瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求助:机器很慢,而且主机总是响,浏览器也被劫持了,有日志

1   1  /  1  页   跳转

求助:机器很慢,而且主机总是响,浏览器也被劫持了,有日志

求助:机器很慢,而且主机总是响,浏览器也被劫持了,有日志

机子很慢,还总是好没响应,请高手帮助看看日志,谢谢

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows 98 SE  -

启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <internat.exe><REM internat.exe>  [Microsoft Corporation]
    <LoadPowerProfile><REM Rundll32.exe powrprof.dll,LoadCurrentPwrScheme>  [Microsoft Corporation]
    <KAVRUN><REM C:\KAV\KAVRUN.EXE>  [kingsoft]
    <TkBellExe><REM "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot>  [RealNetworks, Inc.]
    <kvw3000><REM C:\KVW3000\kvplus.exe /tray>  [Beijing Jiangmin New Tech. & Sci. Co.Ltd.]
    <Kernel32><C:\WINDOWS\SYSTEM\Kernel.dll>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
    <LoadPowerProfile><REM Rundll32.exe powrprof.dll,LoadCurrentPwrScheme>  [Microsoft Corporation]
    <SchedulingAgent><REM C:\WINDOWS\SYSTEM\mstask.exe>  [Microsoft Corporation]
    <KVSrv><REM C:\KVW3000\KVSRVX.EXE -Service>  [LANK Soft.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]

==================================
启动文件夹
N/A

==================================
服务
N/A

==================================
驱动程序
N/A

==================================
浏览器加载项
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\PROGRAM FILES\TENCENT\QQ\QQ.EXE, TENCENT>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH9B.OCX, Adobe Systems, Inc.>
[AxSubmitControl Class]
  {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} <C:\WINDOWS\SYSTEM\SUBMIT~1.DLL, ,>
[RootCertInstall Class]
  {D1056C7C-E30B-4234-9A4B-7E1038B167A7} <C:\WINDOWS\DOWNLO~1\ROOTCERT.DLL, $>
[PowerPlayer Control]
  {5EC7C511-CD0F-42E6-830C-1BD9882F3458} <C:\WINDOWS\DOWNLO~1\POWERP~1.DLL, PPStream Inc.>
[添加QQ网络收藏夹]
  <C:\PROGRAM FILES\TENCENT\NAF.htm, N/A>
[添加到QQ自定义面板]
  <C:\PROGRAM FILES\TENCENT\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\PROGRAM FILES\TENCENT\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\PROGRAM FILES\TENCENT\QQ\SendMMS.htm, N/A>
[上传到QQ网络硬盘]
  <C:\PROGRAM FILES\TENCENT\QQ\AddToNetDisk.htm, N/A>

==================================
正在运行的进程
[PID: 4294940827][C:\WINDOWS\SYSTEM\SPOOL32.EXE]  [Microsoft Corporation, 4.10.1998]
[PID: 4294947579][C:\WINDOWS\SYSTEM\MPREXE.EXE]  [Microsoft Corporation, 4.10.1998]
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  [N/A, N/A]
[PID: 4294866171][C:\WINDOWS\EXPLORER.EXE]  [Microsoft Corporation, 4.72.3110.1]
    [C:\WINDOWS\SYSTEM\KVWSP.DLL]  [JiangMin Ltd., 6, 6, 0, 135]
[PID: 4294785111][C:\WINDOWS\DESKTOP\SRENG.EXE]  [Smallfrogs Studio, 2.2.6.605]

==================================
文件关联
.TXT  OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [C:\WINDOWS\winhlp32.exe %1]
.INI  OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF  OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS  OK. [C:\WINDOWS\WScript.exe "%1" %*]
.JS  OK. [C:\WINDOWS\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
KVWSP over [MS.w95.spi.tcp]
    C:\WINDOWS\SYSTEM\KVWSP.DLL(JiangMin Ltd., KVWSP)
KVWSP over [MS.w95.spi.udp]
    C:\WINDOWS\SYSTEM\KVWSP.DLL(JiangMin Ltd., KVWSP)
MS.w95.spi.osp
    C:\WINDOWS\SYSTEM\mswsosp.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.tcp
    C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.udp
    C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.raw
    C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.rsvptcp
    C:\WINDOWS\SYSTEM\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
MS.w95.spi.rsvpudp
    C:\WINDOWS\SYSTEM\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
KVWSP
    C:\WINDOWS\SYSTEM\KVWSP.DLL(JiangMin Ltd., KVWSP)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
N/A

==================================
最后编辑2006-12-14 22:19:44
分享到:
gototop
 

Windows 98 不慢才怪,升级一下吧
gototop
 

升级是不是就得重装系统?还是怎么升级?
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT