大家帮忙,我21号晚上电脑还好好的第2天就出问题了!
具体表现是,开机以后进程中不短的打开一个小文件,然后消失,不听的占用内存,知道页面内存全部被占,文件公司上写的是TENCENT,我用卡巴杀了,可是没有作用!谁能帮我把它搞掉啊,还原系统也试过了,不行!多谢各位大虾帮帮我啊!谢谢!
建议用NOD32查杀即可!!
按照程序:你应该提供一个扫描日志;
不知用什么杀软,卡巴6和mcafee2006还是不错滴;
我现在用的就是卡巴,几我不知道,在完全模式下杀了一便,没有用,现在连卡巴都挂掉了!呵呵!更新程序挂了,不能再杀毒了!
这个病毒的特征就是开机后无限运行一个程序,不能关闭,可以在进程中看见一下,然后消失,同时占用很大的内存空间直到内存空间和缓存空间全部占满!什么程序都打不开了!
现在提供扫描日志,大家帮忙看看有什么问题,不过,我是在安全模式下扫的,不知道有用没有啊!
HijackThis_815汉化版扫描日志 V1.99.1
保存于 12:36:48, 日期 2006-7-23
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
E:\Program Files\Tencent\TT\TTraveler.exe
C:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Kaspersky Anti-Virus Personal\kav.exe
E:\Program Files\Kaspersky Anti-Virus Personal\kavsvc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
E:\HijackThis汉华版\HijackThis1991zww.exe
R3 - URLSearchHook: QQ Search Hook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\AdPlus\IEHelp1.dll (file missing)
R3 - URLSearchHook: (no name) - {0A65A035-32EE-43D4-8A78-5D3940E7F652} - C:\WINDOWS\system32\Acjh.dll
R3 - URLSearchHook: (no name) - {87B9021E-9FA2-48CB-80FE-A948AEBAA619} - C:\WINDOWS\system32\Bagzz.dll
R3 - URLSearchHook: (no name) - {6B9A5460-3CFD-4784-8EE3-063C8159905B} - C:\WINDOWS\system32\Yrjxfc.dll
R3 - URLSearchHook: (no name) - {4CBBCD84-30C4-40DA-821A-8FCEA89DFC29} - C:\WINDOWS\system32\Xeihcj.dll
R3 - URLSearchHook: (no name) - {42F0DF76-9C4B-40E8-B386-1A9FD5000518} - C:\WINDOWS\system32\Rokuu.dll
R3 - URLSearchHook: (no name) - {B0A99F80-ABFA-4DA8-8266-D9CC5315FA17} - C:\WINDOWS\system32\Qbqdgj.dll
R3 - URLSearchHook: (no name) - {CECB133C-C37C-4C9C-AE36-EBB9BC00E335} - C:\WINDOWS\system32\Dllc.dll
R3 - URLSearchHook: (no name) - {FC6888FC-39F2-4A0A-862E-FD49DBDD339C} - C:\WINDOWS\system32\Gyeg.dll
R3 - URLSearchHook: (no name) - {C9CF8C70-6B40-4122-970D-B5128FDA56D5} - C:\WINDOWS\system32\Ggcrv.dll
R3 - URLSearchHook: (no name) - {9C2AF49C-380C-4C05-B76B-589F4CE29ED0} - C:\WINDOWS\system32\Zwcflo.dll
R3 - URLSearchHook: (no name) - {8D48080F-888A-499B-B3C4-5C1E4248EB70} - C:\WINDOWS\system32\Suorh.dll
R3 - URLSearchHook: (no name) - {2951AA39-4BB1-458B-A838-0D956D9EDD72} - C:\WINDOWS\system32\Vrvi.dll
R3 - URLSearchHook: (no name) - {177BA507-A0B5-482F-AE7E-474C2A177867} - C:\WINDOWS\system32\Rxez.dll
R3 - URLSearchHook: (no name) - {35BD2DEA-91F4-424E-9E59-D3FAEA5487D2} - C:\WINDOWS\system32\Fqgew.dll
R3 - URLSearchHook: (no name) - {6905E8BD-5990-40EA-A5B9-5FA0F672707D} - C:\WINDOWS\system32\Exoy.dll
R3 - URLSearchHook: (no name) - {109D9C83-6DB8-49E3-A12A-A4976ECA4758} - C:\WINDOWS\system32\Ruozdi.dll
R3 - URLSearchHook: (no name) - {4C842028-A909-4E58-87DC-0A8A6DE7D2D4} - C:\WINDOWS\system32\Grmkds.dll
R3 - URLSearchHook: (no name) - {CE95D258-02D1-43F8-B589-AED12BCAB79D} - C:\WINDOWS\system32\Wsfz.dll
R3 - URLSearchHook: (no name) - {A61F7A1D-3A82-40F6-9E31-11A98AB31D92} - C:\WINDOWS\system32\Evpg.dll
R3 - URLSearchHook: (no name) - {CDD2300C-9953-4778-B6F8-43B9EA268DCC} - C:\WINDOWS\system32\Ftnno.dll
R3 - URLSearchHook: (no name) - {BFA07368-F5CB-4716-8C3A-51BF94000186} - C:\WINDOWS\system32\Dkmf.dll
R3 - URLSearchHook: (no name) - {355CC2D6-E6DA-4515-BED6-2AC31138C045} - C:\WINDOWS\system32\Iflxow.dll
R3 - URLSearchHook: (no name) - {7DE51F0E-3F46-4A28-A49C-590A3B0BE6F4} - C:\WINDOWS\system32\Olgw.dll
R3 - URLSearchHook: (no name) - {33647830-F279-46E0-A0AD-EC5E71959D40} - C:\WINDOWS\system32\Nxnhdd.dll
R3 - URLSearchHook: (no name) - {A261011E-78F9-427E-9894-8E79B21FBC3E} - C:\WINDOWS\system32\Fgpxsl.dll
R3 - URLSearchHook: (no name) - {BB6058DA-9ED6-495C-A27F-DC7640EC7A70} - C:\WINDOWS\system32\Bbyqfb.dll
R3 - URLSearchHook: (no name) - {31E98BBE-08EA-4110-9D9E-8920332D209A} - C:\WINDOWS\system32\Ievyif.dll
R3 - URLSearchHook: (no name) - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - (no file)
R3 - URLSearchHook: (no name) - {3E3DE7DD-967B-4BF0-B52F-A858EB0540E6} - C:\WINDOWS\system32\Ybtin.dll
R3 - URLSearchHook: (no name) - {2E3A4C8B-1976-4E21-972E-DB9D40033036} - C:\WINDOWS\system32\Oxaac.dll
R3 - URLSearchHook: (no name) - {C0DF63D1-2F5C-44D3-82D5-BA2DD818642A} - C:\WINDOWS\system32\Tbzl.dll
R3 - URLSearchHook: (no name) - {41673E05-2C0B-4425-9E5B-38CEEC5D5424} - C:\WINDOWS\system32\Jzds.dll
R3 - URLSearchHook: (no name) - {E8C888B5-612F-4B9D-8307-99A3EE29446B} - C:\WINDOWS\system32\Xmie.dll
R3 - URLSearchHook: (no name) - {D28A6D12-4415-4E7E-A4B2-0F76D350D39B} - C:\WINDOWS\system32\Mcky.dll
R3 - URLSearchHook: (no name) - {CCE5ECDD-1B79-4735-95C6-F2C9422AD215} - C:\WINDOWS\system32\Oohkz.dll
R3 - URLSearchHook: (no name) - {C3AA4108-DD1B-4320-A885-841B114DFB42} - C:\WINDOWS\system32\Yeojww.dll
R3 - URLSearchHook: (no name) - {64675532-DF9A-430A-82C4-C8EDAC4919D5} - C:\WINDOWS\system32\Mufm.dll
R3 - URLSearchHook: (no name) - {3C422436-0DEF-41D5-8B53-EF30C013E493} - C:\WINDOWS\system32\Widy.dll
R3 - URLSearchHook: (no name) - {88CEE51D-D696-4B5A-B2C5-3A340A2AF840} - C:\WINDOWS\system32\Djqaqx.dll
R3 - URLSearchHook: (no name) - {9BD97DDC-1561-4438-9E27-BC657D8174CE} - C:\WINDOWS\system32\Bzxlmx.dll
R3 - URLSearchHook: (no name) - {49916E30-E022-4796-B0B1-D32B9A78233F} - C:\WINDOWS\system32\Clwxa.dll
R3 - URLSearchHook: (no name) - {5E83F295-C5F5-4659-AA1B-637C94B74F06} - C:\WINDOWS\system32\Pcqoap.dll
R3 - URLSearchHook: (no name) - {04EF17C1-86BF-459D-9D07-4013CC3A5AB8} - C:\WINDOWS\system32\Yzja.dll
R3 - URLSearchHook: (no name) - {61A12272-AE9F-48D1-A66F-7EFEAF58A752} - C:\WINDOWS\system32\Okjm.dll
R3 - URLSearchHook: (no name) - {7FBEB568-DA50-4FFD-9A9A-8F4BF0F25372} - C:\WINDOWS\system32\Iuaqqi.dll
R3 - URLSearchHook: (no name) - {E3DA6731-7EB2-4BFE-8632-5D64BFF3C933} - C:\WINDOWS\system32\Cllz.dll
R3 - URLSearchHook: (no name) - {152D51D9-2007-4F79-8BF9-64C99E5FE88C} - C:\WINDOWS\system32\Jmduz.dll
R3 - URLSearchHook: (no name) - {628EB561-E0F7-45F1-9DF2-B56A76299C14} - C:\WINDOWS\system32\Zsux.dll
R3 - URLSearchHook: (no name) - {F939D8C9-5A28-4F6E-83A0-F9792A5960D6} - C:\WINDOWS\system32\Tleuh.dll
R3 - URLSearchHook: (no name) - {E4D343FB-4312-42ED-BC86-4EF1A3EDDCB4} - C:\WINDOWS\system32\Fqivzh.dll
R3 - URLSearchHook: (no name) - {772E5517-E405-41EB-81FB-B73808A2AA5A} - C:\WINDOWS\system32\Ziqrqz.dll
R3 - URLSearchHook: (no name) - {F9820D11-6A5C-4F1C-8952-5E83569949BC} - C:\WINDOWS\system32\Hbkyt.dll
R3 - URLSearchHook: (no name) - {19CA3A25-7F3D-4E99-874E-0175D115A1BA} - C:\WINDOWS\system32\Qhccz.dll
R3 - URLSearchHook: (no name) - {EB48AE65-8BAA-463B-9ECC-E615DCF6CB50} - C:\WINDOWS\system32\Xgoyt.dll
R3 - URLSearchHook: (no name) - {458DC71F-B565-4DD4-AD04-1606251E9B4B} - C:\WINDOWS\system32\Gqmyh.dll
R3 - URLSearchHook: (no name) - {48F50590-2038-41E3-B6D4-C751A1911B49} - C:\WINDOWS\system32\Vphid.dll
R3 - URLSearchHook: (no name) - {B415F8AE-BF42-47DD-8819-2210DEFD0EB7} - C:\WINDOWS\system32\Mutr.dll (file missing)
R3 - URLSearchHook: (no name) - {8FC7ABCC-2AFB-4B2D-8557-AB4032BF2204} - C:\WINDOWS\system32\Otrjy.dll
R3 - URLSearchHook: (no name) - {655C75FD-3A34-4C5A-908D-98D280439529} - C:\WINDOWS\system32\Yvtxya.dll
R3 - URLSearchHook: (no name) - {C8B07FB0-D498-48FD-8CD8-3B70F0701DDA} - C:\WINDOWS\system32\Mjuye.dll
R3 - URLSearchHook: (no name) - {ECE70DDE-8DFA-4155-B930-6A504279513B} - C:\WINDOWS\system32\Ncjq.dll
R3 - URLSearchHook: (no name) - {EA35916B-DE58-4CD3-9AC5-1C671AD4BE54} - C:\WINDOWS\system32\Tzyq.dll
R3 - URLSearchHook: (no name) - {E5F33315-D2CA-4479-89E2-77CFECFF1FAB} - C:\WINDOWS\system32\Malg.dll
R3 - URLSearchHook: (no name) - {26EAFF7D-6F73-40ED-A62A-1049FB6EDB6E} - C:\WINDOWS\system32\Mgrdz.dll
R3 - URLSearchHook: (no name) - {16692B80-BD49-43CE-A28B-DC46589940A9} - C:\WINDOWS\system32\Psuz.dll
R3 - URLSearchHook: (no name) - {2B3507E6-1DD8-469B-BE60-891874BF72E1} - C:\WINDOWS\system32\Qxnc.dll
R3 - URLSearchHook: (no name) - {34CABD0C-2C96-4C10-96D5-2DBCD07FFD74} - C:\WINDOWS\system32\Znlupn.dll
R3 - URLSearchHook: (no name) - {1331D794-7AF3-435C-9C2B-D246A079B075} - C:\WINDOWS\system32\Skagiw.dll
R3 - URLSearchHook: (no name) - {7B93484E-1BF6-4C4F-84EA-6216CCBEA28F} - C:\WINDOWS\system32\Hsqg.dll
R3 - URLSearchHook: (no name) - {83EC8A1C-E09C-4601-9541-B2741B19FED5} - C:\WINDOWS\system32\Zwka.dll
R3 - URLSearchHook: (no name) - {560B0887-A030-42F7-9E0E-6100DB50FC82} - C:\WINDOWS\system32\Gngf.dll
R3 - URLSearchHook: (no name) - {BA08773D-813A-4F7A-B683-59CF64C1FBB5} - C:\WINDOWS\system32\Pggmp.dll
R3 - URLSearchHook: (no name) - {C792BF19-CDA1-460F-A035-3E19467D56D9} - C:\WINDOWS\system32\Vuhxi.dll
R3 - URLSearchHook: (no name) - {B9203A37-3B2C-47DB-8D82-7E8181CAEEC2} - C:\WINDOWS\system32\Vloozh.dll
R3 - URLSearchHook: (no name) - {B574EF5B-81B5-4F0F-BD78-EDA588C39023} - C:\WINDOWS\system32\Hnuamm.dll
R3 - URLSearchHook: (no name) - {9300877D-7EE3-47C7-AEC1-FE0C9B899C42} - C:\WINDOWS\system32\Zwnkyy.dll
R3 - URLSearchHook: (no name) - {C29BD6B5-9835-42F4-AF82-8A3D08751361} - C:\WINDOWS\system32\Kakjtz.dll
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v5.dll
O2 - BHO: (no name) - {046167AA-53C2-4576-B362-291D9E852269} - C:\WINDOWS\system32\BBDown.dll
O2 - BHO: (no name) - {04EF17C1-86BF-459D-9D07-4013CC3A5AB8} - C:\WINDOWS\system32\Yzja.dll
O2 - BHO: (no name) - {07E7C180-5B5E-48FB-9238-F2C98022F5C0} - C:\WINDOWS\system32\Wjucl.dll (file missing)
O2 - BHO: MonitorURL Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\PROGRA~1\DESKAD~1\deskipn.dll
O2 - BHO: (no name) - {0A65A035-32EE-43D4-8A78-5D3940E7F652} - C:\WINDOWS\system32\Acjh.dll
O2 - BHO: Tencent Browser Helper - {0C7C23EF-A848-485B-873C-0ED954731014} - (no file)
O2 - BHO: (no name) - {109D9C83-6DB8-49E3-A12A-A4976ECA4758} - C:\WINDOWS\system32\Ruozdi.dll
O2 - BHO: (no name) - {1331D794-7AF3-435C-9C2B-D246A079B075} - C:\WINDOWS\system32\Skagiw.dll
O2 - BHO: (no name) - {152D51D9-2007-4F79-8BF9-64C99E5FE88C} - C:\WINDOWS\system32\Jmduz.dll
O2 - BHO: (no name) - {16692B80-BD49-43CE-A28B-DC46589940A9} - C:\WINDOWS\system32\Psuz.dll
O2 - BHO: (no name) - {177BA507-A0B5-482F-AE7E-474C2A177867} - C:\WINDOWS\system32\Rxez.dll
O2 - BHO: (no name) - {19CA3A25-7F3D-4E99-874E-0175D115A1BA} - C:\WINDOWS\system32\Qhccz.dll
O2 - BHO: (no name) - {26EAFF7D-6F73-40ED-A62A-1049FB6EDB6E} - C:\WINDOWS\system32\Mgrdz.dll
O2 - BHO: (no name) - {2951AA39-4BB1-458B-A838-0D956D9EDD72} - C:\WINDOWS\system32\Vrvi.dll
O2 - BHO: IE Address Browser Helper - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:\Program Files\SearchNet\SNHpr.dll
O2 - BHO: (no name) - {2B3507E6-1DD8-469B-BE60-891874BF72E1} - C:\WINDOWS\system32\Qxnc.dll
O2 - BHO: (no name) - {2E3A4C8B-1976-4E21-972E-DB9D40033036} - C:\WINDOWS\system32\Oxaac.dll
O2 - BHO: (no name) - {31E98BBE-08EA-4110-9D9E-8920332D209A} - C:\WINDOWS\system32\Ievyif.dll
O2 - BHO: (no name) - {33647830-F279-46E0-A0AD-EC5E71959D40} - C:\WINDOWS\system32\Nxnhdd.dll
O2 - BHO: (no name) - {34CABD0C-2C96-4C10-96D5-2DBCD07FFD74} - C:\WINDOWS\system32\Znlupn.dll
O2 - BHO: (no name) - {355CC2D6-E6DA-4515-BED6-2AC31138C045} - C:\WINDOWS\system32\Iflxow.dll
O2 - BHO: (no name) - {35BD2DEA-91F4-424E-9E59-D3FAEA5487D2} - C:\WINDOWS\system32\Fqgew.dll
O2 - BHO: (no name) - {3C422436-0DEF-41D5-8B53-EF30C013E493} - C:\WINDOWS\system32\Widy.dll
O2 - BHO: IE Browser Helper - {3CE496D1-1746-41CD-9489-3C0B93DF10E2} - C:\WINDOWS\Downlo~1\ovjd8xbg.dll (file missing)
O2 - BHO: (no name) - {3E3DE7DD-967B-4BF0-B52F-A858EB0540E6} - C:\WINDOWS\system32\Ybtin.dll
O2 - BHO: NaviHelperObj Class - {3E422F49-1566-40D3-B43D-077EF739AC32} - C:\WINDOWS\system32\NaviHelper.dll
O2 - BHO: (no name) - {41673E05-2C0B-4425-9E5B-38CEEC5D5424} - C:\WINDOWS\system32\Jzds.dll
O2 - BHO: (no name) - {42F0DF76-9C4B-40E8-B386-1A9FD5000518} - C:\WINDOWS\system32\Rokuu.dll
O2 - BHO: (no name) - {458DC71F-B565-4DD4-AD04-1606251E9B4B} - C:\WINDOWS\system32\Gqmyh.dll
O2 - BHO: (no name) - {48F50590-2038-41E3-B6D4-C751A1911B49} - C:\WINDOWS\system32\Vphid.dll
O2 - BHO: (no name) - {49916E30-E022-4796-B0B1-D32B9A78233F} - C:\WINDOWS\system32\Clwxa.dll
O2 - BHO: (no name) - {4C842028-A909-4E58-87DC-0A8A6DE7D2D4} - C:\WINDOWS\system32\Grmkds.dll
O2 - BHO: (no name) - {4CBBCD84-30C4-40DA-821A-8FCEA89DFC29} - C:\WINDOWS\system32\Xeihcj.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - E:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: (no name) - {560B0887-A030-42F7-9E0E-6100DB50FC82} - C:\WINDOWS\system32\Gngf.dll
O2 - BHO: (no name) - {5E83F295-C5F5-4659-AA1B-637C94B74F06} - C:\WINDOWS\system32\Pcqoap.dll
O2 - BHO: Router Layer - {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} - C:\WINDOWS\System32\aclayer.dll (file missing)
O2 - BHO: (no name) - {61A12272-AE9F-48D1-A66F-7EFEAF58A752} - C:\WINDOWS\system32\Okjm.dll
O2 - BHO: (no name) - {628EB561-E0F7-45F1-9DF2-B56A76299C14} - C:\WINDOWS\system32\Zsux.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - (no file)
O2 - BHO: (no name) - {64675532-DF9A-430A-82C4-C8EDAC4919D5} - C:\WINDOWS\system32\Mufm.dll
O2 - BHO: (no name) - {655C75FD-3A34-4C5A-908D-98D280439529} - C:\WINDOWS\system32\Yvtxya.dll
O2 - BHO: (no name) - {669751ED-D558-49AE-B01A-3B374CC7910E} - C:\WINDOWS\system32\ssup.dll
O2 - BHO: (no name) - {6905E8BD-5990-40EA-A5B9-5FA0F672707D} - C:\WINDOWS\system32\Exoy.dll
O2 - BHO: (no name) - {6B9A5460-3CFD-4784-8EE3-063C8159905B} - C:\WINDOWS\system32\Yrjxfc.dll
O2 - BHO: (no name) - {772E5517-E405-41EB-81FB-B73808A2AA5A} - C:\WINDOWS\system32\Ziqrqz.dll
O2 - BHO: (no name) - {7B93484E-1BF6-4C4F-84EA-6216CCBEA28F} - C:\WINDOWS\system32\Hsqg.dll
O2 - BHO: (no name) - {7DE51F0E-3F46-4A28-A49C-590A3B0BE6F4} - C:\WINDOWS\system32\Olgw.dll
O2 - BHO: (no name) - {7FBEB568-DA50-4FFD-9A9A-8F4BF0F25372} - C:\WINDOWS\system32\Iuaqqi.dll
O2 - BHO: (no name) - {83EC8A1C-E09C-4601-9541-B2741B19FED5} - C:\WINDOWS\system32\Zwka.dll
O2 - BHO: (no name) - {87B9021E-9FA2-48CB-80FE-A948AEBAA619} - C:\WINDOWS\system32\Bagzz.dll
O2 - BHO: (no name) - {88CEE51D-D696-4B5A-B2C5-3A340A2AF840} - C:\WINDOWS\system32\Djqaqx.dll
O2 - BHO: (no name) - {8D48080F-888A-499B-B3C4-5C1E4248EB70} - C:\WINDOWS\system32\Suorh.dll
O2 - BHO: (no name) - {8FC7ABCC-2AFB-4B2D-8557-AB4032BF2204} - C:\WINDOWS\system32\Otrjy.dll
O2 - BHO: QwzJmzgb Class - {8FD2146A-C0F0-B2B9-C5D0-F3C701C02C0B} - (no file)
O2 - BHO: (no name) - {9300877D-7EE3-47C7-AEC1-FE0C9B899C42} - C:\WINDOWS\system32\Zwnkyy.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {9BD97DDC-1561-4438-9E27-BC657D8174CE} - C:\WINDOWS\system32\Bzxlmx.dll
O2 - BHO: (no name) - {9C2AF49C-380C-4C05-B76B-589F4CE29ED0} - C:\WINDOWS\system32\Zwcflo.dll
O2 - BHO: (no name) - {A261011E-78F9-427E-9894-8E79B21FBC3E} - C:\WINDOWS\system32\Fgpxsl.dll
O2 - BHO: (no name) - {A61F7A1D-3A82-40F6-9E31-11A98AB31D92} - C:\WINDOWS\system32\Evpg.dll
O2 - BHO: (no name) - {B0A99F80-ABFA-4DA8-8266-D9CC5315FA17} - C:\WINDOWS\system32\Qbqdgj.dll
O2 - BHO: (no name) - {B415F8AE-BF42-47DD-8819-2210DEFD0EB7} - C:\WINDOWS\system32\Mutr.dll (file missing)
O2 - BHO: (no name) - {B574EF5B-81B5-4F0F-BD78-EDA588C39023} - C:\WINDOWS\system32\Hnuamm.dll
O2 - BHO: (no name) - {B9203A37-3B2C-47DB-8D82-7E8181CAEEC2} - C:\WINDOWS\system32\Vloozh.dll
O2 - BHO: (no name) - {BA08773D-813A-4F7A-B683-59CF64C1FBB5} - C:\WINDOWS\system32\Pggmp.dll
O2 - BHO: (no name) - {BB6058DA-9ED6-495C-A27F-DC7640EC7A70} - C:\WINDOWS\system32\Bbyqfb.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\zh-cn\msntb.dll
O2 - BHO: (no name) - {BFA07368-F5CB-4716-8C3A-51BF94000186} - C:\WINDOWS\system32\Dkmf.dll
O2 - BHO: (no name) - {C0DF63D1-2F5C-44D3-82D5-BA2DD818642A} - C:\WINDOWS\system32\Tbzl.dll
O2 - BHO: (no name) - {C29BD6B5-9835-42F4-AF82-8A3D08751361} - C:\WINDOWS\system32\Kakjtz.dll
O2 - BHO: (no name) - {C3AA4108-DD1B-4320-A885-841B114DFB42} - C:\WINDOWS\system32\Yeojww.dll
O2 - BHO: (no name) - {C792BF19-CDA1-460F-A035-3E19467D56D9} - C:\WINDOWS\system32\Vuhxi.dll
O2 - BHO: (no name) - {C8B07FB0-D498-48FD-8CD8-3B70F0701DDA} - C:\WINDOWS\system32\Mjuye.dll
O2 - BHO: (no name) - {C9CF8C70-6B40-4122-970D-B5128FDA56D5} - C:\WINDOWS\system32\Ggcrv.dll
O2 - BHO: (no name) - {CCE5ECDD-1B79-4735-95C6-F2C9422AD215} - C:\WINDOWS\system32\Oohkz.dll
O2 - BHO: (no name) - {CDD2300C-9953-4778-B6F8-43B9EA268DCC} - C:\WINDOWS\system32\Ftnno.dll
O2 - BHO: (no name) - {CE95D258-02D1-43F8-B589-AED12BCAB79D} - C:\WINDOWS\system32\Wsfz.dll
O2 - BHO: (no name) - {CECB133C-C37C-4C9C-AE36-EBB9BC00E335} - C:\WINDOWS\system32\Dllc.dll
O2 - BHO: (no name) - {D28A6D12-4415-4E7E-A4B2-0F76D350D39B} - C:\WINDOWS\system32\Mcky.dll
O2 - BHO: (no name) - {E3DA6731-7EB2-4BFE-8632-5D64BFF3C933} - C:\WINDOWS\system32\Cllz.dll
O2 - BHO: (no name) - {E4D343FB-4312-42ED-BC86-4EF1A3EDDCB4} - C:\WINDOWS\system32\Fqivzh.dll
O2 - BHO: (no name) - {E5F33315-D2CA-4479-89E2-77CFECFF1FAB} - C:\WINDOWS\system32\Malg.dll
O2 - BHO: (no name) - {E8C888B5-612F-4B9D-8307-99A3EE29446B} - C:\WINDOWS\system32\Xmie.dll
O2 - BHO: (no name) - {EA35916B-DE58-4CD3-9AC5-1C671AD4BE54} - C:\WINDOWS\system32\Tzyq.dll
O2 - BHO: (no name) - {EB48AE65-8BAA-463B-9ECC-E615DCF6CB50} - C:\WINDOWS\system32\Xgoyt.dll
O2 - BHO: (no name) - {ECE70DDE-8DFA-4155-B930-6A504279513B} - C:\WINDOWS\system32\Ncjq.dll
O2 - BHO: (no name) - {F939D8C9-5A28-4F6E-83A0-F9792A5960D6} - C:\WINDOWS\system32\Tleuh.dll
O2 - BHO: (no name) - {F9820D11-6A5C-4F1C-8952-5E83569949BC} - C:\WINDOWS\system32\Hbkyt.dll
O2 - BHO: (no name) - {FC6888FC-39F2-4A0A-862E-FD49DBDD339C} - C:\WINDOWS\system32\Gyeg.dll
O3 - IE工具栏增项: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\zh-cn\msntb.dll
O3 - IE工具栏增项: (no name) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - (no file)
O4 - 启动项HKLM\\Run: [IMJPMIG8.1> "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync> C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A> C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [LaunchApp> Alaunch
O4 - 启动项HKLM\\Run: [IgfxTray> C:\WINDOWS\system32\igfxtray.exe
O4 - 启动项HKLM\\Run: [HotKeysCmds> C:\WINDOWS\system32\hkcmd.exe
O4 - 启动项HKLM\\Run: [SynTPLpr> C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - 启动项HKLM\\Run: [SynTPEnh> C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - 启动项HKLM\\Run: [RemoteControl> "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - 启动项HKLM\\Run: [BluetoothAuthenticationAgent> rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - 启动项HKLM\\Run: [MSPY2002> C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - 启动项HKLM\\Run: [ATIPTA> C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - 启动项HKLM\\Run: [EPM-DM> c:\acer\epm\epm-dm.exe
O4 - 启动项HKLM\\Run: [ePowerManagement> C:\Acer\ePM\ePM.exe boot
O4 - 启动项HKLM\\Run: [LManager> C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - 启动项HKLM\\Run: [eRecoveryService> C:\Windows\System32\Check.exe
O4 - 启动项HKLM\\Run: [StormCodec_Helper> "D:\Program Files\Storm Codec\StormSet.exe" /S /opti
O4 - 启动项HKLM\\Run: [TkBellExe> "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [DAEMON Tools-1033> "D:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - 启动项HKLM\\Run: [KAVPersonal50> "E:\Program Files\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - 启动项HKLM\\Run: [Desktop> C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll
O4 - 启动项HKLM\\Run: [rvb5w> RunDll32 "C:\WINDOWS\Downlo~1\rvb5w.dll",Run
O4 - 启动项HKLM\\Run: [SearchNet_Up> "C:\Program Files\SearchNet\ServeUp.exe"
O4 - 启动项HKLM\\Run: [stup.exe> C:\PROGRA~1\TENCENT\Adplus\stup.exe
O4 - HKCU\..\Run: [ctfmon.exe> C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS> "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - IE右键菜单中的新增项目: !搜一搜(&S) - res://C:\Program Files\YiSou\yisou.dll/232
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getAllurl.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - E:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - E:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - E:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 添加到雅虎订阅(&Y) - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - E:\Program Files\Tencent\QQ\SendMMS.htm
O8 - IE右键菜单中的新增项目: 雅虎搜索 - res://C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll/246
O9 - 浏览器额外的按钮: kele8 - {84920E5F-3788-49cd-A274-E365578DF174} - (file missing)
O9 - 浏览器额外的“工具”菜单项: kele8 - {84920E5F-3788-49cd-A274-E365578DF174} - (file missing)
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - 未知的文件在 Winsock LSP: c:\windows\system32\cdnns.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
O16 - DPF: {ABA7CC7F-019D-47DB-A0D2-B3C2B3AC1B44} (Fc2Boot Class) -
O16 - DPF: {EF6205C1-3F17-4829-BCB5-1336ED89E356} (KvScanOnline Control) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{9F988549-28C5-46F6-B828-288C9F34D70A}: NameServer = 211.92.184.129,211.94.184.130
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - NT 服务: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - NT 服务: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - NT 服务: kavsvc - Kaspersky Lab - E:\Program Files\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - NT 服务: Logical System Manage (llsserver) - Unknown owner - C:\Program Files\Common Files\llserv.exe (file missing)
O23 - NT 服务: Remote Log - Unknown owner - C:\WINDOWS\system32\ServeHost.exe (file missing) |
|