查看: 1688|回复: 1
收起左侧

[已解决] 求助

 关闭 [复制链接]
wook117
发表于 2007-4-4 18:49:15 | 显示全部楼层 |阅读模式
各位高手:
非常感谢您留心我这份系统诊断报告,小菜鸟十万火急等待您的帮助!
该诊断报告由360安全卫士提供 http://www.360safe.com
诊断时间: 2007-04-04  18:43:47
诊断平台: Microsoft Windows XP  Service Pack 2
IE版本: Internet Explorer V6.0.2900.2180 Build:62900.2180
计算机物理内存:511MB - 当前可用内存:17MB
100 - 未知 - Process: smss.exe [] - C:\WINDOWS\system32\ShellExt\smss.exe
100 - 未知 - Process: KASStart.exe [Kingsoft System Cleaner Security Center] - C:\Program Files\Kingsoft\KSysCleaner\KASStart.EXE
R0 - 未知 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.hao123.com/
R1 - 未知 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=
O2 - 未知 - BHO: (Thunder Browser Helper) - [XunLeiBHO] - {4E83D566-4697-4F7B-B1F0-A513B01DB89A} - E:\讯雷5\ComDlls\XunLeiBHO_007.dll
O4 - 未知 - HKCU\..\Run: [KASStart] [Kingsoft System Cleaner Security Center] "C:\Program Files\Kingsoft\KSysCleaner\KASStart.EXE" -Startup
O4 - 未知 - Startup folder: [eEye Windows Animated Cursor Patch Checker.lnk] [] C:\Documents and Settings\All Users\「开始」菜单\程序\启动\eEye Windows Animated Cursor Patch Checker.lnk
O8 - 未知 - Extra context menu item: 上传到QQ网络硬盘 - E:\QQ2007\AddToNetDisk.htm
O8 - 未知 - Extra context menu item: 添加到QQ自定义面板 - E:\QQ2007\AddPanel.htm
O8 - 未知 - Extra context menu item: 添加到QQ表情 - E:\QQ2007\AddEmotion.htm
O8 - 未知 - Extra context menu item: 用QQ彩信发送该图片 - E:\QQ2007\SendMMS.htm
O9 - 未知 - Extra button: 启动迅雷5(HKLM) - E:\讯雷5\Thunder.exe
O9 - 未知 - Extra button: 番茄花园(HKLM) - [url=http://www.tomatolei.comhttp://www.tomatolei.com[/color[/url]]
O18 - 未知 - Protocol: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - E:\PROGRA~1\KuGoo3\InExtend\KUGOO3~1.OCX
O28 - 未知 - IELINK: C:\DOCUME~1\ADMINI~1\「开始~1\程序\一键还~1\INTERN~1.LNK - [url=http://www.37021.netwww.37021.net[/color[/url]]
=======================================
100 - 安全 - Process: smss.exe [进程为会话管理子系统用以初始化系统变量,ms-dos驱动名称类似lpt1以及com,调用win32壳子系统和运行在windows登陆过程。] - C:\WINDOWS\System32\smss.exe
100 - 安全 - Process: csrss.exe [客户端服务子系统,用以控制windows图形相关子系统。] - C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=base
100 - 安全 - Process: winlogon.exe [windows nt用户登陆程序。] - C:\WINDOWS\system32\winlogon.exe
100 - 安全 - Process: services.exe [用于管理windows服务系统进程。] - C:\WINDOWS\system32\services.exe
100 - 安全 - Process: lsass.exe [本地安全权限服务控制windows安全机制。] - C:\WINDOWS\system32\lsass.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k DcomLaunch
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k rpcss
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\System32\svchost.exe -k netsvcs
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k NetworkService
100 - 安全 - Process: explorer.exe [windows program manager或者windows explorer用于控制windows图形shell,包括开始菜单、任务栏,桌面和文件管理。] - C:\WINDOWS\Explorer.EXE
100 - 安全 - Process: conime.exe [console ime ime输入法控制台软件。] - C:\WINDOWS\system32\conime.exe
100 - 安全 - Process: avp.exe [卡巴斯基杀毒软件相关程序。] -
100 - 安全 - Process: 360tray.exe [360安全卫士实时监控程序。] - C:\Program Files\360safe\safemon\360tray.exe
100 - 安全 - Process: ctfmon.exe [office xp输入法图标。] - C:\WINDOWS\system32\ctfmon.exe
100 - 安全 - Process: VnetClient.exe [vnet虚拟拨号软件,用于adsl宽带拨号。] - C:\Program Files\ChinaNet\VnetClient.exe
100 - 安全 - Process: avp.exe [卡巴斯基杀毒软件相关程序。] -
100 - 安全 - Process: nvsvc32.exe [nvidia driver helper service在nvida显卡驱动中被安装。] - C:\WINDOWS\system32\nvsvc32.exe
100 - 安全 - Process: wdfmgr.exe [windows media player播放器相关程序。] - C:\WINDOWS\system32\wdfmgr.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k LocalService
100 - 安全 - Process: alg.exe [这是一个应用层网关服务用于网络共享。] - C:\WINDOWS\System32\alg.exe
100 - 安全 - Process: 360Safe.exe [360安全卫士相关程序。] - C:\Program Files\360safe\360safe.exe
R1 - 安全 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\system32\blank.htm
O2 - 安全 - BHO: (VnetCookie Class) - [星空极速, 拨号软件。] - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\chinanet\VNETTR~1.DLL
O4 - 安全 - HKLM\..\Run: [NvCplDaemon] [是NVIDIA显示卡相关动态链接库文件。] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - 安全 - HKLM\..\Run: [kav] [卡巴斯基杀毒软件相关程序。] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - 安全 - HKLM\..\Run: [360Safetray] [360safe实时保护功能模块。] C:\Program Files\360safe\safemon\360tray.exe
O4 - 安全 - HKCU\..\Run: [ctfmon.exe] [office xp输入法图标。] C:\WINDOWS\system32\ctfmon.exe
O4 - 安全 - Startup folder: [星空极速.lnk] [星空极速拨号客户端。] C:\Documents and Settings\All Users\「开始」菜单\程序\启动\星空极速.lnk
O8 - 安全 - Extra context menu item: &使用迅雷下载 - E:\讯雷5\Program\geturl.htm
O8 - 安全 - Extra context menu item: &使用迅雷下载全部链接 - E:\讯雷5\Program\getallurl.htm
O9 - 安全 - Extra button: 卡巴斯基Web反病毒保护插件(HKLM) - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O23 - 安全 - Service: AVP [卡巴斯基杀毒软件相关程序。] - "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r - (running)
O23 - 安全 - Service: NVSvc [是NVIDIA显示卡相关程序。] - C:\WINDOWS\system32\nvsvc32.exe - (running)
=======================================
O40 - winlogon.exe - Kaspersky Lab - C:\WINDOWS\system32\klogon.dll - Logon Visualizer - 7072750eb5c0f0cd54b48f972855ca61
O40 - Explorer.EXE - Thunder Networking Technologies,LTD - E:\讯雷5\ComDlls\XunLeiBHO_007.dll - XunLeiBHO - f86be67dc96656afec3e74784f9546a9
O40 - Explorer.EXE -  - E:\QQ2007\qdshm.dll - QQDiskShellMenu Module - fcda465ddd728fc39c264380e9fb06c5
O40 - Explorer.EXE - Microsoft Corporation - E:\QQ2007\MFC42.DLL - MFCDLL Shared Library - Retail Version - 07a87ef9849e4f340fe7de2d8acda639
O40 - Explorer.EXE - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\shellex.dll - Windows Shell Extension - 62281a8da78c81f4f4695c3de52ba680
=======================================
O41 - kl1 - Kaspersky Unified Driver - C:\WINDOWS\system32\drivers\kl1.sys - (running) - Kaspersky Unified Driver - Kaspersky Lab - 5445b03cd42dedf5f85b9daf712fdd09
O41 - klif - spuper-ptor - C:\WINDOWS\system32\drivers\klif.sys - (running) - spuper-ptor - Kaspersky Lab - 2985985b39e13643f941b6396fb915dd
O41 - NPF - NPF Driver - TME extensions - C:\WINDOWS\system32\drivers\npf.sys - (running) - NPF Driver - TME extensions - Politecnico di Torino - f498c5c3399a60933196fc215ef074f9
O41 - npkcrypt - nProtect KeyCrypt Driver - E:\QQ2007\npkcrypt.sys - (running) - nProtect KeyCrypt Driver - INCA Internet Co., Ltd. - 8bcb281a2540e7aff0cd00f9878fe21f
O41 - nvcap - NVIDIA WDM Video Capture (universal) - C:\WINDOWS\system32\drivers\NVCAP.SYS - (running) - NVIDIA WDM Video Capture (universal) - NVIDIA Corporation - 160c8b784f1ab7f7f14836ef507347cb
O41 - NVXBAR - NVIDIA WDM A/V Crossbar - C:\WINDOWS\system32\drivers\NVXBAR.SYS - (running) - NVIDIA WDM A/V Crossbar - NVIDIA Corporation - aab8a15ca89a1972904037ba583591f0
=======================================
360Shell.exe=1.0.1.2002
360Safe.exe=3.2.1.1001
AntiAdwa.dll=3.2.0.1001
AntiEng.dll=3.0.2.2000
AntiActi.dll=2.0.0.3000
CleanHis.dll=3.0.2.1000
safelive.exe=1.0.0.2007
live.dll=1.0.0.1011
=======================================
操作历史报告:
----------查杀恶意软件历史----------
2007-04-03 14:47
查杀恶意软件 - 灰鸽子变种0006 - 危险 - C:\WINDOWS\HACKER~1.EXE
2007-04-04 18:16
查杀恶意软件 - 灰鸽子变种残留 - 危险 - C:\WINDOWS\Delete.BAT

=======================================
360安全卫士,彻底查杀各种流氓软件,全面保护系统安全,并赠送正版卡巴斯基V6.0
最新免费下载:http://www.360safe.com
wook117
 楼主| 发表于 2007-4-4 18:49:48 | 显示全部楼层
不够 还有SRE扫描的



  1. 2007-04-04,18:28:31

  2. System Repair Engineer 2.4.12.806
  3. Smallfrogs ([url]http://www.KZTechs.com[/url])

  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件


  13. 启动项目
  14. 注册表
  15. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  16.     <KASStart><"C:\Program Files\Kingsoft\KSysCleaner\KASStart.EXE" -Startup>  [Kingsoft Corporation]
  17.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  18. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  19.     <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  20.     <kav><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
  21.     <360Safetray><C:\Program Files\360safe\safemon\360tray.exe>  [奇虎网]
  22. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  23.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  24.     <Userinit><c:\windows\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  25.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
  26. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  27.     <WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll>  [Kaspersky Lab]

  28. ==================================
  29. 启动文件夹
  30. [eEye Windows Animated Cursor Patch Checker]
  31.   <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\eEye Windows Animated Cursor Patch Checker.lnk --> C:\PROGRA~1\EEYEDI~1\WINDOW~1.ANI\ANIPAT~1.EXE [eEye Digital Security]><N>
  32. [星空极速]
  33.   <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\星空极速.lnk --> C:\PROGRA~1\ChinaNet\VNETCL~1.EXE []><N>

  34. ==================================
  35. 服务
  36. [ApplicationExperience / AeLookupSvc][Stopped/Auto Start]
  37.   <C:\WINDOWS\Help\April><N/A>
  38. [卡巴斯基反病毒6.0 / AVP][Running/Auto Start]
  39.   <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
  40. [Human Interface Device Access / HidServ][Stopped/Disabled]
  41.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  42. [NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  43.   <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>

  44. ==================================
  45. 驱动程序
  46. [Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
  47.   <system32\drivers\ALCXSENS.SYS><Sensaura>
  48. [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  49.   <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
  50. [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Running/Manual Start]
  51.   <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
  52. [kl1 / kl1][Running/Boot Start]
  53.   <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
  54. [klif / klif][Running/System Start]
  55.   <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
  56. [Netgroup Packet Filter / NPF][Running/Manual Start]
  57.   <system32\drivers\npf.sys><Politecnico di Torino>
  58. [npkcrypt / npkcrypt][Running/Auto Start]
  59.   <\??\E:\QQ2007\npkcrypt.sys><INCA Internet Co., Ltd.>
  60. [nv / nv][Running/Manual Start]
  61.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  62. [nVidia WDM Video Capture (universal) / nvcap][Running/Auto Start]
  63.   <system32\DRIVERS\nvcap.sys><NVIDIA Corporation>
  64. [nVidia WDM A/V Crossbar / NVXBAR][Running/Auto Start]
  65.   <system32\DRIVERS\NVxbar.sys><NVIDIA Corporation>
  66. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  67.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  68. [Secdrv / Secdrv][Stopped/Manual Start]
  69.   <system32\DRIVERS\secdrv.sys><N/A>
  70. [ViaIde / ViaIde][Running/Boot Start]
  71.   <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
  72. [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  73.   <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
  74. [555031 / 555031][Running/]
  75.   <2 - 系统找不到指定的文件。
  76. ><N/A>

  77. ==================================
  78. 浏览器加载项
  79. [Thunder Browser Helper]
  80.   {4E83D566-4697-4F7B-B1F0-A513B01DB89A} <E:\讯雷5\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
  81. [VnetCookie Class]
  82.   {4E83D567-4697-4F7B-B1F0-A513B01DB89A} <c:\PROGRA~1\chinanet\VNETTR~1.DLL, >
  83. [NavigatMon Class]
  84.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, >
  85. [启动迅雷5]
  86.   {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <E:\讯雷5\Thunder.exe, Thunder Networking Technologies,LTD>
  87. [Web反病毒保护]
  88.   {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll, Kaspersky Lab>
  89. [番茄花园]
  90.   {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <[url]http://www.tomatolei.com[/url], N/A>
  91. [PowerList Control]
  92.   {20C2C286-BDE8-441B-B73D-AFA22D914DA5} <C:\PROGRA~1\PPStream\POWERL~1.OCX, PPStream.com>
  93. [Windows Media Player]
  94.   {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
  95. [HTML Document]
  96.   {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\Mshtml.dll, N/A>
  97. [Thunder Browser Helper]
  98.   {4E83D566-4697-4F7B-B1F0-A513B01DB89A} <E:\讯雷5\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
  99. [VnetCookie Class]
  100.   {4E83D567-4697-4F7B-B1F0-A513B01DB89A} <c:\PROGRA~1\chinanet\VNETTR~1.DLL, >
  101. [Shell Name Space]
  102.   {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
  103. [PowerPlayer Control]
  104.   {5EC7C511-CD0F-42E6-830C-1BD9882F3458} <C:\PROGRA~1\PPStream\POWERP~1.DLL, PPStream Inc.>
  105. [Microsoft Web 浏览器]
  106.   {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
  107. [Thunder Browser Helper]
  108.   {889D2FEB-5411-4565-8998-1DD2C5261283} <E:\讯雷5\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
  109. [Microsoft Scriptlet Component]
  110.   {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\Mshtml.dll, Microsoft Corporation>
  111. [NavigatMon Class]
  112.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <C:\Program Files\360safe\safemon\safemon.dll, >
  113. [RDS.DataSpace]
  114.   {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
  115. [Shockwave Flash Object]
  116.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  117. [&使用迅雷下载]
  118.   <E:\讯雷5\Program\geturl.htm, N/A>
  119. [&使用迅雷下载全部链接]
  120.   <E:\讯雷5\Program\getallurl.htm, N/A>
  121. [上传到QQ网络硬盘]
  122.   <E:\QQ2007\AddToNetDisk.htm, N/A>
  123. [添加到QQ自定义面板]
  124.   <E:\QQ2007\AddPanel.htm, N/A>
  125. [添加到QQ表情]
  126.   <E:\QQ2007\AddEmotion.htm, N/A>
  127. [用QQ彩信发送该图片]
  128.   <E:\QQ2007\SendMMS.htm, N/A>

  129. ==================================
  130. 正在运行的进程
  131. [PID: 612][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  132. [PID: 688][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  133. [PID: 712][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  134.     [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
  135.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  136. [PID: 756][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  137. [PID: 768][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  138. [PID: 928][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  139. [PID: 1008][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  140. [PID: 1120][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  141. [PID: 1476][C:\WINDOWS\system32\ShellExt\smss.exe]  [FREE, 1.00]
  142.     [C:\WINDOWS\system32\MSVBVM60.DLL]  [Microsoft Corporation, 6.00.9690]
  143. [PID: 1500][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  144.     [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
  145.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  146.     [E:\讯雷5\ComDlls\XunLeiBHO_007.dll]  [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
  147. [PID: 1600][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  148. [PID: 1828][C:\Program Files\360safe\safemon\360tray.exe]  [奇虎网, 3, 2, 1, 1001]
  149.     [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
  150.     [C:\Program Files\360safe\safemon\SafeKrnl.dll]  [奇虎网, 3, 2, 0, 1001]
  151.     [C:\Program Files\360safe\AntiAdwa.dll]  [360Safe.com, 3, 2, 0, 1001]
  152. [PID: 1836][C:\Program Files\Kingsoft\KSysCleaner\KASStart.EXE]  [Kingsoft Corporation, 2006, 11, 22, 14]
  153.     [C:\Program Files\Kingsoft\KSysCleaner\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
  154.     [C:\Program Files\Kingsoft\KSysCleaner\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  155.     [C:\Program Files\Kingsoft\KSysCleaner\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
  156.     [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
  157.     [C:\Program Files\Kingsoft\KSysCleaner\PopSprt3.dll]  [Kingsoft Corporation, 2006, 8, 7, 38]
  158. [PID: 1844][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  159. [PID: 1876][C:\Program Files\ChinaNet\VnetClient.exe]  [, 2006, 6, 30, 11]
  160.     [C:\Program Files\ChinaNet\Communicate.dll]  [GDCN, 2006, 2, 15, 1]
  161.     [C:\Program Files\ChinaNet\DialModule.dll]  [GDCN, 2006, 7, 25, 15]
  162.     [C:\Program Files\ChinaNet\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
  163.     [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]
  164.     [C:\PROGRA~1\ChinaNet\CLIENT~1.DLL]  [, 2004, 2, 28, 1]
  165.     [C:\PROGRA~1\ChinaNet\PLUGIN~1.OCX]  [, 2006, 6, 2, 14]
  166.     [C:\PROGRA~1\ChinaNet\sign.dll]  [0, 2004, 12, 1, 1]
  167.     [C:\PROGRA~1\ChinaNet\PostPlug.dll]  [, 2004, 12, 16, 2]
  168.     [C:\PROGRA~1\ChinaNet\ADVERT~1.OCX]  [, 2006, 2, 20, 1]
  169.     [C:\PROGRA~1\ChinaNet\VnetBs.ocx]  [, 2004, 11, 18, 1]
  170.     [C:\PROGRA~1\ChinaNet\VnetSkin.ocx]  [GDDC, 2005, 12, 21, 1]
  171.     [C:\PROGRA~1\ChinaNet\DialogStyle.dll]  [, 1, 0, 0, 1]
  172.     [C:\PROGRA~1\ChinaNet\BDSearch.ocx]  [gdcn, 2005, 12, 22, 1]
  173.     [C:\PROGRA~1\ChinaNet\PageFram.ocx]  [Workgroup, 2006, 9, 21, 21]
  174.     [C:\PROGRA~1\ChinaNet\AccPage.ocx]  [, 6, 12, 6, 11]
  175.     [C:\PROGRA~1\ChinaNet\AccountMgr.dll]  [, 2006, 5, 26, 11]
  176.     [C:\PROGRA~1\ChinaNet\Timer.ocx]  [, 2006, 12, 5, 17]
  177.     [C:\PROGRA~1\ChinaNet\PLUGIN~2.OCX]  [, 2006, 4, 4, 1]
  178.     [C:\PROGRA~1\ChinaNet\NEWMES~1.DLL]  [, 2006, 12, 5, 11]
  179.     [C:\PROGRA~1\ChinaNet\PassCtrl.dll]  [GDCN, 2006, 3, 1, 16]
  180.     [C:\WINDOWS\system32\wpcap.dll]  [Politecnico di Torino, 3, 0, 0, 18]
  181.     [C:\WINDOWS\system32\pthreadVC.dll]  [N/A, ]
  182.     [C:\WINDOWS\system32\packet.dll]  [Politecnico di Torino, 3, 0, 0, 18]
  183.     [C:\PROGRA~1\ChinaNet\PlugPush.dll]  [, 2004, 12, 21, 1]
  184.     [C:\PROGRA~1\ChinaNet\ALLINT~1.DLL]  [, 2006, 7, 19, 14]
  185.     [C:\PROGRA~1\ChinaNet\VNETLO~1.OCX]  [, 2006, 11, 19, 14]
  186.     [C:\PROGRA~1\ChinaNet\StatNum.dll]  [, 2006, 11, 10, 17]
  187.     [C:\PROGRA~1\ChinaNet\VNETON~1.OCX]  [, 2005, 3, 2, 1]
  188.     [C:\PROGRA~1\ChinaNet\ALLFUN~1.DLL]  [GDCN, 2006, 8, 23, 16]
  189.     [C:\PROGRA~1\ChinaNet\VnetOptLog.dll]  [ , 2006, 5, 10, 14]
  190.     [C:\PROGRA~1\ChinaNet\DlgSkin.ocx]  [, 2005, 11, 14, 1]
  191.     [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
  192.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  193.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
  194.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
  195.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
  196.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
  197.     [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
  198.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl]  [Kaspersky Lab, 6.0.0.299]
  199.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
  200.     [c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
  201.     [D:\杀软\SREng.com]  [Smallfrogs Studio, 2.4.12.806]
  202.     [C:\Program Files\360safe\safemon\safemon.dll]  [, 3, 2, 0, 1001]

  203. ==================================
  204. 文件关联
  205. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  206. .EXE  OK. ["%1" %*]
  207. .COM  OK. ["%1" %*]
  208. .PIF  OK. ["%1" %*]
  209. .REG  OK. [regedit.exe "%1"]
  210. .BAT  OK. ["%1" %*]
  211. .SCR  OK. ["%1" /S]
  212. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  213. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  214. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  215. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  216. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  217. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  218. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  219. ==================================
  220. Winsock 提供者
  221. N/A

  222. ==================================
  223. Autorun.inf
  224. N/A

  225. ==================================
  226. HOSTS 文件
  227. 127.0.0.1       localhost

  228. ==================================
  229. API HOOK
  230. RVA  错误: LoadLibraryA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF69C7B25)
  231. RVA  错误: LoadLibraryExA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF69C7D67)
  232. RVA  错误: LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF69C7F0B)
  233. RVA  错误: LoadLibraryW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF69C7C49)
  234. 入口点错误:CreateProcessA (危险等级: 一般,  被下面模块所HOOK: C:\Program Files\360safe\safemon\safemon.dll)
  235. 入口点错误:CreateProcessW (危险等级: 一般,  被下面模块所HOOK: C:\Program Files\360safe\safemon\safemon.dll)
  236. RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: Dest Addr: 0xF69C7E8F)

  237. ==================================
  238. 隐藏进程
  239.     [468] C:\Program Files\Internet Explorer\IEXPLORE.EXE

  240. ==================================


复制代码








还有  我机子最近  重起都是非法关机的提示
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-24 23:59 , Processed in 0.133130 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表