竹竿 - 2006-11-28 10:52:00
2006-11-27,17:49:09
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<Super Rabbit IEPro><D:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD> [Super Rabbit Soft]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<KAVPersonal50><"D:\Kaspersky Anti-Virus Personal\kav.exe" /minimize> [Kaspersky Lab]
<IgfxTray><; C:\WINDOWS\system32\igfxtray.exe> [(Verified)Intel Corporation]
<HotKeysCmds><; C:\WINDOWS\system32\hkcmd.exe> [(Verified)Intel Corporation]
<HP Component Manager><; "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"> [Hewlett-Packard Company]
<HPDJ Taskbar Utility><; C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe> [(Verified)HP]
<HP Software Update><; "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"> [Hewlett-Packard Company]
<StormCodec_Helper><; "e:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> [N/A]
<mmsk><D:\Program Files\木马杀客\mmsk.exe> [www.mmsk.cn]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
==================================
启动文件夹
[腾讯QQ]
<C:\Documents and Settings\zy\「开始」菜单\程序\启动\腾讯QQ.lnk --> D:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><H>
==================================
服务
[Adobe LM Service / Adobe LM Service]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Remote Route Service / AtHome]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\qvhxtd94.dll><N/A>
[Human Interface Device Access / HidServ]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[kavsvc / kavsvc]
<"D:\Kaspersky Anti-Virus Personal\kavsvc.exe"><Kaspersky Lab>
[WindowsNt Workstation / NTWorkStan]
<C:\WINDOWS\System32\svchost.exe -k NTWorkStan-->c:\windows\system32\ntworkstan.dll><Microsoft Corporation>
[Win-SMOS / SMOSWin]
<><N/A>
[SoundMAX Agent Service / SoundMAX Agent Service (default)]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[IPSEC Client / WIDETS]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\CTEIVL75.DLL,Export 1087><N/A>
[Windows Media Connect Service / WmdmPmSp]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\WmdmPmSp.dll><LINKMEDIA Tech>
竹竿 - 2006-11-28 11:04:00
驱动程序
[aeaudio / aeaudio]
<system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[Enhanced Display Driver Helper Service / asuskbnt]
<system32\drivers\atkkbnt.sys><ASUSTeK COMPUTER INC.>
[EIO / EIO]
<\??\C:\WINDOWS\system32\drivers\EIO.sys><N/A>
[ialm / ialm]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[Kl1 / Kl1]
<\SystemRoot\System32\drivers\kl1.sys><Kaspersky Lab>
[Klif / Klif]
<System32\drivers\klif.sys><Kaspersky Labs>
[Klmc / Klmc]
<System32\drivers\klmc.sys><Kaspersky Lab>
[npkcrypt / npkcrypt]
<\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv]
<system32\DRIVERS\secdrv.sys><N/A>
[smwdm / smwdm]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[swhklh40 / swhklh40]
<\??\C:\WINDOWS\system32\drivers\swhklh40.sys><Microsoft Corporation>
[TSP / TSP]
<\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Labs>
==================================
浏览器加载项
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <D:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[启动Web迅雷]
{962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\Program Files\Tencent\QQ\QQIEHelper.dll, N/A>
[Miorosoft Office]
{7BEBDE34-060C-40E1-ABDD-ED9B0866B2C6} <C:\Program Files\Miorosoft Office\tbu00650\Miorosoft Office.dll, IE Toolbar>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <D:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[asusTek_sysctrl Class]
{0D41B8C5-2599-4893-8183-00195EC8D5F9} <C:\WINDOWS\DOWNLO~1\ASUSTE~1.DLL, >
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, N/A>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <D:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <D:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用Web迅雷下载]
<d:\Program Files\Thunder Network\WebThunder\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
<d:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm, N/A>
[使用迅雷下载]
<d:\Program Files\Thunder\geturl.htm, N/A>
[使用迅雷下载全部链接]
<d:\Program Files\Thunder\getAllurl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
竹竿 - 2006-11-28 11:04:00
正在运行的进程
[PID: 484][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 532][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 556][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 604][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 616][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 760][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 808][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 860][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[c:\windows\system32\qvhxtd94.dll] [N/A, N/A]
[c:\windows\system32\wmdmpmsp.dll] [LINKMEDIA Tech, 1, 5, 0, 4]
[PID: 968][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 996][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1212][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[c:\windows\system32\advwhes.dll] [N/A, N/A]
[c:\windows\system32\qvhxtd94.dll] [N/A, N/A]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[d:\program files\winrar\rarext.dll] [N/A, N/A]
[D:\Kaspersky Anti-Virus Personal\shellex.dll] [Kaspersky Lab, 5.0.388.1]
[PID: 1280][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\system32\hpzsnt10.dll] [HP, 2.323.0.0]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll] [Windows (R) 2000 DDK provider, 5.00.2195.1620]
[PID: 1560][D:\Program Files\木马杀客\mmsk.exe] [www.mmsk.cn, 2,0,0,5]
[D:\Program Files\木马杀客\krnln.fnr] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[D:\Program Files\木马杀客\iext.fnr] [, 1, 0, 0, 1]
[D:\Program Files\木马杀客\TrayIcon.fne] [, 1, 0, 0, 1]
[D:\Program Files\木马杀客\iext2.fne] [, 1, 0, 0, 1]
[D:\Program Files\木马杀客\iext3.fne] [, 1, 0, 0, 1]
[D:\Program Files\木马杀客\shell.fne] [N/A, N/A]
[D:\Program Files\木马杀客\xplib.fne] [N/A, N/A]
[D:\Program Files\木马杀客\dp1.fne] [N/A, N/A]
[PID: 1568][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1604][D:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE] [Super Rabbit Soft, 7.90.0001]
[D:\PROGRA~1\SUPERR~1\MagicSet\shlobj71.ocx] [Sky Software (http://www.ssware.com), 7, 1, 0, 0]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1612][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1648][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] [Analog Devices, Inc., 3, 2, 6, 0]
[PID: 1696][C:\WINDOWS\SYSTEM32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\SYSTEM32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1748][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1992][c:\windows\system32\wbem\lsass.exe] [Microsoft, 1.0.0.0]
[PID: 252][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\system32\sdmAgent30.dll] [LINKMEDIA Tech, 1, 5, 0, 8]
[PID: 524][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 528][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1792][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Program Files\Super Rabbit\MagicSet\haokanbar.dll] [Xiang Feng Technology, 2, 2, 0, 1612]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[D:\Kaspersky Anti-Virus Personal\scrchpg.dll] [Kaspersky Lab, 5.0.1.18]
[D:\Kaspersky Anti-Virus Personal\scrch_ag.dll] [Kaspersky Lab, 5.0.388.1]
[D:\Kaspersky Anti-Virus Personal\FSSync.dll] [Kaspersky Lab, 5.0.388.0]
[D:\Kaspersky Anti-Virus Personal\pr_rmt.dll] [Kaspersky Lab, 5.0.388.0]
[D:\Kaspersky Anti-Virus Personal\ccclient.dll] [Kaspersky Lab, 5.0.388.1]
[D:\Kaspersky Anti-Virus Personal\klipc.dll] [Kaspersky Lab, 5.0.388.0]
[D:\Kaspersky Anti-Virus Personal\KLUtil.dll] [Kaspersky Lab, 5.0.388.1]
[D:\Kaspersky Anti-Virus Personal\rpt.dll] [Kaspersky Lab, 5.0.388.2]
[D:\Kaspersky Anti-Virus Personal\CCIFACE.dll] [Kaspersky Lab, 5.0.388.1]
[D:\Kaspersky Anti-Virus Personal\prloader.dll] [Kaspersky Lab, 5.0.388.0]
[D:\Kaspersky Anti-Virus Personal\prkernel.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\kaspersky anti-virus personal\prstring.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\kaspersky anti-virus personal\pr_srv.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\kaspersky anti-virus personal\pr_clnt.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\kaspersky anti-virus personal\tempfile.ppl] [Kaspersky Lab, 5.0.388.0]
[PID: 3316][D:\Program Files\KuGoo3\KuGoo.exe] [, 3.2.0.90]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[D:\Program Files\KuGoo3\mp3lib.dll] [N/A, N/A]
[D:\Kaspersky Anti-Virus Personal\scrchpg.dll] [Kaspersky Lab, 5.0.1.18]
[D:\Kaspersky Anti-Virus Personal\scrch_ag.dll] [Kaspersky Lab, 5.0.388.1]
[D:\Kaspersky Anti-Virus Personal\FSSync.dll] [Kaspersky Lab, 5.0.388.0]
[D:\Kaspersky Anti-Virus Personal\pr_rmt.dll] [Kaspersky Lab, 5.0.388.0]
[D:\Kaspersky Anti-Virus Personal\ccclient.dll] [Kaspersky Lab, 5.0.388.1]
[D:\Kaspersky Anti-Virus Personal\klipc.dll] [Kaspersky Lab, 5.0.388.0]
[D:\Kaspersky Anti-Virus Personal\KLUtil.dll] [Kaspersky Lab, 5.0.388.1]
[D:\Kaspersky Anti-Virus Personal\rpt.dll] [Kaspersky Lab, 5.0.388.2]
[D:\Kaspersky Anti-Virus Personal\CCIFACE.dll] [Kaspersky Lab, 5.0.388.1]
[D:\Kaspersky Anti-Virus Personal\prloader.dll] [Kaspersky Lab, 5.0.388.0]
[D:\Kaspersky Anti-Virus Personal\prkernel.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\kaspersky anti-virus personal\prstring.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\kaspersky anti-virus personal\pr_srv.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\kaspersky anti-virus personal\pr_clnt.ppl] [Kaspersky Lab, 5.0.388.0]
[d:\kaspersky anti-virus personal\tempfile.ppl] [Kaspersky Lab, 5.0.388.0]
[D:\Program Files\KuGoo3\kgmpg.dll] [ , 1, 0, 4, 1]
[D:\Program Files\KuGoo3\mp3parse.dll] [ , 1, 0, 2, 1]
[D:\Program Files\KuGoo3\APEDecode.dll] [RadLight, 1, 0, 0, 4]
[D:\Program Files\KuGoo3\OggSplitter.dll] [RadLight, 1.0.0.2]
[D:\Program Files\KuGoo3\OggDecode.dll] [RadLight, 1, 0, 1, 1]
[PID: 2552][C:\DOCUME~1\zy\LOCALS~1\Temp\Rar$EX02.516\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.2localhost
竹竿 - 2006-11-29 13:57:00
惨了,流氓还在,只是潜伏了。
各位高手:
非常感谢您留心我这份系统诊断报告,小菜鸟十万火急等待您的帮助!
该诊断报告由360安全卫士提供 http://www.360safe.com
诊断时间: 2006-11-29 13:41:09
诊断平台: Microsoft Windows XP Service Pack 2
IE版本: Internet Explorer V6.0.2900.2180 Build:62900.2180
计算机物理内存:246MB - 当前可用内存:138MB
O8 - 未知 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - 未知 - Extra context menu item: 使用迅雷下载 - d:\Program Files\Thunder\geturl.htm
O8 - 未知 - Extra context menu item: 使用迅雷下载全部链接 - d:\Program Files\Thunder\getAllurl.htm
O18 - 未知 - Protocol: CZipHandler Object - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O23 - 未知 - Service: AtHome [网络通讯路由服务,提供临时的网络路由和服务地址的快速解析功能。无法终止此服务。] - C:\WINDOWS\System32\svchost.exe -k netsvcs - (not running)
O23 - 未知 - Service: kavsvc [kavsvc] - "D:\Kaspersky Anti-Virus Personal\kavsvc.exe" - (not running)
O23 - 未知 - Service: SMOSWin [Windows SMOS Servers 自动服务。如果服务被停止,Windown VMwvare 服务进行无法操作。如果服务被禁用,任何依赖它的服务将无法启动。] - - (not running)
O23 - 未知 - Service: WIDETS [管理 IP 安全客户端策略以及启动,为 IP 安全驱动程序提供存储支持。] - C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\CTEIVL75.DLL,Export 1087 - (not running)
O23 - 未知 - Service: WmdmPmSp [使用“通用即插即用”与媒体设备共享媒体。] - C:\WINDOWS\system32\WmdmPmSp.dll - (not running)
=======================================
100 - 安全 - Process: smss.exe [进程为会话管理子系统用以初始化系统变量,ms-dos驱动名称类似lpt1以及com,调用win32壳子系统和运行在windows登陆过程。] - C:\WINDOWS\System32\smss.exe
100 - 安全 - Process: csrss.exe [客户端服务子系统,用以控制windows图形相关子系统。] - C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=base
100 - 安全 - Process: winlogon.exe [windows nt用户登陆程序。] - C:\WINDOWS\system32\winlogon.exe
100 - 安全 - Process: services.exe [用于管理windows服务系统进程。] - C:\WINDOWS\system32\services.exe
100 - 安全 - Process: lsass.exe [本地安全权限服务控制windows安全机制。] - C:\WINDOWS\system32\lsass.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k DcomLaunch
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k rpcss
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k netsvcs
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k NetworkService
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k LocalService
100 - 安全 - Process: explorer.exe [windows program manager或者windows explorer用于控制windows图形shell,包括开始菜单、任务栏,桌面和文件管理。] - C:\WINDOWS\Explorer.EXE
100 - 安全 - Process: 360Safe.exe [360安全卫士] - D:\360safe\360Safe.exe
100 - 安全 - Process: ctfmon.exe [office xp输入法图标。] - C:\WINDOWS\system32\ctfmon.exe
R1 - 安全 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=about:blank
R1 - 安全 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=about:blank
O2 - 安全 - BHO: (超级兔子上网精灵) - [超级兔子上网精灵相关插件。] - {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} - D:\Program Files\Super Rabbit\MagicSet\haokanbar.dll
O3 - 安全 - Toolbar: (超级兔子上网精灵) - [超级兔子上网精灵工具条,随超级兔子软件捆绑安装。] - {43869BB3-22FD-4F15-9B46-238106BA2F4E} - D:\Program Files\Super Rabbit\MagicSet\haokanbar.dll
O4 - 安全 - HKLM\..\Run: [IMJPMIG8.1] [微软Microsoft输入法编辑器程序。] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 安全 - HKLM\..\Run: [PHIME2002ASync] [输入法软件相关程序。] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 安全 - HKLM\..\Run: [PHIME2002A] [输入法软件相关程序。] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 安全 - HKLM\..\Run: [KAVPersonal50] [kaspersky labs公司出品的卡巴斯基反病毒软件的一部分。] "D:\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - 安全 - HKLM\..\Run: [IgfxTray] [是Intel显卡配置和诊断程序,会同Intel 810芯片组的集成显卡安装。] ; C:\WINDOWS\system32\igfxtray.exe
O4 - 安全 - HKLM\..\Run: [HotKeysCmds] [是Intel显示卡相关程序,用于配置和诊断相关设备。] ; C:\WINDOWS\system32\hkcmd.exe
O4 - 安全 - HKCU\..\Run: [ctfmon.exe] [office xp输入法图标。] C:\WINDOWS\system32\ctfmon.exe
O4 - 安全 - HKCU\..\Run: [Super Rabbit IEPro] [超级兔子ie保护专家] D:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD
O8 - 安全 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O16 - 安全 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Flash播放器) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O18 - 安全 - Protocol: OFFICE 相关 - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O23 - 安全 - Service: Adobe LM Service [adobe公司相关产品的许可服务程序。] - "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe" - (not running)
O23 - 安全 - Service: SoundMAX Agent Service (default) [是Analog SoundMAX声卡产品相关程序。] - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe - (not running)
=======================================
O40 - winlogon.exe - SoundMAX - C:\WINDOWS\system32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver - bd9b4450d00d4ac891407b8c0e08de9c
O40 - services.exe - SoundMAX - C:\WINDOWS\system32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver - bd9b4450d00d4ac891407b8c0e08de9c
O40 - lsass.exe - SoundMAX - C:\WINDOWS\system32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver - bd9b4450d00d4ac891407b8c0e08de9c
O40 - svchost.exe - SoundMAX - C:\WINDOWS\system32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver - bd9b4450d00d4ac891407b8c0e08de9c
O40 - svchost.exe - SoundMAX - C:\WINDOWS\system32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver - bd9b4450d00d4ac891407b8c0e08de9c
O40 - svchost.exe - SoundMAX - C:\WINDOWS\system32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver - bd9b4450d00d4ac891407b8c0e08de9c
O40 - svchost.exe - SoundMAX - C:\WINDOWS\system32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver - bd9b4450d00d4ac891407b8c0e08de9c
O40 - svchost.exe - SoundMAX - C:\WINDOWS\system32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver - bd9b4450d00d4ac891407b8c0e08de9c
O40 - Explorer.EXE - SoundMAX - C:\WINDOWS\system32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver - bd9b4450d00d4ac891407b8c0e08de9c
=======================================
O41 - asuskbnt - ASUS Help driver For Keyboard Service. - C:\WINDOWS\system32\drivers\atkkbnt.sys - (not running) - ASUS Help driver For Keyboard Service. - ASUSTeK COMPUTER INC. - f5c2ccdb273a546e9c3a15250f1d9165
O41 - EIO - EIO - C:\WINDOWS\system32\drivers\EIO.sys - (not running) - - -
O41 - Kl1 - Kaspersky Anti-Hacker Only Driver - C:\WINDOWS\system32\drivers\kl1.sys - (running) - Kaspersky Anti-Hacker Only Driver - Kaspersky Lab - 94b73d5dcb3198728394d0292a2f5bc6
O41 - Klif - spuper-ptor - C:\WINDOWS\system32\drivers\klif.sys - (not running) - spuper-ptor - Kaspersky Labs - ac5fcf69b95dde2daa36698a6a0e1f2d
O41 - Klmc - Kaspersky Anti-Virus Mail Checker Proxy - C:\WINDOWS\system32\drivers\klmc.sys - (not running) - Kaspersky Anti-Virus Mail Checker Proxy - Kaspersky Lab - 5a23435829f8724a0e196693d6149edd
O41 - npkcrypt - nProtect KeyCrypt Driver - D:\Program Files\Tencent\QQ\npkcrypt.sys - (not running) - nProtect KeyCrypt Driver - INCA Internet Co., Ltd. - 8bcb281a2540e7aff0cd00f9878fe21f
O41 - swhklh40 - Kernel - C:\WINDOWS\system32\drivers\swhklh40.sys - (not running) - Kernel - Microsoft Corporation - b3a8b44dfaae66c52e88f32de64049ca
O41 - TSP - spuper-ptor - C:\WINDOWS\system32\drivers\klif.sys - (not running) - spuper-ptor - Kaspersky Labs - ac5fcf69b95dde2daa36698a6a0e1f2d
O41 - XTrapD12 - XTrapD12 - C:\WINDOWS\system32\XTrapD12.sys - (not running) - - -
=======================================
360Safe.exe=2.2.0.1000
AntiAdwa.dll=2.2.0.1000
AntiEng.dll=2.2.0.1000
AntiActi.dll=2.0.0.3000
CleanHis.dll=2.0.0.1001
safelive.exe=1.0.0.2007
live.dll=1.0.0.1011
=======================================
操作历史报告:
----------查杀恶意软件历史----------
2006-11-28 11:08
查杀恶意软件 - 伪系统服务 - 危险 -
查杀恶意软件 - 伪lsass.exe - 危险 - C:\WINDOWS\system32\wbem\sholl32.dll
查杀恶意软件 - 实用网址导航(酷站导航) - 危险 - C:\WINDOWS\system32\wbem\ocmor.dll
2006-11-28 11:53
查杀恶意软件 - Web迅雷 - 安全 -
2006-11-29 12:31
查杀恶意软件 - 实用网址导航(酷站导航) - 危险 - C:\WINDOWS\system32\wbem\ocmor.dll
2006-11-29 13:19
查杀恶意软件 - 实用网址导航(酷站导航) - 危险 - C:\WINDOWS\system32\wbem\ocmor.dll
----------插件卸载操作历史----------
2006-11-28 11:09
插件管理 - IE Toolbar - C:\Program Files\Miorosoft Office\tbu00650\Miorosoft Office.dll
插件管理 - 迷你PP -
插件管理 - 酷狗附带的插件 -
插件管理 - 腾讯QQ附带的QQIEHelper插件 -
插件管理 - Web迅雷 - d:\PROGRA~1\THUNDE~1\WEBTHU~1\WEBTHU~2.DLL
2006-11-29 12:32
插件管理 - 腾讯QQ附带的QQIEHelper插件 -
----------全面诊断修复历史----------
2006-11-29 13:22
O16 - 未知 - 下载的ActiveX插件 - C:\WINDOWS\DOWNLO~1\ASUSTE~1.DLL
----------修复IE浏览器操作历史----------
2006-11-29 13:15
R0 - 危险 - IE首页 - HKCU\Software\Microsoft\Internet Explorer\Main
秋日里的蓝天 - 2006-11-29 18:18:00
重新启动电脑,自动检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式(Safe Mode)进入Windows。)
运行(双击)SRENG2,点“启动项目,服务,点“Win32服务应用程序”
勾选“隐藏微软服务”选中病毒服务
Remote Route Service
WindowsNt Workstation
IPSEC Client
Windows Media Connect Service
,选择“删除服务”
点“设置”选择“否”
显示隐藏文件
删除:
C:\WINDOWS\system32\qvhxtd94.dll
c:\windows\system32\ntworkstan.dll
C:\WINDOWS\SYSTEM32\WBEM\CTEIVL75.DLL
C:\WINDOWS\system32\WmdmPmSp.dll
c:\windows\system32\wbem\lsass.exe
© 2000 - 2026 Rising Corp. Ltd.