主页被劫持为
http://www.google.com.sohu.com.baidu.com.bibipv.cn/ren0w1la0lly0so1baidubaidubaidubaidubaidubaidubaidubaidubaidu.htm运用了卡巴斯基,卡卡,瑞星,兔子,兵刃,网页保护神,注册表修改等数十种方法统统的不好使。主页可以修改,但是改过关闭后,再启动还是上述地址。
扫描日志:
瑞星卡卡电脑诊断日志 v1.30 (2009-2-2 14:30:4) 北京瑞星信息技术有限公司
注释: [A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
+ 系统服务
+ HKLM\System\CurrentControlSet\Services
aspnet_state
[A ] 1. c:\windows\microsoft.net\framework\v1.1.4322\aspnet_state.exe
aswUpdSv
[AM] 2. c:\program files\alwil software\avast4\aswupdsv.exe
Ati HotKey Poller
[AM] 3. c:\windows\system32\ati2evxx.exe
avast! Antivirus
[AM] 4. c:\program files\alwil software\avast4\ashserv.exe
avast! Mail Scanner
[AM] 5. c:\program files\alwil software\avast4\ashmaisv.exe
avast! Web Scanner
[AM] 6. c:\program files\alwil software\avast4\ashwebsv.exe
hpqcxs08
[A ] 7. c:\program files\hp\digital imaging\bin\hpqcxs08.dll
MDM
[AM] 8. c:\program files\common files\microsoft shared\vs7debug\mdm.exe
Net Driver HPZ12
[AM] 9. c:\windows\system32\hpzinw12.dll
ose
[A ] 10. c:\program files\common files\microsoft shared\source engine\ose.exe
Pml Driver HPZ12
[AM] 11. c:\windows\system32\hpzipm12.dll
RegSrvc
[AM] 12. c:\windows\system32\regsrvc.exe
S24EventMonitor
[AM] 13. c:\windows\system32\s24evmon.exe
ServiceLayer
[A ] 14. c:\program files\pc connectivity solution\servicelayer.exe
WudfSvc
[AM] 15. c:\windows\system32\wudfsvc.dll
+ 内核驱动
+ HKLM\System\CurrentControlSet\Services
a320raid
[A ] 16. c:\windows\system32\drivers\a320raid.sys
aar1210
[A ] 17. c:\windows\system32\drivers\aar1210.sys
Aavmker4
[A ] 18. c:\windows\system32\drivers\aavmker4.sys
adpu320
[A ] 19. c:\windows\system32\drivers\adpu320.sys
aec6210
[A ] 20. c:\windows\system32\drivers\aec6210.sys
aec6260
[A ] 21. c:\windows\system32\drivers\aec6260.sys
aec6280
[A ] 22. c:\windows\system32\drivers\aec6280.sys
AEC6890
[A ] 23. c:\windows\system32\drivers\aec6890.sys
aec68x5
[A ] 24. c:\windows\system32\drivers\aec68x5.sys
aswRdr
[A ] 25. c:\windows\system32\drivers\aswrdr.sys
aswSP
[A ] 26. c:\windows\system32\drivers\aswsp.sys
aswTdi
[A ] 27. c:\windows\system32\drivers\aswtdi.sys
fasttrak
[A ] 28. c:\windows\system32\drivers\fasttrak.sys
fasttx2k
[A ] 29. c:\windows\system32\drivers\fasttx2k.sys
fasttx2k2
[A ] 30. c:\windows\system32\drivers\fasttx2k2.sys
Hpt366
[A ] 31. c:\windows\system32\drivers\hpt366.sys
HPT371
[A ] 32. c:\windows\system32\drivers\hpt371.sys
hpt374
[A ] 33. c:\windows\system32\drivers\hpt374.sys
hpt3xx
[A ] 34. c:\windows\system32\drivers\hpt3xx.sys
hptmv
[A ] 35. c:\windows\system32\drivers\hptmv.sys
hptpro
[A ] 36. c:\windows\system32\drivers\hptpro.sys
HPZid412
[A ] 37. c:\windows\system32\drivers\hpzid412.sys
HPZipr12
[A ] 38. c:\windows\system32\drivers\hpzipr12.sys
HPZius12
[A ] 39. c:\windows\system32\drivers\hpzius12.sys
HSFHWICH
[A ] 40. c:\windows\system32\drivers\hsfhwich.sys
HSF_DP
[A ] 41. c:\windows\system32\drivers\hsf_dp.sys
iaStor
[A ] 42. c:\windows\system32\drivers\iastor.sys
iteraid
[A ] 43. c:\windows\system32\drivers\iteraid.sys
L8042Kbd
[A ] 44. c:\windows\system32\drivers\l8042kbd.sys
L8042mou
[A ] 45. c:\windows\system32\drivers\l8042mou.sys
LHidFilt
[A ] 46. c:\windows\system32\drivers\lhidfilt.sys
LMouFilt
[A ] 47. c:\windows\system32\drivers\lmoufilt.sys
LMouKE
[A ] 48. c:\windows\system32\drivers\lmouke.sys
LUsbFilt
[A ] 49. c:\windows\system32\drivers\lusbfilt.sys
m5228
[A ] 50. c:\windows\system32\drivers\m5228.sys
m5281
[A ] 51. c:\windows\system32\drivers\m5281.sys
MDC8021X
[A ] 52. c:\windows\system32\drivers\mdc8021x.sys
mdmxsdk
[A ] 53. c:\windows\system32\drivers\mdmxsdk.sys
MegaIDE
[A ] 54. c:\windows\system32\drivers\megaide.sys
mraid2k
[A ] 55. c:\windows\system32\drivers\mraid2k.sys
nmwcd
[A ] 56. c:\windows\system32\drivers\ccdcmb.sys
nmwcdc
[A ] 57. c:\windows\system32\drivers\ccdcmbo.sys
npkcrypt
[A ] 58. c:\windows\system32\npkcrypt.sys
npkycryp
[A ] 59. c:\windows\system32\npkycryp.sys
O2SCBUS
[A ] 60. c:\windows\system32\drivers\ozscr.sys
OMCI
[A ] 61. c:\windows\system32\drivers\omci.sys
pccsmcfd
[A ] 62. c:\windows\system32\drivers\pccsmcfd.sys
Pnp680
[A ] 63. c:\windows\system32\drivers\pnp680.sys
Pnp680r
[A ] 64. c:\windows\system32\drivers\pnp680r.sys
s24trans
[A ] 65. c:\windows\system32\drivers\s24trans.sys
Secdrv
[A ] 66. c:\windows\system32\drivers\secdrv.sys
SI3112
[A ] 67. c:\windows\system32\drivers\si3112.sys
SI3112r
[A ] 68. c:\windows\system32\drivers\si3112r.sys
SI3114
[A ] 69. c:\windows\system32\drivers\si3114.sys
SI3114r
[A ] 70. c:\windows\system32\drivers\si3114r.sys
SI3124
[A ] 71. c:\windows\system32\drivers\si3124.sys
SI3124r
[A ] 72. c:\windows\system32\drivers\si3124r.sys
SiFilter
[A ] 73. c:\windows\system32\drivers\siwinacc.sys
SiSRaid
[A ] 74. c:\windows\system32\drivers\sisraid.sys
SiSRaid1
[A ] 75. c:\windows\system32\drivers\sisraid1.sys
sptrak
[A ] 76. c:\windows\system32\drivers\sptrak.sys
STAC97
[A ] 77. c:\windows\system32\drivers\stac97.sys
SVKP
[A ] 78. c:\windows\system32\svkp.sys
UlSata
[A ] 79. c:\windows\system32\drivers\ulsata.sys
upperdev
[A ] 80. c:\windows\system32\drivers\usbser_lowerflt.sys
UsbserFilt
[A ] 81. c:\windows\system32\drivers\usbser_lowerfltj.sys
VCOM_WirelessMgr
[A ] 82. c:\windows\system32\drivers\vcom_a2000p.sys
viamraid
[A ] 83. c:\windows\system32\drivers\viamraid.sys
viapdsk
[A ] 84. c:\windows\system32\drivers\viapdsk.sys
viaraid
[A ] 85. c:\windows\system32\drivers\viaraid.sys
viasraid
[A ] 86. c:\windows\system32\drivers\viasraid.sys
vmscsi
[A ] 87. c:\windows\system32\drivers\vmscsi.sys
w22n51
[A ] 88. c:\windows\system32\drivers\w22n51.sys
Wdf01000
[A ] 89. c:\windows\system32\drivers\wdf01000.sys
winachsf
[A ] 90. c:\windows\system32\drivers\hsf_cnxt.sys
WudfPf
[A ] 91. c:\windows\system32\drivers\wudfpf.sys
WudfRd
[A ] 92. c:\windows\system32\drivers\wudfrd.sys
zusbdemo
[A ] 93. c:\windows\system32\drivers\zusbdemo.sys
+ 文件系统驱动
+ HKLM\System\CurrentControlSet\Services
aswFsBlk
[A ] 94. c:\windows\system32\drivers\aswfsblk.sys
aswMon2
[A ] 95. c:\windows\system32\drivers\aswmon2.sys
+ 系统登陆自运行
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
AtiExtEvent
[AM] 96. c:\windows\system32\ati2evxx.dll
Sebring
[AM] 97. c:\windows\system32\lgnotify.dll
+ IE浏览器加载模块
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{889D2FEB-5411-4565-8998-1DD2C5261283}
[AM] 98. d:\迅雷\comdlls\xunleibho_now.dll
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
application/octet-stream
[A ] 99. c:\windows\system32\mscoree.dll
application/x-complus
[A ] 99. c:\windows\system32\mscoree.dll
application/x-msdownload
[A ] 99. c:\windows\system32\mscoree.dll
text/xml
[A ] 100. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
ic32pp
[A ] 101. c:\windows\wc98pp.dll
ms-itss
[A ] 102. c:\program files\common files\microsoft shared\information retrieval\msitss.dll
mso-offdap11
[A ] 103. c:\program files\common files\microsoft shared\web components\11\owc11.dll
+ HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers
{0561EC90-CE54-4f0c-9C55-E226110A740C}
[AM] 104. c:\program files\haali\matroskasplitter\mmfinfo.dll
{F9DB5320-233E-11D1-9F84-707F02C10627}
[AM] 105. c:\program files\common files\adobe\acrobat\activex\pdfshell.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 106. c:\windows\system32\hticons.dll
Fusion Cache
[A ] 99. c:\windows\system32\mscoree.dll
Web Folders
[A ] 107. c:\program files\common files\microsoft shared\web folders\msonsext.dll
Microsoft Office HTML Icon Handler
[AM] 108. c:\program files\microsoft office\office11\msohev.dll
avast
[AM] 109. c:\program files\alwil software\avast4\ashshell.dll
WinRAR shell extension
[AM] 110. d:\解压\rarext.dll
PicaView
[A ] 111. d:\acdsee3.1\acdsee\picaview.dll
UnlockerShellExtension
[AM] 112. d:\删除软件\unlocker\unlockercom.dll
Portable Media Devices
[A ] 113. c:\windows\system32\audiodev.dll
Portable Media Devices Menu
[A ] 113. c:\windows\system32\audiodev.dll
Portable Devices
[A ] 114. c:\windows\system32\wpdshext.dll
Portable Devices Menu
[A ] 114. c:\windows\system32\wpdshext.dll
诺基亚手机浏览器
[AM] 115. d:\pcn81\nokia pc suite 7\phonebrowser.dll
Haali Column Provider
[AM] 104. c:\program files\haali\matroskasplitter\mmfinfo.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
WPDShServiceObj
[AM] 116. c:\windows\system32\wpdshserviceobj.dll
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 117. c:\windows\system32\kknative.exe
+ 映像劫持
+ HKCR\.html
htmlfile\Edit\Command
[A ] 118. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 118. c:\program files\microsoft office\office11\msohtmed.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 118. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 118. c:\program files\microsoft office\office11\msohtmed.exe
+ HKCR\.log
UltraEdit.log\open\Command
[A ] 119. c:\program files\idm computer solutions\ultraedit\uedit32.exe
UltraEdit.log\print\Command
[A ] 119. c:\program files\idm computer solutions\ultraedit\uedit32.exe
+ HKCR\.js
UltraEdit.js\open\Command
[A ] 119. c:\program files\idm computer solutions\ultraedit\uedit32.exe
UltraEdit.js\print\Command
[A ] 119. c:\program files\idm computer solutions\ultraedit\uedit32.exe
+ HKCR\.mp3
QQMusic.mp3\QQMusic.1.Play\Command
[A ] 120. d:\qqmusic\qqmusic.exe
QQMusic.mp3\QQMusic.2.Add\Command
[A ] 120. d:\qqmusic\qqmusic.exe
+ HKCR\.ini
UltraEdit.ini\open\Command
[A ] 119. c:\program files\idm computer solutions\ultraedit\uedit32.exe
UltraEdit.ini\print\Command
[A ] 119. c:\program files\idm computer solutions\ultraedit\uedit32.exe
+ 程序初始化和已知动态连接库
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
[AM] 121. c:\windows\system32\kmon.dll
+ 打印机监控
+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
Microsoft Document Imaging Writer Monitor
[AM] 122. c:\windows\system32\mdimon.dll
PCL hpz3l4x6
[AM] 123. c:\windows\system32\hpz3l4x6.dll
+ 其他自启动项目
+ C:\Documents and Settings\Administrator\「开始」菜单\程序\启动
qq.exe
[A ] 124. c:\documents and settings\administrator\「开始」菜单\程序\启动\qq.exe
+ C:\WINDOWS\Tasks
SogouImeMgr.job
[A ] 125. c:\program files\sogouinput\4.0.0.2088\pinyinrepair.exe
+ 正在运行的进程
+ 000000e0(224) SCardSvr.exe
60000000[00074000]
[AM] 121. c:\windows\system32\kmon.dll
+ 0000010c(268) svchost.exe
+ 00000150(336) ZCfgSvc.exe
00400000[00061000]
[ M] 126. c:\windows\system32\zcfgsvc.exe
10000000[0003A000]
[ M] 127. c:\windows\system32\pfmgrapi.dll
00380000[0002D000]
[ M] 128. c:\windows\system32\psregapi.dll
00470000[0008D000]
[ M] 129. c:\windows\system32\wconfig.dll
003B0000[0001C000]
[ M] 130. c:\windows\system32\wifiadap.dll
00500000[000DF000]
[ M] 131. c:\windows\system32\psguimgr.dll
005E0000[00037000]
[ M] 132. c:\windows\system32\c1xstngs.dll
60000000[00074000]
[AM] 121. c:\windows\system32\kmon.dll
01030000[00008000]
[ M] 133. c:\program files\intel\prosetwireless\proset\chs\zcsvcchs.dll
01050000[00005000]
[ M] 134. c:\program files\intel\prosetwireless\proset\chs\pmapichs.dll
01180000[00012000]
[ M] 135. c:\windows\system32\s24mudll.dll
65780000[00023000]
[ M] 136. c:\program files\alwil software\avast4\ahjsctns.dll
018F0000[00010000]
[ M] 137. c:\program files\intel\prosetwireless\proset\chs\c1xstchs.dll
+ 0000018c(396) smss.exe
+ 000001d0(464) rundll32.exe
60000000[00074000]
[AM] 121. c:\windows\system32\kmon.dll
65780000[00023000]
[ M] 136. c:\program files\alwil software\avast4\ahjsctns.dll
+ 0000020c(524) Ati2evxx.exe
00400000[00062000]
[AM] 3. c:\windows\system32\ati2evxx.exe
60000000[00074000]
[AM] 121. c:\windows\system32\kmon.dll
+ 00000250(592) 1XConfig.exe
00400000[00030000]
[ M] 138. c:\windows\system32\1xconfig.exe
10000000[000FF000]
[ M] 139. c:\windows\system32\intelae5.dll
00370000[00024000]
[ M] 140. c:\windows\system32\ssleay32.dll
00430000[000A1000]
[ M] 141. c:\windows\system32\libeay32.dll
003A0000[0002D000]
[ M] 128. c:\windows\system32\psregapi.dll
60000000[00074000]
[AM] 121. c:\windows\system32\kmon.dll
65780000[00023000]
[ M] 136. c:\program files\alwil software\avast4\ahjsctns.dll
+ 000002ac(684) Explorer.EXE
60000000[00074000]
[AM] 121. c:\windows\system32\kmon.dll
65780000[00023000]
[ M] 136. c:\program files\alwil software\avast4\ahjsctns.dll
164A0000[00023000]
[AM] 116. c:\windows\system32\wpdshserviceobj.dll
72C80000[00008000]
[ M] 142. c:\windows\system32\msacm32.drv
10000000[00099000]
[AM] 115. d:\pcn81\nokia pc suite 7\phonebrowser.dll
01CB0000[000CA000]
[ M] 143. d:\pcn81\nokia pc suite 7\ngscm.dll
01B80000[00006000]
[ M] 144. d:\pcn81\nokia pc suite 7\lang\phonebrowser_chi-sc.nlr
02030000[0008E000]
[ M] 145. d:\pcn81\nokia pc suite 7\resource\phonebrowser_nokia.ngr
109C0000[0002C000]
[ M] 146. c:\windows\system32\portabledevicetypes.dll
10930000[00049000]
[ M] 147. c:\windows\system32\portabledeviceapi.dll
014E0000[00006000]
[AM] 112. d:\删除软件\unlocker\unlockercom.dll
01500000[0002E000]
[AM] 110. d:\解压\rarext.dll
01530000[00019000]
[ M] 148. c:\program files\idm computer solutions\ultraedit\ue32ctmn.dll
64F00000[00012000]
[AM] 109. c:\program files\alwil software\avast4\ashshell.dll
02FE0000[0000F000]
[AM] 104. c:\program files\haali\matroskasplitter\mmfinfo.dll
030D0000[0000B000]
[ M] 149. c:\program files\haali\matroskasplitter\mkunicode.dll
03450000[0005B000]
[AM] 105. c:\program files\common files\adobe\acrobat\activex\pdfshell.dll
037C0000[0004C000]
[ M] 150. c:\program files\common files\adobe\acrobat\activex\pdfshell.chs
032A0000[00031000]
[AM] 98. d:\迅雷\comdlls\xunleibho_now.dll
24240000[0000E000]
[ M] 151. d:\迅雷\components\resworker\dsbho_01.dll
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)