瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 来个大哥帮忙分析下日志啊 机器慢的很

1   1  /  1  页   跳转

来个大哥帮忙分析下日志啊 机器慢的很

来个大哥帮忙分析下日志啊 机器慢的很

来个大哥帮忙分析下日志啊  机器慢的很 但是查不出毒来
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SoundMan><SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<ATIPTA><C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe> [ATI Technologies, Inc.]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<wosa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\woso.exe> [N/A]
<ztsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ztso.exe> [N/A]
<mhsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mhso.exe> [N/A]
<fysa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fyso.exe> [N/A]
<jtsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jtso.exe> [N/A]
<wlsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wlso.exe> [N/A]
<wgsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wgso.exe> [N/A]
<wmsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wmso.exe> [N/A]
<qjsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qjso.exe> [N/A]
<rxsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rxso.exe> [N/A]
<wdsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wdso.exe> [N/A]
<tlsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tlso.exe> [N/A]
<runeip><C:\Program Files\Rising\KakaToolBar\runiep.exe> [Beijing Rising Technology Co., Ltd.]
<WebThunder><C:\Program Files\Thunder Network\WebThunder\WebThunder.exe> [(Verified)深圳市迅雷网络技术有限公司]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<RavStub><"C:\PROGRAM FILES\RISING\RAV\ravstub.exe" /RUNONCE> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><F:\征途逍遥游v1.1\antiScanner.dll> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
<{03F6E661-0D5F-3FAD-3E2B-E261E3CB6CD2}><C:\Program Files\Internet Explorer\PLUGINS\HiJack.dll> [N/A]

浏览器加载项
[WebThunder Browser Helper]
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[FGCatchUrl]
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <D:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
[浩方对战平台]
{0A155D3C-68E2-4215-A47A-E800A446447A} <F:\Program Files\浩方对战平台\GameClient.exe, 上海浩方在线信息技术有限公司>
[启动Web迅雷]
{962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[访问瑞星网站]
{FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} <http://www.rising.com.cn, N/A>
[访问卡卡社区]
{FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} <http://www.ikaka.com, N/A>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[WebThunder Browser Helper]
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
[WebThunder Class]
{03507A1A-E0C5-4404-AA26-205385C0892D} <, N/A>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[FGCatchUrl]
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <D:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[FGCatchUrl]
{FB5DA724-162B-11D3-8B9B-AA70B4B0B524} <D:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
[&使用快车(FlashGet)下载]
<D:\Program Files\FlashGet\jc_link.htm, N/A>
[&使用快车(FlashGet)下载全部链接]
<D:\Program Files\FlashGet\jc_all.htm, N/A>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用Web迅雷下载]
<C:\Program Files\Thunder Network\WebThunder\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
<C:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>

文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1 LOCALHOST
219.238.233.202 www.ztztzt.com.cn
219.238.233.202 www.blackzl.com
219.238.233.202 www.555125.com
58.218.179.154 www.youxig.com
58.218.179.154 bbs.youxig.com
58.218.179.154 www.ztztzt.com
58.218.179.154 bbs.ztztzt.com
58.218.179.154 ztztzt.com
219.238.233.202 www.loveuc.com
219.238.233.202 www.wowchian.com
219.238.233.202 wowchian.com
219.238.233.202 www.zhengtusf.com
219.238.233.202 zhengtusf.com
219.238.233.202 zhengtu.uuh.cn
219.238.233.202 www.ztgmme.com.cn
219.238.233.202 ztgmme.com.cn
219.238.233.202 www.zt.yn9.cn
219.238.233.202 www.221122.net
219.238.233.202 www.171737.com
219.238.233.202 www.yxcb.com
219.238.233.202 www.zt930.com
219.238.233.202 zt930.com
219.238.233.202 yxcb.com
219.238.233.202 171737.com
219.238.233.202 www.sy5832.com
219.238.233.202 221122.net
219.238.233.202 18dmm.com
219.238.233.202 www.18dmm.com
219.238.233.202 sa.cn
219.238.233.202 1.sa.cn
219.238.233.202 www.2007ip.com
219.238.233.202 2007ip.com
219.238.233.202 56jb.com
219.238.233.202 iloveck.com
219.238.233.202 www.iloveck.com
219.238.233.202 www.5yip.com
219.238.233.202 mmm.caifu18.net
219.238.233.202 d.qbbd.com
219.238.233.202 www.5117music.com
219.238.233.202 www.union123.com
219.238.233.202 www.wu7x.cn
219.238.233.202 www.54699.com
219.238.233.202 60.169.0.66
219.238.233.202 60.169.1.29
219.238.233.202 www.25zhengtu.cn
219.238.233.202 down.97725.com
219.238.233.202 ip.315hack.com
219.238.233.202 www.baidulink.com
219.238.233.202 do.77276.com
219.238.233.202 www.down.hunll.com
219.238.233.202 www.hunll.com
219.238.233.202 www.9cyy.com
219.238.233.202 www.heixiou.com
219.238.233.202 xulao.com
219.238.233.202 www.41ip.com
219.238.233.202 www1.cw988.cn
219.238.233.202 d.77276.com
219.238.233.202 i.96981.com
219.238.233.202 www.my6688.cn
219.238.233.202 wm.103715.com
219.238.233.202 www.guazhan.cn
219.238.233.202 www.f5game.com
219.238.233.202 222.73.220.45
219.238.233.202 www1.cw988.cn
219.238.233.202 adnx.yygou.cn
219.238.233.202 cool.47555.com
219.238.233.202 www.asdwc.com
219.238.233.202 55880.cn
219.238.233.202 www.5i73.com
219.238.233.202 mir2.5i73.com

[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Potu-WebBrowser www.potu.com; .NET CLR 2.0.50727)
最后编辑2007-11-30 23:49:27
分享到:
gototop
 

日记不齐.重新扫过..不过LZ可以买六合彩了..一群马在跑哦~~
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT