1   1  /  1  页   跳转

高手帮我看一下日志

高手帮我看一下日志

[CODE]

2007-02-20,17:06:00

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <internat.exe><internat.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]

==================================
启动文件夹
[OFF]
  <C:\Documents and Settings\WangJiWei\「开始」菜单\程序\启动\OFF.lnk --> C:\PROGRA~1\ARP绑~1\offarp.EXE [常州诚信网络技术联盟 QQ:535495            QQ群:1577517                                                ]><N>

==================================
服务
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
  <"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[McAfee Framework 服务 / McAfeeFramework][Stopped/Manual Start]
  <C:\Program Files\Network Associates\Common Framework\FrameworkService.exe /ServiceStart><Network Associates, Inc.>
[Network Associates McShield / McShield][Stopped/Manual Start]
  <"C:\Program Files\Network Associates\VirusScan\mcshield.exe"><Network Associates, Inc.>
[Network Associates Task Manager / McTaskManager][Stopped/Manual Start]
  <"C:\Program Files\Network Associates\VirusScan\vstskmgr.exe"><Network Associates, Inc.>
[Remote Administrator Service / r_server][Running/Auto Start]
  <"C:\Program Files\radmin3.2\r_server.exe" /service><N/A>
[WatcherService / WatcherService][Running/Auto Start]
  <C:\Watcher\WATCHE~1.EXE><N/A>
最后编辑2007-02-20 17:17:19
分享到:
gototop
 

==================================
驱动程序
[ADI UAA Function Driver for High Definition Audio Service / ADIHdAudAddService][Running/Manual Start]
  <system32\drivers\ADIHdAud.sys><Analog Devices, Inc.>
[AEAudio Service / AEAudioService][Running/Manual Start]
  <system32\drivers\AEAudio.sys><Andrea Electronics Corporation>
[ati2mtag / ati2mtag][Running/Manual Start]
  <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Broadcom 440x 10/100 Integrated Controller XP Driver / bcm4sbxp][Stopped/Manual Start]
  <system32\DRIVERS\bcm4sbxp.sys><Broadcom Corporation>
[genfs / genfs][Running/Boot Start]
  <2 - 系统找不到指定的文件。
><N/A>
[Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService][Stopped/Manual Start]
  <system32\drivers\HdAudio.sys><Windows (R) Server 2003 DDK provider>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
  <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[NaiAvFilter1 / NaiAvFilter1][Stopped/Manual Start]
  <system32\drivers\naiavf5x.sys><Network Associates, Inc.>
[NaiAvTdi1 / NaiAvTdi1][Running/System Start]
  <system32\drivers\mvstdi5x.sys><Network Associates, Inc.>
[Netgroup Packet Filter / NPF][Running/Manual Start]
  <system32\drivers\npf.sys><CACE Technologies>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\E:\Program Files\IPQQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Running/Manual Start]
  <system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[SenFilt Service / SenFiltService][Running/Manual Start]
  <system32\drivers\Senfilt.sys><Sensaura>
[sptd / sptd][Running/Boot Start]
  <\SystemRoot\System32\Drivers\sptd.sys><N/A>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[VIMICRO USB PC Camera / ZSMC302][Stopped/Manual Start]
  <System32\Drivers\usbVM31b.sys><VM>
[VIMICRO USB PC Camera (ZC0301PLH) / ZSMC303][Running/Manual Start]
  <System32\Drivers\usbVM303.sys><Vimicro Corporation>

==================================
浏览器加载项
[BHOImp Class]
  {70AFF2CB-9DA2-499C-8D15-900729FCE83D} <C:\WINDOWS\system32\YHBO.dll, YHBO>
[ThunderMini Browser Helper]
  {8E6C1C49-F9CE-4311-9FB4-D70E8B0AEAEB} <C:\Program Files\Thunder Network\ThunderMini\ComDlls\XunLeiMiniBHO_001.dll, Thunder Networking Technologies,LTD>
[金山快译(&K)]
  {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <D:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll, 金山软件股份有限公司>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[BHOImp Class]
  {70AFF2CB-9DA2-499C-8D15-900729FCE83D} <C:\WINDOWS\system32\YHBO.dll, YHBO>
[ThunderMini Browser Helper]
  {8E6C1C49-F9CE-4311-9FB4-D70E8B0AEAEB} <C:\Program Files\Thunder Network\ThunderMini\ComDlls\XunLeiMiniBHO_001.dll, Thunder Networking Technologies,LTD>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[&使用迷你迅雷下载]
  <C:\Program Files\Thunder Network\ThunderMini\Program\GetUrl.htm, N/A>
[上传到QQ网络硬盘]
  <E:\Program Files\IPQQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
  <E:\Program Files\IPQQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <E:\Program Files\IPQQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <E:\Program Files\IPQQ\SendMMS.htm, N/A>
gototop
 

==================================
正在运行的进程
[PID: 432][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 480][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 508][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4132]
    [C:\Watcher\APIHook_Dll.dll]  [N/A, N/A]
[PID: 552][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 564][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 704][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4132]
    [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2500]
    [C:\Watcher\APIHook_Dll.dll]  [N/A, N/A]
[PID: 732][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 804][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 988][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1424][C:\Program Files\radmin3.2\r_server.exe]  [N/A, N/A]
    [C:\Program Files\radmin3.2\ADMDLL.dll]  [N/A, N/A]
[PID: 1444][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1464][C:\Watcher\WATCHE~1.EXE]  [N/A, N/A]
[PID: 1496][C:\Watcher\ClientOfWatcher.exe]  [N/A, N/A]
    [C:\Watcher\ProgDataEngine.dll]  [, 1, 0, 0, 1]
    [C:\Watcher\APIHook_Dll.dll]  [N/A, N/A]
[PID: 1544][C:\Watcher\ClientPro.exe]  [, 1, 0, 0, 1]
    [C:\Watcher\APIHook_Dll.dll]  [N/A, N/A]
[PID: 1868][C:\WINDOWS\system32\wbem\wmiprvse.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 980][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4132]
    [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2500]
    [C:\Watcher\APIHook_Dll.dll]  [N/A, N/A]
[PID: 1264][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Watcher\APIHook_Dll.dll]  [N/A, N/A]
    [C:\Program Files\Thunder Network\ThunderMini\ComDlls\XunLeiMiniBHO_001.dll]  [Thunder Networking Technologies,LTD, 2, 0, 0, 1]
[PID: 1916][C:\WINDOWS\system32\internat.exe]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\Watcher\APIHook_Dll.dll]  [N/A, N/A]
[PID: 1736][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Watcher\APIHook_Dll.dll]  [N/A, N/A]
[PID: 240][\\mingyun\tools\工具\sreng2\SREng.EXE]  [N/A, N/A]
    [C:\Watcher\APIHook_Dll.dll]  [N/A, N/A]
    [\\mingyun\tools\工具\sreng2\Plugins\SRECXTMG.SRE]  [N/A, N/A]
[PID: 1072][C:\Program Files\xpmanager5.0_psgl\WinXP Manager.exe]  [Yamicsoft, 5.0.0.0]
    [C:\Program Files\xpmanager5.0_psgl\PCL.dll]  [ , 1.0.0.0]
    [C:\Watcher\APIHook_Dll.dll]  [N/A, N/A]
    [C:\Program Files\xpmanager5.0_psgl\BalloonTip.dll]  [ , 1.0.1787.15773]
    [C:\Program Files\xpmanager5.0_psgl\DevComponents.DotNetBar.dll]  [DevComponents.com, 5.0.0.0]
[PID: 1696][C:\WINDOWS\system32\wbem\wmiprvse.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1344][C:\Program Files\xpmanager5.0_psgl\ProcessManager.exe]  [Yamicsoft, 6.1.0.0]
    [C:\Program Files\xpmanager5.0_psgl\DevComponents.DotNetBar.dll]  [DevComponents.com, 5.0.0.0]
    [C:\Program Files\xpmanager5.0_psgl\DevExpress.XtraTreeList3.dll]  [Developer Express Inc., 1.11.1.0]
    [C:\Program Files\xpmanager5.0_psgl\DevExpress.XtraEditors3.dll]  [Developer Express Inc., 3.2.1.0]
    [C:\Program Files\xpmanager5.0_psgl\DevExpress.Utils3.dll]  [Developer Express Inc., 3.2.1.0]
    [C:\Program Files\xpmanager5.0_psgl\Tracker.dll]  [ , 1.0.844.28400]
    [C:\Program Files\xpmanager5.0_psgl\PCL.dll]  [ , 1.0.0.0]
    [C:\Watcher\APIHook_Dll.dll]  [N/A, N/A]
[PID: 952][C:\Program Files\xpmanager5.0_psgl\ServiceManager.exe]  [Yamicsoft, 5.0.0.0]
    [C:\Program Files\xpmanager5.0_psgl\DevComponents.DotNetBar.dll]  [DevComponents.com, 5.0.0.0]
    [C:\Program Files\xpmanager5.0_psgl\PCL.dll]  [ , 1.0.0.0]
    [C:\Watcher\APIHook_Dll.dll]  [N/A, N/A]
    [C:\Program Files\xpmanager5.0_psgl\ServiceControllerEx.dll]  [ , 1.0.1673.22953]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  Error. ["d:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe" "%1"]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost
127.0.0.1download.3721.com
127.0.0.1cn.download.yahoo.com
127.0.0.1cn.download.zs.yahoo.com
127.0.0.1download.yisou.com127.0.0.1download.3721.com
127.0.0.1cn.download.yahoo.com
127.0.0.1cn.download.zs.yahoo.com
127.0.0.1download.yisou.com

==================================
API HOOK
N/A

==================================


[/CODE]
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT