1   1  /  1  页   跳转

求救

求救

**** Run Keys ****

RUN: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
RUN: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
RUN: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
RUN: [SoundMan] SOUNDMAN.EXE
RUN: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
RUN: [nwiz] nwiz.exe /install
RUN: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
RUN: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
RUN: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
RUN: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
RUN: [BigDogPath] C:\WINDOWS\VM_STI.EXE USB PC Camera 301P
RUN: [CnsMin] Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
RUN: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
RUN: [assistse] "C:\PROGRA~1\3721\assistse.exe"
RUN: [YDTMain.exe] C:\PROGRA~1\YDT\YDTMain.exe
RUN: [internat.exe] internat.exe
RUN: [MoveSearch] C:\Program Files\wsearch\Search.exe
RUN: [BCUpdate] C:\WINDOWS\System32\BCUP.exe
RUN: [迅雷4] D:\讯雷\Thunder\MediaIssue\TDUpdate.exe
RUN: [ADShow] C:\WINDOWS\System32\bcsysnote.ex
RUN: [ClientQyule] C:\Program Files\Qyule\Qyule.exe
RUN: [sp] rundll32 C:\DOCUME~1\lc\LOCALS~1\Temp\se.dll,DllInstall


**** Browser Helper Objects ****

BHO: [ThunderIEHelper Class] C:\WINDOWS\System32\xunleibho_v5.dll
BHO: [AcroIEHlprObj Class] C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
BHO: [Installer] C:\WINDOWS\System32\baoerins.dll
BHO: [] C:\WINDOWS\System32\UrlCom102.dll
BHO: [] C:\WINDOWS\System32\niai.dll
BHO: [IeCatch2 Class] C:\PROGRA~1\FLASHGET\jccatch.dll
BHO: [Google Toolbar Helper] c:\program files\google\googletoolbar2.dll
BHO: [上网助手] C:\PROGRA~1\3721\assist\asbar.dll
BHO: [CnsHook Class] C:\WINDOWS\downlo~1\CnsHook.dll
BHO: [DragSearch BHO] C:\PROGRA~1\YiSou\yisoub.dll


**** IE Toolbars ****

TOOLBAR: [电台(&R)] C:\WINDOWS\System32\msdxm.ocx
TOOLBAR: [FlashGet Bar] C:\PROGRA~1\FLASHGET\fgiebar.dll
TOOLBAR: [金山快译(&K)] C:\PROGRA~1\Kingsoft\FASTAI~1\IEBand.dll
TOOLBAR: [一搜工具条] C:\Program Files\YiSou\yisou.dll
TOOLBAR: [上网助手] C:\PROGRA~1\3721\assist\asbar.dll
TOOLBAR: [&Google] c:\program files\google\googletoolbar2.dll


**** IE Extensions ****

IEExt: [手机短信] http://sms.3721.com/ie/index.htm
IEExt: [浩方对战平台] D:\浩方\浩方对战平台\GameClient.exe
IEExt: [Yahoo 1G电邮] http://cn.mail.yahoo.com/promo/rd1
IEExt: [寻宝乐趣多] http://hot.3721.com/rd/shop_btn.htm
IEExt: [上网助手] http://assistant.3721.com/index.htm?fb=Cns
IEExt: [网际飞音] C:\Program Files\Donor\donor.exe
IEExt: [词霸] C:\Program Files\Donor\donor.exe
IEExt: [@shdoclc.dll,-866] C:\Program Files\Donor\donor.exe
IEExt: [FlashGet] C:\PROGRA~1\FLASHGET\flashget.exe
IEExt: [情景聊天] http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/
IEExt: [情景聊天] http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/
IEExt: [易趣购物] http://click2.ad4all.net/url2/urlmanage/url.asp?id=65
IEExt: [易趣购物] http://click2.ad4all.net/url2/urlmanage/url.asp?id=65


**** Hosts File Entries ****

HOSTS: 127.0.0.1      localhost


**** IE Settings ****

IEProxy: 211.48.62.46:80
IEBypass: 211.48.62.46:80 207.248.240.118:80;<local>
Default Page: http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default Search: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search Page: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch


**** IE Context Menu (Right click) ****

IEContext: [!搜一搜] res://C:\WINDOWS\downlo~1\CnsMinEx.dll/1003
IEContext: [&使用迅雷下载] D:\讯雷\Thunder\geturl.htm
IEContext: [&使用迅雷下载全部链接] D:\讯雷\Thunder\getAllurl.htm
IEContext: [Google 搜索(&G)] res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
IEContext: [使用网际快车下载] C:\PROGRA~1\FLASHGET\jc_link.htm
IEContext: [使用网际快车下载全部链接] C:\PROGRA~1\FLASHGET\jc_all.htm
IEContext: [反向链接] res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
IEContext: [易趣购物] C:\Program Files\AD4All\link1\ebaylink.htm
IEContext: [添加到QQ自定义面板] D:\QQ\AddPanel.htm
IEContext: [添加到QQ表情] D:\QQ\AddEmotion.htm
IEContext: [用QQ彩信发送该图片] D:\QQ\SendMMS.htm
IEContext: [类似网页] res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
IEContext: [缓存的网页快照] res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
IEContext: [翻译英文字词(&T)] res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html


**** Layered Service Providers ****

LSP: MSAFD Tcpip [TCP/IP]
LSP: MSAFD Tcpip [UDP/IP]
LSP: RSVP UDP Service Provider
LSP: RSVP TCP Service Provider
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{202F025C-E881-482C-8884-63E75E47EC12}] SEQPACKET 3
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{202F025C-E881-482C-8884-63E75E47EC12}] DATAGRAM 3
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{80DD29A5-E83F-48A1-8696-7F88D8199F2E}] SEQPACKET 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{80DD29A5-E83F-48A1-8696-7F88D8199F2E}] DATAGRAM 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{9301317B-05CB-4AD8-AADB-E7DF4515B3D4}] SEQPACKET 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{9301317B-05CB-4AD8-AADB-E7DF4515B3D4}] DATAGRAM 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{FDAD768D-C46E-4929-A9FB-EB782208C486}] SEQPACKET 2
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{FDAD768D-C46E-4929-A9FB-EB782208C486}] DATAGRAM 2


**** Blocked Control Panel Items ****

BLOCKED: [ncpa.cpl] No
BLOCKED: [odbccp32.cpl] No


**** Downloaded Program Files ****

Microsoft XML Parser for Java [file://C:\WINDOWS\Java\classes\xmldso.cab]
{7253A666-8D4A-11D7-A4DC-00E04C504779} [http://www.51zsf.net/BDC.cab] C:\WINDOWS\System32\msvcrt.dll C:\WINDOWS\System32\mfc42.dll C:\WINDOWS\System32\olepro32.dll C:\WINDOWS\Downloaded Program Files\BDC.ocx
{D27CDB6E-AE6D-11CF-96B8-444553540000} [http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab]


**** Custom IE Search Items ****

SEARCH: [CustomizeSearch] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
SEARCH: [SearchAssistant] about:blank
SEARCH: [SearchAssistant] about:blank
SEARCH: [CustomizeSearch] http://seek.3721.com/srchcust.htm
SEARCH: [OCustomizeSearch] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
SEARCH: [OSearchAssistant] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
我中了SEARCHFOR外文站,帮我看看
最后编辑2005-08-20 21:14:36
分享到:
gototop
 

【回复“屁话多”的帖子】
建议使用CoolWeb粉碎机:
下载的地址和教程请参考下面这个链接。
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
gototop
 

......
gototop
 

RUN: [MoveSearch] C:\Program Files\wsearch\Search.exe
RUN: [BCUpdate] C:\WINDOWS\System32\BCUP.exe 
RUN: [ADShow] C:\WINDOWS\System32\bcsysnote.ex
RUN: [ClientQyule] C:\Program Files\Qyule\Qyule.exe
RUN: [sp] rundll32 C:\DOCUME~1\lc\LOCALS~1\Temp\se.dll,DllInstall
BHO: [Installer] C:\WINDOWS\System32\baoerins.dll
BHO: [] C:\WINDOWS\System32\UrlCom102.dll
BHO: [] C:\WINDOWS\System32\niai.dll

请用hijackthis修复以上项目,删除相关文件

hijackThis下载地址见置顶贴
[必读]本版说明及常用小软件下载
http://forum.ikaka.com/topic.asp?board=67&artid=5188931


问题仍在的话,请用最新版Hijackthis1.99.1扫描一个log贴上来。

gototop
 

引用:
【魔法学徒的贴子】RUN: [MoveSearch] C:\Program Files\wsearch\Search.exe
RUN: [BCUpdate] C:\WINDOWS\System32\BCUP.exe 
RUN: [ADShow] C:\WINDOWS\System32\bcsysnote.ex
RUN: [ClientQyule] C:\Program Files\Qyule\Qyule.exe
RUN: [sp] rundll32 C:\DOCUME~1\lc\LOCALS~1\Temp\se.dll,DllInstall
BHO: [Installer] C:\WINDOWS\System32\baoerins.dll
BHO: [] C:\WINDOWS\System32\UrlCom102.dll
BHO: [] C:\WINDOWS\System32\niai.dll

请用hijackthis修复以上项目,删除相关文件

hijackThis下载地址见置顶贴
[必读]本版说明及常用小软件下载
http://forum.ikaka.com/topic.asp?board=67&artid=5188931


问题仍在的话,请用最新版Hijackthis1.99.1扫描一个log贴上来。


...........................


我都不会看那里有问题

附件附件:

下载次数:0
文件类型:image/pjpeg
文件大小:
上传时间:2005-8-20 21:14:36
描述:



gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT