找回密码
 立即注册
搜索
查看: 179|回复: 19

我被http://www.8749.com/强行了!

[复制链接]

29

主题

251

回帖

369

积分

中级会员

积分
369
发表于 2007-7-20 23:09:38 | 显示全部楼层 |阅读模式
我的首页被这个网站强行了,用了传统的修改注册表等N多办法都没有改变!(注册表中没有发现这个网址)

就是这个X东东:http://www.8749.com/

27

主题

729

回帖

1000

积分

金牌会员

积分
1000
发表于 2007-7-21 00:06:51 | 显示全部楼层
节哀吧~~
呵呵呵
Frank
回复

使用道具 举报

30

主题

890

回帖

1218

积分

金牌会员

积分
1218
发表于 2007-7-21 00:42:24 | 显示全部楼层
这好像是满难解决的一个绑架网站
回复

使用道具 举报

97

主题

1621

回帖

2382

积分

论坛元老

大片欣赏家

积分
2382
发表于 2007-7-21 08:17:59 | 显示全部楼层
360试过没有?
回复

使用道具 举报

86

主题

2142

回帖

3152

积分

荣誉版主

积分
3152
发表于 2007-7-21 12:06:26 | 显示全部楼层
Windows清理助手

解决不掉的话,贴SREng的log上来,详见我签名
回复

使用道具 举报

18

主题

464

回帖

629

积分

高级会员

积分
629
发表于 2007-7-21 12:33:50 | 显示全部楼层
sreng貌似可以把后缀改成com的
回复

使用道具 举报

1

主题

487

回帖

660

积分

高级会员

积分
660
发表于 2007-7-21 13:12:06 | 显示全部楼层
超级兔子试过没?
回复

使用道具 举报

29

主题

251

回帖

369

积分

中级会员

积分
369
 楼主| 发表于 2007-7-21 20:01:10 | 显示全部楼层

回复 #5 softworm 的帖子

清理助手没能解决,SRENGPS报告如下:



  1. 2007-07-21,19:56:15

  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs ([url]http://www.KZTechs.com[/url])

  4. Windows XP Professional Service Pack 1 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描


  14. 启动项目
  15. 注册表
  16. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <BigDogPath><C:\WINDOWS\VM_STI.EXE ZSMC USB PC Camera>  [N/A]
  18.     <ssMgr_ccb><C:\Program Files\StarSec\ssMgr_ccb.exe -r>  []
  19.     <SecExpert><C:\Program Files\Terminator\SecMain.exe Hide>  [N/A]
  20.     <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
  21.     <MSConfig><C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto>  [(Verified)Microsoft Windows XP Publisher]
  22.     <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
  23. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  24.     <shell><Explorer.exe>  [(Verified)Microsoft Windows XP Publisher]
  25.     <Userinit><C:\WINDOWS\System32\Userinit.exe,>  [(Verified)Microsoft Windows XP Publisher]
  26. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  27.     <AppInit_DLLs><>  [N/A]
  28. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  29.     <UIHost><%SystemRoot%\system32\logonui.exe>  [(Verified)Microsoft Windows XP Publisher]
  30. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  31.     <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
  32.     <{D7B21266-AA85-44b8-B516-3B1A69827400}><C:\PROGRA~1\CNRN\RNEvent.dll>  [(Verified)"INTER CHINA NETWORK SOFTWARE (BEIJING) CO., LTD."]
  33.     <{4A65498A-7653-9801-1647-987114AB7F44}><C:\WINDOWS\System32\zxdpri.dll>  [N/A]
  34. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  35.     <rpn><C:\WINDOWS\System32\MOQ.dll>  [N/A]
  36. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  37.     <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
  38. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  39.     <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
  40. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  41.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
  42. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2E47CE25-E258-CE25-8BD1-479C0258AD13}]
  43.     <N/A><C:\WINDOWS\System32\FamDiy.exe>  [N/A]
  44. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{306D6C21-C1B6-4629-986C-E59E1875B8AF}]
  45.     <N/A><"C:\WINDOWS\System32\rundll32.exe" "C:\Program Files\Messenger\msgsc.dll",ShowIconsUser>  [(Verified)Microsoft Windows XP Publisher]
  46. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  47.     <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
  48. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
  49.     <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows XP Publisher]
  50. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
  51.     <Windows Messenger><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.Install.PerUser>  [(Verified)Microsoft Windows XP Publisher]
  52. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6A202101-A04D-21cf-65CD-31FF5FE1CF20}]
  53.     <N/A><C:\WINDOWS\System32\mydata.exe>  [N/A]
  54. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  55.     <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub>  []
  56. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  57.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
  58. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{81716107-A10D-11cf-64CD-11115FE1CF41}]
  59.     <N/A><C:\WINDOWS\System32\nwizzhuxians.exe>  [N/A]
  60. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  61.     <1r8r8kq1><; C:\DOCUME~1\dududu\LOCALS~1\Temp\c0nime.exe>  [N/A]
  62. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  63.     <AddrPlus3><; C:\PROGRA~1\TENCENT\AddrPlus\Runner.exe C:\PROGRA~1\TENCENT\AddrPlus\QAHook.dll Rundll32>  [N/A]
  64.     <AVPSrv><; C:\WINDOWS\AVPSrv.exe>  [N/A]
  65.     <BigDog303><; C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)>  [N/A]
  66.     <BigDogPath><; C:\WINDOWS\VM_STI.EXE ZSMC USB PC Camera>  [N/A]
  67.     <cmdbcs><; C:\WINDOWS\cmdbcs.exe>  [N/A]
  68.     <fysa><; C:\DOCUME~1\dududu\LOCALS~1\Temp\fyso.exe>  [N/A]
  69.     <helper.dll><; C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>  [N/A]
  70. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  71.     <hvgfy><; C:\DOCUME~1\dududu\LOCALS~1\Temp\iexpl0re.exe>  [N/A]
  72. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  73.     <intranet><; >  [N/A]
  74.     <javavm><; C:\WINDOWS\javavm.exe>  [N/A]
  75.     <jtsa><; C:\DOCUME~1\dududu\LOCALS~1\Temp\jtso.exe>  [N/A]
  76.     <KernelFaultCheck><; %systemroot%\system32\dumprep 0 -k>  [N/A]
  77.     <Kvsc3><; C:\WINDOWS\Kvsc3.exe>  [N/A]
  78.     <mhsa><; C:\DOCUME~1\dududu\LOCALS~1\Temp\mhso.exe>  [N/A]
  79.     <mppds><; C:\WINDOWS\mppds.exe>  [N/A]
  80.     <mppdss><; C:\WINDOWS\mppdss.exe>  [N/A]
  81.     <ms><; >  [N/A]
  82.     <msccrt><; C:\WINDOWS\msccrt.exe>  [N/A]
  83.     <mscct><; C:\WINDOWS\mscct.exe>  [N/A]
  84.     <MsIMMs32><; C:\WINDOWS\MsIMMs32.exe>  [N/A]
  85. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  86.     <MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>  [Microsoft Corporation]
  87.     <MsnMsgr><; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>  [(Verified)Microsoft Corporation]
  88. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  89.     <nwizqjsj><; C:\WINDOWS\System32\nwizqjsj.exe>  [N/A]
  90.     <nwiztlbb><; C:\WINDOWS\System32\nwiztlbb.exe>  [N/A]
  91.     <qjsa><; C:\DOCUME~1\dududu\LOCALS~1\Temp\qjso.exe>  [N/A]
  92.     <qqsa><; C:\DOCUME~1\dududu\LOCALS~1\Temp\qqso.exe>  [N/A]
  93.     <runeip><; C:\Program Files\Rising\AntiSpyware\runiep.exe>  [N/A]
  94.     <rxsa><; C:\DOCUME~1\dududu\LOCALS~1\Temp\rxso.exe>  [N/A]
  95.     <stup.exe><; C:\PROGRA~1\TENCENT\Adplus\stup.exe>  [N/A]
  96.     <testrun><; C:\WINDOWS\testexe.exe>  [N/A]
  97.     <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
  98.     <upxdnd><; C:\WINDOWS\upxdnd.exe>  [N/A]
  99.     <WangWang><; "C:\Program Files\淘宝网\淘宝旺旺\WangWang.EXE">  [N/A]
  100.     <WebThunder><; C:\Program Files\Thunder Network\WebThunder\WebThunder.exe>  [深圳市迅雷网络技术有限公司]
  101.     <wgsa><; C:\DOCUME~1\dududu\LOCALS~1\Temp\wgso.exe>  [N/A]
  102.     <winform><; C:\WINDOWS\winform.exe>  [N/A]
  103.     <wlsa><; C:\DOCUME~1\dududu\LOCALS~1\Temp\wlso.exe>  [N/A]
  104.     <wmsa><; C:\DOCUME~1\dududu\LOCALS~1\Temp\wmso.exe>  [N/A]
  105.     <wosa><; C:\DOCUME~1\dududu\LOCALS~1\Temp\woso.exe>  [N/A]
  106. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  107.     <Yahoo! Pager><; "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet>  [N/A]
  108. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  109.     <ztsa><; C:\DOCUME~1\dududu\LOCALS~1\Temp\ztso.exe>  [N/A]
  110. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  111.     <zvefssxvlee><; C:\DOCUME~1\dududu\LOCALS~1\Temp\c0nime.exe>  [N/A]

  112. ==================================
  113. 启动文件夹
  114. [Microsoft Office]
  115.   <C:\Documents and Settings\All Users.WINDOWS\「开始」菜单\程序\启动\Microsoft Office.lnk --> C:\PROGRA~1\MICROS~2\Office10\OSA.EXE [Microsoft Corporation]><N>

  116. ==================================
  117. 服务
  118. [DF068A2C / DF068A2C][Stopped/Auto Start]
  119.   <2 - 系统找不到指定的文件。
  120. ><N/A>
  121. [Human Interface Device Access / HidServ][Stopped/Disabled]
  122.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  123. [PlugServerD / PlugServer][Running/Auto Start]
  124.   <C:\Program Files\StarSec\PlugServer.exe><GDChina>
  125. [Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  126.   <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
  127. [Rising Personal Firewall Service / RfwService][Running/Auto Start]
  128.   <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
  129. [Rising Process Communication Center / RsCCenter][Running/Auto Start]
  130.   <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
  131. [Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  132.   <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
  133. [Spoooler / Spoooler][Stopped/Auto Start]
  134.   <C:\Program Files\Common Files\Spoooler><N/A>
  135. [Updata Server. / Updata Server.][Stopped/Auto Start]
  136.   <C:\Program Files\Common Files\Update><N/A>
  137. [Messenger 共享文件夹 USN 杂志阅读器服务 / usnjsvc][Stopped/Manual Start]
  138.   <C:\Program Files\MSN Messenger\usnsvc.exe><Microsoft Corporation>
  139. [Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
  140.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\System32\mspmsnsv.dll><Microsoft Corporation>

  141. ==================================
  142. 驱动程序
  143. [360TimeProt / 360TimeProt][Stopped/Boot Start]
  144.   <\SystemRoot\System32\drivers\360TimeProt.sys><N/A>
  145. [Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
  146.   <system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
  147. [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  148.   <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
  149. [awhqwwd / awhqwwd][Stopped/Manual Start]
  150.   <2 - 系统找不到指定的文件。
  151. ><N/A>
  152. [Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  153.   <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
  154. [CNRNDV / CNRNDV][Running/Boot Start]
  155.   <\SystemRoot\System32\drivers\CNRNDV.sys><国风因特软件(北京)有限公司>
  156. [ExpScaner / ExpScaner][Running/Auto Start]
  157.   <\??\C:\PROGRAM FILES\RISING\RAV\ExpScan.sys><>
  158. [HookCont / HookCont][Running/Auto Start]
  159.   <\??\C:\PROGRAM FILES\RISING\RAV\HOOKCONT.sys><Rising>
  160. [HookReg / HookReg][Running/Auto Start]
  161.   <\??\C:\PROGRAM FILES\RISING\RAV\HookReg.sys><>
  162. [HookSys / HookSys][Running/Auto Start]
  163.   <\??\C:\PROGRAM FILES\RISING\RAV\HookSys.sys><Rising>
  164. [HookUrl / HookUrl][Running/Auto Start]
  165.   <\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
  166. [ialm / ialm][Running/Manual Start]
  167.   <System32\DRIVERS\ialmnt5.sys><Intel Corporation>
  168. [IdeBusDr / IdeBusDr][Running/Boot Start]
  169.   <\SystemRoot\System32\DRIVERS\IdeBusDr.sys><Intel Corporation>
  170. [Intel(R) Ultra ATA Controller / IdeChnDr][Running/Boot Start]
  171.   <\SystemRoot\System32\DRIVERS\IdeChnDr.sys><Intel Corporation>
  172. [Klif / Klif][Running/System Start]
  173.   <System32\drivers\klif.sys><Kaspersky Labs>
  174. [Klmc / Klmc][Running/System Start]
  175.   <System32\drivers\klmc.sys><Kaspersky Lab>
  176. [MEMSCAN / MEMSCAN][Running/Auto Start]
  177.   <\??\C:\PROGRAM FILES\RISING\RAV\MEMSCAN.sys><瑞星软件有限公司>
  178. [mProcRs / mProcRs][Running/Auto Start]
  179.   <\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
  180. [Netgroup Packet Filter / NPF][Stopped/Manual Start]
  181.   <system32\drivers\npf.sys><CACE Technologies>
  182. [npkcrypt / npkcrypt][Running/Auto Start]
  183.   <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
  184. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  185.   <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  186. [RsFwDrv / RsFwDrv][Running/Auto Start]
  187.   <\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
  188. [RsNTGDI / RsNTGDI][Running/Boot Start]
  189.   <\SystemRoot\System32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
  190. [RSPPSYS / RSPPSYS][Running/Auto Start]
  191.   <\??\C:\PROGRAM FILES\RISING\RAV\RSPPSYS.sys><Rising>
  192. [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  193.   <System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
  194. [Secdrv / Secdrv][Stopped/Manual Start]
  195.   <System32\DRIVERS\secdrv.sys><N/A>
  196. [vmfilter303 / vmfilter303][Stopped/Manual Start]
  197.   <system32\drivers\vmfilter303.sys><Vimicro Corporation>
  198. [WINIO / WINIO][Stopped/Manual Start]
  199.   <\??\F:\DRIVER\Audio\winio.sys><N/A>
  200. [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  201.   <System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
  202. [xBlock3 / xBlock3][Stopped/Manual Start]
  203.   <\??\C:\WINDOWS\System32\Drivers\xBlock3.sys><N/A>
  204. [xProc / xProc][Stopped/System Start]
  205.   <\??\C:\WINDOWS\System32\Drivers\xProc.sys><N/A>
  206. [ZSMC USB PC Camera / ZSMC301b][Running/Manual Start]
  207.   <System32\Drivers\usbVM31b.sys><VM>
  208. [Teclast 303 PC Camera(VIMICRO ZC0301PLH) / ZSMC303][Stopped/Manual Start]
  209.   <System32\Drivers\usbVM303.sys><N/A>
  210. [Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/Manual Start]
  211.   <system32\drivers\ialmsbw.sys><Intel Corporation>
  212. [Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start]
  213.   <system32\drivers\ialmkchw.sys><Intel Corporation>
  214. [R2A / R2A][Stopped/Disabled]
  215.   <\??\C:\WINDOWS\System32a2.sys><N/A>

  216. ==================================
  217. 浏览器加载项
  218. [WebThunder Browser Helper]
  219.   {00000AAA-A363-466E-BEF5-9BB68697AA7F} <C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_Now.dll, Thunder Networking Technologies,LTD>
  220. [Adobe PDF Reader Link Helper]
  221.   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
  222. [Windows Live Sign-in Helper]
  223.   {9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
  224. []
  225.   {D7B21266-AA85-44b8-B516-3B1A69827400} <C:\PROGRA~1\CNRN\RNEvent.dll, 国风因特软件(北京)有限公司>
  226. []
  227.   {110F6354-E9E3-4f8c-95DD-8487ED86C73D} <[url]http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean[/url], N/A>
  228. [名品 折扣]
  229.   {30778C27-54C7-437e-946A-F04CBB8C460F} <[url]http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138[/url],140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/mall/pro.php?allyesPara=816, N/A>
  230. [Yahoo 3.5G 电邮]
  231.   {4C4A96EA-D26D-4ab1-9D7C-BEA7D3312B6F} <[url]http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail[/url], N/A>
  232. []
  233.   {4D985980-695A-4b42-8B11-34D8D3385676} <[url]http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair[/url], N/A>
  234. [雅虎 WIDGET]
  235.   {6C32C266-E0C3-447c-B1A1-650640D550D0} <[url]http://cn.widget.yahoo.com/index.htm?source=Cns[/url], N/A>
  236. [情景 聊天]
  237.   {7035F492-7EAE-4213-A159-7C4E1E216C12} <[url]http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg[/url], N/A>
  238. [雅虎 助手]
  239.   {BF69897E-F9B4-4c1a-9D81-59822096081F} <[url]http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist[/url], N/A>
  240. [电台(&R)]
  241.   {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
  242. [WebThunder Class]
  243.   {03507A1A-E0C5-4404-AA26-205385C0892D} <, N/A>
  244. [Vod Class]
  245.   {2EEDA47E-8D5C-4d7e-B4B6-E16E19218555} <C:\Program Files\Thunder Network\WebThunder\DownAndPlay\DapPlayer1.1.0.46.dll, XunLei>
  246. [WangWangObj Class]
  247.   {6E213FC7-DD5A-4115-B7E6-D4C7838C361E} <C:\Program Files\淘宝网\淘宝旺旺\WangWangX3.dll, 淘宝(中国)软件有限公司>
  248. []
  249.   {E24B9E23-58CF-4938-B383-49C6D744D728} <C:\PROGRA~1\CNRN\CNRN.dll, 国风因特软件(北京)有限公司>
  250. [上传到QQ网络硬盘]
  251.   <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
  252. [使用Web迅雷下载]
  253.   <C:\Program Files\Thunder Network\WebThunder\GetUrl.htm, N/A>
  254. [使用Web迅雷下载全部链接]
  255.   <C:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm, N/A>
  256. [导出到 Microsoft Excel(&x)]
  257.   <res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000, N/A>
  258. [添加到QQ自定义面板]
  259.   <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
  260. [添加到QQ表情]
  261.   <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
  262. [用QQ彩信发送该图片]
  263.   <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>

  264. ==================================
  265. 正在运行的进程
  266. [PID: 456 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
  267. [PID: 532 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  268. [PID: 556 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
  269.     [C:\WINDOWS\System32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  270.     [C:\WINDOWS\System32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  271. [PID: 600 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  272. [PID: 612 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
  273. [PID: 772 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  274.     [C:\WINDOWS\System32\mscomm.dll]  [N/A, ]
  275. [PID: 840 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  276.     [C:\WINDOWS\System32\mscomm.dll]  [N/A, ]
  277. [PID: 928 / NETWORK SERVICE][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  278. [PID: 948 / LOCAL SERVICE][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  279.     [C:\WINDOWS\System32\mscomm.dll]  [N/A, ]
  280. [PID: 1300 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
  281.     [C:\WINDOWS\system32\QVPPMSV.DLL]  [CASIO COMPUTER CO.,LTD., 1.0.0]
  282.     [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll]  [Windows (R) 2000 DDK provider, 5.00.2195.1620]
  283. [PID: 1404 / SYSTEM][C:\PROGRAM FILES\RISING\RAV\RavStub.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
  284.     [C:\PROGRAM FILES\RISING\RAV\RsCommX.dll]  [rising, 18, 0, 0, 1]
  285.     [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
  286. [PID: 1552 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
  287.     [C:\WINDOWS\System32\mscomm.dll]  [N/A, ]
  288. [PID: 1640 / SYSTEM][C:\Program Files\StarSec\PlugServer.exe]  [GDChina, 1, 1, 0, 2]
  289.     [C:\Program Files\StarSec\plugins\plugstarkey220.dll]  [GDChina, 1, 1, 0, 1]
  290. [PID: 1920 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  291. [PID: 1928 / dududu][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
  292.     [C:\WINDOWS\System32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  293.     [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
  294.     [C:\PROGRA~1\CNRN\RNEvent.dll]  [国风因特软件(北京)有限公司, 2.0.1.1016]
  295.     [C:\PROGRA~1\CNRN\CNRN.dll]  [国风因特软件(北京)有限公司, 2.0.3.1024]
  296.     [C:\PROGRA~1\CNRN\RNHelper.dll]  [国风因特软件(北京)有限公司, 2.0.0.1015]
  297.     [C:\WINDOWS\System32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  298.     [C:\PROGRA~1\WINDOW~2\wmpband.dll]  [Microsoft Corporation, 9.00.00.2980]
  299.     [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
  300.     [C:\WINDOWS\System32\igfxpph.dll]  [Intel Corporation, 3,0,0,2104]
  301.     [C:\WINDOWS\System32\hccutils.DLL]  [Intel Corporation, 3,0,0,2104]
  302.     [C:\WINDOWS\System32\igfxres.dll]  [Intel Corporation, 3,0,0,2104]
  303.     [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
  304.     [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
  305.     [C:\PROGRA~1\CNRN\RNLive.dll]  [国风因特软件(北京)有限公司, 2.0.1.1019]
  306.     [C:\PROGRA~1\CNRN\RNAxtF.dll]  [国风因特软件(北京)有限公司, 2.0.0.1015]
  307.     [C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 2, 10]
  308.     [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.9.2006121800]
  309.     [C:\WINDOWS\System32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  310. [PID: 1948 / SYSTEM][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
  311.     [C:\WINDOWS\System32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  312.     [C:\WINDOWS\System32\mscomm.dll]  [N/A, ]
  313. [PID: 2036 / SYSTEM][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
  314.     [C:\WINDOWS\System32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  315.     [C:\WINDOWS\System32\mscomm.dll]  [N/A, ]
  316. [PID: 144 / dududu][c:\program files\rising\rfw\RfwMain.exe]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 72]
  317.     [c:\program files\rising\rfw\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
  318.     [c:\program files\rising\rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
  319.     [c:\program files\rising\rfw\RfwCtrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
  320.     [c:\program files\rising\rfw\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
  321.     [c:\program files\rising\rfw\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
  322.     [C:\PROGRA~1\CNRN\RNHelper.dll]  [国风因特软件(北京)有限公司, 2.0.0.1015]
  323.     [C:\PROGRA~1\CNRN\CNRN.dll]  [国风因特软件(北京)有限公司, 2.0.3.1024]
  324.     [c:\program files\rising\rfw\PSAPI.DLL]  [Microsoft Corporation, 4.00]
  325. [PID: 820 / dududu][C:\PROGRA~1\CNRN\RNMain.exe]  [国风因特软件(北京)有限公司, 2.0.1.1016]
  326.     [C:\PROGRA~1\CNRN\CNRN.dll]  [国风因特软件(北京)有限公司, 2.0.3.1024]
  327.     [C:\PROGRA~1\CNRN\RNHelper.dll]  [国风因特软件(北京)有限公司, 2.0.0.1015]
  328.     [C:\PROGRA~1\CNRN\RNList.dll]  [国风因特软件(北京)有限公司, 2.0.2.1019]
  329.     [C:\WINDOWS\System32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  330. [PID: 864 / dududu][C:\PROGRA~1\CNRN\RNMain.exe]  [国风因特软件(北京)有限公司, 2.0.1.1016]
  331.     [C:\PROGRA~1\CNRN\RNHelper.dll]  [国风因特软件(北京)有限公司, 2.0.0.1015]
  332.     [C:\WINDOWS\System32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  333.     [C:\WINDOWS\System32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  334.     [C:\PROGRA~1\CNRN\RNLive.dll]  [国风因特软件(北京)有限公司, 2.0.1.1019]
  335.     [C:\PROGRA~1\CNRN\RNAxtF.dll]  [国风因特软件(北京)有限公司, 2.0.0.1015]
  336.     [C:\PROGRA~1\CNRN\RNNtfy.dll]  [国风因特软件(北京)有限公司, 2.0.0.1015]
  337.     [C:\PROGRA~1\CNRN\CNRN.dll]  [国风因特软件(北京)有限公司, 2.0.3.1024]
  338.     [C:\WINDOWS\System32\mscomm.dll]  [N/A, ]
  339. [PID: 2008 / dududu][C:\WINDOWS\VM_STI.EXE]  [VM., 4.2.610.4]
  340.     [C:\PROGRA~1\CNRN\CNRN.dll]  [国风因特软件(北京)有限公司, 2.0.3.1024]
  341.     [C:\PROGRA~1\CNRN\RNHelper.dll]  [国风因特软件(北京)有限公司, 2.0.0.1015]
  342.     [C:\WINDOWS\System32\msdmo.dll]  [, ]
  343.     [C:\WINDOWS\System32\VM31bPrp.Ax]  [VM, 4.2.711.31]
  344. [PID: 336 / dududu][C:\Program Files\StarSec\ssMgr_ccb.exe]  [, 1, 0, 5, 1026]
  345.     [C:\WINDOWS\System32\SSP11_CCB.dll]  [GDChina, 1, 0, 0, 2]
  346.     [C:\PROGRA~1\CNRN\CNRN.dll]  [国风因特软件(北京)有限公司, 2.0.3.1024]
  347.     [C:\PROGRA~1\CNRN\RNHelper.dll]  [国风因特软件(北京)有限公司, 2.0.0.1015]
  348.     [C:\WINDOWS\System32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  349.     [C:\WINDOWS\System32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  350. [PID: 764 / dududu][C:\Program Files\arswp\ArSwp.exe]  [ArSwp.com, 2, 2, 3, 705]
  351.     [C:\PROGRA~1\CNRN\CNRN.dll]  [国风因特软件(北京)有限公司, 2.0.3.1024]
  352.     [C:\PROGRA~1\CNRN\RNHelper.dll]  [国风因特软件(北京)有限公司, 2.0.0.1015]
  353.     [C:\WINDOWS\System32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  354.     [C:\WINDOWS\System32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  355.     [C:\WINDOWS\System32\mscomm.dll]  [N/A, ]
  356.     [C:\Program Files\arswp\plugin\ArFix.dll]  [ArSwp.Com, 2, 2, 2, 0]
  357. [PID: 3948 / dududu][D:\工具\TheWorld2050\TheWorld_cn_2kxp\TheWorld.exe]  [Phoenix Studio, 2, 0, 5, 0]
  358.     [C:\PROGRA~1\CNRN\CNRN.dll]  [国风因特软件(北京)有限公司, 2.0.3.1024]
  359.     [C:\PROGRA~1\CNRN\RNHelper.dll]  [国风因特软件(北京)有限公司, 2.0.0.1015]
  360.     [C:\WINDOWS\System32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  361.     [C:\WINDOWS\System32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  362.     [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
  363.     [C:\WINDOWS\System32\mscomm.dll]  [N/A, ]
  364.     [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
  365. [PID: 3904 / dududu][C:\Program Files\WinRAR\WinRAR.exe]  [Alexander Roshal, 3.70]
  366.     [C:\PROGRA~1\CNRN\CNRN.dll]  [国风因特软件(北京)有限公司, 2.0.3.1024]
  367.     [C:\PROGRA~1\CNRN\RNHelper.dll]  [国风因特软件(北京)有限公司, 2.0.0.1015]
  368.     [C:\WINDOWS\System32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  369.     [C:\WINDOWS\System32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  370. [PID: 412 / dududu][C:\DOCUME~1\dududu\LOCALS~1\Temp\Rar$EX00.891\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
  371.     [C:\PROGRA~1\CNRN\CNRN.dll]  [国风因特软件(北京)有限公司, 2.0.3.1024]
  372.     [C:\PROGRA~1\CNRN\RNHelper.dll]  [国风因特软件(北京)有限公司, 2.0.0.1015]
  373.     [C:\WINDOWS\System32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  374.     [C:\WINDOWS\System32\upengine.dll]  [北京清华紫光软件股份有限公司, 3.0.0.3045]
  375.     [C:\DOCUME~1\dududu\LOCALS~1\Temp\Rar$EX00.891\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
  376.     [C:\WINDOWS\System32\mscomm.dll]  [N/A, ]

  377. ==================================
  378. 文件关联
  379. .TXT  Error. [C:\WINDOWS\NOTEPAD.EXE %1]
  380. .EXE  OK. ["%1" %*]
  381. .COM  OK. ["%1" %*]
  382. .PIF  OK. ["%1" %*]
  383. .REG  OK. [regedit.exe "%1"]
  384. .BAT  OK. ["%1" %*]
  385. .SCR  OK. ["%1" /S]
  386. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  387. .HLP  Error. [C:\WINDOWS\winhlp32.exe %1]
  388. .INI  Error. [C:\WINDOWS\NOTEPAD.EXE %1]
  389. .INF  Error. [C:\WINDOWS\NOTEPAD.EXE %1]
  390. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  391. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  392. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  393. ==================================
  394. Winsock 提供者
  395. MSAPI Tcpip [TCP/IP]
  396.     C:\WINDOWS\System32\mscomm.dll(, N/A)
  397. MSAPI Tcpip [UDP/IP]
  398.     C:\WINDOWS\System32\mscomm.dll(, N/A)

  399. ==================================
  400. Autorun.inf
  401. N/A

  402. ==================================
  403. HOSTS 文件
  404. 125.91.1.20 [url]www.37021.net[/url]
  405. 125.91.1.20 37021.net
  406. 125.91.1.20 5235.net
  407. 125.91.1.20 [url]www.5235.net[/url]

  408. ==================================
  409. 进程特权扫描
  410. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1640, C:\PROGRAM FILES\STARSEC\PLUGSERVER.EXE]
  411. 特殊特权被允许: SeDebugPrivilege [PID = 2008, C:\WINDOWS\VM_STI.EXE]
  412. 特殊特权被允许: SeLoadDriverPrivilege [PID = 2008, C:\WINDOWS\VM_STI.EXE]
  413. 特殊特权被允许: SeDebugPrivilege [PID = 336, C:\PROGRAM FILES\STARSEC\SSMGR_CCB.EXE]
  414. 特殊特权被允许: SeDebugPrivilege [PID = 764, C:\PROGRAM FILES\ARSWP\ARSWP.EXE]
  415. 特殊特权被允许: SeLoadDriverPrivilege [PID = 764, C:\PROGRAM FILES\ARSWP\ARSWP.EXE]
  416. 特殊特权被允许: SeDebugPrivilege [PID = 3948, D:\工具\THEWORLD2050\THEWORLD_CN_2KXP\THEWORLD.EXE]
  417. 特殊特权被允许: SeLoadDriverPrivilege [PID = 3948, D:\工具\THEWORLD2050\THEWORLD_CN_2KXP\THEWORLD.EXE]
  418. 特殊特权被允许: SeDebugPrivilege [PID = 3904, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
  419. 特殊特权被允许: SeLoadDriverPrivilege [PID = 3904, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]

  420. ==================================
  421. API HOOK
  422. RVA  错误: LoadLibraryA (危险等级: 高,  被下面模块所HOOK: \SystemRoot\System32\drivers\klif.sys)
  423. RVA  错误: LoadLibraryExA (危险等级: 高,  被下面模块所HOOK: \SystemRoot\System32\drivers\klif.sys)
  424. RVA  错误: LoadLibraryExW (危险等级: 高,  被下面模块所HOOK: \SystemRoot\System32\drivers\klif.sys)
  425. RVA  错误: LoadLibraryW (危险等级: 高,  被下面模块所HOOK: \SystemRoot\System32\drivers\klif.sys)

  426. ==================================
  427. 隐藏进程
  428. N/A

  429. ==================================


复制代码
回复

使用道具 举报

29

主题

251

回帖

369

积分

中级会员

积分
369
 楼主| 发表于 2007-7-21 20:15:11 | 显示全部楼层
刚才突然发现重启后,那个破主页网站没有了!谢谢SOFTworm斑竹!!!!
回复

使用道具 举报

59

主题

938

回帖

1366

积分

金牌会员

自说自话

积分
1366
发表于 2007-7-21 22:18:04 | 显示全部楼层
楼主的电脑系统也该修补了,我点进去这个垃圾站什么反应也没有啊。
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

Archiver|手机版|小黑屋|海浩社区

GMT+8, 2025-9-22 01:08 , Processed in 0.087442 second(s), 21 queries .

Powered by Discuz! X3.5

© 2001-2025 Discuz! Team.

快速回复 返回顶部 返回列表