瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 双击所有的盘都会出现搜索,请高手帮助啊!
Azuresky2005 - 2007-3-2 17:21:00
双击C、D、U盘都会出现搜索,右键的第一个菜单项是搜索,请高手帮助啊!附图

附件: 635424200732171218.bmp
Azuresky2005 - 2007-3-2 17:23:00
每个文件夹也是的啊?急等啊
Azuresky2005 - 2007-3-2 17:26:00
日志
[CODE]

2007-03-02,17:12:43

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\windows\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <KavPFW><"C:\KAV2007\KPFW32.EXE">  [Kingsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <RunShadowTip><C:\WINDOWS\system32\shadow\ShadowTip.exe>  [PowerShadow]
    <KavStart><"C:\KAV2007\KAVStart.exe" -startup>  [Kingsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <KASTask><C:\KAV2007\KASTask.EXE>  [Kingsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\windows\system32\Userinit.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\windows\system32\年韵20~1.SCR>  [Microsoft Corp.                                                                                                                                                                                                                                              ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <SoundMan><; SOUNDMAN.EXE>  [(Verified)Realtek Semiconductor Corp.]
    <VTTimer><; VTTimer.exe>  [(Verified)S3 Graphics, Inc.]
    <VTTrayp><; VTtrayp.exe>  [(Verified)S3 Graphics Co., Ltd.]
Azuresky2005 - 2007-3-2 17:27:00
启动文件夹
[Adobe Reader Speed Launch]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk --> C:\PROGRA~1\Adobe\READER~1.0\Reader\READER~1.EXE [Adobe Systems Incorporated]><N>
[Adobe Reader Synchronizer]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Reader Synchronizer.lnk --> C:\PROGRA~1\Adobe\READER~1.0\Reader\ADOBEC~1.EXE [N/A]><N>

==================================
服务
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Application Management / AppMgmt][Stopped/Manual Start]
  <C:\windows\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[IIS Admin Service / IISADMIN][Running/Auto Start]
  <C:\WINDOWS\system32\inetsrv\inetinfo.exe><Microsoft Corporation>
[FTP Publishing Service / MSFTPSVC][Running/Auto Start]
  <C:\WINDOWS\system32\inetsrv\inetinfo.exe><Microsoft Corporation>
[Shadow System Service / ShadowSystemService][Running/Auto Start]
  <C:\WINDOWS\system32\shadow\ShadowService.exe><N/A>
[World Wide Web Publishing Service / W3SVC][Running/Auto Start]
  <C:\WINDOWS\system32\inetsrv\inetinfo.exe><Microsoft Corporation>
[Windows Driver Foundation - User-mode Driver Framework / WudfSvc][Stopped/Manual Start]
  <C:\windows\system32\svchost.exe -k WudfServiceGroup-->%SystemRoot%\System32\WUDFSvc.dll><Microsoft Corporation>
[Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
  <C:\KAV2007\KWatch.EXE><Kingsoft Corporation>
[Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
  <"C:\KAV2007\KPfwSvc.EXE"><Kingsoft Corporation>

==================================
驱动程序
[Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
  <system32\drivers\ALCXSENS.SYS><Sensaura>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Running/Manual Start]
  <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[viagfx / viagfx][Running/Manual Start]
  <system32\DRIVERS\vtmini.sys><Copyright (C) VIA/S3 Graphics Co, Ltd.>
[ViaIde / ViaIde][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[Windows Driver Foundation - User-mode Driver Framework Platform Driver / WudfPf][Stopped/Manual Start]
  <system32\DRIVERS\WudfPf.sys><Microsoft Corporation>
[Windows Driver Foundation - User-mode Driver Framework Reflector / WudfRd][Stopped/Manual Start]
  <system32\DRIVERS\wudfrd.sys><Microsoft Corporation>
[KWatch3 / KWatch3][Running/System Start]
  <\??\C:\windows\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
[KNetWch / KNetWch][Running/System Start]
  <\??\C:\KAV2007\KNetWch.SYS><Kingsoft Corporation>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
Azuresky2005 - 2007-3-2 17:28:00
浏览器加载项
[Adobe PDF Reader Link Helper]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[CBrowseStakeout Class]
  {55302805-482E-470E-8A57-6795A1487F90} <C:\KAV2007\KAVAFish.DLL, Kingsoft Corporation>
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Adobe PDF Reader Link Helper]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <C:\windows\system32\ieframe.dll, Microsoft Corporation>
[CBrowseStakeout Class]
  {55302805-482E-470E-8A57-6795A1487F90} <C:\KAV2007\KAVAFish.DLL, Kingsoft Corporation>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\KAV2007\Flash.OCX, Macromedia, Inc.>
[XML HTTP Request]
  {ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\system32\msxml3.dll, N/A>
[XML DOM Document 3.0]
  {F5078F32-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\system32\msxml3.dll, N/A>
[金山毒霸反钓鱼...]
  <C:\KAV2007\KAF\ShowSet.htm, N/A>
Azuresky2005 - 2007-3-2 17:29:00
正在运行的进程
[PID: 532][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 592][\??\C:\windows\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 616][\??\C:\windows\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 660][C:\windows\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 672][C:\windows\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 812][C:\windows\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 900][C:\windows\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 996][C:\windows\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1044][C:\windows\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1164][C:\windows\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1268][C:\windows\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1612][C:\windows\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 8.0.0.0]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS]  [Adobe Systems, Inc., 8.0.0.0]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [d:\爱数加密软件 2006 标准版\encryptshl.dll]  [N/A, N/A]
    [d:\爱数加密软件 2006 标准版\syswrap.dll]  [N/A, N/A]
    [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2006, 12, 21, 241]
    [C:\KAV2007\KMailOEBand.dll]  [Kingsoft Corporation, 2006, 12, 1, 139]
    [C:\KAV2007\KAVEXT.DLL]  [Kingsoft Corporation, 2005, 8, 5, 16]
    [C:\KAV2007\KAScript.DLL]  [Kingsoft Corporation, 2006, 12, 11, 72]
    [C:\KAV2007\KAEPlat.DLL]  [Kingsoft Corp., 2007, 2, 4, 61]
    [C:\KAV2007\KAEMem.DAT]  [Kingsoft, 2006, 9, 25, 16]
    [C:\KAV2007\KAEUnpack.DAT]  [Kingsoft Corp., 2007, 1, 16, 104]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 8.0.0.2006102200]
[PID: 1720][C:\windows\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2006, 12, 21, 241]
    [C:\KAV2007\KMailOEBand.dll]  [Kingsoft Corporation, 2006, 12, 1, 139]
[PID: 436][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  [Microsoft Corporation, 7.00.9466]
[PID: 468][C:\WINDOWS\system32\shadow\ShadowService.exe]  [N/A, N/A]
[PID: 636][C:\WINDOWS\system32\inetsrv\inetinfo.exe]  [Microsoft Corporation, 5.00.0984]
[PID: 1356][C:\windows\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1968][C:\windows\system32\wscntfy.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2006, 12, 21, 241]
[PID: 1032][C:\WINDOWS\system32\shadow\ShadowTip.exe]  [PowerShadow, 1, 0, 0, 1]
    [C:\WINDOWS\system32\shadow\pDeskTop.dll]  [N/A, N/A]
    [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2006, 12, 21, 241]
[PID: 3996][C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE]  [Microsoft Corporation, 11.0.6568]
    [C:\Program Files\Microsoft Office\OFFICE11\STARTUP\MathPage.wll]  [N/A, N/A]
    [C:\windows\system32\SOGOUPY.IME]  [Sohu.com Inc., 2, 0, 0, 0]
    [C:\windows\system32\dllMergeDict.dll]  [N/A, N/A]
    [d:\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS]  [Adobe Systems, Inc., 8.0.0.0]
    [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2006, 12, 21, 241]
    [C:\KAV2007\KMailOEBand.dll]  [Kingsoft Corporation, 2006, 12, 1, 139]
[PID: 828][C:\windows\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2006, 12, 21, 241]
    [C:\KAV2007\KMailOEBand.dll]  [Kingsoft Corporation, 2006, 12, 1, 139]
[PID: 3392][C:\KAV2007\KWatch.EXE]  [Kingsoft Corporation, 2007, 1, 31, 81]
    [C:\KAV2007\KAVIPC2.DLL]  [Kingsoft Corporation, 2007, 1, 15, 30]
    [C:\KAV2007\KAEPlat.DLL]  [Kingsoft Corp., 2007, 2, 4, 61]
    [C:\KAV2007\KAEMem.DAT]  [Kingsoft, 2006, 9, 25, 16]
    [C:\KAV2007\KAEUnpack.DAT]  [Kingsoft Corp., 2007, 1, 16, 104]
    [C:\KAV2007\KAVQuara.DLL]  [Kingsoft Corporation, 2007, 1, 25, 1]
[PID: 2840][C:\KAV2007\KavStart.exe]  [Kingsoft Corporation, 2007, 2, 1, 257]
    [C:\KAV2007\KAVIPC2.DLL]  [Kingsoft Corporation, 2007, 1, 15, 30]
    [C:\KAV2007\SvcTimer.DLL]  [Kingsoft Corporation, 2006.12.22.84]
    [C:\KAV2007\PopSprt3.dll]  [Kingsoft Corporation, 2007, 1, 16, 45]
    [C:\KAV2007\KAVPassp.dll]  [Kingsoft Corporation, 2006, 12, 30, 271]
    [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2006, 12, 21, 241]
    [C:\KAV2007\KMailOEBand.dll]  [Kingsoft Corporation, 2006, 12, 1, 139]
[PID: 2784][C:\KAV2007\KPfwSvc.EXE]  [Kingsoft Corporation, 2007, 2, 2, 31]
[PID: 2968][C:\KAV2007\KMailMon.EXE]  [Kingsoft Corporation, 2006, 12, 27, 942]
    [C:\KAV2007\KAntiSpm.dll]  [Kingsoft Corporation, 2006, 8, 19, 104]
    [C:\KAV2007\KAVIPC2.DLL]  [Kingsoft Corporation, 2007, 1, 15, 30]
    [C:\KAV2007\KAECall2.DLL]  [Kingsoft Corporation, 2004, 12, 28, 7]
    [C:\KAV2007\KAEPlat.DLL]  [Kingsoft Corp., 2007, 2, 4, 61]
    [C:\KAV2007\KAEMem.DAT]  [Kingsoft, 2006, 9, 25, 16]
    [C:\KAV2007\KAEUnpack.DAT]  [Kingsoft Corp., 2007, 1, 16, 104]
    [C:\KAV2007\KAConfig.DLL]  [Kingsoft Corporation, 2007, 1, 11, 41]
    [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2006, 12, 21, 241]
    [C:\KAV2007\KMailOEBand.dll]  [Kingsoft Corporation, 2006, 12, 1, 139]
[PID: 3736][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [C:\KAV2007\KMailOEBand.dll]  [Kingsoft Corporation, 2006, 12, 1, 139]
    [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2006, 12, 21, 241]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 8.0.0.2006102200]
    [C:\KAV2007\KAVAFish.DLL]  [Kingsoft Corporation, 2006, 10, 25, 27]
    [C:\KAV2007\KAScript.DLL]  [Kingsoft Corporation, 2006, 12, 11, 72]
    [C:\KAV2007\KAEPlat.DLL]  [Kingsoft Corp., 2007, 2, 4, 61]
    [C:\KAV2007\KAEMem.DAT]  [Kingsoft, 2006, 9, 25, 16]
    [C:\KAV2007\KAEUnpack.DAT]  [Kingsoft Corp., 2007, 1, 16, 104]
    [C:\KAV2007\Flash.OCX]  [Macromedia, Inc., 7,0,19,0]
    [C:\windows\system32\SOGOUPY.IME]  [Sohu.com Inc., 2, 0, 0, 0]
    [C:\windows\system32\dllMergeDict.dll]  [N/A, N/A]
    [d:\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 8.0.0.0]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS]  [Adobe Systems, Inc., 8.0.0.0]
[PID: 1960][D:\Macromedia\Fireworks 8\Fireworks.exe]  [Macromedia Inc., 8.0.0.777]
    [D:\Macromedia\Fireworks 8\SN.dll]  [N/A, N/A]
    [D:\Macromedia\Fireworks 8\jslib.dll]  [N/A, N/A]
    [D:\Macromedia\Fireworks 8\libpng.dll]  [N/A, N/A]
    [D:\Macromedia\Fireworks 8\zlib.dll]  [N/A, N/A]
    [D:\Macromedia\Fireworks 8\python.dll]  [N/A, N/A]
    [D:\Macromedia\Fireworks 8\giflib.dll]  [N/A, N/A]
    [D:\Macromedia\Fireworks 8\Simplified Chinese\Resources\Fireworks Resources.dll]  [Macromedia, Inc., 8.0]
    [C:\KAV2007\KMailOEBand.dll]  [Kingsoft Corporation, 2006, 12, 1, 139]
    [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2006, 12, 21, 241]
    [D:\Macromedia\Fireworks 8\MMxptResources.dll]  [Macromedia, Inc., 5, 0, 0, 44]
    [D:\Macromedia\Fireworks 8\JSExtensions\MMNotes.dll]  [Macromedia, Inc., 3, 0, 2, 0]
    [D:\Macromedia\Fireworks 8\Plug-Ins\EMLaunch.dll]  [Macromedia, Inc., 1.7.143]
    [D:\Macromedia\Fireworks 8\Plug-Ins\mix32.x32]  [Macromedia, Inc., 1.16]
    [D:\Macromedia\Fireworks 8\Plug-Ins\gsdll32.dll]  [N/A, N/A]
    [D:\Macromedia\Fireworks 8\Plug-Ins\TwainAgent.x32]  [Macromedia, Inc., 1.0]
    [C:\windows\system32\ATMLIB.dll]  [Adobe Systems, 5.1 Build 226]
    [D:\Macromedia\Fireworks 8\Plug-Ins\authplay.dll]  [N/A, N/A]
    [D:\Macromedia\Fireworks 8\Plug-Ins\BMP Import Export.x32]  [N/A, N/A]
[PID: 3452][C:\windows\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3788][D:\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [C:\KAV2007\KMailOEBand.dll]  [Kingsoft Corporation, 2006, 12, 1, 139]
    [C:\KAV2007\KASocket.dll]  [Kingsoft Corporation, 2006, 12, 21, 241]
Azuresky2005 - 2007-3-2 17:29:00
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
入口点错误:LoadLibraryExW

==================================


[/CODE]
Azuresky2005 - 2007-3-2 17:33:00
每个文件夹里都是

附件: 635424200732172349.bmp
afkp4e7 - 2007-3-2 17:58:00
运行regedit
[HKEY_CLASSES_ROOT\Directory\shell]
@="none"
文件夹的
这个键值改成这样@="none"
你试下
afkp4e7 - 2007-3-2 18:06:00
[HKEY_CLASSES_ROOT\Drive\shell]
@="none"
这个是盘符的
find改成none
Azuresky2005 - 2007-3-2 18:15:00
谢谢,我试试啊
afkp4e7 - 2007-3-2 18:16:00
都改成none
Azuresky2005 - 2007-3-2 18:20:00
大侠你好,谢谢,现在不搜索了,但是第一个有搜索变成了资源管理器了
请问怎么办啊!谢谢啊

附件: 635424200732181113.bmp
afkp4e7 - 2007-3-2 18:25:00
[HKEY_CLASSES_ROOT\Directory\shell]
@="none"
这个现在是none么
双击是直接进入还是新开一个资源管理器
afkp4e7 - 2007-3-2 18:27:00
双击那个键值
在里面输入none
dxd1226 - 2007-3-2 18:29:00
我以前下歌插MP3是 移动硬盘右键第一个也是资源管理器,高手指点我 让我先在文件夹选项里把显示所有文件选上  选上后出现了个隐藏的.exe 跟 .ini文件  删了后好了
楼上别笑话  我刚接触这个不太懂 不知道这样行不行
Azuresky2005 - 2007-3-2 18:30:00
谢谢,我试试啊
afkp4e7 - 2007-3-2 18:31:00
搞定没
偶要下班回家了
Azuresky2005 - 2007-3-2 18:33:00
没有用,你的那个是中毒了,我的这个没有,谢谢你啊!
afkp4e7 - 2007-3-2 18:34:00
引用:
【Azuresky2005的贴子】没有用,你的那个是中毒了,我的这个没有,谢谢你啊!
………………



是好了还是没好啊晕
Azuresky2005 - 2007-3-2 18:34:00
现在文件夹和硬盘右击第一个都变成了资源管理器了,不是搜索,请问怎么办呢?谢谢啊
Azuresky2005 - 2007-3-2 18:37:00
现在就是这样,谢谢啊

附件: 635424200732182754.jpg
afkp4e7 - 2007-3-2 18:38:00
你的那个键值现在是none么
[HKEY_CLASSES_ROOT\Directory\shell]
@="none"
双击试试

afkp4e7 - 2007-3-2 18:39:00
这样

附件: 795322200732183001.jpg
Azuresky2005 - 2007-3-2 18:40:00
我再看看啊
消常感谢啊
afkp4e7 - 2007-3-2 18:41:00
我先回家了
不行说声
我回家再上来
Azuresky2005 - 2007-3-2 18:42:00
已经改过了,现在搜索没了,第一个是资源管理器
不好意思耽误您时间了
非常感谢啊
Azuresky2005 - 2007-3-2 18:44:00
谢谢!
afkp4e7 - 2007-3-2 18:51:00
说的这么客气
我怎么走
查下这个键值
[HKEY_CLASSES_ROOT\Folder\shell]
@="open"
改成open
好的说声
afkp4e7 - 2007-3-2 18:52:00
应该是好了
注册表真是难搞
12
查看完整版本: 双击所有的盘都会出现搜索,请高手帮助啊!