附上Sreng的日志:- 2007-09-27,12:42:34
- System Repair Engineer 2.5.16.900
- Smallfrogs (http://www.KZTechs.com)
- Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
- 以下内容被选中:
- 所有的启动项目(包括注册表、启动文件夹、服务等)
- 浏览器加载项
- 正在运行的进程(包括进程模块信息)
- 文件关联
- Winsock 提供者
- Autorun.inf
- HOSTS 文件
- 进程特权扫描
- 启动项目
- 注册表
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
- [www.218.cc]
- [EQSecure]
- <"C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE> [Eset ]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- [(Verified)Microsoft Windows Publisher]
- [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <> [N/A]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- [(Verified)Microsoft Windows Publisher]
- ==================================
- 启动文件夹
- N/A
- ==================================
- 服务
- [Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
- <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe">
- [AntiVir PersonalEdition Classic Scheduler / AntiVirScheduler][Running/Auto Start]
- <"C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe">
- [AntiVir PersonalEdition Classic Guard / AntiVirService][Stopped/Disabled]
- <"C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe">
- [Ati HotKey Poller / Ati HotKey Poller][Stopped/Disabled]
-
- [ATI Smart / ATI Smart][Stopped/Disabled]
- <>
- [E6B121C2 / E6B121C2][Stopped/Auto Start]
- <>
- [EQService / EQService][Running/Auto Start]
-
- [Human Interface Device Access / HidServ][Stopped/Disabled]
- %SystemRoot%\System32\hidserv.dll>
- [NOD32 Kernel Service / NOD32krn][Running/Auto Start]
- <"C:\Program Files\Eset\nod32krn.exe">
- [SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]
-
- ==================================
- 驱动程序
- [aeaudio / aeaudio][Running/Manual Start]
-
- [AMON / AMON][Running/Auto Start]
- <\SystemRoot\system32\drivers\amon.sys>
- [ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter / AN983][Running/Manual Start]
-
- [ati2mtag / ati2mtag][Running/Manual Start]
-
- [avgio / avgio][Running/System Start]
- <\??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys>
- [avgntflt / avgntflt][Stopped/Manual Start]
- <\??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys>
- [avipbb / avipbb][Running/System Start]
-
- [EQSysSecure / EQSysSecure][Running/System Start]
- <\??\C:\WINDOWS\system32\drivers\EQSysSecure.sys>
- [FYTdifltDrv / FYTdifltDrv][Running/System Start]
- <\??\C:\Program Files\FengYun\FYTdiDrv.sys>
- [MidiSyn / MidiSyn][Stopped/Manual Start]
-
- [nod32drv / nod32drv][Running/System Start]
- <\SystemRoot\system32\drivers\nod32drv.sys>
- [Netgroup Packet Filter / NPF][Stopped/Manual Start]
-
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
-
- [Secdrv / Secdrv][Stopped/Manual Start]
-
- [SmartAVS / SmartAVS][Stopped/Manual Start]
- <\??\C:\WINDOWS\system32\drivers\SmartAVS.sys>
- [smwdm / smwdm][Running/Manual Start]
-
- [ssmdrv / ssmdrv][Running/System Start]
-
- [TAP VPN Adapter / tapvpn][Stopped/Manual Start]
-
- [viaraid / viaraid][Running/Boot Start]
- <\SystemRoot\system32\DRIVERS\viaraid.sys>
- ==================================
- 浏览器加载项
- [PowerPlr Control]
- {2354A44B-3CEB-4829-9940-545B03103538}
- [ThunderServer.WebThunder]
- {1DE5794D-B609-4A3E-9E40-22594D5BEAAC}
- [iTrusPTA Class]
- {1E0DFFCF-27FF-4574-849B-55007349FEDA}
- [Thunder Agent Class]
- {485463B7-8FB2-4B3B-B29B-8B919B0EACCE}
- [EditCtrl Class]
- {488A4255-3236-44B3-8F27-FA1AECAA8844}
- [JetCar.Netscape]
- {69C7BEA7-0A70-4291-81ED-405D19AEE270}
- [Windows Media Player]
- {6BF52A52-394A-11D3-B153-00C04F79FAA6}
- [WangWangObj Class]
- {6E213FC7-DD5A-4115-B7E6-D4C7838C361E}
- [360SafeLive]
- {87515F61-A66C-4319-A0E0-D416CB8059E3}
- [RMGetLicense Class]
- {A9FC132B-096D-460B-B7D5-1DB0FAE0C062}
- [Microsoft Scriptlet Component]
- {AE24FDAE-03C6-11D1-8B76-0080C744F389}
- [Shockwave Flash Object]
- {D27CDB6E-AE6D-11CF-96B8-444553540000}
- [使用迅雷下载]
-
- [用比特精灵下载(&B)]
-
- ==================================
- 正在运行的进程
- [PID: 456][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 508][\??\C:\windows\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 536][\??\C:\windows\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\windows\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4121]
- [C:\windows\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 580][C:\windows\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 592][C:\windows\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 732][C:\windows\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 820][C:\windows\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\windows\system32\imon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_imon.dll] [N/A, ]
- [PID: 912][C:\windows\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\windows\system32\imon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_imon.dll] [N/A, ]
- [PID: 1176][C:\windows\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
- [C:\windows\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [C:\Program Files\FengYun\fymon.dll] [www.218.cc, 1.2.3.75]
- [C:\Program Files\WINRAR\rarext.dll] [N/A, ]
- [C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll] [Avira GmbH, 7.00.00.10]
- [C:\Program Files\Avira\AntiVir PersonalEdition Classic\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0]
- [C:\Program Files\Avira\AntiVir PersonalEdition Classic\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
- [C:\Program Files\Eset\nodshex.dll] [N/A, ]
- [C:\windows\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\PROGRA~1\MICROS~2\OFFICE11\MCPS.DLL] [Microsoft Corporation, 11.0.6551]
- [PID: 1296][C:\Program Files\FengYun\FYFireWall.exe] [www.218.cc, 1.2.6.0]
- [C:\Program Files\FengYun\arpinfo.dll] [N/A, ]
- [C:\Program Files\FengYun\fymon.dll] [www.218.cc, 1.2.3.75]
- [PID: 1320][C:\Program Files\Eset\nod32kui.exe] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\nod32rui.dll] [N/A, ]
- [C:\Program Files\FengYun\fymon.dll] [www.218.cc, 1.2.3.75]
- [C:\Program Files\Eset\pu_amon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_amon.dll] [Eset , 2, 70, 16 ]
- [C:\Program Files\Eset\pu_dmon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_dmon.dll] [N/A, ]
- [C:\Program Files\Eset\pu_emon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_emon.dll] [N/A, ]
- [C:\Program Files\Eset\pu_imon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_imon.dll] [N/A, ]
- [C:\Program Files\Eset\pu_nod32.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_nod32.dll] [Eset , 2, 70, 16 ]
- [C:\Program Files\Eset\pu_upd.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_upd.dll] [N/A, ]
- [C:\windows\system32\SOGOUPY.IME] [Sohu.com Inc., 2, 0, 0, 1]
- [C:\windows\system32\dllMergeDict.dll] [N/A, ]
- [D:\SogouInput2.0f\Plugin\SgImeWord.dll] [, 1, 0, 0, 31]
- [PID: 1328][C:\windows\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\Program Files\FengYun\fymon.dll] [www.218.cc, 1.2.3.75]
- [PID: 1360][C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe] [Avira GmbH, 7.00.00.62]
- [C:\Program Files\Avira\AntiVir PersonalEdition Classic\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
- [C:\Program Files\Avira\AntiVir PersonalEdition Classic\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
- [C:\Program Files\Avira\AntiVir PersonalEdition Classic\schedr.dll] [Avira GmbH, 7.00.24.00]
- [C:\Program Files\Avira\AntiVir PersonalEdition Classic\avevtlog.dll] [Avira GmbH, 7.00.00.20]
- [C:\Program Files\Avira\AntiVir PersonalEdition Classic\sqlite3.dll] [, 3, 3, 17, 1]
- [C:\Program Files\Avira\AntiVir PersonalEdition Classic\avipc.dll] [Avira GmbH, 1.00.00.04]
- [PID: 1508][C:\Program Files\Eset\nod32krn.exe] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\nod32krr.dll] [Eset , 2, 70, 32 ]
- [C:\Program Files\Eset\ps_amon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_amon.dll] [Eset , 2, 70, 16 ]
- [C:\Program Files\Eset\ps_dmon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_dmon.dll] [N/A, ]
- [C:\Program Files\Eset\ps_emon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_emon.dll] [N/A, ]
- [C:\windows\system32\imon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_imon.dll] [N/A, ]
- [C:\Program Files\Eset\ps_nod32.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_nod32.dll] [Eset , 2, 70, 16 ]
- [C:\Program Files\Eset\ps_upd.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_upd.dll] [N/A, ]
- [PID: 1532][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] [Analog Devices, Inc., 3, 2, 6, 0]
- [PID: 1576][C:\windows\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\windows\system32\imon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_imon.dll] [N/A, ]
- [PID: 1600][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
- [PID: 324][C:\windows\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 2980][D:\反病毒文件夹\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
- [C:\Program Files\FengYun\fymon.dll] [www.218.cc, 1.2.3.75]
- [D:\反病毒文件夹\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
- [C:\windows\system32\imon.dll] [Eset , 2, 70, 39 ]
- [C:\Program Files\Eset\pr_imon.dll] [N/A, ]
- ==================================
- 文件关联
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .EXE OK. ["%1" %*]
- .COM OK. ["%1" %*]
- .PIF OK. ["%1" %*]
- .REG OK. [regedit.exe "%1"]
- .BAT OK. ["%1" %*]
- .SCR OK. ["%1" /S]
- .CHM OK. ["C:\WINDOWS\hh.exe" %1]
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
- ==================================
- Winsock 提供者
- NOD32 protected [MSAFD Tcpip [TCP/IP]]
- C:\windows\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
- NOD32 protected [MSAFD Tcpip [UDP/IP]]
- C:\windows\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
- NOD32 protected [MSAFD Tcpip [RAW/IP]]
- C:\windows\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
- NOD32 protected [RSVP UDP Service Provider]
- C:\windows\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
- NOD32 protected [RSVP TCP Service Provider]
- C:\windows\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
- NOD32
- C:\windows\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
- ==================================
- Autorun.inf
- N/A
- ==================================
- HOSTS 文件
- 127.0.0.1 localhost
- ==================================
- 进程特权扫描
- 特殊特权被允许: SeSystemtimePrivilege [PID = 1296, C:\PROGRAM FILES\FENGYUN\FYFIREWALL.EXE]
- 特殊特权被允许: SeDebugPrivilege [PID = 1296, C:\PROGRAM FILES\FENGYUN\FYFIREWALL.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 1296, C:\PROGRAM FILES\FENGYUN\FYFIREWALL.EXE]
- 特殊特权被允许: SeSystemtimePrivilege [PID = 1320, C:\PROGRAM FILES\ESET\NOD32KUI.EXE]
- 特殊特权被允许: SeDebugPrivilege [PID = 1320, C:\PROGRAM FILES\ESET\NOD32KUI.EXE]
- 特殊特权被允许: SeLoadDriverPrivilege [PID = 1320, C:\PROGRAM FILES\ESET\NOD32KUI.EXE]
- ==================================
- API HOOK
- N/A
- ==================================
- 隐藏进程
- [1309] C:\Program Files\EQSysSecure\EQSysSecure.exe
- [1401] C:\Program Files\EQSysSecure\EQService.exe
- ==================================
复制代码 |