瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 电脑启动尝试运行system32\wzninet.dll,DLLGetVersion发生意外,有日志

1   1  /  1  页   跳转

电脑启动尝试运行system32\wzninet.dll,DLLGetVersion发生意外,有日志

电脑启动尝试运行system32\wzninet.dll,DLLGetVersion发生意外,有日志

2006-10-17,17:10:25

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <Internat.exe><internat.exe>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <Synchronization Manager><mobsync.exe /logon>  [(Verified)Microsoft Corporation]
    <SoundMan><SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
    <YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>  [Yahoo! China]
    <yassistse><"C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">  [Yahoo! China]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINNT\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <Network.ConnectionTray><C:\WINNT\system32\NETSHELL.dll>  [(Verified)Microsoft Corporation]
    <WebCheck><%SystemRoot%\system32\webcheck.dll>  [(Verified)Microsoft Corporation]
    <SysTray><stobject.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Run]
    <WinlogonNotify: Run><C:\WINNT\system32\j4p00e7meh.dll>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    <WinlogonNotify: sclgntfy><sclgntfy.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
    <WinlogonNotify: wzcnotif><wzcdlg.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Corporation]
    <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Corporation]

==================================
启动文件夹
[腾讯QQ]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk --> D:\PROGRA~1\腾讯QQ\QQ.exe [TENCENT]><N>

==================================
服务
[Logical Disk Manager Administrative Service / dmadmin]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[MSSQLServer / MSSQLServer]
  <c:\MSSQL7\binn\sqlservr.exe><Microsoft Corporation>
[SQLServerAgent / SQLServerAgent]
  <c:\MSSQL7\binn\sqlagent.exe><Microsoft Corporation>
[Portable Media Serial Number Service / WmdmPmSN]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\system32\mspmsnsv.dll><Microsoft Corporation>

==================================
最后编辑2006-10-17 18:19:50
分享到:
gototop
 

驱动程序
[10144056 / 10144056]
  <C:\WINNT\SYSTEM32\DRIVERS\10144056.SYS><N/A>
[2930U2 / 2930U2]
  <\SystemRoot\System32\DRIVERS\2930U2.SYS><N/A>
[3WAREDRV / 3WAREDRV]
  <\SystemRoot\System32\DRIVERS\3WAREDRV.SYS><N/A>
[3WAREFLT / 3WAREFLT]
  <\SystemRoot\System32\DRIVERS\3WAREFLT.SYS><N/A>
[3WAREGSM / 3WAREGSM]
  <\SystemRoot\System32\DRIVERS\3WAREGSM.SYS><N/A>
[3WDRV100 / 3WDRV100]
  <\SystemRoot\System32\DRIVERS\3WDRV100.SYS><N/A>
[A320RAID / A320RAID]
  <\SystemRoot\System32\DRIVERS\A320RAID.SYS><Adaptec, Inc.>
[AAC / AAC]
  <\SystemRoot\System32\DRIVERS\AAC.SYS><N/A>
[AAR1210 / AAR1210]
  <\SystemRoot\System32\DRIVERS\AAR1210.SYS><Adaptec, Inc.>
[abp480n5 / abp480n5]
  <\SystemRoot\System32\DRIVERS\ABP480N5.SYS><Microsoft Corporation>
[ADF6U160 / ADF6U160]
  <\SystemRoot\System32\DRIVERS\ADF6U160.SYS><N/A>
[adpu160m / adpu160m]
  <\SystemRoot\System32\DRIVERS\ADPU160M.SYS><Microsoft Corporation>
[ADPU320 / ADPU320]
  <\SystemRoot\System32\DRIVERS\ADPU320.SYS><Adaptec, Inc.>
[AEC6210 / AEC6210]
  <\SystemRoot\System32\DRIVERS\AEC6210.SYS><ACARD Technology Corp.>
[AEC6260 / AEC6260]
  <\SystemRoot\System32\DRIVERS\AEC6260.SYS><ACARD Technology Corp.>
[AEC6280 / AEC6280]
  <\SystemRoot\System32\DRIVERS\AEC6280.SYS><ACARD Technology Corp.>
[AEC67160 / AEC67160]
  <\SystemRoot\System32\DRIVERS\AEC67160.SYS><N/A>
[AEC671X / AEC671X]
  <\SystemRoot\System32\DRIVERS\AEC671X.SYS><N/A>
[AEC68X5 / AEC68X5]
  <\SystemRoot\System32\DRIVERS\AEC68X5.SYS><ACARD Technology Corp.>
[AFC9XXX / AFC9XXX]
  <\SystemRoot\System32\DRIVERS\AFC9XXX.SYS><N/A>
[Aha154x / Aha154x]
  <C:\WINNT\SYSTEM32\DRIVERS\Aha154x.SYS><Microsoft Corporation>
[aic116x / aic116x]
  <\SystemRoot\System32\DRIVERS\AIC116X.SYS><N/A>
[aic78u2 / aic78u2]
  <\SystemRoot\System32\DRIVERS\AIC78U2.SYS><Microsoft Corporation>
[aic78xx / aic78xx]
  <\SystemRoot\System32\DRIVERS\AIC78XX.SYS><Microsoft Corporation>
[Service for WDM 3D Audio Driver / ALCXSENS]
  <system32\drivers\ALCXSENS.SYS><Sensaura>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[ASA72XX / ASA72XX]
  <\SystemRoot\System32\DRIVERS\ASA72XX.SYS><N/A>
[asc / asc]
  <\SystemRoot\System32\DRIVERS\ASC.SYS><Advanced System Products, Inc.>
[asc3550 / asc3550]
  <C:\WINNT\SYSTEM32\DRIVERS\asc3550.SYS><Advanced System Products, Inc.>
[BaseTDI / BaseTDI]
  <2 - 系统找不到指定的文件。
><N/A>
gototop
 

[HelloNet PPPoE 虚拟网卡 / BRPPPOE]
  <system32\DRIVERS\brpppoe.sys><N/A>
[BusLogic / BusLogic]
  <\SystemRoot\System32\DRIVERS\BUSLOGIC.SYS><N/A>
[CDA1000 / CDA1000]
  <\SystemRoot\System32\DRIVERS\CDA1000.SYS><N/A>
[Cdr4_2K / Cdr4_2K]
  <C:\WINNT\SYSTEM32\DRIVERS\Cdr4_2K.SYS><Roxio>
[Cdralw2k / Cdralw2k]
  <C:\WINNT\SYSTEM32\DRIVERS\Cdralw2k.SYS><Roxio>
[CLRTYFC / CLRTYFC]
  <\SystemRoot\System32\DRIVERS\CLRTYFC.SYS><N/A>
[CMDIDE / CMDIDE]
  <\SystemRoot\System32\DRIVERS\CMDIDE.SYS><CMD Technology, Inc.>
[cpqarry2 / cpqarry2]
  <\SystemRoot\System32\DRIVERS\CPQARRY2.SYS><N/A>
[CPQCISSM / CPQCISSM]
  <\SystemRoot\System32\DRIVERS\CPQCISSM.SYS><N/A>
[cpqfcalm / cpqfcalm]
  <\SystemRoot\System32\DRIVERS\CPQFCALM.SYS><N/A>
[CSB6IDE / CSB6IDE]
  <\SystemRoot\System32\DRIVERS\CSB6IDE.SYS><N/A>
[DAC2W2K / DAC2W2K]
  <\SystemRoot\System32\DRIVERS\DAC2W2K.SYS><Mylex Corporation>
[dmboot / dmboot]
  <System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio]
  <\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload]
  <\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[DMX3191 / DMX3191]
  <\SystemRoot\System32\DRIVERS\DMX3191.SYS><N/A>
[DMX3194 / DMX3194]
  <\SystemRoot\System32\DRIVERS\DMX3194.SYS><N/A>
[DPTI2O / DPTI2O]
  <\SystemRoot\System32\DRIVERS\DPTI2O.SYS><N/A>
[DPTSCSI / DPTSCSI]
  <\SystemRoot\System32\DRIVERS\DPTSCSI.SYS><N/A>
[EXPRESFC / EXPRESFC]
  <\SystemRoot\System32\DRIVERS\EXPRESFC.SYS><N/A>
[EXPRESS2 / EXPRESS2]
  <\SystemRoot\System32\DRIVERS\EXPRESS2.SYS><N/A>
[FASTSX / FASTSX]
  <\SystemRoot\System32\DRIVERS\FASTSX.SYS><Promise Technology, Inc.>
[FASTTRAK / FASTTRAK]
  <\SystemRoot\System32\DRIVERS\FASTTRAK.SYS><Promise Technology, Inc.>
[FASTTX2K / FASTTX2K]
  <\SystemRoot\System32\DRIVERS\FASTTX2K.SYS><Promise Technology, Inc.>
[Fd16_700 / Fd16_700]
  <\SystemRoot\System32\DRIVERS\FD16_700.SYS><N/A>
[fireport / fireport]
  <\SystemRoot\System32\DRIVERS\FIREPORT.SYS><N/A>
[flashpnt / flashpnt]
  <\SystemRoot\System32\DRIVERS\FLASHPNT.SYS><N/A>
[HPT371 / HPT371]
  <\SystemRoot\System32\DRIVERS\HPT371.SYS><HighPoint Technologies, Inc.>
[HPT374 / HPT374]
  <\SystemRoot\System32\DRIVERS\HPT374.SYS><HighPoint Technologies, Inc.>
[HPT3XX / HPT3XX]
  <\SystemRoot\System32\DRIVERS\HPT3XX.SYS><HighPoint Technologies, Inc.>
[HPTMV / HPTMV]
  <\SystemRoot\System32\DRIVERS\HPTMV.SYS><HighPoint Technologies, Inc.>
[HPTPRO / HPTPRO]
  <\SystemRoot\System32\DRIVERS\HPTPRO.SYS><HighPoint Technologies, Inc.>
[I2OMP / I2OMP]
  <\SystemRoot\System32\DRIVERS\I2OMP.SYS><Microsoft Corporation>
[IASTOR / IASTOR]
  <\SystemRoot\System32\DRIVERS\IASTOR.SYS><Intel Corporation>
[IFT2000 / IFT2000]
  <\SystemRoot\System32\DRIVERS\IFT2000.SYS><N/A>
[ini910u / ini910u]
  <\SystemRoot\System32\DRIVERS\INI910U.SYS><Microsoft Corporation>
[INIA100 / INIA100]
  <\SystemRoot\System32\DRIVERS\INIA100.SYS><N/A>
[ipsraidn / ipsraidn]
  <\SystemRoot\System32\DRIVERS\IPSRAIDN.SYS><N/A>
[ITERAID / ITERAID]
  <\SystemRoot\System32\DRIVERS\ITERAID.SYS><Integrated Technology Express, Inc.>
[lp6nds35 / lp6nds35]
  <\SystemRoot\System32\DRIVERS\LP6NDS35.SYS><N/A>
[M5228 / M5228]
  <\SystemRoot\System32\DRIVERS\M5228.SYS><ALi Corporation.>
[M5281 / M5281]
  <\SystemRoot\System32\DRIVERS\M5281.SYS><ALi Corporation>
[MEGAIDE / MEGAIDE]
  <\SystemRoot\System32\DRIVERS\MEGAIDE.SYS><LSI Logic Corporation.>
[MRAID2K / MRAID2K]
  <\SystemRoot\System32\DRIVERS\MRAID2K.SYS><American Megatrends, Inc.>
[mraid35x / mraid35x]
  <\SystemRoot\System32\DRIVERS\MRAID35X.SYS><American MegaTrends Inc.>
[NFRD960 / NFRD960]
  <\SystemRoot\System32\DRIVERS\NFRD960.SYS><N/A>
[npkcrypt / npkcrypt]
  <\??\D:\Program Files\腾讯QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv4 / nv4]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[NVATABUS / NVATABUS]
  <\SystemRoot\System32\DRIVERS\NVATABUS.SYS><NVIDIA Corporation>
[PERC2 / PERC2]
  <\SystemRoot\System32\DRIVERS\PERC2.SYS><Microsoft Corporation>
[PNP649R / PNP649R]
  <\SystemRoot\System32\DRIVERS\PNP649R.SYS><N/A>
[PNP680 / PNP680]
  <\SystemRoot\System32\DRIVERS\PNP680.SYS><Silicon Image, Inc.>
[PNP680R / PNP680R]
  <\SystemRoot\System32\DRIVERS\PNP680R.SYS><Silicon Image, Inc>
[Direct Parallel Link Driver / Ptilink]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[ql1080 / ql1080]
  <\SystemRoot\System32\DRIVERS\QL1080.SYS><QLogic Corporation>
[Ql10wnt / Ql10wnt]
  <\SystemRoot\System32\DRIVERS\QL10WNT.SYS><Microsoft Corporation>
[QL12160 / QL12160]
  <\SystemRoot\System32\DRIVERS\QL12160.SYS><QLogic Corporation>
[QL1280 / QL1280]
  <\SystemRoot\System32\DRIVERS\QL1280.SYS><QLogic Corporation>
[ql2100 / ql2100]
  <\SystemRoot\System32\DRIVERS\QL2100.SYS><N/A>
gototop
 

[QL2200 / QL2200]
  <\SystemRoot\System32\DRIVERS\QL2200.SYS><N/A>
[QL2300 / QL2300]
  <\SystemRoot\System32\DRIVERS\QL2300.SYS><N/A>
[QL4000 / QL4000]
  <\SystemRoot\System32\DRIVERS\QL4000.SYS><N/A>
[QL4010 / QL4010]
  <\SystemRoot\System32\DRIVERS\QL4010.SYS><N/A>
[RAIDSRC / RAIDSRC]
  <\SystemRoot\System32\DRIVERS\RAIDSRC.SYS><N/A>
[Realtek RTL8139-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[SI3112 / SI3112]
  <\SystemRoot\System32\DRIVERS\SI3112.SYS><Silicon Image, Inc.>
[SI3112R / SI3112R]
  <\SystemRoot\System32\DRIVERS\SI3112R.SYS><Silicon Image, Inc>
[SI3114 / SI3114]
  <\SystemRoot\System32\DRIVERS\SI3114.SYS><Silicon Image, Inc.>
[SI3114R / SI3114R]
  <\SystemRoot\System32\DRIVERS\SI3114R.SYS><Silicon Image, Inc>
[SI3124 / SI3124]
  <\SystemRoot\System32\DRIVERS\SI3124.SYS><Silicon Image, Inc.>
[SI3124R / SI3124R]
  <\SystemRoot\System32\DRIVERS\SI3124R.SYS><Silicon Image, Inc>
[SIFILTER / SIFILTER]
  <\SystemRoot\System32\DRIVERS\SIWINACC.SYS><Silicon Image, Inc.>
[SISIDE / SISIDE]
  <\SystemRoot\System32\DRIVERS\SISIDE.SYS><Silicon Integrated Systems Corp.>
[SISRAID / SISRAID]
  <\SystemRoot\System32\DRIVERS\SISRAID.SYS><Silicon Integrated Systems>
[SISRAID1 / SISRAID1]
  <\SystemRoot\System32\DRIVERS\SISRAID1.SYS><Silicon Integrated Systems>
[Sparrow / Sparrow]
  <C:\WINNT\SYSTEM32\DRIVERS\Sparrow.SYS><Adaptec, Inc.>
[SPTRAK / SPTRAK]
  <\SystemRoot\System32\DRIVERS\SPTRAK.SYS><Promise Technology, Inc.>
[Samsung Mobile USB Device II 1.0 driver (WDM) / ssm_bus]
  <system32\DRIVERS\ssm_bus.sys><MCCI>
[Samsung Mobile USB Modem II 1.0 Filter / ssm_mdfl]
  <system32\DRIVERS\ssm_mdfl.sys><MCCI>
[Samsung Mobile USB Modem II 1.0 Drivers / ssm_mdm]
  <system32\DRIVERS\ssm_mdm.sys><MCCI>
[Samsung Mobile USB Device 1.0 driver (WDM) / ss_bus]
  <system32\DRIVERS\ss_bus.sys><MCCI>
[SAMSUNG Mobile USB Modem 1.0 Filter / ss_mdfl]
  <system32\DRIVERS\ss_mdfl.sys><MCCI>
[SAMSUNG Mobile USB Modem 1.0 Drivers / ss_mdm]
  <system32\DRIVERS\ss_mdm.sys><MCCI>
[symc810 / symc810]
  <\SystemRoot\System32\DRIVERS\SYMC810.SYS><Symbios Logic Inc.>
[symc8xx / symc8xx]
  <\SystemRoot\System32\DRIVERS\SYMC8XX.SYS><LSI Logic>
[SYMMPI / SYMMPI]
  <\SystemRoot\System32\DRIVERS\SYMMPI.SYS><N/A>
[sym_hi / sym_hi]
  <\SystemRoot\System32\DRIVERS\SYM_HI.SYS><Symbios Inc.>
[SYM_U3 / SYM_U3]
  <\SystemRoot\System32\DRIVERS\SYM_U3.SYS><LSI Logic>
[TRM3X5 / TRM3X5]
  <\SystemRoot\System32\DRIVERS\TRM3X5.SYS><N/A>
[ULSATA / ULSATA]
  <\SystemRoot\System32\DRIVERS\ULSATA.SYS><Promise Technology, Inc.>
[ULTIMA / ULTIMA]
  <\SystemRoot\System32\DRIVERS\ULTIMA.SYS><N/A>
[ULTIMARX / ULTIMARX]
  <\SystemRoot\System32\DRIVERS\ULTIMARX.SYS><N/A>
[ULTRA / ULTRA]
  <\SystemRoot\System32\DRIVERS\ULTRA.SYS><Promise Technology, Inc.>
gototop
 

浏览器加载项
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\腾讯QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\Program Files\腾讯QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[@msdxmLC.dll,-1@2052,电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
[雅虎助手]
  {406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, yahoo! china>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINNT\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINNT\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[上传到QQ网络硬盘]
  <D:\Program Files\腾讯QQ\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <D:\Program Files\腾讯QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\Program Files\腾讯QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\Program Files\腾讯QQ\SendMMS.htm, N/A>
gototop
 

正在运行的进程
[PID: 1092][C:\WINNT\Explorer.EXE]  [Microsoft Corporation, 5.00.3700.6690]
    [C:\WINNT\system32\WZNINET.DLL]  [N/A, N/A]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll]  [Yahoo! China, 3, 1, 3, 1019]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 3, 1021]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yalive.dll]  [yahoo! china, 3, 2, 5, 1075]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 1, 1010]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
[PID: 1312][C:\WINNT\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.29]
[PID: 1332][C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe]  [Yahoo! China, 3, 1, 3, 1019]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll]  [Yahoo! China, 3, 1, 3, 1019]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 3, 1021]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yalive.dll]  [yahoo! china, 3, 2, 5, 1075]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 1, 1010]
    [C:\Program Files\Yahoo!\Assistant\yNotifier.dll]  [yahoo! china, 3, 0, 0, 1000]
[PID: 1340][C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe]  [Yahoo! China, 3, 0, 2, 1003]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 3, 1021]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll]  [Yahoo! China, 3, 1, 3, 1019]
    [C:\PROGRA~1\Yahoo!\Assistant\shell\yIEAngel.dll]  [Yahoo! China, 3, 0, 1, 1001]
    [C:\PROGRA~1\Yahoo!\Assistant\shell\yAsMenu.dll]  [Yahoo! China, 3, 0, 0, 1001]
    [C:\PROGRA~1\Yahoo!\Assistant\shell\yMenuInfo.dll]  [Yahoo! China, 3, 0, 0, 1000]
[PID: 1276][C:\WINNT\system32\internat.exe]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 3, 1021]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll]  [Yahoo! China, 3, 1, 3, 1019]
[PID: 936][C:\WINNT\system32\conime.exe]  [Microsoft Corporation, 5.00.2195.6655]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 3, 1021]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll]  [Yahoo! China, 3, 1, 3, 1019]
[PID: 284][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2800.1106]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 3, 1021]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll]  [Yahoo! China, 3, 0, 0, 1000]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll]  [Yahoo! China, 3, 1, 3, 1019]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yalive.dll]  [yahoo! china, 3, 2, 5, 1075]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 1, 1010]
    [C:\WINNT\system32\Macromed\Flash\Flash8.ocx]  [Macromedia, Inc., 8,0,22,0]
[PID: 1052][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, N/A]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 3, 1021]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll]  [Yahoo! China, 3, 1, 3, 1019]
[PID: 336][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.223\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 3, 1021]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll]  [Yahoo! China, 3, 1, 3, 1019]
[PID: 428][C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2800.1106]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 3, 1021]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll]  [Yahoo! China, 3, 0, 0, 1000]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll]  [Yahoo! China, 3, 1, 3, 1019]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yalive.dll]  [yahoo! china, 3, 2, 5, 1075]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 1, 1010]
[PID: 644][C:\WINNT\system32\rundll32.exe]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\guard.tmp]  [N/A, N/A]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 3, 1021]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll]  [Yahoo! China, 3, 1, 3, 1019]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINNT\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
gototop
 

运行SREng2,使用“启动项目”--注册表--选中以下的项删除
C:\WINNT\system32\j4p00e7meh.dll

显示隐藏文件
删除
C:\WINNT\system32\j4p00e7meh.dll
C:\WINNT\system32\guard.tmp
C:\WINNT\system32\WZNINET.DLL]
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT