瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】中了病毒,然后在遨游地址栏输入中文搜索网页却打开别的网页

1   1  /  1  页   跳转

【求助】中了病毒,然后在遨游地址栏输入中文搜索网页却打开别的网页

【求助】中了病毒,然后在遨游地址栏输入中文搜索网页却打开别的网页

我在遨游的地址栏里面输入中文进行搜索,回车后结果却打开了这个网页http://abc.265.com/

2006-06-25,10:40:06

System Repair Engineer 2.0.12.350 (2.0 RC 1)
    Windows XP Professional Service Pack 2 - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <load><>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <run><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <MSPY2002><C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <CnsMin><Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <helper.dll><C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <shell><EXPLORER.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <AppInit_DLLs><>

==================================
启动文件夹
[Adobe Gamma Loader]
  <C:\Documents and Settings\All Users.WINDOWS\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>
[IE-BAR]
  <C:\Documents and Settings\All Users.WINDOWS\「开始」菜单\程序\启动\IE-BAR.lnk><N>

==================================
服务
[Ati HotKey Poller / Ati HotKey Poller]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart]
  <C:\WINDOWS\system32\ati2sgag.exe><>
[DefWatch / DefWatch]
  <C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe><Symantec Corporation>
[DriveHealth / DriveHealth]
  <C:\Program Files\Helexis\Drive Health\dhcore.exe><Helexis Software Development>
[Symantec AntiVirus Client / Norton AntiVirus Server]
  <C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe><Symantec Corporation>
[NVIDIA Display Driver Service / NVSvc]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[SigmaTel Audio Service / STacSV]
  <C:\Program Files\SigmaTel\C-Major Audio\WDM\Stacsv.exe><SigmaTel, Inc.>

==================================
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v14.dll, Thunder Networking Technologies,LTD>
[]
  {12C207A8-71F0-44CE-8D05-B4DB9FD5FDA6} <C:\WINDOWS\ODBCIINT.dll, N/A>
[BrowserHelper Class]
  {2D99E8F4-56B7-457B-9A92-61B5D247D263} <C:\WINDOWS\system32\WinDefendor.dll, TODO: <公司名>>
[NewWebController Class]
  {9ACEEE30-143F-471A-AA45-72B061FE7D60} <C:\WINDOWS\system32\AdvSC.dll, N/A>
[MMSAssistMenu]
  {6671A433-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[]
  {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A>
[]
  {FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A>
[CEditCtrl Object]
  {488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\system32\aliedit\AliEdit.dll, www.alipay.com>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[AxSubmitControl Class]
  {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} <C:\WINDOWS\system32\SUBMIT~1.DLL, >
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v14.dll, Thunder Networking Technologies,LTD>
[MonitorURL Class]
  {08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, N/A>
[]
  {12C207A8-71F0-44CE-8D05-B4DB9FD5FDA6} <C:\WINDOWS\ODBCIINT.dll, N/A>
[MyIEHelper Class]
  {16A770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\IEHelper\IEHelper_4663.dll, N/A>
[BrowserHelper Class]
  {2D99E8F4-56B7-457B-9A92-61B5D247D263} <C:\WINDOWS\system32\WinDefendor.dll, TODO: <公司名>>
[Yahoo!Photo]
  {33BBE430-0E42-4F12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll, Yahoo! China>
[雅虎助手]
  {406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[CnsHook Class]
  {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\DOWNLO~1\CnsHook.dll, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[&使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[>>彩信发送<<]
  <res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm, N/A>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\qq\AddEmotion.htm, N/A>

最后编辑2006-06-25 13:54:14
分享到:
gototop
 

剩下的贴不上来。。。。。
怎么回事
gototop
 

==================================
正在运行的进程
[PID: 552][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 624][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 652][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\Ati2evxx.dll]  <ATI Technologies Inc.><6.14.10.4119>
    [C:\WINDOWS\system32\NavLogon.dll]  <N/A><N/A>
[PID: 696][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 708][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 860][C:\WINDOWS\system32\Ati2evxx.exe]  <ATI Technologies Inc.><6.14.10.4119>
    [C:\WINDOWS\system32\Ati2edxx.dll]  <ATI Technologies, Inc.><6, 14, 10, 2497>
[PID: 872][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 952][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1048][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1096][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1228][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1424][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 1576][C:\WINDOWS\system32\Ati2evxx.exe]  <ATI Technologies Inc.><6.14.10.4119>
    [C:\WINDOWS\system32\Ati2edxx.dll]  <ATI Technologies, Inc.><6, 14, 10, 2497>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
[PID: 1672][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\xunleibho_v14.dll]  <Thunder Networking Technologies,LTD><4, 6, 0, 62>
    [C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll]  <Symantec Corporation><8.1.0.821>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\Program Files\ewido\security suite\context.dll]  <ewido networks><1.0.0.1>
    [C:\Program Files\ewido\security suite\lang.dll]  <privat><1, 0, 0, 1>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  <><2, 1, 5, 1045>
    [C:\Program Files\ewido\security suite\shellhook.dll]  <N/A><N/A>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL]  <><1, 2, 7, 1006>
    [C:\WINDOWS\DOWNLO~1\CnsMinIO.dll]  <北京三七二一科技有限公司><1, 0, 3, 6>
    [C:\WINDOWS\DOWNLO~1\cnsio.dll]  <北京三七二一科技有限公司><1, 0, 2, 7>
    [C:\WINDOWS\ODBCIINT.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\WinDefendor.dll]  <TODO: <公司名>><1.0.0.2>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ywiper.dll]  <N/A><1, 0, 1, 1014>
[PID: 1856][C:\WINDOWS\VM_STI.EXE]  <Vimicro><4, 2, 1225, 6>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
[PID: 1904][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
[PID: 936][C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe]  <Symantec Corporation><8.1.0.821>
[PID: 1004][C:\Program Files\Helexis\Drive Health\dhcore.exe]  <Helexis Software Development><2.3.0.110>
[PID: 1104][C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe]  <Symantec Corporation><8.1.0.821>
    [C:\WINDOWS\system32\CBA.DLL]  <Intel? Corporation><6.12.0.105 E>
    [C:\WINDOWS\system32\MsgSys.dll]  <Intel? Corporation><6.12.0.105 E>
    [C:\WINDOWS\system32\NTS.dll]  <Intel? Corporation><6.12.0.105 E>
    [C:\WINDOWS\system32\PDS.DLL]  <Intel? Corporation><6.12.0.105 E>
    [C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVLU.dll]  <Symantec Corporation><8.1.0.821>
    [C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVNTUTL.DLL]  <Symantec/Peter Norton Group><1, 0, 0, 1>
    [C:\PROGRA~1\SYMANT~1\SYMANT~1\i2ldvp3.dll]  <Symantec Corporation><8.1.0.821>
    [C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVAPI32.DLL]  <Symantec Corp.><4.2.0.7>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060621.024\NAVEX32a.DLL]  <Symantec Corporation><20061.1.0.14>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060621.024\NAVENG32.DLL]  <Symantec Corporation><20061.1.0.14>
gototop
 

[C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAP32.DLL]  <Symantec Corporation><9.1.0.26>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vpmsece.dll]  <Symantec Corporation><8.1.0.821>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\SSC\Scandlgs.dll]  <Symantec Corporation><8.1.0.821>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DecSDK.dll]  <Symantec Corporation><3.02.09.07>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2.dll]  <Symantec Corporation><3.02.09.07>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2ID.dll]  <Symantec Corporation><3.02.09.07>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2UUE.dll]  <Symantec Corporation><3.02.09.07>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2AMG.dll]  <Symantec Corporation><3.02.09.07>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2ARJ.dll]  <Symantec Corporation><3.02.09.07>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2CAB.dll]  <Symantec Corporation><3.02.09.07>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2EXE.dll]  <Symantec Corporation><3.02.09.07>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2GZIP.dll]  <Symantec Corporation><3.02.09.07>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2HQX.dll]  <Symantec Corporation><3.02.09.07>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2LHA.dll]  <Symantec Corporation><3.02.09.07>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2LZ.dll]  <Symantec Corporation><3.02.09.07>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2MIME.dll]  <Symantec Corporation><3.02.09.07>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2SS.dll]  <Symantec Corporation><3.02.09.07>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2RTF.dll]  <Symantec Corporation><3.02.09.07>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2TAR.dll]  <Symantec Corporation><3.02.09.07>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2TNEF.dll]  <Symantec Corporation><3.02.09.07>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2ZIP.dll]  <Symantec Corporation><3.02.09.07>
[PID: 1236][C:\Program Files\SigmaTel\C-Major Audio\WDM\Stacsv.exe]  <SigmaTel, Inc.><1.0.4866.0  nd365 cp1>
    [C:\WINDOWS\system32\stacapi.dll]  <SigmaTel, Inc.><1.0.4866.0  nd365 cp1>
[PID: 1208][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1496][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 1812][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1788][C:\Program Files\ewido\security suite\ewidoctrl.exe]  <ewido networks><3, 0, 0, 1>
    [C:\Program Files\ewido\security suite\lang.dll]  <privat><1, 0, 0, 1>
[PID: 2488][C:\WINDOWS\system32\taskmgr.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
[PID: 1176][C:\WINDOWS\system32\Rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\WINDOWS\DOWNLO~1\CnsMinIO.dll]  <北京三七二一科技有限公司><1, 0, 3, 6>
    [C:\WINDOWS\DOWNLO~1\cnsio.dll]  <北京三七二一科技有限公司><1, 0, 2, 7>
[PID: 2256][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3510>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
[PID: 3888][C:\Program Files\ewido\security suite\securitysuite.exe]  <ewido networks><3, 5, 0, 0>
    [C:\Program Files\ewido\security suite\lang.dll]  <privat><1, 0, 0, 1>
    [C:\Program Files\ewido\security suite\wizard.dll]  <N/A><N/A>
    [C:\Program Files\ewido\security suite\framework.dll]  <ewido networks><1, 0, 0, 249>
    [C:\Program Files\ewido\security suite\configuration.dll]  <ewido networks><1, 0, 0, 1>
    [C:\Program Files\ewido\security suite\engine.dll]  <ewido networks GmbH & Co. KG><4, 0, 0, 2>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\Program Files\ewido\security suite\scan.dll]  <ewido networks><1, 0, 0, 2>
    [C:\Program Files\ewido\security suite\modules\autostartviewer.dll]  <ewido networks><1, 0, 0, 114>
    [C:\Program Files\ewido\security suite\TScan1.dll]  <ewido networks><3, 0, 0, 0>
    [C:\Program Files\ewido\security suite\archive.dll]  <N/A><N/A>
    [C:\Program Files\ewido\security suite\modules\connectionwatch.dll]  <ewido networks><1, 0, 0, 2>
    [C:\Program Files\ewido\security suite\modules\processviewer.dll]  <privat><1, 0, 0, 2>
    [C:\Program Files\ewido\security suite\quarantine.dll]  <ewido networks><1, 0, 0, 43>
    [C:\Program Files\ewido\security suite\update.dll]  <ewido networks><1, 0, 0, 8>
    [C:\Program Files\ewido\security suite\update_core.dll]  <N/A><N/A>
    [C:\Program Files\ewido\security suite\info.dll]  <ewido networks><1, 0, 0, 137>
    [C:\Program Files\ewido\security suite\resources.dll]  <N/A><N/A>
[PID: 3644][C:\Program Files\Maxthon\Max.exe]  <Maxthon International Ltd.><1, 5, 3, 18>
    [C:\Program Files\Maxthon\maxzlib.dll]  < ><1, 0, 0, 2>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll]  <Thunder Networking Technologies,LTD><5, 0, 0, 1>
    [C:\Program Files\Maxthon\Services\RealTime\real_time.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
[PID: 1920][C:\Downloads\反病毒\sreng2System Repair Engineer 2.0.12.350 RC1版\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

进入控制面版的添加删除程序中卸载WIE-BAR,MMSASS~1彩信,这两个流氓软件。
关闭所有浏览窗口以及一些不必要的程序
运行(双击)System Repair Engineer,使用“系统修复,浏览器加载项”来删除以下选项
C:\WINDOWS\ODBCIINT.dll
C:\WINDOWS\system32\WinDefendor.dll
C:\WINDOWS\system32\AdvSC.dll
C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
C:\WINDOWS\system32\SUBMIT~1.DLL
C:\PROGRA~1\DESKAD~1\deskipn.dll
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\IEHelper\IEHelper_4663.dll
双击我的电脑,工具,文件夹选项,查看,单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示确定更改时,单击“是”,清除“隐藏已知文件类型的扩展名
删除
C:\Program Files\IE-BAR

C:\WINDOWS\ODBCIINT.dll
C:\WINDOWS\system32\WinDefendor.dll
C:\WINDOWS\system32\AdvSC.dll
C:\Program Files\MMSASS~1
C:\WINDOWS\system32\SUBMIT~1.DLL
C:\Program Files\DESKAD~1
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\IEHelper\IEHelper_4663.dll
gototop
 

谢谢
这个里面已经没有了C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
然后C:\WINDOWS\ODBCIINT.dll
C:\WINDOWS\system32\WinDefendor.dll
删不掉,有程序在用,但是在进程里面找又找不出来是哪个在用

这两个也没有了已经
C:\Program Files\MMSASS~1
C:\Program Files\DESKAD~1

C:\WINDOWS\system32\SUBMIT~1.DLL也没有,不过里面有个一个名为SubmitControl.dll得的文件要不要删除??
谢谢
gototop
 

阿~~对了
MMSASS~1彩信这个流氓软件添加或删除程序的列表里面没有

都不知道这些东西是怎么自己安装近来的....
gototop
 

没有的话。
建议你下载超级兔子。
http://www.pctutu.com/srmsdown.asp
安装好后,打开“超级兔子优化王”“专业卸载,卸载所有提示的垃圾软件,卸载是不要打开任何浏览窗口。卸载不了可以重启后再去卸载。
gototop
 

哦~~兔子我有~
现在这些工具越下越多了....都是为了病毒~~
555~~~
祈祷天下的病毒都死光光吧~~~

谢谢啦~~~
都帮了我几次了
gototop
 

据说安装有3721后,就会有你所说的http://abc.265.com/这个现象。
你的兔子是不是今年六月的版本,如果不是,你可以在线更新。更新后再去卸载。看看能不能解决这个问题。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT