烂笔头1 - 2006-10-10 10:38:00
启动不了,手动启也不行,重新安装过,(卸载后)
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 10:24:28, 日期 2006.10.10
操作系统: Windows 2000 SP4 (WinNT 5.00.2195)
浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)
当前运行的进程:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
D:\WINNT\System32\DRIVERS\CDANTSRV.EXE
D:\WINNT\System32\svchost.exe
D:\WINNT\system32\hidserv.exe
D:\Program Files\VeriSign\NAVI\naviagent.exe
D:\WINNT\System32\nvsvc32.exe
D:\Program Files\Rising\Rav\RavService.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\System32\snmp.exe
D:\WINNT\system32\stisvc.exe
D:\Program Files\UGS\License Servers\UGNXFLEXlm\lmgrd.exe
D:\WINNT\system32\svchost.exe
D:\Program Files\UGS\License Servers\UGNXFLEXlm\uglmd.exe
D:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
D:\Program Files\Rising\Rav\RavTray.exe
F:\AutoCAD 2007\acad.exe
D:\DOCUME~1\liulion\LOCALS~1\Temp\AdskCleanup.0001
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\Program Files\Common Files\Autodesk Shared\WSCommCntr1.exe
D:\WINNT\regedit.exe
D:\WINNT\system32\taskmgr.exe
D:\WINNT\system32\conime.exe
D:\WINNT\explorer.exe
G:\公共文件\sadu\hijackthis\HijackThis1991zww.exe
R3 - URLSearchHook: i-Nav IDN SearchHook - {CE000994-A58C-4441-8938-744CD72AB27F} - D:\Program Files\VeriSign\i-Nav\i-nav_4_2_1.dll
R3 - URLSearchHook: (no name) - {BC207F7D-3E63-4ACA - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: NetAnts.IE.Monitor - {57E91B41-F40A-11D1-B792-444553540000} - D:\Program Files\NetAnts\AntAPI.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\System32\msdxm.ocx
O3 - IE工具栏增项: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - D:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll
O3 - IE工具栏增项: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (file missing)
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\System32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [LoadQM] loadqm.exe
O4 - 启动项HKLM\\Run: [WheelMouse] D:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
O4 - 启动项HKLM\\Run: [nwiz] nwiz.exe /install
O4 - 启动项HKLM\\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - 启动项HKLM\\Run: [Acrobat Assistant 7.0] "D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - 启动项HKLM\\Run: [RavTray] D:\Program Files\Rising\Rav\RavTray.exe
O4 - 启动项HKLM\\RunServices: [Windows ASN Service] asn.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = D:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoCAD 启动加速器.lnk = D:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - IE右键菜单中的新增项目: &Download by NetAnts - D:\PROGRA~1\NetAnts\NAGet.htm
O8 - IE右键菜单中的新增项目: Download &All by NetAnts - D:\PROGRA~1\NetAnts\NAGetAll.htm
O8 - IE右键菜单中的新增项目: 转换为 Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - IE右键菜单中的新增项目: 转换为现有 PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - IE右键菜单中的新增项目: 转换选定的链接为 Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - IE右键菜单中的新增项目: 转换选定的链接为现有 PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - IE右键菜单中的新增项目: 转换选项为 Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - IE右键菜单中的新增项目: 转换选项为现有 PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - IE右键菜单中的新增项目: 转换链接目标为 Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - IE右键菜单中的新增项目: 转换链接目标为现有 PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - 浏览器额外的按钮: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - 浏览器额外的按钮: 金山词霸 - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
O16 - DPF: {15DDE989-CD45-4561-BF99-D22C0D5C2B74} - http://image2.sina.com.cn/home/ddtsource/ddt.cab
O16 - DPF: {58CDB34C-B4D7-418B-A0FB-C4C8A01C2F0E} - http://pi.51.net/download/diybar.cab
O16 - DPF: {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - http://bar.baidu.com/update/IESearch.cab
O16 - DPF: {CF051549-EDE1-40F5-B440-BCD646CF2C25} - http://www.163.com/wwwimages/sms/ppinstall22.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DB47384D-BB88-4692-BC11-A0494F07A096}: NameServer = 202.101.98.55,202.101.98.54
O20 - Winlogon Notify: nwprovau - D:\WINNT\SYSTEM32\nwprovau.dll
O23 - NT 服务: Autodesk Licensing Service - Autodesk - D:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - NT 服务: C-DillaSrv - C-Dilla Ltd - D:\WINNT\System32\DRIVERS\CDANTSRV.EXE
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - NT 服务: VeriSign Updater (navi) - VeriSign, Inc. - D:\Program Files\VeriSign\NAVI\naviagent.exe
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINNT\System32\nvsvc32.exe
O23 - NT 服务: RavService - Unknown owner - D:\Program Files\Rising\Rav\RavService.exe" /service (file missing)
O23 - NT 服务: Unigraphics License Server (uglmd) - Macrovision Corporation - D:\Program Files\UGS\License Servers\UGNXFLEXlm\lmgrd.exe
烂笔头1 - 2006-10-10 10:42:00
2006-10-10,10:24:05
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<rx><D:\WINNT\system32\explore.exe> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><RUNDLL32.EXE D:\WINNT\System32\NvCpl.dll,NvStartup> [NVIDIA Corporation]
<LoadQM><loadqm.exe> [Microsoft Corporation]
<WheelMouse><D:\PROGRA~1\A4Tech\Mouse\Amoumain.exe> [A4Tech Co.,Ltd.]
<nwiz><nwiz.exe /install> [NVIDIA Corporation]
<NvMediaCenter><RUNDLL32.EXE D:\WINNT\System32\NvMcTray.dll,NvTaskbarInit> [NVIDIA Corporation]
<Acrobat Assistant 7.0><"D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"> [Adobe Systems Inc.]
<RavTray><D:\Program Files\Rising\Rav\RavTray.exe> [Rising]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<Windows ASN Service><asn.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE> [Microsoft Corporation]
<Userinit><userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{282C0672-0672-82C6-7282-6722C67282C6}><D:\Program Files\Common Files\Microsoft Shared\MSINFO\067282C6.dll> []
==================================
启动文件夹
[Adobe Acrobat Speed Launcher]
<D:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Acrobat Speed Launcher.lnk><N>
[Adobe Gamma Loader]
<D:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>
[AutoCAD 启动加速器]
<D:\Documents and Settings\All Users\「开始」菜单\程序\启动\AutoCAD 启动加速器.lnk><N>
[Microsoft Office]
<D:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk><N>
==================================
服务
[Autodesk Licensing Service / Autodesk Licensing Service]
<"D:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><Autodesk>
[C-DillaSrv / C-DillaSrv]
<D:\WINNT\System32\DRIVERS\CDANTSRV.EXE><C-Dilla Ltd>
[Logical Disk Manager Administrative Service / dmadmin]
<D:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[VeriSign Updater / navi]
<D:\Program Files\VeriSign\NAVI\naviagent.exe uimode=agentupdate><VeriSign, Inc.>
[NVIDIA Display Driver Service / NVSvc]
<D:\WINNT\System32\nvsvc32.exe><NVIDIA Corporation>
[RavService / RavService]
<"D:\Program Files\Rising\Rav\RavService.exe" /service><Beijing Rising Technology Co., Ltd.>
[WINS Client / RpcPatch]
<D:\WINNT\System32\wins\DLLHOST.EXE><N/A>
[Rising Process Communication Center / RsCCenter]
<D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE><Beijing Rising Technology Co., Ltd.>
[Unigraphics License Server (uglmd) / Unigraphics License Server (uglmd)]
<"D:\Program Files\UGS\License Servers\UGNXFLEXlm\lmgrd.exe"><Macrovision Corporation>
烂笔头1 - 2006-10-10 10:43:00
==================================
浏览器加载项
[NetAnts.IE.Monitor]
{57E91B41-F40A-11D1-B792-444553540000} <D:\Program Files\NetAnts\AntAPI.dll, >
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[JoyoCtrl Class]
{C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} <C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <D:\WINNT\System32\msdxm.ocx, Microsoft Corporation>
[金山快译(&K)]
{6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <D:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll, 金山软件股份有限公司>
[Adobe PDF]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} <D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, N/A>
[IEAnimBehaviorFactory Class]
{A4639D2F-774E-11D3-A490-00C04F6843FB} <D:\PROGRA~1\COMMON~1\MICROS~1\MSORUN\MSORUN.DLL, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <D:\WINNT\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[&Download by NetAnts]
<D:\PROGRA~1\NetAnts\NAGet.htm, N/A>
[Download &All by NetAnts]
<D:\PROGRA~1\NetAnts\NAGetAll.htm, N/A>
[转换为 Adobe PDF]
<res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[转换为现有 PDF]
<res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
[转换选定的链接为 Adobe PDF]
<res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html, N/A>
[转换选定的链接为现有 PDF]
<res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html, N/A>
[转换选项为 Adobe PDF]
<res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[转换选项为现有 PDF]
<res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
[转换链接目标为 Adobe PDF]
<res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
[转换链接目标为现有 PDF]
<res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
==================================
正在运行的进程
[PID: 168][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.00.2195.6601>
[PID: 192][\??\D:\WINNT\system32\csrss.exe] <Microsoft Corporation><5.00.2195.6601>
[PID: 212][\??\D:\WINNT\system32\winlogon.exe] <Microsoft Corporation><5.00.2195.6898>
[PID: 240][D:\WINNT\system32\services.exe] <Microsoft Corporation><5.00.2195.6700>
[PID: 252][D:\WINNT\system32\lsass.exe] <Microsoft Corporation><5.00.2195.6902>
[PID: 440][D:\WINNT\system32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[PID: 468][D:\WINNT\system32\spoolsv.exe] <Microsoft Corporation><5.00.2195.7059>
[D:\WINNT\system32\AdobePDF.dll] <Adobe Systems Incorporated.><7.0.0.00>
[D:\Program Files\Adobe\Acrobat 7.0\Distillr\AdistRes.CHS] <N/A><N/A>
[D:\WINNT\system32\ZLhp1020.DLL] <Zenographics, Inc.><5, 53, 2714, 0>
[D:\WINNT\system32\ZLM.dll] <Zenographics, Inc.><5, 50, 1416, 0>
[D:\WINNT\system32\ZLMhp1.DLL] <Zenographics><5, 51, 1203, 0>
[D:\WINNT\system32\ZPJL.dll] <Zenographics, Inc.><1, 0, 1410, 1>
[D:\WINNT\system32\ZSPOOL.dll] <Zenographics, Inc.><5, 51, 709, 0>
[D:\WINNT\system32\spool\PRTPROCS\W32X86\IMFPrint.DLL] <Zenographics, Inc.><5, 54, 330, 0>
[D:\WINNT\system32\Imf32.dll] <Zenographics, Inc.><5, 51, 405, 0>
[D:\WINNT\system32\ZTAG32.dll] <Zenographics, Inc.><5, 50, 1725, 0>
[D:\WINNT\system32\spool\DRIVERS\W32X86\3\SDNT5UI.DLL] <Zenographics, Inc.><5.60.709.0>
[D:\WINNT\system32\spool\DRIVERS\W32X86\3\SDDM32.DLL] <Zenographics, Inc.><5, 60, 2629, 0>
[D:\WINNT\system32\spool\DRIVERS\W32X86\3\ZGDI32.dll] <Zenographics, Inc.><5, 60, 709, 0>
[D:\WINNT\system32\spool\DRIVERS\W32X86\3\SDDMUI.DLL] <Zenographics, Inc.><5, 60, 2209, 0>
[D:\WINNT\system32\spool\DRIVERS\W32X86\3\SR32.dll] <Zenographics, Inc.><6, 0, 909, 0>
[PID: 496][D:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe] <Autodesk><2.70.000>
[PID: 524][D:\WINNT\System32\DRIVERS\CDANTSRV.EXE] <C-Dilla Ltd><3.28.000>
[PID: 540][D:\WINNT\System32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[PID: 564][D:\WINNT\system32\hidserv.exe] <Microsoft Corporation><5.00.2195.6655>
[PID: 588][D:\Program Files\VeriSign\NAVI\naviagent.exe] <VeriSign, Inc.><2.0.0.14>
[PID: 668][D:\WINNT\System32\nvsvc32.exe] <NVIDIA Corporation><6.14.10.6177>
[PID: 628][D:\Program Files\Rising\Rav\RavService.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 43>
[D:\Program Files\Rising\Rav\DLCenter.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 27>
[D:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[PID: 740][D:\WINNT\system32\regsvc.exe] <Microsoft Corporation><5.00.2195.6701>
[PID: 760][D:\WINNT\System32\snmp.exe] <Microsoft Corporation><5.00.2195.6605>
[PID: 860][D:\PROGRA~1\VeriSign\NAVI\NAVICL~1.EXE] <VeriSign, Inc.><2.0.1.0>
[D:\Program Files\VeriSign\NAVI\naviservice.dll] <VeriSign, Inc.><2.0.2.0>
[PID: 912][D:\WINNT\system32\stisvc.exe] <Microsoft Corporation><5.00.2195.6656>
[PID: 956][D:\Program Files\UGS\License Servers\UGNXFLEXlm\lmgrd.exe] <Macrovision Corporation><9, 2, 2, 0>
[PID: 980][D:\WINNT\system32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[PID: 1064][D:\Program Files\UGS\License Servers\UGNXFLEXlm\uglmd.exe] <N/A><N/A>
[PID: 1328][D:\PROGRA~1\A4Tech\Mouse\Amoumain.exe] <A4Tech Co.,Ltd.><7.42.0.0>
[D:\WINNT\system32\Amhooker.dll] <A4Tech Co.,Ltd.><7.42.0.0>
[D:\WINNT\system32\Amoures.dll] <A4Tech Co.,Ltd.><7.42.0.0>
[D:\Program Files\Common Files\Microsoft Shared\MSINFO\067282C6.dll] <N/A><N/A>
[PID: 1308][D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe] <Adobe Systems Inc.><6.0.1.2004121400>
[D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.chs] <Adobe Systems Inc.><6.0.0.0>
[PID: 1188][D:\Program Files\Rising\Rav\RavTray.exe] <Rising><18, 0, 0, 34>
[D:\Program Files\Rising\Rav\RavUILib.dll] <><18, 0, 0, 1>
[D:\Program Files\Rising\Rav\RavTray936.dll] <Rising><18, 0, 0, 34>
[D:\Program Files\Rising\Rav\RsCommx.dll] <rising><18, 0, 0, 1>
[D:\Program Files\Common Files\Microsoft Shared\MSINFO\067282C6.dll] <N/A><N/A>
[PID: 904][F:\AutoCAD 2007\acad.exe] <Autodesk, Inc.><R17.0.54.0>
烂笔头1 - 2006-10-10 10:45:00
[PID: 696][D:\WINNT\System32\WBEM\WinMgmt.exe] <Microsoft Corporation><1.50.1085.0100>
[PID: 1556][D:\Program Files\Common Files\Autodesk Shared\WSCommCntr1.exe] <Autodesk, Inc.><17.0.54.0>
[D:\Program Files\Common Files\Autodesk Shared\WebServices1.dll] <Autodesk, Inc.><17.0.54.0>
[PID: 1204][D:\WINNT\regedit.exe] <Microsoft Corporation><5.00.2195.6707>
[D:\WINNT\system32\Amhooker.dll] <A4Tech Co.,Ltd.><7.42.0.0>
[D:\Program Files\Common Files\Microsoft Shared\MSINFO\067282C6.dll] <N/A><N/A>
[PID: 304][D:\WINNT\system32\taskmgr.exe] <Microsoft Corporation><5.00.2195.6620>
[D:\WINNT\system32\Amhooker.dll] <A4Tech Co.,Ltd.><7.42.0.0>
[D:\Program Files\Common Files\Microsoft Shared\MSINFO\067282C6.dll] <N/A><N/A>
[D:\WINNT\system32\AcSignIcon.dll] <Autodesk><17.0.54.0>
[PID: 1392][D:\WINNT\system32\conime.exe] <Microsoft Corporation><5.00.2195.6655>
[PID: 1216][D:\WINNT\explorer.exe] <Microsoft Corporation><5.00.3700.6690>
[D:\WINNT\system32\AcSignIcon.dll] <Autodesk><17.0.54.0>
[D:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] <Autodesk><17.0.54.110>
[D:\WINNT\system32\Amhooker.dll] <A4Tech Co.,Ltd.><7.42.0.0>
[D:\Program Files\Common Files\Microsoft Shared\MSINFO\067282C6.dll] <N/A><N/A>
[D:\Program Files\NetAnts\AntAPI.dll] <><1, 25, 1, 0>
[D:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[G:\公共文件\sadu\SREng2\SREng2\SREng.com] <Smallfrogs Studio><2.0.21.505>
[D:\Program Files\Common Files\Microsoft Shared\MSINFO\067282C6.dll] <N/A><N/A>
[D:\WINNT\system32\Amhooker.dll] <A4Tech Co.,Ltd.><7.42.0.0>
==================================
文件关联
.TXT Error. [NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [REGEDIT.EXE "%1"]
.BAT OK. ["%1" %*]
.SCR Error. [AutoCADScriptFile]
.CHM OK. ["D:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
westbeck - 2006-10-10 11:11:00
请到www.27814939.ys168.com,点“我的软件”下载KillBox.exe
重新启动电脑, 开机检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式进入Windows
运行System Repair Engineer,使用“系统修复,文件关联"修复所有文件关联
运行(双击)System Repair Engineer,点“启动项目,服务,点“Win32服务应用程序”勾选“隐藏微软服务”选中病毒服务WINS Client / RpcPatch选择“删除服务”点“设置”选择“否”
运行System Repair Engineer,使用“启动项目,注册表”来删除以下选项
<rx><D:\WINNT\system32\explore.exe>
<Windows ASN Service><asn.exe>
<{282C0672-0672-82C6-7282-6722C67282C6}><D:\Program Files\Common Files\Microsoft Shared\MSINFO\067282C6.dll>
双击打开KillBox.exe,分别删除
D:\WINNT\system32\explore.exe
asn.exe
D:\Program Files\Common Files\Microsoft Shared\MSINFO\067282C6.dll
(删除时勾选“删除前先结束Explorer.EXE进程”)
注:后缀为.dll的文件如果无法删除,请勾选"反注册""再删除
© 2000 - 2026 Rising Corp. Ltd.