瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】启动出现错误进程 附日志

1   1  /  1  页   跳转

【求助】启动出现错误进程 附日志

【求助】启动出现错误进程 附日志

Logfile of HijackThis v1.99.1
Scan saved at 12:38:27, on 2007-1-3
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\conime.exe
C:\DOCUME~1\ABC\LOCALS~1\Temp\loadadv579.exe
C:\WINDOWS\explorer.exe
F:\hijackthis\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,rundll32.exe C:\WINDOWS\System32\winsys16_061231.dll start
O1 - Hosts: 202.109.114.142 survey88.allyes.com
O1 - Hosts: 202.109.114.142 adtaobao.allyes.com
O1 - Hosts: 202.109.114.142 code.qihoo.com
O1 - Hosts: 202.109.114.142 union.mop.com
O1 - Hosts: 202.109.114.142 js.kkunion.com
O1 - Hosts: 202.109.114.142 v.kkunion.com
O1 - Hosts: 202.109.114.142 v.21cn.com
O1 - Hosts: 202.109.114.142 iplusms.allyes.com
O1 - Hosts: 202.109.114.142 mms.t2t2.com
O1 - Hosts: 202.109.114.142 ivr.dobig.net
O1 - Hosts: 202.109.114.142 www.u8u.com
O1 - Hosts: 202.109.114.142 u.u8u.com
O1 - Hosts: 202.109.114.142 img.zhangxiu.com
O1 - Hosts: 202.109.114.142 tl.linktone.com
O1 - Hosts: 202.109.114.142 channel.e78.com
O1 - Hosts: 202.109.114.142 u.7town.com
O1 - Hosts: 202.109.114.142 union.95ol.com.cn
O1 - Hosts: 202.109.114.142 mms1.95ol.com.cn
O1 - Hosts: 202.109.114.142 mfs.95ol.com.cn
O1 - Hosts: 202.109.114.142 tl.a8.com
O1 - Hosts: 202.109.114.142 ad01.a8.com
O1 - Hosts: 202.109.114.142 u2.caiku.com
O1 - Hosts: 202.109.114.142 mms.caiku.com
O1 - Hosts: 202.109.114.142 code1.caiku.com
O1 - Hosts: 202.109.114.142 pub.lele.com
O1 - Hosts: 202.109.114.142 u.lele.com
O1 - Hosts: 202.109.114.142 7town.com
O1 - Hosts: 202.109.114.142 tvsend.7town.com
O1 - Hosts: 202.109.114.142 ivrsend.7town.com
O1 - Hosts: 202.109.114.142 tlt.7town.com
O1 - Hosts: 202.109.114.142 gsend.7town.com
O1 - Hosts: 202.109.114.142 smssend.7town.com
O1 - Hosts: 202.109.114.142 mmssend.moyu.com
O1 - Hosts: 202.109.114.142 91ivr.com
O1 - Hosts: 202.109.114.142 myad.91ivr.com
O1 - Hosts: 202.109.114.142 u.91ivr.com
O1 - Hosts: 202.109.114.142 union.91ivr.com
O1 - Hosts: 202.109.114.142 cm.p4p.cn.yahoo.com
O1 - Hosts: 202.109.114.142 un.265.com
O1 - Hosts: 202.109.114.142 union.qq.com
O1 - Hosts: 202.109.114.142 view.aliunion.cn.yahoo.com
O1 - Hosts: 202.109.114.142 union.narrowad.com
O1 - Hosts: 202.109.114.142 ln.heima8.com
O1 - Hosts: 202.109.114.142 www.fboat.cn
O1 - Hosts: 202.109.114.142 cpro.baidu.com
O1 - Hosts: 202.109.114.142 unstat.baidu.com
O1 - Hosts: 202.109.114.142 y.cnxad.com
O1 - Hosts: 202.109.114.142 www.ewowo.com
O1 - Hosts: 202.109.114.142 template.union.163.com
O1 - Hosts: 202.109.114.142 new.is686.com
O1 - Hosts: 202.109.114.142 creative.unionsys.bolaa.com
O1 - Hosts: 202.109.114.142 www.qyule.com
O1 - Hosts: 202.109.114.142 99e.cc
O1 - Hosts: 202.109.114.142 www.91ivr.com
O1 - Hosts: 202.109.114.142 mg.ukaka.com
O1 - Hosts: 202.109.114.142 kooxoo2.ad4all.net
O1 - Hosts: 202.109.114.142 www.8fff.com
O1 - Hosts: 202.109.114.142 union.pomoho.com
O1 - Hosts: 202.109.114.142 202.107.233.211
O1 - Hosts: 202.109.114.142 www.end123.com
O1 - Hosts: 202.109.114.142 w1.7clink.com
O1 - Hosts: 202.109.114.142 w2.7clink.com
O1 - Hosts: 202.109.114.142 union01.com
O1 - Hosts: 202.109.114.142 click.8le8le.com
O1 - Hosts: 202.109.114.142 stbanner.allyes.com
O1 - Hosts: 202.109.114.142 mms1.moyu.com
O1 - Hosts: 202.109.114.142 u.moyu.com
O1 - Hosts: 202.109.114.142 mmsu.moyu.com
O1 - Hosts: 202.109.114.142 show.moyu.com
O1 - Hosts: 202.109.114.142 ivrsend.moyu.com
O1 - Hosts: 202.109.114.142 ivru.moyu.com
O1 - Hosts: 202.109.114.142 ivr1.moyu.com
O1 - Hosts: 203.191.146.205 corep.dmcast.com
O1 - Hosts: 203.191.146.205 m081.dmcast.com
O1 - Hosts: 203.191.146.205 dcww.dmcast.com
O1 - Hosts: 203.191.146.205 renren.dmcast.com
O1 - Hosts: 203.191.146.205 files.henbang.net
O1 - Hosts: 203.191.146.205 bannerbox.cn
O1 - Hosts: 203.191.146.205 www.bannerbox.cn
O1 - Hosts: 203.191.146.205 action.coopen.cn
O1 - Hosts: 203.191.146.205 u4.sky99.cn
O1 - Hosts: 203.191.146.205 u1.sky99.cn
O1 - Hosts: 203.191.146.205 u2.sky99.cn
O1 - Hosts: 203.191.146.205 u3.sky99.cn
O1 - Hosts: 203.191.146.205 sky99.cn
O1 - Hosts: 203.191.146.205 u.sky99.cn
O1 - Hosts: 203.191.146.205 u.ete.cn
O1 - Hosts: 203.191.146.205 ip.alexaanywhere.com
O1 - Hosts: 203.191.146.205 www.365tan.com
O1 - Hosts: 203.191.146.205 www.winopen.cn
O1 - Hosts: 203.191.146.205 www.tanip.com
O1 - Hosts: 203.191.146.205 alexaanywhere.com
O1 - Hosts: 203.191.146.205 jssb.alexaanywhere.com
O1 - Hosts: 203.191.146.205 ns250.alexaanywhere.com
O1 - Hosts: 203.191.146.205 sb.alexaanywhere.com
O1 - Hosts: 203.191.146.205 ip.alexaanywhere.com
O1 - Hosts: 203.191.146.205 pop.9v.cn
O1 - Hosts: 203.191.146.205 xuni.myad.cn
O1 - Hosts: 203.191.146.205 iebar.t2t2.com
O1 - Hosts: 203.191.146.205 error.newcell.cn
O1 - Hosts: 203.191.146.205 auto.search.msn.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: IEMonitor Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\WINDOWS\System32\IESHEL~1.DLL
O2 - BHO: xhly - {2D369182-BBD0-4843-BE25-48ADEDAD321B} - C:\PROGRA~1\COMMON~1\dquh\huyl.dll
O2 - BHO: QKYAVLWNQFJ - {55DE9BE9-EE2A-46C8-A2AB-520A1242F4BB} - C:\WINDOWS\system32\SCUIE.DLL
O2 - BHO: 实用搜索 - {6CFD436C-7AAD-4e50-992F-C0C87A94CAD2} - C:\Program Files\superutilbar\superutilbar.dll
O2 - BHO: MCBMQ - {7D7D00B6-7C00-4890-A66A-8CD4B71D6DDC} - C:\WINDOWS\system32\TDBEPOTORN.DLL
O2 - BHO: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{39888~1\Bar888.dll
O2 - BHO: (no name) - {D3341007-C77C-4F1C-B2A5-D94D5BE55F7E} - C:\WINDOWS\system32\pbkavgjxwioydly.dll
O2 - BHO: XBTP03742 - {E9640745-EBE0-435a-AEF2-D9C5D77E29F0} - (no file)
O2 - BHO: (no name) - {F770522B-198D-4134-9D74-D30F41B3BA44} - C:\WINDOWS\system32\wclatyetnppaz.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{39888~1\Bar888.dll
O3 - Toolbar: 安全卫士 - {8F621983-8C5B-4BD6-A5AA-E0BD80D7812A} - C:\Program Files\安全卫士\360safe.dll
O3 - Toolbar: 实用搜索工具条2.0 - {03465FF5-00AE-411a-9C34-960ED566EC03} - C:\Program Files\superutilbar\superutilbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SysExplr] C:\Herosoft\HeroV8\SYSEXPLR.EXE
O4 - HKLM\..\Run: [IEBarUp] RunDll32 "C:\WINDOWS\System32\IeBar1.dll",Run
O4 - HKLM\..\Run: [C:\DOCUME~1\ABC\LOCALS~1\Temp\sna.exe] C:\DOCUME~1\ABC\LOCALS~1\Temp\sna.exe
O4 - HKLM\..\Run: [osuiti4r] rundll32.exe C:\WINDOWS\12r3kl0mb5.dll _start@16
O4 - HKLM\..\Run: [Desktop] "C:\WINDOWS\System32\rundll32.exe" "C:\WINDOWS\System32\NTService32.dll",Run
O4 - HKLM\..\Run: [TempCom] C:\WINDOWS\FONTS\E677F.com
O4 - HKLM\..\Run: [worknote1] C:\WINDOWS\System32\SYSNOTE.EXE
O4 - HKLM\..\Run: [sdafdsafds] C:\WINDOWS\temp\sd151.exe
O4 - HKLM\..\Run: [cfpziv48] %systemroot%\system32\Rundll32.exe %systemroot%\system32\cfpziv48.dll,DllUnregisterServer
O4 - HKLM\..\Run: [System] C:\Program Files\Common Files\System\Updaterun.exe
O4 - HKLM\..\RunOnce: [splai] %systemroot%\system32\Rundll32.exe %systemroot%\system32\splai.dll,DllUnregisterServer
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [winsamps] C:\WINDOWS\winamps.exe
O4 - HKCU\..\Run: [myZt3] C:\DOCUME~1\ABC\LOCALS~1\Temp\zt3\SVCHQST.EXE
O4 - HKCU\..\Run: [myWl2] C:\DOCUME~1\ABC\LOCALS~1\Temp\Wl2\lexplore.exe
O8 - Extra context menu item: 豪杰超级解霸V8实时播放 - C:\Herosoft\HeroV8\MPURLGET.HTM
O9 - Extra button: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra 'Tools' menuitem: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra button: 安全卫士 - {8F621983-8C5B-4BD6-A5AA-E0BD80D7812A} - C:\Program Files\安全卫士\360safe.dll
O9 - Extra 'Tools' menuitem: 安全卫士 - {8F621983-8C5B-4BD6-A5AA-E0BD80D7812A} - C:\Program Files\安全卫士\360safe.dll
O9 - Extra button: 词霸 - {9A687CA6-D585-4947-9ED9-BE96071F5CD9} - C:\Program Files\Kingsoft\Powerword 2003\XDictExB.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O18 - Protocol: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - C:\Program Files\Kingsoft\Powerword 2003\XDictExB.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ScCardLogn - C:\WINDOWS\ScNotify.dll
O23 - Service: C920434C - Unknown owner - C:\WINDOWS\System32\C920434C.EXE (file missing)
O23 - Service: CMServerToXPM (CMServerToXP) - Unknown owner - C:\Windows\system32\EDEXLZEEEIMO.EXE
O23 - Service: COM+ Messages - Unknown owner - C:\WINDOWS\System32\svchosts.exe" -e te-110-12-0000049 (file missing)
O23 - Service: Remote Procedure Call System(11RPCS) (RpcS11) - Unknown owner - C:\WINDOWS\System32\Rpcs11.exe (file missing)
O23 - Service: Windows NT Service32 - Unknown owner - C:\WINDOWS\System32\rundll32.exe" "C:\WINDOWS\System32\NTService32.dll",Start (file missing)

最后编辑2007-01-03 14:32:29
分享到:
gototop
 

2007-01-03,12:41:47

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <winsamps><C:\WINDOWS\winamps.exe>  [N/A]
    <myZt3><C:\DOCUME~1\ABC\LOCALS~1\Temp\zt3\SVCHQST.EXE>  [N/A]
    <myWl2><C:\DOCUME~1\ABC\LOCALS~1\Temp\Wl2\lexplore.exe>  [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <{898887D4-0AF0-2052-1104-030505200056}><"C:\Program Files\Common Files\{898887D4-0AF0-2052-1104-030505200056}\Update.exe" te-110-12-0000113>  [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <IgfxTray><C:\WINDOWS\System32\igfxtray.exe>  [(Verified)Intel Corporation]
    <HotKeysCmds><C:\WINDOWS\System32\hkcmd.exe>  [(Verified)Intel Corporation]
    <SysExplr><C:\Herosoft\HeroV8\SYSEXPLR.EXE>  [N/A]
    <IEBarUp><RunDll32 "C:\WINDOWS\System32\IeBar1.dll",Run>  [Microsoft Corporation]
    <C:\DOCUME~1\ABC\LOCALS~1\Temp\sna.exe><C:\DOCUME~1\ABC\LOCALS~1\Temp\sna.exe>  [N/A]
    <osuiti4r><rundll32.exe C:\WINDOWS\12r3kl0mb5.dll _start@16>  [N/A]
    <Desktop><"C:\WINDOWS\System32\rundll32.exe" "C:\WINDOWS\System32\NTService32.dll",Run>  []
    <TempCom><C:\WINDOWS\FONTS\E677F.com>  [gy]
    <worknote1><C:\WINDOWS\System32\SYSNOTE.EXE>  [N/A]
    <sdafdsafds><C:\WINDOWS\temp\sd151.exe>  [N/A]
    <cfpziv48><%systemroot%\system32\Rundll32.exe %systemroot%\system32\cfpziv48.dll,DllUnregisterServer>  [N/A]
    <System><C:\Program Files\Common Files\System\Updaterun.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <splai><%systemroot%\system32\Rundll32.exe %systemroot%\system32\splai.dll,DllUnregisterServer>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,rundll32.exe C:\WINDOWS\System32\winsys16_061231.dll start>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Corporation]
    <CDBurn><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Corporation]
    <WebCheck><%SystemRoot%\System32\webcheck.dll>  [(Verified)Microsoft Corporation]
    <SysTray><C:\WINDOWS\System32\stobject.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCardLogn]
    <WinlogonNotify: ScCardLogn><C:\WINDOWS\ScNotify.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
    <WinlogonNotify: ScCertProp><wlnotify.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
    <WinlogonNotify: Schedule><wlnotify.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    <WinlogonNotify: sclgntfy><sclgntfy.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
    <WinlogonNotify: termsrv><wlnotify.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
    <WinlogonNotify: wlballoon><wlnotify.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\System32\browseui.dll>  [(Verified)Microsoft Corporation]
    <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\System32\browseui.dll>  [(Verified)Microsoft Corporation]

==================================
启动文件夹
N/A

==================================
服务
[73755CB0 / 73755CB0][Stopped/Auto Start]
  <C:\WINDOWS\System32\73755CB0.EXE -service><Microsoft Corporation>
[87CADFDC / 87CADFDC][Stopped/Auto Start]
  <C:\WINDOWS\System32\87CADFDC.EXE -service><Microsoft Corporation>
[Application Management / AppMgmt][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[C920434C / C920434C][Stopped/Auto Start]
  <C:\WINDOWS\System32\C920434C.EXE -service><N/A>
[CMServerToXPM / CMServerToXP][Stopped/Auto Start]
  <C:\Windows\system32\EDEXLZEEEIMO.EXE><N/A>
[COM+ Messages / COM+ Messages][Stopped/Auto Start]
  <"C:\WINDOWS\System32\svchosts.exe" -e te-110-12-0000049><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[WindowsNt Workstation / NTWorkStan][Stopped/Manual Start]
  <2 - 系统找不到指定的文件。
><N/A>
[RestoreService / RestoreService][Stopped/Disabled]
  <2 - 系统找不到指定的文件。
><N/A>
[Remote Procedure Call System(11RPCS) / RpcS11][Stopped/Auto Start]
  <C:\WINDOWS\System32\Rpcs11.exe><N/A>
[SQLServer Supports / sqlservech][Stopped/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k sqlservech-->c:\windows\system32\sqlservech.dll><N/A>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
  <2 - 系统找不到指定的文件。
><N/A>
[Windows NT Service32 / Windows NT Service32][Stopped/Auto Start]
  <"C:\WINDOWS\System32\rundll32.exe" "C:\WINDOWS\System32\NTService32.dll",Start><Microsoft Corporation>
[WinXP DHCP Service / WinXPDHCPsvc][Stopped/Auto Start]
  <C:\WINDOWS\System32\rundll32.exe xpdhcp.dll,start><Microsoft Corporation>
[WindowsNt Network Engine / wnttech][Stopped/Manual Start]
  <2 - 系统找不到指定的文件。
><N/A>
[Vsn xkob Service / xkob][Stopped/Auto Start]
  <C:\WINDOWS\System32\rundll32.exe C:\PROGRA~1\COMMON~1\dquh\kxbo.dll,Service><Microsoft Corporation>
[Intranet Messenger / DiRVIn][Stopped/Auto Start]
  <C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\PHHJQ.DLL,Export 1087><N/A>
[Clipboard / Partner][Stopped/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\System32\zjpvr.dll><Microsoft Corporation>

==================================
驱动程序
[aeaudio / aeaudio][Stopped/Manual Start]
  <system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[Broadcom NetXtreme Gigabit Ethernet / b57w2k][Running/Manual Start]
  <System32\DRIVERS\b57xp32.sys><Broadcom Corporation>
[cfpziv4 / cfpziv48][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\cfpziv48.sys><N/A>
[csksrzgq / csksrzgq][Stopped/Boot Start]
  <\SystemRoot\system32\drivers\csksrzgq.sys><N/A>
[ialm / ialm][Stopped/Manual Start]
  <System32\DRIVERS\ialmnt5.sys><Intel Corporation>
[ivuvpd7 / ivuvpd76][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\ivuvpd76.sys><N/A>
[ixgo / ixgoy][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\ixgoy.sys><N/A>
[izuyafwh / izuyafwh][Running/Boot Start]
  <\SystemRoot\system32\drivers\izuyafwh.sys><N/A>
[mkjuhb63 / mkjuhb63][Stopped/Manual Start]
  <\??\C:\WINDOWS\System32\drivers\mkjuhb63.sys><N/A>
[msprotect / msprotect][Running/System Start]
  <system32\DRIVERS\msprotect.sys><Windows (R) 2000 DDK provider>
[msqmx / msqmx][Stopped/Boot Start]
  <\SystemRoot\system32\drivers\msqmx.sys><Microsoft Corporation>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
  <system32\drivers\npf.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Secdrv / Secdrv][Stopped/Manual Start]
  <System32\DRIVERS\secdrv.sys><N/A>
[smwdm / smwdm][Stopped/Manual Start]
  <system32\drivers\smwdm.sys><Analog Devices, Inc.>
[WINIO / WINIO][Stopped/Manual Start]
  <\??\C:\WINDOWS\Downloaded Program Files\winio.sys><N/A>
[Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Stopped/Manual Start]
  <system32\drivers\ialmsbw.sys><Intel Corporation>
[Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Stopped/Manual Start]
  <system32\drivers\ialmkchw.sys><Intel Corporation>

==================================
gototop
 

浏览器加载项
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[IEMonitor Class]
  {08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\WINDOWS\System32\IESHEL~1.DLL, >
[xhly]
  {2D369182-BBD0-4843-BE25-48ADEDAD321B} <C:\PROGRA~1\COMMON~1\dquh\huyl.dll, >
[QKYAVLWNQFJ]
  {55DE9BE9-EE2A-46C8-A2AB-520A1242F4BB} <C:\WINDOWS\system32\SCUIE.DLL, N/A>
[实用搜索]
  {6CFD436C-7AAD-4e50-992F-C0C87A94CAD2} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[MCBMQ]
  {7D7D00B6-7C00-4890-A66A-8CD4B71D6DDC} <C:\WINDOWS\system32\TDBEPOTORN.DLL, N/A>
[Bar888]
  {C1B4DEC2-2623-438e-9CA2-C9043AB28508} <C:\PROGRA~1\COMMON~1\{39888~1\Bar888.dll, N/A>
[]
  {D3341007-C77C-4F1C-B2A5-D94D5BE55F7E} <C:\WINDOWS\system32\pbkavgjxwioydly.dll, N/A>
[XBTP03742 Class]
  {E9640745-EBE0-435a-AEF2-D9C5D77E29F0} <, N/A>
[]
  {F770522B-198D-4134-9D74-D30F41B3BA44} <C:\WINDOWS\system32\wclatyetnppaz.dll, N/A>
[豪杰超级解霸V8]
  {367E0A21-8601-4986-9C9A-153BF5ACA118} <C:\Herosoft\HeroV8\STHSDVD.EXE, N/A>
[安全卫士]
  {8F621983-8C5B-4BD6-A5AA-E0BD80D7812A} <C:\Program Files\安全卫士\360safe.dll, IE Toolbar>
[金山词霸]
  {9A687CA6-D585-4947-9ED9-BE96071F5CD9} <C:\Program Files\Kingsoft\Powerword 2003\XDictExB.dll, 金山软件股份有限公司>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[Bar888]
  {C1B4DEC2-2623-438e-9CA2-C9043AB28508} <C:\PROGRA~1\COMMON~1\{39888~1\Bar888.dll, N/A>
[安全卫士]
  {8F621983-8C5B-4BD6-A5AA-E0BD80D7812A} <C:\Program Files\安全卫士\360safe.dll, IE Toolbar>
[实用搜索工具条2.0]
  {03465FF5-00AE-411a-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[豪杰超级解霸V8实时播放]
  <C:\Herosoft\HeroV8\MPURLGET.HTM, N/A>

==================================
正在运行的进程
[PID: 504][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 560][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 584][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 628][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 640][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 812][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 964][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1060][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1092][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1780][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
[PID: 1792][C:\WINDOWS\System32\conime.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1500][C:\DOCUME~1\ABC\LOCALS~1\Temp\loadadv579.exe]  [N/A, N/A]
[PID: 348][C:\WINDOWS\explorer.exe]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\System32\igfxpph.dll]  [Intel Corporation, 3.0.0.2249]
    [C:\WINDOWS\System32\hccutils.DLL]  [Intel Corporation, 3.0.0.2249]
    [C:\WINDOWS\System32\igfxres.dll]  [Intel Corporation, 3.0.0.2249]
    [C:\WINDOWS\System32\igfxsrvc.dll]  [Intel Corporation, 3.0.0.2249]
    [C:\WINDOWS\System32\igfxdev.dll]  [Intel Corporation, 3.0.0.2249]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]
[PID: 1868][F:\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [C:\Herosoft\HeroV8\VCvtShell.dll]  [herosoft, 1, 0, 0, 1]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
[D:\]
[autorun]
open=d:\mplay.com

==================================
HOSTS 文件
N/A

==================================
API HOOK
N/A

==================================


[/CODE]
gototop
 

gototop
 

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT