查看: 4250|回复: 16
收起左侧

[已解决] 怀疑木马,窗口自动弹出一二秒钟自动关闭!

 关闭 [复制链接]
yzjxue
发表于 2011-10-16 10:34:49 | 显示全部楼层 |阅读模式
本帖最后由 yzjxue 于 2011-10-16 10:36 编辑

有时窗口自动跳出 1 .  2  秒 还没用看清然后就自动关闭,(窗口感觉像CMD 的窗口,不过不确定)
系统WIN7 32 位

最近有时候网速会突然变慢,网页打不开,Q显示正常。不过断网后,重新连接,重新打开浏览器又正常了!杀毒也没杀到什么
也没有发现其他什么问题!怀疑木马 ?


  1. 2011-10-11,18:36:51

  2. System Repair Engineer 2.8.4.1331
  3. Smallfrogs (http://www.KZTechs.com)

  4. Windows 7 Ultimate Edition Service Pack 1 (Build 7601) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描
  14.     计划任务
  15.     Windows 安全更新检查
  16.     API HOOK
  17.     隐藏进程


  18. 启动项目
  19. 注册表
  20. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  21.     <Sidebar><C:\Program Files\Windows Sidebar\sidebar.exe /autoRun>  [(Verified)Microsoft Windows]
  22.     <YY><; G:\Program Files\duowan\yy-3.0\yylauncher.exe>  [(Verified)Duowan Entertainment Information Technology (Beijing) Co., Ltd.]
  23. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  24.     <load><>  [N/A]
  25. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  26.     <RTHDVCPL><C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s>  [(Verified)Realtek Semiconductor Corp]
  27.     <BeatTrojanWall><C:\Program Files\木马清除大师2010安全套装\木马清除大师防火墙2010\BeatTrojanWall.exe>  [Lofocus(洛克思)安全实验室]
  28.     <!!QQKav><; F:\杀毒\qqkav.exe>  [Jsing.Net & QQKav.Com]
  29.     <Stormtray><; G:\Program Files\StormII\Stormtray.exe /Start>  [(Verified)北京暴风网际]
  30. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  31.     <shell><explorer.exe>  [(Verified)Microsoft Windows]
  32.     <Userinit><C:\Windows\system32\userinit.exe,>  [(Verified)Microsoft Windows]
  33. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  34.     <AppInit_DLLs><>  [N/A]
  35. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  36.     <WebCheck><>  [N/A]
  37. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
  38.     <Microsoft Windows Media Player><%SystemRoot%\system32\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows]
  39. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  40.     <Internet Explorer><C:\Windows\System32\ie4uinit.exe -UserIconConfig>  [(Verified)Microsoft Windows]
  41. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
  42.     <Browser Customizations><"C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP>  [(Verified)Microsoft Windows]
  43. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  44.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
  45. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  46.     <Microsoft Windows><"%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE>  [File is missing]
  47. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  48.     <Microsoft Windows Media Player><%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI>  [(Verified)Microsoft Windows]
  49. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
  50.     <Windows Desktop Update><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows]
  51. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
  52.     <Web Platform Customizations><C:\Windows\System32\ie4uinit.exe -BaseSettings>  [(Verified)Microsoft Windows]
  53. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
  54.     <N/A><C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install>  [(Verified)Microsoft Corporation]

  55. ==================================
  56. 启动文件夹
  57. N/A

  58. ==================================
  59. 服务
  60. [ICBC Daemon Service / ICBC Daemon Service][Running/Auto Start]
  61.   <C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\ICBC_WIN32\IcbcDaemon.exe><N/A>
  62. [MPAV Service / MPAVService][Running/Auto Start]
  63.   <f:\Program Files\MPAV\MPAVSvc.exe><Micropoint Corporation>
  64. [MPSVC Service / MPSVCService][Running/Auto Start]
  65.   <f:\Program Files\Micropoint\MPSvc.exe><Micropoint Corporation>
  66. [NVIDIA Driver Helper Service / NVSvc][Running/Auto Start]
  67.   <C:\Windows\system32\nvvsvc.exe><NVIDIA Corporation>
  68. [木马清除大师配置性服务 / 木马清除大师配置性服务][Stopped/Auto Start]
  69.   <C:\Program Files\木马清除大师2010安全套装\木马清除大师2010\BeatTrojanSvc.exe><Lofocus(洛克思)安全实验室>

  70. ==================================
  71. 驱动程序
  72. [adp94xx / adp94xx][Stopped/Manual Start]
  73.   <\SystemRoot\system32\drivers\adp94xx.sys><Adaptec, Inc.>
  74. [adpahci / adpahci][Stopped/Manual Start]
  75.   <\SystemRoot\system32\drivers\adpahci.sys><Adaptec, Inc.>
  76. [adpu320 / adpu320][Stopped/Manual Start]
  77.   <\SystemRoot\system32\drivers\adpu320.sys><Adaptec, Inc.>
  78. [aic78xx / aic78xx][Stopped/Manual Start]
  79.   <\SystemRoot\system32\drivers\djsvs.sys><Adaptec, Inc.>
  80. [aliide / aliide][Stopped/Manual Start]
  81.   <\SystemRoot\system32\drivers\aliide.sys><Acer Laboratories Inc.>
  82. [amdsata / amdsata][Stopped/Manual Start]
  83.   <\SystemRoot\system32\drivers\amdsata.sys><Advanced Micro Devices>
  84. [amdsbs / amdsbs][Stopped/Manual Start]
  85.   <\SystemRoot\system32\drivers\amdsbs.sys><AMD Technologies Inc.>
  86. [amdxata / amdxata][Running/Boot Start]
  87.   <\SystemRoot\system32\drivers\amdxata.sys><Advanced Micro Devices>
  88. [arc / arc][Stopped/Manual Start]
  89.   <\SystemRoot\system32\drivers\arc.sys><Adaptec, Inc.>
  90. [arcsas / arcsas][Stopped/Manual Start]
  91.   <\SystemRoot\system32\drivers\arcsas.sys><Adaptec, Inc.>
  92. [Broadcom NetXtreme II VBD / b06bdrv][Stopped/Manual Start]
  93.   <\SystemRoot\system32\drivers\bxvbdx.sys><Broadcom Corporation>
  94. [Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 / b57nd60x][Stopped/Manual Start]
  95.   <system32\DRIVERS\b57nd60x.sys><Broadcom Corporation>
  96. [BeatTrojanHelperOne / BeatTrojanHelperOne][Running/Auto Start]
  97.   <\??\C:\Program Files\木马清除大师2010安全套装\木马清除大师2010\BeatTrojanHelperOne.sys><N/A>
  98. [Brother USB Mass-Storage Lower Filter Driver / BrFiltLo][Stopped/Manual Start]
  99.   <\SystemRoot\system32\drivers\BrFiltLo.sys><Brother Industries, Ltd.>
  100. [Brother USB Mass-Storage Upper Filter Driver / BrFiltUp][Stopped/Manual Start]
  101.   <\SystemRoot\system32\drivers\BrFiltUp.sys><Brother Industries, Ltd.>
  102. [Brother MFC Serial Port Interface Driver (WDM) / Brserid][Stopped/Manual Start]
  103.   <\SystemRoot\System32\Drivers\Brserid.sys><Brother Industries Ltd.>
  104. [Brother WDM Serial driver / BrSerWdm][Stopped/Manual Start]
  105.   <\SystemRoot\System32\Drivers\BrSerWdm.sys><Brother Industries Ltd.>
  106. [Brother MFC USB Fax Only Modem / BrUsbMdm][Stopped/Manual Start]
  107.   <\SystemRoot\System32\Drivers\BrUsbMdm.sys><Brother Industries Ltd.>
  108. [Brother MFC USB Serial WDM Driver / BrUsbSer][Stopped/Manual Start]
  109.   <\SystemRoot\System32\Drivers\BrUsbSer.sys><Brother Industries Ltd.>
  110. [cmdide / cmdide][Stopped/Manual Start]
  111.   <\SystemRoot\system32\drivers\cmdide.sys><CMD Technology, Inc.>
  112. [cpuz132 / cpuz132][Stopped/Manual Start]
  113.   <\??\C:\Users\mdtx\AppData\Local\Temp\DTL132\DTL132_x32.sys><N/A>
  114. [Broadcom NetXtreme II 10 GigE VBD / ebdrv][Stopped/Manual Start]
  115.   <\SystemRoot\system32\drivers\evbdx.sys><Broadcom Corporation>
  116. [elxstor / elxstor][Stopped/Manual Start]
  117.   <\SystemRoot\system32\drivers\elxstor.sys><Emulex>
  118. [Hauppauge Consumer Infrared Receiver / hcw85cir][Stopped/Manual Start]
  119.   <\SystemRoot\system32\drivers\hcw85cir.sys><Hauppauge Computer Works, Inc.>
  120. [HpSAMD / HpSAMD][Stopped/Manual Start]
  121.   <\SystemRoot\system32\drivers\HpSAMD.sys><Hewlett-Packard Company>
  122. [HTC Device Driver / HTCAND32][Stopped/Manual Start]
  123.   <System32\Drivers\ANDROIDUSB.sys><HTC1124 Inc>
  124. [HWiNFO32/64 Kernel Driver / HWiNFO32][Running/System Start]
  125.   <\??\g:\Program Files\MyDrivers\DriverGenius2011\Mydrivers32.SYS><REALiX(tm)>
  126. [iaStorV / iaStorV][Stopped/Manual Start]
  127.   <\SystemRoot\system32\drivers\iaStorV.sys><Intel Corporation>
  128. [iirsp / iirsp][Stopped/Manual Start]
  129.   <\SystemRoot\system32\drivers\iirsp.sys><Intel Corp./ICP vortex GmbH>
  130. [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
  131.   <system32\drivers\RTKVHDA.sys><Realtek Semiconductor Corp.>
  132. [LSI_FC / LSI_FC][Stopped/Manual Start]
  133.   <\SystemRoot\system32\drivers\lsi_fc.sys><LSI Corporation>
  134. [LSI_SAS / LSI_SAS][Stopped/Manual Start]
  135.   <\SystemRoot\system32\drivers\lsi_sas.sys><LSI Corporation>
  136. [LSI_SAS2 / LSI_SAS2][Stopped/Manual Start]
  137.   <\SystemRoot\system32\drivers\lsi_sas2.sys><LSI Corporation>
  138. [LSI_SCSI / LSI_SCSI][Stopped/Manual Start]
  139.   <\SystemRoot\system32\drivers\lsi_scsi.sys><LSI Corporation>
  140. [megasas / megasas][Stopped/Manual Start]
  141.   <\SystemRoot\system32\drivers\megasas.sys><LSI Corporation>
  142. [MegaSR / MegaSR][Stopped/Manual Start]
  143.   <\SystemRoot\system32\drivers\MegaSR.sys><LSI Corporation, Inc.>
  144. [mp110001 / mp110001][Running/Auto Start]
  145.   <system32\drivers\mp110001.sys><Micropoint Corporation>
  146. [mp110002 / mp110002][Running/Auto Start]
  147.   <system32\drivers\mp110002.sys><Micropoint Corporation>
  148. [mp110003 / mp110003][Running/Boot Start]
  149.   <\SystemRoot\system32\drivers\mp110003.sys><Micropoint Corporation>
  150. [mp110004 / mp110004][Running/Auto Start]
  151.   <system32\drivers\mp110004.sys><Micropoint Corporation>
  152. [mp110005 / mp110005][Running/Manual Start]
  153.   <system32\drivers\mp110005.sys><Micropoint Corporation>
  154. [mp110006 / mp110006][Running/System Start]
  155.   <system32\DRIVERS\mp110006.sys><Micropoint Corporation>
  156. [mp110007 / mp110007][Running/System Start]
  157.   <system32\DRIVERS\mp110007.sys><Micropoint Corporation>
  158. [mp110008 / mp110008][Running/Auto Start]
  159.   <system32\drivers\mp110008.sys><Micropoint Corporation>
  160. [mp110009 / mp110009][Running/System Start]
  161.   <system32\drivers\mp110009.sys><Micropoint Corporation>
  162. [mp110010 / mp110010][Running/Boot Start]
  163.   <\SystemRoot\system32\drivers\mp110010.sys><Micropoint Corporation>
  164. [mp110011 / mp110011][Running/System Start]
  165.   <system32\drivers\mp110011.sys><Micropoint Corporation>
  166. [mp110012 / mp110012][Running/Boot Start]
  167.   <\SystemRoot\system32\drivers\mp110012.sys><Micropoint Corporation>
  168. [mp110013 / mp110013][Running/Boot Start]
  169.   <\SystemRoot\system32\drivers\mp110013.sys><Micropoint Corporation>
  170. [Micropoint Net Filter / mp110014][Running/Manual Start]
  171.   <system32\DRIVERS\mp110014.sys><Micropoint Corporation>
  172. [mp110020 / mp110020][Running/Boot Start]
  173.   <\SystemRoot\system32\drivers\mp110020.sys><Micropoint Corporation>
  174. [mp110021 / mp110021][Running/System Start]
  175.   <system32\drivers\mp110021.sys><Micropoint Corporation>
  176. [mp110022 / mp110022][Running/System Start]
  177.   <system32\drivers\mp110022.sys><Micropoint Corporation>
  178. [ATK0110 ACPI UTILITY / MTsensor][Running/Manual Start]
  179.   <system32\DRIVERS\ASACPI.sys><>
  180. [nfrd960 / nfrd960][Stopped/Manual Start]
  181.   <\SystemRoot\system32\drivers\nfrd960.sys><IBM Corporation>
  182. [Service for NVIDIA High Definition Audio Driver / NVHDA][Running/Manual Start]
  183.   <system32\drivers\nvhda32v.sys><NVIDIA Corporation>
  184. [nvlddmkm / nvlddmkm][Running/Manual Start]
  185.   <system32\DRIVERS\nvlddmkm.sys><NVIDIA Corporation>
  186. [nvraid / nvraid][Stopped/Manual Start]
  187.   <\SystemRoot\system32\drivers\nvraid.sys><NVIDIA Corporation>
  188. [nvstor / nvstor][Stopped/Manual Start]
  189.   <\SystemRoot\system32\drivers\nvstor.sys><NVIDIA Corporation>
  190. [ql2300 / ql2300][Stopped/Manual Start]
  191.   <\SystemRoot\system32\drivers\ql2300.sys><QLogic Corporation>
  192. [ql40xx / ql40xx][Stopped/Manual Start]
  193.   <\SystemRoot\system32\drivers\ql40xx.sys><QLogic Corporation>
  194. [Realtek 8167 NT Driver / RTL8167][Running/Manual Start]
  195.   <system32\DRIVERS\Rt86win7.sys><Realtek>
  196. [SiSRaid2 / SiSRaid2][Stopped/Manual Start]
  197.   <\SystemRoot\system32\drivers\SiSRaid2.sys><Silicon Integrated Systems Corp.>
  198. [SiSRaid4 / SiSRaid4][Stopped/Manual Start]
  199.   <\SystemRoot\system32\drivers\sisraid4.sys><Silicon Integrated Systems>
  200. [stexstor / stexstor][Stopped/Manual Start]
  201.   <\SystemRoot\system32\drivers\stexstor.sys><Promise Technology>
  202. [VGPU / VGPU][Stopped/Manual Start]
  203.   <System32\drivers\rdvgkmd.sys><N/A>
  204. [viaide / viaide][Stopped/Manual Start]
  205.   <\SystemRoot\system32\drivers\viaide.sys><VIA Technologies, Inc.>
  206. [vsmraid / vsmraid][Stopped/Manual Start]
  207.   <\SystemRoot\system32\drivers\vsmraid.sys><VIA Technologies Inc.,Ltd>
  208. [Look 312P / ZSMC301b][Stopped/Manual Start]
  209.   <System32\Drivers\usbVM31b.sys><VM>

  210. ==================================
  211. 浏览器加载项
  212. [ICBC Anti-Phishing class]
  213.   {BB4491A2-D11A-4c6b-91C0-B53246A3122B} <C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\ICBC_WIN32\Icbc_AntiPhishing.dll, (Signed) 中国工商银行>
  214. [Axcleanctrl Class]
  215.   {36C9539B-49D2-01C7-9C6D-10DACDFEA59C} <C:\Windows\system32\icbcclean.dll, (Signed) >
  216. [GDGetTokenInfo Class]
  217.   {3AA9CF07-DF20-48FF-98BE-DED276E40146} <C:\Windows\system32\GDREAD~1.DLL, (Signed) >
  218. [EditCtrl Class]
  219.   {488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\Windows\system32\aliedit\aliedit.dll, (Signed) >
  220. [SfEdit32 Control]
  221.   {69A5F9C4-01CB-470B-8161-CE67313E3CF4} <C:\Windows\system32\99Bill\SfEdit32.dll, (Signed) 99BILL Corp.>
  222. [AxInputControl Class]
  223.   {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\Windows\system32\InputControl.dll, (Signed) >
  224. [GDGetVer Class]
  225.   {7CCE07A5-A590-4554-B5C3-082840D7012E} <C:\Windows\DOWNLO~1\ICBC_G~1.DLL, (Signed) >
  226. [InfoSecICBCNetSign Class]
  227.   {B1FBC1AD-5644-4084-882A-0F8BA85E7506} <C:\Windows\DOWNLO~1\ICBC_N~1.DLL, (Signed) Infosec Technologies Co., Ltd.>
  228. [Shockwave Flash Object]
  229.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\system32\Macromed\Flash\Flash10u.ocx, (Signed) Adobe Systems, Inc.>
  230. [InstallHelper Class]
  231.   {1DABF8D5-8430-4985-9B7F-A30E53D709B3} <G:\绿色软件\QQ\Plugin\Com.Tencent.QQMusic\bin\QQMusic\MMInstaller.dll, (Signed) Tencent>
  232. [HTML Document]
  233.   {25336920-03F9-11CF-8FD0-00AA00686F13} <C:\Windows\System32\mshtml.dll, (Signed) Microsoft Corporation>
  234. [Axcleanctrl Class]
  235.   {36C9539B-49D2-01C7-9C6D-10DACDFEA59C} <C:\Windows\system32\icbcclean.dll, (Signed) >
  236. [GDGetTokenInfo Class]
  237.   {3AA9CF07-DF20-48FF-98BE-DED276E40146} <C:\Windows\system32\GDREAD~1.DLL, (Signed) >
  238. [EditCtrl Class]
  239.   {488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\Windows\system32\aliedit\aliedit.dll, (Signed) >
  240. [SfEdit32 Control]
  241.   {69A5F9C4-01CB-470B-8161-CE67313E3CF4} <C:\Windows\system32\99Bill\SfEdit32.dll, (Signed) 99BILL Corp.>
  242. [Windows Media Player]
  243.   {6BF52A52-394A-11D3-B153-00C04F79FAA6} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
  244. [AxInputControl Class]
  245.   {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\Windows\system32\InputControl.dll, (Signed) >
  246. [GDGetVer Class]
  247.   {7CCE07A5-A590-4554-B5C3-082840D7012E} <C:\Windows\DOWNLO~1\ICBC_G~1.DLL, (Signed) >
  248. [Microsoft Web Browser]
  249.   {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\Windows\System32\ieframe.dll, (Signed) Microsoft Corporation>
  250. [XML DOM Document 6.0]
  251.   {88D96A05-F192-11D4-A65F-0040963251E5} <%SystemRoot%\System32\msxml6.dll, (Signed) N/A>
  252. [InfoSecICBCNetSign Class]
  253.   {B1FBC1AD-5644-4084-882A-0F8BA85E7506} <C:\Windows\DOWNLO~1\ICBC_N~1.DLL, (Signed) Infosec Technologies Co., Ltd.>
  254. [Shockwave Flash Object]
  255.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Windows\system32\Macromed\Flash\Flash10u.ocx, (Signed) Adobe Systems, Inc.>
  256. [PlayerCtrl Class]
  257.   {E05BC2A3-9A46-4a32-80C9-023A473F5B23} <G:\绿色软件\QQ\Plugin\Com.Tencent.QQMusic\bin\QQMusic\QzoneMusic.dll, (Signed) Tencent>
  258. [SSOForPTLogin2 Class]
  259.   {EAAED308-7322-4B9B-965E-171933ADD473} <C:\Program Files\Common Files\Tencent\TXSSO\1.2.1.30\Bin\SSOAxCtrlForPTLogin.dll, (Signed) >
  260. [TimwpDll.TimwpCheck]
  261.   {ED4CA2E5-0EEA-44C1-AD7E-74A07A7507A4} <G:\绿色软件\QQ\Bin\Timwp.dll, (Signed) Tencent>
  262. [XML HTTP Request]
  263.   {ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
  264. [XML HTTP]
  265.   {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>

  266. ==================================
  267. 正在运行的进程
  268. [PID: 296 / SYSTEM][\SystemRoot\System32\smss.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  269. [PID: 456 / SYSTEM][C:\Windows\system32\csrss.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  270. [PID: 524 / SYSTEM][C:\Windows\system32\wininit.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  271.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  272. [PID: 532 / SYSTEM][C:\Windows\system32\csrss.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  273. [PID: 576 / SYSTEM][C:\Windows\system32\services.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  274.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  275.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师防火墙2010\BeatWall.dll]  [Lofocus(洛克思)安全实验室, 2, 0, 0, 1]
  276. [PID: 600 / SYSTEM][C:\Windows\system32\lsass.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  277. [PID: 608 / SYSTEM][C:\Windows\system32\lsm.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  278.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  279. [PID: 644 / SYSTEM][C:\Windows\system32\winlogon.exe]  [(Verified) Microsoft Corporation, 6.1.7601.17514 (win7sp1_rtm.101119-1850)]
  280. [PID: 760 / SYSTEM][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  281.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  282. [PID: 824 / SYSTEM][C:\Windows\system32\nvvsvc.exe]  [NVIDIA Corporation, 8.17.12.7080]
  283.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  284.     [C:\Program Files\NVIDIA Corporation\Display\NVXDBat.dll]  [NVIDIA Corporation, 7.17.12.7080]
  285. [PID: 968 / NETWORK SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  286.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师防火墙2010\BeatWall.dll]  [Lofocus(洛克思)安全实验室, 2, 0, 0, 1]
  287.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  288. [PID: 1096 / LOCAL SERVICE][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  289.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  290. [PID: 1480 / SYSTEM][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  291.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  292. [PID: 1608 / SYSTEM][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  293.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  294.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师防火墙2010\BeatWall.dll]  [Lofocus(洛克思)安全实验室, 2, 0, 0, 1]
  295. [PID: 1920 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  296.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  297. [PID: 128 / NETWORK SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  298.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  299. [PID: 468 / SYSTEM][C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe]  [NVIDIA Corporation, 7.17.12.7080]
  300.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  301.     [C:\Program Files\NVIDIA Corporation\Display\NVXDApiX.dll]  [NVIDIA Corporation, 7.17.12.7080]
  302.     [C:\Program Files\NVIDIA Corporation\Display\NvUI.dll]  [NVIDIA Corporation, 7.17.12.7080]
  303.     [C:\Windows\system32\nvapi.dll]  [NVIDIA Corporation, 8.17.12.7080]
  304.     [C:\Program Files\NVIDIA Corporation\Display\NVXDBat.dll]  [NVIDIA Corporation, 7.17.12.7080]
  305. [PID: 348 / SYSTEM][C:\Windows\system32\nvvsvc.exe]  [NVIDIA Corporation, 8.17.12.7080]
  306.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  307.     [C:\Windows\system32\NVSVC.DLL]  [NVIDIA Corporation, 8.17.12.7080]
  308.     [C:\Windows\system32\nvapi.dll]  [NVIDIA Corporation, 8.17.12.7080]
  309.     [C:\Windows\system32\NVSVCR.DLL]  [NVIDIA Corporation, 8.17.12.7080]
  310.     [C:\Program Files\NVIDIA Corporation\Display\NVXDBat.dll]  [NVIDIA Corporation, 7.17.12.7080]
  311.     [C:\Program Files\NVIDIA Corporation\Display\NVXDPlcy.dll]  [NVIDIA Corporation, 7.17.12.7080]
  312. [PID: 1708 / SYSTEM][C:\Windows\System32\spoolsv.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  313.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  314.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师防火墙2010\BeatWall.dll]  [Lofocus(洛克思)安全实验室, 2, 0, 0, 1]
  315. [PID: 1712 / SYSTEM][C:\Windows\system32\taskeng.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  316. [PID: 1980 / SYSTEM][g:\PROGRA~1\SOGOUI~1\600~1.623\SGTool.exe]  [Sogou.com Inc., 6.0.0.6236]
  317.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  318. [PID: 316 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  319.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  320.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师防火墙2010\BeatWall.dll]  [Lofocus(洛克思)安全实验室, 2, 0, 0, 1]
  321. [PID: 2164 / SYSTEM][C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\ICBC_WIN32\IcbcDaemon.exe]  [N/A, ]
  322.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  323. [PID: 2276 / SYSTEM][C:\Program Files\木马清除大师2010安全套装\木马清除大师2010\BeatTrojanShields.exe]  [Lofocus(洛克思)安全实验室, 4, 6, 0, 0]
  324.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  325. [PID: 2772 / NETWORK SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  326.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  327.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师防火墙2010\BeatWall.dll]  [Lofocus(洛克思)安全实验室, 2, 0, 0, 1]
  328. [PID: 2964 / mdtx][C:\Windows\system32\taskhost.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  329. [PID: 3060 / mdtx][C:\Windows\system32\Dwm.exe]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  330.     [C:\Windows\system32\nvwgf2um.dll]  [NVIDIA Corporation, 8.17.12.7080]
  331. [PID: 3108 / mdtx][C:\Windows\Explorer.EXE]  [(Verified) Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  332.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  333.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师2010\BtHelpSeven.dll]  [Lofocus (洛克思)安全实验室, 6, 0, 0, 0]
  334.     [C:\Windows\system32\FXSAPI.dll]  [Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  335. [PID: 3576 / mdtx][C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe]  [Realtek Semiconductor, 1, 0, 0, 667]
  336.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  337.     [C:\Windows\system32\RTCOM\RtkCfg.dll]  [Realtek Semiconductor Corp., 1.0.0.2]
  338.     [C:\Windows\system32\RtkAPO.dll]  [Realtek Semiconductor Corp., 11, 0, 6000, 216]
  339. [PID: 3604 / mdtx][C:\Program Files\木马清除大师2010安全套装\木马清除大师防火墙2010\BeatTrojanWall.exe]  [Lofocus(洛克思)安全实验室, 2.0.0.1]
  340.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师防火墙2010\BeatWall.dll]  [Lofocus(洛克思)安全实验室, 2, 0, 0, 1]
  341.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  342.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师防火墙2010\Office2007Black.dll]  [Codejock Software, 12, 0, 1, 0]
  343.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师防火墙2010\CheckPE.dll]  [N/A, ]
  344. [PID: 3616 / mdtx][C:\Program Files\Windows Sidebar\sidebar.exe]  [Microsoft Corporation, 6.1.7600.16385 (win7_rtm.090713-1255)]
  345.     [f:\Program Files\MPAV\mp110200.dll]  [Micropoint Corporation, 1, 2, 10581, 19]
  346. [PID: 3808 / SYSTEM][C:\Windows\system32\wbem\wmiprvse.exe]  [(Verified) Microsoft Corporation, 6.1.7601.17514 (win7sp1_rtm.101119-1850)]
  347. [PID: 3932 / SYSTEM][C:\Program Files\木马清除大师2010安全套装\木马清除大师2010\BeatTrojanMon.exe]  [Lofocus(洛克思)安全实验室, 6, 0, 0, 0]
  348.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  349.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师2010\BtHelpOne.dll]  [Lofocus(洛克思)安全实验室, 4, 6, 0, 0]
  350.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师2010\EgHelperOne.dll]  [Lofocus(洛克思)安全实验室, 5, 0, 0, 0]
  351.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师2010\BtHelpThree.dll]  [Lofocus(洛克思)安全实验室, 4, 6, 0, 0]
  352.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师2010\SystemGuardDelete.dll]  [Lofocus(洛克思)安全实验室, 4, 6, 0, 0]
  353.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师2010\BtHelpEight.dll]  [Lofocus(洛克思)安全实验室, 4, 6, 0, 0]
  354.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师2010\SystemGuardHelper.dll]  [Lofocus(洛克思)安全实验室, 4, 6, 0, 0]
  355.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师2010\BtHelpTwo.dll]  [Lofocus(洛克思)安全实验室, 5, 0, 0, 0]
  356.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师2010\Office2007Black.dll]  [Codejock Software, 12, 0, 1, 0]
  357. [PID: 1748 / SYSTEM][C:\Windows\system32\SearchIndexer.exe]  [(Verified) Microsoft Corporation, 7.00.7600.16385 (win7_rtm.090713-1255)]
  358. [PID: 2500 / mdtx][C:\Windows\system32\SearchProtocolHost.exe]  [(Verified) Microsoft Corporation, 7.00.7600.16385 (win7_rtm.090713-1255)]
  359. [PID: 2488 / SYSTEM][C:\Windows\system32\SearchFilterHost.exe]  [(Verified) Microsoft Corporation, 7.00.7600.16385 (win7_rtm.090713-1255)]
  360. [PID: 3516 / mdtx][C:\Users\mdtx\AppData\Local\Temp\HZ$D.173.2516\HZ$D.173.2517\SREngLdr.EXE]  [Smallfrogs Studio, 2.8.4.1331]
  361.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  362. [PID: 3504 / mdtx][C:\Users\mdtx\AppData\Local\Temp\HZ$D.173.2516\HZ$D.173.2517\SRE2c5db0ca.EXE]  [Smallfrogs Studio, 2.8.4.1331]
  363.     [f:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 2.0.47.1498]
  364.     [C:\Program Files\木马清除大师2010安全套装\木马清除大师防火墙2010\BeatWall.dll]  [Lofocus(洛克思)安全实验室, 2, 0, 0, 1]

  365. ==================================
  366. 文件关联
  367. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  368. .EXE  OK. ["%1" %*]
  369. .COM  OK. ["%1" %*]
  370. .PIF  OK. ["%1" %*]
  371. .REG  OK. [regedit.exe "%1"]
  372. .BAT  OK. ["%1" %*]
  373. .SCR  OK. ["%1" /S]
  374. .CHM  OK. ["%SystemRoot%\hh.exe" %1]
  375. .HLP  OK. [%SystemRoot%\winhlp32.exe %1]
  376. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  377. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  378. .VBS  OK. ["%SystemRoot%\System32\WScript.exe" "%1" %*]
  379. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  380. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  381. ==================================
  382. Winsock 提供者
  383. BeatTrojanWall over [MSAFD Tcpip [TCP/IP]]
  384.     C:\Program Files\木马清除大师2010安全套装\木马清除大师防火墙2010\BeatWall.dll(Lofocus(洛克思)安全实验室, 木马清除大师防火墙组件)
  385. BeatTrojanWall over [MSAFD Tcpip [UDP/IP]]
  386.     C:\Program Files\木马清除大师2010安全套装\木马清除大师防火墙2010\BeatWall.dll(Lofocus(洛克思)安全实验室, 木马清除大师防火墙组件)
  387. BeatTrojanWall over [RSVP TCP 服务提供商]
  388.     C:\Program Files\木马清除大师2010安全套装\木马清除大师防火墙2010\BeatWall.dll(Lofocus(洛克思)安全实验室, 木马清除大师防火墙组件)
  389. BeatTrojanWall over [RSVP UDP 服务提供商]
  390.     C:\Program Files\木马清除大师2010安全套装\木马清除大师防火墙2010\BeatWall.dll(Lofocus(洛克思)安全实验室, 木马清除大师防火墙组件)
  391. BeatTrojanWall
  392.     C:\Program Files\木马清除大师2010安全套装\木马清除大师防火墙2010\BeatWall.dll(Lofocus(洛克思)安全实验室, 木马清除大师防火墙组件)

  393. ==================================
  394. Autorun.inf
  395. N/A

  396. ==================================
  397. HOSTS 文件
  398. N/A

  399. ==================================
  400. 进程特权扫描
  401. N/A

  402. ==================================
  403. 计划任务
  404. [已启用] \\Drivergenius drivers check service
  405.         g:\Program Files\MyDrivers\DriverGenius2011\DriverGenius.exe -static
  406. [已启用] \\SogouImeMgr
  407.         g:\PROGRA~1\SOGOUI~1\600~1.623\SGTool.exe --appid=pinyinrepair /S
  408. [已启用] \\WpsUpdateTask_mdtx
  409.         g:\Program Files\Kingsoft\WPS Office Personal\office6\wpsupdate.exe -from=task
  410. [已禁用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
  411.         N/A
  412. [已启用] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
  413.         N/A
  414. [已禁用] \Microsoft\Windows\AppID\PolicyConverter
  415.         %windir%\system32\appidpolicyconverter.exe
  416. [已禁用] \Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
  417.         %windir%\system32\appidcertstorecheck.exe
  418. [已启用] \Microsoft\Windows\Application Experience\AitAgent
  419.         aitagent
  420. [已启用] \Microsoft\Windows\Application Experience\ProgramDataUpdater
  421.         %windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate
  422. [已启用] \Microsoft\Windows\Autochk\Proxy
  423.         %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
  424. [已启用] \Microsoft\Windows\Bluetooth\UninstallDeviceTask
  425.         BthUdTask.exe $(Arg0)
  426. [已启用] \Microsoft\Windows\CertificateServicesClient\SystemTask
  427.         N/A
  428. [已启用] \Microsoft\Windows\CertificateServicesClient\UserTask
  429.         N/A
  430. [已禁用] \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
  431.         N/A
  432. [已启用] \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
  433.         %SystemRoot%\System32\wsqmcons.exe
  434. [已启用] \Microsoft\Windows\Defrag\ScheduledDefrag
  435.         %windir%\system32\defrag.exe -c
  436. [已启用] \Microsoft\Windows\Location\Notifications
  437.         %windir%\System32\LocationNotifications.exe
  438. [已启用] \Microsoft\Windows\Maintenance\WinSAT
  439.         N/A
  440. [已启用] \Microsoft\Windows\Media Center\ActivateWindowsSearch
  441.         %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
  442. [已启用] \Microsoft\Windows\Media Center\ConfigureInternetTimeService
  443.         %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
  444. [已启用] \Microsoft\Windows\Media Center\DispatchRecoveryTasks
  445.         %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
  446. [已启用] \Microsoft\Windows\Media Center\ehDRMInit
  447.         %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
  448. [已启用] \Microsoft\Windows\Media Center\InstallPlayReady
  449.         %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
  450. [已启用] \Microsoft\Windows\Media Center\mcupdate
  451.         %SystemRoot%\ehome\mcupdate $(Arg0)
  452. [已启用] \Microsoft\Windows\Media Center\MediaCenterRecoveryTask
  453.         %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
  454. [已启用] \Microsoft\Windows\Media Center\MediaCenterRecoveryTask
  455.         %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
  456. [已启用] \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
  457.         %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
  458. [已启用] \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
  459.         %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
  460. [已启用] \Microsoft\Windows\Media Center\OCURActivate
  461.         %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
  462. [已启用] \Microsoft\Windows\Media Center\OCURDiscovery
  463.         %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
  464. [已启用] \Microsoft\Windows\Media Center\PBDADiscovery
  465.         %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
  466. [已启用] \Microsoft\Windows\Media Center\PBDADiscoveryW1
  467.         %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
  468. [已启用] \Microsoft\Windows\Media Center\PBDADiscoveryW2
  469.         %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
  470. [已禁用] \Microsoft\Windows\Media Center\PeriodicScanRetry
  471.         %windir%\ehome\MCUpdate.exe -pscn 0
  472. [已启用] \Microsoft\Windows\Media Center\PvrRecoveryTask
  473.         %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
  474. [已启用] \Microsoft\Windows\Media Center\PvrRecoveryTask
  475.         %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
  476. [已启用] \Microsoft\Windows\Media Center\PvrScheduleTask
  477.         %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
  478. [已启用] \Microsoft\Windows\Media Center\PvrScheduleTask
  479.         %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
  480. [已禁用] \Microsoft\Windows\Media Center\RecordingRestart
  481.         %SystemRoot%\ehome\ehrec /RestartRecording
  482. [已启用] \Microsoft\Windows\Media Center\RegisterSearch
  483.         %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
  484. [已启用] \Microsoft\Windows\Media Center\ReindexSearchRoot
  485.         %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
  486. [已启用] \Microsoft\Windows\Media Center\SqlLiteRecoveryTask
  487.         %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
  488. [已启用] \Microsoft\Windows\Media Center\SqlLiteRecoveryTask
  489.         %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
  490. [已启用] \Microsoft\Windows\Media Center\StartRecording
  491.         %SystemRoot%\ehome\ehrec /StartRecording
  492. [已启用] \Microsoft\Windows\Media Center\UpdateRecordPath
  493.         %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
  494. [已启用] \Microsoft\Windows\MobilePC\HotStart
  495.         N/A
  496. [已启用] \Microsoft\Windows\MUI\LPRemove
  497.         %windir%\system32\lpremove.exe
  498. [已启用] \Microsoft\Windows\Multimedia\SystemSoundsService
  499.         N/A
  500. [已启用] \Microsoft\Windows\NetTrace\GatherNetworkInfo
  501.         %windir%\system32\gatherNetworkInfo.vbs
  502. [已禁用] \Microsoft\Windows\Offline Files\Background Synchronization
  503.         N/A
  504. [已禁用] \Microsoft\Windows\Offline Files\Logon Synchronization
  505.         N/A
  506. [已启用] \Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
  507.         %SystemRoot%\System32\powercfg.exe -energy -auto
  508. [已启用] \Microsoft\Windows\Ras\MobilityManager
  509.         N/A
  510. [已禁用] \Microsoft\Windows\SideShow\AutoWake
  511.         N/A
  512. [已启用] \Microsoft\Windows\SideShow\GadgetManager
  513.         N/A
  514. [已禁用] \Microsoft\Windows\SideShow\SessionAgent
  515.         N/A
  516. [已禁用] \Microsoft\Windows\SideShow\SystemDataProviders
  517.         N/A
  518. [已启用] \Microsoft\Windows\SystemRestore\SR
  519.         %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
  520. [已启用] \Microsoft\Windows\Tcpip\IpAddressConflict1
  521.         %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
  522. [已启用] \Microsoft\Windows\Tcpip\IpAddressConflict2
  523.         %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
  524. [已启用] \Microsoft\Windows\Time Synchronization\SynchronizeTime
  525.         %windir%\system32\sc.exe start w32time task_started
  526. [已启用] \Microsoft\Windows\UPnP\UPnPHostConfig
  527.         sc.exe config upnphost start= auto
  528. [已禁用] \Microsoft\Windows\User Profile Service\HiveUploadTask
  529.         N/A
  530. [已启用] \Microsoft\Windows\Windows Error Reporting\QueueReporting
  531.         %windir%\system32\wermgr.exe -queuereporting
  532. [已启用] \Microsoft\Windows\Windows Media Sharing\UpdateLibrary
  533.         "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
  534. [已启用] \Microsoft\Windows\WindowsBackup\ConfigNotification
  535.         %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
  536. [已禁用] \Microsoft\Windows\WindowsColorSystem\Calibration Loader
  537.         N/A

  538. ==================================
  539. Windows 安全更新检查
  540. N/A

  541. ==================================
  542. API HOOK
  543. N/A

  544. ==================================
  545. 隐藏进程
  546. N/A

  547. ==================================


复制代码
相惜,不离
发表于 2011-10-16 10:39:46 | 显示全部楼层
   告诉你一些简单的操作把。
1,查看有没有可疑进程。
2,查看开机启动项,服务什么的。
3,在你感觉电脑不正常的时候可以试试 CMD  ---  netstat -on   查看是否有可疑连接。


你还可以使用一些软件查看你加载的DLL文件什么的 去分辨他们。。






       菜鸟一个,也只有一些普通的建议,说的不好请别介意。
yzjxue
 楼主| 发表于 2011-10-16 10:47:56 | 显示全部楼层
相惜,不离 发表于 2011-10-16 10:39
告诉你一些简单的操作把。
1,查看有没有可疑进程。
2,查看开机启动项,服务什么的。

谢谢,不过不会看啊。!
相惜,不离
发表于 2011-10-16 10:50:59 | 显示全部楼层
yzjxue 发表于 2011-10-16 10:47
谢谢,不过不会看啊。!

  你是说netstat命令吗?  你打 netstat -no 之后他会把你现在的网络连接都列出来。而且 后面都会跟PID  标识出连接网络的进程    你可以在任务管理器-查看-PID  选项勾选 然后就可以在任务管理器 看出来 你的什么进程在连接网络。 然后判定可疑进程  如果没有就没有拉。。
强妈威武
发表于 2011-10-16 10:52:16 | 显示全部楼层
把Winsock重置一下,其实不行就把那个什么木马大师卸了换金山卫士,那个木马大师很鸡肋
zhou0197
发表于 2011-10-16 10:52:44 | 显示全部楼层
yzjxue 发表于 2011-10-16 10:47
谢谢,不过不会看啊。!

日志没有什么问题,建议先配合金山急救箱+windows清理助手做一下扫描,看看有无线索。CMD弹窗有无特定的触发条件?还有,看到你装了木马清除大师和qqkav,不知是否是这两个的影响?
相惜,不离
发表于 2011-10-16 10:57:02 | 显示全部楼层
  呵呵,专业的来了。LZ问问他们把。
yzjxue
 楼主| 发表于 2011-10-16 10:58:21 | 显示全部楼层
相惜,不离 发表于 2011-10-16 10:50
你是说netstat命令吗?  你打 netstat -no 之后他会把你现在的网络连接都列出来。而且 后面都会跟PID   ...

感谢我试试,! 不过我时菜鸟。联网的进程 要判断出来那些是正常的联网那些是恶意的联网 有点难度!
相惜,不离
发表于 2011-10-16 10:59:52 | 显示全部楼层
yzjxue 发表于 2011-10-16 10:58
感谢我试试,! 不过我时菜鸟。联网的进程 要判断出来那些是正常的联网那些是恶意的联网 有点难度!

  多百度,百度是个好东西、呵呵   而且 你可以把图发到论坛让人看看呗
yzjxue
 楼主| 发表于 2011-10-16 11:01:39 | 显示全部楼层
强妈威武 发表于 2011-10-16 10:52
把Winsock重置一下,其实不行就把那个什么木马大师卸了换金山卫士,那个木马大师很鸡肋

这个WINSOCK 重置 怎么操作!   这个木马清除大师应该还是又点用吧。前段时间 微点其他杀毒软件都没有杀出的木马也给他杀出了。!这二个都是买的! 微点 和木马清除大师! 金山卫士 应该不错,我想同时安装不知道会不会冲突
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-6-6 09:07 , Processed in 0.159985 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表