查看: 1792|回复: 7
收起左侧

[已解决] 大家看看我的日志有没有什么可疑的

 关闭 [复制链接]
逝去の小丑 该用户已被删除
发表于 2007-7-12 12:46:11 | 显示全部楼层 |阅读模式
今天刚刚下载了新版本的sreng,发现启动项里多出了N多东东。是在搞不懂。
特此发上来,大家研究研究。
  1. 2007-07-12,12:34:04
  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描

  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <ctfmon.exe><C:\windows\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  18. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  19.     <nod32kui><"C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE>  [Eset ]
  20.     <FY_FireWall><C:\Program Files\FengYun\FYFireWall.exe>  [www.218.cc]
  21. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  22.     <shell><Explorer.exe>  [(Verified)]
  23.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  24. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  25.     <AppInit_DLLs><>  [N/A]
  26. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  27.     <UIHost><logonui.exe>  [(Verified)]
  28. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  29.     <WinlogonNotify: klogon><C:\windows\system32\klogon.dll>  [(Verified)Kaspersky Lab]
  30. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\System Safety Monitor]
  31.     <WinlogonNotify: System Safety Monitor><SSMWinlogonEx.dll>  [(Verified)System Safety Limited]
  32. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
  33.     <WinlogonNotify: WgaLogon><WgaLogon.dll>  [(Verified)Microsoft Corporation]
  34. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
  35.     <IE7 Uninstall Stub><C:\WINDOWS\system32\ieudinit.exe>  [(Verified)Microsoft Windows Component Publisher]
  36. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  37.     <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
  38. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  39.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
  40. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  41.     <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
  42. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
  43.     <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
  44. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
  45.     <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
  46. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  47.     <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub>  [(Verified)Microsoft Windows Publisher]
  48. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  49.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
  50. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
  51.     <N/A><C:\windows\system32\Rundll32.exe C:\windows\system32\mscories.dll,Install>  [Microsoft Corporation]
  52. ==================================
  53. 启动文件夹
  54. N/A
  55. ==================================
  56. 服务
  57. [Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
  58.   <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
  59. [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Stopped/Disabled]
  60.   <F:\Program Files\anit-virus\AVG Anti-Spyware 7.5\guard.exe><Anti-Malware Development a.s.>
  61. [FLEXnet Licensing Service / FLEXnet Licensing Service][Stopped/Manual Start]
  62.   <"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"><Macrovision Europe Ltd.>
  63. [Machine Debug Manager / MDM][Stopped/Manual Start]
  64.   <"C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"><Microsoft Corporation>
  65. [NOD32 Kernel Service / NOD32krn][Running/Auto Start]
  66.   <"C:\Program Files\Eset\nod32krn.exe"><Eset>
  67. [NVIDIA Display Driver Service / NVSvc][Stopped/Manual Start]
  68.   <C:\windows\system32\nvsvc32.exe><NVIDIA Corporation>
  69. [Shadow System Service / ShadowSystemService][Stopped/Manual Start]
  70.   <C:\windows\system32\shadow\ShadowService.exe><N/A>
  71. [WinTab Service / WinTabService][Stopped/Manual Start]
  72.   <"C:\windows\System32\Drivers\WTSRV.EXE"><Tablet Driver>
  73. ==================================
  74. 驱动程序
  75. [AMON / AMON][Running/Auto Start]
  76.   <\SystemRoot\system32\drivers\amon.sys><Eset>
  77. [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
  78.   <\??\F:\Program Files\anit-virus\AVG Anti-Spyware 7.5\guard.sys><N/A>
  79. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  80.   <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
  81. [C-Media WDM Audio Interface / cmuda][Running/Manual Start]
  82.   <system32\drivers\cmuda.sys><C-Media Inc>
  83. [dtscsi / dtscsi][Stopped/Manual Start]
  84.   <\SystemRoot\System32\Drivers\dtscsi.sys><N/A>
  85. [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Running/Manual Start]
  86.   <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
  87. [Filseclab Dynamic Defense System Driver / filar][Running/System Start]
  88.   <\??\C:\PROGRA~1\COMMON~1\FILSEC~1\filar.sys><Filseclab Corporation>
  89. [Filseclab Process Protection Driver / filpp][Stopped/Manual Start]
  90.   <\??\C:\PROGRA~1\COMMON~1\FILSEC~1\filpp.sys><Filseclab Corporation>
  91. [FYTdifltDrv / FYTdifltDrv][Running/System Start]
  92.   <\??\C:\Program Files\FengYun\FYTdiDrv.sys><N/A>
  93. [GDTdiInterceptor / GDTdiInterceptor][Running/Auto Start]
  94.   <\??\C:\windows\system32\drivers\GDTdiIcpt.sys><>
  95. [Filseclab Twister Kernel Module / IMMDRV][Stopped/Manual Start]
  96.   <\??\F:\PROGRA~1\ANIT-V~1\FILSEC~1\Twister\immdrv.sys><Filseclab Corp.>
  97. [nod32drv / nod32drv][Running/System Start]
  98.   <\SystemRoot\system32\drivers\nod32drv.sys><N/A>
  99. [npkcrypt / npkcrypt][Running/Auto Start]
  100.   <\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
  101. [nv / nv][Running/Manual Start]
  102.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  103. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  104.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  105. [PxHelp20 / PxHelp20][Running/Boot Start]
  106.   <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
  107. [System Safety Monitor 2.0 Core Engine / safemon][Running/Boot Start]
  108.   <\SystemRoot\system32\drivers\safemon.sys><System Safety Limited>
  109. [Secdrv / Secdrv][Stopped/Manual Start]
  110.   <system32\DRIVERS\secdrv.sys><N/A>
  111. [sptd / sptd][Running/Boot Start]
  112.   <\SystemRoot\System32\Drivers\sptd.sys><N/A>
  113. [Serial Tablet Port Driver / Tablet2k][Stopped/Manual Start]
  114.   <"C:\windows\System32\Drivers\Tablet2k.sys"><Windows (R) 2000 DDK provider>
  115. [Tablet Class Driver / TClass2k][Running/Manual Start]
  116.   <system32\DRIVERS\TClass2k.sys><Tablet Driver>
  117. [HID Tablet Port Driver / UCTblHid][Running/Manual Start]
  118.   <system32\DRIVERS\UCTblHid.sys><Tablet Driver>
  119. [ViaIde / ViaIde][Running/Boot Start]
  120.   <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
  121. ==================================
  122. 浏览器加载项
  123. [Thunder Browser Helper]
  124.   {00011267-E188-40DF-A514-835FCD78B1BF} <D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  125. [IE7pro BHO]
  126.   {00011268-E188-40DF-A514-835FCD78B1BF} <C:\Program Files\IE7pro\IE7pro.dll, IE7pro.com>
  127. [ThunderAtOnce Class]
  128.   {01443AEC-0FD1-40fd-9C87-E93D1494C233} <D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
  129. [Adobe PDF Reader Link Helper]
  130.   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
  131. [IE7pro ToolsExt]
  132.   {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} <C:\Program Files\IE7pro\IE7pro.dll, IE7pro.com>
  133. [Office Genuine Advantage Validation Tool]
  134.   {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} <C:\windows\system32\OGACheckControl.DLL, >
  135. [WUWebControl Class]
  136.   {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\windows\system32\wuweb.dll, Microsoft Corporation>
  137. [Office Update Installation Engine]
  138.   {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} <C:\windows\opuc.dll, Microsoft Corporation>
  139. [Thunder Browser Helper]
  140.   {00011267-E188-40DF-A514-835FCD78B1BF} <D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  141. [IE7pro BHO]
  142.   {00011268-E188-40DF-A514-835FCD78B1BF} <C:\Program Files\IE7pro\IE7pro.dll, IE7pro.com>
  143. [ThunderAtOnce Class]
  144.   {01443AEC-0FD1-40FD-9C87-E93D1494C233} <D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
  145. [Thunder Browser Helper]
  146.   {06849E9D-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll, N/A>
  147. [Adobe PDF Reader Link Helper]
  148.   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
  149. [XML DOM Document]
  150.   {2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\system32\msxml3.dll, N/A>
  151. [Thunder Agent Class]
  152.   {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <D:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
  153. [WUWebControl Class]
  154.   {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\windows\system32\wuweb.dll, Microsoft Corporation>
  155. [Windows Media Player]
  156.   {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  157. [Active Desktop Mover]
  158.   {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
  159. [Thunder Browser Helper]
  160.   {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  161. [Shockwave Flash Object]
  162.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\windows\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  163. [XML HTTP]
  164.   {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\system32\msxml3.dll, N/A>
  165. [上传到QQ网络硬盘]
  166.   <D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
  167. [使用迅雷下载]
  168.   <D:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
  169. [使用迅雷下载全部链接]
  170.   <D:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
  171. [添加到QQ自定义面板]
  172.   <D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
  173. [添加到QQ表情]
  174.   <D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
  175. [用QQ彩信发送该图片]
  176.   <D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
  177. [设为 Messenger Live 头像]
  178.   <C:\Program Files\MSNShell\Bin\SetMSNDP.htm, N/A>
  179. ==================================
  180. 正在运行的进程
  181. [PID: 656][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  182. [PID: 812][\??\C:\windows\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  183. [PID: 912][\??\C:\windows\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  184.     [C:\windows\system32\klogon.dll]  [Kaspersky Lab, 7.0.0.120]
  185.     [C:\windows\system32\SSMWinlogonEx.dll]  [System Safety Limited, 2.4.0.618]
  186. [PID: 1020][C:\windows\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  187. [PID: 1032][C:\windows\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  188. [PID: 1240][C:\windows\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  189. [PID: 1364][C:\windows\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  190. [PID: 1396][C:\windows\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  191.     [C:\windows\system32\imon.dll]  [Eset , 2, 70, 39 ]
  192.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  193. [PID: 1736][C:\Program Files\Eset\nod32krn.exe]  [Eset , 2, 70, 39 ]
  194.     [C:\Program Files\Eset\nod32krr.dll]  [Eset , 2, 70, 32 ]
  195.     [C:\Program Files\Eset\ps_amon.dll]  [Eset , 2, 70, 39 ]
  196.     [C:\Program Files\Eset\pr_amon.dll]  [Eset , 2, 70, 16 ]
  197.     [C:\Program Files\Eset\ps_dmon.dll]  [Eset , 2, 70, 39 ]
  198.     [C:\Program Files\Eset\pr_dmon.dll]  [N/A, ]
  199.     [C:\Program Files\Eset\ps_emon.dll]  [Eset , 2, 70, 39 ]
  200.     [C:\Program Files\Eset\pr_emon.dll]  [N/A, ]
  201.     [C:\windows\system32\imon.dll]  [Eset , 2, 70, 39 ]
  202.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  203.     [C:\Program Files\Eset\ps_nod32.dll]  [Eset , 2, 70, 39 ]
  204.     [C:\Program Files\Eset\pr_nod32.dll]  [Eset , 2, 70, 16 ]
  205.     [C:\Program Files\Eset\ps_upd.dll]  [Eset , 2, 70, 39 ]
  206.     [C:\Program Files\Eset\pr_upd.dll]  [N/A, ]
  207. [PID: 632][C:\windows\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  208.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  209.     [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
  210.     [C:\Program Files\Unlocker\UnlockerCOM.dll]  [N/A, ]
  211.     [F:\Program Files\anit-virus\Filseclab\Twister\Twshlext.dll]  [Filseclab Corp., 2, 0, 1, 988]
  212.     [C:\Program Files\Eset\nodshex.dll]  [N/A, ]
  213.     [F:\Program Files\anit-virus\Dr.Web\drwsxtn.dll]  [Doctor Web, Ltd., 4.33.0.200507180]
  214.     [C:\WINDOWS\system32\contmenu.dll]  [N/A, ]
  215.     [F:\Program Files\anit-virus\AVK2006\ShellExt.dll]  [, 10, 0, 0, 0]
  216.     [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 8.0.0.0]
  217.     [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS]  [Adobe Systems, Inc., 8.0.0.0]
  218. [PID: 1420][C:\Program Files\Eset\nod32kui.exe]  [Eset , 2, 70, 39 ]
  219.     [C:\Program Files\Eset\nod32rui.dll]  [N/A, ]
  220.     [C:\Program Files\Eset\pu_amon.dll]  [Eset , 2, 70, 39 ]
  221.     [C:\Program Files\Eset\pr_amon.dll]  [Eset , 2, 70, 16 ]
  222.     [C:\Program Files\Eset\pu_dmon.dll]  [Eset , 2, 70, 39 ]
  223.     [C:\Program Files\Eset\pr_dmon.dll]  [N/A, ]
  224.     [C:\Program Files\Eset\pu_emon.dll]  [Eset , 2, 70, 39 ]
  225.     [C:\Program Files\Eset\pr_emon.dll]  [N/A, ]
  226.     [C:\Program Files\Eset\pu_imon.dll]  [Eset , 2, 70, 39 ]
  227.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  228.     [C:\Program Files\Eset\pu_nod32.dll]  [Eset , 2, 70, 39 ]
  229.     [C:\Program Files\Eset\pr_nod32.dll]  [Eset , 2, 70, 16 ]
  230.     [C:\Program Files\Eset\pu_upd.dll]  [Eset , 2, 70, 39 ]
  231.     [C:\Program Files\Eset\pr_upd.dll]  [N/A, ]
  232.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  233. [PID: 1672][C:\Program Files\FengYun\FYFireWall.exe]  [www.218.cc, 1.2.5.1912]
  234.     [C:\Program Files\FengYun\arpinfo.dll]  [N/A, ]
  235.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  236. [PID: 1696][C:\windows\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  237.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  238. [PID: 1860][D:\jcb_xyzq\TDXW.EXE]  [, ]
  239.     [D:\jcb_xyzq\TCalc.dll]  [, 1, 0, 0, 1]
  240.     [D:\jcb_xyzq\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
  241.     [D:\jcb_xyzq\MSVCP60.dll]  [Microsoft Corporation, 6.00.8972.0]
  242.     [D:\jcb_xyzq\Viewthem.dll]  [, 1, 0, 0, 1]
  243.     [D:\jcb_xyzq\invest.dll]  [, 1.15]
  244.     [D:\jcb_xyzq\Dbf.dll]  [N/A, ]
  245.     [D:\jcb_xyzq\Secure.dll]  [通达信, 1.00.00]
  246.     [D:\jcb_xyzq\TTools.dll]  [, 1.00]
  247.     [D:\jcb_xyzq\TList.dll]  [, 1, 0, 0, 1]
  248.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  249.     [D:\jcb_xyzq\calcer.dll]  [, 1, 0, 0, 1]
  250.     [D:\jcb_xyzq\Advhq.dll]  [, 1, 0, 0, 1]
  251.     [C:\windows\system32\imon.dll]  [Eset , 2, 70, 39 ]
  252.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  253. [PID: 1108][D:\jcb_xyzq\WinWT.exe]  [通达信电子科技有限公司, 4.32]
  254.     [D:\jcb_xyzq\Secure.dll]  [通达信, 1.00.00]
  255.     [D:\jcb_xyzq\Dbf.dll]  [N/A, ]
  256.     [D:\jcb_xyzq\WtCommon.dll]  [N/A, ]
  257.     [D:\jcb_xyzq\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
  258.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  259.     [C:\windows\system32\imon.dll]  [Eset , 2, 70, 39 ]
  260.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  261. [PID: 1812][D:\jcb_xyzq\WinWT.exe]  [通达信电子科技有限公司, 4.32]
  262.     [D:\jcb_xyzq\Secure.dll]  [通达信, 1.00.00]
  263.     [D:\jcb_xyzq\Dbf.dll]  [N/A, ]
  264.     [D:\jcb_xyzq\WtCommon.dll]  [N/A, ]
  265.     [D:\jcb_xyzq\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
  266.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  267.     [C:\windows\system32\imon.dll]  [Eset , 2, 70, 39 ]
  268.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  269. [PID: 1660][D:\jcb_xyzq\WinWT.exe]  [通达信电子科技有限公司, 4.32]
  270.     [D:\jcb_xyzq\Secure.dll]  [通达信, 1.00.00]
  271.     [D:\jcb_xyzq\Dbf.dll]  [N/A, ]
  272.     [D:\jcb_xyzq\WtCommon.dll]  [N/A, ]
  273.     [D:\jcb_xyzq\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
  274.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  275.     [C:\windows\system32\imon.dll]  [Eset , 2, 70, 39 ]
  276.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  277. [PID: 684][D:\Program Files\Tencent\QQ\QQ.exe]  [TENCENT, 7,0,313,1681]
  278.     [D:\Program Files\Tencent\CQQ50B3\CoralAssist.dll]  [Coral Team, 5.0.0 build 20060829]
  279.     [D:\Program Files\Tencent\CQQ50B3\CoralQQ.dll]  [Coral Team, 5.0 Build 20070309]
  280.     [D:\Program Files\Tencent\CQQ50B3\KQL.dll]  [Coral Team, 5.0.0 build 20070301]
  281.     [D:\Program Files\Tencent\QQ\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
  282.     [D:\Program Files\Tencent\CQQ50B3\IPSearcher.dll]  [, 1.0.0.4]
  283.     [D:\Program Files\Tencent\QQ\QQBaseClassInDll.dll]  [TENCENT, 7,0,313,1681]
  284.     [D:\Program Files\Tencent\QQ\QQHelperDll.dll]  [TENCENT, 7,0,313,1681]
  285.     [D:\Program Files\Tencent\QQ\BasicCtrlDll.dll]  [TENCENT, 7, 0, 225, 1651]
  286.     [D:\Program Files\Tencent\CQQ50B3\ConfigHotkey.cqx]  [Coral Team, 1.0]
  287.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  288.     [D:\Program Files\Tencent\QQ\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
  289.     [D:\Program Files\Tencent\QQ\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
  290.     [D:\Program Files\Tencent\QQ\QQAPI.dll]  [TENCENT, 7,0,313,1681]
  291.     [D:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
  292.     [D:\Program Files\Tencent\QQ\LoginCtrl.dll]  [TENCENT, 7,0,313,1681]
  293.     [D:\Program Files\Tencent\QQ\LoginCtrlRes.dll]  [TENCENT, 7,0,313,1681]
  294.     [D:\Program Files\Tencent\QQ\QQRes.dll]  [TENCENT, 7,0,313,1681]
  295.     [D:\Program Files\Tencent\QQ\MailSummary.dll]  [TENCENT, 7,0,313,1681]
  296.     [D:\Program Files\Tencent\QQ\QQMainFrame.dll]  [N/A, ]
  297.     [D:\Program Files\Tencent\QQ\CQQApplication.dll]  [N/A, ]
  298.     [D:\Program Files\Tencent\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
  299.     [D:\Program Files\Tencent\QQ\NewSkin.dll]  [TENCENT, 7,0,313,1681]
  300.     [D:\Program Files\Tencent\QQ\HostingMgr.dll]  [TENCENT, 7,0,313,1681]
  301.     [D:\Program Files\Tencent\QQ\CameraDll.dll]  [TENCENT, 7,0,313,1681]
  302.     [D:\Program Files\Tencent\CQQ50B3\CoralHotkey.cqx]  [Coral Team, 1.0]
  303.     [D:\Program Files\Tencent\QQ\QQKnowledgeSearch.dll]  [TENCENT, 7,0,313,1681]
  304.     [C:\windows\system32\imon.dll]  [Eset , 2, 70, 39 ]
  305.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  306.     [D:\Program Files\Tencent\QQ\QQAllInOne.dll]  [TENCENT, 7,0,313,1681]
  307.     [D:\Program Files\Tencent\QQ\SCCore.dll]  [TENCENT, 1, 6, 0, 2]
  308.     [D:\Program Files\Tencent\QQ\QQSpace.dll]  [TENCENT, 7,0,313,1681]
  309.     [D:\Program Files\Tencent\QQ\vbscript.dll]  [Microsoft Corporation, 5.6.0.7426]
  310.     [C:\windows\system32\msdmo.dll]  [, ]
  311.     [D:\Program Files\Tencent\QQ\QQGroupMng.dll]  [TENCENT, 7,0,313,1681]
  312.     [D:\Program Files\Tencent\QQ\UserDefinedHead.dll]  [TENCENT, 7,0,313,1681]
  313.     [D:\Program Files\Tencent\QQ\QQPlugin.dll]  [N/A, ]
  314.     [D:\Program Files\Tencent\QQ\QQConfigPlugin.dll]  [TENCENT, 7,0,313,1681]
  315.     [D:\Program Files\Tencent\QQ\QQAvatar.dll]  [N/A, ]
  316.     [D:\Program Files\Tencent\QQ\QQCustomFace.dll]  [N/A, ]
  317.     [D:\Program Files\Tencent\QQ\QQPet.dll]  [TENCENT, 7,0,313,1681]
  318.     [D:\Program Files\Tencent\QQ\LongConnection.dll]  [TENCENT, 7,0,313,1681]
  319.     [D:\Program Files\Tencent\QQ\QRingMng.dll]  [N/A, ]
  320.     [D:\Program Files\Tencent\QQ\PhoneAPI.dll]  [TENCENT, 7,0,313,1681]
  321.     [D:\Program Files\Tencent\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
  322.     [D:\Program Files\Tencent\QQ\QQSysMsgMng.dll]  [N/A, ]
  323.     [D:\Program Files\Tencent\QQ\BQQApplication.dll]  [N/A, ]
  324.     [D:\Program Files\Tencent\QQ\CommercesMng.dll]  [TENCENT, 7,0,313,1681]
  325.     [D:\Program Files\Tencent\QQ\PersonalDesktop.dll]  [TENCENT, 7,0,313,1681]
  326.     [D:\Program Files\Tencent\QQ\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 310]
  327.     [D:\Program Files\Tencent\QQ\QQSceneMng.dll]  [N/A, ]
  328.     [D:\Program Files\Tencent\QQ\ImageOle.dll]  [TENCENT, 7,0,313,1681]
  329.     [D:\Program Files\Tencent\QQ\QQLiveQMng.dll]  [TENCENT, 7,0,313,1681]
  330.     [D:\Program Files\Tencent\QQ\QQMagicFace.dll]  [TENCENT, 7,0,313,1681]
  331.     [D:\Program Files\Tencent\QQ\GroupConnection.dll]  [TENCENT, 7,0,313,1681]
  332.     [D:\Program Files\Tencent\QQ\AddrSearch.dll]  [腾讯科技(深圳)有限公司, 2, 1, 9, 93]
  333.     [C:\windows\system32\SOGOUPY.IME]  [Sohu.com Inc., 3, 0, 0, 0]
  334.     [C:\windows\system32\dllMergeDict.dll]  [Sogou.com Inc., 3, 0, 0, 0]
  335.     [C:\Program Files\SogouInput\Plugin\SgImeWord.dll]  [, 1, 0, 0, 31]
  336. [PID: 832][D:\Program Files\Tencent\QQ\TIMPlatform.exe]  [TENCENT, 7,0,225,1651]
  337.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  338.     [D:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
  339. [PID: 936][F:\Program Files\anit-virus\sreng\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
  340.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  341.     [F:\Program Files\anit-virus\sreng\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
  342.     [C:\windows\system32\imon.dll]  [Eset , 2, 70, 39 ]
  343.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  344.     [F:\Program Files\anit-virus\sreng\Plugins\FILEDSV.SRE]  [Smallfrogs Studio, 1, 1, 0, 20]
  345.     [F:\Program Files\anit-virus\sreng\Plugins\NWMON.SRE]  [Smallfrogs Studio, 1, 0, 0, 8]
  346.     [F:\Program Files\anit-virus\sreng\Plugins\NTFSTREAM.SRE]  [Smallfrogs Studio, 1, 0, 0, 5]
  347.     [F:\Program Files\anit-virus\sreng\Plugins\SRECXTMG.SRE]  [Smallfrogs Studio, 1, 5, 0, 55]
  348. ==================================
  349. 文件关联
  350. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  351. .EXE  OK. ["%1" %*]
  352. .COM  OK. ["%1" %*]
  353. .PIF  OK. ["%1" %*]
  354. .REG  OK. [regedit.exe "%1"]
  355. .BAT  OK. ["%1" %*]
  356. .SCR  OK. ["%1" /S]
  357. .CHM  OK. ["C:\windows\hh.exe" %1]
  358. .HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
  359. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  360. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  361. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  362. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  363. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  364. ==================================
  365. Winsock 提供者
  366. NOD32 protected [AVSDA over [MSAFD Tcpip [TCP/IP]]]
  367.     C:\windows\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  368. NOD32 protected [AVSDA over [MSAFD Tcpip [UDP/IP]]]
  369.     C:\windows\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  370. NOD32 protected [MSAFD Tcpip [RAW/IP]]
  371.     C:\windows\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  372. NOD32 protected [RSVP UDP Service Provider]
  373.     C:\windows\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  374. NOD32 protected [RSVP TCP Service Provider]
  375.     C:\windows\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  376. NOD32
  377.     C:\windows\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  378. ==================================
  379. Autorun.inf
  380. N/A
  381. ==================================
  382. HOSTS 文件
  383. 127.0.0.1  localhost
  384. 218.30.108.145  igame.sina.com.cn
  385. 218.30.108.145  xyd.igame.sina.com.cn
  386. 218.30.108.145  bxqt.igame.sina.com.cn
  387. 218.30.108.145  xjz.igame.sina.com.cn
  388. 218.30.108.145  hdw.igame.sina.com.cn
  389. 218.30.108.145  tj2.igame.sina.com.cn
  390. 218.30.108.145  dmx.igame.sina.com.cn
  391. 218.30.108.145  xmcs.igame.sina.com.cn
  392. 218.30.108.145  xjjy.igame.sina.com.cn
  393. ==================================
  394. 进程特权扫描
  395. 特殊特权被允许: SeSystemtimePrivilege [PID = 632, C:\WINDOWS\EXPLORER.EXE]
  396. 特殊特权被允许: SeDebugPrivilege [PID = 632, C:\WINDOWS\EXPLORER.EXE]
  397. 特殊特权被允许: SeLoadDriverPrivilege [PID = 632, C:\WINDOWS\EXPLORER.EXE]
  398. 特殊特权被允许: SeSystemtimePrivilege [PID = 1420, C:\PROGRAM FILES\ESET\NOD32KUI.EXE]
  399. 特殊特权被允许: SeDebugPrivilege [PID = 1420, C:\PROGRAM FILES\ESET\NOD32KUI.EXE]
  400. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1420, C:\PROGRAM FILES\ESET\NOD32KUI.EXE]
  401. 特殊特权被允许: SeSystemtimePrivilege [PID = 1672, C:\PROGRAM FILES\FENGYUN\FYFIREWALL.EXE]
  402. 特殊特权被允许: SeDebugPrivilege [PID = 1672, C:\PROGRAM FILES\FENGYUN\FYFIREWALL.EXE]
  403. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1672, C:\PROGRAM FILES\FENGYUN\FYFIREWALL.EXE]
  404. 特殊特权被允许: SeSystemtimePrivilege [PID = 1860, D:\JCB_XYZQ\TDXW.EXE]
  405. 特殊特权被允许: SeDebugPrivilege [PID = 1860, D:\JCB_XYZQ\TDXW.EXE]
  406. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1860, D:\JCB_XYZQ\TDXW.EXE]
  407. 特殊特权被允许: SeSystemtimePrivilege [PID = 1108, D:\JCB_XYZQ\WINWT.EXE]
  408. 特殊特权被允许: SeDebugPrivilege [PID = 1108, D:\JCB_XYZQ\WINWT.EXE]
  409. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1108, D:\JCB_XYZQ\WINWT.EXE]
  410. 特殊特权被允许: SeSystemtimePrivilege [PID = 1812, D:\JCB_XYZQ\WINWT.EXE]
  411. 特殊特权被允许: SeDebugPrivilege [PID = 1812, D:\JCB_XYZQ\WINWT.EXE]
  412. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1812, D:\JCB_XYZQ\WINWT.EXE]
  413. 特殊特权被允许: SeSystemtimePrivilege [PID = 1660, D:\JCB_XYZQ\WINWT.EXE]
  414. 特殊特权被允许: SeDebugPrivilege [PID = 1660, D:\JCB_XYZQ\WINWT.EXE]
  415. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1660, D:\JCB_XYZQ\WINWT.EXE]
  416. 特殊特权被允许: SeSystemtimePrivilege [PID = 832, D:\PROGRAM FILES\TENCENT\QQ\TIMPLATFORM.EXE]
  417. 特殊特权被允许: SeDebugPrivilege [PID = 832, D:\PROGRAM FILES\TENCENT\QQ\TIMPLATFORM.EXE]
  418. 特殊特权被允许: SeLoadDriverPrivilege [PID = 832, D:\PROGRAM FILES\TENCENT\QQ\TIMPLATFORM.EXE]
  419. ==================================
  420. API HOOK
  421. N/A
  422. ==================================
  423. 隐藏进程
  424. N/A
  425. ==================================
复制代码
PS:TDXW.EXE是证券的行情,winwt是交易的


附上可疑文件

[ 本帖最后由 拍黄瓜 于 2007-7-12 12:50 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
光影
发表于 2007-7-12 13:13:14 | 显示全部楼层
一切正常!
童年
头像被屏蔽
发表于 2007-7-12 15:26:01 | 显示全部楼层
黄瓜的电脑是保密局用的吗,防护软件这么多。。。。。。
逝去の小丑 该用户已被删除
 楼主| 发表于 2007-7-12 15:54:15 | 显示全部楼层
不是保密局`
wangjay1980
发表于 2007-7-12 16:19:31 | 显示全部楼层
建议格盘重装
逝去の小丑 该用户已被删除
 楼主| 发表于 2007-7-12 17:00:06 | 显示全部楼层
为什么啊
Oceanzd
发表于 2007-7-13 03:45:16 | 显示全部楼层
没有任何问题
风雪
发表于 2007-7-13 07:42:43 | 显示全部楼层
日志没有问题。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-26 07:46 , Processed in 0.134373 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表