瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【原创】求助,开机弹出申请QQ,关不掉,请高手帮俺看看日志

1   1  /  1  页   跳转

【原创】求助,开机弹出申请QQ,关不掉,请高手帮俺看看日志

【原创】求助,开机弹出申请QQ,关不掉,请高手帮俺看看日志

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\C\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <bgswitch><rem C:\WINDOWS\system32\bgswitch.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><rem "C:\C\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\C\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\C\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <igfxtray><rem C:\C\system32\igfxtray.exe>  [(Verified)Intel Corporation]
    <igfxhkcmd><rem C:\C\system32\hkcmd.exe>  [(Verified)Intel Corporation]
    <igfxpers><rem C:\C\system32\igfxpers.exe>  [(Verified)Intel Corporation]
    <SoundMan><rem SOUNDMAN.EXE>  [N/A]
    <Thunder><"f:\Program Files\Thunder Network\Thunder\Thunder.exe" /s>  [Thunder Networking Technologies,LTD]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <kav><"G:\卡巴斯基\avp.exe">  [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\C\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
    <UIHost><logonui.exe>  [ORIONNET]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
    <WinlogonNotify: igfxcui><igfxdev.dll>  [(Verified)Intel Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
    <WinlogonNotify: klogon><C:\C\system32\klogon.dll>  [Kaspersky Lab]

==================================
启动文件夹
[腾讯QQ]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk --> G:\QQ\QQ.exe [TENCENT]><N>

==================================
服务
[卡巴斯基反病毒6.0 / AVP]
  <G:\卡巴斯基\avp.exe -r><Kaspersky Lab>
[Human Interface Device Access / HidServ]
  <C:\C\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>

==================================
驱动程序
[ADProt / ADProt]
  <\SystemRoot\system32\drivers\ADProt.sys><腾讯科技(深圳)有限公司>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[Bluetooth Audio Service / BlueletAudio]
  <system32\DRIVERS\blueletaudio.sys><N/A>
[Bluetooth SCO Audio Service / BlueletSCOAudio]
  <system32\DRIVERS\BlueletSCOAudio.sys><N/A>
[Bluetooth PAN Network Adapter / BT]
  <system32\DRIVERS\btnetdrv.sys><N/A>
[Bluetooth USB For Bluetooth Service / Btcsrusb]
  <System32\Drivers\btcusb.sys><N/A>
[Bluetooth HID Enumerator / BTHidEnum]
  <system32\DRIVERS\vbtenum.sys><N/A>
[Bluetooth HID Manager Service / BTHidMgr]
  <\SystemRoot\System32\Drivers\BTHidMgr.sys><N/A>
[cda1000 / cda1000]
  <C:\C\SYSTEM32\DRIVERS\cda1000.SYS><Adaptec, Inc.>
[CdaC15BA / CdaC15BA]
  <\??\C:\C\system32\drivers\CdaC15BA.SYS><Macrovision Europe Ltd>
[ialm / ialm]
  <system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[kl1 / kl1]
  <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif]
  <\??\C:\C\system32\drivers\klif.sys><Kaspersky Lab>
[kmsinput / kmsinput]
  <\??\C:\C\system32\drivers\kmsinput.sys><N/A>
[npkcrypt / npkcrypt]
  <\??\D:\QQ\npkcrypt.sys><N/A>
[Direct Parallel Link Driver / Ptilink]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp]
  <system32\DRIVERS\Rtlnicxp.sys><Realtek Semiconductor Corporation>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[rzxtniwq / rzxtniwq]
  <\SystemRoot\system32\drivers\rzxtniwq.sys><>
[Secdrv / Secdrv]
  <system32\DRIVERS\secdrv.sys><N/A>
[Virtual Serial port driver / VComm]
  <system32\DRIVERS\VComm.sys><N/A>
[Bluetooth VComm Manager Service / VcommMgr]
  <System32\Drivers\VcommMgr.sys><N/A>
最后编辑2006-11-11 04:16:42
分享到:
gototop
 

浏览器加载项
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <G:\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <f:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[启动迅雷]
  {0062C9BD-B349-40DE-91A0-755F37ACD559} <f:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[Web反病毒保护]
  {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <G:\卡巴斯基\scieplugin.dll, Kaspersky Lab>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <G:\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <G:\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <G:\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[MediaComm Class]
  {7670648D-461B-42AF-BDFE-46D26AF5EFF2} <f:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin07.dll, Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <f:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\C\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\C\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[&使用迅雷下载]
  <f:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <f:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
  <D:\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
  <G:\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <G:\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <G:\QQ\SendMMS.htm, N/A>
gototop
 

正在运行的进程
[PID: 496][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 568][\??\C:\C\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 592][\??\C:\C\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\C\system32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 636][C:\C\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 648][C:\C\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 796][C:\C\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 860][C:\C\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 920][C:\C\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 988][C:\C\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1056][C:\C\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1228][C:\C\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1456][C:\C\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 1816][C:\C\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\C\system32\igfxpph.dll]  [Intel Corporation, 3.0.0.4396]
    [C:\C\system32\hccutils.DLL]  [Intel Corporation, 3.0.0.4396]
    [C:\C\system32\igfxres.dll]  [Intel Corporation, 3.0.0.4396]
    [C:\C\system32\igfxress.dll]  [Intel Corporation, 3.0.0.4396]
    [C:\C\system32\igfxsrvc.dll]  [Intel Corporation, 3.0.0.4396]
    [f:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
    [G:\卡巴斯基\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [G:\卡巴斯基\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
    [g:\卡巴斯基\params.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
    [D:\WinRAR\rarext.dll]  [N/A, N/A]
    [D:\QQ\qdshm.dll]  [, 1, 0, 101, 20]
    [G:\卡巴斯基\shellex.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 400][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3208]
[PID: 480][C:\C\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 760][C:\C\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 964][G:\QQ\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [G:\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [G:\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [G:\QQ\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 370]
    [G:\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
    [G:\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [G:\QQ\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [G:\QQ\WizardCtrl.dll]  [, 1, 0, 0, 1]
    [G:\卡巴斯基\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [G:\卡巴斯基\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
    [g:\卡巴斯基\params.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
[PID: 1052][G:\QQ\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [G:\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 4084][G:\QQ\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [G:\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [G:\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [G:\QQ\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 370]
    [G:\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
    [G:\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [G:\QQ\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [G:\QQ\WizardCtrl.dll]  [, 1, 0, 0, 1]
    [G:\卡巴斯基\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [G:\卡巴斯基\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
    [g:\卡巴斯基\params.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
[PID: 856][G:\QQ\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [G:\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [G:\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [G:\QQ\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 370]
    [G:\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
    [G:\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [G:\QQ\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [G:\QQ\WizardCtrl.dll]  [, 1, 0, 0, 1]
    [G:\卡巴斯基\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [G:\卡巴斯基\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
    [g:\卡巴斯基\params.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
[PID: 620][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [G:\QQ\QQIEHelper.dll]  [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
    [f:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
    [G:\卡巴斯基\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [G:\卡巴斯基\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
    [g:\卡巴斯基\params.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
[PID: 3212][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [G:\QQ\QQIEHelper.dll]  [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
    [f:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
    [G:\卡巴斯基\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [G:\卡巴斯基\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
    [g:\卡巴斯基\params.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
    [C:\C\system32\Macromed\Flash\Flash8.ocx]  [Macromedia, Inc., 8,0,22,0]
[PID: 3628][F:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe]  [Thunder Networking Technologies,LTD, 5.4.0.226]
    [F:\Program Files\Thunder Network\Thunder\Program\UpdateDownload.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 8]
    [F:\Program Files\Thunder Network\Thunder\Program\download_interface.dll]  [Thunder Networking Technologies,LTD, 2, 0, 0, 1]
    [F:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
    [F:\Program Files\Thunder Network\Thunder\Program\log4cplus.dll]  [, 1, 0, 2, 1]
    [F:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll]  [N/A, N/A]
    [F:\Program Files\Thunder Network\Thunder\Program\msgmanage.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 15]
    [F:\Program Files\Thunder Network\Thunder\Program\historyinfo_manage.dll]  [Thunder Networking Technologies,LTD, 5, 2, 0, 148]
    [F:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 1, 0, 18]
    [F:\Program Files\Thunder Network\Thunder\Program\FloatBar.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
    [F:\Program Files\Thunder Network\Thunder\Plugins\TingTing\TingTing.dll]  [Thunder Networking Technologies,LTD, 1, 1, 1, 9]
    [F:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll]  [ , 1, 0, 0, 11]
    [f:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed04.dll]  [ , 2, 3, 0, 37]
    [F:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll]  [Thunder Networking Technologies,LTD, 1, 0, 4, 10]
    [G:\卡巴斯基\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [G:\卡巴斯基\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
    [g:\卡巴斯基\params.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
    [F:\Program Files\Thunder Network\Thunder\Program\iTargetAd.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 59]
    [C:\C\system32\Macromed\Flash\Flash8.ocx]  [Macromedia, Inc., 8,0,22,0]
[PID: 3792][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [G:\QQ\QQIEHelper.dll]  [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
    [f:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
    [G:\卡巴斯基\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [G:\卡巴斯基\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [G:\卡巴斯基\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
    [g:\卡巴斯基\params.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
    [g:\卡巴斯基\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
    [C:\C\system32\Macromed\Flash\Flash8.ocx]  [Macromedia, Inc., 8,0,22,0]
    [f:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin07.dll]  [Thunder Networking Technologies,LTD, 2, 3, 0, 49]
    [C:\C\system32\msdmo.dll]  [N/A, N/A]
[PID: 2292][G:\sreng\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\C\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
[D:\]
[autorun]
OPEN=D:\pagefile.pif

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT