1   1  /  1  页   跳转

求助!求助!

求助!求助!

谁帮我看看啊!有问题了!启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
<Super Rabbit IEPro><D:\Program Files\1\1\SRIECLI.EXE /LOAD> [Super Rabbit Soft]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher]
<IgfxTray><C:\WINDOWS\system32\igfxtray.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<HotKeysCmds><C:\WINDOWS\system32\hkcmd.exe> [(Verified)Microsoft Windows Publisher]
<SoundMan><SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{BF8C444B-444B-F8CC-4BF8-44B8C44BF8CC}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\444BF8CC.dll
最后编辑2007-05-21 17:13:54
分享到:
gototop
 

服务
[Fast Client / fast][Stopped/Auto Start]
<C:\WINDOWS\system32\23f1.exe><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Fax 2Client / ms_2fax][Stopped/Auto Start]
<C:\WINDOWS\system32\b8731.exe><N/A>
[SysWindowsScriptHost / WindowsScriptHost][Running/Auto Start]
<C:\Windows\system32\HMTZHNUAHNUAHOU.EXE><N/A>
gototop
 

驱动程序
[acpidisk / acpidisk][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter / AN983][Running/Manual Start]
<system32\DRIVERS\AN983.sys><ADMtek Incorporated.>
[bwzjeo6 / bwzjeo64][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\bwzjeo64.sys><N/A>
[fjidh / fjidhk][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\fjidhk.sys><N/A>
[gkvhwa / gkvhwa][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\gkvhwa.sys><N/A>
[ialm / ialm][Running/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[nqvbp / nqvbpw][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\nqvbpw.sys><N/A>
[opfmit / opfmit][Running/Boot Start]
<\SystemRoot\system32\drivers\opfmit.sys><N/A>
[pksyj / pksyjk][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\pksyjk.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[vkshhg2 / vkshhg20][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\vkshhg20.sys><Microsoft Corporation>
[wngafc0 / wngafc03][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\wngafc03.sys><Microsoft Corporation>
[Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/System Start]
<system32\drivers\ialmsbw.sys><Intel Corporation>
[Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start]
<system32\drivers\ialmkchw.sys><Intel Corporation>


gototop
 

浏览器加载项
[Jpeg Class]
{4970DA77-DB06-4EB9-AAB5-77AF0CC77310} <C:\WINDOWS\system32\b23f.dll, TODO: <公司名>>
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <D:\Program Files\1\1\haokanbar.dll, Xiang Feng Technology>
[ISBJSBKTCLUDMVD]
{8CEF0E2D-282F-4AB7-A088-6AE519307CF6} <C:\WINDOWS\system32\HOWDKRXEKRXELRY.DLL, N/A>
[ff Class]
{FAAAC0F6-94BE-4466-934B-7C53666A2F41} <C:\WINDOWS\system32\1b81.dll, TODO: <公司名>>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Info cache]
{385AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll, N/A>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <D:\Program Files\1\1\haokanbar.dll, Xiang Feng Technology>
[Jpeg Class]
{4970DA77-DB06-4EB9-AAB5-77AF0CC77310} <C:\WINDOWS\system32\b23f.dll, TODO: <公司名>>
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <D:\Program Files\1\1\haokanbar.dll, Xiang Feng Technology>
[ISBJSBKTCLUDMVD]
{8CEF0E2D-282F-4AB7-A088-6AE519307CF6} <C:\WINDOWS\system32\HOWDKRXEKRXELRY.DLL, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\flash.ocx, Macromedia, Inc.>
[ff Class]
{FAAAC0F6-94BE-4466-934B-7C53666A2F41} <C:\WINDOWS\system32\1b81.dll, TODO: <公司名>>

gototop
 

正在运行的进程
[PID: 452][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 516][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 540][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\winlib .dll] [N/A, ]
[PID: 584][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 596][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 748][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 792][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 860][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 900][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 960][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1236][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1368][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\444BF8CC.dll] [N/A, ]
[C:\WINDOWS\system32\pksyjk.dll] [N/A, ]
[C:\WINDOWS\system32\nqvbpw.dll] [N/A, ]
[C:\WINDOWS\system32\fjidhk.dll] [N/A, ]
[C:\WINDOWS\system32\vkshhg20.dll] [, 1, 1, 1, 1015]
[C:\WINDOWS\system32\wngafc03.dll] [, 1, 1, 1, 1009]
[D:\winRAR\rarext.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\b23f.dll] [TODO: <公司名>, 1.0.0.1]
[C:\WINDOWS\system32\HOWDKRXEKRXELRY.DLL] [N/A, ]
[C:\WINDOWS\system32\1b81.dll] [TODO: <公司名>, 1.0.0.1]
[C:\Windows\system32\IPWDLSYFMTZGMTZ.DLL] [, 1.0.0.1]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\WINDOWS\system32\mpg2splt.ax] [, ]
[C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3,0,0,1847]
[PID: 1592][C:\WINDOWS\system32\igfxtray.exe] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\wngafc03.dll] [, 1, 1, 1, 1009]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\444BF8CC.dll] [N/A, ]
[C:\WINDOWS\system32\vkshhg20.dll] [, 1, 1, 1, 1015]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\3f1b.dll] [N/A, ]
[C:\WINDOWS\system32\cb23.dll] [ , 1, 0, 0, 3]
[PID: 1600][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\wngafc03.dll] [, 1, 1, 1, 1009]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\444BF8CC.dll] [N/A, ]
[C:\WINDOWS\system32\vkshhg20.dll] [, 1, 1, 1, 1015]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\igfxhk.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3,0,0,1847]
[C:\WINDOWS\system32\3f1b.dll] [N/A, ]
[C:\WINDOWS\system32\cb23.dll] [ , 1, 0, 0, 3]
[PID: 1612][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5.0.14]
[C:\WINDOWS\system32\3f1b.dll] [N/A, ]
[C:\WINDOWS\system32\cb23.dll] [ , 1, 0, 0, 3]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\444BF8CC.dll] [N/A, ]
[PID: 1660][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\444BF8CC.dll] [N/A, ]
[C:\WINDOWS\system32\vkshhg20.dll] [, 1, 1, 1, 1015]
[C:\WINDOWS\system32\wngafc03.dll] [, 1, 1, 1, 1009]
[C:\WINDOWS\system32\3f1b.dll] [N/A, ]
[C:\WINDOWS\system32\cb23.dll] [ , 1, 0, 0, 3]
[PID: 1676][D:\Program Files\1\1\SRIECLI.EXE] [Super Rabbit Soft, 7.98]
[C:\WINDOWS\system32\msvbvm60.dll] [Microsoft Corporation, 6.00.9690]
[C:\WINDOWS\system32\wngafc03.dll] [, 1, 1, 1, 1009]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\444BF8CC.dll] [N/A, ]
[C:\WINDOWS\system32\vkshhg20.dll] [, 1, 1, 1, 1015]
[D:\PROGRA~1\1\1\shlobj71.ocx] [Sky Software (hxxp://ww.ssware.com), 7, 1, 0, 0]
[C:\WINDOWS\system32\3f1b.dll] [N/A, ]
[C:\WINDOWS\system32\cb23.dll] [ , 1, 0, 0, 3]
[PID: 1248][C:\WINDOWS\system32\MSRundll.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\cb23.dll] [ , 1, 0, 0, 3]
[C:\WINDOWS\system32\wngafc03.dll] [, 1, 1, 1, 1009]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\444BF8CC.dll] [N/A, ]
[C:\WINDOWS\system32\vkshhg20.dll] [, 1, 1, 1, 1015]
[PID: 1684][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\f11.dll] [ , 1, 0, 0, 3]
[C:\WINDOWS\system32\wngafc03.dll] [, 1, 1, 1, 1009]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\444BF8CC.dll] [N/A, ]
[C:\WINDOWS\system32\vkshhg20.dll] [, 1, 1, 1, 1015]
[PID: 1244][C:\WINDOWS\system32\taskmgr.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\wngafc03.dll] [, 1, 1, 1, 1009]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\444BF8CC.dll] [N/A, ]
[C:\WINDOWS\system32\vkshhg20.dll] [, 1, 1, 1, 1015]
[PID: 2440][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\wngafc03.dll] [, 1, 1, 1, 1009]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\444BF8CC.dll] [N/A, ]
[C:\WINDOWS\system32\vkshhg20.dll] [, 1, 1, 1, 1015]
[C:\WINDOWS\system32\b23f.dll] [TODO: <公司名>, 1.0.0.1]
[D:\Program Files\1\1\haokanbar.dll] [Xiang Feng Technology, 2, 2, 0, 1612]
[C:\WINDOWS\system32\HOWDKRXEKRXELRY.DLL] [N/A, ]
[C:\WINDOWS\system32\1b81.dll] [TODO: <公司名>, 1.0.0.1]
[C:\WINDOWS\system32\winafc03.dll] [, 1, 1, 1, 1014]
[C:\WINDOWS\system32\winhhg20.dll] [, 1, 1, 1, 1042]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\javacypt.dll] [Microsoft Corporation, 5.00.3810]
[C:\WINDOWS\system32\msjava.dll] [Microsoft Corporation, 5.00.3810]
[C:\WINDOWS\system32\VMHELPER.DLL] [Microsoft Corporation, 5.00.3810]
[C:\WINDOWS\system32\macromed\flash\flash.ocx] [Macromedia, Inc., 6,0,79,0]
[PID: 2824][F:\下载软件\新建文件夹 (2)\2331.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\444BF8CC.dll] [N/A, ]
[C:\WINDOWS\system32\wngafc03.dll] [, 1, 1, 1, 1009]
[C:\WINDOWS\system32\vkshhg20.dll] [, 1, 1, 1, 1015]

gototop
 

文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]

gototop
 

Autorun.inf
[D:\]
[AutoRun]
open=444BF8CC.exe
shell\open=打开(&O)
shell\open\Command=444BF8CC.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=444BF8CC.exe
[E:\]
[AutoRun]
open=444BF8CC.exe
shell\open=打开(&O)
shell\open\Command=444BF8CC.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=444BF8CC.exe
[F:\]
[AutoRun]
open=444BF8CC.exe
shell\open=打开(&O)
shell\open\Command=444BF8CC.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=444BF8CC.exe

gototop
 

HOSTS 文件
127.0.0.1 localhost

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

杀毒是提示哟东西被破坏了,并且杀毒软件就在打不开,也卸载不了,和装不上!在线等待帮助!谢谢
gototop
 

谢谢你了,我试试看!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT