瑞星卡卡安全论坛
0百子0 - 2006-10-22 15:24:00
以下是我扫描过的内容.见过你帮别人清过希望告诉我该怎么做.先谢谢
2006-10-22,15:13:03
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<KAVPersonal50><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize> [Kaspersky Lab]
<High Definition Audio Property Page Shortcut><HDAShCut.exe> [Windows (R) Server 2003 DDK provider]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<BigDogPath><C:\WINDOWS\VM_STI.EXE SOVIC PC Camera> []
<SoundMAXPnP><C:\Program Files\Analog Devices\Core\smax4pnp.exe> [Analog Devices, Inc.]
<SoundMAX><"C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray> [Analog Devices, Inc.]
<UpdateRun><C:\Program Files\Common Files\updat\Update.exe> []
<UnlockerAssistant><"C:\Program Files\Unlocker\UnlockerAssistant.exe"> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [Microsoft Corporation]
<UIHost><"\Program Files\Logonui.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
<WinlogonNotify: AtiExtEvent><Ati2evxx.dll> [ATI Technologies Inc.]
0百子0 - 2006-10-22 15:24:00
启动文件夹
[Adobe Gamma Loader]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>
==================================
服务
[Adobe LM Service / Adobe LM Service]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Asisuere / Asisuere]
<><N/A>
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart]
<C:\WINDOWS\system32\ati2sgag.exe><>
[C-DillaCdaC11BA / C-DillaCdaC11BA]
<C:\WINDOWS\system32\drivers\CDAC11BA.EXE><Macrovision>
[kavsvc / kavsvc]
<"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe"><Kaspersky Lab>
[IPSEC Client / MOVEESS]
<C:\WINDOWS\SYSTEM32\RUN32.EXE C:\WINDOWS\SYSTEM32\WBEM\BOWRIB68.DLL,Export 1087><N/A>
0百子0 - 2006-10-22 15:25:00
浏览器加载项
[FlashGet]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\Mshtml.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[photo_uploader Control]
{A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <C:\PROGRA~1\PHOTO_~1\PHOTO_~1.OCX, N/A>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\Flash.ocx, Macromedia, Inc.>
[上传到QQ网络硬盘]
<D:\qq\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<D:\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\qq\SendMMS.htm, N/A>
0百子0 - 2006-10-22 15:25:00
正在运行的进程
[PID: 636][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 700][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 728][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\Ati2evxx.dll] <ATI Technologies Inc.><6.14.10.4124>
[PID: 784][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 796][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 952][C:\WINDOWS\system32\Ati2evxx.exe] <ATI Technologies Inc.><6.14.10.4124>
[C:\WINDOWS\system32\Ati2edxx.dll] <ATI Technologies, Inc.><6, 14, 10, 2499>
[PID: 980][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1056][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1156][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1236][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1296][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1588][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1708][C:\WINDOWS\system32\Ati2evxx.exe] <ATI Technologies Inc.><6.14.10.4124>
[C:\WINDOWS\system32\Ati2edxx.dll] <ATI Technologies, Inc.><6, 14, 10, 2499>
[C:\WINDOWS\system32\KB8964225.log] <N/A><N/A>
[PID: 1980][C:\WINDOWS\VM_STI.EXE] <BIGDOG><4, 2, 610, 4>
[C:\WINDOWS\system32\msdmo.dll] <N/A><N/A>
[C:\WINDOWS\system32\VM31bPrp.Ax] <Vimicro><1.00.01.00>
[C:\WINDOWS\system32\KB8964225.log] <N/A><N/A>
[PID: 1992][C:\Program Files\Analog Devices\Core\smax4pnp.exe] <Analog Devices, Inc.><6, 0, 0, 20>
[C:\Program Files\Analog Devices\Core\SMWDMIF.dll] <Analog Devices, Inc.><6, 0, 0, 012>
[C:\WINDOWS\system32\KB8964225.log] <N/A><N/A>
[PID: 2036][C:\Program Files\Analog Devices\SoundMAX\Smax4.exe] <Analog Devices, Inc.><5, 2, 0, 9>
[C:\WINDOWS\system32\KB8964225.log] <N/A><N/A>
[PID: 204][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\KB8964225.log] <N/A><N/A>
[PID: 440][C:\WINDOWS\system32\drivers\CDAC11BA.EXE] <Macrovision><4.20.030>
[PID: 1004][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1100][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1124][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1616][c:\windows\system32\wbem\services.exe] <Microsoft><1.0.0.0>
[PID: 1756][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3476][D:\bt\BitComet\BitComet.exe] <www.BitComet.com><0.63.>
[C:\WINDOWS\system32\KB8964225.log] <N/A><N/A>
[C:\WINDOWS\system32\msdmo.dll] <N/A><N/A>
[PID: 1228][C:\WINDOWS\explorer.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\KB8964225.log] <N/A><N/A>
[PID: 928][C:\Program Files\Internet Explorer\IEXPLORE.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\KB8964225.log] <N/A><N/A>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\scrchpg.dll] <Kaspersky Lab><5.0.1.18>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\scrch_ag.dll] <Kaspersky Lab><5.0.388.1>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\FSSync.dll] <Kaspersky Lab><5.0.388.0>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\pr_rmt.dll] <Kaspersky Lab><5.0.388.0>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\ccclient.dll] <Kaspersky Lab><5.0.388.1>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\klipc.dll] <Kaspersky Lab><5.0.388.0>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\KLUtil.dll] <Kaspersky Lab><5.0.388.1>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\rpt.dll] <Kaspersky Lab><5.0.388.2>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\CCIFACE.dll] <Kaspersky Lab><5.0.388.1>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\prloader.dll] <Kaspersky Lab><5.0.388.0>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\prkernel.ppl] <Kaspersky Lab><5.0.388.0>
[c:\program files\kaspersky lab\kaspersky anti-virus personal pro\prstring.ppl] <Kaspersky Lab><5.0.388.0>
[c:\program files\kaspersky lab\kaspersky anti-virus personal pro\pr_srv.ppl] <Kaspersky Lab><5.0.388.0>
[c:\program files\kaspersky lab\kaspersky anti-virus personal pro\pr_clnt.ppl] <Kaspersky Lab><5.0.388.0>
[c:\program files\kaspersky lab\kaspersky anti-virus personal pro\tempfile.ppl] <Kaspersky Lab><5.0.388.0>
[C:\WINDOWS\system32\macromed\flash\Flash.ocx] <Macromedia, Inc.><7,0,19,0>
[PID: 2484][D:\其他程序\sreng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\WINDOWS\system32\KB8964225.log] <N/A><N/A>
0百子0 - 2006-10-22 15:25:00
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
xp123 - 2006-10-22 15:26:00
<UpdateRun><C:\Program Files\Common Files\updat\Update.exe> []
xp123 - 2006-10-22 15:28:00
[C:\WINDOWS\system32\KB8964225.log] <N/A><N/A>
中了!!!!!!!!!!!!
0百子0 - 2006-10-22 15:44:00
那怎么处理?
秋日里的蓝天 - 2006-10-22 17:57:00
运行(双击)SRENG2,点“启动项目,服务,点“Win32服务应用程序”
勾选“隐藏微软服务”选中病毒服务
IPSEC Client
Asisuere
,选择“删除服务”
点“设置”选择“否”
运行SREng2,使用“启动项目”--注册表--选中以下的项删除
C:\Program Files\Common Files\updat\Update.exe
显示隐藏文件
删除:
C:\WINDOWS\SYSTEM32\WBEM\BOWRIB68.DLL
C:\Program Files\Common Files\updat\文件夹
C:\WINDOWS\system32\KB8964225.log
0百子0 - 2006-10-22 18:37:00
谢谢除了最后要删的第二个没找着其他都做了目前在安全模式用RogueCleaner查杀了一次不知道效果怎么样.
秋日里的蓝天 - 2006-10-22 18:48:00
还有异常重新扫描上来
0百子0 - 2006-10-22 18:57:00
好顽固哦...还会自动放故事给我听....而且我不知道是什么程序在放故事...汗死...还是没清掉
2006-10-22,18:45:42
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<KAVPersonal50><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize> [Kaspersky Lab]
<High Definition Audio Property Page Shortcut><HDAShCut.exe> [Windows (R) Server 2003 DDK provider]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<BigDogPath><C:\WINDOWS\VM_STI.EXE SOVIC PC Camera> []
<SoundMAXPnP><C:\Program Files\Analog Devices\Core\smax4pnp.exe> [Analog Devices, Inc.]
<SoundMAX><"C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray> [Analog Devices, Inc.]
<UnlockerAssistant><"C:\Program Files\Unlocker\UnlockerAssistant.exe"> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [Microsoft Corporation]
<UIHost><"\Program Files\Logonui.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
<WinlogonNotify: AtiExtEvent><Ati2evxx.dll> [ATI Technologies Inc.]
0百子0 - 2006-10-22 18:57:00
启动文件夹
[Adobe Gamma Loader]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>
==================================
服务
[Adobe LM Service / Adobe LM Service]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart]
<C:\WINDOWS\system32\ati2sgag.exe><>
[C-DillaCdaC11BA / C-DillaCdaC11BA]
<C:\WINDOWS\system32\drivers\CDAC11BA.EXE><Macrovision>
[kavsvc / kavsvc]
<"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe"><Kaspersky Lab>
==================================
浏览器加载项
[FlashGet]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\Mshtml.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[photo_uploader Control]
{A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <C:\PROGRA~1\PHOTO_~1\PHOTO_~1.OCX, N/A>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\Flash.ocx, Macromedia, Inc.>
[上传到QQ网络硬盘]
<D:\qq\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<D:\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\qq\SendMMS.htm, N/A>
0百子0 - 2006-10-22 18:57:00
正在运行的进程
[PID: 636][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 708][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 736][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\Ati2evxx.dll] <ATI Technologies Inc.><6.14.10.4124>
[PID: 784][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 796][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 944][C:\WINDOWS\system32\Ati2evxx.exe] <ATI Technologies Inc.><6.14.10.4124>
[C:\WINDOWS\system32\Ati2edxx.dll] <ATI Technologies, Inc.><6, 14, 10, 2499>
[PID: 972][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1052][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1156][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1216][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1356][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1528][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1716][C:\WINDOWS\system32\Ati2evxx.exe] <ATI Technologies Inc.><6.14.10.4124>
[C:\WINDOWS\system32\Ati2edxx.dll] <ATI Technologies, Inc.><6, 14, 10, 2499>
[PID: 1820][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll] <><1, 0, 0, 1>
[PID: 1948][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.3292>
[PID: 1960][C:\WINDOWS\VM_STI.EXE] <BIGDOG><4, 2, 610, 4>
[C:\WINDOWS\system32\msdmo.dll] <N/A><N/A>
[C:\WINDOWS\system32\VM31bPrp.Ax] <Vimicro><1.00.01.00>
[PID: 2004][C:\Program Files\Analog Devices\Core\smax4pnp.exe] <Analog Devices, Inc.><6, 0, 0, 20>
[C:\Program Files\Analog Devices\Core\SMWDMIF.dll] <Analog Devices, Inc.><6, 0, 0, 012>
[PID: 2012][C:\Program Files\Analog Devices\SoundMAX\Smax4.exe] <Analog Devices, Inc.><5, 2, 0, 9>
[PID: 2028][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 368][C:\WINDOWS\system32\drivers\CDAC11BA.EXE] <Macrovision><4.20.030>
[PID: 1128][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1188][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1272][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 244][c:\windows\system32\wbem\services.exe] <Microsoft><1.0.0.0>
[PID: 360][C:\WINDOWS\system32\wbem\wmiprvse.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2260][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3100][D:\千千静听\TTPlayer.exe] <Alen Soft><4, 6, 0, 0>
[D:\千千静听\ttpcomm.dll] <N/A><N/A>
[D:\千千静听\ttpres.dll] <Alen Soft><4, 6, 0, 0>
[D:\千千静听\AddIn\ttp_lrcsh.dll] <N/A><N/A>
[D:\千千静听\AddIn\ttp_ogg.dll] <N/A><N/A>
[D:\千千静听\AddIn\ttp_asf.dll] <N/A><N/A>
[D:\千千静听\AddIn\ttp_aac.dll] <N/A><N/A>
[D:\千千静听\AddIn\ttp_ac3dts.dll] <N/A><N/A>
[PID: 3184][D:\qq\QQ.exe] <TENCENT><0, 0, 0, 0>
[D:\qq\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[D:\qq\QQHelperDll.dll] <><1, 0, 0, 1>
[D:\qq\BasicCtrlDll.dll] <Tencent><5, 0, 200, 160>
[D:\qq\QQAPI.dll] <><1, 0, 0, 1>
[D:\qq\LoginCtrl.dll] <><1, 0, 0, 1>
[D:\qq\npkcntc.dll] <INCA Internet Co., Ltd.><2006, 3, 2, 1>
[D:\qq\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[D:\qq\QQRes.dll] <tencent><1, 0, 0, 1>
[D:\qq\QQMainFrame.dll] <N/A><N/A>
[D:\qq\CQQApplication.dll] <N/A><N/A>
[D:\qq\NewSkin.dll] <><1, 0, 0, 1>
[D:\qq\HostingMgr.dll] <><1, 0, 0, 1>
[D:\qq\CameraDll.dll] <><1, 0, 0, 1>
[D:\qq\MailSummary.dll] <><1, 0, 0, 1>
[D:\qq\QQSpace.dll] <><1, 0, 0, 1>
[D:\qq\QQAllInOne.dll] <N/A><N/A>
[D:\qq\GroupLive.dll] <N/A><N/A>
[D:\qq\SCCore.dll] <N/A><N/A>
[C:\WINDOWS\system32\msdmo.dll] <N/A><N/A>
[D:\qq\QQGroupMng.dll] <><1, 0, 0, 1>
[D:\qq\QQSysMsgMng.dll] <N/A><N/A>
[D:\qq\UserDefinedHead.dll] <><1, 0, 0, 1>
[D:\qq\QQPlugin.dll] <N/A><N/A>
[D:\qq\QQConfigPlugin.dll] <><1, 0, 0, 1>
[D:\qq\FlashAvatarDll.dll] <><1, 4, 0, 1>
[D:\qq\QQAvatar.dll] <N/A><N/A>
[D:\qq\QRingMng.dll] <N/A><N/A>
[D:\qq\PhoneAPI.dll] <><1, 0, 0, 1>
[D:\qq\DialerAllinOne.dll] <tencent><1, 4, 0, 0>
[D:\qq\LongConnection.dll] <tencent><5, 0, 200, 160>
[D:\qq\QQPet.dll] <><1, 0, 0, 1>
[D:\qq\BQQApplication.dll] <N/A><N/A>
[D:\qq\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[D:\qq\CommercesMng.dll] <><1, 0, 0, 1>
[D:\qq\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 200>
[D:\qq\QQSceneMng.dll] <N/A><N/A>
[D:\qq\QQPhoneHelper.dll] <腾讯科技(深圳)有限公司><2, 0, 6, 60>
[PID: 3464][C:\Program Files\Internet Explorer\IEXPLORE.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\macromed\flash\Flash.ocx] <Macromedia, Inc.><7,0,19,0>
[PID: 2428][D:\其他程序\sreng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
0百子0 - 2006-10-22 18:58:00
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
秋日里的蓝天 - 2006-10-22 19:01:00
把你的SRENG升级一下
运行SRENG,左下角有提示升级的,再扫描上来
0百子0 - 2006-10-22 19:03:00
开那软件启动时提示注册表值UIHost被修改为非正常值(默认数值是logonui)请检查你计算机中可能存在的病毒
我不知道怎么办
秋日里的蓝天 - 2006-10-22 19:06:00
用SRENG新版本扫描上来
哪个暂时不用理会
0百子0 - 2006-10-22 19:06:00
先谢谢蓝天的耐心指导:p
扫描结果..我有最新版刚才开错了
2006-10-22,18:55:35
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<KAVPersonal50><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize> [Kaspersky Lab]
<High Definition Audio Property Page Shortcut><HDAShCut.exe> [Windows (R) Server 2003 DDK provider]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<BigDogPath><C:\WINDOWS\VM_STI.EXE SOVIC PC Camera> []
<SoundMAXPnP><C:\Program Files\Analog Devices\Core\smax4pnp.exe> [Analog Devices, Inc.]
<SoundMAX><"C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray> [Analog Devices, Inc.]
<UnlockerAssistant><"C:\Program Files\Unlocker\UnlockerAssistant.exe"> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [Microsoft Corporation]
<UIHost><"\Program Files\Logonui.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
<WinlogonNotify: AtiExtEvent><Ati2evxx.dll> [ATI Technologies Inc.]
0百子0 - 2006-10-22 19:07:00
启动文件夹
[Adobe Gamma Loader]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>
==================================
服务
[Adobe LM Service / Adobe LM Service]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart]
<C:\WINDOWS\system32\ati2sgag.exe><>
[C-DillaCdaC11BA / C-DillaCdaC11BA]
<C:\WINDOWS\system32\drivers\CDAC11BA.EXE><Macrovision>
[kavsvc / kavsvc]
<"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe"><Kaspersky Lab>
0百子0 - 2006-10-22 19:07:00
浏览器加载项
[FlashGet]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\Mshtml.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[photo_uploader Control]
{A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <C:\PROGRA~1\PHOTO_~1\PHOTO_~1.OCX, N/A>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\Flash.ocx, Macromedia, Inc.>
[上传到QQ网络硬盘]
<D:\qq\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<D:\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\qq\SendMMS.htm, N/A>
0百子0 - 2006-10-22 19:07:00
正在运行的进程
[PID: 636][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 708][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 736][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\Ati2evxx.dll] <ATI Technologies Inc.><6.14.10.4124>
[PID: 784][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 796][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 944][C:\WINDOWS\system32\Ati2evxx.exe] <ATI Technologies Inc.><6.14.10.4124>
[C:\WINDOWS\system32\Ati2edxx.dll] <ATI Technologies, Inc.><6, 14, 10, 2499>
[PID: 972][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1052][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1156][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1216][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1356][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1528][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1716][C:\WINDOWS\system32\Ati2evxx.exe] <ATI Technologies Inc.><6.14.10.4124>
[C:\WINDOWS\system32\Ati2edxx.dll] <ATI Technologies, Inc.><6, 14, 10, 2499>
[PID: 1820][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll] <><1, 0, 0, 1>
[PID: 1948][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.3292>
[PID: 1960][C:\WINDOWS\VM_STI.EXE] <BIGDOG><4, 2, 610, 4>
[C:\WINDOWS\system32\msdmo.dll] <N/A><N/A>
[C:\WINDOWS\system32\VM31bPrp.Ax] <Vimicro><1.00.01.00>
[PID: 2004][C:\Program Files\Analog Devices\Core\smax4pnp.exe] <Analog Devices, Inc.><6, 0, 0, 20>
[C:\Program Files\Analog Devices\Core\SMWDMIF.dll] <Analog Devices, Inc.><6, 0, 0, 012>
[PID: 2012][C:\Program Files\Analog Devices\SoundMAX\Smax4.exe] <Analog Devices, Inc.><5, 2, 0, 9>
[PID: 2028][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 368][C:\WINDOWS\system32\drivers\CDAC11BA.EXE] <Macrovision><4.20.030>
[PID: 1128][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1188][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1272][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 244][c:\windows\system32\wbem\services.exe] <Microsoft><1.0.0.0>
[PID: 2260][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3100][D:\千千静听\TTPlayer.exe] <Alen Soft><4, 6, 0, 0>
[D:\千千静听\ttpcomm.dll] <N/A><N/A>
[D:\千千静听\ttpres.dll] <Alen Soft><4, 6, 0, 0>
[D:\千千静听\AddIn\ttp_lrcsh.dll] <N/A><N/A>
[D:\千千静听\AddIn\ttp_ogg.dll] <N/A><N/A>
[D:\千千静听\AddIn\ttp_asf.dll] <N/A><N/A>
[D:\千千静听\AddIn\ttp_aac.dll] <N/A><N/A>
[D:\千千静听\AddIn\ttp_ac3dts.dll] <N/A><N/A>
[PID: 3184][D:\qq\QQ.exe] <TENCENT><0, 0, 0, 0>
[D:\qq\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[D:\qq\QQHelperDll.dll] <><1, 0, 0, 1>
[D:\qq\BasicCtrlDll.dll] <Tencent><5, 0, 200, 160>
[D:\qq\QQAPI.dll] <><1, 0, 0, 1>
[D:\qq\LoginCtrl.dll] <><1, 0, 0, 1>
[D:\qq\npkcntc.dll] <INCA Internet Co., Ltd.><2006, 3, 2, 1>
[D:\qq\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[D:\qq\QQRes.dll] <tencent><1, 0, 0, 1>
[D:\qq\QQMainFrame.dll] <N/A><N/A>
[D:\qq\CQQApplication.dll] <N/A><N/A>
[D:\qq\NewSkin.dll] <><1, 0, 0, 1>
[D:\qq\HostingMgr.dll] <><1, 0, 0, 1>
[D:\qq\CameraDll.dll] <><1, 0, 0, 1>
[D:\qq\MailSummary.dll] <><1, 0, 0, 1>
[D:\qq\QQSpace.dll] <><1, 0, 0, 1>
[D:\qq\QQAllInOne.dll] <N/A><N/A>
[D:\qq\GroupLive.dll] <N/A><N/A>
[D:\qq\SCCore.dll] <N/A><N/A>
[C:\WINDOWS\system32\msdmo.dll] <N/A><N/A>
[D:\qq\QQGroupMng.dll] <><1, 0, 0, 1>
[D:\qq\QQSysMsgMng.dll] <N/A><N/A>
[D:\qq\UserDefinedHead.dll] <><1, 0, 0, 1>
[D:\qq\QQPlugin.dll] <N/A><N/A>
[D:\qq\QQConfigPlugin.dll] <><1, 0, 0, 1>
[D:\qq\FlashAvatarDll.dll] <><1, 4, 0, 1>
[D:\qq\QQAvatar.dll] <N/A><N/A>
[D:\qq\QRingMng.dll] <N/A><N/A>
[D:\qq\PhoneAPI.dll] <><1, 0, 0, 1>
[D:\qq\DialerAllinOne.dll] <tencent><1, 4, 0, 0>
[D:\qq\LongConnection.dll] <tencent><5, 0, 200, 160>
[D:\qq\QQPet.dll] <><1, 0, 0, 1>
[D:\qq\BQQApplication.dll] <N/A><N/A>
[D:\qq\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[D:\qq\CommercesMng.dll] <><1, 0, 0, 1>
[D:\qq\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 200>
[D:\qq\QQSceneMng.dll] <N/A><N/A>
[D:\qq\QQPhoneHelper.dll] <腾讯科技(深圳)有限公司><2, 0, 6, 60>
[D:\qq\QQCustomFace.dll] <N/A><N/A>
[D:\qq\ImageOle.dll] <TODO: <Company name>><1.0.0.1>
[D:\qq\GroupConnection.dll] <Tencent><5, 0, 202, 170>
[D:\qq\videodevice.dll] <Tencent><1.5.0.0>
[D:\qq\inplus.dll] <Tencent><1.5.0.0>
[C:\WINDOWS\system32\l3codeca.acm] <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
[PID: 3464][C:\Program Files\Internet Explorer\IEXPLORE.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\macromed\flash\Flash.ocx] <Macromedia, Inc.><7,0,19,0>
[PID: 3532][D:\其他程序\sreng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
0百子0 - 2006-10-22 19:08:00
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
秋日里的蓝天 - 2006-10-22 19:10:00
又搞错了,把这个删除
下载一个
下载地址
http://free5.ys168.com/?ufwihgu168
0百子0 - 2006-10-22 19:12:00
好的.谢谢
0百子0 - 2006-10-22 19:14:00
2006-10-22,19:03:34
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<KAVPersonal50><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize> [Kaspersky Lab]
<High Definition Audio Property Page Shortcut><HDAShCut.exe> [(Verified)Windows (R) Server 2003 DDK provider]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<BigDogPath><C:\WINDOWS\VM_STI.EXE SOVIC PC Camera> [N/A]
<SoundMAXPnP><C:\Program Files\Analog Devices\Core\smax4pnp.exe> [Analog Devices, Inc.]
<SoundMAX><"C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray> [Analog Devices, Inc.]
<UnlockerAssistant><"C:\Program Files\Unlocker\UnlockerAssistant.exe"> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
<UIHost><"\Program Files\Logonui.exe> [N/A]
0百子0 - 2006-10-22 19:15:00
启动文件夹
[Adobe Gamma Loader]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk --> C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE [Adobe Systems, Inc.]><N>
==================================
服务
[Adobe LM Service / Adobe LM Service]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart]
<C:\WINDOWS\system32\ati2sgag.exe><>
[C-DillaCdaC11BA / C-DillaCdaC11BA]
<C:\WINDOWS\system32\drivers\CDAC11BA.EXE><Macrovision>
[Human Interface Device Access / HidServ]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[kavsvc / kavsvc]
<"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe"><Kaspersky Lab>
[Network Logon / NetWorkLogon]
<rundll32.exe KB8964225.log,start><Microsoft Corporation>
[WindowsNT Protected Storage / NTProStorage]
<C:\WINDOWS\System32\svchost.exe -k NTProStorage-->c:\windows\system32\ntprostorage.dll><Microsoft Corporation>
[Storage Center / NtStub]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\hqtpkn31.dll><Microsoft Corporation>
[Remote IIS Admin Service / ReIISAdmin]
<C:\WINDOWS\System32\svchost.exe -k ReIISAdmin-->c:\windows\system32\reinetinfo.dll><Microsoft Corporation>
0百子0 - 2006-10-22 19:15:00
驱动程序
[ADI UAA Function Driver for High Definition Audio Service / ADIHdAudAddService]
<system32\drivers\ADIHdAud.sys><Analog Devices, Inc.>
[AEAudio Service / AEAudioService]
<system32\drivers\AEAudio.sys><Andrea Electronics Corporation>
[AliIde / AliIde]
<\SystemRoot\System32\DRIVERS\aliide.sys><N/A>
[ati2mtag / ati2mtag]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[CdaC15BA / CdaC15BA]
<\??\C:\WINDOWS\system32\drivers\CDAC15BA.SYS><Macrovision Europe Ltd>
[CmdIde / CmdIde]
<\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[dtscsi / dtscsi]
<\SystemRoot\System32\Drivers\dtscsi.sys><N/A>
[Intel(R) PRO/1000 Adapter Driver / E1000]
<system32\DRIVERS\e1000325.sys><Intel Corporation>
[gwiopm / gwiopm]
<\??\D:\其他程序\wom\gwiopm.sys><N/A>
[Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService]
<system32\drivers\HdAudio.sys><Windows (R) Server 2003 DDK provider>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[Kl1 / Kl1]
<\SystemRoot\System32\drivers\kl1.sys><Kaspersky Lab>
[Klif / Klif]
<System32\drivers\klif.sys><Kaspersky Labs>
[Klmc / Klmc]
<System32\drivers\klmc.sys><Kaspersky Lab>
[kmsinput / kmsinput]
<\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[MegaIDE / MegaIDE]
<\SystemRoot\System32\DRIVERS\MegaIDE.sys><LSI Logic Corporation.>
[nv / nv]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[paraudio / paraudio]
<\??\C:\WINDOWS\system32\drivers\paraudio.sys><Microsoft Corporation>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv]
<system32\DRIVERS\secdrv.sys><N/A>
[SenFilt Service / SenFiltService]
<system32\drivers\Senfilt.sys><Sensaura>
[StarForce Protection Environment Driver (version 1.x) / sfdrv01]
<\SystemRoot\System32\drivers\sfdrv01.sys><Protection Technology>
[StarForce Protection Environment Driver (version 1.x.a) / sfdrv01a]
<\SystemRoot\System32\drivers\sfdrv01a.sys><Protection Technology (StarForce)>
[StarForce Protection Helper Driver (version 2.x) / sfhlp02]
<\SystemRoot\System32\drivers\sfhlp02.sys><Protection Technology (StarForce)>
[StarForce Protection Synchronization Driver (version 2.x) / sfsync02]
<\SystemRoot\System32\drivers\sfsync02.sys><Protection Technology>
[StarForce Protection Synchronization Driver (version 4.x) / sfsync04]
<\SystemRoot\System32\drivers\sfsync04.sys><Protection Technology (StarForce)>
[Intel (R) System Management BIOS Service / SMBios]
<system32\DRIVERS\SMBios.sys><Intel Corporation>
[sptd / sptd]
<\SystemRoot\System32\Drivers\sptd.sys><N/A>
[TCP/IP Protocol Driver / Tcpip]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[TSP / TSP]
<\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Labs>
[ViaIde / ViaIde]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
0百子0 - 2006-10-22 19:15:00
浏览器加载项
[FlashGet]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\Mshtml.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[photo_uploader Control]
{A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <C:\PROGRA~1\PHOTO_~1\PHOTO_~1.OCX, N/A>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\Flash.ocx, Macromedia, Inc.>
[上传到QQ网络硬盘]
<D:\qq\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<D:\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\qq\SendMMS.htm, N/A>
0百子0 - 2006-10-22 19:16:00
正在运行的进程
[PID: 636][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 708][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 736][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4124]
[PID: 784][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 796][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 944][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4124]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2499]
[PID: 972][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1052][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1156][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1216][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1356][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1528][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1716][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4124]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2499]
[PID: 1820][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll] [, 1, 0, 0, 1]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[C:\Program Files\ACDSee\picaview.dll] [ACD Systems, Ltd., 2, 0, 0, 78]
[C:\Program Files\ACDSee\PlugIns\IDE_ACDStd.apl] [ACD Systems, Ltd., 1, 3, 4, 22]
[C:\Program Files\Unlocker\UnlockerCOM.dll] [N/A, N/A]
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\shellex.dll] [Kaspersky Lab, 5.0.388.1]
[PID: 1948][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3292]
[PID: 1960][C:\WINDOWS\VM_STI.EXE] [BIGDOG, 4, 2, 610, 4]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[C:\WINDOWS\system32\VM31bPrp.Ax] [Vimicro, 1.00.01.00]
[PID: 2004][C:\Program Files\Analog Devices\Core\smax4pnp.exe] [Analog Devices, Inc., 6, 0, 0, 20]
[C:\Program Files\Analog Devices\Core\SMWDMIF.dll] [Analog Devices, Inc., 6, 0, 0, 012]
[PID: 2012][C:\Program Files\Analog Devices\SoundMAX\Smax4.exe] [Analog Devices, Inc., 5, 2, 0, 9]
[PID: 2028][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 368][C:\WINDOWS\system32\drivers\CDAC11BA.EXE] [Macrovision, 4.20.030]
[PID: 1128][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1188][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1272][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 244][c:\windows\system32\wbem\services.exe] [Microsoft, 1.0.0.0]
[PID: 2260][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3100][D:\千千静听\TTPlayer.exe] [Alen Soft, 4, 6, 0, 0]
[D:\千千静听\ttpcomm.dll] [N/A, N/A]
[D:\千千静听\ttpres.dll] [Alen Soft, 4, 6, 0, 0]
[D:\千千静听\AddIn\ttp_lrcsh.dll] [N/A, N/A]
[D:\千千静听\AddIn\ttp_ogg.dll] [N/A, N/A]
[D:\千千静听\AddIn\ttp_asf.dll] [N/A, N/A]
[D:\千千静听\AddIn\ttp_aac.dll] [N/A, N/A]
[D:\千千静听\AddIn\ttp_ac3dts.dll] [N/A, N/A]
[PID: 3184][D:\qq\QQ.exe] [TENCENT, 0, 0, 0, 0]
[D:\qq\QQBaseClassInDll.dll] [, 1, 0, 0, 1]
[D:\qq\QQHelperDll.dll] [, 1, 0, 0, 1]
[D:\qq\BasicCtrlDll.dll] [Tencent, 5, 0, 200, 160]
[D:\qq\QQAPI.dll] [, 1, 0, 0, 1]
[D:\qq\LoginCtrl.dll] [, 1, 0, 0, 1]
[D:\qq\npkcntc.dll] [INCA Internet Co., Ltd., 2006, 3, 2, 1]
[D:\qq\npkpdb.dll] [INCA Internet Co., Ltd., 2003, 10, 1, 1]
[D:\qq\QQRes.dll] [tencent, 1, 0, 0, 1]
[D:\qq\QQMainFrame.dll] [N/A, N/A]
[D:\qq\CQQApplication.dll] [N/A, N/A]
[D:\qq\NewSkin.dll] [, 1, 0, 0, 1]
[D:\qq\HostingMgr.dll] [, 1, 0, 0, 1]
[D:\qq\CameraDll.dll] [, 1, 0, 0, 1]
[D:\qq\MailSummary.dll] [, 1, 0, 0, 1]
[D:\qq\QQSpace.dll] [, 1, 0, 0, 1]
[D:\qq\QQAllInOne.dll] [N/A, N/A]
[D:\qq\GroupLive.dll] [N/A, N/A]
[D:\qq\SCCore.dll] [N/A, N/A]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[D:\qq\QQGroupMng.dll] [, 1, 0, 0, 1]
[D:\qq\QQSysMsgMng.dll] [N/A, N/A]
[D:\qq\UserDefinedHead.dll] [, 1, 0, 0, 1]
[D:\qq\QQPlugin.dll] [N/A, N/A]
[D:\qq\QQConfigPlugin.dll] [, 1, 0, 0, 1]
[D:\qq\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[D:\qq\QQAvatar.dll] [N/A, N/A]
[D:\qq\QRingMng.dll] [N/A, N/A]
[D:\qq\PhoneAPI.dll] [, 1, 0, 0, 1]
[D:\qq\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[D:\qq\LongConnection.dll] [tencent, 5, 0, 200, 160]
[D:\qq\QQPet.dll] [, 1, 0, 0, 1]
[D:\qq\BQQApplication.dll] [N/A, N/A]
[D:\qq\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
[D:\qq\CommercesMng.dll] [, 1, 0, 0, 1]
[D:\qq\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 200]
[D:\qq\QQSceneMng.dll] [N/A, N/A]
[D:\qq\QQPhoneHelper.dll] [腾讯科技(深圳)有限公司, 2, 0, 6, 60]
[D:\qq\QQCustomFace.dll] [N/A, N/A]
[D:\qq\ImageOle.dll] [TODO: <Company name>, 1.0.0.1]
[D:\qq\GroupConnection.dll] [Tencent, 5, 0, 202, 170]
[D:\qq\videodevice.dll] [Tencent, 1.5.0.0]
[D:\qq\inplus.dll] [Tencent, 1.5.0.0]
[C:\WINDOWS\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
[C:\WINDOWS\system32\macromed\flash\Flash.ocx] [Macromedia, Inc., 7,0,19,0]
[D:\qq\QQMagicFace.dll] [, 1, 0, 0, 1]
[PID: 3464][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\macromed\flash\Flash.ocx] [Macromedia, Inc., 7,0,19,0]
[PID: 3432][D:\其他程序\sreng最新版\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
© 2000 - 2026 Rising Corp. Ltd.