中了仇鹰后的SRENG2.4日志(进程部分缺少winlogon、lsass和services进程信息):
2007-03-12,14:43:34
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
==================================
正在运行的进程
[PID: 616][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 680][\??\C:\windows\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 184][C:\windows\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\windows\system32\UmxSbxExw.dll] [Computer Associates International, Inc., 6.0.1.58]
[C:\windows\system32\UmxSbxw.dll] [Computer Associates International, Inc., 6.0.1.58]
[C:\Program Files\Internet Download Manager\IDMIECC.dll] [Internet Download Manager Corp., Tonec Inc., 1, 0, 2, 1]
[C:\Program Files\Internet Download Manager\idmmkb.dll] [N/A, ]
[PID: 664][C:\windows\system32\atiptaxx.exe] [ATI Technologies, Inc., 6.13.10.2531]
[C:\windows\system32\UmxSbxExw.dll] [Computer Associates International, Inc., 6.0.1.58]
[C:\windows\system32\UmxSbxw.dll] [Computer Associates International, Inc., 6.0.1.58]
[C:\windows\system32\ATRPUIXX.ENU] [ATI Technologies, Inc., 6.13.10.2531]
[C:\windows\system32\atipdsxx.dll] [ATI Technologies, Inc., 6.13.10.2531]
[PID: 988][C:\windows\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\windows\system32\UmxSbxExw.dll] [Computer Associates International, Inc., 6.0.1.58]
[C:\windows\system32\UmxSbxw.dll] [Computer Associates International, Inc., 6.0.1.58]
[PID: 996][C:\Program Files\Tiny Firewall Pro\amon.exe] [Computer Associates International, Inc., 6.5.3.2]
[C:\windows\system32\UmxSbxExw.dll] [Computer Associates International, Inc., 6.0.1.58]
[C:\windows\system32\UmxSbxw.dll] [Computer Associates International, Inc., 6.0.1.58]
[C:\Program Files\Tiny Firewall Pro\amonres.dll] [Computer Associates International, Inc., 6.5.1.2]
[C:\Program Files\Tiny Firewall Pro\FncIDs.dll] [Computer Associates International, Inc., 6.0.0.1]
[C:\Program Files\Tiny Firewall Pro\portnums.dll] [Computer Associates International, Inc., 6.0.0.1]
[PID: 964][C:\Program Files\Tiny Firewall Pro\cfgtool.exe] [Computer Associates International, Inc., 6.0.0.52]
[C:\windows\system32\UmxSbxExw.dll] [Computer Associates International, Inc., 6.0.1.58]
[C:\windows\system32\UmxSbxw.dll] [Computer Associates International, Inc., 6.0.1.58]
[C:\Program Files\Tiny Firewall Pro\cfgtoolres.dll] [Computer Associates International, Inc., 6.0.0.28]
[C:\Program Files\Common Files\PFShared\Nag.dll] [Tiny Software, Inc., 6.0.1.22]
[C:\Program Files\Common Files\PFShared\cfgwi.dll] [Computer Associates International, Inc., 6.0.0.127]
[C:\Program Files\Common Files\PFShared\Cfgwires.dll] [Computer Associates International, Inc., 6.0.0.27]
[C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\PDM.DLL] [Microsoft Corporation, 7.00.9466]
[C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\2052\mdmui.dll] [Microsoft Corporation, 7.00.9466]
[C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MSDBG2.DLL] [Microsoft Corporation, 7.00.9466]
[C:\Program Files\Common Files\Microsoft Shared\INK\PENCHS.DLL] [Microsoft Corporation, 1.0.1038.0]
[C:\Program Files\Common Files\PFShared\IfaceCtrl.dll] [Computer Associates International, Inc., 6.5.3.3]
[C:\Program Files\Common Files\PFShared\SysObjExp.dll] [Computer Associates International, Inc., 6.0.0.7]
[PID: 1292][C:\Program Files\Tiny Firewall Pro\tralogan.exe] [Computer Associates International, Inc., 6.0.0.17]
[C:\windows\system32\UmxSbxExw.dll] [Computer Associates International, Inc., 6.0.1.58]
[C:\windows\system32\UmxSbxw.dll] [Computer Associates International, Inc., 6.0.1.58]
[C:\windows\system32\msxml4.dll] [Microsoft Corporation, 4.20.9818.0]
[PID: 1256][C:\Program Files\Opera\Opera.exe] [Opera Software, 8679]
[C:\windows\system32\UmxSbxExw.dll] [Computer Associates International, Inc., 6.0.1.58]
[C:\windows\system32\UmxSbxw.dll] [Computer Associates International, Inc., 6.0.1.58]
[C:\Program Files\Opera\Opera.dll] [Opera Software, 8679]
[PID: 3440][C:\Program Files\SRENG\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\windows\system32\UmxSbxExw.dll] [Computer Associates International, Inc., 6.0.1.58]
[C:\windows\system32\UmxSbxw.dll] [Computer Associates International, Inc., 6.0.1.58]
==================================
相比之下,SRENG 2.3似乎更强些。中毒环境下仍可以扫到插入winlogon和services进程的病毒dll(图)。