查看: 3586|回复: 8
收起左侧

浏览器弹出AD页面

[复制链接]
xffsfy
发表于 2007-5-19 14:19:25 | 显示全部楼层 |阅读模式
自打装ADSL以来一直受hxxp://dm91.kulong8.com/120shop.htm这个网站的骚扰,最近又来了个hxxp://www.hltz.com.cn/free/index.aspx?uid=4,实在受不了了。有人说是QQ的问题,但有时候弹网页的时候没有开QQ啊.....另一种说法是网通的推送 ....大家帮忙看看报告,我是看不出来了.....


[CODE]
2007-05-19,14:13:08
System Repair Engineer 2.4.12.806
Smallfrogs (hxxp://www.KZTechs.com)
Windows Server 2003 "R2" Enterprise Edition Service Pack 2 (Build 3790) - 管理权限用户 - 完整功能
以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    HOSTS 文件

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Component Publisher]
    <acdseemc.exe><; C:\Program Files\Common Files\ACD Systems\ACDSeeMC.EXE>  [(Verified)ACD Systems Ltd]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Component Publisher]
    <IMEKRMIG6.1><C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE>  [(Verified)Microsoft Windows Component Publisher]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Component Publisher]
    <SoundMan><SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
    <BigDog303><C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)>  [N/A]
    <jmekey><C:\Program Files\jmesoft\hotkey.exe>  [JME Co., Ltd.]
    <TaskSwitchXP><C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe>  [Alexander Avdonin]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [(Verified)"RealNetworks, Inc."]
    <SunJavaUpdateSched><"C:\Program Files\Java\jre1.6.0\bin\jusched.exe">  [Sun Microsystems, Inc.]
    <MemEmpty><C:\WINDOWS\MemEmpty.exe /h>  [www.jpexe.com]
    <Microsoft Pinyin IME Migration><C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMESC\IMSCMIG.EXE /INSTALL>  [(Verified)Microsoft Corporation]
    <nod32kui><"C:\Program Files\NOD32\nod32kui.exe" /WAITSERVICE>  [(Verified)"ESET, spol. s r.o."]
    <UnlockerAssistant><; "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Component Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><%SystemRoot%\system32\logonui.exe>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
    <IE7 Uninstall Stub><C:\WINDOWS\system32\ieudinit.exe>  [(Verified)Microsoft Windows Component Publisher]

[ 本帖最后由 xffsfy 于 2007-5-19 18:16 编辑 ]
xffsfy
 楼主| 发表于 2007-5-19 14:19:54 | 显示全部楼层
==================================
启动文件夹
[ClipX]
  <C:\Documents and Settings\YXF\「开始」菜单\程序\启动\ClipX.lnk --> D:\YXF\PROGRA~1\ClipX\CLIPX1~1.EXE [N/A]><N>
[EPSnap]
  <C:\Documents and Settings\YXF\「开始」菜单\程序\启动\EPSnap.lnk --> D:\YXF\PROGRA~1\EPSnap\EPSnap.exe [EPWork]><N>
[宽带连接]
  <C:\Documents and Settings\YXF\「开始」菜单\程序\启动\宽带连接.lnk -->  [N/A]><N>

==================================
服务
[Ati HotKey Poller / Ati HotKey Poller][Stopped/Disabled]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[Autodesk Licensing Service / Autodesk Licensing Service][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><Autodesk>
[Windows Presentation Foundation Font Cache 3.0.0.0 / FontCache3.0.0.0][Stopped/Manual Start]
  <C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe><Microsoft Corporation>
[Human Interface Device Access / HidServ][Stopped/Manual Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Windows CardSpace / idsvc][Stopped/Manual Start]
  <"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"><Microsoft Corporation>
[Machine Debug Manager / MDM][Running/Auto Start]
  <"C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe"><Microsoft Corporation>
[Net.Tcp Port Sharing Service / NetTcpPortSharing][Stopped/Disabled]
  <"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"><Microsoft Corporation>
[NOD32 Kernel Service / NOD32krn][Running/Auto Start]
  <"C:\Program Files\NOD32\nod32krn.exe"><Eset>
[O&O Defrag / O&O Defrag][Running/Auto Start]
  <C:\Program Files\O&O Defrag\oodag.exe><O&O Software GmbH>
[StarWind iSCSI Service / StarWindService][Running/Auto Start]
  <C:\Program Files\Alcohol 52\StarWind\StarWindService.exe><Rocket Division Software>
[Event Collector / WECSVC][Running/Auto Start]
  <C:\WINDOWS\system32\svchost.exe -k wecsvc-->%SystemRoot%\system32\wecsvc.dll><Microsoft Corporation>
[Windows Remote Management (WS-Management) / WINRM][Running/Auto Start]
  <C:\WINDOWS\system32\svchost.exe -k WINRM-->%SystemRoot%\system32\WsmSvc.dll><Microsoft Corporation>

==================================
驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[AMON / AMON][Running/Auto Start]
  <\SystemRoot\system32\drivers\amon.sys><Eset>
[ati2mtag / ati2mtag][Running/Manual Start]
  <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
  <system32\DRIVERS\ipinip.sys><N/A>
[nod32drv / nod32drv][Running/System Start]
  <\SystemRoot\system32\drivers\nod32drv.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Feitian ROCKEY4 Device Service / ROCKEYNT][Running/Manual Start]
  <system32\DRIVERS\Rockey4.sys><Feitian Technologies Co., Ltd.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[sptd / sptd][Running/Boot Start]
  <\SystemRoot\System32\Drivers\sptd.sys><N/A>
[ViaIde / ViaIde][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[VIMICRO USB PC Camera (ZC0301PLH) / ZSMC303][Running/Manual Start]
  <System32\Drivers\usbVM303.sys><Vimicro Corporation>
[AVG Anti-Spyware Clean Driver / AvgAsCln][Stopped/System Start]
  <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>

==================================
浏览器加载项
[FGCatchUrl]
  {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <D:\YXF\Program Files\FlashGet\jccatch.dll, www.flashget.com>
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0\bin\ssv.dll, Sun Microsystems, Inc.>
[ViewerHelper Class]
  {78104A01-8E71-4F30-9A36-3793799615B4} <C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll, Microsoft Corporation>
[FlashGet GetFlash Class]
  {F156768E-81EF-470C-9057-481BA8380DBA} <D:\YXF\Program Files\FlashGet\getflash.dll, www.flashget.com>
[Java Plug-in 1.6.0]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll, Sun Microsystems, Inc.>
[MenuHelper Class]
  {685ec120-f786-4498-a8f0-794d47916161} <C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll, Microsoft Corporation>
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL, Microsoft Corporation>
[ViewerHelper Class]
  {aede78a6-42b6-4c3c-96eb-5ae6dbec4859} <C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll, Microsoft Corporation>
[快车]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <D:\YXF\Program Files\FlashGet\FlashGet.exe, FlashGet.com>
[Office Genuine Advantage Validation Tool]
  {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} <C:\WINDOWS\system32\OGACheckControl.DLL, >
[Edit Class]
  {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
[Windows Genuine Advantage Validation Tool]
  {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, Microsoft Corporation>
[UploadListView Class]
  {474F00F5-3853-492C-AC3A-476512BBC336} <C:\WINDOWS\Downloaded Program Files\UploaderX.dll, >
[EditCtrl Class]
  {488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\system32\aliedit\aliedit.dll, >
[MSN Photo Upload Tool]
  {4F1E5B1A-2A80-42CA-8532-2D05CB959537} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
[Windows Live Safety Center Base Module]
  {5ED80217-570B-4DA9-BF44-BE107C0EC166} <C:\WINDOWS\Downloaded Program Files\wlscBase.dll, Microsoft Corporation>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Java Plug-in 1.6.0]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll, Sun Microsystems, Inc.>
[Office Update Installation Engine]
  {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} <C:\WINDOWS\opuc.dll, Microsoft Corporation>
[Java Plug-in 1.6.0]
  {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.6.0]
  {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll, Sun Microsystems, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[Web Browser Applet Control]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\WINDOWS\system32\msjava.dll, Microsoft Corporation>
[FGCatchUrl]
  {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <D:\YXF\Program Files\FlashGet\jccatch.dll, www.flashget.com>
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0\bin\ssv.dll, Sun Microsystems, Inc.>
[ViewerHelper Class]
  {78104A01-8E71-4F30-9A36-3793799615B4} <C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll, Microsoft Corporation>
[Java Plug-in 1.6.0]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll, Sun Microsystems, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[FlashGet GetFlash Class]
  {F156768E-81EF-470C-9057-481BA8380DBA} <D:\YXF\Program Files\FlashGet\getflash.dll, www.flashget.com>
[FGCatchUrl]
  {FB5DA724-162B-11D3-8B9B-AA70B4B0B524} <D:\YXF\Program Files\FlashGet\jccatch.dll, www.flashget.com>
[&使用快车(FlashGet)下载]
  <D:\YXF\Program Files\FlashGet\jc_link.htm, N/A>
[&使用快车(FlashGet)下载全部链接]
  <D:\YXF\Program Files\FlashGet\jc_all.htm, N/A>
[导出到 Microsoft Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000, N/A>

==================================
正在运行的进程
[PID: 368][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
[PID: 416][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 4032][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
[PID: 4068][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.3790.3959 (srv03_sp2_rtm.070216-1710)]
    [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, Inc., 17.1.51.0]
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  [Autodesk, Inc., 17.1.51.0]
    [D:\YXF\Program Files\EPSnap\DxHelper.dll]  [EPWork, 1, 1, 0, 1]
    [C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll]  [Autodesk, 17.1.51.0]
    [D:\YXF\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\Program Files\Unlocker\UnlockerCOM.dll]  [N/A, ]
    [C:\Program Files\NOD32\nodshex.dll]  [N/A, ]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 3, 0, 0, 0]
    [C:\WINDOWS\system32\dllMergeDict.dll]  [Sogou.com Inc., 3, 0, 0, 0]
    [C:\Program Files\Sogoupy\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\Program Files\Common Files\Autodesk Shared\dwf Common\DWFShellExtension.dll]  [Autodesk, Inc., 1.1.0.341]
    [C:\Program Files\Common Files\Autodesk Shared\dwf Common\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Common Files\Autodesk Shared\dwf Common\DWFShellExtensionRes.dll]  [Autodesk, Inc., 1.1.0.341]
    [C:\WINDOWS\system32\dfshim.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Shfusion.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Fusion.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\culture.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\zh-CHS\ShFusRes.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll]  [Microsoft Corporation, 1.0.5027.0]
[PID: 2308][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.39]
[PID: 2524][C:\WINDOWS\VM303_STI.EXE]  [Vimicro, 3, 5, 930, 9]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\WINDOWS\system32\VM303Prp.Ax]  [Vimicro, 3.5.1025. 9]
[PID: 2552][C:\Program Files\jmesoft\hotkey.exe]  [JME Co., Ltd., 3.9.0.1112]
    [C:\Program Files\jmesoft\Keyhook.dll]  [N/A, ]
[PID: 2568][C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe]  [Alexander Avdonin, 2.0.11.0]
[PID: 2740][C:\Program Files\Java\jre1.6.0\bin\jusched.exe]  [Sun Microsystems, Inc., 6.0.0.105]
[PID: 2752][C:\WINDOWS\MemEmpty.exe]  [www.jpexe.com, 1.20]
    [C:\WINDOWS\system32\vb6chs.dll]  [Microsoft Corporation, 6.00.8988]
    [C:\WINDOWS\system32\MSCOREE.DLL]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\fusion.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [D:\YXF\Program Files\EPSnap\DxHelper.dll]  [EPWork, 1, 1, 0, 1]
[PID: 2800][C:\Program Files\NOD32\nod32kui.exe]  [Eset , 2, 70, 37 ]
    [C:\Program Files\NOD32\nod32rui.dll]  [N/A, ]
    [C:\Program Files\NOD32\pu_amon.dll]  [Eset , 2, 70, 37 ]
    [C:\Program Files\NOD32\pr_amon.dll]  [Eset , 2, 70, 16 ]
    [C:\Program Files\NOD32\pu_dmon.dll]  [Eset , 2, 70, 37 ]
    [C:\Program Files\NOD32\pr_dmon.dll]  [N/A, ]
    [C:\Program Files\NOD32\pu_emon.dll]  [Eset , 2, 70, 37 ]
    [C:\Program Files\NOD32\pr_emon.dll]  [N/A, ]
    [C:\Program Files\NOD32\pu_imon.dll]  [Eset , 2, 70, 37 ]
    [C:\Program Files\NOD32\pr_imon.dll]  [N/A, ]
    [D:\YXF\Program Files\EPSnap\DxHelper.dll]  [EPWork, 1, 1, 0, 1]
    [C:\Program Files\NOD32\pu_nod32.dll]  [Eset , 2, 70, 37 ]
    [C:\Program Files\NOD32\pr_nod32.dll]  [Eset , 2, 70, 16 ]
    [C:\Program Files\NOD32\pu_upd.dll]  [Eset , 2, 70, 37 ]
    [C:\Program Files\NOD32\pr_upd.dll]  [N/A, ]
[PID: 2816][D:\YXF\Program Files\ClipX\ClipX 1.0.3.8 汉化版.exe]  [N/A, ]
[PID: 2828][D:\YXF\Program Files\EPSnap\EPSnap.exe]  [EPWork, 2.1.0.1550]
    [D:\YXF\Program Files\EPSnap\DxHelper.dll]  [EPWork, 1, 1, 0, 1]
    [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 70, 37 ]
    [C:\Program Files\NOD32\pr_imon.dll]  [N/A, ]
[PID: 3204][C:\WINDOWS\system32\taskmgr.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\YXF\Program Files\EPSnap\DxHelper.dll]  [EPWork, 1, 1, 0, 1]
[PID: 3680][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710)]
    [D:\YXF\Program Files\EPSnap\DxHelper.dll]  [EPWork, 1, 1, 0, 1]
[PID: 2736][D:\YXF\Program Files\Maxthon\Maxthon.exe]  [Maxthon International ltd., 2, 0, 2, 615]
    [D:\YXF\Program Files\Maxthon\mxpp.dll]  [Maxthon, 1, 0, 0, 50]
    [D:\YXF\Program Files\Maxthon\MxSk.dll]  [Maxthon, 1, 0, 0, 119]
    [D:\YXF\Program Files\Maxthon\MxProxy2.dll]  [, 1, 0, 0, 3115]
    [D:\YXF\Program Files\EPSnap\DxHelper.dll]  [EPWork, 1, 1, 0, 1]
    [D:\YXF\Program Files\Maxthon\MxFav.dll]  [Maxthon, 1, 0, 0, 186]
    [D:\YXF\Program Files\Maxthon\maxzlib.dll]  [, 1.2.3]
    [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 70, 37 ]
    [C:\Program Files\NOD32\pr_imon.dll]  [N/A, ]
    [D:\YXF\Program Files\Maxthon\mxtool.dll]  [, 1, 0, 0, 1]
    [D:\YXF\Program Files\Maxthon\mxfeedU.dll]  [, 1, 0, 45, 45]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CorperfmonExt.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\WINDOWS\system32\SOGOUPY.IME]  [Sohu.com Inc., 3, 0, 0, 0]
    [C:\WINDOWS\system32\dllMergeDict.dll]  [Sogou.com Inc., 3, 0, 0, 0]
    [C:\Program Files\Sogoupy\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
    [C:\Program Files\Microsoft\Rights Management Add-on\RMAFilt.dll]  [Microsoft Corporation, 1.0.5027.0]
    [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll]  [Microsoft Corporation, 2.0.50727.42 (RTM.050727-4200)]
    [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, Inc., 17.1.51.0]
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  [Autodesk, Inc., 17.1.51.0]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
[PID: 3148][E:\系统相关\优化修复\System Repair Engineer 2.4.12.806\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [D:\YXF\Program Files\EPSnap\DxHelper.dll]  [EPWork, 1, 1, 0, 1]
    [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 70, 37 ]
    [C:\Program Files\NOD32\pr_imon.dll]  [N/A, ]
    [E:\系统相关\优化修复\System Repair Engineer 2.4.12.806\Plugins\NWMON.SRE]  [Smallfrogs Studio, 1, 0, 0, 8]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
NOD32 protected [MSAFD Tcpip [TCP/IP]]
    C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [MSAFD Tcpip [UDP/IP]]
    C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [MSAFD Tcpip [RAW/IP]]
    C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [RSVP UDP Service Provider]
    C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [RSVP TCP Service Provider]
    C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32
    C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1       localhost

==================================
API HOOK
RVA  错误: LoadLibraryA (危险等级: 一般,  被下面模块所HOOK: D:\YXF\Program Files\EPSnap\DxHelper.dll)
RVA  错误: LoadLibraryExA (危险等级: 一般,  被下面模块所HOOK: D:\YXF\Program Files\EPSnap\DxHelper.dll)
RVA  错误: LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: D:\YXF\Program Files\EPSnap\DxHelper.dll)
RVA  错误: LoadLibraryW (危险等级: 一般,  被下面模块所HOOK: D:\YXF\Program Files\EPSnap\DxHelper.dll)
RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: D:\YXF\Program Files\EPSnap\DxHelper.dll)

==================================
隐藏进程
N/A

==================================


[/CODE]
xffsfy
 楼主| 发表于 2007-5-19 14:21:15 | 显示全部楼层
以上所有URL都将http替换为hxxp,不能让他们得到一点流量
wangjay1980
发表于 2007-5-19 15:32:34 | 显示全部楼层
报告上看不出问题,你装防火墙了吗,用360等检查一下
xffsfy
 楼主| 发表于 2007-5-19 15:45:10 | 显示全部楼层
原帖由 wangjay1980 于 2007-5-19 15:32 发表
报告上看不出问题,你装防火墙了吗,用360等检查一下

用的XP自带墙.....以前用KIS的时候也出来过.....
360额认为是鸡肋,啥都查不出来
zhaonimm
发表于 2007-5-19 17:52:21 | 显示全部楼层
你有没有在注册表中查找这2个网页的名字!!看有没有!
xffsfy
 楼主| 发表于 2007-5-19 18:17:30 | 显示全部楼层
原帖由 zhaonimm 于 2007-5-19 17:52 发表
你有没有在注册表中查找这2个网页的名字!!看有没有!

没有....
IVKIS
发表于 2007-5-20 00:26:12 | 显示全部楼层
没用QQ,用的是电信ADSL,一直开着KIS,未发生过这种情况
IVKIS
发表于 2007-5-20 00:27:58 | 显示全部楼层
PS:浏览器用的是火狐,IE7.0+IEPRO,Opera[:27:]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-23 07:09 , Processed in 0.127868 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表