瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 浏览器自己弹出网页啊~~~~~~~~~~ 我快疯了

1   1  /  1  页   跳转

浏览器自己弹出网页啊~~~~~~~~~~ 我快疯了

浏览器自己弹出网页啊~~~~~~~~~~ 我快疯了

每次 弹出来,过了2秒 就自动关闭了,我现在一点办法都没有啊
弄得我快疯了
http://220.167.29.103:9123/ndatin.aspx?param=ABdXNlcm5hbWU9bHMzMjcwMzA5JnBvbGljeWlkPTM=
就是这个网站  我快疯了  我一字一字的打出来的
最后编辑2006-08-04 04:01:12
分享到:
gototop
 

C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\DOWNLO~1\SPVXK.DLL
C:\PROGRAM FILES\ACROBATCHS\ACTIVEX\PDFSHELL.DLL
C:\WINDOWS\DOWNLO~1\TTZJW.DLL
C:\WINDOWS\SYSTEM32\XUNLEIBHO_V14.DLL
C:\PROGRAM FILES\ACROBATCHS\ACTIVEX\ACROIEHELPER.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\LOCKFILE2007\SYSHOOK.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\PROGRA~1\MICROS~2\OFFICE11\MCPS.DLL

C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\WINDOWS\SYSTEM32\IMSC40A.IME

C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\WINDOWS\SYSTEM32\MSACM32.DRV

C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\CDNNS.DLL

C:\WINDOWS\LOCKFILE2007\SERVICES.EXE
C:\WINDOWS\SYSTEM32\IMSC40A.IME

C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\CDNNS.DLL

C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\VTTIMER.EXE
C:\WINDOWS\SYSTEM32\IMSC40A.IME

C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM32\IMSC40A.IME

C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
C:\WINDOWS\SYSTEM32\CDNNS.DLL

C:\WINDOWS\SYSTEM32\VTTRAYP.EXE
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\WINDOWS\SYSTEM32\VTDISPLY.DLL
C:\WINDOWS\SYSTEM32\VTGAMMA2.DLL
C:\WINDOWS\SYSTEM32\VTINFO2.DLL
C:\WINDOWS\SYSTEM32\VTOVRLAY.DLL

C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\SYSTEM32\IMSC40A.IME

C:\WINDOWS\SYSTEM32\WDFMGR.EXE
F:\新建文件夹 (2)\RSDETECT.EXE
C:\WINDOWS\DOWNLO~1\SPVXK.DLL
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL

C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\DOWNLO~1\SPVXK.DLL
C:\WINDOWS\DOWNLO~1\TTZJW.DLL
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL
C:\WINDOWS\SYSTEM32\KAKATOOL.DLL
C:\WINDOWS\SYSTEM32\XUNLEIBHO_V14.DLL
C:\PROGRAM FILES\ACROBATCHS\ACTIVEX\ACROIEHELPER.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\LOCKFILE2007\SYSHOOK.DLL
C:\PROGRA~1\CHINANET\VNETTR~1.DLL
C:\PROGRA~1\CHINANET\COMMUNICATE.DLL
C:\PROGRA~1\CHINANET\CLIENT~1.DLL
F:\新建文件夹 (2)\新建文件夹 (2)\QQIEHELPER.DLL
C:\WINDOWS\SYSTEM32\SSUP.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL

C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\DOWNLO~1\SPVXK.DLL
C:\WINDOWS\DOWNLO~1\TTZJW.DLL
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL
C:\WINDOWS\SYSTEM32\KAKATOOL.DLL
C:\WINDOWS\SYSTEM32\XUNLEIBHO_V14.DLL
C:\PROGRAM FILES\ACROBATCHS\ACTIVEX\ACROIEHELPER.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\LOCKFILE2007\SYSHOOK.DLL
C:\PROGRA~1\CHINANET\VNETTR~1.DLL
C:\PROGRA~1\CHINANET\COMMUNICATE.DLL
C:\PROGRA~1\CHINANET\CLIENT~1.DLL
F:\新建文件夹 (2)\新建文件夹 (2)\QQIEHELPER.DLL
C:\WINDOWS\SYSTEM32\SSUP.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\CDNNS.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH8B.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\RMOC3260.DLL
C:\WINDOWS\SYSTEM32\PNCRT.DLL
C:\PROGRAM FILES\COMMON FILES\REAL\COMMON\PNRS3260.DLL


普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE" /SPOIL /REMADVDEF /MIGRATION32
PHIME2002ASync = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME
MSPY2002 = C:\WINDOWS\SYSTEM32\IME\PINTLGNT\IMSCINST.EXE /SYNC
SoundMan = SOUNDMAN.EXE
VTTimer = VTTIMER.EXE
VTTrayp = VTTRAYP.EXE
IMSCMig = C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /PRELOAD
KernelFaultCheck = C:\WINDOWS\SYSTEM32\DUMPREP 0 -K
TkBellExe = "C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE" -OSBOOT
RavTask = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
stup.exe = C:\PROGRA~1\TENCENT\ADPLUS\STUP.EXE
sysHook = C:\WINDOWS\LOCKFILE2007\SERVICES.EXE

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE


AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =


系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde

其它启动项
WIN.INI
无信息

SYSTEM.INI
SHELL = Explorer.exe C:\WINDOWS\LockFile2007\SERVICES.EXE
SCRNSAVE.EXE = C:\WINDOWS\system32\ss3dfo.scr


Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
ScCertProp = WLNOTIFY.DLL
Schedule = WLNOTIFY.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
termsrv = WLNOTIFY.DLL
wlballoon = WLNOTIFY.DLL

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = C:\WINDOWS\SYSTEM32\USERINIT.EXE
shell = EXPLORER.EXE C:\WINDOWS\LOCKFILE2007\SERVICES.EXE


IE - BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{0005A87D-D626-4B3A-84F9-1D9571695F55} = C:\WINDOWS\system32\xunleibho_v14.dll
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} = C:\Program Files\Acrobatchs\ActiveX\AcroIEHelper.dll
{0C7C23EF-A848-485B-873C-0ED954731014} = C:\Program Files\TENCENT\Adplus\SSAddr.dll
{49E0E0F0-5C30-11D4-945D-000000088168} = C:\WINDOWS\LockFile2007\sysHook.dll
{4E83D567-4697-4F7B-B1F0-A513B01DB89A} = c:\PROGRA~1\chinanet\VNETTR~1.DLL
{54EBD53A-9BC1-480B-966A-843A333CA162} = F:\新建文件夹 (2)\新建文件夹 (2)\QQIEHelper.dll
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} = C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
{62EED7C6-9F02-42f9-B634-98E2899E147B} = C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
{669751ED-D558-49AE-B01A-3B374CC7910E} = C:\WINDOWS\system32\ssup.dll
{944864A5-3916-46E2-96A9-A2E84F3F1208} = C:\Program Files\Accoona\ASearchAssist.dll
{F5824EFB-728A-4726-A5A5-85A68B20EDC3} = C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll


Winsock SPI
MSAFD Tcpip [TCP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [UDP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [RAW/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
RSVP UDP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
RSVP TCP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{5693533D-2B86-4F83-A4A8-D52A3AF6BD7E}] SEQPACKET 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{5693533D-2B86-4F83-A4A8-D52A3AF6BD7E}] DATAGRAM 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{AFD1A054-3160-4911-BBF2-2FFDB3D65451}] SEQPACKET 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{AFD1A054-3160-4911-BBF2-2FFDB3D65451}] DATAGRAM 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{27D2AB6D-1C0D-4D41-A036-0E957CC930B1}] SEQPACKET 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{27D2AB6D-1C0D-4D41-A036-0E957CC930B1}] DATAGRAM 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{828065E3-7428-4591-BEB6-86CD658E28E1}] SEQPACKET 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{828065E3-7428-4591-BEB6-86CD658E28E1}] DATAGRAM 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{1B24C8A6-25DC-4008-AA3E-DE9D7E28942B}] SEQPACKET 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{1B24C8A6-25DC-4008-AA3E-DE9D7E28942B}] DATAGRAM 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL

gototop
 

[SMSS.EXE]
CommandLine =

[CSRSS.EXE]
CommandLine = C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

[WINLOGON.EXE]
CommandLine = winlogon.exe

[SERVICES.EXE]
CommandLine = C:\WINDOWS\system32\services.exe

[LSASS.EXE]
CommandLine = C:\WINDOWS\system32\lsass.exe

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss

[CCenter.exe]
CommandLine = "C:\Program Files\Rising\Rav\CCenter.exe"

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost.exe -k NetworkService

[SVCHOST.EXE]
CommandLine = C:\WINDOWS\system32\svchost.exe -k LocalService

[RavMonD.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmond.exe"

[SPOOLSV.EXE]
CommandLine = C:\WINDOWS\system32\spoolsv.exe

[RavStub.exe]
CommandLine = "C:\Program Files\Rising\Rav\RavStub.exe" /RAVMOND

[WDFMGR.EXE]
CommandLine = C:\WINDOWS\system32\wdfmgr.exe

[Explorer.EXE]
CommandLine = Explorer.exe C:\WINDOWS\LockFile2007\SERVICES.EXE

[CTFMON.EXE]
CommandLine = ctfmon.exe

[ALG.EXE]
CommandLine = C:\WINDOWS\System32\alg.exe

[SERVICES.EXE]
CommandLine = "C:\WINDOWS\LockFile2007\SERVICES.EXE"

[SOUNDMAN.EXE]
CommandLine = "C:\WINDOWS\SOUNDMAN.EXE"

[VTTimer.exe]
CommandLine = "C:\WINDOWS\system32\VTTimer.exe"

[VTTrayp.exe]
CommandLine = "C:\WINDOWS\system32\VTtrayp.exe"

[realsched.exe]
CommandLine = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot

[RavTask.exe]
CommandLine = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM

[RavMon.exe]
CommandLine = "C:\Program Files\Rising\Rav\Ravmon.exe" -SYSTEM

[iexplore.exe]
CommandLine = "C:\Program Files\Internet Explorer\iexplore.exe"

[TIMPlatform.exe]
CommandLine = "F:\新建文件夹 (2)\新建文件夹 (2)\TIMPlatform.exe" -Embedding

[QQ.EXE]
CommandLine = "F:\新建文件夹 (2)\新建文件夹 (2)\QQ.EXE"

[QQ.EXE]
CommandLine = "F:\新建文件夹 (2)\新建文件夹 (2)\QQ.EXE"

[QQPet.exe]
CommandLine = "F:\新建文件夹 (2)\新建文件夹 (2)\qqpet\qqpet.exe" 514401010600041200BDA8B9B2BD8C9F8C80B2899AA58C8389818804000000AE040600040F00A0B5A4AFA09182919DAF9487A5999E04000000B24E3916061100BEABBAB1BE8F9C8F83B19D9A9CA0878D850B0000003E2224304130C038013B2B061000BFAABBB0BF8E9D8E82B09C9B9DA48A9640000000FAFCFB8BFD8EFCFCFEFCFA8DFAFEF9898CFCFBFCFB8B8A888FF98FFEFE8F8A8DFA87FDFBFB8C8AFE8E898D8D8B8D8C8888FD8D898A898AFDFEFAFEFBFDF98E86040100AE04000000E1D6C644021400BBAEBFB4BB8A998A86B488BB99849392BF929B8E0100000000

[QQ.EXE]
CommandLine = "F:\新建文件夹 (2)\新建文件夹 (2)\QQ.EXE"

[QQ.EXE]
CommandLine = "F:\新建文件夹 (2)\新建文件夹 (2)\QQ.EXE"

[KkScan.exe]
CommandLine = "F:\新建文件夹 (3)\新建文件夹\KkScan.exe"

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://seek.3721.com/srchasst.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://www.yahoo.com.cn
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.hao123.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page=http://www.yahoo.com.cn
R3 - URLSearchHook: (no name) - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
R3 - URLSearchHook: Tencent SearchHook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\Adplus\SSAddr.dll
F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\LockFile2007\SERVICES.EXE
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v14.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Acrobatchs\ActiveX\AcroIEHelper.dll
O2 - BHO: Tencent Browser Helper - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\Program Files\TENCENT\Adplus\SSAddr.dll
O2 - BHO: IE 4.x-5.x BHO in ObjectPascal - {49E0E0F0-5C30-11D4-945D-000000088168} - C:\WINDOWS\LockFile2007\sysHook.dll
O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\chinanet\VNETTR~1.DLL
O2 - BHO: QQBrowserHelperObject Class - {54EBD53A-9BC1-480B-966A-843A333CA162} - F:\新建文件夹 (2)\新建文件夹 (2)\QQIEHelper.dll
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O2 - BHO: DragSearch BHO - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL (file missing)
O2 - BHO:  - {669751ED-D558-49AE-B01A-3B374CC7910E} - C:\WINDOWS\system32\ssup.dll
O2 - BHO: ADefaultSearch Class - {944864A5-3916-46E2-96A9-A2E84F3F1208} - C:\Program Files\Accoona\ASearchAssist.dll (file missing)
O2 - BHO: WMHlprObj Class - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\KakaTool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [stup.exe] C:\PROGRA~1\TENCENT\Adplus\stup.exe
O4 - HKLM\..\Run: [sysHook] C:\WINDOWS\LockFile2007\SERVICES.EXE
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O8 - Extra context menu item: &使用迅雷下载 - F:\新建文件夹 (2)\新建文件夹\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - F:\新建文件夹 (2)\新建文件夹\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - F:\新建文件夹 (2)\新建文件夹 (2)\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\新建文件夹 (2)\新建文件夹 (2)\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\新建文件夹 (2)\新建文件夹 (2)\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\新建文件夹 (2)\新建文件夹 (2)\SendMMS.htm
O9 - Extra Button: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra 'Tools' menuitem: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra Button: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra Button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\新建文件夹 (2)\新建文件夹 (2)\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\新建文件夹 (2)\新建文件夹 (2)\QQ.EXE
O9 - Extra Button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - F:\新建文件夹 (2)\新建文件夹 (2)\QQIEHelper.dll

gototop
 

O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - F:\新建文件夹 (2)\新建文件夹 (2)\QQIEHelper.dll
O9 - Extra Button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\cdnns.dll
O11 - Options group: [CDNCLIENT]  中文上网
O11 - Options group: [TBH] 搜搜地址栏搜索
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.tvkoo.com/update/KooPlayer.ocx
O16 - DPF: {40CFEA79-ED5B-4B2B-8B8D-B567E40AF812} (sslclient Control) - http://lenovo.tol24.com/download/ocx/sslclientnew.cab
O16 - DPF: {42B6F90A-9B1F-458F-BD6B-03478935A65E} (UDPlayerCtl Control) - http://61.172.202.70/playerctl/UDPlayerCtl.cab
O16 - DPF: {5EC7C511-CD0F-42E6-830C-1BD9882F3458} (PowerPlayer Control) - http://download.ppstream.com/bin/powerplayer.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1133001674187
O16 - DPF: {74447F9C-5691-4A9A-8BE4-564092E40B03} (VnetAnprIns Class) - http://plugin.chinavnet.com/VnetPluginIns.CAB
O16 - DPF: {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} (Qzone Media Tools) - http://qz-photo.qq.com/qzone3/QzoneMediaTools.cab
O16 - DPF: {C661F36D-DF85-4EF4-83C7-E107B83D04B1} (WebActivater Control) - http://dl_dir.qq.com/3dshow/3DShowVM.cab
O16 - DPF: {D0A29C6C-AA71-4423-8C4A-5998B774C448} (IEDown Class) - http://download.ourgame.com/IEDown4.cab
O16 - DPF: {E1207373-6721-4AAD-888B-C8C5A0209E17} (VnetAnpr Class) - http://service.chinavnet.com/zx/VNetInterface/VNetForSP/VnetPlugin.CAB
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl Object) - https://password.qq.com/download/qqedit.cab
O16 - DPF: {F138084D-84D7-48CD-BEA8-04772457516E} (VqqSpeedDlProxy Class) - http://59.36.97.38/jsxz/vqqsdl1009.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1B24C8A6-25DC-4008-AA3E-DE9D7E28942B}: NameServer = 218.6.200.139 61.139.2.69
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O23 - Service: Human Interface Device Access (HidServ) -  - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\Rising\Rav\CCenter.exe"
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\Rising\Rav\Ravmond.exe"
O23 - Service: User Privilege Service (usprserv) - Microsoft Corporation - C:\WINDOWS\system32\svchost.exe -k netsvcs
gototop
 

看我以前写的一篇“如何对付电信强制性弹出广告"
  http://www10.tianya.cn/New/PublicForum/Content.asp?idWriter=7099602&Key=730542922&strItem=it&idArticle=354009&flag=1
  
  还有一点,一定要到10000投诉,不要去找什么故障申告,那里面都是些垃圾,什么都不懂,直接拨10000号按5,告诉他们你要投诉,不要被他们骗了,他们都会说这是病毒,不是他们做的,你坚持,说自己机器是新装的,然后他们就会说你装个上网助手,还会说它会自动关闭就不影响你使用(这些话我都会背了,反正就是抵赖,能抵一步就是一步),你再抗议,说这是强迫性的,总之你一定要让他们向上面反映和记录,这东西只能靠海水投诉攻势才有用


不相信?你的ADSL账号是ls3270309 ,对不对?你觉得谁能知道你的ADSL账号名称?
gototop
 

挖靠 
你怎么知道我的ADSL帐号
强悍

那我上面说的那个网页是干什么的啊,查IP说是成都的ADSL

不过  motol你还真强悍
gototop
 

强烈鄙视电信

我按照motol 后面说的本地安全策略的做了,不过糊里糊涂的
 
不知弄对没有

不过好像这段时间也没有弹了

还有我后来用的腾讯的TT了,好像它有那个网站的屏蔽
我就把它屏蔽了
还有那个Windows优化大师有网站免疫
我也把那个网站免疫了
希望不要再出现了
我整郁闷了
gototop
 

http://forum.ikaka.com/topic.asp?board=28&artid=8105899
下载HijackThis...把日志帖上来..
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT