瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 电脑中毒了,DX帮检查一下原因5555555

1   1  /  1  页   跳转

电脑中毒了,DX帮检查一下原因5555555

电脑中毒了,DX帮检查一下原因5555555

症状是开机提示虚拟内存不足,防火墙成灰色

我扫描了开机启动和运行进程 ,DX帮看看有什么可疑得
最后编辑2007-05-17 11:03:20.857000000
分享到:
gototop
 

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\windows\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
    <H/PC Connection Agent><"C:\Program Files\Microsoft ActiveSync\wcescomm.exe">  [Microsoft Corporation]
    <KpopMon><C:\KAV6\KPopMon.EXE>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <C-Media Mixer><Mixer.exe /startup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher, E=""]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <NeroFilterCheck><C:\WINDOWS\system32\NeroCheck.exe>  [Ahead Software Gmbh]
    <KAVRun><C:\KAV6\KAVRun.EXE>  [kingsoft]
    <Kulansyn><C:\KAV6\Kulansyn.EXE>  [Kingsoft Corp.]
    <RunShadowTip><C:\windows\system32\Shadow\ShadowTip.exe>  [PowerShadow]
    <WheelMouse><C:\Program Files\Win2\Mouse\Amoumain.exe>  [A4Tech Co., Ltd.]
    <NvCplDaemon><RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <nwiz><nwiz.exe /install>  [NVIDIA Corporation]
    <NvMediaCenter><RUNDLL32.EXE C:\windows\system32\NvMcTray.dll,NvTaskbarInit>  [(Verified)Microsoft Windows Publisher]
    <ISUSPM Startup><C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup>  [InstallShield Software Corporation]
    <ISUSScheduler><"C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start>  [InstallShield Software Corporation]
    <TaxKeyManager><C:\Program Files\95599 Certificate Tools\SHANGHAI TAX\TaxKeyManager.exe>  []
    <HDCSP RegCertTool><C:\Program Files\95599 Certificate Tools\CIDC\RegCertTool.exe>  [CIDC]
    <dla><; C:\windows\system32\dla\tfswctrl.exe>  [Sonic Solutions]
    <RegNetPass><; C:\windows\system32\regcsp.exe>  []
    <StormCodec_Helper><; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  []
    <WangWang><; "C:\Program Files\淘宝网\淘宝旺旺\WangWang.EXE">  [淘宝(中国)软件有限公司]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <visin><C:\windows\system32\ctfnom.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
gototop
 

正在运行的进程
[PID: 452][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 516][\??\C:\windows\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 540][\??\C:\windows\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\windows\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1296][C:\windows\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\windows\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\windows\system32\Amhooker.dll]  [A4Tech Co., Ltd., 7.72.1.0]
    [C:\KAV6\KMailFun.dll]  [Kingsoft Co., Ltd, 2005, 4, 28, 227]
    [C:\windows\system32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.7184]
    [C:\windows\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.7184]
    [C:\windows\system32\nvshell.dll]  [NVIDIA Corporation, 6.14.10.10035]
    [C:\windows\system32\dla\tfswshx.dll]  [Sonic Solutions, 1.04.07b]
    [C:\windows\system32\tfswapi.dll]  [Sonic Solutions, 1.04.07b]
    [C:\windows\system32\dla\tfswcres.dll]  [Sonic Solutions, 1.04.07b]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\KAV6\KAVEXT.DLL]  [Kingsoft Corp., 2002, 5, 24, 6]
    [C:\Program Files\Sonic\MyDVD Studio Deluxe\RecordNow!\shlext.dll]  [, 7.0.0.0]
    [C:\Program Files\Sonic\MyDVD Studio Deluxe\RecordNow!\MSVCR70.dll]  [Microsoft Corporation, 7.00.9466.0]
    [C:\PROGRA~1\GlobalSCAPE\CuteFTP\CuteShell.dll]  [, 1, 0, 0, 1]
[PID: 188][C:\windows\Mixer.exe]  [C-Media Electronic Inc. (www.cmedia.com.tw), 1.44]
    [C:\windows\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\cmnprop.dll]  [C-Media Corporation, 5.00.2195.8]
[PID: 356][C:\windows\system32\Shadow\ShadowTip.exe]  [PowerShadow, 1, 0, 0, 1]
    [C:\windows\system32\Shadow\pDeskTop.dll]  [N/A, ]
    [C:\windows\system32\Amhooker.dll]  [A4Tech Co., Ltd., 7.72.1.0]
    [C:\KAV6\KMailFun.dll]  [Kingsoft Co., Ltd, 2005, 4, 28, 227]
[PID: 368][C:\Program Files\Win2\Mouse\Amoumain.exe]  [A4Tech Co., Ltd., 7.72.1.0]
    [C:\windows\system32\Amhooker.dll]  [A4Tech Co., Ltd., 7.72.1.0]
    [C:\windows\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Win2\Mouse\Amoures.dll]  [A4Tech Co.,Ltd., 7.72.1.0]
[PID: 376][C:\KAV6\KWatchUI.EXE]  [, 2004.1.6.119]
    [C:\KAV6\kavcomm.dll]  [Kingsoft Corporation, 2003, 11, 12, 66]
    [C:\KAV6\kavdlg.dll]  [, 2004.7.20.81]
    [C:\KAV6\KAVMLM.DLL]  [Kingsoft Corporation, 2003.11.12.10]
    [C:\KAV6\RpcBrge.DLL]  [kingsoft, 2003, 11, 12, 64]
    [C:\windows\system32\Amhooker.dll]  [A4Tech Co., Ltd., 7.72.1.0]
    [C:\KAV6\KMailFun.dll]  [Kingsoft Co., Ltd, 2005, 4, 28, 227]
[PID: 504][C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe]  [InstallShield Software Corporation, 3, 10, 100, 1155]
[PID: 120][C:\Program Files\95599 Certificate Tools\SHANGHAI TAX\TaxKeyManager.exe]  [, 2, 2, 0, 0]
    [C:\KAV6\KMailFun.dll]  [Kingsoft Co., Ltd, 2005, 4, 28, 227]
[PID: 700][C:\Program Files\95599 Certificate Tools\CIDC\RegCertTool.exe]  [CIDC, 1, 0, 0, 10]
    [C:\KAV6\KMailFun.dll]  [Kingsoft Co., Ltd, 2005, 4, 28, 227]
[PID: 856][C:\windows\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 944][C:\Program Files\Microsoft ActiveSync\wcescomm.exe]  [Microsoft Corporation, 4.1.4841.0]
    [C:\windows\system32\CEUTIL.dll]  [Microsoft Corporation, 4.1.4841.0]
    [C:\windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\windows\system32\RAPI.dll]  [Microsoft Corporation, 4.1.4841.0]
    [C:\Program Files\Microsoft ActiveSync\TCP2UDP.dll]  [Microsoft Corporation, 4.1.4841.0]
    [C:\Program Files\Microsoft ActiveSync\rapiproxystub.dll]  [N/A, ]
    [C:\Program Files\Microsoft ActiveSync\dtptdns.dll]  [Microsoft Corporation, 4.1.4841.0]
[PID: 988][C:\KAV6\KPopMon.EXE]  [, 2004, 2, 2, 31]
    [C:\KAV6\KAVMLM.DLL]  [Kingsoft Corporation, 2003.11.12.10]
[PID: 1096][C:\PROGRA~1\MICROS~3\rapimgr.exe]  [Microsoft Corporation, 4.1.4841.0]
    [C:\windows\system32\CEUTIL.dll]  [Microsoft Corporation, 4.1.4841.0]
    [C:\windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\PROGRA~1\MICROS~3\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Microsoft ActiveSync\rapiproxystub.dll]  [N/A, ]
[PID: 1172][C:\windows\system32\wscntfy.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\KAV6\KMailFun.dll]  [Kingsoft Co., Ltd, 2005, 4, 28, 227]
[PID: 2280][C:\KAV6\MailMon.EXE]  [Kingsoft Co., Ltd, 2004, 2, 6, 245]
    [C:\KAV6\KMFilter.DLL]  [, 2004, 3, 1, 37]
    [C:\KAV6\parse822.dll]  [Quiksoft Corporation, 2, 0, 0, 9]
    [C:\KAV6\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\KAV6\KAVLogFn.dll]  [, 2003, 11, 26, 16]
    [C:\KAV6\KAVMLM.DLL]  [Kingsoft Corporation, 2003.11.12.10]
    [C:\KAV6\KAMsgBox.DLL]  [, 2002.9.27.30]
    [C:\KAV6\KAVComm.dll]  [Kingsoft Corporation, 2003, 11, 12, 66]
    [C:\KAV6\RpcBrge.DLL]  [kingsoft, 2003, 11, 12, 64]
    [C:\KAV6\KAVIPC.DLL]  [Kingsoft Corp., 2002, 3, 29, 8]
    [C:\KAV6\KAVDlg.DLL]  [, 2004.7.20.81]
    [C:\KAV6\KAECall.DLL]  [Kingsoft Corporation, 2003, 11, 14, 66]
    [C:\KAV6\KAEScan.DLL]  [Kingsoft Corp., 2003, 5, 24, 36]
    [C:\KAV6\KAEPlat.DLL]  [Kingsoft Corp., 2005, 12, 29, 56]
    [C:\KAV6\KAEMem.DAT]  [Kingsoft, 2006, 4, 12, 13]
    [C:\KAV6\KAEUnpack.DAT]  [Kingsoft Corp., 2006, 6, 15, 44]
    [C:\KAV6\KMailFun.dll]  [Kingsoft Co., Ltd, 2005, 4, 28, 227]
[PID: 2536][C:\KAV6\KAVPlus.EXE]  [, 2004, 3, 3, 71]
    [C:\KAV6\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\KAV6\KMailFun.dll]  [Kingsoft Co., Ltd, 2005, 4, 28, 227]
gototop
 

[PID: 1040][D:\QQ2006\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [D:\QQ2006\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [D:\QQ2006\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [D:\QQ2006\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 370]
    [D:\QQ2006\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\KAV6\KMailFun.dll]  [Kingsoft Co., Ltd, 2005, 4, 28, 227]
    [D:\QQ2006\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [D:\QQ2006\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [D:\QQ2006\QQAPI.dll]  [, 1, 0, 0, 1]
    [D:\QQ2006\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [D:\QQ2006\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [D:\QQ2006\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [D:\QQ2006\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [C:\windows\system32\Amhooker.dll]  [A4Tech Co., Ltd., 7.72.1.0]
    [D:\QQ2006\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [D:\QQ2006\WizardCtrl.dll]  [, 1, 0, 0, 1]
    [D:\QQ2006\QQMainFrame.dll]  [N/A, ]
    [C:\windows\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\windows\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\QQ2006\CQQApplication.dll]  [N/A, ]
    [D:\QQ2006\NewSkin.dll]  [, 1, 0, 0, 1]
    [D:\QQ2006\HostingMgr.dll]  [, 1, 0, 0, 1]
    [D:\QQ2006\CameraDll.dll]  [, 1, 0, 0, 1]
    [D:\QQ2006\MailSummary.dll]  [, 1, 0, 0, 1]
    [D:\QQ2006\QQSpace.dll]  [, 1, 0, 0, 1]
    [D:\QQ2006\vbscript.dll]  [Microsoft Corporation, 5.6.0.7426]
    [C:\windows\system32\msdmo.dll]  [, ]
    [D:\QQ2006\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [D:\QQ2006\GroupLive.dll]  [N/A, ]
    [D:\QQ2006\QQSysMsgMng.dll]  [N/A, ]
    [D:\QQ2006\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [D:\QQ2006\QQPlugin.dll]  [N/A, ]
    [D:\QQ2006\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [D:\QQ2006\QRingMng.dll]  [N/A, ]
    [D:\QQ2006\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [D:\QQ2006\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [D:\QQ2006\VPortal.dll]  [, 1, 0, 0, 4]
    [D:\QQ2006\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [D:\QQ2006\QQPet.dll]  [, 1, 0, 0, 1]
    [D:\QQ2006\QQAvatar.dll]  [N/A, ]
    [D:\QQ2006\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [D:\QQ2006\BQQApplication.dll]  [N/A, ]
    [D:\QQ2006\CommercesMng.dll]  [, 1, 0, 0, 1]
    [D:\QQ2006\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [D:\QQ2006\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 240]
    [D:\QQ2006\QQSceneMng.dll]  [N/A, ]
    [D:\QQ2006\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 8, 81]
    [D:\QQ2006\QQAllInOne.dll]  [N/A, ]
    [D:\QQ2006\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
    [D:\QQ2006\QQCustomFace.dll]  [N/A, ]
    [D:\QQ2006\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1088][D:\QQ2006\TIMPlatfrom.exe]  [tencent, 0, 3, 1, 8]
    [C:\KAV6\KMailFun.dll]  [Kingsoft Co., Ltd, 2005, 4, 28, 227]
    [D:\QQ2006\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 1964][C:\Program Files\TTPlayer\TTPlayer.exe]  [Alen Soft, 4, 6, 9, 0]
    [C:\Program Files\TTPlayer\ttpcomm.dll]  [N/A, ]
    [C:\KAV6\KMailFun.dll]  [Kingsoft Co., Ltd, 2005, 4, 28, 227]
    [C:\Program Files\TTPlayer\ttpres.dll]  [Alen Soft, 4, 6, 9, 0]
    [C:\Program Files\TTPlayer\msdmo.dll]  [Microsoft Corporation, 6.03.01.0400]
    [C:\windows\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\windows\system32\Amhooker.dll]  [A4Tech Co., Ltd., 7.72.1.0]
    [C:\KAV6\KAVEXT.DLL]  [Kingsoft Corp., 2002, 5, 24, 6]
    [C:\Program Files\TTPlayer\AddIn\ttp_asf.dll]  [N/A, ]
[PID: 224][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\KAV6\KMailFun.dll]  [Kingsoft Co., Ltd, 2005, 4, 28, 227]
    [C:\Program Files\BitComet\tools\BitCometBHO.dll]  [N/A, ]
    [C:\windows\system32\dla\tfswshx.dll]  [Sonic Solutions, 1.04.07b]
    [C:\windows\system32\tfswapi.dll]  [Sonic Solutions, 1.04.07b]
    [C:\windows\system32\dla\tfswcres.dll]  [Sonic Solutions, 1.04.07b]
    [C:\KAV6\KAVEXT.DLL]  [Kingsoft Corp., 2002, 5, 24, 6]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\windows\system32\Amhooker.dll]  [A4Tech Co., Ltd., 7.72.1.0]
    [C:\windows\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 3128][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\KAV6\KMailFun.dll]  [Kingsoft Co., Ltd, 2005, 4, 28, 227]
    [C:\Program Files\BitComet\tools\BitCometBHO.dll]  [N/A, ]
    [C:\windows\system32\dla\tfswshx.dll]  [Sonic Solutions, 1.04.07b]
    [C:\windows\system32\tfswapi.dll]  [Sonic Solutions, 1.04.07b]
    [C:\windows\system32\dla\tfswcres.dll]  [Sonic Solutions, 1.04.07b]
    [C:\KAV6\KAVEXT.DLL]  [Kingsoft Corp., 2002, 5, 24, 6]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\windows\system32\Amhooker.dll]  [A4Tech Co., Ltd., 7.72.1.0]
    [C:\windows\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\windows\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
[PID: 176][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\KAV6\KMailFun.dll]  [Kingsoft Co., Ltd, 2005, 4, 28, 227]
    [C:\Program Files\BitComet\tools\BitCometBHO.dll]  [N/A, ]
    [C:\windows\system32\dla\tfswshx.dll]  [Sonic Solutions, 1.04.07b]
    [C:\windows\system32\tfswapi.dll]  [Sonic Solutions, 1.04.07b]
    [C:\windows\system32\dla\tfswcres.dll]  [Sonic Solutions, 1.04.07b]
    [C:\KAV6\KAVEXT.DLL]  [Kingsoft Corp., 2002, 5, 24, 6]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\windows\system32\Amhooker.dll]  [A4Tech Co., Ltd., 7.72.1.0]
    [C:\windows\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\windows\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSXML5.DLL]  [Microsoft Corporation, 5.00.2916.0]
[PID: 2948][C:\Documents and Settings\V\桌面\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\KAV6\KMailFun.dll]  [Kingsoft Co., Ltd, 2005, 4, 28, 227]
    [C:\windows\system32\Amhooker.dll]  [A4Tech Co., Ltd., 7.72.1.0]
    [C:\windows\system32\NpOpenStore.dll]  [N/A, ]
    [C:\windows\system32\NPCard.dll]  [N/A, ]
    [C:\windows\system32\RsaFun.dll]  [N/A, ]
    [C:\windows\system32\GPKPCSC.dll]  [N/A, ]
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  Error. ["C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe" "%1"]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
入口点错误:LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: C:\KAV6\KMailFun.dll)

==================================
隐藏进程
N/A

==================================
gototop
 

UPPPPPPPPPPPPPPPPPPPPP
gototop
 

垃圾社区
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT