下面是我扫描的报告 ================================== 服务 [C-DillaCdaC11BA / C-DillaCdaC11BA][Running/Auto Start] <C:\WINDOWS\system32\drivers\CDAC11BA.EXE><Macrovision> [Human Interface Device Access / HidServ][Stopped/Disabled] <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A> [SRS Labs License Service / SRS Labs License Service][Stopped/Manual Start] <"C:\Program Files\Common Files\SRS Labs Shared\Service\srslabslicenseservice.exe"><SRS Labs>
================================== 驱动程序 [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start] <system32\drivers\ac97intc.sys><Intel Corporation> [CdaC15BA / CdaC15BA][Running/Auto Start] <\??\C:\WINDOWS\system32\drivers\CDAC15BA.SYS><Macrovision Europe Ltd> [nv / nv][Running/Manual Start] <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.> [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start] <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation> [Secdrv / Secdrv][Stopped/Manual Start] <system32\DRIVERS\secdrv.sys><N/A> [SRS Labs Audio Sandbox (WDM) / SRS_SSCFilter][Running/Manual Start] <system32\drivers\srs_sscfilter.sys><N/A> [TCP/IP Protocol Driver / Tcpip][Running/System Start] <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
================================== 浏览器加载项 [Messenger] {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation> [AcroIEHlprObj Class] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Adobe Reader6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated> [Shell Name Space] {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
================================== 正在运行的进程 [PID: 420][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 476][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 500][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 544][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 556][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 696][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 744][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 780][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 828][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 880][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1116][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2649 (xpsp.050406-1732)] [C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.0.0.86] [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] [Autodesk, 16.0.0.86] [D:\Adobe Reader6.0\Reader\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.1.2003110300] [C:\WINDOWS\system32\msdmo.dll] [N/A, N/A] [C:\Program Files\WinRAR\rarext.dll] [N/A, N/A] [C:\WINDOWS\system32\icm32.dll] [Microsoft Corporation, 5.1.2600.2709 (xpsp_sp2_gdr.050628-1518)] [C:\WINDOWS\system32\mpg2splt.ax] [N/A, N/A] [PID: 1304][C:\WINDOWS\system32\drivers\CDAC11BA.EXE] [Macrovision, 4.20.020] [PID: 1700][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1876][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1884][C:\WINDOWS\system32\temp1.exe] [N/A, N/A] [PID: 1936][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1424][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [PID: 1236][C:\Program Files\TTPlayer\TTPlayer.exe] [Alen Soft, 4, 6, 9, 0] [C:\Program Files\TTPlayer\ttpcomm.dll] [N/A, N/A] [C:\Program Files\TTPlayer\ttpres.dll] [Alen Soft, 4, 6, 9, 0] [C:\Program Files\TTPlayer\AddIn\ttp_asf.dll] [N/A, N/A] [C:\Program Files\TTPlayer\AddIn\ttp_aac.dll] [N/A, N/A] [C:\Program Files\TTPlayer\AddIn\ttp_ac3dts.dll] [N/A, N/A] [C:\Program Files\TTPlayer\AddIn\ttp_lrcsh.dll] [N/A, N/A] [PID: 1068][D:\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
================================== 文件关联 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}]
================================== Winsock 提供者 N/A
================================== Autorun.inf [D:\] [autorun] Shellexecute=copy.exe [E:\] [autorun] Shellexecute=copy.exe [F:\] [autorun] Shellexecute=copy.exe
================================== HOSTS 文件 127.0.0.1 localhost
================================== API HOOK N/A
==================================
[/CODE] |