瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】中毒了,高手请进~~~~~~~~~~~~~~

12   1  /  2  页   跳转

【求助】中毒了,高手请进~~~~~~~~~~~~~~

【求助】中毒了,高手请进~~~~~~~~~~~~~~

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      21:35:22, 日期 2006-8-11
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\E_S00RP1.EXE
E:\security suite\ewidoguard.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Phone\ContentFilter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\SynCor.exe
C:\Program Files\Thunder Network\Thunder\Thunder.exe
D:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
E:\security suite\oldewido.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Super Rabbit\MagicSet\MAGICSET.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\黄河\LOCALS~1\Temp\Rar$EX00.281\HijackThis1991zww.exe

R3 - URLSearchHook: (no name) - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v8.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll (file missing)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\zh-cn\msntb.dll (file missing)
O3 - IE工具栏增项: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - C:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll
O3 - IE工具栏增项: 超级兔子上网精灵 - {43869BB3-22FD-4F15-9B46-238106BA2F4E} - C:\PROGRA~1\SUPERR~1\MAGICSET\haokanbar.dll
O3 - IE工具栏增项: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll (file missing)
O3 - IE工具栏增项: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\zh-cn\msntb.dll (file missing)
O3 - IE工具栏增项: 东方快车 - {3EA85E14-887D-4E2F-91E2-3158CE58ED62} - D:\Program Files\!Sunv\DFKC2003\IEBand.DLL (file missing)
O4 - 启动项HKLM\\Run: [vptray] ; C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - 启动项HKLM\\Run: [xysecond] ; C:\Vrv\Client\vrvmon.exe
O4 - 启动项HKLM\\Run: [Desktop Lock Loader] C:\PROGRA~1\DESKTO~1\TLDL.EXE /BOOT
O4 - 启动项HKLM\\Run: [CAD] \\JDI-1\PUB\LSP\CAD.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] ; "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] ; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [eMuleAutoStart] ; C:\Program Files\eMule\eMule.exe -AutoStart
O4 - Startup: xdict.lnk = D:\Kingsoft\Xdict.exe
O4 - Startup: 加班数.lnk = ?
O4 - Global Startup: adobe gamma loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: ie-bar.lnk = ?
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - IE右键菜单中的新增项目: 东方快车-保存翻译后的网页 - D:\Program Files\!Sunv\DFKC2003\ExtSave.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\QQ2004绿色版\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\QQ2004绿色版\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\QQ2004绿色版\SendMMS.htm
O9 - 浏览器额外的按钮: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm?pid=65226_1006 (file missing)
O9 - 浏览器额外的按钮: 东方快车 - {0B66EBA4-5F53-40e4-B17B-A0E9BC1E8D50} - D:\Program Files\!Sunv\DFKC2003\IEBand.DLL (file missing)
O9 - 浏览器额外的按钮: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - 浏览器额外的按钮: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=?allyesPara=816 (file missing)
O9 - 浏览器额外的按钮: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/?source=Cns (file missing)
O9 - 浏览器额外的按钮: 999软件宝藏网 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.in9.cn (file missing)
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - 浏览器额外的“工具”菜单项: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - 浏览器额外的“工具”菜单项: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\nsp.dll' missing
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1119990630062
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5D019A84-1E2E-4724-8E06-01FE71531832}: NameServer = 192.168.0.88,202.96.129.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{5D019A84-1E2E-4724-8E06-01FE71531832}: NameServer = 192.168.0.88,202.96.129.68
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - NT 服务: Autodesk Licensing Service - Unknown owner - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - NT 服务: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - NT 服务: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - NT 服务: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
O23 - NT 服务: ewido security suite guard - ewido networks - E:\security suite\ewidoguard.exe
O23 - NT 服务: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - NT 服务: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - NT 服务: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - NT 服务: SolidWorks SolidNetWork License Manager - Macrovision Corporation - C:\flexlm\Sw2005_SP0_licenses\SolidWorks SolidNetWork License Manager\lmgrd.exe
O23 - NT 服务: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - NT 服务: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe

最后编辑2006-08-12 10:36:53
分享到:
gototop
 

怎么没人处理啊
gototop
 

请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改。
gototop
 

006-08-12,09:47:21

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
    <MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>  [Microsoft Corporation]
    <MsnMsgr><; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>  [Microsoft Corporation]
    <eMuleAutoStart><; C:\Program Files\eMule\eMule.exe -AutoStart>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
    <run><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <vptray><; C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe>  [Symantec Corporation]
    <xysecond><; C:\Vrv\Client\vrvmon.exe>  []
    <VMAILMON><>  []
    <Desktop Lock Loader><C:\PROGRA~1\DESKTO~1\TLDL.EXE /BOOT>  []
    <CAD><\\JDI-1\PUB\LSP\CAD.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{54D9498B-CF93-414F-8984-8CE7FDE0D391}><>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
    <WinlogonNotify: NavLogon><C:\WINDOWS\system32\NavLogon.dll>  []

==================================
启动文件夹
[adobe gamma loader]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\adobe gamma loader.lnk><N>
[ie-bar]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\ie-bar.lnk><N>
[xdict]
  <C:\Documents and Settings\黄河\「开始」菜单\程序\启动\xdict.lnk><N>
[加班数]
  <C:\Documents and Settings\黄河\「开始」菜单\程序\启动\加班数.lnk><N>

==================================
服务
[Autodesk Licensing Service / Autodesk Licensing Service]
  <"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><N/A>
[C-DillaCdaC11BA / C-DillaCdaC11BA]
  <C:\WINDOWS\system32\drivers\CDAC11BA.EXE><Macrovision>
[DefWatch / DefWatch]
  <"C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[EPSON V3 Service2(03) / EPSON_PM_RPCV2_01]
  <C:\WINDOWS\system32\E_S00RP1.EXE><SEIKO EPSON CORPORATION>
[ewido security suite guard / ewido security suite guard]
  <E:\security suite\ewidoguard.exe><ewido networks>
[Symantec AntiVirus Client / Norton AntiVirus Server]
  <"C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>
[NVIDIA Driver Helper Service / NVSvc]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd]
  <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><N/A>
[SolidWorks SolidNetWork License Manager / SolidWorks SolidNetWork License Manager]
  <C:\flexlm\Sw2005_SP0_licenses\SolidWorks SolidNetWork License Manager\lmgrd.exe><Macrovision Corporation>
[SoundMAX Agent Service / SoundMAX Agent Service (default)]
  <C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[TrueVector Internet Monitor / vsmon]
  <C:\WINDOWS\system32\ZONELABS\vsmon.exe -service><Zone Labs, LLC>

==================================
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v8.dll, Thunder Networking Technologies,LTD>
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll, N/A>
[ST]
  {9394EDE7-C8B5-483E-8773-474BF36AF6E4} <C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll, N/A>
[AcroIEToolbarHelper Class]
  {AE7CD045-E861-484f-8273-0445EE161910} <D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll, N/A>
[MSNToolBandBHO]
  {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\zh-cn\msntb.dll, N/A>
[手机短信]
  {00000000-0000-0001-0001-596BAEDD1289} <http://sms.3721.com/ie/index.htm?pid=65226_1006, N/A>
[江民在线杀毒]
  {06926B30-424E-4f1c-8EE3-543CD96573DC} <http://online.jiangmin.com/online.asp, N/A>
[东方快车]
  {0B66EBA4-5F53-40e4-B17B-A0E9BC1E8D50} <D:\Program Files\!Sunv\DFKC2003\IEBand.DLL, N/A>
[Yahoo 1G电邮]
  {507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.mail.yahoo.com/promo/rd1, N/A>
[寻宝乐趣多]
  {59BC54A2-56B3-44a0-93E5-432D58746E26} <http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=?allyesPara=816, N/A>
[雅虎助手]
  {5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/?source=Cns, N/A>
[999软件宝藏网]
  {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.in9.cn, N/A>
[情景聊天]
  {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/, N/A>
[]
  {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://assistant.3721.com/security1.htm?fb=Cns, N/A>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[]
  {FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://assistant.3721.com/clean1.htm?fb=Cns, N/A>
[金山快译(&K)]
  {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <C:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll, 金山软件股份有限公司>
[超级兔子上网精灵]
  {43869BB3-22FD-4F15-9B46-238106BA2F4E} <C:\PROGRA~1\SUPERR~1\MAGICSET\haokanbar.dll, Xiang Feng Technology>
[Adobe PDF]
  {47833539-D0C5-4125-9FA8-0819E2EAAC93} <D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll, N/A>
[MSN]
  {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\zh-cn\msntb.dll, N/A>
[东方快车]
  {3EA85E14-887D-4E2F-91E2-3158CE58ED62} <D:\Program Files\!Sunv\DFKC2003\IEBand.DLL, N/A>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[MsnMessengerSetupDownloadControl Class]
  {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} <C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[KvScanOnline Control]
  {EF6205C1-3F17-4829-BCB5-1336ED89E356} <C:\WINDOWS\KVSCAN~1\KvDown.ocx, dreamersoft>
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v8.dll, Thunder Networking Technologies,LTD>
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll, N/A>
[Adobe PDF]
  {47833539-D0C5-4125-9FA8-0819E2EAAC93} <D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll, N/A>
[ST]
  {9394EDE7-C8B5-483E-8773-474BF36AF6E4} <C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll, N/A>
[AcroIEToolbarHelper Class]
  {AE7CD045-E861-484F-8273-0445EE161910} <D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll, N/A>
[MSNToolBandBHO]
  {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\zh-cn\msntb.dll, N/A>
[&使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\getallurl.htm, N/A>
[上传到QQ网络硬盘]
  <, N/A>
[东方快车-保存翻译后的网页]
  <D:\Program Files\!Sunv\DFKC2003\ExtSave.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\QQ2004绿色版\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\QQ2004绿色版\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\QQ2004绿色版\SendMMS.htm, N/A>
gototop
 

==================================
正在运行的进程
[PID: 324][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 384][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 408][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\WINDOWS\system32\NavLogon.dll]  <N/A><N/A>
[PID: 452][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 464][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 624][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 672][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 712][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\System32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 816][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 872][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 1040][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\WINDOWS\system32\AdobePDF.dll]  <Adobe Systems Incorporated.><6.0.000>
    [D:\Program Files\Adobe\Acrobat 6.0\Distillr\adistres.dll]  <Adobe Systems Incorporated.><6.0.0.2003051500>
    [C:\WINDOWS\system32\BBPDFPortMon.dll]  <Bluebeam Software, Inc.><1, 0, 0, 1>
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll]  <Windows (R) 2000 DDK provider><5.00.2195.1620>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDNT5UI.DLL]  <Zenographics, Inc.><5.60.709.0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDDM32.DLL]  <Zenographics, Inc.><5, 60, 2629, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZSPOOL.dll]  <Zenographics, Inc.><5, 51, 709, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZGDI32.dll]  <Zenographics, Inc.><5, 60, 709, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZTAG32.dll]  <Zenographics, Inc.><5, 60, 1210, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDDMUI.DLL]  <Zenographics, Inc.><5, 60, 2209, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SR32.dll]  <Zenographics, Inc.><6, 0, 909, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FUICAAP.DLL]  <SEIKO EPSON CORP.><0. 3. 40, 33>
    [C:\WINDOWS\system32\icm32.dll]  <Microsoft Corporation><5.1.2600.2709 (xpsp_sp2_gdr.050628-1518)>
[PID: 1160][C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe]  <N/A><2.51.000>
[PID: 1212][C:\WINDOWS\system32\drivers\CDAC11BA.EXE]  <Macrovision><4.20.020>
[PID: 1244][C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe]  <Symantec Corporation><8.00.00.9374>
[PID: 1284][C:\WINDOWS\system32\E_S00RP1.EXE]  <SEIKO EPSON CORPORATION><2.03>
[PID: 1356][C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe]  <Symantec Corporation><8.00.00.9374>
    [C:\WINDOWS\system32\CBA.DLL]  <Intel? Corporation><6.12.0.71 E>
    [C:\WINDOWS\system32\MsgSys.dll]  <Intel? Corporation><6.12.0.71 E>
    [C:\WINDOWS\system32\NTS.dll]  <Intel? Corporation><6.12.0.71 E>
    [C:\WINDOWS\system32\PDS.DLL]  <Intel? Corporation><6.12.0.71 E>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVLU.dll]  <Symantec Corporation><8.00.00.9374>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVNTUTL.DLL]  <Symantec/Peter Norton Group><1, 0, 0, 1>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\i2ldvp3.dll]  <Symantec Corporation><8.00.00.9374>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAPI32.DLL]  <Symantec Corp.><4.1.0.15>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060803.048\NAVEX32a.DLL]  <Symantec Corporation><20061.2.0.26>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060803.048\NAVENG32.DLL]  <Symantec Corporation><20061.2.0.26>
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAP32.DLL]  <Symantec Corporation><9.0.0.14>
[PID: 1444][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe]  <Analog Devices, Inc.><3, 2, 6, 0>
[PID: 1480][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 1252][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\WINDOWS\system32\AcSignIcon.dll]  <Autodesk><16.0.0.86>
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  <Autodesk><16.1.63.0>
    [C:\WINDOWS\system32\xunleibho_v8.dll]  <Thunder Networking Technologies,LTD><4, 5, 1, 33>
    [C:\Program Files\Common Files\Autodesk Shared\Thumbnail\AcThumbnail16.dll]  <Autodesk><16.0.0.86>
[PID: 372][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\System32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 2104][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 3696][C:\Program Files\SnowFox\DesktopSprite2\DesktopSprite.exe]  <SnowFox Studio.><2.6.0.53>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 2312][C:\Program Files\Outlook Express\msimn.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\WINDOWS\system32\AcSignIcon.dll]  <Autodesk><16.0.0.86>
[PID: 3856][C:\Program Files\Skype\Phone\Skype.exe]  <N/A><N/A>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
[PID: 1952][C:\Program Files\Skype\Phone\ContentFilter.exe]  <TOM Online Inc.><1.0.2.0>
[PID: 3664][D:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE]  <Microsoft Corporation><11.0.6359>
    [D:\Kingsoft\PWOffice2.dll]  <Kingsoft Co, Ltd.><6, 0, 0, 0>
    [C:\Program Files\Kingsoft\FastAIT 2005\AddIns\WordAddIn.dll]  <金山软件股份公司><4, 0, 0, 0>
    [D:\PROGRA~1\Adobe\ACROBA~1.0\PDFMaker\Common\ADOBEP~1.DLL]  <N/A><N/A>
    [C:\WINDOWS\system32\VCDXP.IME]  <风清扬><4.00.950>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDNT5UI.DLL]  <Zenographics, Inc.><5.60.709.0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDDM32.DLL]  <Zenographics, Inc.><5, 60, 2629, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZSPOOL.dll]  <Zenographics, Inc.><5, 51, 709, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZGDI32.dll]  <Zenographics, Inc.><5, 60, 709, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZTAG32.dll]  <Zenographics, Inc.><5, 60, 1210, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDDMUI.DLL]  <Zenographics, Inc.><5, 60, 2209, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SR32.dll]  <Zenographics, Inc.><6, 0, 909, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\IMFNT5.DLL]  <Zenographics, Inc.><0, 3, 3508, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\Imf32.dll]  <Zenographics, Inc.><5, 60, 1204, 0>
[PID: 4020][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 1408][C:\WINDOWS\system32\cmd.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 2128][C:\WINDOWS\system32\cmd.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 2164][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
gototop
 

[C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
[PID: 2176][E:\Program Files\i486_nt\nms\nmsd.exe]  <PTC><24, 0, 2002, 490>
[PID: 2092][E:\Program Files\i486_nt\obj\xtop.exe]  <PTC><24, 0, 2002, 490>
    [E:\Program Files\i486_nt\lib\RgiWrapIsoLib.dll]  <N/A><N/A>
[PID: 1824][E:\Program Files\i486_nt\obj\pro_comm_msg.exe]  <PTC><24, 0, 2002, 490>
[PID: 3872][C:\Programme\AutoCAD 2004\acad.exe]  <Autodesk, Inc.><R16.00.086>
    [C:\Program Files\Common Files\Autodesk Shared\ac1st16.dll]  <Autodesk, Inc.><16.1.63.0>
    [C:\Program Files\Common Files\Autodesk Shared\acdb16.dll]  <Autodesk, Inc.><16.1.63.10>
    [C:\Program Files\Common Files\Autodesk Shared\AcGe16.dll]  <Autodesk, Inc.><16.1.63.0>
    [C:\Programme\AutoCAD 2004\acui16.dll]  <><16.0.0.86>
    [C:\Programme\AutoCAD 2004\ANav.dll]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\adui16.dll]  <><16.0.0.86>
    [C:\Programme\AutoCAD 2004\dswhip.dll]  <Autodesk Inc.><16.0.0.86>
    [C:\Programme\AutoCAD 2004\heidi8.dll]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\dlint8.dll]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\SFTTABAC.dll]  <Softel vdm><16.0.0.86>
    [C:\Programme\AutoCAD 2004\UserData.dll]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\adlmdll.dll]  <Autodesk, Inc.><4.0.0.2>
    [C:\Programme\AutoCAD 2004\adctrls.dll]  <Autodesk, Inc.><16.0.0.86>
    [C:\Programme\AutoCAD 2004\adui16res.dll]  <><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AnavRes.dll]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\acui16res.dll]  <><16.0.0.86>
    [C:\Programme\AutoCAD 2004\DsWhipRes.dll]  <Autodesk Inc.><16.0.0.86>
    [C:\Programme\AutoCAD 2004\sfttabacRes.dll]  <Softel vdm><16.0.0.86>
    [C:\DOCUME~1\黄河\LOCALS~1\Temp\~ef88b6\~df394b.tmp]  <N/A><N/A>
    [C:\DOCUME~1\黄河\LOCALS~1\Temp\~ef88b6\~de8c3a.tmp]  <N/A><2.20.020>
    [C:\Programme\AutoCAD 2004\ADCtrlsRes.dll]  <Autodesk, Inc.><16.0.0.86>
    [C:\Programme\AutoCAD 2004\acadbtn.dll]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\acadres.dll]  <Autodesk, Inc.><16.0.0.86>
    [C:\Program Files\Common Files\Autodesk Shared\acdb16enures.dll]  <Autodesk, Inc.><16.1.63.0>
    [C:\Programme\AutoCAD 2004\adlmres.dll]  <Autodesk, Inc.><4.0.0.2>
    [C:\Programme\AutoCAD 2004\PrxyInet.dll]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\PrxyInetRes.dll]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\oleaprot.arx]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\colorRes.dll]  <><16.0.0.86>
    [C:\Programme\AutoCAD 2004\drv\gdi8.hdi]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\drv\gdi8Res.dll]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\drv\szb8.hdi]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\drv\rblast8.hdi]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\drv\gdifont8.hdi]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\acgs.dll]  <Autodesk Inc.><16.0.0.86>
    [C:\Programme\AutoCAD 2004\acgsRes.dll]  <Autodesk Inc.><16.0.0.86>
    [c:\program files\common files\autodesk shared\achapi16.dbx]  <Autodesk, Inc.><16.1.63.0>
    [C:\Programme\AutoCAD 2004\hcreg8.dll]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\hcreg8Res.dll]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\vl.arx]  <Autodesk Inc.><16.0.0.86>
    [C:\Programme\AutoCAD 2004\VLMSG.DLL]  <Autodesk Inc.><16.0.0.86>
    [C:\Programme\AutoCAD 2004\VLLIB.DLL]  <Autodesk Inc.><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcApp.arx]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcDblClkEdit.arx]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcDblClkEditPE.arx]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcDblClkEditRes.dll]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\acdim.arx]  <><16.0.0.86>
    [C:\Programme\AutoCAD 2004\ShareAC.dll]  <Autodesk, Inc><16.0.0.86>
    [C:\Programme\AutoCAD 2004\ShareMFC.dll]  <Autodesk, Inc><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcDimRes.dll]  <><16.0.0.86>
    [C:\Programme\AutoCAD 2004\aceplotx.arx]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcEplotXRes.dll]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\achlnkui.arx]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\achlnkuiRes.dll]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcIDropMgr.arx]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcIDropMgrRes.dll]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcLayerP.arx]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcLayerPRes.dll]  <Autodesk, Inc.><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcSign.arx]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcSignRes.dll]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcSpaceTrans.arx]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcSpaceTransRes.dll]  <Autodesk, Inc.><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcArxAdlm.arx]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcTp.arx]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcTc.DLL]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcTcUi.dll]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcTcRes.dll]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\AcTcUiRes.dll]  <Autodesk><16.0.0.86>
    [C:\Programme\AutoCAD 2004\whohas.arx]  <><16.0.0.86>
    [C:\Programme\AutoCAD 2004\whohasRes.dll]  <><16.0.0.86>
    [C:\Programme\AutoCAD 2004\acetlodr.arx]  <Autodesk, Inc.><16.0.0.86>
    [C:\Programme\AutoCAD 2004\WSCommCntrAcCon.arx]  <Autodesk, Inc.><16.0.0.86>
    [C:\Programme\AutoCAD 2004\WSCommCntrAcConRes.dll]  <Autodesk><16.0.0.86>
gototop
 

[C:\Programme\AutoCAD 2004\apperr.dll]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\plotcfg8.dll]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\pctres8.dll]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\apperrRes.dll]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\plcfmgr.dll]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\plcfmgrRes.dll]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\plcferr.dll]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\pm8.dll]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\pmres8.dll]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\pmutil8.dll]  <Autodesk, Inc.><8.0.16.86>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDNT5UI.DLL]  <Zenographics, Inc.><5.60.709.0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDDM32.DLL]  <Zenographics, Inc.><5, 60, 2629, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZSPOOL.dll]  <Zenographics, Inc.><5, 51, 709, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZGDI32.dll]  <Zenographics, Inc.><5, 60, 709, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ZTAG32.dll]  <Zenographics, Inc.><5, 60, 1210, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SDDMUI.DLL]  <Zenographics, Inc.><5, 60, 2209, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\SR32.dll]  <Zenographics, Inc.><6, 0, 909, 0>
    [C:\Programme\AutoCAD 2004\drv\gdiplot8.hdi]  <Autodesk, Inc.><8.0.16.86>
    [C:\Programme\AutoCAD 2004\drv\gdiplot8Res.dll]  <Autodesk, Inc.><8.0.16.86>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\IMFNT5.DLL]  <Zenographics, Inc.><0, 3, 3508, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\Imf32.dll]  <Zenographics, Inc.><5, 60, 1204, 0>
    [C:\Programme\AutoCAD 2004\styleeng.dll]  <Autodesk, Inc.><8.0.16.86>
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  <Autodesk><16.1.63.0>
    [C:\DOCUME~1\黄河\LOCALS~1\Temp\~e5d141.tmp]  <Macrovision Europe Ltd.><1, 0, 0, 1>
[PID: 2832][C:\Program Files\Common Files\Autodesk Shared\WSCommCntr1.exe]  <Autodesk, Inc.><1.0.0.1>
    [C:\Program Files\Common Files\Autodesk Shared\WebServices1.dll]  <Autodesk, Inc.><1.0.0.1>
[PID: 2940][C:\Program Files\Maxthon\max.exe]  <Maxthon International Ltd.><1, 5, 3, 18>
    [C:\Program Files\Maxthon\maxzlib.dll]  < ><1, 0, 0, 2>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\WINDOWS\system32\AcSignIcon.dll]  <Autodesk><16.0.0.86>
    [C:\Program Files\Maxthon\Services\RealTime\real_time.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  <Autodesk><16.1.63.0>
    [C:\WINDOWS\KVSCAN~1\KvKill.ocx]  <jiangmin><1, 0, 2, 1>
    [C:\WINDOWS\KVSCAN~1\KVEnhD.dll]  <JiangMin Ltd.><9, 1, 0, 504>
    [C:\WINDOWS\KVSCAN~1\KVEnhO.dll]  <JiangMin New Tech Ltd.><9, 0, 0, 504>
    [C:\WINDOWS\KVSCAN~1\KVEnhC.Dll]  <JiangMin Ltd.><9.0.0.500>
    [C:\WINDOWS\KVSCAN~1\KVEnhS.Dll]  <JiangMin New Tech Ltd.><9, 0, 0, 505>
    [C:\WINDOWS\KVSCAN~1\KVEnhJ.Dll]  <JiangMin New Tech. Ltd.><9, 1, 0, 503>
    [C:\WINDOWS\KVSCAN~1\KVExtCab.dll]  <Jiangmin New Tech. Co. Ltd.><9.0.0.500>
    [C:\WINDOWS\KVSCAN~1\KVExtEml.dll]  <JiangMin New Tech. Ltd.><9, 0, 0, 503>
    [C:\WINDOWS\KVSCAN~1\KvExtRar.dll]  <Jiangmin New Tech. Co. Ltd.><9.0.0.500>
    [C:\WINDOWS\KVSCAN~1\KvExtZip.dll]  <JiangMin Ltd.><9.0.0.500>
    [C:\WINDOWS\KVSCAN~1\KVEnhK.Dll]  <JiangMin Ltd.><9, 0, 0, 504>
    [C:\WINDOWS\system32\VCDXP.IME]  <风清扬><4.00.950>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 3860][C:\Program Files\Thunder Network\Thunder\Thunder.exe]  <Thunder Networking Technologies,LTD><5.0.6.98>
    [C:\Program Files\Thunder Network\Thunder\UpdateDownload.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 1>
    [C:\Program Files\Thunder Network\Thunder\download_interface.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 1>
    [C:\Program Files\Thunder Network\Thunder\log4cplus.dll]  <><1, 0, 2, 1>
    [C:\Program Files\Thunder Network\Thunder\stlport_vc646.dll]  <STLport Consulting, Inc.><4.6.2003.1031>
    [C:\Program Files\Thunder Network\Thunder\historyinfo_manage.dll]  <Thunder Networking Technologies,LTD><5, 0, 0, 73>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>
    [C:\Program Files\Thunder Network\Thunder\iThunder.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 30>
    [C:\Program Files\Thunder Network\Thunder\RegisterDll.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 4>
    [C:\WINDOWS\system32\AcSignIcon.dll]  <Autodesk><16.0.0.86>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 3072][C:\Program Files\WinRAR\WinRAR.exe]  <N/A><N/A>
    [C:\WINDOWS\system32\AcSignIcon.dll]  <Autodesk><16.0.0.86>
[PID: 1704][C:\DOCUME~1\黄河\LOCALS~1\Temp\Rar$EX00.750\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\WINDOWS\system32\SYNCOR11.DLL]  <SoundMAX><1.2.3>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
gototop
 

(file missing)结尾的勾上修复..

修复
R3 - URLSearchHook: (no name) - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll (file missing)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\zh-cn\msntb.dll (file missing)
O3 - IE工具栏增项: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll (file missing)
O3 - IE工具栏增项: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\zh-cn\msntb.dll (file missing)
O3 - IE工具栏增项: 东方快车 - {3EA85E14-887D-4E2F-91E2-3158CE58ED62} - D:\Program Files\!Sunv\DFKC2003\IEBand.DLL (file missing)
O4 - Startup: 加班数.lnk = ?
O4 - Global Startup: ie-bar.lnk = ?
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present


http://www.pctutu.com/srmsdown.asp
下载超级兔子..用超级兔子清理王卸载流氓软件...(安全模式...)
gototop
 

下载超级兔子..用超级兔子清理王卸载流氓软件...(安全模式...)
我有装啊,只有个IE插件我没有卸载,还有个新浪点点通,看新闻的
这些不是病毒吧~~~~~~~~
gototop
 

流氓软件而已..
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT