查看: 1489|回复: 8
收起左侧

[已解决] 大会诊啰!!

 关闭 [复制链接]
剑指七星
发表于 2007-4-17 14:12:17 | 显示全部楼层 |阅读模式
下面的报告是在学校的电脑扫的,大家来会诊一下,看一下这台机器的症状,我们上课的时候,这台机器老是出故障,烦死人了!老机器了,没有办法,整天插U盘,里面病毒奇多无比,毒库一个!

  1. 2007-04-10,09:40:56
  2. System Repair Engineer 2.4.12.806
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows XP Professional Service Pack 1 (Build 2600) - 管理权限用户 - 完整功能
  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件

  13. 启动项目
  14. 注册表
  15. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  16.     <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>  [(Verified)Microsoft Windows XP Publisher]
  17.     <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Windows XP Publisher]
  18.     <DrvMon.exe><C:\WINDOWS\System32\DrvMon.exe>  [Alcor Micro, Corp.]
  19.     <Ntcheck><C:\WINDOWS\mapserver.exe>  [UNDEATH]
  20. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
  21.     <Cmpnt><c:\windows\system\mainsv.exe>  [UNDEATH]
  22. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  23.     <load><>  [N/A]
  24. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  25.     <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows XP Publisher]
  26.     <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows XP Publisher]
  27.     <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows XP Publisher]
  28.     <IgfxTray><C:\WINDOWS\System32\igfxtray.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  29.     <HotKeysCmds><C:\WINDOWS\System32\hkcmd.exe>  [(Verified)Microsoft Windows XP Publisher]
  30.     <Cmaudio><RunDll32 cmicnfg.cpl,CMICtrlWnd>  [N/A]
  31.     <SysExplr><C:\Herosoft\Hero2000\SYSEXPLR.EXE>  []
  32.     <RavTimer><C:\Program Files\Rising\Rav\RavTimer.exe>  [Beijing Rising Technology Co., Ltd.]
  33.     <RavMon><C:\Program Files\Rising\Rav\RavMon.exe -system>  [Beijing Rising Technology Co., Ltd.]
  34.     <Cmpnt><C:\WINDOWS\system\cmpku.exe>  [UNDEATH]
  35. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
  36.     <Shell><c:\windows\system\mainsv.exe>  [UNDEATH]
  37. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  38.     <shell><Explorer.exe>  [(Verified)Microsoft Windows XP Publisher]
  39.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows XP Publisher]
  40. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  41.     <AppInit_DLLs><>  [N/A]
  42. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  43.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows XP Publisher]
  44. ==================================
  45. 启动文件夹
  46. [Microsoft Office]
  47.   <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk --> D:\MICROS~1\Office10\OSA.EXE [Microsoft Corporation]><N>
  48. ==================================
  49. 服务
  50. [Lexar JD31 / LxrJD31s][Running/Auto Start]
  51.   <LxrJD31s.exe><N/A>
  52. [Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start]
  53.   <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><>
  54. [Rising Process Communication Center / RsCCenter][Running/Auto Start]
  55.   <C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE><rising>
  56. [RsRavMon Service / RsRavMon][Running/Auto Start]
  57.   <C:\PROGRAM FILES\RISING\RAV\Ravmond.exe><Beijing Rising Technology Co., Ltd.>
  58. [Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
  59.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\System32\mspmsnsv.dll><Microsoft Corporation>
  60. ==================================
  61. 驱动程序
  62. [BaseTDI / BaseTDI][Running/Auto Start]
  63.   <\??\C:\WINDOWS\System32\drivers\basetdi.sys><Rising>
  64. [C-Media WDM Audio Interface / cmuda][Running/Manual Start]
  65.   <system32\drivers\cmuda.sys><C-Media Inc>
  66. [Rising Exploit Scaner 1.0 / ExpScaner][Running/Manual Start]
  67.   <\??\C:\PROGRAM FILES\RISING\RAV\ExpScan.sys><>
  68. [HOOKAPI / HOOKAPI][Running/Auto Start]
  69.   <\??\C:\PROGRAM FILES\RISING\RAV\HOOKAPI.SYS><瑞星软件有限公司>
  70. [HookCont / HookCont][Running/Auto Start]
  71.   <\??\C:\PROGRAM FILES\RISING\RAV\HOOKCONT.sys><Rising tech Co. ltd>
  72. [HookReg / HookReg][Running/Auto Start]
  73.   <\??\C:\PROGRAM FILES\RISING\RAV\HOOKREG.sys><>
  74. [HookSys / HookSys][Running/Auto Start]
  75.   <\??\C:\PROGRAM FILES\RISING\RAV\hooksys.sys><瑞星>
  76. [ialm / ialm][Running/Manual Start]
  77.   <System32\DRIVERS\ialmnt5.sys><Intel Corporation>
  78. [LxrJD31d / LxrJD31d][Running/Auto Start]
  79.   <\??\C:\WINDOWS\System32\Drivers\LxrJD31d.sys><N/A>
  80. [MEMSCAN / MEMSCAN][Running/Auto Start]
  81.   <\??\C:\PROGRAM FILES\RISING\RAV\MEMSCAN.SYS><瑞星软件有限公司>
  82. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  83.   <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  84. [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  85.   <System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
  86. [Secdrv / Secdrv][Stopped/Manual Start]
  87.   <System32\DRIVERS\secdrv.sys><N/A>
  88. [Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/System Start]
  89.   <system32\drivers\ialmsbw.sys><Intel Corporation>
  90. [Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start]
  91.   <system32\drivers\ialmkchw.sys><Intel Corporation>
  92. ==================================
  93. 浏览器加载项
  94. [@shdoclc.dll,-866]
  95.   {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
  96. [电台(&R)]
  97.   {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
  98. [Shockwave Flash Object]
  99.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\macromed\flash\Flash.ocx, Macromedia, Inc.>
  100. [导出到 Microsoft Excel(&x)]
  101.   <res://D:\MICROS~1\Office10\EXCEL.EXE/3000, N/A>
  102. ==================================
  103. 正在运行的进程
  104. [PID: 536][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
  105. [PID: 616][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  106. [PID: 640][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
  107.     [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
  108.     [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  109. [PID: 1216][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
  110.     [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
  111.     [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  112.     [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
  113.     [C:\WINDOWS\System32\RavExt.DLL]  [Beijing Rising Technology Co., Ltd., 17, 0, 0, 3]
  114.     [D:\Microsoft Office\Office10\msohev.dll]  [Microsoft Corporation, 10.0.2609]
  115.     [C:\WINDOWS\System32\igfxpph.dll]  [Intel Corporation, 3,0,0,1918]
  116.     [C:\WINDOWS\System32\hccutils.DLL]  [Intel Corporation, 3,0,0,1918]
  117. [PID: 1860][C:\WINDOWS\System32\hkcmd.exe]  [Intel Corporation, 3,0,0,1918]
  118.     [C:\WINDOWS\System32\hccutils.DLL]  [Intel Corporation, 3,0,0,1918]
  119.     [C:\WINDOWS\System32\igfxdev.dll]  [Intel Corporation, 3,0,0,1918]
  120.     [C:\WINDOWS\System32\igfxsrvc.dll]  [Intel Corporation, 3,0,0,1918]
  121.     [C:\WINDOWS\System32\igfxhk.dll]  [Intel Corporation, 3,0,0,1918]
  122.     [C:\WINDOWS\System32\igfxres.dll]  [Intel Corporation, 3,0,0,1918]
  123. [PID: 1900][C:\WINDOWS\System32\RunDll32.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  124.     [C:\WINDOWS\system\cmicnfg.cpl]  [C-Media Corporation, 1, 0, 0, 35]
  125. [PID: 1936][C:\Herosoft\Hero2000\SYSEXPLR.EXE]  [N/A, ]
  126.     [C:\Herosoft\Hero2000\AVCDROM.dll]  [N/A, ]
  127. [PID: 1972][C:\Program Files\Rising\Rav\RavTimer.exe]  [Beijing Rising Technology Co., Ltd., 17, 0, 0, 32]
  128.     [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 17, 0, 0, 17]
  129.     [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Rising Corp., 17, 0, 0, 5]
  130.     [C:\Program Files\Rising\Rav\CfgDll.dll]  [rising, 17, 0, 0, 39]
  131.     [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 17, 0, 0, 3]
  132. [PID: 2016][C:\Program Files\Rising\Rav\RavMon.exe]  [Beijing Rising Technology Co., Ltd., 17, 0, 1, 0]
  133.     [C:\Program Files\Rising\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 17, 0, 0, 33]
  134.     [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Rising Corp., 17, 0, 0, 5]
  135.     [C:\Program Files\Rising\Rav\CfgDll.dll]  [rising, 17, 0, 0, 39]
  136.     [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 17, 0, 0, 3]
  137.     [C:\Program Files\Rising\Rav\PngDll.dll]  [Rising, 17, 0, 0, 2]
  138.     [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 17, 0, 0, 17]
  139. [PID: 2024][C:\WINDOWS\system\cmpku.exe]  [UNDEATH, 3.02]
  140.     [C:\WINDOWS\System32\MSVBVM60.DLL]  [Microsoft Corporation, 6.00.9237]
  141. [PID: 124][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
  142. [PID: 172][C:\Program Files\Messenger\msmsgs.exe]  [Microsoft Corporation, 4.7.0041]
  143.     [C:\Program Files\Messenger\MSGSLANG.DLL]  [Microsoft Corporation, 4.7.0041]
  144.     [C:\PROGRA~1\MESSEN~1\rtcimsp.dll]  [Microsoft Corporation, 4.0.3599.0 (Lab02_N(ntvbl02).020107-1351)]
  145.     [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
  146.     [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  147.     [C:\WINDOWS\System32\msdmo.dll]  [, ]
  148. [PID: 184][C:\WINDOWS\System32\DrvMon.exe]  [Alcor Micro, Corp., 1, 0, 0, 9]
  149. [PID: 1296][I:\Tools\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
  150.     [I:\Tools\sreng2\Plugins\NWMON.SRE]  [Smallfrogs Studio, 1, 0, 0, 8]
  151. ==================================
  152. 文件关联
  153. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  154. .EXE  OK. ["%1" %*]
  155. .COM  OK. ["%1" %*]
  156. .PIF  OK. ["%1" %*]
  157. .REG  OK. [regedit.exe "%1"]
  158. .BAT  OK. ["%1" %*]
  159. .SCR  OK. ["%1" /S]
  160. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  161. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  162. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  163. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  164. .VBS  Error. [超级解霸2000]
  165. .JS   Error. ["C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" "%1"]
  166. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  167. ==================================
  168. Winsock 提供者
  169. N/A
  170. ==================================
  171. Autorun.inf
  172. [D:\]
  173. [Autorun]
  174. open=Iexplores.exe
  175. [E:\]
  176. [Autorun]
  177. open=Iexplores.exe
  178. [F:\]
  179. [Autorun]
  180. open=Iexplores.exe
  181. [G:\]
  182. [Autorun]
  183. open=Iexplores.exe
  184. ==================================
  185. HOSTS 文件
  186. 127.0.0.1       localhost
  187. ==================================
  188. API HOOK
  189. N/A
  190. ==================================
  191. 隐藏进程
  192. N/A
  193. ==================================
复制代码
无敌敏敏
发表于 2007-4-17 14:31:57 | 显示全部楼层
<Cmpnt><c:\windows\system\mainsv.exe>  [UNDEATH]
<Ntcheck><C:\WINDOWS\mapserver.exe>  [UNDEATH]
Autorun.inf
[D:\]
[Autorun]
open=Iexplores.exe
[E:\]
[Autorun]
open=Iexplores.exe
[F:\]
[Autorun]
open=Iexplores.exe
[G:\]
[Autorun]
open=Iexplores.exe

2个文件关联错误
.VBS  Error. [超级解霸2000]
.JS   Error. ["C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" "%1"]
剑指七星
 楼主| 发表于 2007-4-17 15:57:49 | 显示全部楼层
对了  这就
老是播放视频的时候  出乱子
mds
发表于 2007-4-17 16:48:51 | 显示全部楼层
经常插U盘备个这个不错!杀U盘病毒不错!七星改用瑞星啦?

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
可樂仔
发表于 2007-4-17 17:10:08 | 显示全部楼层
<DrvMon.exe><C:\WINDOWS\System32\DrvMon.exe>  [Alcor Micro, Corp.]
    <Ntcheck><C:\WINDOWS\mapserver.exe>  [UNDEATH]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <Cmpnt><c:\windows\system\mainsv.exe>  [UNDEATH]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
    <Shell><c:\windows\system\mainsv.exe>  [UNDEATH]

<Cmpnt><C:\WINDOWS\system\cmpku.exe>

Autorun.inf
[D:\]
[Autorun]
open=Iexplores.exe
[E:\]
[Autorun]
open=Iexplores.exe
[F:\]
[Autorun]
open=Iexplores.exe
[G:\]
[Autorun]
open=Iexplores.exe

杀吧
剑指七星
 楼主| 发表于 2007-4-17 18:37:47 | 显示全部楼层
原帖由 mds 于 2007-4-17 16:48 发表
经常插U盘备个这个不错!杀U盘病毒不错!七星改用瑞星啦?


这个是学校的机器   超级老的设备了
剑指七星
 楼主| 发表于 2007-4-17 18:39:06 | 显示全部楼层

回复 #5 可樂仔 的帖子

学校机器的杀毒杀不了    病毒库还是2006年的
什么时候搞个绿色的卡巴去耍一耍   
mds
发表于 2007-4-17 19:19:23 | 显示全部楼层

回复 #7 200530040058 的帖子

绿色大蜘蛛也不错哦!
大胖大胖
发表于 2007-4-20 13:14:59 | 显示全部楼层
请问高手你看那上面那么多乱七八糟的程序怎么看出错误来的啊..我想学习一下...

我现在看那个就头疼啊
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-25 05:45 , Processed in 0.132826 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表