瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 还是http://www.365j.com/? 主页被修改的问题

1   1  /  1  页   跳转

[求助] 还是http://www.365j.com/? 主页被修改的问题

还是http://www.365j.com/? 主页被修改的问题

我的ie被这个恶毒网站设置首页。置顶贴的方法,该原ie的快捷方式可以,可是到遨游的就不行了。
修改方法也是一样的(改完全控制)。为什么一个可以一个不可以?

用了许多方法,什么卡卡,360等等,都不行。

下面是日志,跪求大虾帮忙。不甚感激。[code]2009-08-25,22:55:36
System Repair Engineer 2.7.1.1261
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
    进程特权扫描
    计划任务
    API HOOK
    隐藏进程

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r>  [(Verified)Qizhi Software (beijing) Co. Ltd]
    <360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start>  [(Verified)Qizhi Software (beijing) Co. Ltd]
    <ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe">  [File is missing]
    <BLOG><rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog>  []
    <BluetoothAuthenticationAgent><rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent>  [(Verified)Microsoft Windows Component Publisher]
    <EZEJMNAP><C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe>  [(Verified)Lenovo(Japan)Ltd.]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <LPManager><C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe>  [(Verified)Lenovo(Japan)Ltd.]
    <PWRMGRTR><rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor>  [Lenovo Group Limited]
    <SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <TPHOTKEY><C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe>  [(Verified)Lenovo(Japan)Ltd.]
    <TpShocks><TpShocks.exe>  [(Verified)Lenovo(Japan)Ltd.]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  [File is missing]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Component Publisher]
    <Userinit><userinit.exe,>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Component Publisher]
    <CDBurn><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Component Publisher]
    <WebCheck><%SystemRoot%\system32\webcheck.dll>  [(Verified)Microsoft Windows Component Publisher]
    <SysTray><C:\WINDOWS\system32\stobject.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
    <WinlogonNotify: dimsntfy><%SystemRoot%\System32\dimsntfy.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
    <WinlogonNotify: ScCertProp><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
    <WinlogonNotify: Schedule><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    <WinlogonNotify: sclgntfy><sclgntfy.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
    <WinlogonNotify: termsrv><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tpfnf2]
    <WinlogonNotify: tpfnf2><C:\Program Files\Lenovo\HOTKEY\notifyf2.dll>  [(Verified)Lenovo (Japan) Ltd]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tphotkey]
    <WinlogonNotify: tphotkey><C:\Program Files\Lenovo\HOTKEY\tphklock.dll>  [Lenovo Group Limited]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
    <WinlogonNotify: wlballoon><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    <Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
    <浏览器自定义组件><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\aetsprov]
    <N/A><C:\WINDOWS\system32\regsvr32.exe /s C:\WINDOWS\system32\aetsprov.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
    <Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
    <Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
    <N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\system32\logon.scr>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <Adobe Reader Speed Launcher><; "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe">  [(Verified)"Adobe Systems, Incorporated"]
    <DAEMON Tools-2052><; "C:\Program Files\D-Tools\daemon.exe"  -lang 2052>  [DAEMON'S HOME]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}><; "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020>  [File is missing]
    <Lava-Lava><; "d:\Program Files\DianJi\Lava-Lava\Lava-Lava.exe" /s>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <NeroFilterCheck><; C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe>  [(Verified)Nero AG]
    <QuickTime Task><; "D:\Program Files\QuickTime\QTTask.exe" -atboottime>  [Apple Inc.]
    <swjs><; d:\Program Files\上网记时\swjs.exe>  [File is missing]
    <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [(Verified)"RealNetworks, Inc."]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    <WangWang><; "d:\Program Files\Alisoft\WangWang\WangWang.exe">  [(Verified)"Alibaba Software(Shanghai)Co,. Ltd"]
==================================

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; MAXTHON 2.0)
分享到:
gototop
 

回复:还是http://www.365j.com/? 主页被修改的问题

启动文件夹
N/A

==================================
服务
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[Bluetooth Service / btwdins][Running/Auto Start]
  <D:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe><Broadcom Corporation.>
[Contrl Center of Storm Media / ccosm][Running/Auto Start]
  <d:\Program Files\StormII\stormliv.exe /asservice><北京暴风网际科技有限公司>
[Eset HTTP Server / EhttpSrv][Stopped/Manual Start]
  <"C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe"><ESET>
[Eset Service / ekrn][Running/Auto Start]
  <"C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe"><ESET>
[Intel? PROSet/Wireless Event Log / EvtEng][Running/Auto Start]
  <C:\Program Files\Intel\WiFi\bin\EvtEng.exe><Intel(R) Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[ThinkPad PM Service / IBMPMSVC][Running/Auto Start]
  <C:\WINDOWS\system32\ibmpmsvc.exe><Lenovo>
[Kingsoft Basic Service / kaccore][Stopped/Manual Start]
  <"C:\Program Files\Kingsoft\KAC\Service\kaccore.exe"><(File is missing)>
[Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><>
[NMIndexingService / NMIndexingService][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe"><Nero AG>
[Power Manager DBC Service / Power Manager DBC Service][Running/Auto Start]
  <C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE><>
[Intel? PROSet/Wireless Registry Service / RegSrvc][Running/Auto Start]
  <C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe><Intel(R) Corporation>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd][Stopped/Manual Start]
  <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><CACE Technologies, Inc.>
[Intel?PROSet/Wireless WiFi Service / S24EventMonitor][Running/Auto Start]
  <C:\Program Files\Intel\WiFi\bin\S24EvMon.exe><Intel(R) Corporation>
[TCP IP Configuration / TCP IP Configuration][Stopped/Auto Start]
  <C:\WINDOWS\system32\makecsb.exe runsrv /name:"TCP IP Configuration" /prinum:"32" /cmdline:"C:\WINDOWS\system32\WMSysPr9.prx"><N/A>
[ThinkPad HDD APS Logging Service / TPHDEXLGSVC][Running/Auto Start]
  <System32\TPHDEXLG.exe><(File is missing)>

==================================
驱动程序
[ati2mtag / ati2mtag][Running/Manual Start]
  <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[蓝牙音频设备 / btaudio][Running/Manual Start]
  <system32\drivers\btaudio.sys><Broadcom Corporation.>
[蓝牙虚拟通信驱动程序 / BTDriver][Running/Manual Start]
  <system32\DRIVERS\btport.sys><Broadcom Corporation.>
[蓝牙总线枚举器 / BTKRNL][Running/Manual Start]
  <system32\DRIVERS\btkrnl.sys><Broadcom Corporation.>
[蓝牙局域网接入服务器 / BTWDNDIS][Running/Manual Start]
  <system32\DRIVERS\btwdndis.sys><Broadcom Corporation.>
[蓝牙调制解调器 / btwmodem][Running/Manual Start]
  <system32\DRIVERS\btwmodem.sys><Broadcom Corporation.>
[WIDCOMM USB Bluetooth Driver / BTWUSB][Running/Manual Start]
  <System32\Drivers\btwusb.sys><Broadcom Corporation.>
[Conexant UAA Function Driver for High Definition Audio Service / CnxtHdAudService][Running/Manual Start]
  <system32\drivers\CHDAU32.sys><Conexant Systems Inc.>
[d347bus / d347bus][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\d347bus.sys><>
[d347prt / d347prt][Running/Boot Start]
  <\SystemRoot\System32\Drivers\d347prt.sys><>
[Intel(R) Gigabit Network Connections Driver / e1yexpress][Running/Manual Start]
  <system32\DRIVERS\e1y5132.sys><Intel Corporation>
[eamon / eamon][Running/Auto Start]
  <system32\DRIVERS\eamon.sys><ESET>
[easdrv / easdrv][Running/System Start]
  <system32\DRIVERS\easdrv.sys><ESET>
[epfwtdir / epfwtdir][Running/System Start]
  <system32\DRIVERS\epfwtdir.sys><N/A>
[usb Card Device / ft2kEnum][Running/Manual Start]
  <system32\DRIVERS\ic2kenum.sys><OEM Corporation>
[USB Chip Holder Service / GDBaseSmc][Running/Manual Start]
  <system32\DRIVERS\Chip_smc.sys><OEM>
[USB Chip Service / GD_USB][Stopped/Manual Start]
  <system32\DRIVERS\Chip_usb.sys><>
[Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start]
  <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[Intel(R) Management Engine Interface / HECI][Running/Manual Start]
  <system32\DRIVERS\HECI.sys><Intel Corporation>
[HSFHWAZL / HSFHWAZL][Running/Manual Start]
  <system32\DRIVERS\HSFHWAZL.sys><Conexant Systems, Inc.>
[HSF_DPV / HSF_DPV][Running/Manual Start]
  <system32\DRIVERS\HSF_DPV.sys><Conexant Systems, Inc.>
[IBMPMDRV / IBMPMDRV][Running/Manual Start]
  <system32\DRIVERS\ibmpmdrv.sys><Lenovo.>
[ZTE Mass Storage Filter Driver / massfilter][Stopped/Manual Start]
  <system32\drivers\massfilter.sys><N/A>
[mdmxsdk / mdmxsdk][Running/Auto Start]
  <system32\DRIVERS\mdmxsdk.sys><Conexant>
[Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit / NETw5x32][Running/Manual Start]
  <system32\DRIVERS\NETw5x32.sys><Intel Corporation>
[npkcrypt / npkcrypt][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\npkcrypt.sys><N/A>
[npkycryp / npkycryp][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\npkycryp.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[SmartCard Reader Device  / Reader_Device][Running/Manual Start]
  <system32\DRIVERS\usbic2k.sys><OEM>
[rimmptsk / rimmptsk][Running/Auto Start]
  <system32\DRIVERS\rimmptsk.sys><REDC>
[rimsptsk / rimsptsk][Running/Auto Start]
  <system32\DRIVERS\rimsptsk.sys><REDC>
[Ricoh xD-Picture Card Driver / rismxdp][Running/Auto Start]
  <system32\DRIVERS\rixdptsk.sys><REDC>
[WLAN 传输 / s24trans][Running/Auto Start]
  <system32\DRIVERS\s24trans.sys><Intel Corporation>
[SafeBoxKrnl / SafeBoxKrnl][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\SafeBoxKrnl.sys><360安全中心>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[Shockprf / Shockprf][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\Apsx86.sys><Lenovo.>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
  <system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[TPDIGIMN / TPDIGIMN][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\ApsHM86.sys><Lenovo.>
[TPHKDRV / TPHKDRV][Running/System Start]
  <system32\DRIVERS\TPHKDRV.sys><Lenovo Group Limited>
[TPPWRIF / TPPWRIF][Running/System Start]
  <System32\drivers\Tppwrif.sys><N/A>
[ThirdNET PHS Modem Card v1.00 20071220 / usbmdm][Stopped/Manual Start]
  <system32\DRIVERS\ser3pl.sys><Prolific Technology Inc.>
[winachsf / winachsf][Running/Manual Start]
  <system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>
[ZTE CDMA AT Interface / zgdccat][Stopped/Manual Start]
  <system32\DRIVERS\zgdccat.sys><N/A>
[ZTE CDMA Diagnostics Interface / zgdccdiag][Stopped/Manual Start]
  <system32\DRIVERS\zgdccdiag.sys><N/A>
[ZTE CDMA Proprietary USB Modem / zgdccmdm][Stopped/Manual Start]
  <system32\DRIVERS\zgdccmdm.sys><N/A>
[ZTE CDMA Sound Interface / zgdccvousb][Stopped/Manual Start]
  <system32\DRIVERS\zgdccvousb.sys><N/A>

==================================
浏览器加载项
[启动迅雷5]
  {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <d:\Program Files\Thunder\Thunder.exe, (Signed) Thunder Networking Technologies,LTD>
[myBabylon English Toolbar]
  {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} <C:\Program Files\myBabylon_English\tbmyB1.dll, (Signed) Conduit Ltd.>
[使用迅雷下载]
  <D:\Program Files\Thunder\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
  <D:\Program Files\Thunder\Program\getallurl.htm, N/A>
[发送到 Bluetooth]
  <D:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm, N/A>
[发送到 Bluetooth 设备(&B)...]
  <D:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[百度一下所选文字 (&S)]
  <C:\Program Files\Common Files\baidu\Baidu.html, N/A>
gototop
 

回复:还是http://www.365j.com/? 主页被修改的问题

==================================
正在运行的进程
[PID: 1088 / SYSTEM][\SystemRoot\System32\smss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1156 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1188 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
    [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4177]
    [C:\Program Files\Lenovo\HOTKEY\tphklock.dll]  [Lenovo Group Limited, 1.03]
[PID: 1232 / SYSTEM][C:\WINDOWS\system32\services.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[PID: 1244 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[PID: 1400 / SYSTEM][C:\WINDOWS\system32\ibmpmsvc.exe]  [Lenovo, 1.51]
[PID: 1428 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4199]
    [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2513]
    [C:\WINDOWS\system32\atipdlxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2535]
[PID: 1448 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1508 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1560 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
    [C:\WINDOWS\SYSTEM\msxml3.dll]  [Microsoft Corporation, 8.20.8730.1]
[PID: 1696 / SYSTEM][C:\Program Files\Intel\WiFi\bin\S24EvMon.exe]  [Intel(R) Corporation, 12, 1, 1, 9]
    [C:\Program Files\Intel\WiFi\bin\IntStngs.dll]  [Intel(R) Corporation, 12, 1, 1, 0]
    [C:\Program Files\Intel\WiFi\bin\IWMSPROV.DLL]  [N/A, ]
    [C:\Program Files\Common Files\Intel\WirelessCommon\PsRegApi.dll]  [Intel(R) Corporation, 12, 1, 1, 0]
    [C:\Program Files\Common Files\Intel\WirelessCommon\TraceApi.dll]  [Intel(R) Corporation, 12, 1, 1, 2]
    [C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll]  [The OpenSSL Project, http://www.openssl.org/, 0.9.8]
    [C:\Program Files\Intel\WiFi\bin\KmmdlPlugins\SupplicantPlugin.dll]  [Intel(R) Corporation, 12, 1, 1, 12]
    [C:\Program Files\Intel\WiFi\bin\KmmdlPlugins\WSCPlugin.dll]  [Intel(R) Corporation, 12, 1, 1, 5]
    [C:\Program Files\Intel\WiFi\bin\supplicant.dll]  [Devicescape Software, Inc., 1, 0, 72, 0]
[PID: 1772 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1820 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 268 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4199]
    [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2513]
    [C:\WINDOWS\system32\atipdlxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2535]
    [C:\WINDOWS\system32\ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4177]
[PID: 368 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
    [C:\WINDOWS\system32\bthcrp.dll]  [Broadcom Corporation., 5.5.0.4300]
    [C:\WINDOWS\system32\WidcommSdk.dll]  [Broadcom Corporation., 5.5.0.4300]
    [C:\WINDOWS\system32\wbtapi.dll]  [Broadcom Corporation., 5.5.0.4300]
[PID: 420 / LOCAL SERVICE][C:\WINDOWS\System32\SCardSvr.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[PID: 804 / user][C:\WINDOWS\Explorer.EXE]  [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1021]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 9.1.0.2009022700]
    [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS]  [, ]
    [C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll]  [, 2, 0, 0, 0]
    [C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiamCHS.dll]  [Advanced Micro Devices, Inc., 6.14.10.2001]
    [C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll]  [ESET, 3.0.684 ]
    [d:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\WINDOWS\system32\btncopy.dll]  [Broadcom Corporation., 5.5.0.4300]
    [C:\Program Files\Lenovo\HOTKEY\hkvolkey.dll]  [Lenovo Group Limited, 1.01]
[PID: 900 / user][C:\WINDOWS\system32\rundll32.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[PID: 924 / user][C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe]  [Lenovo Group Ltd., 2, 3, 2, 0]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\SC\EzMApRes.dll]  [Lenovo Group Ltd., 2, 3, 2, 0]
[PID: 948 / user][C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe]  [Lenovo Group Limited, 3, 0, 0, 0]
    [C:\PROGRA~1\THINKV~1\PrdCtr\SC\LPRESMGR.DLL]  [Lenovo Group Limited, 3, 0, 0, 0]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1021]
    [C:\WINDOWS\SYSTEM\msxml3.dll]  [Microsoft Corporation, 8.20.8730.1]
[PID: 956 / user][C:\WINDOWS\system32\rundll32.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL]  [Lenovo Group Limited, 1, 0, 0, 0]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\SC\PWRMGRRT.DLL]  [N/A, ]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRIF.DLL]  [N/A, ]
    [C:\WINDOWS\system32\Sensor.dll]  [Lenovo., 1.60.0.6]
    [C:\WINDOWS\system32\OEMDSPIF.DLL]  [ATI Technologies, Inc., 6.15.0402]
    [C:\WINDOWS\system32\atipdlxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2535]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\ATM.DLL]  [Lenovo Japan, 1, 3, 4, 0]
[PID: 928 / user][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe]  [Synaptics, Inc., 11.1.21.2 06Oct08]
    [C:\WINDOWS\system32\SynCOM.dll]  [Synaptics, Inc., 11.1.21.2 06Oct08]
    [C:\WINDOWS\system32\SynTPAPI.dll]  [Synaptics, Inc., 11.1.21.2 06Oct08]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1021]
[PID: 604 / user][C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe]  [Lenovo Group Limited, 1.04]
    [C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.dll]  [Lenovo Group Limited, 1.00]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1021]
    [C:\Program Files\Lenovo\HOTKEY\hkvolkey.dll]  [Lenovo Group Limited, 1.01]
[PID: 1040 / user][C:\WINDOWS\system32\TpShocks.exe]  [Lenovo., 1.61.0.1]
    [C:\Program Files\ThinkPad\TpShocks\MUI\0804\TpShocks.dll]  [, ]
    [C:\WINDOWS\system32\Sensor.dll]  [Lenovo., 1.60.0.6]
[PID: 1708 / user][C:\WINDOWS\system32\ctfmon.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[PID: 1856 / user][C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe]  [Lenovo Group Limited, 5.01]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1021]
[PID: 1892 / user][C:\Program Files\Lenovo\Zoom\TpScrex.exe]  [Lenovo Group Limited, 2.03]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1021]
[PID: 2004 / user][C:\Program Files\Synaptics\SynTP\SynTPLpr.exe]  [Synaptics, Inc., 11.1.21.2 06Oct08]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1021]
    [C:\WINDOWS\system32\SynCOM.dll]  [Synaptics, Inc., 11.1.21.2 06Oct08]
[PID: 1944 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 2060 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 2124 / SYSTEM][d:\Program Files\StormII\stormliv.exe]  [北京暴风网际科技有限公司, 3, 9, 5, 22]
    [C:\WINDOWS\SYSTEM\msxml3.dll]  [Microsoft Corporation, 8.20.8730.1]
    [d:\Program Files\StormII\bfoptdll.dll]  [北京暴风网际科技有限公司, 3, 8, 7, 16]
    [d:\Program Files\StormII\box\BoxLog.dll]  [北京暴风网际科技有限公司, 3, 9, 6, 27]
[PID: 2144 / SYSTEM][C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe]  [ESET, 3.0.684 ]
    [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnScan.dll]  [ESET, 3.0.684 ]
    [C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnAmon.dll]  [ESET, 3.0.684 ]
    [C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnEmon.dll]  [ESET, 3.0.684 ]
    [C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnEpfw.dll]  [ESET, 3.0.684 ]
    [C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnUpdate.dll]  [ESET, 3.0.684 ]
    [C:\Program Files\ESET\ESET NOD32 Antivirus\updater.dll]  [ESET, 3.0.684 ]
    [C:\Program Files\ESET\ESET NOD32 Antivirus\ekrnMailPlugins.dll]  [ESET, 3.0.684 ]
[PID: 2164 / SYSTEM][C:\Program Files\Intel\WiFi\bin\EvtEng.exe]  [Intel(R) Corporation, 12, 1, 1, 0]
    [C:\Program Files\Intel\WiFi\bin\PfMgrApi.dll]  [Intel(R) Corporation, 12, 1, 1, 2]
    [C:\Program Files\Intel\WiFi\bin\MurocApi.dll]  [Intel(R) Corporation, 12, 1, 1, 5]
    [C:\Program Files\Intel\WiFi\bin\IntStngs.dll]  [Intel(R) Corporation, 12, 1, 1, 0]
    [C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll]  [The OpenSSL Project, http://www.openssl.org/, 0.9.8]
    [C:\Program Files\Common Files\Intel\WirelessCommon\PsRegApi.dll]  [Intel(R) Corporation, 12, 1, 1, 0]
    [C:\Program Files\Common Files\Intel\WirelessCommon\TraceApi.dll]  [Intel(R) Corporation, 12, 1, 1, 2]
    [C:\Program Files\Intel\WiFi\bin\S24MUDLL.dll]  [Intel(R) Corporation, 12, 1, 1, 1]
[PID: 2240 / SYSTEM][C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe]  [Intel(R) Corporation, 12, 1, 1, 0]
[PID: 2656 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 2916 / SYSTEM][C:\WINDOWS\System32\TPHDEXLG.exe]  [Lenovo., 1.60.0.6]
[PID: 2968 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
[PID: 3012 / SYSTEM][C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE]  [, 1, 0, 0, 1]
    [C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRIF.DLL]  [N/A, ]
    [C:\WINDOWS\system32\Sensor.dll]  [Lenovo., 1.60.0.6]
[PID: 3408 / SYSTEM][D:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe]  [Broadcom Corporation., 5.5.0.4300]
[PID: 3880 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[PID: 1096 / SYSTEM][C:\WINDOWS\system32\wbem\wmiprvse.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_qfe.090206-1316)]
[PID: 2548 / user][C:\WINDOWS\system32\conime.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1021]
[PID: 3996 / user][G:\sreng2\SREngLdr.EXE]  [Smallfrogs Studio, 2.7.1.1261]
[PID: 3812 / user][G:\sreng2\SRE73340a5.EXE]  [Smallfrogs Studio, 2.7.1.1261]
    [C:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 5, 0, 0, 1021]
    [G:\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
    [C:\WINDOWS\system32\aetsprov.dll]  [A.E.T. Europe B.V., 2.3.0.9]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost
218.75.159.150  www.kzdh.com
218.75.159.150  www.6781.com
218.75.159.150  www.v2233.com
218.75.159.150  www.iq123.com
218.75.159.150  www.i2345.cn
218.75.159.150  www.haokan123.com
218.75.159.150  www.365wz.net
218.75.159.150  www.5d5e.com
218.75.159.150  www.112r.com
218.75.159.150  www.32e.com
218.75.159.150  www.77177.com
218.75.159.150  www.daluobo.cn
218.75.159.150  www.haha111.com
218.75.159.150  www.haoz123.cn
218.75.159.150  www.85vv.com
218.75.159.150  www.ok100.net.cn
218.75.159.150  www.ai1234.com
218.75.159.150  www.15wz.com
218.75.159.150  www.fm5566.com
218.75.159.150  www.9798.net
218.75.159.150  www.s565.com
218.75.159.150  www.345s.com
218.75.159.150  www.110wz.com
218.75.159.150  www.6dh.com
218.75.159.150  www.tt98.com
218.75.159.150  www.85851.com
218.75.159.150  www.66d8.cn
218.75.159.150  www.baihu.cn
218.75.159.150  www.hang123.com
218.75.159.150  www.17909.com
218.75.159.150     www.838.cc
218.75.159.150  www.ee258.com
218.75.159.150  www.gjj.cc

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1696, C:\PROGRAM FILES\INTEL\WIFI\BIN\S24EVMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2164, C:\PROGRAM FILES\INTEL\WIFI\BIN\EVTENG.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3996, G:\SRENG2\SRENGLDR.EXE]

==================================
计划任务
[已启用] SogouImeMgr.job
        C:\PROGRA~1\SOGOUI~1\360~1.165\PinyinRepair.exe
[已禁用] PMTask.job
        C:\PROGRA~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT