瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 我中病毒了,用hijackthis扫描了,哪位高手帮我看看?谢谢了先
心情niwota - 2006-8-12 8:07:00
怎么复制不了
心情niwota - 2006-8-12 8:13:00
好了
Logfile of HijackThis v1.99.1
Scan saved at 7:51:09, on 2006-8-12
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Conexant\AccessRunner ADSL USB\CnxDslTb.exe
C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\diskman.exe
C:\Program Files\Venturi2\Client\ventc.exe
C:\Program Files\HuaCi\huaci\zsearch.exe
C:\Program Files\DeskMemo\Deskmemo.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DuDu\Speed\dudupros.exe
C:\WINDOWS\System32\svchost.exe
D:\游戏\QQ\QQ.exe
D:\游戏\QQ\TIMPlatform.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\DuDu\Speed\DuDuAcc.exe
D:\ruixing\ha_hijackthis_1991\HijackThis.exe

O2 - BHO: DuDu.com - {00018593-C6BD-46F7-9349-DBA1AA674C90} - C:\Program Files\DuDu\Speed\dddiemon.dll
O2 - BHO: IEMonitor Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\Program Files\DeskAdTop\deskipn.dll
O2 - BHO: SohuDAIEHelper - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - C:\Documents and Settings\user\桌面\P4P\sodaie.dll (file missing)
O2 - BHO: IE Address Browser Helper - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:\Program Files\SearchNet\SNHpr.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll
O2 - BHO: AntiFish Class - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll
O2 - BHO: IE Browser Helper - {3CE496D1-1746-41CD-9489-3C0B93DF10E2} - C:\WINDOWS\Downlo~1\o97z4.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\游戏\QQ\QQIEHelper.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\Progra~1\Baidu\bar\BaiDuBar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: 捜狗直通车 - {DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} - C:\Documents and Settings\user\桌面\P4P\ToolBar.dll (file missing)
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\Progra~1\Baidu\bar\BaiDuBar.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\Conexant\AccessRunner ADSL USB\CnxDslTb.exe" "Conexant\AccessRunner ADSL USB"
O4 - HKLM\..\Run: [Alitalk] C:\PROGRA~1\阿里巴巴\贸易通\AliTalk.EXE -hideframe
O4 - HKLM\..\Run: [Install Alitalk] C:\WINDOWS\temp\alitalk\alitalk.exe -hideframe
O4 - HKLM\..\Run: [MoveSearch] C:\Program Files\HuaCi\huaci\zsearch.exe
O4 - HKLM\..\Run: [Desktop] C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll
O4 - HKLM\..\Run: [y9f] RunDll32 "C:\WINDOWS\Downlo~1\y9f.dll",Run
O4 - HKLM\..\Run: [SearchNet_Up] "C:\Program Files\SearchNet\ServeUp.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [WangWang] "D:\Program Files\淘宝网\淘宝旺旺\WangWang.EXE"
O4 - HKLM\..\Run: [DesktopMemo] "C:\Program Files\DeskMemo\Deskmemo.exe"
O4 - HKLM\..\Run: [res] C:\WINDOWS\system32\res.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: 腾讯QQ.lnk = ?
O4 - Startup: 划词搜索.lnk = C:\Program Files\HuaCi\huaci\zsearch.exe
O4 - Global Startup: DuDu下载加速器.lnk = C:\Program Files\DuDu\Speed\DuDuAcc.exe
O8 - Extra context menu item: &使用DuDu下载 - res://C:\Program Files\DuDu\Speed\dddmext.dll/202
O8 - Extra context menu item: &使用DuDu下载全部链接 - res://C:\Program Files\DuDu\Speed\dddmext.dll/203
O8 - Extra context menu item: &使用DuDu下载选择链接 - res://C:\Program Files\DuDu\Speed\dddmext.dll/204
O8 - Extra context menu item: Google 搜索(&G) - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\游戏\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用搜狗直通车下载 - C:\Documents and Settings\user\桌面\P4P\dl.htm
O8 - Extra context menu item: 反向链接 - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: 发送图片到手机 - C:\Documents and Settings\user\桌面\P4P\cx.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\游戏\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\游戏\QQ\AddEmotion.htm
O8 - Extra context menu item: 添加到“我的订阅” - C:\Documents and Settings\user\桌面\P4P\rss.htm
O8 - Extra context menu item: 添加到雅虎订阅(&Y) - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\游戏\QQ\SendMMS.htm
O8 - Extra context menu item: 类似网页 - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: 缓存的网页快照 - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: 翻译英文字词(&T) - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: 雅虎搜索 - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O9 - Extra button: 我的订阅 - {8755CE6E-0BF7-4441-8751-FB728941B0B4} - C:\Documents and Settings\user\桌面\P4P\rss.dll (file missing)
O9 - Extra button: 网址大全 - {C18CB140-0BBB-11D4-8FE8-0088CC102438} - http://www.k369.com/mp3wz.htm (file missing)
O9 - Extra 'Tools' menuitem: 网址大全 - {C18CB140-0BBB-11D4-8FE8-0088CC102438} - http://www.k369.com/mp3wz.htm (file missing)
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {276BF72D-CA22-4237-9BCF-593B4E490DE9} (DownLoad Class) - http://img.china.alibaba.com/club/upload/cy2101/onlinesetupimg/atdownload.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2287427E-8AA3-4FC7-AEB3-10F97E6B941C}: NameServer = 202.102.134.68 202.102.128.68
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: C:\WINDOWS\system32\SoDAHK.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: P4P Service - Sohu.com Inc. - C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
O23 - Service: Remote Log - Beijing zhongsou online software - C:\WINDOWS\system32\ServeHost.exe
O23 - Service: Universal Disk Manager - Unknown owner - C:\WINDOWS\diskman.exe
O23 - Service: Venturi2 Client (Venturi2) - Fourelle Systems, Inc - C:\Program Files\Venturi2\Client\ventc.exe

mopery - 2006-8-12 8:15:00
http://www.pctutu.com/srmsdown.asp
下载超级兔子..用超级兔子清理王卸载流氓软件...(安全模式...)


处理完重新扫描日志..
心情niwota - 2006-8-12 8:25:00
[Main]
Program=超级兔子IE修复专家
Version=V7.75
WindowsVersion=Windows XP
IEVersion=6.0.2900.2180
WinDir=C:\WINDOWS\
WinSystemDir=C:\WINDOWS\system32\
USERPROFILE=C:\Documents and Settings\user
Admin=1
Detail=1
Date=2006-08-12
Time=08:12:55
Code=,
CDCode=,
Reg=0

[Soft]
1=百度超级搜霸
2=3721网络实名
3=3721上网助手
4=雅虎助手
5=划词搜索
6=DuDu 下载加速器
7=DMCast/桌面传媒/IE-Bar
8=青娱乐
9=搜狗直通车/搜狗工具条
10=地址栏直通车
11=网上购物精彩图铃
12=ShareHelper
13=SearchNet (中搜地址栏搜索)
14=酷站导航
15=桌面媒体
Max=15

[IE]
1_HKey=HKEY_CURRENT_USER
1_Key=Software\Microsoft\Internet Explorer\Main
1_Name=Window Title
1_Value=
2_HKey=HKEY_CURRENT_USER
2_Key=Software\Microsoft\Internet Explorer\Main
2_Name=Local Page
2_Value=C:\WINDOWS\system32\blank.htm
3_HKey=HKEY_CURRENT_USER
3_Key=Software\Microsoft\Internet Explorer\Main
3_Name=Search Page
3_Value=http://g.msn.com/0SEZHCN/SAOS01?FORM=TOOLBR
4_HKey=HKEY_CURRENT_USER
4_Key=Software\Microsoft\Internet Explorer\Main
4_Name=Start Page
4_Value=http://www.msn.com.cn
5_HKey=HKEY_CURRENT_USER
5_Key=Software\Microsoft\Internet Explorer\Main
5_Name=Default_page_url
5_Value=
6_HKey=HKEY_CURRENT_USER
6_Key=Software\Microsoft\Internet Explorer\Main
6_Name=First Home Page
6_Value=
7_HKey=HKEY_LOCAL_MACHINE
7_Key=Software\Microsoft\Internet Explorer\Main
7_Name=Search Page
7_Value=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
8_HKey=HKEY_LOCAL_MACHINE
8_Key=Software\Microsoft\Internet Explorer\Main
8_Name=Start Page
8_Value=http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
9_HKey=HKEY_LOCAL_MACHINE
9_Key=Software\Microsoft\Internet Explorer\Main
9_Name=Default_page_url
9_Value=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
10_HKey=HKEY_LOCAL_MACHINE
10_Key=Software\Microsoft\Internet Explorer\Main
10_Name=First Home Page
10_Value=
11_HKey=HKEY_LOCAL_MACHINE
11_Key=Software\Microsoft\Internet Explorer\Main
11_Name=Search Page
11_Value=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
12_HKey=HKEY_LOCAL_MACHINE
12_Key=Software\Microsoft\Internet Explorer\Main
12_Name=Start Page
12_Value=http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
Max=12
心情niwota - 2006-8-12 8:26:00
[IE2]
1_HKey=HKEY_CURRENT_USER
1_Key=Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
1_Name={01E04581-4EEE-11D0-BFE9-00AA005B4383}
1_FileName=%SystemRoot%\system32\browseui.dll
1_FileSize=1016832
1_FileDate=2004-8-23 16:00:00
1_FileVersion=6.0.2900.2180
2_HKey=HKEY_CURRENT_USER
2_Key=Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
2_Name={0E5CBF21-D15F-11D0-8301-00AA005B4383}
2_FileName=%SystemRoot%\system32\SHELL32.dll
2_FileSize=8241664
2_FileDate=2004-8-23 16:00:00
2_FileVersion=6.0.2900.2180
3_HKey=HKEY_CURRENT_USER
3_Key=Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
3_Name={89FDCC4B-8D91-49B0-81A6-18BCFF582735}
3_FileName=
3_FileVersion=
4_HKey=HKEY_CURRENT_USER
4_Key=Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
4_Name={2318C2B1-4965-11D4-9B18-009027A5CD4F}
4_FileName=c:\program files\google\googletoolbar2.dll
4_FileSize=1178624
4_FileDate=2006-2-14 20:08:22
4_FileVersion=3.0.131.0
5_HKey=HKEY_LOCAL_MACHINE
5_Key=SOFTWARE\Microsoft\Internet Explorer\Toolbar
5_Name={E0E899AB-F487-11D5-8D29-0050BA6940E3}
5_FileName=
5_FileVersion=
6_HKey=HKEY_LOCAL_MACHINE
6_Key=SOFTWARE\Microsoft\Internet Explorer\Toolbar
6_Name={406F94F0-504F-4a40-8DFD-58B0666ABEBD}
6_FileName=C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
6_FileSize=221184
6_FileDate=2006-5-15 16:12:06
6_FileVersion=2.1.8.1048
7_HKey=HKEY_LOCAL_MACHINE
7_Key=SOFTWARE\Microsoft\Internet Explorer\Toolbar
7_Name={2318C2B1-4965-11d4-9B18-009027A5CD4F}
7_FileName=c:\program files\google\googletoolbar2.dll
7_FileSize=1178624
7_FileDate=2006-2-14 20:08:22
7_FileVersion=3.0.131.0
8_HKey=HKEY_LOCAL_MACHINE
8_Key=SOFTWARE\Microsoft\Internet Explorer\Toolbar
8_Name={DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C}
8_FileName=C:\Documents and Settings\user\桌面\P4P\ToolBar.dll
8_FileVersion=
9_HKey=HKEY_LOCAL_MACHINE
9_Key=SOFTWARE\Microsoft\Internet Explorer\Toolbar
9_Name={B580CF65-E151-49C3-B73F-70B13FCA8E86}
9_FileName=C:\Progra~1\Baidu\bar\BaiDuBar.dll
9_FileSize=1028187
9_FileDate=2006-7-25 20:40:36
9_FileVersion=2.0.2.99
Max=9

心情niwota - 2006-8-12 8:27:00
[IE3]
1_HKey=HKEY_CURRENT_USER
1_Key=Software\Microsoft\Internet Explorer\MenuExt\&使用DuDu下载
1_FileName=res://C:\Program Files\DuDu\Speed\dddmext.dll/202
1_FileVersion=
2_HKey=HKEY_CURRENT_USER
2_Key=Software\Microsoft\Internet Explorer\MenuExt\&使用DuDu下载全部链接
2_FileName=res://C:\Program Files\DuDu\Speed\dddmext.dll/203
2_FileVersion=
3_HKey=HKEY_CURRENT_USER
3_Key=Software\Microsoft\Internet Explorer\MenuExt\&使用DuDu下载选择链接
3_FileName=res://C:\Program Files\DuDu\Speed\dddmext.dll/204
3_FileVersion=
4_HKey=HKEY_CURRENT_USER
4_Key=Software\Microsoft\Internet Explorer\MenuExt\Google 搜索(&G)
4_FileName=res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
4_FileVersion=
5_HKey=HKEY_CURRENT_USER
5_Key=Software\Microsoft\Internet Explorer\MenuExt\上传到QQ网络硬盘
5_FileName=D:\游戏\QQ\AddToNetDisk.htm
5_FileSize=534
5_FileDate=2005-9-15 18:19:48
5_FileVersion=
6_HKey=HKEY_CURRENT_USER
6_Key=Software\Microsoft\Internet Explorer\MenuExt\使用搜狗直通车下载
6_FileName=C:\Documents and Settings\user\桌面\P4P\dl.htm
6_FileVersion=
7_HKey=HKEY_CURRENT_USER
7_Key=Software\Microsoft\Internet Explorer\MenuExt\反向链接
7_FileName=res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
7_FileVersion=
8_HKey=HKEY_CURRENT_USER
8_Key=Software\Microsoft\Internet Explorer\MenuExt\发送图片到手机
8_FileName=C:\Documents and Settings\user\桌面\P4P\cx.htm
8_FileVersion=
9_HKey=HKEY_CURRENT_USER
9_Key=Software\Microsoft\Internet Explorer\MenuExt\添加到QQ自定义面板
9_FileName=D:\游戏\QQ\AddPanel.htm
9_FileSize=1815
9_FileDate=2005-9-15 18:19:48
9_FileVersion=
10_HKey=HKEY_CURRENT_USER
10_Key=Software\Microsoft\Internet Explorer\MenuExt\添加到QQ表情
10_FileName=D:\游戏\QQ\AddEmotion.htm
10_FileSize=534
10_FileDate=2005-9-15 18:19:48
10_FileVersion=
11_HKey=HKEY_CURRENT_USER
11_Key=Software\Microsoft\Internet Explorer\MenuExt\添加到“我的订阅”
11_FileName=C:\Documents and Settings\user\桌面\P4P\rss.htm
11_FileVersion=
12_HKey=HKEY_CURRENT_USER
12_Key=Software\Microsoft\Internet Explorer\MenuExt\添加到雅虎订阅(&Y)
12_FileName=res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT
12_FileVersion=
13_HKey=HKEY_CURRENT_USER
13_Key=Software\Microsoft\Internet Explorer\MenuExt\用QQ彩信发送该图片
13_FileName=D:\游戏\QQ\SendMMS.htm
13_FileSize=519
13_FileDate=2005-9-15 18:19:54
13_FileVersion=
14_HKey=HKEY_CURRENT_USER
14_Key=Software\Microsoft\Internet Explorer\MenuExt\类似网页
14_FileName=res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
14_FileVersion=
15_HKey=HKEY_CURRENT_USER
15_Key=Software\Microsoft\Internet Explorer\MenuExt\缓存的网页快照
15_FileName=res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
15_FileVersion=
16_HKey=HKEY_CURRENT_USER
16_Key=Software\Microsoft\Internet Explorer\MenuExt\翻译英文字词(&T)
16_FileName=res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
16_FileVersion=
17_HKey=HKEY_CURRENT_USER
17_Key=Software\Microsoft\Internet Explorer\MenuExt\雅虎搜索
17_FileName=res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
17_FileVersion=
18_HKey=HKEY_LOCAL_MACHINE
18_Key=SOFTWARE\Microsoft\Internet Explorer\Extensions\{8755CE6E-0BF7-4441-8751-FB728941B0B4}
18_Clsid={E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16}
18_ButtonText=我的订阅
18_MenuText=
18_FileName=
18_FileVersion=
19_HKey=HKEY_LOCAL_MACHINE
19_Key=SOFTWARE\Microsoft\Internet Explorer\Extensions\{C18CB140-0BBB-11D4-8FE8-0088CC102438}
19_Clsid={1FBA04EE-3024-11D2-8F1F-0000F87ABD16}
19_ButtonText=网址大全
19_MenuText=网址大全
19_FileName=
19_FileVersion=
20_HKey=HKEY_LOCAL_MACHINE
20_Key=SOFTWARE\Microsoft\Internet Explorer\Extensions\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}
20_Clsid={1FBA04EE-3024-11d2-8F1F-0000F87ABD16}
20_ButtonText=情景聊天
20_MenuText=
20_FileName=
20_FileVersion=
21_HKey=HKEY_CURRENT_USER
21_Key=SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping
21_Clsid=
21_ButtonText=
21_MenuText=
21_FileName=
21_FileVersion=
22_HKey=HKEY_LOCAL_MACHINE
22_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00018593-C6BD-46F7-9349-DBA1AA674C90}
22_Clsid=dddmont Class
22_FileName=C:\Program Files\DuDu\Speed\dddiemon.dll
22_FileSize=106496
22_FileDate=2006-7-26 16:20:44
22_FileVersion=5.0.0.6
23_HKey=HKEY_LOCAL_MACHINE
23_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{08A312BB-5409-49FC-9347-54BB7D069AC6}
23_Clsid=IEMonitor Class
23_FileName=C:\Program Files\DeskAdTop\deskipn.dll
23_FileSize=32768
23_FileDate=2006-6-13 14:22:34
23_FileVersion=1.0.0.1
24_HKey=HKEY_LOCAL_MACHINE
24_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0CA51D02-7739-43EA-8D9A-1E8AD4327B03}
24_Clsid=CPub Object
24_FileName=C:\Documents and Settings\user\桌面\P4P\sodaie.dll
24_FileVersion=
25_HKey=HKEY_LOCAL_MACHINE
25_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0176FE-008B-4706-90F5-BBA532A49731}
25_Clsid=IE Address Browser Helper
25_FileName=C:\Program Files\SearchNet\SNHpr.dll
25_FileSize=40960
25_FileDate=2006-8-3 14:48:58
25_FileVersion=1.0.3.0
26_HKey=HKEY_LOCAL_MACHINE
26_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33BBE430-0E42-4f12-B075-8D21ACB10DCB}
26_Clsid=Yahoo!Photo
26_FileName=C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll
26_FileSize=114688
26_FileDate=2006-3-21 13:51:24
26_FileVersion=1.1.3.1035
27_HKey=HKEY_LOCAL_MACHINE
27_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{38928D50-8A48-44C2-945F-D2F23F771410}
27_Clsid=AntiFish Class
27_FileName=C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll
27_FileSize=163840
27_FileDate=2005-12-15 14:48:40
27_FileVersion=1.0.2.1002
28_HKey=HKEY_LOCAL_MACHINE
28_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CE496D1-1746-41CD-9489-3C0B93DF10E2}
28_Clsid=IE Browser Helper
28_FileName=C:\WINDOWS\Downlo~1\o97z4.dll
28_FileSize=24064
28_FileDate=2006-8-3 14:48:52
28_FileVersion=2.0.2.5
29_HKey=HKEY_LOCAL_MACHINE
29_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{406F94F0-504F-4a40-8DFD-58B0666ABEBD}
29_Clsid=雅虎助手
29_FileName=C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
29_FileSize=221184
29_FileDate=2006-5-15 16:12:06
29_FileVersion=2.1.8.1048
30_HKey=HKEY_LOCAL_MACHINE
30_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{54EBD53A-9BC1-480B-966A-843A333CA162}
30_Clsid=QQBrowserHelperObject Class
30_FileName=D:\游戏\QQ\QQIEHelper.dll
30_FileSize=184320
30_FileDate=2005-9-14 13:38:44
30_FileVersion=1.1.0.5
31_HKey=HKEY_LOCAL_MACHINE
31_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{62EED7C6-9F02-42f9-B634-98E2899E147B}
31_Clsid=DragSearch BHO
31_FileName=C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL
31_FileSize=49152
31_FileDate=2005-11-14 19:39:22
31_FileVersion=1.2.7.1006
32_HKey=HKEY_LOCAL_MACHINE
32_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77FEF28E-EB96-44FF-B511-3185DEA48697}
32_Clsid=BandIE Class
32_FileName=C:\Progra~1\Baidu\bar\BaiDuBar.dll
32_FileSize=1028187
32_FileDate=2006-7-25 20:40:36
32_FileVersion=2.0.2.99
33_HKey=HKEY_LOCAL_MACHINE
33_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}
33_Clsid=Google Toolbar Helper
33_FileName=c:\program files\google\googletoolbar2.dll
33_FileSize=1178624
33_FileDate=2006-2-14 20:08:22
33_FileVersion=3.0.131.0
心情niwota - 2006-8-12 8:28:00
34_HKey=HKEY_LOCAL_MACHINE
34_Key=SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java
34_Download=file://C:\WINDOWS\Java\classes\xmldso.cab
34_FileName=
34_FileVersion=
35_HKey=HKEY_LOCAL_MACHINE
35_Key=SOFTWARE\Microsoft\Code Store Database\Distribution Units\{00B71CFB-6864-4346-A978-C0A14556272C}
35_Download=http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
35_FileName=
35_FileVersion=
36_HKey=HKEY_LOCAL_MACHINE
36_Key=SOFTWARE\Microsoft\Code Store Database\Distribution Units\{276BF72D-CA22-4237-9BCF-593B4E490DE9}
36_Download=http://img.china.alibaba.com/club/upload/cy2101/onlinesetupimg/atdownload.cab
36_FileName=C:\WINDOWS\Downloaded Program Files\atdownload.inf
36_FileSize=248
36_FileDate=2005-7-7 16:02:26
36_FileVersion=
37_HKey=HKEY_LOCAL_MACHINE
37_Key=SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}
37_Download=http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
37_FileName=C:\WINDOWS\Downloaded Program Files\MSNPupld.inf
37_FileSize=587
37_FileDate=2005-10-14 12:49:54
37_FileVersion=
38_HKey=HKEY_LOCAL_MACHINE
38_Key=SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
38_Download=http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
38_FileName=
38_FileVersion=
39_HKey=HKEY_LOCAL_MACHINE
39_Key=SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
39_Download=http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
39_FileName=C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.inf
39_FileSize=227
39_FileDate=2005-6-30 15:19:34
39_FileVersion=
40_HKey=HKEY_LOCAL_MACHINE
40_Key=SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}
40_Download=http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
40_FileName=C:\WINDOWS\Downloaded Program Files\swflash.inf
40_FileSize=5019
40_FileDate=2006-3-27 13:00:04
40_FileVersion=
41_HKey=HKEY_LOCAL_MACHINE
41_Key=SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{03D8E49B-63EA-4E15-BB60-E6EC923548C3}
41_NameServer=
41_Clsid=
41_FileName=
41_FileVersion=
42_HKey=HKEY_LOCAL_MACHINE
42_Key=SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2287427E-8AA3-4FC7-AEB3-10F97E6B941C}
42_NameServer=202.102.134.68 202.102.128.68
42_Clsid=
42_FileName=
42_FileVersion=
43_HKey=HKEY_LOCAL_MACHINE
43_Key=SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{320D6A29-72EC-41B9-A25A-22148A6FD444}
43_NameServer=
43_Clsid=
43_FileName=
43_FileVersion=
44_HKey=HKEY_LOCAL_MACHINE
44_Key=SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{37128D33-4B55-4A5D-879E-BC840FD32C8A}
44_NameServer=
44_Clsid=
44_FileName=
44_FileVersion=
45_HKey=HKEY_LOCAL_MACHINE
45_Key=SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{4DAFA87D-7ED3-4416-99F7-F0CA25413912}
45_NameServer=
45_Clsid=
45_FileName=
45_FileVersion=
46_HKey=HKEY_LOCAL_MACHINE
46_Key=SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{A15FE80C-B952-4DDD-BCE4-6A00F5695FB2}
46_NameServer=
46_Clsid=
46_FileName=
46_FileVersion=
Max=46

[Link]
1_HKey=HKEY_CLASSES_ROOT
1_Key=.exe
1_Name=
1_Value=exefile
1_HKeyLink=HKEY_CLASSES_ROOT
1_KeyLink=exefile\shell\open\command
1_NameLink=
1_ValueLink="%1" %*
2_HKey=HKEY_CLASSES_ROOT
2_Key=.com
2_Name=
2_Value=comfile
2_HKeyLink=HKEY_CLASSES_ROOT
2_KeyLink=comfile\shell\open\command
2_NameLink=
2_ValueLink="%1" %*
3_HKey=HKEY_CLASSES_ROOT
3_Key=.lnk
3_Name=
3_Value=lnkfile
3_HKeyLink=HKEY_CLASSES_ROOT
3_KeyLink=lnkfile\CLSID
3_NameLink=
3_ValueLink={00021401-0000-0000-C000-000000000046}
心情niwota - 2006-8-12 8:28:00
4_HKey=HKEY_CLASSES_ROOT
4_Key=.txt
4_Name=
4_Value=txtfile
4_HKeyLink=HKEY_CLASSES_ROOT
4_KeyLink=txtfile\shell\open\command
4_NameLink=
4_ValueLink=%SystemRoot%\system32\NOTEPAD.EXE %1
4_FileSizeLink=66560
4_FileDateLink=2004-8-23 16:00:00
4_FileVersionLink=5.1.2600.2180
5_HKey=HKEY_CLASSES_ROOT
5_Key=.htm
5_Name=
5_Value=htmlfile
5_HKeyLink=HKEY_CLASSES_ROOT
5_KeyLink=htmlfile\shell\open\command
5_NameLink=
5_ValueLink="D:\游戏\TT\TTraveler.exe" "%1"
5_FileVersionLink=
6_HKey=HKEY_CLASSES_ROOT
6_Key=.html
6_Name=
6_Value=htmlfile
6_HKeyLink=HKEY_CLASSES_ROOT
6_KeyLink=htmlfile\shell\open\command
6_NameLink=
6_ValueLink="D:\游戏\TT\TTraveler.exe" "%1"
6_FileVersionLink=
7_HKey=HKEY_CLASSES_ROOT
7_Key=.url
7_Name=
7_Value=InternetShortcut
7_HKeyLink=HKEY_CLASSES_ROOT
7_KeyLink=InternetShortcut\shell\open\command
7_NameLink=
7_ValueLink=rundll32.exe shdocvw.dll,OpenURL %l
8_HKey=HKEY_CLASSES_ROOT
8_Key=PROTOCOLS\Filter\text/html
8_Name=CLSID
8_Value=
9_HKey=HKEY_CLASSES_ROOT
9_Key=PROTOCOLS\Filter\text/plain
9_Name=CLSID
9_Value=
10_HKey=HKEY_LOCAL_MACHINE
10_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
10_Name=
10_Value=http://
11_HKey=HKEY_LOCAL_MACHINE
11_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes
11_Name=www
11_Value=http://
Max=11

[Shdoclc]
1_FileSize=498176
1_FileDate=2004-8-23 16:00:00
1_FileVersion=6.0.2900.2180
Max=1

[AppInit_DLLs]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
1_Name=AppInit_DLLs
1_Value=C:\WINDOWS\system32\SoDAHK.DLL
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
2_Name=Userinit
2_Value=C:\WINDOWS\system32\userinit.exe,
2_FileSize=23552
2_FileDate=2004-8-23 16:00:00
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
3_Name=Shell
3_Value=Explorer.exe
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
4_Name=System
3_Value=
Max=4

[WinSock2NameSpace]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
1_Name=DisplayString
1_Value=Tcpip
1_Enabled=1
1_LibraryPath=%SystemRoot%\System32\mswsock.dll
1_FileSize=240640
1_FileDate=2004-8-23 16:00:00
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
2_Name=DisplayString
2_Value=NTDS
2_Enabled=1
2_LibraryPath=%SystemRoot%\System32\winrnr.dll
2_FileSize=16896
2_FileDate=2004-8-23 16:00:00
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
3_Name=DisplayString
3_Value=网络位置知晓 (NLA) 名称空间
3_Enabled=1
3_LibraryPath=%SystemRoot%\System32\mswsock.dll
3_FileSize=240640
3_FileDate=2004-8-23 16:00:00
Max=3
心情niwota - 2006-8-12 8:30:00
[WinSock2Protocol]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001
1_Name=PackedCatalogItem
1_FileName=%SystemRoot%\system32\mswsock.dll
1_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ????昀?      ? ????耀?銡?ā              ? ? ? ? ā ?          ?匀????吀挀瀀椀瀀?嬀吀?倀??倀崀                                                                                                                                                                                                                                           
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002
2_Name=PackedCatalogItem
2_FileName=%SystemRoot%\system32\mswsock.dll
2_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ??????      ? ????耀?銡?ā              ? ? ? ? ? ?      ?  MSAFD Tcpip [UDP/IP]                                                                                                                                                                                                                                           
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003
3_Name=PackedCatalogItem
3_FileName=%SystemRoot%\system32\mswsock.dll
3_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ??????      ? ????耀?銡?ā              ? ? ? ? ?  ?    ?  MSAFD Tcpip [RAW/IP]                                                                                                                                                                                                                                           
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004
4_Name=PackedCatalogItem
4_FileName=%SystemRoot%\system32\rsvpsp.dll
4_Value= 餀r  珺  刀u  皳  ?x  祵  ?z  簮? 結  ?~  耉  愀?  ??  萚ò  蕲ò  蛓  ??  销?  誷? 谏ò  走ò  軑  ??  錀?  鋴  唀?  ??  霗ò?☉       ?鵠?????  ???蠂??嚤聵?畕聆?           ?  刀匀嘀倀?唀?倀?匀攀爀瘀椀挀攀?倀爀漀瘀椀搀攀爀 ā ?? 退?  ?粒?  ??粒?粒  ??鋻??????鋮硼鋻??燿鋻??具??畕? ? ??耀?@    唿屵?攀瘀椀挀攀尀笀????????? ??????????????????????????紀 ??????????紀 ?琂????粓錿塼??? ?垊幵?? ???粓錿? 堀?    ??錿?粓 ??粓錿|  堀 ?粓 ??  ? 倀??? ?????  ??尀?甀爀爀攀? ? ? ā ?粓
5_HKey=HKEY_LOCAL_MACHINE
5_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005
5_Name=PackedCatalogItem
5_FileName=%SystemRoot%\system32\rsvpsp.dll
5_Value= 餀r  珺  刀u  皳  ?x  祵  ?z  簮? 結  ?~  耉  愀?  ??  萚ò  蕲ò  蛓  ??  销?  誷? 谏ò  走ò  軑  ??  錀?  鋴  唀?  ??  霗ò??       ?鵠?????  ? ??  谀?専錍|?? ? ? ? ā ?          刀匀嘀倀?吀?倀?匀攀爀瘀椀挀攀?倀爀漀瘀椀搀攀爀 ?   ??婄u 怀?簀???   ?専錍|?    全尿錍|??粓??粓埀? ?   ? 兰? ? ?????瀿????  ? 瀀?? ? ?粓? ??   ?@ 鴰?? 浏ā埜怿 ?  ????錏? ?????  ?専錍|??粓??粓??  ?  ?  耀  ??      ? ???? @  ?栁???倂?ī嘼畕  ??? ?????粒?粒??  ??
6_HKey=HKEY_LOCAL_MACHINE
6_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006
6_Name=PackedCatalogItem
6_FileName=%SystemRoot%\system32\mswsock.dll
6_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ??????         弘玍?锑è往??ā              ? ? ? ? ? ??        ?匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀?? ?????????????????????????????????紀崀?匀?儀倀????吀??                                                                                                                                                                         
7_HKey=HKEY_LOCAL_MACHINE
7_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007
7_Name=PackedCatalogItem
7_FileName=%SystemRoot%\system32\mswsock.dll
7_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ??????         弘玍?锑è往??ā              ? ? ? ? ? ??        ?匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀?? ?????????????????????????????????紀崀???吀??刀????                                                                                                                                                                         
8_HKey=HKEY_LOCAL_MACHINE
8_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008
8_Name=PackedCatalogItem
8_FileName=%SystemRoot%\system32\mswsock.dll
心情niwota - 2006-8-12 8:30:00
8_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ??????      ?  弘玍?锑è往??ā              ? ? ? ? ?  ?        MSAFD NetBIOS [\Device\NetBT_Tcpip_{37128D33-4B55-4A5D-879E-BC840FD32C8A}] SEQPACKET 0                                                                                                                                                                         
9_HKey=HKEY_LOCAL_MACHINE
9_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009
9_Name=PackedCatalogItem
9_FileName=%SystemRoot%\system32\mswsock.dll
9_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ??????      ?  弘玍?锑è往??ā              ? ? ? ? ?  ?        MSAFD NetBIOS [\Device\NetBT_Tcpip_{37128D33-4B55-4A5D-879E-BC840FD32C8A}] DATAGRAM 0                                                                                                                                                                         
10_HKey=HKEY_LOCAL_MACHINE
10_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010
10_Name=PackedCatalogItem
10_FileName=%SystemRoot%\system32\mswsock.dll
10_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ??????         弘玍?锑è往??ā              ? ? ? ? ? ???        MSAFD NetBIOS [\Device\NetBT_Tcpip_{A15FE80C-B952-4DDD-BCE4-6A00F5695FB2}] SEQPACKET 1                                                                                                                                                                         
11_HKey=HKEY_LOCAL_MACHINE
11_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011
11_Name=PackedCatalogItem
11_FileName=%SystemRoot%\system32\mswsock.dll
11_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ??????         弘玍?锑è往??ā              ? ? ? ? ? ???        MSAFD NetBIOS [\Device\NetBT_Tcpip_{A15FE80C-B952-4DDD-BCE4-6A00F5695FB2}] DATAGRAM 1                                                                                                                                                                         
12_HKey=HKEY_LOCAL_MACHINE
12_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012
12_Name=PackedCatalogItem
12_FileName=%SystemRoot%\system32\mswsock.dll
12_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ??????         弘玍?锑è往??ā              ? ? ? ? ? ??        ?匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀????????????????????????? ??????????紀崀?匀?儀倀????吀??                                                                                                                                                                         
13_HKey=HKEY_LOCAL_MACHINE
13_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013
13_Name=PackedCatalogItem
13_FileName=%SystemRoot%\system32\mswsock.dll
13_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ??????         弘玍?锑è往??ā              ? ? ? ? ? ??        ?匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀????????????????????????? ??????????紀崀???吀??刀????                                                                                                                                                                         
14_HKey=HKEY_LOCAL_MACHINE
14_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014
14_Name=PackedCatalogItem
14_FileName=%SystemRoot%\system32\mswsock.dll
14_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ??????         弘玍?锑è往??ā              ? ? ? ? ? ??        ?匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀 ????????????????????? ?????????????紀崀?匀?儀倀????吀??                                                                                                                                                                         
15_HKey=HKEY_LOCAL_MACHINE
15_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015
15_Name=PackedCatalogItem
15_FileName=%SystemRoot%\system32\mswsock.dll
15_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ??????         弘玍?锑è往??ā              ? ? ? ? ? ??        ?匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀 ????????????????????? ?????????????紀崀???吀??刀????                                                                                                                                                                         
16_HKey=HKEY_LOCAL_MACHINE
16_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016
16_Name=PackedCatalogItem
16_FileName=%SystemRoot%\system32\mswsock.dll
16_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ??????         弘玍?锑è往??ā              ? ? ? ? ? ??        ?匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀????????????????????????? ??????????紀崀?匀?儀倀????吀??                                                                                                                                                                         
17_HKey=HKEY_LOCAL_MACHINE
17_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000017
17_Name=PackedCatalogItem
17_FileName=%SystemRoot%\system32\mswsock.dll
17_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ??????         弘玍?锑è往??ā              ? ? ? ? ? ??        ?匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀????????????????????????? ??????????紀崀???吀??刀????                                                                                                                                                                         
18_HKey=HKEY_LOCAL_MACHINE
18_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000018
18_Name=PackedCatalogItem
18_FileName=vlsp.dll ot%\system32\mswsock.dll
18_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ????        ? 焀齥?沪譌???п              @                VENTURI_TP ?錿|    ????????蠟????????㈱??????? 搀晥桧橩??瀀牱遳?砀穹? 怀扡??? 氀湭聯?琀癵硷穹??  ?粓倨?儀錅??粓?  ?粓????  錿????儀錅? ? ???栠???????? ??怠   ???? 怀 ?t ????粒 ?粒??  ?? ????鋮灼錅??淿錅?粓   倰?錿ぼ?  ??????? ā ?  ?   ????粓倰田@          ???? む?      ?? 
19_HKey=HKEY_LOCAL_MACHINE
19_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000019
19_Name=PackedCatalogItem
心情niwota - 2006-8-12 8:30:00
19_FileName=vlsp.dll ot%\system32\mswsock.dll
19_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ????昀      ? 氀濰锃???? ??                         VENTURI_TP MSAFD Tcpip [TCP/IP]                                                                                                                                                                                                                               
20_HKey=HKEY_LOCAL_MACHINE
20_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000020
20_Name=PackedCatalogItem
20_FileName=vlsp.dll ot%\system32\mswsock.dll
20_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ?????      ? 謀????鱡??? ??                     ?  嘀?一吀唀刀?开吀倀??匀????吀挀瀀椀瀀?嬀唀?倀??倀崀                                                                                                                                                                                                                               
21_HKey=HKEY_LOCAL_MACHINE
21_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000021
21_Name=PackedCatalogItem
21_FileName=vlsp.dll ot%\system32\mswsock.dll
21_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ?????      ? ???伃媛竓?З  Д ?          ? ? ? ? ?  ?    ?  VENTURI_TP MSAFD Tcpip [RAW/IP]                                                                                                                                                                                                                               
22_HKey=HKEY_LOCAL_MACHINE
22_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000022
22_Name=PackedCatalogItem
22_FileName=vlsp.dll ot%\system32\mswsock.dll
22_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ?????&      ? 耀鯌??箺邈??? ?? 麗??畖? 唿??? ? ? ? ? ?      ?  VENTURI_TP RSVP UDP Service Provider 粒?  ??粒?粒  ??鋻??????鋮硼鋻??燿鋻??具??畕? ? ??耀?@    唿屵?攀瘀椀挀攀尀笀????????? ??????????????????????????紀 ??????????紀 ?琂????粓錿塼??? ?垊幵?? ???粓錿? 堀?    ??錿?粓 ??粓錿|  堀 ?粓 ??  ? 倀??? ?????  ??尀?甀爀爀攀? ? ? ā ?粓
23_HKey=HKEY_LOCAL_MACHINE
23_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000023
23_Name=PackedCatalogItem
23_FileName=vlsp.dll ot%\system32\mswsock.dll
23_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ????昀      ? 一嚕瘿?????Й  Д ??  谀?専錍|?? ? ? ? ā ?          嘀?一吀唀刀?开吀倀?刀匀嘀倀?吀?倀?匀攀爀瘀椀挀攀?倀爀漀瘀椀搀攀爀  怀?簀???   ?専錍|?    全尿錍|??粓??粓埀? ?   ? 兰? ? ?????瀿????  ? 瀀?? ? ?粓? ??   ?@ 鴰?? 浏ā埜怿 ?  ????錏? ?????  ?専錍|??粓??粓??  ?  ?  耀  ??      ? ???? @  ?栁???倂?ī嘼畕  ??? ?????粒?粒??  ??
24_HKey=HKEY_LOCAL_MACHINE
24_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000024
24_Name=PackedCatalogItem
24_FileName=vlsp.dll ot%\system32\mswsock.dll
24_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ?????        搀寲焠聦????? ??          ? ? ? ? ? ??        嘀?一吀唀刀?开吀倀??匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀?? ?????????????????????????????????紀崀?匀?儀倀????吀??                                                                                                                                                             
25_HKey=HKEY_LOCAL_MACHINE
25_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000025
25_Name=PackedCatalogItem
25_FileName=vlsp.dll ot%\system32\mswsock.dll
25_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ?????        簀?~?????п  Д ?               _?        VENTURI_TP MSAFD NetBIOS [\Device\NetBT_Tcpip_{320D6A29-72EC-41B9-A25A-22148A6FD444}] DATAGRAM 5                                                                                                                                                               
26_HKey=HKEY_LOCAL_MACHINE
26_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000026
26_Name=PackedCatalogItem
26_FileName=vlsp.dll ot%\system32\mswsock.dll
26_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ?????      ? ???伨岨??п  Д ?                耀        嘀?一吀唀刀?开吀倀??匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀???????????????????????????? ???????紀崀?匀?儀倀????吀?                                                                                                                                                              
27_HKey=HKEY_LOCAL_MACHINE
27_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000027
27_Name=PackedCatalogItem
27_FileName=vlsp.dll ot%\system32\mswsock.dll
27_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ?????      ? 怀茚牍殡衍??xН  Д ?                耀        嘀?一吀唀刀?开吀倀??匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀???????????????????????????? ???????紀崀???吀??刀???                                                                                                                                                                
28_HKey=HKEY_LOCAL_MACHINE
28_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000028
28_Name=PackedCatalogItem
28_FileName=vlsp.dll ot%\system32\mswsock.dll
28_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ?????        ???檴??п  Д ?               ??        嘀?一吀唀刀?开吀倀??匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀?????? ???????????????????  ????????紀崀?匀?儀倀????吀??                                                                                                                                                             
29_HKey=HKEY_LOCAL_MACHINE
29_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000029
29_Name=PackedCatalogItem
29_FileName=vlsp.dll ot%\system32\mswsock.dll
29_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ?????        錀???肮?驷?П  Д ?               ??        嘀?一吀唀刀?开吀倀??匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀?????? ???????????????????  ????????紀崀???吀??刀????                                                                                                                                                               
30_HKey=HKEY_LOCAL_MACHINE
30_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000030
30_Name=PackedCatalogItem
30_FileName=vlsp.dll ot%\system32\mswsock.dll
30_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ?????        ????掕?惉?? ??          ? ? ? ? ? ??        嘀?一吀唀刀?开吀倀??匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀????????????????????????? ??????????紀崀?匀?儀倀????吀??                                                                                                                                                             
31_HKey=HKEY_LOCAL_MACHINE
31_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000031
31_Name=PackedCatalogItem
心情niwota - 2006-8-12 8:31:00
31_FileName=vlsp.dll ot%\system32\mswsock.dll
31_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ?????        尀???????? ??          ? ? ? ? ? ??        嘀?一吀唀刀?开吀倀??匀????一攀琀??伀匀?嬀尀?攀瘀椀挀攀尀一攀琀?吀开吀挀瀀椀瀀开笀????????????????????????? ??????????紀崀???吀??刀????                                                                                                                                                               
32_HKey=HKEY_LOCAL_MACHINE
32_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000032
32_Name=PackedCatalogItem
32_FileName=vlsp.dll ot%\system32\mswsock.dll
32_Value= 犙  切s  畒  ?v  研  甀y  竖  ?|?倀}  纨  ??  腡ò  芹  ??  爀?  ??  蠴ò  覕  ?????  瀀?  ??  進ò  醓  ??  鑕ò  閶  ?????        ?摵??鹍???Т  Д А               _?        VENTURI_TP MSAFD NetBIOS [\Device\NetBT_Tcpip_{03D8E49B-63EA-4E15-BB60-E6EC923548C3}] SEQPACKET 3                                                                                                                                                             
Max=32

[WinSock2Winsock]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=System\CurrentControlSet\Services\Winsock2\Winsock
1_Name=PathName
1_Value=
1_Found=0
Max=1

[WOW]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SYSTEM\CurrentControlSet\Control\WOW
1_Name=cmdline
1_Value=%SystemRoot%\system32\ntvdm.exe -o
1_Filename=C:\WINDOWS\SYSTEM32\NTVDM.EXE
1_FileSize=417280
1_FileDate=2004-8-23 16:00:00
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SYSTEM\CurrentControlSet\Control\WOW
2_Name=wowcmdline
2_Value=%SystemRoot%\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386
2_Filename=C:\WINDOWS\SYSTEM32\NTVDM.EXE
2_FileSize=417280
2_FileDate=2004-8-23 16:00:00
Max=2

[ShellExecuteHooks]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
1_Name={AEB6717E-7E19-11d0-97EE-00C04FD91972}
1_ClsidName=URL 执行挂钩
1_FileName=C:\WINDOWS\system32\shell32.dll
1_FileSize=8241664
1_FileDate=2004-8-23 16:00:00
Max=1

[ShellServiceObjectDelayLoad]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
1_Name=PostBootReminder
1_Value={7849596a-48ea-486e-8937-a2a3009f31a9}
1_ClsidName=PostBootReminder 对象
1_FileName=%SystemRoot%\system32\SHELL32.dll
1_FileSize=8241664
1_FileDate=2004-8-23 16:00:00
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
2_Name=CDBurn
2_Value={fbeb8a05-beee-4442-804e-409d6c4515e9}
2_ClsidName=烧 CD 的 ShellFolder
2_FileName=%SystemRoot%\system32\SHELL32.dll
2_FileSize=8241664
2_FileDate=2004-8-23 16:00:00
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
3_Name=WebCheck
3_Value={E6FB5E20-DE35-11CF-9C87-00AA005127ED}
3_ClsidName=WebCheck
3_FileName=%SystemRoot%\system32\webcheck.dll
3_FileSize=265728
3_FileDate=2004-8-23 16:00:00
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
4_Name=SysTray
4_Value={35CEC8A3-2BE6-11D2-8773-92E220524153}
4_ClsidName=SysTray
4_FileName=C:\WINDOWS\system32\stobject.dll
4_FileSize=121344
4_FileDate=2004-8-23 16:00:00
Max=4
心情niwota - 2006-8-12 8:31:00
[SharedTaskScheduler]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
1_Name={438755C2-A8BA-11D1-B96B-00A0C90312E1}
1_Value=Browseui 预加载程序
1_FileName=%SystemRoot%\system32\browseui.dll
1_FileSize=1016832
1_FileDate=2004-8-23 16:00:00
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
2_Name={8C7461EF-2B13-11d2-BE35-3078302C2030}
2_Value=组件类别缓存程序
2_FileName=%SystemRoot%\system32\browseui.dll
2_FileSize=1016832
2_FileDate=2004-8-23 16:00:00
Max=2

[ProtocolDefaults]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
1_Name=
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
2_Name=http
2_Value=3
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
3_Name=https
3_Value=3
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
4_Name=ftp
4_Value=3
5_HKey=HKEY_LOCAL_MACHINE
5_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
5_Name=file
5_Value=3
6_HKey=HKEY_LOCAL_MACHINE
6_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
6_Name=@ivt
6_Value=1
7_HKey=HKEY_LOCAL_MACHINE
7_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
7_Name=shell
7_Value=0
Max=7

[BootExecute]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SYSTEM\CurrentControlSet\Control\Session Manager
1_Name=BootExecute
1_Value=autocheck autochk *
Max=1

[AutoRun]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=Software\Microsoft\Windows\CurrentVersion\Run
1_Name=HotKeysCmds
1_Value=c:\windows\system32\hkcmd.exe
1_FileSize=114688
1_FileDate=2004-10-10 18:38:26
1_FileVersion=3.0.0.2082
2_HKey=HKEY_LOCAL_MACHINE
2_Key=Software\Microsoft\Windows\CurrentVersion\Run
2_Name=SoundMan
2_Value=soundman.exe
2_FileSize=67584
2_FileDate=2004-6-18 16:31:02
2_FileVersion=5.1.0.28
3_HKey=HKEY_LOCAL_MACHINE
3_Key=Software\Microsoft\Windows\CurrentVersion\Run
3_Name=YLive.exe
3_Value=c:\progra~1\yahoo!\assist~1\ylive.exe
3_FileSize=20480
3_FileDate=2005-12-20 13:53:08
3_FileVersion=2.0.0.1002
4_HKey=HKEY_LOCAL_MACHINE
4_Key=Software\Microsoft\Windows\CurrentVersion\Run
4_Name=yassistse
4_Value="c:\progra~1\yahoo!\assistant\yassistse.exe"
4_FileSize=65536
4_FileDate=2005-9-21 6:08:40
4_FileVersion=1.0.1.1001
5_HKey=HKEY_LOCAL_MACHINE
5_Key=Software\Microsoft\Windows\CurrentVersion\Run
5_Name=helper.dll
5_Value=c:\windows\system32\rundll32.exe c:\progra~1\3721\helper.dll,rundll32
5_FileSize=53326
5_FileDate=2006-8-4 19:54:52
5_FileVersion=1.1.0.1325
6_HKey=HKEY_LOCAL_MACHINE
6_Key=Software\Microsoft\Windows\CurrentVersion\Run
6_Name=TkBellExe
6_Value="c:\program files\common files\real\update_ob\realsched.exe"  -osboot
6_FileVersion=
7_HKey=HKEY_LOCAL_MACHINE
7_Key=Software\Microsoft\Windows\CurrentVersion\Run
7_Name=CnxDslTaskBar
7_Value="c:\program files\conexant\accessrunner adsl usb\cnxdsltb.exe" "conexant\accessrunner adsl usb"
7_FileSize=278528
7_FileDate=2004-10-22 18:05:08
7_FileVersion=40.1.18.0
8_HKey=HKEY_LOCAL_MACHINE
8_Key=Software\Microsoft\Windows\CurrentVersion\Run
8_Name=Alitalk
8_Value=c:\progra~1\阿里巴巴\贸易通\alitalk.exe -hideframe
8_FileSize=3067904
心情niwota - 2006-8-12 8:32:00
8_FileDate=2006-4-20 17:27:12
8_FileVersion=3.0.0.1
9_HKey=HKEY_LOCAL_MACHINE
9_Key=Software\Microsoft\Windows\CurrentVersion\Run
9_Name=Install Alitalk
9_Value=c:\windows\temp\alitalk\alitalk.exe -hideframe
9_FileVersion=
10_HKey=HKEY_LOCAL_MACHINE
10_Key=Software\Microsoft\Windows\CurrentVersion\Run
10_Name=MoveSearch
10_Value=c:\program files\huaci\huaci\zsearch.exe
10_FileSize=143360
10_FileDate=2006-1-19 15:32:50
10_FileVersion=1.0.0.1
11_HKey=HKEY_LOCAL_MACHINE
11_Key=Software\Microsoft\Windows\CurrentVersion\Run
11_Name=Desktop
11_Value=c:\windows\system32\rundll32.exe "c:\program files\deskadtop\run.dll" ,rundll
11_FileSize=102400
11_FileDate=2006-7-5 17:22:46
11_FileVersion=1.0.0.1
12_HKey=HKEY_LOCAL_MACHINE
12_Key=Software\Microsoft\Windows\CurrentVersion\Run
12_Name=y9f
12_Value=rundll32 "c:\windows\downlo~1\y9f.dll",run
13_HKey=HKEY_LOCAL_MACHINE
13_Key=Software\Microsoft\Windows\CurrentVersion\Run
13_Name=SearchNet_Up
13_Value="c:\program files\searchnet\serveup.exe"
13_FileSize=12800
13_FileDate=2006-8-3 9:59:20
13_FileVersion=1.0.2.4
14_HKey=HKEY_LOCAL_MACHINE
14_Key=Software\Microsoft\Windows\CurrentVersion\Run
14_Name=CdnCtr
14_Value=
15_HKey=HKEY_LOCAL_MACHINE
15_Key=Software\Microsoft\Windows\CurrentVersion\Run
15_Name=KernelFaultCheck
15_Value=%systemroot%\system32\dumprep 0 -k
16_HKey=HKEY_LOCAL_MACHINE
16_Key=Software\Microsoft\Windows\CurrentVersion\Run
16_Name=WangWang
16_Value="d:\program files\淘宝网\淘宝旺旺\wangwang.exe"
16_FileSize=4210754
16_FileDate=2006-6-28 18:26:10
16_FileVersion=1.6.6.616
17_HKey=HKEY_LOCAL_MACHINE
17_Key=Software\Microsoft\Windows\CurrentVersion\Run
17_Name=DesktopMemo
17_Value="c:\program files\deskmemo\deskmemo.exe"
17_FileSize=65536
17_FileDate=2006-8-4 17:02:48
17_FileVersion=1.0.0.1
18_HKey=HKEY_LOCAL_MACHINE
18_Key=Software\Microsoft\Windows\CurrentVersion\Run
18_Name=res
18_Value=c:\windows\system32\res.exe
18_FileSize=203168
18_FileDate=2004-6-6 13:16:00
18_FileVersion=
19_HKey=HKEY_LOCAL_MACHINE
19_Key=Software\Microsoft\Windows NT\CurrentVersion\Windows
19_Name=load
19_Value=
20_HKey=HKEY_CURRENT_USER
20_Key=Software\Microsoft\Windows\CurrentVersion\Run
20_Name=ctfmon.exe
20_Value=c:\windows\system32\ctfmon.exe
20_FileSize=15360
20_FileDate=2004-8-23 16:00:00
20_FileVersion=5.1.2600.2180
21_HKey=HKEY_CURRENT_USER
21_Key=Software\Microsoft\Windows\CurrentVersion\Run
21_Name=msnmsgr
21_Value="c:\program files\msn messenger\msnmsgr.exe" /background
21_FileSize=7094272
21_FileDate=2006-1-24 20:34:34
21_FileVersion=7.5.324.0
22_HKey=HKEY_CURRENT_USER
22_Key=Software\Microsoft\Windows NT\CurrentVersion\Windows
22_Name=load
22_Value=
Max=22

[ModuleUsage]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/AliTalk_WebUpdate.dll
1_Name=.Owner
1_Value={276BF72D-CA22-4237-9BCF-593B4E490DE9}
1_Clsid=DownLoad Class
1_FileName=C:\WINDOWS\Downloaded Program Files\AliTalk_WebUpdate.dll
1_FileSize=188416
1_FileDate=2005-7-7 16:10:24
1_FileVersion=1.0.0.1
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/messengerstatsclient.dll
2_Name=.Owner
2_Value={8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
2_Clsid=MessengerStatsClient Class
2_FileName=C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll
2_FileSize=160864
2_FileDate=2003-5-29 15:00:20
2_FileVersion=7.1.9502.1
3_HKey=HKEY_LOCAL_MACHINE
心情niwota - 2006-8-12 8:32:00
3_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/msgrchkr.dll
3_Name=.Owner
3_Value={00B71CFB-6864-4346-A978-C0A14556272C}
3_Clsid=Checkers Class
3_FileName=C:\WINDOWS\Downloaded Program Files\msgrchkr.dll
3_FileSize=77408
3_FileDate=2003-5-29 15:00:18
3_FileVersion=7.1.9502.1
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MsnMessengerSetupDownloader.ocx
4_Name=.Owner
4_Value={B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
4_Clsid=MsnMessengerSetupDownloadControl Class
4_FileName=C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx
4_FileSize=113664
4_FileDate=2005-8-14 0:26:04
4_FileVersion=1.0.0.3
5_HKey=HKEY_LOCAL_MACHINE
5_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MsnPUpld.dll
5_Name=.Owner
5_Value={4F1E5B1A-2A80-42CA-8532-2D05CB959537}
5_Clsid=MSN Photo Upload Tool
5_FileName=C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll
5_FileSize=372736
5_FileDate=2005-10-14 11:02:36
5_FileVersion=10.0.911.0
6_HKey=HKEY_LOCAL_MACHINE
6_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/PURen-us.dll
6_Name=.Owner
6_Value={4F1E5B1A-2A80-42CA-8532-2D05CB959537}
6_Clsid=MSN Photo Upload Tool
6_FileName=C:\WINDOWS\Downloaded Program Files\PURen-us.dll
6_FileSize=117088
6_FileDate=2002-6-19 14:11:22
6_FileVersion=5.0.1730.0
7_HKey=HKEY_LOCAL_MACHINE
7_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/YAlive.dll
7_Name=.Owner
7_Value={57421194-58FB-49AE-9B4F-FD48869B9AD4}
7_Clsid=Yahoo!Live
7_FileName=C:\WINDOWS\Downloaded Program Files\YAlive.dll
7_FileVersion=
8_HKey=HKEY_LOCAL_MACHINE
8_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/vqqsdl.dll
8_Name=.Owner
8_Value={F138084D-84D7-48CD-BEA8-04772457516E}
8_Clsid=VqqSpeedDlProxy Class
8_FileName=C:\WINDOWS\vqqsdl.dll
8_FileSize=577536
8_FileDate=2005-4-12 11:38:04
8_FileVersion=1.0.0.9
9_HKey=HKEY_LOCAL_MACHINE
9_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/vqqsdl.exe
9_Name=.Owner
9_Value={F138084D-84D7-48CD-BEA8-04772457516E}
9_Clsid=VqqSpeedDlProxy Class
9_FileName=C:\WINDOWS\vqqsdl.exe
9_FileSize=90112
9_FileDate=2005-4-12 11:48:04
9_FileVersion=1.0.0.9
Max=9
心情niwota - 2006-8-12 8:32:00
[Process]
1_FileName=C:\WINDOWS\SYSTEM32\SMSS.EXE
1_FileSize=50688
1_FileDate=2004-8-23 16:00:00
1_FileVersion=5.1.2600.2180
2_FileName=C:\WINDOWS\SYSTEM32\WINLOGON.EXE
2_FileSize=487424
2_FileDate=2004-8-23 16:00:00
2_FileVersion=5.1.2600.2180
3_FileName=C:\WINDOWS\SYSTEM32\SERVICES.EXE
3_FileSize=108032
3_FileDate=2004-8-23 16:00:00
3_FileVersion=5.1.2600.2180
4_FileName=C:\WINDOWS\SYSTEM32\LSASS.EXE
4_FileSize=13312
4_FileDate=2004-8-23 16:00:00
4_FileVersion=5.1.2600.2180
5_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
5_FileSize=14336
5_FileDate=2004-8-23 16:00:00
5_FileVersion=5.1.2600.2180
6_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
6_FileSize=14336
6_FileDate=2004-8-23 16:00:00
6_FileVersion=5.1.2600.2180
7_FileName=C:\WINDOWS\EXPLORER.EXE
7_FileSize=976896
7_FileDate=2004-8-23 16:00:00
7_FileVersion=6.0.2900.2180
8_FileName=C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
8_FileSize=57856
8_FileDate=2004-8-23 16:00:00
8_FileVersion=5.1.2600.2180
9_FileName=C:\WINDOWS\SYSTEM32\HKCMD.EXE
9_FileSize=114688
9_FileDate=2004-10-10 18:38:26
9_FileVersion=3.0.0.2082
10_FileName=C:\WINDOWS\SOUNDMAN.EXE
10_FileSize=67584
10_FileDate=2004-6-18 16:31:02
10_FileVersion=5.1.0.28
11_FileName=C:\PROGRA~1\YAHOO!\ASSIST~1\YLIVE.EXE
11_FileSize=20480
11_FileDate=2005-12-20 13:53:08
11_FileVersion=2.0.0.1002
12_FileName=C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
12_FileSize=32768
12_FileDate=2004-8-23 16:00:00
12_FileVersion=5.1.2600.2180
13_FileName=C:\PROGRA~1\YAHOO!\ASSISTANT\YASSISTSE.EXE
13_FileSize=65536
13_FileDate=2005-9-21 6:08:40
13_FileVersion=1.0.1.1001
14_FileName=C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
14_FileSize=32768
14_FileDate=2004-8-23 16:00:00
14_FileVersion=5.1.2600.2180
15_FileName=C:\PROGRAM FILES\CONEXANT\ACCESSRUNNER ADSL USB\CNXDSLTB.EXE
15_FileSize=278528
15_FileDate=2004-10-22 18:05:08
15_FileVersion=40.1.18.0
16_FileName=C:\PROGRAM FILES\COMMON FILES\SOGOU PXP\P2PSVR.EXE
16_FileSize=86016
16_FileDate=2006-6-8 20:25:10
16_FileVersion=2.0.0.17
17_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
17_FileSize=14336
17_FileDate=2004-8-23 16:00:00
17_FileVersion=5.1.2600.2180
18_FileName=C:\WINDOWS\DISKMAN.EXE
18_FileSize=77824
18_FileDate=2004-6-1 21:16:00
18_FileVersion=
19_FileName=C:\PROGRAM FILES\VENTURI2\CLIENT\VENTC.EXE
19_FileSize=868352
19_FileDate=2002-7-18 13:28:50
19_FileVersion=1.0.0.1
20_FileName=C:\PROGRAM FILES\HUACI\HUACI\ZSEARCH.EXE
20_FileSize=143360
20_FileDate=2006-1-19 15:32:50
20_FileVersion=1.0.0.1
21_FileName=C:\PROGRAM FILES\DESKMEMO\DESKMEMO.EXE
21_FileSize=65536
21_FileDate=2006-8-4 17:02:48
21_FileVersion=1.0.0.1
22_FileName=C:\WINDOWS\SYSTEM32\CTFMON.EXE
22_FileSize=15360
22_FileDate=2004-8-23 16:00:00
22_FileVersion=5.1.2600.2180
23_FileName=C:\PROGRAM FILES\DUDU\SPEED\DUDUPROS.EXE
23_FileSize=360448
23_FileDate=2006-6-5 9:32:54
23_FileVersion=5.0.0.1
24_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
24_FileSize=14336
24_FileDate=2004-8-23 16:00:00
24_FileVersion=5.1.2600.2180
25_FileName=D:\游戏\QQ\QQ.EXE
25_FileSize=1224704
25_FileDate=2005-10-11 16:36:18
25_FileVersion=14.19.0.220
26_FileName=D:\游戏\QQ\TIMPLATFORM.EXE
26_FileSize=69632
26_FileDate=2005-9-14 13:38:46
26_FileVersion=0.3.1.8
27_FileName=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
27_FileSize=93184
27_FileDate=2004-8-24
27_FileVersion=6.0.2900.2180
28_FileName=C:\PROGRAM FILES\DUDU\SPEED\DUDUACC.EXE
28_FileSize=1159168
28_FileDate=2006-8-2 16:47:00
28_FileVersion=5.0.0.7
29_FileName=D:\RUIXING\HA_HIJACKTHIS_1991\HIJACKTHIS.EXE
29_FileSize=218624
29_FileDate=2005-2-22 2:43:46
29_FileVersion=1.99.0.1
30_FileName=C:\PROGRAM FILES\SUPER RABBIT\MAGICSET\IEHELP.EXE
30_FileSize=735232
30_FileDate=2006-8-9 0:29:16
30_FileVersion=7.75.0.0
31_FileName=[SYSTEM PROCESS]
32_FileName=C:\WINDOWS\system32\CSRSS.EXE
32_FileSize=6144
32_FileDate=2004-8-23 16:00:00
32_FileVersion=5.1.2600.2180
33_FileName=C:\WINDOWS\system32\ALG.EXE
33_FileSize=44544
33_FileDate=2004-8-23 16:00:00
33_FileVersion=5.1.2600.2180
Max=33

[Hosts]
HostsFile=C:\WINDOWS\system32\Drivers\Etc\Hosts
1_Host=127.0.0.1      localhost
Max=1
心情niwota - 2006-8-12 8:33:00
[Service]
1_ServiceName=BRGNS
1_DisplayName=Print Manager
1_Description=提供打印队列优化服务,有效协调及防止文件的丢失。
1_Status=已启动
1_StartType=自动
1_ServiceDll=
1_ImagePath=C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,EXPORT 1087

2_ServiceName=DcomLaunch
2_DisplayName=DCOM Server Process Launcher
2_Description=为 DCOM 服务提供加载功能。
2_Status=已启动
2_StartType=自动
2_ServiceDll=C:\WINDOWS\SYSTEM32\RPCSS.DLL
2_ImagePath=C:\WINDOWS\SYSTEM32\SVCHOST -K DCOMLAUNCH

3_ServiceName=HTTPFilter
3_DisplayName=HTTP SSL
3_Description=此服务通过安全套接字层(SSL)实现 HTTP 服务的安全超文本传送协议(HTTPS)。如果此服务被禁用,任何依赖它的服务将无法启动。
3_Status=已启动
3_StartType=手动
3_ServiceDll=C:\WINDOWS\SYSTEM32\W3SSL.DLL
3_ImagePath=C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K HTTPFILTER

4_ServiceName=NetDDEdsdm
4_DisplayName=Network DDE DSDM
4_Description=管理动态数据交换 (DDE) 网络共享。如果此服务终止,DDE 网络共享将不可用。如果此服务被禁用,任何依赖它的服务将无法启动。
4_Status=停止
4_StartType=已禁用
4_ServiceDll=
4_ImagePath=C:\WINDOWS\SYSTEM32\NETDDE.EXE

5_ServiceName=P4P Service
5_DisplayName=P4P Service
5_Description=
5_Status=已启动
5_StartType=自动
5_ServiceDll=
5_ImagePath=C:\PROGRAM FILES\COMMON FILES\SOGOU PXP\P2PSVR.EXE

6_ServiceName=Remote Log
6_DisplayName=Remote Log
6_Description=IE地址栏搜索服务程序。如果此服务被禁用,任何依赖它的服务将无法启动。
6_Status=停止
6_StartType=自动
6_ServiceDll=
6_ImagePath=SYSTEM32\SERVEHOST.EXE

7_ServiceName=SmallCenter
7_DisplayName=Network Engine
7_Description=Windows 网络通讯引擎,提供高效稳定的网络通讯服务。无法终止此服务。
7_Status=已启动
7_StartType=自动
7_ServiceDll=C:\WINDOWS\SYSTEM\NTSTUB.DLL
7_ImagePath=C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS

8_ServiceName=Universal Disk Manager
8_DisplayName=Universal Disk Manager
8_Description=监测和监视新的通用磁盘驱动器并向逻辑磁盘管理器管理服务发送卷的信息以便配置。如果此服务被终止,动态磁盘状态和配置信息会过时。如果此服务被禁用,任何依赖它的服务将无法启动。
8_Status=已启动
8_StartType=自动
8_ServiceDll=
8_ImagePath=C:\WINDOWS\DISKMAN.EXE

9_ServiceName=Venturi2
9_DisplayName=Venturi2 Client
9_Description=
9_Status=已启动
9_StartType=自动
9_ServiceDll=
9_ImagePath=C:\PROGRAM FILES\VENTURI2\CLIENT\VENTC.EXE

10_ServiceName=WmdmPmSN
10_DisplayName=Portable Media Serial Number Service
10_Description=Retrieves the serial number of any portable media player connected to this computer. If this service is stopped, protected content might not be down loaded to the device.
10_Status=停止
10_StartType=手动
10_ServiceDll=C:\WINDOWS\SYSTEM32\MSPMSNSV.DLL
10_ImagePath=C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS

11_ServiceName=wscsvc
11_DisplayName=Security Center
11_Description=监视系统安全设置和配置。
11_Status=已启动
11_StartType=自动
11_ServiceDll=C:\WINDOWS\SYSTEM32\WSCSVC.DLL
11_ImagePath=C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS

12_ServiceName=xmlprov
12_DisplayName=Network Provisioning Service
12_Description=为自动网络提供管理基于域的 XML 配置文件。
12_Status=停止
12_StartType=手动
12_ServiceDll=C:\WINDOWS\SYSTEM32\XMLPROV.DLL
12_ImagePath=C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS

Max=12

[END]
Max=1
心情niwota - 2006-8-12 8:33:00
好了,怎么这么多,完了,是不是不可救药了
mopery - 2006-8-12 8:40:00
似乎我没叫你发?

http://www.pctutu.com/srmsdown.asp
下载超级兔子..用超级兔子清理王卸载流氓软件...(安全模式...)
心情niwota - 2006-8-12 8:42:00
哦,不用发了阿,呵呵,我下载好了那个,然后呢?
mopery - 2006-8-12 8:50:00
用超级兔子清理王卸载流氓软件...(安全模式...)
1
查看完整版本: 我中病毒了,用hijackthis扫描了,哪位高手帮我看看?谢谢了先