今天机器突然死机,重启后系统巨慢,用ARSWP扫描出一个木马,NOD32和微点居然都没反应.请高手帮忙看看还有病毒否,还有请介绍个对木马查杀比较可靠的杀毒软件- 2007-09-22,21:00:04
- System Repair Engineer 2.5.16.900
- Smallfrogs (http://www.KZTechs.com)
- Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
- 以下内容被选中:
- 所有的启动项目(包括注册表、启动文件夹、服务等)
- 浏览器加载项
- 正在运行的进程(包括进程模块信息)
- 文件关联
- Winsock 提供者
- Autorun.inf
- HOSTS 文件
- 进程特权扫描
- 启动项目
- 注册表
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
- <; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
- <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher]
- <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
- <"C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE> [Eset ]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- [(Verified)]
- [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <> [N/A]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- [(Verified)]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
- [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
- <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
- <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
- <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
- <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
- [(Verified)Microsoft Windows Component Publisher]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
- <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
- [Microsoft Corporation]
- ==================================
- 启动文件夹
- N/A
- ==================================
- 服务
- [Adobe LM Service / Adobe LM Service][Stopped/Disabled]
- <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe">
- [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Stopped/Manual Start]
-
- [EPSON Printer Status Agent2 / EPSONStatusAgent2][Stopped/Disabled]
-
- [Human Interface Device Access / HidServ][Stopped/Disabled]
- %SystemRoot%\System32\hidserv.dll>
- [Machine Debug Manager / MDM][Stopped/Disabled]
- <"C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe">
- [MPSVC Service / MPSVCService][Running/Auto Start]
-
- [NOD32 Kernel Service / NOD32krn][Running/Auto Start]
- <"C:\Program Files\Eset\nod32krn.exe">
- [NVIDIA Display Driver Service / NVSvc][Stopped/Disabled]
-
- [Pml Driver HPZ12 / Pml Driver HPZ12][Stopped/Auto Start]
-
- ==================================
- 驱动程序
- [81687 / 81687][Stopped/Manual Start]
- <\??\C:\WINDOWS\system32\Drivers\81671.sys>
- [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
-
- [aeaudio / aeaudio][Running/Manual Start]
-
- [AMON / AMON][Running/Auto Start]
- <\SystemRoot\system32\drivers\amon.sys>
- [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
- <\??\d:\AVG Anti-Spyware 7.5\guard.sys>
- [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
-
- [bootdrv / bootdrv][Stopped/Boot Start]
- <\SystemRoot\System32\Drivers\bootdrv.sys>
- [Cdsys / Cdsys][Stopped/Manual Start]
- <\??\C:\WINDOWS\system32\cdcd.sys>
- [cpuz / cpuz][Stopped/Manual Start]
- <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cpuz.sys>
- [Creative SBLive! Gameport / ctljystk][Stopped/Manual Start]
-
- [3Com EtherLink XL 90X Adapter Driver / EL90X][Running/Manual Start]
- <3Com Corporation>
- [mp110001 / mp110001][Running/Auto Start]
-
- [mp110002 / mp110002][Running/Auto Start]
-
- [mp110003 / mp110003][Running/Boot Start]
- <\SystemRoot\system32\drivers\mp110003.sys>
- [mp110004 / mp110004][Running/Auto Start]
-
- [mp110005 / mp110005][Running/Manual Start]
-
- [mp110006 / mp110006][Running/System Start]
-
- [mp110007 / mp110007][Running/System Start]
-
- [mp110008 / mp110008][Running/Auto Start]
-
- [mp110009 / mp110009][Running/System Start]
-
- [mp110010 / mp110010][Running/Boot Start]
- <\SystemRoot\system32\drivers\mp110010.sys>
- [mp110011 / mp110011][Running/System Start]
-
- [mp110012 / mp110012][Stopped/Manual Start]
-
- [mp110013 / mp110013][Running/Boot Start]
- <\SystemRoot\system32\drivers\mp110013.sys>
- [nod32drv / nod32drv][Running/System Start]
- <\SystemRoot\system32\drivers\nod32drv.sys>
- [Netgroup Packet Filter / NPF][Stopped/Manual Start]
-
- [npkcrypt / npkcrypt][Running/Auto Start]
- <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys>
- [nv / nv][Running/Manual Start]
-
- [StarForce Protection Environment Driver v6 / prodrv06][Running/System Start]
- <\SystemRoot\System32\drivers\prodrv06.sys>
- [StarForce Protection Helper Driver v2 / prohlp02][Running/Boot Start]
- <\SystemRoot\System32\drivers\prohlp02.sys>
- [StarForce Protection Synchronization Driver v1 / prosync1][Running/Boot Start]
- <\SystemRoot\System32\drivers\prosync1.sys>
- [Psx Hid to Gamepad Port Enabler / PSXGamepadEnabler][Running/Manual Start]
-
- [Psx Port Enumerator / PsxPortEnumerator][Running/Manual Start]
-
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
-
- [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
-
- [Secdrv / Secdrv][Running/Auto Start]
-
- [SFI Service / sf][Running/System Start]
-
- [StarForce Protection Helper Driver / sfhlp01][Running/Boot Start]
- <\SystemRoot\System32\drivers\sfhlp01.sys>
- [smwdm / smwdm][Running/Manual Start]
-
- [sptd / sptd][Running/Boot Start]
- <\SystemRoot\System32\Drivers\sptd.sys>
- [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
-
- [XScanPF / XScanPF][Stopped/Manual Start]
- <\??\C:\Documents and Settings\Administrator\桌面\X-Scan-v3.3-cn\X-Scan-v3.3\dat\xpf.sys>
- [VIMICRO USB PC Camera / ZSMC301b][Running/Manual Start]
-
- ==================================
- 浏览器加载项
- [AcroIEHlprObj Class]
- {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
- [Thunder Browser Helper]
- {889D2FEB-5411-4565-8998-1DD2C5261283}
- [浩方对战平台]
- {0A155D3C-68E2-4215-A47A-E800A446447A}
- [信息检索(&R)]
- {92780B25-18CC-41C8-B9BE-3C9C571A8263}
- [Edit Class]
- {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D}
- [SSReaderPlug]
- {1DE88635-1C72-401E-B23B-93FA86D30F3B}
- [PowerPlr Control]
- {2354A44B-3CEB-4829-9940-545B03103538}
- [CedarLogic.TaoXiWeb]
- {B0AF7D9F-7050-4995-A21C-182AA05727CB}
- [Shockwave Flash Object]
- {D27CDB6E-AE6D-11CF-96B8-444553540000}
- [AcroIEHlprObj Class]
- {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
- [Edit Class]
- {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D}
- [iTrusPTA Class]
- {1E0DFFCF-27FF-4574-849B-55007349FEDA}
- [Windows Media Player]
- {22D6F312-B0F6-11D0-94AB-0080C74C7E95}
- [HTML Document]
- {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\Mshtml.dll, N/A>
- [DHTML Edit Control Safe for Scripting for IE5]
- {2D360201-FFF5-11D1-8D03-00A0C959BC0A}
- [XML Document]
- {48123BC4-99D9-11D1-A6B3-00C04FD91555}
- [EditCtrl Class]
- {488A4255-3236-44B3-8F27-FA1AECAA8844}
- [HHCtrl Object]
- {52A2AAAE-085D-4187-97EA-8C30DB990436}
- [Shell Name Space]
- {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
- [PowerPlayer Control]
- {5EC7C511-CD0F-42E6-830C-1BD9882F3458}
- [StormPlayer Object]
- {6BE52E1D-E586-474F-A6E2-1A85A9B4D9FB}
- [Windows Media Player]
- {6BF52A52-394A-11D3-B153-00C04F79FAA6}
- [WangWangObj Class]
- {6E213FC7-DD5A-4115-B7E6-D4C7838C361E}
- [360SafeLive]
- {87515F61-A66C-4319-A0E0-D416CB8059E3}
- [Microsoft Web 浏览器]
- {8856F961-340A-11D0-A96B-00C04FD705A2}
- [Thunder Browser Helper]
- {889D2FEB-5411-4565-8998-1DD2C5261283}
- [Microsoft Scriptlet Component]
- {AE24FDAE-03C6-11D1-8B76-0080C744F389}
- [SearchAssistantOC]
- {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
- [RDS.DataSpace]
- {BD96C556-65A3-11D0-983A-00C04FC29E36}
- [Tencent Safety Online Base Module]
- {C09B522F-8AED-4E21-A65C-DC1AB652BAEE}
- [RealPlayer G2 Control]
- {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA}
- [Shockwave Flash Object]
- {D27CDB6E-AE6D-11CF-96B8-444553540000}
- [使用迅雷下载]
-
- [导出到 Microsoft Excel(&X)]
-
- [添加到QQ表情]
-
- [添加到Vbuzzer RSS频道列表]
-
- ==================================
- 正在运行的进程
- [PID: 516 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 568 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 592 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10039]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 636 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\AppPatch\AcAdProc.dll] [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
- [C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10039]
- [PID: 648 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10039]
- [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_imon.dll] [N/A, ]
- [PID: 820 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10039]
- [PID: 1044 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10039]
- [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_imon.dll] [N/A, ]
- [PID: 1396 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10039]
- [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_imon.dll] [N/A, ]
- [PID: 1520 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10039]
- [PID: 1576 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10039]
- [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_imon.dll] [N/A, ]
- [PID: 1612 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
- [C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10039]
- [C:\WINDOWS\system32\EBPMON2.DLL] [SEIKO EPSON CORPORATION, 2, 39, 0, 0]
- [C:\WINDOWS\system32\hpzll4pi.dll] [Hewlett-Packard Company, 60.061.243.00]
- [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 12.3.4518.1014]
- [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\hpzpp4pi.dll] [Hewlett-Packard Corporation, 60.061.243.00]
- [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 12.3.4518.1014]
- [PID: 1928 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10039]
- [c:\documents and settings\administrator\application data\ppstream\bin\1.0.0.2\vodrc.dll] [ppstream.com, 1.0.0.2]
- [C:\WINDOWS\system32\WPDShServiceObj.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [C:\WINDOWS\system32\PortableDeviceTypes.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
- [C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
- [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
- [C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.10.9371]
- [C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.10.9371]
- [C:\WINDOWS\system32\nvapi.dll] [N/A, ]
- [C:\WINDOWS\system32\nvshell.dll] [, ]
- [PID: 440 / Administrator][C:\Program Files\Eset\nod32kui.exe] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\nod32rui.dll] [N/A, ]
- [C:\Program Files\Eset\pu_amon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_amon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pu_dmon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_dmon.dll] [N/A, ]
- [C:\Program Files\Eset\pu_emon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_emon.dll] [N/A, ]
- [C:\Program Files\Eset\pu_imon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_imon.dll] [N/A, ]
- [C:\Program Files\Eset\pu_nod32.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_nod32.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pu_upd.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_upd.dll] [N/A, ]
- [C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10039]
- [PID: 548 / SYSTEM][C:\Program Files\Eset\nod32krn.exe] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\nod32krr.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10039]
- [C:\Program Files\Eset\ps_amon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_amon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\ps_dmon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_dmon.dll] [N/A, ]
- [C:\Program Files\Eset\ps_emon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_emon.dll] [N/A, ]
- [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_imon.dll] [N/A, ]
- [C:\Program Files\Eset\ps_nod32.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_nod32.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\ps_upd.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_upd.dll] [N/A, ]
- [PID: 712 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1476 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10039]
- [PID: 2064 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10039]
- [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_imon.dll] [N/A, ]
- [PID: 2136 / Administrator][G:\TOOLS\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
- [G:\TOOLS\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
- [C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10039]
- ==================================
- 文件关联
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .EXE OK. ["%1" %*]
- .COM OK. ["%1" %*]
- .PIF OK. ["%1" %*]
- .REG OK. [regedit.exe "%1"]
- .BAT OK. ["%1" %*]
- .SCR OK. ["%1" /S]
- .CHM Error. ["hh.exe" %1]
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
- ==================================
- Winsock 提供者
- NOD32 protected [MSAFD Tcpip [TCP/IP]]
- C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
- NOD32 protected [MSAFD Tcpip [UDP/IP]]
- C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
- NOD32 protected [MSAFD Tcpip [RAW/IP]]
- C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
- NOD32 protected [RSVP UDP Service Provider]
- C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
- NOD32 protected [RSVP TCP Service Provider]
- C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
- NOD32
- C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
- ==================================
- Autorun.inf
- N/A
- ==================================
- HOSTS 文件
- 127.0.0.1 localhost
- ==================================
- 进程特权扫描
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 1928, C:\WINDOWS\EXPLORER.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 440, C:\PROGRAM FILES\ESET\NOD32KUI.EXE]
- ==================================
- API HOOK
- N/A
- ==================================
- 隐藏进程
- N/A
- ==================================
复制代码 |