瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】各位朋友,帮忙看一下日志!万分感谢!!!

12   2  /  2  页   跳转

【求助】各位朋友,帮忙看一下日志!万分感谢!!!

==================================
正在运行的进程
[PID: 492][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 552][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 576][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 620][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 632][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 780][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 824][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 872][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1304][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Logitech\SetPoint\GameHook.dll]  [N/A, ]
    [C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.30.399]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.7214]
    [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.7214]
    [C:\WINDOWS\system32\nvshell.dll]  [NVIDIA Corporation, 6.14.10.10047]
    [D:\程序\Thunder Network\ComDlls\XunLeiBHO_006.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 3]
[PID: 1772][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.33]
    [C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.30.399]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Logitech\SetPoint\GameHook.dll]  [N/A, ]
[PID: 1796][C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe]  [Nokia Mobile Phones Ltd., 6, 60, 109, 3]
    [C:\Program Files\Common Files\PCSuite\DataLayer\Lang\DataLayer_chi-sc.nlr]  [Nokia, 6, 60, 8, 0]
    [C:\WINDOWS\system32\msxml4.dll]  [Microsoft Corporation, 4.20.9818.0]
    [C:\Program Files\Logitech\SetPoint\GameHook.dll]  [N/A, ]
    [C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.30.399]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
[PID: 1804][F:\N70\Nokia PC Suite 6\LaunchApplication.exe]  [Nokia, 6, 60, 25, 5]
    [C:\WINDOWS\system32\ConnAPI.DLL]  [Nokia., 6, 60, 27, 2]
    [F:\N70\Nokia PC Suite 6\PCSCM.dll]  [Nokia, 6, 60, 45, 4]
    [C:\Program Files\Common Files\PCSuite\ConfServer\ConfServer.dll]  [Nokia, 6, 60, 10, 0]
    [C:\WINDOWS\system32\msxml4.dll]  [Microsoft Corporation, 4.20.9818.0]
    [F:\N70\Nokia PC Suite 6\Lang\LaunchApplication_chi-sc.NLR]  [, 6, 60, 14, 0]
    [C:\Program Files\Logitech\SetPoint\GameHook.dll]  [N/A, ]
    [C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.30.399]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
[PID: 1908][C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE]  [Nokia., 6, 60, 36, 1]
    [C:\WINDOWS\system32\NclTools.dll]  [Nokia., 6, 60, 12, 0]
    [C:\Program Files\Common Files\PCSuite\Transports\NCLIrDAMM.dll]  [Nokia Corp., 6, 60, 19, 0]
    [C:\Program Files\Common Files\PCSuite\Transports\NclMSBTMM.dll]  [Nokia., 6, 60, 29, 0]
    [C:\Program Files\Common Files\PCSuite\Transports\NCLRSMM.dll]  [Nokia, 6,60, 28, 0]
    [C:\Program Files\Common Files\PCSuite\Transports\NCLUSBMM.dll]  [Nokia, 6, 60, 28, 0]
    [C:\Program Files\Logitech\SetPoint\GameHook.dll]  [N/A, ]
    [C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.30.399]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
[PID: 1960][C:\WINDOWS\system32\RUNDLL32.EXE]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\NvMcTray.dll]  [NVIDIA Corporation, 6.14.10.7214]
    [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.7214]
    [C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.30.399]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Logitech\SetPoint\GameHook.dll]  [N/A, ]
[PID: 2012][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.30.399]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Logitech\SetPoint\GameHook.dll]  [N/A, ]
[PID: 228][C:\Program Files\Logitech\SetPoint\SetPoint.exe]  [Logitech Inc., 2.30.399]
    [C:\Program Files\Logitech\SetPoint\KemUtil.dll]  [Logitech Inc., 2.30.399]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Logitech\SetPoint\SetPointCOM.dll]  [Logitech Inc., 2.30.399]
    [C:\Program Files\Logitech\SetPoint\kemutb.dll]  [Logitech Inc., 2.30.399]
    [C:\Program Files\Logitech\SetPoint\KGame.dll]  [TODO: <Company name>, 1.0.0.1]
    [C:\Program Files\Logitech\SetPoint\KemWnd.dll]  [Logitech Inc., 2.30.399]
    [C:\Program Files\Logitech\SetPoint\GameHook.dll]  [N/A, ]
    [C:\Program Files\Logitech\SetPoint\KemXML.dll]  [Logitech Inc., 2.30.399]
    [C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.30.399]
    [C:\Program Files\Logitech\SetPoint\Macros\MacroCore.dll]  [Logitech Inc., 2.30.399]
    [C:\WINDOWS\system32\ATL71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Common Files\Logitech\KHAL\KhalApi.dll]  [Logitech Inc., 2.30.399]
[PID: 292][C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE]  [Logitech Inc., 2.30.314]
    [C:\Program Files\Common Files\Logitech\KHAL\KHALAPI.DLL]  [Logitech Inc., 2.30.399]
    [C:\Program Files\Logitech\SetPoint\GameHook.dll]  [N/A, ]
    [C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.30.399]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Common Files\Logitech\KHAL\KHALITCH.DLL]  [Logitech Inc., 2.30.399]
    [C:\Program Files\Common Files\Logitech\KHAL\KHALMW.DLL]  [Logitech Inc., 2.30.399]
    [C:\Program Files\Common Files\Logitech\KHAL\KHALHPP.DLL]  [Logitech Inc., 2.30.399]
[PID: 2076][C:\Documents and Settings\zm\My Documents\SREng\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\Program Files\Logitech\SetPoint\GameHook.dll]  [N/A, ]
    [C:\Program Files\Logitech\SetPoint\lgscroll.dll]  [Logitech Inc., 2.30.399]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
RVA  错误: LoadLibraryA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF67FCB25)
RVA  错误: LoadLibraryExA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF67FCD67)
RVA  错误: LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF67FCF0B)
RVA  错误: LoadLibraryW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF67FCC49)
RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: Dest Addr: 0xF67FCE8F)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

感谢7、8楼的两位朋友!

谁有时间再帮我看看!!!!


谢谢了!
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT