瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 斑竹进来【求助】Trojan.PSW.Lmir我快让它弄崩溃了!谁来救救我呀!?

123456   2  /  6  页   跳转

斑竹进来【求助】Trojan.PSW.Lmir我快让它弄崩溃了!谁来救救我呀!?

噩梦呀!还存在,怎么删除都没有用啊!
gototop
 

快,大家帮忙看看!我很晕呢!
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit           

+ C:\WINDOWS\system32\userinit.exe    Userinit Logon Application    Microsoft Corporation    c:\windows\system32\userinit.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell           

+ Explorer.exe    Windows Explorer    Microsoft Corporation    c:\windows\explorer.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run           

+ CnsMin    3721    北京三七二一科技有限公司    c:\windows\downloaded program files\cnsmin.dll

+ helper.dll    Run a DLL as an App    Microsoft Corporation    c:\windows\system32\rundll32.exe

+ IMJPMIG8.1    Microsoft IME    Microsoft Corporation    c:\windows\ime\imjp8_1\imjpmig.exe

+ MINI_BFYY    三代科技 版权所有 (C) 2004 - 2005    深圳市三代科技开发有限公司    d:\program files\ringz studio\storm downloader\stormdownloader.exe

+ NvCplDaemon    NVIDIA Display Properties Extension    NVIDIA Corporation    c:\windows\system32\nvcpl.dll

+ NvMediaCenter    NVIDIA Media Center Library    NVIDIA Corporation    c:\windows\system32\nvmctray.dll

+ nwiz    NVIDIA nView Wizard, Version 110.10     NVIDIA Corporation    c:\windows\system32\nwiz.exe

+ PHIME2002A    微軟新注音輸入法 2002a    Microsoft Corporation    c:\windows\system32\ime\tintlgnt\tintsetp.exe

+ PHIME2002ASync    微軟新注音輸入法 2002a    Microsoft Corporation    c:\windows\system32\ime\tintlgnt\tintsetp.exe

+ RavTask    RavTimer    Beijing Rising Technology Co., Ltd.    d:\program files\rising\rav\ravtask.exe

+ RfwMain    Rising Personal FireWall Main Program    Beijing Rising Technology Corporation Limited    c:\program files\rising\rfw\rfwmain.exe

+ StormCodec_Helper            d:\program files\ringz studio\storm codec\stormset.exe

+ yassistse    AssistSetting    Yahoo!    c:\program files\yahoo!\assistant\yassistse.exe

+ YLive.exe    YLive         c:\program files\yahoo!\assistant\ylive.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run           

+ ctfmon.exe    CTF Loader    Microsoft Corporation    c:\windows\system32\ctfmon.exe

+ MsnMsgr    MSN Messenger    Microsoft Corporation    c:\program files\msn messenger\msnmsgr.exe

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components           

+ Internet Explorer    Windows NT User Data Migration Tool    Microsoft Corporation    c:\windows\system32\shmgrate.exe

+ Internet Explorer 6    IE 5.0 Per-User Install Utility    Microsoft Corporation    c:\windows\system32\ie4uinit.exe

+ Microsoft Outlook Express 6    Outlook Express Setup Library    Microsoft Corporation    c:\program files\outlook express\setup50.exe

+ Microsoft Windows Media Player    Microsoft Windows Media Player 安装实用程序    Microsoft Corporation    c:\windows\inf\unregmp2.exe

+ Microsoft Windows Media Player    ADVPACK    Microsoft Corporation    c:\windows\system32\advpack.dll

+ NetMeeting 3.01    ADVPACK    Microsoft Corporation    c:\windows\system32\advpack.dll

+ Outlook Express    Windows NT User Data Migration Tool    Microsoft Corporation    c:\windows\system32\shmgrate.exe

+ Themes Setup    Microsoft(C) Register Server    Microsoft Corporation    c:\windows\system32\regsvr32.exe

+ Windows Messenger    ADVPACK    Microsoft Corporation    c:\windows\system32\advpack.dll

+ Windows 桌面更新    Microsoft(C) Register Server    Microsoft Corporation    c:\windows\system32\regsvr32.exe

+ 通讯簿 6    Outlook Express Setup Library    Microsoft Corporation    c:\program files\outlook express\setup50.exe

+ 浏览器自定义组件    Microsoft Internet Explorer Customization DLL    Microsoft Corporation    c:\windows\system32\iedkcs32.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler           

+ Browseui 预加载程序    Shell Browser UI Library    Microsoft Corporation    c:\windows\system32\browseui.dll

+ 组件类别缓存程序    Shell Browser UI Library    Microsoft Corporation    c:\windows\system32\browseui.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad           

+ CDBurn    Windows Shell Common Dll    Microsoft Corporation    c:\windows\system32\shell32.dll

+ DLMon            c:\windows\system32\dlmain.dll

+ PostBootReminder    Windows Shell Common Dll    Microsoft Corporation    c:\windows\system32\shell32.dll

+ SysTray    Systray shell service object    Microsoft Corporation    c:\windows\system32\stobject.dll

+ WebCheck    Web Site Monitor    Microsoft Corporation    c:\windows\system32\webcheck.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks           

+ cnshook.dll    3721 CNS Module    北京三七二一科技有限公司    c:\windows\downloaded program files\cnshook.dll

+ Rising Execute File Exts hook    Rising Shell Ext Module    Beijing Rising Technology Co., Ltd.    c:\windows\system32\ravext.dll

+ shell32.dll    Windows Shell Common Dll    Microsoft Corporation    c:\windows\system32\shell32.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved           

+ %DESC_PublishDropTarget%    Photo Printing Wizard    Microsoft Corporation    c:\windows\system32\photowiz.dll

+ .CAB file viewer    Cabinet File Viewer Shell Extension    Microsoft Corporation    c:\windows\system32\cabview.dll

+ ActiveX 高速缓存文件夹    Object Control Viewer    Microsoft Corporation    c:\windows\system32\occache.dll

+ Audio Media Properties Handler    Media File Property Extractor Shell Extension    Microsoft Corporation    c:\windows\system32\shmedia.dll

+ Auto Update Property Sheet Extension    Automatic Updates Control Panel    Microsoft Corporation    c:\windows\system32\wuaucpl.cpl

+ Avi Properties Handler    Media File Property Extractor Shell Extension    Microsoft Corporation    c:\windows\system32\shmedia.dll

+ BandProxy    Shell Browser UI Library    Microsoft Corporation    c:\windows\system32\browseui.dll

+ CDF Extension Copy Hook    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll

+ Channel Menu    Channel Definition File Viewer    Microsoft Corporation    c:\windows\system32\cdfview.dll

+ Channel Properties    Channel Definition File Viewer    Microsoft Corporation    c:\windows\system32\cdfview.dll

+ Code Download Agent    Web Site Monitor    Microsoft Corporation    c:\windows\system32\webcheck.dll

+ Compatibility Page    Compatibility Tab Shell Extension DLL    Microsoft Corporation    c:\windows\system32\slayerxp.dll

+ Compressed (zipped) Folder Right Drag Handler    Compressed (zipped) Folders    Microsoft Corporation    c:\windows\system32\zipfldr.dll

+ Compressed (zipped) Folder SendTo Target    Compressed (zipped) Folders    Microsoft Corporation    c:\windows\system32\zipfldr.dll

+ ConnectionAgent    Web Site Monitor    Microsoft Corporation    c:\windows\system32\webcheck.dll

+ Crypto PKO Extension    Crypto Shell Extensions    Microsoft Corporation    c:\windows\system32\cryptext.dll

+ Crypto Sign Extension    Crypto Shell Extensions    Microsoft Corporation    c:\windows\system32\cryptext.dll

+ Darwin App Publisher    Shell Application Manager    Microsoft Corporation    c:\windows\system32\appwiz.cpl

+ Desktop Explorer    NVIDIA Desktop Explorer, Version 110.10     NVIDIA Corporation    c:\windows\system32\nvshell.dll

+ Desktop Explorer Menu    NVIDIA Desktop Explorer, Version 110.10     NVIDIA Corporation    c:\windows\system32\nvshell.dll

+ DfsShell    Distributed File System shell extension    Microsoft Corporation    c:\windows\system32\dfsshlex.dll

+ Directory Context Menu Verbs    Directory Service Common UI    Microsoft Corporation    c:\windows\system32\dsuiext.dll

+ Directory Object Find    Directory Service Find    Microsoft Corporation    c:\windows\system32\dsquery.dll

+ Directory Property UI    Directory Service Common UI    Microsoft Corporation    c:\windows\system32\dsuiext.dll

+ Directory Query UI    Directory Service Find    Microsoft Corporation    c:\windows\system32\dsquery.dll

+ Directory Start/Search Find    Directory Service Find    Microsoft Corporation    c:\windows\system32\dsquery.dll

+ Disk Copy Extension    Windows DiskCopy    Microsoft Corporation    c:\windows\system32\diskcopy.dll

+ Disk Quota UI    Windows Shell Disk Quota UI DLL    Microsoft Corporation    c:\windows\system32\dskquoui.dll

+ Display Adapter CPL Extension    Advanced display adapter properties    Microsoft Corporation    c:\windows\system32\deskadp.dll

+ Display Monitor CPL Extension    Advanced display monitor properties    Microsoft Corporation    c:\windows\system32\deskmon.dll

+ Display Panning CPL Extension            File not found: deskpan.dll

+ Display TroubleShoot CPL Extension    Advanced display performance properties    Microsoft Corporation    c:\windows\system32\deskperf.dll

+ DS Security Page    Directory Service Security UI    Microsoft Corporation    c:\windows\system32\dssec.dll

+ Favorites Band    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll

+ FTP Folders Webview    Microsoft Internet Explorer FTP Folder Shell Extension    Microsoft Corporation    c:\windows\system32\msieftp.dll

+ Fusion Cache    Microsoft .NET Runtime Execution Engine    Microsoft Corporation    c:\windows\system32\mscoree.dll

+ GDI+ 文件缩略图解压缩程序    Windows 图片和传真查看器    Microsoft Corporation    c:\windows\system32\shimgvw.dll

+ HTML 缩略图的解压缩程序    Windows 图片和传真查看器    Microsoft Corporation    c:\windows\system32\shimgvw.dll

+ HyperTerminal Icon Ext    HyperTerminal Applet Library    Hilgraeve, Inc.    c:\windows\system32\hticons.dll

+ ICC 配置文件    Microsoft Color Matching System User Interface DLL    Microsoft Corporation    c:\windows\system32\icmui.dll

+ ICM 打印机管理    Microsoft Color Matching System User Interface DLL    Microsoft Corporation    c:\windows\system32\icmui.dll

+ ICM 监视器管理    Microsoft Color Matching System User Interface DLL    Microsoft Corporation    c:\windows\system32\icmui.dll

+ ICM 扫描仪管理    Microsoft Color Matching System User Interface DLL    Microsoft Corporation    c:\windows\system32\icmui.dll

+ IE4 套件初始屏幕    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll

+ Installed Apps Enumerator    Shell Application Manager    Microsoft Corporation    c:\windows\system32\appwiz.cpl
gototop
 

快,大家帮忙看看!我很晕呢!
ation    c:\windows\system32\shdocvw.dll

+ Internet    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll

+ Internet Name Space    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll

+ Internet 临时文件    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll

+ Internet 临时文件    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll

+ InternetShortcut    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll

+ ISFBand OC    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll

+ Microsoft Agent Character Property Sheet Handler    Microsoft Agent Property Sheet Handler    Microsoft Corporation    c:\windows\msagent\agentpsh.dll

+ Microsoft AutoComplete    Shell Browser UI Library    Microsoft Corporation    c:\windows\system32\browseui.dll

+ Microsoft Browser Architecture    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll

+ Microsoft BrowserBand    Shell Browser UI Library    Microsoft Corporation    c:\windows\system32\browseui.dll

+ Microsoft DocProp Inplace Calendar Control    Microsoft DocProp Shell Ext    Microsoft Corporation    c:\windows\system32\docprop2.dll

+ Microsoft DocProp Inplace Droplist Combo Control    Microsoft DocProp Shell Ext    Microsoft Corporation    c:\windows\system32\docprop2.dll

+ Microsoft DocProp Inplace Edit Box Control    Microsoft DocProp Shell Ext    Microsoft Corporation    c:\windows\system32\docprop2.dll

+ Microsoft DocProp Inplace ML Edit Box Control    Microsoft DocProp Shell Ext    Microsoft Corporation    c:\windows\system32\docprop2.dll

+ Microsoft DocProp Inplace Time Control    Microsoft DocProp Shell Ext    Microsoft Corporation    c:\windows\system32\docprop2.dll

+ Microsoft DocProp Shell Ext    Microsoft DocProp Shell Ext    Microsoft Corporation    c:\windows\system32\docprop2.dll

+ Microsoft Internet 工具栏    Shell Browser UI Library    Microsoft Corporation    c:\windows\system32\browseui.dll

+ Microsoft Url History 服务    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll

+ Microsoft Url 搜索挂接    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll

+ Microsoft 多个自动完成列表容器    Shell Browser UI Library    Microsoft Corporation    c:\windows\system32\browseui.dll

+ Microsoft 历史自动完成列表    Shell Browser UI Library    Microsoft Corporation    c:\windows\system32\browseui.dll

+ Microsoft 数据链接    Microsoft Data Access - OLE DB Core Services    Microsoft Corporation    c:\program files\common files\system\ole db\oledb32.dll

+ Microsoft 外壳文件夹自动完成列表    Shell Browser UI Library    Microsoft Corporation    c:\windows\system32\browseui.dll

+ Midi Properties Handler    Media File Property Extractor Shell Extension    Microsoft Corporation    c:\windows\system32\shmedia.dll

+ MMC Icon Handler    MMC Shell Extension DLL    Microsoft Corporation    c:\windows\system32\mmcshext.dll

+ MRU 自动完成列表    Shell Browser UI Library    Microsoft Corporation    c:\windows\system32\browseui.dll

+ Multimedia File Property Sheet    Control Panel Drivers Applet    Microsoft Corporation    c:\windows\system32\mmsys.cpl

+ MyDocs Copy Hook    My Documents Folder UI    Microsoft Corporation    c:\windows\system32\mydocs.dll

+ MyDocs Drop Target    My Documents Folder UI    Microsoft Corporation    c:\windows\system32\mydocs.dll

+ MyDocs Properties    My Documents Folder UI    Microsoft Corporation    c:\windows\system32\mydocs.dll

+ NTFS Security Page    Security Shell Extension    Microsoft Corporation    c:\windows\system32\rshx32.dll

+ NvCpl DesktopContext Class    NVIDIA Display Properties Extension    NVIDIA Corporation    c:\windows\system32\nvcpl.dll

+ nView Desktop Context Menu    NVIDIA Desktop Explorer, Version 110.10     NVIDIA Corporation    c:\windows\system32\nvshell.dll

+ Offline Files Folder Options    Client Side Caching UI    Microsoft Corporation    c:\windows\system32\cscui.dll

+ Offline Files Menu    Client Side Caching UI    Microsoft Corporation    c:\windows\system32\cscui.dll

+ OLE Docfile Property Page    OLE DocFile Property Page    Microsoft Corporation    c:\windows\system32\docprop.dll

+ Play on my TV helper    NVIDIA Display Properties Extension    NVIDIA Corporation    c:\windows\system32\nvcpl.dll

+ PlusPack CPL Extension    Windows Theme API    Microsoft Corporation    c:\windows\system32\themeui.dll

+ Portable Media Devices    便携媒体设备命令行解释器扩展    Microsoft Corporation    c:\windows\system32\audiodev.dll

+ Portable Media Devices Menu    便携媒体设备命令行解释器扩展    Microsoft Corporation    c:\windows\system32\audiodev.dll

+ PostAgent    Web Site Monitor    Microsoft Corporation    c:\windows\system32\webcheck.dll

+ Printers Security Page    Security Shell Extension    Microsoft Corporation    c:\windows\system32\rshx32.dll

+ Remote Sessions CPL Extension    Remote Sessions CPL Extension    Microsoft Corporation    c:\windows\system32\remotepg.dll

+ RISING    Rising Shell Ext Module    Beijing Rising Technology Co., Ltd.    c:\windows\system32\ravext.dll

+ Search Assistant OC    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll

+ Sendmail service    Send Mail    Microsoft Corporation    c:\windows\system32\sendmail.dll

+ Sendmail service    Send Mail    Microsoft Corporation    c:\windows\system32\sendmail.dll

+ Shell Application Manager    Shell Application Manager    Microsoft Corporation    c:\windows\system32\appwiz.cpl

+ Shell Automation Inproc Service    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll

+ Shell Band Site Menu    Shell Browser UI Library    Microsoft Corporation    c:\windows\system32\browseui.dll

+ Shell DocObject Viewer    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll
gototop
 

快,大家帮忙看看!我很晕呢!

还有好多呢,发不上来了,太多、太大!
gototop
 

刚才又重新保存了个小文本,这次小多了!
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run           

+ CnsMin    3721    北京三七二一科技有限公司    c:\windows\downloaded program files\cnsmin.dll

+ MINI_BFYY    三代科技 版权所有 (C) 2004 - 2005    深圳市三代科技开发有限公司    d:\program files\ringz studio\storm downloader\stormdownloader.exe

+ NvCplDaemon    NVIDIA Display Properties Extension    NVIDIA Corporation    c:\windows\system32\nvcpl.dll

+ NvMediaCenter    NVIDIA Media Center Library    NVIDIA Corporation    c:\windows\system32\nvmctray.dll

+ nwiz    NVIDIA nView Wizard, Version 110.10     NVIDIA Corporation    c:\windows\system32\nwiz.exe

+ RavTask    RavTimer    Beijing Rising Technology Co., Ltd.    d:\program files\rising\rav\ravtask.exe

+ RfwMain    Rising Personal FireWall Main Program    Beijing Rising Technology Corporation Limited    c:\program files\rising\rfw\rfwmain.exe

+ StormCodec_Helper            d:\program files\ringz studio\storm codec\stormset.exe

+ yassistse    AssistSetting    Yahoo!    c:\program files\yahoo!\assistant\yassistse.exe

+ YLive.exe    YLive         c:\program files\yahoo!\assistant\ylive.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad           

+ DLMon            c:\windows\system32\dlmain.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks           

+ cnshook.dll    3721 CNS Module    北京三七二一科技有限公司    c:\windows\downloaded program files\cnshook.dll

+ Rising Execute File Exts hook    Rising Shell Ext Module    Beijing Rising Technology Co., Ltd.    c:\windows\system32\ravext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved           

+ Desktop Explorer    NVIDIA Desktop Explorer, Version 110.10     NVIDIA Corporation    c:\windows\system32\nvshell.dll

+ Desktop Explorer Menu    NVIDIA Desktop Explorer, Version 110.10     NVIDIA Corporation    c:\windows\system32\nvshell.dll

+ Display Panning CPL Extension            File not found: deskpan.dll

+ HyperTerminal Icon Ext    HyperTerminal Applet Library    Hilgraeve, Inc.    c:\windows\system32\hticons.dll

+ NvCpl DesktopContext Class    NVIDIA Display Properties Extension    NVIDIA Corporation    c:\windows\system32\nvcpl.dll

+ nView Desktop Context Menu    NVIDIA Desktop Explorer, Version 110.10     NVIDIA Corporation    c:\windows\system32\nvshell.dll

+ Play on my TV helper    NVIDIA Display Properties Extension    NVIDIA Corporation    c:\windows\system32\nvcpl.dll

+ RISING    Rising Shell Ext Module    Beijing Rising Technology Co., Ltd.    c:\windows\system32\ravext.dll

+ WinRAR shell extension            c:\program files\winrar\rarext.dll

+ Yahoo!Photo    yPhtb    Yahoo! China    c:\program files\yahoo!\assistant\assist\yphtb.dll

+ 粉碎文件    Wiper 动态链接库        c:\program files\yahoo!\assistant\assist\ywiper.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects           

+ AntiFish Class    yangling.dll    Yahoo.    c:\program files\yahoo!\assistant\assist\yangling.dll

+ CnsHook Class    3721 CNS Module    北京三七二一科技有限公司    c:\windows\downloaded program files\cnshook.dll

+ DragSearch BHO    DragSearch        c:\program files\yahoo!\assistant\assist\ydragsearch.dll

+ DragSearch BHO    DragSearch        c:\program files\yisou\yisoub.dll

+ QQBrowserHelperObject Class    QQIEHelper Module    深圳市腾讯计算机系统有限公司    d:\program files\tencent\qq\qqiehelper.dll

+ Router Layer            File not found: C:\WINDOWS\System32\aclayer.dll

+ ThunderIEHelper Class    xunleibho BHO        c:\windows\system32\xunleibho_v8.dll

+ Yahoo!Photo    yPhtb    Yahoo! China    c:\program files\yahoo!\assistant\assist\yphtb.dll

+ 雅虎助手    ToolBar    Yahoo!    c:\program files\yahoo!\assistant\assist\yasbar.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar           

+ 雅虎助手    ToolBar    Yahoo!    c:\program files\yahoo!\assistant\assist\yasbar.dll

+ 一搜            File not found: C:\Program Files\YiSou\yisou.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions           

+ @shdoclc.dll,-864            c:\windows\web\related.htm

+ Yahoo 1G电邮            File not found: http://cn.mail.yahoo.com/promo/rd1

+ 清理上网记录            File not found: http://assistant.3721.com/clean1.htm?fb=Cns

+ 情景聊天            File not found: http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/

+ 手机短信            File not found: http://sms.3721.com/ie/index.htm?pid=1066_1006

+ 腾讯QQ    QQ    TENCENT    d:\program files\tencent\qq\qq.exe

+ 修复浏览器            File not found: http://assistant.3721.com/security1.htm?fb=Cns

+ 寻宝乐趣多            File not found: http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138

+ 雅虎助手            File not found: http://cn.zs.yahoo.com/?source=Cns

+ 易趣购物            File not found: http://click2.ad4all.net/url2/urlmanage/url.asp?id=5

HKLM\System\CurrentControlSet\Services           

+ NVSvc    Provides system and desktop level support to the NVIDIA display driver    NVIDIA Corporation    c:\windows\system32\nvsvc32.exe

+ RfwService    Rising Personal Firewall Service    Beijing Rising Technology Corporation Limited    c:\program files\rising\rfw\rfwsrv.exe

+ RsCCenter    CCenter    Beijing Rising Technology Co., Ltd.    d:\program files\rising\rav\ccenter.exe

+ RsRavMon    RavMond    Beijing Rising Technology Co., Ltd.    d:\program files\rising\rav\ravmond.exe

HKLM\System\CurrentControlSet\Services           

+ ac97intc    Intel(r) Integrated Controller Hub Audio Driver    Intel Corporation    c:\windows\system32\drivers\ac97intc.sys

+ BaseTDI    basetdi    Beijing Rising Technology Co., Ltd.    c:\windows\system32\drivers\basetdi.sys

+ ExpScaner    ExpScan.sys        d:\program files\rising\rav\expscan.sys

+ HookCont    TDI HOOK Driver    Rising tech Co. ltd    d:\program files\rising\rav\hookcont.sys

+ HookReg            d:\program files\rising\rav\hookreg.sys

+ HookSys    Hooksys    Rising    d:\program files\rising\rav\hooksys.sys

+ MEMSCAN    MemScan Driver    瑞星软件有限公司    d:\program files\rising\rav\memscan.sys

+ npkcrypt    nProtect KeyCrypt Driver    INCA Internet Co., Ltd.    d:\program files\tencent\qq\npkcrypt.sys

+ nv    NVIDIA Compatible Windows 2000 Miniport Driver, Version 81.95     NVIDIA Corporation    c:\windows\system32\drivers\nv4_mini.sys

+ Ptilink    Direct Parallel Link Driver    Parallel Technologies, Inc.    c:\windows\system32\drivers\ptilink.sys

+ RsFwDrv    nt_fwdrv    Rising    c:\program files\rising\rfw\rsfwdrv.sys

+ rtl8139    NDIS 5.0 driver                                                                      Realtek Semiconductor Corporation                                                    c:\windows\system32\drivers\rtl8139.sys

+ Secdrv    SafeDisc driver        c:\windows\system32\drivers\secdrv.sys

+ UnlockerDriver4            c:\program files\unlocker\unlockerdriver4.sys

gototop
 

好心的大哥们~你们快来救救我呀!?
gototop
 

大哥,快帮俺看看,是这个不?
2006-01-11,19:56:38

System Repair Engineer 2.0.12.350 (2.0 RC 1)
    Windows XP Professional Service Pack 1 - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <load><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <helper.dll><C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <StormCodec_Helper><"d:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <MINI_BFYY><D:\Program Files\Ringz Studio\Storm Downloader\StormDownloader.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <yassistse><"C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <CnsMin><Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <nwiz><nwiz.exe /install>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <RavTask><"d:\Program Files\Rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <Userinit><C:\WINDOWS\system32\userinit.exe,>

==================================
启动文件夹
服务
[NVIDIA Display Driver Service / NVSvc]
  <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[Rising Personal Firewall Service / RfwService]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Corporation Limited>
[Rising Process Communication Center / RsCCenter]
  <D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"d:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>

==================================
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\System32\xunleibho_v8.dll, >
[Yahoo!Photo]
  {33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll, Yahoo.>
[雅虎助手]
  {406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll, Yahoo!>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <D:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Router Layer]
  {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} <C:\WINDOWS\System32\aclayer.dll, N/A>
[DragSearch BHO]
  {62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, >
[CnsHook Class]
  {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\DOWNLO~1\CnsHook.dll, 北京三七二一科技有限公司>
[DragSearch BHO]
  {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} <C:\PROGRA~1\YiSou\yisoub.dll, >
[手机短信]
  {00000000-0000-0001-0001-596BAEDD1289} <http://sms.3721.com/ie/index.htm?pid=1066_1006, N/A>
[Yahoo 1G电邮]
  {507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.mail.yahoo.com/promo/rd1, N/A>
[寻宝乐趣多]
  {59BC54A2-56B3-44a0-93E5-432D58746E26} <http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=?allyesPara=816, N/A>
[雅虎助手]
  {5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/?source=Cns, N/A>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[易趣购物]
  {DE607141-AC19-421e-862A-2D70ABDF119A} <http://click2.ad4all.net/url2/urlmanage/url.asp?id=5, N/A>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[情景聊天]
  {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/, N/A>
[]
  {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://assistant.3721.com/security1.htm?fb=Cns, N/A>
[]
  {FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://assistant.3721.com/clean1.htm?fb=Cns, N/A>
[一搜工具条]
  {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} <C:\Program Files\YiSou\yisou.dll, N/A>
[雅虎助手]
  {406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll, Yahoo!>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\System32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[Edit Class]
  {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\System32\CMBEdit.dll, >
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\System32\wuweb.dll, Microsoft Corporation>
[AxInputControl Class]
  {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL, >
[Update Class]
  {9F1C11AA-197B-4942-BA54-47A8489BB47F} <C:\WINDOWS\System32\iuctl.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Tech. Co., Ltd.>
[!搜一搜]
  <res://C:\Program Files\YiSou\yisou.dll/232, N/A>
[!搜一搜(&S)]
  <res://C:\Program Files\YiSou\yisou.dll/232, N/A>
[&使用暴风下载器下载]
  <D:\Program Files\Ringz Studio\Storm Downloader\geturl.htm, N/A>
[&使用迅雷下载]
  <d:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <d:\Program Files\Thunder Network\Thunder\getAllurl.htm, N/A>
[上传到QQ网络硬盘]
  <D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
  <D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>

==================================
gototop
 

大哥,快帮俺看看,是这个不?
==================================
正在运行的进程
[PID: 432][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 500][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 524][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 568][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 580][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 748][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 800][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 900][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 984][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1036][D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1052][c:\program files\rising\rfw\rfwsrv.exe]  <Beijing Rising Technology Corporation Limited><3, 2, 0, 0>
    [c:\program files\rising\rfw\Rfwdrv.dll]  <Beijing Rising Technology Corporation Limited><3, 0, 1, 5>
    [c:\program files\rising\rfw\rfwrule.dll]  <Beijing Rising Technology Corporation Limited><3, 1, 0, 0>
    [c:\program files\rising\rfw\rfwlog.dll]  <Beijing Rising Technology Corporation Limited><3, 1, 0, 2>
[PID: 1088][d:\Program Files\Rising\Rav\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 6>
    [d:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [d:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [d:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [d:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [d:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [d:\Program Files\Rising\Rav\RsLog.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [d:\Program Files\Rising\Rav\HOOKSYS.dll]  <Rising><18, 1, 0, 9>
    [d:\Program Files\Rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
    [d:\Program Files\Rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [d:\Program Files\Rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [d:\Program Files\Rising\Rav\regmon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [d:\Program Files\Rising\Rav\HookWeb.dll]  <rising><18, 0, 0, 1>
    [d:\Program Files\Rising\Rav\MemMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
    [d:\Program Files\Rising\Rav\expscan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [d:\Program Files\Rising\Rav\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
    [d:\Program Files\Rising\Rav\MailMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [d:\Program Files\Rising\Rav\SpamEng.dll]  <N/A><18, 0, 0, 4>
    [d:\Program Files\Rising\Rav\engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [d:\Program Files\Rising\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [d:\Program Files\Rising\Rav\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [d:\Program Files\Rising\Rav\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [d:\Program Files\Rising\Rav\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [d:\Program Files\Rising\Rav\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [d:\Program Files\Rising\Rav\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [d:\Program Files\Rising\Rav\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [d:\Program Files\Rising\Rav\RsStore.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [d:\Program Files\Rising\Rav\posttrtx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 1>
    [d:\Program Files\Rising\Rav\Unpacker.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
gototop
 

大哥,快帮俺看看,是这个不?
[PID: 1568][d:\Program Files\Rising\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
    [d:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [d:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1668][c:\program files\rising\rfw\RfwMain.exe]  <Beijing Rising Technology Corporation Limited><3, 1, 0, 19>
    [c:\program files\rising\rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 40>
    [c:\program files\rising\rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
    [c:\program files\rising\rfw\PngDll.dll]  <Rising><17, 0, 0, 2>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 8, 1014>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 2, 3>
[PID: 1724][C:\WINDOWS\system32\rundll32.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 8, 1014>
    [C:\PROGRA~1\3721\autolive.dll]  <><1, 1, 4, 1026>
    [C:\PROGRA~1\3721\alLiveEx.dll]  < ><1, 0, 2, 1005>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 2, 3>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\PROGRA~1\3721\notifier.dll]  <><1, 0, 0, 5>
[PID: 1760][D:\Program Files\Ringz Studio\Storm Downloader\StormDownloader.exe]  <深圳市三代科技开发有限公司><1, 1, 0, 4>
    [D:\Program Files\Ringz Studio\Storm Downloader\boost_thread-vc6-mt-1_31.dll]  <N/A><N/A>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 8, 1014>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 2, 3>
[PID: 1784][C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe]  < ><2, 0, 0, 1002>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 8, 1014>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  <><2, 0, 4, 1030>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  < ><2, 0, 0, 1006>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 2, 3>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\ynotifier.dll]  <><1, 0, 0, 5>
[PID: 1812][C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe]  <Yahoo!><1, 0, 1, 1001>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 8, 1014>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 2, 3>
    [C:\PROGRA~1\Yahoo!\Assistant\shell\yAssecblk.dll]  <Yahoo><1, 0, 1, 1001>
    [C:\PROGRA~1\Yahoo!\Assistant\shell\yMenuInfo.dll]  <Yahoo><1, 0, 0, 2>
    [C:\PROGRA~1\Yahoo!\Assistant\shell\yIEAngel.dll]  <Yahoo><1, 0, 1, 1001>
    [C:\PROGRA~1\Yahoo!\Assistant\shell\yAsMenu.dll]  <Yahoo><1, 0, 1, 1006>
[PID: 1828][C:\WINDOWS\System32\Rundll32.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 2, 3>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 8, 1014>
[PID: 1964][D:\Program Files\Ringz Studio\Storm Downloader\TDUpdate.exe]  <N/A><N/A>
[PID: 1968][D:\Program Files\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [D:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [D:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [D:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 8, 1014>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 2, 3>
gototop
 

大哥,快帮俺看看,是这个不?
[PID: 2008][D:\Program Files\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 99>
    [D:\Program Files\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [D:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [D:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [D:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [D:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [D:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [D:\Program Files\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 2, 3>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 8, 1014>
    [C:\WINDOWS\System32\rodll.dll]  <N/A><N/A>
[PID: 2024][C:\WINDOWS\System32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 2, 3>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 8, 1014>
[PID: 844][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 916][C:\WINDOWS\System32\nvsvc32.exe]  <NVIDIA Corporation><6.14.10.8195>
[PID: 1156][C:\WINDOWS\System32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 364][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 2, 3>
    [C:\WINDOWS\DOWNLO~1\CnsHint.dll]  <3721><1, 0, 0, 6>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll]  <Yahoo><1, 0, 1, 1000>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 8, 1014>
    [C:\PROGRA~1\3721\scrblock.dll]  <3721><1, 0, 1, 1000>
    [C:\PROGRA~1\3721\alrex.dll]  <><1, 0, 0, 1>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]  <><2, 0, 4, 1030>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  < ><2, 0, 0, 1006>
    [C:\PROGRA~1\3721\autolive.dll]  <><1, 1, 4, 1026>
    [C:\PROGRA~1\3721\alLiveEx.dll]  < ><1, 0, 2, 1005>
    [C:\WINDOWS\DOWNLO~1\cnsplus.dll]  <3721><1, 0, 0, 2>
    [C:\WINDOWS\System32\xunleibho_v8.dll]  <><4, 5, 1, 33>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll]  <Yahoo! China><1, 0, 7, 1021>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll]  <Yahoo.><1, 0, 2, 1002>
    [C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll]  <Yahoo!><2, 0, 5, 1027>
    [D:\Program Files\Tencent\QQ\QQIEHelper.dll]  <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL]  <><1, 2, 7, 1006>
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  <北京三七二一科技有限公司><1, 0, 2, 7>
    [C:\PROGRA~1\YiSou\yisoub.dll]  <><1, 1, 2, 4>
    [d:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINDOWS\System32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\WINDOWS\System32\rodll.dll]  <N/A><N/A>
[PID: 2332][F:\剑侠精灵\jl.exe]  <><5.94Z>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 2, 3>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 8, 1014>
    [F:\剑侠精灵\hook.dll]  <N/A><N/A>
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  <北京三七二一科技有限公司><1, 0, 2, 7>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[PID: 3468][E:\JxOnline\game.exe]  <金山软件股份有限公司><3, 0, 0, 6>
    [E:\JxOnline\engine.dll]  <金山软件股份有限公司><3, 0, 0, 1>
    [E:\JxOnline\LuaLibDll.dll]  <N/A><N/A>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 2, 3>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 8, 1014>
    [E:\JxOnline\Represent2.dll]  <金山软件股份有限公司><3, 0, 0, 31>
    [E:\JxOnline\JXReplay.dll]  <N/A><N/A>
    [E:\JxOnline\zlib.dll]  <N/A><1.1.4.0>
    [F:\剑侠精灵\hook.dll]  <N/A><N/A>
[PID: 2852][d:\Program Files\Thunder Network\Thunder\ThunderOrg.exe]  <><5.0.0.72>
    [d:\Program Files\Thunder Network\Thunder\UpdateDownload.dll]  <N/A><N/A>
    [d:\Program Files\Thunder Network\Thunder\download_interface.dll]  <N/A><N/A>
    [d:\Program Files\Thunder Network\Thunder\log4cplus.dll]  <N/A><N/A>
    [d:\Program Files\Thunder Network\Thunder\stlport_vc646.dll]  <STLport Consulting, Inc.><4.6.2003.1031>
    [d:\Program Files\Thunder Network\Thunder\historyinfo_manage.dll]  <N/A><N/A>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 2, 3>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 8, 1014>
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  <北京三七二一科技有限公司><1, 0, 2, 7>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\WINDOWS\System32\rodll.dll]  <N/A><N/A>
[PID: 1032][F:\文件下载\新建文件夹\sreng2\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 2, 3>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <><2, 0, 0, 1013>
    [C:\PROGRA~1\3721\helper.dll]  <><1, 0, 8, 1014>
    [C:\WINDOWS\System32\rodll.dll]  <N/A><N/A>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 
123456   2  /  6  页   跳转
页面顶部
Powered by Discuz!NT