| 引用: |
【三月学毒的贴子】用SRE扫描个日志传上来 ……………… |
大哥,我就指望你了
我在线等待1990-04-12,16:21:02
System Repair Engineer 2.0.12.350 (2.0 RC 1)
Windows XP Professional Service Pack 2 - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><G:\WINDOWS\system32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<bgswitch><C:\WINDOWS\system32\bgswitch.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<MsnMsgr><"G:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<MSMSGS><"G:\Program Files\Messenger\msmsgs.exe" /background>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<360Safetray><G:\Program Files\360safe\safemon\360tray.exe /start>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"G:\Program Files\Rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><G:\WINDOWS\system32\userinit.exe,>
==================================
启动文件夹
[腾讯QQ]
<G:\Documents and Settings\Cabbage\「开始」菜单\程序\启动\腾讯QQ.lnk><N>
==================================
服务
[NT Data Provider / BRGNS]
<G:\WINDOWS\SYSTEM32\RUNDLL2KXP.EXE G:\WINDOWS\SYSTEM32\WBEM\SKKHZ.DLL,Export 1087><N/A>
[COMMAND DLL32 / CMD_DLL32]
<G:\WINDOWS\system32\CMDLL32.EXE><N/A>
[error monitor / EmonSrv]
<G:\WINDOWS\system32\lfrmewrk.exe><N/A>
[Rising Process Communication Center / RsCCenter]
<"G:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"G:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
==================================
浏览器加载项
[NavigatMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <G:\Program Files\360safe\safemon\safemon.dll, >
[CPPIE Class]
{C6844939-C324-41E0-84D0-D42F8DA5EBAD} <G:\WINDOWS\system32\hbcmd.dll, TODO: <公司名>>
[番茄花园]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.tomatolei.com, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <G:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[]
{B17D6D2C-30F8-4C63-9E01-4C2B199547AA} <G:\WINDOWS\system32\xgldmzlnbuzvx.dll, N/A>
[NavigatMon Class]
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} <G:\Program Files\360safe\safemon\safemon.dll, >
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <G:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[CPPIE Class]
{C6844939-C324-41E0-84D0-D42F8DA5EBAD} <G:\WINDOWS\system32\hbcmd.dll, TODO: <公司名>>
[macfed Class]
{CB7CA266-4479-4997-86AF-7554AA8A0AF4} <G:\WINDOWS\system32\atsldr.dll, N/A>
[]
{D40D01E4-0378-430A-A890-382CB46B97B1} <G:\WINDOWS\system32\cebrxhfuwixfm.dll, N/A>
[WinMyFavor Class]
{F7F49040-389C-4F1F-A825-06D5328EAE59} <G:\WINDOWS\system32\MyFavor64.dll, N/A>
[上传到QQ网络硬盘]
<G:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
==================================
正在运行的进程
[PID: 560][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 620][\??\G:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 644][\??\G:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 688][G:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 700][G:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 864][G:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 960][G:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1088][G:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1148][G:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1280][G:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1484][G:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1632][G:\Program Files\Rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><19, 0, 0, 4>
[G:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[G:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><19, 0, 0, 5>
[PID: 1856][G:\WINDOWS\SYSTEM32\RUNDLL2KXP.EXE] <Microsoft Corporation><5.00.2134.1>
[PID: 1936][G:\WINDOWS\system32\CMDLL32.EXE] <N/A><N/A>
[PID: 1976][G:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[G:\PROGRA~1\weea\xffb.nls] <N/A><N/A>
[G:\WINDOWS\system32\zpilix91.dll] <><1, 1, 1, 1008>
[G:\Program Files\360safe\safemon\safemon.dll] <><3, 2, 0, 1001>
[PID: 236][G:\WINDOWS\system32\lfrmewrk.exe] <N/A><N/A>
[PID: 360][G:\WINDOWS\system32\microsoft.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[G:\WINDOWS\system32\ADPT1F.DLL] <mcsoft><1, 0, 0, 0>
[PID: 884][G:\WINDOWS\system32\dgd4bs.exe] <N/A><N/A>
[PID: 2404][G:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2560][G:\WINDOWS\system32\wuauclt.exe] <Microsoft Corporation><5.4.3790.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2640][G:\Program Files\360safe\safemon\360tray.exe] <奇虎网><3, 2, 1, 1001>
[G:\Program Files\360safe\safemon\safemon.dll] <><3, 2, 0, 1001>
[G:\Program Files\360safe\safemon\SafeKrnl.dll] <奇虎网><3, 2, 0, 1001>
[G:\Program Files\360safe\AntiAdwa.dll] <360Safe.com><3, 2, 0, 1001>
[G:\WINDOWS\system32\zpilix91.dll] <><1, 1, 1, 1008>
[PID: 2916][G:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[G:\WINDOWS\system32\zpilix91.dll] <><1, 1, 1, 1008>
[G:\Program Files\360safe\safemon\safemon.dll] <><3, 2, 0, 1001>
[PID: 2972][G:\Program Files\Messenger\msmsgs.exe] <Microsoft Corporation><4.7.3000>
[G:\WINDOWS\system32\zpilix91.dll] <><1, 1, 1, 1008>
[G:\Program Files\360safe\safemon\safemon.dll] <><3, 2, 0, 1001>
[PID: 3292][G:\WINDOWS\system32\MSRundll.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[G:\WINDOWS\system32\bofang.dll] < ><1, 0, 0, 3>
[G:\WINDOWS\system32\zpilix91.dll] <><1, 1, 1, 1008>
[G:\Program Files\360safe\safemon\safemon.dll] <><3, 2, 0, 1001>
[PID: 3356][G:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3808][G:\WINDOWS\system32\conime.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[G:\WINDOWS\system32\zpilix91.dll] <><1, 1, 1, 1008>
[G:\Program Files\360safe\safemon\safemon.dll] <><3, 2, 0, 1001>
[PID: 3884][G:\DOCUME~1\Cabbage\LOCALS~1\Temp\Rar$EX00.301\SREng\SREng.exe] <Smallfrogs Studio><2.0.12.350>
[G:\WINDOWS\system32\zpilix91.dll] <><1, 1, 1, 1008>
[G:\Program Files\360safe\safemon\safemon.dll] <><3, 2, 0, 1001>
==================================
文件关联
.TXT Error. [G:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [G:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================