瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 斑竹~~【应该是流氓软件的问题】2,有图,在线等~~

123   1  /  3  页   跳转

斑竹~~【应该是流氓软件的问题】2,有图,在线等~~

斑竹~~【应该是流氓软件的问题】2,有图,在线等~~

这个,就象QQ消息一样,一会就出来一次

[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)

附件附件:

下载次数:525
文件类型:image/pjpeg
文件大小:
上传时间:2007-12-13 12:56:32
描述:
预览信息:EXIF信息



最后编辑2007-12-27 11:55:29.110000000
分享到:
gototop
 

你用的是什么浏览器,建议用卡卡助手清理
gototop
 

引用:
【9876532的贴子】你用的是什么浏览器,建议用卡卡助手清理
………………

那些都用过了,不管用
gototop
 

用的是什么浏览器
gototop
 

微软的IE6.0
gototop
 

下载SREng,地址:http://www.kztechs.com/sreng/download.html
用智能扫描扫个日志,以附件的形式发上来。
gototop
 

为什么贴不上来?
gototop
 

为什么我的日志贴不上来?
gototop
 

[CODE]

2007-12-13,17:01:29

System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)

Windows 2000 Professional Service Pack 4 (Build 2195) - 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Internat.exe><internat.exe> [(Verified)]
<KASStart><"C:\Program Files\Kingsoft\KSysCleaner\KASStart.EXE" -Startup> [Kingsoft Corporation]
<iDuba Personal FireWall><C:\KAV6\KAVPFW.EXE> [Kingsoft Corporation]
<msnmsgr><"C:\Program Files\MSN Messenger\msnmsgr.exe" /background> [Microsoft Corporation]
<Skype><"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized> [(Verified)Skype Technologies SA]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Synchronization Manager><mobsync.exe /logon> [(Verified)]
<HotKeysCmds><C:\WINNT\system32\hkcmd.exe> [Intel Corporation]
<SigmatelSysTrayApp><stsystra.exe> [SigmaTel, Inc.]
<Logitech Utility><Logi_MwX.Exe> [Logitech Inc.]
<ATICCC><"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay> [N/A]
<KAVRun><C:\KAV6\KAVRun.EXE> [kingsoft]
<Kulansyn><C:\KAV6\Kulansyn.EXE> [Kingsoft Corp.]
<KpopMon><C:\KAV6\KpopMon.EXE> []
<iDuba Personal FireWall><C:\KAV6\KAVPFW.EXE> [Kingsoft Corporation]
<NeroFilterCheck><C:\WINNT\system32\NeroCheck.exe> [Ahead Software Gmbh]
<SoundMAXPnP><C:\Program Files\Analog Devices\Core\smax4pnp.exe> [Analog Devices, Inc.]
<RemoteControl><"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"> [(Verified)CyberLink]
<LanguageShortcut><"C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"> [(Verified)CyberLink]
<StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> []
<桌面图标文字自动透明><C:\Documents and Settings\user.USER-WEE\桌面\rj07080201\优化大师破解版(绿色版)\WoptiMem.exe XP> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)]
<Userinit><C:\WINNT\system32\userinit.exe,> [(Verified)]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer 访问><"C:\WINNT\system32\shmgrate.exe" OCInstallUserConfigIE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express 访问><"C:\WINNT\system32\shmgrate.exe" OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\wmp.inf,PerUserStub> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<Address Book 5><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><C:\WINNT\system32\Rundll32.exe C:\WINNT\system32\mscories.dll,Install> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
<CRLUpdate><%SystemRoot%\system32\updcrl.exe -e -u %SystemRoot%\system32\verisignpub1.crl> [N/A]

==================================
启动文件夹
[金山词霸 2003]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\金山词霸 2003.lnk --> C:\PROGRA~1\Kingsoft\POWERW~1\XDICT.EXE [Kingsoft Co, Ltd.]><H>
[腾讯QQ]
<C:\Documents and Settings\user.USER-WEE\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><N>

==================================
服务
[Adobe LM Service / Adobe LM Service][Running/Manual Start]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
<C:\WINNT\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart][Stopped/Auto Start]
<C:\WINNT\system32\ati2sgag.exe><>
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[EpsonBidirectionalService / EpsonBidirectionalService][Running/Auto Start]
<C:\Program Files\Common Files\EPSON\eEBAPI\eEBSVC.exe><N/A>
[EpsonNet Primitive Service / EpsonNet_Primitive_Service][Running/Auto Start]
<"C:\Program Files\EpsonNet\common\bin\ensrvmgr.exe"><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[Kingsoft AntiVirus Service / KAVSvc][Running/Auto Start]
<C:\KAV6\KAVSvc.EXE><kingsoft Antivirus>
[Telephonyl / micro][Stopped/Auto Start]
<C:\WINNT\system32\micro.exe><N/A>
[Panasonic Trap Monitor Service / Panasonic Trap Monitor Service][Running/Auto Start]
<"C:\Program Files\Panasonic\TrapMonitor\Trapmnnt.exe"><Panasonic>
[Tencent QQUpdate Services / QQUpdateService][Running/Auto Start]
<C:\WINNT\QQUpdate.exe -s><Microsoft Corporation>
[Cyberlink RichVideo Service(CRVS) / RichVideo][Running/Auto Start]
<"C:\Program Files\CyberLink\Shared Files\RichVideo.exe"><>
[VNC Server Version 4 / WinVNC4][Running/Auto Start]
<"C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service><RealVNC Ltd.>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
<C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\system32\mspmsnsv.dll><Microsoft Corporation>
[Z-SAN Service / Z-SANService][Running/Auto Start]
<C:\Program Files\NETGEAR\NETGEAR Storage Central Manager Utility\Z-SANService.exe><Zetera Corporation>
gototop
 

==================================
驱动程序
[ADI UAA Function Driver for High Definition Audio Service / ADIHdAudAddService][Running/Manual Start]
<system32\drivers\ADIHdAud.sys><Analog Devices, Inc.>
[aeaudio / aeaudio][Stopped/Manual Start]
<system32\drivers\aeaudio.sys><N/A>
[ati2mtag / ati2mtag][Running/Manual Start]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Broadcom NetXtreme Gigabit Ethernet / b57w2k][Running/Manual Start]
<system32\DRIVERS\b57w2k.sys><Broadcom Corporation>
[dmboot / dmboot][Stopped/Disabled]
<System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
<\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload][Running/Boot Start]
<\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[Intel(R) PRO Network Connection Driver / E100B][Stopped/Manual Start]
<system32\DRIVERS\e100bnt5.sys><Intel Corporation>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[ialm / ialm][Stopped/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[KNetWch / KNetWch][Running/System Start]
<\??\C:\KAV6\KNetWch.SYS><金山电脑公司>
[KWatch / KWatch][Running/Manual Start]
<\??\C:\WINNT\system32\drivers\KWatch.Sys><Kingsoft Corporation>
[Logitech PS/2 Mouse Filter Driver / L8042PR2][Stopped/Manual Start]
<System32\Drivers\l8042pr2.sys><Logitech, Inc.>
[Logitech HID/USB Mouse Filter Driver / LHidFlt2][Stopped/Manual Start]
<system32\DRIVERS\LHidFlt2.Sys><Logitech, Inc.>
[Logitech USB Receiver device driver / LHidUsb][Stopped/Manual Start]
<System32\Drivers\LHidUsb.Sys><Logitech, Inc.>
[Logitech Mouse Class Filter Driver / LMouFlt2][Stopped/Manual Start]
<System32\Drivers\LMouFlt2.sys><Logitech, Inc.>
[BDA MPE Filter / MPE][Stopped/Manual Start]
<system32\DRIVERS\MPE.sys><Microsoft Corporation>
[NABTS/FEC VBI Codec / NABTSFEC][Stopped/Manual Start]
<system32\DRIVERS\NABTSFEC.sys><Microsoft Corporation>
[OMCI / OMCI][Running/System Start]
<\SystemRoot\SYSTEM32\DRIVERS\OMCI.SYS><Dell Computer Corporation>
[Padus ASPI Shell / pfc][Running/Manual Start]
<system32\drivers\pfc.sys><Padus, Inc.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[SenFilt Service / SenFiltService][Running/Manual Start]
<system32\drivers\Senfilt.sys><Sensaura>
[DataPlow SFS for Zetera Storage Devices / SFSZ][Running/Auto Start]
<\SystemRoot\system32\drivers\sfsz.sys><DataPlow, Incorporated>
[BDA Slip De-Framer / SLIP][Stopped/Manual Start]
<system32\DRIVERS\SLIP.sys><Microsoft Corporation>
[smwdm / smwdm][Stopped/Manual Start]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[High Definition Audio Driver (WDM) - SigmaTel CODEC / STHDA][Stopped/Manual Start]
<system32\drivers\sthda.sys><SigmaTel, Inc.>
[BDA IPSink / streamip][Stopped/Manual Start]
<system32\DRIVERS\StreamIP.sys><Microsoft Corporation>
[TesSafe / TesSafe][Stopped/Manual Start]
<\??\C:\WINNT\system32\TesSafe.sys><TENCENT>
[Microsoft USB 2.0 Enhanced Host Controller Miniport Driver / usbehci][Running/Manual Start]
<system32\DRIVERS\usbehci.sys><Microsoft Corporation>
[USB 2.0 Root Hub Support / usbhub20][Running/Manual Start]
<system32\DRIVERS\usbhub20.sys><Microsoft Corporation>
[Windows CE USB Serial Host Driver / wceusbsh][Stopped/Manual Start]
<system32\DRIVERS\wceusbsh.sys><Microsoft Corporation>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[Zetera Virtual Bus / ZetBus][Running/Manual Start]
<system32\DRIVERS\ZetBus.sys><Zetera Corporation>
[ZetMPD / ZetMPD][Running/Manual Start]
<system32\DRIVERS\ZetMPD.sys><Zetera Corporation>
[ZetSFD / ZetSFD][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\ZetSFD.sys><Zetera Corporation>
[58328 / 58328][Running/]
<2 - 系统找不到指定的文件。
><N/A>

==================================
浏览器加载项
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[SafeMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 奇虎网>
[Java Plug-in 1.5.0]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll, Sun Microsystems, Inc.>
[EditCtrl Class]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINNT\system32\aliedit\aliedit.dll, >
[Java Plug-in 1.5.0]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll, Sun Microsystems, Inc.>
[MsnMessengerSetupDownloadControl Class]
{B38870E4-7ECB-40DA-8C6A-595F0A5519FF} <C:\WINNT\Downloaded Program Files\MsnMessengerSetupDownloader.ocx, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
[360SafeLive]
{87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360safe.com>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
gototop
 
123   1  /  3  页   跳转
页面顶部
Powered by Discuz!NT