瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求助:好像被http://xxx.520530.cn/ad/index.htm劫持了

12   1  /  2  页   跳转

求助:好像被http://xxx.520530.cn/ad/index.htm劫持了

求助:好像被http://xxx.520530.cn/ad/index.htm劫持了

我一打开ie就出现这个网站,首页也无法更改,而且这个网站每隔几秒钟就自动弹出来。而且给qq里的好友发信息,它也会传过去。请各位高手指点迷津,多谢。以下是扫描日志:


HijackThis@Qoo的扫描日志 V1.97.7
Scan saved at 13:15:43, on 2006-5-5
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\SAND\qqfacerclient.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\COMM\Network.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\msime.exe
C:\WINDOWS\system32\winmer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system\czobiwybx.exe
C:\WINDOWS\system32\winlogin.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\baigoo\bgoomain.exe
C:\WINDOWS\weiba.exe
C:\WINDOWS\system32\SHELLEXT\svchs0t.exe
C:\WINDOWS\system32\TVIDLV.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\Javas\msnmon.exe
C:\WINDOWS\alcupd\alcupd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\HuaCi\huaci\zSearch.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\lib\u88setup.exe
C:\WINDOWS\explorer.exe
C:\Program Files\SearchNet\SearchNet.exe
C:\WINDOWS\system32\conime.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\user\LOCALS~1\Temp\mum1\mum1.exe
C:\WINDOWS\NIW.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\user\桌面\HijackThis.exe

R3 - URLSearchHook: (no name) - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
R3 - URLSearchHook:
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\PROGRA~1\DESKAD~1\deskipn.dll
O2 - BHO: SohuDAIEHelper - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - C:\Program Files\P4P\sodaie.dll (file missing)
O2 - BHO: (no name) - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:\Program Files\SearchNet\SNHpr.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll
O2 - BHO: (no name) - {3CE496D1-1746-41CD-9489-3C0B93DF10E2} - C:\WINDOWS\Downlo~1\IEHpr.dll
O2 - BHO:
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: (no name) - {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} - C:\WINDOWS\System32\aclayer.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: DuDu.com - {6BDE1669-B490-48E3-B668-456314F2D6C3} - C:\Program Files\DuDu\DddClient\dddiemon.dll
O2 - BHO: bg - {7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} - C:\Program Files\baigoo\BGooBHO.dll
O2 - BHO: Accoona Search Assistant - {944864A5-3916-46E2-96A9-A2E84F3F1208} - C:\Program Files\Accoona\ASearchAssist.dll
O2 - BHO: (no name) - {A3803141-3CF5-4D66-B7EA-8D2674FE152C} - C:\Program Files\Internet Explorer\lib\stdie.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: (no name) - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} - C:\WINDOWS\system32\microapmddt.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\CnsHook.dll
O3 - Toolbar: ????? - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [KavStart] "D:\KAV2006\KAVStart.exe" -startup
O4 - HKLM\..\Run: [res] C:\WINDOWS\system32\res.exe
O4 - HKLM\..\Run: [HNETPOLCY] rundll32.exe C:\DOCUME~1\user\LOCALS~1\Temp\RarSFX2\HNETPO~1.DLL,Start
O4 - HKLM\..\Run: [czobiwybx.exe] C:\WINDOWS\system\czobiwybx.exe
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [WinLogom] C:\WINDOWS\system32\winlogin.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDAT\Update.exe
O4 - HKLM\..\Run: [SearchNet_Up] "C:\Program Files\SearchNet\ServeUp.exe"
O4 - HKLM\..\Run: [bgoomain.exe] C:\PROGRA~1\baigoo\bgoomain.exe
O4 - HKLM\..\Run: [MoveSearch] C:\Program Files\HuaCi\huaci\zsearch.exe
O4 - HKLM\..\Run: [Sysqq] C:\WINDOWS\weiba.exe
O4 - HKLM\..\Run: [rundll32] C:\WINDOWS\system32\SHELLEXT\svchs0t.exe
O4 - HKLM\..\Run: [I2U6P5] C:\WINDOWS\system32\TVIDLV.exe
O4 - HKLM\..\Run: [stup.exe] C:\PROGRA~1\TENCENT\Adplus\stup.exe
O4 - HKLM\..\Run: [AddrPlus3] C:\PROGRA~1\TENCENT\Adplus\stup.exe C:\PROGRA~1\TENCENT\Adplus\Adplus.dll Rundll32
O4 - HKLM\..\Run: [IESAddr] RunDll32 "C:\WINDOWS\Downlo~1\Gladiator.dll",Boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [update8] C:\WINDOWS\aupdate.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmon] C:\WINDOWS\Javas\msnmon.exe
O4 - HKCU\..\Run: [alcupd.exe] C:\WINDOWS\alcupd\alcupd.exe
O4 - HKCU\..\Run: [HNETPOLCY] rundll32.exe C:\DOCUME~1\user\LOCALS~1\Temp\RarSFX2\HNETPO~1.DLL,Start
O4 - HKCU\..\Run: [NIW] C:\WINDOWS\NIW.exe
O4 - HKLM\..\RunOnce: [IeStub] C:\DOCUME~1\user\LOCALS~1\Temp\gzg.exe
O4 - Startup: NTUSER.DAT
O4 - Startup: Recent.000
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Startup: Recent.001
O4 - Startup: Recent.002
O4 - Startup: Recent.003
O4 - Startup: Recent.004
O4 - Startup: Recent.005
O4 - Startup: ra2.csf
O4 - Startup: ecache01.mix
O4 - Startup: expand01.mix
O4 - Startup: Recent.006
O4 - Startup: Recent.007
O4 - Startup: 另存为desktop.ini
O4 - Startup: 打印机desktop.ini
O4 - Startup: MSNdesktop.ini
O4 - Startup: 回收站desktop.ini
O4 - Startup: 新邮件desktop.ini
O4 - Startup: 记事本desktop.ini
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: >> 彩信发送 << - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
O8 - Extra context menu item: >>彩信发送<< - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 添加到雅虎订阅(&Y) - res://C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yrss.dll/YRSSMENUEXT
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\qq\SendMMS.htm
O8 - Extra context menu item: 雅虎搜索 - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O9 - Extra button: QQ (HKLM)
O11 - Options group: [!CNS]
O11 - Options group: [TBH]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{266440CA-AF9D-4236-A4C6-2ED8B56EF511}: NameServer = 202.194.15.12

最后编辑2006-05-07 14:46:50
分享到:
gototop
 

ALT+CTRL+DEL调出任务管理器,终止
winlogin.exe
weiba.exe
svchs0t.exe
msnmon.exe
u88setup.exe
NIW.exe的进程
关闭所有浏览窗口以及一些不必要的程序
进入控制面版的添加删除程序中卸载Winstdup,地址搜搜,MMSASS彩信
运行Hijackthis,扫描结束后在下列选项前打上勾,然后选"修复""(如果有的话)
O2 - BHO: (no name) - {A3803141-3CF5-4D66-B7EA-8D2674FE152C} - C:\Program Files\Internet Explorer\lib\stdie.dll
O2 - BHO: (no name) - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} - C:\WINDOWS\system32\microapmddt.dll
O4 - HKLM\..\Run: [res] C:\WINDOWS\system32\res.exe
O4 - HKLM\..\Run: [HNETPOLCY] rundll32.exe C:\DOCUME~1\user\LOCALS~1\Temp\RarSFX2\HNETPO~1.DLL,Start
O4 - HKLM\..\Run: [WinLogom] C:\WINDOWS\system32\winlogin.exe
O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDAT\Update.exe
O4 - HKLM\..\Run: [czobiwybx.exe] C:\WINDOWS\system\czobiwybx.exe
O4 - HKLM\..\Run: [Sysqq] C:\WINDOWS\weiba.exe
O4 - HKLM\..\Run: [rundll32] C:\WINDOWS\system32\SHELLEXT\svchs0t.exe
O4 - HKLM\..\Run: [IESAddr] RunDll32 "C:\WINDOWS\Downlo~1\Gladiator.dll",Boot
O4 - HKCU\..\Run: [HNETPOLCY] rundll32.exe C:\DOCUME~1\user\LOCALS~1\Temp\RarSFX2\HNETPO~1.DLL,Start
O4 - HKCU\..\Run: [NIW] C:\WINDOWS\NIW.exe
O4 - HKLM\..\RunOnce: [IeStub] C:\DOCUME~1\user\LOCALS~1\Temp\gzg.exe
以下04项,如果你少知道是什么,就修复。
O4 - Startup: NTUSER.DAT
O4 - Startup: Recent.000
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Startup: Recent.001
O4 - Startup: Recent.002
O4 - Startup: Recent.003
O4 - Startup: Recent.004
O4 - Startup: Recent.005
O4 - Startup: ra2.csf
O4 - Startup: ecache01.mix
O4 - Startup: expand01.mix
O4 - Startup: Recent.006
O4 - Startup: Recent.007
O4 - Startup: 另存为desktop.ini
O4 - Startup: 打印机desktop.ini
O4 - Startup: MSNdesktop.ini
O4 - Startup: 回收站desktop.ini
O4 - Startup: 新邮件desktop.ini
O4 - Startup: 记事本desktop.ini
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: >> 彩信发送 << - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
修复后,请重启。
请下载使用 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描

,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日

志文件内容复制-粘贴上来
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
www.27814939.ys168.com
gototop
 

我按照你说的修复了。但主页还是这个网站http://xxx.520530.cn/ad/index.htm,而且Internet选项里的主页还是灰色的,锁定这个了这个网站。还有我修复重启之后,我又用Hijackthis扫描了一下,结果你让我修复的这两个又出现了(O4 - HKCU\..\Run: [NIW] C:\WINDOWS\NIW.exe和O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present)。
但这个网站已经不再自己往外弹了,而且任务管理器以前刚打开不到半秒钟就自动消失,现在已经可以了。
以下是用SRE扫描的日志,请再帮我看看,多谢:

2006-05-05,18:21:04

System Repair Engineer 2.0.12.350 (2.0 RC 1)
    Windows XP Professional Service Pack 2 - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <update8><C:\WINDOWS\aupdate.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <alcupd.exe><C:\WINDOWS\alcupd\alcupd.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <HNETPOLCY><rundll32.exe C:\DOCUME~1\user\LOCALS~1\Temp\RarSFX2\HNETPO~1.DLL,Start>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <load><>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <run><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <helper.dll><C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <MSPY2002><C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <KavStart><"D:\KAV2006\KAVStart.exe" -startup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <CnsMin><Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <SearchNet_Up><"C:\Program Files\SearchNet\ServeUp.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <CdnCtr><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <I2U6P5><C:\WINDOWS\system32\TVIDLV.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <AddrPlus3><C:\PROGRA~1\TENCENT\Adplus\stup.exe C:\PROGRA~1\TENCENT\Adplus\Adplus.dll Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <HNETPOLCY><rundll32.exe C:\DOCUME~1\user\LOCALS~1\Temp\RarSFX2\HNETPO~1.DLL,Start>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
  <DTService><rundll32.exe C:\DOCUME~1\user\LOCALS~1\Temp\XP44TM~1.DLL,Load>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
  <ip_sec><rundll32.exe C:\PROGRA~1\COMMON~1\system\msdc32.dll,_S1>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
  <HNETPOLCY><rundll32.exe C:\DOCUME~1\user\LOCALS~1\Temp\RarSFX2\HNETPO~1.DLL,Start>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
  <MSNETPOLICY><rundll32.exe C:\WINDOWS\system32\HNETPO~1.DLL,applyDefaultPolicy>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
  <CNETHELPER><rundll32.exe C:\PROGRA~1\COMMON~1\system\msdc32.dll,_S1>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <AppInit_DLLs><>

gototop
 

==================================
启动文件夹
[IE-BAR]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\IE-BAR.lnk><N>

==================================
服务
[BusinessC / BusinessContinuity]
  <"C:\WINDOWS\msstl.exe"><N/A>
[GrayPigeon_Hacker.com.cn / GrayPigeon_Hacker.com.cn]
  <C:\WINDOWS\52cn.exe><N/A>
[Distributed Application Client / MOBILL]
  <C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
[Print Server / Print Server]
  <C:\Program Files\HgzServer\Print.exe><N/A>
[QQFace / QQFace]
  <C:\Program Files\Common Files\SAND\qqfacerclient.exe><N/A>
[Remote Lo / Remote Log]
  <system32\ServeHost.exe><北京中搜在线软件有限公司>
[Network System / Universal Disk Manager]
  <C:\Program Files\Common Files\COMM\Network.exe><COMENET TECHNOLOGY>

==================================
浏览器加载项
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[MonitorURL Class]
  {08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, >
[CPub Object]
  {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} <C:\Program Files\P4P\sodaie.dll, N/A>
[Zhongsou Browser Helper]
  {2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[Yahoo!Photo]
  {33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll, Yahoo.>
[IE Browser Helper]
  {3CE496D1-1746-41CD-9489-3C0B93DF10E2} <C:\WINDOWS\Downlo~1\IEHpr.dll, 中搜在线软件有限公司>
[雅虎助手]
  {406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll, Yahoo!>
[Router Layer]
  {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} <C:\WINDOWS\System32\aclayer.dll, Microsoft Corporation>
[DragSearch BHO]
  {62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL, >
[DDDMon Class]
  {6BDE1669-B490-48E3-B668-456314F2D6C3} <C:\Program Files\DuDu\DddClient\dddiemon.dll, DuDu.com>
[ADefaultSearch Class]
  {944864A5-3916-46E2-96A9-A2E84F3F1208} <C:\Program Files\Accoona\ASearchAssist.dll, N/A>
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~1\FLASHGET\jccatch.dll, Amaze Soft>
[CnsHook Class]
  {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\downlo~1\CnsHook.dll, 北京三七二一科技有限公司>
[Yahoo 1G电邮]
  {507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A>
[寻宝乐趣多]
  {59BC54A2-56B3-44a0-93E5-432D58746E26} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao, N/A>
[雅虎助手]
  {5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, N/A>
[情景聊天]
  {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/, N/A>
[]
  {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A>
[]
  {FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A>
[雅虎助手]
  {406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll, Yahoo!>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[MonitorURL Class]
  {08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, >
[CPub Object]
  {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} <C:\Program Files\P4P\sodaie.dll, N/A>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[Zhongsou Browser Helper]
  {2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[Yahoo!Photo]
  {33BBE430-0E42-4F12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll, Yahoo.>
[IE Browser Helper]
  {3CE496D1-1746-41CD-9489-3C0B93DF10E2} <C:\WINDOWS\Downlo~1\IEHpr.dll, 中搜在线软件有限公司>
[雅虎助手]
  {406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll, Yahoo!>
[Yahoo!Live]
  {57421194-58FB-49AE-9B4F-FD48869B9AD4} <C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll, >
[Router Layer]
  {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} <C:\WINDOWS\System32\aclayer.dll, Microsoft Corporation>
[DragSearch BHO]
  {62EED7C6-9F02-42F9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL, >
[Microsoft 外壳 UI 帮助程序]
  {64AB4BB7-111E-11D1-8F79-00C04FC2FBE1} <%SystemRoot%\system32\shdocvw.dll, N/A>
[DDDMon Class]
  {6BDE1669-B490-48E3-B668-456314F2D6C3} <C:\Program Files\DuDu\DddClient\dddiemon.dll, DuDu.com>
[Active Desktop Mover]
  {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[AutoLive]
  {7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2} <C:\Program Files\3721\AutoLive.dll, >
[ADefaultSearch Class]
  {944864A5-3916-46E2-96A9-A2E84F3F1208} <C:\Program Files\Accoona\ASearchAssist.dll, N/A>
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~1\FLASHGET\jccatch.dll, Amaze Soft>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[CnsHook Class]
  {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\downlo~1\CnsHook.dll, 北京三七二一科技有限公司>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[Messenger Class]
  {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <, N/A>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[添加到雅虎订阅(&Y)]
  <res://C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yrss.dll/YRSSMENUEXT, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\qq\SendMMS.htm, N/A>
[雅虎搜索]
  <res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246, N/A>
gototop
 

正在运行的进程
[PID: 456][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 528][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 572][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 584][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 748][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 796][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 948][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 980][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1076][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\ZLMhp1.DLL]  <Zenographics><5, 51, 1203, 0>
    [C:\WINDOWS\system32\ZLM.dll]  <Zenographics, Inc.><5, 50, 1416, 0>
    [C:\WINDOWS\system32\ZPJL.dll]  <Zenographics, Inc.><1, 0, 1410, 1>
    [C:\WINDOWS\system32\ZSPOOL.dll]  <Zenographics, Inc.><5, 51, 709, 0>
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\IMFPrint.DLL]  <Zenographics, Inc.><5, 50, 1606, 0>
    [C:\WINDOWS\system32\Imf32.dll]  <Zenographics, Inc.><5, 51, 405, 0>
    [C:\WINDOWS\system32\ZTAG32.dll]  <Zenographics, Inc.><5, 50, 1725, 0>
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll]  <Windows (R) 2000 DDK provider><5.00.2195.1620>
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\ZPPPCL.DLL]  <Zenographics, Inc.><5, 51, 710, 0>
    [C:\WINDOWS\system32\ZPP.dll]  <Zenographics, Inc.><5, 51, 709, 0>
    [C:\WINDOWS\system32\ZGDI32.dll]  <Zenographics, Inc.><5, 51, 628, 0>
[PID: 1448][C:\WINDOWS\system32\Rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\WINDOWS\downlo~1\CnsMinIO.dll]  <北京三七二一科技有限公司><1, 0, 3, 5>
    [C:\WINDOWS\downlo~1\cnsio.dll]  <北京三七二一科技有限公司><1, 0, 2, 6>
    [D:\KAV2006\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
    [C:\WINDOWS\system32\mswosck.dll]  <N/A><N/A>
[PID: 1556][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1572][C:\WINDOWS\SYSTEM32\RUNDLL32.EXE]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1724][C:\Program Files\Common Files\SAND\qqfacerclient.exe]  <N/A><N/A>
[PID: 1740][C:\WINDOWS\system32\ServeHost.exe]  <北京中搜在线软件有限公司><1, 0, 2, 4>
[PID: 1776][C:\Program Files\Common Files\COMM\Network.exe]  <COMENET TECHNOLOGY><1, 563, 15, 5>
[PID: 1816][C:\Program Files\SearchNet\SearchNet.exe]  <中搜在线><1, 0, 2, 4>
    [C:\Program Files\SearchNet\SrvNet32.dll]  <N/A><N/A>
[PID: 880][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1260][C:\WINDOWS\system32\msime.exe]  <Microsoft Corporation><5.1.2600.2180>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 6, 1012>
    [D:\KAV2006\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
    [C:\WINDOWS\system32\mswosck.dll]  <N/A><N/A>
[PID: 1268][C:\WINDOWS\system32\winmer.exe]  <Microsoft Corporation><5.1.2600.0>
[PID: 1256][C:\WINDOWS\system32\rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 6, 1012>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\PROGRA~1\3721\AutoLive.dll]  <><1, 1, 2, 1023>
    [D:\KAV2006\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
    [C:\WINDOWS\system32\mswosck.dll]  <N/A><N/A>
[PID: 432][D:\KAV2006\KAVStart.exe]  <Kingsoft Corporation><2005, 11, 22, 183>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 6, 1012>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [D:\KAV2006\KAVIPC2.DLL]  <Kingsoft Corporation><2004, 12, 28, 20>
    [D:\KAV2006\KAVPassp.dll]  <Kingsoft Corporation><2005, 11, 22, 221>
    [D:\KAV2006\PopSprt3.dll]  <Kingsoft Corporation><2005, 11, 8, 28>
    [D:\KAV2006\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
    [C:\WINDOWS\system32\mswosck.dll]  <N/A><N/A>
[PID: 1492][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3249>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 6, 1012>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [D:\KAV2006\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
    [C:\WINDOWS\system32\mswosck.dll]  <N/A><N/A>
[PID: 1540][C:\WINDOWS\system32\TVIDLV.exe]  <N/A><N/A>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 6, 1012>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\WINDOWS\system32\mswosck.dll]  <N/A><N/A>
    [C:\Program Files\SearchNet\SrvNet32.dll]  <N/A><N/A>
    [D:\KAV2006\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
[PID: 1668][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 6, 1012>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\WINDOWS\system32\mswosck.dll]  <N/A><N/A>
    [D:\KAV2006\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
[PID: 1772][C:\Program Files\Messenger\msmsgs.exe]  <Microsoft Corporation><4.7.3000>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 6, 1012>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\WINDOWS\system32\mswosck.dll]  <N/A><N/A>
    [D:\KAV2006\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
[PID: 1764][D:\KAV2006\KMailMon.EXE]  <Kingsoft Corporation><2005, 10, 8, 85>
    [D:\KAV2006\KAntiSpm.dll]  <N/A><1, 0, 0, 2>
    [D:\KAV2006\KAVIPC2.DLL]  <Kingsoft Corporation><2004, 12, 28, 20>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 6, 1012>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\WINDOWS\system32\mswosck.dll]  <N/A><N/A>
    [D:\KAV2006\KAECall2.DLL]  <Kingsoft Corporation><2004, 12, 28, 7>
    [D:\KAV2006\KAEPlat.DLL]  <Kingsoft Corp.><2004, 11, 26, 53>
    [D:\KAV2006\KAEMem.DAT]  <Kingsoft><2004, 11, 9, 11>
    [D:\KAV2006\KAConfig.DLL]  <Kingsoft Corporation><2005, 3, 23, 30>
    [D:\KAV2006\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
[PID: 928][C:\WINDOWS\Javas\msnmon.exe]  <><1, 0, 0, 1>
[PID: 1056][C:\WINDOWS\alcupd\alcupd.exe]  <><1, 0, 0, 1>
[PID: 1760][C:\WINDOWS\system32\rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Progra~1\IE-BAR\Cast\dmipn.dll]  <千橡互联><2, 1, 4, 0>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 6, 1012>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\WINDOWS\system32\mswosck.dll]  <N/A><N/A>
    [C:\Progra~1\IE-BAR\Cast\dmshell.dll]  <千橡互联><2, 1, 4, 0>
    [C:\Progra~1\IE-BAR\Cast\215~1.0\dmplayer.dll]  <千橡互联><2, 1, 5, 0>
    [D:\KAV2006\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
[PID: 1828][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 6, 1012>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\WINDOWS\system32\mswosck.dll]  <N/A><N/A>
    [D:\KAV2006\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
[PID: 184][C:\Program Files\Internet Explorer\lib\u88setup.exe]  <><1, 0, 0, 1>
[PID: 236][C:\WINDOWS\explorer.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 6, 1012>
    [C:\PROGRA~1\3721\alrex.dll]  <><1, 0, 1, 1001>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [D:\KAV2006\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
    [C:\WINDOWS\system32\mswosck.dll]  <N/A><N/A>
    [C:\Program Files\SearchNet\SrvNet32.dll]  <N/A><N/A>
[PID: 2604][C:\Documents and Settings\user\桌面\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 6, 1012>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [D:\KAV2006\KASocket.dll]  <Kingsoft Corporation><2005, 2, 22, 233>
    [C:\WINDOWS\system32\mswosck.dll]  <N/A><N/A>
    [C:\Program Files\SearchNet\SrvNet32.dll]  <N/A><N/A>

==================================
文件关联
.TXT  Error. [C:\WINDOWS\system32\impai.exe "%1"]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
gototop
 

关闭所有浏览窗口以及一些不必要的程序
运行System Repair Engineer,使用“系统修复,文件关联,勾选“全选”点“修复”使所有扩展名都恢复正常
进入控制面版的添加删除程序中卸载,中搜(好像也叫划词搜索,网络猪的,有的话都卸载)卸载,桌面传媒。
添加删除程序,卸载桌面传媒。如果没有它的卸载项。
建议你下载超级兔子。
下载超级兔子http://dl.pconline.com.cn/html_2/1/75/id=273&pn=0.html
安装好后,打开“超级兔子优化王”“专业卸载,卸载 桌面传媒等流氓软件。
[BusinessC / BusinessContinuity]
<"C:\WINDOWS\msstl.exe"><N/A>
[GrayPigeon_Hacker.com.cn / GrayPigeon_Hacker.com.cn]
<C:\WINDOWS\52cn.exe><N/A>
[Distributed Application Client / MOBILL]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
Network System / Universal Disk Manager]
<C:\Program Files\Common Files\COMM\Network.exe><COMENET TECHNOLOGY>
针对以上四项,如果你不知道,就要修复。
运行System Repair Engineer,点“启动项目,服务,勾选“隐藏微软服务”选中病毒服务Network System,Distributed Application Client,GrayPigeon_Hacker.com.cn,BusinessC选择“删除所选服务”“否”最后重启。(每一个逗号隔开的就是一个病毒的服务,请逐一删除)
ALT+CTRL+DEL调出任务管理器,终止所有RUNDLL32.EXE 的进程,以及winlogin.exe
weiba.exe
svchs0t.exe
msnmon.exe
u88setup.exe
NIW.exe的进程(如果有的话。)
关闭所有浏览窗口以及一些不必要的程序
运行System Repair Engineer,使用“启动项目,注册表”来删除以下选项。
(如果在注册表里无法识别那一下,可以选中一项后,点“编辑”这样会有很明细的路径)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<HNETPOLCY><rundll32.exe C:\DOCUME~1\user\LOCALS~1\Temp\RarSFX2\HNETPO~1.DLL,Start>
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<HNETPOLCY><rundll32.exe C:\DOCUME~1\user\LOCALS~1\Temp\RarSFX2\HNETPO~1.DLL,Start>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<DTService><rundll32.exe C:\DOCUME~1\user\LOCALS~1\Temp\XP44TM~1.DLL,Load>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<HNETPOLCY><rundll32.exe C:\DOCUME~1\user\LOCALS~1\Temp\RarSFX2\HNETPO~1.DLL,Start>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<ip_sec><rundll32.exe C:\PROGRA~1\COMMON~1\system\msdc32.dll,_S1>
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<I2U6P5><C:\WINDOWS\system32\TVIDLV.exe>(这一项不知,如果你也不知道,建议删除。)
运行System Repair Engineer,使用“系统修复,浏览器加载项”来删除以下选项。
[Zhongsou Browser Helper]
{2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software
Router Layer]
{5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} <C:\WINDOWS\System32\aclayer.dll, Microsoft Corporation
双击我的电脑--工具---文件夹选项--查看选项卡--单击选取"显示隐藏文件或文件夹"清

除"隐藏受保护的操作系统文件(推荐)"复选框。在提示您确定更改时,单击“是”
(请按上述步骤操作,不要略过)
然后找到如下文件并删除(如果有的话)
C:\DOCUME~1\user\LOCALS~1\Temp(删除里面所有的东东,删除不了的就算了。)
C:\PROGRA~1\COMMON~1\system\msdc32.dll这项似乎很顽固。一会发个在网上搜来的帖子。
C:\WINDOWS\System32\aclayer.dll
C:\WINDOWS\system32\TVIDLV.exe自己确定是否需要。
C:\WINDOWS\msstl.exe
C:\WINDOWS\52cn.exe
C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL
C:\WINDOWS\system32\impai.exe
C:\Program Files\SearchNet

修复后,请重启,再扫个报告粘上来。
gototop
 

下面这一部分你让我修复,我不知道如何修复,用SRE还是Hijackthis? 请指教。
[BusinessC / BusinessContinuity]
<"C:\WINDOWS\msstl.exe"><N/A>
[GrayPigeon_Hacker.com.cn / GrayPigeon_Hacker.com.cn]
<C:\WINDOWS\52cn.exe><N/A>
[Distributed Application Client / MOBILL]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
Network System / Universal Disk Manager]
<C:\Program Files\Common Files\COMM\Network.exe><COMENET TECHNOLOGY>

在按照你说的运行System Repair Engineer,点“启动项目,服务,勾选“隐藏微软服务”选中病毒服务时,里面有个灰鸽子的,我是不是中了病毒了?

你让我删除的C:\WINDOWS\msstl.exe,在WINDOWS下没有?
还有就是C:\Program Files\SearchNet删除不了?

下面是扫描日志:

2006-05-06,14:36:32

System Repair Engineer 2.0.12.350 (2.0 RC 1)
    Windows XP Professional Service Pack 2 - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <update8><; C:\WINDOWS\aupdate.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <alcupd.exe><; C:\WINDOWS\alcupd\alcupd.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <NIW><; C:\WINDOWS\NIW.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <load><>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <run><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <helper.dll><; C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <MSPY2002><; C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <KavStart><; "D:\KAV2006\KAVStart.exe" -startup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <CnsMin><; Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <SearchNet_Up><"C:\Program Files\SearchNet\ServeUp.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <CdnCtr><; >
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <KernelFaultCheck><; %systemroot%\system32\dumprep 0 -k>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <I2U6P5><C:\WINDOWS\system32\TVIDLV.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
  <MSNETPOLICY><; rundll32.exe C:\WINDOWS\system32\HNETPO~1.DLL,applyDefaultPolicy>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
  <CNETHELPER><; rundll32.exe C:\PROGRA~1\COMMON~1\system\msdc32.dll,_S1>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <AppInit_DLLs><>

==================================
启动文件夹
[IE-BAR]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\IE-BAR.lnk><N>
[腾讯QQ]
  <C:\Documents and Settings\user\「开始」菜单\程序\启动\腾讯QQ.lnk><N>

==================================
服务
[Remote Lo / Remote Log]
  <system32\ServeHost.exe><北京中搜在线软件有限公司>
gototop
 

浏览器加载项
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[MonitorURL Class]
  {08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, >
[CPub Object]
  {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} <C:\Program Files\P4P\sodaie.dll, N/A>
[Zhongsou Browser Helper]
  {2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[Yahoo!Photo]
  {33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll, Yahoo.>
[IE Browser Helper]
  {3CE496D1-1746-41CD-9489-3C0B93DF10E2} <C:\WINDOWS\Downlo~1\IEHpr.dll, 中搜在线软件有限公司>
[雅虎助手]
  {406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll, Yahoo!>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[DragSearch BHO]
  {62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL, >
[DDDMon Class]
  {6BDE1669-B490-48E3-B668-456314F2D6C3} <C:\Program Files\DuDu\DddClient\dddiemon.dll, DuDu.com>
[ADefaultSearch Class]
  {944864A5-3916-46E2-96A9-A2E84F3F1208} <C:\Program Files\Accoona\ASearchAssist.dll, N/A>
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~1\FLASHGET\jccatch.dll, Amaze Soft>
[CnsHook Class]
  {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\downlo~1\CnsHook.dll, 北京三七二一科技有限公司>
[Yahoo 1G电邮]
  {507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A>
[寻宝乐趣多]
  {59BC54A2-56B3-44a0-93E5-432D58746E26} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao, N/A>
[雅虎助手]
  {5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[情景聊天]
  {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/, N/A>
[]
  {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A>
[]
  {FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A>
[雅虎助手]
  {406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll, Yahoo!>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[MonitorURL Class]
  {08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, >
[CPub Object]
  {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} <C:\Program Files\P4P\sodaie.dll, N/A>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[Zhongsou Browser Helper]
  {2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[Yahoo!Photo]
  {33BBE430-0E42-4F12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll, Yahoo.>
[IE Browser Helper]
  {3CE496D1-1746-41CD-9489-3C0B93DF10E2} <C:\WINDOWS\Downlo~1\IEHpr.dll, 中搜在线软件有限公司>
[雅虎助手]
  {406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll, Yahoo!>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Yahoo!Live]
  {57421194-58FB-49AE-9B4F-FD48869B9AD4} <C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll, >
[DragSearch BHO]
  {62EED7C6-9F02-42F9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL, >
[Microsoft 外壳 UI 帮助程序]
  {64AB4BB7-111E-11D1-8F79-00C04FC2FBE1} <%SystemRoot%\system32\shdocvw.dll, N/A>
[DDDMon Class]
  {6BDE1669-B490-48E3-B668-456314F2D6C3} <C:\Program Files\DuDu\DddClient\dddiemon.dll, DuDu.com>
[Active Desktop Mover]
  {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[AutoLive]
  {7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2} <C:\Program Files\3721\AutoLive.dll, >
[ADefaultSearch Class]
  {944864A5-3916-46E2-96A9-A2E84F3F1208} <C:\Program Files\Accoona\ASearchAssist.dll, N/A>
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~1\FLASHGET\jccatch.dll, Amaze Soft>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[CnsHook Class]
  {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\downlo~1\CnsHook.dll, 北京三七二一科技有限公司>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[Messenger Class]
  {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <, N/A>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[添加到雅虎订阅(&Y)]
  <res://C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yrss.dll/YRSSMENUEXT, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\qq\SendMMS.htm, N/A>
[雅虎搜索]
  <res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246, N/A>
gototop
 

正在运行的进程
[PID: 456][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 504][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 528][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 572][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 584][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 740][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 796][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 940][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 980][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1156][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\ZLMhp1.DLL]  <Zenographics><5, 51, 1203, 0>
    [C:\WINDOWS\system32\ZLM.dll]  <Zenographics, Inc.><5, 50, 1416, 0>
    [C:\WINDOWS\system32\ZPJL.dll]  <Zenographics, Inc.><1, 0, 1410, 1>
    [C:\WINDOWS\system32\ZSPOOL.dll]  <Zenographics, Inc.><5, 51, 709, 0>
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\IMFPrint.DLL]  <Zenographics, Inc.><5, 50, 1606, 0>
    [C:\WINDOWS\system32\Imf32.dll]  <Zenographics, Inc.><5, 51, 405, 0>
    [C:\WINDOWS\system32\ZTAG32.dll]  <Zenographics, Inc.><5, 50, 1725, 0>
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll]  <Windows (R) 2000 DDK provider><5.00.2195.1620>
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\ZPPPCL.DLL]  <Zenographics, Inc.><5, 51, 710, 0>
    [C:\WINDOWS\system32\ZPP.dll]  <Zenographics, Inc.><5, 51, 709, 0>
    [C:\WINDOWS\system32\ZGDI32.dll]  <Zenographics, Inc.><5, 51, 628, 0>
[PID: 1396][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\Program Files\SearchNet\SrvNet32.dll]  <N/A><N/A>
    [D:\KAV2006\KAVEXT.DLL]  <Kingsoft Corporation><2005, 8, 5, 16>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ywiper.dll]  <N/A><1, 0, 1, 1014>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  <><2, 1, 4, 1044>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  < ><2, 0, 1, 1007>
    [C:\PROGRA~1\FLASHGET\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
[PID: 1456][C:\WINDOWS\system32\Rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\WINDOWS\downlo~1\CnsMinIO.dll]  <北京三七二一科技有限公司><1, 0, 3, 5>
    [C:\WINDOWS\downlo~1\cnsio.dll]  <北京三七二一科技有限公司><1, 0, 2, 6>
[PID: 1472][C:\WINDOWS\system32\msime.exe]  <Microsoft Corporation><5.1.2600.2180>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
[PID: 1604][C:\WINDOWS\system32\ServeHost.exe]  <北京中搜在线软件有限公司><1, 0, 2, 4>
[PID: 1700][C:\Program Files\SearchNet\ServeUp.exe]  <中搜在线><1, 0, 2, 4>
[PID: 1860][C:\Program Files\SearchNet\SearchNet.exe]  <中搜在线><1, 0, 2, 4>
    [C:\Program Files\SearchNet\SrvNet32.dll]  <N/A><N/A>
[PID: 396][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 708][C:\WINDOWS\system32\winmer.exe]  <Microsoft Corporation><5.1.2600.0>
[PID: 852][C:\WINDOWS\system32\rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Progra~1\IE-BAR\Cast\dmipn.dll]  <千橡互联><2, 1, 4, 0>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\Progra~1\IE-BAR\Cast\dmshell.dll]  <千橡互联><2, 1, 4, 0>
    [C:\Progra~1\IE-BAR\Cast\215~1.0\dmplayer.dll]  <千橡互联><2, 1, 5, 0>
[PID: 1600][C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe]  < ><2, 0, 0, 1002>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  <><2, 1, 4, 1044>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  < ><2, 0, 1, 1007>
[PID: 1640][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
[PID: 868][C:\Downloads\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 1>
    [C:\Program Files\SearchNet\SrvNet32.dll]  <N/A><N/A>

==================================
文件关联
.TXT  Error. [C:\WINDOWS\system32\impai.exe "%1"]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
gototop
 

辛苦你了,我无邪,真的是很感谢你,帮我解决了这么多的问题,也很钦佩你懂得这么多。衷心的谢谢你。
上面是这次的扫描日志,还得辛苦你帮忙看下。
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT