1   1  /  1  页   跳转

system327b696e32.EXEA.exe是什么进程?

system327b696e32.EXEA.exe是什么进程?

system327b696e32.EXEA.exe,杀掉了还启动而且在启动时电脑日期显示为1987年,大家帮帮忙/
最后编辑2007-01-17 16:09:52
分享到:
gototop
 

2007-01-17,11:07:35

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件


启动项目


注册表

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
(ctfmon.exe)(C:\WINDOWS\system32\ctfmon.exe) [(Verified)Microsoft Corporation]
(MSNShell)(D:\新建文件夹\MSNShell\BIN\MSNShell.exe autorun) [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
(KernelFaultCheck)(%systemroot%\system32\dumprep 0 -k) [N/A]
(kav)("C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe") [Kaspersky Lab]
(mmsk)(; C:\Program Files\木马杀客\mmsk.exe) [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(shell)(Explorer.exe) [(Verified)Microsoft Corporation]
(Userinit)(C:\WINDOWS\system32\userinit.exe,) [(Verified)Microsoft Corporation]
(UIHost)(logonui.exe) [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
(SysChunk)(C:\WINDOWS\system32\syschunk.dll) []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
(WinlogonNotify: klogon)(C:\WINDOWS\system32\klogon.dll) [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winftsap]
(WinlogonNotify: winftsap)(C:\WINDOWS\system32\winftsap.dll) [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
({B63BFF8C-2E25-4CCC-9A01-68807F567AA7})(C:\WINDOWS\system32\BandRes.dll) [N/A]




--------------------------------------------------------------------------------



启动文件夹

[Panasonic 多功能机 状态监视器]
(C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Panasonic 多功能机 状态监视器.lnk --) C:\PROGRA~1\PANASO~1\多功能机\STATUS~1.EXE [PCC])(N)



--------------------------------------------------------------------------------



服务

[Applications Log / Applog][Running/Auto Start]
(C:\WINDOWS\System32\svchost.exe -k netsvcs--)%SystemRoot%\system32\applog\netuser32.dll)(N/A)
[卡巴斯基反病毒6.0 / AVP][Running/Auto Start]
("C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r)(Kaspersky Lab)
[B9665600 / B9665600][Stopped/Auto Start]
(C:\WINDOWS\system32\B9665600.EXE -service)(N/A)
[C9756B80 / C9756B80][Stopped/Auto Start]
(C:\WINDOWS\system32\C9756B80.EXE -service)(Microsoft Corporation)
[ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard][Stopped/Disabled]
(C:\Program Files\ewido anti-spyware 4.0\guard.exe)(Anti-Malware Development a.s.)
[fan.eeewl.com / fan.eeewl.com][Stopped/Disabled]
(C:\WINDOWS\system32\nsvce32.exe)(N/A)
[Human Interface Device Access / HidServ][Stopped/Disabled]
(C:\WINDOWS\System32\svchost.exe -k netsvcs--)%SystemRoot%\System32\hidserv.dll)(N/A)
[Imsvc / Imsvc][Stopped/Disabled]
(C:\WINDOWS\System32\svchost.exe -k netsvcs--)C:\WINDOWS\system32\Webmail.dll)()
[Intel Alert Handler / Intel Alert Handler][Stopped/Disabled]
(C:\WINDOWS\system32\ams_ii\hndlrsvc.exe)(Intel? Corporation)
[Intel Alert Originator / Intel Alert Originator][Stopped/Disabled]
(C:\WINDOWS\system32\ams_ii\iao.exe)(Intel? Corporation)
[Intel File Transfer / Intel File Transfer][Stopped/Disabled]
(C:\WINDOWS\system32\cba\xfr.exe)(Intel? Corporation)
[Intel PDS / Intel PDS][Stopped/Disabled]
(C:\WINDOWS\system32\cba\pds.exe)(Intel? Corporation)
[Multi-Function Station Device Monitor / KMDevmonSrv][Stopped/Disabled]
(C:\WINDOWS\system32\KMDEVMONSRV.exe)(N/A)
[RestoreServices / RestoreServices][Running/Auto Start]
(C:\WINDOWS\system32\Svchost.exe -k RestoreServices--)C:\WINDOWS\system32\drivers\restore.dll)(Microsoft Corporation All rights reserved)
[SQLServer Supports / sqlservech][Running/Auto Start]
(C:\WINDOWS\System32\svchost.exe -k sqlservech--)c:\windows\system32\sqlservech.dll)(Microsoft Corporation)
[Provisioning Transaction Service / ttt_14][Stopped/Disabled]
(C:\WINDOWS\system32\win.exe)(N/A)

gototop
 

驱动程序

[00007af4 / 00007af4][Stopped/Disabled]
(system32\drivers\00007af4.SYS)(N/A)
[adpu64 / adpu64][Running/Auto Start]
(\??\C:\WINDOWS\system32\drivers\adpu64.sys)(N/A)
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
(system32\drivers\ALCXWDM.SYS)(Realtek Semiconductor Corp.)
[bg / bg][Stopped/Manual Start]
(\??\C:\WINDOWS\system32\drivers\bg.sys)(N/A)
[bgja / bgjar][Running/Boot Start]
(\SystemRoot\System32\DRIVERS\bgjar.sys)(N/A)
[Panasonic MFSUSB Driver / DGIUSB][Running/Manual Start]
(system32\drivers\KMdgiusb.sys)(Conexant Systems, Inc.)
[edagecah / edagecah][Stopped/Boot Start]
(\SystemRoot\system32\drivers\edagecah.sys)(N/A)
[ewido anti-spyware 4.0 driver / ewido anti-spyware 4.0 driver][Running/System Start]
(\??\C:\Program Files\ewido anti-spyware 4.0\guard.sys)(N/A)
[fejfbiff / fejfbiff][Stopped/Boot Start]
(\SystemRoot\system32\drivers\fejfbiff.sys)(N/A)
[ialm / ialm][Running/Manual Start]
(system32\DRIVERS\ialmnt5.sys)(Intel Corporation)
[kl1 / kl1][Running/Boot Start]
(\SystemRoot\system32\drivers\kl1.sys)(Kaspersky Lab)
[klif / klif][Running/System Start]
(\??\C:\WINDOWS\system32\drivers\klif.sys)(Kaspersky Lab)
[kmsinput / kmsinput][Stopped/Manual Start]
(\??\C:\WINDOWS\system32\drivers\kmsinput.sys)(N/A)
[KMsmfpi / KMsmfpi][Running/Auto Start]
(\??\C:\WINDOWS\System32\Drivers\KMSMFPI.sys)(Conexant Systems, Inc.)
[NAVAP / NAVAP][Stopped/Manual Start]
(\??\C:\PROGRA~1\SAV\NAVAP.sys)(N/A)
[NAVAPEL / NAVAPEL][Stopped/Auto Start]
(\??\C:\PROGRA~1\SAV\NAVAPEL.SYS)(N/A)
[NAVENG / NAVENG][Stopped/Manual Start]
(\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070112.052\NAVENG.sys)(N/A)
[NAVEX15 / NAVEX15][Stopped/Manual Start]
(\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070112.052\NAVEX15.sys)(N/A)
[npkcrypt / npkcrypt][Running/Auto Start]
(\??\D:\qq\npkcrypt.sys)(INCA Internet Co., Ltd.)
[npkycryp / npkycryp][Stopped/Manual Start]
(\??\D:\qq\npkycryp.sys)(N/A)
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
(system32\DRIVERS\ptilink.sys)(Parallel Technologies, Inc.)
[quswfk0 / quswfk06][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\quswfk06.sys)(N/A)
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
(\SystemRoot\system32\drivers\RsBoot.sys)(Beijing Rising)
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
(system32\DRIVERS\RTL8139.SYS)(Realtek Semiconductor Corporation)
[rxiefat / rxiefat][Running/Boot Start]
(\SystemRoot\system32\drivers\rxiefat.sys)()
[Secdrv / Secdrv][Stopped/Manual Start]
(system32\DRIVERS\secdrv.sys)(N/A)
[SVKP / SVKP][Running/Auto Start]
(\??\C:\WINDOWS\system32\SVKP.sys)(AntiCracking)
[ufjfiz1 / ufjfiz18][Stopped/Boot Start]
(\SystemRoot\System32\DRIVERS\ufjfiz18.sys)(N/A)
[VECP / VECP][Running/Auto Start]
(\??\C:\WINDOWS\System32\Drivers\VECP.sys)(Conexant Systems, Inc.)
[wspipe / wspipe][Stopped/Auto Start]
(\??\C:\WINDOWS\system32\drivers\wspipe.sys)(N/A)



--------------------------------------------------------------------------------



浏览器加载项

[MSN Shell 4]
{0713E8D2-850A-101B-AFC0-4210102A8DA7} (D:\新建文件夹\MSNShell\Bin\MSNShell.exe, N/A)
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} (C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation)
[FlashGet]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} (C:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft)
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} (C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation)
[Checkers Class]
{00B71CFB-6864-4346-A978-C0A14556272C} (C:\WINDOWS\Downloaded Program Files\msgrchkr.dll, Microsoft Corporation)
[Edit Class]
{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (C:\WINDOWS\system32\CMBEdit.dll, )
[MSN Photo Upload Tool]
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} (C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation)
[PowerPlayer Control]
{5EC7C511-CD0F-42E6-830C-1BD9882F3458} (C:\WINDOWS\system32\stsys\POWERP~1.DLL, PPStream Inc.)
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} (C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation)
[AxInputControl Class]
{73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL, )
[MessengerStatsClient Class]
{8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll, Microsoft Corporation)
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.)
[Edit Class]
{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (C:\WINDOWS\system32\CMBEdit.dll, )
[EWA Control]
{18226BF8-DC0B-4D81-80E9-A41AE37BB73A} (C:\PROGRA~1\COMMON~1\Synacast\SynaLive\SYNACA~1.OCX, Synacast)
[PowerList Control]
{20C2C286-BDE8-441B-B73D-AFA22D914DA5} (C:\WINDOWS\DOWNLO~1\POWERL~1.OCX, PPStream.com)
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} (C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation)
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} (%SystemRoot%\system32\Mshtml.dll, N/A)
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} (C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation)
[Tabular Data Control]
{333C7BC4-460F-11D0-BC04-0080C7055A83} (C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation)
[IETag Factory]
{38481807-CA0E-42D2-BF39-B33AF135CC4D} (C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\IETAG.DLL, Microsoft Corporation)
[XBTP01627 Class]
{4C666711-582C-485C-93BA-33F4DFC19981} (C:\PROGRA~1\soso\soso.dll, N/A)
[CMCBooter Object]
{53AF6E02-F18F-4228-AC13-3E79773FBE50} (C:\WINDOWS\system32\Booter.ocx, 北京高维视讯科技有限公司)
[PowerPlayer Control]
{5EC7C511-CD0F-42E6-830C-1BD9882F3458} (C:\WINDOWS\system32\stsys\POWERP~1.DLL, PPStream Inc.)
[Microsoft 外壳 UI 帮助程序]
{64AB4BB7-111E-11D1-8F79-00C04FC2FBE1} (%SystemRoot%\system32\shdocvw.dll, N/A)
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[List Control]
{70CACCCA-8B83-4BCB-B2D1-188E9A495527} (C:\PROGRA~1\COMMON~1\Synacast\SynaLive\SYNACA~2.OCX, )
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} (%SystemRoot%\system32\SHELL32.dll, N/A)
[AxInputControl Class]
{73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL, )
[CMCLoader Object]
{779769CA-82F1-4973-BBA7-515E6C7BFD0E} (C:\Program Files\GAOV\Mysee2\myclive.dll, N/A)
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} (C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation)
[AxSubmitControl Class]
{8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (C:\WINDOWS\DOWNLO~1\SUBMIT~1.DLL, )
[IeCatch2 Class]
{A5366673-E8CA-11D3-9CD9-0090271D075B} (C:\PROGRA~1\FLASHGET\jccatch.dll, N/A)
[PhotoUploadCtrl Control]
{A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} (, N/A)
[Qzone Media Tools]
{AC3A36A8-9BFF-410A-A33D-2279FFEB69D2} (D:\qq\VQQPLA~1.OCX, Tencent Technology (Shenzhen) Company Limited)
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} (C:\WINDOWS\system32\Mshtml.dll, Microsoft Corporation)
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} (%SystemRoot%\system32\shdocvw.dll, N/A)
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} (C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation)
[AUDIO__MID Moniker Class]
{CD3AFA74-B84F-48F0-9393-7EDC34128127} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[AUDIO__MP3 Moniker Class]
{CD3AFA76-B84F-48F0-9393-7EDC34128127} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[AUDIO__WAV Moniker Class]
{CD3AFA7B-B84F-48F0-9393-7EDC34128127} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[AUDIO__X_MS_WMA Moniker Class]
{CD3AFA84-B84F-48F0-9393-7EDC34128127} (C:\WINDOWS\system32\wmp.dll, Microsoft Corporation)
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.)
[CPasswordEditCtrl Object]
{E787FD25-8D7C-4693-AE67-9406BC6E22DF} (C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司)
[VqqSpeedDlProxy Class]
{F138084D-84D7-48CD-BEA8-04772457516E} (d:\qq\vqqsdl.dll, Tencent Technology (Shenzhen) Company Limited)
[soso]
{F5993947-3A35-4C47-8901-E7FD39C5D386} (C:\Program Files\soso\soso.dll, N/A)
[使用网际快车下载]
(C:\Program Files\FlashGet\jc_link.htm, N/A)
[使用网际快车下载全部链接]
(C:\Program Files\FlashGet\jc_all.htm, N/A)
[导出到 Microsoft Office Excel(&X)]
(res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A)
gototop
 

正在运行的进程

[PID: 488][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 556][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 580][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 6.0.0.299]
[PID: 624][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 636][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 780][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 828][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 868][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 912][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1012][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1120][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\KMPMONNT.DLL] [Conexant Systems, Inc., 0.0.0.1]
[C:\WINDOWS\system32\KMdgimon.dll] [Conexant Systems, Inc., 1.0.0.1]
[C:\WINDOWS\system32\KMPCFXLMON.DLL] [Windows (R) 2000 DDK provider, 5.1.2462.0 built by: WinDDK]
[PID: 1216][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\windows\system32\applog\netuser32.dll] [N/A, N/A]
[PID: 1496][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ydypo.dll] [N/A, N/A]
[C:\WINDOWS\system32\syschunk.dll] [, 5, 1, 100, 2500]
[C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3.0.0.3865]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.3865]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.3865]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.3865]
[C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3.0.0.3865]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[PID: 1624][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1636][C:\Program Files\Panasonic\多功能机\StatusMon.exe] [PCC, 1, 0, 0, 1]
[C:\WINDOWS\system32\KMdgimon.dll] [Conexant Systems, Inc., 1.0.0.1]
[PID: 1672][C:\WINDOWS\system32\KMdevmonx.exe] [Conexant Systems, Inc., 1.0.0.1]
[C:\WINDOWS\system32\KMdgimon.dll] [Conexant Systems, Inc., 1.0.0.1]
[PID: 1952][C:\WINDOWS\system32\Svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\windows\system32\drivers\restore.dll] [Microsoft Corporation All rights reserved, 1, 0, 0, 1]
[PID: 2032][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 196][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
[PID: 952][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2244][C:\Program Files\Panasonic\多功能机\kmeLauncher.exe] [Panasonic Communications Co., Ltd., 3, 0, 0, 1]
[PID: 2260][C:\Program Files\Panasonic\多功能机\kmpcfax.exe] [Panasonic Communications Co.,Ltd., 1, 0, 0, 1]
[C:\WINDOWS\system32\KMdgimon.dll] [Conexant Systems, Inc., 1.0.0.1]
[C:\Program Files\Panasonic\多功能机\PFRCHS.dll] [Panasonic Communications Co., Ltd., 0, 2, 4, 0]
[PID: 2804][C:\Documents and Settings\zhangjie\桌面\sreng2\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
gototop
 

文件关联

.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]



--------------------------------------------------------------------------------



Winsock 提供者

N/A



--------------------------------------------------------------------------------



Autorun.inf

[D:\]
[autorun]



--------------------------------------------------------------------------------



HOSTS 文件

127.0.0.1 localhost



--------------------------------------------------------------------------------



API HOOK

警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
RVA 错误: LoadLibraryA
RVA 错误: LoadLibraryExA
RVA 错误: LoadLibraryExW
RVA 错误: LoadLibraryW



--------------------------------------------------------------------------------
gototop
 

上面是日志希望尽快帮忙解决问题
gototop
 

无法禁用服务,会自动启动
gototop
 

在安全模式下吗?我的电脑没有办法进入安全模式,一进就重启。
gototop
 

搞定了多谢
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT