瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 谁能告诉我为什么开qq会出现这个东西啊?还有怎么解决呢?

1234   1  /  4  页   跳转

谁能告诉我为什么开qq会出现这个东西啊?还有怎么解决呢?

谁能告诉我为什么开qq会出现这个东西啊?还有怎么解决呢?

先出现这个

附件附件:

下载次数:262
文件类型:image/pjpeg
文件大小:
上传时间:2007-2-27 18:18:04
描述:



最后编辑2007-03-01 18:06:14
分享到:
gototop
 

按确定后又出来这个

附件附件:

下载次数:238
文件类型:image/pjpeg
文件大小:
上传时间:2007-2-27 18:19:38
描述:



gototop
 

有没有尝试卸载QQ然后再重新安装新的版本的QQ(最好装在不同的地方)?

除此之外,还有没有其他异常的地方?
gototop
 

【回复“horseluke11”的帖子】
从新安装过,不过还是装在老地方.还有别的就是打开网页的时候有时也会出现这样的问题,按下确定后就全部关掉了
gototop
 

还有这个是什么原因

附件附件:

下载次数:312
文件类型:image/pjpeg
文件大小:
上传时间:2007-2-27 18:37:20
描述:



gototop
 

之所以先不叫你贴日志是因为曾经有类似的帖子:
http://forum.ikaka.com/topic.asp?board=28&artid=8147595


而在微软的搜索中同时都指向了IE7......但是都没有统一的解决方法......

根据第4楼的图片,楼主似乎安装了IE7?


高手们,你们认为用不用扫日志?
gototop
 

想了一想,为了确保自己的想法,烦请楼主扫SREG2的日志上来。

http://www.kztechs.com/sreng/sreng2.zip 下载System Repair Engineer
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改;一次发不完的,请分次发.


如果你对SREG2及扫描出来的日志有兴趣,可以查看以下内容:
SRE(System Repair Engineer)的使用方法:http://forum.ikaka.com/topic.asp?board=28&artid=8270267
手工检测病毒(已完成)(会继续整理一些资料并重新发帖):http://forum.ikaka.com/topic.asp?board=28&artid=8267493
gototop
 

【回复“horseluke11”的帖子】
对的,以前也有一段时间用过IE7也出现了这样的问题.就是开了一些网页后就出现这个问题.不过上次qq还没出现这样的问题.
gototop
 

有事情,可能要离开一下。

楼主扫完日志后看(方法及工具请看第6楼),其他高手帮忙看一下吧。

现在我找到的资料,既跟IE7有关(集中在微软的英文论坛),又跟病毒有关(国内论坛反映居多)......
gototop
 

打开软件后出现这样的东西
[CODE]

2007-02-27,19:01:58

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><; "C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE" /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><; "C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE" /IMEName>  [(Verified)Microsoft Corporation]
    <Symantec NetDriver Monitor><; C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer>  [N/A]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  [N/A]
    <runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <KKDelay><C:\Program Files\Rising\AntiSpyware\RunOnce.exe>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Corporation]

==================================
启动文件夹
[腾讯QQ]
  <C:\Documents and Settings\Owner\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\DOWNLO~1\QQ\QQ.exe [TENCENT]><N>

==================================
服务
[Application Management / AppMgmt][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
  <D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe><Anti-Malware Development a.s.>
[Logical Disk Manager / dmserver][Stopped/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\Zkrulaqh.dll><N/A>
[ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard][Stopped/Auto Start]
  <><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Machine Debug Manager / MDM][Running/Auto Start]
  <"C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"><Microsoft Corporation>
[PCTEL Speaker Phone / Pctspk][Running/Auto Start]
  <C:\WINDOWS\system32\pctspk.exe><PCtel, Inc.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Distributed Link Tracking ClientXyfne2 / ServiceXyfne2][Stopped/Auto Start]
  <><N/A>
[Symantec Network Drivers Service / SNDSrvc][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Symantec AntiVirus / Symantec AntiVirus][Stopped/Disabled]
  <C:\WINDOWS\system32\SVCH0ST.EXE><N/A>
[wingzip / wingzip][Stopped/Auto Start]
  <><N/A>

==================================
驱动程序
[AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
  <\??\D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys><N/A>
[AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
[BaseTDI / BaseTDI][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\basetdi.sys><Beijing Rising Technology Co., Ltd.>
[D-Link DL10050 based Adapter NT Driver / DLH5X][Running/Manual Start]
  <System32\DRIVERS\DLH5XND5.sys><D-Link Corporation>
[EagleNT / EagleNT][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\drivers\EagleNT.sys><N/A>
[ExpScaner / ExpScaner][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[HookCont / HookCont][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[kmsinput / kmsinput][Stopped/Manual Start]
  <\??\C:\WINDOWS\System32\drivers\kmsinput.sys><N/A>
[KWatch3 / KWatch3][Running/System Start]
  <\??\C:\WINDOWS\System32\drivers\KWatch3.SYS><Kingsoft Corporation>
[MEMSCAN / MEMSCAN][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\D:\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[npkycryp / npkycryp][Stopped/Manual Start]
  <\??\D:\QQ\npkycryp.sys><N/A>
[nv / nv][Running/Manual Start]
  <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[nv4 / nv4][Stopped/Manual Start]
  <System32\DRIVERS\nv4.sys><NVIDIA Corporation>
[nwlnksipx / nwlnksipx][Stopped/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\nwlnksipx.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PCTEL Serial Device Driver for PCI / Ptserlp][Running/Manual Start]
  <System32\DRIVERS\ptserlp.sys><PCTEL, INC.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
  <\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Secdrv / Secdrv][Stopped/Manual Start]
  <System32\DRIVERS\secdrv.sys><N/A>
[Prolific Serial port driver / Ser2pl][Stopped/Manual Start]
  <System32\DRIVERS\ser2pl.sys><Prolific Technology Inc.>
[SVKP / SVKP][Running/Auto Start]
  <\??\C:\WINDOWS\system32\SVKP.sys><AntiCracking>
[SYMDNS / SYMDNS][Stopped/Manual Start]
  <\SystemRoot\System32\Drivers\SYMDNS.SYS><Symantec Corporation>
[SymEvent / SymEvent][Stopped/Manual Start]
  <\??\C:\Program Files\Symantec\SYMEVENT.SYS><N/A>
[SYMFW / SYMFW][Stopped/Manual Start]
  <\SystemRoot\System32\Drivers\SYMFW.SYS><Symantec Corporation>
[SYMIDS / SYMIDS][Stopped/Manual Start]
  <\SystemRoot\System32\Drivers\SYMIDS.SYS><Symantec Corporation>
[SYMNDIS / SYMNDIS][Stopped/Manual Start]
  <\SystemRoot\System32\Drivers\SYMNDIS.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV][Stopped/Manual Start]
  <\SystemRoot\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI][Running/System Start]
  <\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <System32\DRIVERS\tcpip.sys><Microsoft Corporation>
[ViaIde / ViaIde][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\viaide.sys><Microsoft Corporation>
[VIA AC'97 Audio Controller (WDM) / VIAudio][Running/Manual Start]
  <system32\drivers\ac97via.sys><VIA Technologies, Inc.>
[XP Vmodem / Vmodem][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\vmodem.sys><PCTEL, INC.>
[XP Vpctcom / Vpctcom][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\vpctcom.sys><PCtel, Inc.>
[XP Vvoice / Vvoice][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\vvoice.sys><PCtel, Inc.>
[Ystmdtea / Ystmdtea][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\drivers\Ystmdtea.sys><N/A>
[Zkrulaqh / Zkrulaqh][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\Zkrulaqh.sys><N/A>
[Zuwcsonv / Zuwcsonv][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\Zuwcsonv.sys><N/A>

附件附件:

下载次数:271
文件类型:image/pjpeg
文件大小:
上传时间:2007-2-27 19:28:37
描述:



gototop
 
1234   1  /  4  页   跳转
页面顶部
Powered by Discuz!NT