1   1  /  1  页   跳转

[求助] 高手帮看看.(附日记)

高手帮看看.(附日记)

[CODE]

2003-01-02,01:20:45

System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
    进程特权扫描


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
    <AutoKill><C:\Documents and Settings\Administrator\桌面\USBkill-v4.0\USBkill-v4.0\USBkill-v4.0\usbkill.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <360Safetray><D:\Program Files\360safe\safemon\360tray.exe /start>  [(Verified)Qizhi Software (beijing) Co. Ltd]
    <NvCplDaemon><; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Publisher]
    <BigDogPath><C:\WINDOWS\VM_STI.EXE USB PC Camera 301P>  [N/A]
    <360Safebox><"C:\Program Files\360Safebox\safeboxTray.exe" /r>  [(Verified)Qizhi Software (beijing) Co. Ltd]
    <Google IME Autoupdater><"C:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe">  [(Verified)Google Inc]
    <NvMediaCenter><; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <nwiz><; nwiz.exe /install>  []
    <SoundMan><; SOUNDMAN.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <switch><; c:\windows\system32\壁纸自动换.exe>  []
    <Google Updater><"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -systray -startup>  [(Verified)Google Inc]
    <Adobe Reader Speed Launcher><"D:\杂物区\Reader\Reader_sl.exe">  [(Verified)"Adobe Systems, Incorporated"]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <BoBoTCPModifyLastDate><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows XP Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\system32\七彩极光.SCR>  [Matt Ginzton]

==================================
启动文件夹
[QQ游戏启动加速程序]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\QQ游戏启动加速程序.lnk --> D:\PROGRA~1\Tencent\QQGAME\Accel.exe [深圳市腾讯计算机系统有限公司]><N>
[彩虹QQ显IP]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\彩虹QQ显IP.lnk --> C:\Program Files\彩虹QQ\CaiHong.exe [N/A]><N>

==================================
服务
[BoBoTurbo / BoBoTurbo][Stopped/Auto Start]
  <C:\WINDOWS\system32\boboturbo\boboturbo.exe><N/A>
[Contrl Center of Storm Media / ccosm][Running/Auto Start]
  <C:\Program Files\StormII\stormliv.exe /asservice><北京暴风网际科技有限公司>
[ClipBook / ClipSrv][Stopped/Auto Start]
  <C:\WINDOWS\system32\svvhost.exe><N/A>
[Google Updater Service / gusvc][Running/Auto Start]
  <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Qvod Terminal / Qvod Terminal][Running/Auto Start]
  <F:\365\QvodPlayer\QvodTerminal.exe><Shenzhen QVOD Technology Co.,Ltd>

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; QQDownload 1.7; TencentTraveler 4.0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) )
分享到:
gototop
 

回复:高手帮看看.(附日记)

==================================
驱动程序
[360TimeProt / 360TimeProt][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\360TimeProt.sys><N/A>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[AliIde / AliIde][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
  <System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
[CmdIde / CmdIde][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[EagleNT / EagleNT][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\drivers\EagleNT.sys><N/A>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[VIA Rhine Family Fast Ethernet Adapter Driver Service / FETNDISB][Running/Manual Start]
  <system32\DRIVERS\fetnd5b.sys><VIA Technologies, Inc.>
[npkcrypt / npkcrypt][Stopped/Auto Start]
  <\??\C:\Program Files\QQ2006\npkcrypt.sys><N/A>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[oreans32 / oreans32][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\oreans32.sys><N/A>
[Profos / Profos][Stopped/Manual Start]
  <\??\C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\profos.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[QKeyServiceDisplay / QKeyService][Running/Boot Start]
  <\SystemRoot\system32\KeyCrypt.sys><Tencent Technology (Shenzhen) Company Limited>
[SafeBoxKrnl / SafeBoxKrnl][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\SafeBoxKrnl.sys><360安全中心>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[TesSafe / TesSafe][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\TesSafe.sys><TENCENT>
[Trufos / Trufos][Stopped/Manual Start]
  <\??\C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\trufos.sys><N/A>
[VIA AGP Filter / viaagp1][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
[ViaIde / ViaIde][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[VIAMRAID / VIAMRAID][Stopped/Boot Start]
  <\SystemRoot\system32\DRIVERS\viamraid.sys><VIA Technologies inc,.ltd>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[USB PC Camera 301P / ZSMC301b][Running/Manual Start]
  <System32\Drivers\usbVM31b.sys><VM>

==================================
浏览器加载项
[Thunder Browser Helper]
  {00000000-12A2-4305-82F9-43058F20E8D2} <C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[QQCycloneHelper Class]
  {00000000-12A3-4305-82F9-43058F20E8D2} <F:\旋窝\QQIEHelper02.dll, 腾讯公司>
[ThunderAtOnce Class]
  {01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[Adobe PDF Link Helper]
  {18DF081C-E8AD-4283-A596-FA578C2EBDC3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll, Adobe Systems Incorporated>
[Google Toolbar Notifier BHO]
  {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll, Google Inc.>
[SafeMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\Program Files\360safe\safemon\safemon.dll, 360.CN>
[RavOnline Class]
  {9FAFB576-6933-4CCC-AB3D-B988EC43D04E} <C:\WINDOWS\Downloaded Program Files\RavOLCtl.dll, Beijing Rising Technology Co., Ltd.>
[Thunder Browser Helper]
  {00000000-12A2-4305-82F9-43058F20E8D2} <C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[QQCycloneHelper Class]
  {00000000-12A3-4305-82F9-43058F20E8D2} <F:\旋窝\QQIEHelper02.dll, 腾讯公司>
[ThunderAtOnce Class]
  {01443AEC-0FD1-40FD-9C87-E93D1494C233} <C:\Program Files\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[Adobe PDF Reader Link Helper]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Adobe PDF Link Helper]
  {18DF081C-E8AD-4283-A596-FA578C2EBDC3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll, Adobe Systems Incorporated>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
  {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[XML Document]
  {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[Thunder Agent Class]
  {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <C:\Program Files\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[360SafeLive]
  {87515F61-A66C-4319-A0E0-D416CB8059E3} <D:\Program Files\360safe\live.dll, 360.cn>
[Google Toolbar Notifier BHO]
  {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll, Google Inc.>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[SafeMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\Program Files\360safe\safemon\safemon.dll, 360.CN>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx, Adobe Systems, Inc.>
[PlayerCtrl Class]
  {E05BC2A3-9A46-4A32-80C9-023A473F5B23} <F:\2008传美\qq\QzoneMusic.dll, 深圳腾讯科技>
[QvodCtrl Class]
  {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, Shenzhen QVOD Technology Co.,Ltd>
[&使用超级旋风下载]
  <F:\旋窝\geturl.htm, N/A>
[&使用超级旋风下载全部链接]
  <F:\旋窝\getAllurl.htm, N/A>
[使用迅雷下载]
  <C:\Program Files\Thunder\Program\geturl.htm, N/A>
[使用迅雷下载全部链接]
  <C:\Program Files\Thunder\Program\getallurl.htm, N/A>
[添加到QQ表情]
  <F:\2008传美\qq\AddEmotion.htm, N/A>
gototop
 

回复:高手帮看看.(附日记)

==================================
正在运行的进程
[PID: 588 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 648 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 672 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 716 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\AppPatch\AcAdProc.dll]  [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
[PID: 728 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 896 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 964 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1084 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1140 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1244 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1460 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1672 / Administrator][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WPDShServiceObj.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [D:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1005]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\PortableDeviceTypes.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 9.0.0.2008061100]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS]  [Adobe Systems, Inc., 9.0.0.0]
    [C:\WINDOWS\system32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\Program Files\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\Program Files\QvodPlayer\QvodBand.dll]  [Shenzhen QVOD Technology Co.,Ltd, 3, 0, 0, 0]
[PID: 1760 / Administrator][C:\WINDOWS\VM_STI.EXE]  [VM., 4.2.610.4]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\WINDOWS\system32\VM31bPrp.Ax]  [VM, 4.2.711.31]
[PID: 1776 / Administrator][C:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe]  [Google Inc., 1, 0, 0, 1]
[PID: 1792 / Administrator][C:\Program Files\Google\Google Updater\GoogleUpdater.exe]  [Google, 2.4.1368.5602.beta]
    [C:\Program Files\Google\Google Updater\2.4.1368.5602\ci.dll]  [Google, 2.4.1368.5602.beta]
    [D:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1005]
    [C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll]  [Google Inc., 4, 1, 805, 4472]
[PID: 1820 / Administrator][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1900 / SYSTEM][C:\WINDOWS\system32\netdde.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2012 / SYSTEM][C:\WINDOWS\system32\netdde.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 116 / SYSTEM][C:\Program Files\StormII\stormliv.exe]  [北京暴风网际科技有限公司, 3, 8, 10, 29]
    [C:\Program Files\StormII\MSVCP60.dll]  [Microsoft Corporation, 6.02.3104.0]
    [C:\Program Files\StormII\bfoptdll.dll]  [北京暴风网际科技有限公司, 3, 8, 7, 16]
[PID: 204 / SYSTEM][C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe]  [Google, 2.4.1368.5602.beta]
[PID: 248 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.9136]
[PID: 400 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1368 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1580 / Administrator][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1005]
[PID: 3168 / Administrator][C:\Program Files\TTPlayer\TTPlayer.exe]  [Alen Soft, 5, 0, 0, 0]
    [C:\Program Files\TTPlayer\ttpcomm.dll]  [N/A, ]
    [D:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1005]
    [C:\Program Files\TTPlayer\ttpres.dll]  [Alen Soft, 5, 0, 0, 0]
    [C:\Program Files\TTPlayer\msdmo.dll]  [Microsoft Corporation, 6.03.01.0400]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\TTPlayer\AddIn\ttp_asf.dll]  [N/A, ]
    [C:\Program Files\TTPlayer\AddIn\ttp_rm.dll]  [N/A, ]
[PID: 1572 / Administrator][F:\2008传美\qq\QQ.exe]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQBaseClassInDll.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQHelperDll.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\BasicCtrlDll.dll]  [TENCENT, 8,0,1248,1851]
    [F:\2008传美\qq\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [F:\2008传美\qq\HookQQ.dll]  [N/A, ]
    [F:\2008传美\qq\MSIMG32.dll]  [N/A, ]
    [F:\2008传美\qq\LoadPatch.dll]  [N/A, ]
    [F:\2008传美\qq\TheTools.dll]  [N/A, ]
    [F:\2008传美\qq\HKDlls\KillQQAd.dll]  [N/A, ]
    [D:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1005]
    [F:\2008传美\qq\CaiHong.dll]  [N/A, ]
    [F:\2008传美\qq\Reporter.dll]  [N/A, ]
    [F:\2008传美\qq\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [F:\2008传美\qq\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [F:\2008传美\qq\QQAPI.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\TXPFProxy.dll]  [N/A, ]
    [F:\2008传美\qq\LoginCtrl.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\LoginCtrlRes.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQRes.dll]  [TENCENT, 8,0,978,1833]
    [F:\2008传美\qq\WizardCtrl.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQMainFrame.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [F:\2008传美\qq\UnReadMsgMgr.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQAllInOne.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\SCCore.dll]  [TENCENT, 1, 6, 0, 2]
    [F:\2008传美\qq\CameraDll.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\CQQApplication.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\FlashAvatarDll.dll]  [, 1, 0, 0, 1]
    [F:\2008传美\qq\NewSkin.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\MailSummary.dll]  [TENCENT, 8,0,1234,1851]
    [F:\2008传美\qq\QQSpace.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\UserDefinedHead.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQPlugin.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\vbscript.dll]  [N/A, ]
    [F:\2008传美\qq\encode.dll]  [Microsoft Corporation, 5.6.0.8825]
    [F:\2008传美\qq\msdmo.dll]  [, ]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx]  [Adobe Systems, Inc., 9,0,124,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [F:\2008传美\qq\QQAvatar.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQSettingCtrl.dll]  [TENCENT, ]
    [F:\2008传美\qq\OEMApplication.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQKnowledgeSearch.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQGroupMng.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQPet.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QRingMng.dll]  [TENCENT, 8,0,1249,1853]
    [C:\WINDOWS\system32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
    [F:\2008传美\qq\LongConnection.dll]  [TENCENT, 8,0,1249,1851]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.5510]
    [F:\2008传美\qq\QQSysMsgMng.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQConfigPlugin.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQCustomFace.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQMagicFace.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\ImageOle.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQLiveQMng.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQSceneMng.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\GroupConnection.dll]  [TENCENT, 8,0,1249,1851]
    [F:\2008传美\qq\BQQApplication.dll]  [TENCENT, 8,0,1249,1853]
    [C:\WINDOWS\system32\JPWB.IME]  [常诚研制, 4.00.950]
    [F:\2008传美\qq\PersonalDesktop.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\CommercesMng.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 330]
    [F:\2008传美\qq\AddrSearch.dll]  [腾讯科技(深圳)有限公司, 2, 2, 1, 22]
gototop
 

回复:高手帮看看.(附日记)

[PID: 184 / Administrator][F:\2008传美\qq\TXPlatform.exe]  [Tencent, 1, 5, 225, 0]
    [D:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1005]
    [F:\2008传美\qq\TXPFProxy.dll]  [N/A, ]
[PID: 516 / Administrator][E:\Program Files\Tencent\TT\bin\TTraveler.exe]  [Tencent, 4, 15, 0, 12]
    [E:\Program Files\Tencent\TT\bin\TTUtilWidget.dll]  [Tencent, 4, 15, 0, 12]
    [E:\Program Files\Tencent\TT\bin\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.42]
    [E:\Program Files\Tencent\TT\bin\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [E:\Program Files\Tencent\TT\bin\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.42]
    [E:\Program Files\Tencent\TT\bin\detoured.dll]  [Microsoft Corporation, Express Version 2.1 Build_216]
    [D:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1005]
    [E:\Program Files\Tencent\TT\bin\TTStore.dll]  [Tencent, 4, 15, 0, 12]
    [E:\Program Files\Tencent\TT\bin\sqlite3.dll]  [N/A, ]
    [E:\Program Files\Tencent\TT\bin\PlatformWidget.dll]  [Tencent, 4, 15, 0, 12]
    [E:\Program Files\Tencent\TT\bin\TTMainFrame.dll]  [Tencent, 4, 15, 0, 12]
    [E:\Program Files\Tencent\TT\bin\UpdateUtil.dll]  [N/A, ]
    [E:\Program Files\Tencent\TT\bin\TTMBrowser.dll]  [Tencent, 4, 15, 0, 12]
    [E:\Program Files\Tencent\TT\bin\TTabMgr.dll]  [Tencent, 4, 15, 0, 12]
    [E:\Program Files\Tencent\TT\bin\TTSkin.dll]  [Tencent, 4, 15, 0, 12]
    [E:\Program Files\Tencent\TT\bin\vbscript.dll]  [Microsoft Corporation, 5.7.0.16535]
    [E:\Program Files\Tencent\TT\bin\TTHtmlApp.dll]  [Tencent, 4, 15, 0, 12]
    [E:\Program Files\Tencent\TT\bin\TTFilter.dll]  [Tencent, 4, 15, 0, 12]
    [E:\Program Files\Tencent\TT\bin\TTNetwork.dll]  [Tencent, 4, 15, 0, 12]
    [E:\Program Files\Tencent\TT\bin\TTPluginMng.dll]  [Tencent, 4, 15, 0, 12]
    [E:\Program Files\Tencent\TT\Plugins\3TTWeather\TTWeather.dll]  [Tencent, 1.0.0.1]
    [E:\Program Files\Tencent\TT\Plugins\WebInfo\WebToolbar.dll]  [Tencent, 1.0.0.1]
    [E:\Program Files\Tencent\TT\bin\FavoriteLogical.dll]  [Tencent, 4, 15, 0, 12]
    [E:\Program Files\Tencent\TT\bin\TSupport.dll]  [TENCENT Inc., 1, 2, 11, 201]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 9.0.0.2008061100]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS]  [Adobe Systems, Inc., 9.0.0.0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\JPWB.IME]  [常诚研制, 4.00.950]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx]  [Adobe Systems, Inc., 9,0,124,0]
[PID: 3836 / Administrator][F:\2008传美\qq\QQ.exe]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQBaseClassInDll.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQHelperDll.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\BasicCtrlDll.dll]  [TENCENT, 8,0,1248,1851]
    [F:\2008传美\qq\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [F:\2008传美\qq\HookQQ.dll]  [N/A, ]
    [F:\2008传美\qq\MSIMG32.dll]  [N/A, ]
    [F:\2008传美\qq\LoadPatch.dll]  [N/A, ]
    [F:\2008传美\qq\TheTools.dll]  [N/A, ]
    [D:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1005]
    [F:\2008传美\彩虹QQ\CaiHong.dll]  [N/A, ]
    [F:\2008传美\qq\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [F:\2008传美\qq\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [F:\2008传美\qq\QQAPI.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\彩虹QQ\Reporter.dll]  [N/A, ]
    [F:\2008传美\qq\LoginCtrl.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\LoginCtrlRes.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQRes.dll]  [TENCENT, 8,0,978,1833]
    [F:\2008传美\qq\WizardCtrl.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQMainFrame.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [F:\2008传美\qq\UnReadMsgMgr.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQAllInOne.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\SCCore.dll]  [TENCENT, 1, 6, 0, 2]
    [F:\2008传美\qq\CameraDll.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\CQQApplication.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\FlashAvatarDll.dll]  [, 1, 0, 0, 1]
    [F:\2008传美\qq\NewSkin.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\MailSummary.dll]  [TENCENT, 8,0,1234,1851]
    [F:\2008传美\qq\QQSpace.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\vbscript.dll]  [N/A, ]
    [F:\2008传美\qq\encode.dll]  [Microsoft Corporation, 5.6.0.8825]
    [F:\2008传美\qq\msdmo.dll]  [, ]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx]  [Adobe Systems, Inc., 9,0,124,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [F:\2008传美\qq\QQAvatar.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQSettingCtrl.dll]  [TENCENT, ]
    [F:\2008传美\qq\OEMApplication.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQKnowledgeSearch.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQGroupMng.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQPlugin.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQPet.dll]  [TENCENT, 8,0,1249,1853]
    [C:\WINDOWS\system32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
    [F:\2008传美\qq\QRingMng.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\LongConnection.dll]  [TENCENT, 8,0,1249,1851]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.5510]
    [F:\2008传美\qq\QQSysMsgMng.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\UserDefinedHead.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQConfigPlugin.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQCustomFace.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\BQQApplication.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\CommercesMng.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\PersonalDesktop.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 330]
    [F:\2008传美\qq\P2PFile\vqqsdl.dll]  [Tencent Technology (Shenzhen) Company Limited, 5, 0, 0, 12]
    [F:\2008传美\qq\QQSceneMng.dll]  [TENCENT, 8,0,1249,1853]
    [F:\2008传美\qq\AddrSearch.dll]  [腾讯科技(深圳)有限公司, 2, 2, 1, 22]
[PID: 2808 / SYSTEM][F:\365\QvodPlayer\QvodTerminal.exe]  [Shenzhen QVOD Technology Co.,Ltd, 2, 5, 0, 54]
[PID: 4076 / Administrator][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
    [D:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1005]
    [C:\WINDOWS\system32\wpdshext.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[PID: 3676 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.328\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [D:\Program Files\360safe\safemon\safemon.dll]  [360.CN, 4, 2, 0, 1005]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.328\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

==================================
文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 

回复:高手帮看看.(附日记)

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
218.85.139.171  www.6moyu.com
218.85.139.171  www.350my.com
218.85.139.171  www.913my.com
218.85.139.171  www.cnz5.com
218.85.139.171  www.xmpa18.com
218.85.139.171  www.cnz5.com
218.85.139.171  www.wanmoyu.com
218.85.139.171  www.003my.com
218.85.139.171  www.71my.com
218.85.139.171  www.3moyu.com
218.85.139.171  www.sfbb3.com
218.85.139.171  www.360moyu.com
218.85.139.171  www.moyu.cn
218.85.139.171  www.76my.com
218.85.139.171  www.885mu.com
218.85.139.171  www.ziyounet.cn
218.85.139.171  www.zhaomy.com
218.85.139.171  www.xkmoyu.com
218.85.139.171  www.laiwow.cn
218.85.139.171  www.911moyu.cn
218.85.139.171  www.4000my.com
218.85.139.171  moyu.name
218.85.139.171  www.54my.com
218.85.139.171  www.96my.com
218.85.139.171  www.0000my.cn
218.85.139.171  www.25000my.cn
218.85.139.171  www.3344my.cn
218.85.139.171  www.utwoool.com
218.85.139.171  www.39my.com
218.85.139.171  www.moyusifu.com
218.85.139.171  www.8888my.com
218.85.139.171  www.haomyw.com
218.85.139.171  www.sssmy.com
218.85.139.171  www.300my.com
218.85.139.171  www.moyusf.com
218.85.139.171  www.haomy8.com
218.85.139.171  www.004my.cn
218.85.139.171  www.288my.com
218.85.139.171  www.3czt.com
218.85.139.171  www.018c.com
218.85.139.171  www.733my.com
218.85.139.171  www.003my.cc
218.85.139.171  www.lllmy.com
127.0.0.1  www.cike007.cn
127.0.0.1  www.exiao01.com
127.0.0.1  qqq.dzydhx.com
127.0.0.1  qqq.hao1658.com
127.0.0.1  www.333292.com
127.0.0.1  down.18dd.net
127.0.0.1  xxx.m111.biz
127.0.0.1  1.jopenqc.com
127.0.0.1  xxx.j41m.com
127.0.0.1  3.joppnqq.com
127.0.0.1  d.93se.com
127.0.0.1  1.jopenkk.com
127.0.0.1  xxx.vh7.biz
127.0.0.1  new.749571.com
127.0.0.1  xtx.kv8.info
127.0.0.1  cao.kv8.info
127.0.0.1  1.jopmmqq.com
127.0.0.1  yu.8s7.net
127.0.0.1  1.jopanqc.com
127.0.0.1  2.joppnqq.com
127.0.0.1  www.868wg.com
127.0.0.1  xxx.mmma.biz
127.0.0.1  ilove.com
127.0.0.1  www.22aaa.com
127.0.0.1  xx.exiao01.com
127.0.0.1  www.exiao01.com
127.0.0.1  tp.shpzhan.cn
127.0.0.1  www.tomwg.com
127.0.0.1  wg.47255.com
127.0.0.1  1.joppnqq.com
127.0.0.1  171817.171817.com
127.0.0.1  d2.llsging.com
127.0.0.1  down.malasc.cn
127.0.0.1  llboss.com
127.0.0.1  nx.51ylb.cn
127.0.0.1  my.531jx.cn
127.0.0.1  up.22x44.com

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1760, C:\WINDOWS\VM_STI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3168, C:\PROGRAM FILES\TTPLAYER\TTPLAYER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 4076, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

回复:高手帮看看.(附日记)

127.0.0.1 www.watcheskiss.com
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1760, C:\WINDOWS\VM_STI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3168, C:\PROGRAM FILES\TTPLAYER\TTPLAYER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 4076, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
gototop
 

回复: 高手帮看看.(附日记)

[oreans32 / oreans32][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\oreans32.sys><N/A>


lz用了 AntiARP防火墙?

建议上传日志时以附件形式上传。。。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT