病毒吧 关注:315,358贴子:1,276,074
  • 5回复贴,共1

【日志】高手请进,谢谢合作

只看楼主收藏回复

[CODE]

2007-03-08,19:55:52

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
 - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <CalSprite><C:\Program Files\CalSprite\CalSprite.exe>  [SnowFox Studio.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <CalSprite><C:\Program Files\CalSprite\CalSprite.exe>  [SnowFox Studio.]
    <MSPY2002><C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC>  [(Verified)N/A]
    <KvMonXP><C:\KV2004\KVMonXP.kxp /auto>  [JiangMin Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{4BAB150F-DD97-476D-9C1E-41B6CDC0CA7A}><C:\PROGRA~1\Yahoo!\ASSIST~1\yclickon.dll>  [(Verified)YAHOO Corporation Limited]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\KV2004\KVSCRK~1.SCR>  [N/A]


1楼2007-03-08 20:06回复
    ==================================
    启动文件夹
    [腾讯QQ]
     <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><N>

    ==================================
    服务
    [GrayPigeonServer / GrayPigeonServer][Stopped/Auto Start]
     <C:\WINDOWS\G_Server2006.exe><N/A>
    [Google Updater Service / gusvc][Stopped/Manual Start]
     <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
    [Human Interface Device Access / HidServ][Stopped/Disabled]
     <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
    [KVSrvXP / KVSrvXP][Running/Auto Start]
     <C:\KV2004\KVSrvXP.exe -Service><JiangMin Ltd.>
    [KVWSC / KVWSC][Running/Auto Start]
     <"C:\KV2004\KVwsc.exe"><Jiangmin Co>

    ==================================
    驱动程序
    [ADProt / ADProt][Stopped/System Start]
     <\SystemRoot\system32\drivers\ADProt.sys><N/A>
    [aefjdhic / aefjdhic][Running/System Start]
     <\??\C:\WINDOWS\system32\drivers\aefjdhic.sys><中国互联网络信息中心(CNNIC)>
    [cdnprot / cdnprot][Stopped/Boot Start]
     <\SystemRoot\system32\drivers\cdnprot.sys><中国互联网络信息中心(CNNIC)>
    [C-Media WDM Audio Interface / cmuda][Running/Manual Start]
     <system32\drivers\cmuda.sys><C-Media Inc>
    [GMSIPCI / GMSIPCI][Stopped/Manual Start]
     <\??\G:\INSTALL\GMSIPCI.SYS><N/A>
    [gpghqii / gpghqii][Running/Boot Start]
     <\SystemRoot\system32\drivers\gpghqii.sys><>
    [KVDriver for NT (KVDP) / KVDP][Running/Manual Start]
     <\??\C:\KV2004\KVDP.sys><Beijing Jiangmin New Sci.&Tec. Co.Ltd.>
    [MSICPL / MSICPL][Stopped/Manual Start]
     <\??\G:\install4\MSICPL.sys><N/A>
    [NTACCESS / NTACCESS][Stopped/Manual Start]
     <\??\G:\NTACCESS.sys><N/A>
    [nv / nv][Running/Manual Start]
     <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
    [paqbrh / paqbrh][Running/Boot Start]
     <\SystemRoot\\SystemRoot\System32\drivers\paqbrh.sys><N/A>
    [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
     <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
    [PxHelp20 / PxHelp20][Running/Boot Start]
     <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
    [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
     <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
    [Secdrv / Secdrv][Stopped/Manual Start]
     <system32\DRIVERS\secdrv.sys><N/A>
    [SetupNTGLM7X / SetupNTGLM7X][Stopped/Manual Start]
     <\??\G:\NTGLM7X.sys><N/A>
    [SVKP / SVKP][Running/Auto Start]
     <\??\C:\WINDOWS\system32\SVKP.sys><AntiCracking>
    [TCP/IP Protocol Driver / Tcpip][Running/System Start]
     <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
    [yaskp / yaskp][Running/Boot Start]
     <\SystemRoot\system32\drivers\yaskp.sys><Copyright (C) yahoo Corporation.>
    [yjaokuer / yjaokuer][Running/Boot Start]
     <\SystemRoot\System32\DRIVERS\yjaokuer.sys><Yahoo! China Corporation>
    [npkycryp / npkycryp][Stopped/Manual Start]
     <\??\C:\Program Files\Tencent\QQ\npkycryp.sys><N/A>


    2楼2007-03-08 20:07
    回复
      2025-12-13 01:10:51
      广告
      不感兴趣
      开通SVIP免广告
      [雅虎助手]
       {5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/start.htm?source=yzs_icon&btn=yassistnew, N/A>
      [QQ]
       {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
      [快车]
       {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <d:\Program Files\FlashGet\FlashGet.exe, N/A>
      [江民杀毒工具栏]
       {B5A34A93-D538-43A7-8371-864CB6148D12} <C:\KV2004\KvShell.dll, JiangMin Lmt>
      [雅虎助手]
       {406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll, yahoo! china>
      [百度超级搜霸]
       {B580CF65-E151-49C3-B73F-70B13FCA8E86} <C:\Progra~1\Baidu\bar\BaiDuBar.dll, Baidu.com, Inc.>
      [快车(FlashGet)]
       {E0E899AB-F487-11D5-8D29-0050BA6940E3} <d:\Program Files\FlashGet\fgiebar.dll, Amaze Soft>
      [&Google]
       {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar3.dll, Google Inc.>
      [Dr.eye WebPage Translation]
       {92B255FE-94E2-4BCA-958D-3926CE38913F} <d:\Program Files\Inventec\Dreye\DreyeMT\DreyeIEBar.dll, >
      [WUWebControl Class]
       {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
      [Thunder Browser Helper]
       {00000000-12C8-4305-82F9-43058F20E8D2} <C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_006.dll, Thunder Networking Technologies,LTD>
      [QQCycloneHelper Class]
       {00000000-12C9-4305-82F9-43058F20E8D2} <C:\Program Files\Tencent\QQDownload\QQIEHelper01.dll, 腾讯公司>
      [Google Script Object]
       {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar3.dll, Google Inc.>
      [Web Browser Applet Control]
       {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\WINDOWS\system32\msjava.dll, Microsoft Corporation>
      [Tencent Browser Helper]
       {0C7C23EF-A848-485B-873C-0ED954731014} <C:\Program Files\TENCENT\Adplus\SSAddr.dll, Tencent>
      [Windows Media Player]
       {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
      [&Google]
       {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar3.dll, Google Inc.>
      [HTML Document]
       {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
      [DHTML Edit Control Safe for Scripting for IE5]
       {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
      [Flashget Catch Url Class]
       {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <D:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
      [Yahoo!Photo]
       {33BBE430-0E42-4F12-B075-8D21ACB10DCB} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll, Yahoo! China>
      [IETag Factory]
       {38481807-CA0E-42D2-BF39-B33AF135CC4D} <C:\PROGRA~1\COMMON~1\MICROS~1\SMARTT~1\IETAG.DLL, Microsoft Corporation>
      [AntiFish Class]
       {38928D50-8A48-44C2-945F-D2F23F771410} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll, yahoo! china>


      4楼2007-03-08 20:08
      回复
        还有下半部分,百度不让我发,呜~~T_T

        能传的时候我就传上去,如真有高手进来看了,请为我解决好吗?

        我能等的,在这里先谢


        6楼2007-03-08 20:15
        回复
          [江民杀毒工具栏]
           {B5A34A93-D538-43A7-8371-864CB6148D12} <C:\KV2004\KvShell.dll, JiangMin Lmt>
          [RealPlayer G2 Control]
           {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks>
          [Shockwave Flash Object]
           {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
          [快车(FlashGet)]
           {E0E899AB-F487-11D5-8D29-0050BA6940E3} <d:\Program Files\FlashGet\fgiebar.dll, Amaze Soft>
          [FlashGet GetFlash Class]
           {F156768E-81EF-470C-9057-481BA8380DBA} <d:\Program Files\FlashGet\getflash.dll, www.flashget.com>
          [JetCarNetscape Class]
           {FB5DA724-162B-11D3-8B9B-AA70B4B0B524} <D:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
          [assist]
           {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll, Yahoo! China>
          [&V使用Vagaa哇嘎下载]
           <D:\Vagaa\Data\vg.htm, N/A>
          [&使用快车(FlashGet)下载]
           <D:\Program Files\FlashGet\jc_link.htm, N/A>
          [&使用快车(FlashGet)下载全部链接]
           <D:\Program Files\FlashGet\jc_all.htm, N/A>
          [&使用超级旋风下载]
           <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>
          [&使用超级旋风下载全部链接]
           <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
          [&使用迅雷下载]
           <C:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
          [&使用迅雷下载全部链接]
           <C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
          [上传到QQ网络硬盘]
           <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
          [导出到 Microsoft Office Excel(&X)]
           <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
          [添加到QQ自定义面板]
           <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
          [添加到QQ表情]
           <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
          [添加到雅虎订阅(&Y)]
           <res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT, N/A>
          [用QQ彩信发送该图片]
           <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
          [百度-搜索MP3]
           <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUMP3.HTM, N/A>
          [百度-搜索图片]
           <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUIMG.HTM, N/A>
          [百度-搜索新闻]
           <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUNEWS.HTM, N/A>
          [百度-搜索歌词]
           <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDULYRIC.HTM, N/A>
          [百度-搜索网页]
           <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUSEARCH.HTM, N/A>
          [百度-搜索贴吧]
           <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUPOST.HTM, N/A>
          [百度-词典搜索]
           <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDU_DIC.HTM, N/A>
          [访问通用网址]
           <C:\Program Files\CNNIC\Cdn\cnnic.htm, N/A>
          [雅虎搜索]
           <res://C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll/203, N/A>


          7楼2007-03-08 21:20
          回复
            [江民杀毒工具栏]
             {B5A34A93-D538-43A7-8371-864CB6148D12} <C:\KV2004\KvShell.dll, JiangMin Lmt>
            [RealPlayer G2 Control]
             {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks>
            [Shockwave Flash Object]
             {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
            [快车(FlashGet)]
             {E0E899AB-F487-11D5-8D29-0050BA6940E3} <d:\Program Files\FlashGet\fgiebar.dll, Amaze Soft>
            [FlashGet GetFlash Class]
             {F156768E-81EF-470C-9057-481BA8380DBA} <d:\Program Files\FlashGet\getflash.dll, www.flashget.com>
            [JetCarNetscape Class]
             {FB5DA724-162B-11D3-8B9B-AA70B4B0B524} <D:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
            [assist]
             {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll, Yahoo! China>
            [&V使用Vagaa哇嘎下载]
             <D:\Vagaa\Data\vg.htm, N/A>
            [&使用快车(FlashGet)下载]
             <D:\Program Files\FlashGet\jc_link.htm, N/A>
            [&使用快车(FlashGet)下载全部链接]
             <D:\Program Files\FlashGet\jc_all.htm, N/A>
            [&使用超级旋风下载]
             <C:\Program Files\Tencent\QQDownload\geturl.htm, N/A>
            [&使用超级旋风下载全部链接]
             <C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A>
            [&使用迅雷下载]
             <C:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
            [&使用迅雷下载全部链接]
             <C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
            [上传到QQ网络硬盘]
             <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
            [导出到 Microsoft Office Excel(&X)]
             <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
            [添加到QQ自定义面板]
             <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
            [添加到QQ表情]
             <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
            [添加到雅虎订阅(&Y)]
             <res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT, N/A>
            [用QQ彩信发送该图片]
             <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
            [百度-搜索MP3]
             <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUMP3.HTM, N/A>
            [百度-搜索图片]
             <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUIMG.HTM, N/A>
            [百度-搜索新闻]
             <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUNEWS.HTM, N/A>
            [百度-搜索歌词]
             <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDULYRIC.HTM, N/A>
            [百度-搜索网页]
             <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUSEARCH.HTM, N/A>
            [百度-搜索贴吧]
             <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUPOST.HTM, N/A>
            [百度-词典搜索]
             <res://C:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDU_DIC.HTM, N/A>
            [访问通用网址]
             <C:\Program Files\CNNIC\Cdn\cnnic.htm, N/A>
            [雅虎搜索]
             <res://C:\PROGRA~1\Yahoo!\Assistant\Assist\yasbar.dll/203, N/A>


            8楼2007-03-08 21:43
            回复