1   1  /  1  页   跳转

【求助】IE恶意弹出网页

【求助】IE恶意弹出网页

浏览时总是弹出一些网页 而且每次都是4.5张

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <Super Rabbit IEPro><D:\Program Files\MagicSet\SRIECLI.EXE /LOAD>  [Super Rabbit Soft]
    <msnnt><; C:\WINDOWS\mcUpdate.exe>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
    <run><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <RavTask><"D:\Program Files\TOOLS\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  []
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <MoveSearch><C:\Program Files\HuaCi\huaci\zsearch.exe>  [中搜在线]
    <spoolsv><C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer>  [广州傲讯信息科技有限公司]
    <bgoomain.exe><C:\PROGRA~1\baigoo\bgoomain.exe>  [BGoo]
    <LetsCool><C:\Program Files\LetsCool\LetsCool.exe>  []
    <RichMedia><C:\WINDOWS\system32\Rundll32.exe  "C:\PROGRA~1\hbclient\HBHelper.dll",WaitWindows>  [Shanghai Henbang Technology Co., Ltd]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\nbekm.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <stdup><C:\WINDOWS\System32\stdup.dll>  [MStdup Co Ltd.]
    <Vision><C:\PROGRA~1\MMSASS~1\Mmsass~1.dll>  []

==================================
启动文件夹
服务
[InstallDriver Table Manager / IDriverT]
  <"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[iPodService / iPodService]
  <C:\Program Files\iPod\bin\iPodService.exe><Apple Computer, Inc.>
[MSCSPTISRV / MSCSPTISRV]
  <"C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe"><Sony Corporation>
[PACSPTISVR / PACSPTISVR]
  <"C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe"><Sony Corporation>
[PeanuthullCore / PeanuthullCore]
  <><N/A>
[Rising Personal Firewall Service / RfwService]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
  <"D:\Program Files\TOOLS\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"D:\Program Files\TOOLS\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Sony SPTI Service / SPTISRV]
  <"C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe"><Sony Corporation>
[SonicStage SCSI Service / SSScsiSV]
  <C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe><Sony Corporation>
[Ulead Burning Helper / UleadBurningHelper]
  <C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe><Ulead Systems, Inc.>
[XDownloadService / XDownloadService]
  <C:\WINDOWS\system32\Rundll32.exe "C:\WINDOWS\Downloader.dll",Run><N/A>

==================================
浏览器加载项
[WebThunder Browser Helper]
  {00000AAA-A363-466E-BEF5-9BB68697AA7F} <D:\Program Files\TOOLS\WebThunder\WebThunderBHO_011.dll, Thunder Networking Technologies,LTD>
[wmpdrm]
  {0E674588-66B7-4E19-9D0E-2053B800F69F} <C:\WINDOWS\system32\wmpdrm.dll, Allsum Info. Tech. Ltd.>
[CdnForIE Class]
  {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[ActiveBHO Class]
  {63C55A7F-6E29-8D4F-5C76-4F850F28D13A} <C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll, >
[MMSAssist BHO]
  {6671A431-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[stdup]
  {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} <C:\WINDOWS\System32\stdup.dll, MStdup Co Ltd.>
[超级兔子上网精灵]
  {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <D:\Program Files\MagicSet\haokanbar.dll, Xiang Feng Technology>
[BandIE Class]
  {77FEF28E-EB96-44FF-B511-3185DEA48697} <C:\Progra~1\Baidu\bar\BaiDuBar.dll, Baidu.com, Inc.>
[Status Class]
  {7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} <C:\Program Files\baigoo\BGooBHO.dll, >
[IEHlprObj Class]
  {999ADFA2-8AD1-47ff-97FC-69FB847458F4} <C:\Progra~1\NetMeeting\nmview.dll, Microsoft Corporation>
[HBObject Class]
  {AE22AFE5-1EF4-4D25-9E23-D2825FB17DA1} <C:\PROGRA~1\hbclient\HBHelper.dll, Shanghai Henbang Technology Co., Ltd>
[Flash 8 ocx ]
  {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} <C:\WINDOWS\system32\flash8.dll, MACROMEDlA>
[WebDownloader Class]
  {E78F50F9-51CF-40EC-AE3F-4F802528150B} <C:\WINDOWS\Downloader.dll, >
[Letscool System Helper]
  {F0C15012-7DBD-4068-95A2-0A82DB03AC35} <C:\WINDOWS\system32\CoolBho.dll, LETSCOOL Network Technology>
[CdnForIE Class]
  {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[MMSAssistMenu]
  {6671A433-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[启动Web迅雷]
  {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[易趣购物]
  {EE60714F-AC17-427e-861A-FD60CBDF119A} <http://click2.ad4all.net/url2/urlmanage/url.asp?id=50, N/A>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[百度超级搜霸]
  {B580CF65-E151-49C3-B73F-70B13FCA8E86} <C:\Progra~1\Baidu\bar\BaiDuBar.dll, Baidu.com, Inc.>
[超级兔子上网精灵]
  {43869BB3-22FD-4F15-9B46-238106BA2F4E} <D:\Program Files\MagicSet\haokanbar.dll, Xiang Feng Technology>
[Checkers Class]
  {00B71CFB-6864-4346-A978-C0A14556272C} <, N/A>
[Minesweeper Flags Class]
  {2917297F-F02B-4B9D-81DF-494B6333150B} <C:\WINDOWS\Downloaded Program Files\minesweeper.dll, Microsoft Corporation>
[Microsoft Chart Control 6.0 (SP4) (OLEDB)]
  {3A2B370C-BA0A-11D1-B137-0000F8753F5D} <C:\WINDOWS\system32\MSCHRT20.OCX, Microsoft Corporation>
[WebActivater Control]
  {3D8F74EE-8692-4F8F-B8D2-7522E732519E} <C:\WINDOWS\system32\WEBACT~1.OCX, QQ>
[Office Update Installation Engine]
  {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} <C:\WINDOWS\opuc.dll, Microsoft Corporation>
[MSN Photo Upload Tool]
  {4F1E5B1A-2A80-42CA-8532-2D05CB959537} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
[FMClass Class]
  {637BB540-6ABA-11D4-901D-00D0090CB3BC} <C:\WINDOWS\system32\flashant\fmplayer\fmplayer.dll, Flashants Inc.>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[FTPone Control]
  {7FA9F9B3-FCD6-428A-A9CA-D181A2A39822} <C:\WINDOWS\DOWNLO~1\FTPONE~1.OCX, >
[Java Plug-in 1.4.1]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\j2re1.4.1\bin\npjpi141.dll, JavaSoft / Sun Microsystems, Inc.>
[MessengerStatsClient Class]
  {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} <C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll, Microsoft Corporation>
[LoaderCore Class]
  {98A62E3F-A8C5-4EF0-8A00-C70CF9D18A89} <, N/A>
[photo_uploader Control]
  {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <D:\PROGRA~1\Netease\popo2004\PHOTO_~1.OCX, N/A>
[Qzone Media Tools]
  {AC3A36A8-9BFF-410A-A33D-2279FFEB69D2} <D:\PROGRA~1\QQ\QQ2005\QQ\VQQPLA~1.OCX, Tencent Technology (Shenzhen) Company Limited>
[MsnMessengerSetupDownloadControl Class]
  {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} <C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx, Microsoft Corporation>
[Java Plug-in 1.4.1]
  {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} <C:\Program Files\Java\j2re1.4.1\bin\npjpi141.dll, JavaSoft / Sun Microsystems, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[Persits Software XUpload]
  {E87F6C8E-16C0-11D3-BEF7-009027438003} <C:\WINDOWS\Downloaded Program Files\XUpload.ocx, Persits Software, Inc.>
[Solitaire Showdown Class]
  {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} <, N/A>
[WebThunder Browser Helper]
  {00000AAA-A363-466E-BEF5-9BB68697AA7F} <D:\Program Files\TOOLS\WebThunder\WebThunderBHO_011.dll, Thunder Networking Technologies,LTD>
[QuickTime Object]
  {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} <C:\Program Files\QuickTime\QTPlugin.ocx, Apple Computer, Inc.>
[wmpdrm]
  {0E674588-66B7-4E19-9D0E-2053B800F69F} <C:\WINDOWS\system32\wmpdrm.dll, Allsum Info. Tech. Ltd.>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[MathPlayer Factory Class]
  {32F66A20-7614-11D4-BD11-00104BD3F987} <C:\Program Files\Design Science\MathPlayer\MathPlayer.dll, N/A>
[Tabular Data Control]
  {333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
[Microsoft Chart Control 6.0 (SP4) (OLEDB)]
  {3A2B370C-BA0A-11D1-B137-0000F8753F5D} <C:\WINDOWS\system32\MSCHRT20.OCX, Microsoft Corporation>
[IE Browser Helper]
  {3CE496D1-1746-41CD-9489-3C0B93DF10E2} <, N/A>
[超级兔子上网精灵]
  {43869BB3-22FD-4F15-9B46-238106BA2F4E} <D:\Program Files\MagicSet\haokanbar.dll, Xiang Feng Technology>
[MSN Photo Upload Tool]
  {4F1E5B1A-2A80-42CA-8532-2D05CB959537} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
[Microsoft Licensed Class Manager 1.0]
  {5220CB21-C88D-11CF-B347-00AA00A28331} <C:\WINDOWS\system32\licmgr10.dll, Microsoft Corporation>
[HHCtrl Object]
  {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
最后编辑2006-07-21 13:00:27
分享到:
gototop
 

[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[CdnForIE Class]
  {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[ActiveBHO Class]
  {63C55A7F-6E29-8D4F-5C76-4F850F28D13A} <C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll, >
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[MMSAssist BHO]
  {6671A431-5C3D-463D-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[stdup]
  {6A512BF7-EC78-4E8D-9841-6C02E8FA9838} <C:\WINDOWS\System32\stdup.dll, MStdup Co Ltd.>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[BHOImp Class]
  {70AFF2CB-9DA2-499C-8D15-900729FCE83D} <, N/A>
[超级兔子上网精灵]
  {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <D:\Program Files\MagicSet\haokanbar.dll, Xiang Feng Technology>
[MediaComm Class]
  {7670648D-461B-42AF-BDFE-46D26AF5EFF2} <D:\Program Files\TOOLS\WebThunder\MediaAddin06.dll, Thunder Networking Technologies,LTD>
[BandIE Class]
  {77FEF28E-EB96-44FF-B511-3185DEA48697} <C:\Progra~1\Baidu\bar\BaiDuBar.dll, Baidu.com, Inc.>
[Status Class]
  {7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} <C:\Program Files\baigoo\BGooBHO.dll, >
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Java Plug-in 1.4.1]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\j2re1.4.1\bin\npjpi141.dll, JavaSoft / Sun Microsystems, Inc.>
[Windows Live Sign-in Helper]
  {9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
[IEHlprObj Class]
  {999ADFA2-8AD1-47FF-97FC-69FB847458F4} <C:\Progra~1\NetMeeting\nmview.dll, Microsoft Corporation>
[photo_uploader Control]
  {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <D:\PROGRA~1\Netease\popo2004\PHOTO_~1.OCX, N/A>
[HBObject Class]
  {AE22AFE5-1EF4-4D25-9E23-D2825FB17DA1} <C:\PROGRA~1\hbclient\HBHelper.dll, Shanghai Henbang Technology Co., Ltd>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[卡卡上网安全助手]
  {AFF6E516-CBE5-4F8A-9C2F-38A68013E766} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[百度超级搜霸]
  {B580CF65-E151-49C3-B73F-70B13FCA8E86} <C:\Progra~1\Baidu\bar\BaiDuBar.dll, Baidu.com, Inc.>
[Flash 8 ocx ]
  {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} <C:\WINDOWS\system32\flash8.dll, MACROMEDlA>
[Adobe Acrobat Control for ActiveX]
  {CA8A9780-280D-11CF-A24D-444553540000} <C:\PROGRA~1\Adobe\ACROBA~2.0\Reader\ActiveX\pdf.ocx, Adobe Systems Incorporated>
[VIDEO__X_MS_ASF Moniker Class]
  {CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
  {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Windows Live Sign-in Control]
  {D2517915-48CE-4286-970F-921E881B8C5C} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[WebDownloader Class]
  {E78F50F9-51CF-40EC-AE3F-4F802528150B} <C:\WINDOWS\Downloader.dll, >
[Letscool System Helper]
  {F0C15012-7DBD-4068-95A2-0A82DB03AC35} <C:\WINDOWS\system32\CoolBho.dll, LETSCOOL Network Technology>
[>>彩信发送<<]
  <res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm, N/A>
[使用Web迅雷下载]
  <D:\Program Files\TOOLS\WebThunder\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
  <D:\Program Files\TOOLS\WebThunder\GetAllUrl.htm, N/A>
[百度-搜索MP3]
  <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUMP3.HTM, N/A>
[百度-搜索图片]
  <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUIMG.HTM, N/A>
[百度-搜索新闻]
  <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUNEWS.HTM, N/A>
[百度-搜索歌词]
  <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDULYRIC.HTM, N/A>
[百度-搜索网页]
  <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUSEARCH.HTM, N/A>
[百度-搜索贴吧]
  <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUPOST.HTM, N/A>
[百度-词典搜索]
  <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDU_DIC.HTM, N/A>
[访问通用网址]
  <C:\Program Files\CNNIC\Cdn\cnnic.htm, N/A>

==================================
正在运行的进程
[PID: 832][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 888][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 912][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 956][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 968][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1136][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1204][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1384][D:\Program Files\TOOLS\Rising\Rav\CCenter.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1400][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1456][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1940][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1972][D:\Program Files\TOOLS\Rising\Rav\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 29>
    [D:\Program Files\TOOLS\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [D:\Program Files\TOOLS\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [D:\Program Files\TOOLS\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [D:\Program Files\TOOLS\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\Program Files\TOOLS\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\Program Files\TOOLS\Rising\Rav\RsLog.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
    [D:\Program Files\TOOLS\Rising\Rav\HOOKSYS.dll]  <Rising><18, 1, 0, 9>
gototop
 

[D:\Program Files\TOOLS\Rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [D:\Program Files\TOOLS\Rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\Program Files\TOOLS\Rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\Program Files\TOOLS\Rising\Rav\regmon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [D:\Program Files\TOOLS\Rising\Rav\HookWeb.dll]  <rising><18, 0, 0, 2>
    [D:\Program Files\TOOLS\Rising\Rav\MemMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [D:\Program Files\TOOLS\Rising\Rav\expscan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\Program Files\TOOLS\Rising\Rav\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
    [D:\Program Files\TOOLS\Rising\Rav\MailMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [D:\Program Files\TOOLS\Rising\Rav\SpamEng.dll]  <N/A><18, 0, 0, 6>
    [D:\Program Files\TOOLS\Rising\Rav\engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [D:\Program Files\TOOLS\Rising\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [D:\Program Files\TOOLS\Rising\Rav\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [D:\Program Files\TOOLS\Rising\Rav\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [D:\Program Files\TOOLS\Rising\Rav\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [D:\Program Files\TOOLS\Rising\Rav\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [D:\Program Files\TOOLS\Rising\Rav\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
    [D:\Program Files\TOOLS\Rising\Rav\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 17>
    [D:\Program Files\TOOLS\Rising\Rav\Unpacker.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [D:\Program Files\TOOLS\Rising\Rav\ExtOLE.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [D:\Program Files\TOOLS\Rising\Rav\RsStore.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 180][c:\program files\rising\rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 25>
    [c:\program files\rising\rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 10>
    [c:\program files\rising\rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [c:\program files\rising\rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 19>
    [c:\program files\rising\rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [c:\program files\rising\rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[PID: 548][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll]  <Windows (R) 2000 DDK provider><5.00.2195.1620>
[PID: 824][D:\Program Files\TOOLS\Rising\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [D:\Program Files\TOOLS\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [D:\Program Files\TOOLS\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1552][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 1264][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 7328][C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe]  <Ulead Systems, Inc.><1, 0, 0, 4>
[PID: 10060][c:\program files\rising\rfw\RfwMain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 42>
    [c:\program files\rising\rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [c:\program files\rising\rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [c:\program files\rising\rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
[PID: 6752][D:\Program Files\TOOLS\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [D:\Program Files\TOOLS\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\Program Files\TOOLS\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [D:\Program Files\TOOLS\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\Program Files\TOOLS\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
[PID: 2284][D:\Program Files\TOOLS\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 30>
    [D:\Program Files\TOOLS\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
    [D:\Program Files\TOOLS\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [D:\Program Files\TOOLS\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [D:\Program Files\TOOLS\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [D:\Program Files\TOOLS\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\Program Files\TOOLS\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [D:\Program Files\TOOLS\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
[PID: 2896][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3208>
    [C:\WINDOWS\system32\msicn\msibm.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
[PID: 1732][C:\PROGRA~1\baigoo\bgoomain.exe]  <BGoo><1, 0, 0, 1006>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [C:\PROGRA~1\baigoo\bgooex.dll]  <><1, 0, 0, 1007>
[PID: 7120][C:\WINDOWS\system32\Rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\hbclient\HBHelper.dll]  <Shanghai Henbang Technology Co., Ltd><1, 1, 3, 3>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
[PID: 2132][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [C:\WINDOWS\system32\msicn\msibm.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
[PID: 4968][D:\Program Files\TOOLS\WebThunder\WebThunder.exe]  <深圳市迅雷网络技术有限公司><1, 1, 5, 40>
    [D:\Program Files\TOOLS\WebThunder\taskmanage.dll]  <Thunder Networking Technologies,LTD><1, 1, 0, 40>
    [D:\Program Files\TOOLS\WebThunder\download_interface.dll]  <Thunder Networking Technologies,LTD><1, 0, 3, 70>
    [D:\Program Files\TOOLS\WebThunder\asyn_dns.dll]  <N/A><N/A>
    [D:\Program Files\TOOLS\WebThunder\RegisterDll.dll]  <Thunder Networking Technologies,LTD><2, 0, 0, 13>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [D:\Program Files\TOOLS\WebThunder\historyinfo_manage.dll]  <Thunder Networking Technologies,LTD><5, 2, 0, 150>
    [D:\Program Files\TOOLS\WebThunder\UpdateDownload.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 8>
gototop
 

[D:\Program Files\TOOLS\WebThunder\UpdateExec.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 5>
    [D:\Program Files\TOOLS\WebThunder\iEmbedShell.dll]  < ><1, 0, 0, 10>
    [D:\Program Files\TOOLS\WebThunder\iEmbed03.dll]  < ><2, 2, 1, 33>
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
    [C:\WINDOWS\system32\PYJJ4.IME]  <加加工作组><4.0.0.21>
[PID: 5012][C:\WINDOWS\system32\Rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\Downloader.dll]  <><1, 0, 0, 1>
[PID: 9128][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
[PID: 8980][C:\WINDOWS\explorer.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [C:\WINDOWS\System32\stdup.dll]  <MStdup Co Ltd.><3, 2, 1, 6>
    [C:\WINDOWS\system32\msicn\msibm.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
    [C:\WINDOWS\system32\msicn\plugins\bse.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
    [C:\WINDOWS\system32\msicn\plugins\lup.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
    [C:\WINDOWS\system32\msicn\plugins\bm.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
    [C:\WINDOWS\system32\msicn\plugins\as.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
    [D:\Program Files\TOOLS\WebThunder\WebThunderBHO_011.dll]  <Thunder Networking Technologies,LTD><6, 0, 0, 2>
    [C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll]  <><1, 0, 0, 1>
    [D:\Program Files\TOOLS\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 2500][D:\Program Files\MagicSet\SRIECLI.EXE]  <Super Rabbit Soft><7.67>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [D:\PROGRA~1\MagicSet\shlobj71.ocx]  <Sky Software (http://www.ssware.com)><7, 1, 0, 0>
[PID: 3896][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [D:\Program Files\MagicSet\haokanbar.dll]  <Xiang Feng Technology><2, 1, 0, 1463>
    [D:\Program Files\TOOLS\WebThunder\WebThunderBHO_011.dll]  <Thunder Networking Technologies,LTD><6, 0, 0, 2>
    [C:\WINDOWS\system32\wmpdrm.dll]  <Allsum Info. Tech. Ltd.><2, 0, 0, 1>
    [C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 0>
    [C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll]  <><1, 0, 0, 1>
    [C:\PROGRA~1\MMSASS~1\Mmsass~1.dll]  <><1, 2, 0, 3>
    [C:\WINDOWS\System32\stdup.dll]  <MStdup Co Ltd.><3, 2, 1, 6>
    [C:\Program Files\baigoo\BGooBHO.dll]  <><1, 0, 0, 1>
    [C:\PROGRA~1\hbclient\HBHelper.dll]  <Shanghai Henbang Technology Co., Ltd><1, 1, 3, 3>
    [C:\WINDOWS\system32\flash8.dll]  <MACROMEDlA><1, 4, 0, 0>
    [C:\WINDOWS\Downloader.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\CoolBho.dll]  <LETSCOOL Network Technology><1, 3, 0, 2>
    [C:\PROGRA~1\baigoo\bgook.dll]  <BAIGOO.COM><1, 0, 0, 1007>
    [C:\PROGRA~1\baigoo\plugin\bgoobar\bgoobar.dll]  <BAIGOO><1, 0, 0, 1007>
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
    [C:\Progra~1\Baidu\bar\BaiDuBar.dll]  <Baidu.com, Inc.><2, 0, 2, 40>
    [C:\WINDOWS\system32\KakaTool.dll]  <Beijing Rising Technology Co., Ltd.><2, 0, 0, 9>
    [C:\WINDOWS\system32\PYJJ4.IME]  <加加工作组><4.0.0.21>
[PID: 6340][C:\WINDOWS\explorer.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [D:\Program Files\TOOLS\WebThunder\WebThunderBHO_011.dll]  <Thunder Networking Technologies,LTD><6, 0, 0, 2>
    [C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\System32\stdup.dll]  <MStdup Co Ltd.><3, 2, 1, 6>
    [C:\Program Files\baigoo\BGooBHO.dll]  <><1, 0, 0, 1>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [D:\Program Files\TOOLS\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 4204][D:\Program Files\TOOLS\加加4.0\jj4\jjsvr4.exe]  <加加开发组><4.0.0.20>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
[PID: 4540][D:\My Documents\我接收到的文件\THUNDER\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. [hh.exe %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [notepad.exe %1]
.INF  Error. [notepad.exe %1]
.VBS  Error. [wscript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

什么感谢
超级兔子正在使用
gototop
 

用Hijackthis1.99专杀就能搞定
gototop
 

删除:

C:\PROGRA~1\hbclient\HBHelper.dll
C:\WINDOWS\System32\stdup.dll
C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
C:\PROGRA~1\baigoo\bgoohk.dll
C:\WINDOWS\system32\msicn\msibm.dll
C:\WINDOWS\system32\msicn\plugins\bse.dll
C:\WINDOWS\system32\msicn\plugins\lup.dll
C:\WINDOWS\system32\msicn\plugins\as.dll
C:\WINDOWS\system32\msicn\plugins\bm.dll

用你的兔子清理流氓软件,修复文件关联.
gototop
 


运行(双击)System Repair Engineer,点“启动项目,服务,点“Win32服务应用程序”勾选“隐藏微软服务”选中病毒服务XDownloadService,选择“删除服务”点“设置”选择“否”
确保你的兔子是今年七月的版本,如果无法确定,卸载后,再下载安装。
下载超级兔子。
http://www.pctutu.com/srmsdown.asp
安装好后,打开“超级兔子清理王”“专业卸载,卸载所有提示的垃圾软件,卸载是不要打开任何浏览窗口。卸载不了可以重启后再去卸载。
卸载完后重启。
运行(双击)System Repair Engineer,使用“启动项目,注册表”来删除以下选项。
C:\WINDOWS\mcUpdate.exe
双击我的电脑,工具,文件夹选项,查看,单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示确定更改时,单击“是”,清除“隐藏已知文件类型的扩展名
删除
C:\WINDOWS\mcUpdate.exe
C:\WINDOWS\Downloader.dll

关于这一项
C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\nbekm.exe
看以下的帖子
http://forum.ikaka.com/topic.asp?board=28&artid=8122808

修复后,重启。
请再扫份日志粘上来。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT