瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 跳网页,IE被改,无邪无邪快来呀
W断了的弦T - 2006-8-29 18:48:00
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
    <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>  [Microsoft Corporation]
    <Xplus_spy><"D:\Xplus\xvcclip.exe" /min>  []
    <MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>  [Microsoft Corporation]
    <Xplus><"D:\xplus\Xplus_Wait.exe" /min>  []
    <xvcclip><D:\xplus\xvcclip.exe>  []
    <Realplayer.exe><C:\WINDOWS\system32\Realplayer.exe>  []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [NVIDIA Corporation]
    <nwiz><nwiz.exe /install>  []
    <AGRSMMSG><AGRSMMSG.exe>  [Agere Systems]
    <fscp><C:\Program Files\AVC Finger-sensing Pad Driver\fscp.exe>  []
    <IgrsSignal><"C:\Program Files\lenovo\IGRS\Ext\IgrsSignal.exe">  [Lenovo Group Limited]
    <IgrsNotify><"C:\Program Files\lenovo\IGRS\Ext\IgrsNotify.exe">  [Lenovo Group Limited]
    <IgrsPortal><"C:\Program Files\lenovo\IGRS EasyShare\IgrsPortal.exe">  [Lenovo Group Limited]
    <NeroFilterCheck><C:\WINDOWS\system32\NeroCheck.exe>  [Ahead Software Gmbh]
    <SoundMan><SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
    <QkOnBtn><C:\Program Files\QBU\QkOnBtn.EXE>  [Dritek System Inc.]
    <RemoteControl><"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe">  [Cyberlink Corp.]
    <EnergyUtility><C:\Program Files\Lenovo\EnergyCut\utilty.exe>  [TODO: <Company name>]
    <EnergyCut><C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe>  []
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [Microsoft Corporation]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <Knight V><>  []
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <DAEMON Tools-1033><"C:\Program Files\D-Tools\daemon.exe"  -lang 1033>  [DAEMON'S HOME]
    <Thunder><"D:\迅雷\Thunder.exe" /s>  [Thunder Networking Technologies,LTD]
    <Mysee Alert><"C:\Program Files\GAOV\Mysee Alert\Mysee Alert.exe" -notray>  [Beijing Gaov Inc.]
    <Desktop><C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll>  []
    <dotn7><RunDll32 "C:\WINDOWS\Downlo~1\dotn7.dll",Run>  [Microsoft Corporation]
    <CdnCtr><>  []
    <BigDog305><C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)>  []
    <stup.exe><C:\PROGRA~1\TENCENT\Adplus\stup.exe>  [Tencent]
    <SearchNet_Up><C:\Program Files\SearchNet\ServeUp.exe>  [中搜在线]
    <SrvNet32><RunDll32 "C:\Program Files\SearchNet\SrvNet32.dll",Run>  []
    <Realplayer.exe><C:\WINDOWS\system32\Realplayer.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
    <{93994DE8-8239-4655-B1D1-5F4E91300429}><C:\PROGRA~1\DVDIDL~1\DVDShell.dll>  [Fengtao Software Inc.]
    <{4FBB761B-558A-41E7-A97B-5E34B364AAC9}><C:\WINDOWS\system32\Qjiv.dll>  []
    <{C0805E87-24F4-45EB-9B65-155EBE86D88D}><C:\WINDOWS\system32\Evxyd.dll>  []
    <{28614639-7B60-4CC8-8AD2-01A3079AC71D}><C:\WINDOWS\system32\Lrtj.dll>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igrswn]
    <WinlogonNotify: igrswn><C:\Program Files\lenovo\IGRS\Ext\igrswn.dll>  [Lenovo Group Limited]

==================================
启动文件夹
[DSLMON]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\DSLMON.lnk><N>
[Picture Package VCD Maker]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Picture Package VCD Maker.lnk><N>
[Picture Package Menu]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Picture Package Menu.lnk><N>
[腾讯QQ]
  <C:\Documents and Settings\lenovo\「开始」菜单\程序\启动\腾讯QQ.lnk><N>
[地址栏搜索]
  <C:\Documents and Settings\lenovo\「开始」菜单\程序\启动\地址栏搜索.lnk><N>

==================================
服务
[FspadSvc / FspadSvc]
  <C:\Program Files\AVC Finger-sensing Pad Driver\FspadSvr.exe><N/A>
[General Updater/AutoUpdater Service / GUA]
  <"C:\Program Files\lenovo\GUA\GUA.exe"><lenovo>
[IGRS / IGRS]
  <C:\Program Files\lenovo\IGRS\IGRS.exe><Lenovo Group Limited>
[IGRSFILE / IGRSFILE]
  <C:\Program Files\lenovo\IGRS Profiles\File Profile\IgrsFile.exe><Lenovo Group Limited>
[IgrsFileShare / IgrsFileShare]
  <"C:\Program Files\lenovo\IGRS EasyShare\FileShare.exe"><联想集团有限公司>
[IgrsMonitor / IgrsMonitor]
  <"C:\Program Files\lenovo\IGRS\Ext\IgrsMonitor.exe"><Lenovo Group Limited>
[MicroGrid DirectRouter / MicroGrid.DirectRouter]
  <C:\Program Files\lenovo\IGRS\Ext\router.exe><Lenovo Group Limited>
[NVIDIA Display Driver Service / NVSvc]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[WMCSVC / WMCSVC]
  <C:\Program Files\lenovo\IGRS\Ext\wmcsvc.exe><Lenovo Group Limited>

==================================
浏览器加载项
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[MonitorURL Class]
  {08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, >
[Tencent Browser Helper]
  {0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\Adplus\SSAddr.dll, Tencent>
[]
  {28614639-7B60-4CC8-8AD2-01A3079AC71D} <C:\WINDOWS\system32\Lrtj.dll, N/A>
[IE Address Browser Helper]
  {2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[IE Browser Helper]
  {3CE496D1-1746-41CD-9489-3C0B93DF10E2} <C:\WINDOWS\Downlo~1\bqny584z.dll, 中搜在线软件有限公司>
[Wbho Class]
  {40E3A34A-3282-41F8-AD2C-051BAB96AD4A} <C:\WINDOWS\system32\Ipripw.dll, >
[]
  {4FBB761B-558A-41E7-A97B-5E34B364AAC9} <C:\WINDOWS\system32\Qjiv.dll, N/A>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <D:\qq2\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[]
  {669751ED-D558-49AE-B01A-3B374CC7910E} <C:\WINDOWS\system32\ssup.dll, TENCENT>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\迅雷\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[Google Toolbar Helper]
  {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[]
  {C0805E87-24F4-45EB-9B65-155EBE86D88D} <C:\WINDOWS\system32\Evxyd.dll, N/A>
[联想]
  {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.lenovo.com, N/A>
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\qq2\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\qq2\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[闪联任意通]
  {0C9B3AB9-DEDF-11D8-A2D4-0050FC464B19} <C:\Program Files\lenovo\IGRS EasyShare\IgrsAnywhere.dll, Lenovo Group Limited>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[Office Update Installation Engine]
  {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} <C:\WINDOWS\opuc.dll, Microsoft Corporation>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Google Script Object]
  {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[MonitorURL Class]
  {08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, >
[Tencent Browser Helper]
  {0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\Adplus\SSAddr.dll, Tencent>
1
查看完整版本: 跳网页,IE被改,无邪无邪快来呀