查看: 1663|回复: 7
收起左侧

[已解决] 帮忙看看俺的日志呗看看有木马没有?

 关闭 [复制链接]
romek
发表于 2007-8-29 13:56:13 | 显示全部楼层 |阅读模式
帮忙看看俺的日志呗看看有木马没有?


  1. 2007-08-28,17:32:42
  2. System Repair Engineer 2.3.13.690
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows XP Professional Service Pack 2 (Build 2600)
  5. - 管理权限用户 - 完整功能
  6. 以下内容被选中:
  7.     所有的启动项目(包括注册表、启动文件夹、服务等)
  8.     浏览器加载项
  9.     正在运行的进程(包括进程模块信息)
  10.     文件关联
  11.     Winsock 提供者
  12.     Autorun.inf
  13.     HOSTS 文件

  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
  18. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  19.     <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)NVIDIA Corporation]
  20.     <360Safetray><C:\Program Files\360safe\safemon\360Tray.exe /start>  [奇虎网]
  21.     <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
  22. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  23.     <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
  24.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
  25. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  26.     <AppInit_DLLs><zxhpri.dll>  [N/A]
  27. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  28.     <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
  29. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  30.     <{4FFAB213-ABCF-F421-FBA1-3FA352343214}><C:\WINDOWS\system32\wsdpri.dll>  [N/A]
  31.     <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll>  [Beijing Rising Technology Co., Ltd.]
  32.     <{8A65498A-7653-9801-1647-987114AB7F48}><C:\WINDOWS\system32\zxhpri.dll>  [N/A]
  33. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  34.     <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Corporation]
  35. ==================================
  36. 启动文件夹
  37. N/A
  38. ==================================
  39. 服务
  40. [Autodesk Licensing Service / Autodesk Licensing Service][Running/Auto Start]
  41.   <"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><Autodesk>
  42. [##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## / Bonjour Service][Running/Auto Start]
  43.   <"C:\Program Files\Bonjour\mDNSResponder.exe"><Apple Computer, Inc.>
  44. [C-DillaCdaC11BA / C-DillaCdaC11BA][Running/Auto Start]
  45.   <C:\WINDOWS\system32\drivers\CDAC11BA.EXE><Macrovision>
  46. [FLEXnet Licensing Service / FLEXnet Licensing Service][Stopped/Manual Start]
  47.   <"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"><Macrovision Europe Ltd.>
  48. [Help and Support / helpsvc][Stopped/Disabled]
  49.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A>
  50. [Human Interface Device Access / HidServ][Stopped/Disabled]
  51.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  52. [mental ray 3.5 Satellite (32-bit) / mi-raysat_3dsmax9_32][Stopped/Auto Start]
  53.   <"D:\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe"><N/A>
  54. [NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Disabled]
  55.   <C:\WINDOWS\system32\mnmsrvc.exe><N/A>
  56. [NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  57.   <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
  58. [Rising Process Communication Center / RsCCenter][Running/Auto Start]
  59.   <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
  60. [Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  61.   <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
  62. [TSECleanUpAssist / TSECleanUpAssist][Stopped/Auto Start]
  63.   <C:\WINDOWS\system32\856.com><N/A>
  64. ==================================
  65. 驱动程序
  66. [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  67.   <system32\drivers\ac97intc.sys><Intel Corporation>
  68. [BaseTDI / BaseTDI][Running/Auto Start]
  69.   <\??\C:\WINDOWS\system32\drivers\basetdi.sys><Beijing Rising Technology Co., Ltd.>
  70. [CdaC15BA / CdaC15BA][Running/Auto Start]
  71.   <\??\C:\WINDOWS\system32\drivers\CDAC15BA.SYS><Macrovision Europe Ltd>
  72. [C-Media High Definition Audio Interface / cmudax][Running/Manual Start]
  73.   <system32\drivers\cmudax.sys><C-Media Inc.>
  74. [Creative SBLive! Gameport / ctljystk][Stopped/Manual Start]
  75.   <system32\DRIVERS\ctljystk.sys><Creative Technology Ltd.>
  76. [ExpScaner / ExpScaner][Running/Auto Start]
  77.   <\??\C:\PROGRAM FILES\RISING\RAV\ExpScan.sys><>
  78. [Microsoft 用于 High Definition Audio 服务的 UAA 功能驱动程序 / HdAudAddService][Stopped/Manual Start]
  79.   <system32\drivers\HdAudio.sys><Windows (R) Server 2003 DDK provider>
  80. [Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start]
  81.   <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
  82. [HookCont / HookCont][Running/Auto Start]
  83.   <\??\C:\PROGRAM FILES\RISING\RAV\HOOKCONT.sys><Rising>
  84. [HookReg / HookReg][Running/Auto Start]
  85.   <\??\C:\PROGRAM FILES\RISING\RAV\HookReg.sys><>
  86. [HookSys / HookSys][Running/Auto Start]
  87.   <\??\C:\PROGRAM FILES\RISING\RAV\HookSys.sys><Rising>
  88. [MEMSCAN / MEMSCAN][Running/Auto Start]
  89.   <\??\C:\PROGRAM FILES\RISING\RAV\MEMSCAN.sys><Beijing Rising Technology Co., Ltd.>
  90. [ATK0110 ACPI UTILITY / MTsensor][Running/Manual Start]
  91.   <system32\DRIVERS\ASACPI.sys><>
  92. [Netgroup Packet Filter / NPF][Stopped/Manual Start]
  93.   <system32\drivers\npf.sys><CACE Technologies>
  94. [npkcrypt / npkcrypt][Stopped/Auto Start]
  95.   <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><N/A>
  96. [nv / nv][Running/Manual Start]
  97.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  98. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  99.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  100. [RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  101.   <\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising Technology Co., Ltd.>
  102. [RsNTGDI / RsNTGDI][Running/Boot Start]
  103.   <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
  104. [RSPPSYS / RSPPSYS][Running/Auto Start]
  105.   <\??\C:\PROGRAM FILES\RISING\RAV\RSPPSYS.sys><Rising>
  106. [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
  107.   <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
  108. [Secdrv / Secdrv][Stopped/Manual Start]
  109.   <system32\DRIVERS\secdrv.sys><N/A>
  110. [TCP/IP Protocol Driver / Tcpip][Running/System Start]
  111.   <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
  112. [NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller / yukonwxp][Running/Manual Start]
  113.   <system32\DRIVERS\yk51x86.sys><Marvell>
  114. ==================================
  115. 浏览器加载项
  116. [ThunderAtOnce Class]
  117.   {01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
  118. [Thunder Browser Helper]
  119.   {2F364305-AA45-47B5-9F9D-39A8B94E7EF7} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  120. [FGCatchUrl]
  121.   {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <C:\Program Files\FlashGet\jccatch_1.dll, www.flashget.com>
  122. [NavigatMon Class]
  123.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, >
  124. [gFlash Class]
  125.   {F156768E-81EF-470C-9057-481BA8380DBA} <C:\Program Files\FlashGet\getflash.dll, www.flashget.com>
  126. [启动迅雷5]
  127.   {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
  128. [Create Mobile Favorite]
  129.   {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} <D:\MICROS~1\INetRepl.dll, Microsoft Corporation>
  130. [Create Mobile Favorite]
  131.   {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} <D:\MICROS~1\INetRepl.dll, Microsoft Corporation>
  132. [信息检索(&R)]
  133.   {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
  134. [快车]
  135.   {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\Program Files\FlashGet\FlashGet.exe, FlashGet.com>
  136. [快车(FlashGet)]
  137.   {E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\Program Files\FlashGet\fgiebar.dll, Amaze Soft>
  138. [BitComet工具栏]
  139.   {3F1ABCDB-A875-46c1-8345-B72A4567E486} <C:\Program Files\BitComet\BitCometBar\BitCometBar0.6.dll, N/A>
  140. [ThunderAtOnce Class]
  141.   {01443AEC-0FD1-40FD-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
  142. [Thunder Browser Helper]
  143.   {2F364305-AA45-47B5-9F9D-39A8B94E7EF7} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  144. [FGCatchUrl]
  145.   {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <C:\Program Files\FlashGet\jccatch_1.dll, www.flashget.com>
  146. [Thunder Agent Class]
  147.   {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
  148. [360SafeLive]
  149.   {87515F61-A66C-4319-A0E0-D416CB8059E3} <C:\Program Files\360safe\live.dll, 360safe.com>
  150. [SearchAssistantOC]
  151.   {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
  152. [NavigatMon Class]
  153.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, >
  154. [Shockwave Flash Object]
  155.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  156. [Vod Class]
  157.   {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} <C:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DapPlayer_Now.dll, XunLei>
  158. [gFlash Class]
  159.   {F156768E-81EF-470C-9057-481BA8380DBA} <C:\Program Files\FlashGet\getflash.dll, www.flashget.com>
  160. [FGCatchUrl]
  161.   {FB5DA724-162B-11D3-8B9B-AA70B4B0B524} <C:\Program Files\FlashGet\jccatch_1.dll, www.flashget.com>
  162. [&使用快车(FlashGet)下载]
  163.   <C:\Program Files\FlashGet\jc_link.htm, N/A>
  164. [&使用快车(FlashGet)下载全部链接]
  165.   <C:\Program Files\FlashGet\jc_all.htm, N/A>
  166. [使用迅雷下载]
  167.   <C:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
  168. [使用迅雷下载全部链接]
  169.   <C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
  170. [导出到 Microsoft Office Excel(&X)]
  171.   <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
  172. [添加到QQ表情]
  173.   <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
  174. ==================================
  175. 正在运行的进程
  176. [PID: 572][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  177. [PID: 636][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  178. [PID: 660][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  179.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  180. [PID: 708][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  181.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  182. [PID: 720][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  183.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  184. [PID: 896][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  185.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  186. [PID: 968][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  187.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  188.     [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
  189. [PID: 1084][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  190.     [C:\WINDOWS\System32\zxhpri.dll]  [N/A, N/A]
  191. [PID: 1168][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  192.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  193. [PID: 1288][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  194.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  195.     [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
  196. [PID: 1644][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
  197.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  198.     [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
  199. [PID: 1720][C:\PROGRAM FILES\RISING\RAV\RavStub.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
  200.     [C:\PROGRAM FILES\RISING\RAV\RsCommX.dll]  [rising, 18, 0, 0, 1]
  201.     [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
  202.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  203. [PID: 1956][C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe]  [Autodesk, 2.70.000]
  204. [PID: 1992][C:\Program Files\Bonjour\mDNSResponder.exe]  [Apple Computer, Inc., 1,0,3,1]
  205.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  206. [PID: 2016][C:\WINDOWS\system32\drivers\CDAC11BA.EXE]  [Macrovision, 4.20.020]
  207. [PID: 268][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  [Microsoft Corporation, 7.00.9466]
  208.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  209. [PID: 416][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  210.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  211.     [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 16.0.0.86]
  212.     [C:\WINDOWS\system32\wsdpri.dll]  [N/A, N/A]
  213.     [C:\WINDOWS\system32\shlhook.dll]  [Beijing Rising Technology Co., Ltd., 4.0.0.9]
  214.     [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  [Autodesk, 17.0.54.110]
  215.     [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
  216.     [C:\WINDOWS\system32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.9147]
  217.     [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.9147]
  218.     [C:\WINDOWS\system32\nvapi.dll]  [N/A, N/A]
  219.     [C:\WINDOWS\system32\nvshell.dll]  [N/A, N/A]
  220.     [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
  221.     [C:\Program Files\Unlocker\UnlockerCOM.dll]  [N/A, N/A]
  222.     [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
  223.     [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
  224.     [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.1.8]
  225.     [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 3, 11]
  226.     [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll]  [, 1, 0, 0, 4]
  227.     [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
  228. [PID: 352][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.9147]
  229.     [C:\WINDOWS\system32\nvapi.dll]  [N/A, N/A]
  230.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  231. [PID: 1524][C:\Program Files\360safe\safemon\360Tray.exe]  [奇虎网, 3, 5, 2, 1001]
  232.     [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
  233.     [C:\Program Files\360safe\safemon\SafeKrnl.dll]  [奇虎网, 3, 5, 0, 1001]
  234.     [C:\Program Files\360safe\AntiAdwa.dll]  [360Safe.com, 3, 5, 1, 1001]
  235.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  236.     [C:\WINDOWS\system32\wsdpri.dll]  [N/A, N/A]
  237. [PID: 152][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  238. [PID: 164][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  239.     [C:\WINDOWS\system32\wsdpri.dll]  [N/A, N/A]
  240.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  241. [PID: 2472][C:\Program Files\Maxthon2\Maxthon.exe]  [Maxthon International ltd., 2, 0, 3, 4020]
  242.     [C:\Program Files\Maxthon2\MxExt.dll]  [N/A, N/A]
  243.     [C:\Program Files\Maxthon2\mxpp.dll]  [Maxthon, 1, 0, 0, 61]
  244.     [C:\Program Files\Maxthon2\MxSk.dll]  [Maxthon, 1, 0, 0, 119]
  245.     [C:\Program Files\Maxthon2\MxProxy2.dll]  [, 1, 0, 0, 3528]
  246.     [C:\Program Files\Maxthon2\IMxWebBoost.dll]  [Maxthon, 1, 0, 0, 67]
  247.     [C:\Program Files\Maxthon2\mxdb.dll]  [N/A, N/A]
  248.     [C:\Program Files\Maxthon2\mxsafe.dll]  [Maxthon, 1, 0, 0, 475]
  249.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  250.     [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
  251.     [C:\Program Files\Maxthon2\MxFav.dll]  [Maxthon, 1, 0, 0, 220]
  252.     [C:\Program Files\Maxthon2\maxzlib.dll]  [N/A, 1.2.3]
  253.     [C:\Program Files\Maxthon2\mxtool.dll]  [, 1, 0, 0, 1]
  254.     [C:\Program Files\Maxthon2\mxfeedU.dll]  [, 1, 0, 45, 82]
  255.     [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 16.0.0.86]
  256.     [C:\WINDOWS\system32\wsdpri.dll]  [N/A, N/A]
  257.     [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
  258.     [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
  259.     [C:\WINDOWS\system32\FREEIME.IME]  [Delphi Fan Studio, 4.00.950]
  260.     [C:\WINDOWS\system32\FOURI_M3.IME]  [北京紫光华宇软件股份有限公司, 4.0.0.5027]
  261.     [C:\WINDOWS\system32\GOOGLEPINYIN.IME]  [Google Inc., N/A]
  262.     [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
  263.     [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 3, 11]
  264.     [C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 3, 20]
  265.     [C:\WINDOWS\system32\shlhook.dll]  [Beijing Rising Technology Co., Ltd., 4.0.0.9]
  266. [PID: 2888][C:\WINDOWS\system32\wuauclt.exe]  [Microsoft Corporation, 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158)]
  267.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  268. [PID: 2632][C:\Documents and Settings\Administrator\桌面\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
  269.     [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 5, 0, 1001]
  270.     [C:\WINDOWS\system32\zxhpri.dll]  [N/A, N/A]
  271.     [C:\WINDOWS\system32\wsdpri.dll]  [N/A, N/A]
  272.     [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Computer, Inc., 1,0,3,1]
  273. ==================================
  274. 文件关联
  275. .TXT  Error. [C:\WINDOWS\notepad.exe %1]
  276. .EXE  OK. ["%1" %*]
  277. .COM  OK. ["%1" %*]
  278. .PIF  OK. ["%1" %*]
  279. .REG  OK. [regedit.exe "%1"]
  280. .BAT  OK. ["%1" %*]
  281. .SCR  OK. ["%1" /S]
  282. .CHM  Error. ["hh.exe" %1]
  283. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  284. .INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
  285. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  286. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  287. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  288. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  289. ==================================
  290. Winsock 提供者
  291. N/A
  292. ==================================
  293. Autorun.inf
  294. N/A
  295. ==================================
  296. HOSTS 文件
  297. 127.0.0.1       localhost
  298. ==================================
  299. API HOOK
  300. N/A
  301. ==================================
复制代码
david_sg
发表于 2007-8-29 14:43:35 | 显示全部楼层
把zxhpri.dl和wsdpri.dll打包发上来看看。应该是Trojan-Spy.Win32.Delf的变种。
856.com是Problem.856
chenzuo83
发表于 2007-8-29 15:03:12 | 显示全部楼层
是病毒吧?
chenzuo83
发表于 2007-8-29 15:05:39 | 显示全部楼层
闪人。,。。。。。。。。。。
shidi
发表于 2007-8-29 18:46:36 | 显示全部楼层
楼主你  07.1.04日   注册的现在才混4点经验啊
codaa
发表于 2007-8-29 18:51:54 | 显示全部楼层
[quote]原帖由 shidi 于 2007-8-29 18:46 发表
楼主你  07.1.04日   注册的现在才混4点经验啊]


楼上的不厚道啊!净揭人短。

楼主的电脑该清理一下了,这么多的插件,启动时得把机器拖死!!平时用的不嫌慢吗?
romek
 楼主| 发表于 2007-8-29 20:13:45 | 显示全部楼层
单位电脑,我都不敢上QQ。。。。。。。使用时候莫名其妙的问题很多,开机总弹出2楼说的那2个文件还有别的什么玩意要修改注册表,要彻底清理怎么弄啊,重做系统啊
shenrenrenren
头像被屏蔽
发表于 2007-8-29 21:07:09 | 显示全部楼层
还有这个,间谍,好像不是瑞星的。<{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}><C:\WINDOWS\system32\shlhook.dll>  [Beijing Rising Technology Co., Ltd.]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-21 19:32 , Processed in 0.132706 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表