瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 运行任何exe程序都会伴随运行某个后台程序导致电脑运行很慢

12   1  /  2  页   跳转

运行任何exe程序都会伴随运行某个后台程序导致电脑运行很慢

运行任何exe程序都会伴随运行某个后台程序导致电脑运行很慢

运行任何exe程序包括打开“我的电脑”、显示桌面、打开注册表、打开任务管理器等时在任务管理器里面都会有一个恶意后台程序伴随运行且打开多个进程,然后又自动关闭。我试着找到并删除这个程序,但每次删除后又会有新的恶意程序产生,而且程序名称也随之改变

请问这是什么病毒,如何解决?谢谢!!
最后编辑2006-08-28 16:06:10
分享到:
gototop
 

这么快,我试试,谢谢啦!!!
gototop
 

注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
    <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <vptray><C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe>  [Symantec Corporation]
    <stup.exe><C:\PROGRA~1\TENCENT\Adplus\stup.exe>  [Tencent]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{2BE9590F-9BBF-4441-A622-A9C9551C0FE3}><C:\WINDOWS\system32\Nmpqnt.dll>  []
    <{A23BDD85-4CC4-46A9-BFE2-52DFC9097DA9}><C:\WINDOWS\system32\Wktog.dll>  []
    <{4C267D48-B74A-42AA-ADAE-701F7ED8E501}><C:\WINDOWS\system32\Jgwe.dll>  []
    <{64990A39-3E2B-4D8C-B0FF-BCE98A060AA3}><C:\WINDOWS\system32\Wwmkgv.dll>  []
    <{1533AEEB-83BC-47CC-8062-1931AA568221}><C:\WINDOWS\system32\Phem.dll>  []
    <{D25AC861-36FB-499D-AB2B-D500EE678C6E}><C:\WINDOWS\system32\Tovs.dll>  []
    <{388129CC-BA73-46A4-B49D-2D53490AAE3F}><C:\WINDOWS\system32\Gpstm.dll>  []
    <{A923996F-9E57-4812-B50A-12D4AD10061B}><C:\WINDOWS\system32\Cicxs.dll>  []
    <{C0204E9B-1B4C-4F23-87EE-27DEF84F43AD}><C:\WINDOWS\system32\Batyzu.dll>  []
    <{CE7CDCF7-BCB7-4A7B-AC67-346DCCB8CC94}><C:\WINDOWS\system32\Uvbx.dll>  []
    <{C1C02431-9613-41DC-AF42-DFD6DFE0FB10}><C:\WINDOWS\system32\Tgcdh.dll>  []
    <{4E1967C0-3326-4142-9288-8700CB83EF23}><C:\WINDOWS\system32\Kpxk.dll>  []
    <{2C19BF14-DBE4-4D37-8097-063BB26EEBAD}><C:\WINDOWS\system32\Xsptde.dll>  []
    <{C74995CD-67A2-49F1-B12D-DD95684EF85F}><C:\WINDOWS\system32\Vcrghf.dll>  []
    <{F46D30D4-7150-4FB7-AD47-B4D3CDA46C14}><C:\WINDOWS\system32\Fbrnsj.dll>  []
    <{1082FC95-2BC0-4241-AFE1-FA79067E3439}><C:\WINDOWS\system32\Lfkdg.dll>  []
    <{63513020-8748-4C10-A804-483C15444CA4}><C:\WINDOWS\system32\Uuzt.dll>  []
    <{8B63F305-9FFE-4441-B22A-1B8E51BDFB88}><C:\WINDOWS\system32\Tbgc.dll>  []
    <{80A9C49A-A5F1-49F4-A756-E6A97944241C}><C:\WINDOWS\system32\Piou.dll>  []
    <{23327C42-0D14-48EE-8CA1-EBCF9A0D728E}><C:\WINDOWS\system32\Hzir.dll>  []
    <{D4A783E0-E9C5-448F-BECE-341BA633F1AC}><C:\WINDOWS\system32\Sxhjhu.dll>  []
    <{6F8EDB03-96ED-4E77-99FA-9F6DC1AC9773}><C:\WINDOWS\system32\Bwpd.dll>  []
    <{520CAF3F-FF0C-4654-89F2-E1D4A9C09902}><C:\WINDOWS\system32\Adxoo.dll>  []
    <{2D5D2EB2-7BFE-46BA-9DD2-8805AE2B463A}><C:\WINDOWS\system32\Gcxo.dll>  []
    <{9C51A9A2-858B-47CA-BE02-3DB667828199}><C:\WINDOWS\system32\Jvxwmq.dll>  []
    <{851DDA46-68DB-4016-99C9-FBA87286B013}><C:\WINDOWS\system32\Aigz.dll>  []
    <{C67C8E7A-B3BE-4EDA-AA4C-C19A6DEC8787}><C:\WINDOWS\system32\Prpfv.dll>  []
    <{02299199-FE9B-4F7B-8B81-18D912DA00CE}><C:\WINDOWS\system32\Seta.dll>  []
    <{1F1DB2C5-B4EF-43AA-842D-9C108A6E9A10}><C:\WINDOWS\system32\Dqotn.dll>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
    <WinlogonNotify: NavLogon><C:\WINDOWS\system32\NavLogon.dll>  []
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\system32\MARINE~1.SCR>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <iTunesHelper><; "C:\Program Files\iTunes\iTunesHelper.exe">  [Apple Computer, Inc.]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    <Load><; C:\windows\system32\wincfgs.exe>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <QuickTime Task><; "C:\Program Files\QuickTime\qttask.exe" -atboottime>  [Apple Computer, Inc.]
    <stup.exe><; C:\PROGRA~1\TENCENT\Adplus\stup.exe>  [Tencent]
    <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot>  [RealNetworks, Inc.]
gototop
 

启动文件夹
[routeadd-200409]
  <C:\Documents and Settings\All Users.WINDOWS\「开始」菜单\程序\启动\routeadd-200409.bat><N>
[腾讯QQ]
  <C:\Documents and Settings\qiuzhaojun\「开始」菜单\程序\启动\腾讯QQ.lnk><N>

==================================
服务
[DefWatch / DefWatch]
  <C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe><Symantec Corporation>
[iPodService / iPodService]
  <C:\Program Files\iPod\bin\iPodService.exe><Apple Computer, Inc.>
[Symantec AntiVirus Client / Norton AntiVirus Server]
  <C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe><Symantec Corporation>
[NVIDIA Driver Helper Service / NVSvc]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
gototop
 

浏览器加载项
[]
  {02299199-FE9B-4F7B-8B81-18D912DA00CE} <C:\WINDOWS\system32\Seta.dll, N/A>
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Tencent Browser Helper]
  {0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\Adplus\SSAddr.dll, Tencent>
[]
  {1082FC95-2BC0-4241-AFE1-FA79067E3439} <C:\WINDOWS\system32\Lfkdg.dll, N/A>
[]
  {1533AEEB-83BC-47CC-8062-1931AA568221} <C:\WINDOWS\system32\Phem.dll, N/A>
[]
  {1F1DB2C5-B4EF-43AA-842D-9C108A6E9A10} <C:\WINDOWS\system32\Dqotn.dll, N/A>
[]
  {23327C42-0D14-48EE-8CA1-EBCF9A0D728E} <C:\WINDOWS\system32\Hzir.dll, N/A>
[]
  {2BE9590F-9BBF-4441-A622-A9C9551C0FE3} <C:\WINDOWS\system32\Nmpqnt.dll, N/A>
[]
  {2C19BF14-DBE4-4D37-8097-063BB26EEBAD} <C:\WINDOWS\system32\Xsptde.dll, N/A>
[]
  {2D5D2EB2-7BFE-46BA-9DD2-8805AE2B463A} <C:\WINDOWS\system32\Gcxo.dll, N/A>
[]
  {388129CC-BA73-46A4-B49D-2D53490AAE3F} <C:\WINDOWS\system32\Gpstm.dll, N/A>
[]
  {4C267D48-B74A-42AA-ADAE-701F7ED8E501} <C:\WINDOWS\system32\Jgwe.dll, N/A>
[]
  {4E1967C0-3326-4142-9288-8700CB83EF23} <C:\WINDOWS\system32\Kpxk.dll, N/A>
[]
  {520CAF3F-FF0C-4654-89F2-E1D4A9C09902} <C:\WINDOWS\system32\Adxoo.dll, N/A>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <D:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[]
  {63513020-8748-4C10-A804-483C15444CA4} <C:\WINDOWS\system32\Uuzt.dll, N/A>
[]
  {64990A39-3E2B-4D8C-B0FF-BCE98A060AA3} <C:\WINDOWS\system32\Wwmkgv.dll, N/A>
[]
  {669751ED-D558-49AE-B01A-3B374CC7910E} <C:\WINDOWS\system32\ssup.dll, TENCENT>
[]
  {6F8EDB03-96ED-4E77-99FA-9F6DC1AC9773} <C:\WINDOWS\system32\Bwpd.dll, N/A>
[BandIE Class]
  {77FEF28E-EB96-44FF-B511-3185DEA48697} <C:\PROGRA~1\baidu\bar\baidubar.dll, N/A>
[]
  {80A9C49A-A5F1-49F4-A756-E6A97944241C} <C:\WINDOWS\system32\Piou.dll, N/A>
[]
  {851DDA46-68DB-4016-99C9-FBA87286B013} <C:\WINDOWS\system32\Aigz.dll, N/A>
[]
  {8B63F305-9FFE-4441-B22A-1B8E51BDFB88} <C:\WINDOWS\system32\Tbgc.dll, N/A>
[]
  {9C51A9A2-858B-47CA-BE02-3DB667828199} <C:\WINDOWS\system32\Jvxwmq.dll, N/A>
[]
  {A23BDD85-4CC4-46A9-BFE2-52DFC9097DA9} <C:\WINDOWS\system32\Wktog.dll, N/A>
[]
  {A923996F-9E57-4812-B50A-12D4AD10061B} <C:\WINDOWS\system32\Cicxs.dll, N/A>
[AcroIEToolbarHelper Class]
  {AE7CD045-E861-484f-8273-0445EE161910} <C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll, N/A>
[]
  {C0204E9B-1B4C-4F23-87EE-27DEF84F43AD} <C:\WINDOWS\system32\Batyzu.dll, N/A>
[]
  {C1C02431-9613-41DC-AF42-DFD6DFE0FB10} <C:\WINDOWS\system32\Tgcdh.dll, N/A>
[]
  {C67C8E7A-B3BE-4EDA-AA4C-C19A6DEC8787} <C:\WINDOWS\system32\Prpfv.dll, N/A>
[]
  {C74995CD-67A2-49F1-B12D-DD95684EF85F} <C:\WINDOWS\system32\Vcrghf.dll, N/A>
[]
  {CE7CDCF7-BCB7-4A7B-AC67-346DCCB8CC94} <C:\WINDOWS\system32\Uvbx.dll, N/A>
[]
  {D25AC861-36FB-499D-AB2B-D500EE678C6E} <C:\WINDOWS\system32\Tovs.dll, N/A>
[]
  {D4A783E0-E9C5-448F-BECE-341BA633F1AC} <C:\WINDOWS\system32\Sxhjhu.dll, N/A>
[]
  {F46D30D4-7150-4FB7-AD47-B4D3CDA46C14} <C:\WINDOWS\system32\Fbrnsj.dll, N/A>
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Adobe PDF]
  {47833539-D0C5-4125-9FA8-0819E2EAAC93} <C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll, N/A>
[百度超级搜霸]
  {B580CF65-E151-49C3-B73F-70B13FCA8E86} <C:\PROGRA~1\baidu\bar\baidubar.dll, N/A>
[VqqSpeedDlProxy Class]
  {F138084D-84D7-48CD-BEA8-04772457516E} <C:\WINDOWS\vqqsdl.dll, Tencent>
[]
  {02299199-FE9B-4F7B-8B81-18D912DA00CE} <C:\WINDOWS\system32\Seta.dll, N/A>
[QuickTime Object]
  {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} <C:\Program Files\QuickTime\QTPlugin.ocx, Apple Computer, Inc.>
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Tencent Browser Helper]
  {0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\Adplus\SSAddr.dll, Tencent>
[]
  {1082FC95-2BC0-4241-AFE1-FA79067E3439} <C:\WINDOWS\system32\Lfkdg.dll, N/A>
[]
  {1533AEEB-83BC-47CC-8062-1931AA568221} <C:\WINDOWS\system32\Phem.dll, N/A>
[]
  {1F1DB2C5-B4EF-43AA-842D-9C108A6E9A10} <C:\WINDOWS\system32\Dqotn.dll, N/A>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[]
  {23327C42-0D14-48EE-8CA1-EBCF9A0D728E} <C:\WINDOWS\system32\Hzir.dll, N/A>
[]
  {2BE9590F-9BBF-4441-A622-A9C9551C0FE3} <C:\WINDOWS\system32\Nmpqnt.dll, N/A>
[]
  {2C19BF14-DBE4-4D37-8097-063BB26EEBAD} <C:\WINDOWS\system32\Xsptde.dll, N/A>
[]
  {2D5D2EB2-7BFE-46BA-9DD2-8805AE2B463A} <C:\WINDOWS\system32\Gcxo.dll, N/A>
[]
  {388129CC-BA73-46A4-B49D-2D53490AAE3F} <C:\WINDOWS\system32\Gpstm.dll, N/A>
[HHCtrl Object]
  {41B23C28-488E-4E5C-ACE2-BB0BBABE99E8} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[Adobe PDF]
  {47833539-D0C5-4125-9FA8-0819E2EAAC93} <C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll, N/A>
[]
  {4C267D48-B74A-42AA-ADAE-701F7ED8E501} <C:\WINDOWS\system32\Jgwe.dll, N/A>
[]
  {4E1967C0-3326-4142-9288-8700CB83EF23} <C:\WINDOWS\system32\Kpxk.dll, N/A>
[]
  {520CAF3F-FF0C-4654-89F2-E1D4A9C09902} <C:\WINDOWS\system32\Adxoo.dll, N/A>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <D:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[]
  {63513020-8748-4C10-A804-483C15444CA4} <C:\WINDOWS\system32\Uuzt.dll, N/A>
[]
  {64990A39-3E2B-4D8C-B0FF-BCE98A060AA3} <C:\WINDOWS\system32\Wwmkgv.dll, N/A>
[]
  {669751ED-D558-49AE-B01A-3B374CC7910E} <C:\WINDOWS\system32\ssup.dll, TENCENT>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[]
  {6F8EDB03-96ED-4E77-99FA-9F6DC1AC9773} <C:\WINDOWS\system32\Bwpd.dll, N/A>
[BandIE Class]
  {77FEF28E-EB96-44FF-B511-3185DEA48697} <C:\PROGRA~1\baidu\bar\baidubar.dll, N/A>
[]
  {80A9C49A-A5F1-49F4-A756-E6A97944241C} <C:\WINDOWS\system32\Piou.dll, N/A>
[]
  {851DDA46-68DB-4016-99C9-FBA87286B013} <C:\WINDOWS\system32\Aigz.dll, N/A>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[]
  {8B63F305-9FFE-4441-B22A-1B8E51BDFB88} <C:\WINDOWS\system32\Tbgc.dll, N/A>
[]
  {9C51A9A2-858B-47CA-BE02-3DB667828199} <C:\WINDOWS\system32\Jvxwmq.dll, N/A>
[]
  {A23BDD85-4CC4-46A9-BFE2-52DFC9097DA9} <C:\WINDOWS\system32\Wktog.dll, N/A>
[]
  {A923996F-9E57-4812-B50A-12D4AD10061B} <C:\WINDOWS\system32\Cicxs.dll, N/A>
[AcroIEToolbarHelper Class]
  {AE7CD045-E861-484F-8273-0445EE161910} <C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll, N/A>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[百度超级搜霸]
  {B580CF65-E151-49C3-B73F-70B13FCA8E86} <C:\PROGRA~1\baidu\bar\baidubar.dll, N/A>
[]
  {C0204E9B-1B4C-4F23-87EE-27DEF84F43AD} <C:\WINDOWS\system32\Batyzu.dll, N/A>
[]
  {C1C02431-9613-41DC-AF42-DFD6DFE0FB10} <C:\WINDOWS\system32\Tgcdh.dll, N/A>
[]
  {C67C8E7A-B3BE-4EDA-AA4C-C19A6DEC8787} <C:\WINDOWS\system32\Prpfv.dll, N/A>
[]
  {C74995CD-67A2-49F1-B12D-DD95684EF85F} <C:\WINDOWS\system32\Vcrghf.dll, N/A>
[VIDEO__X_MS_WMV Moniker Class]
  {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[]
  {CE7CDCF7-BCB7-4A7B-AC67-346DCCB8CC94} <C:\WINDOWS\system32\Uvbx.dll, N/A>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\System32\rmoc3260.dll, RealNetworks>
[]
  {D25AC861-36FB-499D-AB2B-D500EE678C6E} <C:\WINDOWS\system32\Tovs.dll, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\flash.ocx, Macromedia, Inc.>
[]
  {D4A783E0-E9C5-448F-BECE-341BA633F1AC} <C:\WINDOWS\system32\Sxhjhu.dll, N/A>
[]
  {F46D30D4-7150-4FB7-AD47-B4D3CDA46C14} <C:\WINDOWS\system32\Fbrnsj.dll, N/A>
[上传到QQ网络硬盘]
  <D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <C:\Program Files\JetCar-v1.65\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\JetCar-v1.65\jc_all.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
[百度--MP3搜索]
  <RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUMP3.HTM, N/A>
[百度--图片搜索]
  <RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUIMG.HTM, N/A>
[百度--新闻搜索]
  <RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUNEWS.HTM, N/A>
[百度--歌词搜索]
  <RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDULYRIC.HTM, N/A>
[百度--网页搜索]
  <RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUSEARCH.HTM, N/A>
[百度--词典搜索]
  <RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_DIC.HTM, N/A>
[百度--贴吧搜索]
  <RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUPOST.HTM, N/A>
gototop
 

正在运行的进程
[PID: 604][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 660][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 684][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\NavLogon.dll]  <N/A><N/A>
[PID: 728][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 740][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 908][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 976][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1064][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1252][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1288][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1488][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\AdobePDF.dll]  <Adobe Systems Incorporated.><6.0.000>
    [C:\Program Files\Adobe\Acrobat 6.0\Distillr\AdistRes.CHS]  <N/A><N/A>
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll]  <Windows (R) 2000 DDK provider><5.00.2195.1620>
[PID: 1660][C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe]  <Symantec Corporation><8.1.0.821>
[PID: 1720][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  <Microsoft Corporation><7.00.9466>
[PID: 704][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\Nmpqnt.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Wktog.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Jgwe.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Wwmkgv.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Phem.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Tovs.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Gpstm.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Cicxs.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Batyzu.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Uvbx.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Tgcdh.dll]  <N/A><N/A>
    [C:\WINDOWS\downlo~1\Bgyp.dll]  <Tencent><4, 2, 2, 21>
    [C:\WINDOWS\system32\Kpxk.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Xsptde.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Vcrghf.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Fbrnsj.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Lfkdg.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Uuzt.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Tbgc.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Piou.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Hzir.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Sxhjhu.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Bwpd.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Adxoo.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Gcxo.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Jvxwmq.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Aigz.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Prpfv.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Seta.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Dqotn.dll]  <N/A><N/A>
    [C:\WINDOWS\downlo~1\Zgscnu.dll]  <Tencent><4, 2, 2, 21>
    [C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.chs]  <Adobe Systems Inc.><1.0.0.2003051500>
    [C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll]  <Adobe Systems Incorporated><6.0.0.2003051500>
    [C:\WINDOWS\system32\ssup.dll]  <TENCENT><4, 2, 2, 20>
    [C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll]  <Adobe Systems Inc.><1.0.0.2003051500>
    [C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll]  <Symantec Corporation><8.1.0.821>
[PID: 1364][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2308][C:\windows\system32\wincfgs.exe]  <N/A><N/A>
    [C:\WINDOWS\downlo~1\Bgyp.dll]  <Tencent><4, 2, 2, 21>
[PID: 2548][C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe]  <Symantec Corporation><8.1.0.821>
    [C:\WINDOWS\downlo~1\Bgyp.dll]  <Tencent><4, 2, 2, 21>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Cliscan.dll]  <Symantec Corporation><8.1.0.821>
    [C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVNTUTL.DLL]  <Symantec/Peter Norton Group><1, 0, 0, 1>
[PID: 448][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\downlo~1\Bgyp.dll]  <Tencent><4, 2, 2, 21>
[PID: 3028][C:\Program Files\Messenger\msmsgs.exe]  <Microsoft Corporation><4.7.3001>
    [C:\WINDOWS\downlo~1\Bgyp.dll]  <Tencent><4, 2, 2, 21>
[PID: 2408][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\downlo~1\Bgyp.dll]  <Tencent><4, 2, 2, 21>
[PID: 7600][D:\LC\流量计费软件mike2.0\count+.exe]  <麦克工作室><2.00>
    [C:\WINDOWS\downlo~1\Bgyp.dll]  <Tencent><4, 2, 2, 21>
[PID: 12128][D:\Program Files\Maxthon\Max.exe]  <Maxthon International Ltd.><1, 5, 3, 18>
    [D:\Program Files\Maxthon\maxzlib.dll]  < ><1, 0, 0, 2>
    [C:\WINDOWS\downlo~1\Bgyp.dll]  <Tencent><4, 2, 2, 21>
    [D:\Program Files\Maxthon\Services\RealTime\real_time.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\Nmpqnt.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Wktog.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Jgwe.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Wwmkgv.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Phem.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Tovs.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Gpstm.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Cicxs.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Batyzu.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Uvbx.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Tgcdh.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Kpxk.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Xsptde.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Vcrghf.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Fbrnsj.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Lfkdg.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Uuzt.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Tbgc.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Piou.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Hzir.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Sxhjhu.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Bwpd.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Adxoo.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Gcxo.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Jvxwmq.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Aigz.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Prpfv.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Seta.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Dqotn.dll]  <N/A><N/A>
[PID: 11648][C:\WINDOWS\system32\taskmgr.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\downlo~1\Bgyp.dll]  <Tencent><4, 2, 2, 21>
[PID: 10348][C:\Program Files\WinRAR\WinRAR.exe]  <N/A><N/A>
    [C:\WINDOWS\downlo~1\Bgyp.dll]  <Tencent><4, 2, 2, 21>
[PID: 11072][C:\Documents and Settings\qiuzhaojun\桌面\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\WINDOWS\downlo~1\Bgyp.dll]  <Tencent><4, 2, 2, 21>
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

急!!在线等。
还有拜托老大告诉一下怎么看这些日志报告。总不能每次都来麻烦老大吧
gototop
 

老大,启动文件夹里面的routeadd-200409.bat是正常程序没有问题的
gototop
 

routeadd-200409.bat是一个网址阻断的东西,由于我们学校网络管制,上国外或某些网要收费的,所以用这个东东将收费网IP阻断。

还有您说的“删除上述启动项”是不是指在SRE软件里面的启动项目还是指运行"msconfig"后的启动项目。我试过msconfig没有影响
还有“删除各个启动项指向的文件”是什么意思?
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT