12   2  /  2  页   跳转

我的浏览器被劫持了

==================================
正在运行的进程
[PID: 1016][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1064][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1088][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\NavLogon.dll]  <Symantec Corporation><9.0.1.1000>
[PID: 1132][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1144][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1304][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1368][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1484][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [d:\oracle\ora92\bin\oci.dll]  <Oracle Corporation><9.2.0.1.0>
[PID: 1580][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1628][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1752][C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe]  <Symantec Corporation><2.2.1.004>
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  <Symantec Corporation><2.2.1.004>
[PID: 1816][C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe]  <Symantec Corporation><2.2.1.004>
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  <Symantec Corporation><2.2.1.004>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\CCSETEVT.DLL]  <Symantec Corporation><2.2.1.004>
[PID: 1940][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 128][C:\Program Files\Symantec AntiVirus\DefWatch.exe]  <Symantec Corporation><9.0.1.1000>
[PID: 160][C:\WINDOWS\system32\inetsrv\inetinfo.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [d:\oracle\ora92\bin\oci.dll]  <Oracle Corporation><9.2.0.1.0>
[PID: 212][d:\oracle\ora92\bin\omtsreco.exe]  <Oracle Corporation><9.2.0.1.0>
    [d:\oracle\ora92\bin\OCI.dll]  <Oracle Corporation><9.2.0.1.0>
    [d:\oracle\ora92\bin\OraClient9.Dll]  <Oracle Corporation><9.2.0.1.0 Production >
    [d:\oracle\ora92\bin\oracore9.dll]  <Oracle Corporation><9.2.0.1.0 Production>
    [d:\oracle\ora92\bin\oranls9.dll]  <Oracle Corporation><9.2.0.1.0 Production>
    [d:\oracle\ora92\bin\oraunls9.dll]  <Oracle Corporation><9.2.0.1.0 Production>
    [d:\oracle\ora92\bin\oravsn9.dll]  <Oracle Corporation><9.2.0.1.0 Production >
    [d:\oracle\ora92\bin\oracommon9.dll]  <Oracle Corporation><9.2.0.1.0 Production >
    [d:\oracle\ora92\bin\orageneric9.dll]  <Oracle Corporation><9.2.0.1.0 Production >
    [d:\oracle\ora92\bin\oraxml9.dll]  <Oracle Corporation><>
    [d:\oracle\ora92\bin\oraxsd9.dll]  <Oracle Corporation><>
    [d:\oracle\ora92\bin\orannzsbb9.dll]  <Oracle Corporation><9.2.0.1.0 Production>
    [d:\oracle\ora92\bin\oran9.dll]  <Oracle Corporation><9.2.0.1.0 Production>
    [d:\oracle\ora92\bin\oranl9.dll]  <Oracle Corporation><9.2.0.1.0 Production>
    [d:\oracle\ora92\bin\oranldap9.dll]  <Oracle Corporation><9.2.0.1.0 Production>
    [d:\oracle\ora92\bin\oraldapclnt9.dll]  <Oracle Corporation><9.2.0.1.0 Production>
    [d:\oracle\ora92\bin\orancrypt9.dll]  <Oracle Corporation><9.2.0.1.0 Production>
    [d:\oracle\ora92\bin\ORATRACE9.dll]  <N/A><N/A>
    [d:\oracle\ora92\bin\oranro9.dll]  <Oracle Corporation><9.2.0.1.0 Production>
    [d:\oracle\ora92\bin\oranhost9.dll]  <Oracle Corporation><9.2.0.1.0 Production>
    [d:\oracle\ora92\bin\oranoname9.dll]  <Oracle Corporation><9.2.0.1.0 Production>
    [d:\oracle\ora92\bin\orancds9.dll]  <Oracle Corporation><9.2.0.1.0 Production>
    [d:\oracle\ora92\bin\orantns9.dll]  <Oracle Corporation><9.2.0.1.0 Production>
    [d:\oracle\ora92\bin\oranms.dll]  <Oracle Corporation><9.2.0.0.0>
    [d:\oracle\ora92\bin\oranmsp.dll]  <Oracle Corporation><9.2.0.0.0>
    [d:\oracle\ora92\bin\orapls9.dll]  <Oracle Corporation><9.2.0.1.0 Production >
    [d:\oracle\ora92\bin\oraslax9.dll]  <Oracle Corporation><9.2.0.1.0 Production>
    [d:\oracle\ora92\bin\orasnls9.dll]  <Oracle Corporation><9.2.0.1.0 Production>
    [d:\oracle\ora92\bin\orawtc9.dll]  <Oracle Corporation><9.2.0.1.0 Production >
    [d:\oracle\ora92\bin\orasql9.dll]  <Oracle Corporation><9.2.0.1.0 Production>
    [d:\oracle\ora92\bin\omtsrecomsgus.dll]  <Oracle Corporation><9.2.0.0.1>
gototop
 

[PID: 512][C:\Program Files\Symantec AntiVirus\Rtvscan.exe]  <Symantec Corporation><9.0.1.1000>
    [C:\WINDOWS\system32\CBA.DLL]  <Intel? Corporation><6.12.0.126 E>
    [C:\WINDOWS\system32\MsgSys.dll]  <Intel? Corporation><6.12.0.126 E>
    [C:\WINDOWS\system32\NTS.dll]  <Intel? Corporation><6.12.0.126 E>
    [C:\WINDOWS\system32\PDS.DLL]  <Intel? Corporation><6.12.0.126 E>
    [C:\Program Files\Symantec AntiVirus\NAVLU.dll]  <Symantec Corporation><9.0.1.1000>
    [C:\Program Files\Symantec AntiVirus\I2ldvp3.dll]  <Symantec Corporation><9.0.1.1000>
    [C:\Program Files\Symantec AntiVirus\ecmldr32.DLL]  <Symantec Corp.><1.1.0.3>
    [C:\Program Files\Symantec AntiVirus\SAVRT32.DLL]  <Symantec Corporation><9.3.0.28>
    [C:\Program Files\Symantec AntiVirus\NAVNTUTL.DLL]  <Symantec Corporation><9.0.1.1000>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060803.048\ecmsvr32.dll]  <Symantec Corporation><61.2.1.10>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060803.048\NAVEX32a.DLL]  <Symantec Corporation><20061.2.0.26>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060803.048\NAVENG32.DLL]  <Symantec Corporation><20061.2.0.26>
    [C:\Program Files\Symantec AntiVirus\IMail.dll]  <Symantec Corporation><9.0.1.1000>
    [C:\Program Files\Symantec AntiVirus\NotesExt.dll]  <Symantec Corporation><9.0.1.1000>
    [C:\Program Files\Symantec AntiVirus\vpmsece2.dll]  <Symantec Corporation><9.0.1.1000>
    [C:\Program Files\Symantec AntiVirus\DecSDK.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2ID.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2ZIP.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2SS.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2GZIP.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2CAB.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2LHA.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2ARJ.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2TNEF.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2LZ.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2AMG.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2TAR.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2RTF.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Symantec AntiVirus\Dec2Text.dll]  <Symantec Corporation><3.02.12.09>
    [C:\Program Files\Common Files\Symantec Shared\SSC\scandlgs.dll]  <Symantec Corporation><9.0.1.1000>
    [C:\Program Files\Symantec AntiVirus\DefUtDCS.dll]  <Symantec Corporation><1.0.82.0>
[PID: 880][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 740][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  <Adobe Systems, Inc.><7.0.0.0>
    [C:\PROGRA~1\FlashGet\jccatch.dll]  <FlashGet><1, 1, 5, 0>
[PID: 2076][C:\WINDOWS\SOUNDMAN.EXE]  <Realtek Semiconductor Corp.><5.1.0.34>
[PID: 2132][C:\WINDOWS\system32\VTTimer.exe]  <S3 Graphics, Inc.><2.00.01-0307>
[PID: 2188][C:\WINDOWS\system32\VTtrayp.exe]  <S3 Graphics Co., Ltd.><2.00.41-1031>
    [C:\WINDOWS\system32\VTDisply.dll]  <S3 Graphics Co., Ltd.><2.00.58-0523>
    [C:\WINDOWS\system32\VTGamma2.dll]  <S3 Graphics Co., Ltd.><2.00.28-1128>
    [C:\WINDOWS\system32\VTInfo2.dll]  <S3 Graphics Co., Ltd.><2.00.35-1031>
    [C:\WINDOWS\system32\VTOvrlay.dll]  <S3 Graphics Co., Ltd.><2.00.38-1117B>
[PID: 2224][C:\PROGRA~1\SYMANT~1\VPTray.exe]  <Symantec Corporation><9.0.1.1000>
    [C:\Program Files\Symantec AntiVirus\SAVRT32.DLL]  <Symantec Corporation><9.3.0.28>
    [C:\Program Files\Symantec AntiVirus\Cliproxy.dll]  <Symantec Corporation><9.0.1.1000>
    [C:\PROGRA~1\SYMANT~1\NAVNTUTL.DLL]  <Symantec Corporation><9.0.1.1000>
    [C:\Program Files\Symantec AntiVirus\Cliscan.dll]  <Symantec Corporation><9.0.1.1000>
[PID: 2232][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3208>
[PID: 2240][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 712][C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE]  <Microsoft Corporation><11.0.6359>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\hpzpm312.dll]  <HP><2.335.5.0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\hpz2ku12.dll]  <HP><2.335.5.0>
[PID: 1612][C:\Program Files\IDM Computer Solutions\UltraEdit-32\Uedit32.exe]  <IDM Computer Solutions, Inc.><11.20a>
    [C:\Program Files\IDM Computer Solutions\UltraEdit-32\tidylib.dll]  <N/A><N/A>
    [C:\Program Files\IDM Computer Solutions\UltraEdit-32\SftpDLL.dll]  <WeOnlyDo! COM><2, 2, 2, 17>
    [C:\Program Files\IDM Computer Solutions\UltraEdit-32\ueres.dll]  <IDM Computer Solutions, Inc.><11.20a>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\hpzpm312.dll]  <HP><2.335.5.0>
[PID: 2328][C:\WINDOWS\system32\cmd.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3392][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 412][C:\jdk1.4\bin\java.exe]  <N/A><N/A>
    [C:\jdk1.4\jre\bin\client\jvm.dll]  <N/A><N/A>
    [C:\jdk1.4\jre\bin\hpi.dll]  <N/A><N/A>
    [C:\jdk1.4\jre\bin\verify.dll]  <N/A><N/A>
    [C:\jdk1.4\jre\bin\java.dll]  <N/A><N/A>
    [C:\jdk1.4\jre\bin\zip.dll]  <N/A><N/A>
    [C:\jdk1.4\jre\bin\net.dll]  <N/A><N/A>
[PID: 580][C:\Program Files\Maxthon\Maxthon.exe]  <Maxthon International Ltd.><1, 5, 6, 42>
    [C:\Program Files\Maxthon\maxzlib.dll]  < ><1, 0, 0, 2>
    [C:\Program Files\Maxthon\Services\RealTime\real_time.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 3456][C:\WINDOWS\system32\dllhost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [d:\oracle\ora92\bin\oci.dll]  <Oracle Corporation><9.2.0.1.0>
[PID: 3680][\\?\c:\windows\microsoft.net\framework\v1.1.4322\aspnet_wp.exe]  <Microsoft Corporation><1.1.4322.573>
    [c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_2c7f8f81\mscorlib.dll]  <N/A><N/A>
    [c:\windows\assembly\gac\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\cscompmgd.dll]  < ><7.10.3052.4>
    [c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\wbds\4330d651\4eb2b887\ltnnukgj.dll]  < ><0.0.0.0>
    [c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\wbds\4330d651\4eb2b887\assembly\dl2\0675878a\00edba58_3efec501\traceextension.dll]  < ><0.0.0.0>
    [c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\wbds\4330d651\4eb2b887\assembly\dl2\444fd6de\00edba58_3efec501\log.dll]  < ><0.0.0.0>
    [c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\wbds\4330d651\4eb2b887\assembly\dl2\99cd88cf\00edba58_3efec501\mibs.dll]  < ><0.0.0.0>
    [c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\wbds\4330d651\4eb2b887\assembly\dl2\08582c75\00edba58_3efec501\cstalk.dll]  <Microlink Solution Sdn. Bhd.><1.0.0.0>
    [c:\windows\microsoft.net\framework\v1.1.4322\temporary asp.net files\wbds\4330d651\4eb2b887\assembly\dl2\e2780896\00edba58_3efec501\totaformatter.dll]  < ><0.0.0.0>
    [C:\WINDOWS\system32\VBI32.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\VBIM32.DLL]  <N/A><N/A>
    [C:\WINDOWS\system32\SPI32.DLL]  <N/A><N/A>
    [C:\WINDOWS\system32\MSG32.DLL]  <N/A><N/A>
[PID: 3720][C:\Program Files\MSN Messenger\msnmsgr.exe]  <Microsoft Corporation><8.0.0792.00>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
[PID: 3224][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3824][C:\Documents and Settings\Administrator\桌面\sreng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
gototop
 

==================================
文件关联
.TXT  Error. [UltraEdit.txt]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [UltraEdit.ini]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  Error. [UltraEdit.js]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 

没解决呀,再看看吧
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT