趋势杀软更新显示更新成功,但实际没有更新,并会在趋势更新下载目录留有一个不同的配置文件server.ini,文件内容贴于扫描日志后
007-02-26,15:46:49
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows 98 SE -
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<msnmsgr><"D:\MSN 更新\MSNMSGR.EXE" /background> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ScanRegistry><C:\WINDOWS\scanregw.exe /autorun> [Microsoft Corporation]
<TaskMonitor><C:\WINDOWS\taskmon.exe> [Microsoft Corporation]
<internat.exe><internat.exe> [Microsoft Corporation]
<SystemTray><SysTray.Exe> [Microsoft Corporation]
<LoadPowerProfile><Rundll32.exe powrprof.dll,LoadCurrentPwrScheme> [Microsoft Corporation]
<OfficeScan95><"C:\PROGRAM FILES\TREND MICRO\OFFICESCAN CLIENT\pccwin97.exe" -HideWindow> [Trend Micro Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<LoadPowerProfile><Rundll32.exe powrprof.dll,LoadCurrentPwrScheme> [Microsoft Corporation]
<OfficeScan95><"C:\PROGRAM FILES\TREND MICRO\OFFICESCAN CLIENT\pccwin97.exe"> [Trend Micro Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
==================================
启动文件夹
[Microsoft Office]
<C:\WINDOWS\Start Menu\Programs\启动\Microsoft Office.lnk --> C:\PROGRA~1\MICROS~1\OFFICE\OSA9.EXE [Microsoft Corporation]><N>
[腾讯QQ]
<C:\WINDOWS\Start Menu\Programs\启动\腾讯QQ.lnk --> C:\PROGRA~1\TENCENT\QQ\QQ.EXE [TENCENT]><N>
==================================
服务
N/A
==================================
驱动程序
N/A
==================================
浏览器加载项
[@shdoclc.dll,-866@2052,相关站点]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[Encrypt Class]
{35C3D91E-401A-4E45-88A5-F3B32CD72DF4} <C:\WINDOWS\DOWNLOADED PROGRAM FILES\ATXENC.DLL, Trend Micro Inc.>
[Shockwave Flash
Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH9B.OCX, Adobe Systems, Inc.>
[EasyGrid.EGrid]
{E601FC24-92AC-4D2A-A9E8-27A5C1B3DCB2} <C:\WINDOWS\DOWNLOADED PROGRAM FILES\EASYGRID.OCX, FOCI>
[OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class]
{5EFE8CB1-D095-11D1-88FC-0080C859833B} <C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.1\OFFICESCANREMOVECTRL.DLL, Trend Micro Inc.>
[OfficeScan Corp Edition Web-Deployment SetupINICtrl Class]
{08D75BB0-D2B5-11D1-88FC-0080C859833B} <C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.1\OFFICESCANSETUPINI.DLL, Trend Micro Inc.>
[OfficeScan Corp Edition Web-Deployment SetupCtrl Class]
{08D75BC1-D2B5-11D1-88FC-0080C859833B} <C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.1\OFFICESCANSETUP.DLL, Trend Micro Inc.>
[添加到QQ自定义面板]
<C:\PROGRAM FILES\TENCENT\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\PROGRAM FILES\TENCENT\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\PROGRAM FILES\TENCENT\QQ\SendMMS.htm, N/A>
[上传到QQ网络硬盘]
<C:\PROGRAM FILES\TENCENT\QQ\AddToNetDisk.htm, N/A>
==================================
正在运行的进程
[PID: 4294944133][C:\WINDOWS\SYSTEM\MPREXE.EXE] [Microsoft Corporation, 4.10.1998]
[C:\PROGRAM FILES\TREND MICRO\OFFICESCAN CLIENT\OFCPLUGINTRAY.DLL] [Trend Micro Inc., 6.5.0.1106]
[C:\PROGRAM FILES\TREND MICRO\OFFICESCAN CLIENT\OFCPLUGINMAIN.DLL] [Trend Micro Inc., 6.5.0.1106]
[C:\PROGRAM FILES\TREND MICRO\OFFICESCAN CLIENT\PCCWIN97.DLL] [Trend Micro Inc., 6.5.0.1106]
[PID: 4294850153][C:\PROGRAM FILES\TREND MICRO\OFFICESCAN CLIENT\PCCWIN97.EXE] [Trend Micro Inc., 6.5.0.1303]
[C:\PROGRAM FILES\TREND MICRO\OFFICESCAN CLIENT\OFC_LOADHTTP.DLL] [Trend Micro Inc., 6.5.0.1106]
[C:\PROGRAM FILES\TREND MICRO\OFFICESCAN CLIENT\LIBTMCAV.DLL] [Trend Micro Inc., 6.5.0.1106]
[C:\PROGRAM FILES\TREND MICRO\OFFICESCAN CLIENT\PWD.DLL] [Trend Micro Inc., 6.5.0.1106]
[C:\PROGRAM FILES\TREND MICRO\OFFICESCAN CLIENT\OFCPLUGINAPI.DLL] [Trend Micro Inc., 6.5.0.1106]
[C:\PROGRAM FILES\TREND MICRO\OFFICESCAN CLIENT\OFCDOG.DLL] [Trend Micro Inc., 6.5.0.1106]
[C:\PROGRAM FILES\TREND MICRO\OFFICESCAN CLIENT\TIMESTRING.DLL] [N/A, N/A]
[PID: 4294901545][C:\WINDOWS\TEMP\YHFEA4.EXE] [N/A, N/A]
[PID: 4294827929][C:\WINDOWS\SYSTEM\PSTORES.EXE] [Microsoft Corporation, 5.00.1877.3]
[C:\PROGRAM FILES\WINRAR\RAREXT.DLL] [N/A, N/A]
[PID: 4294716097][C:\WINDOWS\EXPLORER.EXE] [Microsoft Corporation, 4.72.3110.1]
[PID: 4294807729][C:\WINDOWS\TASKMON.EXE] [Microsoft Corporation, 4.10.1998]
[PID: 4294827249][C:\WINDOWS\SYSTEM\INTERNAT.EXE] [Microsoft Corporation, 4.80.3008.1]
[PID: 4294729573][C:\WINDOWS\SYSTEM\SYSTRAY.EXE] [Microsoft Corporation, 4.10.2222]
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] [N/A, N/A]
[C:\WINDOWS\SYSTEM\DCIMAN32.DLL] [Intel(R) Corp., Microsoft Corp., 4.03.1998]
[PID: 4294738421][D:\MSN 更新\MSNMSGR.EXE] [Microsoft Corporation, 7.0.0816]
[C:\WINDOWS\SYSTEM\DHCPCSVC.DLL] [N/A, N/A]
[PID: 4294680009][C:\WINDOWS\SYSTEM\WMIEXE.EXE] [Microsoft Corporation, 5.00.1755.1]
[PID: 4294664221][C:\WINDOWS\DESKTOP\SRENG2\SRENG\SRENG.EXE] [Smallfrogs Studio, 2.2.6.605]
==================================
文件关联
.TXT OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [C:\WINDOWS\winhlp32.exe %1]
.INI OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS OK. [C:\WINDOWS\WScript.exe "%1" %*]
.JS OK. [C:\WINDOWS\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MS.w95.spi.osp
C:\WINDOWS\SYSTEM\mswsosp.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.tcp
C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.udp
C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.raw
C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.rsvptcp
C:\WINDOWS\SYSTEM\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
MS.w95.spi.rsvpudp
C:\WINDOWS\SYSTEM\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A