C:\\WINDOWS\\System32\\smss.exe
C:\\WINDOWS\\system32\\winlogon.exe
C:\\WINDOWS\\system32\\services.exe
C:\\WINDOWS\\system32\\lsass.exe
C:\\WINDOWS\\system32\\svchost.exe
C:\\WINDOWS\\System32\\svchost.exe
C:\\WINDOWS\\system32\\spoolsv.exe
C:\\WINDOWS\\Explorer.EXE
C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe
C:\\Program Files\\iCompanion\\ic.exe
C:\\Program Files\\Java\\j2re1.4.2_04\\bin\\jusched.exe
C:\\Program Files\\D-Tools\\daemon.exe
C:\\WINDOWS\\SOUNDMAN.EXE
C:\\Program Files\\WinPoET Broadband Connection\\winpppoverethernet.exe
C:\\WINDOWS\\system32\\ctfmon.exe
C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe
C:\\Program Files\\Maxthon\\Maxthon.exe
C:\\Program Files\\Symantec_Client_Security\\Symantec AntiVirus\\DefWatch.exe
C:\\Program Files\\Symantec_Client_Security\\Symantec AntiVirus\\Rtvscan.exe
C:\\WINDOWS\\System32\\svchost.exe
C:\\Program Files\\WinPoET Broadband Connection\\WrOS.EXE
C:\\Program Files\\BitComet\\BitComet.exe
C:\\Program Files\\FlashGet\\flashget.exe
C:\\DOCUME~1\\seanshen\\LOCALS~1\\Temp\\Rar$EX00.125\\HijackThis.exe
O2 - BHO: (no name) - {04DCC17E-35E1-417A-ABCF-41623FA2ACE7} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\\PROGRA~1\\SPYBOT~1\\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\\PROGRA~1\\FlashGet\\jccatch.dll
O2 - BHO: (no name) - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - (no file)
O3 - Toolbar: (no name) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - (no file)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\\PROGRA~1\\FlashGet\\fgiebar.dll
O3 - Toolbar: CyberArticle Express - {769A6A36-ED24-4376-BC7C-80225BF35698} - C:\\Program Files\\CyberArticle\\CAExp.dll
O4 - HKLM\\..\\Run: [IMJPMIG8.1] \"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32
O4 - HKLM\\..\\Run: [PHIME2002ASync] ; C:\\WINDOWS\\System32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC
O4 - HKLM\\..\\Run: [PHIME2002A] ; C:\\WINDOWS\\System32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName
O4 - HKLM\\..\\Run: [vptray] C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe
O4 - HKLM\\..\\Run: [netmon.exe] C:\\Program Files\\iCompanion\\ic.exe
O4 - HKLM\\..\\Run: [SunJavaUpdateSched] C:\\Program Files\\Java\\j2re1.4.2_04\\bin\\jusched.exe
O4 - HKLM\\..\\Run: [DAEMON Tools-1033] \"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033
O4 - HKLM\\..\\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\\..\\Run: [a-winpoet-service] \"C:\\Program Files\\WinPoET Broadband Connection\\winpppoverethernet.exe\"
O4 - HKLM\\..\\Run: [Super Rabbit SRRestore] ; C:\\PROGRA~1\\SUPERR~1\\MagicSet\\SRRest.exe /autosave
O4 - HKLM\\..\\Run: [KernelFaultCheck] ; %systemroot%\\system32\\dumprep 0 -k
O4 - HKLM\\..\\Run: [TkBellExe] \"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot
O4 - HKCU\\..\\Run: [ctfmon.exe] C:\\WINDOWS\\system32\\ctfmon.exe
O4 - HKCU\\..\\Run: [MsnMsgr] \"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background
O4 - HKCU\\..\\Run: [SpybotSD TeaTimer] C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe
O8 - Extra context menu item: 使用网际快车下载 - C:\\Program Files\\FlashGet\\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\\Program Files\\FlashGet\\jc_all.htm
O9 - Extra button: 金山词霸 - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - C:\\WINDOWS\\System32\\shdocvw.dll
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {991481A7-4669-4E15-8C24-100404E1F5CB} - http://www.bluesky.cn/download/blueskyvoice_60.cab
O16 - DPF: {F2EB8999-766E-4BF6-AAAD-188D398C0D0B} - http://www4.cmbchina.com/download/pb45.cab
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\..\\{75DC4427-90F7-42D1-8872-0A237D1867DE}: NameServer = 202.96.209.6 202.96.209.133
O20 - Winlogon Notify: NavLogon - C:\\WINDOWS\\System32\\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\\Program Files\\Symantec_Client_Security\\Symantec AntiVirus\\DefWatch.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\\Program Files\\Symantec_Client_Security\\Symantec AntiVirus\\Rtvscan.exe
O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\\Program Files\\WinPoET Broadband Connection\\WrOS.EXE
已经在安全模式下在未打开IE的情况下删除
O2 - BHO: (no name) - {04DCC17E-35E1-417A-ABCF-41623FA2ACE7} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - (no file)
三键,IE也清空
可重起后,还是存在这三键。
广告继续弹出。
这三键在注册表里是browse
OBJECT,
依然没有解决问题。
求大家再帮忙仔细看看。
现像。一开始弹出多多宽频的窗口,后来就是不同网址的什么手机铃声什么的。
本人是XP,MAXTHON
已用过 SPY SBOT 和 清理过IE 插件了。