1   1  /  1  页   跳转

【求助】木马??后门病毒??

【求助】木马??后门病毒??

今天下午,瑞星查到一个病毒。类形现示:??**奇怪。
最后编辑2007-07-24 12:25:25
分享到:
gototop
 

下载 System Repair Engineer,
http://www.kztechs.com/sreng/download.html
1 解压缩sreng2.zip
2 运行SREng.exe
3 关掉所有手动打开的东西
4 智能扫描=》扫描=》保存报告
5 把日志中的报告完整拷贝贴上来,不要修改,(一次贴不完分多次贴)!

gototop
 

[CODE]

2007-07-22,20:53:34

System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"D:\程序\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<RfwMain><"D:\程序\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
<MSConfig><C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<RavStub><"D:\程序\RISING\RAV\ravstub.exe" /RUNONCE> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
<WinlogonNotify: igfxcui><igfxdev.dll> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8b15971b-5355-4c82-8c07-7e181ea07608}]
<Fax><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<Acer ePresentation HPD><; C:\Acer\Empowering Technology\ePresentation\ePresentation.exe> [Acer Inc.]
<AGRSMMSG><; AGRSMMSG.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<Alcmtr><; ALCMTR.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<AzMixerSel><; C:\Program Files\Realtek\InstallShield\AzMixerSel.exe> [Realtek Semiconductor Corp.]
<BluetoothAuthenticationAgent><; rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent> [(Verified)Microsoft Windows Publisher]
<Boot><; C:\Acer\Empowering Technology\ePower\Boot.exe> []
<ccApp><; > [N/A]
<eDataSecurity Loader><; C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 0> [N/A]
<ePower_DMC><; C:\Acer\Empowering Technology\ePower\ePower_DMC.exe> []
<eRecoveryService><; C:\Acer\Empowering Technology\eRecovery\eRAgent.exe> [Acer Inc.]
<igfxhkcmd><; C:\WINDOWS\system32\hkcmd.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<igfxpers><; C:\WINDOWS\system32\igfxpers.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<igfxtray><; C:\WINDOWS\system32\igfxtray.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<LaunchApp><; Alaunch> [N/A]
<LManager><; C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE> [Dritek System Inc.]
<LogitechCameraAssistant><; C:\Program Files\Acer\OrbiCam\CameraAssistant.exe> [Acer]
<LogitechCameraService(E)><; C:\WINDOWS\system32\ElkCtrl.exe /automation> [Logitech Inc.]
<LogitechVideo[inspector]><; C:\Program Files\Acer\OrbiCam\InstallHelper.exe /inspect> [Acer]
<LVCOMSX><; C:\WINDOWS\system32\LVCOMSX.EXE> [Logitech]
<miniqqlive><; "C:\Program Files\Tencent\QQLive\MiniQQLive.exe"> [Tencent]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<MSMSGS><; > [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<MSPY2002><; C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC> [(Verified)Microsoft Windows Publisher]
<ntiMUI><; C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe> []
<NvCplDaemon><; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<NvMediaCenter><; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<nwiz><; nwiz.exe /install> []
<PCMService><; "C:\Program Files\Acer\Acer Arcade\PCMService.exe"> [CyberLink Corp.]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
<RTHDCPL><; RTHDCPL.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<runeip><; C:\Program Files\Rising\AntiSpyware\runiep.exe> [Beijing Rising Technology Co., Ltd.]
<SkyTel><; SkyTel.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<stup.exe><; > [N/A]
<SynTPEnh><; C:\Program Files\Synaptics\SynTP\SynTPEnh.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<yhplayer><; > [N/A]
gototop
 

cer\Acer Arcade\Kernel\TV\CLCapSvc.exe] [, 4.05.2423]
[C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapEngine.dll] [, 4.05.2423]
[C:\Program Files\Acer\Acer Arcade\Kernel\TV\PCMRRec4.dll] [CyberLink Corp., 4.01.2426]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\dshowext.ax] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Acer\Acer Arcade\Kernel\TV\PCMRResample.ax] [CyberLink, 4.0.0126 ]
[C:\WINDOWS\system32\lvcodec2.dll] [Logitech, 9.4.4.1082]
[C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvcps.dll] [N/A, ]
[PID: 1936 / SYSTEM][C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe] [Cyberlink, 2, 1, 0, 1815]
[PID: 1972 / SYSTEM][C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe] [Cyberlink, 2, 1, 0, 1815]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[PID: 1988 / SYSTEM][C:\Program Files\Common Files\LightScribe\LSSrvc.exe] [Hewlett-Packard Company, 1.4.97.1]
[C:\Program Files\Common Files\LightScribe\LSSProxy.dll] [Hewlett-Packard Company, 1.4.97.1]
[C:\Program Files\Common Files\LightScribe\LSLog.dll] [Hewlett-Packard Company, 1.4.97.1]
[C:\Program Files\Common Files\LightScribe\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.42]
[C:\Program Files\Common Files\LightScribe\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.42]
[PID: 340 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.8485]
[PID: 352 / acer][D:\程序\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[D:\程序\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[D:\程序\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[D:\程序\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[D:\程序\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 440 / acer][D:\程序\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 45]
[D:\程序\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[D:\程序\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[D:\程序\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[D:\程序\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[D:\程序\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[D:\程序\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[D:\程序\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[D:\程序\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\Acer\Empowering Technology\ePower\SysHook.dll] [, 0, 9, 7, 3]
[PID: 488 / acer][C:\Acer\Empowering Technology\ePower\ePower_DMC.exe] [, 0.34]
[C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 1.1.4322.2032]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll] [Microsoft Corporation, 1.1.4322.2032]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_5d1dbd9c\mscorlib.dll] [N/A, ]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll] [Microsoft Corporation, 1.1.4322.573]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_3f59c1ec\system.windows.forms.dll] [N/A, ]
[c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_f8d4c8ae\system.dll] [N/A, ]
[c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll] [Microsoft Corporation, 1.1.4322.2032]
[c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_cb1d9ec4\system.drawing.dll] [N/A, ]
[c:\acer\empowering technology\epower\acer.empowering.windows.forms.dll] [acer inc., 1.0.1.31790]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\diasymreader.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\NvCpl.dll] [NVIDIA Corporation, 6.14.10.8485]
[C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.10.8485]
[C:\Acer\Empowering Technology\ePower\SysHook.dll] [, 0, 9, 7, 3]
[C:\Acer\Empowering Technology\ePower\DialogDLL.dll] [, 1, 0, 0, 1]
[PID: 692 / acer][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 4.0.0.15]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1116 / acer][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1188 / SYSTEM][C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe] [Intel Corporation, 10, 1, 1, 1]
[PID: 1104 / SYSTEM][C:\Program Files\CyberLink\Shared Files\RichVideo.exe] [, 1.0.1321 ]
[PID: 1308 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1700 / SYSTEM][C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe] [, 4.05.2423]
[C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvcps.dll] [N/A, ]
[C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSchMgr.dll] [, 4.05.2423]
[PID: 2440 / SYSTEM][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2460 / SYSTEM][C:\WINDOWS\system32\wbem\wmiapsrv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3024 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3284 / NETWORK SERVICE][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3296 / acer][C:\WINDOWS\system32\wbem\unsecapp.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll] [Logitech, 9.4.4.1082]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 3588 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3520 / acer][D:\Program Files\Tencent\QQ\QQ.exe] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\QQBaseClassInDll.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\QQHelperDll.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\BasicCtrlDll.dll] [TENCENT, 7, 0, 225, 1651]
[D:\Program Files\Tencent\QQ\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll] [Logitech, 9.4.4.1082]
[D:\Program Files\Tencent\QQ\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
[D:\Program Files\Tencent\QQ\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
[D:\Program Files\Tencent\QQ\QQAPI.dll] [TENCENT, 7,0,225,1651]
[d:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[D:\Program Files\Tencent\QQ\LoginCtrl.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\LoginCtrlRes.dll] [TENCENT, 7,0,225,1651]
[C:\Acer\Empowering Technology\ePower\SysHook.dll] [, 0, 9, 7, 3]
[D:\Program Files\Tencent\QQ\QQRes.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\MailSummary.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\QQMainFrame.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Program Files\Tencent\QQ\CQQApplication.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[D:\Program Files\Tencent\QQ\NewSkin.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\HostingMgr.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\CameraDll.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\QQKnowledgeSearch.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\QQAllInOne.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\SCCore.dll] [TENCENT, 1, 6, 0, 2]
[D:\Program Files\Tencent\QQ\QQSpace.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\vbscript.dll] [Microsoft Corporation, 5.6.0.7426]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[D:\Program Files\Tencent\QQ\QQGroupMng.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\QQSysMsgMng.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\UserDefinedHead.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\QQPlugin.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\QQConfigPlugin.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\QQAvatar.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\QRingMng.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\LongConnection.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\QQPet.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\PhoneAPI.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
gototop
 

[D:\Program Files\Tencent\QQ\QQCustomFace.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\ImageOle.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\QQLiveQMng.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\QQSceneMng.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]
[D:\Program Files\Tencent\QQ\BQQApplication.dll] [N/A, ]
[D:\Program Files\Tencent\QQ\GroupConnection.dll] [TENCENT, 7,0,225,1651]
[C:\WINDOWS\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Program Files\Tencent\QQ\QQMagicFace.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\CommercesMng.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
[D:\Program Files\Tencent\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 300]
[D:\Program Files\Tencent\QQ\QQZip.dll] [TENCENT, 7,0,225,1651]
[D:\Program Files\Tencent\QQ\QQPhoneHelper.dll] [腾讯科技(深圳)有限公司, 2, 1, 9, 93]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.2.54.0]
[PID: 3576 / acer][d:\Program Files\Tencent\QQ\TIMPlatform.exe] [TENCENT, 7,0,225,1651]
[C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll] [Logitech, 9.4.4.1082]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[d:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 3668 / acer][C:\Program Files\Thunder Network\Thunder\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5.3.0.220]
[C:\Program Files\Thunder Network\Thunder\Program\UpdateDownload.dll] [N/A, ]
[C:\Program Files\Thunder Network\Thunder\Program\msgmanage.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 15]
[C:\Program Files\Thunder Network\Thunder\Program\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031]
[C:\Program Files\Thunder Network\Thunder\Program\log4cplus.dll] [, 1, 0, 2, 1]
[C:\Program Files\Thunder Network\Thunder\Program\historyinfo_manage.dll] [Thunder Networking Technologies,LTD, 5, 2, 0, 148]
[C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll] [Logitech, 9.4.4.1082]
[C:\Program Files\Thunder Network\Thunder\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 71]
[C:\Program Files\Thunder Network\Thunder\Program\asyn_dns.dll] [N/A, ]
[C:\Program Files\Thunder Network\Thunder\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 1, 0, 18]
[C:\WINDOWS\system32\msxml4.dll] [Microsoft Corporation, 4.20.9841.0]
[C:\Program Files\Thunder Network\Thunder\Program\FloatBar.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
[C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll] [ , 1, 0, 0, 11]
[C:\Program Files\Thunder Network\Thunder\Components\InMedia\iEmbed04.dll] [ , 2, 3, 0, 37]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.7]
[C:\Acer\Empowering Technology\ePower\SysHook.dll] [, 0, 9, 7, 3]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.2.54.0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2236 / acer][D:\下载\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll] [Logitech, 9.4.4.1082]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\Acer\Empowering Technology\ePower\SysHook.dll] [, 0, 9, 7, 3]
[D:\下载\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]

==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1 localhost

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1272, C:\PROGRAM FILES\INTEL\WIRELESS\BIN\S24EVMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1892, C:\PROGRAM FILES\ACER\ACER ARCADE\KERNEL\TV\CLCAPSVC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 352, D:\程序\RISING\RAV\RAVTASK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 440, D:\程序\RISING\RAV\RAVMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 488, C:\ACER\EMPOWERING TECHNOLOGY\EPOWER\EPOWER_DMC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 692, C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3520, D:\PROGRAM FILES\TENCENT\QQ\QQ.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3576, D:\PROGRAM FILES\TENCENT\QQ\TIMPLATFORM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3668, C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\THUNDER5.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

补充一点
用笔记本浏览过IE 后
桌面上 都会自动出现个 .TXT 记事本 内容 就一个“B”
这个是杂回事
gototop
 

搞定了,谢谢!

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT