昨天晚上下网下载一个木马克星.结果出来了一堆垃圾软件.经验一列系的删除后.在每次起动的时候在右下角(也就是时间栏那里)会出现一个像蚂蚁一样的头像.显示的内容是你当前的网速提升了%......那烦啊.也不知道是什么东西.经过我用优化大师看了以后那个东西的名字:netaccelerate Microsoft基础应用程序!!!请大家帮帮我.这是什么啊.我非常怕是一个盗号木马.!
下面是日志:
启动项目
注册表
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run>
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows>
<load><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
<ggzeqt><RunDll32 "C:\WINDOWS\Downlo~1\ggzeqt.dll",Run>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
<Desktop><C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
<KAVPersonal50><"d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
<searcher><C:\WINDOWS\System\msolesrv.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
<netaccelerate><C:\WINDOWS\accdoofo.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
<SearchNet_Up><"C:\Program Files\SearchNet\ServeUp.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
<Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows>
<AppInit_DLLs><>
==================================
启动文件夹
[Microsoft Office>
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk><N>
==================================
服务
[kavsvc / kavsvc>
<"d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe"><Kaspersky Lab>
[Macromedia Licensing Service / Macromedia Licensing Service>
<"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[Remote Log / Remote Log>
<C:\WINDOWS\system32\ServeHost.exe><Beijing zhongsou online software>
接上贴:
==================================
浏览器加载项
[IE Address Browser Helper>
{2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[IE Browser Helper>
{3CE496D1-1746-41CD-9489-3C0B93DF10E2} <C:\WINDOWS\Downlo~1\wudxub76.dll, 中搜在线软件有限公司>
[QQ>
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class>
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\Program Files\Tencent\QQ\QQIEHelper.dll, N/A>
[Messenger>
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Shockwave Flash Object>
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[ActiveMovieControl Object>
{05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[MonitorURL Class>
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, N/A>
[实用搜索>
{15ADF205-4C54-4CFE-AC88-1EA0BA6D06A0} <, N/A>
[Windows Media Player>
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document>
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[IE Address Browser Helper>
{2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[BrowserHelper Class>
{2D99E8F4-56B7-457B-9A92-61B5D247D263} <C:\WINDOWS\system32\WinDefendor.dll, TODO: <公司名>>
[IE Browser Helper>
{3CE496D1-1746-41CD-9489-3C0B93DF10E2} <C:\WINDOWS\Downlo~1\wudxub76.dll, 中搜在线软件有限公司>
[HHCtrl Object>
{41B23C28-488E-4E5C-ACE2-BB0BBABE99E8} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[QQBrowserHelperObject Class>
{54EBD53A-9BC1-480B-966A-843A333CA162} <D:\Program Files\Tencent\QQ\QQIEHelper.dll, N/A>
[Shell Name Space>
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[NetAccelerate Class>
{5673A7C0-95CC-4646-BB07-3BD71234CEF9} <C:\WINDOWS\system32\MicrosoftNet.dll, N/A>
[Windows Media Player>
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[MSHlper Class>
{721E6521-4CAD-4A8D-A7F1-4E230B31EF19} <C:\WINDOWS\system32\MSHLP.DLL, >
[MediaComm Class>
{7670648D-461B-42AF-BDFE-46D26AF5EFF2} <d:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin05.dll, Thunder Networking Technologies,LTD>
[CpapView Class>
{77962960-536E-47EC-9DDB-52651519705F} <C:\WINDOWS\system32\cpap.dll, >
[Microsoft Web 浏览器>
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper>
{889D2FEB-5411-4565-8998-1DD2C5261283} <d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[Microsoft Scriptlet Component>
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC>
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[>
{B9E914B5-6B61-401F-A49F-9E84E547D3DD} <C:\WINDOWS\system32\leftup.dll, N/A>
[AUDIO__MP3 Moniker Class>
{CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control>
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[QuickBtn>
{D1BB7CF4-4463-4E91-88D7-ECC3CE0A13B7} <C:\Program Files\CoolWebsite\QuickLink.dll, N/A>
[Shockwave Flash Object>
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[iehelper>
{F651FCAA-F826-4922-8990-C6F99CC67AFC} <C:\WINDOWS\Win32ef.dll, N/A>
[&使用迅雷下载>
<d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接>
<d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘>
<D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板>
<D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情>
<D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片>
<D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 460>[\SystemRoot\System32\smss.exe> <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 516>[\??\C:\WINDOWS\system32\csrss.exe> <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 540>[\??\C:\WINDOWS\system32\winlogon.exe> <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 584>[C:\WINDOWS\system32\services.exe> <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 596>[C:\WINDOWS\system32\lsass.exe> <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 748>[C:\WINDOWS\system32\svchost.exe> <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 804>[C:\WINDOWS\system32\svchost.exe> <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 868>[C:\WINDOWS\System32\svchost.exe> <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 912>[C:\WINDOWS\system32\svchost.exe> <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1016>[C:\WINDOWS\system32\svchost.exe> <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1288>[C:\WINDOWS\Explorer.EXE> <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\SearchNet\SrvNet32.dll> <中搜在线><1, 0, 2, 7>
[PID: 1320>[C:\WINDOWS\system32\spoolsv.exe> <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1452>[C:\Program Files\Common Files\Real\Update_OB\realsched.exe> <RealNetworks, Inc.><0.1.0.3292>
[PID: 1500>[C:\WINDOWS\System\msolesrv.exe> <MicroSoft Corporation><5. 0. 3700. 6690>
[PID: 1520>[C:\WINDOWS\accdoofo.exe> <N/A><1, 0, 0, 1>
[PID: 1548>[C:\WINDOWS\system32\ctfmon.exe> <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1844>[C:\WINDOWS\system32\ServeHost.exe> <Beijing zhongsou online software><1, 0, 3, 1>
[PID: 508>[C:\WINDOWS\System32\alg.exe> <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1208>[C:\Program Files\SearchNet\SearchNet.exe> <Beijing zhongsou><1, 0, 3, 1>
[C:\Program Files\SearchNet\SrvNet32.dll> <中搜在线><1, 0, 2, 7>
[PID: 1240>[C:\WINDOWS\system32\wscntfy.exe> <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 976>[C:\WINDOWS\system32\wuauclt.exe> <Microsoft Corporation><5.4.3790.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1084>[F:\新建文件夹 (2)\SREng.exe> <Smallfrogs Studio><2.0.12.350>
[C:\Program Files\SearchNet\SrvNet32.dll> <中搜在线><1, 0, 2, 7>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1>
.EXE OK. ["%1" %*>
.COM OK. ["%1" %*>
.PIF OK. ["%1" %*>
.REG OK. [regedit.exe "%1">
.BAT OK. ["%1" %*>
.SCR OK. ["%1" /S>
.CHM OK. ["C:\WINDOWS\hh.exe" %1>
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1>
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1>
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1>
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*>
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*>
.LNK OK. [{00021401-0000-0000-C000-000000000046}>
启动项停止以下进程。
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
<ggzeqt><RunDll32 "C:\WINDOWS\Downlo~1\ggzeqt.dll",Run>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
<Desktop><C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
<searcher><C:\WINDOWS\System\msolesrv.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
<netaccelerate><C:\WINDOWS\accdoofo.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
<SearchNet_Up><"C:\Program Files\SearchNet\ServeUp.exe">
浏览器加载项:需要删除。
[MonitorURL Class>
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, N/A>
[IE Address Browser Helper>
{2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[CpapView Class>
{77962960-536E-47EC-9DDB-52651519705F} <C:\WINDOWS\system32\cpap.dll, >
[>
{B9E914B5-6B61-401F-A49F-9E84E547D3DD} <C:\WINDOWS\system32\leftup.dll, N/A>
[iehelper>
{F651FCAA-F826-4922-8990-C6F99CC67AFC} <C:\WINDOWS\Win32ef.dll, N/A>
正在运行的进程,关于中搜的都可以停止。或者在安全模式下清理。
我应该怎么删除或者停止呢
原帖由 skybule917 于 2006-6-24 13:31 发表
我应该怎么删除或者停止呢
开始,运行regedit,进入注册表编辑器
删除类似于以下路径的键值:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run>
具体参照我上边回复你的。
版主如何操作:
浏览器加载项:需要删除。
[MonitorURL Class>
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, N/A>
[IE Address Browser Helper>
{2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[CpapView Class>
{77962960-536E-47EC-9DDB-52651519705F} <C:\WINDOWS\system32\cpap.dll, >
[>
{B9E914B5-6B61-401F-A49F-9E84E547D3DD} <C:\WINDOWS\system32\leftup.dll, N/A>
[iehelper>
{F651FCAA-F826-4922-8990-C6F99CC67AFC} <C:\WINDOWS\Win32ef.dll, N/A>
启动项停止以下进程我已经搞好了.
keeper11斑竹的回复在SRENG中都可以操作,参考的操作方法!
谢谢各位版主为我解答!!!
各位版主经过我用SRENG,有一条加载项很顽固删除不了.请各位帮我看看.
{2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[CpapView Class>
先结束[PID: 1208>[C:\Program Files\SearchNet\SearchNet.exe> <Beijing zhongsou><1, 0, 3, 1>
[C:\Program Files\SearchNet\SrvNet32.dll> <中搜在线><1, 0, 2, 7>
进程,然后在控制面板中卸载,最后删除C:\Program Files\SearchNet\
各位版主辛苦了.我在这里向你们表示衷心感谢.
不知道为什么昨天整理碎片的时候卡巴弹出对话框说C:\WINDOWS\Win32ef.dll是病毒
因为是WINDOWS菜单下的dll文件,不敢乱删就忽略掉了,今天开机不久又出现相同的问题,不知道是为什么,
就把这个文件放到卡巴的排除设置里.请各位大虾们帮帮忙,这个到底是什么,删了会有状况出现么,如何处理呢
各位版主,我贴了好几天了啊,最近机子不知道为什么很慢,蜗牛一样.真的这么忙么,哎~~~~ |
|