瑞星卡卡安全论坛
liq1211 - 2006-11-20 20:40:00
部分网站I会E跳转www.tongxunqicai.cn和www.media-china.com.cn等网站,还出现部分网站无法打开。请问是什么问题啊,附2台机器的日志
2006-11-20,11:54:03
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows 2000 Professional Service Pack 4 (Build 2195)
- 非管理权限用户 - 受限功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Internat.exe><Internat.exe> [(Verified)Microsoft Corporation]
<msnmsgr><"C:\Program Files\MSN Messenger\msnmsgr.exe" /background> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Synchronization Manager><mobsync.exe /logon> [(Verified)Microsoft Corporation]
<MisCli><C:\MisCli.exe> [Jack]
<MisMsg><C:\MisMsg.exe> [FOCI]
<OfficeScanNT Monitor><"C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow> [Trend Micro Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINNT\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><(无)> [N/A]
==================================
启动文件夹
[Microsoft Office]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk --> C:\PROGRA~1\MICROS~2\Office\OSA9.EXE [Microsoft Corporation]><N>
==================================
服务
[Logical Disk Manager Administrative Service / dmadmin]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[OfficeScanNT 实时扫描 / ntrtscan]
<C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe><Trend Micro Inc.>
[OfficeScanNT 个人防火墙 / OfcPfwSvc]
<C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe><Trend Micro Inc.>
[OfficeScanNT 侦听程序 / tmlisten]
<C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe><Trend Micro Inc.>
[Portable Media Serial Number Service / WmdmPmSN]
<C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\system32\mspmsnsv.dll><Microsoft Corporation>
==================================
驱动程序
[atirage3 / atirage3]
<system32\DRIVERS\atimpab.sys><ATI Technologies Inc.>
[Cdr4_2K / Cdr4_2K]
<C:\WINNT\SYSTEM32\DRIVERS\Cdr4_2K.SYS><Roxio>
[Cdralw2k / Cdralw2k]
<C:\WINNT\SYSTEM32\DRIVERS\Cdralw2k.SYS><Roxio>
[Legend DFE-530TX PCI Fast Ethernet Adapter / dlkfet]
<system32\DRIVERS\dlkfet.sys><Fast Ethernet PCI Adapter Manufacturer>
[dmboot / dmboot]
<System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio]
<\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload]
<\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Trend Micro Filter / TmFilter]
<\??\C:\Program Files\Trend Micro\OfficeScan Client\TmFilter.sys><Trend Micro Inc.>
[Trend Micro VSAPI NT / VSApiNt]
<\??\C:\Program Files\Trend Micro\OfficeScan Client\VSApiNt.sys><Trend Micro Inc.>
liq1211 - 2006-11-20 20:41:00
浏览器加载项
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx, >
[CibaCtrl Class]
{8DE0FCD4-5EB5-11D3-AD25-00002100131B} <d:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
[JoyoCtrl Class]
{C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} <d:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll, >
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[@msdxmLC.dll,-1@2052,电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
[ObjWinNTCheck Class]
{00134F72-5284-44F7-95A8-52A619F70751} <C:\WINNT\Downloaded Program Files\WinNTChk.dll, Trend Micro Inc.>
[OfficeScan Corp Edition Web-Deployment SetupINICtrl Class]
{08D75BB0-D2B5-11D1-88FC-0080C859833B} <C:\WINNT\Downloaded Program Files\OfficeScanSetupINI.dll, Trend Micro Inc.>
[OfficeScan Corp Edition Web-Deployment SetupCtrl Class]
{08D75BC1-D2B5-11D1-88FC-0080C859833B} <C:\WINNT\Downloaded Program Files\OfficeScanSetup.dll, Trend Micro Inc.>
[Encrypt Class]
{35C3D91E-401A-4E45-88A5-F3B32CD72DF4} <C:\WINNT\Downloaded Program Files\AtxEnc.dll, Trend Micro Inc.>
[OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class]
{5EFE8CB1-D095-11D1-88FC-0080C859833B} <C:\WINNT\Downloaded Program Files\OfficeScanRemoveCtrl.dll, Trend Micro Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
==================================
正在运行的进程
[PID: 1048][C:\WINNT\Explorer.EXE] [Microsoft Corporation, 5.00.3700.6690]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] [, 1, 0, 0, 1]
[PID: 1132][C:\MisCli.exe] [Jack, 1.00]
[C:\WINNT\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8169]
[C:\WINNT\system32\WINSKCHS.DLL] [Microsoft Corporation, 6.00.8163]
[PID: 1140][C:\MisMsg.exe] [FOCI, 1.00]
[C:\WINNT\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8169]
[PID: 1148][C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe] [Trend Micro Inc., 6.5.0.1303]
[C:\Program Files\Trend Micro\OfficeScan Client\loadhttp.dll] [Trend Micro Inc., 6.5.0.1303]
[C:\Program Files\Trend Micro\OfficeScan Client\Pwd.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInAPI.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll] [N/A, N/A]
[C:\Program Files\Trend Micro\OfficeScan Client\TimeString.dll] [N/A, N/A]
[C:\Program Files\Trend Micro\OfficeScan Client\ntmonres.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInMain.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInTray.dll] [Trend Micro Inc., 6.5.0.1106]
[PID: 1156][C:\WINNT\system32\Internat.exe] [Microsoft Corporation, 5.00.2920.0000]
[PID: 1052][C:\Program Files\wnwb\wnwb.exe] [深圳世强软件开发部 www.wn51.com , 2006, 10, 20, 1]
[C:\Program Files\wnwb\flyDll.dll] [N/A, N/A]
[C:\Program Files\wnwb\2304wnmkey.dll] [深圳世强软件开发部 www.wnwb.com , 2005, 7, 5, 1]
[PID: 308][C:\WINNT\system32\conime.exe] [Microsoft Corporation, 5.00.2195.6655]
[PID: 1228][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2800.1106]
[C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] [, 1, 0, 0, 1]
[C:\WINNT\system32\Macromed\Flash\Flash8.ocx] [Macromedia, Inc., 8,0,22,0]
[PID: 1212][C:\Program Files\Foxmail\Foxmail.exe] [Boda Network Technology Inc., 5.0]
[C:\Program Files\Foxmail\FoxAntiSpam.dll] [N/A, N/A]
[C:\Program Files\Foxmail\3rdParty\punylib.dll] [CNNIC, 1, 0, 0, 3]
[PID: 844][C:\Documents and Settings\908027\桌面\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
[D:\]
[autorun]
OPEN=D:\command.com
==================================
HOSTS 文件
127.0.0.1 localhost
203.191.148.73 www.eachwe.com
127.0.0.1 www.tongxunqicai.cn
127.0.0.1 www.media-china.com.cn
liq1211 - 2006-11-20 20:41:00
2006-11-20,16:32:19
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Internat.exe><Internat.exe> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Synchronization Manager><mobsync.exe /logon> [(Verified)Microsoft Corporation]
<Cmaudio><RunDll32 cmicnfg.cpl,CMICtrlWnd> [N/A]
<IgfxTray><C:\WINNT\system32\igfxtray.exe> [(Verified)Intel Corporation]
<HotKeysCmds><C:\WINNT\system32\hkcmd.exe> [(Verified)Intel Corporation]
<OfficeScanNT Monitor><"C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow> [Trend Micro Inc.]
<stup.exe><C:\PROGRA~1\TENCENT\Adplus\stup.exe> [Tencent]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINNT\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><(无)> [N/A]
==================================
启动文件夹
[Microsoft Office]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk --> C:\PROGRA~1\MICROS~2\Office\OSA9.EXE [Microsoft Corporation]><N>
[腾讯QQ]
<C:\Documents and Settings\858004\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><N>
==================================
服务
[Logical Disk Manager Administrative Service / dmadmin]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[InstallDriver Table Manager / IDriverT]
<C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe><Macrovision Corporation>
[OfficeScanNT 实时扫描 / ntrtscan]
<C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe><Trend Micro Inc.>
[OfficeScanNT 个人防火墙 / OfcPfwSvc]
<C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe><Trend Micro Inc.>
[OfficeScanNT 侦听程序 / tmlisten]
<C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe><Trend Micro Inc.>
==================================
驱动程序
[Cdr4_2K / Cdr4_2K]
<C:\WINNT\SYSTEM32\DRIVERS\Cdr4_2K.SYS><Roxio>
[Cdralw2k / Cdralw2k]
<C:\WINNT\SYSTEM32\DRIVERS\Cdralw2k.SYS><Roxio>
[C-Media WDM Audio Interface / cmuda]
<system32\drivers\cmuda.sys><C-Media Inc>
[dmboot / dmboot]
<System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio]
<\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload]
<\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[ialm / ialm]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[npkcrypt / npkcrypt]
<\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Trend Micro Filter / TmFilter]
<\??\C:\Program Files\Trend Micro\OfficeScan Client\TmFilter.sys><Trend Micro Inc.>
==================================
浏览器加载项
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx, >
[Tencent Browser Helper]
{0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\Adplus\SSAddr.dll, Tencent>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[SSBandLoader Class]
{D3A3C954-41C2-4AA1-B011-9D9B0306AC23} <C:\Program Files\RichSpark\StockStar4Standard\SSBand\StockStarBand.dll, StockStar>
[StockStarToolBand Class]
{A2F82B60-F338-11D3-A74A-009027A7903D} <C:\Program Files\RichSpark\StockStar4Standard\SSBand\StockStarBand.dll, StockStar>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[@msdxmLC.dll,-1@2052,电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
[StockStarToolBand Class]
{000FCCCE-C733-11D3-A704-009027A7903D} <C:\Program Files\RichSpark\StockStar4Standard\SSBand\StockStarBand.dll, StockStar>
[ObjWinNTCheck Class]
{00134F72-5284-44F7-95A8-52A619F70751} <C:\WINNT\Downloaded Program Files\WinNTChk.dll, Trend Micro Inc.>
[OfficeScan Corp Edition Web-Deployment SetupINICtrl Class]
{08D75BB0-D2B5-11D1-88FC-0080C859833B} <C:\WINNT\Downloaded Program Files\OfficeScanSetupINI.dll, Trend Micro Inc.>
[OfficeScan Corp Edition Web-Deployment SetupCtrl Class]
{08D75BC1-D2B5-11D1-88FC-0080C859833B} <C:\WINNT\Downloaded Program Files\OfficeScanSetup.dll, Trend Micro Inc.>
[Encrypt Class]
{35C3D91E-401A-4E45-88A5-F3B32CD72DF4} <C:\WINNT\Downloaded Program Files\AtxEnc.dll, Trend Micro Inc.>
[OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class]
{5EFE8CB1-D095-11D1-88FC-0080C859833B} <C:\WINNT\Downloaded Program Files\OfficeScanRemoveCtrl.dll, Trend Micro Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
liq1211 - 2006-11-20 20:44:00
正在运行的进程
[PID: 152][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 176][\??\C:\WINNT\system32\csrss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 196][\??\C:\WINNT\system32\winlogon.exe] [Microsoft Corporation, 5.00.2195.6898]
[PID: 224][C:\WINNT\system32\services.exe] [Microsoft Corporation, 5.00.2195.6700]
[C:\WINNT\system32\dmserver.dll] [VERITAS Software Corp., 2195.6605.297.3]
[PID: 236][C:\WINNT\system32\lsass.exe] [Microsoft Corporation, 5.00.2195.6902]
[PID: 392][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 448][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 504][C:\WINNT\system32\spoolsv.exe] [Microsoft Corporation, 5.00.2195.6659]
[PID: 604][C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe] [Trend Micro Inc., 6.5.0.1303]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcDog.dll] [Trend Micro Inc., 6.5.0.1303]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInAPI.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\TimeString.dll] [N/A, N/A]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll] [N/A, N/A]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInMain.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInTray.dll] [Trend Micro Inc., 6.5.0.1106]
[PID: 712][C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe] [Trend Micro Inc., 6.5.0.1303]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwCommon.dll] [N/A, N/A]
[C:\Program Files\Trend Micro\OfficeScan Client\ZLib.dll] [Trend Micro Inc., 1.31.0.1708]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll] [N/A, N/A]
[C:\Program Files\Trend Micro\OfficeScan Client\tmCfwApi.dll] [Trend Micro Inc., 1.2.0.1020]
[PID: 732][C:\WINNT\system32\regsvc.exe] [Microsoft Corporation, 5.00.2195.6701]
[PID: 752][C:\WINNT\system32\MSTask.exe] [Microsoft Corporation, 4.71.2195.6704]
[PID: 776][C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe] [Trend Micro Inc., 6.5.0.1303]
[C:\Program Files\Trend Micro\OfficeScan Client\TMSOCK.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\loadhttp.dll] [Trend Micro Inc., 6.5.0.1303]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInAPI.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll] [N/A, N/A]
[C:\Program Files\Trend Micro\OfficeScan Client\libTmCAV.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\Pwd.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcDog.dll] [Trend Micro Inc., 6.5.0.1303]
[C:\Program Files\Trend Micro\OfficeScan Client\TmUpdate.dll] [Trend Micro Inc., 1,81,0,1043]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInMain.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInTray.dll] [Trend Micro Inc., 6.5.0.1106]
[PID: 832][C:\WINNT\System32\WBEM\WinMgmt.exe] [Microsoft Corporation, 1.50.1085.0100]
[PID: 856][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\msxml3.dll] [Microsoft Corporation, 8.30.9926.0]
[PID: 876][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 1164][C:\WINNT\TEMP\UJ814B.EXE] [N/A, N/A]
[PID: 1072][C:\WINNT\Explorer.EXE] [Microsoft Corporation, 5.00.3700.6690]
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] [Tencent, 4, 3, 3, 31]
[C:\WINNT\system32\igfxpph.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\hccutils.DLL] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\igfxres.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\igfxsrvc.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\igfxdev.dll] [Intel Corporation, 3,0,0,2104]
[C:\Program Files\TENCENT\Adplus\SSAddr.dll] [Tencent, 4, 3, 3, 31]
[C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] [, 1, 0, 0, 1]
[PID: 1248][C:\WINNT\system32\RunDll32.exe] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system\cmicnfg.cpl] [C-Media Corporation, 1, 0, 41, 6]
[C:\WINNT\System32\udaprop.dll] [C-Media Corporation, 1.0.2.2]
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] [Tencent, 4, 3, 3, 31]
[PID: 1296][C:\WINNT\system32\igfxtray.exe] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\hccutils.DLL] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\igfxdev.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\igfxsrvc.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\igfxres.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\igfxress.dll] [Intel Corporation, 3,0,0,2104]
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] [Tencent, 4, 3, 3, 31]
[PID: 1312][C:\WINNT\system32\hkcmd.exe] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\hccutils.DLL] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\igfxdev.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\igfxsrvc.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\igfxhk.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINNT\system32\igfxres.dll] [Intel Corporation, 3,0,0,2104]
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] [Tencent, 4, 3, 3, 31]
[PID: 1348][C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe] [Trend Micro Inc., 6.5.0.1303]
[C:\Program Files\Trend Micro\OfficeScan Client\loadhttp.dll] [Trend Micro Inc., 6.5.0.1303]
[C:\Program Files\Trend Micro\OfficeScan Client\Pwd.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInAPI.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll] [N/A, N/A]
[C:\Program Files\Trend Micro\OfficeScan Client\TimeString.dll] [N/A, N/A]
[C:\Program Files\Trend Micro\OfficeScan Client\ntmonres.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInMain.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInTray.dll] [Trend Micro Inc., 6.5.0.1106]
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] [Tencent, 4, 3, 3, 31]
[PID: 1332][C:\WINNT\system32\Internat.exe] [Microsoft Corporation, 5.00.2920.0000]
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] [Tencent, 4, 3, 3, 31]
[PID: 1384][C:\WINNT\system32\wuauclt.exe] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] [Tencent, 4, 3, 3, 31]
[PID: 1404][C:\WINNT\system32\conime.exe] [Microsoft Corporation, 5.00.2195.6655]
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] [Tencent, 4, 3, 3, 31]
liq1211 - 2006-11-20 20:44:00
[PID: 1516][C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE] [Microsoft Corporation, 9.0.2416]
[C:\PROGRA~1\MICROS~2\Office\OUTLLIB.dll] [Microsoft Corporation, 9.0.3011]
[C:\PROGRA~1\MICROS~2\Office\MSO9.DLL] [Microsoft Corporation, 9.0.2812]
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] [Tencent, 4, 3, 3, 31]
[C:\PROGRA~1\MICROS~2\Office\2052\outllibr.dll] [Microsoft Corporation, 9.0.3011]
[C:\Program Files\Common Files\System\MAPI\2052\nt\omint.dll] [Microsoft Corporation, 5.5.2809.0]
[C:\PROGRA~1\MICROS~2\Office\OUTLRPC.dll] [Microsoft Corporation, 9.0.2601]
[C:\Program Files\Common Files\System\MAPI\2052\nt\PSTPRX32.DLL] [Microsoft Corporation, 9.0]
[C:\Program Files\Common Files\System\MAPI\2052\nt\OMIPSTNT.DLL] [Microsoft Corporation, 5.5.2806.0]
[C:\PROGRA~1\MICROS~2\Office\OUTLMIME.DLL] [Microsoft Corporation, 9.0.2910.0]
[C:\Program Files\Common Files\System\MAPI\2052\NT\ExSec32.dll] [Microsoft Corporation, 5.5.2561.0]
[C:\PROGRA~1\MICROS~2\Office\2052\OBALLOON.DLL] [Microsoft Corporation, 9.0.2720]
[C:\PROGRA~1\MICROS~2\Office\BLNMGRPS.DLL] [N/A, N/A]
[C:\PROGRA~1\MICROS~2\Office\RTFHTML.dll] [Microsoft Corporation, 9.0.2603]
[C:\WINNT\system32\OUTLWAB.DLL] [Microsoft Corporation, 9.0.2605]
[PID: 1584][C:\WINNT\msagent\AgentSvr.exe] [Microsoft Corporation, 2.00.0.3422]
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] [Tencent, 4, 3, 3, 31]
[C:\Program Files\Microsoft Office\Office\BLNMGR.DLL] [N/A, N/A]
[PID: 1416][C:\Program Files\Tencent\QQ\QQ.exe] [TENCENT, 0, 0, 0, 0]
[C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQHelperDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\BasicCtrlDll.dll] [Tencent, 5, 0, 200, 14]
[C:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] [Tencent, 4, 3, 3, 31]
[C:\Program Files\Tencent\QQ\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
[C:\Program Files\Tencent\QQ\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
[C:\Program Files\Tencent\QQ\QQAPI.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[C:\Program Files\Tencent\QQ\LoginCtrl.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\npkcntc.dll] [INCA Internet Co., Ltd., 2005, 9, 1, 1]
[C:\Program Files\Tencent\QQ\npkpdb.dll] [INCA Internet Co., Ltd., 2003, 10, 1, 1]
[C:\Program Files\Tencent\QQ\QQRes.dll] [tencent, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\WizardCtrl.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQMainFrame.dll] [N/A, N/A]
[C:\WINNT\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\Program Files\Tencent\QQ\CQQApplication.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\NewSkin.dll] [, 1, 0, 0, 1]
[C:\WINNT\system32\MSVCP60.dll] [Microsoft Corporation, 6.00.8168.0]
[C:\Program Files\Tencent\QQ\HostingMgr.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\CameraDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\MailSummary.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQSpace.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\vbscript.dll] [Microsoft Corporation, 5.6.0.7426]
[C:\WINNT\system32\msdmo.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQGroupMng.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\UserDefinedHead.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQPlugin.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQConfigPlugin.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QRingMng.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\PhoneAPI.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[C:\Program Files\Tencent\QQ\QQAvatar.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[C:\Program Files\Tencent\QQ\LongConnection.dll] [tencent, 5, 0, 201, 14]
[C:\Program Files\Tencent\QQ\QQPet.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQSysMsgMng.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\BQQApplication.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\CommercesMng.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
[C:\Program Files\Tencent\QQ\QQUdpGetFileLib.dll] [tencent, 0, 2, 2, 3]
[C:\Program Files\Tencent\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 140]
[C:\Program Files\Tencent\QQ\ShareFiles.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQZip.dll] [tencent, 0, 3, 2, 4]
[C:\Program Files\Tencent\QQ\QQSceneMng.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQPhoneHelper.dll] [腾讯科技(深圳)有限公司, 2, 0, 6, 60]
[C:\Program Files\Tencent\QQ\QQAllInOne.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\SCCore.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Tencent\QQ\QQCustomFace.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\GroupConnection.dll] [Tencent, 5, 0, 202, 30]
[C:\Program Files\Tencent\QQ\QQMsgFriendMng.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQFileTransfer.dll] [Tencent, 5, 0, 202, 40]
[C:\Program Files\Tencent\QQ\QQMagicFace.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQGame\GameLogCore.Dll] [, 0, 10, 106, 13]
[C:\Program Files\Tencent\QQGame\Core.dll] [é??úêDìú???????ú?μí3óD?T1???, 0, 10, 0, 0]
[C:\Program Files\Tencent\QQGame\NetCenter.dll] [é??úêDìú???????ú?μí3óD?T1???, 0, 10, 0, 0]
[C:\Program Files\Tencent\QQGame\CmdCenter.dll] [深圳市腾讯计算机系统有限公司, 0, 10, 0, 0]
[C:\Program Files\Tencent\QQGame\HelpDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQGame\ResEx.dll] [深圳市腾讯计算机系统有限公司, 0, 10, 0, 0]
[C:\Program Files\Tencent\QQGame\GameLogAidMgr.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQGame\COMToolKit.dll] [, 1, 0, 0, 3]
[C:\Program Files\Tencent\QQGame\QQGameAvatar.dll] [深圳市腾讯计算机系统有限公司 Tencent Computer System Ltd., 0, 10, 0, 0]
[C:\Program Files\Tencent\QQ\ImageOle.dll] [TODO: <Company name>, 1.0.0.1]
[PID: 1428][C:\Program Files\Tencent\QQ\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] [Tencent, 4, 3, 3, 31]
[C:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 1172][C:\Documents and Settings\858004\桌面\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\Program Files\TENCENT\Adplus\Adplus1.dll] [Tencent, 4, 3, 3, 31]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
liq1211 - 2006-11-20 20:45:00
各位高手:
非常感谢您留心我这份系统诊断报告,小菜鸟十万火急等待您的帮助!
该诊断报告由360安全卫士提供 http://www.360safe.com
诊断时间: 2006-11-20 16:32:36
诊断平台: Microsoft Windows 2000 Service Pack 4
IE版本: Internet Explorer V6.0.2800.1106 Build:62800.1106
计算机物理内存:247MB - 当前可用内存:24MB
100 - 未知 - Process: UJ814B.EXE [] - C:\WINNT\TEMP\UJ814B.EXE
R0 - 未知 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.qq.com/
R1 - 未知 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://www.google.com
O2 - 未知 - BHO: (SSBandLoader Class) - [StockStarBand Module] - {D3A3C954-41C2-4AA1-B011-9D9B0306AC23} - C:\Program Files\RichSpark\StockStar4Standard\SSBand\StockStarBand.dll
O3 - 未知 - Toolbar: (StockStarToolBand Class) - [StockStarBand Module] - {000FCCCE-C733-11D3-A704-009027A7903D} - C:\Program Files\RichSpark\StockStar4Standard\SSBand\StockStarBand.dll
O8 - 未知 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - 未知 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - 未知 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - 未知 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - 未知 - Extra button: 财神通(HKLM) - C:\Program Files\RichSpark\StockStar4Standard\SSBand\StockStarBand.dll
O9 - 未知 - Extra button: 腾讯QQ(HKLM) - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 未知 - Extra button: QQ炫彩工具条设置(HKLM) - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O11 - 未知 - Options Group: 中文搜搜
O16 - 未知 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupINICtrl) - https://192.168.66.20/officescan/console/ClientInstall/setupini.cab
O16 - 未知 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupCtrl) - https://192.168.66.20/officescan/console/ClientInstall/setup.cab
O16 - 未知 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} (Encrypt) - https://192.168.66.20/officescan/console/html/AtxEnc.cab
O16 - 未知 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl) - https://192.168.66.20/officescan/console/ClientInstall/RemoveCtrl.cab
O23 - 未知 - Service: ntrtscan [OfficeScanNT 实时扫描] - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - 未知 - Service: OfcPfwSvc [OfficeScanNT 个人防火墙] - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - 未知 - Service: tmlisten [OfficeScanNT 侦听程序] - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
=======================================
100 - 安全 - Process: smss.exe [该进程为会话管理子系统用以初始化系统变量,ms-dos驱动名称类似lpt1以及com,调用win32壳子系统和运行在windows登陆过程。] - C:\WINNT\System32\smss.exe
100 - 安全 - Process: csrss.exe [客户端服务子系统,用以控制windows图形相关子系统。] -
100 - 安全 - Process: WINLOGON.EXE [windows nt用户登陆程序。] - C:\WINNT\system32\winlogon.exe
100 - 安全 - Process: services.exe [用于管理windows服务系统进程。] - C:\WINNT\system32\services.exe
100 - 安全 - Process: LSASS.EXE [本地安全权限服务控制windows安全机制。] - C:\WINNT\system32\lsass.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINNT\system32\svchost -k rpcss
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINNT\system32\svchost.exe -k netsvcs
100 - 安全 - Process: SPOOLSV.EXE [windows打印任务控制程序,用以打印机就绪。] - C:\WINNT\system32\spoolsv.exe
100 - 安全 - Process: NTRtScan.exe [trend micro防病毒厂商出品的企业版反病毒程序。] - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
100 - 安全 - Process: OfcPfwSvc.exe [trend micro公司出品officescan是一款企业级反病毒程序。] - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
100 - 安全 - Process: regsvc.exe [远程注册表服务用于访问在远程计算机的注册表。] - C:\WINNT\system32\regsvc.exe
100 - 安全 - Process: mstask.exe [windows计划任务用于设定继承在什么时间或者什么日期备份或者运行。] - C:\WINNT\system32\MSTask.exe
100 - 安全 - Process: TmListen.exe [趋势防病毒公司出品的防病软件的一部分。] - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
100 - 安全 - Process: winmgmt.exe [windows management service透过windows management instrumentation data (wmi)技术处理来自应用客户端的请求。] - C:\WINNT\System32\WBEM\WinMgmt.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINNT\system32\svchost.exe -k wugroup
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINNT\system32\svchost.exe -k BITSgroup
100 - 安全 - Process: explorer.exe [windows program manager或者windows explorer用于控制windows图形shell,包括开始菜单、任务栏,桌面和文件管理。] - C:\WINNT\Explorer.EXE
100 - 安全 - Process: rundll32.exe [windows rundll32为了需要调用dlls的程序。] - C:\WINNT\system32\RunDll32.exe
100 - 安全 - Process: igfxtray.exe [intel显卡相关软件。] - C:\WINNT\system32\igfxtray.exe
100 - 安全 - Process: hkcmd.exe [intel显卡驱动相关软件。] - C:\WINNT\system32\hkcmd.exe
100 - 安全 - Process: PccNTMon.exe [trend micro公司出品的officescan 监控程序。] - C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
100 - 安全 - Process: internat.exe [输入控制图标用于更改类似国家设置、键盘类型和日期格式。] - C:\WINNT\system32\Internat.exe
100 - 安全 - Process: wuauclt.exe [windows操作系统后台程序,用于系统升级。] - C:\WINNT\system32\wuauclt.exe
100 - 安全 - Process: conime.exe [console ime ime输入法控制台软件。] - C:\WINNT\system32\conime.exe
100 - 安全 - Process: OUTLOOK.EXE [microsoft office办公套件的一部分,outlook用于邮件收发和信息管理。] - C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
100 - 安全 - Process: agentsvr.exe [是一个ActiveX插件,用于多媒体程序。] - C:\WINNT\msagent\AgentSvr.exe -Embedding
100 - 安全 - Process: QQ.exe [腾讯公司出品的qq即时通讯软件。] - C:\Program Files\Tencent\QQ\QQ.exe
100 - 安全 - Process: TIMPlatform.exe [腾讯即时通讯客户端软件的一部分。] - C:\Program Files\Tencent\QQ\TIMPlatform.exe
100 - 安全 - Process: 360Safe.exe [360安全卫士相关程序。] - C:\Program Files\360safe\360Safe.exe
R1 - 安全 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINNT\system32\blank.htm
R1 - 安全 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINNT\system32\blank.htm
R3 - 安全 - URLSearchHook: (Tencent SearchHook) - [搜搜工具条,搜索工具栏。] - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\Adplus\SSAddr.dll
R3 - 安全 - URLSearchHook: (Tencent SearchHook) - [搜搜工具条,搜索工具栏。] - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\Adplus\SSAddr.dll
O2 - 安全 - BHO: (AcroIEHlprObj Class) - [Adobe Reader, 查看和打印 Adobe 便携文档格式 (PDF) 文件。] - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - 安全 - BHO: (Tencent Browser Helper) - [搜搜工具条,搜索工具栏。] - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\Program Files\TENCENT\Adplus\SSAddr.dll
O2 - 安全 - BHO: (QQBrowserHelperObject Class) - [腾讯QQ的一个插件。] - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O3 - 安全 - Toolbar: (@msdxmLC.dll,-1@2052,电台(&R)) - [是Windows Media Player播放器ActiveX控制相关文件。] - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - 安全 - HKLM\..\Run: [Synchronization Manager] [资料同步管理器] mobsync.exe /logon
O4 - 安全 - HKLM\..\Run: [Cmaudio] [vxd驱动程序需要] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - 安全 - HKLM\..\Run: [IgfxTray] [是Intel显卡配置和诊断程序,会同Intel 810芯片组的集成显卡安装。] C:\WINNT\system32\igfxtray.exe
O4 - 安全 - HKLM\..\Run: [HotKeysCmds] [是Intel显示卡相关程序,用于配置和诊断相关设备。] C:\WINNT\system32\hkcmd.exe
O4 - 安全 - HKLM\..\Run: [OfficeScanNT Monitor] [trend micro公司出品的officescan 监控程序。] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - 安全 - HKLM\..\Run: [stup.exe] [腾讯qq地址栏搜索插件相关程序。] C:\PROGRA~1\TENCENT\Adplus\stup.exe
O4 - 安全 - HKCU\..\Run: [Internat.exe] [输入法在任务栏里的图标] Internat.exe
O4 - 安全 - Startup folder: [Microsoft Office.lnk] [是offfice的一个快捷方式。 ] C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk
O4 - 安全 - Startup folder: [腾讯QQ.lnk] [qq:即时通讯软件] C:\Documents and Settings\858004\「开始」菜单\程序\启动\腾讯QQ.lnk
O9 - 安全 - Extra button: 电台(HKLM) - C:\WINNT\web\related.htm
O16 - 安全 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} (趋势科技) - https://192.168.66.20/officescan/console/ClientInstall/WinNTChk.cab
O16 - 安全 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Flash播放器) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O23 - 安全 - Service: Fax [微软Microsoft传真服务相关程序,该服务允许用户创建和发送传真到微软Office组件中。] - C:\WINNT\system32\faxsvc.exe
=======================================
040 - Explorer.EXE - Tencent - C:\Program Files\TENCENT\Adplus\Adplus1.dll -
040 - RunDll32.exe - Tencent - C:\Program Files\TENCENT\Adplus\Adplus1.dll -
=======================================
041 - npkcrypt - nProtect KeyCrypt Driver - C:\Program Files\Tencent\QQ\npkcrypt.sys
=======================================
360Safe.exe=2.1.5.1000
AntiAdwa.dll=2.0.1.3002
AntiEng.dll=2.0.1.3001
AntiActi.dll=2.0.0.3000
CleanHis.dll=2.0.0.1001
safelive.exe=1.0.0.2007
live.dll=1.0.0.1011
=======================================
操作历史报告:
=======================================
360安全卫士,彻底查杀各种流氓软件,全面保护系统安全,并赠送正版卡巴斯基V6.0
最新免费下载:http://www.360safe.com
秋日里的蓝天 - 2006-11-20 23:33:00
1
© 2000 - 2026 Rising Corp. Ltd.