[CODE] 2008-08-18,08:38:45 System Repair Engineer 2.6.12.1018 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"> [Kaspersky Lab] <%systemroot%\system32\dumprep 0 -k> [File is missing] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{2876D76C-CAAA-4313-AF97-8D1D9A2A1087}> [File is missing] <{9E8287B0-0F3A-48ae-99C5-A6E0AAC36BC5}> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] [File is missing] [File is missing] [File is missing] [File is missing] [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon] [Kaspersky Lab] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6d506120-e5d8-3a2d-3a2d-f6e9fab94cbf}] [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] ================================== 启动文件夹 N/A ================================== 服务 [956CAA4C / 956CAA4C][Stopped/Auto Start] <><(File is missing)> [卡巴斯基反病毒6.0个人版 / AVP][Stopped/Auto Start] <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r> [Contrl Center of Storm Media / ccosm][Running/Auto Start] <北京暴风网际科技有限公司> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [Rising Process Communication Center / RsCCenter][Running/Auto Start] <"D:\Program Files\Rising\Rav\CCenter.exe"> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] <"D:\PROGRAM FILES\RISING\RAV\Ravmond.exe"> [SmartLinkService / SLService][Running/Auto Start] <> ================================== 驱动程序 [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start] [Dritek HotKey Keyboard Filter Driver / DKbFltr][Running/Manual Start] [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start] [HookCont / HookCont][Running/System Start] <\SystemRoot\system32\drivers\HookCont.sys> [HookNtos / HookNtos][Running/System Start] <\SystemRoot\system32\drivers\HookNtos.sys> [HookReg / HookReg][Running/System Start] <\SystemRoot\system32\drivers\HookReg.sys> [HookSys / HookSys][Running/System Start] <\SystemRoot\system32\drivers\HookSys.sys> [Hanwang Technology CO.LTD HID Tablet Device / hwmouser][Stopped/Manual Start] [ialm / ialm][Running/Manual Start] [kl1 / kl1][Running/Boot Start] <\SystemRoot\system32\drivers\kl1.sys> [klif / klif][Running/System Start] <\??\C:\WINDOWS\system32\drivers\klif.sys> [Mtlmnt5 / Mtlmnt5][Running/Manual Start] <> [Mtlstrm / Mtlstrm][Stopped/Manual Start] <> [Netpas Win32 Virtual Network Adapter / netpasadapter1][Stopped/Manual Start] [NetGroup Packet Filter Driver / NPF][Stopped/Manual Start] [NtMtlFax / NtMtlFax][Stopped/Manual Start] <> [nv / nv][Stopped/Manual Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [QKeyServiceDisplay / QKeyService][Running/Boot Start] <\SystemRoot\system32\KeyCrypt.sys> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start] [Secdrv / Secdrv][Stopped/Manual Start] [SmartLink AMR_PCI Driver / Slntamr][Running/Manual Start] <> [SlNtHal / SlNtHal][Stopped/Manual Start] <> [SlWdmSup / SlWdmSup][Running/Manual Start] [SMC IrCC Miniport Device Driver / SMCIRDA][Running/Manual Start] [SAMSUNG Mobile USB Device II 1.0 driver (WDM) / ssm_bus][Stopped/Manual Start] [SAMSUNG Mobile USB Modem II 1.0 Filter / ssm_mdfl][Stopped/Manual Start] [SAMSUNG Mobile USB Modem II 1.0 Drivers / ssm_mdm][Stopped/Manual Start] [TDDI / TDDI][Running/Auto Start] <\??\C:\WINDOWS\system32\drivers\tddi.sys> [TesSafe / TesSafe][Stopped/Manual Start] <\??\C:\WINDOWS\system32\TesSafe.sys> [Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/Manual Start] [Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start] ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [] {48691221-F05C-4AB4-B9D0-50D6D36CC27F} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [启动迅雷5] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} [Web反病毒统计] {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} [信息检索(&R)] {92780B25-18CC-41C8-B9BE-3C9C571A8263} [PPLive] {95B3F550-91C4-4627-BCC4-521288C52977} [Messenger] {FB5F1910-F110-11d2-BB9E-00C04F795683} [iTrusPTA Class] {1E0DFFCF-27FF-4574-849B-55007349FEDA} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [] {00000000-12C8-4305-82F9-43058F20E8D2} <, > [] {00000000-12C9-4305-82F9-43058F20E8D2} <, > [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <, > [] {0BECAB39-E1F8-45E6-8332-38DD750EBA01} <, > [] {0BECAB3A-E1F8-45E6-8332-38DD750EBA01} <, > [] {0C7C23EE-A848-485B-873C-0ED954731014} <, > [] {0C7C23EF-A848-485B-873C-0ED954731014} <, > [] {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <, > [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [] {48691221-F05C-4AB4-B9D0-50D6D36CC27F} [XMP Class] {6483F145-A768-4C41-AACC-52D4D7845851} [XDRM] {693571CB-54A3-4E90-9D52-EEAE1334E2D3} [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [WangWangObj Class] {6E213FC7-DD5A-4115-B7E6-D4C7838C361E} [MediaComm Class] {7670648D-461B-42AF-BDFE-46D26AF5EFF2} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [] {92780B25-18CC-41C8-B9BE-3C9C571A8263} <, > [] {95B3F550-91C4-4627-BCC4-521288C52977} <, > [RMGetLicense Class] {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} [DapCtrl Class] {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} [SearchAssistantOC] {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A> [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [Thunder DapPlayer] {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} [XPPlayer Class] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} [] {FB5F1910-F110-11D2-BB9E-00C04F795683} <, > [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] [添加到QQ表情] ================================== 正在运行的进程 [PID: 516 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 584 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 608 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 6.0.2.621] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 652 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 664 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 808 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 852 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 892 / SYSTEM][D:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.33] [PID: 908 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 952 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1048 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1216 / Admin][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scrchpg.dll] [Kaspersky Lab, 6.0.2.621] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.18] [D:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\shellex.dll] [Kaspersky Lab, 6.0.2.621] [d:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29] [D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [D:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20] [D:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [D:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510] [PID: 1224 / SYSTEM][D:\PROGRAM FILES\RISING\RAV\ravmond.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.80] [D:\PROGRAM FILES\RISING\RAV\BWList.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.5] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [D:\PROGRAM FILES\RISING\RAV\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [D:\PROGRAM FILES\RISING\RAV\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [D:\PROGRAM FILES\RISING\RAV\RsLog.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.36] [D:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\PROGRAM FILES\RISING\RAV\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.29] [D:\PROGRAM FILES\RISING\RAV\Hooksys.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 12] [D:\PROGRAM FILES\RISING\RAV\HookReg.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [D:\PROGRAM FILES\RISING\RAV\HookNtos.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [D:\PROGRAM FILES\RISING\RAV\rswalmon.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 24] [D:\PROGRAM FILES\RISING\RAV\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 40] [D:\PROGRAM FILES\RISING\RAV\refs.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 18] [D:\PROGRAM FILES\RISING\RAV\ffr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 16] [D:\Program Files\Rising\Rav\RsStore.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.9] [D:\PROGRAM FILES\RISING\RAV\HookCont.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [D:\Program Files\Rising\Rav\fakescan.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.14] [D:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.39] [D:\PROGRAM FILES\RISING\RAV\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27] [D:\PROGRAM FILES\RISING\RAV\extfile.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 32] [D:\PROGRAM FILES\RISING\RAV\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [D:\PROGRAM FILES\RISING\RAV\pearc.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 8] [D:\PROGRAM FILES\RISING\RAV\HookWeb.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.3] [D:\PROGRAM FILES\RISING\RAV\nvfile.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7] [D:\PROGRAM FILES\RISING\RAV\scanexec.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\PROGRAM FILES\RISING\RAV\unexe.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 6] [D:\PROGRAM FILES\RISING\RAV\scanex.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 87] [D:\PROGRAM FILES\RISING\RAV\scanpack.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [D:\PROGRAM FILES\RISING\RAV\revm.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 11] [D:\PROGRAM FILES\RISING\RAV\urutils.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7] [D:\PROGRAM FILES\RISING\RAV\ur000.dat] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 19] [D:\PROGRAM FILES\RISING\RAV\scriptci.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 4] [D:\PROGRAM FILES\RISING\RAV\ur023.dat] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 3] [D:\PROGRAM FILES\RISING\RAV\uroutine.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27] [D:\PROGRAM FILES\RISING\RAV\scansct.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [D:\PROGRAM FILES\RISING\RAV\ur001.dat] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 4] [D:\PROGRAM FILES\RISING\RAV\extmail.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [PID: 1384 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.1897.0] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.1897.0] [PID: 1440 / Admin][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5.1.02] [PID: 1512 / Admin][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1628 / SYSTEM][d:\Program Files\StormII\stormliv.exe] [北京暴风网际科技有限公司, 3, 8, 3, 1] [d:\Program Files\StormII\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0] [PID: 1744 / SYSTEM][C:\WINDOWS\system32\slserv.exe] [ , 2.80.00(24Apr2000)] [PID: 416 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1108 / SYSTEM][D:\PROGRAM FILES\RISING\RAV\RavStub.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.10] [D:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [PID: 1548 / SYSTEM][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)] [PID: 1456 / Admin][C:\Documents and Settings\Admin\桌面\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.6.12.1018] [PID: 2020 / Admin][C:\Documents and Settings\Admin\桌面\sreng2\SRE91156015.EXE] [Smallfrogs Studio, 2.6.12.1018] [C:\Documents and Settings\Admin\桌面\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [D:\PROGRA~1\MICROS~1\OFFICE11\MCPS.DLL] [Microsoft Corporation, 11.0.5510] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 219.235.3.16 search.114.vnet.cn 219.235.3.16 keyword.vnet.cn 219.235.3.16 auto.search.msn.com 219.235.3.16 search.msn.com 219.235.3.16 cnweb.search.live.com 219.235.3.16 www.360safe.com 219.235.3.16 www.k369.com 219.235.3.16 www.5566.net 219.235.3.16 360safe.com 202.165.102.243 update.360safe.com 219.235.3.16 dl.360safe.com 219.235.3.16 down.360safe.com 219.235.3.16 bbs.360safe.com 219.235.3.16 kaba.360safe.com 219.235.3.16 baike.360safe.com 219.235.3.16 www.360.cn 219.235.3.16 360.cn 219.235.3.16 wopti.360.cn 202.165.102.243 update.360.cn 219.235.3.16 dl.360.cn 219.235.3.16 down.360.cn 219.235.3.16 bbs.360.cn 219.235.3.16 kaba.360.cn 219.235.3.16 baike.360.cn 219.235.3.16 360.qihoo.com 219.235.3.16 360safe.qihoo.com 219.235.3.16 forum.ikaka.com 219.235.3.16 www.ikaka.com 202.165.102.243 update.ikaka.com 219.235.3.16 forum.jiangmin.com 202.165.102.243 update.jiangmin.com 219.235.3.16 tieba.baidu.com 219.235.3.16 post.baidu.com 219.235.3.16 zhidao.baidu.com 219.235.3.16 www.baidu.com 202.165.102.243 update.rising.com.cn 219.235.3.16 online.rising.com.cn 202.165.102.243 center.rising.com.cn 219.235.3.16 up.duba.net 219.235.3.16 vi.duba.net 219.235.3.16 shadu.baidu.com 219.235.3.16 du.baidu.com 219.235.3.16 security.symantec.com 219.235.3.16 shadu.duba.net 219.235.3.16 bbs.duba.net 219.235.3.16 www.duba.net 219.235.3.16 online.jiangmin.com 219.235.3.16 cn.mcafee.com 219.235.3.16 www.ahn.com.cn 219.235.3.16 www.kaspersky.com.cn 219.235.3.16 www.pcav.cn 219.235.3.16 www.luosoft.com 219.235.3.16 www.im286.com 219.235.3.16 an.baidu.com 219.235.3.16 ma.baidu.com 219.235.3.16 bbs.htmlman.net 202.165.102.243 download.rising.com.cn 202.165.102.243 rsup08.rising.com.cn 219.235.3.16 10000.286er.com 219.235.3.16 im286.net 219.235.3.16 ju.qihoo.com 219.235.3.16 bbs.chinaz.com 219.235.3.16 www.qihoo.com 202.165.102.243 dnl-cn1.kaspersky-labs.com 202.165.102.243 dnl-cn2.kaspersky-labs.com 202.165.102.243 dnl-cn3.kaspersky-labs.com 202.165.102.243 dnl-cn4.kaspersky-labs.com 202.165.102.243 dnl-cn5.kaspersky-labs.com 202.165.102.243 dnl-cn6.kaspersky-labs.com 202.165.102.243 dnl-cn7.kaspersky-labs.com 202.165.102.243 dnl-cn8.kaspersky-labs.com 202.165.102.243 dnl-cn9.kaspersky-labs.com 202.165.102.243 dnl-cn10.kaspersky-labs.com 202.165.102.243 dnl-cn11.kaspersky-labs.com 202.165.102.243 dnl-cn12.kaspersky-labs.com 202.165.102.243 dnl-cn13.kaspersky-labs.com 202.165.102.243 dnl-cn14.kaspersky-labs.com 202.165.102.243 dnl-cn15.kaspersky-labs.com 202.165.102.243 dnl-eu1.kaspersky-labs.com 202.165.102.243 dnl-eu2.kaspersky-labs.com 202.165.102.243 dnl-eu3.kaspersky-labs.com 202.165.102.243 dnl-eu4.kaspersky-labs.com 202.165.102.243 dnl-eu5.kaspersky-labs.com 202.165.102.243 dnl-eu6.kaspersky-labs.com 202.165.102.243 dnl-eu7.kaspersky-labs.com 202.165.102.243 dnl-eu8.kaspersky-labs.com 202.165.102.243 dnl-eu9.kaspersky-labs.com 202.165.102.243 dnl-eu10.kaspersky-labs.com 202.165.102.243 dnl-eu11.kaspersky-labs.com 202.165.102.243 dnl-eu12.kaspersky-labs.com 202.165.102.243 dnl-eu13.kaspersky-labs.com 202.165.102.243 dnl-eu14.kaspersky-labs.com 202.165.102.243 dnl-eu15.kaspersky-labs.com 202.165.102.243 dnl-us1.kaspersky-labs.com 202.165.102.243 dnl-us2.kaspersky-labs.com 202.165.102.243 dnl-us3.kaspersky-labs.com 202.165.102.243 dnl-us4.kaspersky-labs.com 202.165.102.243 dnl-us5.kaspersky-labs.com 202.165.102.243 dnl-us6.kaspersky-labs.com 202.165.102.243 dnl-us7.kaspersky-labs.com 202.165.102.243 dnl-us8.kaspersky-labs.com 202.165.102.243 dnl-us9.kaspersky-labs.com 202.165.102.243 dnl-us10.kaspersky-labs.com 202.165.102.243 dnl-us11.kaspersky-labs.com 202.165.102.243 dnl-us12.kaspersky-labs.com 202.165.102.243 dnl-us13.kaspersky-labs.com 202.165.102.243 dnl-us14.kaspersky-labs.com 202.165.102.243 dnl-us15.kaspersky-labs.com 202.165.102.243 dnl-ru1.kaspersky-labs.com 202.165.102.243 dnl-ru2.kaspersky-labs.com 202.165.102.243 dnl-ru3.kaspersky-labs.com 202.165.102.243 dnl-ru4.kaspersky-labs.com 202.165.102.243 dnl-ru5.kaspersky-labs.com 202.165.102.243 dnl-ru6.kaspersky-labs.com 202.165.102.243 dnl-ru7.kaspersky-labs.com 202.165.102.243 dnl-ru8.kaspersky-labs.com 202.165.102.243 dnl-ru9.kaspersky-labs.com 202.165.102.243 dnl-ru10.kaspersky-labs.com 202.165.102.243 dnl-ru11.kaspersky-labs.com 202.165.102.243 dnl-ru12.kaspersky-labs.com 202.165.102.243 dnl-ru13.kaspersky-labs.com 202.165.102.243 dnl-ru14.kaspersky-labs.com 202.165.102.243 dnl-ru15.kaspersky-labs.com 202.165.102.243 dnl-jp1.kaspersky-labs.com 202.165.102.243 dnl-jp2.kaspersky-labs.com 202.165.102.243 dnl-jp3.kaspersky-labs.com 202.165.102.243 dnl-jp4.kaspersky-labs.com 202.165.102.243 dnl-jp5.kaspersky-labs.com 202.165.102.243 dnl-jp6.kaspersky-labs.com 202.165.102.243 dnl-jp7.kaspersky-labs.com 202.165.102.243 dnl-jp8.kaspersky-labs.com 202.165.102.243 dnl-jp9.kaspersky-labs.com 202.165.102.243 dnl-jp10.kaspersky-labs.com 202.165.102.243 dnl-jp11.kaspersky-labs.com 202.165.102.243 dnl-jp12.kaspersky-labs.com 202.165.102.243 dnl-jp13.kaspersky-labs.com 202.165.102.243 dnl-jp14.kaspersky-labs.com 202.165.102.243 dnl-jp15.kaspersky-labs.com 202.165.102.243 dnl-kr1.kaspersky-labs.com 202.165.102.243 dnl-kr2.kaspersky-labs.com 202.165.102.243 dnl-kr3.kaspersky-labs.com 202.165.102.243 dnl-kr4.kaspersky-labs.com 202.165.102.243 dnl-kr5.kaspersky-labs.com 202.165.102.243 dnl-kr6.kaspersky-labs.com 202.165.102.243 dnl-kr7.kaspersky-labs.com 202.165.102.243 dnl-kr8.kaspersky-labs.com 202.165.102.243 dnl-kr9.kaspersky-labs.com 202.165.102.243 dnl-kr10.kaspersky-labs.com 202.165.102.243 dnl-kr11.kaspersky-labs.com 202.165.102.243 dnl-kr12.kaspersky-labs.com 202.165.102.243 dnl-kr13.kaspersky-labs.com 202.165.102.243 dnl-kr14.kaspersky-labs.com 202.165.102.243 dnl-kr15.kaspersky-labs.com 202.165.102.243 dnl-cd1.kaspersky-labs.com 202.165.102.243 dnl-cd2.kaspersky-labs.com 202.165.102.243 dnl-cd3.kaspersky-labs.com 202.165.102.243 dnl-cd4.kaspersky-labs.com 202.165.102.243 dnl-cd5.kaspersky-labs.com 202.165.102.243 dnl-cd6.kaspersky-labs.com 202.165.102.243 dnl-cd7.kaspersky-labs.com 202.165.102.243 dnl-cd8.kaspersky-labs.com 202.165.102.243 dnl-cd9.kaspersky-labs.com 202.165.102.243 dnl-cd10.kaspersky-labs.com 202.165.102.243 dnl-cd11.kaspersky-labs.com 202.165.102.243 dnl-cd12.kaspersky-labs.com 202.165.102.243 dnl-cd13.kaspersky-labs.com 202.165.102.243 dnl-cd14.kaspersky-labs.com 202.165.102.243 dnl-cd15.kaspersky-labs.com 202.165.102.243 downloads1.kaspersky-labs.com 202.165.102.243 downloads2.kaspersky-labs.com 202.165.102.243 downloads3.kaspersky-labs.com 202.165.102.243 downloads4.kaspersky-labs.com 202.165.102.243 downloads5.kaspersky-labs.com 219.235.3.16 rss.360safe.com 219.235.3.16 x.360safe.com 219.235.3.16 d.360safe.com 219.235.3.16 updatem.360safe.com 219.235.3.16 softm.360safe.com 219.235.3.16 ishare.sina.com.cn 219.235.3.16 search.cn.yahoo.com 219.235.3.16 www.google.com 219.235.3.16 google.com 219.235.3.16 www.google.cn 219.235.3.16 www.yahoo.com.cn 219.235.3.16 cn.yahoo.com 219.235.3.16 search.tom.com 219.235.3.16 zhuansha.duba.net 219.235.3.16 buy.duba.net 219.235.3.16 kad.www.duba.net 219.235.3.16 cu001.www.duba.net 219.235.3.16 cu002.www.duba.net 219.235.3.16 cu003.www.duba.net 219.235.3.16 cu004.www.duba.net 219.235.3.16 cu005.www.duba.net 219.235.3.16 cu010.www.duba.net 219.235.3.16 client.download.duba.net 219.235.3.16 page.so.163.com 219.235.3.16 www.soso.com 219.235.3.16 sou.china.com 219.235.3.16 test.591jx.com 219.235.3.16 a.topxxxx.cn 219.235.3.16 picon.chinaren.com 219.235.3.16 www.5566.net 127.0.0.1 p.qqkx.com 127.0.0.1 news.netandtv.com 127.0.0.1 z.neter888.cn 127.0.0.1 b.myblank.cn 127.0.0.1 wvw.wokutu.com 127.0.0.1 unionch.qyule.com 127.0.0.1 www.qyule.com 127.0.0.1 it.itjc.cn 127.0.0.1 www.linkwww.com 127.0.0.1 vod.kaicn.com 127.0.0.1 www.tx8688.com 127.0.0.1 b.neter888.cn 127.0.0.1 promote.huanqiu.com 127.0.0.1 www.huanqiu.com 127.0.0.1 www.haokanla.com 127.0.0.1 play.unionsky.cn 127.0.0.1 www.52v.com 127.0.0.1 www.gghka.cn 127.0.0.1 icon.ajiang.net 127.0.0.1 new.ete.cn 127.0.0.1 www.stiae.cn 127.0.0.1 o.neter888.cn 127.0.0.1 comm.jinti.com 127.0.0.1 www.google-analytics.com 127.0.0.1 hz.mmstat.com 127.0.0.1 www.game175.cn 127.0.0.1 x.neter888.cn 127.0.0.1 z.neter888.cn 127.0.0.1 p.etimes888.com 127.0.0.1 hx.etimes888.com 127.0.0.1 abc.qqkx.com 127.0.0.1 dm.popdm.cn 127.0.0.1 www.yl9999.com 127.0.0.1 www.dajiadoushe.cn 127.0.0.1 down.nihao29.cn 127.0.0.1 v.onondown.com.cn 127.0.0.1 www.interoo.net 127.0.0.1 bally1.bally-bally.net 127.0.0.1 www.bao5605509.cn 127.0.0.1 down.nihao29.cn 127.0.0.1 www.mzd020.cn 127.0.0.1 jzm015.cn 127.0.0.1 down.hs7yue.cn 127.0.0.1 new.doups.cn 127.0.0.1 w.qq-uc.cn 127.0.0.1 down.nihao69.cn 127.0.0.1 www.rty456.cn 127.0.0.1 www.werqwer.cn 127.0.0.1 1.360-1.cn 127.0.0.1 5.360-5.cn 127.0.0.1 user1.23-16.net 127.0.0.1 user1.23-18.net 127.0.0.1 www.guccia.net 127.0.0.1 www.interoo.net 127.0.0.1 upa.netsool.net 127.0.0.1 pua.lianxiac.net 127.0.0.1 js.users.51.la 127.0.0.1 vip2.51.la 127.0.0.1 web.51.la 127.0.0.1 qq.gong2008.com 127.0.0.1 2008tl.copyip.com 127.0.0.1 tla.laozihuolaile.cn 127.0.0.1 www.tx6868.cn 127.0.0.1 p001.tiloaiai.com 127.0.0.1 s1.tl8tl.com 127.0.0.1 s1.gong2008.com 127.0.0.1 mm1.laozihuolaile.cn 127.0.0.1 mm2.laozihuolaile.cn 127.0.0.1 tlbm2.laozihuolaile.cn 127.0.0.1 tlbm3.laozihuolaile.cn 127.0.0.1 www.6161q1.cn 127.0.0.1 www.6161q2.cn 127.0.0.1 www.6161h1.cn 127.0.0.1 www.6161h2.cn ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 1456, C:\DOCUMENTS AND SETTINGS\ADMIN\桌面\SRENG2\SRENGLDR.EXE] ================================== API HOOK RVA 错误: LoadLibraryA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) RVA 错误: LoadLibraryExA (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) RVA 错误: LoadLibraryExW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) RVA 错误: LoadLibraryW (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) RVA 错误: GetProcAddress (危险等级: 高, 被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys) ================================== 隐藏进程 N/A ================================== [/CODE]