瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 弹出网页 & SERVICES.EXE问题 (附日志)

1   1  /  1  页   跳转

弹出网页 & SERVICES.EXE问题 (附日志)

弹出网页 & SERVICES.EXE问题 (附日志)

时不时弹出网页如下所示,且还在不停变化中。平常用Maxthon,而这些都是通过IE弹出来的。
127.0.0.1                    www.boooc.com
127.0.0.1                    http://mm.miqiu.com/
127.0.0.1                    http://mm.miqiu.com/#g
127.0.0.1                    http://www.200266.com/

另外,进程中存在SERVICES.EXE,软件检测为可疑进程,但是删除之后,重启还会出现。存在于windows/system32/Com目录下。

以下是日志:
2006-11-11,17:32:05

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <Super Rabbit IEPro><C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD>  [Super Rabbit Soft]
    <swg><C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe>  [(Verified)Google Inc.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <wl><C:\WINDOWS\System32\svvosts.exe>  [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <Apoint><C:\Program Files\Apoint\Apoint.exe>  [(Verified)Alps Electric Co., Ltd.]
    <ATIModeChange><Ati2mdxx.exe>  [(Verified)ATI Technologies, Inc.]
    <ATIPTA><C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>  [ATI Technologies, Inc.]
    <Mouse Suite 98 Daemon><ICO.EXE>  [(Verified)Primax Electronics Ltd.]
    <BluetoothAuthenticationAgent><rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent>  [(Verified)Microsoft Corporation]
    <HKSERV.EXE><C:\Program Files\Sony\HotKey Utility\HKserv.exe>  [Sony Corporation]
    <SonyPowerCfg><C:\Program Files\Sony\VAIO Power Management\SPMgr.exe>  [Sony Corporation]
    <ISBMgr.exe><C:\Program Files\Sony\ISB Utility\ISBMgr.exe>  [Sony Corporation]
    <ezShieldProtector for Px><C:\WINDOWS\System32\ezSP_Px.exe>  [Easy Systems Japan Ltd.]
    <IMEKRMIG6.1><C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE>  [(Verified)Microsoft Corporation]
    <MSPY2002><C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC>  [(Verified)N/A]
    <ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe">  [(Verified)Symantec Corporation]
    <Symantec NetDriver Monitor><C:\PROGRA~1\SYMNET~1\SNDMon.exe>  [(Verified)Symantec Corporation]
    <WinampAgent><C:\Program Files\Winamp\winampa.exe>  [N/A]
    <DAEMON Tools-1033><"C:\Program Files\D-Tools\daemon.exe"  -lang 1033>  [DAEMON'S HOME]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  [N/A]
    <Acrobat Assistant 7.0><"C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe">  [Adobe Systems Inc.]
    <Windows木马防火墙><C:\Program Files\ftc\Trojanwall.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <KernelFaultCheck><C:\WINDOWS\winabc3.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\System32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]

==================================
启动文件夹
[Adobe Acrobat Speed Launcher]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Acrobat Speed Launcher.lnk --> C:\WINDOWS\Installer\{AC76BA86-2052-0000-7760-100000000002}\SC_Acrobat.exe [N/A]><N>

==================================
服务
[831E1E90 / 831E1E90]
  <C:\WINDOWS\System32\831E1E90.EXE -service><Microsoft Corporation>
[Application Management / AppMgmt]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[Ati HotKey Poller / Ati HotKey Poller]
  <C:\WINDOWS\System32\Ati2evxx.exe><N/A>
[Symantec Event Manager / ccEvtMgr]
  <"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc]
  <"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr]
  <"C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[E83E4700 / E83E4700]
  <C:\WINDOWS\System32\E83E4700.EXE -service><Microsoft Corporation>
[GrayPigeon_Hacker.com.cn / GrayPigeon_Hacker.com.cn]
  <C:\WINDOWS\Hacker.com.cn.exe><N/A>
[Human Interface Device Access / HidServ]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Norton AntiVirus Auto Protect Service / navapsvc]
  <"C:\Program Files\Norton AntiVirus\navapsvc.exe"><Symantec Corporation>
[PACSPTISVR / PACSPTISVR]
  <C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe><>
[SAVScan / SAVScan]
  <C:\Program Files\Norton AntiVirus\SAVScan.exe><Symantec Corporation>
[ScriptBlocking Service / SBService]
  <C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe><Symantec Corporation>
[Symantec Network Drivers Service / SNDSrvc]
  <C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe><Symantec Corporation>
[SoundMAX Agent Service / SoundMAX Agent Service (default)]
  <C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[Sony SPTI Service / SPTISRV]
  <C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe><Sony Corporation>

==================================
最后编辑2006-11-11 21:58:22
分享到:
gototop
 

驱动程序
[aeaudio / aeaudio]
  <system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[Alps Pointing-device Filter Driver / ApfiltrService]
  <System32\DRIVERS\Apfiltr.sys><Alps Electric Co., Ltd.>
[ati2mtag / ati2mtag]
  <System32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[d347bus / d347bus]
  <\SystemRoot\System32\DRIVERS\d347bus.sys><>
[d347prt / d347prt]
  <\SystemRoot\System32\Drivers\d347prt.sys><>
[Sony DMI Call service / DMICall]
  <System32\DRIVERS\DMICall.sys><Sony Corporation>
[Intel(R) PRO Adapter Driver / E100B]
  <System32\DRIVERS\e100b325.sys><Intel Corporation>
[HSFHWICH / HSFHWICH]
  <System32\DRIVERS\HSFHWICH.sys><Conexant Systems, Inc.>
[HSF_DP / HSF_DP]
  <System32\DRIVERS\HSF_DP.sys><Conexant Systems, Inc.>
[mdmxsdk / mdmxsdk]
  <System32\DRIVERS\mdmxsdk.sys><Conexant>
[NAVENG / NAVENG]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061108.024\NAVENG.Sys><Symantec Corporation>
[NAVEX15 / NAVEX15]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061108.024\NavEx15.Sys><Symantec Corporation>
[npkcrypt / npkcrypt]
  <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Pnpnt / Pnpnt]
  <\SystemRoot\System32\Drivers\pnpnt.sys><N/A>
[Direct Parallel Link Driver / Ptilink]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20]
  <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[SAVRT / SAVRT]
  <\??\C:\Program Files\Norton AntiVirus\SAVRT.SYS><Symantec Corporation>
[SAVRTPEL / SAVRTPEL]
  <\??\C:\Program Files\Norton AntiVirus\SAVRTPEL.SYS><Symantec Corporation>
[Secdrv / Secdrv]
  <System32\DRIVERS\secdrv.sys><N/A>
[smwdm / smwdm]
  <system32\drivers\smwdm.sys><Analog Devices, Inc.>
[Sony Notebook Control Device / SNC]
  <System32\Drivers\SonyNC.sys><Sony Corporation>
[Sony Programmable I/O Control Device / SPI]
  <System32\DRIVERS\SonyPI.sys><Sony Corporation>
[SymEvent / SymEvent]
  <\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV]
  <\SystemRoot\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI]
  <\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[tifmsony / tifmsony]
  <system32\drivers\tifmsony.sys><Texas Instruments>
[TSKNF700.SYS / TSKNF700.SYS]
  <\??\C:\WINDOWS\System32\Drivers\TSKNF700.SYS><Igor Arsenin>

==================================
浏览器加载项
[超级兔子上网精灵]
  {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <C:\PROGRA~1\SUPERR~1\MagicSet\haokanbar.dll, Xiang Feng Technology>
[启动迅雷]
  {0062C9BD-B349-40DE-91A0-755F37ACD559} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[相关站点]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[Norton AntiVirus]
  {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} <C:\Program Files\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[Adobe PDF]
  {47833539-D0C5-4125-9FA8-0819E2EAAC93} <C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
[超级兔子上网精灵]
  {43869BB3-22FD-4F15-9B46-238106BA2F4E} <C:\PROGRA~1\SUPERR~1\MagicSet\haokanbar.dll, Xiang Feng Technology>
[Edit Class]
  {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\System32\CMBEdit.dll, >
[AxInputControl Class]
  {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL, >
[Java Plug-in 1.4.2_03]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll, JavaSoft / Sun Microsystems, Inc.>
[Java Plug-in 1.4.2_03]
  {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} <C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll, JavaSoft / Sun Microsystems, Inc.>
[&使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
gototop
 

正在运行的进程
[PID: 748][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 836][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 880][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\Ati2evxx.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\TcpIpDog0.dll]  [N/A, N/A]
[PID: 928][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 940][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\TcpIpDog0.dll]  [N/A, N/A]
[PID: 1120][C:\WINDOWS\System32\Ati2evxx.exe]  [N/A, N/A]
[PID: 1172][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\TcpIpDog0.dll]  [N/A, N/A]
[PID: 1580][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\TcpIpDog0.dll]  [N/A, N/A]
[PID: 148][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\TcpIpDog0.dll]  [N/A, N/A]
[PID: 508][C:\WINDOWS\system32\Ati2evxx.exe]  [N/A, N/A]
[PID: 556][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1221 (xpsp2.030511-1403)]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS]  [Adobe Systems, Inc., 7.0.0.0]
    [C:\WINDOWS\System32\TcpIpDog0.dll]  [N/A, N/A]
    [C:\Program Files\Norton AntiVirus\NavShExt.dll]  [Symantec Corporation, 10.00.13]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [C:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll]  [Adobe Systems Inc., 7.0.0.2004121400\0]
    [C:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.chs]  [Adobe Systems Inc., 7.0.0.2004121400\0]
[PID: 564][C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe]  [Symantec Corporation, 2.1.10.2]
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  [Symantec Corporation, 2.1.10.2]
[PID: 768][C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe]  [Symantec Corporation, 2.1.10.2]
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  [Symantec Corporation, 2.1.10.2]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\CCSETEVT.DLL]  [Symantec Corporation, 2.1.10.2]
    [C:\PROGRA~1\NORTON~2\NAVEVENT.DLL]  [Symantec Corporation, 10.00.13]
[PID: 904][C:\Program Files\Apoint\Apoint.exe]  [Alps Electric Co., Ltd., 5.5.7.136]
    [C:\WINDOWS\System32\VXDIF.DLL]  [Alps Electric Co., Ltd., 6.0.2.65]
    [C:\Program Files\Apoint\ApWheel.dll]  [ALPS ELECTRIC CO., LTD., 4.2.0.9]
    [C:\Program Files\Apoint\Apoint.DLL]  [Alps Electric Co., Ltd., 5.5.6.177]
    [C:\Program Files\Apoint\ApRes.dll]  [Alps Electric Co., Ltd., 5.5.6.17]
    [C:\Program Files\Apoint\EzAuto.dll]  [Alps Electric Co., Ltd., 4.5.1.83]
    [C:\Program Files\Apoint\EzLaunch.DLL]  [Alps Electric Co., Ltd., 5.5.1.59]
[PID: 992][C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe]  [ATI Technologies, Inc., 6.14.10.5090]
    [C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll]  [ATI Technologies, Inc., 6.14.10.5090]
    [C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.CHS]  [ATI Technologies, Inc., 6.14.10.5090]
    [C:\Program Files\ATI Technologies\ATI Control Panel\atipdxxx.dll]  [ATI Technologies, Inc., 6.14.10.5090]
[PID: 1232][C:\Program Files\Sony\HotKey Utility\HKserv.exe]  [Sony Corporation, 4, 1, 0, 4010]
    [C:\Program Files\Common Files\Sony Shared\Sony Utilities\SnyUtils.dll]  [Sony Corporation, 4, 1, 0, 2110]
    [C:\Program Files\Sony\HotKey Utility\SuEvent.dll]  [Sony Corporation, 1, 1, 0, 2250]
    [C:\Program Files\Common Files\Sony Shared\SXBIOS\sxbios.dll]  [Sony Corporation, 4.02.8170]
    [C:\WINDOWS\System32\Atipdlxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2488]
[PID: 1240][C:\Program Files\Sony\VAIO Power Management\SPMgr.exe]  [Sony Corporation, 1.3.00.03100]
    [C:\Program Files\Sony\VAIO Power Management\SPMDAM.dll]  [Sony Corporation, 1.0.00.08250]
    [C:\Program Files\Sony\VAIO Power Management\SPMRes.dll]  [Sony Corporation, 1.3.00.03230]
    [C:\Program Files\Sony\VAIO Power Management\SPMDrv.dll]  [Sony Corporation, 1.2.00.13230]
    [C:\Program Files\Common Files\Sony Shared\Sony Utilities\SnyUtils.dll]  [Sony Corporation, 4, 1, 0, 2110]
    [C:\Program Files\Common Files\Sony Shared\SXBIOS\sxbios.dll]  [Sony Corporation, 4.02.8170]
    [C:\WINDOWS\System32\Atipdlxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2488]
[PID: 1272][C:\Program Files\Sony\ISB Utility\ISBMgr.exe]  [Sony Corporation, 1, 0, 0, 2180]
    [C:\Program Files\Common Files\Sony Shared\Sony Utilities\SnyUtils.dll]  [Sony Corporation, 4, 1, 0, 2110]
    [C:\Program Files\Sony\ISB Utility\ISBRes.dll]  [Sony Corporation, 1, 0, 0, 4080]
    [C:\Program Files\Common Files\Sony Shared\SXBIOS\sxbios.dll]  [Sony Corporation, 4.02.8170]
    [C:\WINDOWS\System32\Atipdlxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2488]
gototop
 

[PID: 1288][C:\WINDOWS\System32\ezSP_Px.exe]  [Easy Systems Japan Ltd., 1, 0, 0, 0]
[PID: 1332][C:\Program Files\Common Files\Symantec Shared\ccApp.exe]  [Symantec Corporation, 2.1.10.2]
    [C:\Program Files\Symantec\LiveUpdate\ProductRegCom.DLL]  [Symantec Corporation, 1.90.15.0]
    [C:\Program Files\Symantec\LiveUpdate\LuComServerPS.DLL]  [Symantec Corporation, 1.90.15.0]
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  [Symantec Corporation, 2.1.10.2]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\CCALERT.DLL]  [Symantec Corporation, 2.1.10.2]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\CCEMLPXY.DLL]  [Symantec Corporation, 2.1.10.2]
    [C:\WINDOWS\System32\SYMREDIR.dll]  [Symantec Corporation, 5.4.4.17]
    [C:\PROGRA~1\NORTON~2\CCIMSCAN.DLL]  [Symantec Corporation, 10.0.2.610]
    [C:\PROGRA~1\NORTON~2\DEFALERT.DLL]  [Symantec Corporation, 10.00.13]
    [C:\PROGRA~1\NORTON~2\NAVAPW32.DLL]  [Symantec Corporation, 10.00.13]
    [C:\PROGRA~1\NORTON~2\apwutil.dll]  [Symantec Corporation, 10.00.13]
    [C:\PROGRA~1\NORTON~2\SAVRT32.DLL]  [Symantec Corporation, ]
    [C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll]  [Symantec Corporation, 2.1.10.2]
    [C:\Program Files\Common Files\Symantec Shared\ccProSub.dll]  [Symantec Corporation, 2.1.10.2]
    [C:\Program Files\Norton AntiVirus\NavEmail.dll]  [Symantec Corporation, 10.0.2.610]
    [C:\WINDOWS\System32\TcpIpDog0.dll]  [N/A, N/A]
    [C:\Program Files\Norton AntiVirus\NAVOPTRF.DLL]  [Symantec Corporation, 10.00.2]
    [C:\Program Files\Norton AntiVirus\apwcmdnt.dll]  [Symantec Corporation, 10.00.13]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\ccPwd.dll]  [Symantec Corporation, 2.1.10.2]
    [C:\PROGRA~1\NORTON~2\NAVOpts.dll]  [Symantec Corporation, 10.00.13]
    [C:\PROGRA~1\NORTON~2\N32Exclu.dll]  [Symantec Corporation, 10.00.13]
    [C:\PROGRA~1\NORTON~2\S32NAVO.DLL]  [Symantec Corporation, 5.3.0.182]
    [C:\Program Files\Norton AntiVirus\NAVError.dll]  [Symantec Corporation, 10.00.13]
    [C:\Program Files\Norton AntiVirus\NAVAPSCR.dll]  [Symantec Corporation, 10.00.13]
    [C:\Program Files\Common Files\Symantec Shared\LiveReg\iraLSCl2.dll]  [Symantec Corporation, 2.4.1.2056]
    [C:\Program Files\Common Files\Symantec Shared\LiveReg\IraVcLc3.dll]  [Symantec Corporation, 2.4.1.2056]
[PID: 1452][C:\Program Files\Apoint\Apntex.exe]  [Alps Electric Co., Ltd., 5.0.1.15]
    [C:\WINDOWS\System32\VXDIF.DLL]  [Alps Electric Co., Ltd., 6.0.2.65]
[PID: 1508][C:\Program Files\D-Tools\daemon.exe]  [DAEMON'S HOME, 3.47.0.0]
    [C:\WINDOWS\daemon.dll]  [N/A, 3.47.0.0]
    [C:\Program Files\D-Tools\PFCTOC.DLL]  [Padus(R), Inc., 1, 0, 0, 12]
    [C:\Program Files\D-Tools\Plugins\Images\bw5mount.dll]  [N/A, 1.0.2.0]
    [C:\Program Files\D-Tools\Plugins\Images\ccdmount.dll]  [GENERIC, 1.02.0.0]
    [C:\Program Files\D-Tools\Plugins\Images\mdsmount.dll]  [GENERIC, 1.01.0.0]
    [C:\Program Files\D-Tools\Plugins\Images\nrgmount.dll]  [GENERIC, 1.02.0.0]
    [C:\Program Files\D-Tools\Plugins\Images\pdimount.dll]  [GENERIC, 1.01.0.0]
[PID: 1524][C:\WINDOWS\System32\conime.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1648][C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe]  [Adobe Systems Inc., 6.0.1.2004121400]
    [C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.chs]  [Adobe Systems Inc., 6.0.0.0]
[PID: 1772][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1888][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\AdobePDF.dll]  [Adobe Systems Incorporated., 7.0.0.00]
    [C:\Program Files\Adobe\Acrobat 7.0\Distillr\AdistRes.CHS]  [N/A, N/A]
[PID: 220][C:\Program Files\DrCOM\Dr.COM 宽带登录客户端\ishare_user.exe]  [N/A, N/A]
    [C:\Program Files\DrCOM\Dr.COM 宽带登录客户端\cw3220.DLL]  [Borland International, 2.0]
    [C:\WINDOWS\System32\TcpIpDog0.dll]  [N/A, N/A]
gototop
 

[PID: 352][C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe]  [Google Inc., 1, 2, 908, 5008]
    [C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\res_zh-CN.dll]  [Google Inc., 1, 2, 908, 5008]
    [C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\swg.dll]  [Google Inc., 1, 2, 908, 5008]
    [C:\WINDOWS\System32\TcpIpDog0.dll]  [N/A, N/A]
[PID: 484][C:\Program Files\Sony\HotKey Utility\HKWnd.exe]  [Sony Corporation, 4, 1, 0, 4010]
    [C:\Program Files\Sony\HotKey Utility\HKRes.dll]  [Sony Corporation, 4, 1, 0, 4010]
    [C:\Program Files\Common Files\Sony Shared\Sony Utilities\SnyUtils.dll]  [Sony Corporation, 4, 1, 0, 2110]
    [C:\Program Files\Common Files\Sony Shared\SXBIOS\sxbios.dll]  [Sony Corporation, 4.02.8170]
    [C:\WINDOWS\System32\Atipdlxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2488]
[PID: 1560][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 2164][C:\Program Files\Norton AntiVirus\navapsvc.exe]  [Symantec Corporation, 10.00.2]
    [C:\Program Files\Norton AntiVirus\SAVRT32.DLL]  [Symantec Corporation, ]
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  [Symantec Corporation, 2.1.10.2]
[PID: 2256][C:\Program Files\Norton AntiVirus\SAVScan.exe]  [Symantec Corporation, ]
    [C:\Program Files\Norton AntiVirus\SAVRT32.DLL]  [Symantec Corporation, ]
    [C:\Program Files\Common Files\Symantec Shared\ccScan.dll]  [Symantec Corporation, 2.1.10.2]
    [C:\Program Files\Common Files\Symantec Shared\ecmldr32.DLL]  [Symantec Corporation, 51.2.0.12]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061108.024\ecmsvr32.dll]  [Symantec Corporation, 61.3.0.18]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061108.024\NAVEX32a.DLL]  [Symantec Corporation, 20061.3.0.12]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061108.024\NAVENG32.DLL]  [Symantec Corporation, 20061.3.0.12]
    [C:\Program Files\Norton AntiVirus\NAVAP32.DLL]  [Symantec Corporation, ]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\DECSDK.DLL]  [Symantec Corporation, 3.02.14.08]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll]  [Symantec Corporation, 3.02.14.08]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll]  [Symantec Corporation, 3.02.14.08]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll]  [Symantec Corporation, 3.02.14.08]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll]  [Symantec Corporation, 3.02.14.08]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll]  [Symantec Corporation, 3.02.14.08]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll]  [Symantec Corporation, 3.02.14.08]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll]  [Symantec Corporation, 3.02.14.08]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll]  [Symantec Corporation, 3.02.14.08]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll]  [Symantec Corporation, 3.02.14.08]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll]  [Symantec Corporation, 3.02.14.08]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll]  [Symantec Corporation, 3.02.14.08]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll]  [Symantec Corporation, 3.02.14.08]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll]  [Symantec Corporation, 3.02.14.08]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll]  [Symantec Corporation, 3.02.14.08]
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll]  [Symantec Corporation, 3.02.14.08]
[PID: 2572][C:\WINDOWS\System32\Com\SERVICES.EXE]  [N/A, N/A]
    [C:\WINDOWS\System32\TcpIpDog0.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\scrauth.dll]  [Symantec Corporation, 1, 1, 1, 131]
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll]  [Symantec Corporation, 1, 1, 1, 131]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
[PID: 2616][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe]  [Analog Devices, Inc., 3, 2, 6, 0]
[PID: 2992][C:\Program Files\Maxthon\Maxthon.exe]  [Maxthon International Ltd., 1, 5, 2, 21]
    [C:\Program Files\Maxthon\maxzlib.dll]  [ , 1, 0, 0, 2]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
    [C:\WINDOWS\System32\TcpIpDog0.dll]  [N/A, N/A]
    [C:\Program Files\Maxthon\Services\RealTime\real_time.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\scrauth.dll]  [Symantec Corporation, 1, 1, 1, 131]
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll]  [Symantec Corporation, 1, 1, 1, 131]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS]  [Adobe Systems, Inc., 7.0.0.0]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
[PID: 1280][C:\Program Files\Super Rabbit\MagicSet\SRIEH.EXE]  [Super Rabbit Soft, 7.86.0001]
[PID: 2604][C:\WINDOWS\System32\taskmgr.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 2384][C:\download\RavNovarg.exe]  [Beijing Rising Tech. Co., Ltd., 1, 4, 0, 0]
    [C:\WINDOWS\System32\TcpIpDog0.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\scrauth.dll]  [Symantec Corporation, 1, 1, 1, 131]
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll]  [Symantec Corporation, 1, 1, 1, 131]
[PID: 248][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 708][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\PROGRA~1\SUPERR~1\MagicSet\haokanbar.dll]  [Xiang Feng Technology, 2, 2, 0, 1612]
    [C:\WINDOWS\System32\TcpIpDog0.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\scrauth.dll]  [Symantec Corporation, 1, 1, 1, 131]
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll]  [Symantec Corporation, 1, 1, 1, 131]
[PID: 3272][C:\download\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
    [C:\WINDOWS\System32\TcpIpDog0.dll]  [N/A, N/A]
[PID: 3868][C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe]  [Thunder Networking Technologies,LTD, 5.3.0.220]
    [C:\Program Files\Thunder Network\Thunder\Program\UpdateDownload.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 8]
    [C:\Program Files\Thunder Network\Thunder\Program\download_interface.dll]  [Thunder Networking Technologies,LTD, 1, 0, 4, 71]
    [C:\Program Files\Thunder Network\Thunder\Program\log4cplus.dll]  [, 1, 0, 2, 1]
    [C:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
    [C:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll]  [N/A, N/A]
    [C:\Program Files\Thunder Network\Thunder\Program\msgmanage.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 15]
    [C:\Program Files\Thunder Network\Thunder\Program\historyinfo_manage.dll]  [Thunder Networking Technologies,LTD, 5, 2, 0, 148]
    [C:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 1, 0, 18]
    [C:\Program Files\Thunder Network\Thunder\Program\FloatBar.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
    [C:\WINDOWS\System32\TcpIpDog0.dll]  [N/A, N/A]
    [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll]  [ , 1, 0, 0, 11]
    [C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed04.dll]  [ , 2, 3, 0, 37]
    [C:\Program Files\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll]  [Thunder Networking Technologies,LTD, 1, 0, 3, 8]
    [C:\Program Files\Thunder Network\Thunder\Program\iTargetAd.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 55]
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\scrauth.dll]  [Symantec Corporation, 1, 1, 1, 131]
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll]  [Symantec Corporation, 1, 1, 1, 131]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
gototop
 

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
    C:\WINDOWS\System32\TcpIpDog0.dll(N/A, N/A)
MSAFD Tcpip [UDP/IP]
    C:\WINDOWS\System32\TcpIpDog0.dll(N/A, N/A)
MSAFD Tcpip [RAW/IP]
    C:\WINDOWS\System32\TcpIpDog0.dll(N/A, N/A)
RSVP UDP Service Provider
    C:\WINDOWS\System32\TcpIpDogR0.dll(N/A, N/A)
RSVP TCP Service Provider
    C:\WINDOWS\System32\TcpIpDogR0.dll(N/A, N/A)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1                    localhost
127.0.0.1                    008.cn
127.0.0.1                    ultimate-best-hgh.0my.net
127.0.0.1                    www.139500.com
127.0.0.1                    www.1yin.net
127.0.0.1                    ****cn
127.0.0.1                    www.37021.com
127.0.0.1                    www.47555.net
127.0.0.1                    www.511ring.com
127.0.0.1                    me.5e163.com
127.0.0.1                    www.777888.com
127.0.0.1                    www.77ttt.com
127.0.0.1                    www.9p.cn
127.0.0.1                    abcdesign.ru
127.0.0.1                    gutemine.wu-wien.ac.at
127.0.0.1                    math.kobe-u.ac.jp
127.0.0.1                    www.aifind.info
127.0.0.1                    www.allyes.com
127.0.0.1                    www.aogo.net
127.0.0.1                    baltnet.ru
127.0.0.1                    quotes.barchart.com
127.0.0.1                    free.bestialityhost.com
127.0.0.1                    cctv1.net
127.0.0.1                    cctv8.net
127.0.0.1                    www.cctv8.net
127.0.0.1                    ciachoo.pl
127.0.0.1                    www.play.cn.gs
127.0.0.1                    www.cnqb.net
127.0.0.1                    www.xiliao.com.cn
127.0.0.1                    alexey.pioneers.com.ru
127.0.0.1                    www.coolcdrom.com
127.0.0.1                    www.coolseach.com
127.0.0.1                    puldk490gj.da.ru
127.0.0.1                    dicto.ru
127.0.0.1                    www.dj3344.com
127.0.0.1                    www.donttrip.org
127.0.0.1                    www.ehomeday.com
127.0.0.1                    elemental.ru
127.0.0.1                    errorguard.com
127.0.0.1                    friendlygreeting.com
127.0.0.1                    zhp.gdynia.pl
127.0.0.1                    www.gg888.net
127.0.0.1                    gin.ru
127.0.0.1                    www.girlchinese.com
127.0.0.1                    glass-master.ru
127.0.0.1                    photo.gornet.ru
127.0.0.1                    relay.great.ru
127.0.0.1                    hack-gegen-rechts.com
127.0.0.1                    hgrstrailer.com
127.0.0.1                    www.homepage.com
127.0.0.1                    hotbar.com
127.0.0.1                    intellect.lvc
127.0.0.1                    interfoodtd.ru
127.0.0.1                    jewishgen.org
127.0.0.1                    www.jixian.net
127.0.0.1                    k2kapital.com
127.0.0.1                    security.kolla.de
127.0.0.1                    www.kuliao.com
127.0.0.1                    laugh-mail.net
127.0.0.1                    marketscore.com
127.0.0.1                    www.mir0.com
127.0.0.1                    momentum.ru
127.0.0.1                    www.mtv51.com
127.0.0.1                    www.mydj2005.com
127.0.0.1                    nefkom.net
127.0.0.1                    no-abi2003.de
127.0.0.1                    tdi-router.opola.pl
127.0.0.1                    packages.debian.or.jp
127.0.0.1                    perfectgirls.net
127.0.0.1                    peterstar.ru
127.0.0.1                    pgipearls.com
127.0.0.1                    phg.pl
127.0.0.1                    vip.pnet.pl
127.0.0.1                    sec.polbox.pl
127.0.0.1                    polobeer.de
127.0.0.1                    porno-mania.net
127.0.0.1                    home.profootball.ru
127.0.0.1                    qianbai.com
127.0.0.1                    ad.qingyule.com
127.0.0.1                    www.qq168.net
127.0.0.1                    www.qq3344.com
127.0.0.1                    www.qq92.com
127.0.0.1                    www.qqwz.com
127.0.0.1                    www.qu123.com
127.0.0.1                    republika.pl
127.0.0.1                    www.richfind.com
127.0.0.1                    rollenspielzirkel.de
127.0.0.1                    safer-networking.org
127.0.0.1                    sdsauto.ru
127.0.0.1                    www.searchpage.cc
127.0.0.1                    www.seekeasysoft.net
127.0.0.1                    shadkhan.ru
127.0.0.1                    slavarik.ru
127.0.0.1                    sovea.de
127.0.0.1                    spybot.info
127.0.0.1                    www.start-page.info
127.0.0.1                    lars-s.privat.t-online.de
127.0.0.1                    u.t2cn.com
127.0.0.1                    it.trendmicro-europe.com
127.0.0.1                    trendmicro.it
127.0.0.1                    truefriends.net
127.0.0.1                    www.tthao.com
127.0.0.1                    www.ttrx.net
127.0.0.1                    tuhart.net
127.0.0.1                    www.unionsky.cn
127.0.0.1                    www.unionsky.com
127.0.0.1                    www.unionsky.net
127.0.0.1                    vconsole.net
127.0.0.1                    virtumonde.com
127.0.0.1                    gamma.vyborg.ru
127.0.0.1                    financial.washingtonpost.com
127.0.0.1                    webpark.pl
127.0.0.1                    wishken.com
127.0.0.1                    www.yeapple.com
127.0.0.1                    www.yibinren.com
127.0.0.1                    www.youmiss.com
127.0.0.1                    www.yysky.net
127.0.0.1                    zelnet.ru
127.0.0.1                    www.zhengdian.com
127.0.0.1                    abc.265.com
127.0.0.1                    555.265.com
127.0.0.1                    www.boooc.com
127.0.0.1                    http://mm.miqiu.com/
127.0.0.1                    http://mm.miqiu.com/#g
127.0.0.1                    http://www.200266.com/

==================================
gototop
 

运行(双击)SRENG2,点“启动项目,服务,点“Win32服务应用程序”
勾选“隐藏微软服务”选中病毒服务
831E1E90
E83E4700
Application Management
GrayPigeon_Hacker.com.cn
,选择“删除服务”
点“设置”选择“否”
运行SREng2,使用“启动项目”--注册表--删除
C:\WINDOWS\System32\svvosts.exe
C:\WINDOWS\winabc3.exe
运行SREng2,使用“启动项目”--启动文件夹--删除
Adobe Acrobat Speed Launcher]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Acrobat Speed Launcher.lnk --> C:\WINDOWS\Installer\{AC76BA86-2052-0000-7760-100000000002}\SC_Acrobat.exe [N/A]><N>

重启按F8进入安全模式下修复
显示隐藏文件
删除:               
C:\WINDOWS\System32\831E1E90.EXE       
C:\WINDOWS\System32\E83E4700.EXE
-->%SystemRoot%\System32\appmgmts.dll
C:\WINDOWS\Hacker.com.cn.exe用冰刃删除
C:\WINDOWS\System32\svvosts.exe
C:\WINDOWS\winabc3.exe
C:\WINDOWS\Installer\{AC76BA86-2052-0000-7760-100000000002}\SC_Acrobat.exe
gototop
 

我现在就去试试 谢了呢^^
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT