一开机就弹一堆广告,弹完一堆后就不弹了,到下次开机又有。我检查过启动项,没可疑启动。。不知道怎么回事,扫描恶意软件又没有。从报告可以看出一堆IE进程,他们是隐藏的,我看不到他们。只有在进程里结束。
注释: [A]表示该文件存在自启动关联
[M]表示该文件在内存中
+ 注册表自运行项目
+ 系统服务
+ HKLM\System\CurrentControlSet\Services
Adobe LM Service
[A ] 1. c:\program files\common files\adobe systems shared\service\adobelmsvc.exe
aspnet_state
[A ] 2. c:\windows\microsoft.net\framework\v2.0.50727\aspnet_state.exe
clr_optimization_v2.0.50727_32
[A ] 3. c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe
FontCache3.0.0.0
[A ] 4. c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe
idsvc
[A ] 5. c:\windows\microsoft.net\framework\v3.0\windows communication foundation\infocard.exe
kaccore
[A ] 6. c:\program files\kingsoft\kac\service\kaccore.exe
Kingsoft Rescue Service
[AM] 7. f:\program files\kingsoft\ksm2.0\ksmsvc.exe
KSDSVC
[AM] 8. f:\program files\kingsoft\powerword pe\ksdsvc.exe
KxEServBeta
[AM] 9. c:\program files\common files\kingsoft\commonservice_beta\kxeserv.exe
MDM
[AM] 10. c:\program files\common files\microsoft shared\vs7debug\mdm.exe
NetTcpPortSharing
[A ] 11. c:\windows\microsoft.net\framework\v3.0\windows communication foundation\smsvchost.exe
文件名和"svchost.exe"类似
nlsvc
[A ] 12. f:\program files\netlimiter 2 pro\nlsvc.exe
NVSvc
[A ] 13. c:\windows\system32\nvsvc32.exe
O&O Defrag
[A ] 14. c:\windows\system32\oodag.exe
ose
[A ] 15. c:\program files\common files\microsoft shared\source engine\ose.exe
RsRavMon
[AM] 16. f:\program files\rising\rav\ravmond.exe
SbieSvc
[AM] 17. f:\program files\360 liulanqi\360se3\shield\sbiesvc.exe
TSUSVC
[A ] 18. d:\program files\tencent\qqsoftmgr\tencentupdatesvc.exe
ZhuDongFangYu
[A ] 19. f:\program files\360safe0\deepscan\zhudongfangyu.exe
+ 内核驱动
+ HKLM\System\CurrentControlSet\Services
360AntiArp
[A ] 20. c:\windows\system32\drivers\360antiarp.sys
360SelfProtection
[A ] 21. c:\windows\system32\drivers\360selfprotection.sys
9158CAP
[A ] 22. c:\windows\system32\drivers\9158cap.sys
ALCXWDM
[A ] 23. c:\windows\system32\drivers\alcxwdm.sys
aodunvpn
[A ] 24. c:\windows\system32\drivers\aodunvpn.sys
BFSDRV
[A ] 25. c:\windows\system32\drivers\bfsdrv.sys
bootsafe
[A ] 26. c:\windows\system32\drivers\bootsafe.sys
BREGDRV
[A ] 27. c:\windows\system32\drivers\bregdrv.sys
EagleNT
[A ] 28. c:\windows\system32\drivers\eaglent.sys
EfiMon
[A ] 29. c:\windows\system32\drivers\efimon.sys
ElbyCDFL
[A ] 30. c:\windows\system32\drivers\elbycdfl.sys
ElbyCDIO
[A ] 31. c:\windows\system32\drivers\elbycdio.sys
hookcont
[A ] 32. c:\windows\system32\drivers\hookcont.sys
HookPort
[A ] 33. c:\windows\system32\drivers\hookport.sys
hooksys
[A ] 34. c:\windows\system32\drivers\hooksys.sys
nltdi
[A ] 35. c:\windows\system32\drivers\nltdi.sys
npkcrypt
[A ] 36. c:\windows\system32\npkcrypt.sys
oreans32
[A ] 37. c:\windows\system32\drivers\oreans32.sys
Packet
[A ] 38. c:\windows\system32\drivers\protodrv.sys
QKeyService
[A ] 39. c:\windows\system32\keycrypt.sys
QQGameProtect
[A ] 40. c:\windows\system32\drivers\qqgameprotect.sys
qutmdserv
[A ] 41. c:\windows\system32\drivers\qutmdrv.sys
rsassist
[A ] 42. c:\windows\system32\drivers\rsassist.sys
RsNTGDI
[A ] 43. c:\windows\system32\drivers\rsntgdi.sys
RsProtect
[A ] 44. c:\windows\system32\drivers\rsptect.sys
RTL8023xp
[A ] 45. c:\windows\system32\drivers\rtnicxp.sys
SafeBoxKrnl
[A ] 46. c:\windows\system32\drivers\safeboxkrnl.sys
SbieDrv
[A ] 47. f:\program files\360 liulanqi\360se3\shield\sbiedrv.sys
Secdrv
[A ] 48. c:\windows\system32\drivers\secdrv.sys
sptd
[A ] 49. c:\windows\system32\drivers\sptd.sys
Tcpip
[A ] 50. c:\windows\system32\drivers\tcpip.sys
TesDrvPt
[A ] 51. c:\windows\system32\tesdrvpt.sys
TesSafe
[A ] 52. c:\windows\system32\tessafe.sys
WINIO
[A ] 53. c:\documents and settings\qj\桌面\新建文件夹\小q刷分软件\hknms.sys
+ 文件系统驱动
+ HKLM\System\CurrentControlSet\Services
exFat
[A ] 54. c:\windows\system32\drivers\exfat.sys
+ IE浏览器加载模块
+ HKCU\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks
{CFBFAE00-17A6-11D0-99CB-00C04FD64497}
[AM] 55. c:\windows\system32\ieframe.dll
{69248E74-4015-4ee8-BB78-7247AE9CC7F9}
[AM] 56. f:\program files\super rabbit\magicset\haokanbar.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{01443AEC-0FD1-40fd-9C87-E93D1494C233}
[AM] 57. f:\program files\thunder network\thunder\comdlls\tdatonce_now.dll
{53AC8551-0DE0-4606-8A1E-A51AF20ADD60}
[AM] 58. f:\program files\qvodplayer\qvodextend.dll
{889D2FEB-5411-4565-8998-1DD2C5261283}
[AM] 59. f:\program files\thunder network\thunder\comdlls\xunleibho_now.dll
{98B7C13A-E9CD-4959-8B46-FBEAB41E42A8}
[AM] 60. c:\windows\system32\urlfilter.dll
{9D9E8E93-78DE-4c43-9951-571BE86D5060}
[AM] 56. f:\program files\super rabbit\magicset\haokanbar.dll
{A28581A7-E2A8-4b6c-9CC9-4A4CC1EFD55A}
[AM] 61. f:\program files\kingsoft\powerword pe\selectforie.dll
{B69F34DD-F0F9-42DC-9EDD-957187DA688D}
[AM] 62. f:\program files\360safe0\safemon\safemon.dll
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
application/octet-stream
[AM] 63. c:\windows\system32\mscoree.dll
application/x-complus
[AM] 63. c:\windows\system32\mscoree.dll
application/x-msdownload
[AM] 63. c:\windows\system32\mscoree.dll
text/xml
[A ] 64. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
KuGoo
[A ] 65. c:\windows\system32\kugoo3downxcontrol.ocx
KuGoo3
[A ] 65. c:\windows\system32\kugoo3downxcontrol.ocx
ms-itss
[A ] 66. c:\program files\common files\microsoft shared\information retrieval\msitss.dll
mso-offdap11
[A ] 67. c:\program files\common files\microsoft shared\web components\11\owc11.dll
+ HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
[A ] 68. c:\windows\system32\ieudinit.exe
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
RISING
[AM] 69. c:\windows\system32\ravext.dll
+ 用户登陆自运行项目
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
360Safebox
[A ] 70. f:\program files\360safebox\safeboxtray.exe
360Safetray
[A ] 71. f:\program files\360safe0\safemon\360tray.exe
QuickTime Task
[A ] 72. c:\program files\codec\qttask.exe
RavTray
[AM] 73. f:\program files\rising\rav\rstray.exe
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 74. c:\windows\system32\bsmain.exe
+ 映像劫持
+ HKCR\.html
htmlfile\Edit\Command
[A ] 75. f:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Edit with Dreamweaver 8\Command
[A ] 76. c:\program files\macromedia\dreamweaver 8\dreamweaver.exe
htmlfile\open\Command
[AM] 77. d:\tencent\tt\bin\ttraveler.exe
htmlfile\Print\Command
[A ] 75. f:\program files\microsoft office\office11\msohtmed.exe
htmlfile\TencentTraveler\Command
[AM] 77. d:\tencent\tt\bin\ttraveler.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 75. f:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Edit with Dreamweaver 8\Command
[A ] 76. c:\program files\macromedia\dreamweaver 8\dreamweaver.exe
htmlfile\open\Command
[AM] 77. d:\tencent\tt\bin\ttraveler.exe
htmlfile\Print\Command
[A ] 75. f:\program files\microsoft office\office11\msohtmed.exe
htmlfile\TencentTraveler\Command
[AM] 77. d:\tencent\tt\bin\ttraveler.exe
+ HKCR\.js
JSFile\Edit\Command
[A ] 76. c:\program files\macromedia\dreamweaver 8\dreamweaver.exe
+ HKCR\.mp3
Audio.mp3\open\Command
[A ] 78. f:\program files\ttplayer\ttplayer.exe
Audio.mp3\PlayList\Command
[A ] 78. f:\program files\ttplayer\ttplayer.exe
+ 打印机监控
+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
Microsoft Document Imaging Writer Monitor
[AM] 79. c:\windows\system32\mdimon.dll
+ 其他自启动项目
+ C:\Documents and Settings\QJ\「开始」菜单\程序\启动
QQ游戏启动加速程序.lnk
[A ] 80. d:\program files\腾讯游戏\qqgame\accel.exe
+ C:\WINDOWS\Tasks
SogouImeMgr.job
[A ] 81. f:\program files\sogouinput\4.2.3.2813\pinyinrepair.exe
+ 正在运行的进程
+ 0000031c(796) smss.exe
+ 00000350(848) csrss.exe
+ 00000368(872) winlogon.exe
5ADC0000[00037000]
[ M] 82. c:\windows\system32\uxtheme.dll
72C80000[00008000]
[ M] 83. c:\windows\system32\msacm32.drv
+ 00000394(916) services.exe
5ADC0000[00037000]
[ M] 82. c:\windows\system32\uxtheme.dll
+ 000003a0(928) lsass.exe
5ADC0000[00037000]
[ M] 82. c:\windows\system32\uxtheme.dll
+ 00000424(1060) svchost.exe
5ADC0000[00037000]
[ M] 82. c:\windows\system32\uxtheme.dll
007B0000[00009000]
[ M] 84. c:\windows\system32\normaliz.dll
3EAB0000[00045000]
[ M] 85. c:\windows\system32\iertutil.dll
+ 00000448(1096) svchost.exe
5ADC0000[00037000]
[ M] 82. c:\windows\system32\uxtheme.dll
+ 00000494(1172) svchost.exe
5ADC0000[00037000]
[ M] 82. c:\windows\system32\uxtheme.dll
+ 000004bc(1212) kxeserv.exe
00400000[00023000]
[AM] 9. c:\program files\common files\kingsoft\commonservice_beta\kxeserv.exe
10000000[00012000]
[ M] 86. c:\program files\common files\kingsoft\commonservice_beta\jsonv6.dll
3EAB0000[00045000]
[ M] 85. c:\windows\system32\iertutil.dll
77020000[0009A000]
[ M] 87. c:\program files\common files\kingsoft\commonservice_beta\comres.dll
007A0000[0002F000]
[ M] 88. c:\program files\common files\kingsoft\commonservice_beta\kxedump.dll
008E0000[0000E000]
[ M] 89. c:\program files\common files\kingsoft\commonservice_beta\scom.dll
008F0000[0000D000]
[ M] 90. c:\program files\common files\kingsoft\commonservice_beta\kxebase.dll
00900000[00018000]
[ M] 91. c:\program files\common files\kingsoft\commonservice_beta\kxecore\kxelog.dll
00920000[0003A000]
[ M] 92. c:\program files\common files\kingsoft\commonservice_beta\kxecore\kxecore.dll
00A60000[0003A000]
[ M] 93. c:\program files\common files\kingsoft\commonservice_beta\kxecore\kxestat.dll
00AA0000[00009000]
[ M] 84. c:\windows\system32\normaliz.dll
+ 00000534(1332) svchost.exe
5ADC0000[00037000]
[ M] 82. c:\windows\system32\uxtheme.dll
009F0000[00009000]
[ M] 84. c:\windows\system32\normaliz.dll
3EAB0000[00045000]
[ M] 85. c:\windows\system32\iertutil.dll
+ 000005c0(1472) svchost.exe
5ADC0000[00037000]
[ M] 82. c:\windows\system32\uxtheme.dll
+ 000005d4(1492) RavMonD.exe
00400000[0002F000]
[AM] 16. f:\program files\rising\rav\ravmond.exe
10000000[00032000]
[ M] 94. f:\program files\rising\rav\combase.dll
01020000[00086000]
[ M] 95. f:\program files\rising\rav\cnt09.dll
010C0000[00019000]
[ M] 96. f:\program files\rising\rav\moncomm.dll
012D0000[0001D000]
[ M] 97. f:\program files\rising\rav\monbase.dll
01500000[00084000]
[ M] 98. f:\program files\rising\rav\rslog.dll
015B0000[00018000]
[ M] 99. f:\program files\rising\rav\mondrv.dll
016E0000[0002E000]
[ M] 100. f:\program files\rising\rav\defmon.dll
01720000[00010000]
[ M] 101. f:\program files\rising\rav\moncom08.dll
00E10000[0007E000]
[ M] 102. f:\program files\rising\rav\monrule.dll
00EE0000[00027000]
[ M] 103. f:\program files\rising\rav\filemon.dll
011E0000[0002F000]
[ M] 104. f:\program files\rising\rav\mailmon.dll
01220000[00015000]
[ M] 105. f:\program files\rising\rav\hookweb.dll
01740000[0008C000]
[ M] 106. f:\program files\rising\rav\rsindent.dll
01250000[00019000]
[ M] 107. f:\program files\rising\rav\syslay.dll
01290000[00017000]
[ M] 108. f:\program files\rising\rav\taskplug.dll
017D0000[00012000]
[ M] 109. f:\program files\rising\rav\scansrvp.dll
01BF0000[0001D000]
[ M] 110. f:\program files\rising\rav\cnt08.dll
01E20000[00019000]
[ M] 111. f:\program files\rising\rav\proccomm.dll
02150000[0000E000]
[ M] 112. f:\program files\rising\rav\rsappmgr.dll
02170000[00044000]
[ M] 113. f:\program files\rising\rav\cfgdll.dll
022C0000[0002D000]
[ M] 114. f:\program files\rising\rav\comx3.dll
02430000[00020000]
[ M] 115. f:\program files\rising\rav\hooksys.dll
024E0000[0001F000]
[ M] 116. f:\program files\rising\rav\proccom.dll
02500000[00024000]
[ M] 117. f:\program files\rising\rav\rscommx2.dll
02750000[00013000]
[ M] 118. f:\program files\rising\rav\hookcont.dll
02890000[0006F000]
[ M] 119. f:\program files\rising\rav\bacore.dll
02A20000[0003B000]
[ M] 120. f:\program files\rising\rav\recomp.dll
02A70000[00038000]
[ M] 121. f:\program files\rising\rav\refs.dll
02CD0000[00030000]
[ M] 122. f:\program files\rising\rav\viruslib.dll
02E10000[00029000]
[ M] 123. f:\program files\rising\rav\relibldr.dll
03090000[0007E000]
[ M] 124. f:\program files\rising\rav\rsnetsvr.dll
03350000[00016000]
[ M] 125. f:\program files\rising\rav\bawhite.dll
03580000[0002B000]
[ M] 126. f:\program files\rising\rav\rsstore.dll
035C0000[00040000]
[ M] 127. f:\program files\rising\rav\scanner.dll
03850000[0001B000]
[ M] 128. f:\program files\rising\rav\scanadd.dll
043D0000[0001B000]
[ M] 129. f:\program files\rising\rav\ncomm2.dll
043F0000[00009000]
[ M] 84. c:\windows\system32\normaliz.dll
3EAB0000[00045000]
[ M] 85. c:\windows\system32\iertutil.dll
03610000[00028000]
[ M] 130. f:\program files\rising\rav\rstask.dll
03670000[00018000]
[ M] 131. f:\program files\rising\rav\rsstub.dll
03480000[0001A000]
[ M] 132. f:\program files\rising\rav\scansrv.dll
06250000[0002B000]
[ M] 133. f:\program files\rising\rav\scanpe.dll
06480000[00029000]
[ M] 134. f:\program files\rising\rav\pearc.dll
08480000[0001B000]
[ M] 135. f:\program files\rising\rav\ur000.dat
084B0000[00035000]
[ M] 136. f:\program files\rising\rav\urutils.dll
093D0000[00032000]
[ M] 137. f:\program files\rising\rav\ffr.dll
09420000[00022000]
[ M] 138. f:\program files\rising\rav\nvfile.dll
13AB0000[00045000]
[ M] 139. f:\program files\rising\rav\scanexec.dll
09CC0000[002DD000]
[ M] 140. f:\program files\rising\rav\unexe.dll
09FB0000[000C8000]
[ M] 141. f:\program files\rising\rav\scanex.dll
0A440000[00011000]
[ M] 142. f:\program files\rising\rav\scantj.dll
0D7F0000[00085000]
[ M] 143. f:\program files\rising\rav\methodex.dll
0DA00000[000B9000]
[ M] 144. f:\program files\rising\rav\revm.dll
0D760000[00022000]
[ M] 145. f:\program files\rising\rav\pecompd.dll
0D7A0000[00039000]
[ M] 146. f:\program files\rising\rav\heurex.dll
014D0000[0001C000]
[ M] 147. f:\program files\rising\rav\scanravt.dll
0DF10000[0009A000]
[ M] 148. f:\program files\rising\rav\scanbt.dll
0DFB0000[00019000]
[ M] 149. f:\program files\rising\rav\scanstub.dll
0DFE0000[0001D000]
[ M] 150. f:\program files\rising\rav\extsfx.dll
0E370000[0002F000]
[AM] 62. f:\program files\360safe0\safemon\safemon.dll
0E3C0000[00023000]
[ M] 151. f:\program files\rising\rav\scansct.dll
0EC70000[00099000]
[ M] 152. f:\program files\rising\rav\extarch.dll
0ED20000[00056000]
[ M] 153. f:\program files\rising\rav\extcomp.dll
14210000[0003A000]
[ M] 154. f:\program files\rising\rav\extmail.dll
01AF0000[00015000]
[ M] 155. f:\program files\rising\rav\ur023.dat
0DE50000[00012000]
[ M] 156. f:\program files\rising\rav\ur025.dat
04320000[00045000]
[ M] 157. f:\program files\rising\rav\extole.dll
013D0000[00011000]
[ M] 158. f:\program files\rising\rav\ur001.dat
+ 000005e0(1504) ksdsvc.exe
00400000[00008000]
[AM] 8. f:\program files\kingsoft\powerword pe\ksdsvc.exe
10000000[00009000]
[ M] 159. f:\program files\kingsoft\powerword pe\ksdcallcenter.dll
003F0000[0000F000]
[ M] 160. f:\program files\kingsoft\powerword pe\queryprocesscenter.dll
00880000[00009000]
[ M] 161. f:\program files\kingsoft\powerword pe\ksdipc.dll
009B0000[0001A000]
[ M] 162. f:\program files\kingsoft\powerword pe\plugin\baikequery.dll
009E0000[00009000]
[ M] 84. c:\windows\system32\normaliz.dll
3EAB0000[00045000]
[ M] 85. c:\windows\system32\iertutil.dll
00C20000[00018000]
[ M] 163. f:\program files\kingsoft\powerword pe\plugin\googlequery.dll
00C40000[0001E000]
[ M] 164. f:\program files\kingsoft\powerword pe\plugin\huihuaquery.dll
00C80000[0002A000]
[ M] 165. f:\program files\kingsoft\powerword pe\plugin\localquery.dll
00CD0000[00025000]
[ M] 166. f:\program files\kingsoft\powerword pe\localdictmgr.dll
用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; QQDownload 538; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; CIBA)