[PID: 868][C:\Program Files\XTZJQQ\QQ.exe]  <TENCENT><0, 0, 0, 0>
    [C:\Program Files\XTZJQQ\CoralAssist.DLL]  <Coral Team><4.5.0 build 20060515>
    [C:\Program Files\XTZJQQ\CoralQQ.DLL]  <Coral Team><4.5.1 Build 20060620>
    [C:\Program Files\XTZJQQ\ipsearcher.dll]  <><1.0.0.3>
    [C:\Program Files\XTZJQQ\QQBaseClassInDll.dll]  <><1, 0, 0, 1>
    [C:\Program Files\XTZJQQ\QQHelperDll.dll]  <><1, 0, 0, 1>
    [C:\Program Files\XTZJQQ\BasicCtrlDll.dll]  <Tencent><5, 0, 200, 160>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\Program Files\XTZJQQ\LoginCtrl.dll]  <><1, 0, 0, 1>
    [C:\Program Files\XTZJQQ\npkcntc.dll]  <INCA Internet Co., Ltd.><2006, 3, 2, 1>
    [C:\Program Files\XTZJQQ\npkpdb.dll]  <INCA Internet Co., Ltd.><2003, 10, 1, 1>
    [C:\Program Files\XTZJQQ\QQAPI.dll]  <><1, 0, 0, 1>
    [C:\Program Files\RocketDock\MouseHook2.dll]  <N/A><N/A>
    [C:\Program Files\XTZJQQ\QQRes.dll]  <tencent><1, 0, 0, 1>
    [C:\Program Files\XTZJQQ\QQMainFrame.dll]  <N/A><N/A>
    [C:\Program Files\XTZJQQ\CQQApplication.dll]  <N/A><N/A>
    [C:\Program Files\XTZJQQ\NewSkin.dll]  <><1, 0, 0, 1>
    [C:\Program Files\XTZJQQ\HostingMgr.dll]  <><1, 0, 0, 1>
    [C:\Program Files\XTZJQQ\CameraDll.dll]  <><1, 0, 0, 1>
    [C:\Program Files\XTZJQQ\MailSummary.dll]  <><1, 0, 0, 1>
    [C:\Program Files\XTZJQQ\QQSpace.dll]  <><1, 0, 0, 1>
    [C:\WINNT\system32\msdmo.dll]  <N/A><N/A>
    [C:\Program Files\XTZJQQ\QQGroupMng.dll]  <><1, 0, 0, 1>
    [C:\Program Files\XTZJQQ\GroupLive.dll]  <N/A><N/A>
    [C:\Program Files\XTZJQQ\QQSysMsgMng.dll]  <N/A><N/A>
    [C:\Program Files\XTZJQQ\UserDefinedHead.dll]  <><1, 0, 0, 1>
    [C:\Program Files\XTZJQQ\QQPlugin.dll]  <N/A><N/A>
    [C:\Program Files\XTZJQQ\FlashAvatarDll.dll]  <><1, 4, 0, 1>
    [C:\Program Files\XTZJQQ\QQAvatar.dll]  <N/A><N/A>
    [C:\Program Files\XTZJQQ\LongConnection.dll]  <tencent><5, 0, 200, 160>
    [C:\Program Files\XTZJQQ\QQAllInOne.dll]  <N/A><N/A>
    [C:\Program Files\XTZJQQ\SCCore.dll]  <N/A><N/A>
    [C:\Program Files\XTZJQQ\QQCustomFace.dll]  <N/A><N/A>
    [C:\Program Files\XTZJQQ\GroupConnection.dll]  <Tencent><5, 0, 202, 170>
    [C:\Program Files\XTZJQQ\QRingMng.dll]  <N/A><N/A>
    [C:\Program Files\XTZJQQ\QQPet.dll]  <><1, 0, 0, 1>
    [C:\Program Files\XTZJQQ\BQQApplication.dll]  <N/A><N/A>
    [C:\Program Files\XTZJQQ\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
    [C:\Program Files\XTZJQQ\CommercesMng.dll]  <><1, 0, 0, 1>
    [C:\Program Files\XTZJQQ\QQUdpGetFileLib.dll]  <tencent><0, 2, 2, 3>
    [C:\Program Files\XTZJQQ\QQAddr.dll]  <深圳市腾讯计算机系统有限公司><5, 0, 101, 200>
    [C:\Program Files\XTZJQQ\QQSceneMng.dll]  <N/A><N/A>
    [C:\Program Files\XTZJQQ\QQPhoneHelper.dll]  <腾讯科技(深圳)有限公司><2, 0, 6, 60>
    [C:\Program Files\XTZJQQ\ImageOle.dll]  <TODO: <Company name>><1.0.0.1>
    [C:\Program Files\XTZJQQ\QQMagicFace.dll]  <><1, 0, 0, 1>
    [C:\Program Files\XTZJQQ\QQZip.dll]  <tencent><0, 3, 2, 4>
    [C:\WINNT\system32\JPWB.IME]  <常诚研制><4.00.950>
    [C:\Program Files\XTZJQQ\videodevice.dll]  <Tencent><1.5.0.0>
    [C:\Program Files\XTZJQQ\inplus.dll]  <Tencent><1.5.0.0>
    [C:\Program Files\Ringz Studio\Storm Codec\Codecs\VSFilter.dll]  <Gabest><1, 0, 1, 3>
    [C:\Program Files\Ringz Studio\Storm Codec\Codecs\mlcom.ax]  <Moonlight Cordless Ltd><1, 5, 173, 41217>
    [C:\Program Files\Ringz Studio\Storm Codec\Codecs\empgdmx.ax]  <Elecard Ltd.><1, 0, 19, 51017>
    [C:\Program Files\Ringz Studio\Storm Codec\Codecs\RMSplt.ax]  <Gabest><1, 0, 1, 1>
    [C:\WINNT\system32\l3codecx.ax]  <Fraunhofer Institut Integrierte Schaltungen IIS><1, 5, 0, 50>
    [C:\Program Files\XTZJQQ\ShareFiles.dll]  <N/A><N/A>
    [C:\Program Files\XTZJQQ\QQFileTransfer.dll]  <Tencent><5, 0, 202, 180>
    [C:\WINNT\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
[PID: 1252][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2800.1106>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\Program Files\FlashGet\jccatch.dll]  <FlashGet><1, 1, 5, 0>
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll]  <Thunder Networking Technologies,LTD><5, 0, 0, 2>
    [C:\Program Files\RocketDock\MouseHook2.dll]  <N/A><N/A>
    [C:\WINNT\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
    [C:\WINNT\system32\JPWB.IME]  <常诚研制><4.00.950>
[PID: 1504][C:\WINNT\system32\NOTEPAD.EXE]  <Microsoft Corporation><5.00.2140.1>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\Program Files\RocketDock\MouseHook2.dll]  <N/A><N/A>
[PID: 1580][C:\Program Files\WinRAR\WinRAR.exe]  <N/A><N/A>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\Program Files\RocketDock\MouseHook2.dll]  <N/A><N/A>
[PID: 1428][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.295\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\Program Files\Internet Explorer\PLUGINS\system.sys]  <N/A><N/A>
    [C:\Program Files\RocketDock\MouseHook2.dll]  <N/A><N/A>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINNT\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
gototop
 

请到www.27814939.ys168.com,点“我的软件”下载KillBox.exe
重新启动电脑, 开机检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式进入Windows
双击打开KillBox.exe,分别删除
C:\Program Files\Internet Explorer\PLUGINS\system.sys
(删除时勾选“删除前先结束Explorer.EXE进程”不行再试着勾选"删除DLL文件前反注册此文件"
给菜鸟的东东—KillBox的使用技巧
http://forum.ikaka.com/topic.asp?board=28&artid=8160799

打开System Repair Engineer(也就是你的扫描日志软件SREng.exe),使用“启动项目,注册表”来删除以下选项。
C:\Program Files\Internet Explorer\PLUGINS\system.sys

完后,重启动再扫个日志粘上来。
gototop
 

请关闭端口1434 1394 139 445 455 6969 9996 12345端口,如果是冲击波,要打WINDOWS XP KB823980补丁
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT