灵魂旅行 - 2007-1-8 13:16:00
[CODE]
2007-01-08,13:00:39
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<PcSync><C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog> [Time Information Services Ltd.]
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation]
<Super Rabbit IEPro><C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD> [Super Rabbit Soft]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<IMEKRMIG6.1><C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE> [(Verified)Microsoft Corporation]
<MSPY2002><C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC> [(Verified)N/A]
<OfficeScanNT Monitor><"C:\OfficeScan NT\pccntmon.exe" -HideWindow> [Trend Micro Inc.]
<TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<PCSuiteTrayApplication><C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup> [Nokia]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<tpxhst32.exe><C:\WINDOWS\system32\tpxhst32.exe> [N/A]
<fzg><C:\WINDOWS\Config\svhost32.exe> [N/A]
<runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe> [Beijing Rising Technology Co., Ltd.]
<DxDialog><C:\WINDOWS\system32\dxdlg32.exe> [Microsoft Corporation]
<AMSG><; C:\Program Files\ThinkVantage\AMSG\Amsg.exe> [LENOVO]
<ATIPTA><; C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe> [ATI Technologies, Inc.]
<cssauth><; "C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe" silent> [N/A]
<DiskeeperSystray><; "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"> [Diskeeper Corporation]
<DLA><; C:\WINDOWS\System32\DLA\DLACTRLW.EXE> [Sonic Solutions]
<ISUSPM Startup><; c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup> [InstallShield Software Corporation]
<ISUSScheduler><; "c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start> [InstallShield Software Corporation]
<LPManager><; C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe> [Lenovo Group Limited]
<Mouse Suite 98 Daemon><; ICO.EXE> [Primax Electronics Ltd.]
<PDService.exe><; "C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe"> [Utimaco Safeware AG]
<Picasa Media Detector><; C:\Program Files\Picasa2\PicasaMediaDetector.exe> [Google Inc.]
<SoundMAX><; "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray> [Analog Devices, Inc.]
<SoundMAXPnP><; C:\Program Files\Analog Devices\Core\smax4pnp.exe> [(Verified)Analog Devices, Inc.]
<suScheduler><; C:\Program Files\ThinkVantage\SystemUpdate\UCLauncher.exe /SCHEDULER> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<twin><C:\WINDOWS\system32\twunk32.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
==================================
启动文件夹
N/A
==================================
服务
[891981CC / 891981CC][Stopped/Auto Start]
<C:\WINDOWS\system32\891981CC.EXE -service><Microsoft Corporation>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[Diskeeper / Diskeeper][Running/Auto Start]
<"C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe"><Diskeeper Corporation>
[Gray_Pigeon_Server1.23 / GrayPigeonServer1.23][Stopped/Auto Start]
<C:\WINDOWS\G_Server1.23.exe><N/A>
[Transaction Provisioning Service / hackru][Running/Auto Start]
<C:\WINDOWS\system32\8.txt><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"><Macrovision Corporation>
[IPS 核心服务 / IPSSVC][Running/Auto Start]
<C:\WINDOWS\system32\IPSSVC.EXE><Lenovo Ltd.>
[OfficeScanNT 实时扫描 / ntrtscan][Running/Auto Start]
<C:\OfficeScan NT\ntrtscan.exe><Trend Micro Inc.>
[OfficeScanNT 个人防火墙 / OfcPfwSvc][Running/Auto Start]
<C:\OfficeScan NT\OfcPfwSvc.exe><Trend Micro Inc.>
[IBM PSA Access Driver Control / PsaSrv][Stopped/Manual Start]
<C:\WINDOWS\system32\PsaSrv.exe><N/A>
[ServiceLayer / ServiceLayer][Running/Manual Start]
<"C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe"><Nokia.>
[OfficeScanNT 侦听程序 / tmlisten][Running/Auto Start]
<C:\OfficeScan NT\tmlisten.exe><Trend Micro Inc.>
[TSS Core Service / TSSCoreService][Running/Auto Start]
<"C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe"><IBM>
[TVT Backup Service / TVT Backup Service][Running/Auto Start]
<"C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe"><>
[TVT Scheduler / TVT Scheduler][Running/Auto Start]
<"C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe"><>
[ThinkVantage System Update / UCLauncherService][Running/Auto Start]
<C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe><N/A>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe windhcp.ocx,start><Microsoft Corporation>
[Windows Media Connect (WMC) / WmcCds][Stopped/Manual Start]
<c:\program files\windows media connect\mswmccds.exe><Microsoft Corporation>
[Windows Media Connect (WMC) 帮助程序 / WmcCdsLs][Stopped/Manual Start]
<C:\Program Files\Windows Media Connect\mswmcls.exe><Microsoft Corporation>
==================================
灵魂旅行 - 2007-1-8 13:18:00
驱动程序
[abp480n5 / abp480n5][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ABP480N5.SYS><Microsoft Corporation>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
<system32\drivers\ac97intc.sys><Intel Corporation>
[ADI UAA Function Driver for High Definition Audio Service / ADIHdAudAddService][Running/Manual Start]
<system32\drivers\ADIHdAud.sys><Analog Devices, Inc.>
[adpu160m / adpu160m][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\adpu160m.sys><Microsoft Corporation>
[AEAudio Service / AEAudioService][Running/Manual Start]
<system32\drivers\AEAudio.sys><Andrea Electronics Corporation>
[Aha154x / Aha154x][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\aha154x.sys><Microsoft Corporation>
[aic78u2 / aic78u2][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\aic78u2.sys><Microsoft Corporation>
[aic78xx / aic78xx][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\aic78xx.sys><Microsoft Corporation>
[AliIde / AliIde][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AMD AGP Bus Filter Driver / amdagp][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\amdagp.sys><Advanced Micro Devices, Inc.>
[asc / asc][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\asc.sys><Advanced System Products, Inc.>
[asc3350p / asc3350p][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\asc3350p.sys><Microsoft Corporation>
[asc3550 / asc3550][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\asc3550.sys><Advanced System Products, Inc.>
[ati2mtag / ati2mtag][Running/Manual Start]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[cd20xrnt / cd20xrnt][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\cd20xrnt.sys><Microsoft Corporation>
[CmdIde / CmdIde][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[dac2w2k / dac2w2k][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\dac2w2k.sys><Mylex Corporation>
[DLABOIOM / DLABOIOM][Running/Auto Start]
<System32\DLA\DLABOIOM.SYS><Sonic Solutions>
[DLACDBHM / DLACDBHM][Running/System Start]
<System32\Drivers\DLACDBHM.SYS><Sonic Solutions>
[DLADResN / DLADResN][Running/Auto Start]
<System32\DLA\DLADResN.SYS><Sonic Solutions>
[DLAIFS_M / DLAIFS_M][Running/Auto Start]
<System32\DLA\DLAIFS_M.SYS><Sonic Solutions>
[DLAOPIOM / DLAOPIOM][Running/Auto Start]
<System32\DLA\DLAOPIOM.SYS><Sonic Solutions>
[DLAPoolM / DLAPoolM][Running/Auto Start]
<System32\DLA\DLAPoolM.SYS><Sonic Solutions>
[DLARTL_N / DLARTL_N][Running/System Start]
<System32\Drivers\DLARTL_N.SYS><Sonic Solutions>
[DLAUDFAM / DLAUDFAM][Running/Auto Start]
<System32\DLA\DLAUDFAM.SYS><Sonic Solutions>
[DLAUDF_M / DLAUDF_M][Running/Auto Start]
<System32\DLA\DLAUDF_M.SYS><Sonic Solutions>
[dpti2o / dpti2o][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\dpti2o.sys><Microsoft Corporation>
[DRVMCDB / DRVMCDB][Running/Boot Start]
<\SystemRoot\System32\Drivers\DRVMCDB.SYS><Sonic Solutions>
[DRVNDDM / DRVNDDM][Running/Auto Start]
<System32\Drivers\DRVNDDM.SYS><Sonic Solutions>
[Intel(R) PRO Adapter Driver / E100B][Stopped/Manual Start]
<system32\DRIVERS\e100b325.sys><Intel Corporation>
[Intel(R) PRO/1000 PCI Express Network Connection Driver / e1express][Running/Manual Start]
<system32\DRIVERS\e1e5132.sys><Intel Corporation>
[IBM eGatherer / EGATHDRV][Running/Auto Start]
<\??\C:\WINDOWS\SYSTEM32\EGATHDRV.SYS><IBM Corporation>
[Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[ibmfilter / ibmfilter][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\ibmfilter.sys><IBM>
[ini910u / ini910u][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ini910u.sys><Microsoft Corporation>
[mraid35x / mraid35x][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\mraid35x.sys><American Megatrends Inc.>
[Nokia USB Generic / Nokia USB Generic][Stopped/Manual Start]
<system32\drivers\nmwcdc.sys><Nokia>
[Nokia USB Modem / Nokia USB Modem][Stopped/Manual Start]
<system32\drivers\nmwcdcm.sys><Nokia>
[Nokia USB Phone Parent / Nokia USB Phone Parent][Stopped/Manual Start]
<system32\drivers\nmwcd.sys><Nokia>
[Nokia USB Port / Nokia USB Port][Stopped/Manual Start]
<system32\drivers\nmwcdcj.sys><Nokia>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Stopped/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[PCDRNDISUIO Usermode I/O Protocol / PcdrNdisuio][Stopped/Manual Start]
<system32\DRIVERS\pcdrndisuio.sys><Windows (R) 2000 DDK provider>
[Padus ASPI Shell / Pfc][Running/Manual Start]
<system32\drivers\pfc.sys><Padus, Inc.>
[pmem / pmem][Running/Auto Start]
<\??\C:\WINDOWS\System32\drivers\pmemnt.sys><Microsoft Corporation>
[PrivateDisk / PrivateDisk][Running/Auto Start]
<\??\C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\PrivateDiskM.sys><Utimaco Safeware AG>
[IPS 帮助器驱动程序 / PROCDD][Running/Auto Start]
<system32\DRIVERS\PROCDD.SYS><Lenovo Ltd.>
[IBM PSA Access Driver / psadd][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\Drivers\psadd.sys><Lenovo>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[ql1080 / ql1080][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ql1080.sys><QLogic Corporation>
[Ql10wnt / Ql10wnt][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ql10wnt.sys><Microsoft Corporation>
[ql12160 / ql12160][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ql12160.sys><QLogic Corporation>
[ql1280 / ql1280][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ql1280.sys><QLogic Corporation>
[RsAntiSpyware / RsAntiSpyware][Stopped/Disabled]
<\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[SenFilt Service / SenFiltService][Running/Manual Start]
<system32\drivers\Senfilt.sys><Sensaura>
[SIS AGP Bus Filter / sisagp][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\sisagp.sys><Silicon Integrated Systems Corporation>
[smi2 / smi2][Running/Auto Start]
<\??\C:\Program Files\SMI2\smi2.sys><IBM Corp.>
[Sparrow / Sparrow][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\sparrow.sys><Adaptec, Inc.>
[symc810 / symc810][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\symc810.sys><Symbios Logic Inc.>
[symc8xx / symc8xx][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\symc8xx.sys><LSI Logic>
[sym_hi / sym_hi][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\sym_hi.sys><LSI Logic>
[sym_u3 / sym_u3][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\sym_u3.sys><LSI Logic>
[Trend Micro Filter / TmFilter][Running/Auto Start]
<\??\C:\OfficeScan NT\TmXPFlt.sys><Trend Micro Inc.>
[Trend Micro PreFilter / TmPreFilter][Running/Auto Start]
<\??\C:\OfficeScan NT\TmPreFlt.sys><Trend Micro Inc.>
[Common Firewall Driver / TM_CFW][Running/Auto Start]
<\??\C:\OfficeScan NT\tm_cfw.sys><Trend Micro Inc.>
[TosIde / TosIde][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\toside.sys><Microsoft Corporation>
[NSC Integrated Trusted Platform Module 1.2 / TPM12][Running/Manual Start]
<system32\DRIVERS\nsctpm12.sys><National Semiconductor Corp.>
[ultra / ultra][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\ultra.sys><Promise Technology, Inc.>
[ViaIde / ViaIde][Stopped/Disabled]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[Trend Micro VSAPI NT / VSApiNt][Running/Auto Start]
<\??\C:\OfficeScan NT\VSApiNt.sys><Trend Micro Inc.>
==================================
灵魂旅行 - 2007-1-8 13:20:00
浏览器加载项
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[XML.Tree]
{05A0FADA-678B-4D19-89EB-1468806B1784} <C:\WINDOWS\Downloaded Program Files\XmlTreeControl.ocx, Shangxinge>
[Microsoft Date and Time Picker Control, version 6.0]
{20DD1B9E-87C4-11D1-8BE3-0000F8754DA1} <C:\WINDOWS\Downloaded Program Files\MSCOMCT2.OCX, Microsoft Corporation>
[IOAViewer.IOARtf]
{2C59A438-49FA-11D3-9F84-0020AF70545E} <C:\WINDOWS\Downloaded Program Files\IOAViewer.ocx, Shanghai Intranet System Corp.>
[Java Plug-in 1.4.2]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll, IBM.>
[KeyCheck.CheckKey]
{9F3C5C45-CBB5-46B6-A810-3738752E553D} <C:\WINDOWS\Downloaded Program Files\KeyCheck.ocx, SIntranet>
[Java Plug-in 1.4.2]
{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} <C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll, IBM.>
[urldownload.UserControl1]
{CC5C4083-7A44-469E-AA63-302B173E8642} <C:\WINDOWS\Downloaded Program Files\eoffice_urldownload.ocx, Hewlett-Packard Company>
[MyDialog.MyXDialog]
{DA523934-7F60-447C-8A31-01208B00019D} <C:\WINDOWS\Downloaded Program Files\MyDialog.ocx, Microsoft>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[IOAFlowCtl.WebFlowCtl]
{EA4EBB2C-18AE-4A2A-B5CB-27E20F2C073B} <C:\WINDOWS\Downloaded Program Files\IOAFlowCtl.ocx, Shanghai Intranet System Corp.>
[Upload Class]
{F88EF9D9-2393-11D3-B599-00609764DF1A} <C:\WINDOWS\system32\FileTransfer.dll, Shanghai Intranet>
[IOAFPath.FlowPathPopWin]
{FA3EFBD2-BFD2-11D2-A74E-00609764DDD0} <C:\WINDOWS\system32\IOAFPath.ocx, OA Soft>
[ActiveMovieControl Object]
{05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[XML.Tree]
{05A0FADA-678B-4D19-89EB-1468806B1784} <C:\WINDOWS\Downloaded Program Files\XmlTreeControl.ocx, Shangxinge>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Microsoft Date and Time Picker Control, version 6.0]
{20DD1B9E-87C4-11D1-8BE3-0000F8754DA1} <C:\WINDOWS\Downloaded Program Files\MSCOMCT2.OCX, Microsoft Corporation>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[IOAViewer.IOARtf]
{2C59A438-49FA-11D3-9F84-0020AF70545E} <C:\WINDOWS\Downloaded Program Files\IOAViewer.ocx, Shanghai Intranet System Corp.>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[Microsoft Licensed Class Manager 1.0]
{5220CB21-C88D-11CF-B347-00AA00A28331} <C:\WINDOWS\system32\licmgr10.dll, Microsoft Corporation>
[HHCtrl Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[DriveLetterAccess]
{5CA3D70E-1895-11CF-8E15-001234567890} <C:\WINDOWS\System32\DLA\DLASHX_W.DLL, Sonic Solutions>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[KeyCheck.CheckKey]
{9F3C5C45-CBB5-46B6-A810-3738752E553D} <C:\WINDOWS\Downloaded Program Files\KeyCheck.ocx, SIntranet>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[urldownload.UserControl1]
{CC5C4083-7A44-469E-AA63-302B173E8642} <C:\WINDOWS\Downloaded Program Files\eoffice_urldownload.ocx, Hewlett-Packard Company>
[VIDEO__X_MS_ASF Moniker Class]
{CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[IOAFlowCtl.WebFlowCtl]
{EA4EBB2C-18AE-4A2A-B5CB-27E20F2C073B} <C:\WINDOWS\Downloaded Program Files\IOAFlowCtl.ocx, Shanghai Intranet System Corp.>
[Upload Class]
{F88EF9D9-2393-11D3-B599-00609764DF1A} <C:\WINDOWS\system32\FileTransfer.dll, Shanghai Intranet>
[IOAFPath.FlowPathPopWin]
{FA3EFBD2-BFD2-11D2-A74E-00609764DDD0} <C:\WINDOWS\system32\IOAFPath.ocx, OA Soft>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
==================================
红夜鬼1 - 2007-1-8 17:40:00
运行SREng2,使用“启动项目”--注册表--删除
C:\WINDOWS\system32\tpxhst32.exe
C:\WINDOWS\Config\svhost32.exe
运行(双击)SRENG2,点“启动项目,服务,点“Win32服务应用程序”
勾选“隐藏微软服务”选中病毒服务
891981CC
Gray_Pigeon_Server1.23
Transaction Provisioning Service
,选择“删除服务”
点“设置”选择“否”
重启按F8进入安全模式下
显示隐藏文件
删除:
C:\WINDOWS\system32\8.txt
C:\WINDOWS\system32\891981CC.EXE
C:\WINDOWS\G_Server1.23.exe
C:\WINDOWS\system32\tpxhst32.exe
C:\WINDOWS\Config\svhost32.exe
C:\WINDOWS\system32\twunk32.exe
参考
http://forum.ikaka.com/topic.asp?board=28&artid=8237996
推荐使用360安全卫士清理一下
.360下载地址:
http://www.360safe.com/
http://www.xdowns.com/soft/8/9/2006/Soft_31554.html
使用后删除360安全卫士
kkk600895 - 2007-1-9 1:05:00
红夜鬼的头像好看!今天俺的电脑没病,所以俺也没有吃药.以后没事儿我也常来.
© 2000 - 2026 Rising Corp. Ltd.