附件是我拿照相机拍的东西这是测试结果谢谢了
系统诊断报告
本报告由<Windows木马清道夫>提供
http://www.fygsoft.com报告生成时间:[2008-09-10 13:18:46]
操作系统为:WindowsXP 5.1.2600.2 Service Pack 2
Internet Explorer版本为:V6.0.2900.2180 Build:62900.2180
总共内存为:1021M 剩余内存为:461M
进程模块信息:
1 (安全进程):C:\WINDOWS\system32\smss.exe 命令行: \SystemRoot\System32\smss.exe
2 (安全进程):c:\WINDOWS\system32\csrss.exe 命令行: C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
3 (安全进程):c:\WINDOWS\system32\winlogon.exe 命令行: winlogon.exe
4 (安全进程):c:\WINDOWS\system32\services.exe 命令行: C:\WINDOWS\system32\services.exe
5 (安全进程):c:\WINDOWS\system32\lsass.exe 命令行: C:\WINDOWS\system32\lsass.exe
6 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost -k DcomLaunch
7 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost -k rpcss
8 未知进程:c:\program files\Rising\Rav\CCenter.exe 命令行: "C:\Program Files\Rising\Rav\CCenter.exe"
9 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\System32\svchost.exe -k netsvcs
10 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost.exe -k NetworkService
11 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost.exe -k LocalService
12 未知进程:c:\program files\Rising\Rav\RavMonD.exe 命令行: "C:\PROGRAM FILES\RISING\RAV\ravmond.exe" -step
13 - 未知模块:c:\program files\Rising\Rav\BWList.dll
14 - 未知模块:c:\program files\Rising\Rav\RsAppMgr.dll
15 - 未知模块:c:\program files\Rising\Rav\CfgDll.dll
16 - 未知模块:c:\program files\Rising\Rav\RsLog.dll
17 - 未知模块:c:\program files\Rising\Rav\ProcCom.dll
18 - 未知模块:c:\program files\Rising\Rav\RsCommX2.dll
19 - 未知模块:c:\program files\Rising\Rav\MonRule.dll
20 - 未知模块:c:\program files\Rising\Rav\HOOKSYS.dll
21 - 未知模块:c:\program files\Rising\Rav\HookReg.dll
22 - 未知模块:c:\program files\Rising\Rav\HookNtos.dll
23 - 未知模块:c:\program files\Rising\Rav\rswalmon.dll
24 - 未知模块:c:\program files\Rising\Rav\recomp.dll
25 - 未知模块:c:\program files\Rising\Rav\refs.dll
26 - 未知模块:c:\program files\Rising\Rav\ffr.dll
27 - 未知模块:c:\program files\Rising\Rav\RsStore.dll
28 - 未知模块:c:\program files\Rising\Rav\HookCont.dll
29 - 未知模块:c:\program files\Rising\Rav\FakeScan.dll
30 - 未知模块:c:\program files\Rising\Rav\Scanner.dll
31 - 未知模块:c:\program files\Rising\Rav\VirusLib.dll
32 - 未知模块:c:\program files\Rising\Rav\relibldr.dll
33 - 未知模块:c:\program files\Rising\Rav\HookWeb.dll
34 - 未知模块:c:\program files\Rising\Rav\ExtFile.dll
35 - 未知模块:c:\program files\Rising\Rav\pearc.dll
36 - 未知模块:c:\program files\Rising\Rav\nvfile.dll
37 - 未知模块:c:\program files\Rising\Rav\scanexec.dll
38 - 未知模块:c:\program files\Rising\Rav\unexe.dll
39 - 未知模块:c:\program files\Rising\Rav\ScanEX.dll
40 - 未知模块:c:\program files\Rising\Rav\ScanSct.dll
41 - 未知模块:c:\program files\Rising\Rav\ScanPack.dll
42 - 未知模块:c:\program files\Rising\Rav\revm.dll
43 - 未知模块:c:\program files\Rising\Rav\urutils.dll
44 - 未知模块:c:\program files\Rising\Rav\ur000.dat
45 - 未知模块:c:\program files\Rising\Rav\scriptci.dll
46 - 未知模块:c:\program files\Rising\Rav\ur001.dat
47 - 未知模块:c:\program files\Rising\Rav\ExtMail.dll
48 - 未知模块:c:\program files\Rising\Rav\ExtOLE.dll
49 未知进程:c:\program files\Rising\Rav\RavStub.exe 命令行: "C:\PROGRAM FILES\RISING\RAV\RavStub.exe" /RAVMOND=1023
50 - 未知模块:c:\program files\Rising\Rav\ProcCom.dll
51 - 未知模块:c:\program files\Rising\Rav\RsCommX2.dll
52 - 未知模块:c:\program files\Rising\Rav\RsCommon.dll
53 (安全进程):c:\WINDOWS\system32\spoolsv.exe 命令行: C:\WINDOWS\system32\spoolsv.exe
54 (安全进程):d:\program files\StormII\stormliv.exe 命令行: "d:\Program Files\StormII\stormliv.exe" /asservice
55 (安全进程):c:\WINDOWS\system32\nvsvc32.exe 命令行: C:\WINDOWS\system32\nvsvc32.exe
56 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost.exe -k imgsvc
57 (安全进程):c:\WINDOWS\system32\wdfmgr.exe 命令行: C:\WINDOWS\system32\wdfmgr.exe
58 (安全进程):c:\WINDOWS\system32\alg.exe 命令行: C:\WINDOWS\System32\alg.exe
59 (安全进程):c:\WINDOWS\explorer.exe 命令行: C:\WINDOWS\Explorer.EXE
60 - 未知模块:c:\WINDOWS\system32\RavExt.dll
61 - 未知模块:c:\program files\Rising\Rav\RsCommon.dll
62 未知进程:c:\program files\Rising\Rav\RavMon.exe 命令行: C:\PROGRAM FILES\RISING\RAV\RavMon.exe -SYSTEM
63 - 未知模块:c:\program files\Rising\Rav\ProcCom.dll
64 - 未知模块:c:\program files\Rising\Rav\RsCommX2.dll
65 - 未知模块:c:\program files\Rising\Rav\RsCommon.dll
66 - 未知模块:c:\program files\Rising\Rav\recomp.dll
67 - 未知模块:c:\program files\Rising\Rav\refs.dll
68 - 未知模块:c:\program files\Rising\Rav\VirusLib.dll
69 - 未知模块:c:\program files\Rising\Rav\relibldr.dll
70 - 未知模块:c:\program files\Rising\Rav\RsAppMgr.dll
71 - 未知模块:c:\program files\Rising\Rav\CfgDll.dll
72 - 未知模块:c:\program files\Rising\Rav\MonRule.dll
73 - 未知模块:c:\program files\Rising\Rav\PngDll.dll
74 - 未知模块:c:\program files\Rising\Rav\RsGuiLib.dll
75 - 未知模块:c:\program files\Rising\Rav\RsXML.dll
76 (安全进程):d:\shadu\360safebox\safeboxtray.exe 命令行: "D:\shadu\360Safebox\SafeBoxTray.exe" /r
77 (安全进程):c:\WINDOWS\system32\ctfmon.exe 命令行: "C:\WINDOWS\system32\ctfmon.exe"
78 (安全进程):c:\program files\internet explorer\IEXPLORE.EXE 命令行: "C:\Program Files\Internet Explorer\iexplore.exe"
79 (安全进程):d:\program files\Tencent\QQ\QQ.exe 命令行: "D:\Program Files\Tencent\QQ\QQ.exe"
80 - 未知模块:d:\program files\Tencent\QQ\cqqapplication.dll
81 - 未知模块:d:\program files\Tencent\QQ\qqsysmsgmng.dll
82 - 未知模块:d:\program files\Tencent\QQ\addrsearch.dll
83 (安全进程):d:\program files\Tencent\QQ\txplatform.exe 命令行: "d:\Program Files\Tencent\QQ\TXPlatform.exe" -Embedding
84 (安全进程):c:\WINDOWS\system32\wuauclt.exe 命令行: "C:\WINDOWS\system32\wuauclt.exe" /RunStoreAsComServer Local\[430]SUSDS297a5ecac421c1418f83209fca39a423
85 (安全进程):c:\WINDOWS\system32\conime.exe 命令行: C:\WINDOWS\system32\conime.exe
86 (安全进程):c:\ftc2008\ftcleaner.exe 命令行: C:\ftc2008\FTCleaner.exe
87 (安全进程):c:\ftc2008\fyganalyze.exe 命令行: C:\ftc2008\FygAnalyze.exe
启动信息:
88 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>
89 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<360Safebox><"D:\shadu\360Safebox\SafeBoxTray.exe" /r>
90 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<Windows木马防火墙><C:\ftc2008\Trojanwall.exe>
91 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
92 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Shell><Explorer.exe>
93 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
94 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe>
95 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
96 [C:\Documents and Settings\dongfaliang\「开始」菜单\程序\启动\]
<C:\Documents and Settings\dongfaliang\「开始」菜单\程序\启动\desktop.ini>
97 [C:\Documents and Settings\All Users\「开始」菜单\程序\启动\]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\desktop.ini>
98 [C:\Documents and Settings\All Users\「开始」菜单\程序\启动\]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\大将军连笔王.lnk>
99 [C:\Documents and Settings\All Users\「开始」菜单\程序\启动\]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\瑞星监控中心.lnk>
IE辅助对象BHO信息:
无可疑
IE右键菜单信息:
100 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<使用WEB迅雷下载><D:\Program Files\Thunder Network\WebThunder\GetUrl.htm>
101 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<使用WEB迅雷下载全部链接><D:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm>
IE工具栏项信息:
无可疑
ActiveX对象DPF信息:
102 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]
<{1DABF8D5-8430-4985-9B7F-A30E53D709B3}><C:\Program Files\Tencent\QQLive\QQLiveInstaller.dll>
103 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]
<{52FF336D-A05D-4A14-A3A1-7B6B4B427F88}><C:\WINDOWS\system32\UPLOAD~1.OCX>
104 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]
<{AC414988-E5BB-4C2C-873B-EA53D2F3D23A}><C:\WINDOWS\Downloaded Program Files\CCTVUpdateInstall.dll>
网络服务SPI信息:
无可疑
映像劫持IFEO信息:
无可疑
系统服务信息:
105 [ Rising Process Communication Center | RsCCenter | 启动 ]
c:\program files\rising\rav\ccenter.exe
106 [ Rising RealTime Monitor | RsRavMon | 停用 ]
c:\program files\rising\rav\ravmond.exe
系统驱动信息:
107 [ HookCont | HookCont | 启动 ]
C:\WINDOWS\system32\drivers\hookcont.sys
108 [ HookNtos | HookNtos | 启动 ]
C:\WINDOWS\system32\drivers\hookntos.sys
109 [ HookReg | HookReg | 启动 ]
C:\WINDOWS\system32\drivers\hookreg.sys
110 [ HookSys | HookSys | 启动 ]
C:\WINDOWS\system32\drivers\hooksys.sys
111 [ RsNTGDI | RsNTGDI | 启动 ]
c:\windows\system32\drivers\rsntgdi.sys
112 [ Sonic Focus Plugin for Sigmatel HDA | sfng32 | 启动 ]
c:\windows\system32\drivers\sfng32.sys
113 [ SIODRV | SIODRV | 启动 ]
c:\windows\system32\drivers\siodrv.sys
114 [ High Definition Audio Driver (WDM) - SigmaTel CODEC | STHDA | 启动 ]
c:\windows\system32\drivers\sthda.sys
已经加载的驱动信息:
115 C:\WINDOWS\system32\drivers\rsntgdi.sys
116 C:\WINDOWS\system32\drivers\sthda.sys
117 C:\WINDOWS\system32\drivers\sfng32.sys
118 C:\WINDOWS\system32\drivers\hooksys.sys
119 C:\WINDOWS\system32\drivers\hookhelp.sys
120 C:\WINDOWS\system32\drivers\hookreg.sys
121 C:\WINDOWS\system32\drivers\hookntos.sys
122 C:\WINDOWS\system32\drivers\hookcont.sys
123 c:\windows\system32\drivers\siodrv.sys
==============================================
木马清道夫,最受欢迎的木马查杀软件,超强查杀各类木马病毒
下载地址:
http://www.fygsoft.com