瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】再次发帖求助~ [font_color=#FF0000]附带扫描日志~! [/font]

1   1  /  1  页   跳转

【求助】再次发帖求助~ [font_color=#FF0000]附带扫描日志~! [/font]

【求助】再次发帖求助~ [font_color=#FF0000]附带扫描日志~! [/font]

[CODE]

2007-01-05,12:18:28

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ShStatEXE><"C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE> [N/A]
<McAfeeUpdaterUI><"C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey> [N/A]
<miniqqlive><; "D:\QQ直播\MiniQQLive.exe"> [N/A]
<Super Rabbit Desktop Set><; D:\MagicSet\DS.EXE /Load> [Super Rabbit Software]
<Attractive Clock><; a> [N/A]
<5QIM><; D:\校内通\5QIM.exe> [ 5q.com]
<木马专家><D:\Trojan Expert 2006\mmzj.exe> [Beyond 工作室]
<kav><"D:\新建文件夹\avp.exe"> [Kaspersky Lab]
<CBitSpirit><"D:\应用程序\BitSpirit\BitSpirit.exe" /start> [LANSPIRIT.NET]
<ATICCC><; "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay> [N/A]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<SoundMan><; SOUNDMAN.EXE> [(Verified)Realtek Semiconductor Corp.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ImpsSensor]
<WinlogonNotify: ImpsSensor><ImpsSensor.dll> [China Mobile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
<WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll> [Kaspersky Lab]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><C:\WINDOWS\system32\Orbitron.scr> [Sebastian Stoff]

==================================
启动文件夹
[Service Manager]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Service Manager.lnk --> C:\PROGRA~1\MICROS~4\80\Tools\Binn\sqlmangr.exe [Microsoft Corporation]><H>
[U8管理服务]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\U8管理服务.lnk --> C:\WINDOWS\system32\UfSvrMgr.exe []><H>
[QQ游戏启动加速程序]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\QQ游戏启动加速程序.lnk --> D:\QQ\QQGAME\Accel.exe [深圳市腾讯计算机系统有限公司]><H>
[腾讯QQ]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk --> D:\QQ\QQ.exe [TENCENT]><H>

==================================
服务
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart][Stopped/Auto Start]
<C:\WINDOWS\system32\ati2sgag.exe><>
[卡巴斯基反病毒6.0 / AVP][Running/Auto Start]
<D:\新建文件夹\avp.exe -r><Kaspersky Lab>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[KwMusic / KwMusic][Stopped/Auto Start]
<C:\Program Files\Common Files\KooWo\KwMV.exe /start><酷我科技>
[McAfee Framework 服务 / McAfeeFramework][Stopped/Auto Start]
<><N/A>
[Network Associates Task Manager / McTaskManager][Stopped/Auto Start]
<"C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe"><N/A>
[MSSQLSERVER / MSSQLSERVER][Running/Auto Start]
<C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe -sMSSQLSERVER><Microsoft Corporation>
[MSSQLServerADHelper / MSSQLServerADHelper][Stopped/Manual Start]
<C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe><Microsoft Corporation>
[Windows Gateway / Relations][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\ejjiv.dll><Microsoft Corporation>
[RsRavMon Service / RsRavMon][Stopped/Auto Start]
<"D:\应用程序\Rising\Rav\Ravmond.exe"><N/A>
[SQLSERVERAGENT / SQLSERVERAGENT][Stopped/Manual Start]
<C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE -i MSSQLSERVER><Microsoft Corporation>
[UFSoft SMS Platform / U8SmsSrv][Running/Auto Start]
<C:\WINDOWS\system32\U8SMSSrv.exe><N/A>
[U8管理软件 / UFNet][Running/Auto Start]
<C:\WINDOWS\system32\ServerNT.EXE><N/A>

==================================
驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[AliIde / AliIde][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\aliide.sys><N/A>
[AMD Processor Driver / AmdK8][Running/System Start]
<system32\DRIVERS\AmdK8.sys><Advanced Micro Devices>
[ati2mtag / ati2mtag][Running/Manual Start]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[atitray / atitray][Running/System Start]
<\??\C:\Program Files\Radeon Omega Drivers\v3.8.221\ATI Tray Tools\atitray.sys><N/A>
[Cdsys / Cdsys][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\cdcd.sys><N/A>
[CmdIde / CmdIde][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[cpuz / cpuz][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\cpuz.sys><N/A>
[eebdafdg / eebdafdg][Running/Boot Start]
<\SystemRoot\system32\drivers\eebdafdg.sys><中国互联网络信息中心(CNNIC)>
[EntDrv51 / EntDrv51][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\EntDrv51.sys><N/A>
[ExpScaner / ExpScaner][Stopped/Auto Start]
<\??\D:\应用程序\Rising\Rav\ExpScan.sys><N/A>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
<system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[GMSIPCI / GMSIPCI][Stopped/Manual Start]
<\??\I:\INSTALL\GMSIPCI.SYS><N/A>
[HookCont / HookCont][Stopped/Auto Start]
<\??\D:\应用程序\Rising\Rav\HOOKCONT.sys><N/A>
[HookReg / HookReg][Stopped/Auto Start]
<\??\D:\应用程序\Rising\Rav\HookReg.sys><N/A>
[HookSys / HookSys][Stopped/Auto Start]
<\??\D:\应用程序\Rising\Rav\HookSys.sys><N/A>
[kl1 / kl1][Running/Boot Start]
<\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[MegaIDE / MegaIDE][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\MegaIDE.sys><LSI Logic Corporation.>
[MEMSCAN / MEMSCAN][Stopped/Auto Start]
<\??\D:\应用程序\Rising\Rav\MEMSCAN.sys><N/A>
[NaiAvFilter1 / NaiAvFilter1][Stopped/Manual Start]
<system32\drivers\naiavf5x.sys><N/A>
[NaiAvTdi1 / NaiAvTdi1][Stopped/System Start]
<system32\drivers\mvstdi5x.sys><N/A>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\D:\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nvata / nvata][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\nvata.sys><NVIDIA Corporation>
[NVIDIA nForce Networking Controller Driver / NVENETFD][Running/Manual Start]
<system32\DRIVERS\NVENETFD.sys><NVIDIA Corporation>
[NVIDIA Network Bus Enumerator / nvnetbus][Running/Manual Start]
<system32\DRIVERS\nvnetbus.sys><NVIDIA Corporation>
[Psx Hid to Gamepad Port Enabler / PSXGamepadEnabler][Running/Manual Start]
<system32\drivers\psxpad.sys><Y.Kimura>
[Psx Port Enumerator / PsxPortEnumerator][Running/Manual Start]
<System32\Drivers\psxenum.sys><Y.Kimura>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RSPPSYS / RSPPSYS][Stopped/Auto Start]
<\??\D:\应用程序\Rising\Rav\RSPPSYS.sys><N/A>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[Sense3 / Sense3][Running/Auto Start]
<System32\Drivers\sense3.sys><Beijing Senselock>
[Superk53 / Superk53][Running/Auto Start]
<\SystemRoot\System32\drivers\superk53.sys><Microsoft Corporation>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[ViaIde / ViaIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[WINIO / WINIO][Stopped/Manual Start]
<\??\D:\变速精灵\winio.sys><N/A>
最后编辑2007-01-05 13:38:44
分享到:
gototop
 

==================================
浏览器加载项
[中国商务中心]
{0713E8D2-850A-101B-AFC0-4210102A8DA7} <http://www.ying-cn.com, N/A>
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <D:\应用程序\Thunder.exe, Thunder Networking Technologies,LTD>
[Web反病毒保护]
{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <D:\新建文件夹\scieplugin.dll, Kaspersky Lab>
[番茄花园]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.tomatolei.com, N/A>
[启动Web迅雷]
{962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[FlashGet]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <, N/A>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[WebThunder Browser Helper]
{00000AAA-A363-466E-BEF5-9BB68697AA7F} <, N/A>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, N/A>
[Microsoft ProgressBar Control, version 5.0 (SP2)]
{0713E8D2-850A-101B-AFC0-4210102A8DA7} <C:\WINDOWS\system32\comctl32.ocx, Microsoft Corporation>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[]
{83AEDED7-3418-3A09-AECD-134A43C12CD3} <C:\WINDOWS\system32\NetPolice.dll, 恶意网站克星>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <, N/A>
[IeCatch2 Class]
{A5366673-E8CA-11D3-9CD9-0090271D075B} <, N/A>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[BhoObj Class]
{F039B6BB-D320-1B79-23D9-91460150E6CA} <C:\WINDOWS\system32\fipdzidz.dll, Microsoft Corporation>
[&使用迅雷下载]
<D:\应用程序\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<D:\应用程序\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用Web迅雷下载]
<C:\Program Files\Thunder Network\WebThunder\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
<C:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
[用比特精灵下载(&B)]
<D:\应用程序\BitSpirit\bsurl.htm, N/A>

==================================
正在运行的进程
[PID: 648][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 736][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 760][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 6.0.0.299]
[PID: 804][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 816][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 968][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4117]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2497]
[PID: 980][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1044][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1184][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1260][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1336][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1548][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2527 (xpsp.040919-1030)]
[PID: 1680][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll] [Windows (R) 2000 DDK provider, 5.00.2195.1620]
[PID: 1968][C:\Program Files\Common Files\KooWo\KwMV.exe] [酷我科技, 0, 8, 3, 0]
[C:\Program Files\Common Files\KooWo\KwLogSvr.dll] [KooWo, 1.0.0.1]
[C:\Program Files\Common Files\KooWo\lidx.dll] [N/A, N/A]
[PID: 192][C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe] [Microsoft Corporation, 2000.080.0194.00]
[PID: 528][C:\WINDOWS\system32\U8SMSSrv.exe] [N/A, N/A]
[PID: 540][C:\WINDOWS\system32\ServerNT.EXE] [N/A, N/A]
[C:\WINDOWS\system32\UMiscell.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\sgv.dll] [, 8, 2, 0, 0]
[C:\WINDOWS\system\Sense3.dll] [N/A, N/A]
[C:\WINDOWS\system32\SecuComm.dll] [N/A, N/A]
[C:\WINDOWS\system32\UFCOMSQL\UFBackPlan.dll] [北京用友软件股份有限公司, 8.50.8810]
[PID: 676][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 2428][D:\Trojan Expert 2006\mmzj.exe] [Beyond 工作室, 2,0,0,6]
[D:\Trojan Expert 2006\krnln.fnr] [, 1, 0, 0, 1]
[D:\Trojan Expert 2006\iext.fnr] [, 1, 0, 0, 1]
[D:\Trojan Expert 2006\iext2.fne] [, 1, 0, 0, 1]
[D:\Trojan Expert 2006\TrayIcon.fne] [, 1, 0, 0, 1]
[D:\Trojan Expert 2006\EChartBar.fne] [, 1, 0, 0, 1]
[D:\Trojan Expert 2006\ExtMenu.fne] [, 1, 0, 0, 1]
[D:\Trojan Expert 2006\iext3.fne] [, 1, 0, 0, 1]
[D:\Trojan Expert 2006\dp1.fne] [N/A, N/A]
[D:\Trojan Expert 2006\shell.fne] [N/A, N/A]
[D:\Trojan Expert 2006\xplib.fne] [N/A, N/A]
[D:\Trojan Expert 2006\eAPI.fne] [, 1, 0, 0, 1]
[PID: 2484][D:\应用程序\BitSpirit\BitSpirit.exe] [LANSPIRIT.NET, 3.2.2.117]
[D:\应用程序\BitSpirit\BSOPLIB.DLL] [N/A, 1, 0, 0, 2]
[D:\应用程序\BitSpirit\plugin\tracker.dll] [N/A, N/A]
[PID: 2508][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3444][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3668][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[PID: 3880][D:\QQ\QQ.exe] [TENCENT, 0, 0, 0, 0]
[D:\QQ\CoralAssist.DLL] [Coral Team, 4.5.0 build 20060515]
[D:\QQ\CoralQQ.DLL] [Coral Team, 4.5.4 Build 20061001]
[D:\QQ\ipsearcher.dll] [N/A, 1.0.0.4]
[D:\QQ\QQBaseClassInDll.dll] [, 1, 0, 0, 1]
[D:\QQ\QQHelperDll.dll] [, 1, 0, 0, 1]
[D:\QQ\BasicCtrlDll.dll] [Tencent, 5, 0, 200, 370]
[D:\QQ\QQAPI.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[D:\QQ\LoginCtrl.dll] [, 1, 0, 0, 1]
[D:\QQ\npkcntc.dll] [INCA Internet Co., Ltd., 2006, 6, 27, 1]
[D:\QQ\npkpdb.dll] [INCA Internet Co., Ltd., 2003, 10, 1, 1]
[D:\QQ\QQRes.dll] [tencent, 1, 0, 0, 1]
[D:\QQ\QQMainFrame.dll] [N/A, N/A]
[D:\QQ\CQQApplication.dll] [N/A, N/A]
[D:\QQ\NewSkin.dll] [, 1, 0, 0, 1]
[D:\QQ\HostingMgr.dll] [, 1, 0, 0, 1]
[D:\QQ\CameraDll.dll] [, 1, 0, 0, 1]
[D:\QQ\MailSummary.dll] [, 1, 0, 0, 1]
[D:\QQ\QQSpace.dll] [, 1, 0, 0, 1]
[D:\QQ\QQAllInOne.dll] [N/A, N/A]
[D:\QQ\GroupLive.dll] [N/A, N/A]
[D:\QQ\SCCore.dll] [TENCENT, 2, 0, 0, 1]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[D:\QQ\QQGroupMng.dll] [, 1, 0, 0, 1]
[D:\QQ\QQSysMsgMng.dll] [N/A, N/A]
[D:\QQ\UserDefinedHead.dll] [, 1, 0, 0, 1]
[D:\QQ\QQPlugin.dll] [N/A, N/A]
[D:\QQ\QQCustomFace.dll] [N/A, N/A]
[D:\QQ\QQPet.dll] [, 1, 0, 0, 1]
[D:\QQ\LongConnection.dll] [tencent, 5, 0, 200, 160]
[D:\QQ\QQConfigPlugin.dll] [, 1, 0, 0, 1]
[D:\QQ\QRingMng.dll] [N/A, N/A]
[D:\QQ\PhoneAPI.dll] [, 1, 0, 0, 1]
[D:\QQ\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[D:\QQ\VPortal.dll] [, 1, 0, 0, 4]
[D:\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 240]
[D:\QQ\QQAvatar.dll] [N/A, N/A]
[D:\QQ\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[D:\QQ\BQQApplication.dll] [N/A, N/A]
[D:\QQ\GroupConnection.dll] [Tencent, 0, 3, 3, 5]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[D:\QQ\QQMagicFace.dll] [, 1, 0, 0, 1]
[D:\QQ\QQSceneMng.dll] [N/A, N/A]
[D:\QQ\CommercesMng.dll] [, 1, 0, 0, 1]
[D:\QQ\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
[D:\QQ\QQPhoneHelper.dll] [腾讯科技(深圳)有限公司, 2, 1, 2, 23]
[PID: 4064][D:\QQ\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[C:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 1764][D:\应用程序\Maxthon2\Maxthon\Maxthon.exe] [Maxthon International Ltd., 1, 5, 9, 30]
[D:\应用程序\Maxthon2\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
[D:\应用程序\Maxthon2\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[D:\新建文件夹\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299]
[D:\新建文件夹\klscav.dll] [Kaspersky Lab, 6.0.0.299]
[D:\新建文件夹\pr_remote.dll] [Kaspersky Lab, 6.0.0.299]
[D:\新建文件夹\prloader.dll] [Kaspersky Lab, 6.0.0.299]
[D:\新建文件夹\prkernel.ppl] [Kaspersky Lab, 6.0.0.299]
[d:\新建文件夹\params.ppl] [Kaspersky Lab, 6.0.0.299]
[d:\新建文件夹\pxstub.ppl] [Kaspersky Lab, 6.0.0.299]
[d:\新建文件夹\tempfile.ppl] [Kaspersky Lab, 6.0.0.299]
[d:\新建文件夹\nfio.ppl] [Kaspersky Lab, 6.0.0.299]
[d:\新建文件夹\fsdrvplgn.ppl] [Kaspersky Lab, 6.0.0.299]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[PID: 3580][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3676][D:\Plugins\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
gototop
 

==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1 localhost

==================================
API HOOK
警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
RVA 错误: LoadLibraryA
RVA 错误: LoadLibraryExA
RVA 错误: LoadLibraryExW
RVA 错误: LoadLibraryW

==================================


[/CODE]
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT