瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 日期给修改为.2004.01.22 注册表不能进,瑞星不能使用了.

123   2  /  3  页   跳转

日期给修改为.2004.01.22 注册表不能进,瑞星不能使用了.

把时间调回来,把后缀改成.com试试
gototop
 

为什么有些人不可以学以致用呢。
gototop
 

先谢谢各位的帮助:扫描的结果如下.
[CODE]

2007-01-31,17:15:47

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>  [Microsoft Corporation]
    <internat.exe><internat.exe>  [(Verified)Microsoft Corporation]
    <6gu9hulfud4lsz><C:\WINNT\system.exe>  [N/A]
    <42bdd33vrm><C:\WINNT\winlog0n.exe>  [N/A]
    <yfbj4yymif7><C:\WINNT\iexpl0re.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <Synchronization Manager><mobsync.exe /logon>  [(Verified)Microsoft Corporation]
    <upxdn><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdn.exe>  [N/A]
    <NiceMt><C:\WINNT\Systemt.exe>  [N/A]
    <rxs3><C:\WINNT\rxs3.exe>  [N/A]
    <mhs2><C:\WINNT\mhs2.exe>  [N/A]
    <wls3><C:\WINNT\wls3.exe>  [N/A]
    <cmdbcs><C:\WINNT\cmdbcs.exe>  [N/A]
    <wsvbs><C:\WINNT\wsvbs.exe>  [N/A]
    <msccrt><C:\WINNT\msccrt.exe>  [N/A]
    <YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>  [(Verified)Yahoo! China]
    <uajene><C:\WINNT\system32\pxowon.exe>  [N/A]
    <pxowon><C:\WINNT\system32\severe.exe>  [N/A]
    <kav><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <avp6_post_uninstall><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe C:\WINNT\system32\drivers\conime.exe>  [N/A]
    <Userinit><C:\WINNT\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{4BAB150F-DD97-476D-9C1E-41B6CDC0CA7A}><C:\PROGRA~1\Yahoo!\Assistant\yClickOn.dll>  [(Verified)YAHOO Corporation Limited]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
    <WinlogonNotify: klogon><C:\WINNT\system32\klogon.dll>  [Kaspersky Lab]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><(无)>  [N/A]

==================================
启动文件夹
[Microsoft Office]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk --> C:\PROGRA~1\MICROS~2\Office\OSA9.EXE [Microsoft Corporation]><N>
[金山词霸 2002]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\金山词霸 2002.lnk --> C:\PROGRA~1\Kingsoft\XDict\XDICT.EXE [Kingsoft Co, Ltd.]><N>
[腾讯QQ]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><N>

==================================
gototop
 

先谢谢各位,这就扫描.
gototop
 

[CODE]

2007-01-31,17:15:47

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>  [Microsoft Corporation]
    <internat.exe><internat.exe>  [(Verified)Microsoft Corporation]
    <6gu9hulfud4lsz><C:\WINNT\system.exe>  [N/A]
    <42bdd33vrm><C:\WINNT\winlog0n.exe>  [N/A]
    <yfbj4yymif7><C:\WINNT\iexpl0re.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <Synchronization Manager><mobsync.exe /logon>  [(Verified)Microsoft Corporation]
    <upxdn><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdn.exe>  [N/A]
    <NiceMt><C:\WINNT\Systemt.exe>  [N/A]
    <rxs3><C:\WINNT\rxs3.exe>  [N/A]
    <mhs2><C:\WINNT\mhs2.exe>  [N/A]
    <wls3><C:\WINNT\wls3.exe>  [N/A]
    <cmdbcs><C:\WINNT\cmdbcs.exe>  [N/A]
    <wsvbs><C:\WINNT\wsvbs.exe>  [N/A]
    <msccrt><C:\WINNT\msccrt.exe>  [N/A]
    <YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>  [(Verified)Yahoo! China]
    <uajene><C:\WINNT\system32\pxowon.exe>  [N/A]
    <pxowon><C:\WINNT\system32\severe.exe>  [N/A]
    <kav><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <avp6_post_uninstall><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe C:\WINNT\system32\drivers\conime.exe>  [N/A]
    <Userinit><C:\WINNT\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{4BAB150F-DD97-476D-9C1E-41B6CDC0CA7A}><C:\PROGRA~1\Yahoo!\Assistant\yClickOn.dll>  [(Verified)YAHOO Corporation Limited]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
    <WinlogonNotify: klogon><C:\WINNT\system32\klogon.dll>  [Kaspersky Lab]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><(无)>  [N/A]

==================================
启动文件夹
[Microsoft Office]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk --> C:\PROGRA~1\MICROS~2\Office\OSA9.EXE [Microsoft Corporation]><N>
[金山词霸 2002]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\金山词霸 2002.lnk --> C:\PROGRA~1\Kingsoft\XDict\XDICT.EXE [Kingsoft Co, Ltd.]><N>
[腾讯QQ]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><N>

==================================
gototop
 

服务
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Win32 Display Driver / Win32DDS][Stopped/Auto Start]
  <C:\WINNT\system32\\rundll32.exe windds32.dll,input><Microsoft Corporation>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
  <C:\WINNT\system32\\rundll32.exe windhcp.ocx,input><Microsoft Corporation>
[Windows XP Vista        / Windows XP Vista        ][Stopped/Auto Start]
  <C:\WINNT\svchost.ini><N/A>
[WinXP DHCP Service / WinXPDHCPsvc][Stopped/Auto Start]
  <C:\WINNT\system32\\rundll32.exe xpdhcp.dll,input><Microsoft Corporation>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\system32\mspmsnsv.dll><Microsoft Corporation>
[卡巴斯基反病毒6.0 / AVP][Stopped/Auto Start]
  <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>

==================================
驱动程序
[Rising TDI Base Driver / BaseTDI][Stopped/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[HelloNet PPPoE 虚拟网卡 / BRPPPOE][Running/Manual Start]
  <system32\DRIVERS\brpppoe.sys><N/A>
[dmboot / dmboot][Stopped/Disabled]
  <System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[D-Link DFE-530TX PCI Fast Ethernet Adapter Driver Service / FETNDISB][Running/Manual Start]
  <System32\DRIVERS\dlkfet5b.sys><D-Link>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv4 / nv4][Running/Manual Start]
  <System32\DRIVERS\nv4.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[SVKP / SVKP][Running/Auto Start]
  <\??\C:\WINNT\system32\SVKP.sys><AntiCracking>
[syswav / syswav][Running/System Start]
  <\SystemRoot\system32\drivers\syswav.sys><Intel Corporation.>
[VIA AGP Bus Filter / viaagp][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
[VIA AGP Bus Filter  / viaagp1][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
[VIA USB Filter / viafilter][Stopped/Manual Start]
  <\SystemRoot\System32\Drivers\viausb.sys><VIA Technologies, Inc.>
[viaide / viaide][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\viaide.sys><VIA Technologies, Inc.>
[VIAPFD / VIAPFD][Running/System Start]
  <\SystemRoot\System32\Drivers\VIAPFD.SYS><VIA Technologies. Inc.>
[VIA AC'97 Audio Controller (WDM) / VIAudio][Running/Manual Start]
  <system32\drivers\viaudio.sys><VIA Technologies, Inc.>
[klif / klif][Stopped/System Start]
  <\??\C:\WINNT\system32\drivers\klif.sys><Kaspersky Lab>
[kl1 / kl1][Stopped/Boot Start]
  <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
gototop
 

==================================
浏览器加载项
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[IeCatch5 Class]
  {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <C:\PROGRA~1\FlashGet\jccatch.dll, FlashGet>
[Yahoo!Photo]
  {33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll, yahoo! china>
[DragSearch BHO]
  {62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, yahoo! china>
[]
  {A692062A-11A1-461B-BE99-B520F01F9DAE} <c:\baidu.ini, N/A>
[]
  {A692062A-11A1-461B-BEA0-B520F01F9DAE} <C:\WINNT\system32\3721.ini, N/A>
[BDHlprObj Class]
  {CA92B524-BC8A-4610-BD2C-6BD3E28155D0} <C:\WINNT\DOWNLO~1\BDHelper.dll, >
[xiuj]
  {CFEF1EAD-C8B4-4A94-A34C-E681C446F025} <C:\PROGRA~1\dras\hvew.dll, N/A>
[assist]
  {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} <C:\Program Files\Yahoo!\Assistant\Assist\yassist.dll, Yahoo! China>
[Web反病毒保护]
  {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
[雅虎助手]
  {5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/start.htm?source=yzs_icon&btn=yassistnew, N/A>
[CibaCtrl Class]
  {8DE0FCD4-5EB5-11D3-AD25-00002100131B} <C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
[JoyoCtrl Class]
  {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} <C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[FlashGet]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FlashGet\flashget.exe, FlashGet.com>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\PROGRA~1\FlashGet\fgiebar.dll, Amaze Soft>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
[雅虎助手]
  {406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll, yahoo! china>
[CKAVWebScan Object]
  {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} <C:\WINNT\system32\Kaspersky Lab\Kaspersky Online Scanner Pro\kavwebscan.dll, Kaspersky Lab>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[添加到雅虎订阅(&Y)]
  <res://C:\Program Files\Yahoo!\Assistant\Assist\yrss.dll/YRSSMENUEXT, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
[雅虎搜索]
  <res://C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll/203, N/A>
gototop
 

正在运行的进程
[PID: 144][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.00.2195.6601]
[PID: 168][\??\C:\WINNT\system32\csrss.exe]  [Microsoft Corporation, 5.00.2195.6601]
[PID: 188][\??\C:\WINNT\system32\winlogon.exe]  [Microsoft Corporation, 5.00.2195.6714]
[PID: 216][C:\WINNT\system32\services.exe]  [Microsoft Corporation, 5.00.2195.6700]
    [C:\WINNT\system32\dmserver.dll]  [VERITAS Software Corp., 2195.6605.297.3]
[PID: 228][C:\WINNT\system32\lsass.exe]  [Microsoft Corporation, 5.00.2195.6695]
[PID: 424][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
[PID: 452][C:\WINNT\system32\spoolsv.exe]  [Microsoft Corporation, 5.00.2195.6659]
[PID: 492][C:\WINNT\System32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
[PID: 544][C:\WINNT\system32\regsvc.exe]  [Microsoft Corporation, 5.00.2195.6701]
[PID: 564][C:\WINNT\system32\MSTask.exe]  [Microsoft Corporation, 4.71.2195.6704]
[PID: 768][C:\WINNT\Explorer.exe]  [Microsoft Corporation, 5.00.3700.6690]
    [C:\PROGRA~1\Yahoo!\Assistant\yClickOn.dll]  [YAHOO Corporation Limited, 3, 0, 3, 1004]
    [C:\WINNT\system32\cmdbcs.dll]  [N/A, N/A]
    [C:\WINNT\system32\wsvbs.dll]  [N/A, N/A]
    [C:\WINNT\system32\msccrt.dll]  [N/A, N/A]
    [C:\WINNT\system32\pxowon.dll]  [N/A, N/A]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\WINNT\system32\LgSym.dll]  [N/A, N/A]
    [C:\WINNT\system32\LgSyl.dll]  [N/A, N/A]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, N/A]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll]  [yahoo! china, 3, 6, 0, 1112]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 2, 1011]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.5.2005092300]
    [C:\WINNT\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\PROGRA~1\FlashGet\jccatch.dll]  [FlashGet, 1, 1, 5, 0]
    [C:\WINNT\DOWNLO~1\BDHelper.dll]  [, 1, 0, 0, 6]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll]  [Yahoo! China, 3, 0, 6, 1008]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL]  [yahoo! china, 3, 0, 3, 1003]
    [C:\WINNT\system32\3721.ini]  [N/A, N/A]
    [C:\Program Files\Yahoo!\Assistant\Assist\yassist.dll]  [Yahoo! China, 3, 1, 4, 1019]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ywiper.dll]  [Yahoo! China, 3, 0, 4, 1008]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\shellex.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 812][C:\WINNT\system32\drivers\conime.exe]  [N/A, N/A]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\WINNT\system32\pxowon.dll]  [N/A, N/A]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, N/A]
[PID: 912][C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\WINNT\system32\pxowon.dll]  [N/A, N/A]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll]  [yahoo! china, 3, 6, 0, 1112]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 2, 1011]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, N/A]
    [C:\Program Files\Yahoo!\Assistant\yNotifier.dll]  [yahoo! china, 3, 0, 2, 1002]
[PID: 920][C:\WINNT\system32\pxowon.exe]  [N/A, N/A]
    [C:\WINNT\system32\pxowon.dll]  [N/A, N/A]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, N/A]
[PID: 928][C:\WINNT\system32\severe.exe]  [N/A, N/A]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\WINNT\system32\pxowon.dll]  [N/A, N/A]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, N/A]
[PID: 996][C:\Program Files\MSN Messenger\MsnMsgr.Exe]  [Microsoft Corporation, 7.0.0816]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\WINNT\system32\pxowon.dll]  [N/A, N/A]
    [C:\Program Files\MSN Messenger\MSGSLANG.DLL]  [Microsoft Corporation, 7.0.0816]
    [C:\Program Files\MSN Messenger\custsat.dll]  [Microsoft Corporation, 8.50.0015.0500]
    [C:\WINNT\System32\devenum.dll]  [N/A, N/A]
    [C:\Program Files\MSN Messenger\RICHED20.dll]  [Jiangmin Co Ltd, 10, 0, 0, 831]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, N/A]
    [C:\WINNT\system32\LgSym.dll]  [N/A, N/A]
    [C:\WINNT\system32\LgSyl.dll]  [N/A, N/A]
[PID: 1012][C:\WINNT\system32\internat.exe]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\WINNT\system32\pxowon.dll]  [N/A, N/A]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, N/A]
[PID: 732][C:\WINNT\winlog0n.exe]  [N/A, N/A]
    [C:\WINNT\system32\LgSyl.dll]  [N/A, N/A]
[PID: 1024][C:\WINNT\iexpl0re.exe]  [N/A, N/A]
    [C:\WINNT\system32\LgSym.dll]  [N/A, N/A]
[PID: 1044][C:\WINNT\system32\conime.exe]  [Microsoft Corporation, 5.00.2195.6655]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\WINNT\system32\pxowon.dll]  [N/A, N/A]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, N/A]
gototop
 

[PID: 1060][C:\Program Files\Kingsoft\XDict\XDICT.EXE]  [Kingsoft Co, Ltd., 5, 5, 0, 0]
    [C:\Program Files\Kingsoft\XDict\IHooks.dll]  [N/A, N/A]
    [C:\Program Files\Kingsoft\XDict\ITextOut.dll]  [N/A, N/A]
    [C:\Program Files\Kingsoft\XDict\CJKTAB32.dll]  [N/A, N/A]
    [C:\Program Files\Kingsoft\XDict\XImage32.dll]  [N/A, N/A]
    [C:\Program Files\Kingsoft\XDict\NewWord.dll]  [N/A, N/A]
    [C:\Program Files\Kingsoft\XDict\xfile.dll]  [N/A, N/A]
    [C:\Program Files\Kingsoft\XDict\ITTSEngine.dll]  [N/A, N/A]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\WINNT\system32\pxowon.dll]  [N/A, N/A]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, N/A]
    [C:\WINNT\system32\LgSym.dll]  [N/A, N/A]
    [C:\WINNT\system32\LgSyl.dll]  [N/A, N/A]
[PID: 884][C:\WINNT\System32\WBEM\WinMgmt.exe]  [Microsoft Corporation, 1.50.1085.0100]
[PID: 832][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\msxml3.dll]  [Microsoft Corporation, 8.30.9926.0]
[PID: 1360][C:\WINNT\system32\wuauclt.exe]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, N/A]
    [C:\WINNT\system32\pxowon.dll]  [N/A, N/A]
    [C:\WINNT\system32\LgSym.dll]  [N/A, N/A]
    [C:\WINNT\system32\LgSyl.dll]  [N/A, N/A]
[PID: 1420][C:\Program Files\HelloNet\HNMainUI.exe]  [N/A, 2, 3, 0, 1]
    [C:\Program Files\HelloNet\HNKernel.dll]  [HelloNet, 2.2.0.1]
    [C:\Program Files\HelloNet\HNUtils.dll]  [N/A, 2, 2, 0, 1]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, N/A]
    [C:\WINNT\system32\pxowon.dll]  [N/A, N/A]
    [C:\Program Files\HelloNet\HNRes_0804.dll]  [N/A, 2, 2, 0, 1]
    [C:\Program Files\HelloNet\plugins\Diagnose.dll]  [HelloNet, 2.2.0.1]
    [C:\WINNT\system32\LgSym.dll]  [N/A, N/A]
    [C:\WINNT\system32\LgSyl.dll]  [N/A, N/A]
[PID: 1276][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2800.1106]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll]  [Yahoo! China, 3, 0, 3, 1004]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, N/A]
    [C:\WINNT\system32\pxowon.dll]  [N/A, N/A]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll]  [yahoo! china, 3, 6, 0, 1112]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 2, 1011]
    [C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll]  [yahoo! china, 3, 3, 2, 1093]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ysearch.dll]  [Yahoo! China, 3, 1, 6, 1016]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasnoad.dll]  [yahoo! china, 3, 0, 3, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yzsNetProto.dll]  [Yahoo! China, 3, 0, 2, 1003]
    [C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll]  [Yahoo! China, 3, 0, 6, 1008]
    [C:\Program Files\Yahoo!\Assistant\Assist\yrss.dll]  [Yahoo! China, 3, 0, 3, 1004]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yaswiper.dll]  [Yahoo! China, 3, 0, 5, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasiesec.dll]  [Yahoo! China, 3, 0, 5, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YSETTI~1.DLL]  [yahoo! china, 3, 1, 1, 1022]
    [C:\Program Files\Yahoo!\Assistant\Assist\ymailp.dll]  [Yahoo! China, 3, 0, 4, 1010]
    [C:\Program Files\Yahoo!\Assistant\Assist\ymyweb.dll]  [Yahoo! China, 3, 0, 2, 1004]
    [C:\PROGRA~1\Yahoo!\Assistant\yClickOn.dll]  [YAHOO Corporation Limited, 3, 0, 3, 1004]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.5.2005092300]
    [C:\WINNT\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\PROGRA~1\FlashGet\jccatch.dll]  [FlashGet, 1, 1, 5, 0]
    [C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll]  [yahoo! china, 3, 0, 5, 1007]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL]  [yahoo! china, 3, 0, 3, 1003]
    [C:\WINNT\system32\3721.ini]  [N/A, N/A]
    [C:\WINNT\DOWNLO~1\BDHelper.dll]  [, 1, 0, 0, 6]
    [C:\Program Files\Yahoo!\Assistant\Assist\yassist.dll]  [Yahoo! China, 3, 1, 4, 1019]
    [C:\WINNT\system32\LgSym.dll]  [N/A, N/A]
    [C:\WINNT\system32\LgSyl.dll]  [N/A, N/A]
    [C:\WINNT\system32\msxml3.dll]  [Microsoft Corporation, 8.30.9926.0]
    [C:\WINNT\DOWNLO~1\BDSrHook.dll]  [, 1, 0, 0, 4]
    [C:\WINNT\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\WINNT\system32\UNISPIM.IME]  [北京清华紫光软件股份有限公司, 3.0.0.0 alpha 21225]
    [C:\WINNT\system32\KIme.ime]  [金山软件公司, 1, 0, 0, 1]
    [C:\WINNT\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [c:\progra~1\yahoo!\assist~1\assist\yadfil~1.dll]  [Yahoo! China, 3, 0, 2, 1003]
    [C:\PROGRA~1\yahoo!\assistant\Shell\yAssecblk.dll]  [Yahoo! China, 3, 1, 6, 1022]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yoptimum.dll]  [Yahoo! China, 3, 0, 2, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrepair.dll]  [Yahoo! China, 3, 0, 9, 1012]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasfsks.dll]  [Yahoo! China, 2, 1, 3, 89]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yxpstyle.dll]  [Yahoo! China, 3, 0, 1, 1001]
[PID: 116][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, N/A]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, N/A]
    [C:\WINNT\system32\pxowon.dll]  [N/A, N/A]
    [C:\WINNT\system32\LgSym.dll]  [N/A, N/A]
    [C:\WINNT\system32\LgSyl.dll]  [N/A, N/A]
    [C:\PROGRA~1\Yahoo!\Assistant\yClickOn.dll]  [YAHOO Corporation Limited, 3, 0, 3, 1004]
[PID: 648][C:\WINNT\System32\MsiExec.exe]  [Microsoft Corporation, 3.1.4000.1823]
    [C:\WINNT\system32\SDBAPIU.DLL]  [Microsoft Corporation, 1, 0, 0, 1]
[PID: 200][C:\WINNT\system32\rundll32.exe]  [Microsoft Corporation, 5.00.2134.1]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, N/A]
    [C:\WINNT\system32\pxowon.dll]  [N/A, N/A]
    [C:\WINNT\system32\LgSym.dll]  [N/A, N/A]
    [C:\WINNT\system32\LgSyl.dll]  [N/A, N/A]
[PID: 980][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2800.1106]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll]  [Yahoo! China, 3, 0, 3, 1004]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, N/A]
    [C:\WINNT\system32\pxowon.dll]  [N/A, N/A]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll]  [yahoo! china, 3, 6, 0, 1112]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 2, 1011]
    [C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll]  [yahoo! china, 3, 3, 2, 1093]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ysearch.dll]  [Yahoo! China, 3, 1, 6, 1016]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasnoad.dll]  [yahoo! china, 3, 0, 3, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yzsNetProto.dll]  [Yahoo! China, 3, 0, 2, 1003]
    [C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll]  [Yahoo! China, 3, 0, 6, 1008]
    [C:\Program Files\Yahoo!\Assistant\Assist\yrss.dll]  [Yahoo! China, 3, 0, 3, 1004]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yaswiper.dll]  [Yahoo! China, 3, 0, 5, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasiesec.dll]  [Yahoo! China, 3, 0, 5, 1005]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YSETTI~1.DLL]  [yahoo! china, 3, 1, 1, 1022]
    [C:\Program Files\Yahoo!\Assistant\Assist\ymailp.dll]  [Yahoo! China, 3, 0, 4, 1010]
    [C:\Program Files\Yahoo!\Assistant\Assist\ymyweb.dll]  [Yahoo! China, 3, 0, 2, 1004]
    [C:\PROGRA~1\Yahoo!\Assistant\yClickOn.dll]  [YAHOO Corporation Limited, 3, 0, 3, 1004]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.5.2005092300]
    [C:\WINNT\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\PROGRA~1\FlashGet\jccatch.dll]  [FlashGet, 1, 1, 5, 0]
    [C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll]  [yahoo! china, 3, 0, 5, 1007]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL]  [yahoo! china, 3, 0, 3, 1003]
    [C:\WINNT\system32\3721.ini]  [N/A, N/A]
    [C:\WINNT\DOWNLO~1\BDHelper.dll]  [, 1, 0, 0, 6]
    [C:\Program Files\Yahoo!\Assistant\Assist\yassist.dll]  [Yahoo! China, 3, 1, 4, 1019]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\WINNT\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\Documents and Settings\Administrator\桌面\sreng2\SREng.com]  [Smallfrogs Studio, 2.3.13.690]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 0, 5, 1023]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ykern.dll]  [Yahoo! China, 3, 1, 9, 1025]
    [C:\Program Files\Kingsoft\XDict\Cjktl32.dll]  [N/A, N/A]
    [C:\WINNT\system32\pxowon.dll]  [N/A, N/A]
    [C:\WINNT\system32\LgSym.dll]  [N/A, N/A]
    [C:\WINNT\system32\LgSyl.dll]  [N/A, N/A]
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINNT\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
[D:\]
[AutoRun]
open=OSO.exe
shellexecute=OSO.exe
shell\Auto\command=OSO.exe
[E:\]
[AutoRun]
open=OSO.exe
shellexecute=OSO.exe
shell\Auto\command=OSO.exe

==================================
HOSTS 文件
127.0.0.1      localhost
127.0.0.1      mmsk.cn
127.0.0.1      ikaka.com
127.0.0.1      safe.qq.com
127.0.0.1      360safe.com
127.0.0.1      www.mmsk.cn
127.0.0.1      www.ikaka.com
127.0.0.1      tool.ikaka.com
127.0.0.1      www.360safe.com
127.0.0.1      zs.kingsoft.com
127.0.0.1      forum.ikaka.com
127.0.0.1      up.rising.com.cn
127.0.0.1      scan.kingsoft.com
127.0.0.1      kvup.jiangmin.com
127.0.0.1      reg.rising.com.cn
127.0.0.1      update.rising.com.cn
127.0.0.1      update7.jiangmin.com
127.0.0.1      download.rising.com.cn
127.0.0.1      dnl-us1.kaspersky-labs.com
127.0.0.1      dnl-us2.kaspersky-labs.com
127.0.0.1      dnl-us3.kaspersky-labs.com
127.0.0.1      dnl-us4.kaspersky-labs.com
127.0.0.1      dnl-us5.kaspersky-labs.com
127.0.0.1      dnl-us6.kaspersky-labs.com
127.0.0.1      dnl-us7.kaspersky-labs.com
127.0.0.1      dnl-us8.kaspersky-labs.com
127.0.0.1      dnl-us9.kaspersky-labs.com
127.0.0.1      dnl-us10.kaspersky-labs.com
127.0.0.1      dnl-eu1.kaspersky-labs.com
127.0.0.1      dnl-eu2.kaspersky-labs.com
127.0.0.1      dnl-eu3.kaspersky-labs.com
127.0.0.1      dnl-eu4.kaspersky-labs.com
127.0.0.1      dnl-eu5.kaspersky-labs.com
127.0.0.1      dnl-eu6.kaspersky-labs.com
127.0.0.1      dnl-eu7.kaspersky-labs.com
127.0.0.1      dnl-eu8.kaspersky-labs.com
127.0.0.1      dnl-eu9.kaspersky-labs.com
127.0.0.1      dnl-eu10.kaspersky-labs.com

==================================
API HOOK
N/A

==================================


[/CODE]
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT