瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 开机后goodsou.cn网页自动弹出无数,只能关机,高手请帮忙看看

1   1  /  1  页   跳转

开机后goodsou.cn网页自动弹出无数,只能关机,高手请帮忙看看

开机后goodsou.cn网页自动弹出无数,只能关机,高手请帮忙看看

最大的问题是: 开机3分钟左右,会不停的自动弹出www.goodsou.cn/chajian/URL.htm?3:13:31%20PM的IE网页(后面的数字会变,好像就是当时的系统时间),只能关机。

另外,开机1分钟左右,先会自动弹出http://%20back/的IE网页。以后大概每2-3分钟会自动弹出相同的网页,虽然没有其他影响,但也挺烦人的。

附上我的SReng 2.0 的扫描报告:
最后编辑2006-09-02 22:30:41
分享到:
gototop
 

SReng log [1]

2006-09-02,21:10:43

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- Administrative User - Completed Functions Allowed

Follow item(s) have been choosed:
    All Boot Items (Including Registry, Startup Folders, Services and so on)
    Browser Add-ons
    Runing Processes (Including process model information)
    File Associations


Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>  [Microsoft Corporation]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
    <run><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <BMMGAG><RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor>  [IBM Corp.]
    <TpShocks><TpShocks.exe>  [IBM Corp.]
    <SynTPLpr><C:\Program Files\Synaptics\SynTP\SynTPLpr.exe>  [Synaptics, Inc.]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <MSPY2002><C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC>  []
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime>  [Apple Computer, Inc.]
    <McAfeeUpdaterUI><"C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey>  [McAfee, Inc.]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <NeroFilterCheck><C:\WINDOWS\system32\NeroCheck.exe>  [Ahead Software Gmbh]
    <KAVRUN><C:\pz\Kingsoft\Duba6\KAVRUN.EXE>  [kingsoft]
    <SunJavaUpdateSched><C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe>  [Sun Microsystems, Inc.]
    <YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>  [Yahoo! China]
    <yassistse><"C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">  [Yahoo! China]
    <CnsMin><Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32>  [北京三七二一科技有限公司]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <CnsAssecblk><regsvr32.exe /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YASSEC~1.DLL>  [Yahoo! China]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
gototop
 

SReng log [2]

==================================
Startup Folders
[Acrobat Assistant]
  <C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk><N>
[Connected TaskBar Icon]
  <C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Connected TaskBar Icon.LNK><N>
[金山词霸 2003]
  <C:\Documents and Settings\zpeng\Start Menu\Programs\Startup\金山词霸 2003.lnk><N>

==================================
Services
[Connected Agent Service / AgentSrv]
  <C:\Program Files\Connected\AgentSrv.EXE -asv><Connected Corporation>
[Access Manager Configuration Service / AMBroker]
  <"C:\Program Files\AccessManager\Client\AMBroker.exe"><N/A>
[Ati HotKey Poller / Ati HotKey Poller]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[BlackICE / BlackICE]
  <"C:\Program Files\Network ICE\BlackICE\blackd.exe"><Internet Security Systems, Inc.>
[Cisco Systems, Inc. VPN Service / CVPND]
  <"C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe"><Cisco Systems, Inc.>
[Gray_Pigeon_Server2.03 / GrayPigeonServer2.03]
  <C:\WINDOWS\G_Server2.03.exe><N/A>
[IBM PM Service / IBMPMSVC]
  <C:\WINDOWS\system32\ibmpmsvc.exe><N/A>
[InstallDriver Table Manager / IDriverT]
  <"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[iPodService / iPodService]
  <C:\Program Files\iPod\bin\iPodService.exe><Apple Computer, Inc.>
[LightScribeService Direct Disc Labeling Service / LightScribeService]
  <"C:\Program Files\Common Files\LightScribe\LSSrvc.exe"><Hewlett-Packard Company>
[McAfee Framework Service / McAfeeFramework]
  <"C:\Program Files\Network Associates\Common Framework\FrameworkService.exe" /ServiceStart><McAfee, Inc.>
[Network Associates McShield / McShield]
  <"C:\Program Files\Network Associates\VirusScan\mcshield.exe"><Network Associates, Inc.>
[Network Associates Task Manager / McTaskManager]
  <"C:\Program Files\Network Associates\VirusScan\vstskmgr.exe"><Network Associates, Inc.>
[RapApp / RapApp]
  <"C:\Program Files\Network ICE\BlackICE\RapApp.exe"><Internet Security Systems, Inc.>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd]
  <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><N/A>
[Network Connection2355243 / Service2355243]
  <C:\WINDOWS\system32\netserly.exe><>
[SP Software Installer / SP Software Installer]
  <C:\Program Files\AccessManager\PMAC\sp_SWIns.exe><Smartpipes, Inc.>
[Visual Insight Dial Analysis / sp_spi_da]
  <C:\Program Files\AccessManager\SMOC\spi_da.exe><Smartpipes, Inc.>
[IBM HDD APS Logging Service / TPHDEXLGSVC]
  <System32\TPHDEXLG.EXE><IBM Corporation>
[Protector Suite Virtual Token / vtserver]
  <"C:\Program Files\Common Files\Virtual Token\vtserver.exe"><UPEK Inc.>
gototop
 

SReng log [3]

==================================
Browser Add-ons
[Yahoo!Photo]
  {33BBE430-0E42-4f12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll, Yahoo! China>
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll, yahoo! china>
[DragSearch BHO]
  {62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, yahoo! china>
[Adobe PDF]
  {47833539-D0C5-4125-9FA8-0819E2EAAC93} <C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll, N/A>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, N/A>
[雅虎助手]
  {406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll, yahoo! china>
[Edit Class]
  {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
[EWA Control]
  {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\COMMON~1\Synacast\SynaLive\SYNACA~1.OCX, Synacast>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[Google Script Object]
  {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, N/A>
[QuickTime Object]
  {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} <C:\Program Files\QuickTime\QTPlugin.ocx, Apple Computer, Inc.>
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll, N/A>
[CFForm Runtime]
  {072D3F2E-5FB6-11D3-B461-00C04FA35A21} <C:\WINDOWS\system32\MSJAVA.DLL, Microsoft Corporation>
[Web Browser Applet Control]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\WINDOWS\System32\msjava.dll, Microsoft Corporation>
[Edit Class]
  {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
[EWA Control]
  {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} <C:\PROGRA~1\COMMON~1\Synacast\SynaLive\SYNACA~1.OCX, Synacast>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
  {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, N/A>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[Yahoo!Photo]
  {33BBE430-0E42-4F12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll, Yahoo! China>
[IETag Factory]
  {38481807-CA0E-42D2-BF39-B33AF135CC4D} <C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\IETAG.DLL, Microsoft Corporation>
[AntiFish Class]
  {38928D50-8A48-44C2-945F-D2F23F771410} <C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll, yahoo! china>
[雅虎助手]
  {406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll, yahoo! china>
[Adobe PDF]
  {47833539-D0C5-4125-9FA8-0819E2EAAC93} <C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll, N/A>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\System32\shdocvw.dll, N/A>
[天下搜索]
  {56A7DC70-E102-4408-A34A-AE06FEF01586} <, N/A>
[Yahoo!Live]
  {57421194-58FB-49AE-9B4F-FD48869B9AD4} <C:\Program Files\Yahoo!\Assistant\yaLive.dll, yahoo! china>
[金山毒霸在线杀毒]
  {577A1997-6FD0-4972-B234-885DA583F9CE} <C:\PROGRA~1\KOS\KOSClean.ocx, N/A>
[PowerPlayer Control]
  {5EC7C511-CD0F-42E6-830C-1BD9882F3458} <C:\WINDOWS\DOWNLO~1\POWERP~1.DLL, PPStream Inc.>
[DragSearch BHO]
  {62EED7C6-9F02-42F9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, yahoo! china>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AxInputControl Class]
  {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINDOWS\system32\INPUTC~1.DLL, >
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll, Sun Microsystems, Inc.>
[Microsoft Web Browser]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\System32\shdocvw.dll, Microsoft Corporation>
[Schedule Class]
  {8B316DA1-9950-4926-B9EA-1AEC124AFA45} <C:\WINDOWS\system32\sscli.dll, >
[AxSubmitControl Class]
  {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} <C:\WINDOWS\system32\SUBMIT~1.DLL, >
[Oracle JInitiator 1.1.8.16]
  {9B935470-AD4A-11D5-B63E-00C04FAEDB18} <C:\Apps\Oracle\JInitiator11816\bin\beans.ocx, Oracle Corporation>
[RMGetLicense Class]
  {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation>
[Google Toolbar Helper]
  {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, N/A>
[HBObject Class]
  {AE22AFE5-1EF4-4D25-9E23-D2825FB17DA1} <, N/A>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[AcroIEToolbarHelper Class]
  {AE7CD045-E861-484F-8273-0445EE161910} <C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll, N/A>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\System32\shdocvw.dll, N/A>
[]
  {B69003B3-C55E-4B48-836C-BC5946FC3B28} <C:\Program Files\Messenger\msgsc.dll, Microsoft Corporation>
[3721]
  {B83FC273-3522-4CC6-92EC-75CC86678DA4} <C:\WINDOWS\downlo~1\CnsMin.dll, 北京三七二一科技有限公司>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\MSADC\msadco.dll, Microsoft Corporation>
[Adobe Acrobat Control for ActiveX]
  {CA8A9780-280D-11CF-A24D-444553540000} <C:\PROGRA~1\Adobe\ACROBA~1.0\Acrobat\ActiveX\pdf.ocx, Adobe Systems Incorporated>
[Java Plug-in]
  {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll, Sun Microsystems, Inc.>
[AUDIO__MP3 Moniker Class]
  {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[JmkHrhzm Class]
  {D2F905AA-E5F9-66F2-A94B-F2617C15B14F} <C:\WINDOWS\DOWNLO~1\ngcf.dll, rwuiusoft>
[My99Launch Control]
  {D57A1919-CB3C-461C-8F34-A87A1CD9127E} <C:\WINDOWS\system32\99Launch.ocx, >
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\CONFLICT.1\OL2005.dll, N/A>
[assist]
  {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} <C:\Program Files\Yahoo!\Assistant\Assist\yassist.dll, Yahoo! China>
gototop
 

SReng log [4]

==================================
Running Processes
[PID: 1008][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1056][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1080][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1124][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1136][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1284][C:\Program Files\Common Files\Virtual Token\vtserver.exe]  <UPEK Inc.><4.5.3.139>
    [C:\Program Files\Common Files\Virtual Token\psutil.dll]  <UPEK Inc.><4.5.3.139>
    [C:\Program Files\IBM fingerprint software\psfus.dll]  <UPEK Inc.><4.5.3.139>
    [C:\Program Files\Common Files\Virtual Token\passport.dll]  <UPEK Inc.><4.5.3.139>
    [C:\Program Files\Common Files\Virtual Token\DevTc.dll]  <UPEK Inc.><4.5.3.139>
    [C:\Program Files\Common Files\Virtual Token\BTcVer.dll]  <UPEK Inc.><4.5.3.139>
    [C:\Program Files\Common Files\Virtual Token\Remote.dll]  <UPEK Inc.><4.5.3.139>
[PID: 1300][C:\WINDOWS\system32\ibmpmsvc.exe]  <N/A><N/A>
[PID: 1328][C:\WINDOWS\system32\Ati2evxx.exe]  <ATI Technologies Inc.><6.14.10.4110>
    [C:\WINDOWS\system32\Ati2edxx.dll]  <ATI Technologies, Inc.><6, 14, 10, 2495>
[PID: 1340][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1424][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1460][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1536][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1672][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1968][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
    [C:\WINDOWS\system32\AdobePDF.dll]  <Adobe Systems Incorporated.><6.0.000>
    [C:\Program Files\Adobe\Acrobat 6.0\Distillr\adistres.dll]  <Adobe Systems Incorporated.><6.0.1.2003102300>
[PID: 408][C:\Program Files\Connected\AgentSrv.EXE]  <Connected Corporation><7.5.2.1477>
    [C:\Program Files\Connected\Launcher.dll]  <Connected Corporation><7.5.2.1477>
    [C:\Program Files\Connected\COB.DLL]  <Connected Corporation><7.5.2.1477>
[PID: 484][C:\Program Files\AccessManager\Client\AMBroker.exe]  <N/A><N/A>
[PID: 504][C:\Program Files\Network ICE\BlackICE\blackd.exe]  <Internet Security Systems, Inc.><7.0.69>
    [C:\Program Files\Network ICE\BlackICE\FileSec.dll]  <Internet Security Systems, Inc.><7.0.53>
    [C:\Program Files\Network ICE\BlackICE\AC_Base.dll]  <ISS><7, 0, 69, 10>
    [C:\WINDOWS\system32\blackdll.dll]  <Internet Security Systems, Inc.><7.0.29>
    [C:\Program Files\Network ICE\BlackICE\iss-pam1.dll]  <Internet Security Systems><1.10.104.97>
    [C:\Program Files\Network ICE\BlackICE\VpnICE.dll]  <Internet Security Systems, Inc.><7.0.69>
    [C:\Program Files\Network ICE\BlackICE\RapAd.dll]  <Internet Security Systems, Inc.><7.0.41.0>
[PID: 548][C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe]  <Cisco Systems, Inc.><3.6 (Rel)>
[PID: 728][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 740][C:\Program Files\Common Files\LightScribe\LSSrvc.exe]  <Hewlett-Packard Company><1.4.44.1>
[PID: 764][C:\Program Files\Network Associates\Common Framework\FrameworkService.exe]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\nailog.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\naXML71.dll]  <N/A><N/A>
    [C:\Program Files\Network Associates\Common Framework\naCmnLib71.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\applib.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\0409\AgentRes.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\Logging.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\InternetManager.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\naInet.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\UserSpace.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\SecureFrameworkFactory.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\Management.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\cmalib.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\naPolicyManager.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\ScriptSubSys.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\UpdateSubSys.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\Scheduler.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\Agent.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\naSPIPE.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\ListenServer.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\TCSubSys.dll]  <McAfee, Inc.><3.5.5.438>
[PID: 796][C:\Program Files\Network Associates\VirusScan\mcshield.exe]  <Network Associates, Inc.><7.0.0.237>
    [C:\Program Files\Network Associates\VirusScan\Res09\McShield.DLL]  <Network Associates, Inc.><7.0.0.237>
    [C:\Program Files\Network Associates\VirusScan\FTL.Dll]  <Network Associates, Inc.><7.0.0.187>
    [C:\Program Files\Network Associates\VirusScan\naiann.dll]  <Network Associates, Inc.><7.0.0.237>
    [C:\Program Files\Network Associates\VirusScan\NAEVENTU.DLL]  <Network Associates, Inc.><7.0.0.282>
    [C:\Program Files\Network Associates\VirusScan\Res09\naEvtRes.dll]  <Network Associates, Inc.><7.0.0.282>
    [C:\Program Files\Common Files\Network Associates\Engine\MCSCAN32.DLL]  <McAfee, Inc.><4.4.00>
[PID: 824][C:\Program Files\Network Associates\VirusScan\vstskmgr.exe]  <Network Associates, Inc.><7.0.0.511>
    [C:\Program Files\Network Associates\VirusScan\SHUTIL.dll]  <Network Associates, Inc.><7.0.0.511>
    [C:\Program Files\Network Associates\VirusScan\FTL.dll]  <Network Associates, Inc.><7.0.0.187>
    [C:\Program Files\Network Associates\VirusScan\Res09\VsTskMgr.dll]  <Network Associates, Inc.><7.0.0.511>
    [C:\Program Files\Network Associates\VirusScan\Res09\Product.dll]  <Network Associates, Inc.><7.0.0.511>
    [C:\Program Files\Network Associates\VirusScan\NAKRNLU.DLL]  <Network Associates, Inc.><7.0.0.282>
    [C:\Program Files\Network Associates\VirusScan\NAUTILU.DLL]  <Network Associates, Inc.><7.0.0.282>
    [C:\Program Files\Network Associates\VirusScan\Res09\naUtlRes.dll]  <Network Associates, Inc.><7.0.0.281>
    [C:\Program Files\Network Associates\VirusScan\NAEVENTU.DLL]  <Network Associates, Inc.><7.0.0.282>
    [C:\Program Files\Network Associates\VirusScan\Res09\naEvtRes.dll]  <Network Associates, Inc.><7.0.0.282>
    [C:\Program Files\Network Associates\VirusScan\Res09\Shutilrc.dll]  <Network Associates, Inc.><7.0.0.511>
    [C:\Program Files\Network Associates\VirusScan\MIDUtil.Dll]  <Network Associates, Inc.><7.0>
[PID: 832][C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\naXML71.dll]  <N/A><N/A>
    [C:\Program Files\Network Associates\Common Framework\nailog.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\naCmnLib71.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\applib.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\0409\AgentRes.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\AgentPlugin.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\NAGSHR32.DLL]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\VirusScan\VS7Plugin.dll]  <Network Associates, Inc.><7.0.0.520>
    [C:\Program Files\Network Associates\VirusScan\SHUTIL.dll]  <Network Associates, Inc.><7.0.0.511>
    [C:\Program Files\Network Associates\VirusScan\FTL.dll]  <Network Associates, Inc.><7.0.0.187>
    [C:\Program Files\Network Associates\VirusScan\Res09\Product.dll]  <Network Associates, Inc.><7.0.0.511>
    [C:\Program Files\Network Associates\VirusScan\Res09\Shutilrc.dll]  <Network Associates, Inc.><7.0.0.511>
    [C:\Program Files\Network Associates\VirusScan\NAKRNLU.DLL]  <Network Associates, Inc.><7.0.0.282>
    [C:\Program Files\Network Associates\VirusScan\NAUTILU.DLL]  <Network Associates, Inc.><7.0.0.282>
    [C:\Program Files\Network Associates\VirusScan\Res09\naUtlRes.dll]  <Network Associates, Inc.><7.0.0.281>
[PID: 856][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  <Microsoft Corporation><7.00.9466>
[PID: 968][C:\WINDOWS\system32\netserly.exe]  <><1.0.0.0>
[PID: 996][C:\Program Files\AccessManager\PMAC\sp_SWIns.exe]  <Smartpipes, Inc.><1.3.54.0>
    [C:\Program Files\AccessManager\Client\sp_SWRC.dll]  <><2.6.120.0>
[PID: 1032][C:\WINDOWS\System32\TPHDEXLG.EXE]  <IBM Corporation><1.0.0.1>
[PID: 1488][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 1884][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2520][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll]  <IBM Corp.><1, 0, 0, 0>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <Yahoo! China><3, 0, 2, 1020>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll]  <yahoo! china><3, 2, 5, 1075>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  <Yahoo! China><3, 0, 1, 1010>
    [C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll]  <Yahoo! China><3, 0, 2, 1004>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL]  <yahoo! china><3, 0, 0, 1000>
    [C:\PROGRA~1\WINZIP\WZSHLSTB.DLL]  <WinZip Computing, Inc.><4.1 (32-bit)>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 8>
[PID: 2688][C:\WINDOWS\system32\RunDll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll]  <IBM Corp.><1, 0, 0, 0>
    [C:\PROGRA~1\ThinkPad\UTILIT~1\tppwrw32.dll]  <IBM Corp.><1, 0, 0, 0>
    [C:\WINDOWS\system32\sensor.dll]  <IBM Corporation><1.30.1.0>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 8>
gototop
 

SReng log [5]

[PID: 2708][C:\WINDOWS\system32\TpShocks.exe]  <IBM Corp.><1, 3, 0, 0>
    [C:\Program Files\ThinkPad\TpShocks\MUI\0409\TpShocks.dll]  <IBM Corp.><1, 3, 0, 0>
    [C:\WINDOWS\system32\Sensor.dll]  <IBM Corporation><1.30.1.0>
[PID: 2716][C:\Program Files\Synaptics\SynTP\SynTPLpr.exe]  <Synaptics, Inc.><7.5.17.13 08Nov04>
    [C:\WINDOWS\system32\SynTPFcs.dll]  <Synaptics, Inc.><7.5.17.13 08Nov04>
[PID: 2784][C:\Program Files\QuickTime\qttask.exe]  <Apple Computer, Inc.><7.0.2>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 8>
[PID: 2796][C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\nailog.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\naCmnLib71.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\naXML71.dll]  <N/A><N/A>
    [C:\Program Files\Network Associates\Common Framework\cmalib.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\applib.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\0409\UpdRes.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\0409\AgentRes.dll]  <McAfee, Inc.><3.5.5.438>
    [C:\Program Files\Network Associates\Common Framework\SecureFrameworkFactory.dll]  <McAfee, Inc.><3.5.5.438>
[PID: 2820][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3275>
[PID: 2868][C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe]  <Sun Microsystems, Inc.><5.0.60.5>
[PID: 2884][C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe]  <Yahoo! China><3, 0, 5, 1011>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <Yahoo! China><3, 0, 2, 1020>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll]  <yahoo! china><3, 2, 5, 1075>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  <Yahoo! China><3, 0, 1, 1010>
    [C:\Program Files\Yahoo!\Assistant\yNotifier.dll]  <yahoo! china><3, 0, 0, 1000>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasfsks.dll]  <3721.com><2, 1, 1, 87>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 8>
[PID: 2916][C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe]  <Yahoo! China><3, 0, 0, 1001>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <Yahoo! China><3, 0, 2, 1020>
    [C:\PROGRA~1\Yahoo!\Assistant\shell\yAsMenu.dll]  <Yahoo! China><3, 0, 0, 1001>
    [C:\PROGRA~1\Yahoo!\Assistant\shell\yAssecblk.dll]  <Yahoo! China><3, 0, 0, 1002>
    [C:\PROGRA~1\Yahoo!\Assistant\shell\yIEAngel.dll]  <Yahoo! China><3, 0, 0, 1000>
    [C:\PROGRA~1\Yahoo!\Assistant\shell\yMenuInfo.dll]  <Yahoo! China><3, 0, 0, 1000>
[PID: 2944][C:\Program Files\MSN Messenger\MsnMsgr.Exe]  <Microsoft Corporation><7.5.0324>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <Yahoo! China><3, 0, 2, 1020>
    [C:\WINDOWS\System32\devenum.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
[PID: 2964][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <Yahoo! China><3, 0, 2, 1020>
[PID: 2984][C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe]  <Adobe Systems Inc.><6.0.1.2003102300>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <Yahoo! China><3, 0, 2, 1020>
[PID: 2996][C:\Program Files\Connected\CBSysTray.exe]  <Connected Corporation><7.5.2.1477>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <Yahoo! China><3, 0, 2, 1020>
[PID: 3004][C:\Program Files\Kingsoft\Powerword 2003\xdict.exe]  <Kingsoft Co, Ltd.><6, 0, 3, 0>
    [C:\Program Files\Kingsoft\Powerword 2003\ITextOut.dll]  <Kingsoft><1, 1, 0, 0>
    [C:\Program Files\Kingsoft\Powerword 2003\CJKTAB32.dll]  <N/A><N/A>
    [C:\Program Files\Kingsoft\Powerword 2003\XImage32.dll]  <N/A><N/A>
    [C:\Program Files\Kingsoft\Powerword 2003\xfile.dll]  <N/A><N/A>
    [C:\Program Files\Kingsoft\Powerword 2003\KPic10.dll]  <N/A><N/A>
    [C:\Program Files\Kingsoft\Powerword 2003\ijl11.dll]  <Intel Corporation><1.1.2>
    [C:\Program Files\Kingsoft\Powerword 2003\toTTSEngine50.dll]  <Kingsoft Corporation><1, 0, 0, 1>
    [C:\Program Files\Kingsoft\Powerword 2003\NormGrab.DLL]  <Kingsoft Co, Ltd.><6, 0, 0, 0>
    [C:\Program Files\Kingsoft\Powerword 2003\DicMngr.dll]  <Kingsoft><1, 0, 0, 0>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <Yahoo! China><3, 0, 2, 1020>
    [C:\Program Files\Kingsoft\Powerword 2003\DBCore10.dll]  <Kingsoft  Corp.><1, 0, 0, 0>
    [C:\Program Files\Kingsoft\Powerword 2003\XdictGrb.dll]  <Kingsoft Co, Ltd.><6, 0, 0, 0>
[PID: 3436][C:\Program Files\Huawei technologies\HUAWEI Mobile Connect\HUAWEIDataCard.exe]  <HUAWEI Technologies Co., Ltd.><HOST.25.11.01B>
    [C:\Program Files\Huawei technologies\HUAWEI Mobile Connect\resource.dll]  <N/A><N/A>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <Yahoo! China><3, 0, 2, 1020>
    [C:\Program Files\Huawei technologies\HUAWEI Mobile Connect\HostAPI.dll]  <N/A><N/A>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 8>
[PID: 3916][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <Yahoo! China><3, 0, 2, 1020>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll]  <Yahoo! China><3, 0, 0, 1000>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll]  <yahoo! china><3, 2, 5, 1075>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  <Yahoo! China><3, 0, 1, 1010>
    [C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll]  <Yahoo! China><3, 0, 2, 1004>
    [C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll]  <yahoo! china><3, 0, 1, 1002>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL]  <yahoo! china><3, 0, 0, 1000>
[PID: 680][C:\WINDOWS\system32\wuauclt.exe]  <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[PID: 2292][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll]  <yahoo! china><3, 0, 7, 1051>
    [C:\Program Files\Yahoo!\Assistant\Assist\ysearch.dll]  <Yahoo! China><3, 0, 4, 1005>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasnoad.dll]  <yahoo! china><3, 0, 1, 1003>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yzsNetProto.dll]  <Yahoo! China><3, 0, 0, 1000>
    [C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll]  <Yahoo! China><3, 0, 2, 1004>
    [C:\Program Files\Yahoo!\Assistant\Assist\yrss.dll]  <Yahoo! China><3, 0, 0, 1000>
    [C:\Program Files\Yahoo!\Assistant\Assist\yaswiper.dll]  <Yahoo! China><3, 0, 0, 1000>
    [C:\Program Files\Yahoo!\Assistant\Assist\yasiesec.dll]  <Yahoo! China><3, 0, 0, 1000>
    [C:\Program Files\Yahoo!\Assistant\Assist\ysettings.dll]  <yahoo! china><3, 0, 3, 1006>
    [C:\Program Files\Yahoo!\Assistant\Assist\ymailp.dll]  <Yahoo! China><3.0.0.1006>
    [C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll]  <yahoo! china><3, 0, 1, 1002>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL]  <yahoo! china><3, 0, 0, 1000>
[PID: 2312][C:\Documents and Settings\zpeng\My Documents\magicset776\MagicSet\magicset.exe]  <Super Rabbit Soft><7.76>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <Yahoo! China><3, 0, 2, 1020>
[PID: 2764][C:\Documents and Settings\zpeng\My Documents\sreng\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <Yahoo! China><3, 0, 2, 1020>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 8>
[PID: 2852][C:\WINDOWS\system32\Rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 8>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  <Yahoo! China><3, 0, 2, 1020>
gototop
 

SReng log [6]


==================================
File Associations
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider

==================================
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT