SREng 扫描日志!
[CODE]
2007-10-18,17:03:14
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<bgswitch><; C:\WINDOWS\system32\bgswitch.exe> [N/A]
<updatereal><; C:\WINDOWS\realupdate.exe other> [N/A]
<winsamps><; C:\WINDOWS\winamps.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<kav><"D:\Kaspersky6.0\avp.exe"> [Kaspersky Lab]
<Desktop><"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Run> []
<MSConfig><C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto> [(Verified)Microsoft Corporation]
<{A06CE1C0-085A-2052-0323-050220040056}><; "C:\Program Files\Common Files\{A06CE1C0-085A-2052-0323-050220040056}\Update.exe" te-110-12-0000173> [N/A]
<wdfmgr32><; C:\WINDOWS\system32\wdfmgr32.exe> [N/A]
<ba9ro><; rundll32.exe C:\WINDOWS\flvk9clgk715.dll _start@16> [N/A]
<bm0od68j5><; rundll32.exe C:\WINDOWS\08aqga63v.dll _start@16> [N/A]
<IEBarUp><; RunDll32 "C:\WINDOWS\system32\IeBar1.dll",Run> [Microsoft Corporation]
<IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<IpWins><; C:\Program Files\Ipwindows\ipwins.exe> [N/A]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<sdafdsafds><; D;]XJOEPXT]ufnq]te266/fyf> [N/A]
<System><; C:\Program Files\Common Files\System\Updaterun.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,rundll32.exe C:\WINDOWS\system32\winsys16_070121.dll start> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{48B783AE-8F87-4046-8154-7D82FBCE42D2}><C:\WINDOWS\system32\dsfhw.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad]
<SysChunk><C:\WINDOWS\system32\syschunk.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptimg]
<WinlogonNotify: cryptimg><cryptig.dll> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
<WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll> [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCardLogn]
<WinlogonNotify: ScCardLogn><C:\WINDOWS\ScNotify.dll> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{B63BFF8C-2E25-4CCC-9A01-68807F567AA7}><C:\WINDOWS\system32\WsReource.dll> []
==================================
启动文件夹
N/A
==================================
服务
[卡巴斯基反病毒软件6.0 / AVP][Running/Auto Start]
<D:\Kaspersky6.0\avp.exe -r><Kaspersky Lab>
[WinCheckWeb / CheckWeb][Running/Auto Start]
<C:\Windows\system32\MVDKRZG.EXE><N/A>
[COM+ Messages / COM+ Messages][Running/Auto Start]
<"C:\WINDOWS\system32\svchosts.exe" -e te-110-12-0000173><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Logical Disk Manager Administrator Service / Logical Disk Manager Administrator Service][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\ntxml.dll><>
[Messenger / Messenger][Running/Auto Start]
<C:\WINDOWS\System32\svchost -k DcomLaunch-->C:\WINDOWS\system32\msgsvc32.dll><Microsoft Corporation>
[Indexing Data / MOBILL][Running/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\KFEAS.DLL,Export 1087><N/A>
[WindowsNt Workstation / NTWorkStan][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k NTWorkStan-->c:\windows\system32\ntworkstan.dll><Microsoft Corporation>
[RestoreServices / RestoreServices][Running/Auto Start]
<C:\WINDOWS\system32\Svchost.exe -k RestoreServices-->C:\WINDOWS\system32\drivers\restore.dll><Microsoft Corporation All rights reserved>
[Security / Security][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\oivbj.dll><Microsoft Corporation>
[SQLServer Supports / sqlservech][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k sqlservech-->c:\windows\system32\sqlservech.dll><Microsoft Corporation>
[Provisioning Transaction Service / ttt_14][Running/Auto Start]
<C:\WINDOWS\system32\win.exe><N/A>
[Vsn ujyl Service / ujyl][Running/Auto Start]
<C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\xper\ewly.dll,Service><Microsoft Corporation>
[Windows NT Service32 / Windows NT Service32][Stopped/Auto Start]
<"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Start><Microsoft Corporation>
[Windows Media Connect Service / WmdmPmSp][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\WmdmPmSp.dll><LINKMEDIA Tech>
[WindowsNt Network Engine / wnttech][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k wnttech-->c:\windows\system32\wnttech.dll><Microsoft Corporation>
==================================
驱动程序
[acpidisk / acpidisk][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[adpu64 / adpu64][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\adpu64.sys><N/A>
[ast / ast][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\ast.sys><N/A>
[fdyqmml / fdyqmml][Running/Boot Start]
<\SystemRoot\system32\drivers\fdyqmml.sys><N/A>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Running/Manual Start]
<system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[kl1 / kl1][Running/Boot Start]
<\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[kxsmp / kxsmp][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\kxsmp.sys><N/A>
[msprotect / msprotect][Running/System Start]
<system32\DRIVERS\msprotect.sys><Windows (R) 2000 DDK provider>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[rl_hlp / rl_hlp][Running/Boot Start]
<\SystemRoot\system32\drivers\rl_hlp.sys><N/A>
[S3SavageNB / S3SavageNB][Running/Manual Start]
<system32\DRIVERS\s3gnbm.sys><S3 Graphics, Inc.>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[SVKP / SVKP][Running/Auto Start]
<\??\C:\WINDOWS\system32\SVKP.sys><AntiCracking>
[ViaIde / ViaIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
==================================
浏览器加载项
[IEMonitor Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\WINDOWS\system32\IESHEL~1.DLL, >
[CAdLogic
Object]
{11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\CPUSH\cpush0.dll, N/A>
[]
{13B80B13-6D02-424C-88E4-5EABF0883CA0} <C:\WINDOWS\system32\vabqsiecziutw.dll, N/A>
[SafeMe Internet Explorer Helper]
{3AE06CEE-58A6-4F5F-AF89-6C5350842F16} <C:\WINDOWS\system32\SafeHelper12.dll, LINKMEDIA Tech>
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[ui Class]
{4CEB0B7C-0729-412b-8627-0088FB4F6D9F} <C:\WINDOWS\system32\BHO04.dll, >
[rgvi]
{5D8D2854-28B7-4674-B4A8-4E7CAB720E13} <C:\PROGRA~1\xper\baiv.dll, >
[]
{6671A431-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\xper\.dll, N/A>
[实用搜索]
{6CFD436C-7AAD-4e50-992F-C0C87A94CAD2} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[QOYGQ]
{BFCDA400-6B71-47D9-85BA-51484FCEADE7} <C:\WINDOWS\system32\DJQXGNTAHOVCIPW.DLL, N/A>
[Bar888]
{C1B4DEC2-2623-438e-9CA2-C9043AB28508} <C:\PROGRA~1\COMMON~1\{306CE~1\Bar888.dll, N/A>
[IEHlprObj Class]
{DE7C3CF0-4B15-11D1-ABED-709549C10000} <C:\WINDOWS\POPNTS.DLL, >
[16ad]
{DFCB34B6-902D-426E-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\4c9cntos.dll, N/A>
[Web反病毒保护]
{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <D:\Kaspersky6.0\scieplugin.dll, Kaspersky Lab>
[番茄花园]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.tomatolei.com, N/A>
[易趣购物]
{BE9C13C3-9E46-4db1-BC05-BD8DA44599F2} <http://adfarm.mediaplex.com/ad/ck/4080-22910-9640-151?cn=song;icon;hp&mpro=http://www.ebay.com.cn, N/A>
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[16ad]
{DFCB34B6-902D-426E-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\4c9cntos.dll, N/A>
[Bar888]
{C1B4DEC2-2623-438e-9CA2-C9043AB28508} <C:\PROGRA~1\COMMON~1\{306CE~1\Bar888.dll, N/A>
[实用搜索工具条2.0]
{03465FF5-00AE-411a-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[实用搜索工具条2.0]
{03465FF5-00AE-411A-9C34-960ED566EC03} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[IEMonitor Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\WINDOWS\system32\IESHEL~1.DLL, >
[CAdLogic
Object]
{11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\CPUSH\cpush0.dll, N/A>
[]
{13B80B13-6D02-424C-88E4-5EABF0883CA0} <C:\WINDOWS\system32\vabqsiecziutw.dll, N/A>
[SafeMe Internet Explorer Helper]
{3AE06CEE-58A6-4F5F-AF89-6C5350842F16} <C:\WINDOWS\system32\SafeHelper12.dll, LINKMEDIA Tech>
[雅虎助手]
{406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[ui Class]
{4CEB0B7C-0729-412B-8627-0088FB4F6D9F} <C:\WINDOWS\system32\BHO04.dll, >
[rgvi]
{5D8D2854-28B7-4674-B4A8-4E7CAB720E13} <C:\PROGRA~1\xper\baiv.dll, >
[]
{6671A431-5C3D-463D-A7CF-5587F9B7E191} <C:\PROGRA~1\xper\.dll, N/A>
[实用搜索]
{6CFD436C-7AAD-4E50-992F-C0C87A94CAD2} <C:\Program Files\superutilbar\superutilbar.dll, www.shiyongsousuo.com>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[QOYGQ]
{BFCDA400-6B71-47D9-85BA-51484FCEADE7} <C:\WINDOWS\system32\DJQXGNTAHOVCIPW.DLL, N/A>
[Bar888]
{C1B4DEC2-2623-438E-9CA2-C9043AB28508} <C:\PROGRA~1\COMMON~1\{306CE~1\Bar888.dll, N/A>
[Shockwave Flash
Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\Flash85.ocx, Macromedia, Inc.>
[IEHlprObj Class]
{DE7C3CF0-4B15-11D1-ABED-709549C10000} <C:\WINDOWS\POPNTS.DLL, >
[16ad]
{DFCB34B6-902D-426E-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\4c9cntos.dll, N/A>
[雅虎搜索]
<res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246, N/A>