查看: 4993|回复: 37
收起左侧

[求助] 刚才我犯贱,救命

[复制链接]
运指如飞
发表于 2007-12-6 23:58:07 | 显示全部楼层 |阅读模式
刚才下载了个灰鸽子
为了测试,把EQ和小红伞的监控全部关闭了

中了后我手动清除
但不知道系统干净没有,我用网银的
麻烦大家帮我看看






  1. 2007-12-06,23:30:25
  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描

  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  18.     <ATI><C:\Program Files\ATITool\ha_ATITool.exe>  [http://atitool.techpowerup.com]
  19. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  20.     <load><>  [N/A]
  21. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  22.     <avgnt><"C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min /nosplash>  [Avira GmbH]
  23.     <EQSysSecure><C:\Program Files\EQSysSecure\EQSysSecure.exe /background>  [EQSecure]
  24.     <FY_FireWall><C:\Program Files\FengYun\FYFireWall.exe>  [www.218.cc]
  25. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  26.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  27.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  28. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  29.     <AppInit_DLLs><>  [N/A]
  30. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  31.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
  32. ==================================
  33. 启动文件夹
  34. N/A
  35. ==================================
  36. 服务
  37. [AntiVir PersonalEdition Premium MailGuard / AntiVirMailService][Stopped/Disabled]
  38.   <"C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe"><Avira GmbH>
  39. [AntiVir PersonalEdition Premium Scheduler / AntiVirScheduler][Running/Auto Start]
  40.   <"C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe"><Avira GmbH>
  41. [AntiVir PersonalEdition Premium Guard / AntiVirService][Running/Auto Start]
  42.   <"C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe"><Avira GmbH>
  43. [Ati HotKey Poller / Ati HotKey Poller][Stopped/Disabled]
  44.   <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
  45. [ATI Smart / ATI Smart][Stopped/Disabled]
  46.   <C:\WINDOWS\system32\ati2sgag.exe><>
  47. [AntiVir PersonalEdition Premium MailGuard helper service / AVEService][Stopped/Disabled]
  48.   <"C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe"><Avira GmbH>
  49. [EQService / EQService][Running/Auto Start]
  50.   <C:\Program Files\EQSysSecure\EQService.exe><EQSecure>
  51. [SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]
  52.   <C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
  53. ==================================
  54. 驱动程序
  55. [aeaudio / aeaudio][Running/Manual Start]
  56.   <system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
  57. [ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter / AN983][Running/Manual Start]
  58.   <system32\DRIVERS\AN983.sys><ADMtek Incorporated.>
  59. [ati2mtag / ati2mtag][Running/Manual Start]
  60.   <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
  61. [ATITool Overclocking Utility / ATITool][Running/System Start]
  62.   <system32\DRIVERS\ATITool.sys><>
  63. [avgio / avgio][Running/System Start]
  64.   <\??\C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgio.sys><Avira GmbH>
  65. [avgntflt / avgntflt][Running/Manual Start]
  66.   <\??\C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgntflt.sys><Avira GmbH>
  67. [avipbb / avipbb][Running/System Start]
  68.   <system32\DRIVERS\avipbb.sys><AVIRA GmbH>
  69. [EQSysSecure / EQSysSecure][Running/System Start]
  70.   <\??\C:\WINDOWS\system32\drivers\EQSysSecure.sys><EQSecure>
  71. [FYTdifltDrv / FYTdifltDrv][Running/System Start]
  72.   <\??\C:\Program Files\FengYun\FYTdiDrv.sys><N/A>
  73. [MidiSyn / MidiSyn][Stopped/Manual Start]
  74.   <system32\drivers\MidiSyn.sys><Analog Devices Inc>
  75. [Netgroup Packet Filter / NPF][Stopped/Manual Start]
  76.   <system32\drivers\npf.sys><Politecnico di Torino>
  77. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  78.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  79. [Secdrv / Secdrv][Stopped/Manual Start]
  80.   <system32\DRIVERS\secdrv.sys><N/A>
  81. [smwdm / smwdm][Running/Manual Start]
  82.   <system32\drivers\smwdm.sys><Analog Devices, Inc.>
  83. [ssmdrv / ssmdrv][Running/System Start]
  84.   <system32\DRIVERS\ssmdrv.sys><Avira GmbH>
  85. [viaraid / viaraid][Running/Boot Start]
  86.   <\SystemRoot\system32\DRIVERS\viaraid.sys><VIA Technologies inc,.ltd>
  87. ==================================
  88. 浏览器加载项
  89. [Thunder Agent Class]
  90.   {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <D:\Thunder-AyuConfig\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
  91. [WangWangObj Class]
  92.   {6E213FC7-DD5A-4115-B7E6-D4C7838C361E} <C:\Program Files\Alisoft\WangWang\WangWangX4.dll, 阿里巴巴软件(上海)有限公司>
  93. [Shockwave Flash Object]
  94.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  95. [使用迅雷下载]
  96.   <D:\Thunder-AyuConfig\Program\geturl.htm, N/A>
  97. ==================================
  98. 正在运行的进程
  99. [PID: 456][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  100. [PID: 516][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  101. [PID: 544][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  102.     [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4121]
  103. [PID: 588][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  104. [PID: 600][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  105. [PID: 736][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  106. [PID: 824][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  107. [PID: 912][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  108. [PID: 948][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  109. [PID: 1056][C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe]  [Avira GmbH, 7.00.00.82]
  110.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgio.dll]  [Avira GmbH, 7.00.00.01]
  111.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\avevtlog.dll]  [Avira GmbH, 7.00.00.20]
  112.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\guardmsg.dll]  [Avira GmbH, 7.00.11.00]
  113.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\sqlite3.dll]  [, 3, 3, 17, 1]
  114.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  115.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVPREF.DLL]  [Avira GmbH, 7.00.02.02]
  116.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\SMTPLIB.DLL]  [Avira GmbH, 1.02.00.17]
  117.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVPACK32.DLL]  [Avira GmbH, 7.03.00.15]
  118.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\unacev2.dll]  [N/A, ]
  119.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\avipc.dll]  [Avira GmbH, 1.00.00.04]
  120.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVEWIN32.DLL]  [Avira GmbH, 7.6.0.34]
  121. [PID: 1224][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  122.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  123.     [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
  124.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\shlext.dll]  [Avira GmbH, 7.00.00.10]
  125.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
  126.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  127. [PID: 1380][C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe]  [Avira GmbH, 7.02.00.16]
  128.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
  129.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  130.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\cclib.dll]  [Avira GmbH, 7.02.00.03]
  131.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
  132.     [c:\program files\avira\antivir personaledition premium\ccgen.dll]  [Avira GmbH, 7.02.00.10]
  133.     [c:\program files\avira\antivir personaledition premium\ccgenrc.dll]  [Avira GmbH, 7.02.04.02]
  134.     [c:\program files\avira\antivir personaledition premium\ccguard.dll]  [Avira GmbH, 7.00.01.35]
  135.     [c:\program files\avira\antivir personaledition premium\ccgrdrc.dll]  [Avira GmbH, 7.00.06.00]
  136.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\avipc.dll]  [Avira GmbH, 1.00.00.04]
  137.     [c:\program files\avira\antivir personaledition premium\ccupdate.dll]  [Avira GmbH, 7.02.00.04]
  138.     [c:\program files\avira\antivir personaledition premium\ccupdrc.dll]  [Avira GmbH, 7.02.01.00]
  139.     [c:\program files\avira\antivir personaledition premium\cclic.dll]  [Avira GmbH, 7.02.00.04]
  140.     [c:\program files\avira\antivir personaledition premium\cclicrc.dll]  [Avira GmbH, 7.02.01.00]
  141.     [c:\program files\avira\antivir personaledition premium\ccmsg.dll]  [Avira GmbH, 7.00.00.00]
  142.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  143. [PID: 1396][C:\Program Files\FengYun\FYFireWall.exe]  [www.218.cc, 1.2.6.0]
  144.     [C:\Program Files\FengYun\arpinfo.dll]  [N/A, ]
  145.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  146. [PID: 1404][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  147.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  148. [PID: 1412][C:\Program Files\ATITool\ha_ATITool.exe]  [http://atitool.techpowerup.com, 0, 26, 0, 0]
  149.     [C:\Program Files\ATITool\ATITOOLHOOKS.dll]  [N/A, ]
  150.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  151. [PID: 1592][C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe]  [Avira GmbH, 7.00.00.62]
  152.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  153.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
  154.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\schedr.dll]  [Avira GmbH, 7.00.24.00]
  155.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\avevtlog.dll]  [Avira GmbH, 7.00.00.20]
  156.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\sqlite3.dll]  [, 3, 3, 17, 1]
  157.     [C:\Program Files\Avira\AntiVir PersonalEdition Premium\avipc.dll]  [Avira GmbH, 1.00.00.04]
  158. [PID: 1704][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe]  [Analog Devices, Inc., 3, 2, 6, 0]
  159. [PID: 1728][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
  160. [PID: 1892][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  161. [PID: 160][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  162. [PID: 2016][D:\TENCENT\QQ2007DIY1201\QQ.exe]  [TENCENT, 7,1,576,1763]
  163.     [D:\TENCENT\QQ2007DIY1201\QQBaseClassInDll.dll]  [TENCENT, 7,1,576,1763]
  164.     [D:\TENCENT\QQ2007DIY1201\QQHelperDll.dll]  [TENCENT, 7,1,576,1763]
  165.     [D:\TENCENT\QQ2007DIY1201\BasicCtrlDll.dll]  [TENCENT, 7,1,576,1763]
  166.     [D:\TENCENT\QQ2007DIY1201\MSIMG32.dll]  [N/A, ]
  167.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  168.     [D:\TENCENT\QQ2007DIY1201\FinePlus.dll]  [N/A, ]
  169.     [D:\TENCENT\QQ2007DIY1201\fphelper.dll]  [N/A, ]
  170.     [D:\TENCENT\QQ2007DIY1201\QQAPI.dll]  [TENCENT, 7,1,576,1763]
  171.     [D:\TENCENT\QQ2007DIY1201\LoginCtrl.dll]  [TENCENT, 7,1,576,1763]
  172.     [D:\TENCENT\QQ2007DIY1201\LoginCtrlRes.dll]  [TENCENT, 7,1,575,1761]
  173.     [D:\TENCENT\QQ2007DIY1201\QQRes.dll]  [TENCENT, 7,1,576,1763]
  174.     [D:\TENCENT\QQ2007DIY1201\QQMainFrame.dll]  [N/A, ]
  175.     [D:\TENCENT\QQ2007DIY1201\UnReadMsgMgr.dll]  [N/A, ]
  176.     [D:\TENCENT\QQ2007DIY1201\CQQApplication.dll]  [N/A, ]
  177.     [D:\TENCENT\QQ2007DIY1201\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
  178.     [D:\TENCENT\QQ2007DIY1201\NewSkin.dll]  [TENCENT, 7,1,576,1763]
  179.     [D:\TENCENT\QQ2007DIY1201\decode.dll]  [N/A, ]
  180.     [D:\TENCENT\QQ2007DIY1201\aqing.dll]  [Microsoft Corporation, 5.6.0.8825]
  181.     [D:\TENCENT\QQ2007DIY1201\MailSummary.dll]  [TENCENT, 7,1,576,1763]
  182.     [D:\TENCENT\QQ2007DIY1201\QQSpace.dll]  [TENCENT, 7,1,576,1763]
  183.     [D:\TENCENT\QQ2007DIY1201\vbscript.dll]  [Microsoft Corporation, 5.6.0.8825]
  184.     [C:\WINDOWS\system32\msdmo.dll]  [, ]
  185.     [D:\TENCENT\QQ2007DIY1201\QQKnowledgeSearch.dll]  [TENCENT, 7,1,576,1763]
  186.     [D:\TENCENT\QQ2007DIY1201\QQGroupMng.dll]  [TENCENT, 7,1,576,1763]
  187.     [D:\TENCENT\QQ2007DIY1201\QQAllInOne.dll]  [TENCENT, 7,1,576,1763]
  188.     [D:\TENCENT\QQ2007DIY1201\SCCore.dll]  [TENCENT, 1, 6, 0, 2]
  189.     [D:\TENCENT\QQ2007DIY1201\CameraDll.dll]  [TENCENT, 7,1,576,1763]
  190.     [D:\TENCENT\QQ2007DIY1201\QQPet.dll]  [TENCENT, 7,1,576,1763]
  191.     [D:\TENCENT\QQ2007DIY1201\QQSysMsgMng.dll]  [N/A, ]
  192.     [D:\TENCENT\QQ2007DIY1201\UserDefinedHead.dll]  [TENCENT, 7,1,576,1763]
  193.     [D:\TENCENT\QQ2007DIY1201\QQPlugin.dll]  [N/A, ]
  194.     [D:\TENCENT\QQ2007DIY1201\QQConfigPlugin.dll]  [TENCENT, 7,1,576,1763]
  195.     [D:\TENCENT\QQ2007DIY1201\QQCustomFace.dll]  [N/A, ]
  196.     [D:\TENCENT\QQ2007DIY1201\QQLiveQMng.dll]  [TENCENT, 7,1,576,1763]
  197.     [D:\TENCENT\QQ2007DIY1201\QRingMng.dll]  [N/A, ]
  198.     [D:\TENCENT\QQ2007DIY1201\QQAvatar.dll]  [N/A, ]
  199.     [D:\TENCENT\QQ2007DIY1201\LongConnection.dll]  [TENCENT, 7,1,576,1763]
  200.     [D:\TENCENT\QQ2007DIY1201\PhoneAPI.dll]  [TENCENT, 7,1,576,1763]
  201.     [D:\TENCENT\QQ2007DIY1201\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
  202.     [D:\TENCENT\QQ2007DIY1201\GroupConnection.dll]  [TENCENT, 7,1,576,1763]
  203.     [D:\TENCENT\QQ2007DIY1201\BQQApplication.dll]  [N/A, ]
  204.     [D:\TENCENT\QQ2007DIY1201\PersonalDesktop.dll]  [TENCENT, 7,1,576,1763]
  205.     [D:\TENCENT\QQ2007DIY1201\CommercesMng.dll]  [TENCENT, 7,1,576,1763]
  206.     [D:\TENCENT\QQ2007DIY1201\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 310]
  207.     [D:\TENCENT\QQ2007DIY1201\QQSceneMng.dll]  [N/A, ]
  208.     [C:\WINDOWS\system32\UNISPIM6.IME]  [北京紫光华宇软件股份有限公司, 6.0.0.6182]
  209.     [D:\TENCENT\QQ2007DIY1201\QQMagicFace.dll]  [TENCENT, 7,1,576,1763]
  210.     [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
  211. [PID: 2752][D:\反病毒文件夹\sreng2\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
  212.     [C:\Program Files\FengYun\fymon.dll]  [www.218.cc, 1.2.3.75]
  213.     [D:\反病毒文件夹\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
  214. ==================================
  215. 文件关联
  216. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  217. .EXE  OK. ["%1" %*]
  218. .COM  OK. ["%1" %*]
  219. .PIF  OK. ["%1" %*]
  220. .REG  OK. [regedit.exe "%1"]
  221. .BAT  OK. ["%1" %*]
  222. .SCR  OK. ["%1" /S]
  223. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  224. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  225. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  226. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  227. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  228. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  229. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  230. ==================================
  231. Winsock 提供者
  232. N/A
  233. ==================================
  234. Autorun.inf
  235. N/A
  236. ==================================
  237. HOSTS 文件
  238. 127.0.0.1       localhost
  239. ==================================
  240. 进程特权扫描
  241. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1056, C:\PROGRAM FILES\AVIRA\ANTIVIR PERSONALEDITION PREMIUM\AVGUARD.EXE]
  242. 特殊特权被允许: SeSystemtimePrivilege [PID = 1380, C:\PROGRAM FILES\AVIRA\ANTIVIR PERSONALEDITION PREMIUM\AVGNT.EXE]
  243. 特殊特权被允许: SeDebugPrivilege [PID = 1380, C:\PROGRAM FILES\AVIRA\ANTIVIR PERSONALEDITION PREMIUM\AVGNT.EXE]
  244. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1380, C:\PROGRAM FILES\AVIRA\ANTIVIR PERSONALEDITION PREMIUM\AVGNT.EXE]
  245. 特殊特权被允许: SeSystemtimePrivilege [PID = 1396, C:\PROGRAM FILES\FENGYUN\FYFIREWALL.EXE]
  246. 特殊特权被允许: SeDebugPrivilege [PID = 1396, C:\PROGRAM FILES\FENGYUN\FYFIREWALL.EXE]
  247. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1396, C:\PROGRAM FILES\FENGYUN\FYFIREWALL.EXE]
  248. 特殊特权被允许: SeSystemtimePrivilege [PID = 1412, C:\PROGRAM FILES\ATITOOL\HA_ATITOOL.EXE]
  249. 特殊特权被允许: SeDebugPrivilege [PID = 1412, C:\PROGRAM FILES\ATITOOL\HA_ATITOOL.EXE]
  250. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1412, C:\PROGRAM FILES\ATITOOL\HA_ATITOOL.EXE]
  251. ==================================
  252. API HOOK
  253. N/A
  254. ==================================
  255. 隐藏进程
  256.     [1389] C:\Program Files\EQSysSecure\EQSysSecure.exe
  257.     [1613] C:\Program Files\EQSysSecure\EQService.exe
  258. ==================================
复制代码
东京时空
头像被屏蔽
发表于 2007-12-7 00:00:08 | 显示全部楼层
很难说。。我建议你重装系统。。。
运指如飞
 楼主| 发表于 2007-12-7 00:01:25 | 显示全部楼层
这。。。。。。。。。。。

我再补充一个日志
麻烦大家了
运指如飞
 楼主| 发表于 2007-12-7 00:02:53 | 显示全部楼层
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 0:02:27, on 2007-12-7
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe
C:\Program Files\FengYun\FYFireWall.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATITool\ha_ATITool.exe
C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\svchost.exe
D:\TENCENT\QQ2007DIY1201\QQ.exe
D:\Maxthon 1[1].6.1增强绿色版\Maxthon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
D:\反病毒文件夹\HiJackThis v2.0\HiJackThis v2.0.exe

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min /nosplash
O4 - HKLM\..\Run: [EQSysSecure] C:\Program Files\EQSysSecure\EQSysSecure.exe /background
O4 - HKLM\..\Run: [FY_FireWall] C:\Program Files\FengYun\FYFireWall.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ATI] C:\Program Files\ATITool\ha_ATITool.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: 使用迅雷下载 - D:\Thunder-AyuConfig\Program\geturl.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{4464ECDE-2627-49AB-8294-14395B02CFC7}: NameServer = 202.103.24.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{4464ECDE-2627-49AB-8294-14395B02CFC7}: NameServer = 202.103.24.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{4464ECDE-2627-49AB-8294-14395B02CFC7}: NameServer = 202.103.24.68
O22 - SharedTaskScheduler: Browseui 预加载程序 - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: 组件类别缓存程序 - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AntiVir PersonalEdition Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
O23 - Service: AntiVir PersonalEdition Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
O23 - Service: EQService - EQSecure - C:\Program Files\EQSysSecure\EQService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 3098 bytes
capsshift
发表于 2007-12-7 00:10:39 | 显示全部楼层
楼主,你狠,这些东西,要测试的话,用虚拟机好了。
GBUser
发表于 2007-12-7 00:13:07 | 显示全部楼层
小红伞,EQ,风云,东西还真不少咧
一个区区灰鸽子,让它折腾也折腾不起来吧
运指如飞
 楼主| 发表于 2007-12-7 00:17:22 | 显示全部楼层
原帖由 GBUser 于 2007-12-7 00:13 发表
小红伞,EQ,风云,东西还真不少咧
一个区区灰鸽子,让它折腾也折腾不起来吧


^_^,除了风云防护墙,红伞和EQ关闭监控后运行的
运指如飞
 楼主| 发表于 2007-12-7 00:18:03 | 显示全部楼层
不过看日志我觉得我应该清理干净了,还是要麻烦各位帮忙看看
是否有漏掉的
sharkheadsan
发表于 2007-12-7 00:44:39 | 显示全部楼层
看到头都晕~楼主的机子还是你熟点,有什么软件和程序你清楚点~不放心就用其他杀软(绿色)查查,楼主的装备也够强的。
yxy0708
发表于 2007-12-7 01:09:16 | 显示全部楼层
太强悍了……
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-29 10:05 , Processed in 0.128580 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表