瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】请高手帮忙看下,我只看出一小点而已。

1   1  /  1  页   跳转

【求助】请高手帮忙看下,我只看出一小点而已。

【求助】请高手帮忙看下,我只看出一小点而已。

有些网址打不开,怀疑是给一些恶意软件给修改了,但是找不出,希望各位高手能帮我看下。
[CODE]

2007-11-13,11:13:23

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <jiajiasr><C:\Program Files\jj4\jiajiasr.exe>  [加加工作组]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <AVP><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe">  [(Verified)Kaspersky Lab]
    <RunmeAtStartup><C:\Program Files\IM\IM.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <360safeuninst><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\REMOVE~1.BAT>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
    <WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll>  [(Verified)Kaspersky Lab]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    <WinlogonNotify: WgaLogon><WgaLogon.dll>  [(Verified)Microsoft Corporation]

==================================
启动文件夹
N/A

==================================
服务
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[卡巴斯基反病毒6.0 Windows工作站 / AVP][Running/Auto Start]
  <"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe" -r><Kaspersky Lab>
[BlueSoleil Hid Service / BlueSoleil Hid Service][Running/Auto Start]
  <C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[卡巴斯基网络代理 / klnagent][Running/Auto Start]
  <"C:\Program Files\Kaspersky Lab\NetworkAgent\klnagent.exe"><Kaspersky Lab>
[BNESS / lDOMANE][Stopped/Auto Start]
  <C:\WINDOWS\SYSTEM32\RUNDLL2000.EXE C:\WINDOWS\SYSTEM32\WBEM\OIPSJ.DLL,Export 1087><N/A>
[ServiceLayer / ServiceLayer][Stopped/Manual Start]
  <"C:\Program Files\PC Connectivity Solution\ServiceLayer.exe"><Nokia.>

==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
  <System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
[Bluetooth Audio Service / BlueletAudio][Running/Manual Start]
  <system32\DRIVERS\blueletaudio.sys><IVT Corporation>
[Bluetooth PAN Network Adapter / BT][Stopped/Manual Start]
  <system32\DRIVERS\btnetdrv.sys><IVT Corporation>
[Bluetooth USB For Bluetooth Service / Btcsrusb][Stopped/Manual Start]
  <System32\Drivers\btcusb.sys><IVT Corporation>
[Bluetooth HID Enumerator / BTHidEnum][Running/Manual Start]
  <system32\DRIVERS\vbtenum.sys><N/A>
[Bluetooth HID Manager Service / BTHidMgr][Running/Boot Start]
  <\SystemRoot\System32\Drivers\BTHidMgr.sys><IVT Corporation>
[Intel(R) PRO Network Connection Driver / E100B][Running/Manual Start]
  <system32\DRIVERS\e100b325.sys><Intel Corporation>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[ialm / ialm][Running/Manual Start]
  <system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[kl1 / kl1][Running/Boot Start]
  <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[Kaspersky Anti-Virus NDIS Filter / klim5][Running/Manual Start]
  <system32\DRIVERS\klim5.sys><Kaspersky Lab>
[kmsinput / kmsinput][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[Nokia USB Phone Parent / nmwcd][Stopped/Manual Start]
  <system32\drivers\nmwcd.sys><Nokia>
[Nokia USB Generic / nmwcdc][Stopped/Manual Start]
  <system32\drivers\nmwcdc.sys><Nokia>
[Nokia USB Port / nmwcdcj][Stopped/Manual Start]
  <system32\drivers\nmwcdcj.sys><Nokia>
[Nokia USB Modem / nmwcdcm][Stopped/Manual Start]
  <system32\drivers\nmwcdcm.sys><Nokia>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
  <system32\drivers\npf.sys><CACE Technologies>
[npkcrypt / npkcrypt][Stopped/Auto Start]
  <\??\E:\88\npkcrypt.sys><N/A>
[npkycryp / npkycryp][Stopped/Manual Start]
  <\??\E:\88\npkycryp.sys><N/A>
[nv / nv][Stopped/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[NVIDIA Compatible Windows Miniport Driver / nvmini][Stopped/Auto Start]
  <system32\DRIVERS\nvmini.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[senfilt / senfilt][Running/Manual Start]
  <system32\drivers\senfilt.sys><Creative Technology Ltd.>
[smwdm / smwdm][Running/Manual Start]
  <system32\drivers\smwdm.sys><Analog Devices, Inc.>
[SNIFFER Protocol Driver / Sniffer][Running/Auto Start]
  <system32\DRIVERS\sniffer.sys><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[Virtual Serial port driver / VComm][Running/Manual Start]
  <system32\DRIVERS\VComm.sys><IVT Corporation>
[Bluetooth VComm Manager Service / VcommMgr][Running/Manual Start]
  <System32\Drivers\VcommMgr.sys><IVT Corporation>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[5166843 / 5166843][Running/Manual Start]
  <2 - 系统找不到指定的文件。
><N/A>

==================================

[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; MAXTHON 2.0)
最后编辑2007-11-22 22:13:02
分享到:
gototop
 

浏览器加载项
[Web反病毒统计]
  {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\SCIEPlgn.dll, Kaspersky Lab>
[快车]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\Program Files\FlashGet\FlashGet.exe, FlashGet.com>
[Windows Genuine Advantage Validation Tool]
  {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>
[PowerList Control]
  {20C2C286-BDE8-441B-B73D-AFA22D914DA5} <C:\WINDOWS\DOWNLO~1\POWERL~1.OCX, PPStream.com>
[EditCtrl Class]
  {488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\system32\aliedit\aliedit.dll, >
[AutoUpdate Control]
  {62E3A3CE-6DDE-4754-B0BE-167BAAF2D4E2} <C:\WINDOWS\DOWNLO~1\URRPInst.ocx, 广州市网天科技有限公司(Netsky)>
[163Uploader Control]
  {8686F2A6-DC01-4E8F-BDE3-DCC7DBBAD6AE} <C:\WINDOWS\system32\163UPL~1.OCX, 广州网易互动娱乐有限公司>
[Java Plug-in 1.4.1_02]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\j2re1.4.1_02\bin\npjpi141_02.dll, JavaSoft / Sun Microsystems, Inc.>
[SimpleWebOffice]
  {B240E9F4-6FC3-4FC3-9CDE-B31D5575AF91} <C:\WINDOWS\DOWNLO~1\SIMPLE~1.DLL, GDCN>
[Java Plug-in 1.4.1_02]
  {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} <C:\Program Files\Java\j2re1.4.1_02\bin\npjpi141_02.dll, JavaSoft / Sun Microsystems, Inc.>
[OpenAttachment Object]
  {D288E1E5-BE77-40AF-8F0F-D9F628406B9F} <C:\WINDOWS\DOWNLO~1\ATTACH~1.DLL, 广东南方通信高科技有限公司>
[&使用快车(FlashGet)下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[&使用快车(FlashGet)下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>
[使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到反广告黑名单]
  <C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\ie_banner_deny.htm, N/A>

==================================
正在运行的进程
[PID: 656][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 724][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 748][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\WINDOWS\system32\PYJJ4.IME]  [加加工作组, 4, 1, 0, 48]
[PID: 792][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 804][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 960][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1024][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1112][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\adialhk.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\Program Files\Oracle\Ora901\bin\oci.dll]  [Oracle Corporation, 9.0.1.1.1]
[PID: 1144][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1344][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1376][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1560][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
    [C:\WINDOWS\system32\PYJJ4.IME]  [加加工作组, 4, 1, 0, 48]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\scrchpg.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\ShellEx.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll]  [Nokia, 6, 84, 83, 7]
    [C:\Program Files\Nokia\Nokia PC Suite 6\PCSCM.dll]  [Nokia, 6, 84, 100, 4]
    [C:\Program Files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_chi-sc.nlr]  [Nokia, 6, 84, 51, 0]
    [C:\Program Files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr]  [Nokia, 6, 84, 15, 1]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\adialhk.dll]  [Kaspersky Lab, 6.0.2.690]
[PID: 1712][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1836][C:\Program Files\jj4\jiajiasr.exe]  [加加工作组, 4, 1, 0, 47]
    [C:\WINDOWS\system32\PYJJ4.IME]  [加加工作组, 4, 1, 0, 48]
[PID: 1904][C:\Program Files\IM\IM.exe]  [, 1, 0, 0, 1]
    [C:\Program Files\IM\IMEncrypt.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\IM\DGXML.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\PYJJ4.IME]  [加加工作组, 4, 1, 0, 48]
    [C:\Program Files\IM\IMClient.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\IM\IMUDP.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\IM\IMCMsg.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\IM\MsgRecord.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\IM\IMCShare.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\IM\IMCInfo.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\IM\IMftm.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\IM\ImTransFile.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\IM\MessManger.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\IM\IMUpdate.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\IM\IMShowImage.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\IM\NoteClient.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\IM\IMCAVControl.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\adialhk.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\Program Files\IM\BTDL.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\IM\bt.dll]  [, 1, 0, 0, 1]
    [C:\PROGRA~1\IM\IMGIFA~1.DLL]  [, 1, 0, 0, 1]
[PID: 1920][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\PYJJ4.IME]  [加加工作组, 4, 1, 0, 48]
[PID: 2036][C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe]  [N/A, N/A]
[PID: 276][C:\Program Files\Kaspersky Lab\NetworkAgent\klnagent.exe]  [Kaspersky Lab, 6.0.1405.0]
    [C:\Program Files\Kaspersky Lab\NetworkAgent\klcsrt.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
    [C:\Program Files\Kaspersky Lab\NetworkAgent\klcsagt.dll]  [Kaspersky Lab, 6.0.1405.0]
    [C:\Program Files\Kaspersky Lab\NetworkAgent\klcsstd.dll]  [Kaspersky Lab, 6.0.1405.0]
    [C:\Program Files\Kaspersky Lab\NetworkAgent\FSSync.dll]  [Kaspersky Lab, 6.0.1405.0]
    [C:\Program Files\Kaspersky Lab\NetworkAgent\LIBEAY32.dll]  [OpenSSL, 9, 7, 0, 1]
    [C:\Program Files\Kaspersky Lab\NetworkAgent\klcstr.dll]  [Kaspersky Lab, 6.0.1405.0]
    [C:\Program Files\Kaspersky Lab\NetworkAgent\SSLEAY32.dll]  [OpenSSL, 9, 7, 0, 1]
    [C:\Program Files\Kaspersky Lab\NetworkAgent\klcskca.dll]  [Kaspersky Lab, 6.0.1405.0]
    [C:\Program Files\Kaspersky Lab\NetworkAgent\klcsnagt.dll]  [Kaspersky Lab, 6.0.1405.0]
    [C:\Program Files\Kaspersky Lab\NetworkAgent\cleanapi.dll]  [Kaspersky Lab, 1.0.24.0]
    [C:\Program Files\Kaspersky Lab\NetworkAgent\klsecur2.dll]  [Kaspersky Lab, 6.0.1405.0]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\adialhk.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\AVPCon.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\prremote.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\prloader.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\prkernel.ppl]  [Kaspersky Lab, 6.0.2.690]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0 for windows workstations\pxstub.ppl]  [Kaspersky Lab, 6.0.2.690]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0 for windows workstations\params.ppl]  [Kaspersky Lab, 6.0.2.690]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0 for windows workstations\winreg.ppl]  [Kaspersky Lab, 6.0.2.690]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0 for windows workstations\thpimpl.ppl]  [Kaspersky Lab, 6.0.2.690]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0 for windows workstations\report.ppl]  [Kaspersky Lab, 6.0.2.690]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0 for windows workstations\nfio.ppl]  [Kaspersky Lab, 6.0.2.690]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0 for windows workstations\fsdrvplg.ppl]  [Kaspersky Lab, 6.0.2.690]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0 for windows workstations\base64.ppl]  [Kaspersky Lab, 6.0.2.690]
[PID: 388][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2372][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
gototop
 

[PID: 3292][E:\Tencent\qq\QQ.exe]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\QQBaseClassInDll.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\QQHelperDll.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\BasicCtrlDll.dll]  [TENCENT, 7, 1, 518, 1751]
    [C:\WINDOWS\system32\PYJJ4.IME]  [加加工作组, 4, 1, 0, 48]
    [E:\Tencent\qq\FreePlus.dll]  [Morning.Ye, 0, 2, 0, 8]
    [E:\Tencent\qq\QQAPI.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [E:\Tencent\qq\LoginCtrl.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\LoginCtrlRes.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\QQRes.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\QQMainFrame.dll]  [N/A, N/A]
    [E:\Tencent\qq\UnReadMsgMgr.dll]  [N/A, N/A]
    [E:\Tencent\qq\CQQApplication.dll]  [N/A, N/A]
    [E:\Tencent\qq\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [E:\Tencent\qq\NewSkin.dll]  [TENCENT, 7,0,431,1723]
    [E:\Tencent\qq\decode.dll]  [N/A, N/A]
    [E:\Tencent\qq\MailSummary.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\QQSpace.dll]  [TENCENT, 7,1,518,1751]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
    [E:\Tencent\qq\QQKnowledgeSearch.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\QQGroupMng.dll]  [TENCENT, 7,1,518,1751]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\adialhk.dll]  [Kaspersky Lab, 6.0.2.690]
    [E:\Tencent\qq\QQAllInOne.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\SCCore.dll]  [TENCENT, 1, 6, 0, 2]
    [E:\Tencent\qq\CameraDll.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\QQSettingCtrl.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\QQSysMsgMng.dll]  [N/A, N/A]
    [E:\Tencent\qq\LongConnection.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\QQPlugin.dll]  [N/A, N/A]
    [E:\Tencent\qq\UserDefinedHead.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\QQConfigPlugin.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\QQAvatar.dll]  [N/A, N/A]
    [E:\Tencent\qq\QQCustomFace.dll]  [N/A, N/A]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\scrchpg.dll]  [Kaspersky Lab, 6.0.2.690]
    [E:\Tencent\qq\QRingMng.dll]  [N/A, N/A]
    [E:\Tencent\qq\QQPet.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\BQQApplication.dll]  [N/A, N/A]
    [E:\Tencent\qq\PersonalDesktop.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\CommercesMng.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 310]
    [E:\Tencent\qq\QQSceneMng.dll]  [N/A, N/A]
    [E:\Tencent\qq\ImageOle.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\QQLiveQMng.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\QQMagicFace.dll]  [TENCENT, 7,1,518,1751]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\klscav.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\prremote.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\prloader.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\prkernel.ppl]  [Kaspersky Lab, 6.0.2.690]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0 for windows workstations\params.ppl]  [Kaspersky Lab, 6.0.2.690]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0 for windows workstations\pxstub.ppl]  [Kaspersky Lab, 6.0.2.690]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0 for windows workstations\tempfile.ppl]  [Kaspersky Lab, 6.0.2.690]
    [E:\Tencent\qq\GroupConnection.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\QQFileTransfer.dll]  [TENCENT, 7,1,518,1751]
    [E:\Tencent\qq\OEMApplication.dll]  [TENCENT, 7,1,518,1751]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
    [C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll]  [Nokia, 6, 84, 83, 7]
    [C:\Program Files\Nokia\Nokia PC Suite 6\PCSCM.dll]  [Nokia, 6, 84, 100, 4]
    [C:\Program Files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_chi-sc.nlr]  [Nokia, 6, 84, 51, 0]
    [C:\Program Files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr]  [Nokia, 6, 84, 15, 1]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
[PID: 3344][E:\Tencent\qq\TIMPlatform.exe]  [TENCENT, 7,0,365,1701]
    [C:\360Safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
    [E:\Tencent\qq\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 3316][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\PYJJ4.IME]  [加加工作组, 4, 1, 0, 48]
[PID: 2980][C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE]  [Microsoft Corporation, 11.0.5612]
    [C:\WINDOWS\system32\PYJJ4.IME]  [加加工作组, 4, 1, 0, 48]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\offguard.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNMUI34.DLL]  [CANON INC., 1.50.2.6]
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNMDR34.DLL]  [CANON INC., 1.50.2.6]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\scrchpg.dll]  [Kaspersky Lab, 6.0.2.690]
[PID: 1048][C:\WINDOWS\regedit.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\PYJJ4.IME]  [加加工作组, 4, 1, 0, 48]
[PID: 3748][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\scrchpg.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\WINDOWS\system32\PYJJ4.IME]  [加加工作组, 4, 1, 0, 48]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\adialhk.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\klscav.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\prremote.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\prloader.dll]  [Kaspersky Lab, 6.0.2.690]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\prkernel.ppl]  [Kaspersky Lab, 6.0.2.690]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0 for windows workstations\params.ppl]  [Kaspersky Lab, 6.0.2.690]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0 for windows workstations\pxstub.ppl]  [Kaspersky Lab, 6.0.2.690]
    [c:\program files\kaspersky lab\kaspersky anti-virus 6.0 for windows workstations\tempfile.ppl]  [Kaspersky Lab, 6.0.2.690]
[PID: 588][C:\Documents and Settings\Administrator\桌面\IT_sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [C:\WINDOWS\system32\PYJJ4.IME]  [加加工作组, 4, 1, 0, 48]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\adialhk.dll]  [Kaspersky Lab, 6.0.2.690]

==================================
文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
RVA  错误: LoadLibraryA
RVA  错误: LoadLibraryExA
RVA  错误: LoadLibraryExW
RVA  错误: LoadLibraryW

==================================


[/CODE]
gototop
 

请问API HOOK
警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
RVA 错误: LoadLibraryA
RVA 错误: LoadLibraryExA
RVA 错误: LoadLibraryExW
RVA 错误: LoadLibraryW

这个如果处理?
还有我只看出驱动[5166843 / 5166843][Running/Manual Start]
这个有问题。

[C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]这个是不是也有问题?
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT