[CODE] 2008-12-25,15:21:53 System Repair Engineer 2.7.0.1210 Smallfrogs (http://www.KZTechs.com) Windows 2000 Server Service Pack 4 (Build 2195) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 计划任务 API HOOK 隐藏进程 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [N/A] <"C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE> [(Verified)"McAfee, Inc."] <"C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey> [(Verified)"McAfee, Inc."] [File is missing] <"C:\Program Files\Rising\AntiSpyware\rstray.exe" /startup> [(Verified)Beijing Rising Information Technology Corporation Limited] <"C:\Program Files\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Information Technology Corporation Limited] [就要安插件联盟] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows 2000 Publisher] [File is missing] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AEB6717E-7E19-11d0-97EE-00C04FD91972}> [(Verified)Microsoft Windows Component Publisher] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}> [(Verified)Beijing Rising Information Technology Corporation Limited] <{EF8EFC85-0038-479B-BB0E-B0A52A15CECA}> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] [(Verified)Microsoft Windows 2000 Publisher] <%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\PCANotify] [Symantec Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] <自定义浏览器> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6A5110B5-E14B-4268-A065-EF89FF33C325}] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] <%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] <%SystemRoot%\system32\updcrl.exe -e -u %SystemRoot%\system32\verisignpub1.crl> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kissvc.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVHistory.kxp] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVPopup.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVRun.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVScanSys.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PromptIns.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwstub.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeboxtray.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SetupLD.exe] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Thunder5.exe] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VirusBox.kxp] [N/A] ================================== 启动文件夹 N/A ================================== 服务 [ASP.NET State Service / aspnet_state][Stopped/Manual Start] [pcAnywhere Host Service / awhost32][Stopped/Manual Start] [Background Intelligent Transfer Service / BITS][Stopped/Auto Start] C:\WINNT1\system32\TcmbtqD.dll><@ Microsoft Corporation. All rights reserved.> [Windows XP CDN Promote Client / cdnksvc][Stopped/Disabled] c:\winnt1\system32\cdnksvc.dll> [Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start] [DNS Server / Dnsservice][Stopped/Manual Start] %SystemRoot%\System32\qwaggh.dll> [GhostStartService / GhostStartService][Stopped/Manual Start] [Irmon System Services / Irmon][Stopped/Manual Start] %SystemRoot%\system32\a.dll> [CNG Key Service / KeySvc][Stopped/Manual Start] <(File is missing)> [McAfee Framework Service / McAfeeFramework][Stopped/Auto Start] <"C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart> [McAfee McShield / McShield][Running/Auto Start] <"C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe"> [McAfee Task Manager / McTaskManager][Running/Auto Start] <"C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe"> [Media Serial Number Service / MPlugPlay][Stopped/Disabled] %SystemRoot%\System32\lsjctc.dll> [NVIDIA Dispy Driverv / NVIDIA Dispy Driverv][Running/Auto Start] [Port Share Service / PortShare][Stopped/Disabled] <(File is missing)> [Remote Procedure Call (RPC) / RpcSs][Others/Auto Start] c:\winnt1\system32\rpcss.dll> [Rising Process Communication Center / RsCCenter][Stopped/Auto Start] <"C:\Program Files\Rising\Rav\CCenter.exe"> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"> [System Event Log Service / SystemLog][Stopped/Auto Start] [Windows UPNP Shell Uninterruptible Power Supply / uppnssvc][Stopped/Disabled] c:\winnt1\system32\uppnssvc.dll> [Windows DDK Machine Debug Manager / vnjdksvc][Stopped/Disabled] c:\winnt1\system32\vnjdksvc.dll> ================================== 驱动程序 [acpidisk / acpidisk][Running/Auto Start] <\??\C:\WINNT1\system32\drivers\acpidisk.sys> [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start] [aliimz / aliimz][Stopped/Manual Start] [atirage3 / atirage3][Running/Manual Start] [awecho / awecho][Running/System Start] [awlegacy / awlegacy][Running/System Start] <\SystemRoot\System32\Drivers\awlegacy.sys> [AW_HOST / AW_HOST][Running/System Start] [Broadcom NetXtreme Gigabit Ethernet / b57w2k][Running/Manual Start] [dmboot / dmboot][Stopped/Disabled] [Logical Disk Manager Driver / dmio][Running/Boot Start] <\SystemRoot\System32\drivers\dmio.sys> [dmload / dmload][Running/Boot Start] <\SystemRoot\System32\drivers\dmload.sys> [GhostPciScanner / GhPciScan][Running/System Start] <\??\C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys> [HookCont / HookCont][Running/System Start] <\SystemRoot\system32\drivers\HookCont.sys> [HookNtos / HookNtos][Running/System Start] <\SystemRoot\system32\drivers\HookNtos.sys> [HookReg / HookReg][Running/System Start] <\SystemRoot\system32\drivers\HookReg.sys> [HookSys / HookSys][Stopped/Disabled] <\SystemRoot\system32\drivers\HookSys.sys> [IBM (Version 5.25) Automatic Server Restart / ibmspw][Running/Manual Start] [icml / icml][Running/Boot Start] <\SystemRoot\system32\drivers\khq.sys> [4ZQPNVMJ / M2745MACE][Stopped/Manual Start] <\??\C:\WINNT1\DKTF09NJA.txt> [McAfee Inc. / mfeapfk][Running/Manual Start] [McAfee Inc. / mfeavfk][Running/Manual Start] [McAfee Inc. / mfebopk][Running/Manual Start] [McAfee Inc. / mfehidk][Running/Manual Start] [VSCore mferkdk / mferkdk][Running/System Start] <\??\C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys> [McAfee Inc. / mfetdik][Running/System Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [SymEvent / SymEvent][Stopped/Manual Start] <\??\C:\Program Files\Symantec\SYMEVENT.SYS> [yhsfibby / yhsfibby][Stopped/Auto Start] <\??\C:\WINNT1\system32\drivers\jwozav.sys> [yhvbxtsi / yhvbxtsi][Stopped/Auto Start] <\??\C:\WINNT1\system32\drivers\tvghbh.sys> [yvfcjnct / yvfcjnct][Stopped/Auto Start] <\??\C:\WINNT1\system32\drivers\wgvfir.sys> ================================== 浏览器加载项 [AcroIEHlprObj Class] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [Info cache] {295AB8C6-FB22-4D17-8834-064E2BA0A6F0} [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [] {EF8EFC85-0038-479B-BB0E-B0A52A15CECA} [@shdoclc.dll,-866] {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, > [电台(&R)] {8E718888-423F-11D2-876E-00A0C9082467} [Netvisiondvr Control] {3896F800-6EFB-422F-A04B-AA7D44D9A4A9} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} <, > ================================== 正在运行的进程 [PID: 168][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.00.2195.6601] [PID: 200][\??\C:\WINNT1\system32\csrss.exe] [Microsoft Corporation, 5.00.2195.6601] [C:\WINNT1\system32\MSVCRT.dll] [Microsoft Corporation, 6.00.8797.0] [PID: 220][\??\C:\WINNT1\system32\winlogon.exe] [Microsoft Corporation, 5.00.2195.6997] [C:\WINNT1\system32\MSVCRT.dll] [Microsoft Corporation, 6.00.8797.0] [C:\WINNT1\system32\sfc.dll] [Microsoft Corporation, 5.00.2195.6673] [C:\WINNT1\system32\winlib .dll] [N/A, ] [C:\WINNT1\system32\PCANotify.dll] [Symantec Corporation, 11.5.0.121] [C:\WINNT1\system32\MSVCR70.dll] [Microsoft Corporation, 7.00.9466.0] [PID: 248][C:\WINNT1\system32\services.exe] [Microsoft Corporation, 5.00.2195.7035] [C:\WINNT1\system32\MSVCRT.dll] [Microsoft Corporation, 6.00.8797.0] [PID: 260][C:\WINNT1\system32\lsass.exe] [Microsoft Corporation, 5.00.2195.7011] [C:\WINNT1\system32\MSVCRT.dll] [Microsoft Corporation, 6.00.8797.0] [PID: 464][C:\WINNT1\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1] [C:\WINNT1\system32\msvcrt.dll] [Microsoft Corporation, 6.00.8797.0] [C:\WINNT1\system32\MSVCP60.dll] [Microsoft Corporation, 6.00.8972.0] [PID: 584][C:\PROGRAM FILES\RISING\RAV\RavStub.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.10] [C:\WINNT1\system32\MSVCRT.dll] [Microsoft Corporation, 6.00.8797.0] [C:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [PID: 660][C:\WINNT1\System32\llssrv.exe] [Microsoft Corporation, 5.00.2195.7021] [C:\WINNT1\system32\MSVCRT.dll] [Microsoft Corporation, 6.00.8797.0] [PID: 692][C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe] [McAfee, Inc., VSCORE.13.3.1.100.x86] [C:\WINNT1\system32\MSVCRT.DLL] [Microsoft Corporation, 6.00.8797.0] [C:\Program Files\McAfee\VirusScan Enterprise\LockDown.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86] [C:\Program Files\McAfee\VirusScan Enterprise\mytilus.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86] [C:\Program Files\McAfee\VirusScan Enterprise\mytilus2.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86] [C:\Program Files\McAfee\VirusScan Enterprise\RES0402\McShield.dll] [McAfee, Inc., VSCORE.13.3.1.100] [C:\Program Files\McAfee\VirusScan Enterprise\FTL.Dll] [McAfee, Inc., VSCORE.13.3.1.100.x86] [C:\Program Files\McAfee\VirusScan Enterprise\naiann.dll] [McAfee, Inc., 8.5.0.781] [C:\Program Files\McAfee\VirusScan Enterprise\VsEvntUI.dll] [N/A, ] [C:\Program Files\McAfee\VirusScan Enterprise\NAEvent.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86] [C:\Program Files\McAfee\VirusScan Enterprise\shutil.dll] [McAfee, Inc., 8.5.0.781] [C:\Program Files\McAfee\VirusScan Enterprise\wmain.dll] [McAfee, Inc., 8.5.0.781] [C:\Program Files\McAfee\Common Framework\GenEvtInf.dll] [McAfee, Inc., 3.6.0.453] [C:\Program Files\McAfee\Common Framework\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\McAfee\Common Framework\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\McAfee\Common Framework\SecureFrameworkFactory.dll] [McAfee, Inc., 3.6.0.453] [C:\Program Files\McAfee\VirusScan Enterprise\scriptsv.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86] [C:\Program Files\McAfee\VirusScan Enterprise\mfebopa.dll] [McAfee, Inc., SYSCORE.13.3.0.116.x86] [C:\Program Files\McAfee\VirusScan Enterprise\mfehida.dll] [McAfee, Inc., SYSCORE.13.3.0.116.x86] [C:\Program Files\McAfee\VirusScan Enterprise\mfeapfa.dll] [McAfee, Inc., SYSCORE.13.3.0.116.x86] [C:\Program Files\McAfee\VirusScan Enterprise\mfeavfa.dll] [McAfee, Inc., SYSCORE.13.3.0.116.x86] [C:\Program Files\Common Files\McAfee\Engine\mcscan32.dll] [McAfee, Inc., 5.3.00] [PID: 780][C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe] [McAfee, Inc., 8.5.0.781] [C:\Program Files\McAfee\VirusScan Enterprise\LockDown.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86] [C:\WINNT1\system32\msvcrt.dll] [Microsoft Corporation, 6.00.8797.0] [C:\Program Files\McAfee\VirusScan Enterprise\mytilus2.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86] [C:\Program Files\McAfee\VirusScan Enterprise\mytilus.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86] [C:\Program Files\McAfee\VirusScan Enterprise\shutil.dll] [McAfee, Inc., 8.5.0.781] [C:\Program Files\McAfee\VirusScan Enterprise\wmain.dll] [McAfee, Inc., 8.5.0.781] [C:\Program Files\McAfee\VirusScan Enterprise\condl.dll] [McAfee, Inc., 8.5.0.781] [C:\Program Files\McAfee\VirusScan Enterprise\RES0402\McShield.dll] [McAfee, Inc., VSCORE.13.3.1.100] [C:\Program Files\McAfee\VirusScan Enterprise\MIDUtil.Dll] [McAfee, Inc., 8.5.0.148] [PID: 908][C:\WINNT1\system32\Dfssvc.exe] [Microsoft Corporation, 5.00.2195.6664] [C:\WINNT1\system32\MSVCRT.dll] [Microsoft Corporation, 6.00.8797.0] [PID: 788][C:\WINNT1\system32\cmd.exe] [Microsoft Corporation, 5.00.2195.6995] [C:\WINNT1\system32\MSVCRT.dll] [Microsoft Corporation, 6.00.8797.0] [PID: 768][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2800.1106] [C:\WINNT1\system32\msvcrt.dll] [Microsoft Corporation, 6.00.8797.0] [C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [PID: 1120][C:\WINNT1\Explorer.EXE] [Microsoft Corporation, 5.00.3700.6690] [C:\WINNT1\system32\msvcrt.dll] [Microsoft Corporation, 6.00.8797.0] [C:\Program Files\McAfee\Common Framework\JrMac.dll] [McAfee, Inc., 1.0.0.125] [C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [C:\WINNT1\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.18] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [PID: 1180][C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE] [McAfee, Inc., 8.5.0.781] [C:\Program Files\McAfee\VirusScan Enterprise\LockDown.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86] [C:\WINNT1\system32\msvcrt.dll] [Microsoft Corporation, 6.00.8797.0] [C:\Program Files\McAfee\VirusScan Enterprise\ftcfg.dll] [McAfee, Inc., 8.5.0.781] [C:\Program Files\McAfee\VirusScan Enterprise\mytilus2.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86] [C:\Program Files\McAfee\VirusScan Enterprise\mytilus.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86] [C:\Program Files\McAfee\VirusScan Enterprise\wmain.dll] [McAfee, Inc., 8.5.0.781] [C:\Program Files\McAfee\VirusScan Enterprise\shutil.dll] [McAfee, Inc., 8.5.0.781] [C:\Program Files\McAfee\VirusScan Enterprise\RES0402\McShield.dll] [McAfee, Inc., VSCORE.13.3.1.100] [C:\Program Files\McAfee\VirusScan Enterprise\Graphics.dll] [McAfee, Inc., 8.5.0.781] [PID: 1204][C:\Program Files\Rising\AntiSpyware\rstray.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.16] [C:\Program Files\Rising\AntiSpyware\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 8] [C:\WINNT1\system32\msvcrt.dll] [Microsoft Corporation, 6.00.8797.0] [C:\Program Files\Rising\AntiSpyware\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [C:\Program Files\Rising\AntiSpyware\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\Program Files\Rising\AntiSpyware\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\Program Files\Rising\AntiSpyware\ComServ.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.31] [C:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [C:\Program Files\Rising\AntiSpyware\rscommon.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.1.1] [C:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.37] [C:\Program Files\Rising\AntiSpyware\pngdll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [C:\Program Files\Rising\AntiSpyware\runiep.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.42] [C:\Program Files\Rising\AntiSpyware\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.11] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\AntiSpyware\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\WINNT1\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.18] [PID: 1212][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.24] [C:\WINNT1\system32\msvcrt.dll] [Microsoft Corporation, 6.00.8797.0] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [PID: 1224][C:\WINNT1\system32\internat.exe] [Microsoft Corporation, 5.00.2920.0000] [C:\WINNT1\system32\MSVCRT.DLL] [Microsoft Corporation, 6.00.8797.0] [PID: 1284][C:\Program Files\McAfee\Common Framework\McTray.exe] [McAfee, Inc., 1.0.0.125] [C:\Program Files\McAfee\Common Framework\JrMac.dll] [McAfee, Inc., 1.0.0.125] [C:\WINNT1\system32\msvcrt.dll] [Microsoft Corporation, 6.00.8797.0] [PID: 140][C:\Documents and Settings\Administrator.WEB\桌面\SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210] [PID: 1428][C:\Documents and Settings\Administrator.WEB\桌面\SREcf150e09.EXE] [Smallfrogs Studio, 2.7.0.1210] [C:\WINNT1\system32\msvcrt.dll] [Microsoft Corporation, 6.00.8797.0] [C:\WINNT1\system32\sfc.dll] [Microsoft Corporation, 5.00.2195.6673] ================================== 文件关联 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINNT1\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 N/A ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 1284, C:\PROGRAM FILES\MCAFEE\COMMON FRAMEWORK\MCTRAY.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 140, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.WEB\桌面\SRENGLDR.EXE] ================================== 计划任务 N/A ================================== API HOOK N/A ================================== 隐藏进程 [820] C:\WINNT1\NVIDIA.exe ================================== [/CODE]