首 页文章中心下载中心娱乐八卦本站论坛拜仁联盟球迷社区博客日志建站服务域名抢注繁體中文
设为首页
加入收藏
联系我们
E-mail:WebMaster#fcbu.com
载入中…
当前位置:站长天下 -> 电脑医院 -> 重发求助贴!让费心了.

重发求助贴!让费心了.


作者:TTXS(Fcbu.Com)   来源:互联网   发表时间:2006-08-23  
昨天晚上下网下载一个木马克星.结果出来了一堆垃圾软件.经验一列系的删除后.在每次起动的时候在右下角(也就是时间栏那里)会出现一个像蚂蚁一样的头像.显示的内容是你当前的网速提升了%......那烦啊.也不知道是什么东西.经过我用优化大师看了以后那个东西的名字:netaccelerate Microsoft基础应用程序!!!请大家帮帮我.这是什么啊.我非常怕是一个盗号木马.!
下面是日志:
启动项目
注册表
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run>
  <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows>
  <load><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
  <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
  <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
  <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
  <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
  <ggzeqt><RunDll32 "C:\WINDOWS\Downlo~1\ggzeqt.dll",Run>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
  <Desktop><C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
  <KAVPersonal50><"d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
  <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
  <searcher><C:\WINDOWS\System\msolesrv.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
  <netaccelerate><C:\WINDOWS\accdoofo.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
  <SearchNet_Up><"C:\Program Files\SearchNet\ServeUp.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
  <shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
  <Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows>
  <AppInit_DLLs><>
==================================
启动文件夹
[Microsoft Office>
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk><N>
==================================
服务
[kavsvc / kavsvc>
  <"d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe"><Kaspersky Lab>
[Macromedia Licensing Service / Macromedia Licensing Service>
  <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[Remote Log / Remote Log>
  <C:\WINDOWS\system32\ServeHost.exe><Beijing zhongsou online software> 接上贴:
==================================
浏览器加载项
[IE Address Browser Helper>
  {2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[IE Browser Helper>
  {3CE496D1-1746-41CD-9489-3C0B93DF10E2} <C:\WINDOWS\Downlo~1\wudxub76.dll, 中搜在线软件有限公司>
[QQ>
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class>
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\Program Files\Tencent\QQ\QQIEHelper.dll, N/A>
[Messenger>
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Shockwave Flash Object>
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[ActiveMovieControl Object>
  {05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[MonitorURL Class>
  {08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, N/A>
[实用搜索>
  {15ADF205-4C54-4CFE-AC88-1EA0BA6D06A0} <, N/A>
[Windows Media Player>
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document>
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[IE Address Browser Helper>
  {2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[BrowserHelper Class>
  {2D99E8F4-56B7-457B-9A92-61B5D247D263} <C:\WINDOWS\system32\WinDefendor.dll, TODO: <公司名>>
[IE Browser Helper>
  {3CE496D1-1746-41CD-9489-3C0B93DF10E2} <C:\WINDOWS\Downlo~1\wudxub76.dll, 中搜在线软件有限公司>
[HHCtrl Object>
  {41B23C28-488E-4E5C-ACE2-BB0BBABE99E8} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[QQBrowserHelperObject Class>
  {54EBD53A-9BC1-480B-966A-843A333CA162} <D:\Program Files\Tencent\QQ\QQIEHelper.dll, N/A>
[Shell Name Space>
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[NetAccelerate Class>
  {5673A7C0-95CC-4646-BB07-3BD71234CEF9} <C:\WINDOWS\system32\MicrosoftNet.dll, N/A>
[Windows Media Player>
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[MSHlper Class>
  {721E6521-4CAD-4A8D-A7F1-4E230B31EF19} <C:\WINDOWS\system32\MSHLP.DLL, >
[MediaComm Class>
  {7670648D-461B-42AF-BDFE-46D26AF5EFF2} <d:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin05.dll, Thunder Networking Technologies,LTD>
[CpapView Class>
  {77962960-536E-47EC-9DDB-52651519705F} <C:\WINDOWS\system32\cpap.dll, >
[Microsoft Web 浏览器>
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper>
  {889D2FEB-5411-4565-8998-1DD2C5261283} <d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[Microsoft Scriptlet Component>
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC>
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[>
  {B9E914B5-6B61-401F-A49F-9E84E547D3DD} <C:\WINDOWS\system32\leftup.dll, N/A>
[AUDIO__MP3 Moniker Class>
  {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control>
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[QuickBtn>
  {D1BB7CF4-4463-4E91-88D7-ECC3CE0A13B7} <C:\Program Files\CoolWebsite\QuickLink.dll, N/A>
[Shockwave Flash Object>
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[iehelper>
  {F651FCAA-F826-4922-8990-C6F99CC67AFC} <C:\WINDOWS\Win32ef.dll, N/A>
[&使用迅雷下载>
  <d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接>
  <d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘>
  <D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板>
  <D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情>
  <D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片>
  <D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 460>[\SystemRoot\System32\smss.exe>  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 516>[\??\C:\WINDOWS\system32\csrss.exe>  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 540>[\??\C:\WINDOWS\system32\winlogon.exe>  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 584>[C:\WINDOWS\system32\services.exe>  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 596>[C:\WINDOWS\system32\lsass.exe>  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 748>[C:\WINDOWS\system32\svchost.exe>  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 804>[C:\WINDOWS\system32\svchost.exe>  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 868>[C:\WINDOWS\System32\svchost.exe>  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 912>[C:\WINDOWS\system32\svchost.exe>  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1016>[C:\WINDOWS\system32\svchost.exe>  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1288>[C:\WINDOWS\Explorer.EXE>  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\SearchNet\SrvNet32.dll>  <中搜在线><1, 0, 2, 7>
[PID: 1320>[C:\WINDOWS\system32\spoolsv.exe>  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1452>[C:\Program Files\Common Files\Real\Update_OB\realsched.exe>  <RealNetworks, Inc.><0.1.0.3292>
[PID: 1500>[C:\WINDOWS\System\msolesrv.exe>  <MicroSoft Corporation><5. 0. 3700. 6690>
[PID: 1520>[C:\WINDOWS\accdoofo.exe>  <N/A><1, 0, 0, 1>
[PID: 1548>[C:\WINDOWS\system32\ctfmon.exe>  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1844>[C:\WINDOWS\system32\ServeHost.exe>  <Beijing zhongsou online software><1, 0, 3, 1>
[PID: 508>[C:\WINDOWS\System32\alg.exe>  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1208>[C:\Program Files\SearchNet\SearchNet.exe>  <Beijing zhongsou><1, 0, 3, 1>
    [C:\Program Files\SearchNet\SrvNet32.dll>  <中搜在线><1, 0, 2, 7>
[PID: 1240>[C:\WINDOWS\system32\wscntfy.exe>  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 976>[C:\WINDOWS\system32\wuauclt.exe>  <Microsoft Corporation><5.4.3790.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1084>[F:\新建文件夹 (2)\SREng.exe>  <Smallfrogs Studio><2.0.12.350>
    [C:\Program Files\SearchNet\SrvNet32.dll>  <中搜在线><1, 0, 2, 7>
==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1>
.EXE  OK. ["%1" %*>
.COM  OK. ["%1" %*>
.PIF  OK. ["%1" %*>
.REG  OK. [regedit.exe "%1">
.BAT  OK. ["%1" %*>
.SCR  OK. ["%1" /S>
.CHM  OK. ["C:\WINDOWS\hh.exe" %1>
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1>
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1>
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1>
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*>
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*>
.LNK  OK. [{00021401-0000-0000-C000-000000000046}> 启动项停止以下进程。
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
  <ggzeqt><RunDll32 "C:\WINDOWS\Downlo~1\ggzeqt.dll",Run>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
  <Desktop><C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
  <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
  <searcher><C:\WINDOWS\System\msolesrv.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
  <netaccelerate><C:\WINDOWS\accdoofo.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
  <SearchNet_Up><"C:\Program Files\SearchNet\ServeUp.exe">
浏览器加载项:需要删除。
[MonitorURL Class>
  {08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, N/A>
[IE Address Browser Helper>
  {2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[CpapView Class>
  {77962960-536E-47EC-9DDB-52651519705F} <C:\WINDOWS\system32\cpap.dll, >
[>
  {B9E914B5-6B61-401F-A49F-9E84E547D3DD} <C:\WINDOWS\system32\leftup.dll, N/A>
[iehelper>
  {F651FCAA-F826-4922-8990-C6F99CC67AFC} <C:\WINDOWS\Win32ef.dll, N/A>
正在运行的进程,关于中搜的都可以停止。或者在安全模式下清理。 我应该怎么删除或者停止呢 原帖由 skybule917 于 2006-6-24 13:31 发表
我应该怎么删除或者停止呢
开始,运行regedit,进入注册表编辑器
删除类似于以下路径的键值:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
具体参照我上边回复你的。 版主如何操作:
浏览器加载项:需要删除。
[MonitorURL Class>
  {08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, N/A>
[IE Address Browser Helper>
  {2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[CpapView Class>
  {77962960-536E-47EC-9DDB-52651519705F} <C:\WINDOWS\system32\cpap.dll, >
[>
  {B9E914B5-6B61-401F-A49F-9E84E547D3DD} <C:\WINDOWS\system32\leftup.dll, N/A>
[iehelper>
  {F651FCAA-F826-4922-8990-C6F99CC67AFC} <C:\WINDOWS\Win32ef.dll, N/A>
启动项停止以下进程我已经搞好了. keeper11斑竹的回复在SRENG中都可以操作,参考的操作方法! 谢谢各位版主为我解答!!! 各位版主经过我用SRENG,有一条加载项很顽固删除不了.请各位帮我看看.
{2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[CpapView Class> 先结束[PID: 1208>[C:\Program Files\SearchNet\SearchNet.exe>  <Beijing zhongsou><1, 0, 3, 1>
    [C:\Program Files\SearchNet\SrvNet32.dll>  <中搜在线><1, 0, 2, 7>
进程,然后在控制面板中卸载,最后删除C:\Program Files\SearchNet\ 各位版主辛苦了.我在这里向你们表示衷心感谢. 不知道为什么昨天整理碎片的时候卡巴弹出对话框说C:\WINDOWS\Win32ef.dll是病毒
因为是WINDOWS菜单下的dll文件,不敢乱删就忽略掉了,今天开机不久又出现相同的问题,不知道是为什么,
就把这个文件放到卡巴的排除设置里.请各位大虾们帮帮忙,这个到底是什么,删了会有状况出现么,如何处理呢 各位版主,我贴了好几天了啊,最近机子不知道为什么很慢,蜗牛一样.真的这么忙么,哎~~~~
打印本文  返回顶部  加入收藏  关闭窗口
广 告 位 招 租
  • 上一篇: 请大哥帮我看看````
  • 下一篇: 有个QQ空间。进去一下就会有跳的别的网页是怎么回事?
  • 关于本站 - 网站帮助 - 广告合作 - 下载声明 - 友情连接 - 网站地图 - 管理登录
    联系方式
    Copyright © 2004-2007 FCBU.Com All Rights Reserved.
    版权所有:『站长天下』 新凌讯网络;保留所有权利. 赣ICP备05002812