瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】哇~好难过。请大家救救我的电脑!!

1234   3  /  4  页   跳转

【求助】哇~好难过。请大家救救我的电脑!!

谢谢楼上的。我照着你的话做了。其中一项C:\WINDOWS\svchost.exe  无法删除。电脑说无法删除,请确定被保护或者磁盘未写满什么东东的。。

别的我都删除了。

现在终于可以正常上网了。可以开机了。万分的感谢!!^^

可是目前还是总是有很多的垃圾网页不断的弹出来。

刚开机的时候,弹出一个对话框,说什么安全进程,有三个选择。具体我忘记了。5~~~不能陈述下来。

现在我再把日志贴上来哦。拜托!!!!

gototop
 

【回复“默默小艾”的帖子】
C:\WINDOWS\svchost.exe这项一定要删掉,你是否结束了这和进程。。还有弹出广告的话,去下载个超级兔子,用兔子清理王卸载垃圾插件(安全模式下)。。。再扫个日志上来
gototop
 

2006-08-19,11:42:57

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
    <msnmsgr><; rem "C:\Program Files\MSN Messenger\msnmsgr.exe" /background>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <{7C215DC4-0710-2052-1220-051114050056}><"C:\Program Files\Common Files\{7C215DC4-0710-2052-1220-051114050056}\Update.exe" mc-110-12-0000228>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <SoundMan><SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
    <ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe">  [Symantec Corporation]
    <spoolsv><C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer>  [广州傲讯信息科技有限公司]
    <MSConfig><C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto>  [Microsoft Corporation]
    <91cast><; >  []
    <defender><; C:\\dfndrff_11.exe>  [3u38742897r8yuruy4u3yru743433r]
    <IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [Microsoft Corporation]
    <keyboard><; C:\\kybrdff_11.exe>  [*&&*#&$*#RU*#Y&*#YR&Y#&RY#R]
    <newname><; C:\\nwnmff_11.exe>  [(%)(%)(%)(%)(%)(%)(%)(%)(%)(%)]
    <pbmini><; C:\Program Files\pcast\PodcastbarMini\PodcastBar.exe -hide>  []
    <QuickTime Task><; "C:\Program Files\QuickTime\qttask.exe" -atboottime>  [Apple Computer, Inc.]
    <SysExplr><; rem C:\Program Files\HEROSOFT\Hero3000\SYSEXPLR.EXE>  []
    <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <vptray><; C:\PROGRA~1\SYMANT~1\VPTray.exe>  [Symantec Corporation]
    <yassistse><; rem "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">  [Yahoo!]
    <YLive.exe><; rem C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>  [ ]
    <随手贴><; "C:\PROGRA~1\工具超人\随手贴\随手贴.EXE"              >  [Wondersoft]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <CheckFaultKernel><C:\WINDOWS\system32\mswdm.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{1A404685-7563-4d02-B0F6-58B308A406A9}><c:\program files\symantec antivirus\hkuxdfbe.dll>  []
    <{F3F54390-D513-4D99-A5DA-476EA9DC6022}><C:\Program Files\Internet Explorer\PLUGINS\system2.sys>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <webwork><C:\WINDOWS\webwork\webwork.dll>  [MSWebwork Cop.]

==================================
启动文件夹
服务
[Symantec Event Manager / ccEvtMgr]
  <"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc]
  <"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr]
  <"C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[Symantec AntiVirus Definition Watcher / DefWatch]
  <"C:\Program Files\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[Macromedia Licensing Service / Macromedia Licensing Service]
  <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[SavRoam / SavRoam]
  <"C:\Program Files\Symantec AntiVirus\SavRoam.exe"><symantec>
[Symantec Network Drivers Service / SNDSrvc]
  <"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Symantec AntiVirus / Symantec AntiVirus]
  <"C:\Program Files\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>
gototop
 

==================================
浏览器加载项
[wmpdrm]
  {0E674588-66B7-4E19-9D0E-2053B800F69F} <C:\WINDOWS\system32\wmpdrm.dll, Allsum Info. Tech. Ltd.>
[MyIEHelper Class]
  {16B770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper2006818_4700.dll, Microsoft Corporation>
[启动迅雷]
  {0062C9BD-B349-40DE-91A0-755F37ACD559} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[雅虎助手]
  {406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[WebThunder Browser Helper]
  {00000AAA-A363-466E-BEF5-9BB68697AA7F} <C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_011.dll, Thunder Networking Technologies,LTD>
[Google Script Object]
  {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[QuickTime Object]
  {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} <C:\Program Files\QuickTime\QTPlugin.ocx, Apple Computer, Inc.>
[internet explorer helper]
  {02C9B9AB-6372-46C5-B356-773FAF3B6B1E} <C:\WINDOWS\fonts\msshapi.dll, >
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[MonitorURL Class]
  {08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, >
[ALiBaBar]
  {0A1375E1-56C2-11D6-8E45-8933A0FB5235} <C:\PROGRA~1\ALiBaBar\ALiBaBar.dll, Alfred, C. S. Li>
[wmpdrm]
  {0E674588-66B7-4E19-9D0E-2053B800F69F} <C:\WINDOWS\system32\wmpdrm.dll, Allsum Info. Tech. Ltd.>
[DjVuCtl Class]
  {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} <C:\WINDOWS\system32\DjVuCntl.dll, LizardTech>
[TrustSession Class]
  {168953DC-731B-4360-8783-072A2B0F894A} <C:\WINDOWS\system32\SecuiJoinsIE.dll, >
[MyIEHelper Class]
  {16B770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper2006818_4700.dll, Microsoft Corporation>
[XLink Class]
  {18F57D30-EF36-4C0E-9343-7BFA6DF79B4A} <C:\WINDOWS\system32\quartz32.dll, >
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
  {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[Menu Class]
  {27D784D7-9217-4227-B43B-E06E4781E0CB} <C:\WINDOWS\system32\AlxTB1.dll, Alexa Internet>
[DHTML Edit Control Safe for Scripting for IE5]
  {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[HtmlDlgSafeHelper Class]
  {3050F819-98B5-11CF-BB82-00AA00BDCE0B} <C:\WINDOWS\system32\mshtmled.dll, Microsoft Corporation>
[Yahoo!Photo]
  {33BBE430-0E42-4F12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll, Yahoo! China>
[IETag Factory]
  {38481807-CA0E-42D2-BF39-B33AF135CC4D} <C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\IETAG.DLL, Microsoft Corporation>
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll, Yahoo.>
[Alexa]
  {3CEFF6CD-6F08-4E4D-BCCD-FF7415288C3B} <C:\WINDOWS\system32\SHDOCVW.DLL, Microsoft Corporation>
[雅虎助手]
  {406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[HHCtrl Object]
  {41B23C28-488E-4E5C-ACE2-BB0BBABE99E8} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Yahoo!Live]
  {57421194-58FB-49AE-9B4F-FD48869B9AD4} <C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll, >
[CdnForIE Class]
  {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, N/A>
[DragSearch BHO]
  {62EED7C6-9F02-42F9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, >
[JMX.JmxCenter]
  {63859236-76BF-493C-A587-DF479EBA2D4B} <C:\WINDOWS\system32\EJMX.dll, 广州盛行网络有限公司>
[MMSAssist BHO]
  {6671A431-5C3D-463D-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[SecureSession Class]
  {6989C944-3529-4DA8-8C60-187E95F580E2} <C:\WINDOWS\system32\SecuiJoinsIE.dll, >
[BrowserProxy4 Class]
  {69A72A8A-84ED-4A75-8CE7-263DBEF3E5D3} <C:\WINDOWS\system32\AlxTB1.dll, Alexa Internet>
[stdup]
  {6A512BF7-EC78-4E8D-9841-6C02E8FA9838} <C:\WINDOWS\System32\stdup.dll, MStdup Co Ltd.>
[bbmao Toolbar]
  {6AE02E1C-8859-4F57-9097-5A55A56A4CAF} <C:\Program Files\bbmao toolbar\bbmao_tb_v1_0_pd1002.dll, N/A>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[XBTP05676 Class]
  {72BA415A-AE03-4279-ACAB-39A3DF73FD4E} <C:\PROGRA~1\BBMAOT~1\BBMAO_~1.DLL, N/A>
[MediaComm Class]
  {7670648D-461B-42AF-BDFE-46D26AF5EFF2} <C:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin07.dll, Thunder Networking Technologies,LTD>
[CpapView Class]
  {77962960-536E-47EC-9DDB-52651519705F} <C:\WINDOWS\system32\Rundll32.dll, >
[Status Class]
  {7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} <C:\PROGRA~1\baigoo\BaigooBH.dll, N/A>
[BrowserObject Class]
  {808EAF87-61B8-4EEA-8B85-27480D1BDBEE} <C:\Program Files\baigoo\bgook.dll, N/A>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[CibaCtrl Class]
  {8DE0FCD4-5EB5-11D3-AD25-00002100131B} <C:\POWERW~1\IEPlugin.dll, >
[Windows Live Sign-in Helper]
  {9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
[The_Christian_Post Toolbar]
  {A4F77919-340E-42ED-BE7A-ADB640BCFDBF} <C:\Program Files\The_Christian_Post\tbThe_.dll, N/A>
[Yahoo Bar]
  {A697BC46-BC93-4833-93F5-1E365011E88A} <C:\WINDOWS\DBINT.dll, N/A>
[DeskbarBHO]
  {A8B28872-3324-4CD2-8AA3-7D555C872D96} <C:\Program Files\Deskbar\deskbar.dll, N/A>
[Google Toolbar Helper]
  {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[isObject Class]
  {BE0B5843-553A-48C2-9A42-258A1D791AFC} <C:\PROGRA~1\pcast\hbcast.dll, Shanghai Henbang Technology Co., Ltd>
[JoyoCtrl Class]
  {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} <C:\POWERW~1\IEPlugin.dll, >
[Webacc Class]
  {CAC068F3-A608-406B-8581-458788A67694} <C:\WINDOWS\system32\svchost.dll, N/A>
[ToolBar888]
  {CBCC61FA-0221-4CCC-B409-CEE865CACA3A} <C:\Program Files\ToolBar888\MyToolBar.dll, N/A>
[AUDIO__WAV Moniker Class]
  {CD3AFA7B-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AUDIO__X_MS_WMA Moniker Class]
  {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_ASF Moniker Class]
  {CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
  {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[ALiBaBar_Helper]
  {CE439C63-384A-747A-A357-23D96B5D652B} <C:\PROGRA~1\ALiBaBar\ALiBaBar.dll, Alfred, C. S. Li>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[51导航]
  {D271A289-57EB-4D0E-9131-A0CD25D4D1F8} <C:\WINDOWS\system32\browsewmzero.dll, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[AlxTB BHO Class]
  {F1FABE79-25FC-46DE-8C5A-2C6DB9D64333} <C:\WINDOWS\system32\AlxTB1.dll, Alexa Internet>
[BHelper Class]
  {F2E37336-BFDB-409B-8D0E-6F013C438B20} <C:\WINDOWS\system32\a3eo62b1.dll, N/A>
[WMHlprObj Class]
  {F5824EFB-728A-4726-A5A5-85A68B20EDC3} <C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll, N/A>
[assist]
  {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll, Yahoo!>
[JmwQesmb Class]
  {FF469701-2354-972A-961C-A3B6ABEAE1FE} <C:\WINDOWS\DOWNLO~1\lnxwh.dll, iqqwdsoft>
[&使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[Alexa Web Search]
  <http://client.alexa.com/holiday/script/actions/search.htm, N/A>
[Get Alexa Data]
  <http://client.alexa.com/holiday/script/actions/sitedata.htm, N/A>
[Mail to a Friend...]
  <http://client.alexa.com/holiday/script/actions/mailto.htm, N/A>
[See Related Links]
  <http://client.alexa.com/holiday/script/actions/related.htm, N/A>
[Write a Review...]
  <http://client.alexa.com/holiday/script/actions/review.htm, N/A>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[添加到雅虎订阅(&Y)]
  <res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
[雅虎搜索]
  <res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246, N/A>
gototop
 

==================================
正在运行的进程
[PID: 208][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [c:\program files\symantec antivirus\hkuxdfbe.dll]  <><1, 0, 0, 11>
    [C:\WINDOWS\system32\packet.dll]  <CACE Technologies><3, 1, 0, 27>
    [C:\WINDOWS\system32\WanPacket.dll]  <CACE Technologies><3, 1, 0, 27>
    [C:\Program Files\Internet Explorer\PLUGINS\system2.sys]  <N/A><N/A>
    [C:\WINDOWS\system32\msicn\msibm.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
    [C:\WINDOWS\system32\msicn\plugins\as.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
    [C:\WINDOWS\system32\msicn\plugins\bm.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
    [C:\WINDOWS\system32\msicn\plugins\bse.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
    [C:\WINDOWS\system32\msicn\plugins\lup.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
    [C:\WINDOWS\system32\quartz32.dll]  <><4, 0, 0, 0>
    [C:\WINDOWS\webwork\webwork.nls]  <MSWebwork Cop.><1, 0, 0, 1>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 2, 1019>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  <Adobe Systems, Inc.><7.0.0.0>
    [C:\PROGRA~1\ESTsoft\ALZip\AZCTM.DLL]  <N/A><N/A>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  <><2, 0, 5, 1031>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  < ><2, 0, 1, 1007>
[PID: 1176][C:\WINDOWS\SOUNDMAN.EXE]  <Realtek Semiconductor Corp.><5.1.0.40>
    [C:\Program Files\Internet Explorer\PLUGINS\system2.sys]  <N/A><N/A>
[PID: 1192][C:\Program Files\Common Files\Symantec Shared\ccApp.exe]  <Symantec Corporation><2.2.0.577>
    [C:\Program Files\Internet Explorer\PLUGINS\system2.sys]  <N/A><N/A>
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  <Symantec Corporation><2.2.0.577>
    [C:\Program Files\Symantec\LiveUpdate\ProductRegCom.DLL]  <Symantec Corporation><2.0.39.0>
    [C:\Program Files\Symantec\LiveUpdate\LuComServerPS.DLL]  <Symantec Corporation><2.0.39.0>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\CCALERT.DLL]  <Symantec Corporation><2.2.0.577>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\CCEMLPXY.DLL]  <Symantec Corporation><2.2.0.577>
    [C:\WINDOWS\system32\SYMREDIR.dll]  <Symantec Corporation><5.3.0.46>
    [C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll]  <Symantec Corporation><2.2.0.577>
    [C:\Program Files\Common Files\Symantec Shared\ccProSub.dll]  <Symantec Corporation><2.2.0.577>
    [C:\Program Files\Symantec AntiVirus\SavEmail.dll]  <Symantec Corporation><9.0.0.338>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\system32\quartz32.dll]  <><4, 0, 0, 0>
    [C:\WINDOWS\system32\msicn\msibm.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
[PID: 1364][C:\Program Files\Common Files\{7C215DC4-0710-2052-1220-051114050056}\Update.exe]  <N/A><N/A>
[PID: 1372][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\Internet Explorer\PLUGINS\system2.sys]  <N/A><N/A>
    [C:\WINDOWS\system32\msicn\msibm.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\system32\quartz32.dll]  <><4, 0, 0, 0>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 2, 1019>
[PID: 2380][C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe]  < ><2, 0, 0, 1002>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 2, 1019>
    [C:\Program Files\Internet Explorer\PLUGINS\system2.sys]  <N/A><N/A>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  <><2, 0, 5, 1031>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  < ><2, 0, 1, 1007>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\ynotifier.dll]  <><1, 0, 0, 5>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\system32\quartz32.dll]  <><4, 0, 0, 0>
[PID: 2508][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 2, 1019>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll]  <Yahoo><1, 0, 2, 1002>
    [C:\Program Files\Internet Explorer\PLUGINS\system2.sys]  <N/A><N/A>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  <><2, 0, 5, 1031>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  < ><2, 0, 1, 1007>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll]  <Yahoo!><2, 1, 8, 1048>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yaswiper.dll]  <Yahoo><1, 0, 1, 1004>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasiesec.dll]  <Yahoo><1, 0, 2, 1003>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasnoad.dll]  <><1, 1, 4, 1006>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yzsNetProto.dll]  <Yahoo><1, 0, 0, 1>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll]  <Yahoo! China><1, 1, 3, 1035>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll]  <Yahoo! China><1, 0, 1, 1015>
    [C:\WINDOWS\system32\packet.dll]  <CACE Technologies><3, 1, 0, 27>
    [C:\WINDOWS\system32\WanPacket.dll]  <CACE Technologies><3, 1, 0, 27>
    [C:\WINDOWS\system32\wmpdrm.dll]  <Allsum Info. Tech. Ltd.><2, 0, 0, 1>
    [C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper2006818_4700.dll]  <Microsoft Corporation><1, 3, 3, 0>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\system32\quartz32.dll]  <><4, 0, 0, 0>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
    [c:\progra~1\yahoo!\assist~1\assist\yadfil~1.dll]  < ><1, 0, 3, 1002>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrepair.dll]  <Yahoo! China><3, 0, 0, 1000>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasfsks.dll]  <3721.com><2, 1, 1, 87>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yoptimum.dll]  <Yahoo><1, 0, 1, 1001>
    [C:\PROGRA~1\yahoo!\assistant\Shell\yAssecblk.dll]  <Yahoo><1, 0, 2, 1002>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yXPStyle.dll]  <Yahoo><1, 0, 2, 1309>
[PID: 3104][C:\Program Files\Oleaf\Oleaf.exe]  <Staelens & Deckers><2.2>
    [C:\Program Files\Oleaf\libbind.dll]  <N/A><N/A>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 2, 1019>
    [C:\Program Files\Internet Explorer\PLUGINS\system2.sys]  <N/A><N/A>
    [C:\WINDOWS\system32\quartz32.dll]  <><4, 0, 0, 0>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\system32\UNISPIM.IME]  <北京清华紫光软件股份有限公司><3.0.0.3045>
    [C:\WINDOWS\system32\upengine.dll]  <北京清华紫光软件股份有限公司><3.0.0.3045>
[PID: 3512][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 2, 1019>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll]  <Yahoo><1, 0, 2, 1002>
    [C:\Program Files\Internet Explorer\PLUGINS\system2.sys]  <N/A><N/A>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  <><2, 0, 5, 1031>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  < ><2, 0, 1, 1007>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll]  <Yahoo!><2, 1, 8, 1048>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yaswiper.dll]  <Yahoo><1, 0, 1, 1004>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasiesec.dll]  <Yahoo><1, 0, 2, 1003>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasnoad.dll]  <><1, 1, 4, 1006>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yzsNetProto.dll]  <Yahoo><1, 0, 0, 1>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll]  <Yahoo! China><1, 1, 3, 1035>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll]  <Yahoo! China><1, 0, 1, 1015>
    [c:\program files\symantec antivirus\hkuxdfbe.dll]  <><1, 0, 0, 11>
    [C:\WINDOWS\system32\packet.dll]  <CACE Technologies><3, 1, 0, 27>
    [C:\WINDOWS\system32\WanPacket.dll]  <CACE Technologies><3, 1, 0, 27>
    [C:\WINDOWS\system32\wmpdrm.dll]  <Allsum Info. Tech. Ltd.><2, 0, 0, 1>
    [C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper2006818_4700.dll]  <Microsoft Corporation><1, 3, 3, 0>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\system32\quartz32.dll]  <><4, 0, 0, 0>
[PID: 3664][C:\DOCUME~1\CROSSM~1\LOCALS~1\Temp\oprar.exe]  <WHITEHOUSE><1.1.1.0>
    [C:\DOCUME~1\CROSSM~1\LOCALS~1\Temp\7.dll]  <Microsoft Corporation><5.00.1764.1>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 2, 1019>
    [C:\Program Files\Internet Explorer\PLUGINS\system2.sys]  <N/A><N/A>
    [C:\DOCUME~1\CROSSM~1\LOCALS~1\Temp\packet.dll]  <CACE Technologies><3, 1, 0, 27>
    [C:\DOCUME~1\CROSSM~1\LOCALS~1\Temp\WanPacket.dll]  <CACE Technologies><3, 1, 0, 27>
[PID: 3732][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3776][C:\Documents and Settings\crossmap_yanhui\桌面\shasha\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 2, 1019>
    [C:\Program Files\Internet Explorer\PLUGINS\system2.sys]  <N/A><N/A>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\system32\quartz32.dll]  <><4, 0, 0, 0>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  Error. [超级解霸3000]
.JS  Error. ["C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" "%1"]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

扫描类型:  自动防护 扫描
事件:  发现威胁!
威胁: Downloader
文件:  C:\Documents and Settings\crossmap_yanhui\Local Settings\Temporary Internet Files\Content.IE5\Q2Z5PV9V\c[1].gif
位置:  C:\Documents and Settings\crossmap_yanhui\Local Settings\Temporary Internet Fiales\Content.IE5\Q2Z5PV9V
计算机:  CROSSMAP-YANHUI
用户:  crossmap_yanhui
采用的操作:  清除 失败 : 隔离 失败 : 拒绝访问
发现的日期: 2006年8月19日  11:34:14



扫描类型:  自动防护 扫描
事件:  发现威胁!
威胁: Downloader
文件:  C:\Documents and Settings\crossmap_yanhui\Local Settings\Temporary Internet Files\Content.IE5\Q2Z5PV9V\c[1].gif
位置:  C:\Documents and Settings\crossmap_yanhui\Local Settings\Temporary Internet Files\Content.IE5\Q2Z5PV9V
计算机:  CROSSMAP-YANHUI
用户:  crossmap_yanhui
采用的操作:  清除 失败 : 隔离 失败 : 删除 成功 : 拒绝访问
发现的日期: 2006年8月19日  11:34:15



扫描类型:  自动防护 扫描
事件:  发现威胁!
威胁: Downloader
文件:  C:\Documents and Settings\crossmap_yanhui\Local Settings\Temporary Internet Files\Content.IE5\Q2Z5PV9V\c[1].gif
位置:  C:\Documents and Settings\crossmap_yanhui\Local Settings\Temporary Internet Files\Content.IE5\Q2Z5PV9V
计算机:  CROSSMAP-YANHUI
用户:  crossmap_yanhui
采用的操作:  清除 失败 : 隔离 失败 : 拒绝访问
发现的日期: 2006年8月19日  11:35:14



扫描类型:  自动防护 扫描
事件:  发现威胁!
威胁: Downloader
文件:  C:\Documents and Settings\crossmap_yanhui\Local Settings\Temporary Internet Files\Content.IE5\Q2Z5PV9V\c[1].gif
位置:  C:\Documents and Settings\crossmap_yanhui\Local Settings\Temporary Internet Files\Content.IE5\Q2Z5PV9V
计算机:  CROSSMAP-YANHUI
用户:  crossmap_yanhui
采用的操作:  清除 失败 : 隔离 失败 : 删除 成功 : 拒绝访问
发现的日期: 2006年8月19日  11:35:15




扫描类型:  自动防护 扫描
事件:  发现威胁!
威胁: Downloader
文件:  C:\Documents and Settings\crossmap_yanhui\Local Settings\Temporary Internet Files\Content.IE5\Q2Z5PV9V\c[1].gif
位置:  C:\Documents and Settings\crossmap_yanhui\Local Settings\Temporary Internet Files\Content.IE5\Q2Z5PV9V
计算机:  CROSSMAP-YANHUI
用户:  crossmap_yanhui
采用的操作:  清除 失败 : 隔离 失败 : 删除 成功 : 拒绝访问
发现的日期: 2006年8月19日  11:35:15


扫描类型:  自动防护 扫描
事件:  发现威胁!
威胁: Downloader
文件:  C:\Documents and Settings\crossmap_yanhui\Local Settings\Temporary Internet Files\Content.IE5\Q2Z5PV9V\c[1].gif
位置:  C:\Documents and Settings\crossmap_yanhui\Local Settings\Temporary Internet Files\Content.IE5\Q2Z5PV9V
计算机:  CROSSMAP-YANHUI
用户:  crossmap_yanhui
采用的操作:  清除 失败 : 隔离 失败 : 拒绝访问
发现的日期: 2006年8月19日  11:36:14


扫描类型:  自动防护 扫描
事件:  发现威胁!
威胁: Downloader
文件:  C:\Documents and Settings\crossmap_yanhui\Local Settings\Temporary Internet Files\Content.IE5\Q2Z5PV9V\c[1].gif
位置:  C:\Documents and Settings\crossmap_yanhui\Local Settings\Temporary Internet Files\Content.IE5\Q2Z5PV9V
计算机:  CROSSMAP-YANHUI
用户:  crossmap_yanhui
采用的操作:  清除 失败 : 隔离 失败 : 删除 成功 : 拒绝访问
发现的日期: 2006年8月19日  11:36:15




现在电脑总是弹出这些东西
gototop
 

还是那句话...我都按我说的做...

清空IE临时文件夹...

附件附件:

下载次数:155
文件类型:image/pjpeg
文件大小:
上传时间:2006-8-19 16:36:20
描述:



gototop
 

还是那句话...我都按我说的做...

清空IE临时文件夹...
gototop
 

打开一个IE窗口,工具,internte选项,点“删除文件”弹出一个窗口勾选“删除所有脱机内容”删除cookies,确定
建议你下载超级兔子。
http://www.pctutu.com/srmsdown.asp
安装好后,打开“超级兔子优化王”“专业卸载,卸载所有提示的垃圾软件,卸载是不要打开任何浏览窗口。卸载不了可以重启后再去卸载。

请到www.27814939.ys168.com,点“我的软件”下载KillBox.exe

请到http://forum.ikaka.com/topic.asp?board=67&artid=5188931,下载,LSPFix.exe,WinsockXPFix这两个软件
重新启动电脑, 开机检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式进入Windows
运行(双击)System Repair Engineer,使用“启动项目,注册表”来删除以下选项。
C:\Program Files\Common Files\{7C215DC4-0710-2052-1220-051114050056}\Update.exe
C:\\dfndrff_11.exe
C:\\kybrdff_11.exe
C:\\nwnmff_11.exe
C:\WINDOWS\system32\mswdm.exe
C:\WINDOWS\webwork\webwork.dll
双击打开KillBox.exe,分别删除
C:\WINDOWS\webwork\webwork.nls
C:\Program Files\Internet Explorer\PLUGINS\system2.sys
(删除时勾选“删除前先结束Explorer.EXE进程”

运行LSPFix.exe
删除
quartz32.dll
附说明一份
LSPFix.exe这个软件主要用来辅助修复HijackThis扫描发现的O10项。
使用时,请关闭所有IE界面和文件夹界面后运行LSPFix,运行后,把要修复的那一个O10项从左边转到右边,点“Finish”即可。(不过这之前,需要在“I know what I`m doing”前面打勾。)
双击我的电脑,工具,文件夹选项,查看,单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示确定更改时,单击“是”,清除“隐藏已知文件类型的扩展名
删除
C:\Program Files\Common Files\{7C215DC4-0710-2052-1220-051114050056}\Update.exe
C:\\dfndrff_11.exe
C:\\kybrdff_11.exe
C:\\nwnmff_11.exe
C:\WINDOWS\system32\mswdm.exe
C:\WINDOWS\webwork\webwork.dll
C:\WINDOWS\system32\quartz32.dll
修复后重启,如果无法上网,请运行WinsockXPFix,让它修复一下。
回到正常模式,请再扫日志粘上来。
gototop
 

哇。谢谢“我无邪”。我试试哦
gototop
 
1234   3  /  4  页   跳转
页面顶部
Powered by Discuz!NT