开机winlogon.exe连接网络,用zonealarm阻止,然后winlogon.exe内存不停的增长,应该是一直想连接网络却被zonealarm阻止的缘故。
利用System Repair Engine查看,发现winlogon加载了system32下的systen.dll,应该是个病毒文件,用icesword删除,又重新出现,在注册表的位置是HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\BITS
内容是加载c:\windows\system32\systen.dll
下面是System Repair Engineer的报告。
[CODE]
2007-05-10,15:55:28
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
<Foxmail><"D:\Program Files\Tencent\Foxmail\Foxmail.exe" -min> [Tencent Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"> [(Verified)Symantec Corporation]
<vptray><C:\PROGRA~1\SYMANT~1\VPTray.exe> [(Verified)Symantec Corporation]
<SoundMan><SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<Zone Labs Client><C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe> [(Verified)Check Point Software Technologies Inc.]
<TE_RegProtect><C:\Program Files\Anti Trojan Elite\TERegPct.exe> []
<Picasa Media Detector><d:\Program Files\Picasa2\PicasaMediaDetector.exe> [(Verified)Google Inc.]
<Google IME Autoupdater><"d:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe"> [(Verified)Google Inc]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [NVIDIA Corporation]
<powerword 2007><"D:\Program Files\Kingsoft\Powerword 2007\xdict.exe" -s -nosplash> [Kingsoft Co, Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\BITS]
<WinlogonNotify: BITS><C:\WINDOWS\System32\Systen.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
<WinlogonNotify: NavLogon><C:\WINDOWS\system32\NavLogon.dll> [(Verified)Microsoft Windows Publisher]
==================================
启动文件夹
N/A
==================================
服务
[Symantec Event Manager / ccEvtMgr][Running/Auto Start]
<"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc][Stopped/Manual Start]
<"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr][Running/Auto Start]
<"C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[Condor / Condor][Stopped/Manual Start]
<C:\condor\bin\condor_master.exe><N/A>
[Symantec AntiVirus Definition Watcher / DefWatch][Running/Auto Start]
<"C:\Program Files\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[DeinoMPI process manager service / DeinoPM][Running/Auto Start]
<"D:\Program Files\DeinoMPI\bin\DeinoPM.exe"><Deino Software>
[Google Updater Service / gusvc][Stopped/Manual Start]
<"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"><Macrovision Corporation>
[MATLAB Server / matlabserver][Stopped/Manual Start]
<d:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe><N/A>
[MATLAB Distributed Computing Engine / mdced][Stopped/Manual Start]
<"D:\Program Files\MATLAB\R2006a\toolbox\distcomp\bin\win32\mdced.exe" -s "D:\Program Files\MATLAB\R2006a\toolbox\distcomp\config\wrapper-phoenix.config"><N/A>
[Machine Debug Manager / MDM][Stopped/Manual Start]
<"C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"><Microsoft Corporation>
[MPICH2 Process Manager, Argonne National Lab / mpich2_smpd][Running/Auto Start]
<C:\Program Files\MPICH2\bin\smpd.exe><Argonne National Lab>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[P4P Service / P4P Service][Stopped/Manual Start]
<C:\Program Files\Common Files\Sogou PXP\p2psvr.exe><Sohu.com Inc.>
[SavRoam / SavRoam][Stopped/Manual Start]
<"C:\Program Files\Symantec AntiVirus\SavRoam.exe"><symantec>
[SolidPDFConverterReadSpool / ScReadSpool][Stopped/Manual Start]
<D:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe><VoyagerSoft, LLC>
[Symantec Network Drivers Service / SNDSrvc][Stopped/Manual Start]
<"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Symantec SPBBCSvc / SPBBCSvc][Stopped/Manual Start]
<"C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"><Symantec Corporation>
[Symantec AntiVirus / Symantec AntiVirus][Running/Auto Start]
<"C:\Program Files\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>
[Visual Studio Analyzer RPC bridge / Visual Studio Analyzer RPC bridge][Stopped/Manual Start]
<D:\Program Files\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr\varpc.exe><Microsoft Corporation>
[TrueVector Internet Monitor / vsmon][Running/Auto Start]
<C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service><Zone Labs, LLC>
==================================
驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[ATE_PROCMON / ATE_PROCMON][Stopped/Manual Start]
<\??\C:\Program Files\Anti Trojan Elite\ATEPMon.sys><N/A>
[d347bus / d347bus][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\d347bus.sys><>
[d347prt / d347prt][Running/Boot Start]
<\SystemRoot\System32\Drivers\d347prt.sys><>
[DS1410D / DS1410D][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\ds1410d.sys><N/A>
[Symantec Eraser Control driver / eeCtrl][Running/System Start]
<\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys><Symantec Corporation>
[EraserUtilRebootDrv / EraserUtilRebootDrv][Running/Manual Start]
<\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys><Symantec Corporation>
[hardlock / hardlock][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\hardlock.sys><Aladdin Knowledge Systems>
[Haspnt / Haspnt][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\Haspnt.sys><Aladdin Knowledge Systems>
[hexmagic / hexmagic][Stopped/Disabled]
<\??\C:\WINDOWS\system32\drivers\hexmagic.sys><N/A>
[Motorola_NA USBLAN / Motorola_NA USBLAN][Stopped/Manual Start]
<system32\DRIVERS\motblan.sys><N/A>
[MotoSwitch Service / MotoSwitchService][Stopped/Manual Start]
<system32\DRIVERS\motswch.sys><Motorola INC.>
[NAVENG / NAVENG][Running/Manual Start]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070429.016\naveng.sys><Symantec Corporation>
[NAVEX15 / NAVEX15][Running/Manual Start]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070429.016\navex15.sys><Symantec Corporation>
[DriverStudio Device Filter / nmfilter][Stopped/Manual Start]
<system32\DRIVERS\nmfilter.sys><N/A>
[npkcrypt / npkcrypt][Stopped/Disabled]
<\??\D:\Program Files\Tencent\qq\npkcrypt.sys><N/A>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Motorola USB Device / P2k][Stopped/Manual Start]
<system32\DRIVERS\P2k.sys><Motorola Inc>
[Padus ASPI Shell / pfc][Running/Manual Start]
<system32\drivers\pfc.sys><Padus, Inc.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[SAVRT / SAVRT][Running/System Start]
<\??\C:\Program Files\Symantec AntiVirus\savrt.sys><Symantec Corporation>
[SAVRTPEL / SAVRTPEL][Running/System Start]
<\??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys><Symantec Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[Sentinel / Sentinel][Running/Auto Start]
<\SystemRoot\System32\Drivers\SENTINEL.SYS><Rainbow Technologies, Inc.>
[Rainbow USB SuperPro / Sntnlusb][Stopped/Manual Start]
<system32\DRIVERS\SNTNLUSB.SYS><Rainbow Technologies Inc.>
[SPBBCDrv / SPBBCDrv][Stopped/Manual Start]
<\??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys><Symantec Corporation>
[SymEvent / SymEvent][Running/Manual Start]
<\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV][Running/Manual Start]
<\SystemRoot\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI][Running/System Start]
<\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[Motorola USB Modem Driver for MPT / usbsermpt][Stopped/Manual Start]
<system32\DRIVERS\usbsermpt.sys><Microsoft Corporation>
[vsdatant / vsdatant][Running/System Start]
<System32\vsdatant.sys><Zone Labs, LLC>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[FAMETECH USB PC CAMERA / ZSMC301b][Stopped/Manual Start]
<System32\Drivers\usbVM31b.sys><VM>