12
返回列表 发新帖
楼主: lmq_fqh520
收起左侧

Backdoor.Win32.SdBot.bdh

[复制链接]
lmq_fqh520
 楼主| 发表于 2007-3-3 13:36:41 | 显示全部楼层

用SRE扫描的 报告 超长

[CODE]

2007-03-03,13:29:22

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <Internat.exe><internat.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <Synchronization Manager><mobsync.exe /logon>  [Microsoft Corporation]
    <kav><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINNT\system32\userinit.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <Network.ConnectionTray><C:\WINNT\system32\NETSHELL.dll>  [Microsoft Corporation]
    <WebCheck><%SystemRoot%\system32\webcheck.dll>  [Microsoft Corporation]
    <SysTray><stobject.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    <WinlogonNotify: cscdll><cscdll.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
    <WinlogonNotify: igfxcui><igfxdev.dll>  [Intel Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
    <WinlogonNotify: klogon><C:\WINNT\system32\klogon.dll>  [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    <WinlogonNotify: sclgntfy><sclgntfy.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    <WinlogonNotify: SensLogn><WlNotify.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
    <WinlogonNotify: wzcnotif><wzcdlg.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Corporation]
    <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINNT\system32\ssflwbox.scr>  [Microsoft Corporation]

==================================
启动文件夹
[迅雷4]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\迅雷4.lnk --> C:\PROGRA~1\SANDAI~1\Thunder\Thunder.exe [深圳市三代科技开发有限公司]><N>

==================================
服务
[08141 / 08141][Stopped/Manual Start]
  <\\96.1.10.234\Admin$\eraseme_30638.exe><N/A>
[Alerter / Alerter][Stopped/Manual Start]
  <C:\WINNT\system32\services.exe><Microsoft Corporation>
[Application Management / AppMgmt][Stopped/Manual Start]
  <C:\WINNT\system32\services.exe><Microsoft Corporation>
[卡巴斯基反病毒6.0 / AVP][Running/Auto Start]
  <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe -r><Kaspersky Lab>
[Background Intelligent Transfer Service / BITS][Stopped/Manual Start]
  <C:\WINNT\system32\svchost.exe -k BITSgroup-->C:\WINNT\system32\qmgr.dll><Microsoft Corporation>
[Computer Browser / Browser][Running/Auto Start]
  <C:\WINNT\system32\services.exe><Microsoft Corporation>
[Indexing Service / cisvc][Stopped/Disabled]
  <C:\WINNT\system32\cisvc.exe><Microsoft Corporation>
[ClipBook / ClipSrv][Stopped/Manual Start]
  <C:\WINNT\system32\clipsrv.exe><Microsoft Corporation>
[DHCP Client / Dhcp][Running/Auto Start]
  <C:\WINNT\system32\services.exe><Microsoft Corporation>
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Logical Disk Manager / dmserver][Running/Auto Start]
  <C:\WINNT\System32\services.exe><Microsoft Corporation>
[DNS Client / Dnscache][Running/Auto Start]
  <C:\WINNT\system32\services.exe><Microsoft Corporation>
[Event Log / Eventlog][Running/Auto Start]
  <C:\WINNT\system32\services.exe><Microsoft Corporation>
[Fax Service / Fax][Stopped/Manual Start]
  <C:\WINNT\system32\faxsvc.exe><Microsoft Corporation>
[Server / lanmanserver][Running/Auto Start]
  <C:\WINNT\system32\services.exe><Microsoft Corporation>
[Workstation / lanmanworkstation][Running/Auto Start]
  <C:\WINNT\system32\services.exe><Microsoft Corporation>
[TCP/IP NetBIOS Helper Service / LmHosts][Running/Auto Start]
  <C:\WINNT\system32\services.exe><Microsoft Corporation>
[Messenger / Messenger][Running/Auto Start]
  <C:\WINNT\system32\services.exe><Microsoft Corporation>
[NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]
  <C:\WINNT\system32\mnmsrvc.exe><Microsoft Corporation>
[Distributed Transaction Coordinator / MSDTC][Stopped/Manual Start]
  <C:\WINNT\system32\msdtc.exe><Microsoft Corporation>
[Windows Installer / MSIServer][Stopped/Manual Start]
  <C:\WINNT\system32\msiexec.exe /V><Microsoft Corporation>
[Removable Storage / NtmsSvc][Running/Auto Start]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\NtmsSvc.dll><Microsoft Corporation>
[OracleOraHome81ClientCache / OracleOraHome81ClientCache][Stopped/Manual Start]
  <c:\Oracle\Ora81\BIN\ONRSD.EXE><N/A>
[Plug and Play / PlugPlay][Running/Auto Start]
  <C:\WINNT\system32\services.exe><Microsoft Corporation>
[Protected Storage / ProtectedStorage][Running/Auto Start]
  <C:\WINNT\system32\services.exe><Microsoft Corporation>
[Remote Access Auto Connection Manager / RasAuto][Stopped/Manual Start]
  <C:\WINNT\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\rasauto.dll><Microsoft Corporation>
[Routing and Remote Access / RemoteAccess][Stopped/Disabled]
  <C:\WINNT\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\mprdim.dll><Microsoft Corporation>
[Remote Registry Service / RemoteRegistry][Running/Auto Start]
  <C:\WINNT\system32\regsvc.exe><Microsoft Corporation>
[Remote Procedure Call (RPC) Locator / RpcLocator][Stopped/Manual Start]
  <C:\WINNT\system32\locator.exe><Microsoft Corporation>
[QoS RSVP / RSVP][Stopped/Manual Start]
  <C:\WINNT\system32\rsvp.exe -s><Microsoft Corporation>
[Smart Card / SCardSvr][Stopped/Manual Start]
  <C:\WINNT\System32\SCardSvr.exe><N/A>
[RunAs Service / seclogon][Running/Auto Start]
  <C:\WINNT\system32\services.exe><Microsoft Corporation>
[System Event Notification / SENS][Running/Auto Start]
  <C:\WINNT\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\sens.dll><Microsoft Corporation>
[Performance Logs and Alerts / SysmonLog][Stopped/Manual Start]
  <C:\WINNT\system32\smlogsvc.exe><Microsoft Corporation>
[Telnet / TlntSvr][Stopped/Manual Start]
  <C:\WINNT\system32\tlntsvr.exe><Microsoft Corporation>
[Distributed Link Tracking Client / TrkWks][Running/Auto Start]
  <C:\WINNT\system32\services.exe><Microsoft Corporation>
[Uninterruptible Power Supply / UPS][Stopped/Manual Start]
  <C:\WINNT\System32\ups.exe><Microsoft Corporation>
[Utility Manager / UtilMan][Stopped/Manual Start]
  <C:\WINNT\System32\UtilMan.exe><Microsoft Corporation>
[Windows Time / W32Time][Stopped/Manual Start]
  <C:\WINNT\System32\services.exe><Microsoft Corporation>
[Windows Management Instrumentation / WinMgmt][Running/Auto Start]
  <C:\WINNT\System32\WBEM\WinMgmt.exe><Microsoft Corporation>
[Windows Management Instrumentation Driver Extensions / Wmi][Running/Manual Start]
  <C:\WINNT\system32\Services.exe><Microsoft Corporation>
[Automatic Updates / wuauserv][Running/Auto Start]
  <C:\WINNT\system32\svchost.exe -k wugroup-->C:\WINNT\system32\wuauserv.dll><Microsoft Corporation>
[Wireless Configuration / WZCSVC][Stopped/Manual Start]
  <C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\wzcsvc.dll><Microsoft Corporation>
lmq_fqh520
 楼主| 发表于 2007-3-3 13:38:04 | 显示全部楼层

继续提交

==================================
驱动程序
[Microsoft ACPI Driver / ACPI][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\ACPI.sys><Microsoft Corporation>
[AFD 网络支持环境 / AFD][Running/Auto Start]
  <\SystemRoot\System32\drivers\afd.sys><Microsoft Corporation>
[RAS Asynchronous Media Driver / AsyncMac][Stopped/Manual Start]
  <system32\DRIVERS\asyncmac.sys><Microsoft Corporation>
[Standard IDE/ESDI Hard Disk Controller / atapi][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\atapi.sys><Microsoft Corporation>
[ATM ARP Client Protocol / Atmarpc][Stopped/Manual Start]
  <system32\DRIVERS\atmarpc.sys><Microsoft Corporation>
[Audio Stub Driver / audstub][Running/Manual Start]
  <system32\DRIVERS\audstub.sys><Microsoft Corporation>
[Closed Caption Decoder / CCDECODE][Stopped/Manual Start]
  <system32\DRIVERS\CCDECODE.sys><Microsoft Corporation>
[CD-ROM Driver / Cdrom][Running/System Start]
  <system32\DRIVERS\cdrom.sys><Microsoft Corporation>
[d347bus / d347bus][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\d347bus.sys><>
[d347prt / d347prt][Running/Boot Start]
  <\SystemRoot\System32\Drivers\d347prt.sys><>
[Disk Driver / Disk][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\disk.sys><Microsoft Corporation>
[dmboot / dmboot][Stopped/Disabled]
  <System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload][Running/Boot Start]
  <\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[Intel(R) PRO Network Connection Driver / E100B][Running/Manual Start]
  <system32\DRIVERS\e100bnt5.sys><Intel Corporation>
[FsVga / FsVga][Running/System Start]
  <system32\DRIVERS\fsvga.sys><Microsoft Corporation>
[Volume Manager Driver / Ftdisk][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\ftdisk.sys><Microsoft Corporation>
[Generic Packet Classifier / Gpc][Running/Manual Start]
  <system32\DRIVERS\msgpc.sys><Microsoft Corporation>
[Microsoft HID Class Driver / hidusb][Running/Auto Start]
  <system32\DRIVERS\hidusb.sys><Microsoft Corporation>
[ialm / ialm][Running/Manual Start]
  <system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[IntelIde / IntelIde][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\intelide.sys><Microsoft Corporation>
[IP Traffic Filter Driver / IpFilterDriver][Stopped/Manual Start]
  <system32\DRIVERS\ipfltdrv.sys><Microsoft Corporation>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
  <system32\DRIVERS\ipinip.sys><Microsoft Corporation>
[IP Network Address Translator / IpNat][Stopped/Manual Start]
  <system32\DRIVERS\ipnat.sys><Microsoft Corporation>
[IR Enumerator Service / IRENUM][Stopped/Manual Start]
  <System32\DRIVERS\irenum.sys><Microsoft Corporation>
[PnP ISA/EISA Bus Driver / isapnp][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\isapnp.sys><Microsoft Corporation>
[Keyboard Class Driver / Kbdclass][Running/System Start]
  <system32\DRIVERS\kbdclass.sys><Microsoft Corporation>
[Keyboard HID Driver / kbdhid][Running/System Start]
  <system32\DRIVERS\kbdhid.sys><Microsoft Corporation>
[kl1 / kl1][Running/Boot Start]
  <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif][Running/System Start]
  <\??\C:\WINNT\system32\drivers\klif.sys><Kaspersky Lab>
[Mouse Class Driver / Mouclass][Running/System Start]
  <system32\DRIVERS\mouclass.sys><Microsoft Corporation>
[Mouse HID Driver / mouhid][Running/Manual Start]
  <system32\DRIVERS\mouhid.sys><Microsoft Corporation>
[BDA MPE Filter / MPE][Stopped/Manual Start]
  <system32\DRIVERS\MPE.sys><Microsoft Corporation>
[Microsoft Streaming Service Proxy / MSKSSRV][Stopped/Manual Start]
  <system32\drivers\MSKSSRV.sys><Microsoft Corporation>
[Microsoft Streaming Clock Proxy / MSPCLOCK][Stopped/Manual Start]
  <system32\drivers\MSPCLOCK.sys><Microsoft Corporation>
[Microsoft Streaming Quality Manager Proxy / MSPQM][Stopped/Manual Start]
  <system32\drivers\MSPQM.sys><Microsoft Corporation>
[Microsoft Streaming Tee/Sink-to-Sink Converter / MSTEE][Stopped/Manual Start]
  <system32\drivers\MSTEE.sys><Microsoft Corporation>
[NABTS/FEC VBI Codec / NABTSFEC][Stopped/Manual Start]
  <system32\DRIVERS\NABTSFEC.sys><Microsoft Corporation>
[NetBEUI Protocol / Nbf][Running/Auto Start]
  <system32\DRIVERS\nbf.sys><Microsoft Corporation>
[Remote Access NDIS TAPI Driver / NdisTapi][Running/Manual Start]
  <system32\DRIVERS\ndistapi.sys><Microsoft Corporation>
[NDIS 用户模式 I/O 协议 / Ndisuio][Stopped/Manual Start]
  <system32\DRIVERS\ndisuio.sys><Microsoft Corporation>
[Remote Access NDIS WAN Driver / NdisWan][Running/Manual Start]
  <system32\DRIVERS\ndiswan.sys><Microsoft Corporation>
[NetBIOS Interface / NetBIOS][Running/System Start]
  <system32\DRIVERS\netbios.sys><Microsoft Corporation>
[NetBios over Tcpip / NetBT][Running/System Start]
  <system32\DRIVERS\netbt.sys><Microsoft Corporation>
[NetDetect / NetDetect][Stopped/Manual Start]
  <\SystemRoot\system32\drivers\netdtect.sys><Microsoft Corporation>
[IPX Traffic Filter Driver / NwlnkFlt][Stopped/Manual Start]
  <system32\DRIVERS\nwlnkflt.sys><Microsoft Corporation>
[IPX Traffic Forwarder Driver / NwlnkFwd][Stopped/Manual Start]
  <system32\DRIVERS\nwlnkfwd.sys><Microsoft Corporation>
[Parallel class driver / Parallel][Running/Manual Start]
  <system32\DRIVERS\parallel.sys><Microsoft Corporation>
[Parallel port driver / Parport][Running/System Start]
  <system32\DRIVERS\parport.sys><Microsoft Corporation>
[PCI Bus Driver / PCI][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\pci.sys><Microsoft Corporation>
[PCIIde / PCIIde][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\pciide.sys><Microsoft Corporation>
[Padus ASPI Shell / pfc][Running/Manual Start]
  <system32\drivers\pfc.sys><Padus, Inc.>
[WAN Miniport (PPTP) / PptpMiniport][Running/Manual Start]
  <system32\DRIVERS\raspptp.sys><Microsoft Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Remote Access Auto Connection Driver / RasAcd][Running/System Start]
  <system32\DRIVERS\rasacd.sys><Microsoft Corporation>
[WAN Miniport (L2TP) / Rasl2tp][Running/Manual Start]
  <system32\DRIVERS\rasl2tp.sys><Microsoft Corporation>
[Direct Parallel / Raspti][Running/Manual Start]
  <system32\DRIVERS\raspti.sys><Microsoft Corporation>
[Microsoft Streaming Network Raw Channel Access / RCA][Stopped/Manual Start]
  <system32\drivers\RCA.sys><Microsoft Corporation>
[Digital CD Audio Playback Filter Driver / redbook][Stopped/System Start]
  <system32\DRIVERS\redbook.sys><Microsoft Corporation>
[ROCKEYNT / ROCKEYNT][Running/Auto Start]
  <\??\C:\WINNT\system32\drivers\Rockeynt.sys><FeiTian Tech Co.,Ltd>
[SecDrv / SecDrv][Running/Auto Start]
  <\??\C:\WINNT\system32\drivers\SECDRV.SYS><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[Sense3 / Sense3][Running/Auto Start]
  <System32\Drivers\sense3.sys><Beijing Senselock>
[Serenum Filter Driver / serenum][Running/Manual Start]
  <system32\DRIVERS\serenum.sys><Microsoft Corporation>
[Serial port driver / Serial][Running/System Start]
  <system32\DRIVERS\serial.sys><Microsoft Corporation>
[BDA Slip De-Framer / SLIP][Stopped/Manual Start]
  <system32\DRIVERS\SLIP.sys><Microsoft Corporation>
[BDA IPSink / streamip][Stopped/Manual Start]
  <system32\DRIVERS\StreamIP.sys><Microsoft Corporation>
[Software Bus Driver / swenum][Running/Manual Start]
  <system32\DRIVERS\swenum.sys><Microsoft Corporation>
[TSP / TSP][Stopped/Manual Start]
  <\??\C:\WINNT\system32\drivers\klif.sys><Kaspersky Lab>
[Microsoft USB Universal Host Controller Driver / uhcd][Running/Manual Start]
  <system32\DRIVERS\uhcd.sys><Microsoft Corporation>
[Conexant Setup API / UIUSys][Stopped/Manual Start]
  <system32\drivers\UIUSys.sys><N/A>
[Microcode Update Driver / Update][Running/Manual Start]
  <system32\DRIVERS\update.sys><Microsoft Corporation>
[Microsoft USB 2.0 Enhanced Host Controller Miniport Driver / usbehci][Running/Manual Start]
  <system32\DRIVERS\usbehci.sys><Microsoft Corporation>
[Microsoft USB Standard Hub Driver / usbhub][Running/Manual Start]
  <system32\DRIVERS\usbhub.sys><Microsoft Corporation>
[USB 2.0 Root Hub Support / usbhub20][Running/Manual Start]
  <system32\DRIVERS\usbhub20.sys><Microsoft Corporation>
[USB Mass Storage Driver / USBSTOR][Stopped/Manual Start]
  <system32\DRIVERS\USBSTOR.SYS><Microsoft Corporation>
[VgaSave / VgaSave][Running/System Start]
  <\SystemRoot\System32\drivers\vga.sys><Microsoft Corporation>
[Remote Access IP ARP Driver / Wanarp][Running/Manual Start]
  <system32\DRIVERS\wanarp.sys><Microsoft Corporation>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>

==================================
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F57} <C:\WINNT\system32\THUNDE~1.DLL, >
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx, >
[Web反病毒保护]
  {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
[迅雷]
  {1FBA04EE-3024-11D2-8F1F-000019796948} <C:\Program Files\Sandai Technologies Inc\Thunder\Thunder.exe, 深圳市三代科技开发有限公司>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[@msdxmLC.dll,-1@2052,电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
[Edit Class]
  {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINNT\system32\CMBEdit.dll, N/A>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINNT\system32\wuweb.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINNT\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[&使用迅雷下载]
  <C:\Program Files\Sandai Technologies Inc\Thunder\geturl.htm, N/A>

==================================
正在运行的进程
[PID: 192][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.00.2195.6601]
[PID: 216][\??\C:\WINNT\system32\csrss.exe]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\CSRSRV.dll]  [Microsoft Corporation, 5.00.2195.6601]
[PID: 212][\??\C:\WINNT\system32\winlogon.exe]  [Microsoft Corporation, 5.00.2195.6970]
    [C:\WINNT\system32\MSVCRT.dll]  [Microsoft Corporation, 6.10.9844.0]
    [C:\WINNT\system32\NDdeApi.dll]  [Microsoft Corporation, 5.00.2195.6661]
    [C:\WINNT\system32\sfc.dll]  [Microsoft Corporation, 5.00.2195.6673]
    [C:\WINNT\system32\Secur32.dll]  [Microsoft Corporation, 5.00.2195.6695]
    [C:\WINNT\system32\PROFMAP.dll]  [Microsoft Corporation, 5.00.2195.6610]
    [C:\WINNT\system32\NTDSAPI.dll]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\WSOCK32.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\system32\WS2_32.DLL]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\WS2HELP.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\WLDAP32.DLL]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\NETRAP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\IMM32.DLL]  [Microsoft Corporation, 5.00.2195.6655]
    [C:\WINNT\system32\WINSTA.dll]  [Microsoft Corporation, 5.00.2195.6701]
    [C:\WINNT\system32\WINMM.dll]  [Microsoft Corporation, 5.00.2161.1]
    [C:\WINNT\system32\setupapi.dll]  [Microsoft Corporation, 5.00.2195.6622]
    [C:\WINNT\system32\cscdll.dll]  [Microsoft Corporation, 5.00.2195.6713]
    [C:\WINNT\system32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\WINNT\system32\OLEAUT32.dll]  [Microsoft Corporation, 2.40.4522]
    [C:\WINNT\system32\WlNotify.dll]  [Microsoft Corporation, 5.00.2195.6706]
    [C:\WINNT\system32\CERTCLI.DLL]  [Microsoft Corporation, 5.00.2195.6619]
    [C:\WINNT\system32\ATL.DLL]  [Microsoft Corporation, 3.00.9435]
    [C:\WINNT\system32\WINSCARD.DLL]  [Microsoft Corporation, 5.00.2195.6609]
    [C:\WINNT\system32\WINSPOOL.DRV]  [Microsoft Corporation, 5.00.2195.6659]
    [C:\WINNT\system32\asycfilt.dll]  [Microsoft Corporation, 2.40.4522]
    [C:\WINNT\system32\UNISPIM5.IME]  [北京紫光华宇软件股份有限公司, 5.0.0.5076]
    [C:\WINNT\system32\cscui.dll]  [Microsoft Corporation, 5.00.2195.6705]
    [C:\WINNT\system32\wzcdlg.dll]  [Microsoft Corporation, 5.00.2195.6604]
    [C:\WINNT\system32\WZCSAPI.DLL]  [Microsoft Corporation, 5.00.2195.6604]
    [C:\WINNT\system32\ICMP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\MPRAPI.dll]  [Microsoft Corporation, 5.00.2181.1]
    [C:\WINNT\system32\ACTIVEDS.DLL]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\ADSLDPC.DLL]  [Microsoft Corporation, 5.00.2195.6701]
    [C:\WINNT\system32\RTUTILS.DLL]  [Microsoft Corporation, 5.00.2168.1]
    [C:\WINNT\system32\RASAPI32.dll]  [Microsoft Corporation, 5.00.2195.6625]
    [C:\WINNT\system32\RASMAN.DLL]  [Microsoft Corporation, 5.00.2195.6604]
    [C:\WINNT\system32\TAPI32.DLL]  [Microsoft Corporation, 5.00.2195.6664]
    [C:\WINNT\system32\igfxdev.dll]  [Intel Corporation, 3.0.0.4299]
[PID: 264][C:\WINNT\system32\services.exe]  [Microsoft Corporation, 5.00.2195.6700]
lmq_fqh520
 楼主| 发表于 2007-3-3 13:41:30 | 显示全部楼层

继续

[C:\WINNT\system32\MSVCRT.dll]  [Microsoft Corporation, 6.10.9844.0]
    [C:\WINNT\system32\Secur32.dll]  [Microsoft Corporation, 5.00.2195.6695]
    [C:\WINNT\system32\NTDSAPI.dll]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\WSOCK32.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\system32\WS2_32.DLL]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\WS2HELP.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\WLDAP32.DLL]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\NETRAP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\IMM32.DLL]  [Microsoft Corporation, 5.00.2195.6655]
    [C:\WINNT\system32\ICMP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\MPRAPI.dll]  [Microsoft Corporation, 5.00.2181.1]
    [C:\WINNT\system32\OLEAUT32.DLL]  [Microsoft Corporation, 2.40.4522]
    [C:\WINNT\system32\ACTIVEDS.DLL]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\ADSLDPC.DLL]  [Microsoft Corporation, 5.00.2195.6701]
    [C:\WINNT\system32\RTUTILS.DLL]  [Microsoft Corporation, 5.00.2168.1]
    [C:\WINNT\system32\SETUPAPI.DLL]  [Microsoft Corporation, 5.00.2195.6622]
    [C:\WINNT\system32\RASAPI32.dll]  [Microsoft Corporation, 5.00.2195.6625]
    [C:\WINNT\system32\RASMAN.DLL]  [Microsoft Corporation, 5.00.2195.6604]
    [C:\WINNT\system32\TAPI32.DLL]  [Microsoft Corporation, 5.00.2195.6664]
    [C:\WINNT\system32\lmhsvc.dll]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\rsaenh.dll]  [Microsoft Corporation, 5.00.2195.6611]
    [C:\WINNT\system32\WINSTA.DLL]  [Microsoft Corporation, 5.00.2195.6701]
    [C:\WINNT\system32\dmserver.dll]  [VERITAS Software Corp., 2195.6605.297.3]
    [C:\WINNT\system32\CFGMGR32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\WINSPOOL.DRV]  [Microsoft Corporation, 5.00.2195.6659]
    [C:\WINNT\system32\cryptdll.dll]  [Microsoft Corporation, 5.00.2195.6607]
    [C:\WINNT\system32\trkwks.dll]  [Microsoft Corporation, 5.00.2195.6623]
    [C:\WINNT\system32\msgsvc.dll]  [Microsoft Corporation, 5.00.2195.6656]
    [C:\WINNT\system32\mswsock.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\system32\msafd.dll]  [Microsoft Corporation, 5.00.2195.6602]
    [C:\WINNT\System32\wshtcpip.dll]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\System32\rnr20.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\System32\winrnr.dll]  [Microsoft Corporation, 5.00.2160.1]
    [C:\WINNT\system32\wmicore.dll]  [Microsoft Corporation, 5.00.2195.6611]
[PID: 276][C:\WINNT\system32\lsass.exe]  [Microsoft Corporation, 5.00.2195.6902]
    [C:\WINNT\system32\MSVCRT.dll]  [Microsoft Corporation, 6.10.9844.0]
    [C:\WINNT\system32\cryptdll.dll]  [Microsoft Corporation, 5.00.2195.6607]
    [C:\WINNT\system32\Secur32.dll]  [Microsoft Corporation, 5.00.2195.6695]
    [C:\WINNT\system32\WSOCK32.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\system32\WS2_32.DLL]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\WS2HELP.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\NTDSAPI.dll]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\WLDAP32.DLL]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\NETRAP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\IMM32.DLL]  [Microsoft Corporation, 5.00.2195.6655]
    [C:\WINNT\system32\msprivs.dll]  [Microsoft Corporation, 5.00.2195.6695]
    [C:\WINNT\system32\ICMP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\MPRAPI.dll]  [Microsoft Corporation, 5.00.2181.1]
    [C:\WINNT\system32\OLEAUT32.DLL]  [Microsoft Corporation, 2.40.4522]
    [C:\WINNT\system32\ACTIVEDS.DLL]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\ADSLDPC.DLL]  [Microsoft Corporation, 5.00.2195.6701]
    [C:\WINNT\system32\RTUTILS.DLL]  [Microsoft Corporation, 5.00.2168.1]
    [C:\WINNT\system32\SETUPAPI.DLL]  [Microsoft Corporation, 5.00.2195.6622]
    [C:\WINNT\system32\RASAPI32.dll]  [Microsoft Corporation, 5.00.2195.6625]
    [C:\WINNT\system32\RASMAN.DLL]  [Microsoft Corporation, 5.00.2195.6604]
    [C:\WINNT\system32\TAPI32.DLL]  [Microsoft Corporation, 5.00.2195.6664]
    [C:\WINNT\system32\rsabase.dll]  [Microsoft Corporation, 5.00.2195.6619]
    [C:\WINNT\system32\MFC42LOC.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\WINNT\system32\msafd.dll]  [Microsoft Corporation, 5.00.2195.6602]
    [C:\WINNT\System32\wshtcpip.dll]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\rsaenh.dll]  [Microsoft Corporation, 5.00.2195.6611]
    [C:\WINNT\system32\dssenh.dll]  [Microsoft Corporation, 5.00.2195.6612]
[PID: 456][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\IMM32.DLL]  [Microsoft Corporation, 5.00.2195.6655]
    [C:\WINNT\system32\MSVCRT.dll]  [Microsoft Corporation, 6.10.9844.0]
    [c:\winnt\system32\WS2_32.dll]  [Microsoft Corporation, 5.00.2195.6601]
    [c:\winnt\system32\WS2HELP.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [c:\winnt\system32\Secur32.dll]  [Microsoft Corporation, 5.00.2195.6695]
    [c:\winnt\system32\WINSTA.dll]  [Microsoft Corporation, 5.00.2195.6701]
    [C:\WINNT\system32\rsaenh.dll]  [Microsoft Corporation, 5.00.2195.6611]
    [C:\WINNT\system32\mswsock.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\system32\WSOCK32.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\system32\msafd.dll]  [Microsoft Corporation, 5.00.2195.6602]
    [C:\WINNT\System32\wshtcpip.dll]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\System32\rnr20.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\system32\ICMP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\MPRAPI.dll]  [Microsoft Corporation, 5.00.2181.1]
    [C:\WINNT\system32\NTDSAPI.dll]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\WLDAP32.DLL]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\NETRAP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\OLEAUT32.DLL]  [Microsoft Corporation, 2.40.4522]
    [C:\WINNT\system32\ACTIVEDS.DLL]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\ADSLDPC.DLL]  [Microsoft Corporation, 5.00.2195.6701]
    [C:\WINNT\system32\RTUTILS.DLL]  [Microsoft Corporation, 5.00.2168.1]
    [C:\WINNT\system32\SETUPAPI.DLL]  [Microsoft Corporation, 5.00.2195.6622]
    [C:\WINNT\system32\RASAPI32.dll]  [Microsoft Corporation, 5.00.2195.6625]
    [C:\WINNT\system32\RASMAN.DLL]  [Microsoft Corporation, 5.00.2195.6604]
    [C:\WINNT\system32\TAPI32.DLL]  [Microsoft Corporation, 5.00.2195.6664]
    [C:\WINNT\System32\winrnr.dll]  [Microsoft Corporation, 5.00.2160.1]
    [C:\WINNT\System32\wshnetbs.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\msi.dll]  [Microsoft Corporation, 2.0.2600.1183]
[PID: 484][C:\WINNT\system32\spoolsv.exe]  [Microsoft Corporation, 5.00.2195.7059]
    [C:\WINNT\system32\MSVCRT.dll]  [Microsoft Corporation, 6.10.9844.0]
    [C:\WINNT\system32\IMM32.DLL]  [Microsoft Corporation, 5.00.2195.6655]
    [C:\WINNT\system32\WS2_32.dll]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\WS2HELP.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\Secur32.dll]  [Microsoft Corporation, 5.00.2195.6695]
    [C:\WINNT\system32\NTDSAPI.dll]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\WSOCK32.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\system32\WLDAP32.DLL]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\NETRAP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\ICMP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\MPRAPI.dll]  [Microsoft Corporation, 5.00.2181.1]
    [C:\WINNT\system32\OLEAUT32.DLL]  [Microsoft Corporation, 2.40.4522]
    [C:\WINNT\system32\ACTIVEDS.DLL]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\ADSLDPC.DLL]  [Microsoft Corporation, 5.00.2195.6701]
    [C:\WINNT\system32\RTUTILS.DLL]  [Microsoft Corporation, 5.00.2168.1]
    [C:\WINNT\system32\SETUPAPI.DLL]  [Microsoft Corporation, 5.00.2195.6622]
    [C:\WINNT\system32\RASAPI32.dll]  [Microsoft Corporation, 5.00.2195.6625]
    [C:\WINNT\system32\RASMAN.DLL]  [Microsoft Corporation, 5.00.2195.6604]
    [C:\WINNT\system32\TAPI32.DLL]  [Microsoft Corporation, 5.00.2195.6664]
    [C:\WINNT\system32\localspl.dll]  [Microsoft Corporation, 5.00.2195.6714]
    [C:\WINNT\system32\VERSION.DLL]  [Microsoft Corporation, 5.00.2195.6623]
    [C:\WINNT\system32\LZ32.DLL]  [Microsoft Corporation, 5.00.2195.6611]
    [C:\WINNT\system32\SFC.DLL]  [Microsoft Corporation, 5.00.2195.6673]
    [C:\WINNT\system32\winspool.drv]  [Microsoft Corporation, 5.00.2195.6659]
    [C:\WINNT\system32\cnbjmon.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\pjlmon.dll]  [Microsoft Corporation, 5.00.2165.1]
    [C:\WINNT\system32\tcpmon.dll]  [Microsoft Corporation, 5.00.2195.6659]
    [C:\WINNT\system32\usbmon.dll]  [Microsoft Corporation, 5.00.2195.6684]
    [C:\WINNT\System32\rnr20.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\System32\winrnr.dll]  [Microsoft Corporation, 5.00.2160.1]
    [C:\WINNT\system32\msafd.dll]  [Microsoft Corporation, 5.00.2195.6602]
    [C:\WINNT\System32\wshtcpip.dll]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\inetpp.dll]  [Microsoft Corporation, 5.00.2195.6707]
    [C:\WINNT\system32\spool\DRIVERS\W32X86\3\CNMUI16.DLL]  [CANON INC., 1.50.2.6]
    [C:\WINNT\system32\comdlg32.dll]  [Microsoft Corporation, 5.00.3700.6693]
    [C:\WINNT\system32\MSIMG32.dll]  [Microsoft Corporation, 5.00.2180.1]
    [C:\WINNT\system32\icm32.dll]  [Microsoft Corporation, 5.00]
[PID: 528][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\IMM32.DLL]  [Microsoft Corporation, 5.00.2195.6655]
    [C:\WINNT\system32\MSVCRT.dll]  [Microsoft Corporation, 6.10.9844.0]
    [C:\WINNT\system32\OLEAUT32.dll]  [Microsoft Corporation, 2.40.4522]
    [c:\winnt\system32\ntmssvc.dll]  [Microsoft Corporation, 5.00.2195.6655]
    [c:\winnt\system32\sens.dll]  [Microsoft Corporation, 5.00.2195.6627]
    [C:\WINNT\system32\WS2_32.dll]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\WS2HELP.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\Secur32.dll]  [Microsoft Corporation, 5.00.2195.6695]
    [C:\WINNT\system32\NTDSAPI.dll]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\WSOCK32.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\system32\WLDAP32.DLL]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\NETRAP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\VERSION.dll]  [Microsoft Corporation, 5.00.2195.6623]
    [C:\WINNT\system32\LZ32.DLL]  [Microsoft Corporation, 5.00.2195.6611]
    [C:\WINNT\system32\CLUSAPI.DLL]  [Microsoft Corporation, 5.00.2195.6683]
    [C:\WINNT\system32\RESUTILS.DLL]  [Microsoft Corporation, 5.00.2195.6702]
    [c:\winnt\system32\rtutils.dll]  [Microsoft Corporation, 5.00.2168.1]
    [c:\winnt\system32\netcfgx.dll]  [Microsoft Corporation, 5.00.2195.6604]
    [c:\winnt\system32\RASAPI32.dll]  [Microsoft Corporation, 5.00.2195.6625]
    [c:\winnt\system32\RASMAN.DLL]  [Microsoft Corporation, 5.00.2195.6604]
    [c:\winnt\system32\TAPI32.DLL]  [Microsoft Corporation, 5.00.2195.6664]
    [c:\winnt\system32\RASDLG.dll]  [Microsoft Corporation, 5.00.2195.6625]
    [c:\winnt\system32\MPRAPI.dll]  [Microsoft Corporation, 5.00.2181.1]
    [c:\winnt\system32\ACTIVEDS.DLL]  [Microsoft Corporation, 5.00.2195.6601]
    [c:\winnt\system32\ADSLDPC.DLL]  [Microsoft Corporation, 5.00.2195.6701]
    [c:\winnt\system32\SETUPAPI.DLL]  [Microsoft Corporation, 5.00.2195.6622]
    [C:\WINNT\system32\rastapi.dll]  [Microsoft Corporation, 5.00.2195.6604]
    [C:\WINNT\system32\unimdm.tsp]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\uniplat.dll]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\CFGMGR32.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\NTMARTA.DLL]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\WINSPOOL.DRV]  [Microsoft Corporation, 5.00.2195.6659]
    [C:\WINNT\system32\kmddsp.tsp]  [Microsoft Corporation, 5.00.2150.1]
    [C:\WINNT\system32\ndptsp.tsp]  [Microsoft Corporation, 5.00.2143.1]
    [C:\WINNT\system32\ipconf.tsp]  [Microsoft Corporation, 5.00.2143.1]
    [C:\WINNT\system32\ICMP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\rasppp.dll]  [Microsoft Corporation, 5.00.2195.6626]
    [C:\WINNT\system32\ntlsapi.dll]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\System32\raschap.dll]  [Microsoft Corporation, 5.00.2195.6663]
    [C:\WINNT\system32\ATL.DLL]  [Microsoft Corporation, 3.00.9435]
    [C:\WINNT\System32\rastls.dll]  [Microsoft Corporation, 5.00.2195.6680]
    [C:\WINNT\system32\CRYPTUI.dll]  [Microsoft Corporation, 5.131.2195.6628]
    [C:\WINNT\system32\IMAGEHLP.dll]  [Microsoft Corporation, 5.00.2195.6613]
    [C:\WINNT\system32\WinSCard.dll]  [Microsoft Corporation, 5.00.2195.6609]
    [C:\WINNT\system32\NTMSDBA.dll]  [Microsoft Corporation, 5.00.2195.6655]
    [C:\WINNT\system32\msi.dll]  [Microsoft Corporation, 2.0.2600.1183]
    [C:\WINNT\system32\NETSHELL.dll]  [Microsoft Corporation, 5.00.2195.6604]
    [C:\WINNT\system32\WMI.dll]  [Microsoft Corporation, 5.00.2191.1]
[PID: 568][C:\WINNT\system32\regsvc.exe]  [Microsoft Corporation, 5.00.2195.6701]
    [C:\WINNT\system32\secur32.dll]  [Microsoft Corporation, 5.00.2195.6695]
[PID: 556][C:\WINNT\system32\MSTask.exe]  [Microsoft Corporation, 4.71.2195.6920]
lmq_fqh520
 楼主| 发表于 2007-3-3 13:42:24 | 显示全部楼层

再继续

[C:\WINNT\system32\MSVCRT.dll]  [Microsoft Corporation, 6.10.9844.0]
    [C:\WINNT\system32\VERSION.dll]  [Microsoft Corporation, 5.00.2195.6623]
    [C:\WINNT\system32\LZ32.DLL]  [Microsoft Corporation, 5.00.2195.6611]
    [C:\WINNT\system32\Secur32.dll]  [Microsoft Corporation, 5.00.2195.6695]
    [C:\WINNT\system32\NTDSAPI.dll]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\WSOCK32.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\system32\WS2_32.DLL]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\WS2HELP.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\WLDAP32.DLL]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\NETRAP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\IMM32.DLL]  [Microsoft Corporation, 5.00.2195.6655]
    [C:\WINNT\system32\mswsock.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\system32\msafd.dll]  [Microsoft Corporation, 5.00.2195.6602]
    [C:\WINNT\System32\wshtcpip.dll]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\System32\rnr20.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\system32\ICMP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\MPRAPI.dll]  [Microsoft Corporation, 5.00.2181.1]
    [C:\WINNT\system32\OLEAUT32.DLL]  [Microsoft Corporation, 2.40.4522]
    [C:\WINNT\system32\ACTIVEDS.DLL]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\ADSLDPC.DLL]  [Microsoft Corporation, 5.00.2195.6701]
    [C:\WINNT\system32\RTUTILS.DLL]  [Microsoft Corporation, 5.00.2168.1]
    [C:\WINNT\system32\SETUPAPI.DLL]  [Microsoft Corporation, 5.00.2195.6622]
    [C:\WINNT\system32\RASAPI32.dll]  [Microsoft Corporation, 5.00.2195.6625]
    [C:\WINNT\system32\RASMAN.DLL]  [Microsoft Corporation, 5.00.2195.6604]
    [C:\WINNT\system32\TAPI32.DLL]  [Microsoft Corporation, 5.00.2195.6664]
    [C:\WINNT\System32\winrnr.dll]  [Microsoft Corporation, 5.00.2160.1]
    [C:\WINNT\system32\MSIDLE.DLL]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\WINNT\system32\cscui.dll]  [Microsoft Corporation, 5.00.2195.6705]
    [C:\WINNT\system32\CSCDLL.DLL]  [Microsoft Corporation, 5.00.2195.6713]
    [C:\WINNT\system32\rsaenh.dll]  [Microsoft Corporation, 5.00.2195.6611]
[PID: 348][C:\WINNT\System32\WBEM\WinMgmt.exe]  [Microsoft Corporation, 1.50.1085.0100]
    [C:\WINNT\System32\WBEM\wbemcomn.dll]  [Microsoft Corporation, 1.50.1085.0100]
    [C:\WINNT\system32\MSVCRT.dll]  [Microsoft Corporation, 6.10.9844.0]
    [C:\WINNT\system32\OLEAUT32.dll]  [Microsoft Corporation, 2.40.4522]
    [C:\WINNT\system32\IMM32.DLL]  [Microsoft Corporation, 5.00.2195.6655]
[PID: 760][C:\WINNT\system32\svchost.exe]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\IMM32.DLL]  [Microsoft Corporation, 5.00.2195.6655]
    [c:\winnt\system32\wuauserv.dll]  [Microsoft Corporation, 5.4.3630.2554 built by: lab04_n]
    [C:\WINNT\system32\msvcrt.dll]  [Microsoft Corporation, 6.10.9844.0]
    [C:\WINNT\system32\OLEAUT32.dll]  [Microsoft Corporation, 2.40.4522]
    [C:\WINNT\system32\ADVPACK.dll]  [Microsoft Corporation, 5.00.3502.6601]
    [C:\WINNT\system32\VERSION.dll]  [Microsoft Corporation, 5.00.2195.6623]
    [C:\WINNT\system32\LZ32.DLL]  [Microsoft Corporation, 5.00.2195.6611]
    [C:\WINNT\system32\SHFOLDER.dll]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\WINNT\system32\WS2_32.dll]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\WS2HELP.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\ESENT.dll]  [Microsoft Corporation, 6.1.3940.31]
    [C:\WINNT\system32\WTSAPI32.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\UTILDLL.dll]  [Microsoft Corporation, 5.00.2195.6701]
    [C:\WINNT\system32\TAPI32.dll]  [Microsoft Corporation, 5.00.2195.6664]
    [C:\WINNT\system32\SETUPAPI.dll]  [Microsoft Corporation, 5.00.2195.6622]
    [C:\WINNT\system32\Secur32.dll]  [Microsoft Corporation, 5.00.2195.6695]
    [C:\WINNT\system32\NTDSAPI.dll]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\WSOCK32.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\system32\WLDAP32.DLL]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\NETRAP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\WINSTA.dll]  [Microsoft Corporation, 5.00.2195.6701]
    [C:\WINNT\system32\REGAPI.dll]  [Microsoft Corporation, 5.00.2195.6602]
    [C:\WINNT\system32\MPRAPI.dll]  [Microsoft Corporation, 5.00.2181.1]
    [C:\WINNT\system32\ACTIVEDS.DLL]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\ADSLDPC.DLL]  [Microsoft Corporation, 5.00.2195.6701]
    [C:\WINNT\system32\RTUTILS.DLL]  [Microsoft Corporation, 5.00.2168.1]
    [C:\WINNT\system32\WINSPOOL.DRV]  [Microsoft Corporation, 5.00.2195.6659]
    [C:\WINNT\system32\IMAGEHLP.dll]  [Microsoft Corporation, 5.00.2195.6613]
    [C:\WINNT\system32\Cabinet.dll]  [Microsoft Corporation, 5.00.2147.1]
    [C:\WINNT\system32\mspatcha.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINNT\system32\sfc.dll]  [Microsoft Corporation, 5.00.2195.6673]
    [C:\WINNT\system32\msafd.dll]  [Microsoft Corporation, 5.00.2195.6602]
    [C:\WINNT\System32\wshtcpip.dll]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\msi.dll]  [Microsoft Corporation, 2.0.2600.1183]
[PID: 584][C:\WINNT\system32\internat.exe]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\WINNT\system32\IMM32.DLL]  [Microsoft Corporation, 5.00.2195.6655]
    [C:\WINNT\system32\SETUPAPI.DLL]  [Microsoft Corporation, 5.00.2195.6622]
    [C:\WINNT\system32\MSVCRT.DLL]  [Microsoft Corporation, 6.10.9844.0]
    [C:\WINNT\system32\UNISPIM5.IME]  [北京紫光华宇软件股份有限公司, 5.0.0.5076]
    [C:\WINNT\system32\INDICDLL.dll]  [Microsoft Corporation, 5.00.2920.0000]
[PID: 1344][C:\WINNT\explorer.exe]  [Microsoft Corporation, 5.00.3700.6690]
    [C:\WINNT\system32\IMM32.DLL]  [Microsoft Corporation, 5.00.2195.6655]
    [C:\WINNT\system32\shim.dll]  [Microsoft Corporation, 5.00.2195.6717]
    [C:\WINNT\AppPatch\AcLayers.DLL]  [Microsoft Corporation, 5.00.2195.6717]
    [C:\WINNT\system32\INDICDLL.dll]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\WINNT\system32\UNISPIM5.IME]  [北京紫光华宇软件股份有限公司, 5.0.0.5076]
    [C:\WINNT\system32\OLEAUT32.dll]  [Microsoft Corporation, 2.40.4522]
    [C:\WINNT\system32\MSVCRT.dll]  [Microsoft Corporation, 6.10.9844.0]
    [C:\WINNT\system32\cscui.dll]  [Microsoft Corporation, 5.00.2195.6705]
    [C:\WINNT\system32\CSCDLL.DLL]  [Microsoft Corporation, 5.00.2195.6713]
    [C:\WINNT\system32\ntshrui.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\ATL.DLL]  [Microsoft Corporation, 3.00.9435]
    [C:\WINNT\system32\Secur32.dll]  [Microsoft Corporation, 5.00.2195.6695]
    [C:\WINNT\system32\NTDSAPI.dll]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\WSOCK32.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\system32\WS2_32.DLL]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\WS2HELP.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\WLDAP32.DLL]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\NETRAP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\mydocs.dll]  [Microsoft Corporation, 5.00.3502.6601]
    [C:\WINNT\System32\NETUI0.dll]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\System32\NETUI1.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\NETSHELL.dll]  [Microsoft Corporation, 5.00.2195.6604]
    [C:\WINNT\system32\webcheck.dll]  [Microsoft Corporation, 5.00.3502.6601]
    [C:\WINNT\system32\stobject.dll]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\BATMETER.DLL]  [Microsoft Corporation, 5.00.3502.6601]
    [C:\WINNT\system32\SETUPAPI.DLL]  [Microsoft Corporation, 5.00.2195.6622]
    [C:\WINNT\system32\POWRPROF.DLL]  [Microsoft Corporation, 5.00.3502.6601]
    [C:\WINNT\system32\WINMM.DLL]  [Microsoft Corporation, 5.00.2161.1]
    [C:\WINNT\system32\msi.dll]  [Microsoft Corporation, 2.0.2600.1183]
    [C:\WINNT\system32\browselc.dll]  [Microsoft Corporation, 5.00.3700.6661]
    [C:\WINNT\system32\THUNDE~1.DLL]  [, 4, 0, 0, 17]
    [C:\WINNT\system32\MFC42.DLL]  [Microsoft Corporation, 6.00.9586.0]
    [C:\WINNT\system32\MFC42LOC.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\WINNT\system32\VERSION.dll]  [Microsoft Corporation, 5.00.2195.6623]
    [C:\WINNT\system32\LZ32.DLL]  [Microsoft Corporation, 5.00.2195.6611]
    [C:\WINNT\system32\mlang.dll]  [Microsoft Corporation, 5.00.3700.6655]
    [C:\WINNT\system32\shdoclc.dll]  [Microsoft Corporation, 5.00.3700.6668]
    [C:\WINNT\system32\igfxpph.dll]  [Intel Corporation, 3.0.0.4299]
    [C:\WINNT\system32\hccutils.DLL]  [Intel Corporation, 3.0.0.4299]
    [C:\WINNT\system32\igfxres.dll]  [Intel Corporation, 3.0.0.4299]
    [C:\WINNT\system32\igfxress.dll]  [Intel Corporation, 3.0.0.4299]
    [C:\WINNT\system32\igfxsrvc.dll]  [Intel Corporation, 3.0.0.4299]
[PID: 1280][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX04.672\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [C:\WINNT\system32\COMDLG32.dll]  [Microsoft Corporation, 5.00.3700.6693]
    [C:\WINNT\system32\MSVCRT.DLL]  [Microsoft Corporation, 6.10.9844.0]
    [C:\WINNT\system32\WINSPOOL.DRV]  [Microsoft Corporation, 5.00.2195.6659]
    [C:\WINNT\system32\OLEAUT32.dll]  [Microsoft Corporation, 2.40.4522]
    [C:\WINNT\system32\VERSION.dll]  [Microsoft Corporation, 5.00.2195.6623]
    [C:\WINNT\system32\LZ32.DLL]  [Microsoft Corporation, 5.00.2195.6611]
    [C:\WINNT\system32\WINMM.dll]  [Microsoft Corporation, 5.00.2161.1]
    [C:\WINNT\system32\WS2_32.dll]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\WS2HELP.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\IMM32.DLL]  [Microsoft Corporation, 5.00.2195.6655]
    [C:\WINNT\system32\INDICDLL.dll]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\WINNT\system32\UNISPIM5.IME]  [北京紫光华宇软件股份有限公司, 5.0.0.5076]
    [C:\WINNT\system32\sfc.dll]  [Microsoft Corporation, 5.00.2195.6673]
    [C:\WINNT\system32\mlang.dll]  [Microsoft Corporation, 5.00.3700.6655]
    [C:\WINNT\system32\wsock32.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\system32\msafd.dll]  [Microsoft Corporation, 5.00.2195.6602]
    [C:\WINNT\System32\wshtcpip.dll]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\RASAPI32.DLL]  [Microsoft Corporation, 5.00.2195.6625]
    [C:\WINNT\system32\RASMAN.DLL]  [Microsoft Corporation, 5.00.2195.6604]
    [C:\WINNT\system32\TAPI32.DLL]  [Microsoft Corporation, 5.00.2195.6664]
    [C:\WINNT\system32\RTUTILS.DLL]  [Microsoft Corporation, 5.00.2168.1]
    [C:\WINNT\system32\sensapi.dll]  [Microsoft Corporation, 5.00.2195.6627]
    [C:\WINNT\system32\Secur32.dll]  [Microsoft Corporation, 5.00.2195.6695]
    [C:\WINNT\system32\NTDSAPI.dll]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\WLDAP32.DLL]  [Microsoft Corporation, 5.00.2195.6666]
    [C:\WINNT\system32\NETRAP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\System32\rnr20.dll]  [Microsoft Corporation, 5.00.2195.6603]
    [C:\WINNT\system32\ICMP.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\MPRAPI.dll]  [Microsoft Corporation, 5.00.2181.1]
    [C:\WINNT\system32\ACTIVEDS.DLL]  [Microsoft Corporation, 5.00.2195.6601]
    [C:\WINNT\system32\ADSLDPC.DLL]  [Microsoft Corporation, 5.00.2195.6701]
    [C:\WINNT\system32\SETUPAPI.DLL]  [Microsoft Corporation, 5.00.2195.6622]
    [C:\WINNT\System32\winrnr.dll]  [Microsoft Corporation, 5.00.2160.1]
    [C:\WINNT\system32\IMAGEHLP.dll]  [Microsoft Corporation, 5.00.2195.6613]
    [C:\WINNT\system32\rsaenh.dll]  [Microsoft Corporation, 5.00.2195.6611]
    [C:\WINNT\system32\ntshrui.dll]  [Microsoft Corporation, 5.00.2134.1]
    [C:\WINNT\system32\ATL.DLL]  [Microsoft Corporation, 3.00.9435]
    [C:\WINNT\system32\cscui.dll]  [Microsoft Corporation, 5.00.2195.6705]
    [C:\WINNT\system32\CSCDLL.DLL]  [Microsoft Corporation, 5.00.2195.6713]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [C:\WINNT\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
lmq_fqh520
 楼主| 发表于 2007-3-3 13:43:50 | 显示全部楼层

要晕了 最后一部分。请大侠判定一下哪里出错

==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD Tcpip [UDP/IP]
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD Tcpip [RAW/IP]
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
RSVP UDP Service Provider
    C:\WINNT\system32\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
RSVP TCP Service Provider
    C:\WINNT\system32\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
MSAFD NetBIOS [\Device\Nbf_{D6A130D6-CC13-48ED-872D-930847672B1E}] SEQPACKET 3
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\Nbf_{D6A130D6-CC13-48ED-872D-930847672B1E}] DATAGRAM 3
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{A5AEC058-7321-472B-8C1D-03C512B7ED83}] SEQPACKET 4
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{A5AEC058-7321-472B-8C1D-03C512B7ED83}] DATAGRAM 4
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{734C5FE2-1396-482E-84F4-722584044209}] SEQPACKET 5
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{734C5FE2-1396-482E-84F4-722584044209}] DATAGRAM 5
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{1B97F01D-3E80-42CD-B2A2-66670FBA7632}] SEQPACKET 6
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{1B97F01D-3E80-42CD-B2A2-66670FBA7632}] DATAGRAM 6
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{D6727FE9-99E2-4823-9CF0-98523135D7B9}] SEQPACKET 7
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{D6727FE9-99E2-4823-9CF0-98523135D7B9}] DATAGRAM 7
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{5785340D-7C46-4EAC-BD47-9A5AE72B6543}] SEQPACKET 8
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{5785340D-7C46-4EAC-BD47-9A5AE72B6543}] DATAGRAM 8
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{C5F62E77-6722-40CA-9295-CC30F128AC32}] SEQPACKET 9
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{C5F62E77-6722-40CA-9295-CC30F128AC32}] DATAGRAM 9
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D6A130D6-CC13-48ED-872D-930847672B1E}] SEQPACKET 0
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D6A130D6-CC13-48ED-872D-930847672B1E}] DATAGRAM 0
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{087436AC-AB3B-41A5-BF3E-E7347DA43F58}] SEQPACKET 1
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{087436AC-AB3B-41A5-BF3E-E7347DA43F58}] DATAGRAM 1
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{804E5453-83DB-483F-BC86-DCEB0F385208}] SEQPACKET 2
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{804E5453-83DB-483F-BC86-DCEB0F385208}] DATAGRAM 2
    C:\WINNT\system32\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1       localhost

==================================
API HOOK
警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
RVA  错误: LoadLibraryA
RVA  错误: LoadLibraryExA
RVA  错误: LoadLibraryExW
RVA  错误: LoadLibraryW

==================================


[/CODE]
lmq_fqh520
 楼主| 发表于 2007-3-3 13:48:41 | 显示全部楼层

我的是WIN2000系统,每天都用卡巴扫

wangjay1980
发表于 2007-3-3 20:46:26 | 显示全部楼层
我的天,你的系统是用来作什么的,这么多的驱动和服务。

[08141 / 08141][Stopped/Manual Start]
  <\\96.1.10.234\Admin$\eraseme_30638.exe><N/A>
用SRE把这个服务删除或者设置为disabled的
然后用卡吧全盘查杀,再用360和卡卡查查。用这个清理一下

arswp_1[1].6.0.rar

516.92 KB, 下载次数: 105

lmq_fqh520
 楼主| 发表于 2007-3-5 16:44:01 | 显示全部楼层

先在此谢过

我最后还是忍不住重装了,但还是有这病毒。
我去试下!!!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-22 16:37 , Processed in 0.107452 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表