|
帮忙看看:SREng、hijackthis、360safe分析文件
感觉进程怪怪的,连任务管理器也是大写的。(MP**** 这几个文件不必怀疑,是正常的,微点的。)- 2007-03-29,15:09:56
- System Repair Engineer 2.4.12.806
- Smallfrogs (http://www.KZTechs.com)
- Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
- 以下内容被选中:
- 所有的启动项目(包括注册表、启动文件夹、服务等)
- 浏览器加载项
- 正在运行的进程(包括进程模块信息)
- 文件关联
- Winsock 提供者
- Autorun.inf
- HOSTS 文件
- 启动项目
- 注册表
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- <ctfmon.exe><; C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
- <IgfxTray><C:\WINDOWS\system32\igfxtray.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
- <HotKeysCmds><C:\WINDOWS\system32\hkcmd.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
- <Cmaudio><; RunDll32 cmicnfg.cpl,CMICtrlWnd> [N/A]
- <IMJPMIG8.1><; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
- <PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher]
- <PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
- <Userinit><C:\WINDOWS\SYSTEM32\USERINIT.EXE,> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <AppInit_DLLs><> [N/A]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
- ==================================
- 启动文件夹
- N/A
- ==================================
- 服务
- [Human Interface Device Access / HidServ][Stopped/Disabled]
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
- [MPSVC Service / MPSVCService][Running/Auto Start]
- <d:\Program Files\Micropoint\MPSVC.exe><Micropoint Corporation>
- [MSSQLSERVER / MSSQLSERVER][Running/Auto Start]
- <C:\PROGRA~1\MICROS~2\MSSQL\binn\sqlservr.exe><Microsoft Corporation>
- [MSSQLServerADHelper / MSSQLServerADHelper][Stopped/Manual Start]
- <C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe><Microsoft Corporation>
- [SQLSERVERAGENT / SQLSERVERAGENT][Stopped/Manual Start]
- <C:\PROGRA~1\MICROS~2\MSSQL\binn\sqlagent.exe><Microsoft Corporation>
- ==================================
- 驱动程序
- [AVG Anti-Spyware Clean Driver / AvgAsCln][Stopped/System Start]
- <System32\DRIVERS\AvgAsCln.sys><N/A>
- [C-Media WDM Audio Interface / cmuda][Running/Manual Start]
- <system32\drivers\cmuda.sys><C-Media Inc>
- [ialm / ialm][Running/Manual Start]
- <system32\DRIVERS\ialmnt5.sys><Intel Corporation>
- [IdeBusDr / IdeBusDr][Running/Boot Start]
- <\SystemRoot\system32\DRIVERS\IdeBusDr.sys><Intel Corporation>
- [Intel(R) Ultra ATA Controller / IdeChnDr][Running/Boot Start]
- <\SystemRoot\system32\DRIVERS\IdeChnDr.sys><Intel Corporation>
- [mp110001 / mp110001][Running/Auto Start]
- <system32\drivers\mp110001.sys><MicroPoint Corporation>
- [mp110002 / mp110002][Running/Auto Start]
- <system32\drivers\mp110002.sys><Micropoint Corporation>
- [mp110003 / mp110003][Running/Boot Start]
- <\SystemRoot\system32\drivers\mp110003.sys><Micropoint Corporation>
- [mp110004 / mp110004][Running/Auto Start]
- <system32\drivers\mp110004.sys><Micropoint Corporation>
- [mp110005 / mp110005][Running/Manual Start]
- <system32\drivers\mp110005.sys><Micropoint Corporation>
- [mp110006 / mp110006][Running/System Start]
- <system32\drivers\mp110006.sys><Micropoint Corporation>
- [mp110007 / mp110007][Running/System Start]
- <system32\drivers\mp110007.sys><Micropoint Corporation>
- [mp110008 / mp110008][Running/Auto Start]
- <system32\drivers\mp110008.sys><Micropoint Corporation>
- [mp110009 / mp110009][Running/System Start]
- <system32\drivers\mp110009.sys><Micropoint Corporation>
- [mp110010 / mp110010][Running/Boot Start]
- <\SystemRoot\system32\drivers\mp110010.sys><Micropoint Corporation>
- [mp110011 / mp110011][Running/System Start]
- <system32\drivers\mp110011.sys><Micropoint Corporation>
- [mp110012 / mp110012][Stopped/Manual Start]
- <system32\drivers\mp110012.sys><Micropoint Corporation>
- [mp110013 / mp110013][Running/Boot Start]
- <\SystemRoot\system32\drivers\mp110013.sys><Micropoint Corporation>
- [npkcrypt / npkcrypt][Running/Auto Start]
- <\??\D:\Program Files\Tencent3\npkcrypt.sys><INCA Internet Co., Ltd.>
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
- <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
- [Realtek RTL8139/810x/8169/8110 all in one NDIS NT Driver / RTL8023][Running/Manual Start]
- <system32\DRIVERS\Rtlnic51.sys><Realtek Semiconductor Corporation>
- [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
- <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
- [Secdrv / Secdrv][Stopped/Manual Start]
- <system32\DRIVERS\secdrv.sys><N/A>
- ==================================
- 浏览器加载项
- [CLDown Object]
- {0BECAB3A-E1F8-45E6-8332-38DD750EBA01} <C:\Program Files\Tuotu\TuoTuHelper_v8.dll, Tuotu.com>
- [Thunder Browser Helper]
- {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Downloads\上传下载\Thunder.v5.5.1.241.NoAD-Ayu\Thunder\ComDlls\XunLeiBHO_004.dll, Thunder Networking Technologies,LTD>
- [浩方对战平台]
- {0A155D3C-68E2-4215-A47A-E800A446447A} <C:\Program Files\浩方对战平台\GameClient.exe, 上海浩方在线信息技术有限公司>
- [Messenger]
- {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
- [Easy-WebPrint]
- {327C2873-E90D-4c37-AA9D-10AC9BABA46C} <C:\Program Files\Canon\Easy-WebPrint\Toolband.dll, >
- [CLDown Object]
- {0BECAB3A-E1F8-45E6-8332-38DD750EBA01} <C:\Program Files\Tuotu\TuoTuHelper_v8.dll, Tuotu.com>
- [HTML Document]
- {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\Mshtml.dll, N/A>
- [Easy-WebPrint]
- {327C2873-E90D-4C37-AA9D-10AC9BABA46C} <C:\Program Files\Canon\Easy-WebPrint\Toolband.dll, >
- [Windows Media Player]
- {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
- [Active Desktop Mover]
- {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
- [Microsoft Web 浏览器]
- {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
- [Thunder Browser Helper]
- {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\Downloads\上传下载\Thunder.v5.5.1.241.NoAD-Ayu\Thunder\ComDlls\XunLeiBHO_004.dll, Thunder Networking Technologies,LTD>
- [Microsoft Scriptlet Component]
- {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\Mshtml.dll, Microsoft Corporation>
- [SearchAssistantOC]
- {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
- [RDS.DataSpace]
- {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
- [Shockwave Flash Object]
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\flash.ocx, Macromedia, Inc.>
- [Easy-WebPrint打印]
- <res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html, N/A>
- [Easy-WebPrint添加到打印列表]
- <res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html, N/A>
- [Easy-WebPrint预览]
- <res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html, N/A>
- [Easy-WebPrint高速打印]
- <res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html, N/A>
- [上传到QQ网络硬盘]
- <D:\Program Files\Tencent3\AddToNetDisk.htm, N/A>
- [使用脱兔下载]
- <C:\Program Files\Tuotu\TT_one.htm, N/A>
- [使用脱兔下载全部链接]
- <C:\Program Files\Tuotu\TT_all.htm, N/A>
- [使用迅雷下载]
- <D:\Downloads\上传下载\Thunder.v5.5.1.241.NoAD-Ayu\Thunder\Program\geturl.htm, N/A>
- [使用迅雷下载全部链接]
- <D:\Downloads\上传下载\Thunder.v5.5.1.241.NoAD-Ayu\Thunder\Program\getallurl.htm, N/A>
- [导出到 Microsoft Office Excel(&X)]
- <res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000, N/A>
- [添加到QQ自定义面板]
- <D:\Program Files\Tencent3\AddPanel.htm, N/A>
- [添加到QQ表情]
- <D:\Program Files\Tencent3\AddEmotion.htm, N/A>
- [用QQ彩信发送该图片]
- <D:\Program Files\Tencent3\SendMMS.htm, N/A>
- ==================================
- 正在运行的进程
- [PID: 428][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 496][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 520][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [d:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10032]
- [C:\WINDOWS\system32\FREEWB.IME] [Delphi Fan Studio, 5.0]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 1368][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\FREEWB.IME] [Delphi Fan Studio, 5.0]
- [d:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10032]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [C:\Program Files\Tuotu\TuoTuHelper_v8.dll] [Tuotu.com, 2.0.0.6]
- [D:\Downloads\上传下载\Thunder.v5.5.1.241.NoAD-Ayu\Thunder\ComDlls\XunLeiBHO_004.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 3]
- [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
- [PID: 1248][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\FREEWB.IME] [Delphi Fan Studio, 5.0]
- [d:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10032]
- [PID: 1268][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3.0.0.4020]
- [C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4020]
- [d:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10032]
- [C:\WINDOWS\system32\igfxdev.dll] [Intel Corporation, 3.0.0.4020]
- [C:\WINDOWS\system32\FREEWB.IME] [Delphi Fan Studio, 5.0]
- [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4020]
- [C:\WINDOWS\system32\igfxhk.dll] [Intel Corporation, 3.0.0.4020]
- [C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4020]
- [PID: 1292][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\FREEWB.IME] [Delphi Fan Studio, 5.0]
- [PID: 2364][C:\WINDOWS\system32\taskmgr.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\FREEWB.IME] [Delphi Fan Studio, 5.0]
- [d:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10032]
- [PID: 2976][D:\Downloads\系统优化清理\sreng2\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
- [C:\WINDOWS\system32\FREEWB.IME] [Delphi Fan Studio, 5.0]
- [d:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.2.10032]
- ==================================
- 文件关联
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .EXE OK. ["%1" %*]
- .COM OK. ["%1" %*]
- .PIF OK. ["%1" %*]
- .REG OK. [regedit.exe "%1"]
- .BAT OK. ["%1" %*]
- .SCR OK. ["%1" /S]
- .CHM OK. ["C:\WINDOWS\hh.exe" %1]
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
- .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
- .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
- ==================================
- Winsock 提供者
- N/A
- ==================================
- Autorun.inf
- N/A
- ==================================
- HOSTS 文件
- 127.0.0.1 localhost
- ==================================
- API HOOK
- N/A
- ==================================
- 隐藏进程
- [769] d:\Program Files\Micropoint\MPSVC.exe
- [797] d:\Program Files\Micropoint\MPSVC2.exe
- [941] d:\Program Files\Micropoint\MPSVC1.exe
- [1417] d:\Program Files\Micropoint\MPMon.exe
- ==================================
复制代码- HijackThis_zww汉化版扫描日志 V1.99.1
- 保存于 15:10:27, 日期 2007-03-29
- 操作系统: Windows XP SP2 (WinNT 5.01.2600)
- 浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
- 当前运行的进程:
- C:\WINDOWS\System32\smss.exe
- C:\WINDOWS\system32\winlogon.exe
- C:\WINDOWS\system32\services.exe
- C:\WINDOWS\system32\lsass.exe
- C:\WINDOWS\system32\svchost.exe
- C:\WINDOWS\System32\svchost.exe
- C:\WINDOWS\Explorer.EXE
- C:\WINDOWS\system32\spoolsv.exe
- C:\PROGRA~1\MICROS~2\MSSQL\binn\sqlservr.exe
- C:\WINDOWS\system32\wscntfy.exe
- C:\WINDOWS\system32\hkcmd.exe
- C:\WINDOWS\system32\ctfmon.exe
- C:\WINDOWS\system32\taskmgr.exe
- D:\Downloads\系统优化清理\HijackThis\HijackThis1991zww~.exe
- O2 - BHO: TuoTuHelper.LDown - {0BECAB3A-E1F8-45E6-8332-38DD750EBA01} - C:\Program Files\Tuotu\TuoTuHelper_v8.dll
- O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\Downloads\上传下载\Thunder.v5.5.1.241.NoAD-Ayu\Thunder\ComDlls\XunLeiBHO_004.dll
- O3 - IE工具栏增项: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
- O4 - 启动项HKLM\\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
- O4 - 启动项HKLM\\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
- O4 - 启动项HKLM\\Run: [Cmaudio] ; RunDll32 cmicnfg.cpl,CMICtrlWnd
- O4 - 启动项HKLM\\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
- O4 - 启动项HKLM\\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
- O4 - 启动项HKLM\\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
- O4 - HKCU\..\Run: [ctfmon.exe] ; C:\WINDOWS\system32\ctfmon.exe
- O8 - IE右键菜单中的新增项目: Easy-WebPrint打印 - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
- O8 - IE右键菜单中的新增项目: Easy-WebPrint添加到打印列表 - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
- O8 - IE右键菜单中的新增项目: Easy-WebPrint预览 - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
- O8 - IE右键菜单中的新增项目: Easy-WebPrint高速打印 - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
- O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - D:\Program Files\Tencent3\AddToNetDisk.htm
- O8 - IE右键菜单中的新增项目: 使用脱兔下载 - C:\Program Files\Tuotu\TT_one.htm
- O8 - IE右键菜单中的新增项目: 使用脱兔下载全部链接 - C:\Program Files\Tuotu\TT_all.htm
- O8 - IE右键菜单中的新增项目: 使用迅雷下载 - D:\Downloads\上传下载\Thunder.v5.5.1.241.NoAD-Ayu\Thunder\Program\geturl.htm
- O8 - IE右键菜单中的新增项目: 使用迅雷下载全部链接 - D:\Downloads\上传下载\Thunder.v5.5.1.241.NoAD-Ayu\Thunder\Program\getallurl.htm
- O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
- O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\Program Files\Tencent3\AddPanel.htm
- O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\Program Files\Tencent3\AddEmotion.htm
- O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\Program Files\Tencent3\SendMMS.htm
- O9 - 浏览器额外的按钮: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - C:\Program Files\浩方对战平台\GameClient.exe
- O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
- O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
- O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
- O23 - NT 服务: MPSVC Service (MPSVCService) - Micropoint Corporation - d:\Program Files\Micropoint\MPSVC.exe
复制代码 |
|