|
作者: hnyzbin [hnyzbin] 论坛用户 | 登录 |
请各位解释一下各进程所代表的意义,谢谢~~! 完美卸载 - 系统检查检测报告! 建议:修复时请按照高手的反馈编号在修复工具中打勾进行修复. --------------------------系统环境------------------------- 检测日期: 2006-4-4 20:46 Windows: Microsoft Windows XP ServicePack: Service Pack 2 Update: 2600.xpsp_sp2_gdr.050301-1519 Internet Explorer: 6.0.2900.2180 -----------------------网络基础安全测试-------------------- 密码安全检测:没有管理员密码,极容易被黑客攻击! 网络漏洞检测:存在IPC$空连接,容易被黑客攻击! 方案:<a href="File://F:\完美卸载V2006\IPCRepair.reg">下载此注册表文件并导入!</a> 服务名称 是否运行 描述 RemoteRegistry [运行中] [说明:这个服务可能被利用远程操作注册表] Windows Time [运行中] [说明:这个服务可能被黑客利用来启动木马] Telnet [已停止] [说明:这个服务可能被黑客登录到您计算机] Messenger [已停止] [说明:这个服务常被广告商用来发垃圾广告] Server [运行中] [说明:如果你的电脑不用局域网中,可以关闭] -----------------------计算机网络端口---------------------- 协议 端口号 端口类型 TCP 135 微软DCE RPC end-point mapper服务 TCP 445 Microsoft-DS TCP 6059 未知类型 TCP 1026 未知类型 TCP 139 微软Netbios Name服务(用于文件及打印机共享) TCP 1113 未知类型 TCP 1114 未知类型 TCP 445 公共Internet文件系统(CIFS) TCP 500 Internet密钥交换 TCP 1025 Maverick's Matrix 1.2 - 2.0 TCP 1048 未知类型 TCP 4500 sae-urn TCP 123 未知类型 TCP 1900 未知类型 TCP 123 未知类型 TCP 137 未知类型 TCP 138 未知类型 TCP 1900 未知类型 --------------------计算机系统组件体检---------------------- [编号:0] [名称:\SystemRoot\System32\smss.exe] [类型:运行进程] [内容:未知] [编号:1] [名称:\??\C:\WINDOWS\system32\winlogon.exe] [类型:运行进程] [内容:未知] [编号:2] [名称:C:\WINDOWS\system32\services.exe] [类型:运行进程] [内容:Microsoft(R) Windows(R) Operating System (C) Microsoft Corporation. All rights reserved.] [编号:3] [名称:C:\WINDOWS\system32\lsass.exe] [类型:运行进程] [内容:Microsoft? Windows? Operating System ? Microsoft Corporation. All rights reserved.] [编号:4] [名称:C:\WINDOWS\system32\svchost.exe] [类型:运行进程] [内容:Microsoft? Windows? Operating System ? Microsoft Corporation. All rights reserved.] [编号:5] [名称:F:\Rising\Rav\CCenter.exe] [类型:运行进程] [内容:Rising Antivirus Software Copyright Rising 2002] [编号:6] [名称:C:\WINDOWS\System32\svchost.exe] [类型:运行进程] [内容:Microsoft? Windows? Operating System ? Microsoft Corporation. All rights reserved.] [编号:7] [名称:F:\Rising\Rav\Ravmond.exe] [类型:运行进程] [内容:Rising Antivirus Software Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:8] [名称:C:\WINDOWS\system32\spoolsv.exe] [类型:运行进程] [内容:Microsoft? Windows? Operating System ? Microsoft Corporation. All rights reserved.] [编号:9] [名称:F:\Rising\Rav\RavStub.exe] [类型:运行进程] [内容:RavStub Application Copyright (c) 1998-2005 Rising Corp.] [编号:10] [名称:C:\WINDOWS\Explorer.EXE] [类型:运行进程] [内容:Microsoft(R) Windows(R) Operating System (C) Microsoft Corporation. All rights reserved.] [编号:11] [名称:C:\WINDOWS\SOUNDMAN.EXE] [类型:运行进程] [内容:Realtek Sound Manager Copyright (c) 2001-2004 Realtek Semiconductor Corp.] [编号:12] [名称:F:\Java\jre1.5.0_06\bin\jusched.exe] [类型:运行进程] [内容:Java(TM) 2 Platform Standard Edition 5.0 Update 6 Copyright ? 2004] [编号:13] [名称:F:\Rising\Rav\RavTask.exe] [类型:运行进程] [内容:Rising Antivirus Software Copyright (c) 1998-2006 Rising Corp.] [编号:14] [名称:F:\Rising\Rav\Ravmon.exe] [类型:运行进程] [内容:Rising Anti-Virus Monitor Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:15] [名称:C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [类型:运行进程] [内容:RealPlayer (32-bit) Copyright ? RealNetworks, Inc. 1995-2004] [编号:16] [名称:C:\WINDOWS\system32\ctfmon.exe] [类型:运行进程] [内容:Microsoft? Windows? Operating System ? Microsoft Corporation. All rights reserved.] [编号:17] [名称:F:\完美卸载V2006\MainCon.exe] [类型:运行进程] [内容:MainCon 应用程序 版权所有 (C) 2004] [编号:18] [名称:F:\完美卸载V2006\WjfClean.exe] [类型:运行进程] [内容:完美工作室 WjfClean Copyright ? 2002] [编号:19] [名称:F:\完美卸载V2006\RegistryDoctor.exe] [类型:运行进程] [内容:RegistryDoctor 应用程序 版权所有 (C) 2003] [编号:20] [名称:F:\完美卸载V2006\SysSec.exe] [类型:运行进程] [内容:完美卸载V2006-ChinaHijackThis 版权所有 (C) 2006] [编号:21] [分隔符:---------------------------------------------------------------------] [编号:22] [名称:F:\Rising\Rav\BWList.dll] [类型:已加载DLL] [内容:BWList Dynamic Link Library Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:23] [名称:F:\Rising\Rav\RsCommX.dll] [类型:已加载DLL] [内容:rising RsCommX Copyright ? 2002] [编号:24] [名称:F:\Rising\Rav\RSAPPMGR.DLL] [类型:已加载DLL] [内容:Rising AntiVirus 2006 Copyright ? 2004 - 2005] [编号:25] [名称:F:\Rising\Rav\CfgDll.dll] [类型:已加载DLL] [内容:Rising AntiVirus 2006 Copyright ? 2004 - 2006] [编号:26] [名称:F:\Rising\Rav\RSCOMMON.DLL] [类型:已加载DLL] [内容:Rising Antivirus Software Copyright (c) 1998-2006 Rising Corp.] [编号:27] [名称:F:\Rising\Rav\RsLog.dll] [类型:已加载DLL] [内容:RsLog Dynamic Link Library Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:28] [名称:F:\Rising\Rav\HOOKSYS.dll] [类型:已加载DLL] [内容:HOOKSYS Dynamic Link Library Copyright (C) 2005] [编号:29] [名称:F:\Rising\Rav\Scanner.dll] [类型:已加载DLL] [内容:Rising RsScanner Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:30] [名称:F:\Rising\Rav\libload.dll] [类型:已加载DLL] [内容:rising libload Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:31] [名称:F:\Rising\Rav\VirusLib.dll] [类型:已加载DLL] [内容:Rising VirusLib Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:32] [名称:F:\Rising\Rav\regmon.dll] [类型:已加载DLL] [内容: regmon Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:33] [名称:F:\Rising\Rav\HookWeb.dll] [类型:已加载DLL] [内容:rising HookWeb Copyright ? 2004] [编号:34] [名称:F:\Rising\Rav\MemMon.dll] [类型:已加载DLL] [内容:北京瑞星 MemMon Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:35] [名称:F:\Rising\Rav\expscan.dll] [类型:已加载DLL] [内容:ExpScan Dynamic Link Library Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:36] [名称:F:\Rising\Rav\mPorts.dll] [类型:已加载DLL] [内容:Personal Firewall Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:37] [名称:F:\Rising\Rav\MailMon.dll] [类型:已加载DLL] [内容:mailmon Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:38] [名称:F:\Rising\Rav\SpamEng.dll] [类型:已加载DLL] [内容: SpamEng Dynamic Link Library Copyright (C) 2004] [编号:39] [名称:F:\Rising\Rav\engine.dll] [类型:已加载DLL] [内容:rising engine Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:40] [名称:F:\Rising\Rav\PostTrt.dll] [类型:已加载DLL] [内容:Rising PostTrt Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:41] [名称:F:\Rising\Rav\UnExe.dll] [类型:已加载DLL] [内容:rising UnExe Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:42] [名称:F:\Rising\Rav\ScanExec.dll] [类型:已加载DLL] [内容:rising ScanExec Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:43] [名称:F:\Rising\Rav\ScanEx.dll] [类型:已加载DLL] [内容:Rising ScanEX Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:44] [名称:F:\Rising\Rav\NvFile.dll] [类型:已加载DLL] [内容:rising NVFile Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:45] [名称:F:\Rising\Rav\ScanMac.dll] [类型:已加载DLL] [内容:rising ScanMac Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:46] [名称:F:\Rising\Rav\ScanSct.dll] [类型:已加载DLL] [内容:rising ScanSct Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:47] [名称:F:\Rising\Rav\Unpacker.dll] [类型:已加载DLL] [内容:rising UnPacker Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:48] [名称:F:\Rising\Rav\ExtOLE.dll] [类型:已加载DLL] [内容:rising ExtOLE Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [编号:49] [名称:C:\WINDOWS\system32\xunleibho_v14.dll] [类型:已加载DLL] [内容:XunLeiBHO Module Copyright 2004-2006] [编号:50] [名称:F:\Rising\Rav\RsGuiLib.dll] [类型:已加载DLL] [内容:Rising Antivirus Software Copyright (c) 1998-2006 Rising Corp.] [编号:51] [名称:F:\Rising\Rav\PngDll.dll] [类型:已加载DLL] [内容:Rising Antivirus Software Copyright (c) 1998-2005 Rising Corp.] [编号:52] [分隔符:---------------------------------------------------------------------] [编号:53] [名称:IMJPMIG8.1] [类型:开机启动] [内容:"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32] [编号:54] [名称:PHIME2002ASync] [类型:开机启动] [内容:C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC] [编号:55] [名称:PHIME2002A] [类型:开机启动] [内容:C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName] [编号:56] [名称:SiSUSBRG] [类型:开机启动] [内容:C:\WINDOWS\SiSUSBrg.exe] [编号:57] [名称:SoundMan] [类型:开机启动] [内容:SOUNDMAN.EXE] [编号:58] [名称:IMSCMig] [类型:开机启动] [内容:C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload] [编号:59] [名称:SunJavaUpdateSched] [类型:开机启动] [内容:F:\Java\jre1.5.0_06\bin\jusched.exe] [编号:60] [名称:RavTask] [类型:开机启动] [内容:"F:\Rising\Rav\RavTask.exe" -system] [编号:61] [名称:TkBellExe] [类型:开机启动] [内容:"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot] [编号:62] [分隔符:---------------------------------------------------------------------] [编号:63] [名称:AFD] [类型:服务:未知] [内容:\SystemRoot\System32\drivers\afd.sys] [编号:64] [名称:Service for Realtek AC97 Audio (WDM)] [类型:服务:Windows (R) WDM driver for Realtek AC'97 Audio(HRTF data Copyright 1994 by MIT Media Lab) Copyright (c) Realtek Semiconductor Corp.1998-2004] [内容:C:\WINDOWS\system32\drivers\alcxwdm.sys] [编号:65] [名称:aslm75] [类型:服务:未知] [内容:c:\windows\system32\drivers\aslm75.sys] [编号:66] [名称:Basetdi] [类型:服务:Rising PFW Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited] [内容:c:\windows\system32\drivers\basetdi.sys] [编号:67] [名称:DCOM Server Process Launcher] [类型:服务:未知] [内容:C:\WINDOWS\system32\svchost ] [编号:68] [名称:ExpScaner] [类型:服务:ExpScan.sys Copyright (C) 2004 Rising] [内容:f:\rising\rav\expscan.sys] [编号:69] [名称:HookCont] [类型:服务:TDIHOOK Driver for Windows NT Copyright ] [内容:f:\rising\rav\hookcont.sys] [编号:70] [名称:HookReg] [类型:服务: 版权所有 (@) 2003] [内容:f:\rising\rav\hookreg.sys] [编号:71] [名称:HookSys] [类型:服务:Hooksys Copyright (C) 2004] [内容:f:\rising\rav\hooksys.sys] [编号:72] [名称:Macromedia Licensing Service] [类型:服务:未知] [内容:"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"] [编号:73] [名称:MEMSCAN] [类型:服务:MemScan Drivers for Windows NT Copyright (C) RFW Corp. 2000-2002] [内容:f:\rising\rav\memscan.sys] [编号:74] [名称:Windows Installer] [类型:服务:未知] [内容:C:\WINDOWS\system32\msiexec.exe /V] [编号:75] [名称:npkcrypt] [类型:服务:nProtect KeyCrypt Driver Copyright (C) INCA Internet. 2000-2005] [内容:f:\tencent\qq2006 beta1\npkcrypt.sys] [编号:76] [名称:Office Source Engine] [类型:服务:未知] [内容:"C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"] [编号:77] [名称:Remote Procedure Call (RPC)] [类型:服务:未知] [内容:C:\WINDOWS\system32\svchost ] [编号:78] [名称:Rising Process Communication Center] [类型:服务:未知] [内容:"F:\Rising\Rav\CCenter.exe"] [编号:79] [名称:RsRavMon Service] [类型:服务:未知] [内容:"F:\Rising\Rav\Ravmond.exe"] [编号:80] [名称:Secdrv] [类型:服务:未知] [内容:C:\WINDOWS\system32\drivers\secdrv.sys] [编号:81] [名称:SiS AGP Filter] [类型:服务:SiS AGPv3.5 Filter for Windows XP Copyright (C) Silicon Integrated Systems Corp.] [内容:C:\WINDOWS\system32\drivers\sisagpx.sys] [编号:82] [名称:sisidex] [类型:服务:Windows (R) 2000 DDK driver ] [内容:C:\WINDOWS\system32\drivers\sisidex.sys] [编号:83] [名称:SiS PCI Fast Ethernet Adapter Driver] [类型:服务:NDIS 5.1 NIC Driver SiS Corporation] [内容:C:\WINDOWS\system32\drivers\sisnic.sys] [编号:84] [名称:SiS PCI Fast Ethernet Adapter Driver for NDIS51] [类型:服务:NDIS 5.1 NIC Driver SiS Corporation] [内容:C:\WINDOWS\system32\drivers\sisnicxp.sys] [编号:85] [名称:Terminal Services] [类型:服务:未知] [内容:C:\WINDOWS\system32\svchost ] [编号:86] [分隔符:---------------------------------------------------------------------] [编号:87] [名称:Start Page] [类型:IE主页-当前用户] [内容:http://www.baidu.com/] [编号:88] [名称:Search Page] [类型:IE搜索-当前用户] [内容:http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch] [编号:89] [名称:Start Page] [类型:IE主页-所有用户] [内容:http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home] [编号:90] [名称:Search Page] [类型:IE搜索-所有用户] [内容:http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch] [编号:91] [名称:Default_Page_URL] [类型:默认IE主页-所有用户] [内容:http://www.tomatolei.com] [编号:92] [名称:Default_Search_URL] [类型:默认IE搜索-所有用户] [内容:http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch] [编号:93] [分隔符:---------------------------------------------------------------------] [编号:94] [名称:ThunderIEHelper Class] [类型:IE 嵌入对象] [内容:C:\WINDOWS\system32\xunleibho_v14.dll] [编号:95] [名称:QQBrowserHelperObject Class] [类型:IE 嵌入对象] [内容:F:\Tencent\QQ2006 Beta1\QQIEHelper.dll] [编号:96] [名称:SSVHelper Class] [类型:IE 嵌入对象] [内容:F:\Java\jre1.5.0_06\bin\ssv.dll] [编号:97] [名称:CpapView Class] [类型:IE 嵌入对象] [内容:C:\WINDOWS\system32\cacb.dll] [编号:98] [名称:] [类型:IE 嵌入对象] [内容:F:\KUGOOV~1.206\KUGOO3~1.OCX] [编号:99] [分隔符:---------------------------------------------------------------------] [编号:100] [名称:{08B0E5C0-4FCB-11CF-AAA5-00401C608501}] [类型:IE 扩展按钮] [内容:G 路径:G] [编号:101] [名称:{367E0A21-8601-4986-9C9A-153BF5ACA118}] [类型:IE 扩展按钮] [内容:豪杰超级解霸9 路径:F:\Hero 9\STHSDVD.EXE] [编号:102] [名称:{6096E38F-5AC1-4391-8EC4-75DFA92FB32F}] [类型:IE 扩展按钮] [内容:番茄花园 路径:http://www.tomatolei.com] [编号:103] [名称:{92780B25-18CC-41C8-B9BE-3C9C571A8263}] [类型:IE 扩展按钮] [内容:信息检索 路径:信息检索] [编号:104] [名称:{c95fe080-8f5d-11d2-a20b-00aa003c157b}] [类型:IE 扩展按钮] [内容:QQ 路径:F:\Tencent\QQ2006 Beta1\QQ.EXE] [编号:105] [名称:{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6}] [类型:IE 扩展按钮] [内容:F:\T 路径:F:\T] [编号:106] [分隔符:---------------------------------------------------------------------] [编号:107] [名称:&使用迅雷下载] [类型:IE 右键按钮] [内容: 路径:] [编号:108] [名称:&使用迅雷下载全部链接] [类型:IE 右键按钮] [内容: 路径:] [编号:109] [名称:上传到QQ网络硬盘] [类型:IE 右键按钮] [内容: 路径:] [编号:110] [名称:使用KuGoo3下载(&K)] [类型:IE 右键按钮] [内容: 路径:] [编号:111] [名称:使用超级解霸播放] [类型:IE 右键按钮] [内容: 路径:] [编号:112] [名称:在Foxmail中添加该RSS频道/频道组] [类型:IE 右键按钮] [内容: 路径:] [编号:113] [名称:导出到 Microsoft Office Excel(&X)] [类型:IE 右键按钮] [内容: 路径:] [编号:114] [名称:添加到QQ自定义面板] [类型:IE 右键按钮] [内容: 路径:] [编号:115] [名称:添加到QQ表情] [类型:IE 右键按钮] [内容: 路径:] [编号:116] [名称:用QQ彩信发送该图片] [类型:IE 右键按钮] [内容: 路径:] [编号:117] [分隔符:---------------------------------------------------------------------] [编号:118] [名称:SharedDocs] [类型:共享文件] [内容:C:\DOCUMENTS AND SETTINGS\ALL USERS\DOCUMENTS ] [编号:119] [名称:print$] [类型:共享文件] [内容:C:\WINDOWS\system32\spool\drivers ] [编号:120] [名称:打印机] [类型:共享文件] [内容:Microsoft Office Document Image Writer,LocalsplOnly ] [编号:121] [分隔符:---------------------------------------------------------------------] [编号:122] [名称:PostBootReminder] [类型:正常嵌入对象] [内容:%SystemRoot%\system32\SHELL32.dll] [编号:123] [名称:CDBurn] [类型:正常嵌入对象] [内容:%SystemRoot%\system32\SHELL32.dll] [编号:124] [名称:WebCheck] [类型:正常嵌入对象] [内容:%SystemRoot%\system32\webcheck.dll] [编号:125] [名称:SysTray] [类型:正常嵌入对象] [内容:C:\WINDOWS\system32\stobject.dll] [编号:126] [分隔符:---------------------------------------------------------------------] [编号:127] [名称:] [类型:EXE关联] [内容:"%1" %*] [编号:128] [名称:] [类型:TXT关联] [内容:%SystemRoot%\system32\NOTEPAD.EXE %1] [编号:129] [名称:] [类型:vbs关联] [内容:%SystemRoot%\System32\WScript.exe "%1" %*] [编号:130] [名称:] [类型:Js关联] [内容:%SystemRoot%\System32\WScript.exe "%1" %*] [编号:131] [名称:] [类型:htmlfile关联] [内容:"F:\Tencent\Tencent Traveler 3.0 正式版SP02\TTraveler.exe" "%1"] [编号:132] [名称:] [类型:HTTP协议] [内容:"F:\Tencent\Tencent Traveler 3.0 正式版SP02\TTraveler.exe" "%1"] [编号:133] [名称:] [类型:FTP协议] [内容:"F:\Tencent\Tencent Traveler 3.0 正式版SP02\TTraveler.exe" "%1"] [编号:134] [分隔符:---------------------------------------------------------------------] [编号:135] [名称:c:\windows\system32\deskpan.dll] [类型:第三方 COM/ActiveX组件] [内容:显示摇曳 CPL 扩展---发布公司:未知] [编号:136] [名称:c:\windows\system32\rtlcpapi.dll] [类型:第三方 COM/ActiveX组件] [内容:RtlCP Class---发布公司:RtlCPAPI Module Copyright 2004] --------------------感谢您关注我的软件--------------------- 网站: [URL=http://www.wjfsoft.com ]http://www.wjfsoft.com [/URL] 产品:完美卸载V2006 [此贴被 hnyzbin(hnyzbin) 在 04月19日13时47分 编辑过] |
地主 发表时间: 06-04-05 18:30 |
|
20CN网络安全小组版权所有
Copyright © 2000-2010 20CN Security Group. All Rights Reserved.
论坛程序编写:NetDemon
粤ICP备05087286号