瑞星卡卡安全论坛
kourou6800 - 2007-1-4 21:55:00
开机后就自动弹出贴图中的1号窗口,然后点击确定接着弹出2号窗口,如此反复一直到8号窗口为止。
以后就是每隔个5分钟就弹出1号窗口,非常烦人,有时玩个游戏一出来就打开个40多个窗口。
我用卡卡,McAfee 2006安全组合套装,ewido anti-spyware 4.0.0.172,升级到最新病毒数据没有查出任何问题。
原来我还以为是杀毒软件的自动更新出了问题,但我把他们的自动更新,还有Windows的自动更新都关了问题还是存在。
然后我把网线给拔了,就开始频繁弹出9号窗口,我怀疑是有病毒或木马在频繁在连接,但用冰刃始终查不出是那个进程或程序。谢谢大家帮助分析一下!!
sreng 日志扫描如下:(图看不清可点击打开)
附件:
814546200714214557.JPG
kourou6800 - 2007-1-4 21:55:00
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background> [(Verified)Microsoft Corporation]
<MsnMsgr><; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<VSOCheckTask><"C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask> [McAfee, Inc.]
<VirusScan Online><C:\Program Files\McAfee.com\VSO\mcvsshld.exe> [McAfee, Inc.]
<OASClnt><C:\Program Files\McAfee.com\VSO\oasclnt.exe> [McAfee, Inc.]
<MCAgentExe><c:\PROGRA~1\mcafee.com\agent\mcagent.exe> [McAfee, Inc]
<MCUpdateExe><c:\PROGRA~1\mcafee.com\agent\mcupdate.exe> [McAfee, Inc]
<MPFExe><C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe> [(Verified)McAfee Security]
<BigDogPath><C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera> [N/A]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe> [Beijing Rising Technology Co., Ltd.]
<!ewido><"D:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized> [Anti-Malware Development a.s.]
<SoundMan><; SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<StormCodec_Helper><; "d:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> [N/A]
<WangWang><; "d:\Program Files\淘宝网\淘宝旺旺\WangWang.EXE"> [淘宝(中国)软件有限公司]
<YOKAssiant><; Rundll32.exe C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll,YOKAssiant> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\Userinit.exe,,"d:\Program Files\HFEE\SVOHOST.EXE" un userinit.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{57B86673-276A-48B2-BAE7-C6DBB3020EB8}><d:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll> [Anti-Malware Development a.s.]
<{48B783AE-8F87-4046-8154-7D82FBCE42D2}><C:\WINDOWS\system32\ntmgr.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<NetWork><> [N/A]
<WebSecurity><C:\WINDOWS\system32\PvSec.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{B63BFF8C-2E25-4CCC-9A01-68807F567AA7}><C:\WINDOWS\system32\BandRes.dll> []
==================================
启动文件夹
N/A
==================================
kourou6800 - 2007-1-4 21:56:00
服务
[Routing Protect Access / 8NASCAR][Stopped/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLL.EXE C:\WINDOWS\SYSTEM32\WBEM\SMTPCONFS.DLL,Export 1087><N/A>
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
<C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart][Stopped/Auto Start]
<C:\WINDOWS\system32\ati2sgag.exe><>
[ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard][Running/Auto Start]
<d:\Program Files\ewido anti-spyware 4.0\guard.exe><Anti-Malware Development a.s.>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[KDDelegateService / KDDelegateService][Stopped/Manual Start]
<d:\Program Files\Kingdee\KIS\Advance\KDDelegateService.exe><N/A>
[Remote Registry Protect / Live][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\mssapi.dll><N/A>
[Logical Disk Manager Administrator Service / Logical Disk Manager Administrator Service][Running/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\Program Files\Messenger\msnsvc.dll><N/A>
[McAfee WSC Integration / McDetect.exe][Running/Auto Start]
<c:\program files\mcafee.com\agent\mcdetect.exe><McAfee, Inc>
[McAfee.com McShield / McShield][Running/Auto Start]
<c:\PROGRA~1\mcafee.com\vso\mcshield.exe><McAfee Inc.>
[McAfee Task Scheduler / McTskshd.exe][Running/Auto Start]
<c:\PROGRA~1\mcafee.com\agent\mctskshd.exe><McAfee, Inc>
[McAfee SecurityCenter Update Manager / mcupdmgr.exe][Stopped/Manual Start]
<C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe><McAfee, Inc>
[McAfee Personal Firewall Service / MpfService][Running/Auto Start]
<C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe><McAfee Corporation>
[MSSQLSERVER / MSSQLSERVER][Running/Auto Start]
<C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe -sMSSQLSERVER><Microsoft Corporation>
[MSSQLServerADHelper / MSSQLServerADHelper][Stopped/Manual Start]
<C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe><Microsoft Corporation>
[Net Monitor / Net Monitor][Others/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\WinSafe.dll><N/A>
[Performance Monitor / Performance Monitor][Others/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\WinSafe.dll><N/A>
[RestoreService / RestoreService][Running/Auto Start]
<C:\WINDOWS\system32\Svchost.exe -k RestoreService-->C:\WINDOWS\system32\drivers\restore.dll><Microsoft Corporation All rights reserved>
[SQLSERVERAGENT / SQLSERVERAGENT][Stopped/Disabled]
<C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE -i MSSQLSERVER><Microsoft Corporation>
[Remote Access Connection Management / Remote Access Connection Management][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\Program Files\Messenger\msnhost.dll><N/A>
==================================
kourou6800 - 2007-1-4 21:56:00
驱动程序
[a347bus / a347bus][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\a347bus.sys><>
[a347scsi / a347scsi][Running/Boot Start]
<\SystemRoot\System32\Drivers\a347scsi.sys><>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[标准 IDE/ESDI 硬盘控制器 / atapi][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\atapi.sys><N/A>
[ati2mtag / ati2mtag][Running/Manual Start]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[atmsig / atmsig][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\atmsig.sys><N/A>
[bejgbece / bejgbece][Stopped/System Start]
<\??\C:\WINDOWS\system32\drivers\bejgbece.sys><N/A>
[BVNN VNC Virtual Network Adapter / bvnndev][Stopped/Manual Start]
<system32\DRIVERS\bvnnvnic.sys><VNN B.J.>
[fffiebia / fffiebia][Stopped/System Start]
<\??\C:\WINDOWS\system32\drivers\fffiebia.sys><N/A>
[hardlock / hardlock][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\hardlock.sys><Aladdin Knowledge Systems>
[Haspnt / Haspnt][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\Haspnt.sys><Aladdin Knowledge Systems>
[hidport / hidport][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\hidport.sys><N/A>
[jr / jr][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\jr.sys><N/A>
[kxsmp / kxsmp][Running/Disabled]
<\??\C:\WINDOWS\system32\drivers\kxsmp.sys><N/A>
[MPFIREWL / MPFIREWL][Running/System Start]
<System32\Drivers\MpFirewall.sys><McAfee>
[mpsmp / mpsmp][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\mpsmp.sys><N/A>
[mtiklm3 / mtiklm34][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\mtiklm34.sys><N/A>
[NaiAvFilter1 / NaiAvFilter1][Running/Manual Start]
<system32\drivers\naiavf5x.sys><McAfee Inc.>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[npkycryp / npkycryp][Stopped/Manual Start]
<\??\D:\Program Files\Tencent\QQ\npkycryp.sys><N/A>
[nwlnksipx / nwlnksipx][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\nwlnksipx.sys><N/A>
[parcls / parcls][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\parcls.sys><N/A>
[StarForce Protection Environment Driver v6 / prodrv06][Running/System Start]
<\SystemRoot\System32\drivers\prodrv06.sys><Protection Technology>
[StarForce Protection Helper Driver v2 / prohlp02][Running/Boot Start]
<\SystemRoot\System32\drivers\prohlp02.sys><Protection Technology>
[StarForce Protection Synchronization Driver v1 / prosync1][Running/Boot Start]
<\SystemRoot\System32\drivers\prosync1.sys><Protection Technology>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
<\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[Sentinel / Sentinel][Running/Auto Start]
<\SystemRoot\System32\Drivers\SENTINEL.SYS><Rainbow Technologies, Inc.>
[StarForce Protection Environment Driver (version 1.x) / sfdrv01][Running/Boot Start]
<\SystemRoot\System32\drivers\sfdrv01.sys><Protection Technology>
[StarForce Protection Helper Driver / sfhlp01][Running/Boot Start]
<\SystemRoot\System32\drivers\sfhlp01.sys><Protection Technology>
[StarForce Protection Helper Driver (version 2.x) / sfhlp02][Running/Boot Start]
<\SystemRoot\System32\drivers\sfhlp02.sys><Protection Technology>
[StarForce Protection Synchronization Driver (version 2.x) / sfsync02][Running/Boot Start]
<\SystemRoot\System32\drivers\sfsync02.sys><Protection Technology>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[VNN VNC Virtual Network Adapter / vnndev][Stopped/Manual Start]
<system32\DRIVERS\vnnvnic.sys><VNN B.J.>
[wspipe / wspipe][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\wspipe.sys><N/A>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[VIMICRO USB PC Camera / ZSMC301b][Stopped/Manual Start]
<System32\Drivers\usbVM31b.sys><VM>
==================================
kourou6800 - 2007-1-4 21:57:00
浏览器加载项
[Flashget Catch Url Class]
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <D:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
[]
{41d8184a-5221-4857-ae2b-1b294ae19f4f} <C:\WINDOWS\system32\4857ntos.dll, N/A>
[]
{545c4d31-5c34-44a3-ae2b-1b294ae19f4f} <C:\WINDOWS\system32\44a3ntos.dll, N/A>
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[gFlash Class]
{F156768E-81EF-470C-9057-481BA8380DBA} <D:\Program Files\FlashGet\getflash.dll, >
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[快车]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <D:\PROGRA~1\FlashGet\flashget.exe, FlashGet.com>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[快车(FlashGet)]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <D:\Program Files\FlashGet\fgiebar.dll, Amaze Soft>
[McAfee VirusScan]
{BA52B914-B692-46c4-B683-905236F6F655} <c:\progra~1\mcafee.com\vso\mcvsshl.dll, McAfee, Inc.>
[金山快译(&K)]
{6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <D:\Program Files\Kingsoft\FastAIT 2006\IEBand.dll, 金山软件股份有限公司>
[5c34]
{DFCB34B6-902D-426E-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\44a3ntos.dll, N/A>
[Flashget Catch Url Class]
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <D:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
[]
{41D8184A-5221-4857-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\4857ntos.dll, N/A>
[]
{545C4D31-5C34-44A3-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\44a3ntos.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[金山快译(&K)]
{6C3797D2-3FEF-4CD4-B654-D3AE55B4128C} <D:\Program Files\Kingsoft\FastAIT 2006\IEBand.dll, 金山软件股份有限公司>
[]
{A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX, N/A>
[McAfee VirusScan]
{BA52B914-B692-46C4-B683-905236F6F655} <c:\progra~1\mcafee.com\vso\mcvsshl.dll, McAfee, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[5c34]
{DFCB34B6-902D-426E-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\44a3ntos.dll, N/A>
[快车(FlashGet)]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <D:\Program Files\FlashGet\fgiebar.dll, Amaze Soft>
[gFlash Class]
{F156768E-81EF-470C-9057-481BA8380DBA} <D:\Program Files\FlashGet\getflash.dll, >
[&使用快车(FlashGet)下载]
<D:\Program Files\FlashGet\jc_link.htm, N/A>
[&使用快车(FlashGet)下载全部链接]
<D:\Program Files\FlashGet\jc_all.htm, N/A>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到AMV视频转换工具...]
<D:\Program Files\MP3播放器管理工具 4.05\AMVConverter\grab.html, N/A>
[添加到QQ自定义面板]
<D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[添加到媒体管理器...]
<D:\Program Files\MP3播放器管理工具 4.05\MediaManager\grab.html, N/A>
[添加到广告杀手]
<d:\Program Files\TweakAssist\AdKiller.htm, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
==================================
kourou6800 - 2007-1-4 21:58:00
==================================
正在运行的进程
[PID: 488][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 552][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 580][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4132]
[PID: 624][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 636][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 796][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4132]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2500]
[PID: 808][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 872][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 936][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\program files\messenger\msnsvc.dll] [N/A, N/A]
[c:\windows\system32\winsafe.dll] [N/A, N/A]
[PID: 980][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1024][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1240][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1400][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4132]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2500]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[PID: 1596][d:\Program Files\ewido anti-spyware 4.0\guard.exe] [Anti-Malware Development a.s., 4, 0, 0, 172]
[d:\Program Files\ewido anti-spyware 4.0\engine.dll] [Anti-Malware Development a.s., 4, 0, 0, 172]
[PID: 1648][c:\program files\mcafee.com\agent\mcdetect.exe] [McAfee, Inc, 6, 0, 0, 19]
[PID: 1660][c:\PROGRA~1\mcafee.com\vso\mcshield.exe] [McAfee Inc., 11.0.0.151]
[c:\PROGRA~1\mcafee.com\vso\RES00\McShield.DLL] [McAfee Inc., 11.0.0.137]
[c:\PROGRA~1\mcafee.com\vso\FTL.Dll] [McAfee Inc., 11.0.0.151]
[c:\PROGRA~1\mcafee.com\vso\naiann.dll] [McAfee, Inc., 10, 0, 0, 21]
[c:\PROGRA~1\mcafee.com\vso\mytilus.dll] [McAfee Inc., 11.0.0.151]
[C:\Program Files\McAfee.com\VSO\MCSCAN32.DLL] [McAfee, Inc., 5.1.00]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\naiannps.dll] [McAfee, Inc, 10, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\mcvsps.dll] [McAfee, Inc, 10, 0, 0, 17]
[PID: 1708][c:\PROGRA~1\mcafee.com\agent\mctskshd.exe] [McAfee, Inc, 6, 0, 0, 13]
[PID: 1780][d:\Program Files\HFEE\SVOHOST.EXE] [, 3000.0.0.0]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[D:\Program Files\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[PID: 1788][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[d:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll] [Anti-Malware Development a.s., 4, 0, 0, 172]
[C:\WINDOWS\system32\dsfhw.dll] [, 1, 0, 0, 1]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[C:\WINDOWS\system32\BandRes.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\PvSec.dll] [, 5, 1, 100, 2500]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[D:\Program Files\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[d:\Program Files\TuneUp Utilities 2006\sdshelex.dll] [TuneUp Software GmbH, 1.0.0.253]
[d:\Program Files\TuneUp Utilities 2006\rtl60.bpl] [Borland Software Corporation, 6.0.6.241]
[d:\Program Files\TuneUp Utilities 2006\vcl60.bpl] [Borland Software Corporation, 6.0.6.240]
[d:\Program Files\ewido anti-spyware 4.0\context.dll] [Anti-Malware Development a.s., 4, 0, 0, 172]
[c:\progra~1\mcafee.com\vso\mcvsshl.dll] [McAfee, Inc., 10, 0, 0, 19]
[c:\progra~1\mcafee.com\vso\ShlRes.dll] [McAfee, Inc., 10, 0, 0, 19]
[D:\Program Files\FlashGet\jccatch.dll] [www.flashget.com, 1, 8, 0, 1003]
[D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] [N/A, N/A]
[PID: 1860][c:\PROGRA~1\mcafee.com\vso\OasClnt.exe] [McAfee, Inc., 10, 0, 0, 24]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\naiannps.dll] [McAfee, Inc, 10, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\mcvsps.dll] [McAfee, Inc, 10, 0, 0, 17]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[PID: 1904][C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe] [McAfee Corporation, 7.1.0.113]
[C:\WINDOWS\system32\MPFAPI.dll] [McAfee, 7.1.0.113]
[PID: 1944][C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe] [Microsoft Corporation, 2000.080.0760.00]
[C:\Program Files\Microsoft SQL Server\MSSQL\Binn\OPENDS60.DLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Microsoft SQL Server\MSSQL\Binn\UMS.DLL] [Microsoft Corporation, 2000.080.0760.00]
[C:\Program Files\Microsoft SQL Server\MSSQL\Binn\SQLSORT.DLL] [Microsoft Corporation, 2000.080.0760.00]
[C:\Program Files\Microsoft SQL Server\MSSQL\Binn\Resources\2052\sqlevn70.RLL] [Microsoft Corporation, 2000.080.0760.00]
[C:\Program Files\Microsoft SQL Server\MSSQL\Binn\SSNETLIB.dll] [Microsoft Corporation, 2000.080.0766.00]
[C:\Program Files\Microsoft SQL Server\MSSQL\Binn\SSNMPN70.dll] [Microsoft Corporation, 2000.080.0534.00]
[C:\Program Files\Microsoft SQL Server\MSSQL\Binn\SSmsLPCn.dll] [Microsoft Corporation, 2000.080.0760.00]
[PID: 1976][c:\program files\mcafee.com\vso\mcvsshld.exe] [McAfee, Inc., 10, 0, 0, 22]
[C:\Program Files\McAfee.com\VSO\VsCfgW32.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\program files\mcafee.com\vso\ashldres.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\program files\mcafee.com\agent\submgr\6,0,0,15\mcsubmgr.dll] [McAfee, Inc, 6, 0, 0, 15]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\mcvsps.dll] [McAfee, Inc, 10, 0, 0, 17]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[c:\program files\mcafee.com\shared\mcuicfg\6,0,0,4\mcuicfg.dll] [McAfee, Inc, 6, 0, 0, 4]
[D:\Program Files\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[PID: 1996][c:\program files\mcafee.com\agent\mcagent.exe] [McAfee, Inc, 6, 0, 0, 16]
[c:\program files\mcafee.com\agent\SCRes.dll] [McAfee, Inc, 6, 0, 0, 7]
[c:\program files\mcafee.com\agent\submgr\6,0,0,15\mcsubmgr.dll] [McAfee, Inc, 6, 0, 0, 15]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
kourou6800 - 2007-1-4 21:59:00
[PID: 2000][c:\progra~1\mcafee.com\vso\mcvsescn.exe] [McAfee, Inc., 10, 0, 0, 20]
[c:\progra~1\mcafee.com\vso\ashldres.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\progra~1\mcafee.com\vso\EmScnRes.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\program files\mcafee.com\vso\vsoupd.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\progra~1\mcafee.com\vso\McVsWorm.dll] [McAfee, Inc., 10, 0, 0, 19]
[C:\Program Files\McAfee.com\VSO\VsCfgW32.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\progra~1\mcafee.com\vso\WormRes.dll] [McAfee, Inc., 10, 0, 0, 19]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[PID: 152][C:\WINDOWS\system32\Svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\windows\system32\drivers\restore.dll] [Microsoft Corporation All rights reserved, 1, 0, 0, 1]
[PID: 216][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 200][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 2292][C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe] [McAfee Security, 7.1.0.113]
[C:\PROGRA~1\McAfee.com\PERSON~1\Localized.DLL] [McAfee Security, 7.1.0.113]
[C:\WINDOWS\system32\MPFAPI.dll] [McAfee, 7.1.0.113]
[c:\program files\mcafee.com\agent\submgr\6,0,0,15\mcsubmgr.dll] [McAfee, Inc, 6, 0, 0, 15]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[D:\Program Files\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[PID: 2312][C:\WINDOWS\VM_STI.EXE] [Vimicro, 4, 2, 1225, 6]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[PID: 2336][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3536]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 2356][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 3]
[C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 2444][D:\Program Files\ewido anti-spyware 4.0\ewido.exe] [Anti-Malware Development a.s., 4, 0, 0, 172]
[D:\Program Files\ewido anti-spyware 4.0\engine.dll] [Anti-Malware Development a.s., 4, 0, 0, 172]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 2464][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 2732][C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe] [McAfee Security, 7.1.0.113]
[C:\PROGRA~1\McAfee.com\PERSON~1\Localized.DLL] [McAfee Security, 7.1.0.113]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[c:\program files\mcafee.com\agent\submgr\6,0,0,15\mcsubmgr.dll] [McAfee, Inc, 6, 0, 0, 15]
[PID: 2968][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3644][C:\WINDOWS\system32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\dsssvc.dll] [, 5.1.1800.2813]
[D:\Program Files\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 1360][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Program Files\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 3600][D:\Program Files\Maxthon\Maxthon.exe] [Maxthon International Ltd., 1, 5, 9, 30]
[D:\Program Files\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
[D:\Program Files\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 1.1.4322.573]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CorperfmonExt.dll] [Microsoft Corporation, 1.1.4322.573]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\PROGRA~1\MICROS~3\MSSQL\Binn\sqlctr80.dll] [Microsoft Corporation, 2000.080.0534.00]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[D:\Program Files\FlashGet\jccatch.dll] [www.flashget.com, 1, 8, 0, 1003]
[D:\Program Files\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[PID: 1504][D:\Program Files\FlashGet\flashget.exe] [FlashGet.com, 1, 8, 0, 1002]
[D:\Program Files\FlashGet\FGBTCORE.dll] [N/A, 1, 0, 0, 25]
[D:\Program Files\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[PID: 3564][C:\Documents and Settings\powerice\桌面\sreng2_PConline\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[D:\Program Files\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 7]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 26]
[C:\Documents and Settings\powerice\桌面\sreng2_PConline\Plugins\SRECXTMG.SRE] [Smallfrogs Studio, 1, 5, 0, 55]
kourou6800 - 2007-1-4 22:00:00
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 LOCALHOST
==================================
API HOOK
N/A
==================================
[/CODE]
小蝴蝶燕燕 - 2007-1-4 22:04:00
参考下面网站
http://www.help-online.org/bbs/redirect.php?tid=9619&goto=lastpost
kourou6800 - 2007-1-6 12:22:00
8楼的MM谢谢了
1
© 2000 - 2026 Rising Corp. Ltd.