查看: 4751|回复: 11
收起左侧

[已解决] SREng扫描API HOOK 入口点错误

 关闭 [复制链接]
lvcan
发表于 2012-2-26 03:33:00 | 显示全部楼层 |阅读模式
本帖最后由 fivezy361 于 2012-3-2 06:58 编辑

U盘安装 Windows 7 With SP1 64位简体中文旗舰版
文件名 cn_windows_7_ultimate_with_sp1_x64_dvd_u_677408.iso
发布日期 (UTC): 5/12/2011 2:46:19 PM 上次更新日期 (UTC): 5/12/2011 2:46:19 PM
SHA1: 2CE0B2DB34D76ED3F697CE148CB7594432405E23 ISO/CRC: 69F54CA4

SREng扫描API HOOK  入口点错误:FindFirstFileA (危险等级: 高,  被下面模块所HOOK: 0xB999DDE6)


windows 7旗舰版64 安装之初的SRENG日志:


  1. 2012-02-25,07:48:14

  2. System Repair Engineer 2.8.4.1331
  3. Smallfrogs (http://www.KZTechs.com)

  4. Windows 7 Ultimate Edition Service Pack 1 (Build 7601) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描
  14.     计划任务
  15.     Windows 安全更新检查
  16.     API HOOK
  17.     隐藏进程


  18. 启动项目
  19. 注册表
  20. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  21.     <shell><explorer.exe>  [(Verified)Microsoft Windows]
  22.     <Userinit><userinit.exe>  [(Verified)Microsoft Windows]
  23. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  24.     <AppInit_DLLs><>  [N/A]
  25. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  26.     <WebCheck><>  [N/A]
  27. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
  28.     <Microsoft Windows Media Player><%SystemRoot%\system32\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows]
  29. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  30.     <Internet Explorer><C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig>  [(Verified)Microsoft Windows]
  31. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
  32.     <Browser Customizations><"C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP>  [(Verified)Microsoft Windows]
  33. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  34.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
  35. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  36.     <Microsoft Windows><"%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE>  [File is missing]
  37. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  38.     <Microsoft Windows Media Player><%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI>  [(Verified)Microsoft Windows]
  39. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
  40.     <Windows Desktop Update><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows]
  41. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
  42.     <Web Platform Customizations><C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings>  [(Verified)Microsoft Windows]
  43. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
  44.     <N/A><C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install>  [(Verified)Microsoft Corporation]

  45. ==================================
  46. 启动文件夹
  47. N/A

  48. ==================================
  49. 服务
  50. [Application Experience / AeLookupSvc][Running/Manual Start]
  51.   <C:\Windows\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\aelupsvc.dll><Microsoft Corporation>
  52. [Windows Defender / WinDefend][Running/Auto Start]
  53.   <C:\Windows\System32\svchost.exe -k secsvcs-->%ProgramFiles%\Windows Defender\mpsvc.dll><N/A>
  54. [Windows Management Instrumentation / Winmgmt][Running/Auto Start]
  55.   <C:\Windows\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\wbem\WMIsvc.dll><Microsoft Corporation>
  56. [WLAN AutoConfig / Wlansvc][Stopped/Manual Start]
  57.   <C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted-->%SystemRoot%\System32\wlansvc.dll><Microsoft Corporation>

  58. ==================================
  59. 驱动程序
  60. [adp94xx / adp94xx][Stopped/Manual Start]
  61.   <\SystemRoot\system32\drivers\adp94xx.sys><Adaptec, Inc.>
  62. [adpahci / adpahci][Stopped/Manual Start]
  63.   <\SystemRoot\system32\drivers\adpahci.sys><Adaptec, Inc.>
  64. [adpu320 / adpu320][Stopped/Manual Start]
  65.   <\SystemRoot\system32\drivers\adpu320.sys><Adaptec, Inc.>
  66. [aliide / aliide][Stopped/Manual Start]
  67.   <\SystemRoot\system32\drivers\aliide.sys><Acer Laboratories Inc.>
  68. [amdsata / amdsata][Stopped/Manual Start]
  69.   <\SystemRoot\system32\drivers\amdsata.sys><Advanced Micro Devices>
  70. [amdsbs / amdsbs][Stopped/Manual Start]
  71.   <\SystemRoot\system32\drivers\amdsbs.sys><AMD Technologies Inc.>
  72. [amdxata / amdxata][Running/Boot Start]
  73.   <\SystemRoot\system32\drivers\amdxata.sys><Advanced Micro Devices>
  74. [arc / arc][Stopped/Manual Start]
  75.   <\SystemRoot\system32\drivers\arc.sys><Adaptec, Inc.>
  76. [arcsas / arcsas][Stopped/Manual Start]
  77.   <\SystemRoot\system32\drivers\arcsas.sys><Adaptec, Inc.>
  78. [Broadcom NetXtreme II VBD / b06bdrv][Stopped/Manual Start]
  79.   <\SystemRoot\system32\drivers\bxvbda.sys><Broadcom Corporation>
  80. [Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 / b57nd60a][Stopped/Manual Start]
  81.   <system32\DRIVERS\b57nd60a.sys><Broadcom Corporation>
  82. [Brother USB Mass-Storage Lower Filter Driver / BrFiltLo][Stopped/Manual Start]
  83.   <\SystemRoot\system32\drivers\BrFiltLo.sys><Brother Industries, Ltd.>
  84. [Brother USB Mass-Storage Upper Filter Driver / BrFiltUp][Stopped/Manual Start]
  85.   <\SystemRoot\system32\drivers\BrFiltUp.sys><Brother Industries, Ltd.>
  86. [Brother MFC Serial Port Interface Driver (WDM) / Brserid][Stopped/Manual Start]
  87.   <\SystemRoot\System32\Drivers\Brserid.sys><Brother Industries Ltd.>
  88. [Brother WDM Serial driver / BrSerWdm][Stopped/Manual Start]
  89.   <\SystemRoot\System32\Drivers\BrSerWdm.sys><Brother Industries Ltd.>
  90. [Brother MFC USB Fax Only Modem / BrUsbMdm][Stopped/Manual Start]
  91.   <\SystemRoot\System32\Drivers\BrUsbMdm.sys><Brother Industries Ltd.>
  92. [Brother MFC USB Serial WDM Driver / BrUsbSer][Stopped/Manual Start]
  93.   <\SystemRoot\System32\Drivers\BrUsbSer.sys><Brother Industries Ltd.>
  94. [cmdide / cmdide][Stopped/Manual Start]
  95.   <\SystemRoot\system32\drivers\cmdide.sys><CMD Technology, Inc.>
  96. [Broadcom NetXtreme II 10 GigE VBD / ebdrv][Stopped/Manual Start]
  97.   <\SystemRoot\system32\drivers\evbda.sys><Broadcom Corporation>
  98. [elxstor / elxstor][Stopped/Manual Start]
  99.   <\SystemRoot\system32\drivers\elxstor.sys><Emulex>
  100. [Hauppauge Consumer Infrared Receiver / hcw85cir][Stopped/Manual Start]
  101.   <\SystemRoot\system32\drivers\hcw85cir.sys><Hauppauge Computer Works, Inc.>
  102. [HpSAMD / HpSAMD][Stopped/Manual Start]
  103.   <\SystemRoot\system32\drivers\HpSAMD.sys><Hewlett-Packard Company>
  104. [iaStorV / iaStorV][Stopped/Manual Start]
  105.   <\SystemRoot\system32\drivers\iaStorV.sys><Intel Corporation>
  106. [iirsp / iirsp][Stopped/Manual Start]
  107.   <\SystemRoot\system32\drivers\iirsp.sys><Intel Corp./ICP vortex GmbH>
  108. [LSI_FC / LSI_FC][Stopped/Manual Start]
  109.   <\SystemRoot\system32\drivers\lsi_fc.sys><LSI Corporation>
  110. [LSI_SAS / LSI_SAS][Stopped/Manual Start]
  111.   <\SystemRoot\system32\drivers\lsi_sas.sys><LSI Corporation>
  112. [LSI_SAS2 / LSI_SAS2][Stopped/Manual Start]
  113.   <\SystemRoot\system32\drivers\lsi_sas2.sys><LSI Corporation>
  114. [LSI_SCSI / LSI_SCSI][Stopped/Manual Start]
  115.   <\SystemRoot\system32\drivers\lsi_scsi.sys><LSI Corporation>
  116. [megasas / megasas][Stopped/Manual Start]
  117.   <\SystemRoot\system32\drivers\megasas.sys><LSI Corporation>
  118. [MegaSR / MegaSR][Stopped/Manual Start]
  119.   <\SystemRoot\system32\drivers\MegaSR.sys><LSI Corporation, Inc.>
  120. [nfrd960 / nfrd960][Stopped/Manual Start]
  121.   <\SystemRoot\system32\drivers\nfrd960.sys><IBM Corporation>
  122. [nvraid / nvraid][Stopped/Manual Start]
  123.   <\SystemRoot\system32\drivers\nvraid.sys><NVIDIA Corporation>
  124. [nvstor / nvstor][Stopped/Manual Start]
  125.   <\SystemRoot\system32\drivers\nvstor.sys><NVIDIA Corporation>
  126. [ql2300 / ql2300][Stopped/Manual Start]
  127.   <\SystemRoot\system32\drivers\ql2300.sys><QLogic Corporation>
  128. [ql40xx / ql40xx][Stopped/Manual Start]
  129.   <\SystemRoot\system32\drivers\ql40xx.sys><QLogic Corporation>
  130. [Serial port driver / Serial][Running/System Start]
  131.   <system32\DRIVERS\serial.sys><Brother Industries Ltd.>
  132. [SiSRaid2 / SiSRaid2][Stopped/Manual Start]
  133.   <\SystemRoot\system32\drivers\SiSRaid2.sys><Silicon Integrated Systems Corp.>
  134. [SiSRaid4 / SiSRaid4][Stopped/Manual Start]
  135.   <\SystemRoot\system32\drivers\sisraid4.sys><Silicon Integrated Systems>
  136. [stexstor / stexstor][Stopped/Manual Start]
  137.   <\SystemRoot\system32\drivers\stexstor.sys><Promise Technology>
  138. [VGPU / VGPU][Stopped/Manual Start]
  139.   <System32\drivers\rdvgkmd.sys><N/A>
  140. [viaide / viaide][Stopped/Manual Start]
  141.   <\SystemRoot\system32\drivers\viaide.sys><VIA Technologies, Inc.>
  142. [vsmraid / vsmraid][Stopped/Manual Start]
  143.   <\SystemRoot\system32\drivers\vsmraid.sys><VIA Technologies Inc.,Ltd>

  144. ==================================
  145. 浏览器加载项
  146. N/A

  147. ==================================
  148. 正在运行的进程
  149. [PID: 2344 / SYSTEM][C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe]  [(Verified) Microsoft Corporation, 2.0.50727.4927 (NetFXspW7.050727-4900)]
  150. [PID: 2060 / LUCK][D:\TDDOWNLOAD\sreng2\SREngLdr.EXE]  [Smallfrogs Studio, 2.8.4.1331]
  151. [PID: 2056 / LUCK][D:\TDDOWNLOAD\sreng2\SREb5d7fb6a.EXE]  [Smallfrogs Studio, 2.8.4.1331]

  152. ==================================
  153. 文件关联
  154. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  155. .EXE  OK. ["%1" %*]
  156. .COM  OK. ["%1" %*]
  157. .PIF  OK. ["%1" %*]
  158. .REG  OK. [regedit.exe "%1"]
  159. .BAT  OK. ["%1" %*]
  160. .SCR  OK. ["%1" /S]
  161. .CHM  OK. ["%SystemRoot%\hh.exe" %1]
  162. .HLP  OK. [%SystemRoot%\winhlp32.exe %1]
  163. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  164. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  165. .VBS  OK. ["%SystemRoot%\System32\WScript.exe" "%1" %*]
  166. .JS   Error. [C:\Windows\System32\WScript.exe "%1" %*]
  167. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  168. ==================================
  169. Winsock 提供者
  170. N/A

  171. ==================================
  172. Autorun.inf
  173. N/A

  174. ==================================
  175. HOSTS 文件
  176. N/A

  177. ==================================
  178. 进程特权扫描
  179. N/A

  180. ==================================
  181. 计划任务
  182. [已禁用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
  183.         N/A
  184. [已启用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
  185.         N/A
  186. [已禁用] \Microsoft\Windows\AppID\PolicyConverter
  187.         %windir%\system32\appidpolicyconverter.exe
  188. [已禁用] \Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
  189.         %windir%\system32\appidcertstorecheck.exe
  190. [已启用] \Microsoft\Windows\Application Experience\AitAgent
  191.         aitagent
  192. [已启用] \Microsoft\Windows\Application Experience\ProgramDataUpdater
  193.         %windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate
  194. [已启用] \Microsoft\Windows\Autochk\Proxy
  195.         %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
  196. [已启用] \Microsoft\Windows\Bluetooth\UninstallDeviceTask
  197.         BthUdTask.exe $(Arg0)
  198. [已启用] \Microsoft\Windows\CertificateServicesClient\SystemTask
  199.         N/A
  200. [已启用] \Microsoft\Windows\CertificateServicesClient\UserTask
  201.         N/A
  202. [已禁用] \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
  203.         N/A
  204. [已启用] \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
  205.         %SystemRoot%\System32\wsqmcons.exe
  206. [已启用] \Microsoft\Windows\Defrag\ScheduledDefrag
  207.         %windir%\system32\defrag.exe -c
  208. [已启用] \Microsoft\Windows\Location\Notifications
  209.         %windir%\System32\LocationNotifications.exe
  210. [已启用] \Microsoft\Windows\Maintenance\WinSAT
  211.         N/A
  212. [已启用] \Microsoft\Windows\Media Center\ActivateWindowsSearch
  213.         %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
  214. [已启用] \Microsoft\Windows\Media Center\ConfigureInternetTimeService
  215.         %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
  216. [已启用] \Microsoft\Windows\Media Center\DispatchRecoveryTasks
  217.         %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
  218. [已启用] \Microsoft\Windows\Media Center\ehDRMInit
  219.         %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
  220. [已启用] \Microsoft\Windows\Media Center\InstallPlayReady
  221.         %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
  222. [已启用] \Microsoft\Windows\Media Center\mcupdate
  223.         %SystemRoot%\ehome\mcupdate $(Arg0)
  224. [已启用] \Microsoft\Windows\Media Center\MediaCenterRecoveryTask
  225.         %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
  226. [已启用] \Microsoft\Windows\Media Center\MediaCenterRecoveryTask
  227.         %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
  228. [已启用] \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
  229.         %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
  230. [已启用] \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
  231.         %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
  232. [已启用] \Microsoft\Windows\Media Center\OCURActivate
  233.         %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
  234. [已启用] \Microsoft\Windows\Media Center\OCURDiscovery
  235.         %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
  236. [已启用] \Microsoft\Windows\Media Center\PBDADiscovery
  237.         %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
  238. [已启用] \Microsoft\Windows\Media Center\PBDADiscoveryW1
  239.         %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
  240. [已启用] \Microsoft\Windows\Media Center\PBDADiscoveryW2
  241.         %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
  242. [已禁用] \Microsoft\Windows\Media Center\PeriodicScanRetry
  243.         %windir%\ehome\MCUpdate.exe -pscn 0
  244. [已启用] \Microsoft\Windows\Media Center\PvrRecoveryTask
  245.         %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
  246. [已启用] \Microsoft\Windows\Media Center\PvrRecoveryTask
  247.         %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
  248. [已启用] \Microsoft\Windows\Media Center\PvrScheduleTask
  249.         %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
  250. [已启用] \Microsoft\Windows\Media Center\PvrScheduleTask
  251.         %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
  252. [已禁用] \Microsoft\Windows\Media Center\RecordingRestart
  253.         %SystemRoot%\ehome\ehrec /RestartRecording
  254. [已启用] \Microsoft\Windows\Media Center\RegisterSearch
  255.         %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
  256. [已启用] \Microsoft\Windows\Media Center\ReindexSearchRoot
  257.         %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
  258. [已启用] \Microsoft\Windows\Media Center\SqlLiteRecoveryTask
  259.         %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
  260. [已启用] \Microsoft\Windows\Media Center\SqlLiteRecoveryTask
  261.         %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
  262. [已启用] \Microsoft\Windows\Media Center\UpdateRecordPath
  263.         %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
  264. [已启用] \Microsoft\Windows\MobilePC\HotStart
  265.         N/A
  266. [已启用] \Microsoft\Windows\MUI\LPRemove
  267.         %windir%\system32\lpremove.exe
  268. [已启用] \Microsoft\Windows\Multimedia\SystemSoundsService
  269.         N/A
  270. [已启用] \Microsoft\Windows\NetTrace\GatherNetworkInfo
  271.         %windir%\system32\gatherNetworkInfo.vbs
  272. [已禁用] \Microsoft\Windows\Offline Files\Background Synchronization
  273.         N/A
  274. [已禁用] \Microsoft\Windows\Offline Files\Logon Synchronization
  275.         N/A
  276. [已启用] \Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
  277.         %SystemRoot%\System32\powercfg.exe -energy -auto
  278. [已启用] \Microsoft\Windows\Ras\MobilityManager
  279.         N/A
  280. [已禁用] \Microsoft\Windows\SideShow\AutoWake
  281.         N/A
  282. [已启用] \Microsoft\Windows\SideShow\GadgetManager
  283.         N/A
  284. [已禁用] \Microsoft\Windows\SideShow\SessionAgent
  285.         N/A
  286. [已禁用] \Microsoft\Windows\SideShow\SystemDataProviders
  287.         N/A
  288. [已启用] \Microsoft\Windows\SystemRestore\SR
  289.         %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
  290. [已启用] \Microsoft\Windows\Tcpip\IpAddressConflict1
  291.         %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
  292. [已启用] \Microsoft\Windows\Tcpip\IpAddressConflict2
  293.         %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
  294. [已启用] \Microsoft\Windows\Time Synchronization\SynchronizeTime
  295.         %windir%\system32\sc.exe start w32time task_started
  296. [已启用] \Microsoft\Windows\UPnP\UPnPHostConfig
  297.         sc.exe config upnphost start= auto
  298. [已禁用] \Microsoft\Windows\User Profile Service\HiveUploadTask
  299.         N/A
  300. [已启用] \Microsoft\Windows\Windows Error Reporting\QueueReporting
  301.         %windir%\system32\wermgr.exe -queuereporting
  302. [已启用] \Microsoft\Windows\Windows Media Sharing\UpdateLibrary
  303.         "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
  304. [已启用] \Microsoft\Windows\WindowsBackup\ConfigNotification
  305.         %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
  306. [已禁用] \Microsoft\Windows\WindowsColorSystem\Calibration Loader
  307.         N/A

  308. ==================================
  309. Windows 安全更新检查
  310. N/A

  311. ==================================
  312. API HOOK
  313. 入口点错误:FindFirstFileA (危险等级: 高,  被下面模块所HOOK: 0xB999DDE6)

  314. ==================================
  315. 隐藏进程
  316. N/A

  317. ==================================


复制代码
lvcan
 楼主| 发表于 2012-2-26 03:34:08 | 显示全部楼层
安装系统程序 后的SRENG日志:  

API HOOK
入口点错误:FindFirstFileA (危险等级: 高,  被下面模块所HOOK: 0xBA76DDB6)


  1. 2012-02-26,01:05:29

  2. System Repair Engineer 2.8.4.1331
  3. Smallfrogs (http://www.KZTechs.com)

  4. Windows 7 Ultimate Edition Service Pack 1 (Build 7601) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描
  14.     计划任务
  15.     Windows 安全更新检查
  16.     API HOOK
  17.     隐藏进程


  18. 启动项目
  19. 注册表
  20. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  21.     <IAStorIcon><C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe>  [(Verified)Intel Corporation]
  22. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  23.     <shell><explorer.exe>  [(Verified)Microsoft Windows]
  24.     <Userinit><userinit.exe>  [(Verified)Microsoft Windows]
  25. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  26.     <AppInit_DLLs><>  [N/A]
  27. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  28.     <WebCheck><>  [N/A]
  29. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
  30.     <Microsoft Windows Media Player><%SystemRoot%\system32\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows]
  31. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  32.     <Internet Explorer><C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig>  [(Verified)Microsoft Windows]
  33. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
  34.     <Browser Customizations><"C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP>  [(Verified)Microsoft Corporation]
  35. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  36.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
  37. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  38.     <Microsoft Windows><"%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE>  [File is missing]
  39. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  40.     <Microsoft Windows Media Player><%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI>  [(Verified)Microsoft Windows]
  41. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
  42.     <Windows Desktop Update><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows]
  43. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
  44.     <Web Platform Customizations><C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings>  [(Verified)Microsoft Windows]
  45. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
  46.     <N/A><C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install>  [(Verified)Microsoft Corporation]

  47. ==================================
  48. 启动文件夹
  49. N/A

  50. ==================================
  51. 服务
  52. [Application Experience / AeLookupSvc][Running/Manual Start]
  53.   <C:\Windows\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\aelupsvc.dll><Microsoft Corporation>
  54. [ESET Service / ekrn][Running/Auto Start]
  55.   <"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"><ESET>
  56. [Intel(R) Rapid Storage Technology / IAStorDataMgrSvc][Running/Auto Start]
  57.   <"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"><Intel Corporation>
  58. [IKE and AuthIP IPsec Keying Modules / IKEEXT][Running/Auto Start]
  59.   <C:\Windows\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\ikeext.dll><Microsoft Corporation>
  60. [PnP-X IP Bus Enumerator / IPBusEnum][Stopped/Manual Start]
  61.   <C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted-->%SystemRoot%\system32\ipbusenum.dll><Microsoft Corporation>
  62. [IP Helper / iphlpsvc][Running/Auto Start]
  63.   <C:\Windows\System32\svchost.exe -k NetSvcs-->%SystemRoot%\System32\iphlpsvc.dll><Microsoft Corporation>
  64. [Intel(R) Management and Security Application Local Management Service / LMS][Running/Auto Start]
  65.   <C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe><Intel Corporation>
  66. [Media Center Extender Service / Mcx2Svc][Stopped/Disabled]
  67.   <C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation-->%SystemRoot%\system32\Mcx2Svc.dll><Microsoft Corporation>
  68. [Multimedia Class Scheduler / MMCSS][Running/Auto Start]
  69.   <C:\Windows\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\mmcss.dll><Microsoft Corporation>
  70. [Windows Firewall / MpsSvc][Running/Auto Start]
  71.   <C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork-->%SystemRoot%\system32\mpssvc.dll><Microsoft Corporation>
  72. [Intel(R) Management and Security Application User Notification Service / UNS][Running/Auto Start]
  73.   <"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"><Intel Corporation>
  74. [Desktop Window Manager Session Manager / UxSms][Running/Auto Start]
  75.   <C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted-->%SystemRoot%\System32\uxsms.dll><Microsoft Corporation>
  76. [Windows Defender / WinDefend][Running/Auto Start]
  77.   <C:\Windows\System32\svchost.exe -k secsvcs-->%ProgramFiles%\Windows Defender\mpsvc.dll><N/A>
  78. [Windows Management Instrumentation / Winmgmt][Running/Auto Start]
  79.   <C:\Windows\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\wbem\WMIsvc.dll><Microsoft Corporation>
  80. [WLAN AutoConfig / Wlansvc][Running/Manual Start]
  81.   <C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted-->%SystemRoot%\System32\wlansvc.dll><Microsoft Corporation>

  82. ==================================
  83. 驱动程序
  84. [adp94xx / adp94xx][Stopped/Manual Start]
  85.   <\SystemRoot\system32\drivers\adp94xx.sys><Adaptec, Inc.>
  86. [adpahci / adpahci][Stopped/Manual Start]
  87.   <\SystemRoot\system32\drivers\adpahci.sys><Adaptec, Inc.>
  88. [adpu320 / adpu320][Stopped/Manual Start]
  89.   <\SystemRoot\system32\drivers\adpu320.sys><Adaptec, Inc.>
  90. [aliide / aliide][Stopped/Manual Start]
  91.   <\SystemRoot\system32\drivers\aliide.sys><Acer Laboratories Inc.>
  92. [amdsata / amdsata][Stopped/Manual Start]
  93.   <\SystemRoot\system32\drivers\amdsata.sys><Advanced Micro Devices>
  94. [amdsbs / amdsbs][Stopped/Manual Start]
  95.   <\SystemRoot\system32\drivers\amdsbs.sys><AMD Technologies Inc.>
  96. [amdxata / amdxata][Running/Boot Start]
  97.   <\SystemRoot\system32\drivers\amdxata.sys><Advanced Micro Devices>
  98. [arc / arc][Stopped/Manual Start]
  99.   <\SystemRoot\system32\drivers\arc.sys><Adaptec, Inc.>
  100. [arcsas / arcsas][Stopped/Manual Start]
  101.   <\SystemRoot\system32\drivers\arcsas.sys><Adaptec, Inc.>
  102. [Broadcom NetXtreme II VBD / b06bdrv][Stopped/Manual Start]
  103.   <\SystemRoot\system32\drivers\bxvbda.sys><Broadcom Corporation>
  104. [Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 / b57nd60a][Stopped/Manual Start]
  105.   <system32\DRIVERS\b57nd60a.sys><Broadcom Corporation>
  106. [Brother USB Mass-Storage Lower Filter Driver / BrFiltLo][Stopped/Manual Start]
  107.   <\SystemRoot\system32\drivers\BrFiltLo.sys><Brother Industries, Ltd.>
  108. [Brother USB Mass-Storage Upper Filter Driver / BrFiltUp][Stopped/Manual Start]
  109.   <\SystemRoot\system32\drivers\BrFiltUp.sys><Brother Industries, Ltd.>
  110. [Brother MFC Serial Port Interface Driver (WDM) / Brserid][Stopped/Manual Start]
  111.   <\SystemRoot\System32\Drivers\Brserid.sys><Brother Industries Ltd.>
  112. [Brother WDM Serial driver / BrSerWdm][Stopped/Manual Start]
  113.   <\SystemRoot\System32\Drivers\BrSerWdm.sys><Brother Industries Ltd.>
  114. [Brother MFC USB Fax Only Modem / BrUsbMdm][Stopped/Manual Start]
  115.   <\SystemRoot\System32\Drivers\BrUsbMdm.sys><Brother Industries Ltd.>
  116. [Brother MFC USB Serial WDM Driver / BrUsbSer][Stopped/Manual Start]
  117.   <\SystemRoot\System32\Drivers\BrUsbSer.sys><Brother Industries Ltd.>
  118. [cmdide / cmdide][Stopped/Manual Start]
  119.   <\SystemRoot\system32\drivers\cmdide.sys><CMD Technology, Inc.>
  120. [eamonm / eamonm][Running/Auto Start]
  121.   <system32\DRIVERS\eamonm.sys><ESET>
  122. [Broadcom NetXtreme II 10 GigE VBD / ebdrv][Stopped/Manual Start]
  123.   <\SystemRoot\system32\drivers\evbda.sys><Broadcom Corporation>
  124. [ehdrv / ehdrv][Running/System Start]
  125.   <system32\DRIVERS\ehdrv.sys><ESET>
  126. [elxstor / elxstor][Stopped/Manual Start]
  127.   <\SystemRoot\system32\drivers\elxstor.sys><Emulex>
  128. [epfw / epfw][Running/Auto Start]
  129.   <system32\DRIVERS\epfw.sys><ESET>
  130. [Epfw NDIS LightWeight Filter / EpfwLWF][Running/System Start]
  131.   <system32\DRIVERS\EpfwLWF.sys><ESET>
  132. [epfwwfp / epfwwfp][Running/Boot Start]
  133.   <\SystemRoot\system32\DRIVERS\epfwwfp.sys><ESET>
  134. [Hauppauge Consumer Infrared Receiver / hcw85cir][Stopped/Manual Start]
  135.   <\SystemRoot\system32\drivers\hcw85cir.sys><Hauppauge Computer Works, Inc.>
  136. [HpSAMD / HpSAMD][Stopped/Manual Start]
  137.   <\SystemRoot\system32\drivers\HpSAMD.sys><Hewlett-Packard Company>
  138. [Intel AHCI Controller / iaStor][Running/Boot Start]
  139.   <\SystemRoot\system32\DRIVERS\iaStor.sys><Intel Corporation>
  140. [iaStorV / iaStorV][Stopped/Manual Start]
  141.   <\SystemRoot\system32\drivers\iaStorV.sys><Intel Corporation>
  142. [igfx / igfx][Running/Manual Start]
  143.   <system32\DRIVERS\igdkmd64.sys><Intel Corporation>
  144. [iirsp / iirsp][Stopped/Manual Start]
  145.   <\SystemRoot\system32\drivers\iirsp.sys><Intel Corp./ICP vortex GmbH>
  146. [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
  147.   <system32\drivers\RTKVHD64.sys><Realtek Semiconductor Corp.>
  148. [英特尔(R) 显示器音频 / IntcDAud][Running/Manual Start]
  149.   <system32\DRIVERS\IntcDAud.sys><Intel(R) Corporation>
  150. [NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller / L1C][Running/Manual Start]
  151.   <system32\DRIVERS\L1C62x64.sys><Atheros Communications, Inc.>
  152. [LSI_FC / LSI_FC][Stopped/Manual Start]
  153.   <\SystemRoot\system32\drivers\lsi_fc.sys><LSI Corporation>
  154. [LSI_SAS / LSI_SAS][Stopped/Manual Start]
  155.   <\SystemRoot\system32\drivers\lsi_sas.sys><LSI Corporation>
  156. [LSI_SAS2 / LSI_SAS2][Stopped/Manual Start]
  157.   <\SystemRoot\system32\drivers\lsi_sas2.sys><LSI Corporation>
  158. [LSI_SCSI / LSI_SCSI][Stopped/Manual Start]
  159.   <\SystemRoot\system32\drivers\lsi_scsi.sys><LSI Corporation>
  160. [megasas / megasas][Stopped/Manual Start]
  161.   <\SystemRoot\system32\drivers\megasas.sys><LSI Corporation>
  162. [MegaSR / MegaSR][Stopped/Manual Start]
  163.   <\SystemRoot\system32\drivers\MegaSR.sys><LSI Corporation, Inc.>
  164. [Intel(R) Management Engine Interface / MEIx64][Running/Manual Start]
  165.   <system32\DRIVERS\HECIx64.sys><Intel Corporation>
  166. [nfrd960 / nfrd960][Stopped/Manual Start]
  167.   <\SystemRoot\system32\drivers\nfrd960.sys><IBM Corporation>
  168. [nvraid / nvraid][Stopped/Manual Start]
  169.   <\SystemRoot\system32\drivers\nvraid.sys><NVIDIA Corporation>
  170. [nvstor / nvstor][Stopped/Manual Start]
  171.   <\SystemRoot\system32\drivers\nvstor.sys><NVIDIA Corporation>
  172. [ql2300 / ql2300][Stopped/Manual Start]
  173.   <\SystemRoot\system32\drivers\ql2300.sys><QLogic Corporation>
  174. [ql40xx / ql40xx][Stopped/Manual Start]
  175.   <\SystemRoot\system32\drivers\ql40xx.sys><QLogic Corporation>
  176. [SiSRaid2 / SiSRaid2][Stopped/Manual Start]
  177.   <\SystemRoot\system32\drivers\SiSRaid2.sys><Silicon Integrated Systems Corp.>
  178. [SiSRaid4 / SiSRaid4][Stopped/Manual Start]
  179.   <\SystemRoot\system32\drivers\sisraid4.sys><Silicon Integrated Systems>
  180. [stexstor / stexstor][Stopped/Manual Start]
  181.   <\SystemRoot\system32\drivers\stexstor.sys><Promise Technology>
  182. [VGPU / VGPU][Stopped/Manual Start]
  183.   <System32\drivers\rdvgkmd.sys><N/A>
  184. [viaide / viaide][Stopped/Manual Start]
  185.   <\SystemRoot\system32\drivers\viaide.sys><VIA Technologies, Inc.>
  186. [vsmraid / vsmraid][Stopped/Manual Start]
  187.   <\SystemRoot\system32\drivers\vsmraid.sys><VIA Technologies Inc.,Ltd>

  188. ==================================
  189. 浏览器加载项
  190. [Shockwave Flash Object]
  191.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\SysWOW64\Macromed\Flash\Flash11f.ocx, (Signed) Adobe Systems, Inc.>
  192. [HTML Document]
  193.   {25336920-03F9-11CF-8FD0-00AA00686F13} <C:\Windows\SysWOW64\mshtml.dll, (Signed) Microsoft Corporation>
  194. [XML DOM Document]
  195.   {2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
  196. [Windows Media Player]
  197.   {6BF52A52-394A-11D3-B153-00C04F79FAA6} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
  198. [XML DOM Document 6.0]
  199.   {88D96A05-F192-11D4-A65F-0040963251E5} <%SystemRoot%\System32\msxml6.dll, (Signed) N/A>
  200. [XML HTTP 6.0]
  201.   {88D96A0A-F192-11D4-A65F-0040963251E5} <%SystemRoot%\System32\msxml6.dll, (Signed) N/A>
  202. [Shockwave Flash Object]
  203.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\SysWOW64\Macromed\Flash\Flash11f.ocx, (Signed) Adobe Systems, Inc.>
  204. [XML HTTP Request]
  205.   {ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
  206. [XML HTTP]
  207.   {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>

  208. ==================================
  209. 正在运行的进程
  210. [PID: 1368 / SYSTEM][C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe]  [ESET, 5.0.94.4 ]
  211.     [C:\Program Files\ESET\ESET Smart Security\x86\ekrnHips.dll]  [ESET, 5.0.94.4 ]
  212.     [C:\Program Files\ESET\ESET Smart Security\x86\ekrnScan.dll]  [ESET, 5.0.94.4 ]
  213.     [C:\Program Files\ESET\ESET Smart Security\x86\ekrnAmon.dll]  [ESET, 5.0.95.0 ]
  214.     [C:\Program Files\ESET\ESET Smart Security\x86\ekrnEmon.dll]  [ESET, 5.0.94.4 ]
  215.     [C:\Program Files\ESET\ESET Smart Security\x86\ekrnDmon.dll]  [ESET, 5.0.94.4 ]
  216.     [C:\Program Files\ESET\ESET Smart Security\x86\ekrnEpfw.dll]  [ESET, 5.0.94.4 ]
  217.     [C:\Program Files\ESET\ESET Smart Security\x86\ekrnSmon.dll]  [ESET, 5.0.94.4 ]
  218.     [C:\Program Files\ESET\ESET Smart Security\x86\ekrnUpdate.dll]  [ESET, 5.0.94.4 ]
  219.     [C:\Program Files\ESET\ESET Smart Security\x86\updater.dll]  [ESET, 5.0.94.4 ]
  220.     [C:\Program Files\ESET\ESET Smart Security\x86\ekrnMailPlugins.dll]  [ESET, 5.0.94.4 ]
  221.     [C:\Program Files\ESET\ESET Smart Security\x86\ekrnParental.dll]  [ESET, 5.0.94.4 ]
  222. [PID: 2460 / LUCK][C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe]  [Intel Corporation, 10.1.0.1008]
  223.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll]  [Microsoft Corporation, 2.0.50727.5448 (Win7SP1GDR.050727-5400)]
  224.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\System.ni.dll]  [Microsoft Corporation, 2.0.50727.5453 (Win7SP1GDR.050727-5400)]
  225.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\bc264c7dba2096c2c88080090bf42600\IAStorUtil.ni.dll]  [Intel Corporation, 10.1.0.1008]
  226.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ab87129c2b603f218e4aa5300c9b1bdd\System.Drawing.ni.dll]  [Microsoft Corporation, 2.0.50727.5420 (Win7SP1.050727-5400)]
  227.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6c51e152e7404188914c9fa4d8503ff9\System.Windows.Forms.ni.dll]  [Microsoft Corporation, 2.0.50727.5446 (Win7SP1GDR.050727-5400)]
  228.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e620323cacb5b6bfd93fd28d263440e4\System.Configuration.ni.dll]  [Microsoft Corporation, 2.0.50727.5420 (Win7SP1.050727-5400)]
  229.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\9866d1f6178e1cde25642f1ac293ff8d\System.Xml.ni.dll]  [Microsoft Corporation, 2.0.50727.5420 (Win7SP1.050727-5400)]
  230.     [C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\zh-CN\IAStorIcon.resources.dll]  [Intel Corporation, 10.1.0.1008]
  231.     [C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IntelVisualDesign.dll]  [Intel Corporation, 0.0.0.0]
  232.     [C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\zh-CN\IntelVisualDesign.resources.dll]  [Intel Corporation, 0.0.0.0]
  233.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\a1c4a635721f85bef0ea4194b888b871\System.Runtime.Remoting.ni.dll]  [Microsoft Corporation, 2.0.50727.5420 (Win7SP1.050727-5400)]
  234.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\47b9e7f070271ff50f988f75ea68fa3e\WindowsBase.ni.dll]  [Microsoft Corporation, 3.0.6920.5011 built by: Win7SP1]
  235.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\6aef03034d33721bfbd588d9d7fffe60\IAStorCommon.ni.dll]  [Intel Corp., 1.0.0.0]
  236.     [C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorUIHelper.dll]  [Intel Corporation, 10.1.0.1008]
  237. [PID: 384 / SYSTEM][C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe]  [(Verified) Microsoft Corporation, 2.0.50727.4927 (NetFXspW7.050727-4900)]
  238. [PID: 2500 / SYSTEM][C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe]  [Intel Corporation, 10.1.0.1008]
  239.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll]  [Microsoft Corporation, 2.0.50727.5448 (Win7SP1GDR.050727-5400)]
  240.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\System.ni.dll]  [Microsoft Corporation, 2.0.50727.5453 (Win7SP1GDR.050727-5400)]
  241.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgrSvc\6ca46fe242ee129f64382347606a3ce4\IAStorDataMgrSvc.ni.exe]  [Intel Corporation, 10.1.0.1008]
  242.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\075d9c27aa02085fef8983b5f5f85834\System.ServiceProcess.ni.dll]  [Microsoft Corporation, 2.0.50727.5420 (Win7SP1.050727-5400)]
  243.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgr\65c33a2173a7f24592123e723aca73db\IAStorDataMgr.ni.dll]  [Intel Corporation, 10.1.0.1008]
  244.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\bc264c7dba2096c2c88080090bf42600\IAStorUtil.ni.dll]  [Intel Corporation, 10.1.0.1008]
  245.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e620323cacb5b6bfd93fd28d263440e4\System.Configuration.ni.dll]  [Microsoft Corporation, 2.0.50727.5420 (Win7SP1.050727-5400)]
  246.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\9866d1f6178e1cde25642f1ac293ff8d\System.Xml.ni.dll]  [Microsoft Corporation, 2.0.50727.5420 (Win7SP1.050727-5400)]
  247.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\a1c4a635721f85bef0ea4194b888b871\System.Runtime.Remoting.ni.dll]  [Microsoft Corporation, 2.0.50727.5420 (Win7SP1.050727-5400)]
  248.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\a4ffd1822f036fe7e4eb9b7ba72b7cdc\IsdiInterop.ni.dll]  [N/A, ]
  249.     [C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll]  [N/A, ]
  250.     [C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\ISDI.dll]  [Intel Corporation, 10.1.0.1008]
  251.     [C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\zh-CN\IAStorDataMgr.resources.dll]  [Intel Corporation, 10.1.0.1008]
  252.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\47b9e7f070271ff50f988f75ea68fa3e\WindowsBase.ni.dll]  [Microsoft Corporation, 3.0.6920.5011 built by: Win7SP1]
  253.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\6aef03034d33721bfbd588d9d7fffe60\IAStorCommon.ni.dll]  [Intel Corp., 1.0.0.0]
  254.     [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\42ae8760f0a74ab774e82a64368aa1f6\System.Web.ni.dll]  [Microsoft Corporation, 2.0.50727.5456 (Win7SP1GDR.050727-5400)]
  255. [PID: 2396 / SYSTEM][C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe]  [Intel Corporation, 7.0.4.1197]
  256. [PID: 1848 / SYSTEM][C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe]  [Intel Corporation, 7.0.4.1197]
  257.     [C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\StatusStrings.dll]  [Intel Corporation, 3.0.0.1]
  258.     [C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\xerces-c_2_7.dll]  [Apache Software Foundation, 2, 7, 0]
  259. [PID: 2796 / LUCK][D:\TDDOWNLOAD\sreng2\SREngLdr.EXE]  [Smallfrogs Studio, 2.8.4.1331]
  260. [PID: 808 / LUCK][D:\TDDOWNLOAD\sreng2\SREb5d7fb6a.EXE]  [Smallfrogs Studio, 2.8.4.1331]

  261. ==================================
  262. 文件关联
  263. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  264. .EXE  OK. ["%1" %*]
  265. .COM  OK. ["%1" %*]
  266. .PIF  OK. ["%1" %*]
  267. .REG  OK. [regedit.exe "%1"]
  268. .BAT  OK. ["%1" %*]
  269. .SCR  OK. ["%1" /S]
  270. .CHM  OK. ["%SystemRoot%\hh.exe" %1]
  271. .HLP  OK. [%SystemRoot%\winhlp32.exe %1]
  272. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  273. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  274. .VBS  OK. ["%SystemRoot%\System32\WScript.exe" "%1" %*]
  275. .JS   Error. [C:\Windows\System32\WScript.exe "%1" %*]
  276. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  277. ==================================
  278. Winsock 提供者
  279. N/A

  280. ==================================
  281. Autorun.inf
  282. N/A

  283. ==================================
  284. HOSTS 文件
  285. N/A

  286. ==================================
  287. 进程特权扫描
  288. N/A

  289. ==================================
  290. 计划任务
  291. [已禁用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
  292.         N/A
  293. [已启用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
  294.         N/A
  295. [已禁用] \Microsoft\Windows\AppID\PolicyConverter
  296.         %windir%\system32\appidpolicyconverter.exe
  297. [已禁用] \Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
  298.         %windir%\system32\appidcertstorecheck.exe
  299. [已启用] \Microsoft\Windows\Application Experience\AitAgent
  300.         aitagent
  301. [已启用] \Microsoft\Windows\Application Experience\ProgramDataUpdater
  302.         %windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate
  303. [已启用] \Microsoft\Windows\Autochk\Proxy
  304.         %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
  305. [已启用] \Microsoft\Windows\Bluetooth\UninstallDeviceTask
  306.         BthUdTask.exe $(Arg0)
  307. [已启用] \Microsoft\Windows\CertificateServicesClient\SystemTask
  308.         N/A
  309. [已启用] \Microsoft\Windows\CertificateServicesClient\UserTask
  310.         N/A
  311. [已禁用] \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
  312.         N/A
  313. [已启用] \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
  314.         %SystemRoot%\System32\wsqmcons.exe
  315. [已启用] \Microsoft\Windows\Defrag\ScheduledDefrag
  316.         %windir%\system32\defrag.exe -c
  317. [已启用] \Microsoft\Windows\Location\Notifications
  318.         %windir%\System32\LocationNotifications.exe
  319. [已启用] \Microsoft\Windows\Maintenance\WinSAT
  320.         N/A
  321. [已启用] \Microsoft\Windows\Media Center\ActivateWindowsSearch
  322.         %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
  323. [已启用] \Microsoft\Windows\Media Center\ConfigureInternetTimeService
  324.         %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
  325. [已启用] \Microsoft\Windows\Media Center\DispatchRecoveryTasks
  326.         %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
  327. [已启用] \Microsoft\Windows\Media Center\ehDRMInit
  328.         %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
  329. [已启用] \Microsoft\Windows\Media Center\InstallPlayReady
  330.         %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
  331. [已启用] \Microsoft\Windows\Media Center\mcupdate
  332.         %SystemRoot%\ehome\mcupdate $(Arg0)
  333. [已启用] \Microsoft\Windows\Media Center\MediaCenterRecoveryTask
  334.         %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
  335. [已启用] \Microsoft\Windows\Media Center\MediaCenterRecoveryTask
  336.         %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
  337. [已启用] \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
  338.         %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
  339. [已启用] \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
  340.         %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
  341. [已启用] \Microsoft\Windows\Media Center\OCURActivate
  342.         %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
  343. [已启用] \Microsoft\Windows\Media Center\OCURDiscovery
  344.         %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
  345. [已启用] \Microsoft\Windows\Media Center\PBDADiscovery
  346.         %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
  347. [已启用] \Microsoft\Windows\Media Center\PBDADiscoveryW1
  348.         %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
  349. [已启用] \Microsoft\Windows\Media Center\PBDADiscoveryW2
  350.         %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
  351. [已禁用] \Microsoft\Windows\Media Center\PeriodicScanRetry
  352.         %windir%\ehome\MCUpdate.exe -pscn 0
  353. [已启用] \Microsoft\Windows\Media Center\PvrRecoveryTask
  354.         %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
  355. [已启用] \Microsoft\Windows\Media Center\PvrRecoveryTask
  356.         %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
  357. [已启用] \Microsoft\Windows\Media Center\PvrScheduleTask
  358.         %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
  359. [已启用] \Microsoft\Windows\Media Center\PvrScheduleTask
  360.         %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
  361. [已禁用] \Microsoft\Windows\Media Center\RecordingRestart
  362.         %SystemRoot%\ehome\ehrec /RestartRecording
  363. [已启用] \Microsoft\Windows\Media Center\RegisterSearch
  364.         %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
  365. [已启用] \Microsoft\Windows\Media Center\ReindexSearchRoot
  366.         %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
  367. [已启用] \Microsoft\Windows\Media Center\SqlLiteRecoveryTask
  368.         %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
  369. [已启用] \Microsoft\Windows\Media Center\SqlLiteRecoveryTask
  370.         %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
  371. [已启用] \Microsoft\Windows\Media Center\UpdateRecordPath
  372.         %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
  373. [已启用] \Microsoft\Windows\MobilePC\HotStart
  374.         N/A
  375. [已启用] \Microsoft\Windows\MUI\LPRemove
  376.         %windir%\system32\lpremove.exe
  377. [已启用] \Microsoft\Windows\Multimedia\SystemSoundsService
  378.         N/A
  379. [已启用] \Microsoft\Windows\NetTrace\GatherNetworkInfo
  380.         %windir%\system32\gatherNetworkInfo.vbs
  381. [已禁用] \Microsoft\Windows\Offline Files\Background Synchronization
  382.         N/A
  383. [已禁用] \Microsoft\Windows\Offline Files\Logon Synchronization
  384.         N/A
  385. [已启用] \Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
  386.         %SystemRoot%\System32\powercfg.exe -energy -auto
  387. [已启用] \Microsoft\Windows\Ras\MobilityManager
  388.         N/A
  389. [已禁用] \Microsoft\Windows\SideShow\AutoWake
  390.         N/A
  391. [已启用] \Microsoft\Windows\SideShow\GadgetManager
  392.         N/A
  393. [已禁用] \Microsoft\Windows\SideShow\SessionAgent
  394.         N/A
  395. [已禁用] \Microsoft\Windows\SideShow\SystemDataProviders
  396.         N/A
  397. [已启用] \Microsoft\Windows\SystemRestore\SR
  398.         %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
  399. [已启用] \Microsoft\Windows\Tcpip\IpAddressConflict1
  400.         %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
  401. [已启用] \Microsoft\Windows\Tcpip\IpAddressConflict2
  402.         %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
  403. [已启用] \Microsoft\Windows\Time Synchronization\SynchronizeTime
  404.         %windir%\system32\sc.exe start w32time task_started
  405. [已启用] \Microsoft\Windows\UPnP\UPnPHostConfig
  406.         sc.exe config upnphost start= auto
  407. [已禁用] \Microsoft\Windows\User Profile Service\HiveUploadTask
  408.         N/A
  409. [已启用] \Microsoft\Windows\Windows Error Reporting\QueueReporting
  410.         %windir%\system32\wermgr.exe -queuereporting
  411. [已启用] \Microsoft\Windows\Windows Media Sharing\UpdateLibrary
  412.         "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
  413. [已启用] \Microsoft\Windows\WindowsBackup\ConfigNotification
  414.         %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
  415. [已禁用] \Microsoft\Windows\WindowsColorSystem\Calibration Loader
  416.         N/A

  417. ==================================
  418. Windows 安全更新检查
  419. KB2483139,  拉脱维亚语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  420. KB2483139,  捷克语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  421. KB2483139,  俄语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  422. KB2483139,  英语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  423. KB2483139,  丹麦语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  424. KB2483139,  意大利语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  425. KB2483139,  匈牙利语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  426. KB2483139,  朝鲜语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  427. KB2483139,  瑞典语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  428. KB2483139,  波兰语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  429. KB2483139,  克罗地亚语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  430. KB2483139,  乌克兰语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  431. KB2483139,  挪威语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  432. KB2483139,  希腊语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  433. KB2483139,  保加利亚语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  434. KB2483139,  葡萄牙语(葡萄牙)语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  435. KB2483139,  荷兰语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  436. KB2483139,  葡萄牙语(巴西)语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  437. KB2483139,  西班牙语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  438. KB2483139,  斯洛文尼亚语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  439. KB2483139,  繁体中文语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  440. KB2483139,  日语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  441. KB2483139,  泰国语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  442. KB2483139,  德语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  443. KB2483139,  爱沙尼亚语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  444. KB2483139,  立陶宛语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  445. KB2483139,  斯洛伐克语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  446. KB2483139,  芬兰语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  447. KB2483139,  阿拉伯语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  448. KB2483139,  希伯来语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  449. KB2483139,  塞尔维亚语(拉丁语)语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  450. KB2483139,  罗马尼亚语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  451. KB2483139,  法语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  452. KB2483139,  土耳其语语言包 - 适用于 x64 系统的 Windows 7 Service Pack 1 (KB2483139)
  453. KB2505438,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2505438)
  454. KB2529073,  用于基于 x64 的系统的 Windows 7 更新程序 (KB2529073)
  455. KB982018,  用于基于 x64 的系统的 Windows 7 更新程序 (KB982018)
  456. KB2532531,  用于基于 x64 的系统的 Windows 7 安全更新程序 (KB2532531) MS11-053
  457. KB982670,  用于基于 x64 的系统的 Windows 7 的 Microsoft .NET Framework 4 Client Profile (KB982670)
  458. KB890830,  Windows 恶意软件删除工具 x64 - 2012 年 2 月 (KB890830)

  459. ==================================
  460. API HOOK
  461. 入口点错误:FindFirstFileA (危险等级: 高,  被下面模块所HOOK: 0xBA76DDB6)

  462. ==================================
  463. 隐藏进程
  464. N/A

  465. ==================================


复制代码
sspa668
发表于 2012-2-26 12:53:48 | 显示全部楼层
这个是正常的,我的也经常提示这个的。我忽略了。
强妈威武
发表于 2012-2-26 15:12:43 | 显示全部楼层
楼主以后上日志的时候请打包好么,话说这个有可能是软替换的
青春虎
发表于 2012-2-26 15:42:38 | 显示全部楼层


可能是杀软造成的,我的也有这提示
lvcan
 楼主| 发表于 2012-2-26 18:35:09 | 显示全部楼层
windows 7旗舰版64 安装之初的SRENG日志:  API HOOK
入口点错误:FindFirstFileA (危险等级: 高,  被下面模块所HOOK: 0xB999DDE6)
那时还没有安装杀软!!!

安装系统程序后(包括杀软)的SRENG日志: API HOOK
入口点错误:FindFirstFileA (危险等级: 高,  被下面模块所HOOK: 0xBA76DDB6)
lvcan
 楼主| 发表于 2012-2-26 18:35:29 | 显示全部楼层
青春虎 发表于 2012-2-26 15:42
可能是杀软造成的,我的也有这提示

windows 7旗舰版64 安装之初的SRENG日志:  API HOOK
入口点错误:FindFirstFileA (危险等级: 高,  被下面模块所HOOK: 0xB999DDE6)
那时还没有安装杀软!!!

安装系统程序后(包括杀软)的SRENG日志: API HOOK
入口点错误:FindFirstFileA (危险等级: 高,  被下面模块所HOOK: 0xBA76DDB6)
sasalemma
发表于 2012-2-26 18:37:02 来自手机 | 显示全部楼层
什么软件都没装?别忘了Win7自带的那个反间谍的Df
tacmot
发表于 2012-2-26 19:32:35 | 显示全部楼层
用XT之类的ARK工具看看这个函数是被谁挂了,如果是已知的就不要紧。
lvcan
 楼主| 发表于 2012-2-26 19:44:16 | 显示全部楼层
sasalemma 发表于 2012-2-26 18:37
什么软件都没装?别忘了Win7自带的那个反间谍的Df

对啊!!!谢谢!!!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-14 16:28 , Processed in 0.138386 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表