开机自动在进程中启动IE进程
开机自动在进程中启动用户名为SYSTEM的IE进程是在打开一个AkumaEngine的软件以后才出现的这种情况
不知道哪位高手可以指点在下一二? 建议用sreng扫描一个报告贴出来.
)X-vO'gmi8clE
AkumaEngine 好像是网游加速相关的软件, 不清楚以前遇到过一次,但那好像是中毒了 建议使用360扫描,清除. 还是 360 比较简单。V7qR&I8i
可是用他扫下 一款加速器软件,可能LZ在某个小站上下的,里面集成了一些流氓软件 哦 对了 还有一点 平时的IE进程为小写 那个开机就启动的是大写的
:[1\0n(~4WG7uD
另附上本人SREng扫描报告
[code]
2008-05-26,19:56:08 t6F+L+k1??u
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)lUi.n.m e oA-G
Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:xm3yM8]"P9r
所有的启动项目(包括注册表、启动文件夹、服务等)&s9X!v7]P*Lk T2B
浏览器加载项)M%K:jA3AL}jF
正在运行的进程(包括进程模块信息)
文件关联1cq JAl
Winsock 提供者U7v!Ku3eCI
Autorun.inf
HOSTS 文件3lS)Pkn(BA
进程特权扫描%sZ(Ex5]al#S*[
启动项目O}3bgO
注册表E%SvIe.a!S3S
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]f@#p@m:t{
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]3s/L Kt)S$dV:vo e
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SoundMan><SOUNDMAN.EXE> [Realtek Semiconductor Corp.]w(f)W~L"G*CrZw
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Component Publisher]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Component Publisher]*H%OUj ig
<HotKeysCmds><; C:\WINDOWS\system32\hkcmd.exe> [(Verified)Microsoft Windows Component Publisher](Q(Sj"tP1{8u~:P
<IgfxTray><; C:\WINDOWS\system32\igfxtray.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]9DL A }%s]f
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Component Publisher]z;p,P?iTg5KAy
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]t B#ZWi3S8JV#s
<shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]/p7o8NZ;Hc v&M\
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Component Publisher])`IPq.ia,C5Z
<UIHost><logonui.exe> [(Verified)Microsoft Windows Component Publisher]-R4W?,Mz? s2J
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]W1O$a3iKN ks
<WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]b(n Psj^*o/X&O"I
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]9IK(W(ml%f+S
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]-m#jK W k:f-}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]Uw/Q6n*kB_
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]H5nXb c+SM
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]0['rm4m1hF[2K
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_CURRENT_USER\Control Panel\Desktop]&erNgx%\
<SCRNSAVE.EXE><C:\PROGRA~1\MY.scr> [N/A]
==================================
启动文件夹W4E;Z9s/J}V
N/A E0Lg"WZ b&C:y
==================================
服务
[卡巴斯基互联网安全套装 7.0 / AVP][Stopped/Manual Start]
<"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" -r><Kaspersky Lab>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>.KKt4|4R^
[Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start]S}x] _Hn
<"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><> eMgU#_"v8N qiN
==================================
驱动程序D3c_#o5j9DX
[360AntiArp / 360AntiArp][Running/System Start]/Qadp|$bC.H
<\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><360安全中心>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter / AN983][Running/Manual Start]
<system32\DRIVERS\AN983.sys><ADMtek Incorporated.>
[cdiskdun / cdiskdun][Stopped/Manual Start] {8W,hcZr |3s\ w
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cdiskdun.sys><N/A>u0]W ujP TB1s
[cdspacex / cdspacex][Stopped/Manual Start]L6O0Dw(s
<system32\DRIVERS\CDSPACEX.sys><N/A>
[DBKDRVR54 / DBKDRVR54][Stopped/Manual Start]/@#g0M_ev
<\??\D:\CE\dbk32.sys><N/A>
[ialm / ialm][Running/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[kl1 / kl1][Running/Boot Start]PwVd K4};S]
<\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>+W,J q x&bv|v
[klif / klif][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[Kaspersky Anti-Virus NDIS Filter / klim5][Running/Manual Start]g-l1_Eqj
<system32\DRIVERS\klim5.sys><Kaspersky Lab>
[kmsinput / kmsinput][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[npkycryp / npkycryp][Stopped/Manual Start]`-KH'x#_{&[S+]
<\??\C:\WINDOWS\system32\npkycryp.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]l `G_%`
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>y#t%s|QV]#K6u
[q2dhn / q2dhn][Stopped/System Start]
<\??\C:\WINDOWS\system32\drivers\q2dhn.sys><N/A>*k4?c N1Lz9Y e
[QKeyServiceDisplay / QKeyService][Running/Boot Start]&yLl(Z~ ?X
<\SystemRoot\system32\KeyCrypt.sys><Tencent Technology (Shenzhen) Company Limited>
[SafeBoxKrnl / SafeBoxKrnl][Running/System Start]ab E+?4@1l!T
<\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys><360安全中心>!| O ?)r.{;e neY9H
[System Safety Monitor 2.0 Core Engine / safemon][Stopped/Boot Start]
<\SystemRoot\system32\drivers\safemon.sys><System Safety Limited>%f(w {n-W C
[Secdrv / Secdrv][Stopped/Manual Start]6r7kf+P](E
<system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[TesSafe / TesSafe][Stopped/Manual Start]+fH!t6A Su:`
<\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>e"I w~Y(\g|
[TSP / TSP][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>8X-S1\y8W3hLl P
[Two Rabbits Live Bus / TwoRabts][Stopped/Manual Start]
<system32\DRIVERS\TwoRabts.sys><N/A>oO1T"u9M&\
[Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/Manual Start]
<system32\drivers\ialmsbw.sys><Intel Corporation>4WA%PA _*D M
[Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start]R*E9pK7F4]&?]
<system32\drivers\ialmkchw.sys><Intel Corporation>.v&f:u'p |2lT{
==================================1F:]].Jy
浏览器加载项u-V?"A)nZ9D Zgw o
[QQCycloneHelper Class]
{01443AEB-0FD1-40FD-9C87-E93D1494C233} <E:\不可乱动\Tencent\QQDownload\QQIEHelper01.dll, 腾讯公司> G#x X#k|/H
[ThunderAtOnce Class]
{01443AEC-0FD1-40fd-9C87-E93D1494C233} <E:\不可乱动\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <E:\不可乱动\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>)?;S-]!Og_&o
[SafeMon Class]4~9M;h4Na%T
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, 360.CN>
[启动迅雷5]&F,}wU-lDX
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <E:\不可乱动\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>z/E C&~/U%AT6W D
[]
{e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Office Genuine Advantage Validation Tool]
{05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} <C:\WINDOWS\system32\OGACheckControl.DLL, >kN8}gI ^"e&M'Q
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>hi["e!R Bd$W^` O#z
[Microsoft Genuine Advantage Self Support Tool]
{1E3F1348-4370-4BBE-A67A-CC7ED824CA85} <C:\WINDOWS\system32\SelfHelpControl.DLL, Microsoft Corporation>
[PhotoDraw Class]
{2375BEE5-F175-4F1C-81EC-8E4E2E72E2DD} <E:\不可乱动\Tencent\QQ\Qzone\QQPhotoDraw.dll, TENCENT>
[ScreenCapture Class]
{B4D9857D-8A55-4442-A577-6B3ED5D4E41B} <C:\WINDOWS\system32\FMO.dll, Tencent Inc.>R |i2k@n9d{
[ScreenCapture Class]
{BFB79EE1-04AE-4D4A-B85E-27EE5F30C095} <C:\WINDOWS\system32\TXGYMailActiveX.dll, Tencent Inc.>
[Tencent Safety Online Base Module]
{C09B522F-8AED-4E21-A65C-DC1AB652BAEE} <C:\WINDOWS\DOWNLO~1\TSOBase.ocx, Tencent Corporation>6g!Q w6n9UkmPr
[WebActivater Control]
{C661F36D-DF85-4EF4-83C7-E107B83D04B1} <C:\WINDOWS\system32\3DShowVM.ocx, QQ> G%NF`%HBO\
[Office Update Installation Engine]
{C7DB51B4-BCF7-4923-8874-7F1A0DC92277} <C:\WINDOWS\opuc.dll, Microsoft Corporation>
[Shockwave Flash Object]nQ#[*K%HH"oQ o
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
[Thunder Browser Helper]
{00000000-12AC-4305-82F9-43058F20E8D2} <E:\不可乱动\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>|Q!e1u _y `!G
[Thunder Browser Helper]
{01443AEA-0FD1-40FD-9C87-E93D1494C233} <E:\不可乱动\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>3O(zT+Ol
[QQCycloneHelper Class]
{01443AEB-0FD1-40FD-9C87-E93D1494C233} <E:\不可乱动\Tencent\QQDownload\QQIEHelper01.dll, 腾讯公司>.u+Ow d(Egbr+}
[ThunderAtOnce Class]
{01443AEC-0FD1-40FD-9C87-E93D1494C233} <E:\不可乱动\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[Office Genuine Advantage Validation Tool]9V7X,v+hlZ;P
{05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} <C:\WINDOWS\system32\OGACheckControl.DLL, >x)PS8LA W
[IeHelper Class]
{0D42E1BD-09DD-4873-A826-9C7E793EB7B6} <, N/A>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>L0Z.yuf0d
[InstallHelper Class]
{1DABF8D5-8430-4985-9B7F-A30E53D709B3} <, N/A>
[UploadFilePartition Class]
{2030B925-DF6E-4535-AB9A-C2787F2FEB53} <C:\WINDOWS\system32\TXGYUploader.dll, Tencent >!wXuw#`7]3k(~
[Windows Media Player]