cmd乱了,求求电脑高手qq帮助

查看: 874|回复: 6
求助高手,本人菜鸟
oneyearslater
本帖最后由 oneyearslater 于
19:08 编辑
最近出了个问题,开机桌面自动会生成一个空文件夹,删除了又生成了,一开始没注意,今天刚删除了,过了几个小时现在又生成了,真好今天网络奇卡无比,网络测试才40kb多下载速度,所有觉得有问题用sreng。wsyscheck,xuetr查了半天也没发现什么,或许是我太菜了吧。。然后用微点也没查出问题,file:///C:/DOCUME%7E1/MYLIFE%7E1/LOCALS%7E1/Temp/moz-screenshot.png附上
最近也没乱进什么网站,只是安装了nba live游戏和Photoshop cs2而已,这些文件都已经用微点+小红伞+nod32扫描过无问题,在安装过程中comodo也没发现什么异常
System Repair Engineer 2.8.2.1321
Smallfrogs ([url][/url])
Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
& & 所有的启动项目(包括注册表、启动文件夹、服务等)
& & 浏览器加载项
& & 正在运行的进程(包括进程模块信息)
& & 文件关联
& & Winsock 提供者
& & Autorun.inf
& & HOSTS 文件
& & 进程特权扫描
& & 计划任务
& & Windows 安全更新检查
& & API HOOK
& & 隐藏进程
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
& & &ctfmon.exe&&C:\WINDOWS\system32\ctfmon.exe&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
& & &load&&&&&[N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
& & &IMJPMIG8.1&&&C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE& /Spoil /RemAdvDef /Migration32&&&[(Verified)Microsoft Windows Component Publisher]
& & &PHIME2002ASync&&C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC&&&[(Verified)Microsoft Windows Component Publisher]
& & &PHIME2002A&&C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName&&&[(Verified)Microsoft Windows Component Publisher]
& & &COMODO Internet Security&&&C:\Program Files\COMODO\COMODO Internet Security\cfp.exe& -h&&&[(Verified)Comodo Security Solutions, Inc.]
& & &Shadow Defender Daemon&&&C:\Program Files\Shadow Defender\DefenderDaemon.exe& /auto&&&[]
& & &DAEMON Tools-1033&&&C:\Program Files\D-Tools\daemon.exe&&&-lang 1033&&&[DAEMON'S HOME]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
& & &shell&&Explorer.exe&&&[(Verified)Microsoft Windows Component Publisher]
& & &Userinit&&C:\WINDOWS\system32\userinit.exe,&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
& & &AppInit_DLLs&& C:\WINDOWS\system32\guard32.dll&&&[(Verified)Comodo Security Solutions]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
& & &UIHost&&logonui.exe&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
& & &{AEB-11d0-97EE-00C04FD91972}&&shell32.dll&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
& & &PostBootReminder&&%SystemRoot%\system32\SHELL32.dll&&&[(Verified)Microsoft Windows Component Publisher]
& & &CDBurn&&%SystemRoot%\system32\SHELL32.dll&&&[(Verified)Microsoft Windows Component Publisher]
& & &WebCheck&&%SystemRoot%\system32\webcheck.dll&&&[(Verified)Microsoft Windows Component Publisher]
& & &SysTray&&C:\WINDOWS\system32\stobject.dll&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
& & &WinlogonNotify: crypt32chain&&crypt32.dll&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
& & &WinlogonNotify: cryptnet&&cryptnet.dll&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
& & &WinlogonNotify: cscdll&&cscdll.dll&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
& & &WinlogonNotify: dimsntfy&&%SystemRoot%\System32\dimsntfy.dll&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
& & &WinlogonNotify: ScCertProp&&wlnotify.dll&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
& & &WinlogonNotify: Schedule&&wlnotify.dll&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
& & &WinlogonNotify: sclgntfy&&sclgntfy.dll&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
& & &WinlogonNotify: SensLogn&&WlNotify.dll&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
& & &WinlogonNotify: termsrv&&wlnotify.dll&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
& & &WinlogonNotify: wlballoon&&wlnotify.dll&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
& & &{-A8BA-11D1-B96B-00A0C90312E1}&&%SystemRoot%\system32\browseui.dll&&&[(Verified)Microsoft Windows Component Publisher]
& & &{8C7461EF-2B13-11d2-BE35-0}&&%SystemRoot%\system32\browseui.dll&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\&{22d6f312-b0f6-11d0-94ab-e95}]
& & &Microsoft Windows Media Player&&C:\WINDOWS\inf\unregmp2.exe /HideWMP&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\&{d38-484f-9b9e-dec}]
& & &Internet Explorer&&%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE&&&[File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\&{60B49E34-C7CC-11D0-C90347FF}MICROS]
& & &浏览器自定义组件&&RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\&{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
& & &Outlook Express&&%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE&&&[File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09--FED}]
& & &Themes Setup&&%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll&&&[File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
& & &Microsoft Outlook Express 6&&&%ProgramFiles%\Outlook Express\setup50.exe& /APP:OE /CALLER:WINNT /user /install&&&[File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
& & &NetMeeting 3.01&&rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{e7d-11d1-bc44-00c04fd912be}]
& & &Windows Messenger 4.7&&rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
& & &Microsoft Windows Media Player&&rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{71-11d2-AF11-00C04FA35D02}]
& & &通讯簿 6&&&%ProgramFiles%\Outlook Express\setup50.exe& /APP:WAB /CALLER:WINNT /user /install&&&[File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{-ECBD-11cf-8B85-00AA005B4340}]
& & &Windows 桌面更新&&regsvr32.exe /s /n /i:U shell32.dll&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{-ECBD-11cf-8B85-00AA005B4383}]
& & &Internet Explorer 6&&%SystemRoot%\system32\ie4uinit.exe&&&[(Verified)Microsoft Windows Component Publisher]
[HKEY_CURRENT_USER\Control Panel\Desktop]
& & &SCRNSAVE.EXE&&C:\WINDOWS\system32\logon.scr&&&[(Verified)Microsoft Windows Component Publisher]
==================================
启动文件夹
N/A
==================================
服务
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
&&&&C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&&&Adobe Systems&
[COMODO Internet Security Helper Service / cmdAgent][Running/Auto Start]
&&&&C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe&&&COMODO&
[Human Interface Device Access / HidServ][Stopped/Disabled]
&&&C:\WINDOWS\System32\svchost.exe -k netsvcs--&%SystemRoot%\System32\hidserv.dll&&N/A&
[Sandboxie Service / SbieSvc][Running/Auto Start]
&&&&C:\Program Files\Sandboxie\SbieSvc.exe&&&tzuk&
==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
&&&system32\drivers\ac97intc.sys&&Intel Corporation&
[COMODO Internet Security Sandbox Driver / cmdGuard][Running/System Start]
&&&System32\DRIVERS\cmdguard.sys&&COMODO&
[COMODO Internet Security Helper Driver / cmdHlp][Running/System Start]
&&&System32\DRIVERS\cmdhlp.sys&&COMODO&
[d347bus / d347bus][Running/Boot Start]
&&&\SystemRoot\system32\DRIVERS\d347bus.sys&&&
[d347prt / d347prt][Running/Boot Start]
&&&\SystemRoot\System32\Drivers\d347prt.sys&&&
[COMODO Internet Security Firewall Driver / Inspect][Running/Boot Start]
&&&\SystemRoot\System32\DRIVERS\inspect.sys&&COMODO&
[nv / nv][Running/Manual Start]
&&&system32\DRIVERS\nv4_mini.sys&&NVIDIA Corporation&
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
&&&system32\DRIVERS\ptilink.sys&&Parallel Technologies, Inc.&
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
&&&system32\DRIVERS\RTL8139.SYS&&Realtek Semiconductor Corporation&
[SbieDrv / SbieDrv][Running/Manual Start]
&&&\??\C:\Program Files\Sandboxie\SbieDrv.sys&&tzuk&
[Secdrv / Secdrv][Stopped/Manual Start]
&&&system32\DRIVERS\secdrv.sys&&Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.&
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
&&&system32\DRIVERS\tcpip.sys&&Microsoft Corporation&
[KernelCheck / KernelCheck][Running/Manual Start]
&&&\??\C:\DOCUME~1\MYLIFE~1\LOCALS~1\Temp\flbs\KpCheck.sys&&N/A&
==================================
浏览器加载项
[ThunderAtOnce Class]
&&{01443AEC-0FD1-40fd-9C87-E93D} &C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD&
[Thunder Browser Helper]
&&{889D2FEB-98-1DD2C5261283} &C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD&
[启动迅雷5]
&&{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} &C:\Program Files\Thunder Network\Thunder\Thunder.exe, (Signed) 深圳市迅雷网络技术有限公司&
[]
&&{e2e2dd38-d088--f2ba} &%windir%\Network Diagnostic\xpnetdiag.exe, (Signed) N/A&
[Messenger]
&&{FB5Fd2-BB9E-00C04F795683} &C:\Program Files\Messenger\msmsgs.exe, (Signed) Microsoft Corporation&
[ThunderAtOnce Class]
&&{01443AEC-0FD1-40FD-9C87-E93D} &C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, (Signed) Thunder Networking Technologies,LTD&
[]
&&{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} &, &
[Thunder Browser Helper]
&&{889D2FEB-98-1DD2C5261283} &C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, (Signed) Thunder Networking Technologies,LTD&
[Shockwave Flash Object]
&&{D27CDB6E-AE6D-11CF-96B8-} &C:\WINDOWS\system32\Macromed\Flash\Flash10l.ocx, (Signed) Adobe Systems, Inc.&
[]
&&{E2E2DD38-D088--F2BA} &, &
[使用迅雷下载]
&&&C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A&
[使用迅雷下载全部链接]
&&&C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A&
==================================
正在运行的进程
[PID: 384][\SystemRoot\System32\smss.exe]&&[(Verified) Microsoft Corporation, 5.1. (xpsp.1)]
[PID: 568][\??\C:\WINDOWS\system32\csrss.exe]&&[(Verified) Microsoft Corporation, 5.1. (xpsp.1)]
[PID: 592][\??\C:\WINDOWS\system32\winlogon.exe]&&[(Verified) Microsoft Corporation, 5.1. (xpsp.3)]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
[PID: 636][C:\WINDOWS\system32\services.exe]&&[(Verified) Microsoft Corporation, 5.1. (xpsp.1)]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
[PID: 648][C:\WINDOWS\system32\lsass.exe]&&[(Verified) Microsoft Corporation, 5.1. (xpsp.3)]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
[PID: 816][C:\WINDOWS\system32\svchost.exe]&&[(Verified) Microsoft Corporation, 5.1. (xpsp.1)]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
[PID: 880][C:\WINDOWS\system32\svchost.exe]&&[(Verified) Microsoft Corporation, 5.1. (xpsp.1)]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
[PID: 1104][C:\WINDOWS\Explorer.EXE]&&[(Verified) Microsoft Corporation, 6.00. (xpsp.5)]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
& & [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]&&[Thunder Networking Technologies,LTD, 5, 0, 8, 120]
& & [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll]&&[深圳市迅雷网络技术有限公司, 1, 0, 0, 20]
& & [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll]&&[深圳市迅雷网络技术有限公司, 1, 0, 0, 16]
& & [C:\Program Files\WinRAR\rarext.dll]&&[N/A, ]
& & [C:\Program Files\Shadow Defender\ShellExt.dll]&&[, 1.1.0.275]
& & [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll]&&[Thunder Networking Technologies,LTD, 1.0.5.34]
& & [C:\WINDOWS\system32\MSVCP71.dll]&&[Microsoft Corporation, 7.10.3077.0]
& & [C:\WINDOWS\system32\MSVCR71.dll]&&[Microsoft Corporation, 7.10.3052.4]
& & [C:\WINDOWS\system32\SOGOUPY.IME]&&[ Inc., 5.0.0.3787]
[PID: 1164][C:\WINDOWS\system32\svchost.exe]&&[(Verified) Microsoft Corporation, 5.1. (xpsp.1)]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
[PID: 1248][C:\WINDOWS\system32\svchost.exe]&&[(Verified) Microsoft Corporation, 5.1. (xpsp.1)]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
[PID: 1304][C:\WINDOWS\system32\svchost.exe]&&[(Verified) Microsoft Corporation, 5.1. (xpsp.1)]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
[PID: 1644][C:\Program Files\Sandboxie\SbieSvc.exe]&&[tzuk, 3.442]
& & [C:\Program Files\Sandboxie\SbieDll.dll]&&[tzuk, 3.442]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
[PID: 1940][C:\Program Files\Shadow Defender\DefenderDaemon.exe]&&[, 1.1.0.275]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
& & [C:\Program Files\Shadow Defender\ShellExt.dll]&&[, 1.1.0.275]
[PID: 1968][C:\Program Files\D-Tools\daemon.exe]&&[DAEMON'S HOME, 3.47.0.0]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
& & [C:\WINDOWS\daemon.dll]&&[, 3.47.0.0]
& & [C:\Program Files\D-Tools\PFCTOC.DLL]&&[Padus(R), Inc., 1, 0, 0, 12]
& & [C:\Program Files\D-Tools\Plugins\Images\bw5mount.dll]&&[, 1.0.2.0]
& & [C:\Program Files\D-Tools\Plugins\Images\ccdmount.dll]&&[GENERIC, 1.02.0.0]
& & [C:\Program Files\D-Tools\Plugins\Images\mdsmount.dll]&&[GENERIC, 1.01.0.0]
& & [C:\Program Files\D-Tools\Plugins\Images\nrgmount.dll]&&[GENERIC, 1.02.0.0]
& & [C:\Program Files\D-Tools\Plugins\Images\pdimount.dll]&&[GENERIC, 1.01.0.0]
[PID: 1976][C:\WINDOWS\system32\ctfmon.exe]&&[(Verified) Microsoft Corporation, 5.1. (xpsp.5)]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
[PID: 572][C:\WINDOWS\System32\svchost.exe]&&[(Verified) Microsoft Corporation, 5.1. (xpsp.1)]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
[PID: 1876][C:\Program Files\TTPlayer\TTPlayer.exe]&&[Alen Soft, 5, 5, 2, 0]
& & [C:\Program Files\TTPlayer\ttpcomm.dll]&&[N/A, ]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
& & [C:\Program Files\TTPlayer\ttpres.dll]&&[Alen Soft, 5, 5, 2, 0]
& & [C:\WINDOWS\system32\msdmo.dll]&&[, ]
& & [C:\Program Files\TTPlayer\AddIn\ttp_ape.dll]&&[N/A, ]
[PID: 752][C:\WINDOWS\system32\svchost.exe]&&[(Verified) Microsoft Corporation, 5.1. (xpsp.1)]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
[PID: 1600][C:\DOCUME~1\MYLIFE~1\LOCALS~1\Temp\Rar$EX00.782\wsyscheck0223中文版\Wsyscheck.exe]&&[[email].cn[/email], 1.68.33.0]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
& & [C:\Program Files\WinRAR\rarext.dll]&&[N/A, ]
& & [C:\Program Files\Shadow Defender\ShellExt.dll]&&[, 1.1.0.275]
[PID: 432][C:\Program Files\Mozilla Firefox\firefox.exe]&&[Mozilla Corporation, 1.9.2.13]
& & [C:\Program Files\Mozilla Firefox\xul.dll]&&[Mozilla Foundation, 1.9.2.13]
& & [C:\Program Files\Mozilla Firefox\sqlite3.dll]&&[sqlite.org, 3.7.1]
& & [C:\Program Files\Mozilla Firefox\MOZCRT19.dll]&&[Mozilla Foundation, 8.00.0000]
& & [C:\Program Files\Mozilla Firefox\js3250.dll]&&[N/A, ]
& & [C:\Program Files\Mozilla Firefox\nspr4.dll]&&[Mozilla Foundation, 4.8.6]
& & [C:\Program Files\Mozilla Firefox\smime3.dll]&&[Mozilla Foundation, 3.12.8.0 Basic ECC]
& & [C:\Program Files\Mozilla Firefox\nss3.dll]&&[Mozilla Foundation, 3.12.8.0 Basic ECC]
& & [C:\Program Files\Mozilla Firefox\nssutil3.dll]&&[Mozilla Foundation, 3.12.8.0]
& & [C:\Program Files\Mozilla Firefox\plc4.dll]&&[Mozilla Foundation, 4.8.6]
& & [C:\Program Files\Mozilla Firefox\plds4.dll]&&[Mozilla Foundation, 4.8.6]
& & [C:\Program Files\Mozilla Firefox\ssl3.dll]&&[Mozilla Foundation, 3.12.8.0 Basic ECC]
& & [C:\Program Files\Mozilla Firefox\MOZCPP19.dll]&&[Mozilla Foundation, 8.00.0000]
& & [C:\Program Files\Mozilla Firefox\xpcom.dll]&&[Mozilla Foundation, 1.9.2.13]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
& & [C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll]&&[Mozilla Foundation, 1.9.2.13]
& & [C:\Program Files\Mozilla Firefox\softokn3.dll]&&[Mozilla Foundation, 3.12.8.0 Basic ECC]
& & [C:\Program Files\Mozilla Firefox\nssdbm3.dll]&&[Mozilla Foundation, 3.12.8.0 Basic ECC]
& & [C:\Program Files\Mozilla Firefox\freebl3.dll]&&[Mozilla Foundation, 3.12.8.0 Basic ECC]
& & [C:\Program Files\Mozilla Firefox\nssckbi.dll]&&[Mozilla Foundation, 1.80]
& & [C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll]&&[Mozilla Foundation, 1.9.2.13]
& & [C:\Documents and Settings\MY LIFE\Application Data\Mozilla\Firefox\Profiles\njwceobx.default\extensions\[email][/email]\components\windowTrayIcon.dll]&&[N/A, ]
& & [C:\Documents and Settings\MY LIFE\Application Data\Mozilla\Firefox\Profiles\njwceobx.default\extensions\[email][/email]\components\mediacenter-com.dll]&&[N/A, ]
& & [C:\WINDOWS\system32\SOGOUPY.IME]&&[ Inc., 5.0.0.3787]
& & [C:\WINDOWS\system32\icm32.dll]&&[Microsoft Corporation, 5.1. (xpsp.5)]
[PID: 2420][C:\WINDOWS\system32\conime.exe]&&[(Verified) Microsoft Corporation, 5.1. (xpsp.5)]
& & [C:\WINDOWS\system32\guard32.dll]&&[COMODO, 3, 14, 6]
[PID: 3836][C:\DOCUME~1\MYLIFE~1\LOCALS~1\Temp\Rar$EX00.442\SREngLdr.EXE]&&[Smallfrogs Studio, 2.8.2.1321]
[PID: 3936][C:\DOCUME~1\MYLIFE~1\LOCALS~1\Temp\Rar$EX00.442\SREd127fdb.EXE]&&[Smallfrogs Studio, 2.8.2.1321]
& & [C:\DOCUME~1\MYLIFE~1\LOCALS~1\Temp\Rar$EX00.442\Upload\3rdUpd.DLL]&&[Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT&&OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE&&OK. [&%1& %*]
.COM&&OK. [&%1& %*]
.PIF&&OK. [&%1& %*]
.REG&&OK. [regedit.exe &%1&]
.BAT&&OK. [&%1& %*]
.SCR&&OK. [&%1& /S]
.CHM&&OK. [&C:\WINDOWS\hh.exe& %1]
.HLP&&OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI&&OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF&&OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS&&OK. [%SystemRoot%\System32\WScript.exe &%1& %*]
.JS& &OK. [%SystemRoot%\System32\WScript.exe &%1& %*]
.LNK&&OK. [{0-}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1& && & localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1876, C:\PROGRAM FILES\TTPLAYER\TTPLAYER.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1600, C:\DOCUME~1\MYLIFE~1\LOCALS~1\TEMP\RAR$EX00.782\WSYSCHECK0223中文版\WSYSCHECK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1600, C:\DOCUME~1\MYLIFE~1\LOCALS~1\TEMP\RAR$EX00.782\WSYSCHECK0223中文版\WSYSCHECK.EXE]
==================================
计划任务
N/A
==================================
Windows 安全更新检查
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
似乎没看出什么。文件夹是什么名字?
oneyearslater
新建文件夹
Markel.Scofield
日志没问题
LZ装的安全软件好多呀
会不会LZ是在开着SD的模式下删除文件的呀
oneyearslater
额,不是,其实我一个杀毒软件都没装,是在影子系统中安装的,临时扫描下
oneyearslater
求高人解答
用msconfig查看启动项目,再试关闭可疑程序自动运行。也可尝试Windows注册表里“新建文件夹 ”路径。
Copyright & KaFan & All Rights Reserved.
Powered by Discuz! X3.1( 苏ICP备号 ) GMT+8,}

我要回帖

更多关于 求电脑高手qq 的文章

更多推荐

版权声明:文章内容来源于网络,版权归原作者所有,如有侵权请点击这里与我们联系,我们将及时删除。

点击添加站长微信