查看: 1400|回复: 8
收起左侧

[已解决] 帮我看看日志有没有问题

 关闭 [复制链接]
Graybird
发表于 2007-12-4 11:20:18 | 显示全部楼层 |阅读模式
  1. 2007-12-04,11:16:18
  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描

  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  18. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  19.     <FY_FireWall><D:\FengYun\FYFireWall.exe>  [www.218.cc]
  20.     <avgnt><"F:\AntiVir\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min>  [Avira GmbH]
  21. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  22.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  23.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  24. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  25.     <AppInit_DLLs><>  [N/A]
  26. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  27.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
  28. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  29.     <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
  30. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  31.     <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
  32. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  33.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
  34. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  35.     <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
  36. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
  37.     <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
  38. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
  39.     <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
  40. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  41.     <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
  42. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  43.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
  44. [HKEY_CURRENT_USER\Control Panel\Desktop]
  45.     <SCRNSAVE.EXE><C:\WINDOWS\system32\PARTIC~1.SCR>  [Longbow Digital Arts]
  46. ==================================
  47. 启动文件夹
  48. N/A
  49. ==================================
  50. 服务
  51. [AntiVir PersonalEdition Classic Scheduler / AntiVirScheduler][Running/Auto Start]
  52.   <"F:\AntiVir\Avira\AntiVir PersonalEdition Classic\sched.exe"><Avira GmbH>
  53. [AntiVir PersonalEdition Classic Guard / AntiVirService][Running/Auto Start]
  54.   <"F:\AntiVir\Avira\AntiVir PersonalEdition Classic\avguard.exe"><Avira GmbH>
  55. [Human Interface Device Access / HidServ][Stopped/Disabled]
  56.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  57. ==================================
  58. 驱动程序
  59. [A320RAID / A320RAID][Stopped/Boot Start]
  60.   <\SystemRoot\System32\Drivers\a320raid.sys><Adaptec, Inc.>
  61. [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
  62.   <system32\drivers\ac97intc.sys><Intel Corporation>
  63. [adpu160m / adpu160m][Running/Boot Start]
  64.   <\SystemRoot\System32\Drivers\adpu160m.sys><Microsoft Corporation>
  65. [ADPU320 / ADPU320][Stopped/Boot Start]
  66.   <\SystemRoot\System32\Drivers\adpu320.sys><Adaptec, Inc.>
  67. [ahci8086 / ahci8086][Running/Boot Start]
  68.   <\SystemRoot\System32\Drivers\ahci8086.sys><ATI Technologies Inc.>
  69. [aic78u2 / aic78u2][Running/Boot Start]
  70.   <\SystemRoot\System32\Drivers\aic78u2.sys><Microsoft Corporation>
  71. [aic78xx / aic78xx][Running/Boot Start]
  72.   <\SystemRoot\System32\Drivers\aic78xx.sys><Microsoft Corporation>
  73. [AmdK8 Compatible Device / AmdK8][Stopped/Manual Start]
  74.   <System32\drivers\amdk8.sys><Advanced Micro Devices>
  75. [avgio / avgio][Running/System Start]
  76.   <\??\F:\AntiVir\Avira\AntiVir PersonalEdition Classic\avgio.sys><Avira GmbH>
  77. [avgntflt / avgntflt][Running/Manual Start]
  78.   <\??\F:\AntiVir\Avira\AntiVir PersonalEdition Classic\avgntflt.sys><Avira GmbH>
  79. [avipbb / avipbb][Running/System Start]
  80.   <system32\DRIVERS\avipbb.sys><AVIRA GmbH>
  81. [CSB6IDE / CSB6IDE][Running/Boot Start]
  82.   <\SystemRoot\System32\Drivers\csb6ide.sys><ServerWorks Corporation>
  83. [FASTTRAK / FASTTRAK][Running/Boot Start]
  84.   <\SystemRoot\System32\Drivers\fasttrak.sys><Promise Technology, Inc.>
  85. [VIA Rhine Family Fast Ethernet Adapter Driver Service / FETNDISB][Stopped/Manual Start]
  86.   <system32\DRIVERS\fetnd5b.sys><VIA Technologies, Inc.>
  87. [FTSATA2 / FTSATA2][Running/Boot Start]
  88.   <\SystemRoot\System32\Drivers\ftsata2.sys><Promise Technology, Inc.>
  89. [FYTdifltDrv / FYTdifltDrv][Running/System Start]
  90.   <\??\D:\FengYun\FYTdiDrv.sys><N/A>
  91. [HSFHWBS2 / HSFHWBS2][Running/Manual Start]
  92.   <system32\DRIVERS\HSFBS2S2.sys><Conexant Systems, Inc.>
  93. [HSF_DP / HSF_DP][Running/Manual Start]
  94.   <system32\DRIVERS\HSFDPSP2.sys><Conexant Systems, Inc.>
  95. [IASTOR / IASTOR][Running/Boot Start]
  96.   <\SystemRoot\System32\Drivers\iaStor.sys><Intel Corporation>
  97. [ITERAID / ITERAID][Stopped/Boot Start]
  98.   <\SystemRoot\System32\Drivers\iteraid.sys><Integrated Technology Express, Inc.>
  99. [JRAID / JRAID][Running/Boot Start]
  100.   <\SystemRoot\System32\Drivers\JRAID.SYS><JMicron Technology Corp.>
  101. [M5228 / M5228][Stopped/Boot Start]
  102.   <\SystemRoot\System32\Drivers\m5228.sys><ALi Corporation.>
  103. [M5281 / M5281][Running/Boot Start]
  104.   <\SystemRoot\System32\Drivers\m5281.sys><ALi Corporation>
  105. [M5289 / M5289][Running/Boot Start]
  106.   <\SystemRoot\System32\Drivers\m5289.sys><ULi Electronics Inc.>
  107. [mdmxsdk / mdmxsdk][Running/Auto Start]
  108.   <system32\DRIVERS\mdmxsdk.sys><Conexant>
  109. [NVATABUS / NVATABUS][Running/Boot Start]
  110.   <\SystemRoot\System32\Drivers\NVATABUS.SYS><NVIDIA Corporation>
  111. [Service for NVIDIA(R) nForce(TM) MIDI UART / nvmpu401][Running/Manual Start]
  112.   <system32\drivers\nvmpu401.sys><NVIDIA Corporation>
  113. [NVRAID / NVRAID][Running/Boot Start]
  114.   <\SystemRoot\System32\Drivers\NVRAID.SYS><NVIDIA Corporation>
  115. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  116.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  117. [Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Running/Manual Start]
  118.   <system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
  119. [Secdrv / Secdrv][Stopped/Manual Start]
  120.   <system32\DRIVERS\secdrv.sys><N/A>
  121. [SI3112R / SI3112R][Stopped/Boot Start]
  122.   <\SystemRoot\System32\Drivers\SI3112r.sys><Silicon Image, Inc>
  123. [SI3114R / SI3114R][Stopped/Boot Start]
  124.   <\SystemRoot\SYSTEM32\Drivers\SI3114R.sys><Silicon Image, Inc>
  125. [SI3114R5 / SI3114R5][Stopped/Boot Start]
  126.   <\SystemRoot\System32\Drivers\Si3114r5.sys><Silicon Image, Inc>
  127. [SI3124 / SI3124][Stopped/Boot Start]
  128.   <\SystemRoot\SYSTEM32\Drivers\SI3124.sys><Silicon Image, Inc.>
  129. [SI3124R / SI3124R][Stopped/Boot Start]
  130.   <\SystemRoot\SYSTEM32\Drivers\SI3124R.sys><Silicon Image, Inc>
  131. [SI3124R5 / SI3124R5][Stopped/Boot Start]
  132.   <\SystemRoot\SYSTEM32\Drivers\Si3124r5.sys><Silicon Image, Inc>
  133. [SI3132 / SI3132][Stopped/Boot Start]
  134.   <\SystemRoot\System32\Drivers\SI3132.sys><Silicon Image, Inc.>
  135. [SI3132R5 / SI3132R5][Stopped/Boot Start]
  136.   <\SystemRoot\System32\Drivers\Si3132r5.sys><Silicon Image, Inc>
  137. [SiS315 / SiS315][Running/Manual Start]
  138.   <system32\DRIVERS\sisgrp.sys><Silicon Integrated Systems Corporation>
  139. [SISRAID2 / SISRAID2][Stopped/Boot Start]
  140.   <\SystemRoot\System32\Drivers\SiSRaid2.sys><Silicon Integrated Systems Corp>
  141. [SISRAID4 / SISRAID4][Stopped/Boot Start]
  142.   <\SystemRoot\System32\Drivers\SiSRaid4.sys><Silicon Integrated Systems>
  143. [ssmdrv / ssmdrv][Running/System Start]
  144.   <system32\DRIVERS\ssmdrv.sys><Avira GmbH>
  145. [SYMMPI / SYMMPI][Stopped/Boot Start]
  146.   <\SystemRoot\System32\Drivers\symmpi.sys><LSI Logic>
  147. [sym_hi / sym_hi][Running/Boot Start]
  148.   <\SystemRoot\System32\Drivers\sym_hi.sys><LSI Logic>
  149. [sym_u3 / sym_u3][Running/Boot Start]
  150.   <\SystemRoot\System32\Drivers\sym_u3.sys><LSI Logic>
  151. [ULSATA / ULSATA][Running/Boot Start]
  152.   <\SystemRoot\System32\Drivers\ulsata.sys><Promise Technology, Inc.>
  153. [ULSATA2 / ULSATA2][Running/Boot Start]
  154.   <\SystemRoot\System32\Drivers\ulsata2.sys><Promise Technology, Inc.>
  155. [VIAMRAID / VIAMRAID][Stopped/Boot Start]
  156.   <\SystemRoot\System32\Drivers\viamraid.sys><VIA Technologies inc,.ltd>
  157. [vmscsi / vmscsi][Stopped/Boot Start]
  158.   <\SystemRoot\System32\Drivers\vmscsi.sys><VMware, Inc.>
  159. [winachsf / winachsf][Running/Manual Start]
  160.   <system32\DRIVERS\HSFCXTS2.sys><Conexant Systems, Inc.>
  161. ==================================
  162. 浏览器加载项
  163. [雨林木风]
  164.   {7550D5D5-D85C-414F-B623-0AD223AEC216} <http://www.ylmf.com, N/A>
  165. [Windows Genuine Advantage Validation Tool]
  166.   {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, Microsoft Corporation>
  167. [WUWebControl Class]
  168.   {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
  169. [导出到 Microsoft Office Excel(&X)]
  170.   <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
  171. [添加到QQ表情]
  172.   <E:\QQ\AddEmotion.htm, N/A>
  173. ==================================
  174. 正在运行的进程
  175. [PID: 432 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  176. [PID: 492 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  177. [PID: 516 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  178.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  179. [PID: 560 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  180. [PID: 572 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  181. [PID: 708 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  182. [PID: 776 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  183. [PID: 840 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  184. [PID: 900 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  185. [PID: 972 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  186. [PID: 1172 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
  187. [PID: 1208 / SYSTEM][F:\AntiVir\Avira\AntiVir PersonalEdition Classic\avguard.exe]  [Avira GmbH, 7.00.00.82]
  188.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\avgio.dll]  [Avira GmbH, 7.00.00.01]
  189.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\avevtlog.dll]  [Avira GmbH, 7.00.00.20]
  190.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\guardmsg.dll]  [Avira GmbH, 7.00.11.00]
  191.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\sqlite3.dll]  [, 3, 3, 17, 1]
  192.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  193.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\AVPREF.DLL]  [Avira GmbH, 7.00.02.02]
  194.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\SMTPLIB.DLL]  [Avira GmbH, 1.02.00.17]
  195.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\AVPACK32.DLL]  [Avira GmbH, 7.03.00.15]
  196.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\unacev2.dll]  [N/A, ]
  197.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\avipc.dll]  [Avira GmbH, 1.00.00.04]
  198.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\AVEWIN32.DLL]  [Avira GmbH, 7.6.0.34]
  199. [PID: 1396 / Administrator][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  200.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  201.     [D:\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  202.     [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
  203.     [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
  204.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\shlext.dll]  [Avira GmbH, 7.00.00.10]
  205.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
  206.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  207.     [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.3790.3646 built by: DNSRV(bld4act)]
  208. [PID: 1548 / Administrator][D:\FengYun\FYFireWall.exe]  [www.218.cc, 1.2.6.0]
  209.     [D:\FengYun\arpinfo.dll]  [N/A, ]
  210.     [D:\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  211. [PID: 1556 / Administrator][F:\AntiVir\Avira\AntiVir PersonalEdition Classic\avgnt.exe]  [Avira GmbH, 7.02.00.16]
  212.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
  213.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  214.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\cclib.dll]  [Avira GmbH, 7.02.00.03]
  215.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
  216.     [f:\antivir\avira\antivir personaledition classic\ccgen.dll]  [Avira GmbH, 7.02.00.10]
  217.     [f:\antivir\avira\antivir personaledition classic\ccgenrc.dll]  [Avira GmbH, 7.02.04.02]
  218.     [f:\antivir\avira\antivir personaledition classic\ccguard.dll]  [Avira GmbH, 7.00.01.35]
  219.     [f:\antivir\avira\antivir personaledition classic\ccgrdrc.dll]  [Avira GmbH, 7.00.06.00]
  220.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\avipc.dll]  [Avira GmbH, 1.00.00.04]
  221.     [f:\antivir\avira\antivir personaledition classic\ccupdate.dll]  [Avira GmbH, 7.02.00.04]
  222.     [f:\antivir\avira\antivir personaledition classic\ccupdrc.dll]  [Avira GmbH, 7.02.01.00]
  223.     [f:\antivir\avira\antivir personaledition classic\cclic.dll]  [Avira GmbH, 7.02.00.04]
  224.     [f:\antivir\avira\antivir personaledition classic\cclicrc.dll]  [Avira GmbH, 7.02.01.00]
  225.     [f:\antivir\avira\antivir personaledition classic\ccmsg.dll]  [Avira GmbH, 7.00.00.00]
  226.     [D:\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  227. [PID: 1564 / Administrator][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  228.     [D:\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  229. [PID: 348 / SYSTEM][F:\AntiVir\Avira\AntiVir PersonalEdition Classic\sched.exe]  [Avira GmbH, 7.00.00.62]
  230.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  231.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
  232.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\schedr.dll]  [Avira GmbH, 7.00.24.00]
  233.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\avevtlog.dll]  [Avira GmbH, 7.00.00.20]
  234.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\sqlite3.dll]  [, 3, 3, 17, 1]
  235.     [F:\AntiVir\Avira\AntiVir PersonalEdition Classic\avipc.dll]  [Avira GmbH, 1.00.00.04]
  236. [PID: 1404 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  237. [PID: 3476 / Administrator][D:\TW\TheWorld 2.0\TheWorld.exe]  [Phoenix Studio, 2, 1, 0, 1]
  238.     [D:\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  239.     [D:\TW\THEWOR~1.0\Plugin\SysState\SysState.dll]  [Phoenix Stdio, 1, 0, 0, 7]
  240.     [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.5510]
  241.     [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
  242.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  243.     [C:\WINDOWS\system32\msdmo.dll]  [, ]
  244.     [C:\WINDOWS\system32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
  245.     [C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx]  [Adobe Systems, Inc., 9,0,47,0]
  246. [PID: 2420 / Administrator][E:\sreng\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
  247.     [D:\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  248.     [E:\sreng\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
  249. ==================================
  250. 文件关联
  251. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  252. .EXE  OK. ["%1" %*]
  253. .COM  OK. ["%1" %*]
  254. .PIF  OK. ["%1" %*]
  255. .REG  OK. [regedit.exe "%1"]
  256. .BAT  OK. ["%1" %*]
  257. .SCR  OK. ["%1" /S]
  258. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  259. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  260. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  261. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  262. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  263. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  264. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  265. ==================================
  266. Winsock 提供者
  267. N/A
  268. ==================================
  269. Autorun.inf
  270. N/A
  271. ==================================
  272. HOSTS 文件
  273. 127.0.0.1       localhost
  274. ==================================
  275. 进程特权扫描
  276. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1208, F:\ANTIVIR\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\AVGUARD.EXE]
  277. 特殊特权被允许: SeSystemtimePrivilege [PID = 1548, D:\FENGYUN\FYFIREWALL.EXE]
  278. 特殊特权被允许: SeDebugPrivilege [PID = 1548, D:\FENGYUN\FYFIREWALL.EXE]
  279. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1548, D:\FENGYUN\FYFIREWALL.EXE]
  280. 特殊特权被允许: SeSystemtimePrivilege [PID = 1556, F:\ANTIVIR\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\AVGNT.EXE]
  281. 特殊特权被允许: SeDebugPrivilege [PID = 1556, F:\ANTIVIR\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\AVGNT.EXE]
  282. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1556, F:\ANTIVIR\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\AVGNT.EXE]
  283. 特殊特权被允许: SeSystemtimePrivilege [PID = 3476, D:\TW\THEWORLD 2.0\THEWORLD.EXE]
  284. 特殊特权被允许: SeDebugPrivilege [PID = 3476, D:\TW\THEWORLD 2.0\THEWORLD.EXE]
  285. 特殊特权被允许: SeLoadDriverPrivilege [PID = 3476, D:\TW\THEWORLD 2.0\THEWORLD.EXE]
  286. ==================================
  287. API HOOK
  288. N/A
  289. ==================================
  290. 隐藏进程
  291. N/A
  292. ==================================
复制代码

[ 本帖最后由 Graybird 于 2007-12-4 11:58 编辑 ]
wj321314
发表于 2007-12-4 11:26:15 | 显示全部楼层
沙发都没人坐啦????

偶看不懂!
command
发表于 2007-12-4 11:28:34 | 显示全部楼层
日志没有问题啊!

评分

参与人数 1经验 +2 收起 理由
etly + 2 感谢支持,欢迎常来: )

查看全部评分

fzhaaaa
头像被屏蔽
发表于 2007-12-4 11:42:03 | 显示全部楼层
吐血~~~~日志看太多头晕~
伊の星
发表于 2007-12-4 11:47:59 | 显示全部楼层
原帖由 command 于 2007-12-4 11:28 发表
日志没有问题啊!

日志确实没什么问题,
楼主维护得真好
Graybird
 楼主| 发表于 2007-12-4 11:52:32 | 显示全部楼层

回复 5楼 etly 的帖子

没问题~ 我就放心了~
jpzy
发表于 2007-12-4 11:59:40 | 显示全部楼层
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
这里似乎是启动后安装一个Active控件,安装文件在系统文件夹system32下面,文件名叫shmgrate.exe,请你确定这个东西没问题!
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
这里跟上面一样,是安装这个控件到Outlook Express!
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
这个不知道是做什么的!你是不是自己安装什么美化界面了?!我记得windows的主题控件是uxthemes.dll,不知道这个启动就注册的themeui.dll是什么东西!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
对了,你是不是刚装完Outlook Express或者Office,并且还没有重启啊!

    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
这里的几个,表面上看起来没问题,不过,正常情况下应该没有这些东西的!再次怀疑,Lz是否安装了什么windows组件,并且没有重启!
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\system32\PARTIC~1.SCR>  [Longbow Digital Arts]
控制面板项目,似乎是某个软件安装的控制面板项目!是不是某些软件安装完,提示重启,还没有重启啊?!

基本上LZ的日志看不出什么问题,红伞+风云的组合应该比较安全了!
伊の星
发表于 2007-12-4 12:14:46 | 显示全部楼层

回复 7楼 jpzy 的帖子

shmgrate.exe有两个,一个是outlook的,一个是ie的
刚装完的原版xp就有。应该没有问题。
[td]<%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
也是如此.......
随便附上没装任何软件的xp报告。
不过报告不代表一切。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
jpzy
发表于 2007-12-4 12:23:47 | 显示全部楼层
那就没问题了~!
估计重启以后,这些东西应该就没有了~!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-26 09:52 , Processed in 0.143944 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表