瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 昨天刚有高手帮我解决了问题,但今天不但老毒发作新毒也出来了~~付日志~

1   1  /  1  页   跳转

昨天刚有高手帮我解决了问题,但今天不但老毒发作新毒也出来了~~付日志~

昨天刚有高手帮我解决了问题,但今天不但老毒发作新毒也出来了~~付日志~

昨天是Win32.Parite.a,但今天又出来一个...请高手们帮帮忙~~
2006-07-30,13:19:21

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联


启动项目


注册表

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
(ctfmon.exe)(C:\WINDOWS\system32\ctfmon.exe) [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(load)() []
(run)() []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
(YLive.exe)(C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe) [ ]
(CnsMin)(Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32) [北京三七二一科技有限公司]
(yassistse)("C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe") [Yahoo!]
(SecExpert)(C:\Program Files\Terminator\SecMain.exe Hide) []
(KavStart)("C:\KAV2006\KAVStart.exe" -startup) [Kingsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
(Register C:\Program Files\Tencent\QQ\QQIEHelper.dll)("C:\WINDOWS\system32\rundll32.exe" "C:\Program Files\Tencent\QQ\QQIEHelper.dll",DllRegisterServer) [深圳市腾讯计算机系统有限公司]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx]
(Flags)(8
) []
(Title)(Windows Update) []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(shell)(Explorer.exe) [Microsoft Corporation]
(Userinit)(C:\WINDOWS\system32\userinit.exe,) [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(AppInit_DLLs)() []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(UIHost)(logonui.exe) [Microsoft Corporation]




--------------------------------------------------------------------------------



启动文件夹

[腾讯QQ]
(C:\Documents and Settings\XX\「开始」菜单\程序\启动\腾讯QQ.lnk)(N)



--------------------------------------------------------------------------------



服务

[DuDu Accelerator o / DDDProxy]
()(N/A)
[EPSON Printer Status Agent2 / EPSONStatusAgent2]
(C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe)(SEIKO EPSON CORPORATION)
[JMediaService / JMediaService]
(C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\MMSASS~1\MMSSVER.DLL,Service)(N/A)
[Kingsoft Personal Firewall Service / KPfwSvc]
("C:\KAV2006\KPfwSvc.EXE")(Kingsoft Corporation)
[Kingsoft Antivirus KWatch Service / KWatchSvc]
(C:\KAV2006\KWatch.EXE)(Kingsoft Corporation)
[Rising Process Communication Center / RsCCenter]
(C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE)(rising)
[Network ConnectionHuahua101 / Service101]
(C:\WINDOWS\system32\lassess.exe)(N/A)
[Te1net / Te1net]
(C:\WINDOWS\System32\VIPTray.exe)(N/A)



--------------------------------------------------------------------------------



最后编辑2006-07-30 16:30:20
分享到:
gototop
 

浏览器加载项

[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} (C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司)
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} (C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC)
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} (C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT)
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} (C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司)
[访问瑞星网站]
{FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} (http://www.rising.com.cn/?u=RSTB, N/A)
[访问卡卡社区]
{FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} (http://www.ikaka.com/?u=RSTB, N/A)
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} (C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.)
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.)
[Ravonline]
{DA984A6D-508E-11D6-AA49-0050FF3C628D} (C:\WINDOWS\Downloaded Program Files\RsOnline.dll, Beijing Rising Tech. Co., Ltd.)
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} (C:\WINDOWS\system32\xunleibho_v14.dll, N/A)
[internet explorer helper]
{02C9B9AB-6372-46C5-B356-773FAF3B6B1E} (C:\WINDOWS\fonts\msshapi.dll, )
[MonitorURL Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} (C:\PROGRA~1\DESKAD~1\deskipn.dll, )
[wmpdrm]
{0E674588-66B7-4E19-9D0E-2053B800F69F} (C:\WINDOWS\system32\wmpdrm.dll, Allsum Info. Tech. Ltd.)
[实用搜索]
{15ADF205-4C54-4CFE-AC88-1EA0BA6D06A0} (, N/A)
[MyIEHelper Class]
{16A770A0-0E87-4278-B748-2460D64A8386} (C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4683.dll, Microsoft Corporation)
[FltSetUp Class]
{1D49D58D-5C84-4B50-8359-D9809BEB2B32} (C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll, Microsoft Corporation)
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} (C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation)
[&Google]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} (c:\program files\google\googletoolbar1.dll, N/A)
[Adobe-Plugins Manager]
{2AFA7CEC-26D9-4256-AF57-497A13180BA5} (C:\WINDOWS\System32\Agm.dll, AdoBeSoft Co.)
[CaiShowBH Class]
{3AF40CB8-B3BA-4E2D-8968-4BF8DB172997} (C:\Program Files\CaiShow Tech\CaiShow\BrowerHelper.dll, N/A)
[雅虎助手]
{406F94F0-504F-4A40-8DFD-58B0666ABEBD} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!)
[HHCtrl Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} (C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation)
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} (C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司)
[NetAccelerate Class]
{5673A7C0-95CC-4646-BB07-3BD71234CEF9} (C:\WINDOWS\system32\wuwebex.dll, Microsoft Corporation)
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} (C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC)
[IEYHlprObj Class]
{5C761D09-377E-4EAC-ADA1-C9CDE39B5674} (C:\WINDOWS\IEYHelper.dll, Eastday Corporation)
[ActiveBHO Class]
{63C55A7F-6E29-8D4F-5C76-4F850F28D13A} (C:\Progra~1\DoDoorRSSFinder\ActiveBandObject.dll, )
[Vision]
{6671A431-5C3D-463D-A7CF-5587F9B7E191} (C:\PROGRA~1\MMSASS~1\mmsass~1.dll, )
[stdup]
{6A512BF7-EC78-4E8D-9841-6C02E8FA9838} (C:\WINDOWS\System32\stdup.dll, MStdup Co Ltd.)
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[金山快译(&K)]
{6C3797D2-3FEF-4CD4-B654-D3AE55B4128C} (C:\PROGRA~1\Kingsoft\FastAIT\IEBand.dll, N/A)
[Status Class]
{7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} (C:\Program Files\baigoo\BGooBHO.dll, )
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} (C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll, Thunder Networking Technologies,LTD)
[Mini PPGou BHO]
{92FB5F8F-8254-4978-9C50-03D9B0405062} (C:\PROGRA~1\MINIPP~1\MINIPP~1.DLL, N/A)
[IE标准栏]
{954F618B-0DEC-4D1A-9317-E0FC96F87865} (C:\WINDOWS\system32\amstreamxb.dll, )
[IEHlprObj Class]
{999ADFA2-8AD1-47FF-97FC-69FB847458F4} (C:\Progra~1\NetMeeting\nmview.dll, Microsoft Corporation)
[WinSC Class]
{9ACEEE31-1440-471B-AA46-72B061FE7D61} (C:\WINDOWS\system32\WinSC.dll, N/A)
[win32core Class]
{A297EEAE-A541-496B-B2AE-554AD0153B72} (C:\WINDOWS\system32\win32help01.dll, N/A)
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} (C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A)
[Google Toolbar Helper]
{AA58ED58-01DD-4D91-8333-CF10577473F7} (c:\program files\google\googletoolbar1.dll, N/A)
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} (C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation)
[卡卡上网安全助手]
{AFF6E516-CBE5-4F8A-9C2F-38A68013E766} (C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.)
[T2BHO Class]
{B1D147E7-873E-4909-8127-695D9BB78728} (C:\WINDOWS\Downloaded Program Files\barhelp24.0.dll, N/A)
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} (%SystemRoot%\System32\shdocvw.dll, N/A)
[Webacc Class]
{CAC068F3-A608-406B-8581-458788A67694} (C:\WINDOWS\system32\svchost.dll, )
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.)
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} (C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.)
[]
{ECE87D9F-9933-483B-942B-7D7FB569F525} (C:\WINDOWS\system32\Mfhlp.dll, N/A)
[BHelper Class]
{F2E37336-BFDB-409B-8D0E-6F013C438B20} (C:\WINDOWS\system\81aoe810.dll, N/A)
[google bar]
{F651FCAA-F826-4922-8990-C6F99CC67AFC} (C:\WINDOWS\Win32ef.dll, N/A)
[上传到QQ网络硬盘]
(C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A)
[添加到QQ自定义面板]
(C:\Program Files\Tencent\QQ\AddPanel.htm, N/A)
[添加到QQ表情]
(C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A)
[用QQ彩信发送该图片]
(C:\Program Files\Tencent\QQ\SendMMS.htm, N/A)



--------------------------------------------------------------------------------



gototop
 

正在运行的进程

[PID: 1172][C:\WINDOWS\Explorer.EXE] (Microsoft Corporation)(6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\KAV2006\KASocket.dll] (Kingsoft Corporation)(2005, 2, 22, 233)
[C:\KAV2006\KMailOEBand.dll] (N/A)(2006, 5, 19, 118)
[C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll] ()(2, 1, 6, 1046)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] ( )(2, 0, 1, 1007)
[C:\KAV2006\KAVEXT.DLL] (Kingsoft Corporation)(2005, 8, 5, 16)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ywiper.dll] (N/A)(1, 0, 1, 1014)
[C:\Program Files\WinRAR1\rarext.dll] (N/A)(N/A)
[C:\WINDOWS\system32\RAVEXT.DLL] (Beijing Rising Technology Co., Ltd.)(17, 0, 0, 8)
[C:\Program Files\Herosoft\Hero Audio Convert\HeroExt.dll] (N/A)(N/A)
[PID: 1724][C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe] ( )(2, 0, 0, 1002)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll] ()(2, 1, 6, 1046)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] ( )(2, 0, 1, 1007)
[C:\KAV2006\KASocket.dll] (Kingsoft Corporation)(2005, 2, 22, 233)
[C:\KAV2006\KMailOEBand.dll] (N/A)(2006, 5, 19, 118)
[C:\PROGRA~1\Yahoo!\ASSIST~1\ynotifier.dll] ()(1, 0, 0, 5)
[PID: 1748][C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe] (Yahoo!)(1, 0, 1, 1001)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\PROGRA~1\Yahoo!\Assistant\shell\yAsMenu.dll] (Yahoo)(1, 0, 1, 1006)
[C:\PROGRA~1\Yahoo!\Assistant\shell\yAssecblk.dll] (Yahoo)(1, 0, 2, 1002)
[C:\PROGRA~1\Yahoo!\Assistant\shell\yIEAngel.dll] (Yahoo)(1, 0, 1, 1001)
[C:\PROGRA~1\Yahoo!\Assistant\shell\yMenuInfo.dll] (Yahoo)(1, 0, 0, 2)
[C:\KAV2006\KASocket.dll] (Kingsoft Corporation)(2005, 2, 22, 233)
[PID: 1944][C:\WINDOWS\system32\ctfmon.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\KAV2006\KASocket.dll] (Kingsoft Corporation)(2005, 2, 22, 233)
[PID: 1976][C:\KAV2006\KMailMon.EXE] (Kingsoft Corporation)(2006, 4, 12, 106)
[C:\KAV2006\KAntiSpm.dll] (N/A)(1, 0, 0, 2)
[C:\KAV2006\KAVIPC2.DLL] (Kingsoft Corporation)(2004, 12, 28, 20)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\KAV2006\KAECall2.DLL] (Kingsoft Corporation)(2004, 12, 28, 7)
[C:\KAV2006\KAEPlat.DLL] (Kingsoft Corp.)(2005, 12, 29, 56)
[C:\KAV2006\KAEMem.DAT] (Kingsoft)(2006, 4, 12, 13)
[C:\KAV2006\KAEUnpack.DAT] (Kingsoft Corp.)(2006, 6, 15, 44)
[C:\KAV2006\KAConfig.DLL] (Kingsoft Corporation)(2005, 3, 23, 30)
[C:\KAV2006\KASocket.dll] (Kingsoft Corporation)(2005, 2, 22, 233)
[C:\KAV2006\KMailOEBand.dll] (N/A)(2006, 5, 19, 118)
[PID: 2316][C:\WINDOWS\system32\wuauclt.exe] (Microsoft Corporation)(5.8.0.2469 built by: lab01_n(wmbla))
[C:\KAV2006\KMailOEBand.dll] (N/A)(2006, 5, 19, 118)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\KAV2006\KASocket.dll] (Kingsoft Corporation)(2005, 2, 22, 233)
[PID: 628][C:\Program Files\Tencent\QQ\QQ.exe] (TENCENT)(0, 0, 0, 0)
[C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll] ()(1, 0, 0, 1)
[C:\Program Files\Tencent\QQ\QQHelperDll.dll] ()(1, 0, 0, 1)
[C:\Program Files\Tencent\QQ\BasicCtrlDll.dll] (Tencent)(5, 0, 200, 160)
[C:\KAV2006\KMailOEBand.dll] (N/A)(2006, 5, 19, 118)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\KAV2006\KASocket.dll] (Kingsoft Corporation)(2005, 2, 22, 233)
[C:\Program Files\Tencent\QQ\QQAPI.dll] ()(1, 0, 0, 1)
[C:\Program Files\Tencent\QQ\TIMProxy.dll] (tencent)(0, 3, 2, 4)
[C:\Program Files\Tencent\QQ\LoginCtrl.dll] ()(1, 0, 0, 1)
[C:\Program Files\Tencent\QQ\npkcntc.dll] (INCA Internet Co., Ltd.)(2006, 3, 2, 1)
[C:\Program Files\Tencent\QQ\npkpdb.dll] (INCA Internet Co., Ltd.)(2003, 10, 1, 1)
[C:\Program Files\Tencent\QQ\QQRes.dll] (tencent)(1, 0, 0, 1)
[C:\Program Files\Tencent\QQ\QQMainFrame.dll] (N/A)(N/A)
[C:\Program Files\Tencent\QQ\CQQApplication.dll] (N/A)(N/A)
[C:\Program Files\Tencent\QQ\NewSkin.dll] ()(1, 0, 0, 1)
[C:\Program Files\Tencent\QQ\HostingMgr.dll] ()(1, 0, 0, 1)
[C:\Program Files\Tencent\QQ\CameraDll.dll] ()(1, 0, 0, 1)
[C:\Program Files\Tencent\QQ\MailSummary.dll] ()(1, 0, 0, 1)
[C:\Program Files\Tencent\QQ\QQSpace.dll] ()(1, 0, 0, 1)
[C:\Program Files\Tencent\QQ\QQAllInOne.dll] (N/A)(N/A)
[C:\Program Files\Tencent\QQ\GroupLive.dll] (N/A)(N/A)
[C:\Program Files\Tencent\QQ\SCCore.dll] (N/A)(N/A)
[C:\WINDOWS\system32\msdmo.dll] (N/A)(N/A)
[C:\Program Files\Tencent\QQ\QQGroupMng.dll] ()(1, 0, 0, 1)
[C:\Program Files\Tencent\QQ\UserDefinedHead.dll] ()(1, 0, 0, 1)
[C:\Program Files\Tencent\QQ\QQPlugin.dll] (N/A)(N/A)
[C:\Program Files\Tencent\QQ\QQConfigPlugin.dll] ()(1, 0, 0, 1)
[C:\Program Files\Tencent\QQ\QQSysMsgMng.dll] (N/A)(N/A)
[C:\Program Files\Tencent\QQ\LongConnection.dll] (tencent)(5, 0, 200, 160)
[C:\Program Files\Tencent\QQ\QQPet.dll] ()(1, 0, 0, 1)
[C:\Program Files\Tencent\QQ\QRingMng.dll] (N/A)(N/A)
[C:\Program Files\Tencent\QQ\PhoneAPI.dll] ()(1, 0, 0, 1)
[C:\Program Files\Tencent\QQ\DialerAllinOne.dll] (tencent)(1, 4, 0, 0)
[C:\Program Files\Tencent\QQ\QQCustomFace.dll] (N/A)(N/A)
[C:\Program Files\Tencent\QQ\GroupConnection.dll] (Tencent)(5, 0, 202, 170)
[C:\Program Files\Tencent\QQ\QQAvatar.dll] (N/A)(N/A)
[C:\Program Files\Tencent\QQ\FlashAvatarDll.dll] ()(1, 4, 0, 1)
[C:\Program Files\Tencent\QQ\BQQApplication.dll] (N/A)(N/A)
[C:\Program Files\Tencent\QQ\CommercesMng.dll] ()(1, 0, 0, 1)
[C:\Program Files\Tencent\QQ\PersonalDesktop.dll] (深圳市腾讯计算机系统公司QQ工作小组)(1, 0, 0, 2)
[C:\Program Files\Tencent\QQ\QQUdpGetFileLib.dll] (tencent)(0, 2, 2, 3)
[C:\Program Files\Tencent\QQ\QQAddr.dll] (深圳市腾讯计算机系统有限公司)(5, 0, 101, 200)
[C:\Program Files\Tencent\QQ\QQSettingCtrl.dll] ()(1, 0, 0, 1)
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] (Macromedia, Inc.)(8,0,22,0)
[C:\Program Files\Tencent\QQ\QQSceneMng.dll] (N/A)(N/A)
[C:\Program Files\Tencent\QQ\QQPhoneHelper.dll] (腾讯科技(深圳)有限公司)(2, 0, 5, 50)
[C:\Program Files\Tencent\QQ\QQFileTransfer.dll] (Tencent)(5, 0, 202, 180)
[C:\KAV2006\KAScript.DLL] (Kingsoft Corporation)(2006, 2, 10, 60)
[C:\KAV2006\KAEPlat.DLL] (Kingsoft Corp.)(2005, 12, 29, 56)
[C:\KAV2006\KAEMem.DAT] (Kingsoft)(2006, 4, 12, 13)
[C:\KAV2006\KAEUnpack.DAT] (Kingsoft Corp.)(2006, 6, 15, 44)
[C:\Program Files\Tencent\QQ\ImageOle.dll] (TODO: (Company name))(1.0.0.1)
[PID: 932][C:\Program Files\Tencent\QQ\TIMPlatform.exe] (tencent)(0, 3, 1, 8)
[C:\KAV2006\KMailOEBand.dll] (N/A)(2006, 5, 19, 118)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\KAV2006\KASocket.dll] (Kingsoft Corporation)(2005, 2, 22, 233)
[C:\Program Files\Tencent\QQ\TIMProxy.dll] (tencent)(0, 3, 2, 4)
[PID: 4044][C:\Program Files\Internet Explorer\iexplore.exe] (Microsoft Corporation)(6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))
[C:\KAV2006\KMailOEBand.dll] (N/A)(2006, 5, 19, 118)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll] (Yahoo)(1, 0, 2, 1002)
[C:\KAV2006\KASocket.dll] (Kingsoft Corporation)(2005, 2, 22, 233)
[C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll] ()(2, 1, 6, 1046)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] ( )(2, 0, 1, 1007)
[C:\WINDOWS\system32\kakatool.dll] (Beijing Rising Technology Co., Ltd.)(2, 0, 0, 9)
[C:\Program Files\Tencent\QQ\QQIEHelper.dll] (深圳市腾讯计算机系统有限公司)(1, 1, 0, 5)
[C:\KAV2006\KAScript.DLL] (Kingsoft Corporation)(2006, 2, 10, 60)
[C:\KAV2006\KAEPlat.DLL] (Kingsoft Corp.)(2005, 12, 29, 56)
[C:\KAV2006\KAEMem.DAT] (Kingsoft)(2006, 4, 12, 13)
[C:\KAV2006\KAEUnpack.DAT] (Kingsoft Corp.)(2006, 6, 15, 44)
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] (Macromedia, Inc.)(8,0,22,0)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll] (Yahoo!)(2, 1, 8, 1048)
[PID: 3736][C:\Program Files\sreng2\SREng2\SREng.exe] (Smallfrogs Studio)(2.0.21.505)
[C:\KAV2006\KMailOEBand.dll] (N/A)(2006, 5, 19, 118)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\KAV2006\KASocket.dll] (Kingsoft Corporation)(2005, 2, 22, 233)



--------------------------------------------------------------------------------



文件关联

.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP Error. [winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]



--------------------------------------------------------------------------------


Winsock 提供者



--------------------------------------------------------------------------------
gototop
 

小弟我在线等~~大哥门帮帮我吧~~
gototop
 

嗯好,我这就去
gototop
 

HijackThis_815汉化版扫描日志 V1.99.1
保存于      13:28:17, 日期 2006-7-30
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Unable to get Internet Explorer version!

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\KAV2006\KWatch.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\KAV2006\KMailMon.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\KAV2006\KPfwSvc.EXE
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\TIMPlatform.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\sreng2\SREng2\SREng.exe
C:\Program Files\Hijackthis1991zww\HijackThis1991zww.exe

R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: (no name) - {D424FE4E-CAF9-4fdd-BC5F-E6E6B91D53BF} - (no file)
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - 启动项HKLM\\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - 启动项HKLM\\Run: [CnsMin] Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32
O4 - 启动项HKLM\\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - 启动项HKLM\\Run: [SecExpert] C:\Program Files\Terminator\SecMain.exe Hide
O4 - 启动项HKLM\\Run: [KavStart] "C:\KAV2006\KAVStart.exe" -startup
O4 - 启动项HKLM\\RunOnce: [Register C:\Program Files\Tencent\QQ\QQIEHelper.dll] "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files\Tencent\QQ\QQIEHelper.dll",DllRegisterServer
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\QQ\QQ.exe
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - 浏览器额外的按钮: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - 浏览器额外的“工具”菜单项: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - 浏览器额外的按钮: (no name) - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108}? - (no file)
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的按钮: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} - http://www.rising.com.cn/?u=RSTB (file missing)
O9 - 浏览器额外的按钮: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com/?u=RSTB (file missing)
O11 - Options group: [!CNS]  网络实名
O11 - Options group: [CDNCLIENT]  中文上网
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C4B15D9C-0FC3-4727-A25B-81F6A0B69CB1}: NameServer = 202.109.15.135 202.96.209.134
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - NT 服务: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - NT 服务: Kingsoft Personal Firewall Service (KPfwSvc) - Kingsoft Corporation - C:\KAV2006\KPfwSvc.EXE
O23 - NT 服务: Kingsoft Antivirus KWatch Service (KWatchSvc) - Kingsoft Corporation - C:\KAV2006\KWatch.EXE
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: Security Expert Back Service (SecBkSrv) - CNNS - C:\Program Files\Terminator\SecBkSrv.exe

gototop
 

来个高手帮帮我吧~~
gototop
 

来个人帮帮我吧....
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT