找回密码
 立即注册

QQ登录

只需一步,快速开始

楼主: speed_

电脑出问题了

[复制链接]

该用户从未签到

 楼主| 发表于 2007-12-1 11:06:02 | 显示全部楼层
  1. 2007-12-01,11:01:53

  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs (http://www.KZTechs.com)

  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描


  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)]
  18. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  19.     <load><>  [N/A]
  20. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  21.     <switch><c:\windows\system32\壁纸自动换.exe>  []
  22.     <helper.dll><C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>  []
  23.     <CnsMin><Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32>  [(Verified)"INTER CHINA NETWORK SOFTWARE (BEIJING) CO., LTD."]
  24.     <SoundMan><SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
  25. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  26.     <shell><Explorer.exe>  [(Verified)]
  27.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)]
  28. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  29.     <AppInit_DLLs><>  [N/A]
  30. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  31.     <UIHost><logonui.exe>  [(Verified)]
  32. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  33.     <{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINDOWS\DOWNLO~1\CnsHook.dll>  [(Verified)"INTER CHINA NETWORK SOFTWARE (BEIJING) CO., LTD."]
  34. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  35.     <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
  36. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  37.     <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
  38. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  39.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
  40. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  41.     <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
  42. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
  43.     <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  []
  44. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  45.     <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub>  []
  46. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  47.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]

  48. ==================================
  49. 启动文件夹
  50. N/A

  51. ==================================
  52. 服务
  53. [Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  54.   <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
  55. [Human Interface Device Access / HidServ][Stopped/Disabled]
  56.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  57. [Windows User Mode Driver Framework / UMWdf][Running/Auto Start]
  58.   <C:\WINDOWS\system32\wdfmgr.exe><Microsoft Corporation>

  59. ==================================
  60. 驱动程序
  61. [100133 / 100133][Running/Boot Start]
  62.   <\SystemRoot\System32\drivers\100133.sys><N/A>
  63. [a0 / a0][Running/Boot Start]
  64.   <\SystemRoot\\SystemRoot\System32\drivers\100133.sys><N/A>
  65. [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  66.   <system32\drivers\ac97intc.sys><Intel Corporation>
  67. [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  68.   <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
  69. [AliIde / AliIde][Running/Boot Start]
  70.   <\SystemRoot\System32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
  71. [AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
  72.   <System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
  73. [ati2mtag / ati2mtag][Running/Manual Start]
  74.   <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
  75. [CmdIde / CmdIde][Running/Boot Start]
  76.   <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
  77. [CnsMinKP / CnsMinKP][Running/Boot Start]
  78.   <\SystemRoot\system32\drivers\CnsMinKP.sys><国风因特软件(北京)有限公司>
  79. [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  80.   <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
  81. [nv / nv][Stopped/Manual Start]
  82.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  83. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  84.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  85. [Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Running/Manual Start]
  86.   <system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
  87. [Secdrv / Secdrv][Stopped/Manual Start]
  88.   <system32\DRIVERS\secdrv.sys><N/A>

  89. ==================================
  90. 浏览器加载项
  91. [CnsHook Class]
  92.   {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\DOWNLO~1\CnsHook.dll, 国风因特软件(北京)有限公司>
  93. [SrchHook Class]
  94.   {F08555B0-9CC3-11D2-AA8E-000000000000} <C:\WINDOWS\system32\IEBHO.dll, >
  95. [Yahoo 3.5G电邮]
  96.   {507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A>
  97. [名品折扣]
  98.   {59BC54A2-56B3-44a0-93E5-432D58746E26} <http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/mall/pro.php?allyesPara=816, N/A>
  99. [雅虎助手]
  100.   {5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A>
  101. [雅虎WIDGET]
  102.   {6354ABE6-05F1-49ed-B850-E423120EC338} <http://cn.widget.yahoo.com/index.htm?source=Cns, N/A>
  103. [情景聊天]
  104.   {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg, N/A>
  105. []
  106.   {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A>
  107. []
  108.   {FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A>
  109. [IE搜索工具条]
  110.   {BE830FD4-E393-417F-9F4B-CC70ABB3384C} <C:\WINDOWS\system32\IETool.dll, N/A>
  111. [AutoLive]
  112.   {7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2} <C:\PROGRA~1\3721\autolive.dll, >
  113. [IE搜索工具条]
  114.   {BE830FD4-E393-417F-9F4B-CC70ABB3384C} <C:\WINDOWS\system32\IETool.dll, N/A>
  115. [CnsHook Class]
  116.   {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\DOWNLO~1\CnsHook.dll, 国风因特软件(北京)有限公司>
  117. [Shockwave Flash Object]
  118.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  119. [SrchHook Class]
  120.   {F08555B0-9CC3-11D2-AA8E-000000000000} <C:\WINDOWS\system32\IEBHO.dll, >
  121. [导出到 Microsoft Office Excel(&X)]
  122.   <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>

  123. ==================================
  124. 正在运行的进程
  125. [PID: 440 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  126. [PID: 500 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  127. [PID: 528 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  128.     [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4146]
  129.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  130. [PID: 572 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  131. [PID: 584 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  132. [PID: 736 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4146]
  133.     [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2504]
  134. [PID: 748 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  135. [PID: 816 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  136. [PID: 892 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  137.     [C:\WINDOWS\system32\wups2.dll]  [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)]
  138. [PID: 968 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4146]
  139.     [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2504]
  140.     [C:\WINDOWS\system32\ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4146]
  141. [PID: 1032 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  142. [PID: 1060 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  143. [PID: 1340 / Administrator][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  144.     [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.1.2]
  145.     [C:\PROGRA~1\3721\helper.dll]  [, 1, 1, 1, 1327]
  146.     [C:\PROGRA~1\3721\alrex.dll]  [, 1, 0, 1, 1001]
  147.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  148.     [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
  149.     [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [国风因特软件(北京)有限公司, 2.5.1.7]
  150.     [C:\PROGRA~1\3721\autolive.dll]  [, 1, 1, 9, 1329]
  151.     [C:\PROGRA~1\3721\alLiveEx.dll]  [ , 1, 0, 3, 1006]
  152.     [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
  153. [PID: 1444 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
  154. [PID: 1580 / Administrator][C:\WINDOWS\system32\Rundll32.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  155.     [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.1.2]
  156.     [C:\WINDOWS\DOWNLO~1\CnsMinIO.dll]  [国风因特软件(北京)有限公司, 2.5.0.6]
  157.     [C:\WINDOWS\DOWNLO~1\cnsio.dll]  [国风因特软件(北京)有限公司, 2.5.0.4]
  158.     [C:\WINDOWS\DOWNLO~1\CnsMinEx.dll]  [国风因特软件(北京)有限公司, 2.5.0.4]
  159. [PID: 1600 / Administrator][C:\WINDOWS\system32\rundll32.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  160.     [C:\PROGRA~1\3721\helper.dll]  [, 1, 1, 1, 1327]
  161.     [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.1.2]
  162.     [C:\PROGRA~1\3721\autolive.dll]  [, 1, 1, 9, 1329]
  163.     [C:\PROGRA~1\3721\notifier.dll]  [, 1, 0, 0, 5]
  164.     [C:\PROGRA~1\3721\alLiveEx.dll]  [ , 1, 0, 3, 1006]
  165. [PID: 1616 / Administrator][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5, 1, 0, 52]
  166.     [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.1.2]
  167. [PID: 1624 / Administrator][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  168.     [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.1.2]
  169. [PID: 1768 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
  170. [PID: 852 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  171. [PID: 1760 / SYSTEM][C:\WINDOWS\system32\wuauclt.exe]  [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)]
  172.     [C:\WINDOWS\system32\wups2.dll]  [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)]
  173. [PID: 2000 / Administrator][D:\新建文件夹\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
  174.     [C:\PROGRA~1\3721\helper.dll]  [, 1, 1, 1, 1327]
  175.     [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [国风因特软件(北京)有限公司, 2.5.1.2]
  176.     [D:\新建文件夹\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

  177. ==================================
  178. 文件关联
  179. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  180. .EXE  OK. ["%1" %*]
  181. .COM  OK. ["%1" %*]
  182. .PIF  OK. ["%1" %*]
  183. .REG  OK. [regedit.exe "%1"]
  184. .BAT  OK. ["%1" %*]
  185. .SCR  OK. ["%1" /S]
  186. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  187. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  188. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  189. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  190. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  191. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  192. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  193. ==================================
  194. Winsock 提供者
  195. N/A

  196. ==================================
  197. Autorun.inf
  198. N/A

  199. ==================================
  200. HOSTS 文件
  201. 127.0.0.1       localhost
  202. 0.0.0.0 182838.com
  203. 0.0.0.0 204.177.92.68
  204. 0.0.0.0 asiafriendfinder.com
  205. 0.0.0.0 asqin123.51.net
  206. 0.0.0.0 babe520.5188.org
  207. 0.0.0.0 music.feifa.com
  208. 0.0.0.0 music.v111.com
  209. 0.0.0.0 www.jpbeauty.com
  210. 0.0.0.0 beautishow.com
  211. 0.0.0.0 goodmovies88.com
  212. 0.0.0.0 hothack.home.chinaren.com
  213. 0.0.0.0 hualiao.net
  214. 0.0.0.0 iplus.allyes.com
  215. 0.0.0.0 jjkafei.longcity.net
  216. 0.0.0.0 kaomm.8m.cn
  217. 0.0.0.0 l3iaoliao.com
  218. 0.0.0.0 lingaonbvm.myrice.com
  219. 0.0.0.0 lovejava.boy.net.cn
  220. 0.0.0.0 love7liao.com
  221. 0.0.0.0 asqin123.51.net
  222. 0.0.0.0 babe520.5188.org
  223. 0.0.0.0 music.feifa.com
  224. 0.0.0.0 jjkafei.longcity.net
  225. 0.0.0.0 kaomm.8m.cn
  226. 0.0.0.0 l3iaoliao.com
  227. 0.0.0.0 l3iaoliao.com
  228. 0.0.0.0 lingaonbvm.myrice.com
  229. 0.0.0.0 lovejava.boy.net.cn
  230. 0.0.0.0 love7liao.com
  231. 0.0.0.0 babe520.5188.org
  232. 0.0.0.0 music.feifa.com
  233. 0.0.0.0 music.v111.com
  234. 0.0.0.0 babe520.5188.org
  235. 0.0.0.0 music.feifa.com
  236. 0.0.0.0 jjkafei.longcity.net
  237. 0.0.0.0 kaomm.8m.cn
  238. 0.0.0.0 l3iaoliao.com
  239. 0.0.0.0 l3iaoliao.com
  240. 0.0.0.0 lingaonbvm.myrice.com
  241. 0.0.0.0 lovejava.boy.net.cn
  242. 0.0.0.0 love7liao.com
  243. 0.0.0.0 babe520.5188.org
  244. 0.0.0.0 music.feifa.com
  245. 0.0.0.0 music.v111.com
  246. 219.153.32.215 auto.search.msn.com

  247. ==================================
  248. 进程特权扫描
  249. 特殊特权被允许: SeLoadDriverPrivilege [PID = 528, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
  250. 特殊特权被允许: SeLoadDriverPrivilege [PID = 584, C:\WINDOWS\SYSTEM32\LSASS.EXE]
  251. 特殊特权被允许: SeDebugPrivilege [PID = 1340, C:\WINDOWS\EXPLORER.EXE]
  252. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1340, C:\WINDOWS\EXPLORER.EXE]
  253. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1444, C:\WINDOWS\SYSTEM32\SPOOLSV.EXE]
  254. 特殊特权被允许: SeDebugPrivilege [PID = 1600, C:\WINDOWS\SYSTEM32\RUNDLL32.EXE]
  255. 特殊特权被允许: SeDebugPrivilege [PID = 1616, C:\WINDOWS\SOUNDMAN.EXE]
  256. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1616, C:\WINDOWS\SOUNDMAN.EXE]
  257. 特殊特权被允许: SeDebugPrivilege [PID = 1624, C:\WINDOWS\SYSTEM32\CTFMON.EXE]
  258. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1356, C:\WINDOWS\SYSTEM32\DRWTSN32.EXE]
  259. 特殊特权被允许: SeSystemtimePrivilege [PID = 1356, C:\WINDOWS\SYSTEM32\DRWTSN32.EXE]

  260. ==================================
  261. API HOOK
  262. N/A

  263. ==================================
  264. 隐藏进程
  265. N/A

  266. ==================================
复制代码

该用户从未签到

发表于 2007-12-1 11:54:44 | 显示全部楼层
1.建议使用XDelBox删除以下文件:(XDelBox1.6下载)
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择剪贴板导入不检查路径,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。

c:\progra~1\3721\alliveex.dll
c:\progra~1\3721\alrex.dll
c:\progra~1\3721\autolive.dll
c:\progra~1\3721\helper.dll
c:\windows\downlo~1\cnshook.dll
c:\windows\downlo~1\cnsmin.dll
c:\windows\downlo~1\cnsio.dll
c:\windows\downlo~1\cnsminex.dll
c:\windows\downlo~1\cnsminio.dll
c:\progra~1\3721\notifier.dll
rundll32.exe c:\windows\downlo~1\cnsmin.dll,rundll32
c:\windows\system32\rundll32.exe c:\progra~1\3721\helper.dll,rundll32
c:\windows\system32\drivers\100133.sys
c:\windows\\systemroot\system32\drivers\100133.sys
c:\windows\system32\drivers\cnsminkp.sys

2.删除重启后使用SREng修复下面各项:

    启动项目 -- 注册表之如下项删除:
[CnsMin]    <Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32>
[helper.dll]    <C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>
[{D157330A-9EF3-49F8-9A67-4141AC41ADD4}]    <C:\WINDOWS\DOWNLO~1\CnsHook.dll>

    启动项目 -- 服务-- 驱动程序之如下项禁用:
[100133 / 100133]    <\SystemRoot\System32\drivers\100133.sys>
[a0 / a0]    <\SystemRoot\\SystemRoot\System32\drivers\100133.sys>
[CnsMinKP / CnsMinKP]    <\SystemRoot\system32\drivers\CnsMinKP.sys>

    系统修复-- HOSTS文件--重置


===============================================================================
Windows清理助手及杀毒软件升级安全模式下查一下:
http://www.arswp.com/download/arswp2/arswp2.zip

恶意软件清理工具下载建议升级到最新):
http://update1.tommsoft.com/rscleaner/roguecleaner.rar

[ 本帖最后由 修一明 于 2007-12-1 11:59 编辑 ]

该用户从未签到

发表于 2007-12-1 12:45:04 | 显示全部楼层
100133.sys

该用户从未签到

发表于 2007-12-1 13:47:54 | 显示全部楼层
哇!!要删得东西可真不少啊

该用户从未签到

 楼主| 发表于 2007-12-1 14:58:51 | 显示全部楼层
毒是清除了  
但是还是要自动重启
最后拿去修 结果主版坏了

该用户从未签到

发表于 2007-12-1 20:12:20 | 显示全部楼层
- -|
我还在想3721竟然能让机器重启?

不好意思没帮上忙!

该用户从未签到

 楼主| 发表于 2007-12-1 21:03:53 | 显示全部楼层
原帖由 修一明 于 2007-12-1 20:12 发表
- -|
我还在想3721竟然能让机器重启?

不好意思没帮上忙!

没关系啦 我也借这个机会把电脑升升级

该用户从未签到

发表于 2007-12-1 22:05:15 | 显示全部楼层
   太多 插件了
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表