瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求助:怎样清除木马病毒Trojan.Agent.ddj

12   1  /  2  页   跳转

求助:怎样清除木马病毒Trojan.Agent.ddj

求助:怎样清除木马病毒Trojan.Agent.ddj

哪位大侠帮助哈!谢谢
最后编辑2006-07-20 16:46:47
分享到:
gototop
 

自己顶上,请高手帮忙!
gototop
 

病毒路径..
gototop
 

C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346
gototop
 

C:\WINDOWS\system32Baodfy.dll
C:\WINDOWS\system32Ciba.dll
C:\WINDOWS\system32Ckacj.dll
C:\WINDOWS\system32Ddmlh.dll
C:\WINDOWS\system32Fpbc.dll
C:\WINDOWS\system32Gphv.dll
C:\WINDOWS\system32Gvgqq.dll
C:\WINDOWS\system32Igohx.dll
C:\WINDOWS\system32Iipsf.dll
C:\WINDOWS\system32Jlipoc.dll
C:\WINDOWS\system32Kcmo.dll
C:\WINDOWS\system32Kmisuq.dll
C:\WINDOWS\system32Lqsoy.dll
C:\WINDOWS\system32Mjklu.dll
C:\WINDOWS\system32Mtlz.dll
C:\WINDOWS\system32Qkxim.dll
C:\WINDOWS\system32Shcjfg.dll
C:\WINDOWS\system32Spweyl.dll
C:\WINDOWS\system32Ucpfb.dll
C:\WINDOWS\system32Vadys.dll
C:\WINDOWS\system32Vtmoj.dll
C:\WINDOWS\system32Vvrrjg.dll
C:\WINDOWS\system32Vvrtj.dll
C:\WINDOWS\system32Wbtmm.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134634.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134635.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134636.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134637.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134638.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134639.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134640.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134641.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134642.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134643.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134644.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134645.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134646.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134647.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134648.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134649.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134650.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134651.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134652.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134653.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134654.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134655.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134656.dll
C:\System Volume Information\_restore{DBE6E16E-041D-4A14-B2A8-69E68B086FD8}\RP346A0134657.dll
gototop
 

我的电脑-右键-属性-系统还原-在所有磁盘上关闭系统还原

重启..再把他开启...

http://forum.ikaka.com/topic.asp?board=28&artid=8105899
下载HijackThis...把日志帖上来..
gototop
 

HijackThis_815汉化版扫描日志 V1.99.1
保存于      16:06:34, 日期 2006-7-20
操作系统:  Windows XP SP1 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
d:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
d:\Program Files\Rising\Rav\Ravmond.exe
d:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
d:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ZarvaSoft\Smart Update Utility\Ahnsdsv.exe
d:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\System32\TpShocks.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\ZarvaSoft\Smart Update Utility\AhnSD.exe
D:\Program Files\Hero3000\SYSEXPLR.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\Rising\Rav\RavTask.exe
D:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
D:\Program Files\Tencent\TT\TTraveler.exe
D:\Program Files\Tencent\TT\TCPlus.exe
C:\WINDOWS\NOTEPAD.EXE
E:\Downloads\Hijackthis1991zww\HijackThis1991zww.exe
gototop
 

R3 - URLSearchHook: (no name) - {BA55B7C7-5A20-4A9A-A6E2-237818599E21} - (no file)
R3 - URLSearchHook: (no name) - {E662B920-B819-47B0-851E-44B9FECD38A7} - (no file)
R3 - URLSearchHook: (no name) - {30DC50FE-491B-4204-AB7E-C71F14BC5EDA} - (no file)
R3 - URLSearchHook: (no name) - {64395360-4DBF-4120-B4C8-998E6C13FAEC} - (no file)
R3 - URLSearchHook: (no name) - {76F4547F-9EF4-4E06-9172-FC4E55598EC6} - (no file)
R3 - URLSearchHook: (no name) - {6FBFDE4E-1C4C-4660-90C9-B69135666BCD} - (no file)
R3 - URLSearchHook: (no name) - {6CD66AF2-23B9-4B54-9770-8238524F8E85} - (no file)
R3 - URLSearchHook: (no name) - {D97C20A8-15F3-4B73-9C71-F5E58D3D1C5C} - (no file)
R3 - URLSearchHook: (no name) - {24BC9E8A-1FAD-4018-86BB-74D331215168} - (no file)
R3 - URLSearchHook: (no name) - {88D47C8A-4A53-48C0-A795-59F026B7653C} - (no file)
R3 - URLSearchHook: (no name) - {4AB1B213-40DF-4FE9-AB7C-5F8E98398806} - (no file)
R3 - URLSearchHook: (no name) - {7A04A45B-737A-44B9-893A-5B8BC6BA9AEF} - (no file)
R3 - URLSearchHook: (no name) - {217AC640-BA23-4E00-AF16-1BF90BBFFD82} - (no file)
R3 - URLSearchHook: (no name) - {B9607554-DDD7-461F-A5A8-E7111E99108E} - (no file)
R3 - URLSearchHook: (no name) - {601F80CC-FA55-4AEA-BEF8-D7E2E735EAE4} - (no file)
R3 - URLSearchHook: (no name) - {BEE405E6-1055-4D4A-8C9F-075DC8196814} - (no file)
R3 - URLSearchHook: (no name) - {D2DD614B-0AD6-4A20-891E-9932A670DC24} - (no file)
R3 - URLSearchHook: (no name) - {104D6001-F0DA-4368-91E6-EC7DF17653D0} - (no file)
R3 - URLSearchHook: (no name) - {2349719D-920E-49C7-A4C3-EE8BCEF4F6E2} - (no file)
R3 - URLSearchHook: (no name) - {E81693AC-BD46-46DA-84AF-8D44438FDFBA} - (no file)
R3 - URLSearchHook: (no name) - {C86710BE-F8AC-4E27-BB8C-FFA8CDD1E5B8} - (no file)
R3 - URLSearchHook: (no name) - {F335773A-EF75-4C55-A3F8-E297381F9B2F} - (no file)
R3 - URLSearchHook: (no name) - {80F543B2-CA61-48E5-9A88-7B86D24FC039} - (no file)
R3 - URLSearchHook: (no name) - {310BDA68-90A1-45FF-BAC8-FABCBE068032} - (no file)
R3 - URLSearchHook: (no name) - {8B62C235-AF70-4910-84C6-0D7BA1EC9156} - (no file)
R3 - URLSearchHook: (no name) - {363C61BA-C738-4033-8FB0-DC9589D78281} - (no file)
R3 - URLSearchHook: (no name) - {E92F34DF-5B6A-4C3B-9B40-C2E86C93F828} - (no file)
R3 - URLSearchHook: (no name) - {DE055D32-3716-4D3F-993F-9E9538129373} - (no file)
R3 - URLSearchHook: (no name) - {F432C279-A18F-465E-B6B3-26EB8061A370} - (no file)
R3 - URLSearchHook: (no name) - {3C9B7C61-A9DF-4889-8D0C-614A121CA04A} - (no file)
R3 - URLSearchHook: (no name) - {C552C87C-0FB9-4BB7-94B5-75A47865771A} - (no file)
R3 - URLSearchHook: (no name) - {FF67986D-A103-41F5-BED4-B14104D37F5C} - (no file)
R3 - URLSearchHook: (no name) - {176FE04E-DB82-4053-A797-4D1C46E6EC8D} - (no file)
R3 - URLSearchHook: (no name) - {05B5CD8F-0036-4DEE-976D-D8067BC34649} - (no file)
R3 - URLSearchHook: (no name) - {E220E915-F305-4AD7-ADC4-8426ADF4580E} - (no file)
R3 - URLSearchHook: (no name) - {A327DF40-64F9-4A7C-AD2C-ED763428826D} - (no file)
R3 - URLSearchHook: (no name) - {184BF1AA-46CA-4FDE-8D2C-86C1EA9FEB61} - (no file)
R3 - URLSearchHook: (no name) - {2BB4B83F-6649-4F59-8A5F-CD4143A6E396} - (no file)
R3 - URLSearchHook: (no name) - {EE98E4AA-933D-4282-AF6E-379FF0E3294A} - (no file)
R3 - URLSearchHook: (no name) - {5AA45459-8216-4B3D-A445-DB9171D09729} - (no file)
R3 - URLSearchHook: (no name) - {56D5C2AF-43AA-409A-88E4-C0C6BF391D4D} - (no file)
R3 - URLSearchHook: (no name) - {2B7E606E-E848-436B-A7FE-E91BABD6D818} - (no file)
R3 - URLSearchHook: (no name) - {6521317F-91F8-43AB-A906-81375AC56942} - (no file)
R3 - URLSearchHook: (no name) - {B47905EF-43B6-4583-A996-610C775B7FAE} - (no file)
R3 - URLSearchHook: (no name) - {480370C6-BDB5-4325-A1FE-079DD1589AA4} - (no file)
R3 - URLSearchHook: (no name) - {C44AA568-C3D5-482C-AFD4-2CD7AF00BC8D} - (no file)
R3 - URLSearchHook: (no name) - {7E3034AF-D863-45D3-BCDE-BC2A6AC1F39B} - (no file)
R3 - URLSearchHook: (no name) - {A4C1A595-C7A2-4A43-AC2E-45051CA46CFB} - (no file)
R3 - URLSearchHook: (no name) - {2639CAE6-8463-48F6-945B-2DBF932BD3B6} - (no file)
R3 - URLSearchHook: (no name) - {45226679-77E2-48B2-AE0E-8402C1B71E7D} - (no file)
R3 - URLSearchHook: (no name) - {DC3B5986-4383-4DAE-9FEC-3672426E44D2} - (no file)
R3 - URLSearchHook: (no name) - {A5CD672C-1111-4833-8CF6-67494268C13D} - (no file)
R3 - URLSearchHook: (no name) - {256728DB-4E61-4FC0-8A97-697EF25BA1D5} - (no file)
R3 - URLSearchHook: (no name) - {B218141F-AF33-4366-9B06-9E6CEA2AEB45} - (no file)
R3 - URLSearchHook: (no name) - {05727A78-65C6-43EF-A897-AFA44E0FD576} - (no file)
R3 - URLSearchHook: (no name) - {77D0E9F7-6F2A-4EB5-A468-88E7C9E3589C} - (no file)
R3 - URLSearchHook: (no name) - {20CC8452-AA01-4625-9E40-BBC5060898AC} - (no file)
R3 - URLSearchHook: (no name) - {DBD9C93E-8FDC-4406-B0B6-4A081A14A1EA} - (no file)
R3 - URLSearchHook: (no name) - {FCE63972-ADC1-4B00-ACA3-BAEC011A8124} - (no file)
R3 - URLSearchHook: (no name) - {D12047DD-3F16-476F-BC1D-D21536067C2E} - (no file)
R3 - URLSearchHook: (no name) - {225CB4DD-E06B-4762-B56D-8AA6F7FF460D} - (no file)
R3 - URLSearchHook: (no name) - {FBA20BE5-3D36-4689-B1DF-0C6A93807374} - (no file)
R3 - URLSearchHook: (no name) - {966E8A36-D4E0-4A14-AB7F-9CC1A8C8D219} - (no file)
R3 - URLSearchHook: (no name) - {53B356FB-D2E1-4FC2-817C-407534928E5D} - (no file)
R3 - URLSearchHook: (no name) - {1A929605-8513-4F63-A058-397CAF360E35} - (no file)
R3 - URLSearchHook: (no name) - {0BA73B1D-4A5D-497A-B081-8C2F5B1727AE} - (no file)
R3 - URLSearchHook: (no name) - {D7979245-176C-4937-8312-BE604DC34677} - (no file)
R3 - URLSearchHook: (no name) - {73146FFB-2BCA-4A55-8EE7-45CDB74E9CF8} - (no file)
R3 - URLSearchHook: (no name) - {969E053C-9E03-4954-848C-B1BC4D9D038F} - (no file)
R3 - URLSearchHook: (no name) - {49ADE813-0158-4160-AF01-BFAFEF895D88} - (no file)
R3 - URLSearchHook: (no name) - {905FD713-AEB4-47F7-B041-51AF2AFAB5B8} - (no file)
R3 - URLSearchHook: (no name) - {B9677148-D403-4DC2-8C1A-03948E844A1B} - (no file)
R3 - URLSearchHook: (no name) - {9FB491AB-092E-4E34-A6BD-A04C92CC2860} - (no file)
R3 - URLSearchHook: (no name) - {38B62807-2CCE-4ADE-92A2-03337508207C} - (no file)
R3 - URLSearchHook: (no name) - {3E67D982-5D81-4AE6-A9BF-75AD1DC0DDEC} - (no file)
R3 - URLSearchHook: (no name) - {A2EBE7FB-E16A-4320-A403-F06630A123E9} - (no file)
R3 - URLSearchHook: (no name) - {E671E258-2EAF-48D6-B5D6-2B109320DB8F} - (no file)
R3 - URLSearchHook: (no name) - {4DB50296-D637-4DBE-8C8E-3436EC165001} - (no file)
R3 - URLSearchHook: (no name) - {E27ED343-A7A6-478F-B900-262279665CA9} - (no file)
R3 - URLSearchHook: (no name) - {6A4CA00E-1A92-47E6-8DA5-C45CC6E047DB} - (no file)
gototop
 

O2 - BHO: (no name) - {05727A78-65C6-43EF-A897-AFA44E0FD576} - (no file)
O2 - BHO: (no name) - {05B5CD8F-0036-4DEE-976D-D8067BC34649} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {0BA73B1D-4A5D-497A-B081-8C2F5B1727AE} - (no file)
O2 - BHO: (no name) - {104D6001-F0DA-4368-91E6-EC7DF17653D0} - (no file)
O2 - BHO: (no name) - {176FE04E-DB82-4053-A797-4D1C46E6EC8D} - (no file)
O2 - BHO: (no name) - {184BF1AA-46CA-4FDE-8D2C-86C1EA9FEB61} - (no file)
O2 - BHO: (no name) - {1A929605-8513-4F63-A058-397CAF360E35} - (no file)
O2 - BHO: (no name) - {20CC8452-AA01-4625-9E40-BBC5060898AC} - (no file)
O2 - BHO: (no name) - {217AC640-BA23-4E00-AF16-1BF90BBFFD82} - (no file)
O2 - BHO: (no name) - {225CB4DD-E06B-4762-B56D-8AA6F7FF460D} - (no file)
O2 - BHO: (no name) - {2349719D-920E-49C7-A4C3-EE8BCEF4F6E2} - (no file)
O2 - BHO: (no name) - {24BC9E8A-1FAD-4018-86BB-74D331215168} - (no file)
O2 - BHO: (no name) - {256728DB-4E61-4FC0-8A97-697EF25BA1D5} - (no file)
O2 - BHO: (no name) - {2639CAE6-8463-48F6-945B-2DBF932BD3B6} - (no file)
O2 - BHO: (no name) - {2B7E606E-E848-436B-A7FE-E91BABD6D818} - (no file)
O2 - BHO: (no name) - {2BB4B83F-6649-4F59-8A5F-CD4143A6E396} - (no file)
O2 - BHO: (no name) - {30DC50FE-491B-4204-AB7E-C71F14BC5EDA} - (no file)
O2 - BHO: (no name) - {310BDA68-90A1-45FF-BAC8-FABCBE068032} - (no file)
O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O2 - BHO: (no name) - {363C61BA-C738-4033-8FB0-DC9589D78281} - (no file)
O2 - BHO: (no name) - {38B62807-2CCE-4ADE-92A2-03337508207C} - (no file)
O2 - BHO: (no name) - {3C9B7C61-A9DF-4889-8D0C-614A121CA04A} - (no file)
O2 - BHO: (no name) - {3E67D982-5D81-4AE6-A9BF-75AD1DC0DDEC} - (no file)
O2 - BHO: (no name) - {45226679-77E2-48B2-AE0E-8402C1B71E7D} - (no file)
O2 - BHO: (no name) - {480370C6-BDB5-4325-A1FE-079DD1589AA4} - (no file)
O2 - BHO: (no name) - {49ADE813-0158-4160-AF01-BFAFEF895D88} - (no file)
O2 - BHO: (no name) - {4AB1B213-40DF-4FE9-AB7C-5F8E98398806} - (no file)
O2 - BHO: (no name) - {4DB50296-D637-4DBE-8C8E-3436EC165001} - (no file)
O2 - BHO: (no name) - {53B356FB-D2E1-4FC2-817C-407534928E5D} - (no file)
O2 - BHO: (no name) - {56D5C2AF-43AA-409A-88E4-C0C6BF391D4D} - (no file)
O2 - BHO: (no name) - {5AA45459-8216-4B3D-A445-DB9171D09729} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - (no file)
O2 - BHO: (no name) - {601F80CC-FA55-4AEA-BEF8-D7E2E735EAE4} - (no file)
O2 - BHO: (no name) - {64395360-4DBF-4120-B4C8-998E6C13FAEC} - (no file)
O2 - BHO: (no name) - {6521317F-91F8-43AB-A906-81375AC56942} - (no file)
O2 - BHO: (no name) - {6A4CA00E-1A92-47E6-8DA5-C45CC6E047DB} - (no file)
O2 - BHO: (no name) - {6CD66AF2-23B9-4B54-9770-8238524F8E85} - (no file)
O2 - BHO: (no name) - {6FBFDE4E-1C4C-4660-90C9-B69135666BCD} - (no file)
O2 - BHO: (no name) - {73146FFB-2BCA-4A55-8EE7-45CDB74E9CF8} - (no file)
O2 - BHO: (no name) - {76F4547F-9EF4-4E06-9172-FC4E55598EC6} - (no file)
O2 - BHO: (no name) - {77D0E9F7-6F2A-4EB5-A468-88E7C9E3589C} - (no file)
O2 - BHO: (no name) - {7A04A45B-737A-44B9-893A-5B8BC6BA9AEF} - (no file)
O2 - BHO: (no name) - {7E3034AF-D863-45D3-BCDE-BC2A6AC1F39B} - (no file)
O2 - BHO: (no name) - {80F543B2-CA61-48E5-9A88-7B86D24FC039} - (no file)
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - (no file)
O2 - BHO: (no name) - {88D47C8A-4A53-48C0-A795-59F026B7653C} - (no file)
O2 - BHO: (no name) - {8B62C235-AF70-4910-84C6-0D7BA1EC9156} - (no file)
O2 - BHO: (no name) - {905FD713-AEB4-47F7-B041-51AF2AFAB5B8} - (no file)
O2 - BHO: (no name) - {966E8A36-D4E0-4A14-AB7F-9CC1A8C8D219} - (no file)
O2 - BHO: (no name) - {969E053C-9E03-4954-848C-B1BC4D9D038F} - (no file)
O2 - BHO: (no name) - {9FB491AB-092E-4E34-A6BD-A04C92CC2860} - (no file)
O2 - BHO: (no name) - {A2EBE7FB-E16A-4320-A403-F06630A123E9} - (no file)
O2 - BHO: (no name) - {A327DF40-64F9-4A7C-AD2C-ED763428826D} - (no file)
O2 - BHO: (no name) - {A4C1A595-C7A2-4A43-AC2E-45051CA46CFB} - (no file)
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: (no name) - {A5CD672C-1111-4833-8CF6-67494268C13D} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {B218141F-AF33-4366-9B06-9E6CEA2AEB45} - (no file)
O2 - BHO: (no name) - {B47905EF-43B6-4583-A996-610C775B7FAE} - (no file)
O2 - BHO: (no name) - {B9607554-DDD7-461F-A5A8-E7111E99108E} - (no file)
O2 - BHO: (no name) - {B9677148-D403-4DC2-8C1A-03948E844A1B} - (no file)
O2 - BHO: (no name) - {BA55B7C7-5A20-4A9A-A6E2-237818599E21} - (no file)
O2 - BHO: (no name) - {BEE405E6-1055-4D4A-8C9F-075DC8196814} - (no file)
O2 - BHO: (no name) - {C44AA568-C3D5-482C-AFD4-2CD7AF00BC8D} - (no file)
O2 - BHO: (no name) - {C552C87C-0FB9-4BB7-94B5-75A47865771A} - (no file)
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - (no file)
O2 - BHO: (no name) - {C86710BE-F8AC-4E27-BB8C-FFA8CDD1E5B8} - (no file)
O2 - BHO: (no name) - {D12047DD-3F16-476F-BC1D-D21536067C2E} - (no file)
O2 - BHO: (no name) - {D2DD614B-0AD6-4A20-891E-9932A670DC24} - (no file)
O2 - BHO: (no name) - {D7979245-176C-4937-8312-BE604DC34677} - (no file)
O2 - BHO: (no name) - {D97C20A8-15F3-4B73-9C71-F5E58D3D1C5C} - (no file)
O2 - BHO: (no name) - {DBD9C93E-8FDC-4406-B0B6-4A081A14A1EA} - (no file)
O2 - BHO: (no name) - {DC3B5986-4383-4DAE-9FEC-3672426E44D2} - (no file)
O2 - BHO: (no name) - {DE055D32-3716-4D3F-993F-9E9538129373} - (no file)
O2 - BHO: (no name) - {E220E915-F305-4AD7-ADC4-8426ADF4580E} - (no file)
O2 - BHO: (no name) - {E27ED343-A7A6-478F-B900-262279665CA9} - (no file)
O2 - BHO: (no name) - {E662B920-B819-47B0-851E-44B9FECD38A7} - (no file)
O2 - BHO: (no name) - {E671E258-2EAF-48D6-B5D6-2B109320DB8F} - (no file)
O2 - BHO: (no name) - {E81693AC-BD46-46DA-84AF-8D44438FDFBA} - (no file)
O2 - BHO: (no name) - {E92F34DF-5B6A-4C3B-9B40-C2E86C93F828} - (no file)
O2 - BHO: (no name) - {EE98E4AA-933D-4282-AF6E-379FF0E3294A} - (no file)
O2 - BHO: (no name) - {F335773A-EF75-4C55-A3F8-E297381F9B2F} - (no file)
O2 - BHO: (no name) - {F432C279-A18F-465E-B6B3-26EB8061A370} - (no file)
O2 - BHO: (no name) - {FBA20BE5-3D36-4689-B1DF-0C6A93807374} - (no file)
O2 - BHO: (no name) - {FCE63972-ADC1-4B00-ACA3-BAEC011A8124} - (no file)
O2 - BHO: (no name) - {FF67986D-A103-41F5-BED4-B14104D37F5C} - (no file)
gototop
 

O3 - IE工具栏增项: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - D:\PROGRA~1\POWERW~1\IEBand.dll
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [S3TRAY2] S3Tray2.exe
O4 - 启动项HKLM\\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - 启动项HKLM\\Run: [TpShocks] TpShocks.exe
O4 - 启动项HKLM\\Run: [TP4EX] tp4ex.exe
O4 - 启动项HKLM\\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - 启动项HKLM\\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - 启动项HKLM\\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - 启动项HKLM\\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - 启动项HKLM\\Run: [AHNSD] "C:\Program Files\ZarvaSoft\Smart Update Utility\AhnSD.exe"
O4 - 启动项HKLM\\Run: [SysExplr] D:\Program Files\Hero3000\SYSEXPLR.EXE
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [RfwMain] "D:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [RavTask] "d:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [Anti Trojan Elite] D:\Program Files\Anti Trojan Elite\TJEnder.exe :NO
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: 服务管理器.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - IE右键菜单中的新增项目: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - IE右键菜单中的新增项目: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - IE右键菜单中的新增项目: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - IE右键菜单中的新增项目: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - IE右键菜单中的新增项目: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - IE右键菜单中的新增项目: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - IE右键菜单中的新增项目: 使用影音传送带下载 - D:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - IE右键菜单中的新增项目: 使用影音传送带下载全部链接 - D:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - D:\Program Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - D:\Program Files\FlashGet\jc_all.htm
O9 - 浏览器额外的按钮: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java141\jre\bin\NPJPI141.dll
O9 - 浏览器额外的“工具”菜单项: IBM Java 控制台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java141\jre\bin\NPJPI141.dll
O9 - 浏览器额外的按钮: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - 浏览器额外的“工具”菜单项: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - 浏览器额外的按钮: 卓越 - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - D:\PROGRA~1\POWERW~1\POWERW~1\IEPlugin.dll
O9 - 浏览器额外的按钮: 网际飞音 - {8E4E4123-AAC7-42CA-AF1B-68CE70B8D385} - D:\Program Files\Donor\donor.exe
O9 - 浏览器额外的“工具”菜单项: 网际飞音(&D) - {8E4E4123-AAC7-42CA-AF1B-68CE70B8D385} - D:\Program Files\Donor\donor.exe
O9 - 浏览器额外的按钮: 词霸 - {9A687CA6-D585-4947-9ED9-BE96071F5CD9} - D:\PROGRA~1\POWERW~1\POWERW~1\XDictExB.dll
O9 - 浏览器额外的按钮: 金山词霸 - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - D:\PROGRA~1\POWERW~1\POWERW~1\IEPlugin.dll
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\flashget.exe
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\cdnns.dll
O11 - Options group: [CDNCLIENT]  中文上网
O11 - Options group: [JAVA_IBM] Java (IBM)
O17 - HKLM\System\CCS\Services\Tcpip\..\{262F24EA-C942-4B57-AF5C-9B490526814C}: NameServer = 10.37.0.1,202.98.160.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{262F24EA-C942-4B57-AF5C-9B490526814C}: NameServer = 10.37.0.1,202.98.160.68
O18 - 列举现有的协议: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - D:\PROGRA~1\POWERW~1\POWERW~1\XDictExB.dll
O23 - NT 服务: Ahnlab Task Scheduler - AhnLab, Inc. - C:\Program Files\ZarvaSoft\Smart Update Utility\Ahnsdsv.exe
O23 - NT 服务: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - NT 服务: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - NT 服务: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - NT 服务: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - NT 服务: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwproxy.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - d:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - d:\Program Files\Rising\Rav\Ravmond.exe
O23 - NT 服务: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\System32\S24EvMon.exe
O23 - NT 服务: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT