1234   3  /  4  页   跳转

花在吗? 帮我看下

2006-01-04,15:02:16

System Repair Engineer 2.0.12.350 (2.0 RC 1)
    Windows XP Professional Service Pack 2 - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <load><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <RfwMain><"C:\Program Files\rising\Rfw\rfwmain.exe" -Startup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <NMGameX_AutoRun><C:\WINDOWS\system32\Rundll32.exe NMGameX.dll,LiveProcess /aa>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <RavTask><"C:\Program Files\rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <AppInit_DLLs><APIHookDll.dll>

==================================
启动文件夹
[EPSON Online Register]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\EPSON Online Register.lnk><N>

==================================
服务
[Dcfssvc / Dcfssvc]
  <C:\WINDOWS\system32\drivers\dcfssvc.exe><Eastman Kodak Company>
[Rising Personal Firewall Service / RfwService]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>

==================================
浏览器加载项
[VnetCookie Class]
  {4E83D567-4697-4F7B-B1F0-A513B01DB89A} <c:\PROGRA~1\chinanet\VNETTR~1.DLL, >
[EpsonToolBandKicker Class]
  {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} <C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll, SEIKO EPSON CORPORATION>
[寻论网--中学作业解答]
  {6924091F-CD97-41E1-B1D4-D9079409D423} <http://www.xunlun.com, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <, N/A>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[EPSON Web-To-Page]
  {EE5D279F-081B-4404-994D-C6B60AAEBA6D} <C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll, SEIKO EPSON CORPORATION>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[VnetCookie Class]
  {4E83D567-4697-4F7B-B1F0-A513B01DB89A} <c:\PROGRA~1\chinanet\VNETTR~1.DLL, >
[HHCtrl Object]
  {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[AUDIO__MID Moniker Class]
  {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
  {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[NMChatX Control]
  {D7F0CC2E-FB09-4B38-B9A7-6807CBCD4859} <C:\WINDOWS\system32\NMChatX.ocx, Netmarble>
[EpsonToolBandKicker Class]
  {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} <C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll, SEIKO EPSON CORPORATION>
[EPSON Web-To-Page]
  {EE5D279F-081B-4404-994D-C6B60AAEBA6D} <C:\Program Files\EPSON\EPSON
gototop
 

[D:\QQ\QQBaseClassInDll.dll]  <><1, 0, 0, 1>
    [D:\QQ\QQHelperDll.dll]  <><1, 0, 0, 1>
    [D:\QQ\BasicCtrlDll.dll]  <Tencent><0, 2, 2, 2>
    [D:\QQ\QQZip.dll]  <tencent><2.05>
    [C:\WINDOWS\system32\APIHookDll.dll]  <N/A><N/A>
    [D:\QQ\ImagePro.dll]  <Tencent><1.3.8.4>
    [D:\QQ\InPlus.dll]  <Tencent><1.3.8.4>
    [D:\QQ\CoralQQ.dll]  <Coral Team><2.4.0.0>
    [D:\QQ\IPSearcher.dll]  <><1.0.0.3>
    [D:\QQ\QQAPI.dll]  <><1, 0, 0, 1>
    [D:\QQ\TIMProxy.dll]  <tencent><2.05>
    [D:\QQ\HostingMgr.dll]  <><1, 0, 0, 1>
    [D:\QQ\LoginCtrl.dll]  <><1, 0, 0, 1>
    [D:\QQ\QQRes.dll]  <tencent><1, 0, 0, 1>
    [D:\QQ\QQMainFrame.dll]  <N/A><N/A>
    [D:\QQ\CQQApplication.dll]  <N/A><N/A>
    [D:\QQ\QQSysMsgMng.dll]  <N/A><N/A>
    [D:\QQ\LongConnection.dll]  <tencent><0, 2, 2, 2>
    [D:\QQ\QQConfigPlugin.dll]  <><1, 0, 0, 1>
    [D:\QQ\CameraDll.dll]  <><1, 0, 0, 1>
    [D:\QQ\QQGroupMng.dll]  <><1, 0, 0, 1>
    [D:\QQ\QQPlugin.dll]  <N/A><N/A>
    [D:\QQ\UserDefinedHead.dll]  <><1, 0, 0, 1>
    [D:\QQ\QQCustomFace.dll]  <N/A><N/A>
    [D:\QQ\QQAllInOne.dll]  <N/A><N/A>
    [D:\QQ\SCCore.dll]  <N/A><N/A>
    [D:\QQ\GroupConnection.dll]  <Tencent><0, 3, 1, 14>
    [D:\QQ\NewSkin.dll]  <><1, 0, 0, 1>
    [D:\QQ\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
    [D:\QQ\BQQApplication.dll]  <N/A><N/A>
    [D:\QQ\QQMMSender.dll]  <N/A><N/A>
    [D:\QQ\QQAvatar.dll]  <N/A><N/A>
    [D:\QQ\QRingMng.dll]  <N/A><N/A>
    [D:\QQ\videodevice.dll]  <Tencent><1.3.8.4>
    [D:\QQ\QQSceneMng.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [D:\QQ\QQHook.dll]  <N/A><N/A>
    [D:\QQ\QQMagicFace.dll]  <><1, 0, 0, 1>
    [D:\QQ\QQUdpGetFileLib.dll]  <tencent><2.05>
    [D:\QQGame\GameLogCore.Dll]  <><0, 10, 106, 13>
    [D:\QQGame\Core.dll]  <é??úêDìú???????ú?μí3óD?T1???><0, 10, 0, 0>
    [D:\QQGame\NetCenter.dll]  <é??úêDìú???????ú?μí3óD?T1???><0, 10, 0, 0>
    [D:\QQGame\CmdCenter.dll]  <深圳市腾讯计算机系统有限公司><0, 10, 0, 0>
    [D:\QQGame\HelpDll.dll]  <><1, 0, 0, 1>
    [D:\QQGame\ResEx.dll]  <深圳市腾讯计算机系统有限公司><0, 10, 0, 0>
    [D:\QQGame\GameLogAidMgr.dll]  <><1, 0, 0, 1>
    [D:\QQGame\COMToolKit.dll]  <><1, 0, 0, 3>
    [D:\QQGame\QQGameAvatar.dll]  <深圳市腾讯计算机系统有限公司                                    Tencent Computer System Ltd.><0, 10, 0, 0>
    [D:\QQ\ImageOle.dll]  <TODO: <Company name>><1.0.0.1>
    [D:\QQ\QQFileTransfer.dll]  <Tencent><0, 3, 1, 16>
[PID: 3876][D:\QQ\TIMPlatform.exe]  <tencent><2.05>
    [C:\WINDOWS\system32\APIHookDll.dll]  <N/A><N/A>
    [D:\QQ\TIMProxy.dll]  <tencent><2.05>
[PID: 2784][F:\sreng2\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\WINDOWS\system32\APIHookDll.dll]  <N/A><N/A>
    [D:\QQ\QQHook.dll]  <N/A><N/A>

==================================
文件关联
.TXT  Error. [NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
gototop
 

斑竹怎么不来看啊 我贴上来了啊
gototop
 

【回复“smartzlm18”的帖子】
没什么问题.
删除这些:
[寻论网--中学作业解答]
{6924091F-CD97-41E1-B1D4-D9079409D423} <http://www.xunlun.com, N/A>

修复一下.txt文件关联.
gototop
 

可是那个木马怎么办啊  老提示有木马啊  TEMP里面的垃圾现在删不了啊  每次开机多变多  现在多的没的说了快帮忙啊
gototop
 

在安全模式下用killbox删,选择重启后删除可以的
gototop
 

那些删不了的是个病毒产生的东西 在安全模式下可以删  可是一启动又有了在正常模式下是什么办法多删不了  你说的那个也删不了啊 也不可以打包 说有程序在运用不可以打包啊 我试了好几次了 急死人了 昨天到现在多24小时了 今天下了个卡巴斯基也没杀到 可是瑞星还是提示有木马啊 真没的说了 TEMP是怎么搞多搞不掉
gototop
 

您的sreng日志似乎未贴全啊?
gototop
 

不会吧 多上了 分了三次
gototop
 

正在运行进程不全,连基本的系统进程都没看到
gototop
 
1234   3  /  4  页   跳转
页面顶部
Powered by Discuz!NT