[CODE] 2008-11-14,01:59:20 System Repair Engineer 2.7.0.1210 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [NVIDIA Corporation] [] [NVIDIA Corporation] [] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] [] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] [] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AEB6717E-7E19-11d0-97EE-00C04FD91972}> [(Verified)Microsoft Windows Component Publisher] <{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}><122B901E.dll> [] <{C8FFD223-C0FB-40C5-94A0-FD7891AC18E9}> [] <{D7C79813-9233-4AE0-832C-99B2E8019673}> [] <{F65BDEC7-4BF3-4512-840F-68B166B6D7AC}> [] <{E4814792-EFA3-4C20-93D0-8B130A59F9A8}> [] <{755D0ED0-3996-4ADB-9B1F-AD8F0E9E4738}><755D0ED0.dll> [] <{9F684DE8-3E87-4174-9033-E02A3DFD8B61}><9F684DE8.dll> [] <{43ACDCC5-9009-4AF4-B80A-93BC656EF298}><43ACDCC5.dll> [] <{4FBFD5A4-5FE8-4444-8BD9-FD0FAFA64F96}><4FBFD5A4.dll> [] <{BA7EDF54-8408-4B21-B351-7B447B344BA4}> [] <{DA63E650-537C-4042-87BB-9D19D844680B}> [] <{B3721C07-62B3-411A-9DC7-F5F27E3E21FF}> [] <{58FF3024-8A83-4B1A-88E9-302F47646EEE}><58FF3024.dll> [] <{66AFCB56-FAA9-42D2-8C72-2767A46C7FA8}><66AFCB56.dll> [] <{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E}><08223B03.dll> [] <{9CA963CA-107C-4089-B0AB-31380F90D7E3}><9CA963CA.dll> [] <{2EF0D734-21FD-4225-A1A2-BCD296182AAF}><2EF0D734.dll> [] <{F6A454AE-156A-415E-9F89-3795677A8A91}> [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher] <%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <浏览器自定义组件> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows Publisher] [HKEY_CURRENT_USER\Control Panel\Desktop] [(Verified)Microsoft Windows Publisher] ================================== 启动文件夹 N/A ================================== 服务 [DCOM Server Process Launcher / DcomLaunch][Running/Auto Start] %SystemRoot%\system32\rpcss.dll> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [Windows Installer / MSIServer][Stopped/Manual Start] [NVIDIA Display Driver Service / NVSvc][Running/Auto Start] [Remote Procedure Call (RPC) / RpcSs][Running/Auto Start] %SystemRoot%\system32\rpcss.dll> ================================== 驱动程序 [GMSIPCI / GMSIPCI][Stopped/Manual Start] <\??\G:\INSTALL\GMSIPCI.SYS> [Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start] [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start] [MSICPL / MSICPL][Stopped/Manual Start] <\??\G:\install4\MSICPL.sys> [NTACCESS / NTACCESS][Stopped/Manual Start] <\??\G:\NTACCESS.sys> [nv / nv][Running/Manual Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver / RTLE8023xp][Running/Manual Start] [Secdrv / Secdrv][Stopped/Manual Start] [SetupNTGLM7X / SetupNTGLM7X][Stopped/Manual Start] <\??\G:\NTGLM7X.sys> [TCP/IP Protocol Driver / Tcpip][Running/System Start] [HBKernel32 Driver / HBKernel32][Stopped/Boot Start] <\SystemRoot\system32\drivers\HBKernel32.sys> [Kisstusb / Kisstusb][Running/] <2 - 系统找不到指定的文件。 > [c39e8db / c39e8db][Stopped/Manual Start] <\??\C:\WINDOWS\system32\c39e8db.sys> [aliimz / aliimz][Stopped/Manual Start] [d7b49fa / d7b49fa][Stopped/Manual Start] <\??\C:\WINDOWS\system32\d7b49fa.sys> [de8296f / de8296f][Running/Manual Start] <\??\C:\WINDOWS\system32\de8296f.sys> ================================== 浏览器加载项 [SrchHook Class] {F08555B0-9CC3-11D2-AA8E-000000000000} [] {F6A454AE-156A-415E-9F89-3795677A8A91} [番茄花园] {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} [番茄工具条3.21] {6451F285-9E41-4D8C-813D-794CA7BFEAB4} [] {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <, > [番茄工具条3.21] {6451F285-9E41-4D8C-813D-794CA7BFEAB4} [360SafeLive] {87515F61-A66C-4319-A0E0-D416CB8059E3} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [SrchHook Class] {F08555B0-9CC3-11D2-AA8E-000000000000} [] {F6A454AE-156A-415E-9F89-3795677A8A91} [查看当前站点排名] ================================== 正在运行的进程 [PID: 628 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 688 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 712 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 756 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 768 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 920 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [c:\windows\system32\rpcss.dll] [N/A, ] [PID: 996 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [c:\windows\system32\rpcss.dll] [N/A, ] [PID: 1092 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1172 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1256 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1412 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp.050610-1527)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1608 / Administrator][C:\WINDOWS\system32\userinit.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\D7C79813.dll] [N/A, ] [C:\WINDOWS\system32\755D0ED0.dll] [N/A, ] [C:\WINDOWS\system32\43ACDCC5.dll] [N/A, ] [C:\WINDOWS\system32\4FBFD5A4.dll] [N/A, ] [C:\WINDOWS\system32\DA63E650.dll] [N/A, ] [C:\WINDOWS\system32\58FF3024.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\Program Files\Internet Explorer\53u1ttMe.2ys] [N/A, ] [PID: 1636 / Administrator][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_qfe.070613-1311)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\HBmhly.dll] [N/A, ] [C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.11.7531] [C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.11.7531] [C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.7531] [C:\WINDOWS\system32\nvshell.dll] [, ] [C:\WINDOWS\system32\HBJTLQ.dll] [N/A, ] [C:\WINDOWS\system32\HBWOW.dll] [N/A, ] [C:\WINDOWS\system32\HBDNF.dll] [N/A, ] [C:\WINDOWS\system32\HBTL.dll] [N/A, ] [C:\WINDOWS\system32\HBQQSG.dll] [N/A, ] [C:\WINDOWS\system32\HBQQXX.dll] [N/A, ] [C:\WINDOWS\system32\D7C79813.dll] [N/A, ] [C:\WINDOWS\system32\122B901E.dll] [N/A, ] [C:\WINDOWS\system32\C8FFD223.dll] [N/A, ] [C:\WINDOWS\system32\F65BDEC7.dll] [N/A, ] [C:\WINDOWS\system32\E4814792.dll] [N/A, ] [C:\WINDOWS\system32\sh18015.dll] [N/A, ] [C:\WINDOWS\system32\sh05003.dll] [N/A, ] [C:\WINDOWS\system32\sh01008.dll] [N/A, ] [C:\WINDOWS\system32\sh14010.dll] [N/A, ] [C:\WINDOWS\system32\755D0ED0.dll] [N/A, ] [C:\WINDOWS\system32\43ACDCC5.dll] [N/A, ] [C:\WINDOWS\system32\4FBFD5A4.dll] [N/A, ] [C:\WINDOWS\system32\DA63E650.dll] [N/A, ] [C:\WINDOWS\system32\58FF3024.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\WINDOWS\system32\LeakCheck.dll] [N/A, ] [C:\Program Files\Internet Explorer\53u1ttMe.2ys] [N/A, ] [C:\WINDOWS\system32\9F684DE8.dll] [N/A, ] [C:\WINDOWS\system32\BA7EDF54.dll] [N/A, ] [C:\WINDOWS\system32\B3721C07.dll] [N/A, ] [C:\WINDOWS\system32\66AFCB56.dll] [N/A, ] [C:\WINDOWS\system32\9CA963CA.dll] [N/A, ] [PID: 1716 / Administrator][C:\WINDOWS\RTHDCPL.EXE] [Realtek Semiconductor Corp., 2.2.2.5] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\D7C79813.dll] [N/A, ] [C:\WINDOWS\system32\755D0ED0.dll] [N/A, ] [C:\WINDOWS\system32\43ACDCC5.dll] [N/A, ] [C:\WINDOWS\system32\4FBFD5A4.dll] [N/A, ] [C:\WINDOWS\system32\DA63E650.dll] [N/A, ] [C:\WINDOWS\system32\58FF3024.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\Program Files\Internet Explorer\53u1ttMe.2ys] [N/A, ] [PID: 1776 / Administrator][C:\WINDOWS\system32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\NvMcTray.dll] [NVIDIA Corporation, 6.14.11.7531] [C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.7531] [C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.11.7531] [C:\WINDOWS\system32\D7C79813.dll] [N/A, ] [C:\WINDOWS\system32\43ACDCC5.dll] [N/A, ] [C:\WINDOWS\system32\755D0ED0.dll] [N/A, ] [C:\WINDOWS\system32\4FBFD5A4.dll] [N/A, ] [C:\WINDOWS\system32\58FF3024.dll] [N/A, ] [C:\WINDOWS\system32\DA63E650.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\Program Files\Internet Explorer\53u1ttMe.2ys] [N/A, ] [PID: 1784 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\D7C79813.dll] [N/A, ] [C:\WINDOWS\system32\755D0ED0.dll] [N/A, ] [C:\WINDOWS\system32\43ACDCC5.dll] [N/A, ] [C:\WINDOWS\system32\4FBFD5A4.dll] [N/A, ] [C:\WINDOWS\system32\DA63E650.dll] [N/A, ] [C:\WINDOWS\system32\58FF3024.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\Program Files\Internet Explorer\53u1ttMe.2ys] [N/A, ] [PID: 436 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.11.7531] [C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.7531] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1892 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1932 / Administrator][C:\WINDOWS\system32\System.exe] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\HBmhly.dll] [N/A, ] [C:\WINDOWS\system32\HBJTLQ.dll] [N/A, ] [C:\WINDOWS\system32\HBWOW.dll] [N/A, ] [C:\WINDOWS\system32\HBWD.dll] [N/A, ] [C:\WINDOWS\system32\HBTL.dll] [N/A, ] [C:\WINDOWS\system32\HBDNF.dll] [N/A, ] [C:\WINDOWS\system32\D7C79813.dll] [N/A, ] [C:\WINDOWS\system32\HBQQXX.dll] [N/A, ] [C:\WINDOWS\system32\HBQQSG.dll] [N/A, ] [C:\WINDOWS\system32\755D0ED0.dll] [N/A, ] [C:\WINDOWS\system32\43ACDCC5.dll] [N/A, ] [C:\WINDOWS\system32\4FBFD5A4.dll] [N/A, ] [C:\WINDOWS\system32\DA63E650.dll] [N/A, ] [C:\WINDOWS\system32\58FF3024.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\Program Files\Internet Explorer\53u1ttMe.2ys] [N/A, ] [PID: 1476 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\HBmhly.dll] [N/A, ] [C:\WINDOWS\system32\D7C79813.dll] [N/A, ] [C:\WINDOWS\system32\43ACDCC5.dll] [N/A, ] [C:\WINDOWS\system32\755D0ED0.dll] [N/A, ] [C:\WINDOWS\system32\4FBFD5A4.dll] [N/A, ] [C:\WINDOWS\system32\58FF3024.dll] [N/A, ] [C:\WINDOWS\system32\DA63E650.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\Program Files\Internet Explorer\53u1ttMe.2ys] [N/A, ] [PID: 1564 / Administrator][C:\DOCUME~1\ADMINI~1.507\LOCALS~1\Temp\evcDE.tmp] [, 1, 0, 0, 1] [C:\WINDOWS\system32\HBmhly.dll] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 2868 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\HBmhly.dll] [N/A, ] [C:\WINDOWS\system32\HBJTLQ.dll] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\IETool.dll] [N/A, ] [C:\WINDOWS\system32\IEBHO.dll] [N/A, ] [C:\WINDOWS\system32\HBTL.dll] [N/A, ] [C:\WINDOWS\system32\HBDNF.dll] [N/A, ] [C:\WINDOWS\system32\HBQQXX.dll] [N/A, ] [C:\WINDOWS\system32\HBWOW.dll] [N/A, ] [C:\WINDOWS\system32\D7C79813.dll] [N/A, ] [C:\WINDOWS\system32\HBQQSG.dll] [N/A, ] [C:\WINDOWS\system32\755D0ED0.dll] [N/A, ] [C:\WINDOWS\system32\43ACDCC5.dll] [N/A, ] [C:\WINDOWS\system32\4FBFD5A4.dll] [N/A, ] [C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx] [Adobe Systems, Inc., 9,0,47,0] [C:\WINDOWS\system32\DA63E650.dll] [N/A, ] [C:\WINDOWS\system32\58FF3024.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\Program Files\Internet Explorer\53u1ttMe.2ys] [N/A, ] [C:\WINDOWS\system32\122B901E.dll] [N/A, ] [C:\WINDOWS\system32\C8FFD223.dll] [N/A, ] [C:\WINDOWS\system32\F65BDEC7.dll] [N/A, ] [C:\WINDOWS\system32\E4814792.dll] [N/A, ] [C:\WINDOWS\system32\9F684DE8.dll] [N/A, ] [C:\WINDOWS\system32\BA7EDF54.dll] [N/A, ] [C:\WINDOWS\system32\B3721C07.dll] [N/A, ] [C:\WINDOWS\system32\66AFCB56.dll] [N/A, ] [C:\WINDOWS\system32\9CA963CA.dll] [N/A, ] [PID: 3436 / Administrator][C:\WINDOWS\system32\NOTEPAD.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\UxTheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\HBmhly.dll] [N/A, ] [C:\WINDOWS\system32\HBJTLQ.dll] [N/A, ] [C:\WINDOWS\system32\HBWOW.dll] [N/A, ] [C:\WINDOWS\system32\HBWD.dll] [N/A, ] [C:\WINDOWS\system32\HBTL.dll] [N/A, ] [C:\WINDOWS\system32\HBDNF.dll] [N/A, ] [C:\WINDOWS\system32\HBQQXX.dll] [N/A, ] [C:\WINDOWS\system32\HBQQSG.dll] [N/A, ] [C:\WINDOWS\system32\D7C79813.dll] [N/A, ] [C:\WINDOWS\system32\43ACDCC5.dll] [N/A, ] [C:\WINDOWS\system32\755D0ED0.dll] [N/A, ] [C:\WINDOWS\system32\4FBFD5A4.dll] [N/A, ] [C:\WINDOWS\system32\58FF3024.dll] [N/A, ] [C:\WINDOWS\system32\DA63E650.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\Program Files\Internet Explorer\53u1ttMe.2ys] [N/A, ] [PID: 3708 / Administrator][C:\DOCUME~1\ADMINI~1.507\LOCALS~1\Temp\815065] [N/A, ] [C:\WINDOWS\system32\HBmhly.dll] [N/A, ] [C:\WINDOWS\system32\HBJTLQ.dll] [N/A, ] [C:\WINDOWS\system32\HBWOW.dll] [N/A, ] [C:\WINDOWS\system32\HBWD.dll] [N/A, ] [C:\WINDOWS\system32\HBTL.dll] [N/A, ] [C:\WINDOWS\system32\HBDNF.dll] [N/A, ] [C:\WINDOWS\system32\HBQQXX.dll] [N/A, ] [C:\WINDOWS\system32\HBQQSG.dll] [N/A, ] [PID: 3044 / Administrator][C:\DOCUME~1\ADMINI~1.507\LOCALS~1\Temp\866050] [N/A, ] [C:\WINDOWS\system32\HBmhly.dll] [N/A, ] [C:\WINDOWS\system32\HBWD.dll] [N/A, ] [C:\WINDOWS\system32\HBTL.dll] [N/A, ] [C:\WINDOWS\system32\HBDNF.dll] [N/A, ] [C:\WINDOWS\system32\HBQQXX.dll] [N/A, ] [C:\WINDOWS\system32\HBQQSG.dll] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Internet Explorer\53u1ttMe.2ys] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\58FF3024.dll] [N/A, ] [C:\WINDOWS\system32\DA63E650.dll] [N/A, ] [C:\WINDOWS\system32\4FBFD5A4.dll] [N/A, ] [C:\WINDOWS\system32\43ACDCC5.dll] [N/A, ] [C:\WINDOWS\system32\755D0ED0.dll] [N/A, ] [C:\WINDOWS\system32\D7C79813.dll] [N/A, ] [PID: 1220 / Administrator][C:\Documents and Settings\Administrator.5079C90BBA364D7\桌面\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210] [C:\WINDOWS\system32\HBmhly.dll] [N/A, ] [C:\WINDOWS\system32\HBWOW.dll] [N/A, ] [C:\WINDOWS\system32\HBDNF.dll] [N/A, ] [C:\WINDOWS\system32\HBTL.dll] [N/A, ] [C:\WINDOWS\system32\HBQQSG.dll] [N/A, ] [C:\WINDOWS\system32\HBQQXX.dll] [N/A, ] [C:\WINDOWS\system32\HBWD.dll] [N/A, ] [C:\WINDOWS\system32\HBJTLQ.dll] [N/A, ] [PID: 1544 / Administrator][C:\Documents and Settings\Administrator.5079C90BBA364D7\桌面\sreng2\SRE83455ede.EXE] [Smallfrogs Studio, 2.7.0.1210] [C:\WINDOWS\system32\HBmhly.dll] [N/A, ] [C:\WINDOWS\system32\HBWOW.dll] [N/A, ] [C:\WINDOWS\system32\HBDNF.dll] [N/A, ] [C:\WINDOWS\system32\HBTL.dll] [N/A, ] [C:\WINDOWS\system32\HBQQSG.dll] [N/A, ] [C:\WINDOWS\system32\HBQQXX.dll] [N/A, ] [C:\WINDOWS\system32\HBWD.dll] [N/A, ] [C:\WINDOWS\system32\HBJTLQ.dll] [N/A, ] [C:\WINDOWS\system32\uxtheme.dll] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Internet Explorer\53u1ttMe.2ys] [N/A, ] [C:\WINDOWS\system32\2EF0D734.dll] [N/A, ] [C:\WINDOWS\system32\08223B03.dll] [N/A, ] [C:\WINDOWS\system32\58FF3024.dll] [N/A, ] [C:\WINDOWS\system32\DA63E650.dll] [N/A, ] [C:\WINDOWS\system32\4FBFD5A4.dll] [N/A, ] [C:\WINDOWS\system32\43ACDCC5.dll] [N/A, ] [C:\WINDOWS\system32\755D0ED0.dll] [N/A, ] [C:\WINDOWS\system32\D7C79813.dll] [N/A, ] [C:\WINDOWS\system32\sfc_os.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Documents and Settings\Administrator.5079C90BBA364D7\桌面\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] ================================== 文件关联 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 v.onondown.com.cn 127.0.0.2 ymsdasdw1.cn 127.0.0.3 h96b.info 127.0.0.0 fuck.zttwp.cn 127.0.0.0 www.hackerbf.cn 127.0.0.0 geekbyfeng.cn 127.0.0.0 ppp.etimes888.com 127.0.0.0 www.bypk.com 127.0.0.1 va9sdhun23.cn 127.0.0.2 bnasnd83nd.cn 127.0.0.0 www.gamehacker.com.cn 127.0.0.0 gamehacker.com.cn 127.0.0.3 adlaji.cn 127.0.0.1 858656.com 127.1.1.1 bnasnd83nd.cn 127.0.0.1 my123.com 127.0.0.0 user1.12-27.net 127.0.0.1 8749.com 127.0.0.0 fengent.cn 127.0.0.1 4199.com 127.0.0.1 user1.16-22.net 127.0.0.1 7379.com 127.0.0.1 2be37c5f.3f6e2cc5f0b.com 127.0.0.1 7255.com 127.0.0.1 user1.23-12.net 127.0.0.1 3448.com 127.0.0.1 www.guccia.net 127.0.0.1 7939.com 127.0.0.1 a.o1o1o1.nEt 127.0.0.1 8009.com 127.0.0.1 user1.12-73.cn 127.0.0.1 piaoxue.com 127.0.0.1 3n8nlasd.cn 127.0.0.1 kzdh.com 127.0.0.0 www.sony888.cn 127.0.0.1 about.blank.la 127.0.0.0 user1.asp-33.cn 127.0.0.1 6781.com 127.0.0.0 www.netkwek.cn 127.0.0.1 7322.com 127.0.0.0 ymsdkad6.cn 127.0.0.1 localhost 127.0.0.0 www.lkwueir.cn 127.0.0.1 06.jacai.com 127.0.1.1 user1.23-17.net 127.0.0.1 1.jopenkk.com 127.0.0.0 upa.luzhiai.net 127.0.0.1 1.jopenqc.com 127.0.0.0 www.guccia.net 127.0.0.1 1.joppnqq.com 127.0.0.0 4m9mnlmi.cn 127.0.0.1 1.xqhgm.com 127.0.0.0 mm119mkssd.cn 127.0.0.1 100.332233.com 127.0.0.0 61.128.171.115:8080 127.0.0.1 121.11.90.79 127.0.0.0 www.1119111.com 127.0.0.1 121565.net 127.0.0.0 win.nihao69.cn 127.0.0.1 125.90.88.38 127.0.0.1 16888.6to23.com 127.0.0.1 2.joppnqq.com 127.0.0.0 puc.lianxiac.net 127.0.0.1 204.177.92.68 127.0.0.0 pud.lianxiac.net 127.0.0.1 210.74.145.236 127.0.0.0 210.76.0.133 127.0.0.1 219.129.239.220 127.0.0.0 61.166.32.2 127.0.0.1 219.153.40.221 127.0.0.0 218.92.186.27 127.0.0.1 219.153.46.27 127.0.0.0 www.fsfsfag.cn 127.0.0.1 219.153.52.123 127.0.0.0 ovo.ovovov.cn 127.0.0.1 221.195.42.71 127.0.0.0 dw.com.com 127.0.0.1 222.73.218.115 127.0.0.1 203.110.168.233:80 127.0.0.1 3.joppnqq.com 127.0.0.1 203.110.168.221:80 127.0.0.1 363xx.com 127.0.0.1 www1.ip10086.com.cm 127.0.0.1 4199.com 127.0.0.1 blog.ip10086.com.cn 127.0.0.1 43242.com 127.0.0.1 www.ccji68.cn 127.0.0.1 5.xqhgm.com 127.0.0.0 t.myblank.cn 127.0.0.1 520.mm5208.com 127.0.0.0 x.myblank.cn 127.0.0.1 59.34.131.54 127.0.0.1 210.51.45.5 127.0.0.1 59.34.198.228 127.0.0.1 www.ew1q.cn 127.0.0.1 59.34.198.88 127.0.0.1 59.34.198.97 127.0.0.1 60.190.114.101 127.0.0.1 60.190.218.34 127.0.0.0 qq-xing.com.cn 127.0.0.1 60.191.124.252 127.0.0.1 61.145.117.212 127.0.0.1 61.157.109.222 127.0.0.1 75.126.3.216 127.0.0.1 75.126.3.217 127.0.0.1 75.126.3.218 127.0.0.0 59.125.231.177:17777 127.0.0.1 75.126.3.220 127.0.0.1 75.126.3.221 127.0.0.1 75.126.3.222 127.0.0.1 772630.com 127.0.0.1 832823.cn 127.0.0.1 8749.com 127.0.0.1 888.jopenqc.com 127.0.0.1 89382.cn 127.0.0.1 8v8.biz 127.0.0.1 97725.com 127.0.0.1 9gg.biz 127.0.0.1 www.9000music.com 127.0.0.1 test.591jx.com 127.0.0.1 a.topxxxx.cn 127.0.0.1 picon.chinaren.com 127.0.0.1 www.5566.net 127.0.0.1 p.qqkx.com 127.0.0.1 news.netandtv.com 127.0.0.1 z.neter888.cn 127.0.0.1 b.myblank.cn 127.0.0.1 wvw.wokutu.com 127.0.0.1 unionch.qyule.com 127.0.0.1 www.qyule.com 127.0.0.1 it.itjc.cn 127.0.0.1 www.linkwww.com 127.0.0.1 vod.kaicn.com 127.0.0.1 www.tx8688.com 127.0.0.1 b.neter888.cn 127.0.0.1 promote.huanqiu.com 127.0.0.1 www.huanqiu.com 127.0.0.1 www.haokanla.com 127.0.0.1 play.unionsky.cn 127.0.0.1 www.52v.com 127.0.0.1 www.gghka.cn 127.0.0.1 icon.ajiang.net 127.0.0.1 new.ete.cn 127.0.0.1 www.stiae.cn 127.0.0.1 o.neter888.cn 127.0.0.1 comm.jinti.com 127.0.0.1 www.google-analytics.com 127.0.0.1 hz.mmstat.com 127.0.0.1 www.game175.cn 127.0.0.1 x.neter888.cn 127.0.0.1 z.neter888.cn 127.0.0.1 p.etimes888.com 127.0.0.1 hx.etimes888.com 127.0.0.1 abc.qqkx.com 127.0.0.1 dm.popdm.cn 127.0.0.1 www.yl9999.com 127.0.0.1 www.dajiadoushe.cn 127.0.0.1 v.onondown.com.cn 127.0.0.1 www.interoo.net 127.0.0.1 bally1.bally-bally.net 127.0.0.1 www.bao5605509.cn 127.0.0.1 www.rty456.cn 127.0.0.1 www.werqwer.cn 127.0.0.1 1.360-1.cn 127.0.0.1 user1.23-16.net 127.0.0.1 www.guccia.net 127.0.0.1 www.interoo.net 127.0.0.1 upa.netsool.net 127.0.0.1 js.users.51.la 127.0.0.1 vip2.51.la 127.0.0.1 web.51.la 127.0.0.1 qq.gong2008.com 127.0.0.1 2008tl.copyip.com 127.0.0.1 tla.laozihuolaile.cn 127.0.0.1 www.tx6868.cn 127.0.0.1 p001.tiloaiai.com 127.0.0.1 s1.tl8tl.com 127.0.0.1 s1.gong2008.com 127.0.0.1 4b3ce56f9g.3f6e2cc5f0b.com 127.0.0.1 2be37c5f.3f6e2cc5f0b.com ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 436, C:\WINDOWS\SYSTEM32\NVSVC32.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 1564, C:\DOCUME~1\ADMINI~1.507\LOCALS~1\TEMP\EVCDE.TMP] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1564, C:\DOCUME~1\ADMINI~1.507\LOCALS~1\TEMP\EVCDE.TMP] 特殊特权被允许: SeDebugPrivilege [PID = 1220, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.5079C90BBA364D7\桌面\SRENG2\SRENGLDR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1220, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.5079C90BBA364D7\桌面\SRENG2\SRENGLDR.EXE] ================================== 计划任务 N/A ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]