瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 有点怪怪的:(已附SREng日志11楼起))【求助】

1234   3  /  4  页   跳转

有点怪怪的:(已附SREng日志11楼起))【求助】

[C:\WINDOWS\system32\comctl32.dll]  [Microsoft Corporation, 5.82 (xpsp.060825-0040)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\PINTLGNT.IME]  [Microsoft Corporation, 5.3.0.4427]
    [C:\WINDOWS\system32\Secur32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2148][C:\Program Files\ExPLabs.com\LinkScanner\linkscannerconsole.exe]  [Exploit Prevention Labs, Inc., 2.6.6.90]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301)]
    [C:\Program Files\ExPLabs.com\LinkScanner\XPLmwSDK.dll]  [Exploit Prevention Labs, Inc., 2.6.6.90]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WININET.dll]  [Microsoft Corporation, 6.00.2900.3164 (xpsp_sp2_qfe.070626-1258)]
    [C:\WINDOWS\system32\CRYPT32.dll]  [Microsoft Corporation, 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.1.2600.3159 (xpsp_sp2_gdr.070619-1300)]
    [C:\WINDOWS\system32\VBAJET32.DLL]  [Microsoft Corporation, 6.1.9431]
    [C:\WINDOWS\system32\expsrv.dll]  [Microsoft Corporation, 6.0.9589]
    [C:\WINDOWS\System32\mswsock.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\DNSAPI.dll]  [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]
    [C:\WINDOWS\system32\iphlpapi.dll]  [Microsoft Corporation, 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003)]
    [C:\WINDOWS\System32\winrnr.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WLDAP32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\rasadhlp.dll]  [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]
    [C:\Program Files\ExPLabs.com\LinkScanner\LinkScannerConnectPS.dll]  [N/A, ]
    [C:\WINDOWS\system32\SXS.DLL]  [Microsoft Corporation, 5.1.2600.3019 (xpsp_sp2_gdr.061019-0414)]
    [C:\WINDOWS\system32\msxml3.dll]  [Microsoft Corporation, 8.90.1101.0]
    [C:\Program Files\ExPLabs.com\LinkScanner\wrnetdrv.dll]  [Exploit Prevention Labs, Inc., 2.6.6.90]
    [C:\WINDOWS\system32\hnetcfg.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\ExPLabs.com\LinkScanner\SiteBlocker.dll]  [Exploit Prevention Labs, Inc., 2.6.6.90]
    [C:\Program Files\ExPLabs.com\LinkScanner\zlib1.dll]  [, 1.2.3]
    [C:\Program Files\ExPLabs.com\LinkScanner\SploitChecker.dll]  [Exploit Prevention Labs, Inc., 2.6.6.90]
    [C:\WINDOWS\System32\wshtcpip.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2228][C:\Program Files\ExPLabs.com\LinkScanner\LinkScannerConnect.exe]  [CallingID Ltd., 1.0.0.24]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.1.2600.3159 (xpsp_sp2_gdr.070619-1300)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.2900.3157 (xpsp_sp2_qfe.070614-1244)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]
gototop
 

[C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 5.1.2600.3139]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0420.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UmxSbxExw.dll]  [Computer Associates International, Inc., 6.0.1.58]
    [C:\WINDOWS\system32\UmxSbxw.dll]  [Computer Associates International, Inc., 6.0.1.58]
    [C:\WINDOWS\system32\psapi.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\comctl32.dll]  [Microsoft Corporation, 5.82 (xpsp.060825-0040)]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\CLBCATQ.DLL]  [Microsoft Corporation, 2001.12.4414.308]
    [C:\WINDOWS\system32\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.258]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\xpsp2res.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\PINTLGNT.IME]  [Microsoft Corporation, 5.3.0.4427]
    [C:\WINDOWS\system32\Secur32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Common Files\System\ado\msado15.dll]  [Microsoft Corporation, 2.81.1128.0 (xpsp_sp2_gdr.061226-0034)]
    [C:\WINDOWS\system32\MSDART.DLL]  [Microsoft Corporation, 2.81.1117.0 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\comdlg32.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Common Files\System\Ole DB\oledb32.dll]  [Microsoft Corporation, 2.81.1117.0 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Common Files\System\Ole DB\OLEDB32R.DLL]  [Microsoft Corporation, 2.81.1117.0 built by: (_sqlbld)]
    [C:\WINDOWS\system32\msjetoledb40.dll]  [Microsoft Corporation, 4.00.8227.0]
    [C:\WINDOWS\system32\msjet40.dll]  [Microsoft Corporation, 4.00.8618.0]
    [C:\WINDOWS\system32\mswstr10.dll]  [Microsoft Corporation, 4.00.8905.0]
    [C:\WINDOWS\system32\msjter40.dll]  [Microsoft Corporation, 4.00.6508.0]
    [C:\WINDOWS\system32\MSJINT40.DLL]  [Microsoft Corporation, 4.00.8905.0]
    [C:\WINDOWS\system32\SETUPAPI.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\comsvcs.dll]  [Microsoft Corporation, 2001.12.4414.308]
    [C:\WINDOWS\system32\colbact.DLL]  [Microsoft Corporation, 2001.12.4414.308]
    [C:\WINDOWS\system32\MTXCLU.DLL]  [Microsoft Corporation, 2001.12.4414.311]
    [C:\WINDOWS\system32\WSOCK32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\NETAPI32.dll]  [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]
    [C:\WINDOWS\system32\CLUSAPI.DLL]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\RESUTILS.DLL]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msjtes40.dll]  [Microsoft Corporation, 4.00.8618.0]
    [C:\WINDOWS\system32\VBAJET32.DLL]  [Microsoft Corporation, 6.1.9431]
    [C:\WINDOWS\system32\expsrv.dll]  [Microsoft Corporation, 6.0.9589]
    [C:\Program Files\Common Files\System\ado\msadrh15.dll]  [Microsoft Corporation, 2.81.1117.0 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\ExPLabs.com\LinkScanner\LinkScannerConnectPS.dll]  [N/A, ]
[PID: 2572][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.1.2600.3159 (xpsp_sp2_gdr.070619-1300)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.2900.3157 (xpsp_sp2_qfe.070614-1244)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\SHDOCVW.dll]  [Microsoft Corporation, 6.00.2900.3157 (xpsp_sp2_qfe.070614-1244)]
    [C:\WINDOWS\system32\CRYPT32.dll]  [Microsoft Corporation, 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\MSASN1.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\CRYPTUI.dll]  [Microsoft Corporation, 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WINTRUST.dll]  [Microsoft Corporation, 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\IMAGEHLP.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 5.1.2600.3139]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]
    [C:\WINDOWS\system32\NETAPI32.dll]  [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]
    [C:\WINDOWS\system32\WININET.dll]  [Microsoft Corporation, 6.00.2900.3164 (xpsp_sp2_qfe.070626-1258)]
    [C:\WINDOWS\system32\WLDAP32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0420.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UmxSbxExw.dll]  [Computer Associates International, Inc., 6.0.1.58]
    [C:\WINDOWS\system32\UmxSbxw.dll]  [Computer Associates International, Inc., 6.0.1.58]
    [C:\WINDOWS\system32\psapi.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]
    [C:\WINDOWS\system32\comctl32.dll]  [Microsoft Corporation, 5.82 (xpsp.060825-0040)]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\BROWSEUI.dll]  [Microsoft Corporation, 6.00.2900.3157 (xpsp_sp2_qfe.070614-1244)]
    [D:\program file\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\WINDOWS\system32\browselc.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\appHelp.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\CLBCATQ.DLL]  [Microsoft Corporation, 2001.12.4414.308]
    [C:\WINDOWS\system32\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.258]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\PINTLGNT.IME]  [Microsoft Corporation, 5.3.0.4427]
    [C:\WINDOWS\system32\Secur32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\cscui.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\CSCDLL.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\SETUPAPI.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\urlmon.dll]  [Microsoft Corporation, 6.00.2900.3157 (xpsp_sp2_qfe.070614-1244)]
gototop
 

[C:\Program Files\ExPLabs.com\LinkScanner\LinkScannerIE.dll]  [Exploit Prevention Labs, Inc., 2.6.6.90]
    [C:\Program Files\ExPLabs.com\LinkScanner\XPLmwSDK.dll]  [Exploit Prevention Labs, Inc., 2.6.6.90]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\ExPLabs.com\LinkScanner\LSCoreLight.dll]  [CallingID Ltd., 1.0.0.24]
    [C:\WINDOWS\system32\xpsp2res.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Common Files\System\ado\msado15.dll]  [Microsoft Corporation, 2.81.1128.0 (xpsp_sp2_gdr.061226-0034)]
    [C:\WINDOWS\system32\MSDART.DLL]  [Microsoft Corporation, 2.81.1117.0 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\comdlg32.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Common Files\System\Ole DB\oledb32.dll]  [Microsoft Corporation, 2.81.1117.0 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Common Files\System\Ole DB\OLEDB32R.DLL]  [Microsoft Corporation, 2.81.1117.0 built by: (_sqlbld)]
    [C:\WINDOWS\system32\msjetoledb40.dll]  [Microsoft Corporation, 4.00.8227.0]
    [C:\WINDOWS\system32\msjet40.dll]  [Microsoft Corporation, 4.00.8618.0]
    [C:\WINDOWS\system32\mswstr10.dll]  [Microsoft Corporation, 4.00.8905.0]
    [C:\WINDOWS\system32\msjter40.dll]  [Microsoft Corporation, 4.00.6508.0]
    [C:\WINDOWS\system32\MSJINT40.DLL]  [Microsoft Corporation, 4.00.8905.0]
    [C:\WINDOWS\system32\comsvcs.dll]  [Microsoft Corporation, 2001.12.4414.308]
    [C:\WINDOWS\system32\colbact.DLL]  [Microsoft Corporation, 2001.12.4414.308]
    [C:\WINDOWS\system32\MTXCLU.DLL]  [Microsoft Corporation, 2001.12.4414.311]
    [C:\WINDOWS\system32\WSOCK32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\CLUSAPI.DLL]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\RESUTILS.DLL]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Common Files\System\ado\msadrh15.dll]  [Microsoft Corporation, 2.81.1117.0 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msjtes40.dll]  [Microsoft Corporation, 4.00.8618.0]
    [C:\WINDOWS\system32\VBAJET32.DLL]  [Microsoft Corporation, 6.1.9431]
    [C:\WINDOWS\system32\expsrv.dll]  [Microsoft Corporation, 6.0.9589]
    [C:\WINDOWS\System32\mswsock.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\DNSAPI.dll]  [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]
    [C:\WINDOWS\System32\winrnr.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\rasadhlp.dll]  [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]
    [C:\Program Files\ExPLabs.com\LinkScanner\LinkScannerConnectPS.dll]  [N/A, ]
    [C:\WINDOWS\system32\SXS.DLL]  [Microsoft Corporation, 5.1.2600.3019 (xpsp_sp2_gdr.061019-0414)]
    [D:\360Safe\safemon\safemon.dll]  [, 3, 6, 1, 1001]
    [C:\WINDOWS\system32\msxml3.dll]  [Microsoft Corporation, 8.90.1101.0]
    [C:\Program Files\ExPLabs.com\LinkScanner\wrnetdrv.dll]  [Exploit Prevention Labs, Inc., 2.6.6.90]
    [C:\WINDOWS\system32\hnetcfg.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\ExPLabs.com\LinkScanner\NetProcTrack.dll]  [Exploit Prevention Labs, Inc., 2.6.6.90]
    [C:\Program Files\ExPLabs.com\LinkScanner\SiteBlocker.dll]  [Exploit Prevention Labs, Inc., 2.6.6.90]
    [C:\Program Files\ExPLabs.com\LinkScanner\zlib1.dll]  [, 1.2.3]
    [C:\WINDOWS\system32\shdoclc.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\mlang.dll]  [Microsoft Corporation, 6.00.2900.2530 (xpsp.040919-1030)]
    [C:\Program Files\ExPLabs.com\LinkScanner\SploitChecker.dll]  [Exploit Prevention Labs, Inc., 2.6.6.90]
    [C:\WINDOWS\System32\wshtcpip.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\RASAPI32.DLL]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\rasman.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\TAPI32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\rtutils.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WINMM.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\program file\adialhk.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\WINDOWS\system32\msv1_0.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\iphlpapi.dll]  [Microsoft Corporation, 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003)]
    [C:\WINDOWS\system32\mshtml.dll]  [Microsoft Corporation, 6.00.2900.3157 (xpsp_sp2_qfe.070614-1244)]
    [C:\WINDOWS\system32\msls31.dll]  [Microsoft Corporation, 3.10.349.0]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\WINDOWS\system32\jscript.dll]  [Microsoft Corporation, 5.6.0.8831]
    [D:\program file\klscav.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\program file\prremote.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\program file\prloader.dll]  [Kaspersky Lab, 6.0.2.621]
    [D:\program file\prkernel.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\program file\params.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\program file\pxstub.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\program file\tempfile.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\program file\nfio.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\program file\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\program file\basegui.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\program file\thpimpl.ppl]  [Kaspersky Lab, 6.0.2.621]
    [d:\program file\FSSync.dll]  [Kaspersky Lab, 6.0.5.621]
    [d:\program file\winreg.ppl]  [Kaspersky Lab, 6.0.2.621]
    [C:\WINDOWS\system32\mshtmled.dll]  [Microsoft Corporation, 6.00.2900.3157 (xpsp_sp2_qfe.070614-1244)]
    [C:\WINDOWS\system32\ImgUtil.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\pngfilt.dll]  [Microsoft Corporation, 6.00.2900.3157 (xpsp_sp2_qfe.070614-1244)]
    [C:\WINDOWS\system32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\MSACM32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\midimap.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\Macromed\Flash\flash.ocx]  [Macromedia, Inc., 8,0,22,0]
    [C:\WINDOWS\system32\ddrawex.dll]  [Microsoft Corporation, 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\DDRAW.dll]  [Microsoft Corporation, 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\DCIMAN32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2924][D:\Program Files\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\WINDOWS\system32\ntdll.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.1.2600.3159 (xpsp_sp2_gdr.070619-1300)]
    [C:\WINDOWS\system32\comdlg32.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.2900.3157 (xpsp_sp2_qfe.070614-1244)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.2900.3051 (xpsp_sp2_gdr.061219-0316)]
    [C:\WINDOWS\system32\WINSPOOL.DRV]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\oledlg.dll]  [Microsoft Corporation, 1.0 (xpsp_sp2_gdr.061016-0148)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 5.1.2600.3139]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\CRYPT32.dll]  [Microsoft Corporation, 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\MSASN1.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WINMM.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.1.2600.2180
gototop
 

xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WININET.dll]  [Microsoft Corporation, 6.00.2900.3164 (xpsp_sp2_qfe.070626-1258)]
    [C:\WINDOWS\system32\IMM32.DLL]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\LPK.DLL]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\USP10.dll]  [Microsoft Corporation, 1.0420.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UmxSbxExw.dll]  [Computer Associates International, Inc., 6.0.1.58]
    [C:\WINDOWS\system32\UmxSbxw.dll]  [Computer Associates International, Inc., 6.0.1.58]
    [C:\WINDOWS\system32\psapi.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\RICHED20.DLL]  [Microsoft Corporation, 5.30.23.1228]
    [C:\WINDOWS\system32\NTMARTA.DLL]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WLDAP32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\SAMLIB.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\Secur32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msctfime.ime]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\PINTLGNT.IME]  [Microsoft Corporation, 5.3.0.4427]
    [C:\WINDOWS\system32\sfc.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\sfc_os.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WINTRUST.dll]  [Microsoft Corporation, 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\IMAGEHLP.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\wsock32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\RASAPI32.DLL]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\rasman.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\NETAPI32.dll]  [Microsoft Corporation, 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106)]
    [C:\WINDOWS\system32\TAPI32.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\rtutils.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\program file\adialhk.dll]  [Kaspersky Lab, 6.0.2.621]
    [C:\WINDOWS\system32\msv1_0.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\iphlpapi.dll]  [Microsoft Corporation, 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003)]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\urlmon.dll]  [Microsoft Corporation, 6.00.2900.3157 (xpsp_sp2_qfe.070614-1244)]
    [C:\WINDOWS\System32\mswsock.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\DNSAPI.dll]  [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]
    [C:\WINDOWS\system32\rasadhlp.dll]  [Microsoft Corporation, 5.1.2600.2938 (xpsp_sp2_gdr.060626-0020)]
    [C:\Program Files\ExPLabs.com\LinkScanner\wrnetdrv.dll]  [Exploit Prevention Labs, Inc., 2.6.6.90]
    [C:\WINDOWS\system32\hnetcfg.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\ExPLabs.com\LinkScanner\NetProcTrack.dll]  [Exploit Prevention Labs, Inc., 2.6.6.90]
    [C:\Program Files\ExPLabs.com\LinkScanner\SiteBlocker.dll]  [Exploit Prevention Labs, Inc., 2.6.6.90]
    [C:\Program Files\ExPLabs.com\LinkScanner\zlib1.dll]  [, 1.2.3]
    [C:\Program Files\ExPLabs.com\LinkScanner\SploitChecker.dll]  [Exploit Prevention Labs, Inc., 2.6.6.90]
    [C:\WINDOWS\System32\wshtcpip.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\Winsta.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\utildll.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\SETUPAPI.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\xpsp2res.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\rsaenh.dll]  [Microsoft Corporation, 5.1.2600.2161 (xpsp.040706-1629)]
    [C:\WINDOWS\system32\cryptnet.dll]  [Microsoft Corporation, 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WINHTTP.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\SensApi.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
WRProvider over [MSAFD Tcpip [TCP/IP]]
    C:\Program Files\ExPLabs.com\LinkScanner\wrnetdrv.dll(Exploit Prevention Labs, Inc., LinkScanner LSP)
WRProvider over [MSAFD Tcpip [UDP/IP]]
    C:\Program Files\ExPLabs.com\LinkScanner\wrnetdrv.dll(Exploit Prevention Labs, Inc., LinkScanner LSP)
WRProvider over [MSAFD Tcpip [RAW/IP]]
    C:\Program Files\ExPLabs.com\LinkScanner\wrnetdrv.dll(Exploit Prevention Labs, Inc., LinkScanner LSP)
WRProvider over [RSVP UDP Service Provider]
    C:\Program Files\ExPLabs.com\LinkScanner\wrnetdrv.dll(Exploit Prevention Labs, Inc., LinkScanner LSP)
WRProvider over [RSVP TCP Service Provider]
    C:\Program Files\ExPLabs.com\LinkScanner\wrnetdrv.dll(Exploit Prevention Labs, Inc., LinkScanner LSP)
WRProvider
    C:\Program Files\ExPLabs.com\LinkScanner\wrnetdrv.dll(Exploit Prevention Labs, Inc., LinkScanner LSP)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
N/A

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 2040, D:\PROGRAM FILES\AMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2228, C:\PROGRAM FILES\EXPLABS.COM\LINKSCANNER\LINKSCANNERCONNECT.EXE]

==================================
gototop
 

==================================
API HOOK
入口点错误:EnumServicesStatusA (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:EnumServicesStatusExA (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:ChangeServiceConfigA (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:ChangeServiceConfig2A (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:EnumServicesStatusW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:EnumServicesStatusExW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:ChangeServiceConfigW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:ChangeServiceConfig2W (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:ControlService (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:CreateServiceA (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:CreateServiceW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:DeleteService (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:EnumDependentServicesA (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:QueryServiceConfigA (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:QueryServiceConfig2A (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:QueryServiceStatus (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:QueryServiceStatusEx (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:EnumDependentServicesW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:QueryServiceConfigW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:QueryServiceConfig2W (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
RVA  错误: LoadLibraryA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: LoadLibraryExA (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
RVA  错误: LoadLibraryExW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
RVA  错误: LoadLibraryW (危险等级: 高,  被下面模块所HOOK: \??\C:\WINDOWS\system32\drivers\klif.sys)
入口点错误:TerminateProcess (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:TerminateThread (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:CreateProcessA (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:CreateProcessW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:CreateRemoteThread (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:ExitProcess (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:FreeLibrary (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:WriteProcessMemory (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:OpenThread (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:PostMessageA (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:PostMessageW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:PostThreadMessageA (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:PostThreadMessageW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:SendMessageA (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:SendMessageCallbackA (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:SendMessageCallbackW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:SendMessageTimeoutA (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:SendMessageTimeoutW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:SendMessageW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:SendNotifyMessageA (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:SendNotifyMessageW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:SetWindowsHookA (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:SetWindowsHookExA (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:SetWindowsHookExW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)
入口点错误:SetWindowsHookW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\UmxSbxw.dll)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

[Add to Anti-Banner]
<D:\program file\ie_banner_deny.htm, N/A>
看来这东西可疑!
gototop
 

发完了日志自己都没时间将它看完。

怎么没有高手继续帮看呢?

自己顶一下。
gototop
 

引用:
【baohe的贴子】【回复“两个铁球”的帖子】
日志未见异常
………………

谢谢!真是怪了,ie企图关掉卡巴服务的纪录,TINY依然每天都有。上面我怀疑的那个文件,不让改名也不让删(但不知是否TINY的一些设置使然),刚才偶做了备份“另存为”(这法可能不行)后,想法子打开其内容,其中有涉及已弃用的AVG的文字。究竟咋回事,回头有时间再理。
gototop
 


if TypeName(srcAnchor) = "HTMLImg" Then
DoCommand("banner_deny:" + srcAnchor.href)
elseif TypeName(srcAnchor) = "HTMLAnchorElement" Then
DoCommand("banner_deny:" + srcAnchor.href)
elseif TypeName(srcAnchor) = "HTMLAreaElement" Then
DoCommand("banner_deny:" + srcEvent.srcElement.href)
elseif TypeName(srcAnchor) = "HTMLInputElement" Then
DoCommand("banner_deny:" + srcAnchor.src)
end if

'' Allow link for web antivirus
'end if

</script></head></html>
gototop
 

各位高手、斑竹:两天了。我的问题依然如故。今天下午,卡巴Kis6居然不声不响的被挂掉了!(不仅停止Klif服务的一贯企图得逞了,而且卡巴的所有进程、图标都没了。我在SSM和Tiny里对卡巴的保护都设置好了的,甚至在SSM里设置了“若被关闭则重起”,但是不论从哪个途径重启卡巴都马上又被关闭(tiny的Activity Monitor详细记载可知。)不久,连tiny的ActivityMonitor和其托盘图标也挂了,从ssm的“规则”里启动都不行!无奈,进入“安全模式”,胡乱的用冰刀删除了所有的临时文件,重启计算机,好了!可是,卡巴的“反黑客功能”没有了!
gototop
 
1234   3  /  4  页   跳转
页面顶部
Powered by Discuz!NT