查看: 2464|回复: 6
收起左侧

[已解决] 帮忙看下日志

[复制链接]
jon112233
发表于 2009-12-31 09:16:50 | 显示全部楼层 |阅读模式
本帖最后由 jon112233 于 2009-12-31 19:06 编辑

那位高人帮忙看下这个日志有什么问题?
Malwarebytes' Anti-Malware 1.43
数据库版本: 3460
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
2009-12-31 9:21:41
mbam-log-2009-12-31 (09-21-39).txt
扫描类型:快速扫描
被扫描对象数目: 101635
时间过去: 3 minute(s), 59 second(s)
被感染内存进程数目: 0
被感染内存模块数目: 0
被感染注册表项数目: 0
被感染注册表值数目: 1
被感染注册表数据项数目: 6
被感染文件夹数目: 0
被感染文件数目: 2
被感染内存进程数目:
(没有检测到有害项目)
被感染内存模块数目:
(没有检测到有害项目)
被感染注册表项数目:
(没有检测到有害项目)
被感染注册表值数目:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\disableconfig (Windows.Tool.Disabled) -> No action taken.
被感染注册表数据项数目:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
被感染文件夹数目:
(没有检测到有害项目)
被感染文件数目:
C:\WINDOWS\syste
tawny2008
发表于 2009-12-31 11:55:07 | 显示全部楼层
用sreng扫描个上来
jon112233
 楼主| 发表于 2009-12-31 12:27:46 | 显示全部楼层
回复 2# tawny2008


  1. 2009-12-31,12:34:31

  2. System Repair Engineer 2.8.2.1321
  3. Smallfrogs (http://www.KZTechs.com)

  4. Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描
  14.     计划任务
  15.     API HOOK
  16.     隐藏进程


  17. 启动项目
  18. 注册表
  19. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  20.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Component Publisher]
  21. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  22.     <ACMON><C:\Program Files\ASUS\Splendid\ACMON.exe>  [ATK]
  23.     <HControl><C:\WINDOWS\ATK0100\HControl.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  24.     <Wireless Console 2><C:\Program Files\Wireless Console 2\wcourier.exe>  []
  25.     <Power_Gear><C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1>  [File is missing]
  26.     <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  27.     <nwiz><nwiz.exe /install>  []
  28.     <avgnt><"C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min>  [Avira GmbH]
  29.     <Shadow Defender Daemon><"C:\Program Files\Shadow Defender\DefenderDaemon.exe" /auto>  [shadowdefender.com]
  30.     <AntiLogger><"C:\Program Files\AntiLogger\AntiLogger.exe" /minimized>  [(Verified)Zemana Information Technologies Industry Limited]
  31.     <AdobeCS4ServiceManager><"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin>  [(Verified)Adobe Systems Incorporated]
  32.     <Adobe Reader Speed Launcher><; "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe">  [(Verified)Adobe Systems, Incorporated]
  33.     <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Component Publisher]
  34.     <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Component Publisher]
  35.     <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Component Publisher]
  36.     <SMSERIAL><; sm56hlpr.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  37.     <WebThunder><; >  [N/A]
  38. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  39.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Component Publisher]
  40.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Component Publisher]
  41.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Component Publisher]
  42. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  43.     <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Windows Component Publisher]
  44.     <{4F07DA45-8170-4859-9B5F-037EF2970034}><>  [N/A]
  45. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  46.     <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Component Publisher]
  47.     <CDBurn><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Component Publisher]
  48.     <WebCheck><%SystemRoot%\system32\webcheck.dll>  [(Verified)Microsoft Windows Component Publisher]
  49.     <SysTray><C:\WINDOWS\system32\stobject.dll>  [(Verified)Microsoft Windows Component Publisher]
  50. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
  51.     <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Windows Component Publisher]
  52. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
  53.     <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Windows Component Publisher]
  54. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
  55.     <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Windows Component Publisher]
  56. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
  57.     <WinlogonNotify: dimsntfy><%SystemRoot%\System32\dimsntfy.dll>  [(Verified)Microsoft Windows Component Publisher]
  58. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
  59.     <WinlogonNotify: ScCertProp><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
  60. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
  61.     <WinlogonNotify: Schedule><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
  62. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
  63.     <WinlogonNotify: sclgntfy><sclgntfy.dll>  [(Verified)Microsoft Windows Component Publisher]
  64. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
  65.     <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Windows Component Publisher]
  66. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
  67.     <WinlogonNotify: termsrv><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
  68. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
  69.     <WinlogonNotify: WgaLogon><WgaLogon.dll>  []
  70. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
  71.     <WinlogonNotify: wlballoon><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
  72. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
  73.     <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
  74.     <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
  75. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
  76.     <Microsoft Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows Component Publisher]
  77. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  78.     <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [File is missing]
  79. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
  80.     <浏览器自定义组件><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP>  [(Verified)Microsoft Windows Component Publisher]
  81. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  82.     <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [File is missing]
  83. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  84.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
  85. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  86.     <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [File is missing]
  87. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
  88.     <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Component Publisher]
  89. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
  90.     <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Component Publisher]
  91. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  92.     <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
  93. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  94.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]
  95. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
  96.     <Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows Component Publisher]
  97. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
  98.     <Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe>  [(Verified)Microsoft Windows Component Publisher]
  99. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
  100.     <N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install>  [(Verified)Microsoft Corporation]
  101. [HKEY_CURRENT_USER\Control Panel\Desktop]
  102.     <SCRNSAVE.EXE><C:\WINDOWS\System32\logon.scr>  [(Verified)Microsoft Windows Component Publisher]

  103. ==================================
  104. 启动文件夹
  105. N/A

  106. ==================================
  107. 服务
  108. [a-squared Free Service / a2free][Running/Auto Start]
  109.   <"E:\下载\A2USB\a2service.exe"><Emsi Software GmbH>
  110. [Avira AntiVir MailGuard / AntiVirMailService][Stopped/Disabled]
  111.   <"C:\Program Files\Avira\AntiVir Desktop\avmailc.exe"><Avira GmbH>
  112. [Avira AntiVir Scheduler / AntiVirSchedulerService][Running/Auto Start]
  113.   <"C:\Program Files\Avira\AntiVir Desktop\sched.exe"><Avira GmbH>
  114. [Avira AntiVir Guard / AntiVirService][Running/Auto Start]
  115.   <"C:\Program Files\Avira\AntiVir Desktop\avguard.exe"><Avira GmbH>
  116. [Avira AntiVir WebGuard / AntiVirWebService][Running/Auto Start]
  117.   <"C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE"><Avira GmbH>
  118. [FLEXnet Licensing Service / FLEXnet Licensing Service][Stopped/Manual Start]
  119.   <"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"><Acresso Software Inc.>
  120. [Human Interface Device Access / HidServ][Stopped/Disabled]
  121.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  122. [iolo FileInfoList Service / ioloFileInfoList][Running/Auto Start]
  123.   <C:\Program Files\iolo\common\lib\ioloServiceManager.exe><>
  124. [iolo System Service / ioloSystemService][Running/Auto Start]
  125.   <C:\Program Files\iolo\common\lib\ioloServiceManager.exe><>
  126. [NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  127.   <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
  128. [TuneUp Designerweiterung / UxTuneUp][Running/Auto Start]
  129.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\uxtuneup.dll><TuneUp Software GmbH>

  130. ==================================
  131. 驱动程序
  132. [ADI UAA Function Driver for High Definition Audio Service / ADIHdAudAddService][Running/Manual Start]
  133.   <system32\drivers\ADIHdAud.sys><Analog Devices, Inc.>
  134. [AMD Processor Driver / AmdK8][Running/System Start]
  135.   <system32\DRIVERS\AmdK8.sys><Advanced Micro Devices>
  136. [AntiLog32 / AntiLog32][Running/System Start]
  137.   <\??\C:\Program Files\AntiLogger\AntiLog32.sys><Zemana Ltd.>
  138. [Atheros Wireless Network Adapter Service / AR5211][Running/Manual Start]
  139.   <system32\DRIVERS\ar5211.sys><Atheros Communications, Inc.>
  140. [ASNDIS5 Protocol Driver / ASNDIS5][Running/Manual Start]
  141.   <\??\C:\WINDOWS\ATK0100\ASNDIS5.SYS><Printing Communications Assoc., Inc. (PCAUSA)>
  142. [avgio / avgio][Running/System Start]
  143.   <\??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys><Avira GmbH>
  144. [avgntflt / avgntflt][Running/Auto Start]
  145.   <system32\DRIVERS\avgntflt.sys><Avira GmbH>
  146. [avipbb / avipbb][Running/System Start]
  147.   <system32\DRIVERS\avipbb.sys><Avira GmbH>
  148. [Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start]
  149.   <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
  150. [ISO DVD/CD-ROM Device Driver / ISODrive][Running/System Start]
  151.   <\??\C:\Program Files\UltraISO\drivers\ISODrive.sys><EZB Systems, Inc.>
  152. [ATK0100 ACPI UTILITY / MTsensor][Running/Manual Start]
  153.   <system32\DRIVERS\ATKACPI.sys><>
  154. [nv / nv][Running/Manual Start]
  155.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  156. [nvsmu / nvsmu][Running/Manual Start]
  157.   <system32\DRIVERS\nvsmu.sys><NVIDIA Corporation>
  158. [OADriver / OADevice][Stopped/System Start]
  159.   <\??\C:\WINDOWS\system32\drivers\OADriver.sys><N/A>
  160. [OAmon / OAmon][Stopped/System Start]
  161.   <\??\C:\WINDOWS\system32\drivers\OAmon.sys><N/A>
  162. [OAnet / OAnet][Stopped/System Start]
  163.   <\??\C:\WINDOWS\system32\drivers\OAnet.sys><N/A>
  164. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  165.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  166. [rimmptsk / rimmptsk][Running/Manual Start]
  167.   <system32\DRIVERS\rimmptsk.sys><REDC>
  168. [rimsptsk / rimsptsk][Running/Manual Start]
  169.   <system32\DRIVERS\rimsptsk.sys><REDC>
  170. [Ricoh xD-Picture Card Driver / rismxdp][Running/Manual Start]
  171.   <system32\DRIVERS\rixdptsk.sys><REDC>
  172. [Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Stopped/Manual Start]
  173.   <system32\DRIVERS\Rtlnicxp.sys><Realtek Semiconductor Corporation>
  174. [Secdrv / Secdrv][Stopped/Manual Start]
  175.   <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
  176. [SmartAVS / SmartAVS][Stopped/Manual Start]
  177.   <\??\C:\WINDOWS\system32\drivers\SmartAVS.sys><All-In-Smart [CWJ]>
  178. [SMSC IrCC Miniport Device Driver / SMCIRDA][Running/Manual Start]
  179.   <system32\DRIVERS\smcirda.sys><SMSC>
  180. [smserial / smserial][Running/Manual Start]
  181.   <system32\DRIVERS\smserial.sys><Motorola Inc.>
  182. [SRS Labs Premium Sound / SRS_PremiumSound_Service][Stopped/Manual Start]
  183.   <system32\drivers\srs_PremiumSound_i386.sys><>
  184. [ssmdrv / ssmdrv][Running/System Start]
  185.   <system32\DRIVERS\ssmdrv.sys><Avira GmbH>
  186. [TCP/IP Protocol Driver / Tcpip][Running/System Start]
  187.   <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
  188. [tmcomm / tmcomm][Stopped/Manual Start]
  189.   <\??\C:\WINDOWS\system32\drivers\tmcomm.sys><Trend Micro Inc.>
  190. [USB2.0 0.35M WebCam / usbvm321][Running/Manual Start]
  191.   <System32\Drivers\usbvm321.sys><Vimicro Corporation>
  192. [WINIO / WINIO][Stopped/Manual Start]
  193.   <\??\C:\Program Files\DriveTheLife\winio.sys><N/A>

  194. ==================================
  195. 浏览器加载项
  196. [ThunderAtOnce Class]
  197.   {01443AEC-0FD1-40fd-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD>
  198. [Adobe PDF Reader Link Helper]
  199.   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll, (Signed) Adobe Systems Incorporated>
  200. [Thunder Browser Helper]
  201.   {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD>
  202. [启动迅雷5]
  203.   {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, (Signed) ShenZhen Thunder Networking Technologies,LTD>
  204. []
  205.   {e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, (Signed) N/A>
  206. [Messenger]
  207.   {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, (Signed) Microsoft Corporation>
  208. []
  209.   {00000AAA-A363-466E-BEF5-9BB68697AA7F} <, >
  210. [ThunderAtOnce Class]
  211.   {01443AEC-0FD1-40FD-9C87-E93D1494C233} <C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD>
  212. []
  213.   {03507A1A-E0C5-4404-AA26-205385C0892D} <, >
  214. [Adobe PDF Reader Link Helper]
  215.   {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll, (Signed) Adobe Systems Incorporated>
  216. []
  217.   {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <, >
  218. [Thunder Agent Class]
  219.   {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, (Signed) Thunder Networking Technologies,LTD>
  220. [XMP Class]
  221.   {6483F145-A768-4C41-AACC-52D4D7845851} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work, ShenZhen Thunder Networking Technologies,LTD>
  222. [MediaComm Class]
  223.   {7670648D-461B-42AF-BDFE-46D26AF5EFF2} <C:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin18.dll, (Signed) ShenZhen Thunder Networking Technologies,LTD>
  224. [Microsoft Web 浏览器]
  225.   {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, (Signed) Microsoft Corporation>
  226. [Thunder Browser Helper]
  227.   {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD>
  228. []
  229.   {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} <, >
  230. []
  231.   {962EFB8E-2683-42D4-AC74-AAA4C759B9C6} <, >
  232. [OFrameObject Class]
  233.   {9701758C-4373-482E-B13C-776C048EC890} <C:\Program Files\Common Files\Thunder Network\KanKan\DapCtrl.2.3.5814.166.(49).dll, (Signed) ShenZhen Thunder Networking Technologies Ltd.>
  234. [VersionDetector Class]
  235.   {9EFF1953-9694-47B1-AEF6-B2A3FE8BFE9B} <C:\Program Files\Common Files\Thunder Network\KanKan\vd.1.1.0.15.(49).dll, (Signed) ShenZhen Thunder Networking Technologies,Ltd.>
  236. [DapCtrl Class]
  237.   {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} <C:\Program Files\Common Files\Thunder Network\KanKan\DapCtrl.2.3.5814.166.(49).dll, (Signed) ShenZhen Thunder Networking Technologies Ltd.>
  238. [Shockwave Flash Object]
  239.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\Flash9f.ocx, (Signed) Adobe Systems, Inc.>
  240. []
  241.   {E2E2DD38-D088-4134-82B7-F2BA38496583} <, >
  242. [XPPlayer Class]
  243.   {F3E70CEA-956E-49CC-B444-73AFE593AD7F} <C:\Program Files\Common Files\Thunder Network\KanKan\PPlayer.2.1.58110.250.(410).dll, (Signed) ShenZhen Thunder Networking Technologies,LTD>
  244. []
  245.   {FB5F1910-F110-11D2-BB9E-00C04F795683} <, >
  246. [使用迅雷下载]
  247.   <C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
  248. [使用迅雷下载全部链接]
  249.   <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
  250. [导出到 Microsoft Office Excel(&X)]
  251.   <res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>

  252. ==================================
  253. 正在运行的进程
  254. [PID: 552][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  255. [PID: 668][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  256. [PID: 696][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
  257.     [C:\WINDOWS\system32\sfc_os.dll]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  258.     [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  259.     [C:\WINDOWS\system32\WgaLogon.dll]  [, ]
  260. [PID: 740][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  261. [PID: 752][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
  262.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  263. [PID: 924][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  264.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  265. [PID: 972][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  266.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  267.     [C:\Program Files\Avira\AntiVir Desktop\avsda.dll]  [Avira GmbH, 9.00.01.01]
  268. [PID: 1012][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  269.     [C:\WINDOWS\System32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  270.     [c:\windows\system32\uxtuneup.dll]  [TuneUp Software GmbH, 2.0.0.11]
  271.     [C:\Program Files\Avira\AntiVir Desktop\avsda.dll]  [Avira GmbH, 9.00.01.01]
  272.     [C:\WINDOWS\System32\sfc_os.dll]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  273. [PID: 1100][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  274.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  275.     [C:\Program Files\Avira\AntiVir Desktop\avsda.dll]  [Avira GmbH, 9.00.01.01]
  276. [PID: 1384][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
  277.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  278.     [C:\WINDOWS\system32\sfc_os.dll]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  279. [PID: 1504][C:\Program Files\Avira\AntiVir Desktop\sched.exe]  [Avira GmbH, 9.00.00.09]
  280.     [C:\Program Files\Avira\AntiVir Desktop\schedr.dll]  [Avira GmbH, 8.00.05.00]
  281.     [C:\Program Files\Avira\AntiVir Desktop\avevtlog.dll]  [Avira GmbH, 9.00.00.07]
  282.     [C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll]  [, 3.06.01.00]
  283. [PID: 1512][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  284.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  285.     [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 8, 120]
  286.     [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll]  [ShenZhen Thunder Networking Technologies,LTD, 1, 0, 0, 20]
  287.     [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll]  [ShenZhen Thunder Networking Technologies,LTD, 1, 0, 0, 16]
  288.     [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS]  [Adobe Systems, Inc., 8.0.0.0]
  289.     [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
  290.     [C:\Program Files\Shadow Defender\shellext.dll]  [shadowdefender.com, 1.1.0.216]
  291.     [C:\Program Files\Avira\AntiVir Desktop\shlext.dll]  [Avira GmbH, 9.00.00.04]
  292.     [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 8.1.0.0]
  293.     [C:\WINDOWS\system32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.8602]
  294.     [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.8602]
  295.     [C:\WINDOWS\system32\nvshell.dll]  [, ]
  296.     [C:\WINDOWS\system32\shdoclc.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  297.     [C:\Program Files\UltraISO\isoshell.dll]  [EZB Systems, Inc., 1, 0, 0, 2]
  298. [PID: 1524][C:\Program Files\Avira\AntiVir Desktop\avguard.exe]  [Avira GmbH, 9.00.01.32]
  299.     [C:\Program Files\Avira\AntiVir Desktop\AVEvtLog.dll]  [Avira GmbH, 9.00.00.07]
  300.     [C:\Program Files\Avira\AntiVir Desktop\guardmsg.dll]  [Avira GmbH, 9.00.02.00]
  301.     [C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll]  [, 3.06.01.00]
  302.     [C:\Program Files\Avira\AntiVir Desktop\AVPREF.DLL]  [Avira GmbH, 9.00.03.00]
  303.     [C:\Program Files\Avira\AntiVir Desktop\SMTPLIB.DLL]  [Avira GmbH, 9.02.00.25]
  304.     [C:\Program Files\Avira\AntiVir Desktop\AVGIO.DLL]  [Avira GmbH, 9.00.01.04]
  305.     [C:\Program Files\Avira\AntiVir Desktop\aecore.dll]  [Avira GmbH, 8.1.9.1]
  306.     [C:\Program Files\Avira\AntiVir Desktop\aevdf.dll]  [Avira GmbH, 8.1.1.2]
  307.     [C:\Program Files\Avira\AntiVir Desktop\aescript.dll]  [Avira GmbH, 8.1.3.4]
  308.     [C:\Program Files\Avira\AntiVir Desktop\aescn.dll]  [Avira GmbH, 8.1.3.0]
  309.     [C:\Program Files\Avira\AntiVir Desktop\aesbx.dll]  [Avira GmbH, 8.1.1.1]
  310.     [C:\Program Files\Avira\AntiVir Desktop\aerdl.dll]  [Avira GmbH, 8.1.3.4]
  311.     [C:\Program Files\Avira\AntiVir Desktop\aepack.dll]  [Avira GmbH, 8.2.0.3]
  312.     [C:\Program Files\Avira\AntiVir Desktop\unacev2.dll]  [ACE Compression Software, 2.6.0.2]
  313.     [C:\Program Files\Avira\AntiVir Desktop\aeoffice.dll]  [Avira GmbH, 8.1.0.38]
  314.     [C:\Program Files\Avira\AntiVir Desktop\aeheur.dll]  [Avira GmbH, 8.1.0.189]
  315.     [C:\Program Files\Avira\AntiVir Desktop\aehelp.dll]  [Avira GmbH, 8.1.9.0]
  316.     [C:\Program Files\Avira\AntiVir Desktop\aegen.dll]  [Avira GmbH, 8.1.1.82]
  317.     [C:\Program Files\Avira\AntiVir Desktop\aeemu.dll]  [Avira GmbH, 8.1.1.0]
  318.     [C:\Program Files\Avira\AntiVir Desktop\aebb.dll]  [Avira GmbH, 8.1.0.3]
  319.     [C:\Program Files\Avira\AntiVir Desktop\avesvc.dll]  [Avira GmbH, 9.00.02.07]
  320.     [C:\Program Files\Avira\AntiVir Desktop\avesvcr.dll]  [Avira GmbH, 9.00.00.00]
  321.     [C:\Program Files\Avira\AntiVir Desktop\onlcfg.dll]  [Avira GmbH, 1.00.00.01]
  322.     [C:\Program Files\Avira\AntiVir Desktop\avipc.dll]  [Avira GmbH, 1.1.3.4]
  323.     [C:\Program Files\Avira\AntiVir Desktop\webcat.dll]  [Avira GmbH, 9.00.14.00]
  324. [PID: 1640][C:\Program Files\ASUS\Splendid\ACMON.exe]  [ATK, 1, 0, 4, 221]
  325.     [C:\Program Files\ASUS\Splendid\GLCDdll.dll]  [, 1, 0, 0, 729]
  326.     [C:\Program Files\ASUS\Splendid\Chameleon.dll]  [ASUSTeK, 1, 0, 0, 3]
  327. [PID: 1648][C:\WINDOWS\ATK0100\HControl.exe]  [, 1043, 2, 15, 58]
  328.     [C:\WINDOWS\ATK0100\CMSSC.dll]  [N/A, ]
  329.     [C:\WINDOWS\ATK0100\inter_f2.dll]  [ATK, 1043, 2, 15, 52]
  330.     [C:\WINDOWS\ATK0100\ATKWLIOC.DLL]  [ACTIONTEC Electronics,Inc, 2.01.02]
  331.     [C:\WINDOWS\ATK0100\SiSPkt.dll]  [Silicon Integrated Systems Corp., 1, 0, 0, 45]
  332.     [C:\WINDOWS\ATK0100\ASUSNET.dll]  [, 1, 9, 9, 1]
  333.     [C:\WINDOWS\ATK0100\ASW32N50.dll]  [Printing Communications Assoc., Inc. (PCAUSA), 5.00.13.50]
  334. [PID: 1656][C:\Program Files\Wireless Console 2\wcourier.exe]  [, 2, 0, 2, 0]
  335.     [C:\Program Files\Wireless Console 2\MSIMG32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  336. [PID: 1664][C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe]  [ASUSTeK Computer Inc., 1043, 6, 15, 116]
  337.     [C:\Program Files\ASUS\Power4 Gear\ATKMETHOD.dll]  [ASUSTeK Computer Inc., 1043, 6, 15, 116]
  338. [PID: 1700][C:\WINDOWS\system32\ACEngSvr.exe]  [ASUSTeK, 1, 0, 0, 4]
  339.     [C:\WINDOWS\system32\icm32.dll]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
  340. [PID: 1776][C:\Program Files\Avira\AntiVir Desktop\avgnt.exe]  [Avira GmbH, 9.00.00.12]
  341.     [C:\Program Files\Avira\AntiVir Desktop\cclib.dll]  [Avira GmbH, 9.00.00.10]
  342.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  343.     [c:\program files\avira\antivir desktop\ccgen.dll]  [Avira GmbH, 9.00.00.35]
  344.     [c:\program files\avira\antivir desktop\ccgenrc.dll]  [Avira GmbH, 9.00.17.01]
  345.     [c:\program files\avira\antivir desktop\ccguard.dll]  [Avira GmbH, 9.00.00.19]
  346.     [c:\program files\avira\antivir desktop\ccgrdrc.dll]  [Avira GmbH, 9.00.06.02]
  347.     [c:\program files\avira\antivir desktop\avipc.dll]  [Avira GmbH, 1.1.3.4]
  348.     [c:\program files\avira\antivir desktop\ccupdate.dll]  [Avira GmbH, 9.00.00.16]
  349.     [c:\program files\avira\antivir desktop\ccupdrc.dll]  [Avira GmbH, 9.00.06.01]
  350.     [c:\program files\avira\antivir desktop\cclic.dll]  [Avira GmbH, 9.00.00.06]
  351.     [c:\program files\avira\antivir desktop\cclicrc.dll]  [Avira GmbH, 9.00.01.00]
  352.     [c:\program files\avira\antivir desktop\ccwgrd.dll]  [Avira GmbH, 9.00.00.17]
  353.     [c:\program files\avira\antivir desktop\ccwgrdrc.dll]  [Avira GmbH, 9.00.07.00]
  354.     [c:\program files\avira\antivir desktop\ccmsg.dll]  [Avira GmbH, 9.00.02.01]
  355. [PID: 1784][C:\Program Files\Shadow Defender\DefenderDaemon.exe]  [shadowdefender.com, 1, 1, 0, 216]
  356. [PID: 1812][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
  357.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  358. [PID: 588][E:\下载\A2USB\a2service.exe]  [Emsi Software GmbH, 4.5.0.31]
  359. [PID: 604][C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE]  [Avira GmbH, 9.0.5.0]
  360.     [C:\Program Files\Avira\AntiVir Desktop\avipc.dll]  [Avira GmbH, 1.1.3.4]
  361.     [C:\Program Files\Avira\AntiVir Desktop\msgclient.dll]  [Avira GmbH, 9.00.00.00]
  362.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  363.     [C:\Program Files\Avira\AntiVir Desktop\avsda.dll]  [Avira GmbH, 9.00.01.01]
  364. [PID: 176][C:\Program Files\iolo\common\lib\ioloServiceManager.exe]  [, ]
  365.     [C:\Program Files\iolo\Common\Lib\fbembed.dll]  [The Firebird Project, WI-V1.5.2.4731]
  366.     [C:\Program Files\Avira\AntiVir Desktop\avsda.dll]  [Avira GmbH, 9.00.01.01]
  367. [PID: 1040][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.8602]
  368. [PID: 1836][C:\WINDOWS\system32\wuauclt.exe]  [Microsoft Corporation, 7.4.7600.226 (winmain_wtr_wsus3sp2(wmbla).090806-1834)]
  369.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  370. [PID: 2272][C:\WINDOWS\ATK0100\ATKOSD.exe]  [, 1043, 2, 15, 57]
  371. [PID: 2296][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
  372.     [C:\WINDOWS\System32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  373.     [C:\Program Files\Avira\AntiVir Desktop\avsda.dll]  [Avira GmbH, 9.00.01.01]
  374. [PID: 1444][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  375.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  376.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.5581 (xpsp_sp3_qfe.080415-1416)]
  377. [PID: 508][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  378.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  379.     [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.5.34]
  380.     [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
  381.     [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 8.0.0.2006102200]
  382.     [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 8, 120]
  383.     [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll]  [ShenZhen Thunder Networking Technologies,LTD, 1, 0, 0, 20]
  384.     [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll]  [ShenZhen Thunder Networking Technologies,LTD, 1, 0, 0, 16]
  385.     [C:\WINDOWS\system32\shdoclc.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  386.     [C:\Program Files\Avira\AntiVir Desktop\avsda.dll]  [Avira GmbH, 9.00.01.01]
  387.     [C:\WINDOWS\system32\macromed\flash\Flash9f.ocx]  [Adobe Systems, Inc., 9,0,124,0]
  388.     [C:\WINDOWS\system32\GOOGLEPINYIN2.IME]  [Google Inc., 2.1.9.59]
  389.     [C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.5581 (xpsp_sp3_qfe.080415-1416)]
  390. [PID: 3092][C:\WINDOWS\system32\wbem\wmiprvse.exe]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)]
  391.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  392. [PID: 3520][C:\Documents and Settings\yEL@ng\桌面\SREngLdr.EXE]  [Smallfrogs Studio, 2.8.2.1321]
  393. [PID: 3532][C:\Documents and Settings\yEL@ng\桌面\SREc34be30.EXE]  [Smallfrogs Studio, 2.8.2.1321]
  394.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  395.     [C:\Program Files\Avira\AntiVir Desktop\avsda.dll]  [Avira GmbH, 9.00.01.01]
  396.     [C:\WINDOWS\system32\sfc_os.dll]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  397. [PID: 3244][C:\Documents and Settings\yEL@ng\桌面\SREc34be30.EXE]  [Smallfrogs Studio, 2.8.2.1321]
  398.     [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
  399.     [C:\WINDOWS\system32\sfc_os.dll]  [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
  400.     [C:\Documents and Settings\yEL@ng\桌面\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
  401.     [C:\Program Files\Avira\AntiVir Desktop\avsda.dll]  [Avira GmbH, 9.00.01.01]

  402. ==================================
  403. 文件关联
  404. .TXT  Error. []
  405. .EXE  OK. ["%1" %*]
  406. .COM  OK. ["%1" %*]
  407. .PIF  OK. ["%1" %*]
  408. .REG  OK. [regedit.exe "%1"]
  409. .BAT  OK. ["%1" %*]
  410. .SCR  Error. [NOTEPAD.EXE %1]
  411. .CHM  Error. ["hh.exe" %1]
  412. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  413. .INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
  414. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  415. .VBS  Error. [NOTEPAD.EXE %1]
  416. .JS   Error. []
  417. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  418. ==================================
  419. Winsock 提供者
  420. AVSDA over [MSAFD Tcpip [TCP/IP]]
  421.     C:\Program Files\Avira\AntiVir Desktop\avsda.dll(Avira GmbH, AntiVir layered service provider)
  422. AVSDA over [MSAFD Tcpip [UDP/IP]]
  423.     C:\Program Files\Avira\AntiVir Desktop\avsda.dll(Avira GmbH, AntiVir layered service provider)
  424. AVSDA
  425.     C:\Program Files\Avira\AntiVir Desktop\avsda.dll(Avira GmbH, AntiVir layered service provider)

  426. ==================================
  427. Autorun.inf
  428. N/A

  429. ==================================
  430. HOSTS 文件
  431. 127.0.0.1       localhost
  432. 127.0.0.1 activate.adobe.com
  433. 127.0.0.1 practivate.adobe.com
  434. 127.0.0.1 ereg.adobe.com
  435. 127.0.0.1 activate.wip3.adobe.com
  436. 127.0.0.1 wip3.adobe.com
  437. 127.0.0.1 3dns-3.adobe.com
  438. 127.0.0.1 3dns-2.adobe.com
  439. 127.0.0.1 adobe-dns.adobe.com
  440. 127.0.0.1 adobe-dns-2.adobe.com
  441. 127.0.0.1 adobe-dns-3.adobe.com
  442. 127.0.0.1 ereg.wip3.adobe.com
  443. 127.0.0.1 activate-sea.adobe.com
  444. 127.0.0.1 wwis-dubc1-vip60.adobe.com
  445. 127.0.0.1 activate-sjc0.adobe.com
  446. 127.0.0.1 activate.adobe.com

  447. ==================================
  448. 进程特权扫描
  449. 特殊特权被允许: SeLoadDriverPrivilege [PID = 696, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
  450. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1504, C:\PROGRAM FILES\AVIRA\ANTIVIR DESKTOP\SCHED.EXE]
  451. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1524, C:\PROGRAM FILES\AVIRA\ANTIVIR DESKTOP\AVGUARD.EXE]
  452. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1640, C:\PROGRAM FILES\ASUS\SPLENDID\ACMON.EXE]
  453. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1656, C:\PROGRAM FILES\WIRELESS CONSOLE 2\WCOURIER.EXE]
  454. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1664, C:\PROGRAM FILES\ASUS\POWER4 GEAR\BATTERYLIFE.EXE]
  455. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1700, C:\WINDOWS\SYSTEM32\ACENGSVR.EXE]
  456. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1776, C:\PROGRAM FILES\AVIRA\ANTIVIR DESKTOP\AVGNT.EXE]
  457. 特殊特权被允许: SeLoadDriverPrivilege [PID = 1784, C:\PROGRAM FILES\SHADOW DEFENDER\DEFENDERDAEMON.EXE]

  458. ==================================
  459. 计划任务
  460. [已启用] AWC AutoSweep.job
  461.         C:\Program Files\IObit\Advanced SystemCare 3\AutoSweep.exe
  462. [已启用] 12-27-2009_190200.job
  463.         C:\Program Files\Spyware Cease\SpywareCease.exe

  464. ==================================
  465. Windows 安全更新检查
  466. N/A

  467. ==================================
  468. API HOOK
  469. N/A

  470. ==================================
  471. 隐藏进程
  472. N/A

  473. ==================================


复制代码
tawny2008
发表于 2009-12-31 18:54:48 | 显示全部楼层
回复 3# jon112233


    不知道你想问什么,日志没什么问题
jon112233
 楼主| 发表于 2009-12-31 18:57:12 | 显示全部楼层
回复 4# tawny2008


    其实我是问一楼的扫描出来的东西是什么?是不是误报
tawny2008
发表于 2009-12-31 19:01:07 | 显示全部楼层
本帖最后由 tawny2008 于 2009-12-31 19:02 编辑

回复 5# jon112233

一楼的日志是因为你自己改了一些文件关联,所以才报的,在sreng日志里面看出来了,另外一些是你的杀软改的,100%误报。
jon112233
 楼主| 发表于 2009-12-31 19:04:45 | 显示全部楼层
本帖最后由 jon112233 于 2010-1-6 19:00 编辑

回复 6# tawny2008
很好,感谢你的解答[:27:]
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-12 08:05 , Processed in 0.147738 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表