系统诊断报告
本报告由<Windows木马清道夫>提供
http://www.fygsoft.com报告生成时间:[2009-08-25 12:55:15]
操作系统为:WindowsXP 5.1.2600.2 Service Pack 3
Internet Explorer版本为:V6.0.2900.5512 Build:62900.5512
总共内存为:1023M 剩余内存为:661M
进程模块信息:
1 (安全进程):C:\WINDOWS\system32\smss.exe 命令行: \SystemRoot\System32\smss.exe
2 (安全进程):c:\WINDOWS\system32\csrss.exe 命令行: C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
3 (安全进程):c:\WINDOWS\system32\winlogon.exe 命令行: winlogon.exe
4 (安全进程):c:\WINDOWS\system32\services.exe 命令行: C:\WINDOWS\system32\services.exe
5 (安全进程):c:\WINDOWS\system32\lsass.exe 命令行: C:\WINDOWS\system32\lsass.exe
6 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost -k DcomLaunch
7 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost -k rpcss
8 (安全进程):d:\Rising\Ris\CCenter.exe 命令行: "D:\Rising\Ris\CCENTER.EXE" -Next
9 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\System32\svchost.exe -k netsvcs
10 (安全进程):d:\Rising\Ris\RavTask.exe 命令行: "D:\Rising\Ris\RavTask.exe" RisTask
11 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost.exe -k NetworkService
12 (安全进程):c:\WINDOWS\system32\svchost.exe 命令行: C:\WINDOWS\system32\svchost.exe -k LocalService
13 (安全进程):d:\Rising\Ris\RavMonD.exe 命令行: "D:\Rising\Ris\RavMonD.exe" -Next
14 - 未知模块:d:\Rising\Ris\RsLog.dll
15 - 未知模块:d:\Rising\Ris\RfwLog.dll
16 - 未知模块:d:\Rising\Ris\RsStore.dll
17 - 未知模块:d:\Rising\Ris\ScanEX.dll
18 - 未知模块:d:\Rising\Ris\ur000.dat
19 (安全进程):c:\WINDOWS\explorer.exe 命令行: C:\WINDOWS\Explorer.EXE
20 - 未知模块:d:\360safe\safemon\safemon.dll
21 - 未知模块:d:\qqdownload\ComDlls\xunleibho_now.dll
22 - 未知模块:c:\documents and settings\all users\application data\thunder network\thunder_439ed03c-c16c-4c9b-8632-3b2636cf9815_\components\resworker\DsBho_00.dll
23 - 未知模块:c:\documents and settings\all users\application data\thunder network\thunder_439ed03c-c16c-4c9b-8632-3b2636cf9815_\components\resworker\dataprocessor_00.dll
24 (安全进程):c:\WINDOWS\system32\alg.exe 命令行: C:\WINDOWS\System32\alg.exe
25 (安全进程):d:\Rising\Ris\ScanFrm.exe 命令行: "D:\Rising\Ris\ScanFrm.exe" -Next
26 - 未知模块:d:\Rising\Ris\ScanBT.dll
27 - 未知模块:d:\Rising\Ris\RsLog.dll
28 - 未知模块:d:\Rising\Ris\ScanEX.dll
29 - 未知模块:d:\Rising\Ris\ur000.dat
30 未知进程:d:\360safe\safemon\360tray.exe 命令行: "D:\360safe\safemon\360tray.exe" /start
31 - 未知模块:d:\360safe\safemon\360compro.dll
32 - 未知模块:d:\360safe\safemon\safemon.dll
33 - 未知模块:d:\360safe\safemon\safekrnl.dll
34 - 未知模块:d:\360safe\safemon\360webpro.dll
35 - 未知模块:d:\360safe\safemon\360procmon.dll
36 - 未知模块:d:\360safe\safemon\selfprotectapi2.dll
37 - 未知模块:d:\360safe\live.dll
38 - 未知模块:d:\360safe\EfiProc.dll
39 - 未知模块:d:\360safe\PDown.dll
40 - 未知模块:d:\360safe\liveupd360.dll
41 - 未知模块:d:\360safe\360net.dll
42 (安全进程):d:\Rising\Ris\RsTray.exe 命令行: "D:\Rising\Ris\RsTray.exe" -system
43 - 未知模块:d:\Rising\Ris\RfwLog.dll
44 (安全进程):d:\Rising\Ris\rsnetsvr.exe 命令行: "D:\Rising\Ris\rsnetsvr.exe"
45 (安全进程):d:\trojanwall.exe 命令行: D:\Trojanwall.exe
46 - 未知模块:d:\360safe\safemon\safemon.dll
47 (安全进程):d:\ftcleaner.exe 命令行: D:\FTCleaner.exe
48 - 未知模块:d:\360safe\safemon\safemon.dll
49 未知进程:d:\3\360se3\360SE.exe 命令行: "D:\3\360se3\360SE.exe"
50 - 未知模块:d:\360safe\safemon\safemon.dll
51 - 未知模块:d:\3\360se3\extensions\ComCore\ComCore.dll
52 - 未知模块:d:\3\360se3\extensions\extaddons\extaddons.dll
53 - 未知模块:d:\3\360se3\extensions\extadfilter\extadfilter.dll
54 - 未知模块:d:\3\360se3\extensions\extdownload\extdownload.dll
55 - 未知模块:d:\3\360se3\extensions\ExtPages\ExtPages.dll
56 - 未知模块:d:\3\360se3\extensions\extsuggest\extsuggest.dll
57 - 未知模块:d:\3\360se3\extensions\favorites\favorites.dll
58 - 未知模块:d:\3\360se3\extensions\minisearchbar\minisearchbar.dll
59 - 未知模块:d:\3\360se3\extensions\onlinefav\onlinefav.dll
60 - 未知模块:d:\3\360se3\extensions\pluginbar\pluginbar.dll
61 - 未知模块:d:\3\360se3\extensions\safecentral\safecentral.dll
62 - 未知模块:d:\3\360se3\extensions\UICenter\UICenter.dll
63 未知进程:d:\3\360se3\360SE.exe 命令行: "D:\3\360se3\360SE.exe" /tp:1 /w:459454 /t:59478952 /r:393678 /m:1 /f:1
64 - 未知模块:d:\360safe\safemon\safemon.dll
65 - 未知模块:d:\3\360se3\extensions\ComCore\ComCore.dll
66 - 未知模块:d:\3\360se3\extensions\extadfilter\extadfilter.dll
67 - 未知模块:d:\3\360se3\extensions\safecentral\safecentral.dll
68 - 未知模块:c:\WINDOWS\system32\Macromed\Flash\Flash10c.ocx
69 (安全进程):d:\fyganalyze.exe 命令行: D:\FygAnalyze.exe
70 - 未知模块:d:\360safe\safemon\safemon.dll
启动信息:
71 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<amd_dc_opt><C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe>
72 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<360Safetray><"D:\360safe\safemon\360tray.exe" /start>
73 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<RisTray><"D:\Rising\Ris\RsTray.exe" -system>
74 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>
75 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<Windows木马防火墙><D:\Trojanwall.exe>
76 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Shell><Explorer.exe>
77 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
78 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe>
79 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
80 [C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\desktop.ini>
81 [C:\Documents and Settings\All Users\「开始」菜单\程序\启动\]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\desktop.ini>
IE辅助对象BHO信息:
82 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
<{01443AEC-0FD1-40fd-9C87-E93D1494C233}><D:\QQDownload\ComDlls\TDAtOnce_Now.dll>
83 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
<{889D2FEB-5411-4565-8998-1DD2C5261283}><D:\QQDownload\ComDlls\xunleiBHO_Now.dll>
84 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
<{B69F34DD-F0F9-42DC-9EDD-957187DA688D}><D:\360safe\safemon\safemon.dll>
IE右键菜单信息:
85 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<使用迅雷下载><D:\QQDownload\Program\geturl.htm>
86 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<使用迅雷下载全部链接><D:\QQDownload\Program\getallurl.htm>
IE工具栏项信息:
无可疑
ActiveX对象DPF信息:
无可疑
网络服务SPI信息:
无可疑
映像劫持IFEO信息:
无可疑
系统服务信息:
87 [ ATI Smart | ATI Smart | 停用 ]
c:\windows\system32\ati2sgag.exe
系统驱动信息:
88 [ 360SelfProtection | 360SelfProtection | 启动 ]
c:\windows\system32\drivers\360selfprotection.sys
89 [ BREGDRV | BREGDRV | 启动 ]
c:\windows\system32\drivers\bregdrv.sys
90 [ EfiSystemMon | EfiMon | 启动 ]
c:\windows\system32\drivers\efimon.sys
91 [ HookPort | HookPort | 启动 ]
c:\windows\system32\drivers\hookport.sys
92 [ hooksys | hooksys | 启动 ]
c:\windows\system32\drivers\hooksys.sys
93 [ RsProtect | RsProtect | 启动 ]
c:\windows\system32\drivers\rsptect.sys
已经加载的驱动信息:
94 C:\WINDOWS\system32\drivers\hookport.sys
95 C:\WINDOWS\system32\drivers\360selfprotection.sys
96 C:\WINDOWS\system32\drivers\rsptect.sys
97 C:\WINDOWS\system32\drivers\hooksys.sys
98 C:\WINDOWS\system32\drivers\hookhelp.sys
99 C:\WINDOWS\system32\drivers\efimon.sys
100 c:\windows\system32\drivers\bregdrv.sys
==============================================
木马清道夫,最受欢迎的木马查杀软件,超强查杀各类木马病毒
下载地址:
http://www.fygsoft.com用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; 360SE)