找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 1092|回复: 6

help/?|| - -

[复制链接]

该用户从未签到

发表于 2008-2-23 09:28:48 | 显示全部楼层 |阅读模式

  1. 2008-02-23,09:27:51
  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描

  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  18. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
  19.     <FlashPlayerUpdate><C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe>  [(Verified)Adobe Systems Incorporated]
  20. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  21.     <AntiARPStandalone><C:\Program Files\AntiARP Stand-alone Edition\AntiArp.exe>  []
  22.     <switch><c:\windows\system32\壁纸自动换.exe>  []
  23.     <YuanZhiStudent><C:\Program Files\YuanZhi\Multimedia Education Network\Student.exe RunServices>  [N/A]
  24.     <runeip><"C:\Program Files\Rising\AntiSpyware\runiep.exe" /startup>  [Beijing Rising Technology Co., Ltd.]
  25.     <360Safetray><D:\D盘内容(软件)\⑤杀毒软件\360安全卫士\safemon\360tray.exe /start>  [奇虎网]
  26.     <360Antiarp><d:\d盘内容(软件)\⑤杀毒软件\360安全卫士\antiarp\AntiArp.exe /start>  [奇虎网]
  27. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
  28.     <wiasoisao><wiasoisao.exe>  []
  29. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  30.     <shell><Explorer.exe>  []
  31.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  32. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  33.     <AppInit_DLLs><>  [N/A]
  34. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  35.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
  36. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  37.     <{696ccf2b-badc-48ed-b6a6-4c74639663ba}><C:\WINDOWS\system32\CBBCBB1030.dll>  []
  38.     <{4f79092a-66ba-4317-b2c7-f839909661f0}><C:\WINDOWS\system32\KABKAB1032.dll>  []
  39.     <{9eb02d98-1c8f-45f5-93af-f66fa9174db0}><C:\WINDOWS\system32\BAABAA1028.dll>  []
  40.     <{6167F471-EF2B-41DD-A5E5-C26ACDB5C096}><C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys>  []
  41.     <{cd51bd9c-6264-4df0-96bf-8603019818e5}><C:\WINDOWS\system32\HACHAC1035.dll>  []
  42.     <{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><C:\WINDOWS\system32\sgrefg.dll>  []
  43.     <{5aca2e15-0790-4170-812a-890df2fb6144}><C:\WINDOWS\system32\QABQAB1013.dll>  []
  44.     <{4FA10261-B890-F432-A453-69F1023513F4}><C:\WINDOWS\Fonts\gjcsdyc.dll>  []
  45. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  46.     <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Publisher]
  47. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DfLogon]
  48.     <WinlogonNotify: DfLogon><LogonDll.dll>  []
  49. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  50.     <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
  51. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  52.     <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
  53. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  54.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
  55. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  56.     <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
  57. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
  58.     <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
  59. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
  60.     <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
  61. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  62.     <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub>  [(Verified)Microsoft Windows Publisher]
  63. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  64.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]
  65. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  66.     <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>  [N/A]
  67.     <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [N/A]
  68.     <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>  [N/A]
  69. ==================================
  70. 启动文件夹
  71. N/A
  72. ==================================
  73. 服务
  74. [DF5Serv / DF5Serv][Running/Auto Start]
  75.   <C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe><Faronics Corporation>
  76. [Human Interface Device Access / HidServ][Stopped/Disabled]
  77.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  78. [Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start]
  79.   <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><>
  80. ==================================
  81. 驱动程序
  82. [360AntiArp / 360AntiArp][Running/System Start]
  83.   <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><奇虎网>
  84. [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  85.   <system32\drivers\ac97intc.sys><Intel Corporation>
  86. [AliIde / AliIde][Running/Boot Start]
  87.   <\SystemRoot\System32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
  88. [AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
  89.   <System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
  90. [AntiARP NDIS Protocol Driver / AntiArpNdisProt][Running/Auto Start]
  91.   <system32\DRIVERS\AntiArpNdisProt.sys><Windows (R) 2000 DDK provider>
  92. [CmdIde / CmdIde][Running/Boot Start]
  93.   <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
  94. [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  95.   <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
  96. [VIA Rhine Family Fast Ethernet Adapter Driver Service / FETNDISB][Running/Manual Start]
  97.   <system32\DRIVERS\fetnd5b.sys><VIA Technologies, Inc.>
  98. [npkcrypt / npkcrypt][Stopped/Auto Start]
  99.   <\??\C:\Program Files\QQ2006\npkcrypt.sys><N/A>
  100. [nv / nv][Stopped/Manual Start]
  101.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  102. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  103.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  104. [RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  105.   <\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising Technology Co., Ltd.>
  106. [Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Stopped/Manual Start]
  107.   <system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
  108. [S3SavageNB / S3SavageNB][Running/Manual Start]
  109.   <system32\DRIVERS\s3gnbm.sys><S3 Graphics, Inc.>
  110. [Secdrv / Secdrv][Stopped/Manual Start]
  111.   <system32\DRIVERS\secdrv.sys><N/A>
  112. [VIA AGP Filter / viaagp1][Running/Boot Start]
  113.   <\SystemRoot\system32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
  114. [ViaIde / ViaIde][Running/Boot Start]
  115.   <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
  116. [Vinyl AC'97 Audio Controller (WDM) / VIAudio][Stopped/Manual Start]
  117.   <system32\drivers\vinyl97.sys><VIA Technologies, Inc.>
  118. [xAntiArpSpoof Service / xAntiArp][Running/Manual Start]
  119.   <system32\DRIVERS\xAntiArp.sys><Windows (R) 2000 DDK provider>
  120. [fpids32 / fpids32][Running/Auto Start]
  121.   <\??\C:\WINDOWS\system32\drivers\msosfpids32.sys><N/A>
  122. [msertk / msertk][Running/Auto Start]
  123.   <system32\drivers\msyecp.sys><N/A>
  124. [pop / pop][Running/Manual Start]
  125.   <\??\C:\WINDOWS\system32\DRIVERS\pop.sys><N/A>
  126. ==================================
  127. 浏览器加载项
  128. [ThunderAtOnce Class]
  129.   {01443AEC-0FD1-40fd-9C87-E93D1494C233} <c:\program files\thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
  130. []
  131.   {6167F471-EF2B-41DD-A5E5-C26ACDB5C096} <C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys, N/A>
  132. [Thunder Browser Helper]
  133.   {B69F34DC-F0F9-42DC-9EDD-957187DA688D} <c:\program files\thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  134. [SafeMon Class]
  135.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <d:\D盘内~1\⑤杀毒~1\360安~1\safemon\safemon.dll, 奇虎网>
  136. [ThunderAtOnce Class]
  137.   {01443AEC-0FD1-40FD-9C87-E93D1494C233} <c:\program files\thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
  138. [Thunder Agent Class]
  139.   {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <c:\program files\thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
  140. []
  141.   {6167F471-EF2B-41DD-A5E5-C26ACDB5C096} <C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys, N/A>
  142. [360SafeLive]
  143.   {87515F61-A66C-4319-A0E0-D416CB8059E3} <D:\D盘内容(软件)\⑤杀毒软件\360安全卫士\live.dll, 360safe.com>
  144. [Microsoft Web 浏览器]
  145.   {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
  146. [SearchAssistantOC]
  147.   {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
  148. [Thunder Browser Helper]
  149.   {B69F34DC-F0F9-42DC-9EDD-957187DA688D} <c:\program files\thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  150. [SafeMon Class]
  151.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <d:\D盘内~1\⑤杀毒~1\360安~1\safemon\safemon.dll, 奇虎网>
  152. [RDS.DataSpace]
  153.   {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
  154. [Shockwave Flash Object]
  155.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  156. [使用迅雷下载]
  157.   <c:\program files\thunder\Program\geturl.htm, N/A>
  158. [使用迅雷下载全部链接]
  159.   <c:\program files\thunder\Program\getallurl.htm, N/A>
  160. [导出到 Microsoft Office Excel(&X)]
  161.   <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
  162. [添加到QQ表情]
  163.   <d:\Program Files\QQ2007\AddEmotion.htm, N/A>
  164. ==================================
  165. 正在运行的进程
  166. [PID: 1644 / Administrator][C:\WINDOWS\Explorer.EXE]  [N/A, ]
  167.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  168.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  169.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  170.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  171.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  172.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  173.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  174.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  175.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  176.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  177.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  178.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  179.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  180. [PID: 1796 / Administrator][C:\WINDOWS\system32\dllcache\explorer.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  181.     [C:\WINDOWS\system32\dllcache\BROWSEUI.dll]  [Microsoft Corporation, 6.00.2900.3231 (xpsp_sp2_gdr.071010-1320)]
  182.     [C:\WINDOWS\system32\dllcache\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  183.     [C:\WINDOWS\system32\dllcache\ShimEng.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  184.     [C:\WINDOWS\system32\dllcache\WINMM.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  185.     [C:\WINDOWS\system32\dllcache\MSACM32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  186.     [C:\WINDOWS\system32\dllcache\LPK.DLL]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  187.     [C:\WINDOWS\system32\dllcache\USP10.dll]  [Microsoft Corporation, 1.0420.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  188.     [C:\WINDOWS\system32\dllcache\CLBCATQ.DLL]  [Microsoft Corporation, 2001.12.4414.308]
  189.     [C:\WINDOWS\system32\dllcache\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.258]
  190.     [C:\WINDOWS\system32\dllcache\LINKINFO.dll]  [Microsoft Corporation, 5.1.2600.2751 (xpsp_sp2_gdr.050831-1520)]
  191.     [C:\WINDOWS\system32\dllcache\ntshrui.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  192.     [C:\WINDOWS\system32\dllcache\ATL.DLL]  [Microsoft Corporation, 3.05.2284]
  193.     [C:\WINDOWS\system32\dllcache\msi.dll]  [Microsoft Corporation, 3.1.4000.4039]
  194.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  195.     [C:\WINDOWS\system32\dllcache\WINSTA.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  196.     [C:\WINDOWS\system32\WPDShServiceObj.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
  197.     [C:\WINDOWS\system32\PortableDeviceTypes.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
  198.     [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
  199.     [C:\WINDOWS\system32\dllcache\rsaenh.dll]  [Microsoft Corporation, 5.1.2600.2161 (xpsp.040706-1629)]
  200.     [C:\WINDOWS\system32\dllcache\SXS.DLL]  [Microsoft Corporation, 5.1.2600.3019 (xpsp_sp2_gdr.061019-0414)]
  201.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  202.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  203.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  204.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  205.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  206.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  207.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  208.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  209.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  210.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  211.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  212.     [C:\WINDOWS\Fonts\gjcsdyc.dll]  [N/A, ]
  213.     [C:\WINDOWS\system32\CBBCBB1030.dll]  [N/A, ]
  214.     [C:\WINDOWS\system32\KABKAB1032.dll]  [N/A, ]
  215.     [C:\WINDOWS\system32\BAABAA1028.dll]  [N/A, ]
  216.     [C:\WINDOWS\system32\HACHAC1035.dll]  [N/A, ]
  217.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  218.     [C:\WINDOWS\system32\QABQAB1013.dll]  [N/A, ]
  219.     [C:\WINDOWS\system32\dllcache\RASAPI32.DLL]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  220.     [C:\WINDOWS\system32\dllcache\rasman.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  221.     [C:\WINDOWS\system32\dllcache\TAPI32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  222.     [C:\WINDOWS\system32\dllcache\sensapi.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  223.     [C:\WINDOWS\system32\dllcache\DNSAPI.dll]  [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]
  224.     [C:\WINDOWS\system32\dllcache\rasadhlp.dll]  [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]
  225.     [C:\WINDOWS\system32\dllcache\hnetcfg.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  226.     [C:\WINDOWS\system32\dllcache\browselc.dll]  [Microsoft Corporation, 6.00.2600.0000]
  227.     [C:\WINDOWS\system32\dllcache\DUSER.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  228. [PID: 1880 / Administrator][C:\Program Files\AntiARP Stand-alone Edition\AntiArp.exe]  [N/A, ]
  229.     [C:\Program Files\AntiARP Stand-alone Edition\xantiarp.dll]  [N/A, ]
  230.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  231.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  232.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  233.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  234.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  235.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  236.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  237.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  238.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  239.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  240.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  241.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  242.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  243.     [C:\WINDOWS\Fonts\gjcsdyc.dll]  [N/A, ]
  244. [PID: 1900 / Administrator][C:\Program Files\YuanZhi\Multimedia Education Network\Student.exe]  [TopDomain Technologies Co., LTD., 1.00.1.282]
  245.     [C:\Program Files\YuanZhi\Multimedia Education Network\TDMaster.dll]  [TopDomain Technologies Co., LTD., 1.00.1.282]
  246.     [C:\Program Files\YuanZhi\Multimedia Education Network\Language\0804\StudentRes.dll]  [TopDomain Technologies Co., LTD., 1.00.1.282]
  247.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  248.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  249.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  250.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  251.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  252.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  253.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  254.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  255.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  256.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  257.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  258.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  259.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  260. [PID: 1916 / Administrator][C:\Program Files\Rising\AntiSpyware\runiep.exe]  [Beijing Rising Technology Co., Ltd., 4.0.0.18]
  261.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  262.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  263.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  264.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  265.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  266.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  267.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  268.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  269.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  270.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  271.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  272.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  273.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  274.     [C:\WINDOWS\Fonts\gjcsdyc.dll]  [N/A, ]
  275. [PID: 1944 / Administrator][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  276.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  277.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  278.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  279.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  280.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  281.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  282.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  283.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  284.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  285.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  286.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  287.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  288.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  289. [PID: 1592 / Administrator][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  290.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  291.     [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
  292.     [C:\Program Files\Real\RealPlayer\rpplugins\ierpplug.dll]  [RealNetworks, Inc., 1.0.1.2254]
  293.     [C:\WINDOWS\system32\PNCRT.dll]  [Real Networks, Inc, 6.0.0.0]
  294.     [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
  295.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  296.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  297.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  298.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  299.     [C:\WINDOWS\Fonts\gjcsdyc.dll]  [N/A, ]
  300.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  301.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  302.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  303.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  304.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  305.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  306.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  307.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  308.     [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
  309.     [C:\WINDOWS\system32\CBBCBB1030.dll]  [N/A, ]
  310.     [C:\WINDOWS\system32\KABKAB1032.dll]  [N/A, ]
  311.     [C:\WINDOWS\system32\BAABAA1028.dll]  [N/A, ]
  312.     [C:\WINDOWS\system32\HACHAC1035.dll]  [N/A, ]
  313.     [C:\WINDOWS\system32\QABQAB1013.dll]  [N/A, ]
  314.     [C:\Program Files\Thunder\ComDlls\ThunderAgent_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 3, 20]
  315. [PID: 1608 / Administrator][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  316.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  317.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  318.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  319.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  320.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  321.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  322.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  323.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  324.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  325.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  326.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  327.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  328.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  329. [PID: 2276 / Administrator][d:\d盘内容(软件)\⑤杀毒软件\360安全卫士\antiarp\AntiArp.exe]  [奇虎网, 1, 0, 1, 1003]
  330.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  331.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  332.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  333.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  334.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  335.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  336.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  337.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  338.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  339.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  340.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  341.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  342.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  343.     [C:\WINDOWS\Fonts\gjcsdyc.dll]  [N/A, ]
  344. [PID: 2552 / Administrator][c:\program files\thunder\Program\Thunder5.exe]  [Thunder Networking Technologies,LTD, 5, 6, 2, 300]
  345.     [c:\program files\thunder\Program\ThunderEx.dll]  [, 1, 1, 2, 6]
  346.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  347.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  348.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  349.     [c:\program files\thunder\Program\TaskManager.dll]  [Thunder Networking Technologies,LTD, 1, 1, 0, 21]
  350.     [c:\program files\thunder\Program\download_interface.dll]  [Thunder Networking Technologies,LTD, 2, 15, 2, 85]
  351.     [c:\program files\thunder\Program\stlport_vc646.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
  352.     [c:\program files\thunder\Program\asyn_dns.dll]  [Thunder Networking Technologies,LTD, 2, 15, 2, 85]
  353.     [c:\program files\thunder\Program\BHOStub.dll]  [Thunder Networking Technologies,LTD, 1, 1, 0, 8]
  354.     [c:\program files\thunder\Program\FloatBar.dll]  [Giganology Inc., 1, 0, 0, 2]
  355.     [c:\program files\thunder\Components\DownAndPlay\DownAndPlay.dll]  [, 1, 0, 0, 3]
  356.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  357.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  358.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  359.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  360.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  361.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  362.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  363.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  364.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  365.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  366.     [c:\program files\thunder\Program\iTargetAD.dll]  [N/A, ]
  367.     [C:\WINDOWS\Fonts\gjcsdyc.dll]  [N/A, ]
  368.     [c:\program files\thunder\Components\Community\XLCommunity.dll]  [Thunder Networking Technologies,LTD, 1, 0, 7, 29]
  369.     [c:\program files\thunder\Components\Security\ThunderSafe.dll]  [深圳市迅雷网络技术有限公司, 1.0.0.10]
  370.     [c:\program files\thunder\Components\ExplorerHelper\ExplorerHelper.dll]  [Thunder Networking Technologies,LTD, 1, 0, 4, 15]
  371.     [c:\program files\thunder\Program\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 13, 2, 61]
  372.     [c:\program files\thunder\Program\XLNet.Dll]  [Thunder Networking Technologies,LTD, 1, 2, 0, 8]
  373.     [c:\program files\thunder\Plugins\BhoAdv\bho_adv.dll]  [深圳市迅雷网络技术有限公司, 1.0.1.0]
  374.     [c:\program files\thunder\ComDlls\ThunderAgent_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 3, 20]
  375.     [c:\program files\thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
  376.     [c:\program files\thunder\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.0.4]
  377.     [C:\WINDOWS\system32\CBBCBB1030.dll]  [N/A, ]
  378.     [C:\WINDOWS\system32\KABKAB1032.dll]  [N/A, ]
  379.     [C:\WINDOWS\system32\BAABAA1028.dll]  [N/A, ]
  380.     [C:\WINDOWS\system32\HACHAC1035.dll]  [N/A, ]
  381.     [C:\WINDOWS\system32\QABQAB1013.dll]  [N/A, ]
  382. [PID: 1700 / Administrator][c:\documents and settings\administrator\桌面\srengps.exe]  [Smallfrogs Studio, 2.5.16.900]
  383.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  384.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  385.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  386.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  387.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  388.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  389.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  390.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  391.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  392.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  393.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  394.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  395.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  396.     [C:\WINDOWS\Fonts\gjcsdyc.dll]  [N/A, ]
  397.     [c:\documents and settings\administrator\桌面\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
  398. ==================================
  399. 文件关联
  400. .TXT  Error. [C:\WINDOWS\notepad.exe %1]
  401. .EXE  OK. ["%1" %*]
  402. .COM  OK. ["%1" %*]
  403. .PIF  OK. ["%1" %*]
  404. .REG  OK. [regedit.exe "%1"]
  405. .BAT  OK. ["%1" %*]
  406. .SCR  OK. ["%1" /S]
  407. .CHM  Error. ["hh.exe" %1]
  408. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  409. .INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
  410. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  411. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  412. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  413. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  414. ==================================
  415. Winsock 提供者
  416. N/A
  417. ==================================
  418. Autorun.inf
  419. N/A
  420. ==================================
  421. HOSTS 文件
  422. 127.0.0.1       localhost
  423. 127.0.0.1  picon.chinaren.com
  424. 127.0.0.1  a.topxxxx.cn
  425. 127.0.0.1  588.star-google.com
  426. 127.0.0.1  mm.tt1890.com
  427. 127.0.0.1  ppp.buyaoni.com
  428. 127.0.0.1  ppp.749571.com
  429. 127.0.0.1  dd.749571.com
  430. 127.0.0.1  niu.xinniankl.com
  431. 127.0.0.1  xxx.haoqq1680.com
  432. 127.0.0.1  exe.xinniankl.com
  433. 127.0.0.1  the.microgood.net
  434. 127.0.0.1  iii.wzxyq.com
  435. 127.0.0.1  mm.sqmnoopt.com
  436. 127.0.0.1  ppp.buyaoni.com
  437. 127.0.0.1  keeppure.cn
  438. 127.0.0.1  aaa.1l1l1l.com
  439. 127.0.0.1  www.cfjs119.cn
  440. 127.0.0.1  cool.e0shop.cn
  441. 127.0.0.1  yun.yun878.com
  442. 127.0.0.1  web.47255.com
  443. 127.0.0.1  www.cike007.cn
  444. 127.0.0.1  www.exiao01.com
  445. 127.0.0.1  qqq.dzydhx.com
  446. 127.0.0.1  qqq.hao1658.com
  447. 127.0.0.1  www.333292.com
  448. 127.0.0.1  down.18dd.net
  449. 127.0.0.1  xxx.m111.biz
  450. 127.0.0.1  1.jopenqc.com
  451. 127.0.0.1  xxx.j41m.com
  452. 127.0.0.1  3.joppnqq.com
  453. 127.0.0.1  d.93se.com
  454. 127.0.0.1  1.jopenkk.com
  455. 127.0.0.1  xxx.vh7.biz
  456. 127.0.0.1  new.749571.com
  457. 127.0.0.1  xtx.kv8.info
  458. 127.0.0.1  cao.kv8.info
  459. 127.0.0.1  1.jopmmqq.com
  460. 127.0.0.1  yu.8s7.net
  461. 127.0.0.1  1.jopanqc.com
  462. 127.0.0.1  2.joppnqq.com
  463. 127.0.0.1  www.868wg.com
  464. 127.0.0.1  xxx.mmma.biz
  465. 127.0.0.1  ilove.com
  466. 127.0.0.1  www.22aaa.com
  467. 127.0.0.1  xx.exiao01.com
  468. 127.0.0.1  www.exiao01.com
  469. 127.0.0.1  tp.shpzhan.cn
  470. 127.0.0.1  www.tomwg.com
  471. 127.0.0.1  wg.47255.com
  472. 127.0.0.1  1.joppnqq.com
  473. 127.0.0.1  171817.171817.com
  474. 127.0.0.1  d2.llsging.com
  475. 127.0.0.1  llboss.com
  476. 127.0.0.1  nx.51ylb.cn
  477. 127.0.0.1  my.531jx.cn
  478. 127.0.0.1  up.22x44.com
  479. ==================================
  480. 进程特权扫描
  481. 特殊特权被允许: SeLoadDriverPrivilege [PID = 2276, D:\D盘内容(软件)\⑤杀毒软件\360安全卫士\ANTIARP\ANTIARP.EXE]
  482. 特殊特权被允许: SeLoadDriverPrivilege [PID = 2552, C:\PROGRAM FILES\THUNDER\PROGRAM\THUNDER5.EXE]
  483. ==================================
  484. API HOOK
  485. 入口点错误:CreateProcessW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\LotusHlp.dll)
  486. ==================================
  487. 隐藏进程
  488. N/A
  489. ==================================
复制代码

该用户从未签到

 楼主| 发表于 2008-2-23 09:30:46 | 显示全部楼层
x学校电脑病毒真多呀....

同志,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,****...................

该用户从未签到

 楼主| 发表于 2008-2-23 09:33:41 | 显示全部楼层
第二次的
  1. 2008-02-23,09:34:23

  2. System Repair Engineer 2.5.16.900
  3. Smallfrogs (http://www.KZTechs.com)

  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13.     进程特权扫描


  14. 启动项目
  15. 注册表
  16. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  17.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  18. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
  19.     <FlashPlayerUpdate><C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe>  [(Verified)Adobe Systems Incorporated]
  20. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  21.     <AntiARPStandalone><C:\Program Files\AntiARP Stand-alone Edition\AntiArp.exe>  []
  22.     <switch><c:\windows\system32\壁纸自动换.exe>  []
  23.     <YuanZhiStudent><C:\Program Files\YuanZhi\Multimedia Education Network\Student.exe RunServices>  [N/A]
  24.     <runeip><"C:\Program Files\Rising\AntiSpyware\runiep.exe" /startup>  [Beijing Rising Technology Co., Ltd.]
  25.     <360Safetray><D:\D盘内容(软件)\⑤杀毒软件\360安全卫士\safemon\360tray.exe /start>  [奇虎网]
  26.     <360Antiarp><d:\d盘内容(软件)\⑤杀毒软件\360安全卫士\antiarp\AntiArp.exe /start>  [奇虎网]
  27.     <IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>  [N/A]
  28.     <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [N/A]
  29.     <PHIME2002ASync><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>  [N/A]
  30. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
  31.     <wiasoisao><wiasoisao.exe>  []
  32. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  33.     <shell><Explorer.exe>  []
  34.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  35. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  36.     <AppInit_DLLs><>  [N/A]
  37. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  38.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
  39. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  40.     <{696ccf2b-badc-48ed-b6a6-4c74639663ba}><C:\WINDOWS\system32\CBBCBB1030.dll>  []
  41.     <{4f79092a-66ba-4317-b2c7-f839909661f0}><C:\WINDOWS\system32\KABKAB1032.dll>  []
  42.     <{9eb02d98-1c8f-45f5-93af-f66fa9174db0}><C:\WINDOWS\system32\BAABAA1028.dll>  []
  43.     <{6167F471-EF2B-41DD-A5E5-C26ACDB5C096}><C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys>  []
  44.     <{cd51bd9c-6264-4df0-96bf-8603019818e5}><C:\WINDOWS\system32\HACHAC1035.dll>  []
  45.     <{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><C:\WINDOWS\system32\sgrefg.dll>  []
  46.     <{5aca2e15-0790-4170-812a-890df2fb6144}><C:\WINDOWS\system32\QABQAB1013.dll>  []
  47.     <{4FA10261-B890-F432-A453-69F1023513F4}><C:\WINDOWS\Fonts\gjcsdyc.dll>  []
  48. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
  49.     <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Component Publisher]
  50. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DfLogon]
  51.     <WinlogonNotify: DfLogon><LogonDll.dll>  []
  52. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
  53.     <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
  54. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
  55.     <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
  56. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
  57.     <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
  58. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
  59.     <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
  60. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
  61.     <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
  62. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
  63.     <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
  64. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
  65.     <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
  66. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
  67.     <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]

  68. ==================================
  69. 启动文件夹
  70. N/A

  71. ==================================
  72. 服务
  73. [DF5Serv / DF5Serv][Running/Auto Start]
  74.   <C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe><Faronics Corporation>
  75. [Human Interface Device Access / HidServ][Stopped/Disabled]
  76.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  77. [Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start]
  78.   <"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><>

  79. ==================================
  80. 驱动程序
  81. [360AntiArp / 360AntiArp][Running/System Start]
  82.   <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><奇虎网>
  83. [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  84.   <system32\drivers\ac97intc.sys><Intel Corporation>
  85. [AliIde / AliIde][Running/Boot Start]
  86.   <\SystemRoot\System32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
  87. [AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
  88.   <System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
  89. [AntiARP NDIS Protocol Driver / AntiArpNdisProt][Running/Auto Start]
  90.   <system32\DRIVERS\AntiArpNdisProt.sys><Windows (R) 2000 DDK provider>
  91. [CmdIde / CmdIde][Running/Boot Start]
  92.   <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
  93. [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  94.   <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
  95. [VIA Rhine Family Fast Ethernet Adapter Driver Service / FETNDISB][Running/Manual Start]
  96.   <system32\DRIVERS\fetnd5b.sys><VIA Technologies, Inc.>
  97. [npkcrypt / npkcrypt][Stopped/Auto Start]
  98.   <\??\C:\Program Files\QQ2006\npkcrypt.sys><N/A>
  99. [nv / nv][Stopped/Manual Start]
  100.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  101. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  102.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  103. [RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  104.   <\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising Technology Co., Ltd.>
  105. [Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Stopped/Manual Start]
  106.   <system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
  107. [S3SavageNB / S3SavageNB][Running/Manual Start]
  108.   <system32\DRIVERS\s3gnbm.sys><S3 Graphics, Inc.>
  109. [Secdrv / Secdrv][Stopped/Manual Start]
  110.   <system32\DRIVERS\secdrv.sys><N/A>
  111. [VIA AGP Filter / viaagp1][Running/Boot Start]
  112.   <\SystemRoot\system32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
  113. [ViaIde / ViaIde][Running/Boot Start]
  114.   <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
  115. [Vinyl AC'97 Audio Controller (WDM) / VIAudio][Stopped/Manual Start]
  116.   <system32\drivers\vinyl97.sys><VIA Technologies, Inc.>
  117. [xAntiArpSpoof Service / xAntiArp][Running/Manual Start]
  118.   <system32\DRIVERS\xAntiArp.sys><Windows (R) 2000 DDK provider>
  119. [fpids32 / fpids32][Running/Auto Start]
  120.   <\??\C:\WINDOWS\system32\drivers\msosfpids32.sys><N/A>
  121. [msertk / msertk][Running/Auto Start]
  122.   <system32\drivers\msyecp.sys><N/A>
  123. [pop / pop][Running/Manual Start]
  124.   <\??\C:\WINDOWS\system32\DRIVERS\pop.sys><N/A>

  125. ==================================
  126. 浏览器加载项
  127. [ThunderAtOnce Class]
  128.   {01443AEC-0FD1-40fd-9C87-E93D1494C233} <c:\program files\thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
  129. []
  130.   {6167F471-EF2B-41DD-A5E5-C26ACDB5C096} <C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys, N/A>
  131. [Thunder Browser Helper]
  132.   {B69F34DC-F0F9-42DC-9EDD-957187DA688D} <c:\program files\thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  133. [SafeMon Class]
  134.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <d:\D盘内~1\⑤杀毒~1\360安~1\safemon\safemon.dll, 奇虎网>
  135. [ThunderAtOnce Class]
  136.   {01443AEC-0FD1-40FD-9C87-E93D1494C233} <c:\program files\thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
  137. [Thunder Agent Class]
  138.   {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <c:\program files\thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
  139. []
  140.   {6167F471-EF2B-41DD-A5E5-C26ACDB5C096} <C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys, N/A>
  141. [360SafeLive]
  142.   {87515F61-A66C-4319-A0E0-D416CB8059E3} <D:\D盘内容(软件)\⑤杀毒软件\360安全卫士\live.dll, 360safe.com>
  143. [Microsoft Web 浏览器]
  144.   {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
  145. [SearchAssistantOC]
  146.   {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
  147. [Thunder Browser Helper]
  148.   {B69F34DC-F0F9-42DC-9EDD-957187DA688D} <c:\program files\thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
  149. [SafeMon Class]
  150.   {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <d:\D盘内~1\⑤杀毒~1\360安~1\safemon\safemon.dll, 奇虎网>
  151. [RDS.DataSpace]
  152.   {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
  153. [Shockwave Flash Object]
  154.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  155. [使用迅雷下载]
  156.   <c:\program files\thunder\Program\geturl.htm, N/A>
  157. [使用迅雷下载全部链接]
  158.   <c:\program files\thunder\Program\getallurl.htm, N/A>
  159. [导出到 Microsoft Office Excel(&X)]
  160.   <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
  161. [添加到QQ表情]
  162.   <d:\Program Files\QQ2007\AddEmotion.htm, N/A>

  163. ==================================
  164. 正在运行的进程
  165. [PID: 1644 / Administrator][C:\WINDOWS\Explorer.EXE]  [N/A, ]
  166.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  167.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  168.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  169.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  170.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  171.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  172.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  173.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  174.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  175.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  176.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  177.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  178.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  179. [PID: 1796 / Administrator][C:\WINDOWS\system32\dllcache\explorer.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  180.     [C:\WINDOWS\system32\dllcache\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  181.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  182.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  183.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  184.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  185.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  186.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  187.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  188.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  189.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  190.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  191.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  192.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  193.     [C:\WINDOWS\Fonts\gjcsdyc.dll]  [N/A, ]
  194.     [C:\WINDOWS\system32\CBBCBB1030.dll]  [N/A, ]
  195.     [C:\WINDOWS\system32\KABKAB1032.dll]  [N/A, ]
  196.     [C:\WINDOWS\system32\BAABAA1028.dll]  [N/A, ]
  197.     [C:\WINDOWS\system32\HACHAC1035.dll]  [N/A, ]
  198.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  199.     [C:\WINDOWS\system32\QABQAB1013.dll]  [N/A, ]
  200.     [C:\WINDOWS\system32\dllcache\browselc.dll]  [Microsoft Corporation, 6.00.2600.0000]
  201. [PID: 1880 / Administrator][C:\Program Files\AntiARP Stand-alone Edition\AntiArp.exe]  [N/A, ]
  202.     [C:\Program Files\AntiARP Stand-alone Edition\xantiarp.dll]  [N/A, ]
  203.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  204.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  205.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  206.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  207.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  208.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  209.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  210.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  211.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  212.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  213.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  214.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  215.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  216.     [C:\WINDOWS\Fonts\gjcsdyc.dll]  [N/A, ]
  217. [PID: 1900 / Administrator][C:\Program Files\YuanZhi\Multimedia Education Network\Student.exe]  [TopDomain Technologies Co., LTD., 1.00.1.282]
  218.     [C:\Program Files\YuanZhi\Multimedia Education Network\TDMaster.dll]  [TopDomain Technologies Co., LTD., 1.00.1.282]
  219.     [C:\Program Files\YuanZhi\Multimedia Education Network\Language\0804\StudentRes.dll]  [TopDomain Technologies Co., LTD., 1.00.1.282]
  220.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  221.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  222.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  223.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  224.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  225.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  226.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  227.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  228.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  229.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  230.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  231.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  232.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  233. [PID: 1916 / Administrator][C:\Program Files\Rising\AntiSpyware\runiep.exe]  [Beijing Rising Technology Co., Ltd., 4.0.0.18]
  234.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  235.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  236.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  237.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  238.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  239.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  240.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  241.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  242.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  243.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  244.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  245.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  246.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  247.     [C:\WINDOWS\Fonts\gjcsdyc.dll]  [N/A, ]
  248. [PID: 1944 / Administrator][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  249.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  250.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  251.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  252.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  253.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  254.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  255.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  256.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  257.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  258.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  259.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  260.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  261.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  262. [PID: 1592 / Administrator][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  263.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  264.     [C:\WINDOWS\system32\WINWB86.IME]  [Microsoft Corporation, 4.00.950]
  265.     [C:\Program Files\Real\RealPlayer\rpplugins\ierpplug.dll]  [RealNetworks, Inc., 1.0.1.2254]
  266.     [C:\WINDOWS\system32\PNCRT.dll]  [Real Networks, Inc, 6.0.0.0]
  267.     [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
  268.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  269.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  270.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  271.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  272.     [C:\WINDOWS\Fonts\gjcsdyc.dll]  [N/A, ]
  273.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  274.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  275.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  276.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  277.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  278.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  279.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  280.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  281.     [C:\WINDOWS\system32\CBBCBB1030.dll]  [N/A, ]
  282.     [C:\WINDOWS\system32\KABKAB1032.dll]  [N/A, ]
  283.     [C:\WINDOWS\system32\BAABAA1028.dll]  [N/A, ]
  284.     [C:\WINDOWS\system32\HACHAC1035.dll]  [N/A, ]
  285.     [C:\WINDOWS\system32\QABQAB1013.dll]  [N/A, ]
  286.     [C:\Program Files\Thunder\ComDlls\ThunderAgent_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 3, 20]
  287. [PID: 1608 / Administrator][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  288.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  289.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  290.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  291.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  292.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  293.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  294.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  295.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  296.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  297.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  298.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  299.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  300.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  301. [PID: 2276 / Administrator][d:\d盘内容(软件)\⑤杀毒软件\360安全卫士\antiarp\AntiArp.exe]  [奇虎网, 1, 0, 1, 1003]
  302.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  303.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  304.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  305.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  306.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  307.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  308.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  309.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  310.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  311.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  312.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  313.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  314.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  315.     [C:\WINDOWS\Fonts\gjcsdyc.dll]  [N/A, ]
  316. [PID: 1700 / Administrator][c:\documents and settings\administrator\桌面\srengps.exe]  [Smallfrogs Studio, 2.5.16.900]
  317.     [C:\WINDOWS\system32\ygoviotzyzj.dll]  [Microsoft Corporation, 5.1.2600.3099]
  318.     [C:\WINDOWS\system32\fktyhotwow.dll]  [Microsoft Corporation, 5.1.2600.3099]
  319.     [C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys]  [N/A, ]
  320.     [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
  321.     [C:\WINDOWS\system32\sgrefg.dll]  [N/A, ]
  322.     [C:\WINDOWS\system32\LotusHlp.dll]  [N/A, ]
  323.     [C:\WINDOWS\system32\DbgHlp32.dlL]  [N/A, ]
  324.     [C:\WINDOWS\system32\upxdnd.dll]  [N/A, ]
  325.     [C:\WINDOWS\system32\NVDispDrv.dll]  [N/A, ]
  326.     [C:\WINDOWS\system32\PTSShell.dll]  [N/A, ]
  327.     [C:\WINDOWS\system32\MsIMMs32.dll]  [N/A, ]
  328.     [C:\WINDOWS\kiefncol.dll]  [N/A, ]
  329.     [C:\WINDOWS\kfnrthoh.dll]  [N/A, ]
  330.     [C:\WINDOWS\Fonts\gjcsdyc.dll]  [N/A, ]
  331.     [c:\documents and settings\administrator\桌面\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
  332.     [c:\documents and settings\administrator\桌面\Plugins\NTFSTREAM.SRE]  [Smallfrogs Studio, 1, 0, 0, 5]
  333.     [C:\WINDOWS\system32\CBBCBB1030.dll]  [N/A, ]
  334.     [C:\WINDOWS\system32\KABKAB1032.dll]  [N/A, ]
  335.     [C:\WINDOWS\system32\BAABAA1028.dll]  [N/A, ]
  336.     [C:\WINDOWS\system32\HACHAC1035.dll]  [N/A, ]
  337.     [C:\WINDOWS\system32\QABQAB1013.dll]  [N/A, ]

  338. ==================================
  339. 文件关联
  340. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  341. .EXE  OK. ["%1" %*]
  342. .COM  OK. ["%1" %*]
  343. .PIF  OK. ["%1" %*]
  344. .REG  OK. [regedit.exe "%1"]
  345. .BAT  OK. ["%1" %*]
  346. .SCR  OK. ["%1" /S]
  347. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  348. .HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
  349. .INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  350. .INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  351. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  352. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  353. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  354. ==================================
  355. Winsock 提供者
  356. N/A

  357. ==================================
  358. Autorun.inf
  359. N/A

  360. ==================================
  361. HOSTS 文件
  362. 127.0.0.1       localhost
  363. 127.0.0.1  picon.chinaren.com
  364. 127.0.0.1  a.topxxxx.cn
  365. 127.0.0.1  588.star-google.com
  366. 127.0.0.1  mm.tt1890.com
  367. 127.0.0.1  ppp.buyaoni.com
  368. 127.0.0.1  ppp.749571.com
  369. 127.0.0.1  dd.749571.com
  370. 127.0.0.1  niu.xinniankl.com
  371. 127.0.0.1  xxx.haoqq1680.com
  372. 127.0.0.1  exe.xinniankl.com
  373. 127.0.0.1  the.microgood.net
  374. 127.0.0.1  iii.wzxyq.com
  375. 127.0.0.1  mm.sqmnoopt.com
  376. 127.0.0.1  ppp.buyaoni.com
  377. 127.0.0.1  keeppure.cn
  378. 127.0.0.1  aaa.1l1l1l.com
  379. 127.0.0.1  www.cfjs119.cn
  380. 127.0.0.1  cool.e0shop.cn
  381. 127.0.0.1  yun.yun878.com
  382. 127.0.0.1  web.47255.com
  383. 127.0.0.1  www.cike007.cn
  384. 127.0.0.1  www.exiao01.com
  385. 127.0.0.1  qqq.dzydhx.com
  386. 127.0.0.1  qqq.hao1658.com
  387. 127.0.0.1  www.333292.com
  388. 127.0.0.1  down.18dd.net
  389. 127.0.0.1  xxx.m111.biz
  390. 127.0.0.1  1.jopenqc.com
  391. 127.0.0.1  xxx.j41m.com
  392. 127.0.0.1  3.joppnqq.com
  393. 127.0.0.1  d.93se.com
  394. 127.0.0.1  1.jopenkk.com
  395. 127.0.0.1  xxx.vh7.biz
  396. 127.0.0.1  new.749571.com
  397. 127.0.0.1  xtx.kv8.info
  398. 127.0.0.1  cao.kv8.info
  399. 127.0.0.1  1.jopmmqq.com
  400. 127.0.0.1  yu.8s7.net
  401. 127.0.0.1  1.jopanqc.com
  402. 127.0.0.1  2.joppnqq.com
  403. 127.0.0.1  www.868wg.com
  404. 127.0.0.1  xxx.mmma.biz
  405. 127.0.0.1  ilove.com
  406. 127.0.0.1  www.22aaa.com
  407. 127.0.0.1  xx.exiao01.com
  408. 127.0.0.1  www.exiao01.com
  409. 127.0.0.1  tp.shpzhan.cn
  410. 127.0.0.1  www.tomwg.com
  411. 127.0.0.1  wg.47255.com
  412. 127.0.0.1  1.joppnqq.com
  413. 127.0.0.1  171817.171817.com
  414. 127.0.0.1  d2.llsging.com
  415. 127.0.0.1  llboss.com
  416. 127.0.0.1  nx.51ylb.cn
  417. 127.0.0.1  my.531jx.cn
  418. 127.0.0.1  up.22x44.com

  419. ==================================
  420. 进程特权扫描
  421. 特殊特权被允许: SeLoadDriverPrivilege [PID = 2276, D:\D盘内容(软件)\⑤杀毒软件\360安全卫士\ANTIARP\ANTIARP.EXE]

  422. ==================================
  423. API HOOK
  424. 入口点错误:CreateProcessW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\LotusHlp.dll)

  425. ==================================
  426. 隐藏进程
  427. N/A

  428. ==================================
复制代码

该用户从未签到

发表于 2008-2-23 10:07:18 | 显示全部楼层
不要指望我,我看拉这东西头晕~~~~~~~~~~~

该用户从未签到

发表于 2008-2-23 10:12:25 | 显示全部楼层
。。。。。。。。。好多。。

该用户从未签到

发表于 2008-2-23 12:10:51 | 显示全部楼层
好多垃圾网站哦。。。

该用户从未签到

发表于 2008-2-23 12:41:34 | 显示全部楼层
机器狗...  而且还有其他病毒 汗...  不光有 还相当的多....

把瑞星卸载了吧....  那玩意没啥用....    现在很多杀软都有KEY的...  推荐用微点
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表