我的maxthon老是弹出很多窗口, 隔一段时间就弹一次, 请高手诊断, 谢谢
启动项报告: 2006-9-13, 0:49:40
启动项扫描器版本: 1.52.2
开始于: C:\Program Files\HijackThis1991汉化版\HijackThis1991zww.EXE
系统检测: Windows XP SP2 (WinNT 5.01.2600)
系统检测: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* 使用默认选项
* 选择“列出主要的部分(标准)”方式
==================================================
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\CyberArmor\pcshelp.exe
C:\Program Files\Nortel Networks Virus Definition Updater\NVDUSch.exe
C:\Program Files\Nortel Networks\Remote Access Manager\RAMDatabaseUpdater.exe
C:\Program Files\Visual Networks\Visual IP InSight\Nortel\IPMon32.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\jj4\jjsvr4.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe
C:\Program Files\Nortel Networks\TunnelGuard\platforms\win32\TGIconApp.EXE
C:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\10.00\Inetd\inetd32.exe
C:\WINDOWS\system32\i2050QosSvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
C:\Program Files\Nortel Networks\Remote Access Manager\NNDService.exe
C:\Program Files\Nortel Networks\Remote Access Manager\RAMSettings.exe
C:\PROGRA~1\Support.com\bin\TgSrvc.Exe
c:\windows\system32\inetsrv\csrss.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Nortel Networks\TunnelGuard\CueAgent_srv.exe
C:\Program Files\WPMS\wpmsmon.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\CyberArmor\casvc.exe
C:\PROGRA~1\CYBERA~1\pcs.exe
C:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe
C:\Program Files\Visual Networks\Visual IP InSight\Nortel\IPClient.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Nortel Networks Virus Definition Updater\NortVDU.exe
C:\Program Files\Windows 流氓软件清理大师\clean.exe
C:\Program Files\Globallink\Game\share\glWorld.exe
C:\Program Files\Globallink\Game\share\OurFriend\ourfriend.exe
C:\Program Files\Maxthon\Max.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe
C:\Program Files\IDM Computer Solutions\UltraEdit-32\uedit32.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\CYBERA~1\pcshelp.exe
C:\Program Files\HijackThis1991汉化版\HijackThis1991zww.exe
--------------------------------------------------
文件夹中的启动项
Shell folders Startup:
[D:\Profiles\zgchen\Start Menu\Programs\Startup]
desktop.ini
Shell folders Common Startup:
[D:\Profiles\All Users\Start Menu\Programs\Startup]
Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader\reader_sl.exe
desktop.ini
Monitor Apache Servers.lnk = C:\Program Files\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe
TunnelGuard Tray Monitor.lnk = ?SystemRoot%\Installer\{5650A422-0789-473F-B2C7-6C3D10CC9FFB}\Icon079d381e2.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
注册表中的启动项:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
MSPY2002 = ; C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
PHIME2002ASync = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
vptray = C:\PROGRA~1\SYMANT~1\VPTray.exe
CyberArmorHelper = C:\Program Files\CyberArmor\pcshelp.exe -check
HumMeteringClient = rundll32.exe "C:\Program Files\Hummingbird\Connectivity\10.00\Accessories\MeteringClient.dll",RegisterProduct
NVDUSch = "C:\Program Files\Nortel Networks Virus Definition Updater\NVDUSch.exe"
TkBellExe = ; C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
RAMConnectionChecker = "C:\Program Files\Nortel Networks\Remote Access Manager\RAMConnChecker.exe" -m
RAMDatabaseUpdater = "C:\Program Files\Nortel Networks\Remote Access Manager\RAMDatabaseUpdater.exe" -u
RAMGINAConnWatch = "C:\Program Files\Nortel Networks\Remote Access Manager\RAMConnWatcher.exe"
IPInSightMonitor 01 = "C:\Program Files\Visual Networks\Visual IP InSight\Nortel\IPMon32.exe"
ATIModeChange = Ati2mdxx.exe
Apoint = C:\Program Files\Apoint\Apoint.exe
StormCodec_Helper = ; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
Thunder = "C:\Program Files\Thunder Network\Thunder\Thunder.exe" /s
NeroFilterCheck = ; C:\WINDOWS\system32\NeroCheck.exe
tgcmd = "C:\Program Files\Support.com\bin\tgcmd.exe" /server
ThunderMini = ; C:\Program Files\Thunder Network\ThunderMini\ThunderMiniShell.exe
Logitech Utility = Logi_MwX.Exe
--------------------------------------------------
注册表中的启动项:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
ANetFox ADClean = "C:\Program Files\Windows 流氓软件清理大师\clean.exe" /autokill:86
--------------------------------------------------
注册表中的启动项:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
pyjj = C:\Program Files\jj4\jjsvr4.exe
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
--------------------------------------------------
文件打开方式关联 for .TXT:
HKEY_CLASSES_ROOT\UltraEdit.txt\shell\open\command
(黙认) = notepad.exe %1
--------------------------------------------------
Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)
[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP
[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll
[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe
[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
--------------------------------------------------
Load/Run keys from C:\WINDOWS\WIN.INI:
load=* 未找到INI相关项目值 *
run=* 未找到INI相关项目值 *
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=* 未找到相关注册表键值 *
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=* 未找到相关注册表键值 *
HKLM\..\Windows\CurrentVersion\WinLogon: load=* 未找到相关注册表键值 *
HKLM\..\Windows\CurrentVersion\WinLogon: run=* 未找到相关注册表键值 *
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=* 未找到相关注册表键值 *
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=* 未找到相关注册表键值 *
HKCU\..\Windows\CurrentVersion\WinLogon: load=* 未找到相关注册表键值 *
HKCU\..\Windows\CurrentVersion\WinLogon: run=* 未找到相关注册表键值 *
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=
HKLM\..\Windows NT\CurrentVersion\Windows: load=
HKLM\..\Windows NT\CurrentVersion\Windows: run=
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=
--------------------------------------------------
外壳扩展和屏幕保护程序的键值 从 C:\WINDOWS\SYSTEM.INI:
Shell=* 未找到INI相关项目值 *
SCRNSAVE.EXE=* 未找到INI相关项目值 *
drivers=* 未找到INI相关项目值 *
外壳扩展和屏幕保护程序的键值 从 注册表
Shell=Explorer.exe
SCRNSAVE.EXE=* 未找到相关注册表键值 *
drivers=* 未找到相关注册表键值 *
Policies Shell key:
HKCU\..\Policies: Shell=* 未找到相关注册表键值 *
HKLM\..\Policies: Shell=* 未找到相关注册表键值 *
--------------------------------------------------
Checking for EXPLORER.EXE instances:
C:\WINDOWS\Explorer.exe: PRESENT!
C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present
--------------------------------------------------
Checking for superhidden extensions:
.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.
vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.
js: not hidden
.jse: not hidden
--------------------------------------------------
列举下载的程序文件:
[{87CCFDB0-C4BE-4BC2-A78C-9EAA7CF96667}]
CODEBASE = http://ps.itv.mop.com/dn/files/vodupdate_1.0.0.9_20060425.cab
[Shockwave Flash
Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab