查看: 1719|回复: 7
收起左侧

请高手帮我看看SREngine扫描日志!

[复制链接]
++++++
发表于 2007-2-23 17:40:36 | 显示全部楼层 |阅读模式

  1. 2007-02-23,17:34:40
  2. System Repair Engineer 2.3.13.690
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows XP Professional Service Pack 2 (Build 2600)
  5. - 管理权限用户 - 完整功能
  6. 以下内容被选中:
  7.     所有的启动项目(包括注册表、启动文件夹、服务等)
  8.     浏览器加载项
  9.     正在运行的进程(包括进程模块信息)
  10.     文件关联
  11.     Winsock 提供者
  12.     Autorun.inf
  13.     HOSTS 文件

  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
  18. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  19.     <load><>  [N/A]
  20. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  21.     <kav><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
  22. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  23.     <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
  24.     <Userinit><C:\WINDOWS\system32\userinit.exe>  [(Verified)Microsoft Corporation]
  25. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  26.     <AppInit_DLLs><>  [N/A]
  27. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  28.     <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
  29. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  30.     <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Corporation]
  31. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  32.     <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Corporation]
  33.     <WebCheck><%SystemRoot%\system32\webcheck.dll>  [(Verified)Microsoft Corporation]
  34.     <SysTray><C:\WINDOWS\system32\stobject.dll>  [(Verified)Microsoft Corporation]
  35. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
  36.     <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Corporation]
  37. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
  38.     <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Corporation]
  39. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
  40.     <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Corporation]
  41. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  42.     <WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll>  [Kaspersky Lab]
  43. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
  44.     <WinlogonNotify: termsrv><wlnotify.dll>  [N/A]
  45. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
  46.     <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Corporation]
  47.     <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Corporation]
  48. ==================================
  49. 启动文件夹
  50. N/A
  51. ==================================
  52. 服务
  53. [Ati HotKey Poller / Ati HotKey Poller][Stopped/Disabled]
  54.   <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
  55. [ATI Smart / ATI Smart][Stopped/Disabled]
  56.   <C:\WINDOWS\system32\ati2sgag.exe><>
  57. [卡巴斯基反病毒6.0 / AVP][Running/Auto Start]
  58.   <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
  59. [Human Interface Device Access / HidServ][Stopped/Disabled]
  60.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  61. [LightScribeService Direct Disc Labeling Service / LightScribeService][Stopped/Disabled]
  62.   <"C:\Program Files\Common Files\LightScribe\LSSrvc.exe"><Hewlett-Packard Company>
  63. [SoundMAX Agent Service / SoundMAX Agent Service (default)][Stopped/Disabled]
  64.   <C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
  65. ==================================
  66. 驱动程序
  67. [aeaudio / aeaudio][Running/Manual Start]
  68.   <system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
  69. [ati2mtag / ati2mtag][Running/Manual Start]
  70.   <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
  71. [IdeBusDr / IdeBusDr][Running/Boot Start]
  72.   <\SystemRoot\system32\DRIVERS\IdeBusDr.sys><Intel Corporation>
  73. [Intel(R) Ultra ATA Controller / IdeChnDr][Running/Boot Start]
  74.   <\SystemRoot\system32\DRIVERS\IdeChnDr.sys><Intel Corporation>
  75. [ISO CD-ROM Device Driver / ISODrive][Stopped/Manual Start]
  76.   <\??\D:\软件\UltraISO-8.5\drivers\ISODrive.sys><EZB Systems, Inc.>
  77. [kl1 / kl1][Running/Boot Start]
  78.   <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
  79. [klif / klif][Running/System Start]
  80.   <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
  81. [npkcrypt / npkcrypt][Stopped/Auto Start]
  82.   <\??\D:\软件\QQ\npkcrypt.sys><N/A>
  83. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  84.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  85. [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  86.   <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
  87. [Secdrv / Secdrv][Stopped/Manual Start]
  88.   <system32\DRIVERS\secdrv.sys><N/A>
  89. [smwdm / smwdm][Running/Manual Start]
  90.   <system32\drivers\smwdm.sys><Analog Devices, Inc.>
  91. [sptd / sptd][Running/Boot Start]
  92.   <\SystemRoot\System32\Drivers\sptd.sys><N/A>
  93. [TCP/IP Protocol Driver / Tcpip][Running/System Start]
  94.   <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
  95. [GWIOPM / GWIOPM][Running/Manual Start]
  96.   <\??\D:\软件\Wom_7.69\GWIOPM.sys><N/A>
  97. ==================================
  98. 浏览器加载项
  99. [Thunder Browser Helper]
  100.   {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\软件\Thunder\ComDlls\XunLeiBHO_002.dll, N/A>
  101. [Web反病毒保护]
  102.   {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
  103. [Thunder Browser Helper]
  104.   {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\软件\Thunder\ComDlls\XunLeiBHO_002.dll, N/A>
  105. [Shockwave Flash Object]
  106.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
  107. [使用迅雷下载]
  108.   <, N/A>
  109. [使用迅雷下载全部链接]
  110.   <, N/A>
  111. ==================================
  112. 正在运行的进程
  113. [PID: 532][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  114. [PID: 604][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  115. [PID: 628][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  116.     [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
  117.     [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4110]
  118.     [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
  119. [PID: 672][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  120. [PID: 684][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  121.     [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
  122. [PID: 832][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  123.     [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
  124. [PID: 880][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  125.     [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
  126. [PID: 944][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  127.     [C:\WINDOWS\System32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
  128. [PID: 996][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  129.     [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
  130. [PID: 1380][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  131.     [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
  132. [PID: 1972][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  133.     [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
  134. [PID: 1060][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  135.     [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
  136. [PID: 3624][C:\WINDOWS\explorer.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  137.     [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
  138.     [D:\软件\Thunder\ComDlls\XunLeiBHO_002.dll]  [N/A, N/A]
  139.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
  140.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
  141.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\shellex.dll]  [Kaspersky Lab, 6.0.0.299]
  142.     [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
  143. [PID: 424][D:\软件\Wom_7.69\WoptiUtilities.exe]  [鲁锦, 7.69.7.130]
  144.     [D:\软件\Wom_7.69\woptip2p.dll]  [鲁锦, 1.3.6.1222]
  145.     [D:\软件\Wom_7.69\d3dx81ab.dll]  [鲁锦, 1.0.0.0]
  146.     [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
  147. [PID: 2892][D:\软件\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
  148.     [C:\WINDOWS\system32\SYNCOR11.DLL]  [SoundMAX, 1.2.3]
  149. ==================================
  150. 文件关联
  151. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  152. .EXE  OK. ["%1" %*]
  153. .COM  OK. ["%1" %*]
  154. .PIF  OK. ["%1" %*]
  155. .REG  OK. [regedit.exe "%1"]
  156. .BAT  OK. ["%1" %*]
  157. .SCR  OK. ["%1" /S]
  158. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  159. .HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
  160. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  161. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  162. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  163. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  164. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  165. ==================================
  166. Winsock 提供者
  167. N/A
  168. ==================================
  169. Autorun.inf
  170. N/A
  171. ==================================
  172. HOSTS 文件
  173. 127.0.0.1       localhost
  174. ==================================
  175. API HOOK
  176. 警告!System Repair Engineer 提醒
  177. 你下面的函数内容与预期值不符,他
  178. 们可能被一些恶意的软件所修改:
  179. RVA  错误: LoadLibraryA
  180. RVA  错误: LoadLibraryExA
  181. RVA  错误: LoadLibraryExW
  182. RVA  错误: LoadLibraryW
  183. ==================================
复制代码





请帮我看看有什么不对的地方
谢谢拉
++++++
 楼主| 发表于 2007-2-23 19:23:48 | 显示全部楼层
静静地期待高手的到来
wangjay1980
发表于 2007-2-23 20:49:37 | 显示全部楼层
看不出什么问题,如果你已经卸载了deamon tools就把[sptd / sptd][Running/Boot Start]  <\SystemRoot\System32\Drivers\sptd.sys><N/A>这个驱动删除吧
++++++
 楼主| 发表于 2007-2-24 14:26:51 | 显示全部楼层
看不出什么问题,如果你已经卸载了deamon tools就把[sptd / sptd][Running/Boot Start]  <\SystemRoot\System32\Drivers\sptd.sys><N/A>这个驱动删除吧


我用的是酒精
能删除吗?
jimmyleo
发表于 2007-2-24 15:20:30 | 显示全部楼层
这个是DAEMON TOOLS的防拷贝驱动 如果确认自己没装的话 删除
++++++
 楼主| 发表于 2007-2-25 15:02:30 | 显示全部楼层

谢谢你
DietCoke
发表于 2007-2-25 17:56:31 | 显示全部楼层
C:\WINDOWS\system32\SYNCOR11.DLL, 这个文件怎么会插入这么多进程?

如果把启动项SoundMAX 项去掉,看看,还是会插入这些进程?
wangjay1980
发表于 2007-2-25 20:43:40 | 显示全部楼层
SoundMAX虽然是个正常的软件,但是还是比较流氓的,插入了每一个进程
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-24 07:31 , Processed in 0.122333 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表