查看: 2131|回复: 9
收起左侧

[已解决] 我这个是被攻击了吗

 关闭 [复制链接]
wre2010
发表于 2011-6-28 11:32:47 | 显示全部楼层 |阅读模式

这俩天总是死机,不知道什么回事,装了风云墙后提示这个。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
ouquanwen
发表于 2011-6-28 11:39:53 | 显示全部楼层
水印额。。。。。
blue_仰望
发表于 2011-6-28 11:43:48 | 显示全部楼层
本帖最后由 lniwn 于 2011-6-28 11:45 编辑

同2楼,关键信息看不到……


不过你死机和这个应该是没关系的,除非是防火墙资源占用过高导致死机……

Sailer.X 该用户已被删除
发表于 2011-6-28 11:44:57 | 显示全部楼层
你用局域网?小区宽带吗?看样子是风云拦截了局域网内另一台电脑的IP访问请求。规则被水印挡住,看不到。不过应该不是被攻击。对于局域网而言,如果用DDOS,那么它自己的带宽也会被耗尽。如果用UDP洪水,也应该有类似结果。话说最常用的入侵是端口扫描和ping啊,而且看图也不像ARP,可以提供详细日志吗?另外死机通常与网络攻击无关~(除非你设置不对或已经肉鸡了)你可以断开网络看看,会不会是最近装了什么软件或驱动引起冲突造成无响应?方便的话请提供Sreng日志。

评分

参与人数 1人气 +1 收起 理由
ouquanwen + 1 热心~~~~

查看全部评分

wre2010
 楼主| 发表于 2011-6-28 11:54:10 | 显示全部楼层
话说我刚重装过,日志一份

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
wre2010
 楼主| 发表于 2011-6-28 11:54:59 | 显示全部楼层


  1. 2011-06-28,11:54:35

  2. System Repair Engineer 2.8.4.1331
  3. Smallfrogs (http://www.KZTechs.com)

  4. Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描
  14.     计划任务
  15.     Windows 安全更新检查
  16.     API HOOK
  17.     隐藏进程


  18. 启动项目
  19. 注册表
  20. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  21.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Component Publisher]
  22. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  23.     <load><>  [N/A]
  24. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  25.     <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Component Publisher]
  26.     <FY_FireWall><D:\FengYun\FYFireWall.exe>  [www.218.cc]
  27. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  28.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Component Publisher]
  29.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Component Publisher]
  30. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  31.     <AppInit_DLLs><>  [N/A]
  32. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  33.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Component Publisher]
  34. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  35.     <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Windows Component Publisher]
  36. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  37.     <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Component Publisher]
  38.     <CDBurn><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Component Publisher]
  39.     <WebCheck><C:\WINDOWS\system32\webcheck.dll>  [(Verified)Microsoft Windows]
  40.     <SysTray><C:\WINDOWS\system32\stobject.dll>  [(Verified)Microsoft Windows Component Publisher]
  41. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
  42.     <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Windows Component Publisher]
  43. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
  44.     <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Windows Component Publisher]
  45. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
  46.     <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Windows Component Publisher]
  47. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
  48.     <WinlogonNotify: dimsntfy><%SystemRoot%\System32\dimsntfy.dll>  [(Verified)Microsoft Windows Component Publisher]
  49. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
  50.     <WinlogonNotify: ScCertProp><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
  51. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
  52.     <WinlogonNotify: Schedule><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
  53. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
  54.     <WinlogonNotify: sclgntfy><sclgntfy.dll>  [(Verified)Microsoft Windows Component Publisher]
  55. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
  56.     <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Windows Component Publisher]
  57. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
  58.     <WinlogonNotify: termsrv><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
  59. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
  60.     <WinlogonNotify: wlballoon><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
  61. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
  62.     <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
  63.     <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
  64. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
  65.     <Internet Explorer 版本更新><C:\WINDOWS\system32\ieudinit.exe>  [(Verified)Microsoft Windows]
  66. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
  67.     <Microsoft Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows Component Publisher]
  68. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  69.     <Internet Explorer><C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig>  [(Verified)Microsoft Windows Component Publisher]
  70. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
  71.     <Browser Customizations><"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP>  [(Verified)Microsoft Windows Component Publisher]
  72. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  73.     <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [File is missing]
  74. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  75.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
  76. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  77.     <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [File is missing]
  78. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
  79.     <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Component Publisher]
  80. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
  81.     <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Component Publisher]
  82. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  83.     <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
  84. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  85.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]
  86. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
  87.     <Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows Component Publisher]
  88. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
  89.     <Internet Explorer><C:\WINDOWS\system32\ie4uinit.exe -BaseSettings>  [(Verified)Microsoft Windows Component Publisher]
  90. [HKEY_CURRENT_USER\Control Panel\Desktop]
  91.     <SCRNSAVE.EXE><C:\WINDOWS\System32\logon.scr>  [(Verified)Microsoft Windows Component Publisher]

  92. ==================================
  93. 启动文件夹
  94. N/A

  95. ==================================
  96. 服务
  97. [Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  98.   <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
  99. [Human Interface Device Access / HidServ][Stopped/Disabled]
  100.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  101. [Tencent Software Update Service / TSUSVC][Stopped/Auto Start]
  102.   <"d:\Tencent\QQSoftMgr\1.0.375.203\TencentUpdateSvc.exe" -run><Tencent>

  103. ==================================
  104. 驱动程序
  105. [ati2mtag / ati2mtag][Running/Manual Start]
  106.   <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
  107. [FengYunTdiDrv / FengYunTdiDrv][Running/System Start]
  108.   <\??\d:\FengYun\FYTdiDrv.sys><www.218.cc>
  109. [NTSIM / NTSIM][Stopped/Manual Start]
  110.   <\??\C:\WINDOWS\system32\ntsim.sys><VIA Networking Technologies, Inc.>
  111. [nvatabus / nvatabus][Running/Boot Start]
  112.   <\SystemRoot\system32\DRIVERS\nvatabus.sys><NVIDIA Corporation>
  113. [Service for NVIDIA(R) nForce(TM) Audio Enumerator / nvax][Running/Manual Start]
  114.   <system32\drivers\nvax.sys><NVIDIA Corporation>
  115. [NVIDIA nForce Networking Controller Driver / NVENET][Running/Manual Start]
  116.   <system32\DRIVERS\NVENET.sys><NVIDIA Corporation>
  117. [Service for NVIDIA(R) nForce(TM) Audio / nvnforce][Running/Manual Start]
  118.   <system32\drivers\nvapu.sys><NVIDIA Corporation>
  119. [NVIDIA nForce AGP Bus Filter / nv_agp][Running/Boot Start]
  120.   <\SystemRoot\system32\DRIVERS\nv_agp.sys><NVIDIA Corporation>
  121. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  122.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  123. [Secdrv / Secdrv][Stopped/Manual Start]
  124.   <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
  125. [SogouNetopt / SogouNetopt][Running/Auto Start]
  126.   <\??\d:\SogouExplorer\sogounetopt.sys><Sogou.com>

  127. ==================================
  128. 浏览器加载项
  129. [联想]
  130.   {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.lenovo.com, N/A>
  131. []
  132.   {e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, (Signed) N/A>
  133. [Messenger]
  134.   {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, (Signed) Microsoft Corporation>
  135. [Windows Genuine Advantage Validation Tool]
  136.   {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, (Signed) Microsoft Corporation>
  137. [WUWebControl Class]
  138.   {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, (Signed) Microsoft Corporation>
  139. [MUWebControl Class]
  140.   {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\system32\muweb.dll, (Signed) Microsoft Corporation>
  141. [Shockwave Flash Object]
  142.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash6.ocx, (Signed) Macromedia, Inc.>
  143. [Windows Genuine Advantage Validation Tool]
  144.   {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, (Signed) Microsoft Corporation>
  145. []
  146.   {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <, >
  147. [WUWebControl Class]
  148.   {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, (Signed) Microsoft Corporation>
  149. [MUWebControl Class]
  150.   {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\system32\muweb.dll, (Signed) Microsoft Corporation>
  151. [Shockwave Flash Object]
  152.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash6.ocx, (Signed) Macromedia, Inc.>
  153. []
  154.   {E2E2DD38-D088-4134-82B7-F2BA38496583} <, >
  155. [XML HTTP Request]
  156.   {ED8C108E-4349-11D2-91A4-00C04F7969E8} <C:\WINDOWS\system32\msxml3.dll, (Signed) Microsoft Corporation>
  157. []
  158.   {FB5F1910-F110-11D2-BB9E-00C04F795683} <, >
  159. []
  160.   {FDAEAB93-6DC0-4A63-81C6-95C88ED36F6A} <, >

  161. ==================================
  162. 正在运行的进程
  163. [PID: 404 / SYSTEM][\SystemRoot\System32\smss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  164. [PID: 664 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  165. [PID: 688 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
  166.     [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4110]
  167. [PID: 732 / SYSTEM][C:\WINDOWS\system32\services.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)]
  168. [PID: 744 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
  169. [PID: 912 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4110]
  170.     [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2495]
  171. [PID: 924 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  172. [PID: 1004 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  173. [PID: 1100 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  174. [PID: 1144 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  175. [PID: 1184 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  176. [PID: 1468 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [(Verified) Microsoft Corporation, 5.1.2600.6024 (xpsp_sp3_gdr.100817-1626)]
  177. [PID: 536 / Administrator][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4110]
  178.     [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2495]
  179.     [D:\FengYun\FYMon.dll]  [www.218.cc, 1.3.0.20]
  180. [PID: 564 / Administrator][C:\WINDOWS\Explorer.EXE]  [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  181.     [D:\FengYun\FYMon.dll]  [www.218.cc, 1.3.0.20]
  182.     [C:\WINDOWS\system32\SOGOUPY.IME]  [Sogou.com Inc., 6.0.0.5909]
  183.     [d:\SogouInput\6.0.0.5909\Resource.dll]  [Sogou.com Inc., 6.0.0.5909]
  184.     [d:\7-Zip\7-zip.dll]  [Igor Pavlov, 9.20]
  185. [PID: 660 / Administrator][D:\FengYun\FYFireWall.exe]  [www.218.cc, 1.3.0.900]
  186.     [D:\FengYun\ArpInfo.dll]  [www.218.cc, 1.3.0.2]
  187.     [D:\FengYun\FYMon.dll]  [www.218.cc, 1.3.0.20]
  188.     [C:\WINDOWS\system32\msjetoledb40.dll]  [, ]
  189. [PID: 668 / Administrator][C:\WINDOWS\system32\ctfmon.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
  190.     [D:\FengYun\FYMon.dll]  [www.218.cc, 1.3.0.20]
  191. [PID: 1800 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  192. [PID: 1676 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
  193. [PID: 1924 / Administrator][C:\WINDOWS\system32\wscntfy.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)]
  194.     [D:\FengYun\FYMon.dll]  [www.218.cc, 1.3.0.20]
  195. [PID: 2956 / Administrator][d:\SogouInput\6.0.0.5909\SogouCloud.exe]  [Sogou.com Inc., 6.0.0.5909]
  196. [PID: 3468 / Administrator][D:\SogouExplorer\sogouexplorer.exe]  [Sogou.com, 2.2.0.2070]
  197.     [D:\FengYun\FYMon.dll]  [www.218.cc, 1.3.0.20]
  198.     [C:\Documents and Settings\Administrator\Application Data\SogouExplorer\Bin\bseapi.dll]  [Keniu Network Technology., 1.1.0.1130]
  199.     [C:\Documents and Settings\Administrator\Application Data\SogouExplorer\Bin\bseupd.dll]  [Keniu Network Technology., 1.1.0.1130]
  200.     [C:\Documents and Settings\Administrator\Application Data\SogouExplorer\Bin\bsecore.dll]  [Keniu Network Technology., 1.1.0.1130]
  201.     [d:\SogouExplorer\sogouipfilter.dll]  [Sogou.com, 2.2.0.2070]
  202.     [D:\SogouExplorer\framework.dll]  [Sogou.com, 1, 0, 0, 41]
  203.     [D:\SogouExplorer\video_acc.dll]  [Sogou.com, 1, 1, 0, 28]
  204.     [D:\SogouExplorer\sogounet.dll]  [Sogou.com, 1.1.0.31]
  205.     [D:\SogouExplorer\SoDaLib.dll]  [Sogou.com, 1, 4, 2, 3]
  206.     [D:\SogouExplorer\MetaSearch.dll]  [Sogou.com, 2.2.0.2070]
  207.     [D:\SogouExplorer\Dialog.dll]  [Sogou.com, 2.2.0.2070]
  208. [PID: 624 / Administrator][D:\SogouExplorer\sogouexplorer.exe]  [Sogou.com, 2.2.0.2070]
  209.     [D:\SogouExplorer\WebkitCore.dll]  [Sogou.com, 2, 2, 0, 263]
  210.     [D:\FengYun\FYMon.dll]  [www.218.cc, 1.3.0.20]
  211.     [d:\SogouExplorer\sogouipfilter.dll]  [Sogou.com, 2.2.0.2070]
  212. [PID: 2340 / Administrator][D:\SogouExplorer\sogouexplorer.exe]  [Sogou.com, 2.2.0.2070]
  213.     [D:\SogouExplorer\WebkitCore.dll]  [Sogou.com, 2, 2, 0, 263]
  214.     [D:\FengYun\FYMon.dll]  [www.218.cc, 1.3.0.20]
  215.     [D:\SogouExplorer\avcodec-52.dll]  [N/A, ]
  216.     [D:\SogouExplorer\avutil-50.dll]  [N/A, ]
  217.     [D:\SogouExplorer\avformat-52.dll]  [N/A, ]
  218.     [D:\SogouExplorer\DialogCore.dll]  [Sogou.com, 2.2.0.2070]
  219.     [C:\WINDOWS\system32\SOGOUPY.IME]  [Sogou.com Inc., 6.0.0.5909]
  220.     [d:\SogouInput\6.0.0.5909\Resource.dll]  [Sogou.com Inc., 6.0.0.5909]
  221. [PID: 3584 / Administrator][F:\SREngLdr.EXE]  [Smallfrogs Studio, 2.8.4.1331]
  222. [PID: 3532 / Administrator][F:\SREfdca405a.EXE]  [Smallfrogs Studio, 2.8.4.1331]
  223.     [D:\FengYun\FYMon.dll]  [www.218.cc, 1.3.0.20]

  224. ==================================
  225. 文件关联
  226. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  227. .EXE  OK. ["%1" %*]
  228. .COM  OK. ["%1" %*]
  229. .PIF  OK. ["%1" %*]
  230. .REG  OK. [regedit.exe "%1"]
  231. .BAT  OK. ["%1" %*]
  232. .SCR  OK. ["%1" /S]
  233. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  234. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  235. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  236. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  237. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  238. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  239. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  240. ==================================
  241. Winsock 提供者
  242. N/A

  243. ==================================
  244. Autorun.inf
  245. N/A

  246. ==================================
  247. HOSTS 文件
  248. 127.0.0.1       localhost

  249. ==================================
  250. 进程特权扫描
  251. 特殊特权被允许: SeSystemtimePrivilege [PID = 660, D:\FENGYUN\FYFIREWALL.EXE]
  252. 特殊特权被允许: SeDebugPrivilege [PID = 660, D:\FENGYUN\FYFIREWALL.EXE]
  253. 特殊特权被允许: SeLoadDriverPrivilege [PID = 660, D:\FENGYUN\FYFIREWALL.EXE]

  254. ==================================
  255. 计划任务
  256. [已启用] SogouImeMgr.job
  257.         d:\SOGOUI~1\600~1.590\SGTool.exe

  258. ==================================
  259. Windows 安全更新检查
  260. Microsoft .NET Framework 版本 1.1,简体中文版
  261. KB925850,  Windows Media Player 11
  262. KB940157,  用于 Windows XP 的 Windows 搜索 4.0 (KB940157)
  263. KB909520,  Microsoft 基本智能卡加密服务提供程序包: x86 (KB909520)
  264. KB951847,  Microsoft .NET Framework 3.5 Service Pack 1 和 .NET Framework 3.5 Family Update (KB951847) x86
  265. KB971513,  Windows XP 更新程序 (KB971513)
  266. KB971513,  Windows Live 软件包
  267. KB982670,  用于 Windows XP x86 的 Microsoft .NET Framework 4 Client Profile (KB982670)
  268. KB2267621,  Microsoft Security Essentials - KB2267621
  269. KB931125,  根证书更新 [2011 年 3 月] (KB931125)
  270. KB2492386,  Windows XP 更新程序 (KB2492386)
  271. KB2512827,  Microsoft Silverlight (KB2512827)

  272. ==================================
  273. API HOOK
  274. N/A

  275. ==================================
  276. 隐藏进程
  277. N/A

  278. ==================================


复制代码
Sailer.X 该用户已被删除
发表于 2011-6-28 12:37:29 | 显示全部楼层
看日志没啥大问题
137端口,为局域网中提供计算机的名字或IP地址查询服务。
138端口,提供计算机名浏览功能。
通过对这两个端口建立连接,可以知道你的计算机名和IP地址。138端口还提供共享功能。
如果频繁接到这个访问请求,的确有被入侵风险,且风云连续的拦截请求的确会消耗系统资源,配置低会卡~
对了,你那局域网内IP是固定的吗?
192.168.1.2和192.168.1.3应该不是一台机子吧~
wre2010
 楼主| 发表于 2011-6-28 14:17:33 | 显示全部楼层
我也不知道是不是局域网,我是电信的宽带,不是小区的。
纠_缠~。
发表于 2011-6-28 14:26:11 | 显示全部楼层
楼主被攻击了嘛。那里刚好挡住了
wre2010
 楼主| 发表于 2011-6-28 14:31:02 | 显示全部楼层
也有杭州西湖。宁波奉化的。来访问我,我说他不是攻击我来访问我干什么啊,我又不认识。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-11-2 18:44 , Processed in 0.161647 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表