huaxue05 - 2006-7-15 19:21:00
这两天开Maxthon会弹出一个"139要你好玩"的网页,大虾帮忙看看,多谢~~
---------------------------------------------------
D:\本本常用\mobmeter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\conime.exe
D:\HijackThis.exe
R3 - URLSearchHook: 全能助手广告拦截专家 - {ED51E9A3-16C5-4236-99E0-9F093B021433} - D:\WINDOW~1\AssistIEBar.dll
R3 - URLSearchHook: (no name) - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - (no file)
O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\chinanet\VNETTR~1.DLL
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - d:\QQ\QQIEHelper.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - D:\NetTransport\NTIEHelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O3 - Toolbar: 全能助手广告拦截专家 - {ED51E9A3-16C5-4236-99E0-9F093B021433} - D:\WINDOW~1\AssistIEBar.dll
O4 - HKLM\..\Run: [KAVPersonal50] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe /minimize
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iamapp] D:\SYMANT~1\IAMAPP.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\qq\AddToNetDisk.htm
O8 - Extra context menu item: 使用影音传送带下载 - D:\NetTransport\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - D:\NetTransport\NTAddList.html
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\qq\SendMMS.htm
O9 - Extra button: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - d:\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - d:\QQ\QQIEHelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1094285144061
O16 - DPF: {9BBD100C-E820-4930-9937-E8F3AA40E584} (DFVSScanFile Control) - http://antivirus3.sunv.com/dfvsolDown/dfvsol.cab
O16 - DPF: {C8BD9ACB-F7EC-48E6-BB2F-DAADC6789E9A} (Kingsoft DUBA OnlineScan) - http://211.152.52.102/duba/antiscan/update/OCX/KAVClean.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{0728C570-A8DF-4FEC-B273-364ADB4FDEE6}: NameServer = 210.34.240.100,202.101.107.55
O17 - HKLM\System\CCS\Services\Tcpip\..\{88E7A528-48DB-4E86-902F-20808E774B3E}: NameServer = 61.147.37.1 61.177.7.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{0728C570-A8DF-4FEC-B273-364ADB4FDEE6}: NameServer = 210.34.240.100,202.101.107.55
O17 - HKLM\System\CS2\Services\Tcpip\..\{0728C570-A8DF-4FEC-B273-364ADB4FDEE6}: NameServer = 210.34.240.100,202.101.107.55
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - D:\Bluetooth Software\bin\btwdins.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Symantec Client Firewall Service (NISSERV) - Symantec Corporation - D:\Symantec Client Firewall\NISSERV.EXE
O23 - Service: Symantec Client Firewall Accounts Manager (NISUM) - Symantec Corporation - D:\Symantec Client Firewall\NISUM.EXE
O23 - Service: dds (sdasdsd) - Unknown owner - C:\WINDOWS\system32\com\com
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec Client Firewall Proxy Service (SymPxSvc) - Symantec Corporation - D:\Symantec Client Firewall\SymPxSvc.exe
魔法学徒 - 2006-7-15 19:37:00
O23 - Service: dds (sdasdsd) - Unknown owner - C:\WINDOWS\system32\com\com
打开什么网页都会弹出吗?
huaxue05 - 2006-7-16 21:23:00
回楼上,基本是这样的.
今天下游戏,结果又中了广告病毒,过几十秒就弹一次
具体的我有发了个帖,还请帮忙啊,地址http://forum.ikaka.com/topic.asp?board=67&artid=8123207
我无邪 - 2006-7-17 0:15:00
O23 - Service: dds (sdasdsd) - Unknown owner - C:\WINDOWS\system32\com\com
这东东你不识的话就删除
开始→运行→输入services.msc,打开“服务”→查找 dds→双击→启动类型→禁止→停止→应用→确定。禁止dds这个服务
重启删除
C:\WINDOWS\system32\com
如果还没有解决问题
请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改。
huaxue05 - 2006-7-18 14:37:00
最新日志,大家帮忙
Logfile of HijackThis v1.99.1
Scan saved at 14:26:17, on 2006-7-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
D:\Symantec Client Firewall\NISUM.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
D:\SYMANT~1\IAMAPP.EXE
D:\Symantec Client Firewall\SymPxSvc.exe
D:\Symantec Client Firewall\NISSERV.EXE
D:\Symantec Client Firewall\ATRACK.EXE
C:\Program Files\ChinaNet\VnetClient.exe
D:\mcombocn\Maxthon\Maxthon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
D:\HijackThis.exe
O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} -
c:\PROGRA~1\chinanet\VNETTR~1.DLL
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} -
D:\NetTransport\NTIEHelper.dll
O4 - HKLM\..\Run: [KAVPersonal50] C:\Program Files\Kaspersky Lab\Kaspersky
Anti-Virus Personal\kav.exe /minimize
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iamapp] D:\SYMANT~1\IAMAPP.EXE
O4 - HKLM\..\Run: [ATIPTA] ; C:\Program Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DAEMON Tools] ; "d:\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil
/RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMSCMig] ; C:\PROGRA~1\COMMON~1\MICROS~1
\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [Mirabilis ICQ] ; D:\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [MSPY2002] ; C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe
/SYNC
O4 - HKLM\..\Run: [NeroFilterCheck] ; ; C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PHIME2002A] ; ; C:\WINDOWS\system32
\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PHIME2002ASync] ; ; C:\WINDOWS\system32
\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Zone Labs Client] ;
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Any To-Do List] ; "D:\备忘小纸条\AnyToDo.exe"
O4 - HKCU\..\Run: [STYLEXP] ; C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -
Hide
O4 - HKCU\..\Run: [Super Rabbit IEPro] ;
O8 - Extra context menu item: 使用影音传送带下载 -
D:\NetTransport\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 -
D:\NetTransport\NTAddList.html
O8 - Extra context menu item: 使用网际快车下载 - C:\Program
Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program
Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\qq\AddPanel.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuwe
b_site.cab?1094285144061
O16 - DPF: {9BBD100C-E820-4930-9937-E8F3AA40E584} (DFVSScanFile Control) -
http://antivirus3.sunv.com/dfvsolDown/dfvsol.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0728C570-A8DF-4FEC-B273-
364ADB4FDEE6}: NameServer = 210.34.240.100,202.101.107.55
O17 - HKLM\System\CCS\Services\Tcpip\..\{88E7A528-48DB-4E86-902F-
20808E774B3E}: NameServer = 61.147.37.1 61.177.7.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{0728C570-A8DF-4FEC-B273-
364ADB4FDEE6}: NameServer = 210.34.240.100,202.101.107.55
O17 - HKLM\System\CS2\Services\Tcpip\..\{0728C570-A8DF-4FEC-B273-
364ADB4FDEE6}: NameServer = 210.34.240.100,202.101.107.55
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1
\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. -
C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. -
D:\Bluetooth Software\bin\btwdins.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision
Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel
32\IDriverT.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky
Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program
Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Symantec Client Firewall Service (NISSERV) - Symantec
Corporation - D:\Symantec Client Firewall\NISSERV.EXE
O23 - Service: Symantec Client Firewall Accounts Manager (NISUM) - Symantec
Corporation - D:\Symantec Client Firewall\NISUM.EXE
O23 - Service: StyleXPService - Unknown owner - C:\Program
Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec Client Firewall Proxy Service (SymPxSvc) - Symantec
Corporation - D:\Symantec Client Firewall\SymPxSvc.exe
我无邪 - 2006-7-18 14:42:00
看不出问题了
如果还没有解决问题
请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改。
huaxue05 - 2006-7-18 15:01:00
回楼上
2006-07-18,14:51:28
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [Microsoft Corporation]
<Any To-Do List><; "D:\备忘小纸条\AnyToDo.exe"> [Any Utils]
<STYLEXP><; C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide> []
<Super Rabbit IEPro><; > []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<KAVPersonal50><C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe /minimize> [Kaspersky Lab]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> []
<iamapp><D:\SYMANT~1\IAMAPP.EXE> [Symantec Corporation]
<ATIPTA><; C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe> [ATI Technologies, Inc.]
<DAEMON Tools><; "d:\DAEMON Tools\daemon.exe" -lang 1033> [DT Soft Ltd.]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [Microsoft Corporation]
<Mirabilis ICQ><; D:\ICQ\ICQNet.exe> []
<MSPY2002><; C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC> []
<NeroFilterCheck><; ; C:\WINDOWS\system32\NeroCheck.exe> [Ahead Software Gmbh]
<PHIME2002A><; ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<PHIME2002ASync><; ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> []
<Zone Labs Client><; > []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\SYSTEM32\Userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><C:\Program Files\TGTSoft\StyleXP\Logon\CurrentLogon.EXE> []
==================================
启动文件夹
服务
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[Bluetooth Service / btwdins]
<D:\Bluetooth Software\bin\btwdins.exe><Broadcom Corporation.>
[InstallDriver Table Manager / IDriverT]
<"C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"><Macrovision Corporation>
[kavsvc / kavsvc]
<C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe><Kaspersky Lab>
[Macromedia Licensing Service / Macromedia Licensing Service]
<"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[Symantec Client Firewall Service / NISSERV]
<"D:\Symantec Client Firewall\NISSERV.EXE"><Symantec Corporation>
[Symantec Client Firewall Accounts Manager / NISUM]
<"D:\Symantec Client Firewall\NISUM.EXE"><Symantec Corporation>
[StyleXPService / StyleXPService]
<"C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe"><>
[Symantec Client Firewall Proxy Service / SymPxSvc]
<"D:\Symantec Client Firewall\SymPxSvc.exe"><Symantec Corporation>
==================================
浏览器加载项
[VnetCookie Class]
{4E83D567-4697-4F7B-B1F0-A513B01DB89A} <c:\PROGRA~1\chinanet\VNETTR~1.DLL, >
[NTIECatcher Class]
{C56CB6B0-0D96-11D6-8C65-B2868B609932} <D:\NetTransport\NTIEHelper.dll, Xi>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[DFVSScanFile Control]
{9BBD100C-E820-4930-9937-E8F3AA40E584} <C:\WINDOWS\system32\dfvs\dfvsol\DFVSSFOL.ocx, >
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[VnetCookie Class]
{4E83D567-4697-4F7B-B1F0-A513B01DB89A} <c:\PROGRA~1\chinanet\VNETTR~1.DLL, >
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[NTIECatcher Class]
{C56CB6B0-0D96-11D6-8C65-B2868B609932} <D:\NetTransport\NTIEHelper.dll, Xi>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[使用影音传送带下载]
<D:\NetTransport\NTAddLink.html, N/A>
[使用影音传送带下载全部链接]
<D:\NetTransport\NTAddList.html, N/A>
[使用网际快车下载]
<, N/A>
[使用网际快车下载全部链接]
<, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<D:\qq\AddPanel.htm, N/A>
==================================
正在运行的进程
[PID: 504][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 552][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 576][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 624][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 644][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 796][C:\WINDOWS\system32\Ati2evxx.exe] <ATI Technologies Inc.><6.14.10.4114>
[C:\WINDOWS\system32\Ati2edxx.dll] <ATI Technologies, Inc.><6, 14, 10, 2496>
[PID: 808][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 876][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 952][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 988][C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe] <><0, 20, 0, 3000>
[PID: 1064][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1132][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1252][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[C:\WINDOWS\system32\bthcrp.dll] <Broadcom Corporation.><4.0.1.2601>
[C:\WINDOWS\system32\WidcommSdk.dll] <Broadcom Corporation.><4.0.1.2601>
[C:\WINDOWS\system32\wbtapi.dll] <Broadcom Corporation.><4.0.1.2601>
[PID: 1384][D:\Bluetooth Software\bin\btwdins.exe] <Broadcom Corporation.><4.0.1.2601>
[PID: 1412][C:\WINDOWS\system32\inetsrv\inetinfo.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1512][D:\Symantec Client Firewall\NISUM.EXE] <Symantec Corporation><5.0.0.375>
[C:\WINDOWS\system32\SYMSTORE.dll] <Symantec Corporation><4.6.0.53>
[D:\Symantec Client Firewall\NISUMPS.DLL] <Symantec Corporation><5.0.0.375>
[PID: 1748][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[C:\WINDOWS\system32\vdshell.dll] <FarStone Technology Inc.><1, 5, 0, 0>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\shellex.dll] <Kaspersky Lab><5.0.142.1>
[D:\NetTransport\NTIEHelper.dll] <Xi><1.91.12>
[PID: 1792][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[PID: 1948][D:\SYMANT~1\IAMAPP.EXE] <Symantec Corporation><5.0.0.375>
[D:\SYMANT~1\iamevent.dll] <Symantec Corporation><5.0.0.375>
[D:\SYMANT~1\NISRES.DLL] <N/A><N/A>
[C:\WINDOWS\system32\SYMSTORE.dll] <Symantec Corporation><4.6.0.53>
[D:\SYMANT~1\IAMLOG.dll] <Symantec Corporation><5.0.0.375>
[D:\SYMANT~1\N32USERL.DLL] <Symantec Corporation><5.0.0.375>
[D:\SYMANT~1\UMCBK.DLL] <Symantec Corporation><5.0.0.375>
[D:\SYMANT~1\NISALERT.DLL] <Symantec Corporation><5.0.0.375>
[D:\Symantec Client Firewall\NISUMPS.DLL] <Symantec Corporation><5.0.0.375>
[D:\SYMANT~1\IAMCPL.CPL] <Symantec Corporation><5.0.0.375>
[D:\SYMANT~1\tlevel.dll] <Symantec Corporation><5.0.0.375>
[D:\SYMANT~1\NAVAPI32.DLL] <Symantec Corp.><4.1.0.15>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[C:\Program Files\Common Files\Symantec Shared\BRUNOALE.DLL] <Symantec Corporation><5.0.0.375>
[C:\Program Files\Common Files\Symantec Shared\PProfile.dll] <Symantec Corporation><5.0.0.375>
[PID: 236][D:\Symantec Client Firewall\SymPxSvc.exe] <Symantec Corporation><5.0.0.375>
[D:\Symantec Client Firewall\SymProxy.dll] <Symantec Corporation><5.0.0.375>
[C:\WINDOWS\system32\SYMREDIR.dll] <Symantec Corporation><4.6.0.53>
[C:\WINDOWS\system32\SYMSTORE.dll] <Symantec Corporation><4.6.0.53>
[D:\Symantec Client Firewall\NISALERT.DLL] <Symantec Corporation><5.0.0.375>
[D:\Symantec Client Firewall\NISRES.DLL] <N/A><N/A>
[D:\Symantec Client Firewall\ProxyIM.DLL] <Symantec Corporation><5.0.0.375>
[D:\Symantec Client Firewall\StrmFilt.dll] <Symantec Corporation><5.0.0.375>
[D:\Symantec Client Firewall\SymIConv.dll] <Symantec Corporation><5.0.0.375>
[D:\Symantec Client Firewall\SymPxAlt.dll] <Symantec Corporation><5.0.0.375>
huaxue05 - 2006-7-18 15:02:00
[D:\Symantec Client Firewall\SymURL.dll] <Symantec Corporation><5.0.0.375>
[D:\Symantec Client Firewall\iamevent.dll] <Symantec Corporation><5.0.0.375>
[D:\Symantec Client Firewall\PrxyNNTP.DLL] <Symantec Corporation><5.0.0.375>
[D:\Symantec Client Firewall\PrxyHTTP.dll] <Symantec Corporation><5.0.0.375>
[D:\Symantec Client Firewall\NISUMPS.DLL] <Symantec Corporation><5.0.0.375>
[PID: 420][D:\Symantec Client Firewall\NISSERV.EXE] <Symantec Corporation><5.0.0.375>
[D:\Symantec Client Firewall\IAMLOG.dll] <Symantec Corporation><5.0.0.375>
[D:\Symantec Client Firewall\iamevent.dll] <Symantec Corporation><5.0.0.375>
[D:\Symantec Client Firewall\NISRES.DLL] <N/A><N/A>
[C:\WINDOWS\system32\SYMSTORE.dll] <Symantec Corporation><4.6.0.53>
[D:\Symantec Client Firewall\NISUMPS.DLL] <Symantec Corporation><5.0.0.375>
[PID: 1892][D:\Symantec Client Firewall\ATRACK.EXE] <Symantec Corporation><5.0.0.375>
[D:\Symantec Client Firewall\iamevent.dll] <Symantec Corporation><5.0.0.375>
[D:\Symantec Client Firewall\NISRES.DLL] <N/A><N/A>
[C:\WINDOWS\system32\SYMSTORE.dll] <Symantec Corporation><4.6.0.53>
[D:\Symantec Client Firewall\NISUMPS.DLL] <Symantec Corporation><5.0.0.375>
[D:\Symantec Client Firewall\tdit_msg.dll] <Symantec Corporation><5.0.0.375>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[PID: 2076][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 772][C:\Program Files\ChinaNet\VnetClient.exe] <><2005, 3, 7, 1>
[C:\Program Files\ChinaNet\Communicate.dll] <0><2005, 3, 3, 1>
[C:\Program Files\ChinaNet\DialModule.dll] <><2005, 1, 18, 1>
[C:\PROGRA~1\ChinaNet\CLIENT~1.DLL] <><2004, 2, 28, 1>
[C:\PROGRA~1\ChinaNet\PLUGIN~1.OCX] <><2005, 3, 7, 1>
[C:\PROGRA~1\ChinaNet\sign.dll] <0><2004, 12, 1, 1>
[C:\PROGRA~1\ChinaNet\WEBPLU~1.DLL] <><2005, 2, 17, 1>
[C:\PROGRA~1\ChinaNet\PostPlug.dll] <><2004, 12, 16, 2>
[C:\PROGRA~1\ChinaNet\ADVERT~1.OCX] <><2004, 12, 30, 0>
[C:\PROGRA~1\ChinaNet\VnetBs.ocx] <><2004, 11, 18, 1>
[C:\PROGRA~1\ChinaNet\ACCOUN~2.DLL] <><2005, 3, 3, 1>
[C:\PROGRA~1\ChinaNet\AccountMgr.dll] <><2005, 3, 7, 2>
[C:\PROGRA~1\ChinaNet\PLUGIN~2.OCX] <><2005, 2, 24, 1>
[C:\PROGRA~1\ChinaNet\NEWMES~1.DLL] <><2004, 11, 25, 0>
[C:\PROGRA~1\ChinaNet\PassCtrl.dll] <><1, 0, 0, 1>
[C:\WINDOWS\system32\wpcap.dll] <Politecnico di Torino><3, 0, 0, 18>
[C:\WINDOWS\system32\pthreadVC.dll] <N/A><N/A>
[C:\WINDOWS\system32\packet.dll] <Politecnico di Torino><3, 0, 0, 18>
[C:\PROGRA~1\ChinaNet\PlugPush.dll] <><2004, 12, 21, 1>
[C:\PROGRA~1\ChinaNet\ALLINT~1.DLL] <><2004, 11, 23, 1>
[C:\PROGRA~1\ChinaNet\VNetLog.ocx] <><2005, 10, 9, 1>
[C:\PROGRA~1\ChinaNet\StatNum.dll] <><2004, 11, 18, 1>
[C:\PROGRA~1\ChinaNet\VNETON~1.OCX] <><2005, 3, 2, 1>
[C:\PROGRA~1\ChinaNet\ALLFUN~1.DLL] <><2005, 3, 9, 1>
[C:\PROGRA~1\ChinaNet\VnetOptLog.dll] <><2004, 11, 23, 1>
[C:\PROGRA~1\ChinaNet\DialogStyle.dll] <><1, 0, 0, 1>
[C:\PROGRA~1\ChinaNet\Timer.ocx] <><2004, 11, 25, 1>
[C:\PROGRA~1\ChinaNet\VnetSkin.ocx] <GDDC><1, 0, 0, 1>
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpscrch.dll] <Kaspersky Lab><1.0.142.342>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\concl.dll] <Kaspersky Lab><1.0.142.3>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\FSSync.dll] <Kaspersky Lab><5.0.0.0>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\ipc.dll] <Kaspersky Lab><5.0.142.0>
[C:\PROGRA~1\ChinaNet\DlgSkin.ocx] <><1, 0, 0, 1>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[PID: 2756][D:\mcombocn\Maxthon\Maxthon.exe] <MY Soft Technology><1, 5, 0, 95>
[D:\mcombocn\Maxthon\maxzlib.dll] < ><1, 0, 0, 2>
[D:\mcombocn\Maxthon\Services\RealTime\real_time.dll] <><1, 0, 0, 1>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpscrch.dll] <Kaspersky Lab><1.0.142.342>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\concl.dll] <Kaspersky Lab><1.0.142.3>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\FSSync.dll] <Kaspersky Lab><5.0.0.0>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\ipc.dll] <Kaspersky Lab><5.0.142.0>
[C:\WINDOWS\system32\UNISPIM.IME] <北京清华紫光软件股份有限公司><3.0.0.3045>
[C:\WINDOWS\system32\upengine.dll] <北京清华紫光软件股份有限公司><3.0.0.3045>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[PID: 3984][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3784][C:\WINDOWS\system32\taskmgr.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[PID: 2792][D:\本本常用\mobmeter.exe] <hexmagic><0, 3, 1, 0>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[PID: 3612][D:\魔法兔子\MagicSet\winspeed.exe] <Super Rabbit Soft><7.15>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[D:\魔法兔子\MagicSet\shlObj7.ocx] <Sky Software (http://www.ssware.com)><7, 0, 0, 0>
[D:\魔法兔子\MagicSet\vbalIml6.ocx] <vbAccelerator><2.00.0001>
[D:\魔法兔子\MagicSet\vbalexpbar6.ocx] <vbAccelerator><1.00.0009>
[C:\WINDOWS\system32\SSubTmr6.dll] <vbAccelerator><1.01.0003>
[D:\魔法兔子\MagicSet\fv7.ocx] <Sky Software (http://www.ssware.com)><7, 0, 0, 0>
[PID: 3164][E:\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
我无邪 - 2006-7-18 15:06:00
你这样试试,打开一个IE窗口,工具,internte选项,点“删除文件”弹出一个窗口勾选“删除所有脱机内容”删除cookies,确定
运行(双击)System Repair Engineer,使用“系统修复,Internet Explorer”“全选”“修复"看看能不能解决问题。
huaxue05 - 2006-7-18 15:09:00
大哥,还是不行啊~~...............
阿诺8979 - 2006-7-18 15:22:00
C:\WINDOWS\system32\inetsrv\inetinfo.exe
huaxue05 - 2006-7-18 22:40:00
http://ad.aaahaatv.com/sz.html?classid=4914¶m=ADdXNuMj1GODU3RUU4MDQzNzZCQ0JDRUEzQjFFNzU3MDQ0ODExNyZwcm92aW5jZWlkPTE2JmNpdHlpZD04JnVzZXJpcD0yMTguMi4zOC4yNDcmY2xhc3NpZD00OTE0JnNvdXJjZXVybD13d3cueWFob28uY29tLmNuLw%3d%3d
http://139.com/learn12.html?cid=421&classid=4560¶m=ADdXNuMj1GODU3RUU4MDQzNzZCQ0JDRUEzQjFFNzU3MDQ0ODExNyZwcm92aW5jZWlkPTE2JmNpdHlpZD04JnVzZXJpcD0yMTguMi4zOC4yNDcmY2xhc3NpZD00NTYwJnNvdXJjZXVybD13d3cueWFob28uY29tLmNuLw%3d%3d
http://139.com/learn12.html?cid=421&classid=4560¶m=ADdXNuMj1GODU3RUU4MDQzNzZCQ0JDRUEzQjFFNzU3MDQ0ODExNyZwcm92aW5jZWlkPTE2JmNpdHlpZD04JnVzZXJpcD0yMTguMi4zOC4yNDcmY2xhc3NpZD00NTYwJnNvdXJjZXVybD13d3cueWFob28uY29tLmNuLw%3d%3d
主要是这几个网站,还有一些别的~~
© 2000 - 2026 Rising Corp. Ltd.