查看: 1443|回复: 7
收起左侧

[已解决] 开机多了1~2个进程

 关闭 [复制链接]
景圣临
发表于 2007-7-21 09:47:26 | 显示全部楼层 |阅读模式
是不是中马了?

扫描日志如下:

  1. 2007-07-21,09:39:28

  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs (http://www.KZTechs.com)

  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描


  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  18. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  19.     <load><>  [N/A]
  20. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  21.     <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
  22.     <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
  23.     <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
  24.     <Memory Saviour><D:\工具\MemorySaviour\MemorySaviour.exe /autorun>  []
  25.     <PcBoost><"C:\Program Files\PcBoost\PcBoost.exe" /start>  [(Verified)PGWARE LLC]
  26.     <AVP><"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe">  [(Verified)Kaspersky Lab]
  27. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  28.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  29.     <Userinit><C:\WINDOWS\system32\Userinit.exe>  [(Verified)Microsoft Windows Publisher]
  30. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  31.     <AppInit_DLLs><C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll>  [(Verified)Kaspersky Lab]
  32. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  33.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
  34. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  35.     <{57B86673-276A-48B2-BAE7-C6DBB3020EB8}><C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll>  [(Verified)GRISOFT LTD]
  36. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  37.     <WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll>  [(Verified)Kaspersky Lab]
  38. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
  39.     <IE7 Uninstall Stub><C:\WINDOWS\system32\ieudinit.exe>  [(Verified)Microsoft Windows Component Publisher]
  40. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  41.     <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
  42. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  43.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
  44. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  45.     <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
  46. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
  47.     <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
  48. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
  49.     <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
  50. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  51.     <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
  52. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  53.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]

  54. ==================================
  55. 启动文件夹
  56. N/A

  57. ==================================
  58. 服务
  59. [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
  60.   <C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe><GRISOFT s.r.o.>
  61. [Kaspersky Internet Security 7.0 / AVP][Running/Auto Start]
  62.   <"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" -r><Kaspersky Lab>
  63. [InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
  64.   <"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
  65. [NVIDIA Display Driver Service / NVSvc][Stopped/Manual Start]
  66.   <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>

  67. ==================================
  68. 驱动程序
  69. [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
  70.   <\??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys><N/A>
  71. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  72.   <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
  73. [Broadcom NetXtreme Gigabit Ethernet / b57w2k][Running/Manual Start]
  74.   <system32\DRIVERS\b57xp32.sys><Broadcom Corporation>
  75. [Broadcom Advanced Server Program Driver / Blfp][Stopped/Manual Start]
  76.   <system32\DRIVERS\baspxp32.sys><Broadcom Corporation>
  77. [Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
  78.   <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
  79. [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
  80.   <system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
  81. [KAVBootC / KAVBootC][Running/Boot Start]
  82.   <\SystemRoot\system32\Drivers\KAVBootC.sys><Kingsoft Corporation>
  83. [kl1 / kl1][Running/Boot Start]
  84.   <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
  85. [klif / klif][Running/System Start]
  86.   <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
  87. [Kaspersky Anti-Virus NDIS Filter / klim5][Running/Manual Start]
  88.   <system32\DRIVERS\klim5.sys><Kaspersky Lab>
  89. [nv / nv][Running/Manual Start]
  90.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  91. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  92.   <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  93. [QuakeDRV / QuakeDRV][Running/Boot Start]
  94.   <\SystemRoot\system32\DRIVERS\quakedrv.sys><N/A>
  95. [Secdrv / Secdrv][Stopped/Manual Start]
  96.   <System32\DRIVERS\secdrv.sys><N/A>
  97. [sptd / sptd][Running/Boot Start]
  98.   <\SystemRoot\System32\Drivers\sptd.sys><N/A>

  99. ==================================
  100. 浏览器加载项
  101. [ThunderAtOnce Class]
  102.   {01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
  103. [FGCatchUrl]
  104.   {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <C:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
  105. [Thunder Browser Helper]
  106.   {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  107. [FlashGet GetFlash Class]
  108.   {F156768E-81EF-470C-9057-481BA8380DBA} <C:\Program Files\FlashGet\getflash.dll, www.flashget.com>
  109. [启动迅雷5]
  110.   {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
  111. [Web Anti-Virus statistics]
  112.   {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll, Kaspersky Lab>
  113. [QQ]
  114.   {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
  115. [快车]
  116.   {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\Program Files\FlashGet\FlashGet.exe, FlashGet.com>
  117. [Messenger]
  118.   {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
  119. [WUWebControl Class]
  120.   {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
  121. [MUWebControl Class]
  122.   {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\system32\muweb.dll, Microsoft Corporation>
  123. [Shockwave Flash Object]
  124.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
  125. [ThunderAtOnce Class]
  126.   {01443AEC-0FD1-40FD-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
  127. [XML DOM Document]
  128.   {2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\system32\msxml3.dll, N/A>
  129. [FGCatchUrl]
  130.   {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <C:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
  131. [Thunder Agent Class]
  132.   {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
  133. [WUWebControl Class]
  134.   {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
  135. [Windows Media Player]
  136.   {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  137. [MUWebControl Class]
  138.   {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\system32\muweb.dll, Microsoft Corporation>
  139. [360SafeLive]
  140.   {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360safe.com>
  141. [Thunder Browser Helper]
  142.   {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  143. [XML DOM Document 4.0]
  144.   {88D969C0-F192-11D4-A65F-0040963251E5} <%SystemRoot%\system32\msxml4.dll, N/A>
  145. [Shockwave Flash Object]
  146.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
  147. [XML HTTP Request]
  148.   {ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\system32\msxml3.dll, N/A>
  149. [Vod Class]
  150.   {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} <C:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DapPlayer1.0.0.41.dll, XunLei>
  151. [FlashGet GetFlash Class]
  152.   {F156768E-81EF-470C-9057-481BA8380DBA} <C:\Program Files\FlashGet\getflash.dll, www.flashget.com>
  153. [XML HTTP]
  154.   {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\system32\msxml3.dll, N/A>
  155. [FGAutoLive]
  156.   {F90D830D-C175-4bbe-82C7-FF94669A4C42} <C:\Program Files\FlashGet\fgupdate.dll, www.flashget.com>
  157. [FGCatchUrl]
  158.   {FB5DA724-162B-11D3-8B9B-AA70B4B0B524} <C:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
  159. [&使用快车(FlashGet)下载]
  160.   <C:\Program Files\FlashGet\jc_link.htm, N/A>
  161. [&使用快车(FlashGet)下载全部链接]
  162.   <C:\Program Files\FlashGet\jc_all.htm, N/A>
  163. [Add to Anti-Banner]
  164.   <C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm, N/A>
  165. [上传到QQ网络硬盘]
  166.   <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
  167. [下载页面上的ED2(&K)链接]
  168.   <C:\Program Files\eMule\ed2k.html, N/A>
  169. [使用迅雷下载]
  170.   <C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
  171. [使用迅雷下载全部链接]
  172.   <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
  173. [添加到QQ自定义面板]
  174.   <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
  175. [添加到QQ表情]
  176.   <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
  177. [用QQ彩信发送该图片]
  178.   <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
  179. [用比特精灵下载(&B)]
  180.   <C:\Program Files\BitSpirit\bsurl.htm, N/A>

  181. ==================================
  182. 正在运行的进程
  183. [PID: 1032 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  184. [PID: 1108 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  185. [PID: 1132 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  186.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.123]
  187.     [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 7.0.0.123]
  188. [PID: 1176 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  189.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.123]
  190. [PID: 1188 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  191.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll]  [Kaspersky Lab, 7.0.0.123]
  192.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.123]
  193. [PID: 1348 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  194.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\adialhk.dll]  [Kaspersky Lab, 7.0.0.123]
  195. [PID: 1684 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  196.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.123]
  197. [PID: 168 / Dracula][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  198.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.123]
  199.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\scrchpg.dll]  [Kaspersky Lab, 7.0.0.123]
  200.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\adialhk.dll]  [Kaspersky Lab, 7.0.0.123]
  201.     [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
  202.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ShellEx.dll]  [Kaspersky Lab, 7.0.0.123]
  203.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.42]
  204.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.42]
  205.     [C:\Program Files\TuneUp Utilities 2007\SDShelEx-win32.dll]  [TuneUp Software GmbH, 2.0.0.4]
  206. [PID: 332 / SYSTEM][C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe]  [GRISOFT s.r.o., 7, 5, 1, 22]
  207.     [C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll]  [GRISOFT s.r.o., 4, 2, 0, 19]
  208.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.123]
  209.     [D:\工具\MemorySaviour\ClnMem.dll]  [N/A, ]
  210. [PID: 672 / Dracula][D:\工具\MemorySaviour\MemorySaviour.exe]  [N/A, ]
  211.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll]  [Kaspersky Lab, 7.0.0.123]
  212.     [D:\工具\MemorySaviour\ClnMem.dll]  [N/A, ]
  213. [PID: 680 / Dracula][C:\Program Files\PcBoost\PcBoost.exe]  [PGWARE LLC, 3.0.0.1]

  214. ==================================
  215. 文件关联
  216. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  217. .EXE  OK. ["%1" %*]
  218. .COM  OK. ["%1" %*]
  219. .PIF  OK. ["%1" %*]
  220. .REG  OK. [regedit.exe "%1"]
  221. .BAT  OK. ["%1" %*]
  222. .SCR  OK. ["%1" /S]
  223. .CHM  Error. ["hh.exe" %1]
  224. .HLP  Error. [C:\WINDOWS\system32\winhlp32.exe %1]
  225. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  226. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  227. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  228. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  229. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  230. ==================================
  231. Winsock 提供者
  232. N/A

  233. ==================================
  234. Autorun.inf
  235. N/A

  236. ==================================
  237. HOSTS 文件
  238. 127.0.0.1       localhost

  239. ==================================
  240. 进程特权扫描
  241. 特殊特权被允许: SeDebugPrivilege [PID = 672, D:\工具\MEMORYSAVIOUR\MEMORYSAVIOUR.EXE]
  242. 特殊特权被允许: SeLoadDriverPrivilege [PID = 672, D:\工具\MEMORYSAVIOUR\MEMORYSAVIOUR.EXE]

  243. ==================================
  244. API HOOK
  245. RVA  错误: LoadLibraryA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  246. RVA  错误: LoadLibraryExA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  247. RVA  错误: LoadLibraryExW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  248. RVA  错误: LoadLibraryW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
  249. RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)

  250. ==================================
  251. 隐藏进程
  252. N/A

  253. ==================================
复制代码
zhaonimm
发表于 2007-7-21 10:45:51 | 显示全部楼层
注意该项[Userinit]修改:把<C:\WINDOWS\system32\Userinit.exe>修改为<C:\WINDOWS\system32\userinit.exe,>逗号不可省略
报告中唯一可能的问题!!!
你说说  多了那两个进程呢?
Giggs
发表于 2007-7-21 10:46:16 | 显示全部楼层
没问题
景圣临
 楼主| 发表于 2007-7-21 10:46:54 | 显示全部楼层
我记得原来SVCHOST是4个。
景圣临
 楼主| 发表于 2007-7-21 10:47:27 | 显示全部楼层
谢谢。
zhaonimm
发表于 2007-7-21 10:50:19 | 显示全部楼层
4个SVCHOST是正常的 你要是优化系统做得好的话 可能到2个或者3个的 没问题!!!
景圣临
 楼主| 发表于 2007-7-21 11:11:38 | 显示全部楼层
现在是5个,,,

不过貌似没什么问题。

以前都4个,
景圣临
 楼主| 发表于 2007-7-21 13:03:06 | 显示全部楼层
昨天用AVG查出的毒,卡7挂,今天又出现了

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-26 10:05 , Processed in 0.136930 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表