瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 中了至少2个病毒……|||realplayer.exe和an85.com,好象还有其他滴

1   1  /  1  页   跳转

中了至少2个病毒……|||realplayer.exe和an85.com,好象还有其他滴

中了至少2个病毒……|||realplayer.exe和an85.com,好象还有其他滴

昨天发现中了realplayer.exe病毒,自己按照置顶的帖子把它个删了,只是不知道弄干净没(中途操作出先过问题)
同时桌面出现an85.com的MS-DOS 应用程序,肯定是病毒,就是不知道奥妙弄,还请大人们指教……

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [Microsoft Corporation]
    <iDuba Personal FireWall><C:\KAV6\Kavpfw.EXE>  [Kingsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <SoundMan><SOUNDMAN.EXE>  [Avance Logic, Inc.]
    <NvCplDaemon><RUNDLL32.EXE NvQTwk,NvCplDaemon initialize>  []
    <nwiz><nwiz.exe /install>  []
    <BigDogPath><C:\WINDOWS\VM_STI.EXE USB PC Camera 301P>  []
    <KAVRun><C:\KAV6\KAVRun.EXE>  [kingsoft]
    <Kulansyn><C:\KAV6\Kulansyn.EXE>  [Kingsoft Corp.]
    <KpopMon><C:\KAV6\KpopMon.EXE>  []
    <iDuba Personal FireWall><C:\KAV6\Kavpfw.EXE>  [Kingsoft Corporation]
    <ISC_UpDate><>  []
    <ISC><>  []
    <IMJPMIG8.1><rem ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <MyIMLite><rem ; >  []
    <PHIME2002A><rem ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <PHIME2002ASync><rem ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
    <StormCodec_Helper><"e:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\System32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><>  []

==================================
启动文件夹
[Adobe Gamma Loader]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>

==================================
服务
[C-DillaCdaC11BA / C-DillaCdaC11BA]
  <C:\WINDOWS\System32\drivers\CDAC11BA.EXE><N/A>
[C-DillaSrv / C-DillaSrv]
  <C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE><C-Dilla Ltd>
[Canon Camera Access Library 8 / CCALib8]
  <C:\Program Files\Canon\CAL\CALMAIN.exe><Canon Inc.>
[DCPFLICS / DCPFLICS]
  <C:\Program Files\DCPFLICS\DCPFLICS.exe><N/A>
[Kingsoft AntiVirus Service / KAVSvc]
  <C:\KAV6\KAVSvc.EXE><kingsoft Antivirus>
[Macromedia Licensing Service / Macromedia Licensing Service]
  <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[Leadtek Driver Helper Service / nvsvc]
  <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>

==================================
浏览器加载项
[MusicSearch Class]
  {3D33EAE4-9EAA-4542-BCC8-9A9061392D56} <, N/A>
[Router Layer]
  {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} <, N/A>
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~1\FLASHGET\jccatch.dll, Amaze Soft>
[解霸]
  {367E0A21-8601-4986-9C9A-153BF5ACA118} <E:\Program Files\豪杰3000\MPLAYER.EXE, N/A>
[金山卓越]
  {8DE0FCD4-5EB5-11D3-AD25-00002100131B} <url:http://www.joyo.com, N/A>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[FlashGet]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft>
[金山毒霸网站]
  {e1fc9760-7b95-49cd-80b9-8c9e41017b93} <url:http://www.duba.net, N/A>
[在线查毒]
  {f58d36c3-40be-4418-a786-d8fbe3eb3554} <C:\KAV6\kavie.HTM, N/A>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\MSMSGS.EXE, Microsoft Corporation>
[金山毒霸]
  {A9BE2902-C447-420A-BB7F-A5DE921E6138} <C:\KAV6\KAIEPlus.DLL, >
[InstaFred]
  {1F831FA1-42FC-11D4-95A6-0080AD30DCE1} <C:\WINDOWS\DOWNLO~1\InstFred.ocx, Autodesk, Inc.>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\System32\wuweb.dll, Microsoft Corporation>
[MUWebControl Class]
  {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\System32\muweb.dll, Microsoft Corporation>
[AcDcToday 控件]
  {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} <C:\WINDOWS\DOWNLO~1\ACDCTO~1.OCX, Autodesk>
[Qzone Media Tools]
  {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} <C:\WINDOWS\System32\QZONEM~1.OCX, Tencent Technology (Shenzhen) Company Limited>
[NOXLATE-BANR]
  {AE563722-B4F5-11D4-A415-00108302FDFD} <C:\WINDOWS\DOWNLO~1\InstBanr.ocx, Autodesk, Inc.>
[Blueskyvoice Control]
  {BA0F088C-72C1-475A-92F8-42391DEF6961} <C:\WINDOWS\DOWNLO~1\BLUESK~1.OCX, 蓝天工作室(http://www.bluesky.cn)>
[ImgProcessControl Class]
  {BD1B565A-347F-4666-847F-403EAE910A15} <C:\WINDOWS\DOWNLO~1\IMGPRO~1.DLL, >
[WebEngine Control]
  {C2B9EE9C-D9E4-4C35-A7B2-62AE1D9E2997} <C:\WINDOWS\DOWNLO~1\WEBENG~1.OCX, 江苏天泽信息产业>
[cycnset Class]
  {C50341E9-CDC1-4377-AB88-3486CCD0FDA1} <C:\WINDOWS\System32\cycnset.dll, ? SK Communications>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[PowerDld Control]
  {DF6FE46D-1D23-4668-AD3A-CDEA1262B282} <C:\WINDOWS\DOWNLO~1\PowerDld.ocx, Powerise Digital>
[AcPreview 控件]
  {F281A59C-7B65-11D3-8617-0010830243BD} <C:\WINDOWS\DOWNLO~1\ACPREV~1.OCX, Autodesk>
[SHLaunch Control]
  {FA463B6E-93D5-4E02-B7F2-E0BA98DA73FC} <C:\WINDOWS\System32\SHLaunch.ocx, >
[上传到QQ网络硬盘]
  <E:\Program Files\新版QQ\IPQQ2006\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <E:\Program Files\新版QQ\IPQQ2006\AddPanel.htm, N/A>
[添加到QQ表情]
  <E:\Program Files\新版QQ\IPQQ2006\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <E:\Program Files\新版QQ\IPQQ2006\SendMMS.htm, N/A>

==================================
最后编辑2006-09-03 09:54:02
分享到:
gototop
 

正在运行的进程
[PID: 596][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 668][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 692][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.1557 (xpsp2_gdr.040517-1325)>
[PID: 736][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 748][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 900][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 924][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1128][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1152][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1468][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.0 (XPClient.010817-1148)>
[PID: 1544][C:\WINDOWS\SOUNDMAN.EXE]  <Avance Logic, Inc.><5, 0, 0, 0>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 1568][C:\WINDOWS\VM_STI.EXE]  <VM.><4.2.610.4>
    [C:\WINDOWS\System32\msdmo.dll]  <N/A><N/A>
[PID: 1608][C:\KAV6\KpopMon.EXE]  <><2004, 2, 2, 31>
    [C:\KAV6\KAVMLM.DLL]  <Kingsoft Corporation><2003.11.12.10>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 1764][C:\KAV6\KWatchUI.EXE]  <><2004.1.6.119>
    [C:\KAV6\kavcomm.dll]  <Kingsoft Corporation><2003, 11, 12, 66>
    [C:\KAV6\kavdlg.dll]  <><2004.7.20.81>
    [C:\KAV6\KAVMLM.DLL]  <Kingsoft Corporation><2003.11.12.10>
    [C:\KAV6\RpcBrge.DLL]  <kingsoft><2003, 11, 12, 64>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 1784][C:\WINDOWS\System32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 1800][C:\KAV6\Kavpfw.EXE]  <Kingsoft Corporation><2004, 8, 16, 295>
    [C:\KAV6\KAVMLM.DLL]  <Kingsoft Corporation><2003.11.12.10>
    [C:\KAV6\PFWScanC.dll]  <KingSoft><2002, 4, 12, 3>
    [C:\KAV6\KAMsgBox.dll]  <><2002.9.27.30>
    [C:\KAV6\NetShare.dll]  <Kingsoft Antivirus><2004, 2, 20, 67>
    [C:\KAV6\KAEPlat.DLL]  <Kingsoft Corp.><2005, 12, 29, 56>
    [C:\KAV6\KAEMem.DAT]  <Kingsoft><2006, 4, 12, 13>
    [C:\KAV6\KAEUnpack.DAT]  <Kingsoft Corp.><2006, 6, 15, 44>
    [C:\KAV6\KAEQSCAN.DLL]  <Kingsoft Corp><2004, 3, 26, 69>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
    [C:\KAV6\KAVLogFn.dll]  <N/A><2003, 11, 26, 16>
[PID: 2004][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 2016][C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE]  <C-Dilla Ltd><3.25.010>
[PID: 2032][C:\Program Files\DCPFLICS\DCPFLICS.exe]  <N/A><N/A>
[PID: 172][C:\KAV6\KAVSvc.EXE]  <kingsoft Antivirus><2003, 11, 12, 70>
    [C:\KAV6\SvcComm.dll]  <kingsoft Antivirus><2004, 7, 28, 1>
    [C:\KAV6\SvcTimer.DLL]  <Kingsoft><2004.4.29.79>
    [C:\KAV6\KavComm.dll]  <Kingsoft Corporation><2003, 11, 12, 66>
    [C:\KAV6\RpcBrge.DLL]  <kingsoft><2003, 11, 12, 64>
    [C:\KAV6\KWatchFn2.dll]  <kingsoft Corporation><2004, 8, 24, 25>
    [C:\KAV6\KAEPlat.DLL]  <Kingsoft Corp.><2005, 12, 29, 56>
    [C:\KAV6\KAEMem.DAT]  <Kingsoft><2006, 4, 12, 13>
    [C:\KAV6\KAEUnpack.DAT]  <Kingsoft Corp.><2006, 6, 15, 44>
    [C:\KAV6\KAVUtils.dll]  <Kingsoft Corp><2004, 2, 12, 69>
    [C:\KAV6\KAVDlg.DLL]  <><2004.7.20.81>
    [C:\KAV6\KAVLogFn.dll]  <N/A><2003, 11, 26, 16>
[PID: 196][C:\WINDOWS\System32\nvsvc32.exe]  <NVIDIA Corporation><6.13.10.2750>
[PID: 292][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 488][C:\KAV6\MailMon.EXE]  <Kingsoft Co., Ltd><2004, 2, 6, 245>
    [C:\KAV6\KMFilter.DLL]  <><2004, 3, 1, 37>
    [C:\KAV6\parse822.dll]  <Quiksoft Corporation><2, 0, 0, 9>
    [C:\KAV6\KAVLogFn.dll]  <N/A><2003, 11, 26, 16>
    [C:\KAV6\KAVMLM.DLL]  <Kingsoft Corporation><2003.11.12.10>
    [C:\KAV6\KAMsgBox.DLL]  <><2002.9.27.30>
    [C:\KAV6\KAVComm.dll]  <Kingsoft Corporation><2003, 11, 12, 66>
    [C:\KAV6\RpcBrge.DLL]  <kingsoft><2003, 11, 12, 64>
    [C:\KAV6\KAVIPC.DLL]  <Kingsoft Corp.><2002, 3, 29, 8>
    [C:\KAV6\KAVDlg.DLL]  <><2004.7.20.81>
    [C:\KAV6\KAECall.DLL]  <Kingsoft Corporation><2003, 11, 14, 66>
    [C:\KAV6\KAEScan.DLL]  <Kingsoft Corp.><2003, 5, 24, 36>
    [C:\KAV6\KAEPlat.DLL]  <Kingsoft Corp.><2005, 12, 29, 56>
    [C:\KAV6\KAEMem.DAT]  <Kingsoft><2006, 4, 12, 13>
    [C:\KAV6\KAEUnpack.DAT]  <Kingsoft Corp.><2006, 6, 15, 44>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 852][C:\KAV6\KAVPlus.EXE]  <><2004, 3, 3, 71>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 980][C:\Program Files\Canon\CAL\CALMAIN.exe]  <Canon Inc.><8, 0, 0, 21>
[PID: 3572][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
    [C:\PROGRA~1\FLASHGET\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
    [C:\KAV6\KAVEXT.DLL]  <Kingsoft Corp.><2002, 5, 24, 6>
    [C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
[PID: 2108][C:\WINDOWS\Explorer.exe]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\PROGRA~1\FLASHGET\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
    [C:\KAV6\KAVEXT.DLL]  <Kingsoft Corp.><2002, 5, 24, 6>
[PID: 3860][F:\光盘快件\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

HijackThis v1.99.1的扫描结果:

Logfile of HijackThis v1.99.1
Scan saved at 12:29:23, on 2006-9-2
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\VM_STI.EXE
C:\KAV6\KpopMon.EXE
C:\KAV6\KWatchUI.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\KAV6\Kavpfw.EXE
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\Program Files\DCPFLICS\DCPFLICS.exe
C:\KAV6\KAVSvc.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\KAV6\MailMon.EXE
C:\KAV6\KAVPlus.EXE
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\Explorer.exe
F:\光盘快件\HijackThis.exe

O2 - BHO: MusicSearch Class - {3D33EAE4-9EAA-4542-BCC8-9A9061392D56} - (no file)
O2 - BHO: Router Layer - {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} - (no file)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O3 - Toolbar: (no name) - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - (no file)
O3 - Toolbar: 金山毒霸 - {A9BE2902-C447-420A-BB7F-A5DE921E6138} - C:\KAV6\KAIEPlus.DLL
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE USB PC Camera 301P
O4 - HKLM\..\Run: [KAVRun] C:\KAV6\KAVRun.EXE
O4 - HKLM\..\Run: [Kulansyn] C:\KAV6\Kulansyn.EXE
O4 - HKLM\..\Run: [KpopMon] C:\KAV6\KpopMon.EXE
O4 - HKLM\..\Run: [iDuba Personal FireWall] C:\KAV6\Kavpfw.EXE
O4 - HKLM\..\Run: [IMJPMIG8.1] rem ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MyIMLite] rem ;
O4 - HKLM\..\Run: [PHIME2002A] rem ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PHIME2002ASync] rem ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [StormCodec_Helper] "e:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [iDuba Personal FireWall] C:\KAV6\Kavpfw.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - E:\Program Files\新版QQ\IPQQ2006\AddToNetDisk.htm
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\Program Files\新版QQ\IPQQ2006\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\Program Files\新版QQ\IPQQ2006\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\Program Files\新版QQ\IPQQ2006\SendMMS.htm
O9 - Extra button: 解霸 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - E:\Program Files\豪杰3000\MPLAYER.EXE
O9 - Extra 'Tools' menuitem: 超级解霸 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - E:\Program Files\豪杰3000\MPLAYER.EXE
O9 - Extra button: 金山卓越 - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - url:http://www.joyo.com (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra button: 金山毒霸网站 - {e1fc9760-7b95-49cd-80b9-8c9e41017b93} - url:http://www.duba.net (file missing)
O9 - Extra button: 在线查毒 - {f58d36c3-40be-4418-a786-d8fbe3eb3554} - C:\KAV6\kavie.HTM
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {1F831FA1-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file://E:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1156814912046
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156815447734
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday 控件) - file://E:\Program Files\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} (Qzone Media Tools) - http://qz-photo.qq.com/qzone3/QzoneMediaTools.cab
O16 - DPF: {AE563722-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://E:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {BA0F088C-72C1-475A-92F8-42391DEF6961} (Blueskyvoice Control) - http://www.bluesky.cn/download/blueskyvoice_26.cab
O16 - DPF: {BD1B565A-347F-4666-847F-403EAE910A15} (ImgProcessControl Class) - http://www1.uufriends.com/download/ImgProControl.cab
O16 - DPF: {C2B9EE9C-D9E4-4C35-A7B2-62AE1D9E2997} (WebEngine Control) - http://218.94.6.186/Engine.CAB
O16 - DPF: {C50341E9-CDC1-4377-AB88-3486CCD0FDA1} (cycnset Class) - http://ms1.cyworld.com.cn/music/package/cycnset.cab
O16 - DPF: {DF6FE46D-1D23-4668-AD3A-CDEA1262B282} (PowerDld Control) - http://bbsky.wuhan.net.cn/plugin/PowerDld.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview 控件) - file://E:\Program Files\AutoCAD 2002\AcPreview.ocx
O16 - DPF: {FA463B6E-93D5-4E02-B7F2-E0BA98DA73FC} (SHLaunch Control) - http://61.153.32.90/VideoChat/SHLaunch_0935.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2050B68D-479B-4A61-BE38-DE43F48018C0}: NameServer = 202.103.24.68,202.103.0.117
O17 - HKLM\System\CCS\Services\Tcpip\..\{79300FEC-AE0B-41B0-A54A-F595545040C1}: NameServer = 202.103.24.68 202.103.44.150
O23 - Service: C-DillaCdaC11BA - Unknown owner - C:\WINDOWS\System32\drivers\CDAC11BA.EXE (file missing)
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: DCPFLICS - Unknown owner - C:\Program Files\DCPFLICS\DCPFLICS.exe
O23 - Service: Kingsoft AntiVirus Service (KAVSvc) - kingsoft Antivirus - C:\KAV6\KAVSvc.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Leadtek Driver Helper Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

gototop
 

居然没人帮忙……555~~
gototop
 

realplayer.exe 看置顶贴
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT