瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】如何清除自动弹出“http://t.sjzl88.com/ad2.htm”

12   1  /  2  页   跳转

【求助】如何清除自动弹出“http://t.sjzl88.com/ad2.htm”

【求助】如何清除自动弹出“http://t.sjzl88.com/ad2.htm”

【求助】我的用的是WinXP,在打开“我的电脑”时自动打开“http://t.sjzl88.com/ad2.htm”会网页,请瑞星工程师们或那位网络高手帮忙解决。谢谢!
最后编辑2007-01-11 10:37:50
分享到:
gototop
 

请下载SREng2(最新版) ,使用“智能扫描”,按下“扫描”按钮进行扫描,
扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告
日志文件内容复制-粘贴上来,,日志一次粘不完,分次粘完,请不要修改。

下载地址
http://www.kztechs.com/sreng/sreng2.zip
gototop
 

2006-12-06,21:17:54

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>  [Microsoft Corporation]
    <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Corporation]
    <Creative Detector><C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R>  [Creative Technology Ltd]
    <Creative MediaSource Go><"C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe" /SCB>  [Creative Technology Ltd]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup>  [(Verified)NVIDIA Corporation]
    <nwiz><nwiz.exe /install>  [N/A]
    <NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit>  [(Verified)NVIDIA Corporation]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <CameraFixer><C:\WINDOWS\CameraFixer.exe>  []
    <snpstd3><C:\WINDOWS\vsnpstd3.exe>  []
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <CTHelper><CTHELPER.EXE>  [Creative Technology Ltd]
    <CTDVDDET><"C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE">  [Creative Technology Ltd]
    <CTSysVol><C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe /r>  [Creative Technology Ltd]
    <RCSystem><"C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup>  [N/A]
    <AudioDrvEmulator><"C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll">  [N/A]
    <UpdReg><C:\WINDOWS\UpdReg.EXE>  [Creative Technology Ltd.]
    <NeroFilterCheck><C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe>  [Nero AG]
    <kis><"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe">  [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll>  [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
    <WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll>  [Kaspersky Lab]

==================================
启动文件夹
N/A

==================================
服务
[ASP.NET State Service / aspnet_state]
  <C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[卡巴斯基互联网安全套装 6.0 / AVP]
  <"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r><Kaspersky Lab>
[Bluetooth Service / btwdins]
  <C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe><WIDCOMM, Inc.>
[Creative Service for CDROM Access / Creative Service for CDROM Access]
  <C:\WINDOWS\system32\CTsvcCDA.EXE><Creative Technology Ltd>
[GhostStartService / GhostStartService]
  <C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe><Symantec Corporation>
[Human Interface Device Access / HidServ]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NBService / NBService]
  <C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe><Nero AG>
[NVIDIA Display Driver Service / NVSvc]
  <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd]
  <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><NetGroup - Politecnico di Torino>
[Windows Media Connect Service / WMConnectCDS]
  <C:\Program Files\Windows Media Connect 2\wmccds.exe><Microsoft Corporation>
gototop
 

==================================
驱动程序
[SAA7130 TV Card / 713xTVCard]
  <system32\DRIVERS\SAA713x.sys><Philips Semiconductors>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM]
  <system32\drivers\ALCXWDM.SYS><N/A>
[Aspi32 / Aspi32]
  <C:\WINDOWS\SYSTEM32\DRIVERS\Aspi32.SYS><Adaptec>
[Bluetooth Audio / BtAudio]
  <system32\DRIVERS\btaudio.sys><WIDCOMM, Inc.>
[Bluetooth Virtual Communications Driver / BTDriver]
  <system32\DRIVERS\btport.sys><WIDCOMM, Inc.>
[Bluetooth Protocol Stack / BTKRNL]
  <\SystemRoot\system32\drivers\btkrnl.sys><WIDCOMM, Inc.>
[Bluetooth Serial Driver / BTSERIAL]
  <\??\C:\WINDOWS\system32\drivers\btserial.sys><N/A>
[Bluetooth Port Client Driver / BTSLBCSP]
  <\??\C:\WINDOWS\system32\drivers\btslbcsp.sys><WIDCOMM, Inc.>
[Bluetooth LAN Access Server / BTWDNDIS]
  <system32\DRIVERS\btwdndis.sys><WIDCOMM, Inc.>
[WIDCOMM USB Bluetooth Driver / BTWUSB]
  <System32\Drivers\btwusb.sys><WIDCOMM, Inc.>
[TV Card(Philips) Capture / Cap7134]
  <system32\DRIVERS\Cap7134.sys><Philips Semiconductors>
[Creative AC3 Software Decoder / ctac32k]
  <system32\drivers\ctac32k.sys><Creative Technology Ltd>
[Creative Audio Driver (WDM) / ctaud2k]
  <system32\drivers\ctaud2k.sys><Creative Technology Ltd>
[Creative DVD-Audio Device Driver / ctdvda2k]
  <system32\drivers\ctdvda2k.sys><Creative Technology Ltd>
[Creative Proxy Driver / ctprxy2k]
  <system32\drivers\ctprxy2k.sys><Creative Technology Ltd>
[Creative SoundFont Management Device Driver / ctsfm2k]
  <system32\drivers\ctsfm2k.sys><Creative Technology Ltd>
[Intel(R) PRO/1000 Network Connection Driver / E1000]
  <System32\DRIVERS\e1000325.sys><Intel Corporation>
[3Com EtherLink XL 90XB/C Adapter Driver / EL90XBC]
  <system32\DRIVERS\el90xbc5.sys><3Com Corporation>
[E-mu Plug-in Architecture Driver / emupia]
  <system32\drivers\emupia2k.sys><Creative Technology Ltd>
[GhostPciScanner / GhPciScan]
  <\??\C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys><Symantec Corporation>
[Creative Hardware Abstract Layer Driver / ha10kx2k]
  <system32\drivers\ha10kx2k.sys><Creative Technology Ltd>
[Creative P16V HAL Driver / hap16v2k]
  <system32\drivers\hap16v2k.sys><Creative Technology Ltd>
[Creative P17V HAL Driver / hap17v2k]
  <system32\drivers\hap17v2k.sys><Creative Technology Ltd>
[IVI ASPI Shell / Iviaspi]
  <system32\drivers\iviaspi.sys><InterVideo, Inc.>
[kl1 / kl1]
  <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif]
  <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[ATK0110 ACPI UTILITY / MTsensor]
  <System32\DRIVERS\ASACPI.sys><>
[NetGroup Packet Filter Driver / NPF]
  <system32\drivers\npf.sys><NetGroup - Politecnico di Torino>
[npkcrypt / npkcrypt]
  <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv]
  <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[nvata / nvata]
  <\SystemRoot\System32\DRIVERS\nvata.sys><NVIDIA Corporation>
[Creative OS Services Driver / ossrv]
  <system32\drivers\ctoss2k.sys><Creative Technology Ltd.>
[PfModNT / PfModNT]
  <\??\C:\WINDOWS\system32\drivers\PfModNT.sys><Creative Technology Ltd.>
[TV Card(Philips) WDM TVTuner / PhTVTune]
  <system32\DRIVERS\PhTVTune.sys><Philips Semiconductors>
[Direct Parallel Link Driver / Ptilink]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
  <System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv]
  <System32\DRIVERS\secdrv.sys><N/A>
[SNIFFER Protocol Driver / Sniffer]
  <system32\DRIVERS\sniffer.sys><N/A>
[USB PC Camera (SNPSTD3) / SNPSTD3]
  <system32\DRIVERS\snpstd3.sys><N/A>
[Motorola USB Modem Driver for MPT / usbsermpt]
  <system32\DRIVERS\usbsermpt.sys><Microsoft Corporation>

==================================
浏览器加载项
[BHO.clsInetSpeak]
  {0CD5C894-57C5-44BB-9D73-84AE18E2D938} <C:\WINDOWS\system32\msidb.dll, Microsoft Corporation>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_004.dll, Thunder Networking Technologies,LTD>
[启动迅雷5]
  {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[Web反病毒保护]
  {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll, Kaspersky Lab>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\PROGRA~1\Tencent\QQ\QQ.EXE, TENCENT>
[Creative Software AutoUpdate]
  {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} <C:\WINDOWS\DOWNLO~1\CTSUEng.ocx, Creative Technology Ltd>
[Windows Genuine Advantage Validation Tool]
  {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, Microsoft? Corporation>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[Creative Software AutoUpdate Support Package]
  {F6ACF75C-C32C-447B-9BEF-46B766368D29} <C:\WINDOWS\DOWNLO~1\CTPID.ocx, Creative Technology Ltd>
[QuickTime Object]
  {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} <C:\Program Files\QuickTime\QTPlugin.ocx, Apple Computer, Inc.>
[Web Browser Applet Control]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\WINDOWS\system32\msjava.dll, Microsoft Corporation>
[BHO.clsInetSpeak]
  {0CD5C894-57C5-44BB-9D73-84AE18E2D938} <C:\WINDOWS\system32\msidb.dll, Microsoft Corporation>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[Recorder Control]
  {2423AB16-9F42-457B-A337-FE3B11964DB0} <C:\PROGRA~1\bluesky\BLUESK~1\recorder.ocx, Bluesky Studio (http://www.bluesky.cn)>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\System32\mshtml.dll, N/A>
[BlueskyVideo Control]
  {2EA6D939-4445-43F1-A12B-8CB3DDA8B855} <C:\PROGRA~1\bluesky\BLUESK~1\v2.ocx, 蓝天工作室(http://www.bluesky.cn)>
[Share Control]
  {3072B1F1-0C4D-4E76-A7C6-FBAF129DBCC9} <C:\PROGRA~1\bluesky\BLUESK~1\share.ocx, http://www.bluesky.cn>
[IconX Class]
  {37C5D6EF-B34A-45E3-8529-B0443B8BAD3C} <C:\WINDOWS\system32\BTXPPA~1.DLL, WIDCOMM, Inc.>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[PP Control]
  {7005341F-8E42-47E3-987B-3DBE6288048C} <C:\PROGRA~1\bluesky\BLUESK~1\pp.ocx, Bluesky Studio (http://www.bluesky.cn)>
[Videohelp Control]
  {75B75D86-D88B-4BEA-BC59-BFD9D7300518} <C:\PROGRA~1\bluesky\BLUESK~1\VIDEOH~1.OCX, Bluesky Studio(http://www.bluesky.cn)>
[MediaComm Class]
  {7670648D-461B-42AF-BDFE-46D26AF5EFF2} <C:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin09.dll, Thunder Networking Technologies,LTD>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\System32\shdocvw.dll, Microsoft Corporation>
[Filetran Control]
  {88734439-46D0-42C0-A13F-7E881EE550CF} <C:\PROGRA~1\bluesky\BLUESK~1\filetran.ocx, Bluesky Studio(http://www.bluesky.cn)>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_004.dll, Thunder Networking Technologies,LTD>
[Chat Control]
  {94EFE58C-E678-4808-AD65-24CE4B94C1FE} <C:\PROGRA~1\bluesky\BLUESK~1\chat.ocx, Bluesky Studio(http://www.bluesky.cn)>
[Blueskyvoice Control]
  {991481A7-4669-4e15-8C24-100404E1F5CB} <C:\PROGRA~1\bluesky\BLUESK~1\BLUESK~1.OCX, 蓝天工作室(http://www.bluesky.cn)>
[Display Control]
  {A1D97DB3-E564-4743-B2E7-6F5182CBF406} <C:\PROGRA~1\bluesky\BLUESK~1\display.ocx, Bluesky Studio (http://www.bluesky.cn)>
[Tracechat Control]
  {A40335C4-D3D1-4E7B-9130-039CDA5B603C} <C:\PROGRA~1\bluesky\BLUESK~1\TRACEC~1.OCX, bluesky studio>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\System32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\System32\shdocvw.dll, N/A>
[Blueskyvoice Control]
  {BA0F088C-72C1-475a-92F8-42391DEF6961} <C:\PROGRA~1\bluesky\BLUESK~1\BLUESK~2.OCX, 蓝天工作室(http://www.bluesky.cn)>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Client Control]
  {C7B0C764-5D4E-433E-A854-591F28520577} <C:\PROGRA~1\bluesky\BLUESK~1\client.ocx, >
[Play Control]
  {CC20DDA1-9A21-4DEC-B5BE-E61E0351FCA9} <C:\PROGRA~1\bluesky\BLUESK~1\play.ocx, Bluesky Studio (http://www.bluesky.cn)>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[&使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
gototop
 

==================================
正在运行的进程
[PID: 408][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 460][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 484][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 528][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 540][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 708][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 756][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 824][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 916][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1032][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1160][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
    [C:\WINDOWS\system32\bthcrp.dll]  [WIDCOMM, Inc., 1.4.2 Build 10]
    [C:\WINDOWS\system32\WidcommSdk.dll]  [WIDCOMM, Inc., 1.4.2 Build 10]
    [C:\WINDOWS\system32\wbtapi.dll]  [WIDCOMM, Inc., 1.4.2 Build 10]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll]  [Windows (R) 2000 DDK provider, 5.00.2195.1620]
[PID: 1292][C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe]  [WIDCOMM, Inc., 1.4.2 Build 10]
[PID: 1304][C:\WINDOWS\system32\CTsvcCDA.EXE]  [Creative Technology Ltd, 1.0.1.0]
[PID: 1344][C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe]  [Symantec Corporation, 2003.775]
[PID: 1368][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  [Microsoft Corporation, 7.00.9466]
[PID: 1420][C:\WINDOWS\System32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.7801]
[PID: 1680][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\ctagent.dll]  [Creative Technology Ltd, 1, 0, 0, 11]
    [C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll]  [Nero AG, 2, 0, 0, 8]
    [C:\WINDOWS\System32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.7801]
    [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.7801]
    [C:\WINDOWS\System32\nvshell.dll]  [N/A, N/A]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_004.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 3]
    [C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll]  [Nero AG, 2, 2, 10, 0]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\shellex.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\btncopy.dll]  [WIDCOMM, Inc., 1.4.2 Build 10]
[PID: 1736][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1768][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 300][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1100][C:\WINDOWS\system32\RUNDLL32.EXE]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\NvMcTray.dll]  [NVIDIA Corporation, 6.14.10.7801]
    [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.7801]
[PID: 1452][C:\WINDOWS\CameraFixer.exe]  [, 1, 0, 0, 2]
[PID: 1456][C:\WINDOWS\vsnpstd3.exe]  [, 1, 0, 2, 2]
[PID: 1496][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3208]
[PID: 1572][C:\WINDOWS\CTHELPER.EXE]  [Creative Technology Ltd, 2, 0, 0, 29]
    [C:\WINDOWS\SYSTEM32\CTDCIFCE.DLL]  [Creative Technology Ltd, 5.12.01.1161-2.08.0070]
    [C:\WINDOWS\system32\ctagent.dll]  [Creative Technology Ltd, 1, 0, 0, 11]
    [C:\WINDOWS\system32\ctspkhlp.dll]  [Creative Technology Ltd, 1, 0, 3, 6]
    [C:\WINDOWS\SYSTEM32\CTDC0001.DLL]  [Creative Technology Ltd, 5.12.01.1161-2.08.0070]
    [C:\WINDOWS\SYSTEM32\ctosuser.dll]  [Creative Technology Ltd, 5.12.01.1161-2.08.0070]
    [C:\WINDOWS\SYSTEM32\CTDPROXY.DLL]  [Creative Technology Ltd, 5.12.01.1161-2.08.0070]
    [C:\WINDOWS\SYSTEM32\PIAPROXY.DLL]  [Creative Technology Ltd, 5.12.01.1161-2.08.0070]
    [C:\WINDOWS\CTDCRCHS.DLL]  [Creative Technology Ltd, 5.12.01.1140-2.07.0070]
    [C:\WINDOWS\CTDCRES.DLL]  [Creative Technology Ltd, 5.12.01.1140-2.07.0070]
    [C:\WINDOWS\system32\ctpcmcia.dll]  [Creative Technology Ltd, 2, 0, 1, 4]
[PID: 1644][C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE]  [Creative Technology Ltd, 1.0.3.0]
    [C:\Program Files\Creative\Shared Files\CTAudNav.dll]  [Creative Technology Ltd, 3.0.8.0]
gototop
 

[PID: 1672][C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe]  [Creative Technology Ltd, 1.4.2.0]
    [C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.crl]  [Creative Technology Ltd, 1.4.1.0]
    [C:\Program Files\Creative\Shared Files\CTTheme.dll]  [Creative Technology Ltd, 3.1.3.0]
    [C:\Program Files\Creative\Shared Files\CtrlSrc.dll]  [Creative Technology Ltd, 2.0.12.0]
    [C:\Program Files\Creative\Shared Files\CTIniF.dll]  [Creative Technology Ltd, 1.1.0.0]
    [C:\Program Files\Creative\Shared Files\GDICtrl.skc]  [Creative Technology Ltd, 3.1.18.0]
    [C:\Program Files\Creative\Shared Files\GDICtrl2.skc]  [Creative Technology Ltd, 3.0.14.0]
    [C:\Program Files\Creative\Shared Files\GDICtrl3.skc]  [Creative Technology Ltd, 3.1.4.0]
    [C:\Program Files\Creative\Shared Files\RtxCtrl.skc]  [Creative Technology Ltd, 3.1.3.0]
    [C:\Program Files\Creative\Shared Files\mxlib.dll]  [Creative Technology Ltd., 1.00.0.13]
    [C:\WINDOWS\system32\ctagent.dll]  [Creative Technology Ltd, 1, 0, 0, 11]
[PID: 1544][C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe]  [Creative Technology Ltd., 1.0.21.0]
    [C:\Program Files\Creative\SBAudigy4\Entertainment Center\RCSystem.dll]  [Creative Technology Ltd., 1.0.16.0]
    [C:\Program Files\Creative\SBAudigy4\Entertainment Center\RCSystem.CRL]  [Creative Technology Ltd., 1.0.1.0]
    [C:\Program Files\Creative\ShareDLL\CADI\ctcadi.dll]  [Creative Technology Ltd, 1.0.2.24]
    [C:\Program Files\Creative\ShareDLL\CADI\ctdmzspi.dll]  [Creative Technology Ltd, 0.0.2.4]
    [C:\Program Files\Creative\SBAudigy4\Entertainment Center\RCRx\RcHidUsb.dll]  [Creative Technology Ltd, 1.0.8.0]
    [C:\Program Files\Creative\SBAudigy4\Entertainment Center\RCRx\RCIDM.dll]  [Creative Technology Ltd., 2.0.2.0]
    [C:\Program Files\Creative\SBAudigy4\Entertainment Center\RCRx\RCKSIRWp.dll]  [Creative Technology Ltd, 1.0.7.0]
    [C:\Program Files\Creative\SBAudigy4\Entertainment Center\RCRx\RCSBUSB.DLL]  [Creative Technology Ltd, 1.1.0.5]
    [C:\Program Files\Creative\SBAudigy4\Entertainment Center\RCRx\rcks1k.dll]  [Creative Technology Ltd., 1.40.23]
    [C:\WINDOWS\SYSTEM32\CTDPROXY.DLL]  [Creative Technology Ltd, 5.12.01.1161-2.08.0070]
[PID: 1760][C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe]  [Creative Technology Ltd., 1.0.21.0]
    [C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll]  [Creative Technology Ltd., 1.2.11.0]
    [C:\Program Files\Creative\SBAudigy4\Entertainment Center\CTAudSel.dll]  [Creative Technology Ltd, 1.0.2.0]
    [C:\Program Files\Creative\Shared Files\Module Loader\OSD\PanelSvc.dll]  [Creative Technology Ltd., 1.0.26.0]
    [C:\WINDOWS\SYSTEM32\CTDCIFCE.DLL]  [Creative Technology Ltd, 5.12.01.1161-2.08.0070]
    [C:\WINDOWS\SYSTEM32\CTDC0001.DLL]  [Creative Technology Ltd, 5.12.01.1161-2.08.0070]
    [C:\WINDOWS\SYSTEM32\ctosuser.dll]  [Creative Technology Ltd, 5.12.01.1161-2.08.0070]
    [C:\WINDOWS\SYSTEM32\CTDPROXY.DLL]  [Creative Technology Ltd, 5.12.01.1161-2.08.0070]
    [C:\WINDOWS\SYSTEM32\PIAPROXY.DLL]  [Creative Technology Ltd, 5.12.01.1161-2.08.0070]
    [C:\WINDOWS\CTDCRCHS.DLL]  [Creative Technology Ltd, 5.12.01.1140-2.07.0070]
    [C:\WINDOWS\CTDCRES.DLL]  [Creative Technology Ltd, 5.12.01.1140-2.07.0070]
    [C:\Program Files\Creative\SBAudigy4\Entertainment Center\EAXMod.dll]  [Creative Technology Ltd., 1.0.9.0]
    [C:\Program Files\Creative\SBAudigy4\Entertainment Center\RemoteEA.CRL]  [Creative Technology Ltd, 3.0.7.0]
    [C:\Program Files\Creative\SBAudigy4\Entertainment Center\EAXCADI.DLL]  [Creative Technology Ltd., 1.0.12.0]
    [C:\Program Files\Creative\ShareDLL\CADI\ctcadi.dll]  [Creative Technology Ltd, 1.0.2.24]
    [C:\Program Files\Creative\ShareDLL\CADI\ctdmzspi.dll]  [Creative Technology Ltd, 0.0.2.4]
    [C:\Program Files\Creative\ShareDLL\CADI\dbacs.dll]  [Creative Technology Ltd, 1.00.10.01]
    [C:\Program Files\Creative\ShareDLL\CADI\ctaudspi.dll]  [Creative Technology Ltd, 0.0.0.14]
    [C:\WINDOWS\SYSTEM32\CTMMACTL.DLL]  [N/A, 1.0.1.23]
    [C:\Program Files\Creative\ShareDLL\CADI\ctpxspi.dll]  [Creative Technology Ltd, 0.0.0.10]
    [C:\Program Files\Creative\ShareDLL\CADI\ctmbspi.dll]  [Creative Technology Ltd, 0.0.0.11]
    [C:\Program Files\Creative\ShareDLL\CADI\ctksspi.dll]  [Creative Technology Ltd, 0.0.0.10]
    [C:\Program Files\Creative\ShareDLL\CADI\CTPreset.dll]  [Creative Technology Ltd., 1.0.0.19]
[PID: 1852][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2036][C:\Program Files\MSN Messenger\MsnMsgr.Exe]  [Microsoft Corporation, 7.5.0324]
    [C:\WINDOWS\system32\ctagent.dll]  [Creative Technology Ltd, 1, 0, 0, 11]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 176][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 372][C:\Program Files\Messenger\msmsgs.exe]  [Microsoft Corporation, 4.7.3001]
[PID: 284][C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe]  [Creative Technology Ltd, 3.0.2.0]
    [C:\Program Files\Creative\MediaSource\Detector\CTIntrfc.dll]  [Creative Technology Ltd, 2.1.0.0]
    [C:\Program Files\Creative\MediaSource\Detector\CTDetect.Crl]  [Creative Technology Ltd, 2.1.0.0]
    [C:\WINDOWS\system32\ctagent.dll]  [Creative Technology Ltd, 1, 0, 0, 11]
    [C:\Program Files\Creative\MediaSource\Detector\DtctrMgr.det]  [Creative Technology Ltd, 3.0.2.0]
    [C:\Program Files\Creative\MediaSource\Detector\Hdd.det]  [Creative Technology Ltd, 1.0.6.0]
    [C:\Program Files\Creative\Shared Files\ThmRes.DLL]  [Creative Technology Ltd, 2.0.12.0]
    [C:\Program Files\Creative\Shared Files\CTIniF.dll]  [Creative Technology Ltd, 1.1.0.0]
    [C:\Program Files\Creative\MediaSource\Detector\Disc.det]  [Creative Technology Ltd, 2.4.2.0]
[PID: 396][C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe]  [Creative Technology Ltd, 3.0.1.0]
    [C:\Program Files\Creative\MediaSource\Go\CTCMSGo.crl]  [Creative Technology Ltd, 2.1.0.0]
    [C:\WINDOWS\system32\ctagent.dll]  [Creative Technology Ltd, 1, 0, 0, 11]
    [C:\Program Files\Creative\Shared Files\CTTheme.dll]  [Creative Technology Ltd, 3.1.3.0]
    [C:\Program Files\Creative\Shared Files\CtrlSrc.dll]  [Creative Technology Ltd, 2.0.12.0]
    [C:\Program Files\Creative\Shared Files\CTIniF.dll]  [Creative Technology Ltd, 1.1.0.0]
    [C:\Program Files\Creative\Shared Files\GDICtrl.skc]  [Creative Technology Ltd, 3.1.18.0]
    [C:\Program Files\Creative\Shared Files\GDICtrl2.skc]  [Creative Technology Ltd, 3.0.14.0]
    [C:\Program Files\Creative\Shared Files\GDICtrl3.skc]  [Creative Technology Ltd, 3.1.4.0]
    [C:\Program Files\Creative\Shared Files\RtxCtrl.skc]  [Creative Technology Ltd, 3.1.3.0]
    [C:\Program Files\Creative\Shared Files\ThmRes.DLL]  [Creative Technology Ltd, 2.0.12.0]
[PID: 3132][C:\WINDOWS\system32\wuauclt.exe]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[PID: 2548][C:\WINDOWS\system32\wscntfy.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1972][C:\Program Files\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
    [C:\WINDOWS\system32\ctagent.dll]  [Creative Technology Ltd, 1, 0, 0, 11]
    [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]

==================================
文件关联
.TXT  Error. [notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. [hh.exe %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [notepad.exe %1]
.INF  Error. [notepad.exe %1]
.VBS  Error. [wscript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
N/A

==================================
gototop
 

运行(双击)SRENG2,点“启动项目,服务,点“Win32服务应用程序”
勾选“隐藏微软服务”选中病毒服务
Remote Packet Capture Protocol v.0
,选择“删除服务”
点“设置”选择“否”
重启按F8进入安全模式下
显示隐藏文件
删除:     
C:\Program Files\WinPcap\rpcapd.exe
"C:\Program Files\WinPcap\rpcapd.ini
C:\WINDOWS\system32\ctagent.dll
gototop
 

我按照你给出的方法已经搞掂。谢谢你“红夜鬼1”!
gototop
 

求助,偶的电话也遇到了同样的问题,会自动弹出“http://t.sjzl88.com/的网页。麻烦楼主帮偶解决一下,十分感谢!!!!!!

srengl.log如下
2007-01-11,09:39:02

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
gototop
 

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <CTFMON.EXE><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Corporation]
    <PcSync><; C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog>  [Time Information Services Ltd.]
    <STYLEXP><; C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide>  [N/A]
    <updateMgr><; C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_0_5 -reboot 1>  [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <iTunesHelper><; "C:\Program Files\iTunes\iTunesHelper.exe">  [(Verified)Apple Computer, Inc.]
    <Acrobat Assistant 7.0><; "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe">  [Adobe Systems Inc.]
    <AddrPlus3><; C:\PROGRA~1\TENCENT\AdPlus\Runner.exe C:\PROGRA~1\TENCENT\AdPlus\SSAddr.dll Rundll32>  [N/A]
    <Apoint><; C:\Program Files\Apoint\Apoint.exe>  [(Verified)Alps Electric Co., Ltd.]
    <ATIModeChange><; Ati2mdxx.exe>  [(Verified)ATI Technologies, Inc.]
    <ATIPTA><; C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>  [ATI Technologies, Inc.]
    <BigDogPath><; C:\WINDOWS\VM_STI.EXE Teclast WE PC Camera>  [N/A]
    <DataLayer><; C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE>  [Nokia Mobile Phones Ltd.]
    <ezShieldProtector for Px><; C:\WINDOWS\system32\ezSP_Px.exe>  [Easy Systems Japan Ltd.]
    <HKSERV.EXE><; C:\Program Files\Sony\HotKey Utility\HKserv.exe>  [Sony Corporation]
    <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <Mouse Suite 98 Daemon><; ICO.EXE>  [(Verified)Primax Electronics Ltd.]
    <MSPY2002><; C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC>  [(Verified)N/A]
    <PCSuiteTrayApplication><; C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup>  [Nokia]
    <PHIME2002A><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <QuickTime Task><; "C:\Program Files\QuickTime\qttask.exe" -atboottime>  [Apple Computer, Inc.]
    <res><; C:\WINDOWS\system32\res.exe>  [N/A]
    <snpstd3><; C:\WINDOWS\vsnpstd3.exe>  [N/A]
    <TkBellExe><; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <Update><; C:\Program Files\Common Files\UPDATE\Update.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><C:\Program Files\TGTSoft\StyleXP\Logon\CurrentLogon.EXE>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
    <{57B86673-276A-48B2-BAE7-C6DBB3020EB8}><C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll>  [Anti-Malware Development a.s.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    <WinlogonNotify: WgaLogon><WgaLogon.dll>  [Microsoft Corporation]

==================================
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT