在上网的时候总是会自动跳出www.121818.com等一大排莫名其妙的网站
这个使用System Repair Engineer扫的,希望各位高手帮忙看看!2006-03-14,18:42:44
System Repair Engineer 2.0.12.350 (2.0 RC 1)
Windows 98 Second Edition
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ScanRegistry><C:\WINDOWS\scanregw.exe /autorun>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TaskMonitor><C:\WINDOWS\taskmon.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SystemTray><SysTray.Exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<LoadPowerProfile><Rundll32.exe powrprof.dll,LoadCurrentPwrScheme>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvMcTray.dll,NvTaskbarInit>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<CnsMin><Rundll32.exe C:\WINDOWS\DOWNLO~1\CNSMIN.DLL,Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<LoadPowerProfile><Rundll32.exe powrprof.dll,LoadCurrentPwrScheme>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<SchedulingAgent><mstask.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<RsCcenter><"C:\Program Files\Rising\Rav\CCenter.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<RavMond><"C:\Program Files\Rising\Rav\RavMond.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<RavMon><"C:\Program Files\Rising\Rav\RavMon.exe" -system>
==================================
启动文件夹
[Microsoft Office]
<C:\WINDOWS\Start Menu\Programs\启动\Microsoft Office.lnk><N>
==================================
服务
==================================
浏览器加载项
[@shdoclc.dll,-866@2052,相关站点]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[雅虎助手]
{5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A>
[寻宝乐趣多]
{59BC54A2-56B3-44a0-93E5-432D58746E26} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao, N/A>
[Yahoo 1G电邮]
{507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A>
[情景聊天]
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg, N/A>
[]
{FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A>
[]
{ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A>
[Shockwave Flash
Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX, Macromedia, Inc.>
[IEDown Class]
{D0A29C6C-AA71-4423-8C4A-5998B774C448} <C:\WINDOWS\SYSTEM\GLIEDO~1.DLL, 联众公司>
==================================
正在运行的进程
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4294946989][C:\WINDOWS\SYSTEM\MPREXE.EXE] <Microsoft Corporation><4.10.1998>
[PID: 4294844497][C:\WINDOWS\SYSTEM\MSTASK.EXE] <Microsoft Corporation><4.71.1959.1>
[PID: 4294847853][C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\PROGRAM FILES\RISING\RAV\SCANNET.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\PROGRAM FILES\RISING\RAV\EXTOLE.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\PROGRAM FILES\RISING\RAV\UNPACKER.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\PROGRAM FILES\RISING\RAV\SCANEXEC.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\PROGRAM FILES\RISING\RAV\SCANSCT.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\PROGRAM FILES\RISING\RAV\SCANMAC.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\PROGRAM FILES\RISING\RAV\NVFILE.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\PROGRAM FILES\RISING\RAV\SCANEX.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\PROGRAM FILES\RISING\RAV\UNEXE.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\PROGRAM FILES\RISING\RAV\POSTTRT.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\PROGRAM FILES\RISING\RAV\ENGINE.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
[C:\PROGRAM FILES\RISING\RAV\SPAMENG.DLL] <N/A><18, 0, 0, 4>
[C:\PROGRAM FILES\RISING\RAV\MAILMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\PROGRAM FILES\RISING\RAV\MEMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
[C:\PROGRAM FILES\RISING\RAV\HOOKWEB.DLL] <rising><18, 0, 0, 1>
[C:\PROGRAM FILES\RISING\RAV\REGMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\PROGRAM FILES\RISING\RAV\VIRUSLIB.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\PROGRAM FILES\RISING\RAV\LIBLOAD.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\PROGRAM FILES\RISING\RAV\SCANNER.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
[C:\PROGRAM FILES\RISING\RAV\HOOKSYS.DLL] <Rising><18, 1, 0, 9>
[C:\PROGRAM FILES\RISING\RAV\RSLOG.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL] <rising><18, 0, 0, 1>
[PID: 4294852485][C:\PROGRAM FILES\RISING\RAV\RAVMOND.EXE] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 16>
[C:\PROGRAM FILES\RISING\RAV\BWLIST.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\PROGRAM FILES\RISING\RAV\PNGDLL.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL] <rising><18, 0, 0, 1>
[C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[PID: 4294896217][C:\PROGRAM FILES\RISING\RAV\RAVMON.EXE] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 16>
[C:\PROGRAM FILES\RISING\RAV\BWLIST.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\PROGRAM FILES\RISING\RAV\RSGUILIB.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
[C:\WINDOWS\SYSTEM\DHCPCSVC.DLL] <N/A><N/A>
[C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\PROGRAM FILES\WINRAR\RAREXT.DLL] <N/A><N/A>
[C:\WINDOWS\SYSTEM\VDSHELL.DLL] <FarStone Technology Inc.><1, 5, 0, 0>
[C:\WINDOWS\SYSTEM\RAVEXT.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\WINDOWS\SYSTEM\SYSTEM.DLL] <><5.0.2159.6601>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSHOOK.DLL] <北京三七二一科技有限公司><1, 0, 2, 7>
[PID: 4294795929][C:\WINDOWS\EXPLORER.EXE] <Microsoft Corporation><4.72.3110.1>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4294771333][C:\WINDOWS\SYSTEM\RPCSS.EXE] <Microsoft Corporation><4.71.2900>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSIO.DLL] <北京三七二一科技有限公司><1, 0, 2, 7>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMINIO.DLL] <北京三七二一科技有限公司><1, 0, 3, 6>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4294746977][C:\WINDOWS\RUNDLL32.EXE] <Microsoft Corporation><4.10.1998>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4294660213][C:\WINDOWS\TASKMON.EXE] <Microsoft Corporation><4.10.1998>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4294663673][C:\WINDOWS\SYSTEM\SYSTRAY.EXE] <Microsoft Corporation><4.10.2222>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4294692249][C:\WINDOWS\SYSTEM\DDHELP.EXE] <Microsoft Corporation><4.09.00.0900>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL] <rising><18, 0, 0, 1>
[C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 4294695409][C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[PID: 4294645925][C:\WINDOWS\SYSTEM\WMIEXE.EXE] <Microsoft Corporation><5.00.1755.1>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[PID: 4294704557][C:\WINDOWS\SYSTEM\RNAAPP.EXE] <Microsoft Corporation><4.10.2222>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4294594769][C:\WINDOWS\SYSTEM\TAPISRV.EXE] <Microsoft Corporation><4.10.2222>
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\CNSMIN.DLL] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] <N/A><N/A>
[PID: 4294558905][D:\下载\新建文件夹 (2)\SRENG.EXE] <Smallfrogs Studio><2.0.12.350>
==================================
文件关联
.TXT OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [C:\WINDOWS\winhlp32.exe %1]
.INI OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS OK. [C:\WINDOWS\WScript.exe "%1" %*]
.JS OK. [C:\WINDOWS\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================