[中毒] 救救我~~~~~~~~~T_________T EFix
EFix Ver 4.05
2008/05/28 星期三 19:03:06.57
Microsoft Windows XP [版本 5.1.2600]
Service Pack 2
===========================================================
IE Temp file folder in C:\Documents and Settings\user\Local Settings\Temporary Internet Files
desktop in C:\Documents and Settings\user\桌面
Windows Temp file in %SystemRoot%\TEMP ; C:\DOCUME~1\user\LOCALS~1\Temp
===========================================================
delete files list
===========================================================
delete failed files list
===========================================================
autorun.inf
===========================================================
delete files backup list
===========================================================
Backup Registry list
C:\NEFix\Backup\Reg\HKCU-Run.reg
C:\NEFix\Backup\Reg\HKCU-RunOnce.reg
C:\NEFix\Backup\Reg\HKCU-RunServices.reg
C:\NEFix\Backup\Reg\HKCU-RunServicesOnce.reg
C:\NEFix\Backup\Reg\HKLM-Hidden.reg
C:\NEFix\Backup\Reg\HKLM-Run.reg
C:\NEFix\Backup\Reg\HKLM-RunOnce.reg
C:\NEFix\Backup\Reg\HKLM-RunServices.reg
C:\NEFix\Backup\Reg\HKLM-ShellExecuteHooks.reg
===========================================================
registry keys list
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
load=
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"shell"="Explorer.exe"
"userinit"="C:\WINDOWS\system32\userinit.exe,"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"=""
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe"
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe "
"ATnotes.exe"="C:\Program Files\ATnotes\ATnotes.exe"
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"LESS DOWNLOAD"="C:\DOCUME~1\user\APPLIC~1\MPEGKN~1\Defywmacomp.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE "
"RTHDCPL"="RTHDCPL.EXE"
"SkyTel"="SkyTel.EXE"
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe"
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe"
"MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot"
"KAVPersonal50"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe "
"CJIMETIPSYNC"="C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE "
"PHIMETIPSYNC"="C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE "
"EPSON Stylus C79 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBGP.EXE "
"mobiswing"="C:\PROGRA~1\BITTOR~1\BitP.exe"
"Itch ford four knob"="C:\Documents and Settings\All Users\Application Data\third lies itch ford\Itch 4.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="%SystemRoot%\system32\browseui.dll"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="%SystemRoot%\system32\browseui.dll"
===========================================================
Services \ Drivers
S0 = Boot Start S1 = System Start S2 = Auto Start S3 = Manual Start S4 = Disable
S1 Klmc;Klmc = C:\WINDOWS\system32\drivers\klmc.sys
===========================================================
Startup Folder:
[C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動]
Adobe Reader Speed Launch.lnk
[C:\Documents and Settings\user\「開始」功能表\程式集\啟動]
PPS.lnk
--
好久不見!愛情!
http://www.wretch.cc/blog/sjoy2139
--
※ 發信站: 批踢踢實業坊(ptt.cc)
◆ From: 192.192.131.209
→
06/01 20:58, , 1F
06/01 20:58, 1F
→
06/01 20:58, , 2F
06/01 20:58, 2F
AntiVirus 近期熱門文章
PTT數位生活區 即時熱門文章