+ -
当前位置:首页 → 问答吧 → 求救, 电脑会突然发出滑鼠点击声

求救, 电脑会突然发出滑鼠点击声

时间:2014-05-06

来源:互联网

电脑会突然发出滑鼠点击声, 扫瞄咗好多次都冇发现, 已确定唔关滑鼠事, 系咪中咗毒?
附上 hijackthis
hijackthis.log (15.95 KB)

2014-4-19 05:26 PM, 下载次数: 5

作者: a021417   发布时间: 2014-05-06

开机按F8,入安全模式做Fix checked & OTM 删除。
1. 执行Hijackthis > Do a system scan only > 勾选下列项目 > 按Fix Checked (fix checked时关闭所有browsers/程式) > 按"是"。
引用:
R3 - URLSearchHook: (no name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
O2 - BHO: VideoUrlSniffer - {00000ADA-7E0D-47C1-986C-F017D09C4304} - C:\Users\Public\Thunder Network\XMP4\Addins\VideoUrlSniffer.2.2.0.146.(539).dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: ShowHKToolbar Class - {06433BFE-4946-4E89-823D-CD359C81CD06} - C:\Program Files\881903\IETOOLBAR\hktbar.dll
O2 - BHO: Browsie2suayve - {1476C5EF-7FAA-090A-76F2-AEA540B59DFC} - C:\ProgramData\Browsie2suayve\51406b5567072.dll
O2 - BHO: Web Assistant Helper - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll
O2 - BHO: Hong Kong Toolbar - {481EE3EC-C026-4F9A-BA22-FD07654ADFC0} - C:\Program Files\881903\IETOOLBAR\hktbar.dll
O2 - BHO: 瑞俴弝畦温挚狟婥郪璃 - {4ADBABBD-E1CA-4f11-BD01-73B0B6E4B5BA} - C:\Users\Francis\funshion\funshiontools\FunshionHelper.dll
O2 - BHO: Incredibar.com Helper Object - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll
O2 - BHO: XunleiBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\BHO\XunleiBHO7.9.16.4670.dll
O2 - BHO: EEbbookBrrowwse - {D6C7D3BE-68DE-FB61-3464-08E692C4DA62} - C:\ProgramData\EEbbookBrrowwse\51406b8151efe.dll
O2 - BHO: Xunlei BHO Platform - {DE05CF4A-7B0A-4775-B5E5-396244938679} - C:\Program Files\Thunder Network\Thunder\Thunder BHO Platform\np_tdieplat.dll
O3 - Toolbar: Incredibar Toolbar - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll
O3 - Toolbar: Hong Kong Toolbar - {481EE3EC-C026-4F9A-BA22-FD07654ADFC0} - C:\Program Files\881903\IETOOLBAR\hktbar.dll

O4 - HKLM\..\Run: [Norton Online Backup] C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [QvodTerminal] "C:\Program Files\QvodPlayer\QvodTerminal.exe" -autorun
O4 - HKLM\..\Run: [HKToolbarManager] "C:\Program Files\881903\IETOOLBAR\hkmgr.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKCU\..\Run: [PPS Accelerator] C:\PPStream\PPSAP.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [aliim] C:\Program Files\AliWangWang\AliIM.exe /run:auto
O4 - HKCU\..\Run: [Optimizer Pro] C:\Program Files\Optimizer Pro\OptProLauncher.exe
O4 - HKCU\..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [tcactive] C:\Program Files\The Cleaner\tcap.exe
O4 - HKCU\..\Run: [GarenaMessenger] "C:\Program Files\Garena Plus\GarenaMessenger.exe" -autolaunch
O4 - HKCU\..\Run: [HKToolbarManager] "C:\Program Files\881903\IETOOLBAR\hkmgr.exe"
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Users\Francis\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
O4 - HKCU\..\Run: [XMP] "C:\Users\Public\THUNDE~1\XMP4\Core\Program\XMP.exe" /embedding /sstartfrom Startup104
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-2422033491-3628020344-2953189145-1003\..\Run: [aliim] C:\Program Files\AliWangWang\AliIM.exe /run:auto (User 'Winnie')
O4 - HKUS\S-1-5-21-2422033491-3628020344-2953189145-1003\..\Run: [Optimizer Pro] C:\Program Files\Optimizer Pro\OptProLauncher.exe (User 'Winnie')
O4 - HKUS\S-1-5-21-2422033491-3628020344-2953189145-1003\..\Run: [tcactive] C:\Program Files\The Cleaner\tcap.exe (User 'Winnie')
O4 - HKUS\S-1-5-21-2422033491-3628020344-2953189145-1003\..\Run: [GarenaMessenger] "C:\Program Files\Garena Plus\GarenaMessenger.exe" -autolaunch (User 'Winnie')
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe

O8 - Extra context menu item: &妏蚚&捃泞烛盄狟婥 - C:\Program Files\Thunder Network\Thunder\BHO\OfflineDownload.htm
O8 - Extra context menu item: &妏蚚&捃泞狟婥 - C:\Program Files\Thunder Network\Thunder\BHO\geturl.htm
O8 - Extra context menu item: &妏蚚&捃泞狟婥窒蝈诿 - C:\Program Files\Thunder Network\Thunder\BHO\GetAllUrl.htm
O8 - Extra context menu item: Foxy ?? - res://C:\Program Files\Foxy\Foxy.exe/download.htm
O8 - Extra context menu item: Foxy ?? - res://C:\Program Files\Foxy\Foxy.exe/download.htm
O8 - Extra context menu item: Foxy ?塈 - res://C:\Program Files\Foxy\Foxy.exe/download.htm
O8 - Extra context menu item: 使用迅雷看看播放器播放 - C:\Users\Public\Thunder Network\XMP4\Core\Program\XmpIEMenu.htm
O8 - Extra context menu item: 氝楼峈陕爵咺咺桶 - C:\Program Files\AliWangWang\7.20.01C\AddNewEmotion.htm
O9 - Extra button: (no name) - {14c1d00e-0b92-4379-880b-444fa2d740dd} - C:\Users\Public\Thunder Network\XMP4\Core\Program\XmpIEToolMenu.htm
O9 - Extra 'Tools' menuitem: ??V迅雷看看播放器 - {14c1d00e-0b92-4379-880b-444fa2d740dd} - C:\Users\Public\Thunder Network\XMP4\Core\Program\XmpIEToolMenu.htm
O9 - Extra button: ??V迅雷看看播放器 - {24c1d00e-0b92-4379-880b-444fa2d740dd} - C:\Users\Public\Thunder Network\XMP4\Core\Program\XmpIEToolBar.htm
O9 - Extra button: (no name) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: (no name) - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (no file)

O23 - Service: IBUpdaterService - Unknown owner - C:\Windows\system32\dmwu.exe
O23 - Service: Web Assistant - Unknown owner - C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
2. 下载/执行 OTM做删除。
copy & paste 以下项目於Paste Instructions for Items to be Moved的框格内。
按MoveIt > OK > 重启电脑。
引用:
:files
C:\Windows\System32\jmdp\stij.exe
C:\Program Files\QvodPlayer\QvodTerminal.exe
C:\Program Files\881903\IETOOLBAR\hkmgr.exe
C:\PPStream\PPSAP.exe
C:\Users\Public\Thunder Network\XMP4\Addins\VideoUrlSniffer.2.2.0.146.(539).dll
C:\Program Files\881903\IETOOLBAR\hktbar.dll
C:\ProgramData\Browsie2suayve\51406b5567072.dll
C:\Program Files\Web Assistant\Extension32.dll
C:\Users\Francis\funshion\funshiontools\FunshionHelper.dll
C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll
C:\Program Files\Thunder Network\Thunder\BHO\XunleiBHO7.9.16.4670.dll
C:\ProgramData\EEbbookBrrowwse\51406b8151efe.dll
C:\Program Files\Thunder Network\Thunder\Thunder BHO Platform\np_tdieplat.dll
C:\Program Files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
C:\Program Files\Optimizer Pro\OptProLauncher.exe
C:\Program Files\The Cleaner\tcap.exe
C:\Users\Public\THUNDE~1\XMP4\Core\Program\XMP.exe
C:\Windows\system32\dmwu.exe
C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
3. 下载/执行WinSockFix.bat for windows 7修正/重设winsocks > 重启电脑。

4. 下载/执行Junkware Removal Tool扫毒。执行扫毒前请关闭所有浏览器同程式。
(JRT会自动删除附於浏览器的恶意程式/档案/登录档)

5. 关闭所有防毒软件(包括Windows Defender),下载ComboFix至桌面 ,执行 ComboFix 扫毒。
扫瞄时不要执行其他程式或点击 ComboFix视窗。
完成扫瞄后,ComboFix 报告会自动弹出。


请贴上以下报告:
a. JRT扫毒报告。
b. ComboFix扫毒报告。
c. 新1份Hijackthis扫瞄报告。

作者: SILVESTERABEND   发布时间: 2014-05-06

ComboFix扫瞄后自动重新启动, 但开机之后佢个视窗不停快速自动弹出关闭, 无法停止, 到底出咗咩问题?

作者: a021417   发布时间: 2014-05-06

我将antivirus del咗, 重新执行combofix多次, 今次顺利执行

但系依然无故有滑鼠声, 不过之前嘅滑鼠声多啲, 宜家系快速地一两下咁

[ 本帖最后由 a021417 於 2014-4-19 11:07 PM 编辑 ]
JRT.txt (20.07 KB)

2014-4-19 10:51 PM, 下载次数: 4

log.txt (123.78 KB)

2014-4-19 10:51 PM, 下载次数: 4

hijackthis1.log (10.46 KB)

2014-4-19 10:51 PM, 下载次数: 6

作者: a021417   发布时间: 2014-05-06

引用:原帖由 a021417 於 2014-4-19 09:35 PM 发表
ComboFix扫瞄后自动重新启动, 但开机之后佢个视窗不停快速自动弹出关闭, 无法停止, 到底出咗咩问题?
1. 请跟#8帖先移除ComboFix扫瞄软件。
http://computer.uwants.com/viewthread.php?tid=12999541&extra=page%3D1

2.下载/执行WinSockFix.bat for windows 7修正/重设winsocks > 重启电脑。

3. 再执行Hijackthis > Do a system scan only > 勾选下列项目 > 按Fix Checked (fix checked时关闭所有browsers/程式) > 按"是"。
引用:O2 - BHO: ShowHKToolbar Class - {06433BFE-4946-4E89-823D-CD359C81CD06} - C:\Program Files\881903\IETOOLBAR\hktbar.dll (file missing)
O2 - BHO: Hong Kong Toolbar - {481EE3EC-C026-4F9A-BA22-FD07654ADFC0} - C:\Program Files\881903\IETOOLBAR\hktbar.dll (file missing)
O2 - BHO: XunleiBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\BHO\XunleiBHO7.9.16.4670.dll (file missing)
O3 - Toolbar: Hong Kong Toolbar - {481EE3EC-C026-4F9A-BA22-FD07654ADFC0} - C:\Program Files\881903\IETOOLBAR\hktbar.dll (file missing)
O9 - Extra button: (no name) - {14c1d00e-0b92-4379-880b-444fa2d740dd} - (no file)
O9 - Extra button: (no name) - {24c1d00e-0b92-4379-880b-444fa2d740dd} - (no file)
O9 - Extra button: (no name) - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - (no file)
O9 - Extra button: (no name) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: (no name) - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (no file)
O23 - Service: Web Assistant - Unknown owner - C:\Program Files\Web Assistant\ExtensionUpdaterService.exe (file missing)

作者: SILVESTERABEND   发布时间: 2014-05-06

楼主完成#5帖3个程序后,再做以下扫瞄:

1. 下载/执行 AdwCleaner (Xplode) 扫毒。(按[Clean] 扫毒/删除)
(执行AdwCleaner关闭所有浏览器/程式)

2. 下载/安装Malwarebytes Anti-Malware Free 扫毒。更新后做Threat Scan扫瞄/删除。

3. 下载 OTL.exe於桌面。双按OTL.exe > 按Run Scan > 完成后请将OTL扫瞄报告(OTL.txt)贴上。
(OTL扫瞄需时较长,请耐心等候)



请贴上以下报告:
a. AdwCleaner删毒报告。
b. MBAM扫毒报告。
c. OTL.txt扫瞄报告。

作者: SILVESTERABEND   发布时间: 2014-05-06

做完
AdwCleaner[S0].txt (4.77 KB)

2014-4-20 07:03 PM, 下载次数: 3

MBAM.txt (20.13 KB)

2014-4-20 07:03 PM, 下载次数: 3

OTL.Txt (144.71 KB)

2014-4-20 07:03 PM, 下载次数: 5

作者: a021417   发布时间: 2014-05-06

双按OTL.exe > 将下列档案copy & paste 到Custom Scans/Fixes框架内 > 按左上角[Run Fix];执行fix前要关闭浏览器。
成功fixed (删除)会有通知(Fix complete! Click OK to open the fix log.) >按OK > 重启电脑。

请将OTL fix log贴上。
引用:
:OTL
PRC - [2014/03/07 19:26:40 | 000,540,032 | ---- | M] (Alipay Inc. ) -- C:\Program Files\alipay\alieditplus\AlipaySecSvc.exe
PRC - [2014/02/13 17:33:52 | 000,208,264 | ---- | M] (深圳市迅雷网络技术有限公司) -- C:\Users\Public\Thunder Network\KKVideo\Core\Program\KKV.exe
PRC - [2014/01/16 08:40:24 | 000,277,920 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
PRC - [2013/12/24 11:04:46 | 001,051,520 | ---- | M] (Alipay Inc. ) -- C:\Program Files\alipay\SafeTransaction\Alipaybsm.exe
PRC - [2013/12/21 14:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/12/18 02:03:44 | 000,894,280 | ---- | M] (阿里巴巴(中&#22269有限公司) -- C:\Program Files\alipay\SafeTransaction\TaobaoProtect.exe
PRC - [2009/10/15 07:53:20 | 000,635,416 | ---- | M] (PDF Complete Inc) -- C:\Program Files\PDF Complete\pdfsvc.exe
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{1ADA3647-E5A6-4341-AB2D-536BF0EA0126}: "URL" =
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{C3CA0A01-690F-4E2F-A28D-701CFA8019C8}: "URL" = http://www.bing.com/search?q={searchTerms}&form=CPDTDF&pc=CPDTDF&src=IE-SearchBox
IE - HKCU\..\SearchScopes\{1ADA3647-E5A6-4341-AB2D-536BF0EA0126}: "URL" =
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7SHCN_en
IE - HKCU\..\SearchScopes\{7ED5D112-F93F-46BC-B21E-3370BE2E40DB}: "URL" =
IE - HKCU\..\SearchScopes\{8677BE15-99A6-49C5-98CC-246DB8B26943}: "URL" =
IE - HKCU\..\SearchScopes\{BD9ED333-EB3C-490F-9F81-C267F2FF2D47}: "URL" =
IE - HKCU\..\SearchScopes\{C1653697-A834-4244-84F7-422F35976CF3}: "URL" =
IE - HKCU\..\SearchScopes\{C3CA0A01-690F-4E2F-A28D-701CFA8019C8}: "URL" = http://www.bing.com/search?q={searchTerms}&form=CPDTDF&pc=CPDTDF&src=IE-SearchBox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\@funshion.com/npFunshion: C:\Users\Francis\funshion\funshiontools\npFunshion.dll File not found
FF - HKLM\Software\MozillaPlugins\@xunlei.com/DapCtrl: C:\Program Files\Common Files\Thunder Network\KanKan\npDapCtrl.3.1.0.7.(544).dll (ShenZhen Thunder Networking Technologies Ltd.)
FF - HKLM\Software\MozillaPlugins\@xunlei.com/npaplayer: C:\Users\Public\Thunder Network\APlayer\codecs\npaplayer.dll (ShenZhen Thunder Networking Technologies, LTD)
FF - HKLM\Software\MozillaPlugins\@xunlei.com/npxluser: C:\Program Files\Common Files\Thunder Network\UserAgent\npxluser2.0.2.3.dll File not found
FF - HKLM\Software\MozillaPlugins\@xunlei.com/npxunlei;version=1.0.0.2: C:\Program Files\Thunder Network\Thunder\Data\npxunlei1.0.0.2.dll ( )
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Users\Francis\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1103234-0-npoctoshape.dll (Octoshape ApS)
[2011/06/23 09:29:47 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
[2012/01/18 16:37:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
CHR - plugin: Error reading preferences file
O2 - BHO: (ShowHKToolbar Class) - {06433BFE-4946-4E89-823D-CD359C81CD06} - C:\Program Files\881903\IETOOLBAR\hktbar.dll File not found
O2 - BHO: (Hong Kong Toolbar) - {481EE3EC-C026-4F9A-BA22-FD07654ADFC0} - C:\Program Files\881903\IETOOLBAR\hktbar.dll File not found
O2 - BHO: (捃泞狟婥盓厥) - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\BHO\XunleiBHO7.9.16.4670.dll File not found
O3 - HKLM\..\Toolbar: (Hong Kong Toolbar) - {481EE3EC-C026-4F9A-BA22-FD07654ADFC0} - C:\Program Files\881903\IETOOLBAR\hktbar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Hong Kong Toolbar) - {481EE3EC-C026-4F9A-BA22-FD07654ADFC0} - C:\Program Files\881903\IETOOLBAR\hktbar.dll File not found
O4 - HKCU..\Run: [aliim] C:\Program Files\AliWangWang\AliIM.exe (Alibaba software (Shanghai) Corporation.)
O4 - HKCU..\Run: [GarenaMessenger] C:\Program Files\Garena Plus\GarenaMessenger.exe ()
O4 - HKCU..\Run: [Octoshape Streaming Services] C:\Users\Francis\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKLM..\RunOnce: [NCPluginUpdater] C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe (Hewlett-Packard)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &妏蚚&捃泞狟婥 - C:\Program Files\Thunder Network\Thunder\BHO\geturl.htm ()
O8 - Extra context menu item: &妏蚚&捃泞狟婥窒蝈诿 - C:\Program Files\Thunder Network\Thunder\BHO\getAllurl.htm ()
O8 - Extra context menu item: &妏蚚&捃泞烛盄狟婥 - C:\Program Files\Thunder Network\Thunder\BHO\OfflineDownload.htm ()
O8 - Extra context menu item: &使用&迅雷下载 - C:\Program Files\Thunder Network\Thunder\BHO\\GetUrl.htm ()
O8 - Extra context menu item: &使用&迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\BHO\\GetAllUrl.htm ()
O8 - Extra context menu item: &使用&迅雷离线下载 - C:\Program Files\Thunder Network\Thunder\BHO\OfflineDownload.htm ()
O8 - Extra context menu item: Foxy 、Uク - Reg Error: Key error. File not found
O8 - Extra context menu item: Foxy ?? - res://C:\Program Files\Foxy\Foxy.exe/download.htm File not found
O8 - Extra context menu item: Foxy キjエM - C:\Users\Francis\Desktop\Foxy1.8.9版本免安装2011-4-15制\Foxy.exe (Foxy, Inc.)
O8 - Extra context menu item: Foxy ?塈 - res://C:\Program Files\Foxy\Foxy.exe/download.htm File not found
O8 - Extra context menu item: Foxy 穓碝 - res://C:\Program Files\Foxy\Foxy.exe/search.htm File not found
O8 - Extra context menu item: 使用快车3下载 - C:\Users\Francis\AppData\Roaming\FlashGetBHO\GetUrl.htm ()
O8 - Extra context menu item: 使用快车3下载全部视频 - C:\Users\Francis\AppData\Roaming\FlashGetBHO\GetAllFlvUrl.htm ()
O8 - Extra context menu item: 使用快车3下载全部链接 - C:\Users\Francis\AppData\Roaming\FlashGetBHO\GetAllUrl.htm ()
O8 - Extra context menu item: 使用快车3下载当前视频 - C:\Users\Francis\AppData\Roaming\FlashGetBHO\GetFlvUrl.htm ()
O8 - Extra context menu item: 使用迅雷看看播放器播放 - C:\Users\Public\Thunder Network\XMP4\Core\Program\XmpIEMenu.htm ()
O8 - Extra context menu item: 氝楼峈陕爵咺咺桶ロ - C:\Program Files\AliWangWang\7.20.01C\AddNewEmotion.htm File not found
O8 - Extra context menu item: 添加当前页到迅雷看看播放器标签 - C:\Users\Public\Thunder Network\XMP4\Core\Program\XmpIEMenuAddStoreTab.htm ()
O9 - Extra 'Tools' menuitem : 启动迅雷看看播放器 - {14c1d00e-0b92-4379-880b-444fa2d740dd} - C:\Users\Public\Thunder Network\XMP4\Core\Program\XmpIEToolMenu.htm ()
O9 - Extra Button: 启动迅雷看看播放器 - {24c1d00e-0b92-4379-880b-444fa2d740dd} - C:\Users\Public\Thunder Network\XMP4\Core\Program\XmpIEToolBar.htm ()
O9 - Extra Button: Reg Error: Key error. - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Reg Error: Key error. - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Key error. File not found
O9 - Extra Button: Reg Error: Key error. - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Reg Error: Key error. - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - Reg Error: Key error. File not found
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{571F3459-9953-4921-AF74-EB695CEAFABB}: DhcpNameServer = 192.168.1.1
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
[2014/03/01 01:59:13 | 000,000,000 | ---D | M](C:\迅雷下?) -- C:\迅雷下载
[2014/03/01 00:18:05 | 000,000,000 | ---D | C](C:\迅雷下?) -- C:\迅雷下载
(C:\Users\Francis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\??游?) -- C:\Users\Francis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯游戏
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\迅雷?件) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\迅雷软件
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\???件) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:3EA6F39A
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TempFC5A2B2

:Files
C:\Users\Francis\FunShion.ini
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\AliUpdater{FDA42FAE-0352-4366-BE7B-F42CB0F24B7D}.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\HPCeeScheduleForFrancis.job
C:\Windows\tasks\HPCeeScheduleForWinnie.job
C:\ProgramData\0x0304A000.sfl

ipconfig /flushdns /c

:Commands
[PURITY]
[EMPTYJAVA]
[EMPTYFLASH]
[EMPTYTEMP]
[reboot]

作者: SILVESTERABEND   发布时间: 2014-05-06

用记事簿SAVE唔到, 所以COPY&PASTE咗去WORD。。。。。。
000.rtf (21.96 KB)

2014-4-20 10:30 PM, 下载次数: 2

作者: a021417   发布时间: 2014-05-06

系统运作重有冇异常或持续滑鼠点击声?

作者: SILVESTERABEND   发布时间: 2014-05-06

依然无故有滑鼠声, 系一次一两下咁,亦都冇之前咁密同多

作者: a021417   发布时间: 2014-05-06

引用:原帖由 a021417 於 2014-4-21 01:39 PM 发表
依然无故有滑鼠声, 系一次一两下咁,亦都冇之前咁密同多



请将所有启动项目截图贴上。(开始 > 输入 msconfig > 按Enter)

作者: SILVESTERABEND   发布时间: 2014-05-06

做完
a.png (67.23 KB)

2014-4-21 03:15 PM

b.png (65.76 KB)

2014-4-21 03:15 PM

作者: a021417   发布时间: 2014-05-06

引用:原帖由 a021417 於 2014-4-21 03:15 PM 发表
做完
祗保留Anti-phishing /Panda Cloud Antivirus两个启动,取消勾选所有其他启动程式 > 重启电脑。

[ 本帖最后由 SILVESTERABEND 於 2014-4-21 03:49 PM 编辑 ]

作者: SILVESTERABEND   发布时间: 2014-05-06

依然有滑鼠声。。。

作者: a021417   发布时间: 2014-05-06

楼主重新做1份OTL txt同OTL Extras扫瞄报告贴上

作者: SILVESTERABEND   发布时间: 2014-05-06

OK
04232014_184855.log (28.66 KB)

2014-4-23 06:59 PM, 下载次数: 1

OTL.Txt (84.21 KB)

2014-4-23 06:59 PM, 下载次数: 2

作者: a021417   发布时间: 2014-05-06

下载/执行WinSockFix.bat for windows 7修正/重设winsocks > 重启电脑。

作者: SILVESTERABEND   发布时间: 2014-05-06