查看: 1298|回复: 1
收起左侧

[已解决] 我中了什么毒啊?

 关闭 [复制链接]
踏雪之痕
发表于 2007-4-23 23:08:44 | 显示全部楼层 |阅读模式
请高手能帮我看看





  1. 2007-04-23,22:57:32
  2. System Repair Engineer 2.4.12.806
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件

  13. 启动项目
  14. 注册表
  15. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  16.     <jiajiasr><D:\news\jiajia\jj4\jiajiasr.exe>  [加加工作组]
  17. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  18.     <load><>  [N/A]
  19.     <run><>  [N/A]
  20. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  21.     <kis><"D:\shadu\kis\avp.exe">  [Kaspersky Lab]
  22.     <TkBellExe><"E:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [(Verified)"RealNetworks, Inc."]
  23. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  24.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  25.     <Userinit><E:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  26. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  27.     <AppInit_DLLs><D:\shadu\kis\adialhk.dll>  [Kaspersky Lab]
  28. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  29.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
  30. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  31.     <WinlogonNotify: klogon><E:\WINDOWS\system32\klogon.dll>  [Kaspersky Lab]
  32. [HKEY_CURRENT_USER\Control Panel\Desktop]
  33.     <SCRNSAVE.EXE><E:\WINDOWS\system32\KALEIDO.SCR>  [WeiserWare]
  34. ==================================
  35. 启动文件夹
  36. N/A
  37. ==================================
  38. 服务
  39. [Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
  40.   <"E:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
  41. [卡巴斯基互联网安全套装 6.0 / AVP][Running/Auto Start]
  42.   <D:\shadu\kis\avp.exe -r><Kaspersky Lab>
  43. [Human Interface Device Access / HidServ][Stopped/Disabled]
  44.   <E:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  45. ==================================
  46. 驱动程序
  47. [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  48.   <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
  49. [VIA Rhine-Family Fast Ethernet Adapter Driver Service / FETND5BV][Running/Manual Start]
  50.   <system32\DRIVERS\fetnd5bv.sys><VIA Technologies, Inc.>
  51. [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  52.   <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
  53. [kl1 / kl1][Running/Boot Start]
  54.   <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
  55. [klif / klif][Running/System Start]
  56.   <\??\E:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
  57. [npkcrypt / npkcrypt][Running/Auto Start]
  58.   <\??\D:\news\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
  59. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  60.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  61. [Secdrv / Secdrv][Stopped/Manual Start]
  62.   <system32\DRIVERS\secdrv.sys><N/A>
  63. [USB PC Camera (SNPSTD3) / SNPSTD3][Stopped/Manual Start]
  64.   <system32\DRIVERS\snpstd3.sys><>
  65. [viagfx / viagfx][Running/Manual Start]
  66.   <system32\DRIVERS\vtmini.sys><Copyright (C) VIA/S3 Graphics Co, Ltd.>
  67. [ViaIde / ViaIde][Running/Boot Start]
  68.   <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
  69. [viamraid / viamraid][Running/Boot Start]
  70.   <\SystemRoot\system32\DRIVERS\viamraid.sys><VIA Technologies inc,.ltd>
  71. [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  72.   <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
  73. ==================================
  74. 浏览器加载项
  75. N/A
  76. ==================================
  77. 正在运行的进程
  78. [PID: 604][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  79. [PID: 684][\??\E:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  80. [PID: 708][\??\E:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  81.     [E:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
  82.     [E:\WINDOWS\system32\PYJJ4.IME]  [加加工作组, 4, 1, 0, 48]
  83.     [E:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  84. [PID: 752][E:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  85. [PID: 764][E:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  86. [PID: 924][E:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  87. [PID: 1008][E:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  88. [PID: 1112][E:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  89.     [D:\shadu\kis\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  90. [PID: 1856][E:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  91.     [E:\WINDOWS\system32\PYJJ4.IME]  [加加工作组, 4, 1, 0, 48]
  92.     [E:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  93.     [E:\Program Files\WinRAR\rarext.dll]  [N/A, ]
  94.     [D:\shadu\kis\shellex.dll]  [Kaspersky Lab, 6.0.0.299]
  95.     [D:\shadu\kis\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  96. [PID: 940][E:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3760]
  97.     [E:\WINDOWS\system32\PYJJ4.IME]  [加加工作组, 4, 1, 0, 48]
  98. [PID: 948][D:\news\jiajia\jj4\jiajiasr.exe]  [加加工作组, 4, 1, 0, 47]
  99.     [E:\WINDOWS\system32\PYJJ4.IME]  [加加工作组, 4, 1, 0, 48]
  100. [PID: 2316][E:\DOCUME~1\专用\LOCALS~1\Temp\Rar$EX00.375\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
  101.     [E:\WINDOWS\system32\PYJJ4.IME]  [加加工作组, 4, 1, 0, 48]
  102.     [D:\shadu\kis\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
  103. ==================================
  104. 文件关联
  105. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  106. .EXE  OK. ["%1" %*]
  107. .COM  OK. ["%1" %*]
  108. .PIF  OK. ["%1" %*]
  109. .REG  OK. [regedit.exe "%1"]
  110. .BAT  OK. ["%1" %*]
  111. .SCR  OK. ["%1" /S]
  112. .CHM  OK. ["E:\WINDOWS\hh.exe" %1]
  113. .HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
  114. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  115. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  116. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  117. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  118. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  119. ==================================
  120. Winsock 提供者
  121. N/A
  122. ==================================
  123. Autorun.inf
  124. N/A
  125. ==================================
  126. HOSTS 文件
  127. 127.0.0.1       localhost
  128. ==================================
  129. API HOOK
  130. RVA  错误: LoadLibraryA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF5BFAB25)
  131. RVA  错误: LoadLibraryExA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF5BFAD67)
  132. RVA  错误: LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF5BFAF0B)
  133. RVA  错误: LoadLibraryW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF5BFAC49)
  134. RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: Dest Addr: 0xF5BFAE8F)
  135. ==================================
  136. 隐藏进程
  137. N/A
  138. ==================================
复制代码
wangjay1980
发表于 2007-4-23 23:32:20 | 显示全部楼层
没问题
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-25 06:37 , Processed in 0.122207 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表