Ê× Ò³ ©ª ÎÄÕÂÖÐÐÄ ©ª ÏÂÔØÖÐÐÄ ©ª ÓéÀÖ°ËØÔ ©ª ±¾Õ¾ÂÛ̳ ©ª °ÝÈÊÁªÃË ©ª ÇòÃÔÉçÇø ©ª ²©¿ÍÈÕÖ¾ ©ª ½¨Õ¾·þÎñ ©ª ÓòÃûÇÀ×¢ ©ª ·±ówÖÐÎÄ
ÉèΪÊ×Ò³
¼ÓÈëÊÕ²Ø
ÁªÏµÎÒÃÇ
E-mail:WebMaster#fcbu.com
ÔØÈëÖС­
µ±Ç°Î»ÖÃ:Õ¾³¤ÌìÏ -> µçÄÔÒ½Ôº -> ¸ßÊÖ°ïÎÒ¿´¿´½ø³ÌÀïÃæÄÄЩÓÐÎÊÌâ

¸ßÊÖ°ïÎÒ¿´¿´½ø³ÌÀïÃæÄÄЩÓÐÎÊÌâ


×÷ÕߣºTTXS(Fcbu.Com)¡¡¡¡ À´Ô´£º»¥ÁªÍø¡¡¡¡ ·¢±íʱ¼ä£º2006-08-23¡¡¡¡
HijackThis_815ºº»¯°æÉ¨ÃèÈÕÖ¾ V1.99.1
±£´æÓÚ¡¡ ¡¡¡¡ ¡¡10:51:36, ÈÕÆÚ 2006-07-12
²Ù×÷ϵͳ£º¡¡¡¡Windows XP SP1 (WinNT 5.01.2600)
ä¯ÀÀÆ÷£º¡¡ ¡¡ Internet Explorer v6.00 SP1 (6.00.2800.1106)
µ±Ç°ÔËÐеĽø³Ì£º¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\KV2006\KVSrvXP.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\wincup\wincup.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\Rundll32.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\KV2006\KVMonXP.kxp
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\PROGRA~1\baigoo\bgoomain.exe
C:\WINDOWS\System32\dxvwzdss.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\KV2006\TrojDie.kxp
C:\Program Files\eMule\emule.exe
C:\Program Files\KV2006\KRegEx.exe
C:\Program Files\KV2006\UIHost.exe
C:\Program Files\Tencent\TM\TMDlls\TM.exe
C:\Program Files\Tencent\TM\TMDlls\TIMPlatform.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\×ÀÃæ\HijackThisºº»ª°æ\HijackThis1991zww.exe
R3 - URLSearchHook: ÑÅ»¢ÖúÊÖ - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ya[×öÈËÒªºñµÀ£¬ÓôÊÒªÎÄÃ÷>ar.dll
F2 - REG:system.ini: Shell=explorer.exe¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡ £¢C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00015.exe£¢
O2 - BHO: FiltrateWebObj Class - {42AFACEE-2A77-41EB-9EE2-D9F8AF827F90} - C:\Program Files\KV2006\KVBHO.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O2 - BHO: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: bg - {7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} - C:\Program Files\baigoo\BGooBHO.dll
O2 - BHO: BrowseHelper Class - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} - C:\Program Files\KV2006\KvShell.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLO~1\CnsHook.dll
O3 - IE¹¤¾ßÀ¸ÔöÏî: µç̨(£¦R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - IE¹¤¾ßÀ¸ÔöÏî: ½­Ãñɱ¶¾¹¤¾ßÀ¸ - {B5A34A93-D538-43A7-8371-864CB6148D12} - C:\Program Files\KV2006\KvShell.dll
O3 - IE¹¤¾ßÀ¸ÔöÏî: VeryCD³¬¼¶ËÑË÷ - {F869BB38-FFEF-4589-B986-610B7AD0ADA2} - C:\Program Files\YOK.com\SuperSearch\YOK_SuperSearch.dll
O3 - IE¹¤¾ßÀ¸ÔöÏî: £¦Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - IE¹¤¾ßÀ¸ÔöÏî: ÑÅ»¢ÖúÊÖ - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ya[×öÈËÒªºñµÀ£¬ÓôÊÒªÎÄÃ÷>ar.dll
O4 - Æô¶¯ÏîHKLM\\Run: [PHIME2002ASync> C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - Æô¶¯ÏîHKLM\\Run: [PHIME2002A> C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - Æô¶¯ÏîHKLM\\Run: [IMJPMIG8.1> ; £¢C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE£¢ /Spoil /RemAdvDef /Migration32
O4 - Æô¶¯ÏîHKLM\\Run: [IgfxTray> C:\WINDOWS\System32\igfxtray.exe
O4 - Æô¶¯ÏîHKLM\\Run: [HotKeysCmds> C:\WINDOWS\System32\hkcmd.exe
O4 - Æô¶¯ÏîHKLM\\Run: [RemoteControl> ; C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
O4 - Æô¶¯ÏîHKLM\\Run: [SoundMan> SOUNDMAN.EXE
O4 - Æô¶¯ÏîHKLM\\Run: [InterbaseGuardian> ; e:\Ò½±£Éê~1\bin\ibserver.exe -a
O4 - Æô¶¯ÏîHKLM\\Run: [SoundMAXPnP> C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - Æô¶¯ÏîHKLM\\Run: [SoundMAX> £¢C:\Program Files\Analog Devices\SoundMAX\Smax4.exe£¢ /tray
O4 - Æô¶¯ÏîHKLM\\Run: [Çý¶¯×Ô¶¯°²×°> D:\setup\PAuto.exe
O4 - Æô¶¯ÏîHKLM\\Run: [CnsMin> Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32
O4 - Æô¶¯ÏîHKLM\\Run: [KernelFaultCheck> %systemroot%\system32\dumprep 0 -k
O4 - Æô¶¯ÏîHKLM\\Run: [Rav> £¢C:\Program Files\Rising\Rav\Update\setup.exe£¢ /UNINSTALL /S /ONCE
O4 - Æô¶¯ÏîHKLM\\Run: [KvMonXP> £¢C:\Program Files\KV2006\KVMonXP.kxp£¢ /auto
O4 - Æô¶¯ÏîHKLM\\Run: [TkBellExe> £¢C:\Program Files\Common Files\Real\Update_OB\realsched.exe£¢¡¡¡¡-o[×öÈËÒªºñµÀ£¬ÓôÊÒªÎÄÃ÷>oot
O4 - Æô¶¯ÏîHKLM\\Run: [YLive.exe> C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - Æô¶¯ÏîHKLM\\Run: [bgoomain.exe> C:\PROGRA~1\baigoo\bgoomain.exe
O4 - Æô¶¯ÏîHKLM\\Run: [Explorer 2238> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\28688\explorer.exe
O4 - Æô¶¯ÏîHKLM\\Run: [SysTray> C:\Program Files\bmllajh.exe
O4 - Æô¶¯ÏîHKLM\\Run: [ÿ_zskhjrnfdulzmv>`>uo40inkrwksz_> c:\windows\system32\_zskwrkni04ou>`>vmzludfnrjh.exe
O4 - Æô¶¯ÏîHKLM\\RunServices: [ÿ_zskhjrnfdulzmv>`>uo40inkrwksz_> c:\windows\system32\_zskwrkni04ou>`>vmzludfnrjh.exe
O4 - HKCU\..\Run: [ctfmon.exe> C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS> ; £¢C:\Program Files\Messenger\msmsgs.exe£¢ /background
O4 - HKCU\..\Run: [KvXP> £¢C:\Program Files\KV2006\KvXP.kxp£¢ /ScanBoot /ScanSys
O4 - HKCU\..\Run: [ÿ_zskhjrnfdulzmv>`>uo40inkrwksz_> c:\windows\system32\_zskwrkni04ou>`>vmzludfnrjh.exe
O4 - HKCU\..\Run: [eMuleAutoStart> C:\Program Files\eMule\emule.exe -AutoStart
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: £¦Ê¹ÓÃѸÀ×ÏÂÔØ - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: £¦Ê¹ÓÃѸÀ×ÏÂÔØÈ«²¿Á´½Ó - C:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: £¾£¾²ÊÐÅ·¢ËÍ£¼£¼ - res://C:\PROGRA~1\MMSASS~1\mmsass~1.dll/mms.htm
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: Google ËÑË÷(£¦G) - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: YOKËÑË÷ - C:\Program Files\YOK.com\SuperSearch\yoksch.htm
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: ʹÓÃKuGoo3ÏÂÔØ(£¦K) - C:\Program Files\KuGoo3\KuGoo3DownX.htm
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: ·´ÏòÁ´½Ó - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: µ¼³öµ½ Microsoft Excel(£¦x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: Ò×Ȥ¹ºÎï - C:\Program Files\AD4All\link1\ebaylink.htm
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: Ìí¼Óµ½ÑÅ»¢¶©ÔÄ(£¦Y) - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: ÀàËÆÍøÒ³ - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: ¾«²ÊͼÁå - C:\Program Files\AD4All\link2\phone.htm
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: »º´æµÄÍøÒ³¿ìÕÕ - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: ·­ÒëÓ¢ÎÄ×Ö´Ê(£¦T) - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: ÑÅ»¢ËÑË÷ - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ya[×öÈËÒªºñµÀ£¬ÓôÊÒªÎÄÃ÷>ar.dll/246
O9 - ä¯ÀÀÆ÷¶îÍâµÄ°´Å¥: Yahoo 1GµçÓÊ - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - [×öÈËÒªºñµÀ£¬ÓôÊÒªÎÄÃ÷>utton.htm£¿source=cns£¦btn=yahoomail (file missing)
O9 - ä¯ÀÀÆ÷¶îÍâµÄ°´Å¥: ÑÅ»¢ÖúÊÖ - {5D73EE86-05F1-49ed-B850-E423120EC338} -
[×öÈËÒªºñµÀ£¬ÓôÊÒªÎÄÃ÷>utton.htm£¿source=cns£¦btn=yassist (file missing)
O9 - ä¯ÀÀÆ÷¶îÍâµÄ°´Å¥: ÁªÏë - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} -
(file missing)
O9 - ä¯ÀÀÆ÷¶îÍâµÄ°´Å¥: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - ä¯ÀÀÆ÷¶îÍâµÄ°´Å¥: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} -
[×öÈËÒªºñµÀ£¬ÓôÊÒªÎÄÃ÷>utton.htm£¿source=cns£¦btn=clean (file missing)
O9 - ä¯ÀÀÆ÷¶îÍâµÄ¡°¹¤¾ß¡±²Ëµ¥Ïî: ÇåÀíÉÏÍø¼Ç¼ - {FD00D911-7529-4084-9946-A29F1BDF4FE5} -
[×öÈËÒªºñµÀ£¬ÓôÊÒªÎÄÃ÷>utton.htm£¿source=cns£¦btn=clean (file missing)
O11 - Options group: [!CNS>¡¡¡¡ÍøÂçʵÃû
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com
O16 - DPF: {1E0DFFCF-27FF-4574-849B-55007349FEDA} (iTrusPTA Class) -

O16 - DPF: {2354A44B-3CEB-4829-9940-545B03103538} (PowerPlr Control) -

O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) -

O17 - HKLM\System\CCS\Services\Tcpip\..\{D3F235D9-D528-4D17-A426-1735A53154C6}: NameServer = 202.103.0.117,202.103.24.68
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: SysTime - {724C75F1-B757-408D-A50A-4CF99DA35D73} - C:\PROGRA~1\WinKld\WinKld.dll
O21 - SSODL: DCOM Server 2238 - {2C1CD3D7-86AC-4068-93BC-A02304BB2238} - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\28688\explorer.exe
O23 - NT ·þÎñ: KVSrvXP - Jiangmin Co. Ltd - C:\Program Files\KV2006\KVSrvXP.exe
O23 - NT ·þÎñ: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - NT ·þÎñ: WinWrCup - MsWinCup - C:\WINDOWS\wincup\wincup.exe ½¨ÒéÏÞÓÃÖö¥Ìû×ÓÂäÄ»ÍÆ¼öµÄ ¶ñÒâÈí¼þÇåÀí¹¤¾ß¡¡¡¡ÇåÀíÒ»´Î
O21 - SSODL: DCOM Server 2238 - {2C1CD3D7-86AC-4068-93BC-A02304BB2238} - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\28688\explorer.exe
ÐÞ¸´£¬É¾³ýÎļþ£¬ÔÚÁÙʱÎļþ¼ÐÖÐ
O23 - NT ·þÎñ: WinWrCup - MsWinCup - C:\WINDOWS\wincup\wincup.exe
¹Ø±Õ·þÎñ¡¡¡¡WinWrCup¡¡¡¡É¾³ýÎļþ¼Ð
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: Google ËÑË÷(£¦G) - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: YOKËÑË÷ - C:\Program Files\YOK.com\SuperSearch\yoksch.htm
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: ʹÓÃKuGoo3ÏÂÔØ(£¦K) - C:\Program Files\KuGoo3\KuGoo3DownX.htm
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: ·´ÏòÁ´½Ó - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: µ¼³öµ½ Microsoft Excel(£¦x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: Ò×Ȥ¹ºÎï - C:\Program Files\AD4All\link1\ebaylink.htm
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: Ìí¼Óµ½ÑÅ»¢¶©ÔÄ(£¦Y) - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: ÀàËÆÍøÒ³ - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: ¾«²ÊͼÁå - C:\Program Files\AD4All\link2\phone.htm
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: »º´æµÄÍøÒ³¿ìÕÕ - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: ·­ÒëÓ¢ÎÄ×Ö´Ê(£¦T) - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: ÑÅ»¢ËÑË÷ - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ya[×öÈËÒªºñµÀ£¬ÓôÊÒªÎÄÃ÷>ar.dll/246
O9 - ä¯ÀÀÆ÷¶îÍâµÄ°´Å¥: Yahoo 1GµçÓÊ - {507F9113-CD77-4866-BA92-0E86DA3D0B97} -
[×öÈËÒªºñµÀ£¬ÓôÊÒªÎÄÃ÷>utton.htm£¿source=cns£¦btn=yahoomail (file missing)
O9 - ä¯ÀÀÆ÷¶îÍâµÄ°´Å¥: ÑÅ»¢ÖúÊÖ - {5D73EE86-05F1-49ed-B850-E423120EC338} -
[×öÈËÒªºñµÀ£¬ÓôÊÒªÎÄÃ÷>utton.htm£¿source=cns£¦btn=yassist (file missing)
O9 - ä¯ÀÀÆ÷¶îÍâµÄ°´Å¥: ÁªÏë - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} -
(file missing)
O9 - ä¯ÀÀÆ÷¶îÍâµÄ°´Å¥: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - ä¯ÀÀÆ÷¶îÍâµÄ°´Å¥: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} -
[×öÈËÒªºñµÀ£¬ÓôÊÒªÎÄÃ÷>utton.htm£¿source=cns£¦btn=clean (file missing)
O9 - ä¯ÀÀÆ÷¶îÍâµÄ¡°¹¤¾ß¡±²Ëµ¥Ïî: ÇåÀíÉÏÍø¼Ç¼ - {FD00D911-7529-4084-9946-A29F1BDF4FE5} -
[×öÈËÒªºñµÀ£¬ÓôÊÒªÎÄÃ÷>utton.htm£¿source=cns£¦btn=clean (file missing)
O11 - Options group: [!CNS>¡¡¡¡ÍøÂçʵÃû
Ö±½ÓÐÞ¸´£¬Èç¹ûÓá¡¡¡¶ñÒâÈí¼þÇåÀíÇåÀíÇåÀíºó»¹Óеϰ
O4 - Æô¶¯ÏîHKLM\\Run: [CnsMin> Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32
ÐÞ¸´£¬Ç¿ÐÐɾ³ýÕâdllÎļþ£¬½èÖúºº»¯°ækillbox
O4 - Æô¶¯ÏîHKLM\\Run: [KernelFaultCheck> %systemroot%\system32\dumprep 0 -k
ÐÞ¸´
O4 - Æô¶¯ÏîHKLM\\Run: [bgoomain.exe> C:\PROGRA~1\baigoo\bgoomain.exe
Ð¶ÔØ°Ù¹·ËÑË÷ºóÐÞ¸´
O4 - Æô¶¯ÏîHKLM\\Run: [Explorer 2238> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\28688\explorer.exe
ÐÞ¸´£¬È¨ÏÞɾ³ýÎļþ¼Ð C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\28688
O4 - Æô¶¯ÏîHKLM\\Run: [SysTray> C:\Program Files\bmllajh.exe
ÐÞ¸´
O4 - Æô¶¯ÏîHKLM\\Run: [ÿ_zskhjrnfdulzmv>`>uo40inkrwksz_> c:\windows\system32\_zskwrkni04ou>`>vmzludfnrjh.exe
O4 - Æô¶¯ÏîHKLM\\RunServices: [ÿ_zskhjrnfdulzmv>`>uo40inkrwksz_> c:\windows\system32\_zskwrkni04ou>`>vmzludfnrjh.exe
ÕâÊÇɶ£¿²»Çå³þ½¨ÒéÐÞ¸´
O4 - HKCU\..\Run: [MSMSGS> ; £¢C:\Program Files\Messenger\msmsgs.exe£¢ /background
½¨ÒéÐÞ¸´
O4 - HKCU\..\Run: [ÿ_zskhjrnfdulzmv>`>uo40inkrwksz_> c:\windows\system32\_zskwrkni04ou>`>vmzludfnrjh.exe
ÉÏÃæÒѾ­»Ø¸´
O4 - HKCU\..\Run: [eMuleAutoStart> C:\Program Files\eMule\emule.exe -AutoStart
Ö±½ÓÐÞ¸´
R3 - URLSearchHook: ÑÅ»¢ÖúÊÖ - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ya[×öÈËÒªºñµÀ£¬ÓôÊÒªÎÄÃ÷>ar.dll
Ð¶ÔØÑÅ»¢ºóÐÞ¸´£¬Ç¿ÐÐɾ³ýÎļþ¼Ð C:\PROGRA~1\Yahoo!
F2 - REG:system.ini: Shell=explorer.exe¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡ £¢C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00015.exe£¢
ÐÞ¸´£¬
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
ÒѾ­»Ø¸´
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
Ö±½ÓÐÞ¸´
O2 - BHO: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
Ö±½ÓÐÞ¸´£¬qq´øµÄ²å¼þ
O2 - BHO: bg - {7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} - C:\Program Files\baigoo\BGooBHO.dll
°Ù¹·ËÑË÷£¬Ö±½ÓÐÞ¸´
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLO~1\CnsHook.dll
ÐÞ¸´£¬Ç¿ÐÐɾ³ýÕâdllÎļþ£¬½èÖúºº»¯°ækillbox¡¡¡¡3721Ïà¹Ø
O3 - IE¹¤¾ßÀ¸ÔöÏî: µç̨(£¦R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
½¨ÒéÖ±½ÓÐÞ¸´
O3 - IE¹¤¾ßÀ¸ÔöÏî: VeryCD³¬¼¶ËÑË÷ - {F869BB38-FFEF-4589-B986-610B7AD0ADA2} - C:\Program Files\YOK.com\SuperSearch\YOK_SuperSearch.dll
Ð¶ÔØÕⳬ¼¶ËÑË÷£¬É¾³ýÎļþ¼Ð C:\Program Files\YOK.com
O3 - IE¹¤¾ßÀ¸ÔöÏî: £¦Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
½¨ÒéÐ¶ÔØgoogleËÑË÷
O3 - IE¹¤¾ßÀ¸ÔöÏî: ÑÅ»¢ÖúÊÖ - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ya[×öÈËÒªºñµÀ£¬ÓôÊÒªÎÄÃ÷>ar.dll
ÐÞ¸´£¬ÒѾ­»Ø¸´
Ö÷ÒªÎÊÌ⣺
O21 - SSODL: DCOM Server 2238 - {2C1CD3D7-86AC-4068-93BC-A02304BB2238} - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\28688\explorer.exe
O23 - NT ·þÎñ: WinWrCup - MsWinCup - C:\WINDOWS\wincup\wincup.exe
F2 - REG:system.ini: Shell=explorer.exe¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡¡¡ ¡¡ £¢C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00015.exe£¢
O4 - Æô¶¯ÏîHKLM\\Run: [Explorer 2238> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\28688\explorer.exe
¿ÉÒÉÎÊÌ⣺
O4 - Æô¶¯ÏîHKLM\\Run: [ÿ_zskhjrnfdulzmv>`>uo40inkrwksz_> c:\windows\system32\_zskwrkni04ou>`>vmzludfnrjh.exe
O4 - Æô¶¯ÏîHKLM\\RunServices: [ÿ_zskhjrnfdulzmv>`>uo40inkrwksz_> c:\windows\system32\_zskwrkni04ou>`>vmzludfnrjh.exe
O4 - HKCU\..\Run: [ÿ_zskhjrnfdulzmv>`>uo40inkrwksz_> c:\windows\system32\_zskwrkni04ou>`>vmzludfnrjh.exe Ô­ÌûÓÉ ºìÌÒjacker ÓÚ 2006-7-12 11:43 ·¢±í
½¨ÒéÏÞÓÃÖö¥Ìû×ÓÂäÄ»ÍÆ¼öµÄ ¶ñÒâÈí¼þÇåÀí¹¤¾ß¡¡¡¡ÇåÀíÒ»´Î
ÂäÄ»ÊÇË­£¬Ôõôû¿´¼ûѽ£¿ Ô­ÌûÓÉ ºìÌÒjacker ÓÚ 2006-7-12 11:43 ·¢±í
½¨ÒéÏÞÓÃÖö¥Ìû×ÓÂäÄ»ÍÆ¼öµÄ ¶ñÒâÈí¼þÇåÀí¹¤¾ß¡¡¡¡ÇåÀíÒ»´Î
ÂäÄ»ÊÇË­£¬Ôõôû¿´¼ûѽ£¿
²»ºÃÒâ˼£¬½ñÌìÀϳöÏÖ´í±ð×Ö¡£
½¨ÒéÏÞ£¨ÏÈ£©ÓÃÖö¥Ìû×ÓÂäÄ»£¨ÀïÃæ£©ÍƼöµÄ ¶ñÒâÈí¼þÇåÀí¹¤¾ß¡¡¡¡ÇåÀíÒ»´Î ºÇºÇ£¬´í±ð×Ö£¬·´²¡¶¾Ð¡¹¤¾ßÏÂÔØÀïµÄ¡°¶ñÒâÈí¼þÇåÀí¹¤¾ß¡±
£¨5Â¥£©
´òÓ¡±¾ÎÄ¡¡ ·µ»Ø¶¥²¿¡¡ ¼ÓÈëÊղء¡ ¹Ø±Õ´°¿Ú
¹ã ¸æ λ ÕÐ ×â
  • ÉÏһƪ£º ¸÷λ¸ßÊÖÀ´°ï°ïæ!!!
  • ÏÂһƪ£º Çó½Ì´óϺ
  • ¹ØÓÚ±¾Õ¾ - ÍøÕ¾°ïÖú - ¹ã¸æºÏ×÷ - ÏÂÔØÉùÃ÷ - ÓÑÇéÁ¬½Ó - ÍøÕ¾µØÍ¼ - ¹ÜÀíµÇ¼
    ÁªÏµ·½Ê½
    Copyright © 2004-2007 FCBU.Com All Rights Reserved.
    °æÈ¨ËùÓÐ:¡ºÕ¾³¤ÌìÏ¡» ÐÂÁèÑ¶ÍøÂç;±£ÁôËùÓÐȨÀû. ¸ÓICP±¸05002812