1   1  /  1  页   跳转

[求助] SOS!!

SOS!!

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <360Safebox><"D:\Program Files\360\360safebox\safeboxTray.exe" /r>  [(Verified)Qizhi Software (beijing) Co. Ltd]
    <360Safetray><D:\Program Files\360\360Safe\safemon\360tray.exe /start>  [(Verified)Qizhi Software (beijing) Co. Ltd]
    <kugou><; D:\KuGou2008\KuGoo.exe min>  [File is missing]
    <StartCCC><"C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun>  [File is missing]
    <ULiRaid5289><C:\Program Files\ULI5289\ULi5289.exe>  [ALi Corporation]
    <Adobe Reader Speed Launcher><"C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe">  [(Verified)"Adobe Systems, Incorporated"]
    <egui><"C:\Documents and Settings\All Users\「开始」菜单\程序\ESET\ESET NOD32 Antivirus\ESET NOD32 Antivirus.lnk" /hide /waitservice>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Component Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Component Publisher]
    <CDBurn><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Component Publisher]
    <WebCheck><C:\WINDOWS\system32\webcheck.dll>  [(Verified)Microsoft Windows]
    <SysTray><C:\WINDOWS\system32\stobject.dll>  [(Verified)Microsoft Windows Publisher]
    <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
    <WinlogonNotify: ScCertProp><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
    <WinlogonNotify: Schedule><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    <WinlogonNotify: sclgntfy><sclgntfy.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
    <WinlogonNotify: termsrv><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
    <WinlogonNotify: wlballoon><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
    <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
    <Internet Explorer 版本更新><C:\WINDOWS\system32\ieudinit.exe>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    <Microsoft Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
    <Browser Customizations><"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
    <浏览器自定义组件><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
    <Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
    <Internet Explorer><C:\WINDOWS\system32\ie4uinit.exe -BaseSettings>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
    <N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\system32\logon.scr>  [(Verified)Microsoft Windows Publisher]

==================================
启动文件夹
[启动iTudou]
  <C:\Documents and Settings\Liy\「开始」菜单\程序\启动\启动iTudou.lnk --> D:\PROGRA~1\Tudou\iTudou\iTudou.exe [土豆网]><N>

==================================
服务
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart][Stopped/Auto Start]
  <C:\WINDOWS\system32\ati2sgag.exe><>
[Eset HTTP Server / EhttpSrv][Stopped/Manual Start]
  <"D:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe"><ESET>
[Eset Service / ekrn][Running/Auto Start]
  <"D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe"><ESET>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Hotspot Shield Service / HotspotShieldService][Running/Auto Start]
  <C:\Program Files\Hotspot Shield\bin\openvpnas.exe><N/A>
[Hotspot Shield Helper Service / HssSrv][Running/Auto Start]
  <C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe><AnchorFree Inc.>
[Hotspot Shield Tray Service / HssTrayService][Stopped/Manual Start]
  <C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE><N/A>
[Qvod Terminal / Qvod Terminal][Stopped/Auto Start]
  <d:\Program Files\快播(Qvod Player)3.0\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>
[Windows Live Setup Service / WLSetupSvc][Stopped/Manual Start]
  <"C:\Program Files\Windows Live\installer\WLSetupSvc.exe"><>

==================================
驱动程序
[360AntiArp / 360AntiArp][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
[aeaudio / aeaudio][Running/Manual Start]
  <system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[Service for WDM 3D Audio Driver / ALCXSENS][Stopped/Manual Start]
  <system32\drivers\ALCXSENS.SYS><Sensaura>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Stopped/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[ULi PCI to USB Enhanced Host Controller / ALIEHCD][Running/Auto Start]
  <System32\Drivers\ALIEHCI.sys><ULi Corporation>
[USB Composite Device / aligp][Stopped/Manual Start]
  <system32\DRIVERS\AliGP.sys><ULi Corporation>
[AliIde / AliIde][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\aliide.sys><ALi Corporation>
[aliperf / aliperf][Running/Boot Start]
  <\SystemRoot\system32\drivers\aliperf.sys><Windows (R) 2000 DDK provider>
[USB 2.0 Root Hub / aliroothub][Running/Manual Start]
  <system32\DRIVERS\AliRtHub.sys><ULi Corporation>
[ati2mtag / ati2mtag][Running/Manual Start]
  <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[eamon / eamon][Running/Auto Start]
  <system32\DRIVERS\eamon.sys><ESET>
[easdrv / easdrv][Running/System Start]
  <system32\DRIVERS\easdrv.sys><ESET>
[epfwtdir / epfwtdir][Running/System Start]
  <system32\DRIVERS\epfwtdir.sys><N/A>
[Lavalys EVEREST Kernel Driver / EverestDriver][Stopped/Manual Start]
  <\??\C:\Documents and Settings\Liy\桌面\新建文件夹 (2)\新建文件夹\EVERESTUltimate-v5.01\EVEREST Ultimate Edition\kerneld.wnt><N/A>
[Infoscape virtual NIC Adapter V8 / isvpn0806][Stopped/Manual Start]
  <system32\DRIVERS\isvpn0806.sys><The IsVPN Project>
[Infoscape virtual NIC Adapter V9 / isvpn0901][Stopped/Manual Start]
  <system32\DRIVERS\isvpn0901.sys><The XJGame Project>
[m5289 / m5289][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\m5289.sys><ULi Electronics Inc.>
[Mkd2kfNt / Mkd2kfNt][Stopped/Manual Start]
  <system32\drivers\Mkd2kfNt.sys><AhnLab, Inc.>
[Mkd2Nadr / Mkd2Nadr][Stopped/Manual Start]
  <system32\drivers\Mkd2Nadr.sys><AhnLab, Inc.>
[WinPcap Packet Driver (NPF) / NPF][Running/Manual Start]
  <system32\drivers\NPF.sys><CACE Technologies>
[DDK PACKET Protocol / Packet][Running/Manual Start]
  <system32\DRIVERS\ProtoDrv.sys><360安全中心>
[pcidump / pcidump][Stopped/Manual Start]
  <System32\DRIVERS\pcidump.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[QKeyServiceDisplay / QKeyService][Running/Boot Start]
  <\SystemRoot\system32\KeyCrypt.sys><Tencent Technology (Shenzhen) Company Limited>
[SafeBoxKrnl / SafeBoxKrnl][Running/System Start]
  <\??\C:\WINDOWS\system32\Drivers\safeboxkrnl.sys><360安全中心>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[smwdm / smwdm][Running/Manual Start]
  <system32\drivers\smwdm.sys><Analog Devices, Inc.>
[sptd / sptd][Running/Boot Start]
  <\SystemRoot\System32\Drivers\sptd.sys><N/A>
[TAP VPN Adapter / tapvpn][Running/Manual Start]
  <system32\DRIVERS\tapvpn.sys><The OpenVPN Project>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[TesSafe / TesSafe][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>
[ULi M526X Ethernet NT Driver / ULI5261XP][Running/Manual Start]
  <system32\DRIVERS\ULILAN51.SYS><ULi Electronics Inc.>
[ULi AGP Bus Filter Driver / uliagpkx][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\agpkx.sys><ULi Electronics Inc.>
[360FkAdv / 360FkAdv][Running/Manual Start]
  <2 - 系统找不到指定的文件。
><N/A>

==================================

用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; QQDownload 1.7; .NET CLR 2.0.50727; MAXTHON 2.0)
最后编辑天月来了 最后编辑于 2009-07-18 15:37:02
分享到:
gototop
 

SOS!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!2222

正在运行的进程
[PID: 748 / SYSTEM][\SystemRoot\System32\smss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 796 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 832 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4178]
    [C:\WINDOWS\system32\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.258]
[PID: 876 / SYSTEM][C:\WINDOWS\system32\services.exe]  [(Verified) Microsoft Corporation, 5.1.2600.3520 (xpsp_sp2_qfe.090206-1239)]
[PID: 888 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1052 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4222]
    [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2514]
    [C:\WINDOWS\system32\atipdlxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2550]
[PID: 1064 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.258]
[PID: 1176 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.258]
[PID: 1332 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.258]
[PID: 1384 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1416 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4222]
    [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2514]
    [C:\WINDOWS\system32\atipdlxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2550]
    [C:\WINDOWS\system32\ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4178]
[PID: 1516 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.258]
[PID: 1780 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
    [C:\WINDOWS\system32\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.258]
[PID: 200 / Liy][C:\WINDOWS\Explorer.EXE]  [(Verified) Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
    [C:\WINDOWS\system32\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.258]
    [D:\Program Files\360\360Safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1019]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 9.1.0.2009022700]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS]  [, ]
    [C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll]  [Advanced Micro Devices, Inc., 6.14.10.2001]
    [C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiamchs.dll]  [Advanced Micro Devices, Inc., 6.14.10.2001]
    [D:\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll]  [, 1, 0, 0, 12]
    [D:\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 13]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [d:\Program Files\快播(Qvod Player)3.0\QvodBand.dll]  [Shenzhen QVOD Technology Co.,Ltd, 3, 0, 0, 0]
    [D:\NamiRobot\Data\NamipanExt1.dll]  [N/A, ]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\YouKuDesktopShell.dll]  [www.youku.com, 1.2.7.1700]
    [C:\WINDOWS\system32\TudouUpload.dll]  [www.Tudou.com, 1.1.0.0]
    [D:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll]  [ESET, 3.0.684 ]
[PID: 284 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 444 / Liy][C:\Program Files\ULI5289\ULi5289.exe]  [ALi Corporation, 6, 0, 0, 3]
[PID: 532 / SYSTEM][C:\Program Files\Hotspot Shield\bin\openvpnas.exe]  [N/A, ]
    [C:\Program Files\Hotspot Shield\bin\libcurl.dll]  [The cURL library, http://curl.haxx.se/, 7.18.0]
    [C:\Program Files\Hotspot Shield\bin\libeay32.dll]  [N/A, ]
    [C:\Program Files\Hotspot Shield\bin\libssl32.dll]  [N/A, ]
[PID: 2224 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.258]
[PID: 2280 / Liy][C:\WINDOWS\system32\wscntfy.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\Program Files\360\360Safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1019]
[PID: 2872 / SYSTEM][D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe]  [ESET, 3.0.684 ]
    [D:\Program Files\ESET\ESET NOD32 Antivirus\ekrnScan.dll]  [ESET, 3.0.684 ]
    [D:\Program Files\ESET\ESET NOD32 Antivirus\ekrnAmon.dll]  [ESET, 3.0.684 ]
    [D:\Program Files\ESET\ESET NOD32 Antivirus\ekrnEmon.dll]  [ESET, 3.0.684 ]
    [D:\Program Files\ESET\ESET NOD32 Antivirus\ekrnEpfw.dll]  [ESET, 3.0.684 ]
    [D:\Program Files\ESET\ESET NOD32 Antivirus\ekrnUpdate.dll]  [ESET, 3.0.684 ]
    [D:\Program Files\ESET\ESET NOD32 Antivirus\updater.dll]  [ESET, 3.0.684 ]
    [D:\Program Files\ESET\ESET NOD32 Antivirus\ekrnMailPlugins.dll]  [ESET, 3.0.684 ]
    [C:\WINDOWS\system32\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.258]
[PID: 3748 / Liy][D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe]  [ESET, 3.0.684 ]
    [D:\Program Files\360\360Safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1019]
    [D:\Program Files\ESET\ESET NOD32 Antivirus\eguiScan.dll]  [ESET, 3.0.684 ]
    [D:\Program Files\ESET\ESET NOD32 Antivirus\eguiAmon.dll]  [ESET, 3.0.684 ]
    [D:\Program Files\ESET\ESET NOD32 Antivirus\eguiEmon.dll]  [ESET, 3.0.684 ]
    [D:\Program Files\ESET\ESET NOD32 Antivirus\eguiEpfw.dll]  [ESET, 3.0.684 ]
    [D:\Program Files\ESET\ESET NOD32 Antivirus\eguiUpdate.dll]  [ESET, 3.0.684 ]
    [D:\Program Files\ESET\ESET NOD32 Antivirus\eguiMailPlugins.dll]  [ESET, 3.0.684 ]
[PID: 948 / Liy][C:\WINDOWS\system32\conime.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\Program Files\360\360Safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1019]
[PID: 3244 / SYSTEM][C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe]  [AnchorFree Inc., 1, 0, 0, 1]
    [C:\WINDOWS\system32\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.258]
[PID: 3216 / Liy][C:\WINDOWS\system32\ctfmon.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\Program Files\360\360Safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1019]
[PID: 3116 / Liy][D:\360compkill\SuperKiller.exe]  [360安全中心, 4, 0, 0, 1013]
    [D:\360compkill\BugRePort.dll]  [360安全中心, 1, 0, 0, 1001]
    [D:\360compkill\FrontScan.dll]  [360安全中心, 1, 0, 0, 1002]
    [D:\360compkill\BFsAndReg.dll]  [360安全中心, 1, 0, 0, 1002]
    [D:\360compkill\BREGDLL.dll]  [360安全中心, 1, 0, 0, 1005]
    [D:\360compkill\bfsdll.dll]  [360安全中心, 1, 0, 0, 1006]
    [D:\360compkill\SysRepairLog.dll]  [360安全中心, 1, 0, 0, 1001]
    [D:\360compkill\deepscan.dll]  [360安全中心, 1, 0, 0, 1013]
    [D:\360compkill\ave.dll]  [360安全中心, 1, 0, 0, 1002]
    [D:\360compkill\sysfilerep.dll]  [360安全中心, 2, 0, 0, 1001]
    [D:\360compkill\360wservice.dll]  [360安全中心, 1, 0, 0, 1007]
    [D:\360compkill\AutorunFixer.dll]  [360安全中心, 1, 0, 0, 1004]
    [D:\360compkill\AutoRunKiller.dll]  [360安全中心, 1, 0, 0, 1001]
    [D:\360compkill\AntiDllHiJack.dll]  [360安全中心, 1, 0, 0, 1004]
    [D:\360compkill\360verify.dll]  [360安全中心, 1, 0, 0, 1003]
    [D:\360compkill\NetService.dll]  [360安全中心, 1, 0, 0, 1001]
    [D:\360compkill\sqlite3.dll]  [N/A, ]
    [D:\360compkill\SeclutionCallBack.dll]  [qihoo, 1, 0, 0, 1002]
    [D:\360compkill\AntiWriteBack.dll]  [360安全中心, 1, 0, 0, 1001]
    [D:\360compkill\spkill.dll]  [360安全中心, 1, 0, 0, 1002]
[PID: 292 / Liy][C:\DOCUME~1\Liy\LOCALS~1\Temp\Rar$EX00.453\SREngLdr.EXE]  [Smallfrogs Studio, 2.7.1.1261]
[PID: 3008 / Liy][C:\DOCUME~1\Liy\LOCALS~1\Temp\Rar$EX00.453\SRE795f4ec7.EXE]  [Smallfrogs Studio, 2.7.1.1261]
    [D:\Program Files\360\360Safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1019]
    [C:\DOCUME~1\Liy\LOCALS~1\Temp\Rar$EX00.453\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
    [C:\WINDOWS\system32\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.258]
==================================
文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; QQDownload 1.7; .NET CLR 2.0.50727; MAXTHON 2.0)
gototop
 

回复:SOS!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

楼主电脑出现什么问题了?
好像这个东西要删掉:c:\windows\system32\drivers\pcidump.sys
注册表中这项删掉:
[pcidump / pcidump][Stopped/Manual Start]
  <System32\DRIVERS\pcidump.sys><N/A>
其他的没看出来

ps: 楼主还是把日志以附件形式发上来,看着方便一些
gototop
 

求助啊~!机子上网超慢。。。。。。。。

前几天机子中过一次毒,搞了半天才杀掉。。弄的差点格机子。。NOD32和360顽固木马都查不到毒了。但就是上网总是特卡。。不知道怎么回事。。搞的我很郁闷。。望高人能帮忙解决下。。。。。。。。。。。。。

用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; QQDownload 1.7; .NET CLR 2.0.50727; MAXTHON 2.0)

附件附件:

下载次数:140
文件类型:application/octet-stream
文件大小:
上传时间:2009-7-18 15:26:51
描述:log

gototop
 

回复:SOS!!

高人指点下啊~~~~~~~~~~~
gototop
 

回复:SOS!!

先去卸载所有你已装的安全软件、杀毒软件,再观察看情况如何

如果还不行,就去继续卸载所有非Windows的后来安装的各种软件

例如什么土豆类软件
百年以后,你的墓碑旁 刻着的名字不是我
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT