我觉得最近电脑速度一直下降,而且怪事很多,后来又是信使服务什么的,现在,不知道怎么了。每次开机就弹出:
Explorer.exe 遇到问题需要关闭......这个对话框.把他关了,一会儿又弹出-----系统不能用了.所以我现在所幸不管他,直接上网来,可是过一会儿就会死机...
废话不说了,我用杀毒软件杀毒时发现了好多病毒而且都杀不掉(还有木马阿),我也不知哪个最主要了,还请高手们帮忙啊!!!
而且现在还经常弹出来一个[computer registry software advertisement...]的网页。。
**这是我用这里下载的软件扫出来的,不知能不能有用:
Logfile of HijackThis v1.99.1
Scan saved at 18:01:55, on 2005-8-1
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Explorer.exe
f:\windows\system32\dqdrmt.exe
F:\WINDOWS\System32\dwwin.exe
F:\KAV6\Kulansyn.EXE
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\WINDOWS\system32\rundll32.exe
F:\PROGRA~1\3721\assistse.exe
F:\Program Files\D-Tools\daemon.exe
F:\KAV6\KPopMon.exe
F:\WINDOWS\System32\symantecblows.exe
F:\KAV6\MailMon.EXE
F:\program files\180searchassistant\sac.exe
F:\Program Files\Media Access\MediaAccK.exe
F:\Program Files\Media Access\MediaAccess.exe
F:\WINDOWS\System32\msupdater.exe
F:\Program Files\ISTsvc\istsvc.exe
F:\WINDOWS\wqkvpn.exe
F:\Program Files\BullsEye Network\bin\bargains.exe
F:\KAV6\KAVPlus.EXE
F:\WINDOWS\System32\ctfmon.exe
F:\Program Files\Messenger\msmsgs.exe
F:\KAV6\KAVSvc.EXE
F:\WINDOWS\System32\svchost.exe
F:\Program Files\WIBUKEY\Server\WkSvW32.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Sandai Technologies Inc\Thunder\Thunder.exe
F:\Program Files\Sandai Technologies Inc\Thunder\MediaIssue\Issue.exe
F:\DOCUME~1\ADMINI~2\LOCALS~1\Temp\Rar$EX00.016\HijackThis.exe
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe F:\WINDOWS\Nail.exe
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - F:\WINDOWS\downlo~1\CnsHook.dll
O4 - HKLM\..\Run: [KAVRun] F:\KAV6\KAVRun.EXE
O4 - HKLM\..\Run: [Kulansyn] F:\KAV6\Kulansyn.EXE
O4 - HKLM\..\Run: [iDuba Personal FireWall] F:\KAV6\KAVPFW.EXE
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [helper.dll] F:\WINDOWS\system32\rundll32.exe F:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [assistse] "F:\PROGRA~1\3721\assistse.exe"
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe F:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [DAEMON Tools-2052] "F:\Program Files\D-Tools\daemon.exe" -lang 2052
O4 - HKLM\..\Run: [Symantec Autoscan] symantecblows.exe
O4 - HKLM\..\Run: [sac] f:\program files\180searchassistant\sac.exe
O4 - HKLM\..\Run: [Media Access] F:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [Microsoft Windows Updater] msupdater.exe
O4 - HKLM\..\Run: [ho9Hkb2BY] F:\WINDOWS\wqkvpn.exe
O4 - HKLM\..\Run: [BullsEye Network] F:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\Run: [bkizdu] f:\windows\system32\dqdrmt.exe r
O4 - HKLM\..\Run: [wfurotqf] F:\WINDOWS\wfurotqf.exe
O4 - HKLM\..\Run: [IST Service] F:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [checkrun] F:\windows\system32\elitehai32.exe
O4 - HKLM\..\RunServices: [Symantec Autoscan] symantecblows.exe
O4 - HKLM\..\RunServices: [Microsoft Windows Updater] msupdater.exe
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Symantec Autoscan] symantecblows.exe
O4 - HKCU\..\RunServices: [Symantec Autoscan] symantecblows.exe
O8 - Extra context menu item: !搜一搜 - res://F:\WINDOWS\downlo~1\CnsMinEx.dll/1003
O8 - Extra context menu item: &使用迅雷下载 - F:\Program Files\Sandai Technologies Inc\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - F:\Program Files\Sandai Technologies Inc\Thunder\getAllurl.htm
O8 - Extra context menu item: 使用网际快车下载 - F:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - F:\Program Files\FlashGet\jc_all.htm
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm (file missing)
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O11 - Options group: [!CNS] 网络实名
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1118624973656
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {99410CDE-6F16-42ce-9D49-3807F78F0287} (ClientInstaller Class) - http://www.180searchassistant.com/180saax.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5BDB8028-F205-4579-9F9B-4A62EABEEEB1}: NameServer = 202.106.46.151 202.106.0.20
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - F:\WINDOWS\System32\mshtml.dll
O18 - Protocol: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - F:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - C:\POWERW~1\XDictExB.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - F:\WINDOWS\System32\msvidctl.dll
O18 - Protocol: emucn - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - F:\WINDOWS\System32\mshtml.dll
O18 - Protocol: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - F:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - F:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - F:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - F:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - F:\WINDOWS\system32\urlmon.dll
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - F:\WINDOWS\System32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - F:\WINDOWS\System32\mshtml.dll
O18 - Protocol: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - F:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - F:\WINDOWS\System32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - F:\WINDOWS\System32\inetcomm.dll
O18 - Protocol: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - F:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - F:\WINDOWS\System32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - F:\WINDOWS\System32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - F:\WINDOWS\System32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - F:\WINDOWS\System32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - F:\WINDOWS\System32\mshtml.dll
O18 - Protocol: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - F:\WINDOWS\System32\msdxm.ocx
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - F:\WINDOWS\System32\wiascr.dll
O20 - Winlogon Notify: igfxcui - F:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Kingsoft AntiVirus Service (KAVSvc) - kingsoft Antivirus - F:\KAV6\KAVSvc.EXE
O23 - Service: Professional Version (Professional) - Unknown owner - F:\WINDOWS\System32\windos.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Srv32 - Unknown owner - F:\WINDOWS\system32\srv32.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - F:\WINDOWS\svcproc.exe
O23 - Service: WIBU-KEY Server (WkSvW32) - WIBU-SYSTEMS AG - F:\Program Files\WIBUKEY\Server\WkSvW32.exe