瑞星卡卡安全论坛
liangzr - 2006-5-10 19:08:00
Logfile of Kaka v2. 0. 0. 8 Scan Module v2. 0. 0. 1
Scan saved at 19:04:10, on 2006-05-10
Platform: Microsoft Windows XP Professional Service Pack 2 (Build 2600)
MSIE: Internet Explorer v6.00 SP2; (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))
Running processes:
[smss.exe]
CommandLine =
[csrss.exe]
CommandLine = C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[winlogon.exe]
CommandLine = winlogon.exe
[SERVICES.EXE]
CommandLine = C:\WINDOWS\system32\services.exe
[LSASS.EXE]
CommandLine = C:\WINDOWS\system32\lsass.exe
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss
[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k NetworkService
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k LocalService
[spoolsv.exe]
CommandLine = C:\WINDOWS\system32\spoolsv.exe
[SCardSvr.exe]
CommandLine = C:\WINDOWS\System32\SCardSvr.exe
[Explorer.EXE]
CommandLine = C:\WINDOWS\Explorer.EXE
[NTRtScan.exe]
CommandLine = "C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe"
[rundll32.exe]
CommandLine = C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\STDSVER.DLL,Service
[TmListen.exe]
CommandLine = "C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe"
[wdfmgr.exe]
CommandLine = C:\WINDOWS\system32\wdfmgr.exe
[PccNTMon.exe]
CommandLine = "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
[POP3Trap.exe]
CommandLine = "C:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exe"
[EOC755.EXE]
CommandLine = "C:\WINDOWS\TEMP\EOC755.EXE"
[OfcPfwSvc.exe]
CommandLine = "C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe"
[ALG.EXE]
CommandLine = C:\WINDOWS\System32\alg.exe
[PccNTUpd.exe]
CommandLine = "C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe"
[IEXPLORE.EXE]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe"
[rundll32.exe]
CommandLine = C:\WINDOWS\SYSTEM32\stdup.dll,Entry
[rundll32.exe]
CommandLine = rundll32.exe C:\Progra~1\IE-BAR\Cast\dmipn.dll,Always
[KkScan.exe]
CommandLine = "D:\上网助手\KkScan.exe"
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://sw.265.com/
R3 - Default URLSearchHook is missing
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINDOWS\system32\wmpdrm.dll
O2 - BHO: MMSAssist BHO - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - Startup: Foxmail.lnk = F:\新建文件夹\Foxmail.exe
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O4 - Global Startup: IE-BAR.lnk = C:\WINDOWS\system32\rundll32.exe
O8 - Extra context menu item: >>彩信发送<< - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
O9 - Extra Button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O9 - Extra 'Tools' menuitem: 彩E精灵设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {43E839C5-E10F-443A-BC1F-F09CFD2ABC77} - http://www.uusee.com/player/updateC.cab
O16 - DPF: {9BDBC41E-C335-4263-83C0-ECE78EE28A33} (SysMonOCX Control) - http://www.ahn.com.cn/aspservice/plugin/myfirewall20.cab
O16 - DPF: {BE9535B7-76FB-4572-AD20-B32BADB3643B} (TV Stream Source) - http://image2.sina.com.cn/cctv/Chaos203b.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} (pCastPanel Class) - http://ps.itv.mop.com/dn/files/pCastCtl_1.0.0.80_20060123.cab
O17 - HKLM\Software\..\Telephony: DomainName = WATCHDATA.COM
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = WATCHDATA.COM
O17 - HKLM\System\CCS\Services\Tcpip\..\{FB1691ED-0D0D-4ECE-89D6-EC84091F1997}: NameServer = 10.0.0.2,202.106.0.20
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O21 - SSODL: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O21 - SSODL: SysTime - {724C75F1-B757-408D-A50A-4CF99DA35D73} - C:\PROGRA~1\winkld\winkld.dll
O23 - Service: Human Interface Device Access (HidServ) - - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Event Service (Popular) - - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: SDAgent Service (SDAgentService) - 北京兴华基业软件技术有限公司 - C:\Program Files\Common Files\smartde\sde.exe
O23 - Service: StdService (StdService) - - C:\WINDOWS\system32\rundll32.exe c:\windows\system32\stdsver.dll,service
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: Windows Install Helper (WalALET) - - C:\WINDOWS\system32\rundll32.exe c:\windows\system32\wbem\irjit.dll,export 1087
拜托了!!!!!!
liangzr - 2006-5-10 19:18:00
我今天杀了一天的病毒.可网页还是不行.
笑世 - 2006-5-10 19:29:00
。。。试试看用雅虎助手修复一下浏览器,再优化一下系统~
我无邪 - 2006-5-10 19:43:00
开始→运行→输入services.msc,打开“服务”→查找SDAgent Service,StdService,Windows Install Helper →双击→启动类型→禁止→停止→应用→确定。禁止SDAgent Service,StdService,Windows Install Helper这3个服务 (每一个逗号隔开的就是一个病毒的服务,请逐一禁用)
进入控制面版的添加删除程序中卸载Winstdup,MMSASS~1彩信,这2个流氓软件
如果无法卸载,建议你下载超级兔子。
http://dl.pconline.com.cn/html_2/1/75/id=273&pn=0.html
安装好后,打开“超级兔子优化王”“专业卸载
如果用卡卡不知如何修复,请下载HijackThis.exe
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
关闭所有浏览窗口以及一些不必要的程序
运行Hijackthis,扫描结束后在下列选项前打上勾,然后选"修复""(如果有的话)
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINDOWS\system32\wmpdrm.dll
O2 - BHO: MMSAssist BHO - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O8 - Extra context menu item: >>彩信发送<< - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
O9 - Extra Button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O9 - Extra 'Tools' menuitem: 彩E精灵设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O21 - SSODL: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
双击我的电脑--工具---文件夹选项--查看--单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示您确定更改时,单击“是”
(请按上述步骤操作,不要略过)
然后找到如下文件并删除(如果有的话)提示C:\PROGRA~1其实为C:\Program Files目录
c:\windows\system32\wbem\irjit.dll
c:\windows\system32\stdsver.dll
C:\Program Files\Common Files\smartde
C:\PROGRA~1\MMSASS~1
C:\WINDOWS\system32\wmpdrm.dll
C:\WINDOWS\SYSTEM32\stdup.dll
liangzr - 2006-5-11 8:33:00
谢谢我无邪 老师,进入控制面版的添加删除程序中卸载Winstdup,MMSASS~1彩信,这2个流氓软件没有找到,这3个(C:\PROGRA~1\MMSASS~1,C:\WINDOWS\system32\wmpdrm.dll,C:\WINDOWS\SYSTEM32\stdup.dll)也删除不了.
不言放弃 - 2006-5-11 8:51:00
【回复“liangzr”的帖子】
C:\WINDOWS\SYSTEM32\stdup.dll是间谍广告插件
具体操作参考
http://forum.ikaka.com/topic.asp?board=28&artid=7971417
C:\WINDOWS\system32\wmpdrm.dll是傲迅浏览器辅助流氓插件
具体操作参考
http://forum.ikaka.com/topic.asp?board=28&artid=7948848
liangzr - 2006-5-11 14:13:00
谢谢楼上大哥,现在比以前好多了。但总有一些删不了。如1116,spoolsv,wmpdrm.dll,MMSAssist.下面是现在的日志:不知还有什么问题,应如何解决。
Logfile of Kaka v2. 0. 0. 8 Scan Module v2. 0. 0. 1
Scan saved at 14:08:17, on 2006-05-11
Platform: Microsoft Windows XP Professional Service Pack 2 (Build 2600)
MSIE: Internet Explorer v6.00 SP2; (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))
Running processes:
[smss.exe]
CommandLine =
[csrss.exe]
CommandLine = C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[winlogon.exe]
CommandLine = winlogon.exe
[SERVICES.EXE]
CommandLine = C:\WINDOWS\system32\services.exe
[LSASS.EXE]
CommandLine = C:\WINDOWS\system32\lsass.exe
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss
[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k NetworkService
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k LocalService
[spoolsv.exe]
CommandLine = C:\WINDOWS\system32\spoolsv.exe
[SCardSvr.exe]
CommandLine = C:\WINDOWS\System32\SCardSvr.exe
[NTRtScan.exe]
CommandLine = "C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe"
[TmListen.exe]
CommandLine = "C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe"
[wdfmgr.exe]
CommandLine = C:\WINDOWS\system32\wdfmgr.exe
[OfcPfwSvc.exe]
CommandLine = "C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe"
[EXPLORER.EXE]
CommandLine = C:\WINDOWS\Explorer.EXE
[PccNTMon.exe]
CommandLine = "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
[rundll32.exe]
CommandLine = "C:\WINDOWS\system32\rundll32.exe" C:\Progra~1\IE-BAR\Cast\dmipn.dll,Always
[IN1507.EXE]
CommandLine = "C:\WINDOWS\TEMP\IN1507.EXE"
[alg.exe]
CommandLine = C:\WINDOWS\System32\alg.exe
[PccNTUpd.exe]
CommandLine = "C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe"
[Foxmail.exe]
CommandLine = "F:\新建文件夹\Foxmail.exe"
[iexplore.exe]
CommandLine = "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
[Manager.exe]
CommandLine = "\\10.0.0.7\sharemgr\Manager.exe"
[KkScan.exe]
CommandLine = "D:\上网助手\KkScan.exe"
R3 - Default URLSearchHook is missing
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINDOWS\system32\wmpdrm.dll
O2 - BHO: MMSAssist BHO - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - Startup: Foxmail.lnk = F:\新建文件夹\Foxmail.exe
O4 - Startup: desktop.ini =
O4 - Startup: 快捷方式 到 wnwb.lnk = D:\wnwb.exe
O4 - Global Startup: desktop.ini =
O8 - Extra context menu item: >>彩信发送<< - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
O9 - Extra Button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O9 - Extra 'Tools' menuitem: 彩E精灵设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {43E839C5-E10F-443A-BC1F-F09CFD2ABC77} - http://www.uusee.com/player/updateC.cab
O16 - DPF: {9BDBC41E-C335-4263-83C0-ECE78EE28A33} (SysMonOCX Control) - http://www.ahn.com.cn/aspservice/plugin/myfirewall20.cab
O16 - DPF: {BE9535B7-76FB-4572-AD20-B32BADB3643B} (TV Stream Source) - http://image2.sina.com.cn/cctv/Chaos203b.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} (pCastPanel Class) - http://ps.itv.mop.com/dn/files/pCastCtl_1.0.0.80_20060123.cab
O17 - HKLM\Software\..\Telephony: DomainName = WATCHDATA.COM
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = WATCHDATA.COM
O17 - HKLM\System\CCS\Services\Tcpip\..\{FB1691ED-0D0D-4ECE-89D6-EC84091F1997}: NameServer = 10.0.0.2,202.106.0.20
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O21 - SSODL: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O21 - SSODL: SysTime - {724C75F1-B757-408D-A50A-4CF99DA35D73} - C:\PROGRA~1\winkld\winkld.dll
O23 - Service: Human Interface Device Access (HidServ) - - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Event Service (Popular) - - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: SDAgent Service (SDAgentService) - - C:\Program Files\Common Files\smartde\sde.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: Windows Install Helper (WalALET) - - C:\WINDOWS\system32\rundll32.exe c:\windows\system32\wbem\irjit.dll,export 1087
我无邪 - 2006-5-11 14:23:00
楼主看来没有修复
请下载使用 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
www.27814939.ys168.com
如果愿意,请通过悄悄话留下你的QQ。
liangzr - 2006-5-12 17:05:00
我无邪你好,以下日志文件。辛苦了,谢谢
2006-05-12,16:58:45
System Repair Engineer 2.0.12.350 (2.0 RC 1)
Windows XP Professional Service Pack 2 - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<OfficeScanNT Monitor><"C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<HomeNow><C:\PROGRA~1\HomeNow\HomeNow.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<avicap32><; >
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<HNETPOLCY><; rundll32.exe C:\DOCUME~1\LIANGZ~1.WAT\LOCALS~1\Temp\RarSFX0\HNETPO~1.DLL,Start>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ISC><; >
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ISC_UpDate><; >
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<KernelFaultCheck><; %systemroot%\system32\dumprep 0 -k>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<MyIMLite><; >
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<MyIMLite_UpDate><; >
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\Userinit.exe,>
==================================
启动文件夹
[快捷方式 到 wnwb]
<C:\Documents and Settings\liangzr.WATCHDATA\「开始」菜单\程序\启动\快捷方式 到 wnwb.lnk><N>
==================================
服务
[OfficeScanNT RealTime Scan / ntrtscan]
<C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe><Trend Micro Inc.>
[OfficeScanNT Personal Firewall / OfcPfwSvc]
<C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe><Trend Micro Inc.>
[SDAgent Service / SDAgentService]
<C:\Program Files\Common Files\smartde\sde.exe><N/A>
[OfficeScanNT Listener / tmlisten]
<C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe><Trend Micro Inc.>
[Windows Install Helper / WalALET]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
==================================
浏览器加载项
[wmpdrm]
{0E674588-66B7-4E19-9D0E-2053B800F69F} <C:\WINDOWS\system32\wmpdrm.dll, N/A>
[MMSAssist BHO]
{6671A431-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[MMSAssistMenu]
{6671A433-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[Edit Class]
{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
[SysMonOCX Control]
{9BDBC41E-C335-4263-83C0-ECE78EE28A33} <C:\WINDOWS\DOWNLO~1\SYSMON~1.OCX, AhnLab>
[TV Stream Source]
{BE9535B7-76FB-4572-AD20-B32BADB3643B} <C:\WINDOWS\system32\FAggr.ax, www.sina.com.cn>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[pCastPanel Class]
{FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} <C:\WINDOWS\Downloaded Program Files\pCastCtl.dll, >
[CPub Object]
{0CA51D02-7739-43EA-8D9A-1E8AD4327B03} <C:\Program Files\P4P\sodaie.dll, N/A>
[wmpdrm]
{0E674588-66B7-4E19-9D0E-2053B800F69F} <C:\WINDOWS\system32\wmpdrm.dll, N/A>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[DragSearch BHO]
{62EED7C6-9F02-42F9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, N/A>
[MMSAssist BHO]
{6671A431-5C3D-463D-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[std software]
{6A512BF7-EC78-4E8D-9841-6C02E8FA9838} <C:\WINDOWS\SYSTEM32\stdup.dll, N/A>
[SysMonOCX Control]
{9BDBC41E-C335-4263-83C0-ECE78EE28A33} <C:\WINDOWS\DOWNLO~1\SYSMON~1.OCX, AhnLab>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[卡卡上网安全助手]
{AFF6E516-CBE5-4F8A-9C2F-38A68013E766} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[AUDIO__MP3 Moniker Class]
{CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[>>彩信发送<<]
<res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm, N/A>
[上传到QQ网络硬盘]
<F:\aa\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<F:\aa\AddPanel.htm, N/A>
[添加到QQ表情]
<F:\aa\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<F:\aa\SendMMS.htm, N/A>
liangzr - 2006-5-12 17:06:00
跟上贴
正在运行的进程
[PID: 444][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 580][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 636][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 712][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 732][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 992][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1052][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1120][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1192][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1304][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1484][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll] <Windows (R) 2000 DDK provider><5.00.2195.1620>
[PID: 1528][C:\WINDOWS\System32\SCardSvr.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2024][C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcDog.dll] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInAPI.dll] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\TimeString.dll] <N/A><N/A>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll] <N/A><N/A>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInMain.dll] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInTray.dll] <Trend Micro Inc.><7.0.0.1040>
[PID: 188][C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\TMSOCK.dll] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\loadhttp.dll] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInAPI.dll] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll] <N/A><N/A>
[C:\Program Files\Trend Micro\OfficeScan Client\libTmCAV.dll] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\Pwd.dll] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcDog.dll] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInMain.dll] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInTray.dll] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\TmUpdate.dll] <Trend Micro Inc.><2,6,0,1362>
[PID: 492][C:\WINDOWS\system32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 1064][C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwCommon.dll] <N/A><N/A>
[C:\Program Files\Trend Micro\OfficeScan Client\ZLib.dll] <Trend Micro Inc.><1.31.0.1708>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll] <N/A><N/A>
[C:\Program Files\Trend Micro\OfficeScan Client\tmCfwApi.dll] <Trend Micro Inc.><1.2.0.1020>
[PID: 496][C:\WINDOWS\TEMP\PM9E30.EXE] <N/A><N/A>
[PID: 1348][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2528][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\MMSASS~1\Mmsass~1.dll] <><1, 2, 0, 3>
[C:\PROGRA~1\winkld\Winkld.dat] <www.88dog.com><2, 0, 0, 1>
[D:\dfjasl\WNMKEY.DLL] <N/A><N/A>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[C:\WINDOWS\system32\icm32.dll] <Microsoft Corporation><5.1.2600.2709 (xpsp_sp2_gdr.050628-1518)>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[PID: 3792][C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\loadhttp.dll] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\Pwd.dll] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInAPI.dll] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll] <N/A><N/A>
[C:\Program Files\Trend Micro\OfficeScan Client\TimeString.dll] <N/A><N/A>
[C:\Program Files\Trend Micro\OfficeScan Client\ntmonres.dll] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInMain.dll] <Trend Micro Inc.><7.0.0.1040>
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInTray.dll] <Trend Micro Inc.><7.0.0.1040>
[PID: 3788][C:\PROGRA~1\HomeNow\HomeNow.exe] <N/A><N/A>
[PID: 576][D:\dfjasl\wnwb.exe] <五笔爱好者论坛 www.wbfans.com ><2005, 4, 3, 1>
[D:\dfjasl\WNMKEY.DLL] <N/A><N/A>
[PID: 680][C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe] <Trend Micro Inc.><7.0.0.1040>
[PID: 1640][F:\新建文件夹\Foxmail.exe] <Boda Network Technology Inc.><5.0>
[F:\新建文件夹\FoxAntiSpam.dll] <N/A><N/A>
[D:\dfjasl\WNMKEY.DLL] <N/A><N/A>
[F:\新建文件夹\3rdParty\punylib.dll] <CNNIC><1, 0, 0, 3>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[F:\新建文件夹\3rdParty\cmplugin.dll] <N/A><N/A>
[PID: 3392][C:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exe] <Trend Micro Incorporated.><10.0.5.1159>
[C:\Program Files\Trend Micro\OfficeScan Client\POP3UTIL.dll] <Trend Micro Incorporated.><10.0.4.1141>
[C:\Program Files\Trend Micro\OfficeScan Client\tmdbg.dll] <N/A><N/A>
[C:\Program Files\Trend Micro\OfficeScan Client\tmCfwApi.dll] <Trend Micro Inc.><1.2.0.1020>
[PID: 3980][\\10.0.0.7\sharemgr\Manager.exe] <N/A><N/A>
[\\10.0.0.7\sharemgr\mgrrtl.bpl] <N/A><N/A>
[\\10.0.0.7\sharemgr\mgrcom.bpl] <N/A><N/A>
[C:\WINDOWS\system32\midas.dll] <Borland Software Corporation><7.1.1692.668>
[D:\dfjasl\WNMKEY.DLL] <N/A><N/A>
[\\10.0.0.7\sharemgr\Sys.DLL] <N/A><N/A>
[\\10.0.0.7\sharemgr\Mrp.DLL] <N/A><N/A>
[C:\WINDOWS\system32\Vcf132.ocx] <Visual Components, Inc.><4.1.0.5>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[\\10.0.0.7\sharemgr\Inv.DLL] <N/A><N/A>
[PID: 1932][C:\Program Files\Internet Explorer\IEXPLORE.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\kakatool.dll] <Beijing Rising Technology Co., Ltd.><2, 0, 0, 8>
[C:\WINDOWS\system32\wmpdrm.dll] <N/A><2.0.0.1>
[C:\PROGRA~1\MMSASS~1\Mmsass~1.dll] <><1, 2, 0, 3>
[D:\dfjasl\WNMKEY.DLL] <N/A><N/A>
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[PID: 2412][D:\sreng2\SREng.exe] <Smallfrogs Studio><2.0.12.350>
[D:\dfjasl\WNMKEY.DLL] <N/A><N/A>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
我无邪 - 2006-5-12 20:38:00
下载超级兔子。
http://dl.pconline.com.cn/html_2/1/75/id=273&pn=0.html
安装好后,打开“超级兔子优化王”“专业卸载,卸载所有除迅雷外的垃圾软件。
卸载完后,请重启,重启后,随便打开浏览器,上上网。再打开专业卸载,看看是否还有提示未卸载的软件。
运行System Repair Engineer,点“启动项目,服务,勾选“隐藏微软服务”选中病毒服务SDAgent Service,Windows Install Helper选择“删除所选服务”“否”最后重启。(每一个逗号隔开的就是一个病毒的服务,请逐一删除)
以下两项不知,如果你也不知道,建议修复。
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<HomeNow><C:\PROGRA~1\HomeNow\HomeNow.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<HNETPOLCY><; rundll32.exe C:\DOCUME~1\LIANGZ~1.WAT\LOCALS~1\Temp\RarSFX0\HNETPO~1.DLL,Start>
ALT+CTRL+DELETE调出任务管理器,终止所有RUNDLL32.EXE 的进程,如果无法终止,请到www.27814939.ys168.com下载诺顿进程管理器终止所有RUNDLL32.EXE 的进程
关闭所有浏览窗口以及一些不必要的程序
运行System Repair Engineer,使用“启动项目,注册表”来删除以下选项。
(如果在注册表里无法识别那一下,可以选中一项后,点“编辑”这样会有很明细的路径)
删除
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<HomeNow><C:\PROGRA~1\HomeNow\HomeNow.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<HNETPOLCY><; rundll32.exe C:\DOCUME~1\LIANGZ~1.WAT\LOCALS~1\Temp\RarSFX0\HNETPO~1.DLL,Start>
运行System Repair Engineer,使用“系统修复,浏览器加载项”来删除以下选项。
wmpdrm]
{0E674588-66B7-4E19-9D0E-2053B800F69F} <C:\WINDOWS\system32\wmpdrm.dll, N/A>
[MMSAssist BHO]
{6671A431-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[MMSAssistMenu]
{6671A433-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll,
[Edit Class]
{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
pCastPanel Class]
[MMSAssist BHO]
{6671A431-5C3D-463D-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[std software]
{6A512BF7-EC78-4E8D-9841-6C02E8FA9838} <C:\WINDOWS\SYSTEM32\stdup.dll, N/A>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
双击我的电脑--工具---文件夹选项--查看--单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示您确定更改时,单击“是”
(请按上述步骤操作,不要略过)
然后找到如下文件并删除(如果有的话)提示C:\PROGRA~1其实为C:\Program Files目录
C:\PROGRA~1\HomeNow
C:\DOCUME~1\LIANGZ~1.WAT\LOCALS~1\Temp(删除所有能删除的东东
C:\Program Files\Common Files\smartde
C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL
C:\WINDOWS\system32\wmpdrm.dll
C:\PROGRA~1\MMSASS~1
C:\WINDOWS\system32\CMBEdit.dll
C:\WINDOWS\SYSTEM32\stdup.dll
liangzr - 2006-5-13 16:20:00
我下了超级兔子做了半天,其它照你写的弄了.现在出现了新问题,我的桌面程序explorer.exe好像被禁止了,开机后无法显示桌面.任务栏也没有.但可以进行任务管理器进行打开程序.在进程里也没有explorer.exe,我试着打开新任务explorer.exe,但出一下,就自动关闭了.请快帮帮我呀.谢谢
我无邪 - 2006-5-13 16:30:00
1. 右键单击桌面。
2. 指向排列图标。
3. 单击显示桌面图标。
去试试,不行烦再报上来
liangzr - 2006-5-13 17:14:00
没有进入桌面,不能右键单击桌面.
liangzr - 2006-5-13 19:46:00
谢谢大家对我的帮助。我在这里谢过了。我的问题已经解决了。谢谢《我无邪》
我无邪 - 2006-5-13 19:56:00
你试试看win+R键,(就是在键盘左边最下面第二个,有着微软薇标的那个)能调出运行吗?
如果能,就这样再试试。
开始--运行
regedit
找到
HKEY_CURRENT_USER\software\microsoft\windows\current version\polices\exlorer,右边的nodesktop,键值修改为 "0 "
重启一下试试。
1
© 2000 - 2026 Rising Corp. Ltd.