.Nfu947
下面是扫描日志:
2006-12-27,09:20:20
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\Windows\System32\ctfmon.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<kav><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"> [Kaspersky Lab]
<!ewido><"C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized> [Anti-Malware Development a.s.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\Windows\System32\userinit.exe,> [Microsoft Corporation]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<NetWork><> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<rfw><; ; C:\Program Files\rising\Rfw\Rfw.exe> []
<RfwMain><; ; C:\Program Files\rising\Rfw\rfwmain.exe> []
==================================
启动文件夹
服务
[Altiris Client Service / AClient]
<C:\COMPAQ\ACLIENT\ACLIENT.exe -service><Windows (R) 2000 DDK provider>
[卡巴斯基反病毒6.0 / AVP]
<C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe -r><Kaspersky Lab>
[Compaq Local Alerter / CPQALERT]
<C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe><Compaq Computer Corporation> ~
[Compaq Remote Diagnostics Enabling Agent / CpqDfwWebAgent]
<C:\Windows\Cpqdiag\Cpqdfwag.exe><Compaq Computer Corporation>
[cpqdmi / cpqdmi]
<C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe><Compaq Computer Corporation>
[Compaq DMI Web Agent / cpqWebDmi]
<><N/A>
[ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard]
<C:\Program Files\ewido anti-spyware 4.0\guard.exe><Anti-Malware Development a.s.>
[IMAPI CD-Burning COM Service / ImapiService]
<C:\WINDOWS\System32\imapi.exe><Microsoft Corporation>
[Local Connection Manager / MOVEESS]
<C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE C:\WINDOWS\SYSTEM32\WBEM\KIPHSU54.DLL,Export 1087><N/A>
[Intel(R) NMS / NMSSvc]
<C:\Windows\System32\NMSSvc.exe><Intel Corporation>
[NVIDIA Driver Helper Service / NVSvc]
<C:\Windows\System32\nvsvc32.exe><NVIDIA Corporation>
[WIN32SL / WIN32SL]
<C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe><Intel>
==================================
浏览器加载项
[symndis]
{166DF856-08F0-4D1C-991D-7CE3DB5C26F5} <C:\Windows\System32\rasacd.dll, N/A>
[SrchHook Class]
{6E1BC898-505A-44f4-BC88-BCE43016AC96} <C:\Windows\System32\SeaBar.dll, N/A>
[UMU Class]
{86450826-9507-44DC-9009-F92D2F5864EE} <C:\Windows\System32\sysag.dll, N/A>
[]
{869c45ee-82c4-40a6-ae2b-1b294ae19f4f} <C:\Windows\System32\40a6ntos.dll, N/A>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <, N/A>
[实用搜索工具条2.0]
{03465FF5-00AE-411a-9C34-960ED566EC03} <, N/A>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\Windows\system32\msdxm.ocx, Microsoft Corporation>
[&Google Search]
<res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html, N/A>
[上传到QQ网络硬盘] ,
<C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 620][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 672][\?\C:\Windows\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 696][\?\C:\Windows\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.149 (xpclnt_qfe.021108-2107)>
[C:\Windows\system32\SYNCOR11.DLL] <SoundMAX><1.2.2>
[PID: 740][C:\Windows\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 752][C:\Windows\system32\lsass.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\Windows\system32\SYNCOR11.DLL] <SoundMAX><1.2.2>
[PID: 940][C:\Windows\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\Windows\system32\SYNCOR11.DLL] <SoundMAX><1.2.2>
[PID: 1040][C:\Windows\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\Windows\System32\SYNCOR11.DLL] <SoundMAX><1.2.2>
[c:\windows\system32\winsafe.dll] <N/A><N/A>
[PID: 1164][C:\Windows\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\Windows\System32\SYNCOR11.DLL] <SoundMAX><1.2.2>
[PID: 1176][C:\Windows\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\Windows\System32\SYNCOR11.DLL] <SoundMAX><1.2.2>
[PID: 1272][C:\Windows\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.0 (XPClient.010817-1148)> 本文来自(www.dngz.net)
[C:\Windows\system32\SYNCOR11.DLL] <SoundMAX><1.2.2>
[C:\Windows\system32\ZLMhp1.DLL] <Zenographics><5, 51, 1203, 0>
[C:\Windows\system32\ZLM.dll] <Zenographics, Inc.><5, 50, 1416, 0>
[C:\Windows\system32\ZPJL.dll] <Zenographics, Inc.><1, 0, 1410, 1>
[C:\Windows\system32\ZSPOOL.dll] <Zenographics, Inc.><5, 51, 709, 0>
[C:\Windows\System32\spool\PRTPROCS\W32X86\IMFPrint.DLL] <Zenographics, Inc.><5, 50, 1606, 0>
[C:\Windows\system32\Imf32.dll] <Zenographics, Inc.><5, 51, 405, 0>
[C:\Windows\system32\ZTAG32.dll] <Zenographics, Inc.><5, 50, 1725, 0>
[C:\Windows\System32\spool\PRTPROCS\W32X86\vprproc.dll] <Windows (R) 2000 DDK provider><5.00.2195.1620>
[C:\Windows\System32\spool\PRTPROCS\W32X86\ZPPPCL.DLL] <Zenographics, Inc.><5, 51, 710, 0>
[C:\Windows\system32\ZPP.dll] <Zenographics, Inc.><5, 51, 709, 0>
[C:\Windows\system32\ZGDI32.dll] <Zenographics, Inc.><5, 51, 628, 0>
[PID: 1532][C:\Windows\Explorer.EXE] <Microsoft Corporation><6.00.2600.0000 (xpclient.010817-1148)>
[C:\Windows\System32\SYNCOR11.DLL] <SoundMAX><1.2.2>
[C:\Program Files\Tencent\QQ\qdshm.dll] <><1, 0, 101, 20>
[C:\PROGRA~1\WinZip\WZSHLSTB.DLL] <WinZip Computing, Inc.><3.0 (32-bit)>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\shellex.dll] <Kaspersky Lab><6.0.0.299>
[C:\Program Files\ewido anti-spyware 4.0\context.dll] <Anti-Malware Development a.s.><4, 0, 0, 172>
[PID: 1976][C:\Program Files\ewido anti-spyware 4.0\ewido.exe] <Anti-Malware Development a.s.><4, 0, 0, 201>
[C:\Program Files\ewido anti-spyware 4.0\engine.dll] <Anti-Malware Development a.s.><4, 0, 0, 172>
[C:\Windows\System32\SYNCOR11.DLL] <SoundMAX><1.2.2> 本文来自(www.dngz.net)
[PID: 2008][C:\Windows\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 436][C:\Windows\System32\taskmgr.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\Windows\System32\SYNCOR11.DLL] <SoundMAX><1.2.2>
[PID: 444][C:\Windows\System32\alg.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 484][C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe] <Compaq Computer Corporation><5.0.3.4>
[C:\Program Files\Compaq\Compaq Management Agents\CPQHCI.DLL] <Compaq Computer Corporation><5.0.3.4>
[C:\Program Files\Compaq\Compaq Management Agents\CPQDMSC.DLL] <Compaq Computer Corporation><5.0.3.4>
[PID: 528][C:\Windows\Cpqdiag\Cpqdfwag.exe] <Compaq Computer Corporation><2.14.2001>
[C:\Windows\Cpqdiag\CPQHMMO.DLL] <Compaq Computer Corp.><2.5.0>
[PID: 640][C:\Windows\System32\NMSSvc.exe] <Intel Corporation><2.1.9.0>
[PID: 1032][C:\Windows\System32\nvsvc32.exe] <NVIDIA Corporation><6.13.10.3100>
[PID: 1136][C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe] <Intel><2, 0, 0, 54>
[C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\WSDMIDCE.DLL] <Intel><2, 0, 0, 54>
[C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\WDMIUTIL.dll] <Intel><2, 0, 0, 54>
[C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\WDMI2API.dll] <Intel><2, 0, 0, 54>
[C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\DMIAPI32.DLL] <><2, 0, 0, 54>
[PID: 1748][C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe] <Compaq Computer Corporation><5.0.3.4>
[C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\Bin\DMIAPI32.dll] <><2, 0, 0, 54>
[C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\Bin\WCDMI.dll] <Intel><2, 0, 0, 54> (www.dngz.net)
[C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\Bin\WDMIUTIL.dll] <Intel><2, 0, 0, 54>
[C:\PROGRA~1\Compaq\COMPAQ~1\CPQHCI.DLL] <Compaq Computer Corporation><5.0.3.4>
[C:\PROGRA~1\Compaq\COMPAQ~1\CPQDMSC.DLL] <Compaq Computer Corporation><5.0.3.4>
[C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\Bin\WDMI2API.DLL] <Intel><2, 0, 0, 54>
[C:\PROGRA~1\Compaq\COMPAQ~1\CPQCI.DLL] <Compaq Computer Corporation><5.0.3.4>
[C:\PROGRA~1\Compaq\COMPAQ~1\CPQVID.DLL] <Compaq Computer Corporation><5.0.3.4>
[PID: 3484][C:\Program Files\港湾网络\宽带接入客户端\HammerSupplicant.exe] <HarbourNetworks><1, 0, 0, 1>
[C:\Windows\System32\W32N50.dll] <Printing Communications Assoc., Inc. (PCAUSA)><5.00.13.50>
[C:\Windows\System32\SYNCOR11.DLL] <SoundMAX><1.2.2>
[PID: 3080][C:\Windows\System32\conime.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 3676][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2600.0000 (xpclient.010817-1148)>
[C:\Windows\System32\SYNCOR11.DLL] <SoundMAX><1.2.2>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scr_ch_pg.dll] <Kaspersky Lab><1.0.6.299>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\klscav.dll] <Kaspersky Lab><6.0.0.299>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\pr_remote.dll] <Kaspersky Lab><6.0.0.299>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prloader.dll] <Kaspersky Lab><6.0.0.299>
[C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\prkernel.ppl] <Kaspersky Lab><6.0.0.304>
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\params.ppl] <Kaspersky Lab><6.0.0.299>
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\pxstub.ppl] <Kaspersky Lab><6.0.0.299> dngz.net
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\tempfile.ppl] <Kaspersky Lab><6.0.0.299>
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\nfio.ppl] <Kaspersky Lab><6.0.0.299>
[c:\program files\kaspersky lab\kaspersky anti-virus 6.0\fsdrvplgn.ppl] <Kaspersky Lab><6.0.0.299>
[PID: 3072][C:\WINDOWS\regedit.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1336][D:\信息安全\系统诊断配置工具\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\Windows\System32\SYNCOR11.DLL] <SoundMAX><1.2.2>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. [C:\Windows\hh.exe %1]
.HLP Error. [C:\Windows\winhlp32.exe %1]
.INI Error. [C:\Windows\NOTEPAD.EXE %1]
.INF Error. [C:\Windows\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
浏览器加载项
[symndis]
{166DF856-08F0-4D1C-991D-7CE3DB5C26F5} <C:\Windows\System32\rasacd.dll, N/A>
[SrchHook Class]
{6E1BC898-505A-44f4-BC88-BCE43016AC96} <C:\Windows\System32\SeaBar.dll, N/A>
[UMU Class]
{86450826-9507-44DC-9009-F92D2F5864EE} <C:\Windows\System32\sysag.dll, N/A>
[]
{869c45ee-82c4-40a6-ae2b-1b294ae19f4f} <C:\Windows\System32\40a6ntos.dll, N/A>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <, N/A>
[实用搜索工具条2.0]
{03465FF5-00AE-411a-9C34-960ED566EC03} <, N/A> ;
同时启动项中间,瑞星和kb不要同时存在
文件关联///用sreng修复
.CHM Error. [C:\Windows\hh.exe %1]
.HLP Error. [C:\Windows\winhlp32.exe %1]
.INI Error. [C:\Windows\NOTEPAD.EXE %1]
.INF Error. [C:\Windows\NOTEPAD.EXE %1]
最后建议说明kb不能查杀的病毒名称,文件位置,提示消息等。