查看: 1602|回复: 0
收起左侧

[求助] 请高手帮忙看看有病毒否

[复制链接]
jonck
发表于 2007-9-22 21:12:43 | 显示全部楼层 |阅读模式
今天机器突然死机,重启后系统巨慢,用ARSWP扫描出一个木马,NOD32和微点居然都没反应.请高手帮忙看看还有病毒否,还有请介绍个对木马查杀比较可靠的杀毒软件
  1. 2007-09-22,21:00:04
  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描

  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.       [(Verified)Microsoft Windows Publisher]
  18. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  19.     <; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
  20.     <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
  21.     <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
  22.     <"C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE>  [Eset ]
  23. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  24.       [(Verified)]
  25.       [(Verified)Microsoft Windows Publisher]
  26. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  27.     <>  [N/A]
  28. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  29.       [(Verified)]
  30. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  31.       [(Verified)Microsoft Windows Component Publisher]
  32. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  33.     <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
  34. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  35.     <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
  36. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  37.     <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
  38. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  39.     <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
  40. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  41.       [(Verified)Microsoft Windows Component Publisher]
  42. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  43.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
  44. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
  45.       [Microsoft Corporation]
  46. ==================================
  47. 启动文件夹
  48. N/A
  49. ==================================
  50. 服务
  51. [Adobe LM Service / Adobe LM Service][Stopped/Disabled]
  52.   <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe">
  53. [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Stopped/Manual Start]
  54.   
  55. [EPSON Printer Status Agent2 / EPSONStatusAgent2][Stopped/Disabled]
  56.   
  57. [Human Interface Device Access / HidServ][Stopped/Disabled]
  58.   %SystemRoot%\System32\hidserv.dll>
  59. [Machine Debug Manager / MDM][Stopped/Disabled]
  60.   <"C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe">
  61. [MPSVC Service / MPSVCService][Running/Auto Start]
  62.   
  63. [NOD32 Kernel Service / NOD32krn][Running/Auto Start]
  64.   <"C:\Program Files\Eset\nod32krn.exe">
  65. [NVIDIA Display Driver Service / NVSvc][Stopped/Disabled]
  66.   
  67. [Pml Driver HPZ12 / Pml Driver HPZ12][Stopped/Auto Start]
  68.   
  69. ==================================
  70. 驱动程序
  71. [81687 / 81687][Stopped/Manual Start]
  72.   <\??\C:\WINDOWS\system32\Drivers\81671.sys>
  73. [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  74.   
  75. [aeaudio / aeaudio][Running/Manual Start]
  76.   
  77. [AMON / AMON][Running/Auto Start]
  78.   <\SystemRoot\system32\drivers\amon.sys>
  79. [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
  80.   <\??\d:\AVG Anti-Spyware 7.5\guard.sys>
  81. [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  82.   
  83. [bootdrv / bootdrv][Stopped/Boot Start]
  84.   <\SystemRoot\System32\Drivers\bootdrv.sys>
  85. [Cdsys / Cdsys][Stopped/Manual Start]
  86.   <\??\C:\WINDOWS\system32\cdcd.sys>
  87. [cpuz / cpuz][Stopped/Manual Start]
  88.   <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cpuz.sys>
  89. [Creative SBLive! Gameport / ctljystk][Stopped/Manual Start]
  90.   
  91. [3Com EtherLink XL 90X Adapter Driver / EL90X][Running/Manual Start]
  92.   <3Com Corporation>
  93. [mp110001 / mp110001][Running/Auto Start]
  94.   
  95. [mp110002 / mp110002][Running/Auto Start]
  96.   
  97. [mp110003 / mp110003][Running/Boot Start]
  98.   <\SystemRoot\system32\drivers\mp110003.sys>
  99. [mp110004 / mp110004][Running/Auto Start]
  100.   
  101. [mp110005 / mp110005][Running/Manual Start]
  102.   
  103. [mp110006 / mp110006][Running/System Start]
  104.   
  105. [mp110007 / mp110007][Running/System Start]
  106.   
  107. [mp110008 / mp110008][Running/Auto Start]
  108.   
  109. [mp110009 / mp110009][Running/System Start]
  110.   
  111. [mp110010 / mp110010][Running/Boot Start]
  112.   <\SystemRoot\system32\drivers\mp110010.sys>
  113. [mp110011 / mp110011][Running/System Start]
  114.   
  115. [mp110012 / mp110012][Stopped/Manual Start]
  116.   
  117. [mp110013 / mp110013][Running/Boot Start]
  118.   <\SystemRoot\system32\drivers\mp110013.sys>
  119. [nod32drv / nod32drv][Running/System Start]
  120.   <\SystemRoot\system32\drivers\nod32drv.sys>
  121. [Netgroup Packet Filter / NPF][Stopped/Manual Start]
  122.   
  123. [npkcrypt / npkcrypt][Running/Auto Start]
  124.   <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys>
  125. [nv / nv][Running/Manual Start]
  126.   
  127. [StarForce Protection Environment Driver v6 / prodrv06][Running/System Start]
  128.   <\SystemRoot\System32\drivers\prodrv06.sys>
  129. [StarForce Protection Helper Driver v2 / prohlp02][Running/Boot Start]
  130.   <\SystemRoot\System32\drivers\prohlp02.sys>
  131. [StarForce Protection Synchronization Driver v1 / prosync1][Running/Boot Start]
  132.   <\SystemRoot\System32\drivers\prosync1.sys>
  133. [Psx Hid to Gamepad Port Enabler / PSXGamepadEnabler][Running/Manual Start]
  134.   
  135. [Psx Port Enumerator / PsxPortEnumerator][Running/Manual Start]
  136.   
  137. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  138.   
  139. [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
  140.   
  141. [Secdrv / Secdrv][Running/Auto Start]
  142.   
  143. [SFI Service / sf][Running/System Start]
  144.   
  145. [StarForce Protection Helper Driver / sfhlp01][Running/Boot Start]
  146.   <\SystemRoot\System32\drivers\sfhlp01.sys>
  147. [smwdm / smwdm][Running/Manual Start]
  148.   
  149. [sptd / sptd][Running/Boot Start]
  150.   <\SystemRoot\System32\Drivers\sptd.sys>
  151. [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  152.   
  153. [XScanPF / XScanPF][Stopped/Manual Start]
  154.   <\??\C:\Documents and Settings\Administrator\桌面\X-Scan-v3.3-cn\X-Scan-v3.3\dat\xpf.sys>
  155. [VIMICRO USB PC Camera / ZSMC301b][Running/Manual Start]
  156.   
  157. ==================================
  158. 浏览器加载项
  159. [AcroIEHlprObj Class]
  160.   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
  161. [Thunder Browser Helper]
  162.   {889D2FEB-5411-4565-8998-1DD2C5261283}
  163. [浩方对战平台]
  164.   {0A155D3C-68E2-4215-A47A-E800A446447A}
  165. [信息检索(&R)]
  166.   {92780B25-18CC-41C8-B9BE-3C9C571A8263}
  167. [Edit Class]
  168.   {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D}
  169. [SSReaderPlug]
  170.   {1DE88635-1C72-401E-B23B-93FA86D30F3B}
  171. [PowerPlr Control]
  172.   {2354A44B-3CEB-4829-9940-545B03103538}
  173. [CedarLogic.TaoXiWeb]
  174.   {B0AF7D9F-7050-4995-A21C-182AA05727CB}
  175. [Shockwave Flash Object]
  176.   {D27CDB6E-AE6D-11CF-96B8-444553540000}
  177. [AcroIEHlprObj Class]
  178.   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
  179. [Edit Class]
  180.   {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D}
  181. [iTrusPTA Class]
  182.   {1E0DFFCF-27FF-4574-849B-55007349FEDA}
  183. [Windows Media Player]
  184.   {22D6F312-B0F6-11D0-94AB-0080C74C7E95}
  185. [HTML Document]
  186.   {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\Mshtml.dll, N/A>
  187. [DHTML Edit Control Safe for Scripting for IE5]
  188.   {2D360201-FFF5-11D1-8D03-00A0C959BC0A}
  189. [XML Document]
  190.   {48123BC4-99D9-11D1-A6B3-00C04FD91555}
  191. [EditCtrl Class]
  192.   {488A4255-3236-44B3-8F27-FA1AECAA8844}
  193. [HHCtrl Object]
  194.   {52A2AAAE-085D-4187-97EA-8C30DB990436}
  195. [Shell Name Space]
  196.   {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
  197. [PowerPlayer Control]
  198.   {5EC7C511-CD0F-42E6-830C-1BD9882F3458}
  199. [StormPlayer Object]
  200.   {6BE52E1D-E586-474F-A6E2-1A85A9B4D9FB}
  201. [Windows Media Player]
  202.   {6BF52A52-394A-11D3-B153-00C04F79FAA6}
  203. [WangWangObj Class]
  204.   {6E213FC7-DD5A-4115-B7E6-D4C7838C361E}
  205. [360SafeLive]
  206.   {87515F61-A66C-4319-A0E0-D416CB8059E3}
  207. [Microsoft Web 浏览器]
  208.   {8856F961-340A-11D0-A96B-00C04FD705A2}
  209. [Thunder Browser Helper]
  210.   {889D2FEB-5411-4565-8998-1DD2C5261283}
  211. [Microsoft Scriptlet Component]
  212.   {AE24FDAE-03C6-11D1-8B76-0080C744F389}
  213. [SearchAssistantOC]
  214.   {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
  215. [RDS.DataSpace]
  216.   {BD96C556-65A3-11D0-983A-00C04FC29E36}
  217. [Tencent Safety Online Base Module]
  218.   {C09B522F-8AED-4E21-A65C-DC1AB652BAEE}
  219. [RealPlayer G2 Control]
  220.   {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA}
  221. [Shockwave Flash Object]
  222.   {D27CDB6E-AE6D-11CF-96B8-444553540000}
  223. [使用迅雷下载]
  224.   
  225. [导出到 Microsoft Excel(&X)]
  226.   
  227. [添加到QQ表情]
  228.   
  229. [添加到Vbuzzer RSS频道列表]
  230.   
  231. ==================================
  232. 正在运行的进程
  233. [PID: 516 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  234. [PID: 568 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  235. [PID: 592 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  236.     [C:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10039]
  237.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  238. [PID: 636 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  239.     [C:\WINDOWS\AppPatch\AcAdProc.dll]  [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
  240.     [C:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10039]
  241. [PID: 648 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  242.     [C:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10039]
  243.     [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 70, 39 ]
  244.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  245. [PID: 820 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  246.     [C:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10039]
  247. [PID: 1044 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  248.     [C:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10039]
  249.     [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 70, 39 ]
  250.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  251. [PID: 1396 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  252.     [C:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10039]
  253.     [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 70, 39 ]
  254.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  255. [PID: 1520 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  256.     [C:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10039]
  257. [PID: 1576 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  258.     [C:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10039]
  259.     [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 70, 39 ]
  260.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  261. [PID: 1612 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
  262.     [C:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10039]
  263.     [C:\WINDOWS\system32\EBPMON2.DLL]  [SEIKO EPSON CORPORATION, 2, 39, 0, 0]
  264.     [C:\WINDOWS\system32\hpzll4pi.dll]  [Hewlett-Packard Company, 60.061.243.00]
  265.     [C:\WINDOWS\system32\mdimon.dll]  [Microsoft Corporation, 12.3.4518.1014]
  266.     [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\hpzpp4pi.dll]  [Hewlett-Packard Corporation, 60.061.243.00]
  267.     [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll]  [Microsoft Corporation, 12.3.4518.1014]
  268. [PID: 1928 / Administrator][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  269.     [C:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10039]
  270.     [c:\documents and settings\administrator\application data\ppstream\bin\1.0.0.2\vodrc.dll]  [ppstream.com, 1.0.0.2]
  271.     [C:\WINDOWS\system32\WPDShServiceObj.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
  272.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  273.     [C:\WINDOWS\system32\PortableDeviceTypes.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
  274.     [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
  275.     [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
  276.     [C:\WINDOWS\system32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.9371]
  277.     [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.9371]
  278.     [C:\WINDOWS\system32\nvapi.dll]  [N/A, ]
  279.     [C:\WINDOWS\system32\nvshell.dll]  [, ]
  280. [PID: 440 / Administrator][C:\Program Files\Eset\nod32kui.exe]  [Eset , 2, 70, 39 ]
  281.     [C:\Program Files\Eset\nod32rui.dll]  [N/A, ]
  282.     [C:\Program Files\Eset\pu_amon.dll]  [Eset , 2, 70, 39 ]
  283.     [C:\Program Files\Eset\pr_amon.dll]  [Eset , 2, 70, 39 ]
  284.     [C:\Program Files\Eset\pu_dmon.dll]  [Eset , 2, 70, 39 ]
  285.     [C:\Program Files\Eset\pr_dmon.dll]  [N/A, ]
  286.     [C:\Program Files\Eset\pu_emon.dll]  [Eset , 2, 70, 39 ]
  287.     [C:\Program Files\Eset\pr_emon.dll]  [N/A, ]
  288.     [C:\Program Files\Eset\pu_imon.dll]  [Eset , 2, 70, 39 ]
  289.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  290.     [C:\Program Files\Eset\pu_nod32.dll]  [Eset , 2, 70, 39 ]
  291.     [C:\Program Files\Eset\pr_nod32.dll]  [Eset , 2, 70, 39 ]
  292.     [C:\Program Files\Eset\pu_upd.dll]  [Eset , 2, 70, 39 ]
  293.     [C:\Program Files\Eset\pr_upd.dll]  [N/A, ]
  294.     [C:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10039]
  295. [PID: 548 / SYSTEM][C:\Program Files\Eset\nod32krn.exe]  [Eset , 2, 70, 39 ]
  296.     [C:\Program Files\Eset\nod32krr.dll]  [Eset , 2, 70, 39 ]
  297.     [C:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10039]
  298.     [C:\Program Files\Eset\ps_amon.dll]  [Eset , 2, 70, 39 ]
  299.     [C:\Program Files\Eset\pr_amon.dll]  [Eset , 2, 70, 39 ]
  300.     [C:\Program Files\Eset\ps_dmon.dll]  [Eset , 2, 70, 39 ]
  301.     [C:\Program Files\Eset\pr_dmon.dll]  [N/A, ]
  302.     [C:\Program Files\Eset\ps_emon.dll]  [Eset , 2, 70, 39 ]
  303.     [C:\Program Files\Eset\pr_emon.dll]  [N/A, ]
  304.     [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 70, 39 ]
  305.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  306.     [C:\Program Files\Eset\ps_nod32.dll]  [Eset , 2, 70, 39 ]
  307.     [C:\Program Files\Eset\pr_nod32.dll]  [Eset , 2, 70, 39 ]
  308.     [C:\Program Files\Eset\ps_upd.dll]  [Eset , 2, 70, 39 ]
  309.     [C:\Program Files\Eset\pr_upd.dll]  [N/A, ]
  310. [PID: 712 / Administrator][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  311. [PID: 1476 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  312.     [C:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10039]
  313. [PID: 2064 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  314.     [C:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10039]
  315.     [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 70, 39 ]
  316.     [C:\Program Files\Eset\pr_imon.dll]  [N/A, ]
  317. [PID: 2136 / Administrator][G:\TOOLS\sreng2\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
  318.     [G:\TOOLS\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
  319.     [C:\Program Files\Micropoint\mp110031.dll]  [Micropoint Corporation, 1.2.10039]
  320. ==================================
  321. 文件关联
  322. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  323. .EXE  OK. ["%1" %*]
  324. .COM  OK. ["%1" %*]
  325. .PIF  OK. ["%1" %*]
  326. .REG  OK. [regedit.exe "%1"]
  327. .BAT  OK. ["%1" %*]
  328. .SCR  OK. ["%1" /S]
  329. .CHM  Error. ["hh.exe" %1]
  330. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  331. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  332. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  333. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  334. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  335. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  336. ==================================
  337. Winsock 提供者
  338. NOD32 protected [MSAFD Tcpip [TCP/IP]]
  339.     C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  340. NOD32 protected [MSAFD Tcpip [UDP/IP]]
  341.     C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  342. NOD32 protected [MSAFD Tcpip [RAW/IP]]
  343.     C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  344. NOD32 protected [RSVP UDP Service Provider]
  345.     C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  346. NOD32 protected [RSVP TCP Service Provider]
  347.     C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  348. NOD32
  349.     C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  350. ==================================
  351. Autorun.inf
  352. N/A
  353. ==================================
  354. HOSTS 文件
  355. 127.0.0.1       localhost
  356. ==================================
  357. 进程特权扫描
  358. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1928, C:\WINDOWS\EXPLORER.EXE]
  359. 特殊特权被允许: SeLoadDriverPrivilege [PID = 440, C:\PROGRAM FILES\ESET\NOD32KUI.EXE]
  360. ==================================
  361. API HOOK
  362. N/A
  363. ==================================
  364. 隐藏进程
  365. N/A
  366. ==================================
复制代码
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-11 14:22 , Processed in 0.123177 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表