热点科技

标题: [求助] 我这是不是中马了? 请大家帮我看看 [打印本页]

作者: wuyouwulv    时间: 2007-4-20 11:25
标题: [求助] 我这是不是中马了? 请大家帮我看看
我这是不是中马了? 请大家帮我看看
<AppInit_DLLs><D:\Personal\Temp\Rar$EX00.547\IceShield\ISSYSPROTECT.DLL>  [N/A]
清楚不掉,不知是什么东西,请大家帮我看看,如何解决?

============================================================
  1. 2007-04-20,11:09:03
  2. System Repair Engineer 2.4.12.806
  3. Smallfrogs (http://www.KZTechs.com)
  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件
  13. 启动项目
  14. 注册表
  15. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  16.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  17. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  18.     <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
  19.     <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
  20.     <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
  21.     <IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
  22.     <IMEKRMIG6.1><; C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE>  [(Verified)Microsoft Windows Publisher]
  23.     <MSPY2002><; C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC>  [(Verified)Microsoft Windows Publisher]
  24.     <nod32kui><; "d:\Program Files\Eset\nod32kui.exe" /WAITSERVICE>  [Eset ]
  25.     <runeip><; D:\Program Files\Rising\AntiSpyware\runiep.exe>  [Beijing Rising Technology Co., Ltd.]
  26.     <avgnt><"D:\Program Files\AntiVir PersonalEdition Premium\avgnt.exe" /min>  [Avira GmbH]
  27.     <CAPON><C:\WINDOWS\system32\Spool\Drivers\w32x86\3\CAPONN.EXE>  [CANON INC.]
  28. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  29.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  30.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  31. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  32.     <AppInit_DLLs><D:\Personal\Temp\Rar$EX00.547\IceShield\ISSYSPROTECT.DLL>  [N/A]
  33. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  34.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
  35. ==================================
  36. 启动文件夹
  37. [Canon LBP-810 状态窗口]
  38.   <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Canon LBP-810 状态窗口.LNK --> C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE [CANON INC.]><N>
  39. ==================================
  40. 服务
  41. [AntiVir PersonalEdition Premium MailGuard / AntiVirMailService][Stopped/Disabled]
  42.   <D:\Program Files\AntiVir PersonalEdition Premium\avmailc.exe><Avira GmbH>
  43. [AntiVir PersonalEdition Premium Guard / AntiVirService][Running/Auto Start]
  44.   <D:\Program Files\AntiVir PersonalEdition Premium\avguard.exe><Avira GmbH>
  45. [ASP.NET State Service / aspnet_state][Stopped/Manual Start]
  46.   <C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe><N/A>
  47. [Autodesk Licensing Service / Autodesk Licensing Service][Stopped/Manual Start]
  48.   <"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><Autodesk>
  49. [AntiVir PersonalEdition Premium MailGuard helper service / AVEService][Stopped/Disabled]
  50.   <D:\Program Files\AntiVir PersonalEdition Premium\avesvc.exe><Avira GmbH>
  51. [Human Interface Device Access / HidServ][Stopped/Disabled]
  52.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  53. [McAfee Framework Service / McAfeeFramework][Stopped/Auto Start]
  54.   <><N/A>
  55. [MSSQLSERVER / MSSQLSERVER][Stopped/Manual Start]
  56.   <d:\PROGRA~1\MICROS~3\MSSQL\binn\sqlservr.exe><Microsoft Corporation>
  57. [MSSQLServerADHelper / MSSQLServerADHelper][Stopped/Manual Start]
  58.   <C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe><Microsoft Corporation>
  59. [MSSQLServerOLAPService / MSSQLServerOLAPService][Running/Auto Start]
  60.   <d:\Program Files\Microsoft Analysis Services\Bin\msmdsrv.exe><Microsoft Corporation>
  61. [NOD32 Kernel Service / NOD32krn][Stopped/Manual Start]
  62.   <"d:\Program Files\Eset\nod32krn.exe"><Eset>
  63. [SQLSERVERAGENT / SQLSERVERAGENT][Stopped/Manual Start]
  64.   <d:\PROGRA~1\MICROS~3\MSSQL\binn\sqlagent.exe><Microsoft Corporation>
  65. ==================================
  66. 驱动程序
  67. [AMON / AMON][Running/Auto Start]
  68.   <\??\C:\WINDOWS\system32\drivers\amon.sys><Eset>
  69. [avgio / avgio][Running/System Start]
  70.   <\??\D:\Program Files\AntiVir PersonalEdition Premium\avgio.sys><Avira GmbH>
  71. [avgntflt / avgntflt][Running/Manual Start]
  72.   <\??\D:\Program Files\AntiVir PersonalEdition Premium\avgntflt.sys><Avira GmbH>
  73. [KRegEx / KRegEx][Stopped/System Start]
  74.   <\??\C:\PROGRA~1\KV2006\KRegEx.sys><N/A>
  75. [KvMemon / KvMemon][Stopped/Manual Start]
  76.   <\??\C:\PROGRA~1\KV2006\KvMemon.sys><N/A>
  77. [MINICD / MINICD][Running/Auto Start]
  78.   <system32\DRIVERS\minicd.sys><http://www.138soft.com>
  79. [npkcrypt / npkcrypt][Running/Auto Start]
  80.   <\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
  81. [PNP14918 / PNP14918][Running/Boot Start]
  82.   <\SystemRoot\system32\Drivers\pnp14716.sys><Anti Driver>
  83. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  84.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  85. [RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  86.   <\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
  87. [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
  88.   <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
  89. [sptd / sptd][Running/Boot Start]
  90.   <\SystemRoot\System32\Drivers\sptd.sys><N/A>
  91. [ssmdrv / ssmdrv][Stopped/Manual Start]
  92.   <system32\DRIVERS\ssmdrv.sys><Avira GmbH>
  93. [trid3d / trid3d][Running/Manual Start]
  94.   <system32\DRIVERS\trid3dm.sys><Trident Microsystems Inc.>
  95. [VIA AGP Filter / viaagp1][Running/Boot Start]
  96.   <\SystemRoot\system32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
  97. [ViaIde / ViaIde][Running/Boot Start]
  98.   <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
  99. [VIA AC'97 Audio Controller (WDM) / VIAudio][Running/Manual Start]
  100.   <system32\drivers\ac97via.sys><VIA Technologies, Inc.>
  101. ==================================
  102. 浏览器加载项
  103. [FGCatchUrl]
  104.   {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <D:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
  105. [QQ]
  106.   {c95fe080-8f5d-11d2-a20b-00aa003c157b}? <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
  107. [Windows Genuine Advantage Validation Tool]
  108.   {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>
  109. [Windows Media Player]
  110.   {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
  111. [Windows Media Player]
  112.   {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  113. [Microsoft Web 浏览器]
  114.   {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
  115. [Thunder Browser Helper]
  116.   {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
  117. [AUDIO__MP3 Moniker Class]
  118.   {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  119. [VIDEO__X_MS_WMV Moniker Class]
  120.   {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  121. [PasswordEditCtrl Class]
  122.   {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <d:\Program Files\Tencent\QQ\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
  123. [&使用快车(FlashGet)下载]
  124.   <D:\Program Files\FlashGet\jc_link.htm, N/A>
  125. [&使用快车(FlashGet)下载全部链接]
  126.   <D:\Program Files\FlashGet\jc_all.htm, N/A>
  127. [导出到 Microsoft Office Excel(&X)]
  128.   <res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
  129. [添加到QQ自定义面板]
  130.   <D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
  131. ==================================
  132. 正在运行的进程
  133. [PID: 348][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  134. [PID: 436][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  135.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  136. [PID: 480][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  137. [PID: 492][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  138.     [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 51, 26 ]
  139. [PID: 640][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  140. [PID: 1144][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  141.     [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 17.0.54.0]
  142.     [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  [Autodesk, 17.0.54.110]
  143.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  144. [PID: 1408][D:\Program Files\AntiVir PersonalEdition Premium\avgnt.exe]  [Avira GmbH, 7.00.04.05]
  145.     [D:\Program Files\AntiVir PersonalEdition Premium\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
  146.     [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 51, 26 ]
  147. [PID: 1720][C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE]  [CANON INC., 1.00.1.012]
  148.     [C:\WINDOWS\system32\imon.dll]  [Eset , 2, 51, 26 ]
  149. ==================================
  150. 文件关联
  151. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  152. .EXE  OK. ["%1" %*]
  153. .COM  OK. ["%1" %*]
  154. .PIF  OK. ["%1" %*]
  155. .REG  OK. [regedit.exe "%1"]
  156. .BAT  OK. ["%1" %*]
  157. .SCR  OK. ["%1" /S]
  158. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  159. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  160. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  161. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  162. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  163. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  164. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]
  165. ==================================
  166. Winsock 提供者
  167. NOD32 protected [MSAFD Tcpip [TCP/IP]]
  168.     C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  169. NOD32 protected [MSAFD Tcpip [RAW/IP]]
  170.     C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  171. NOD32 protected [RSVP TCP Service Provider]
  172.     C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  173. NOD32
  174.     C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
  175. ==================================
  176. Autorun.inf
  177. N/A
  178. ==================================
  179. HOSTS 文件
  180. 127.0.0.1       localhost
  181. ==================================
  182. API HOOK
  183. N/A
  184. ==================================
  185. 隐藏进程
  186. N/A
  187. ==================================
复制代码





欢迎光临 热点科技 (http://www.itheat.com/activity/) Powered by Discuz! X3.2