瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求助,多了个rundllforour的进程,瑞星启动不了啊

12   1  /  2  页   跳转

求助,多了个rundllforour的进程,瑞星启动不了啊

求助,多了个rundllforour的进程,瑞星启动不了啊

如题,而且文件夹也不能显示隐藏文件了,上网还会莫名其妙的重启,望高手指点啊
最后编辑2007-07-02 21:47:27
分享到:
gototop
 

下载 System Repair Engineer系统扫描工具软件,下载地址如下:
http://www.kztechs.com/sreng/download.html
扫描和上传日志的方法:
1、解压缩所下载的sreng2.zip压缩包;
2、请确认当前你机的系统时间是和真实时间一致的,如果被病毒篡改为1980年、1990年、2005年等不正常的时间(这里先要排除主板电池没电的原因,辨别方法是看BIOS中的时间和登陆系统后系统显示的时间是否一致,如果不一致则为病毒影响,如果一致则可能电池没电),请双击系统托盘的时间图标将系统时间改为正常。
3、打开已经解压缩的SRENG文件夹,双击运行其中的SREng.exe(如果不能运行,请删除已经用压缩包解压的SRENG文件夹和其包含的所有文件,重新下载新的压缩包或用已下载的压缩包重新解压,解压时请将解压后的文件夹名改为111,解压后,进入111文件夹,不要运行其中的SREng.exe这个可执行文件,先将其直接改名为111.bat、111.scr、111.com或111.pif,或者改为111.exe,然后再双击运行);
4、依次按“智能扫描”、“扫描”、“保存报告”,将日志保存到硬盘上;
5、找到并打开日志,把日志中的内容用“复制”--“粘贴”命令拷贝到帖子上,不要修改地传上来(日志很长,一个帖子搞不完,请手动将全部内容在同一个主题帖下分多个回复帖子传上来)。
友情提示:
1、扫描日志前请先关闭所有打开的软件(如QQ、迅雷等下载程序什么的程序)和IE窗口(请注意,是彻底关闭而不是最小化窗口)。谁再在开着QQ的情况下扫日志我跟谁急!
2、注意在没有进一步提示前,请勿用SRENG工具胡乱修复,否则系统可能变的情况更糟。
3、SRENG操作图文详解:http://forum.ikaka.com/topic.asp?board=67&artid=8125594
gototop
 

我的机子都不能下了啊,还要用的别人的机器下的,郁闷啊
这是报告
[CODE]

2007-07-02,15:11:45

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <SMcfg><smcfg.exe -s>  []
    <SoundMan><SOUNDMAN.EXE>  [(Verified)Microsoft Windows Publisher]
    <SiSPower><Rundll32.exe SiSPower.dll,ModeAgent>  [Silicon Integrated Systems Corporation]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><qhbpri.dll>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{EC43866E-866E-C43F-6EC4-66E4366EC43F}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\866EC43F.dll>  []
    <{26368135-64FA-BC34-DA32-DCF4FD431C92}><C:\WINDOWS\system32\qhbpri.dll>  []
    <{91B1E846-2BEF-4345-8848-7699C7C9935F}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysWFGQQ2.dll>  []
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\demo.scr>  [Goldshell Digital Media]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <CameraFixer><; C:\WINDOWS\CameraFixer.exe>  []
    <hxgame-update><; >  [N/A]
    <KernelFaultCheck><; %systemroot%\system32\dumprep 0 -k>  [N/A]
    <Knight V><; D:\超级兔子\MagicSet\SRFC.EXE /Load>  [Super Rabbit Soft]
    <miniqqlive><; "C:\Program Files\Tencent\QQLive\MiniQQLive.exe">  [N/A]
    <RavAV><; >  [N/A]
    <snp325><; C:\WINDOWS\vsnp325.exe>  []
    <StormCodec_Helper><; "D:\Storm Codec\StormSet.exe" /S /opti>  [N/A]
    <Super Rabbit SafeEdit><; D:\超级兔子\MagicSet\SRFC.EXE /Load>  [Super Rabbit Soft]
    <System><; C:\Program Files\Common Files\system\Updaterun.exe>  []
    <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [(Verified)"RealNetworks, Inc."]
    <tsnpstd325><; C:\WINDOWS\tsnp325.exe>  []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <xg3m.exe><; C:\WINDOWS\system32\xg3m.exe C:\WINDOWS\system32\drivers\xgzi.sys Rundll32>  [N/A]
gototop
 

服务
[LightScribeService Direct Disc Labeling Service / LightScribeService][Stopped/Disabled]
  <"C:\Program Files\Common Files\LightScribe\LSSrvc.exe"><Hewlett-Packard Company>
[QoS Service / Mercha2][Stopped/Auto Start]
  <><N/A>
[Fax 2Client / ms_2fax][Stopped/Auto Start]
  <><N/A>
[Rising Proxy  Service / RfwProxySrv][Stopped/Disabled]
  <d:\rising\rfw\rfwproxy.exe><N/A>
[Rising Personal Firewall Service / RfwService][Stopped/Disabled]
  <d:\rising\rfw\rfwsrv.exe><N/A>
[Rising Process Communication Center / RsCCenter][Stopped/Disabled]
  <"D:\Rising\Rav\CCenter.exe"><N/A>
[Rising RealTime Monitor / RsRavMon][Stopped/Disabled]
  <"D:\RISING\RAV\Ravmond.exe"><N/A>
[System Recover Servic / SysreSrv][Stopped/Disabled]
  <sysresrv.exe><N/A>
[Clipboard / Tech][Running/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\ngkty.dll><Microsoft Corporation>
[Windows tfpf RunThem / tfpf][Running/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\oaka\ykuk.dll>< >

==================================
驱动程序
[acpidisk / acpidisk][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[cdnprot / cdnprot][Running/Boot Start]
  <\SystemRoot\system32\drivers\cdnprot.sys><中国互联网络信息中心(CNNIC)>
[cdntran / cdntran][Running/Auto Start]
  <system32\drivers\cdntran.sys><CNNIC>
[ExpScaner / ExpScaner][Stopped/Disabled]
  <\??\D:\RISING\RAV\ExpScan.sys><N/A>
[fhhjcjdf / fhhjcjdf][Stopped/Boot Start]
  <\SystemRoot\system32\drivers\fhhjcjdf.sys><N/A>
[HookCont / HookCont][Stopped/Disabled]
  <\??\D:\RISING\RAV\HOOKCONT.sys><N/A>
[HookReg / HookReg][Stopped/Disabled]
  <\??\D:\RISING\RAV\HookReg.sys><N/A>
[HookSys / HookSys][Stopped/Disabled]
  <\??\D:\RISING\RAV\HookSys.sys><N/A>
[HookUrl / HookUrl][Stopped/Disabled]
  <\??\D:\Rising\Rfw\HookUrl.sys><N/A>
[KWatch3 / KWatch3][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
[MEMSCAN / MEMSCAN][Stopped/Disabled]
  <\??\D:\RISING\RAV\MEMSCAN.sys><N/A>
[mProcRs / mProcRs][Stopped/Disabled]
  <\??\d:\rising\rfw\mProcRs.sys><N/A>
[Mtlmnt5 / Mtlmnt5][Stopped/Manual Start]
  <system32\DRIVERS\Mtlmnt5.sys><>
[Mtlstrm / Mtlstrm][Stopped/Manual Start]
  <system32\DRIVERS\Mtlstrm.sys><>
[npkcrypt / npkcrypt][Stopped/Auto Start]
  <\??\D:\QQ\QQ2007\npkcrypt.sys><N/A>
[npkcusb / npkcusb][Stopped/Auto Start]
  <\??\D:\QQ\QQ2007\npkcusb.sys><N/A>
[npkycryp / npkycryp][Stopped/Manual Start]
  <\??\D:\QQ\QQ2007\npkycryp.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
  <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[RecAgent / RecAgent][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\RecAgent.sys><>
[RsFwDrv / RsFwDrv][Stopped/Disabled]
  <\??\D:\Rising\Rfw\RsFwDrv.sys><N/A>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Stopped/Disabled]
  <\??\D:\RISING\RAV\RSPPSYS.sys><N/A>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[SiS315 / SiS315][Running/Manual Start]
  <system32\DRIVERS\sisgrp.sys><Silicon Integrated Systems Corporation>
[SiSkp / SiSkp][Running/System Start]
  <system32\DRIVERS\srvkp.sys><Silicon Integrated Systems Corporation>
[SiS PCI Fast Ethernet Adapter Driver / SISNIC][Running/Manual Start]
  <system32\DRIVERS\sisnic.sys><SiS Corporation>
[SmartLink AMR_PCI Driver / Slntamr][Stopped/Manual Start]
  <system32\DRIVERS\slntamr.sys><>
[SlNtHal / SlNtHal][Stopped/Manual Start]
  <system32\DRIVERS\Slnthal.sys><>
[SlWdmSup / SlWdmSup][Stopped/Manual Start]
  <system32\DRIVERS\SlWdmSup.sys><>
[USB PC Camera (SNPSTD325) / SNP325][Stopped/Manual Start]
  <system32\DRIVERS\snp325.sys><Sonix Co. Ltd.>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
gototop
 

浏览器加载项
[Info cache]
  {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll, 金泰丰(广州)科技有限公司>
[CdnForIE Class]
  {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[ff Class]
  {FAAAC0F6-94BE-4466-934B-7C53666A2F41} <C:\WINDOWS\system32\f891.dll, TODO: <公司名>>
[启动迅雷]
  {0062C9BD-B349-40DE-91A0-755F37ACD559} <D:\迅雷5\Thunder.exe, Thunder Networking Technologies,LTD>
[CdnForIE Class]
  {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\QQ\QQ2007\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <, N/A>
[MMCPlayer Class]
  {05C1004E-2596-48E5-8E26-39362985EEB9} <C:\WINDOWS\Downloaded Program Files\MMCShell.dll, Sohu.com Inc.>
[KooPlayer Control]
  {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} <C:\WINDOWS\DOWNLO~1\KOOPLA~1.OCX, Koos>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[ActiveMovieControl Object]
  {05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[MMCPlayer Class]
  {05C1004E-2596-48E5-8E26-39362985EEB9} <C:\WINDOWS\Downloaded Program Files\MMCShell.dll, Sohu.com Inc.>
[EWA Control]
  {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <D:\PPLive\SYNACA~2.OCX, Synacast>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[Info cache]
  {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll, 金泰丰(广州)科技有限公司>
[CdnForIE Class]
  {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[PowerPlayer Control]
  {5EC7C511-CD0F-42E6-830C-1BD9882F3458} <D:\ppstream\新建文~1\PPStream\POWERP~1.DLL, PPStream Inc.>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\system\msadc\msadco.dll, Microsoft Corporation>
[AUDIO__X_MS_WMA Moniker Class]
  {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[ff Class]
  {FAAAC0F6-94BE-4466-934B-7C53666A2F41} <C:\WINDOWS\system32\f891.dll, TODO: <公司名>>
[&使用迅雷下载]
  <D:\迅雷5\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <D:\迅雷5\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
  <D:\QQ\QQ2007\AddToNetDisk.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <D:\QQ\QQ2007\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\QQ\QQ2007\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\QQ\QQ2007\SendMMS.htm, N/A>
gototop
 

正在运行的进程
[PID: 420][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 480][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 504][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\qhbpri.dll]  [N/A, ]
    [C:\WINDOWS\system32\winlib0.dll]  [N/A, ]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [c:\progra~1\oaka\bnxn.dll]  [, 5, 0, 0, 4]
    [c:\progra~1\oaka\gscs.dll]  [ , 5, 0, 0, 4]
[PID: 552][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\qhbpri.dll]  [N/A, ]
[PID: 572][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\qhbpri.dll]  [N/A, ]
[PID: 732][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\qhbpri.dll]  [N/A, ]
[PID: 812][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\qhbpri.dll]  [N/A, ]
[PID: 852][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\qhbpri.dll]  [N/A, ]
    [c:\windows\system32\ngkty.dll]  [Microsoft Corporation, 5.1.2600.0]
[PID: 1540][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\qhbpri.dll]  [N/A, ]
    [c:\progra~1\oaka\bnxn.dll]  [, 5, 0, 0, 4]
    [c:\progra~1\oaka\gscs.dll]  [ , 5, 0, 0, 4]
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  [CNNIC, 2, 2, 0, 1]
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  [CNNIC, 2, 1, 0, 12]
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  [CNNIC, 2, 5, 0, 0]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\866EC43F.dll]  [N/A, ]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysWFGQQ2.dll]  [N/A, ]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
    [D:\Rising\Rav\RSCOMMON.DLL]  [N/A, ]
    [c:\windows\system32\ngkty.dll]  [Microsoft Corporation, 5.1.2600.0]
    [C:\WINDOWS\system32\f891.dll]  [TODO: <公司名>, 1.0.0.1]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[PID: 1652][C:\Program Files\CNNIC\Cdn\cdnup.exe]  [CNNIC, 2, 5, 0, 8]
    [c:\progra~1\oaka\bnxn.dll]  [, 5, 0, 0, 4]
    [c:\progra~1\oaka\gscs.dll]  [ , 5, 0, 0, 4]
    [C:\Program Files\CNNIC\Cdn\cdnuplib.dll]  [CNNIC, 2, 5, 0, 11]
    [C:\Program Files\CNNIC\Cdn\cdnprh.dll]  [CNNIC, 2, 4, 0, 7]
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  [CNNIC, 2, 5, 0, 0]
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  [CNNIC, 2, 1, 0, 12]
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  [CNNIC, 2, 2, 0, 1]
    [C:\Program Files\CNNIC\Cdn\cdntdns.dll]  [CNNIC, 2, 2, 0, 3]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\866EC43F.dll]  [N/A, ]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysWFGQQ2.dll]  [N/A, ]
[PID: 1884][C:\WINDOWS\smcfg.exe]  [, 2, 80, 1, 0]
    [C:\WINDOWS\system32\qhbpri.dll]  [N/A, ]
[PID: 1892][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.30]
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  [CNNIC, 2, 2, 0, 1]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\866EC43F.dll]  [N/A, ]
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  [CNNIC, 2, 1, 0, 12]
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  [CNNIC, 2, 5, 0, 0]
    [c:\progra~1\oaka\bnxn.dll]  [, 5, 0, 0, 4]
    [c:\progra~1\oaka\gscs.dll]  [ , 5, 0, 0, 4]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysWFGQQ2.dll]  [N/A, ]
[PID: 1936][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\qhbpri.dll]  [N/A, ]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\866EC43F.dll]  [N/A, ]
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  [CNNIC, 2, 2, 0, 1]
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  [CNNIC, 2, 1, 0, 12]
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  [CNNIC, 2, 5, 0, 0]
    [c:\progra~1\oaka\bnxn.dll]  [, 5, 0, 0, 4]
    [c:\progra~1\oaka\gscs.dll]  [ , 5, 0, 0, 4]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysWFGQQ2.dll]  [N/A, ]
[PID: 1512][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\866EC43F.dll]  [N/A, ]
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  [CNNIC, 2, 2, 0, 1]
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  [CNNIC, 2, 1, 0, 12]
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  [CNNIC, 2, 5, 0, 0]
    [c:\progra~1\oaka\bnxn.dll]  [, 5, 0, 0, 4]
    [c:\progra~1\oaka\gscs.dll]  [ , 5, 0, 0, 4]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysWFGQQ2.dll]  [N/A, ]
[PID: 3540][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\qhbpri.dll]  [N/A, ]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\866EC43F.dll]  [N/A, ]
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  [CNNIC, 2, 2, 0, 1]
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  [CNNIC, 2, 1, 0, 12]
    [C:\Program Files\CNNIC\Cdn\cdnuplib.dll]  [CNNIC, 2, 5, 0, 11]
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  [CNNIC, 2, 5, 0, 0]
    [c:\progra~1\oaka\bnxn.dll]  [, 5, 0, 0, 4]
    [c:\progra~1\oaka\gscs.dll]  [ , 5, 0, 0, 4]
    [C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll]  [金泰丰(广州)科技有限公司, 2, 3, 0, 0]
    [C:\WINDOWS\system32\f891.dll]  [TODO: <公司名>, 1.0.0.1]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysWFGQQ2.dll]  [N/A, ]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
[PID: 4088][C:\Documents and Settings\as\My Documents\My QQ Files\111.exe.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\WINDOWS\system32\qhbpri.dll]  [N/A, ]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\866EC43F.dll]  [N/A, ]
    [C:\Program Files\CNNIC\Cdn\imaoe.dll]  [CNNIC, 2, 2, 0, 1]
    [C:\Program Files\CNNIC\Cdn\cdnforie.dll]  [CNNIC, 2, 1, 0, 12]
    [C:\Program Files\CNNIC\Cdn\cdndet.dll]  [CNNIC, 2, 5, 0, 0]
    [c:\progra~1\oaka\bnxn.dll]  [, 5, 0, 0, 4]
    [c:\progra~1\oaka\gscs.dll]  [ , 5, 0, 0, 4]
    [C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysWFGQQ2.dll]  [N/A, ]
gototop
 

文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
RSVP UDP Service Provider
    C:\WINDOWS\system32\ESPI11.dll(DYWT, ESPI)
RSVP TCP Service Provider
    C:\WINDOWS\system32\ESPI11.dll(DYWT, ESPI)

==================================
Autorun.inf
[D:\]
[AutoRun]
open=866EC43F.exe
shell\open=打开(&O)
shell\open\Command=866EC43F.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=866EC43F.exe
[E:\]
[AutoRun]
open=866EC43F.exe
shell\open=打开(&O)
shell\open\Command=866EC43F.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=866EC43F.exe
[F:\]
[AutoRun]
open=866EC43F.exe
shell\open=打开(&O)
shell\open\Command=866EC43F.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=866EC43F.exe
[G:\]
[AutoRun]
open=866EC43F.exe
shell\open=打开(&O)
shell\open\Command=866EC43F.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=866EC43F.exe

==================================
HOSTS 文件
127.0.0.1      localhost
127.0.0.1      www.jack.coyo.eu
127.0.0.1      www.51zc.com
127.0.0.1      www.caiyi8.com
127.0.0.1      vod.caiyi8.com

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

超级兔子也不能用了,一打开有关杀毒的网页就自动关了
gototop
 

中了AV病毒,下载专杀
gototop
 

呜呜,没人管啊
安全模式也进不去了
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT