1   1  /  1  页   跳转

我的天啊`谁来救救我

我的天啊`谁来救救我

只要一连上网`电脑就会自动下载一些垃圾软件`还会自动安装`广告左一个又一个`还会死机`还会自动播放视频文件(一个钟转着数着数)下面是日志`朋友们帮我看看
2006-08-05,09:17:31

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional  (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [Microsoft Corporation]
    <MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>  [Microsoft Corporation]
    <swg><C:\Program Files\Google\GoogleToolbarNotifier\1.0.711.1664\GoogleToolbarNotifier.exe>  [Google Inc.]
    <91cast><>  []
    <svc><C:\WINDOWS\svchost.exe>  []
    <msnnt><C:\WINDOWS\Updated.exe>  []
    <MyShares><c:\program Files\忆多多\MyShares.exe /tray>  [北京亿多多信息技术有限公司]
    <NetCounter><c:\Program Files\NetCounter\NetCount.exe>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
    <run><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  []
    <Synchronization Manager><; %SystemRoot%\system32\mobsync.exe /logon>  []
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <iTunesHelper><C:\Program Files\iTunes\iTunesHelper.exe>  [Apple Computer, Inc.]
    <BalaLive><>  []
    <BalaAutoDown><E:\Program Files\BaLa\bin\GetAutoDown.exe>  []
    <LetsCool><C:\Program Files\LetsCool\LetsCool.exe>  []
    <iebaru><C:\WINDOWS\System32\101228u.exe>  []
    <sysmini><C:\WINDOWS\system32\sysmini.exe>  []
    <bgoomain.exe><C:\PROGRA~1\baigoo\bgoomain.exe>  [BGoo]
    <spoolsv><C:\WINDOWS\System32\spoolsv\spoolsv.exe -printer>  [广州傲讯信息科技有限公司]
    <Desktop><C:\WINDOWS\System32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll>  []
    <YOKAssiant><Rundll32.exe C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll,YOKAssiant>  [www.YOK.com]
    <91cast><>  []
    <svc><C:\WINDOWS\svchost.exe>  []
    <CdnCtr><C:\Program Files\CNNIC\Cdn\cdnup.exe>  []
    <MSService_v1.0><C:\WINDOWS\system\realsched.exe>  []
    <MiniPPGou.exe><C:\Program Files\MiniPPGou\MiniPPGou.exe>  []
    <winlass><C:\Program Files\Outlook Express\winlass.exe>  [ ]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\System32\userinit.exe,C:\WINDOWS\System32\mouser.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><KB75976M.LOG>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <DVDBurn><C:\WINDOWS\Downloaded Program Files\AfxEdit.dll>  []
    <Vision><C:\PROGRA~1\MMSASS~1\Mmsass~1.dll>  []
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><>  []

==================================
启动文件夹
服务
[InstallDriver Table Manager / IDriverT]
  <C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe><Macrovision Corporation>
[IMAPI CD-Burning COM Service / ImapiService]
  <C:\WINDOWS\System32\imapi.exe><Microsoft Corporation>
[iPod 服务 / iPodService]
  <C:\Documents and Settings\苏雄专用\桌面\bin\iPodService.exe><Apple Computer, Inc.>
[IpServicer / IpServicer]
  <><N/A>
[Macromedia Licensing Service / Macromedia Licensing Service]
  <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>

==================================
浏览器加载项
[internet explorer helper]
  {02C9B9AB-6372-46C5-B356-773FAF3B6B1E} <C:\WINDOWS\fonts\msshapi.dll, >
[MonitorURL Class]
  {08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, >
[Shockwave Flash Object]
  {14A21378-5BB1-4BC4-95D5-5D3F51527F6F} <C:\WINDOWS\system32\smflash.ocx, Macromedia, Inc.>
[MyIEHelper Class]
  {16A770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4711.dll, Microsoft Corporation>
[Adobe-Plugins Manager]
  {2AFA7CEC-26D9-4256-AF57-497A13180BA5} <C:\WINDOWS\System32\Agm.dll, AdoBeSoft Co.>
[DwaVyvsw Class]
  {4A744F5A-F0AA-D23B-0EE7-DA77472D188D} <C:\WINDOWS\DOWNLO~1\zchzysbi.dll, awwbpsoft>
[CdnForIE Class]
  {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[MMSAssist BHO]
  {6671A431-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[stdup]
  {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} <C:\WINDOWS\System32\stdup.dll, MStdup Co Ltd.>
[超级兔子上网精灵]
  {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <C:\DOCUME~1\苏雄专用\桌面\游戏\新建文~1\MagicSet\haokanbar.dll, Xiang Feng Technology>
[YOK超级搜索]
  {75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688} <C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll, www.YOK.com>
[BandIE Class]
  {77FEF28E-EB96-44FF-B511-3185DEA48697} <C:\Progra~1\Baidu\bar\BaiDuBar.dll, Baidu.com, Inc.>
[Status Class]
  {7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} <C:\Program Files\baigoo\BGooBHO.dll, >
[Mini PPGou BHO]
  {92FB5F8F-8254-4978-9C50-03D9B0405062} <C:\PROGRA~1\MINIPP~1\MINIPP~1.DLL, N/A>
[WinSC Class]
  {9ACEEE31-1440-471B-AA46-72B061FE7D61} <C:\WINDOWS\system32\WinSC32.dll, N/A>
[Internet_Explorer_Service]
  {9E1E1371-9D8F-4421-81B9-F8D2E1773A59} <C:\WINDOWS\system32\HelperService.dll, N/A>
[estAliveObj Class]
  {A2B7A0F0-B697-4A71-8D91-43443F57D7BB} <C:\WINDOWS\estAlive.dll, Eastday Corporation>
[Webacc Class]
  {CAC068F3-A608-406B-8581-458788A67694} <C:\WINDOWS\System32\svchost.dll, >
[DuiSo.com Search]
  {E2218499-2FD4-4EED-A94A-7F0B9C6E300E} <C:\WINDOWS\system32\Inte32.dll, N/A>
[Letscool System Helper]
  {F0C15012-7DBD-4068-95A2-0A82DB03AC35} <C:\WINDOWS\System32\CoolBho.dll, LETSCOOL Network Technology>
[WMHlprObj Class]
  {F5824EFB-728A-4726-A5A5-85A68B20EDC3} <C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll, CNNIC>
[CdnForIE Class]
  {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[MMSAssistMenu]
  {6671A433-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[酷热影音]
  {7D73FF86-05F1-39ed-C850-A423120EC338} <www.kuree.com/index.htm?id=00011001, N/A>
[YOK超级搜索]
  {F869BB38-FFEF-4589-B986-610B7AD0ADA2} <http://www.yok.com, N/A>
[超级兔子上网精灵]
  {43869BB3-22FD-4F15-9B46-238106BA2F4E} <C:\DOCUME~1\苏雄专用\桌面\游戏\新建文~1\MagicSet\haokanbar.dll, Xiang Feng Technology>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <, N/A>
[江民杀毒工具栏]
  {B5A34A93-D538-43A7-8371-864CB6148D12} <, N/A>
[系统标准按钮(&E)]
  {6B2455FD-3669-4555-8DF8-69FD5BC846F8} <C:\WINDOWS\system32\SystemToolbar.dll, N/A>
[YOK超级搜索]
  {F869BB38-FFEF-4589-B986-610B7AD0ADA2} <C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll, www.YOK.com>
[IE标准栏]
  {954F618B-0DEC-4D1A-9317-E0FC96F87865} <C:\WINDOWS\system32\amstreamxb1.dll, >
[百度超级搜霸]
  {B580CF65-E151-49C3-B73F-70B13FCA8E86} <C:\Progra~1\Baidu\bar\BaiDuBar.dll, Baidu.com, Inc.>
[Yahoo! 相册轻松上载工具 Class]
  {0150EB11-5FB4-4D9E-85EA-0F155705227E} <C:\WINDOWS\Downloaded Program Files\YDropperCN.dll, Yahoo! Inc.>
[&Google Search]
  <res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html, N/A>
[&使用迅雷下载]
  <D:\迅雷5\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <D:\迅雷5\Program\GetAllUrl.htm, N/A>
[&使用迷你屁屁狗[PPGou]加速下载]
  <C:\Program Files\MiniPPGou\geturl.htm, N/A>
[>>彩信发送<<]
  <res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm, N/A>
[YOK超级搜索]
  <C:\Program Files\YOK.com\SuperSearch\yoksch.htm, N/A>
[上传到QQ网络硬盘]
  <D:\新建文件夹\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
  <D:\新建文件夹\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\新建文件夹\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\新建文件夹\SendMMS.htm, N/A>
[百度-搜索MP3]
  <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUMP3.HTM, N/A>
[百度-搜索图片]
  <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUIMG.HTM, N/A>
[百度-搜索新闻]
  <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUNEWS.HTM, N/A>
[百度-搜索歌词]
  <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDULYRIC.HTM, N/A>
[百度-搜索网页]
  <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUSEARCH.HTM, N/A>
[百度-搜索贴吧]
  <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUPOST.HTM, N/A>
[百度-词典搜索]
  <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDU_DIC.HTM, N/A>
[访问通用网址]
  <C:\Program Files\CNNIC\Cdn\cnnic.htm, N/A>
最后编辑2006-08-05 09:35:33
分享到:
gototop
 

正在运行的进程
[PID: 432][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 472][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 496][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
[PID: 548][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
[PID: 560][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
[PID: 756][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 872][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 992][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
[PID: 1032][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
[PID: 1156][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.0 (XPClient.010817-1148)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll]  <Windows (R) 2000 DDK provider><5.00.2195.1620>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 1320][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2600.0000 (xpclient.010817-1148)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\WINDOWS\System32\msicn\msibm.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [C:\WINDOWS\Downloaded Program Files\swflash.dll]  <N/A><N/A>
    [C:\PROGRA~1\MMSASS~1\Mmsass~1.dll]  <><1, 2, 0, 3>
    [C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll]  <www.YOK.com><2.0.1.7>
    [C:\WINDOWS\System32\msicn\plugins\bse.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\fonts\msshapi.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\System32\svchost.dll]  <><1, 0, 0, 1>
[PID: 1328][C:\WINDOWS\System32\mouser.exe]  <N/A><N/A>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 1764][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3510>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
[PID: 1772][C:\Program Files\iTunes\iTunesHelper.exe]  <Apple Computer, Inc.><4.7.1.30>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\Program Files\iTunes\iTunesHelper.Resources\zh_CN.lproj\iTunesHelperLocalized.DLL]  <Apple Computer, Inc.><4.7.1.30>
    [C:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.DLL]  <Apple Computer, Inc.><4.7.1.30>
[PID: 1796][C:\Program Files\LetsCool\LetsCool.exe]  <N/A><3, 0, 0, 1>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
[PID: 1908][C:\WINDOWS\system32\sysmini.exe]  <N/A><1.00>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
[PID: 1940][C:\PROGRA~1\baigoo\bgoomain.exe]  <BGoo><1, 0, 0, 1006>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [C:\PROGRA~1\baigoo\bgooex.dll]  <><1, 0, 0, 1007>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
gototop
 

[PID: 340][C:\Program Files\CNNIC\Cdn\cdnup.exe]  <><2, 4, 0, 4>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  <CNNIC><2, 0, 0, 2>
    [C:\Program Files\CNNIC\Cdn\cdntdns.dll]  <CNNIC><2, 2, 0, 3>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  <CNNIC><2, 4, 0, 1>
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  <CNNIC><2, 2, 0, 1>
[PID: 356][C:\WINDOWS\system\realsched.exe]  <N/A><N/A>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
[PID: 388][C:\Program Files\MiniPPGou\MiniPPGou.exe]  <N/A><N/A>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 448][C:\Program Files\Outlook Express\winlass.exe]  < ><5.01.2715>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
[PID: 976][C:\WINDOWS\System32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [C:\WINDOWS\System32\msicn\msibm.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
[PID: 796][C:\Program Files\Google\GoogleToolbarNotifier\1.0.711.1664\GoogleToolbarNotifier.exe]  <Google Inc.><1, 0, 711, 1664>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [C:\Program Files\Google\GoogleToolbarNotifier\1.0.711.1664\swg.dll]  <Google Inc.><1, 0, 711, 1664>
    [C:\Program Files\Google\GoogleToolbarNotifier\1.0.711.1664\res_en.dll]  <Google Inc.><1, 0, 711, 1664>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
[PID: 1596][C:\WINDOWS\System32\conime.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
[PID: 256][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [c:\windows\system32\winmide32.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 396][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
[PID: 1928][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [c:\windows\system32\tasklist.dll]  <N/A><N/A>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 1964][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
[PID: 916][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
[PID: 1112][C:\WINDOWS\System32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
[PID: 1268][C:\WINDOWS\System32\VKTServ.exe]  <Microsoft Corporation><1.1.2600.2180>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
[PID: 1592][C:\WINDOWS\System32\taskmgr.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
[PID: 2540][C:\Documents and Settings\苏雄专用\桌面\bin\iPodService.exe]  <Apple Computer, Inc.><4.7.1.30>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\Documents and Settings\苏雄专用\桌面\bin\iPodService.Resources\zh_CN.lproj\iPodServiceLocalized.DLL]  <Apple Computer, Inc.><4.7.1.30>
    [C:\Documents and Settings\苏雄专用\桌面\bin\iPodService.Resources\iPodService.DLL]  <Apple Computer, Inc.><4.7.1.30>
[PID: 2976][C:\WINDOWS\svchost.exe]  <N/A><N/A>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
[PID: 3432][D:\新建文件夹\TTraveler.exe]  <腾讯公司><3.0.0.250>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [D:\新建文件夹\Plugins\QQFloatBar\QQFloatBar4TT2.dll]  <腾讯公司><1, 1, 0, 5>
    [D:\新建文件夹\Plugins\TWeather\TWeather.dll]  <><1, 0, 0, 3>
    [D:\新建文件夹\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
    [C:\WINDOWS\System32\msicn\msibm.dll]  <广州傲讯信息科技有限公司><2, 0, 0, 1>
[PID: 2288][C:\WINDOWS\System32\rundll32.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\WINDOWS\Downloaded Program Files\NProtect.dll]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
[PID: 3764][C:\Documents and Settings\苏雄专用\桌面\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
[PID: 1816][C:\Documents and Settings\苏雄专用\setup.exe]  <N/A><N/A>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
[PID: 3512][C:\WINDOWS\System32\msiexec.exe]  <Microsoft Corporation><2.0.2600.0>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
[PID: 476][C:\Documents and Settings\苏雄专用\plugin.exe]  <N/A><1.00>
    [C:\WINDOWS\KB75976M.LOG]  <N/A><N/A>
    [C:\PROGRA~1\baigoo\bgoohk.dll]  < ><1, 0, 0, 1007>
    [C:\Documents and Settings\苏雄专用\UpdatePlugIn.dll]  <N/A><N/A>
    [C:\WINDOWS\System32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\System32\wshcon32.dll]  <><4, 0, 0, 0>
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

打开SRE 启动项目 注册表 删除
<91cast><> []
<svc><C:\WINDOWS\svchost.exe> []
<msnnt><C:\WINDOWS\Updated.exe> []
<iebaru><C:\WINDOWS\System32\101228u.exe> []
<sysmini><C:\WINDOWS\system32\sysmini.exe> []
<91cast><> []
<svc><C:\WINDOWS\svchost.exe> []
<MSService_v1.0><C:\WINDOWS\system\realsched.exe> []
<winlass><C:\Program Files\Outlook Express\winlass.exe> [ ]
<AppInit_DLLs><KB75976M.LOG> []
删除
C:\WINDOWS\svchost.exe
C:\WINDOWS\Updated.exe
C:\WINDOWS\System32\101228u.exe
C:\WINDOWS\system32\sysmini.exe
C:\WINDOWS\system\realsched.exe
C:\Program Files\Outlook Express\winlass.exe
C:\WINDOWS\KB75976M.LOG

<Userinit>编辑 改成C:\WINDOWS\System32\userinit.exe,
删除
C:\WINDOWS\System32\mouser.exe

http://www.pctutu.com/srmsdown.asp
下载超级兔子..用超级兔子清理王卸载流氓软件...(安全模式...)
gototop
 

谢谢mopery`!!!!!!!!!!!!!!!!!!!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT