瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】帮忙看下日志,看了半天没看出什么

1   1  /  1  页   跳转

【求助】帮忙看下日志,看了半天没看出什么

【求助】帮忙看下日志,看了半天没看出什么

高手帮忙看下日志,水平太低,看了半天没看出什么




2007-02-11,12:11:03

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows 98 SE  -

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <internat.exe><internat.exe>  [Microsoft Corporation]
    <ScanRegistry><C:\WINDOWS\scanregw.exe /autorun>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]

==================================
启动文件夹
N/A

==================================
服务
N/A

==================================
驱动程序
N/A

==================================
浏览器加载项
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <D:\PROGRAM FILES\FLASHGET\JCCATCH.DLL, Amaze Soft>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH8.OCX, Macromedia, Inc.>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\DOWNLOADED PROGRAM FILES\OL2005.DLL, Beijing Rising Technology Co., Ltd.>
[使用网际快车下载]
  <D:\PROGRAM FILES\FLASHGET\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <D:\PROGRAM FILES\FLASHGET\jc_all.htm, N/A>
[雅虎搜索]
  <res://C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL/246, N/A>
[添加到雅虎订阅(&Y)]
  <res://C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YRSS.DLL/YRSSMENUEXT, N/A>

==================================
正在运行的进程
[PID: 4294965293][C:\WINDOWS\SYSTEM\MPREXE.EXE]  [Microsoft Corporation, 4.10.1998]
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  [N/A, N/A]
    [D:\PROGRAM FILES\FLASHGET\JCCATCH.DLL]  [Amaze Soft, 1, 1, 4, 0]
[PID: 4294844781][C:\WINDOWS\EXPLORER.EXE]  [Microsoft Corporation, 4.72.3110.1]
[PID: 4294853153][C:\WINDOWS\SYSTEM\RPCSS.EXE]  [Microsoft Corporation, 4.71.2900]
[PID: 4294776153][C:\WINDOWS\SYSTEM\INTERNAT.EXE]  [Microsoft Corporation, 4.10.2222]
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  [N/A, N/A]
    [C:\PROGRAM FILES\EFFICIENT NETWORKS\ENTERNET 500\APP\RESENU.DLL]  [Efficient Networks, Inc., 1, 5, 0, 18]
[PID: 4294714717][C:\PROGRAM FILES\EFFICIENT NETWORKS\ENTERNET 500\APP\ENTERNET.EXE]  [N/A, N/A]
    [C:\PROGRAM FILES\EFFICIENT NETWORKS\ENTERNET 500\APP\DSLAPI32.DLL]  [Efficient Networks Inc., 1, 5, 0, 18]
    [C:\PROGRAM FILES\EFFICIENT NETWORKS\ENTERNET 500\APP\PACKETLOG.DLL]  [Efficient Networks, Inc., 1, 5, 0, 18]
    [C:\PROGRAM FILES\EFFICIENT NETWORKS\ENTERNET 500\APP\RESMSGENU.DLL]  [Efficient Networks, Inc., 1, 5, 0, 17]
    [C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WEB 文件夹\MSONSEXT.DLL]  [N/A, N/A]
    [C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH8.OCX]  [Macromedia, Inc., 8,0,22,0]
    [D:\PROGRAM FILES\FLASHGET\JCCATCH.DLL]  [Amaze Soft, 1, 1, 4, 0]
[PID: 4294746857][C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2800.1106]
[PID: 4294658173][C:\PROGRAM FILES\ACCESSORIES\WORDPAD.EXE]  [Microsoft Corporation, 5.00.1691.1]
    [C:\WINDOWS\SYSTEM\DD300_32.DLL]  [Silicon Integrated Systems Corporation, 4.13.01.1133]
[PID: 4294672981][C:\WINDOWS\SYSTEM\DDHELP.EXE]  [Microsoft Corporation, 4.09.00.0900]
    [C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WEB 文件夹\MSONSEXT.DLL]  [N/A, N/A]
    [C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH8.OCX]  [Macromedia, Inc., 8,0,22,0]
    [D:\PROGRAM FILES\FLASHGET\JCCATCH.DLL]  [Amaze Soft, 1, 1, 4, 0]
[PID: 4294806209][C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2800.1106]
[PID: 4294608433][C:\WINDOWS\TEMP\RAR$EX00.751\SRENG.EXE]  [Smallfrogs Studio, 2.3.13.690]

==================================
文件关联
.TXT  OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [C:\WINDOWS\winhlp32.exe %1]
.INI  OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF  OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS  OK. [C:\WINDOWS\WScript.exe "%1" %*]
.JS  OK. [C:\WINDOWS\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
MS.w95.spi.osp
    C:\WINDOWS\SYSTEM\mswsosp.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.tcp
    C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.udp
    C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.raw
    C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.rsvptcp
    C:\WINDOWS\SYSTEM\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
MS.w95.spi.rsvpudp
    C:\WINDOWS\SYSTEM\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
N/A

==================================
API HOOK
N/A

==================================




最后编辑2007-02-11 13:03:02
分享到:
gototop
 

[C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WEB 文件夹\MSONSEXT.DLL] [N/

这个是什么文件?机子有什么问题?

是win2000系统?裸奔?佩服!

有点流氓软件。
gototop
 

<ScanRegistry><C:\WINDOWS\scanregw.exe /autorun> [Microsoft Corporation]
这个删除
你的日志干净,我喜欢
gototop
 

谢谢楼上的,我运行瑞星在线查毒一查EXPLORER就被中止了,能帮忙解决下吗
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT