瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 找魔法斑竹和其他朋友---继续请教

123   2  /  3  页   跳转

找魔法斑竹和其他朋友---继续请教

2006-02-11,08:05:29

System Repair Engineer 2.0.12.350 (2.0 RC 1)
    Windows XP Professional Service Pack 2 - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <msnmsgr><"C:\Program Files\MSN Messenger\msnmsgr.exe" /background>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <load><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <TrackPointSrv><tp4serv.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <AGRSMMSG><AGRSMMSG.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <EZEJMNAP><C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <TPHOTKEY><d:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <TPKMAPHELPER><C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <QCTRAY><C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <QCWLICON><C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <TP4EX><tp4ex.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <vptray><D:\PROGRA~1\SYMANT~1\VPTray.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <AppInit_DLLs><>
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  <MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  <MsnMsgr><; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>

==================================
启动文件夹
服务
[Symantec Event Manager / ccEvtMgr]
  <"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc]
  <"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr]
  <"C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[Symantec AntiVirus Definition Watcher / DefWatch]
  <"D:\Program Files\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[ThinkPad PM Service / IBMPMSVC]
  <C:\WINDOWS\system32\ibmpmsvc.exe><N/A>
[Intel NCS NetService / NetSvc]
  <C:\Program Files\Intel\NCS\Sync\NetSvc.exe><Intel(R) Corporation>
[QCONSVC / QCONSVC]
  <System32\QCONSVC.EXE><Lenovo>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd]
  <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><N/A>
[SavRoam / SavRoam]
  <"D:\Program Files\Symantec AntiVirus\SavRoam.exe"><symantec>
[Symantec Network Drivers Service / SNDSrvc]
  <"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Symantec SPBBCSvc / SPBBCSvc]
  <"C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"><Symantec Corporation>
[Symantec AntiVirus / Symantec AntiVirus]
  <"D:\Program Files\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>
[IBM KCU Service / TpKmpSVC]
  <C:\WINDOWS\system32\TpKmpSVC.exe><N/A>

==================================
浏览器加载项
[]
  {53707962-6F74-2D53-2644-206D7942484F} <D:\PROGRA~1\SPYBOT~1\SDHelper.dll, Safer Networking Limited>
[更新 ThinkPad 软件]
  {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} <d:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe, Lenovo Group Limited>
[FlashGet]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <D:\Program Files\FlashGet\flashget.exe, Amaze Soft>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[ActiveMovieControl Object]
  {05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[Windows Genuine Advantage]
  {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.dll, Microsoft? Corporation>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[HHCtrl Object]
  {41B23C28-488E-4E5C-ACE2-BB0BBABE99E8} <C:\WINDOWS\system32\HHCTRL.OCX, Microsoft Corporation>
[HHCtrl Object]
  {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\HHCTRL.OCX, Microsoft Corporation>
[]
  {53707962-6F74-2D53-2644-206D7942484F} <D:\PROGRA~1\SPYBOT~1\SDHelper.dll, Safer Networking Limited>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <d:\program files\flashget\jccatch.dll, Amaze Soft>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[]
  {B69003B3-C55E-4B48-836C-BC5946FC3B28} <C:\Program Files\Messenger\msgsc.dll, Microsoft Corporation>
[AUDIO__MP3 Moniker Class]
  {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[IERPCtl Class]
gototop
 

{FDC7A535-4070-4B92-A0EA-D9994BCC0DC5} <d:\Program Files\Real\RealPlayer\rpplugins\ierpplug.dll, RealNetworks, Inc.>
[使用网际快车下载]
  <D:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <D:\Program Files\FlashGet\jc_all.htm, N/A>

==================================
正在运行的进程
[PID: 532][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 596][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 624][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\tphklock.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\NavLogon.dll]  <Symantec Corporation><10.0.1.1000>
[PID: 668][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 680][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 820][C:\WINDOWS\system32\ibmpmsvc.exe]  <N/A><N/A>
[PID: 848][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 908][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 964][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1052][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1384][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [D:\PROGRA~1\SPYBOT~1\SDHelper.dll]  <Safer Networking Limited><1, 4, 0, 0>
    [d:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll]  <Symantec Corporation><10.0.1.1000>
[PID: 1468][C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe]  <Symantec Corporation><103.5.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ccL35.dll]  <Symantec Corporation><103.5.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  <Symantec Corporation><103.5.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll]  <Symantec Corporation><103.5.4.3>
[PID: 1500][C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe]  <Symantec Corporation><103.5.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ccL35.dll]  <Symantec Corporation><103.5.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  <Symantec Corporation><103.5.4.3>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\SPBBC\BB.DLL]  <Symantec Corporation><1,5,1,3>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\SPBBC\SPBBCEVT.DLL]  <Symantec Corporation><1,5,1,3>
    [C:\Program Files\Common Files\Symantec Shared\ccSet.dll]  <Symantec Corporation><103.5.4.3>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\CCSETEVT.DLL]  <Symantec Corporation><103.5.4.3>
[PID: 1648][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 476][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 560][D:\Program Files\Symantec AntiVirus\DefWatch.exe]  <Symantec Corporation><10.0.1.1000>
[PID: 892][C:\WINDOWS\System32\QCONSVC.EXE]  <Lenovo><3, 8, 1, 0>
[PID: 1368][D:\Program Files\Symantec AntiVirus\Rtvscan.exe]  <Symantec Corporation><10.0.1.1000>
    [C:\WINDOWS\system32\CBA.DLL]  <LANDesk Software Ltd.><6.12.0.137 E>
    [C:\WINDOWS\system32\MsgSys.dll]  <LANDesk Software Ltd.><6.12.0.137 E>
    [C:\WINDOWS\system32\NTS.dll]  <LANDesk Software Ltd.><6.12.0.137 E>
    [C:\WINDOWS\system32\PDS.DLL]  <LANDesk Software Ltd.><6.12.0.137 E>
    [D:\Program Files\Symantec AntiVirus\NAVLU.dll]  <Symantec Corporation><10.0.1.1000>
    [D:\Program Files\Symantec AntiVirus\NAVNTUTL.DLL]  <Symantec Corporation><10.0.1.1000>
    [c:\program files\common files\symantec shared\ssc\ScsComms.dll]  <Symantec Corporation><10.0.1.1000>
    [D:\Program Files\Symantec AntiVirus\I2ldvp3.dll]  <Symantec Corporation><10.0.1.1000>
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  <Symantec Corporation><103.5.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ccL35.dll]  <Symantec Corporation><103.5.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ccDec.dll]  <Symantec Corporation><103.5.4.3>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\decsdk.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll]  <Symantec Corporation><3.02.12.35>
    [C:\Program Files\Common Files\Symantec Shared\ccScan.dll]  <Symantec Corporation><103.5.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ecmldr32.DLL]  <Symantec Corporation><1.4.0.11>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060209.007\ccEraser.dll]  <Symantec Corporation><105.0.2.3>
    [D:\Program Files\Symantec AntiVirus\DefUtDCD.dll]  <Symantec Corporation><3.1.13a.0>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060209.007\ecmsvr32.dll]  <Symantec Corporation><51.3.0.11>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060209.007\NAVEX32a.DLL]  <Symantec Corporation><20051.3.1.11>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060209.007\NAVENG32.DLL]  <Symantec Corporation><20051.3.1.11>
    [D:\Program Files\Symantec AntiVirus\NAVAP32.DLL]  <Symantec Corporation><9.5.0.44>
    [D:\Program Files\Symantec AntiVirus\SAVRT32.DLL]  <Symantec Corporation><9.5.0.44>
    [D:\Program Files\Symantec AntiVirus\IMail.dll]  <Symantec Corporation><10.0.1.1000>
    [D:\Program Files\Symantec AntiVirus\SymProtectStorage.dll]  <Symantec Corporation><10.0.1.1000>
    [C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCEvt.dll]  <Symantec Corporation><1,5,1,3>
[PID: 1828][C:\WINDOWS\system32\TpKmpSVC.exe]  <N/A><N/A>
[PID: 996][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 332][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 684][C:\WINDOWS\system32\tp4serv.exe]  <Lenovo Group Limited><3.55>
    [C:\WINDOWS\system32\tp4uires.dll]  <N/A><N/A>
[PID: 728][C:\WINDOWS\AGRSMMSG.exe]  <Agere Systems><2.1.31 2.1.31 06/27/2003 08:53:31>
[PID: 772][C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe]  <Lenovo Group Limited><1, 0, 0, 0>
    [C:\PROGRA~1\ThinkPad\UTILIT~1\SC\EzMApRes.dll]  <N/A><N/A>
[PID: 1040][D:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe]  <N/A><N/A>
    [C:\WINDOWS\system32\Oemdspif.dll]  <S3 Graphics, Inc.><1.00.04-1203>
    [D:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\tpfnf7.dll]  <N/A><N/A>
[PID: 1360][C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE]  <Lenovo><3, 8, 1, 0>
    [C:\Program Files\ThinkPad\ConnectUtilities\QCON.dll]  <Lenovo><3, 8, 1, 0>
    [C:\Program Files\ThinkPad\ConnectUtilities\MerlinC201.dll]  <Novatel Wireless Inc.><1, 0, 0, 1>
    [C:\Program Files\ThinkPad\ConnectUtilities\Res\SC\TrayRes.dll]  <N/A><N/A>
    [C:\Program Files\ThinkPad\ConnectUtilities\ANCA.dll]  <IBM Corp.><8.3>
    [C:\Program Files\ThinkPad\ConnectUtilities\ANC.dll]  <IBM Corp.><8.3>
[PID: 1880][d:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe]  <N/A><N/A>
[PID: 1464][C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE]  <Lenovo><3, 8, 1, 0>
    [C:\Program Files\ThinkPad\ConnectUtilities\QCON.dll]  <Lenovo><3, 8, 1, 0>
    [C:\Program Files\ThinkPad\ConnectUtilities\MerlinC201.dll]  <Novatel Wireless Inc.><1, 0, 0, 1>
    [C:\Program Files\ThinkPad\ConnectUtilities\Res\SC\IconRes.dll]  <N/A><N/A>
[PID: 1620][C:\Program Files\Common Files\Symantec Shared\ccApp.exe]  <Symantec Corporation><103.5.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ccL35.dll]  <Symantec Corporation><103.5.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  <Symantec Corporation><103.5.4.3>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\CCALERT.DLL]  <Symantec Corporation><103.5.4.3>
    [C:\PROGRA~1\COMMON~1\SYMANT~1\CCEMLPXY.DLL]  <Symantec Corporation><103.5.4.3>
gototop
 

[C:\WINDOWS\system32\SYMREDIR.DLL]  <Symantec Corporation><5.5.2.1>
    [C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll]  <Symantec Corporation><103.5.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ccProSub.dll]  <Symantec Corporation><103.5.4.3>
    [D:\Program Files\Symantec AntiVirus\SavEmail.dll]  <Symantec Corporation><10.0.1.1000>
[PID: 1836][D:\PROGRA~1\SYMANT~1\VPTray.exe]  <Symantec Corporation><10.0.1.1000>
    [D:\Program Files\Symantec AntiVirus\SAVRT32.DLL]  <Symantec Corporation><9.5.0.44>
    [D:\Program Files\Symantec AntiVirus\Cliscan.dll]  <Symantec Corporation><10.0.1.1000>
    [D:\PROGRA~1\SYMANT~1\NAVNTUTL.DLL]  <Symantec Corporation><10.0.1.1000>
    [D:\Program Files\Symantec AntiVirus\Cliproxy.dll]  <Symantec Corporation><10.0.1.1000>
[PID: 2028][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3427>
[PID: 1912][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2140][C:\Program Files\MSN Messenger\msnmsgr.exe]  <Microsoft Corporation><7.5.0311>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
[PID: 2164][C:\Program Files\Messenger\msmsgs.exe]  <Microsoft Corporation><4.7.3001>
[PID: 2888][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [D:\PROGRA~1\SPYBOT~1\SDHelper.dll]  <Safer Networking Limited><1, 4, 0, 0>
    [d:\program files\flashget\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
[PID: 2896][d:\Program Files\WinRAR\WinRAR.exe]  <N/A><N/A>
[PID: 3936][C:\DOCUME~1\ff\LOCALS~1\Temp\Rar$EX00.764\SREng.exe]  <Smallfrogs Studio><2.0.12.350>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

8楼spy修复以后不起任何作用。
gototop
 

每天被劫持的网站不确定,劫持时间也不确定,没有规律。
比如打开瑞星社区,会自动转向到4楼所示的那个网址,并且有弹出窗口。
gototop
 

http://forum.ikaka.com/topic.asp?board=67&artid=5188931
下载CWShredder
使用前请升级CWShredder到最新版本
gototop
 

**** Run Keys ****

RUN: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
RUN: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
RUN: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
RUN: [TrackPointSrv] tp4serv.exe
RUN: [AGRSMMSG] AGRSMMSG.exe
RUN: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
RUN: [TPHOTKEY] d:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
RUN: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
RUN: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
RUN: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
RUN: [TP4EX] tp4ex.exe
RUN: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
RUN: [vptray] D:\PROGRA~1\SYMANT~1\VPTray.exe
RUN: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
RUN: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
RUN: [msnmsgr] ; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
RUN: [MSMSGS] ; "C:\Program Files\Messenger\msmsgs.exe" /background


**** Browser Helper Objects ****

BHO: [] D:\PROGRA~1\SPYBOT~1\SDHelper.dll


**** IE Toolbars ****



**** IE Extensions ****

IEExt: [更新 ThinkPad 软件] d:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
IEExt: [FlashGet] D:\Program Files\FlashGet\flashget.exe
IEExt: [Messenger] C:\Program Files\Messenger\msmsgs.exe


**** Hosts File Entries ****

HOSTS: 127.0.0.1      localhost
HOSTS: 127.0.0.1      localhost


**** IE Settings ****

IEProxy: 10.76.32.2:80
IEBypass: 10.*;*.dg.cnpc.com.cn;<local>
Default Page: http://www.microsoft.com/windows/ie_intl/cn/start/
Default Search: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Local Page: about:blank
Search Page: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch


**** IE Context Menu (Right click) ****

IEContext: [使用网际快车下载] D:\Program Files\FlashGet\jc_link.htm
IEContext: [使用网际快车下载全部链接] D:\Program Files\FlashGet\jc_all.htm


**** Layered Service Providers ****

LSP: MSAFD Irda [IrDA]
LSP: MSAFD Tcpip [TCP/IP]
LSP: MSAFD Tcpip [UDP/IP]
LSP: RSVP UDP Service Provider
LSP: RSVP TCP Service Provider
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{B0DBA77A-529A-4AC9-A790-B79976534E0B}] SEQPACKET 3
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{B0DBA77A-529A-4AC9-A790-B79976534E0B}] DATAGRAM 3
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{40852D4C-EB40-497C-8B8B-892D90573311}] SEQPACKET 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{40852D4C-EB40-497C-8B8B-892D90573311}] DATAGRAM 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{834062C8-6D69-42AD-9F55-6118F77DB16C}] SEQPACKET 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{834062C8-6D69-42AD-9F55-6118F77DB16C}] DATAGRAM 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4D347E2D-15AB-421C-9D51-6AE02BE357DC}] SEQPACKET 2
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4D347E2D-15AB-421C-9D51-6AE02BE357DC}] DATAGRAM 2
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{8E827227-AF6D-4501-B174-B17EB443872C}] SEQPACKET 4
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{8E827227-AF6D-4501-B174-B17EB443872C}] DATAGRAM 4
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{07D81F1F-6A1F-4BEA-990A-F035390F122E}] SEQPACKET 5
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{07D81F1F-6A1F-4BEA-990A-F035390F122E}] DATAGRAM 5


**** Blocked Control Panel Items ****

BLOCKED: [ncpa.cpl] No
BLOCKED: [odbccp32.cpl] No


**** Downloaded Program Files ****

{6414512B-B978-451D-A0D8-FCFDF33E833C} [http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1139565127956] C:\WINDOWS\system32\wuweb.dll
{D27CDB6E-AE6D-11CF-96B8-444553540000} [http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab]
{D30CA0FD-1CA0-11D4-AC78-006008A9A8BC} [http://navs.dg.cnpc.com.cn/webinst/webinst.cab]


**** Windows Services ****

[Alerter] %SystemRoot%\system32\svchost.exe -k LocalService
[ALG] %SystemRoot%\System32\alg.exe
[AppMgmt] %SystemRoot%\system32\svchost.exe -k netsvcs
[AudioSrv] %SystemRoot%\System32\svchost.exe -k netsvcs
[BITS] %SystemRoot%\system32\svchost.exe -k netsvcs
[Browser] %SystemRoot%\system32\svchost.exe -k netsvcs
[ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
[ccPwdSvc] "C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"
[ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
[CiSvc] %SystemRoot%\system32\cisvc.exe
[ClipSrv] %SystemRoot%\system32\clipsrv.exe
[COMSysApp] C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
[CryptSvc] %SystemRoot%\system32\svchost.exe -k netsvcs
[DcomLaunch] %SystemRoot%\system32\svchost -k DcomLaunch
[DefWatch] "D:\Program Files\Symantec AntiVirus\DefWatch.exe"
[Dhcp] %SystemRoot%\system32\svchost.exe -k netsvcs
[dmadmin] %SystemRoot%\System32\dmadmin.exe /com
[dmserver] %SystemRoot%\System32\svchost.exe -k netsvcs
[Dnscache] %SystemRoot%\system32\svchost.exe -k NetworkService
[ERSvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[Eventlog] %SystemRoot%\system32\services.exe
[EventSystem] C:\WINDOWS\system32\svchost.exe -k netsvcs
[FastUserSwitchingCompatibility] %SystemRoot%\System32\svchost.exe -k netsvcs
[helpsvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[HidServ] %SystemRoot%\System32\svchost.exe -k netsvcs
[HTTPFilter] %SystemRoot%\System32\svchost.exe -k HTTPFilter
[IBMPMSVC] %SystemRoot%\system32\ibmpmsvc.exe
[ImapiService] C:\WINDOWS\system32\imapi.exe
[Irmon] %SystemRoot%\system32\svchost.exe -k netsvcs
[lanmanserver] %SystemRoot%\system32\svchost.exe -k netsvcs
[lanmanworkstation] %SystemRoot%\system32\svchost.exe -k netsvcs
[LmHosts] %SystemRoot%\system32\svchost.exe -k LocalService
[Messenger] %SystemRoot%\system32\svchost.exe -k netsvcs
[mnmsrvc] C:\WINDOWS\system32\mnmsrvc.exe
[MSDTC] C:\WINDOWS\system32\msdtc.exe
[MSIServer] C:\WINDOWS\system32\msiexec.exe /V
[NetDDE] %SystemRoot%\system32\netdde.exe
[NetDDEdsdm] %SystemRoot%\system32\netdde.exe
[Netlogon] %SystemRoot%\system32\lsass.exe
[Netman] %SystemRoot%\System32\svchost.exe -k netsvcs
[NetSvc] C:\Program Files\Intel\NCS\Sync\NetSvc.exe
[Nla] %SystemRoot%\system32\svchost.exe -k netsvcs
[NtLmSsp] %SystemRoot%\system32\lsass.exe
[NtmsSvc] %SystemRoot%\system32\svchost.exe -k netsvcs
[PlugPlay] %SystemRoot%\system32\services.exe
[PolicyAgent] %SystemRoot%\system32\lsass.exe
[ProtectedStorage] %SystemRoot%\system32\lsass.exe
[QCONSVC] System32\QCONSVC.EXE
[RasAuto] %SystemRoot%\system32\svchost.exe -k netsvcs
[RasMan] %SystemRoot%\system32\svchost.exe -k netsvcs
[RDSessMgr] C:\WINDOWS\system32\sessmgr.exe
[RemoteAccess] %SystemRoot%\system32\svchost.exe -k netsvcs
[RemoteRegistry] %SystemRoot%\system32\svchost.exe -k LocalService
[rpcapd] "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini"
[RpcLocator] %SystemRoot%\system32\locator.exe
[RpcSs] %SystemRoot%\system32\svchost -k rpcss
[RSVP] %SystemRoot%\system32\rsvp.exe
[SamSs] %SystemRoot%\system32\lsass.exe
[SavRoam] "D:\Program Files\Symantec AntiVirus\SavRoam.exe"
[SCardSvr] %SystemRoot%\System32\SCardSvr.exe
[Schedule] %SystemRoot%\System32\svchost.exe -k netsvcs
[seclogon] %SystemRoot%\System32\svchost.exe -k netsvcs
[SENS] %SystemRoot%\system32\svchost.exe -k netsvcs
[SharedAccess] %SystemRoot%\system32\svchost.exe -k netsvcs
gototop
 

[ShellHWDetection] %SystemRoot%\System32\svchost.exe -k netsvcs
[SNDSrvc] "C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"
[SPBBCSvc] "C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"
[Spooler] %SystemRoot%\system32\spoolsv.exe
[srservice] %SystemRoot%\system32\svchost.exe -k netsvcs
[SSDPSRV] %SystemRoot%\system32\svchost.exe -k LocalService
[stisvc] %SystemRoot%\system32\svchost.exe -k imgsvc
[SwPrv] C:\WINDOWS\system32\dllhost.exe /Processid:{EBB92B56-6DF7-427B-8E88-3BCE346148FB}
[Symantec AntiVirus] "D:\Program Files\Symantec AntiVirus\Rtvscan.exe"
[SysmonLog] %SystemRoot%\system32\smlogsvc.exe
[TapiSrv] %SystemRoot%\System32\svchost.exe -k netsvcs
[TermService] %SystemRoot%\System32\svchost -k DComLaunch
[Themes] %SystemRoot%\System32\svchost.exe -k netsvcs
[TlntSvr] C:\WINDOWS\system32\tlntsvr.exe
[TpKmpSVC] C:\WINDOWS\system32\TpKmpSVC.exe
[TrkWks] %SystemRoot%\system32\svchost.exe -k netsvcs
[UMWdf] C:\WINDOWS\system32\wdfmgr.exe
[upnphost] %SystemRoot%\system32\svchost.exe -k LocalService
[UPS] %SystemRoot%\System32\ups.exe
[VSS] %SystemRoot%\System32\vssvc.exe
[W32Time] %SystemRoot%\System32\svchost.exe -k netsvcs
[WebClient] %SystemRoot%\system32\svchost.exe -k LocalService
[winmgmt] %systemroot%\system32\svchost.exe -k netsvcs
[WmdmPmSN] %SystemRoot%\System32\svchost.exe -k netsvcs
[Wmi] %SystemRoot%\System32\svchost.exe -k netsvcs
[WmiApSrv] C:\WINDOWS\system32\wbem\wmiapsrv.exe
[wscsvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[wuauserv] %systemroot%\system32\svchost.exe -k netsvcs
[WZCSVC] %SystemRoot%\System32\svchost.exe -k netsvcs
[xmlprov] %SystemRoot%\System32\svchost.exe -k netsvcs


**** Custom IE Search Items ****

SEARCH: [SearchAssistant] http://www.baidu.com/
SEARCH: [CustomizeSearch] http://www.baidu.com/


**** Complete IE Options ****

IEOPT: [NoUpdateCheck] 
IEOPT: [NoJITSetup] 
IEOPT: [Disable Script Debugger] yes
IEOPT: [Show_ChannelBand] No
IEOPT: [Anchor Underline] yes
IEOPT: [Cache_Update_Frequency] Once_Per_Session
IEOPT: [Display Inline Images] yes
IEOPT: [Do404Search] 
IEOPT: [Local Page] about:blank
IEOPT: [Save_Session_History_On_Exit] no
IEOPT: [Show_FullURL] no
IEOPT: [Show_StatusBar] yes
IEOPT: [Show_ToolBar] yes
IEOPT: [Show_URLinStatusBar] yes
IEOPT: [Show_URLToolBar] yes
IEOPT: [Start Page] http://www.baidu.com/
IEOPT: [Use_DlgBox_Colors] yes
IEOPT: [Search Page] http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IEOPT: [FullScreen] no
IEOPT: [Window_Placement] ,
IEOPT: [AddToFavoritesExpanded] 
IEOPT: [Use FormSuggest] no
IEOPT: [NotifyDownloadComplete] yes
IEOPT: [Enable Browser Extensions] yes
IEOPT: [AutoSearch] 
IEOPT: [Print_Background] no
IEOPT: [Play_Animations] yes
IEOPT: [Play_Background_Sounds] yes
IEOPT: [Display Inline Videos] yes
IEOPT: [Enable_MyPics_Hoverbar] yes
IEOPT: [Enable AutoImageResize] yes
IEOPT: [Show image placeholders] 
IEOPT: [Expand Alt Text] no
IEOPT: [Move System Caret] no
IEOPT: [UseThemes] 
IEOPT: [NscSingleExpand] 
IEOPT: [DisableScriptDebuggerIE] yes
IEOPT: [FavIntelliMenus] no
IEOPT: [NoWebJITSetup] 
IEOPT: [Force Offscreen Composition] 
IEOPT: [SmoothScroll] 
IEOPT: [Error Dlg Displayed On Every Error] no
IEOPT: [Friendly http errors] no
IEOPT: [Page_Transitions] 
IEOPT: [ShowGoButton] yes
IEOPT: [AllowWindowReuse] 
IEOPT: [Window Title] Microsoft Internet Explorer
IEOPT: [Default_Page_URL] http://www.microsoft.com/windows/ie_intl/cn/start/
IEOPT: [Default_Search_URL] http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IEOPT: [Search Page] http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IEOPT: [Enable_Disk_Cache] yes
IEOPT: [Cache_Percent_of_Disk] 
IEOPT: [Delete_Temp_Files_On_Exit] yes
IEOPT: [Local Page] about:blank
IEOPT: [Anchor_Visitation_Horizon] 
IEOPT: [Use_Async_DNS] yes
IEOPT: [Placeholder_Width] 
IEOPT: [Placeholder_Height] 
IEOPT: [Start Page] about:blank
IEOPT: [CompanyName] Microsoft Corporation
IEOPT: [Custom_Key] MICROSO
IEOPT: [Wizard_Version] 6.0.2600.0000
IEOPT: [FullScreen] no
gototop
 

用那个工具修复了吗
gototop
 

点击了fix,还是那样,笔记本上卡卡上不来了,只好用这个电脑。
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT