1   1  /  1  页   跳转

好象中了winsec.exe

好象中了winsec.exe

前几天玩游戏的是时候网镖突然出现询问是否让C:\WINDOWS\system32\winsec.exe通道~~~~我禁止了,可是后来开网页都开不开的说,上网查相关的winsec.exe都说是病毒,可以不让通过的话我都打不开网页的说
现在也是让它通过了才上能上论坛滴~~~~~55555555~~~~~~不知道会不会有问题呀~~~
请斑斑救救偶啊~~~~~

顺便帮偶看看那些东西可以不要呢,麻烦斑斑大人了!!

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [Microsoft Corporation]
    <iDuba Personal FireWall><C:\KAV6\Kavpfw.EXE>  [Kingsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <SoundMan><SOUNDMAN.EXE>  [Avance Logic, Inc.]
    <NvCplDaemon><RUNDLL32.EXE NvQTwk,NvCplDaemon initialize>  []
    <nwiz><nwiz.exe /install>  []
    <BigDogPath><C:\WINDOWS\VM_STI.EXE USB PC Camera 301P>  []
    <KAVRun><C:\KAV6\KAVRun.EXE>  [kingsoft]
    <Kulansyn><C:\KAV6\Kulansyn.EXE>  [Kingsoft Corp.]
    <KpopMon><C:\KAV6\KpopMon.EXE>  []
    <iDuba Personal FireWall><C:\KAV6\Kavpfw.EXE>  [Kingsoft Corporation]
    <ISC_UpDate><>  []
    <ISC><>  []
    <StormCodec_Helper><"e:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  []
    <cesmain.dll><rem ; >  []
    <helper.dll><rem ; >  []
    <IMJPMIG8.1><rem ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <MyIMLite><rem ; >  []
    <PHIME2002A><rem ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <PHIME2002ASync><rem ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><>  []

==================================
启动文件夹
[Adobe Gamma Loader]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>

==================================
服务
[C-DillaCdaC11BA / C-DillaCdaC11BA]
  <C:\WINDOWS\System32\drivers\CDAC11BA.EXE><N/A>
[C-DillaSrv / C-DillaSrv]
  <C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE><C-Dilla Ltd>
[Canon Camera Access Library 8 / CCALib8]
  <C:\Program Files\Canon\CAL\CALMAIN.exe><Canon Inc.>
[DCPFLICS / DCPFLICS]
  <C:\Program Files\DCPFLICS\DCPFLICS.exe><N/A>
[Kingsoft AntiVirus Service / KAVSvc]
  <C:\KAV6\KAVSvc.EXE><kingsoft Antivirus>
[Macromedia Licensing Service / Macromedia Licensing Service]
  <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[Network service / Network service]
  <C:\WINDOWS\system32\Netservice.exe><N/A>
[Leadtek Driver Helper Service / nvsvc]
  <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[PsShutdown / PsShutdownSvc]
  <C:\WINDOWS\System32\PSSDNSVC.EXE><N/A>
[Windows Security / Windows Security]
  <C:\WINDOWS\System32\Winsec.exe><N/A>

==================================
浏览器加载项
[MusicSearch Class]
  {3D33EAE4-9EAA-4542-BCC8-9A9061392D56} <, N/A>
[Router Layer]
  {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} <, N/A>
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~1\FLASHGET\jccatch.dll, Amaze Soft>
[解霸]
  {367E0A21-8601-4986-9C9A-153BF5ACA118} <E:\Program Files\豪杰3000\MPLAYER.EXE, N/A>
[金山卓越]
  {8DE0FCD4-5EB5-11D3-AD25-00002100131B} <url:http://www.joyo.com, N/A>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[FlashGet]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft>
[金山毒霸网站]
  {e1fc9760-7b95-49cd-80b9-8c9e41017b93} <url:http://www.duba.net, N/A>
[在线查毒]
  {f58d36c3-40be-4418-a786-d8fbe3eb3554} <C:\KAV6\kavie.HTM, N/A>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\MSMSGS.EXE, Microsoft Corporation>
[金山毒霸]
  {A9BE2902-C447-420A-BB7F-A5DE921E6138} <C:\KAV6\KAIEPlus.DLL, >
[Shockwave ActiveX Control]
  {166B1BCA-3F9C-11CF-8075-444553540000} <C:\WINDOWS\System32\macromed\Shockwave 10\Download.dll, Macromedia, Inc.>
[InstaFred]
  {1F831FA1-42FC-11D4-95A6-0080AD30DCE1} <C:\WINDOWS\DOWNLO~1\InstFred.ocx, Autodesk, Inc.>
[PowerPlr Control]
  {2354A44B-3CEB-4829-9940-545B03103538} <C:\WINDOWS\DOWNLO~1\PowerPlr.ocx, Powerise Digital>
[LSInstall Class]
  {41A28BC3-6B52-437B-B6CF-F055D0CFC69A} <C:\WINDOWS\Downloaded Program Files\LSInstall.dll, >
[DIYBAR]
  {58CDB34C-B4D7-418B-A0FB-C4C8A01C2F0E} <C:\WINDOWS\System32\51.net\diybar\diybar.dll, 北京金络神电子商务有限责任公司>
[AcDcToday 控件]
  {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} <C:\WINDOWS\DOWNLO~1\ACDCTO~1.OCX, Autodesk>
[Qzone Media Tools]
  {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} <C:\WINDOWS\System32\QZONEM~1.OCX, Tencent Technology (Shenzhen) Company Limited>
[NOXLATE-BANR]
  {AE563722-B4F5-11D4-A415-00108302FDFD} <C:\WINDOWS\DOWNLO~1\InstBanr.ocx, Autodesk, Inc.>
[Blueskyvoice Control]
  {BA0F088C-72C1-475A-92F8-42391DEF6961} <C:\WINDOWS\DOWNLO~1\BLUESK~1.OCX, 蓝天工作室(http://www.bluesky.cn)>
[ImgProcessControl Class]
  {BD1B565A-347F-4666-847F-403EAE910A15} <C:\WINDOWS\DOWNLO~1\IMGPRO~1.DLL, >
[WebEngine Control]
  {C2B9EE9C-D9E4-4C35-A7B2-62AE1D9E2997} <C:\WINDOWS\DOWNLO~1\WEBENG~1.OCX, 江苏天泽信息产业>
[cycnset Class]
  {C50341E9-CDC1-4377-AB88-3486CCD0FDA1} <C:\WINDOWS\System32\cycnset.dll, ? SK Communications>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[PowerDld Control]
  {DF6FE46D-1D23-4668-AD3A-CDEA1262B282} <C:\WINDOWS\DOWNLO~1\PowerDld.ocx, Powerise Digital>
[AcPreview 控件]
  {F281A59C-7B65-11D3-8617-0010830243BD} <C:\WINDOWS\DOWNLO~1\ACPREV~1.OCX, Autodesk>
[SHLaunch Control]
  {FA463B6E-93D5-4E02-B7F2-E0BA98DA73FC} <C:\WINDOWS\System32\SHLaunch.ocx, >
[上传到QQ网络硬盘]
  <E:\Program Files\新版QQ\IPQQ2006\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <E:\Program Files\新版QQ\IPQQ2006\AddPanel.htm, N/A>
[添加到QQ表情]
  <E:\Program Files\新版QQ\IPQQ2006\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <E:\Program Files\新版QQ\IPQQ2006\SendMMS.htm, N/A>
最后编辑2006-08-11 23:39:53
分享到:
gototop
 

==================================
正在运行的进程
[PID: 596][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 668][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 692][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.1557 (xpsp2_gdr.040517-1325)>
    [C:\WINDOWS\system32\NetserviceKey.DLL]  <N/A><N/A>
[PID: 736][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 748][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 900][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 924][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1128][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1152][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1408][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
    [C:\WINDOWS\system32\NetserviceKey.DLL]  <N/A><N/A>
    [C:\PROGRA~1\FLASHGET\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\KAV6\KAVEXT.DLL]  <Kingsoft Corp.><2002, 5, 24, 6>
    [C:\Program Files\Real\RealOne Player\rpshell.dll]  <RealNetworks, Inc.><1.0.1.2021>
    [C:\WINDOWS\System32\PNCRT.dll]  <Real Networks, Inc><6.0.0.0>
    [C:\Program Files\Real\RealOne Player\lang\rpext_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
[PID: 1468][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.0 (XPClient.010817-1148)>
[PID: 1548][C:\WINDOWS\SOUNDMAN.EXE]  <Avance Logic, Inc.><5, 0, 0, 0>
    [C:\WINDOWS\system32\NetserviceKey.DLL]  <N/A><N/A>
[PID: 1576][C:\WINDOWS\VM_STI.EXE]  <VM.><4.2.610.4>
    [C:\WINDOWS\System32\msdmo.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\NetserviceKey.DLL]  <N/A><N/A>
[PID: 1600][C:\KAV6\KpopMon.EXE]  <><2004, 2, 2, 31>
    [C:\KAV6\KAVMLM.DLL]  <Kingsoft Corporation><2003.11.12.10>
    [C:\WINDOWS\system32\NetserviceKey.DLL]  <N/A><N/A>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 1608][C:\KAV6\Kavpfw.EXE]  <Kingsoft Corporation><2004, 8, 16, 295>
    [C:\KAV6\KAVMLM.DLL]  <Kingsoft Corporation><2003.11.12.10>
    [C:\KAV6\PFWScanC.dll]  <KingSoft><2002, 4, 12, 3>
    [C:\KAV6\KAMsgBox.dll]  <><2002.9.27.30>
    [C:\KAV6\NetShare.dll]  <Kingsoft Antivirus><2004, 2, 20, 67>
    [C:\KAV6\KAEPlat.DLL]  <Kingsoft Corp.><2005, 12, 29, 56>
    [C:\KAV6\KAEMem.DAT]  <Kingsoft><2006, 4, 12, 13>
    [C:\KAV6\KAEUnpack.DAT]  <Kingsoft Corp.><2006, 6, 15, 44>
    [C:\KAV6\KAEQSCAN.DLL]  <Kingsoft Corp><2004, 3, 26, 69>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
    [C:\KAV6\KAVLogFn.dll]  <N/A><2003, 11, 26, 16>
    [C:\WINDOWS\system32\NetserviceKey.DLL]  <N/A><N/A>
[PID: 1760][C:\KAV6\KWatchUI.EXE]  <><2004.1.6.119>
    [C:\KAV6\kavcomm.dll]  <Kingsoft Corporation><2003, 11, 12, 66>
    [C:\KAV6\kavdlg.dll]  <><2004.7.20.81>
    [C:\KAV6\KAVMLM.DLL]  <Kingsoft Corporation><2003.11.12.10>
    [C:\KAV6\RpcBrge.DLL]  <kingsoft><2003, 11, 12, 64>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
    [C:\WINDOWS\system32\NetserviceKey.DLL]  <N/A><N/A>
[PID: 1792][C:\WINDOWS\System32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\system32\NetserviceKey.DLL]  <N/A><N/A>
[PID: 2024][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 2036][C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE]  <C-Dilla Ltd><3.25.010>
[PID: 112][C:\Program Files\DCPFLICS\DCPFLICS.exe]  <N/A><N/A>
[PID: 208][C:\KAV6\KAVSvc.EXE]  <kingsoft Antivirus><2003, 11, 12, 70>
    [C:\KAV6\SvcComm.dll]  <kingsoft Antivirus><2004, 7, 28, 1>
    [C:\KAV6\SvcTimer.DLL]  <Kingsoft><2004.4.29.79>
    [C:\KAV6\KavComm.dll]  <Kingsoft Corporation><2003, 11, 12, 66>
    [C:\KAV6\RpcBrge.DLL]  <kingsoft><2003, 11, 12, 64>
    [C:\KAV6\KWatchFn2.dll]  <kingsoft Corporation><2004, 8, 24, 25>
    [C:\KAV6\KAEPlat.DLL]  <Kingsoft Corp.><2005, 12, 29, 56>
    [C:\KAV6\KAEMem.DAT]  <Kingsoft><2006, 4, 12, 13>
    [C:\KAV6\KAEUnpack.DAT]  <Kingsoft Corp.><2006, 6, 15, 44>
    [C:\KAV6\KAVUtils.dll]  <Kingsoft Corp><2004, 2, 12, 69>
    [C:\KAV6\KAVDlg.DLL]  <><2004.7.20.81>
    [C:\KAV6\KAVLogFn.dll]  <N/A><2003, 11, 26, 16>
    [C:\WINDOWS\system32\NetserviceKey.DLL]  <N/A><N/A>
[PID: 380][C:\KAV6\MailMon.EXE]  <Kingsoft Co., Ltd><2004, 2, 6, 245>
    [C:\KAV6\KMFilter.DLL]  <><2004, 3, 1, 37>
    [C:\KAV6\parse822.dll]  <Quiksoft Corporation><2, 0, 0, 9>
    [C:\KAV6\KAVLogFn.dll]  <N/A><2003, 11, 26, 16>
    [C:\KAV6\KAVMLM.DLL]  <Kingsoft Corporation><2003.11.12.10>
    [C:\KAV6\KAMsgBox.DLL]  <><2002.9.27.30>
    [C:\KAV6\KAVComm.dll]  <Kingsoft Corporation><2003, 11, 12, 66>
    [C:\KAV6\RpcBrge.DLL]  <kingsoft><2003, 11, 12, 64>
    [C:\KAV6\KAVIPC.DLL]  <Kingsoft Corp.><2002, 3, 29, 8>
    [C:\KAV6\KAVDlg.DLL]  <><2004.7.20.81>
    [C:\KAV6\KAECall.DLL]  <Kingsoft Corporation><2003, 11, 14, 66>
    [C:\KAV6\KAEScan.DLL]  <Kingsoft Corp.><2003, 5, 24, 36>
    [C:\KAV6\KAEPlat.DLL]  <Kingsoft Corp.><2005, 12, 29, 56>
    [C:\KAV6\KAEMem.DAT]  <Kingsoft><2006, 4, 12, 13>
    [C:\KAV6\KAEUnpack.DAT]  <Kingsoft Corp.><2006, 6, 15, 44>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
    [C:\WINDOWS\system32\NetserviceKey.DLL]  <N/A><N/A>
[PID: 456][C:\WINDOWS\System32\nvsvc32.exe]  <NVIDIA Corporation><6.13.10.2750>
    [C:\WINDOWS\system32\NetserviceKey.DLL]  <N/A><N/A>
[PID: 508][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 552][C:\KAV6\KAVPlus.EXE]  <><2004, 3, 3, 71>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
    [C:\WINDOWS\system32\NetserviceKey.DLL]  <N/A><N/A>
[PID: 672][C:\Program Files\Canon\CAL\CALMAIN.exe]  <Canon Inc.><8, 0, 0, 21>
[PID: 636][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\system32\NetserviceKey.DLL]  <N/A><N/A>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
    [C:\PROGRA~1\FLASHGET\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
    [C:\KAV6\KAVEXT.DLL]  <Kingsoft Corp.><2002, 5, 24, 6>
[PID: 3132][F:\光盘快件\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\WINDOWS\system32\NetserviceKey.DLL]  <N/A><N/A>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 

PsShutdown / PsShutdownSvc]
<C:\WINDOWS\System32\PSSDNSVC.EXE><N/A>
不知道这个是啥,偶是菜鸟……|||||

我先有木马专杀沙了毒,然后按照大人的方法把东西都删了,可是重启后我找不到
C:\WINDOWS\system32\NetserviceKey.DLL
C:\WINDOWS\system32\Netservice.exe
C:\WINDOWS\System32\Winsec.exe
这个不要紧吧~~~

2006-08-11,23:16:21

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [Microsoft Corporation]
    <iDuba Personal FireWall><C:\KAV6\Kavpfw.EXE>  [Kingsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <SoundMan><SOUNDMAN.EXE>  [Avance Logic, Inc.]
    <NvCplDaemon><RUNDLL32.EXE NvQTwk,NvCplDaemon initialize>  []
    <nwiz><nwiz.exe /install>  []
    <BigDogPath><C:\WINDOWS\VM_STI.EXE USB PC Camera 301P>  []
    <KAVRun><C:\KAV6\KAVRun.EXE>  [kingsoft]
    <Kulansyn><C:\KAV6\Kulansyn.EXE>  [Kingsoft Corp.]
    <KpopMon><C:\KAV6\KpopMon.EXE>  []
    <iDuba Personal FireWall><C:\KAV6\Kavpfw.EXE>  [Kingsoft Corporation]
    <ISC_UpDate><>  []
    <ISC><>  []
    <StormCodec_Helper><"e:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>  []
    <cesmain.dll><rem ; >  []
    <helper.dll><rem ; >  []
    <IMJPMIG8.1><rem ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <MyIMLite><rem ; >  []
    <PHIME2002A><rem ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <PHIME2002ASync><rem ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><>  []

==================================
启动文件夹
[Adobe Gamma Loader]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>

==================================
服务
[C-DillaCdaC11BA / C-DillaCdaC11BA]
  <C:\WINDOWS\System32\drivers\CDAC11BA.EXE><N/A>
[C-DillaSrv / C-DillaSrv]
  <C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE><C-Dilla Ltd>
[Canon Camera Access Library 8 / CCALib8]
  <C:\Program Files\Canon\CAL\CALMAIN.exe><Canon Inc.>
[DCPFLICS / DCPFLICS]
  <C:\Program Files\DCPFLICS\DCPFLICS.exe><N/A>
[Kingsoft AntiVirus Service / KAVSvc]
  <C:\KAV6\KAVSvc.EXE><kingsoft Antivirus>
[Macromedia Licensing Service / Macromedia Licensing Service]
  <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[Leadtek Driver Helper Service / nvsvc]
  <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[PsShutdown / PsShutdownSvc]
  <C:\WINDOWS\System32\PSSDNSVC.EXE><N/A>

gototop
 

==================================
浏览器加载项
[MusicSearch Class]
  {3D33EAE4-9EAA-4542-BCC8-9A9061392D56} <, N/A>
[Router Layer]
  {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} <, N/A>
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~1\FLASHGET\jccatch.dll, Amaze Soft>
[解霸]
  {367E0A21-8601-4986-9C9A-153BF5ACA118} <E:\Program Files\豪杰3000\MPLAYER.EXE, N/A>
[金山卓越]
  {8DE0FCD4-5EB5-11D3-AD25-00002100131B} <url:http://www.joyo.com, N/A>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[FlashGet]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft>
[金山毒霸网站]
  {e1fc9760-7b95-49cd-80b9-8c9e41017b93} <url:http://www.duba.net, N/A>
[在线查毒]
  {f58d36c3-40be-4418-a786-d8fbe3eb3554} <C:\KAV6\kavie.HTM, N/A>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\MSMSGS.EXE, Microsoft Corporation>
[金山毒霸]
  {A9BE2902-C447-420A-BB7F-A5DE921E6138} <C:\KAV6\KAIEPlus.DLL, >
[Shockwave ActiveX Control]
  {166B1BCA-3F9C-11CF-8075-444553540000} <C:\WINDOWS\System32\macromed\Shockwave 10\Download.dll, Macromedia, Inc.>
[InstaFred]
  {1F831FA1-42FC-11D4-95A6-0080AD30DCE1} <C:\WINDOWS\DOWNLO~1\InstFred.ocx, Autodesk, Inc.>
[PowerPlr Control]
  {2354A44B-3CEB-4829-9940-545B03103538} <C:\WINDOWS\DOWNLO~1\PowerPlr.ocx, Powerise Digital>
[LSInstall Class]
  {41A28BC3-6B52-437B-B6CF-F055D0CFC69A} <C:\WINDOWS\Downloaded Program Files\LSInstall.dll, >
[DIYBAR]
  {58CDB34C-B4D7-418B-A0FB-C4C8A01C2F0E} <C:\WINDOWS\System32\51.net\diybar\diybar.dll, N/A>
[AcDcToday 控件]
  {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} <C:\WINDOWS\DOWNLO~1\ACDCTO~1.OCX, Autodesk>
[Qzone Media Tools]
  {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} <C:\WINDOWS\System32\QZONEM~1.OCX, Tencent Technology (Shenzhen) Company Limited>
[NOXLATE-BANR]
  {AE563722-B4F5-11D4-A415-00108302FDFD} <C:\WINDOWS\DOWNLO~1\InstBanr.ocx, Autodesk, Inc.>
[Blueskyvoice Control]
  {BA0F088C-72C1-475A-92F8-42391DEF6961} <C:\WINDOWS\DOWNLO~1\BLUESK~1.OCX, 蓝天工作室(http://www.bluesky.cn)>
[ImgProcessControl Class]
  {BD1B565A-347F-4666-847F-403EAE910A15} <C:\WINDOWS\DOWNLO~1\IMGPRO~1.DLL, >
[WebEngine Control]
  {C2B9EE9C-D9E4-4C35-A7B2-62AE1D9E2997} <C:\WINDOWS\DOWNLO~1\WEBENG~1.OCX, 江苏天泽信息产业>
[cycnset Class]
  {C50341E9-CDC1-4377-AB88-3486CCD0FDA1} <C:\WINDOWS\System32\cycnset.dll, ? SK Communications>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[PowerDld Control]
  {DF6FE46D-1D23-4668-AD3A-CDEA1262B282} <C:\WINDOWS\DOWNLO~1\PowerDld.ocx, Powerise Digital>
[AcPreview 控件]
  {F281A59C-7B65-11D3-8617-0010830243BD} <C:\WINDOWS\DOWNLO~1\ACPREV~1.OCX, Autodesk>
[SHLaunch Control]
  {FA463B6E-93D5-4E02-B7F2-E0BA98DA73FC} <C:\WINDOWS\System32\SHLaunch.ocx, >
[上传到QQ网络硬盘]
  <E:\Program Files\新版QQ\IPQQ2006\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <E:\Program Files\新版QQ\IPQQ2006\AddPanel.htm, N/A>
[添加到QQ表情]
  <E:\Program Files\新版QQ\IPQQ2006\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <E:\Program Files\新版QQ\IPQQ2006\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 596][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 668][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 692][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.1557 (xpsp2_gdr.040517-1325)>
[PID: 736][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 748][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 900][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 924][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1128][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1144][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1408][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
    [C:\PROGRA~1\FLASHGET\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
[PID: 1452][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.0 (XPClient.010817-1148)>
[PID: 1548][C:\WINDOWS\SOUNDMAN.EXE]  <Avance Logic, Inc.><5, 0, 0, 0>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 1576][C:\WINDOWS\VM_STI.EXE]  <VM.><4.2.610.4>
    [C:\WINDOWS\System32\msdmo.dll]  <N/A><N/A>
[PID: 1600][C:\KAV6\KpopMon.EXE]  <><2004, 2, 2, 31>
    [C:\KAV6\KAVMLM.DLL]  <Kingsoft Corporation><2003.11.12.10>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 1620][C:\KAV6\Kavpfw.EXE]  <Kingsoft Corporation><2004, 8, 16, 295>
    [C:\KAV6\KAVMLM.DLL]  <Kingsoft Corporation><2003.11.12.10>
    [C:\KAV6\PFWScanC.dll]  <KingSoft><2002, 4, 12, 3>
    [C:\KAV6\KAMsgBox.dll]  <><2002.9.27.30>
    [C:\KAV6\NetShare.dll]  <Kingsoft Antivirus><2004, 2, 20, 67>
    [C:\KAV6\KAEPlat.DLL]  <Kingsoft Corp.><2005, 12, 29, 56>
    [C:\KAV6\KAEMem.DAT]  <Kingsoft><2006, 4, 12, 13>
    [C:\KAV6\KAEUnpack.DAT]  <Kingsoft Corp.><2006, 6, 15, 44>
    [C:\KAV6\KAEQSCAN.DLL]  <Kingsoft Corp><2004, 3, 26, 69>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
    [C:\KAV6\KAVLogFn.dll]  <N/A><2003, 11, 26, 16>
[PID: 1680][C:\KAV6\KWatchUI.EXE]  <><2004.1.6.119>
    [C:\KAV6\kavcomm.dll]  <Kingsoft Corporation><2003, 11, 12, 66>
    [C:\KAV6\kavdlg.dll]  <><2004.7.20.81>
    [C:\KAV6\KAVMLM.DLL]  <Kingsoft Corporation><2003.11.12.10>
    [C:\KAV6\RpcBrge.DLL]  <kingsoft><2003, 11, 12, 64>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 1812][C:\WINDOWS\System32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 2032][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 2044][C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE]  <C-Dilla Ltd><3.25.010>
[PID: 164][C:\Program Files\DCPFLICS\DCPFLICS.exe]  <N/A><N/A>
[PID: 208][C:\KAV6\KAVSvc.EXE]  <kingsoft Antivirus><2003, 11, 12, 70>
    [C:\KAV6\SvcComm.dll]  <kingsoft Antivirus><2004, 7, 28, 1>
    [C:\KAV6\SvcTimer.DLL]  <Kingsoft><2004.4.29.79>
    [C:\KAV6\KavComm.dll]  <Kingsoft Corporation><2003, 11, 12, 66>
    [C:\KAV6\RpcBrge.DLL]  <kingsoft><2003, 11, 12, 64>
    [C:\KAV6\KWatchFn2.dll]  <kingsoft Corporation><2004, 8, 24, 25>
    [C:\KAV6\KAEPlat.DLL]  <Kingsoft Corp.><2005, 12, 29, 56>
    [C:\KAV6\KAEMem.DAT]  <Kingsoft><2006, 4, 12, 13>
    [C:\KAV6\KAEUnpack.DAT]  <Kingsoft Corp.><2006, 6, 15, 44>
    [C:\KAV6\KAVUtils.dll]  <Kingsoft Corp><2004, 2, 12, 69>
    [C:\KAV6\KAVDlg.DLL]  <><2004.7.20.81>
    [C:\KAV6\KAVLogFn.dll]  <N/A><2003, 11, 26, 16>
[PID: 272][C:\WINDOWS\System32\nvsvc32.exe]  <NVIDIA Corporation><6.13.10.2750>
[PID: 320][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 396][C:\KAV6\MailMon.EXE]  <Kingsoft Co., Ltd><2004, 2, 6, 245>
    [C:\KAV6\KMFilter.DLL]  <><2004, 3, 1, 37>
    [C:\KAV6\parse822.dll]  <Quiksoft Corporation><2, 0, 0, 9>
    [C:\KAV6\KAVLogFn.dll]  <N/A><2003, 11, 26, 16>
    [C:\KAV6\KAVMLM.DLL]  <Kingsoft Corporation><2003.11.12.10>
    [C:\KAV6\KAMsgBox.DLL]  <><2002.9.27.30>
    [C:\KAV6\KAVComm.dll]  <Kingsoft Corporation><2003, 11, 12, 66>
    [C:\KAV6\RpcBrge.DLL]  <kingsoft><2003, 11, 12, 64>
    [C:\KAV6\KAVDlg.DLL]  <><2004.7.20.81>
    [C:\KAV6\KAECall.DLL]  <Kingsoft Corporation><2003, 11, 14, 66>
    [C:\KAV6\KAEScan.DLL]  <Kingsoft Corp.><2003, 5, 24, 36>
    [C:\KAV6\KAEPlat.DLL]  <Kingsoft Corp.><2005, 12, 29, 56>
    [C:\KAV6\KAEMem.DAT]  <Kingsoft><2006, 4, 12, 13>
    [C:\KAV6\KAEUnpack.DAT]  <Kingsoft Corp.><2006, 6, 15, 44>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 664][C:\KAV6\KAVPlus.EXE]  <><2004, 3, 3, 71>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
[PID: 948][C:\Program Files\Canon\CAL\CALMAIN.exe]  <Canon Inc.><8, 0, 0, 21>
[PID: 1748][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>
    [C:\PROGRA~1\FLASHGET\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
    [C:\KAV6\KAVEXT.DLL]  <Kingsoft Corp.><2002, 5, 24, 6>
    [C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
[PID: 1872][F:\光盘快件\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\KAV6\KMailFun.dll]  <Kingsoft Co., Ltd><2005, 4, 28, 227>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

找到个NetserviceKey.log的文件,请问这个是病毒吗?
gototop
 

真的太感谢大人了~~~~~
现在赶快改密码去~~5555555~~~~
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT