电脑中毒,求助高手帮忙?

电脑中毒,求助高手帮忙?
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <WinFaxAppPortStarter><wfxsnt40.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><EXPLORER.EXE>  [(Verified)Microsoft Windows XP Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,c:\WINDOWS\811.exe>  [N/A]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
    <{A213B520-C6C2-11d0-AF9D-008029E1027E}><C:\Program Files\Symantec\WinFax\WfxSeh32.Dll>  [Symantec Corporation]
    <{A6011F8F-A7F8-49AA-9ADA-49127D43138F}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.bmt>  []
    <{1496D5ED-7A09-46D0-8C92-B8E71A4304DF}><C:\WINDOWS\System32\scandisk.dll>  []
    <{754FB7D8-B8FE-4810-B363-A788CD060F1F}><C:\Program Files\Internet Explorer\PLUGINS\System64.Sys>  []
    <{99F1D023-7CEB-4586-80F7-BB1A98DB7602}><C:\Program Files\Internet Explorer\IEXPLORE.Sys>  []
    <{FEB94F5A-69F3-4645-8C2B-9E71D270AF2E}><C:\Program Files\Internet Explorer\IEXPLORE.Dat>  []
    <{923509F1-45CB-4EC0-BDE0-1DED35B8FD60}><C:\Program Files\Internet Explorer\IEXPLORE.win>  []

启动文件夹
[Controller]
  <C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Controller.LNK --> C:\PROGRA~1\Symantec\WinFax\WFXCTL32.EXE [N/A]><N>

==================================
服务
[40DCD340 / 40DCD340][Stopped/Auto Start]
  <C:\WINDOWS\System32\977F0550.EXE -p><Microsoft Corporation>
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Ati HotKey Poller / Ati HotKey Poller][Stopped/Disabled]
  <C:\WINDOWS\System32\Ati2evxx.exe><>
[Gray_Pigeon_Server2.0 / GrayPigeonServer2.0][Stopped/Disabled]
  <C:\WINDOWS\G_Server2.0.exe><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[IBM PM Service / IBMPMSVC][Stopped/Disabled]
  <C:\WINDOWS\System32\ibmpmsvc.exe><N/A>
[kernl32 / kernl32][Stopped/Auto Start]
  <C:\WINDOWS\System32\kernl32.exe><N/A>
[ks8j3jsisd / ks8j3jsisd][Stopped/Auto Start]
  <C:\WINDOWS\System32\ks8j3jsisd.exe -j><Microsoft Corporation>
[kusn33sd / kusn33sd][Stopped/Auto Start]
  <C:\WINDOWS\System32\kusn33sd.exe -j><Microsoft Corporation>
[QCONSVC / QCONSVC][Stopped/Auto Start]
  <System32\QCONSVC.EXE><N/A>
[Remote Debug Service / RemoteDbg][Stopped/Auto Start]
  <C:\WINDOWS\System32\rundll32.exe RemoteDbg.dll,input><Microsoft Corporation>
[Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[svchost / svchost][Stopped/Auto Start]
  <C:\WINDOWS\svchost.exe><N/A>
[IBM KCU Service / TpKmpSVC][Stopped/Disabled]
  <C:\WINDOWS\system32\TpKmpSVC.exe><N/A>
[TrueVector Internet Monitor / vsmon][Running/Auto Start]
  <C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service><Zone Labs Inc.>
[WinFax PRO / wfxsvc][Running/Auto Start]
  <C:\WINDOWS\System32\WFXSVC.EXE><Symantec Corporation>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
  <C:\WINDOWS\System32\rundll32.exe windhcp.ocx,input><Microsoft Corporation>
[Windowso / WindowsDown][Stopped/Auto Start]
  <C:\WINDOWS\System32\servet.exe><N/A>
[WMI Performance API / WMIApiSrv][Stopped/Auto Start]
  <C:\WINDOWS\System32\rundll32.exe WMIApiSrv.dll,input><Microsoft Corporation>
[Wireless Service / WZCSRVC][Stopped/Auto Start]
  <C:\WINDOWS\System32\rundll32.exe netsrvcs.dll,input><Microsoft Corporation>
[Windows yvjy RunThem / yvjy][Running/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\tqet\daod.dll>< >
最后编辑2007-06-14 11:29:44.200000000