瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 继续求助!十分讨厌的掌门网,依然无法去除

12   2  /  2  页   跳转

继续求助!十分讨厌的掌门网,依然无法去除

???????????各位老大的留贴我怎么找不到了?
gototop
 

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <msnmsgr><"C:\Program Files\MSN Messenger\msnmsgr.exe" /background>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <pyjj><C:\Program Files\jj4\jjsvr4.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <KavPFW><"C:\KAV2005\KPFW32.EXE">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <Super Rabbit SRRestore><C:\Program Files\Super Rabbit\MagicSet\srrest.exe /autosave>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
  <CNETHELPER><rundll32.exe C:\PROGRA~1\COMMON~1\system\msdc32.dll,_S1>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <Userinit><userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <AppInit_DLLs><>

==================================
启动文件夹
[microsoft office]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\microsoft office.lnk><N>
[Active Messenger]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\Active Messenger.lnk><N>
[快捷方式 到 KAV32]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\快捷方式 到 KAV32.lnk><N>

==================================
服务
[pcAnywhere Host Service / awhost32]
  <C:\Program Files\Symantec\pcAnywhere\awhost32.exe><Symantec Corporation>
[C-DillaCdaC11BA / C-DillaCdaC11BA]
  <C:\WINDOWS\System32\drivers\CDAC11BA.EXE><Macrovision>
[User Authentication Manager / DpHost]
  <C:\Program Files\DigitalPersona\UareUPro\DpHost.exe><Digital Persona, Inc.>
[Kingsoft Personal Firewall Service / KPfwSvc]
  <"C:\KAV2005\KPfwSvc.EXE"><Kingsoft Corporation>
[Kingsoft Antivirus KWatch Service / KWatchSvc]
  <C:\KAV2005\KWatch.EXE><Kingsoft Corporation>
[NVIDIA Display Driver Service / NVSvc]
  <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd]
  <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><N/A>
[ServiceLayer / ServiceLayer]
  <"C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe"><Nokia.>
[SoundMAX Agent Service / SoundMAX Agent Service (default)]
  <C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>

==================================
浏览器加载项
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\System32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[&使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\getAllurl.htm, N/A>
gototop
 

正在运行的进程
[PID: 468][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 524][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 548][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 592][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 604][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\system32\w2pxdrv.dll]  <Proxy Labs><2, 0, 1, 1>
[PID: 784][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\system32\w2pxdrv.dll]  <Proxy Labs><2, 0, 1, 1>
[PID: 832][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\System32\w2pxdrv.dll]  <Proxy Labs><2, 0, 1, 1>
[PID: 928][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\System32\w2pxdrv.dll]  <Proxy Labs><2, 0, 1, 1>
[PID: 972][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\System32\w2pxdrv.dll]  <Proxy Labs><2, 0, 1, 1>
[PID: 1064][C:\KAV2005\KWatch.EXE]  <Kingsoft Corporation><2005, 9, 27, 51>
    [C:\KAV2005\KAVIPC2.DLL]  <Kingsoft Corporation><2004, 12, 28, 20>
    [C:\KAV2005\KAEPlat.DLL]  <Kingsoft Corp.><2005, 12, 29, 56>
    [C:\KAV2005\KAEMem.DAT]  <Kingsoft><2006, 4, 12, 13>
    [C:\KAV2005\KAEUnpack.DAT]  <Kingsoft Corp.><2006, 3, 21, 17>
[PID: 1120][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.1699 (xpsp2.050610-1533)>
    [C:\WINDOWS\System32\AdobePDF.dll]  <Adobe Systems Incorporated.><7.0.0.00>
    [C:\Program Files\Adobe\Acrobat 7.0\Distillr\AdistRes.CHS]  <N/A><N/A>
    [C:\WINDOWS\system32\awmon.dll]  <Symantec Corporation><9.2.1>
[PID: 1392][C:\WINDOWS\System32\drivers\CDAC11BA.EXE]  <Macrovision><4.20.020>
[PID: 1416][C:\Program Files\DigitalPersona\UareUPro\DpHost.exe]  <Digital Persona, Inc.><1.1.0.0>
    [C:\Program Files\DigitalPersona\UareUPro\DPPS.dll]  <Digital Persona, Inc.><1.1.0.0>
    [C:\Program Files\DigitalPersona\UareUPro\DpCmpMgt.dll]  <Digital Persona, Inc.><1.1.0.0>
    [C:\Program Files\DigitalPersona\UareUPro\DpDtObjs.dll]  <Digital Persona, Inc.><1.1.0.0>
    [C:\Program Files\DigitalPersona\UareUPro\DPDevAgt.dll]  <Digital Persona, Inc.><1.1.0.0>
    [C:\WINDOWS\System32\dpDevCtl.dll]  <DigitalPersona, Inc.><2.1.1.499>
[PID: 1480][C:\WINDOWS\System32\inetsrv\inetinfo.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\System32\w2pxdrv.dll]  <Proxy Labs><2, 0, 1, 1>
[PID: 1500][C:\KAV2005\KPfwSvc.EXE]  <Kingsoft Corporation><2005, 9, 5, 28>
[PID: 1524][C:\WINDOWS\System32\nvsvc32.exe]  <NVIDIA Corporation><6.14.10.5672>
[PID: 1592][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe]  <Analog Devices, Inc.><3, 2, 6, 0>
[PID: 1744][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\System32\AcSignIcon.dll]  <Autodesk><16.0.0.86>
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  <Autodesk><16.0.0.86>
    [C:\PROGRA~1\COMMON~1\system\msdc32.dll]  <C1NETHELPER><1, 0, 0, 1>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  <Adobe Systems, Inc.><7.0.0.0>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS]  <Adobe Systems, Inc.><7.0.0.0>
    [C:\WINDOWS\System32\nvcpl.dll]  <NVIDIA Corporation><6.14.10.5672>
    [C:\WINDOWS\System32\nvshell.dll]  <NVIDIA Corporation><6.14.10.5672>
    [C:\WINDOWS\System32\NVWRSZHC.DLL]  <NVIDIA Corporation><6.14.10.5672>
[PID: 1884][C:\WINDOWS\System32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1908][C:\Program Files\MSN Messenger\msnmsgr.exe]  <Microsoft Corporation><7.5.0324>
    [C:\WINDOWS\System32\w2pxdrv.dll]  <Proxy Labs><2, 0, 1, 1>
    [C:\WINDOWS\System32\msdmo.dll]  <N/A><N/A>
    [C:\KAV2005\KAScript.DLL]  <Kingsoft Corporation><2006, 2, 10, 60>
    [C:\KAV2005\KAEPlat.DLL]  <Kingsoft Corp.><2005, 12, 29, 56>
    [C:\KAV2005\KAEMem.DAT]  <Kingsoft><2006, 4, 12, 13>
    [C:\KAV2005\KAEUnpack.DAT]  <Kingsoft Corp.><2006, 3, 21, 17>
[PID: 1916][C:\Program Files\jj4\jjsvr4.exe]  <加加开发组><4.0.0.20>
[PID: 1932][C:\KAV2005\KPFW32.EXE]  <Kingsoft Corporation><2006, 1, 17, 609>
    [C:\KAV2005\KAVIPC2.DLL]  <Kingsoft Corporation><2004, 12, 28, 20>
    [C:\KAV2005\KAConfig.DLL]  <Kingsoft Corporation><2005, 3, 23, 30>
    [C:\KAV2005\FiltList.dll]  <N/A><N/A>
    [C:\KAV2005\KAVPassp.DLL]  <Kingsoft Corporation><2006, 5, 26, 246>
    [C:\WINDOWS\System32\AcSignIcon.dll]  <Autodesk><16.0.0.86>
    [C:\KAV2005\KAEPlat.DLL]  <Kingsoft Corp.><2005, 12, 29, 56>
    [C:\KAV2005\KAEMem.DAT]  <Kingsoft><2006, 4, 12, 13>
    [C:\KAV2005\KAEUnpack.DAT]  <Kingsoft Corp.><2006, 3, 21, 17>
    [C:\WINDOWS\System32\w2pxdrv.dll]  <Proxy Labs><2, 0, 1, 1>
    [C:\KAV2005\KAScript.DLL]  <Kingsoft Corporation><2006, 2, 10, 60>
[PID: 2000][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
gototop
 

[C:\WINDOWS\System32\hpwx3770.dll]  <Hewlett-Packard><3.2.2.674>
    [C:\WINDOWS\System32\hpgt3770.dll]  <Hewlett-Packard><1.0.2.682>
[PID: 2036][C:\WINDOWS\System32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 264][C:\Program Files\Activesoft\Active Messenger\Msger.exe]  <Activesoft><3, 0, 6, 1>
    [C:\WINDOWS\System32\w2pxdrv.dll]  <Proxy Labs><2, 0, 1, 1>
[PID: 2836][E:\game\sreng2\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\WINDOWS\System32\w2pxdrv.dll]  <Proxy Labs><2, 0, 1, 1>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
PROXYCAP MSAFD Tcpip [TCP/IP]
    w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP MSAFD Tcpip [UDP/IP]
    w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP MSAFD Tcpip [RAW/IP]
    w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP RSVP UDP Service Provider
    w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP RSVP TCP Service Provider
    w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)
PROXYCAP LSP
    w2pxdrv.dll(Proxy Labs, Winsock2 Proxy Driver)

==================================
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT