sdlily - 2006-12-15 10:40:00
2006-12-15,10:27:35
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [(Verified)Microsoft Corporation]
<MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background> [(Verified)Microsoft Corporation]
<swg><C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe> [(Verified)Google Inc.]
<ibmmessages><C:\Program Files\IBM\Messages By IBM\ibmmessages.exe> [IBM]
<slack12><C:\WINDOWS\system32\mfcee.exe> [N/A]
<sysemls><C:\WINDOWS\system32\sysem.exe> [N/A]
<jon315><C:\WINDOWS\system32\ssrvc.exe> [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<S3TRAY2><S3Tray2.exe> [(Verified)S3 Graphics, Inc.]
<SynTPLpr><C:\Program Files\Synaptics\SynTP\SynTPLpr.exe> [(Verified)Synaptics, Inc.]
<SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe> [(Verified)Synaptics, Inc.]
<ATIModeChange><Ati2mdxx.exe> [(Verified)ATI Technologies, Inc.]
<BluetoothAuthenticationAgent><rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent> [(Verified)Microsoft Corporation]
<TPHOTKEY><C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe> [N/A]
<BMMGAG><RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor> [IBM Corp.]
<BMMLREF><C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE> [N/A]
<TPKMAPMN><C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe> [N/A]
<EZEJMNAP><C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe> [IBM Corp.]
<AGRSMMSG><AGRSMMSG.exe> [(Verified)Agere Systems]
<ATIPTA><C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe> [ATI Technologies, Inc.]
<tgcmd><"C:\Program Files\Support.com\bin\tgcmd.exe" /server> [SupportSoft, Inc.]
<StorageGuard><"c:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r> [VERITAS Software, Inc.]
<dla><C:\WINDOWS\system32\dla\tfswctrl.exe> [VERITAS Software, Inc.]
<ibmmessages><C:\Program Files\IBM\Messages By IBM\ibmmessages.exe> [IBM]
<IMEKRMIG6.1><C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE> [(Verified)Microsoft Corporation]
<MSPY2002><C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC> [(Verified)N/A]
<ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"> [(Verified)Symantec Corporation]
<NAV CfgWiz><C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"> [(Verified)Symantec Corporation]
<Symantec NetDriver Monitor><C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer> [(Verified)Symantec Corporation]
<SSC_UserPrompt><C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe> [(Verified)Symantec Corporation]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<Services><C:\WINDOWS\System32\cdqz.exe> [N/A]
<StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> [N/A]
<mysvcig38><mysvcc.exe> [N/A]
<msvcc25><svcchost.exe> [N/A]
<slack12><C:\WINDOWS\system32\mfcee.exe> [N/A]
<sysemls><C:\WINDOWS\system32\sysem.exe> [N/A]
<jon315><C:\WINDOWS\system32\ssrvc.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<CE2EBE0B><C:\WINDOWS\System32\dior4f45558871.exe> [N/A]
<mysvcig38><mysvcc.exe> [N/A]
<msvcc25><svcchost.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}><C:\WINDOWS\system32\iifffda.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbaxv]
<WinlogonNotify: cbaxv><C:\WINDOWS\System32\cbaxv.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\iifffda]
<WinlogonNotify: iifffda><iifffda.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rpcc]
<WinlogonNotify: rpcc><C:\WINDOWS\System32\rpcc.dll> [N/A]
==================================
启动文件夹
[Adobe Reader Speed Launch]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk --> C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [Adobe Systems Incorporated]><N>
[Microsoft Office]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk --> C:\PROGRA~1\MICROS~2\Office10\OSA.EXE [Microsoft Corporation]><N>
[WinZip Quick Pick]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\WinZip Quick Pick.lnk --> C:\PROGRA~1\WinZip\WZQKPICK.EXE [WinZip Computing LP]><N>
==================================
服务
[Print Spooler Service / anral6yzlei]
<C:\WINDOWS\System32\dior4f45558871.exe /service><N/A>
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\System32\Ati2evxx.exe><N/A>
[Symantec Password Validation / ccPwdSvc]
<"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Human Interface Device Access / HidServ]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[IBM PM Service / IBMPMSVC]
<C:\WINDOWS\System32\ibmpmsvc.exe><N/A>
[Norton AntiVirus Auto Protect Service / navapsvc]
<"C:\Program Files\Norton AntiVirus\navapsvc.exe"><Symantec Corporation>
[QCONSVC / QCONSVC]
<System32\QCONSVC.EXE><N/A>
[RegSrvc / RegSrvc]
<C:\WINDOWS\System32\RegSrvc.exe><Intel Corporation>
[Spectrum24 Event Monitor / S24EventMonitor]
<C:\WINDOWS\System32\S24EvMon.exe><Intel Corporation>
[SAVScan / SAVScan]
<C:\Program Files\Norton AntiVirus\SAVScan.exe><Symantec Corporation>
[ScriptBlocking Service / SBService]
<C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe><Symantec Corporation>
[Symantec Network Drivers Service / SNDSrvc]
<C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe><Symantec Corporation>
[SymWMI Service / SymWSC]
<C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe><Symantec Corporation>
sdlily - 2006-12-15 10:40:00
==================================
驱动程序
[abp480n5 / abp480n5]
<\SystemRoot\System32\DRIVERS\ABP480N5.SYS><Microsoft Corporation>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc]
<system32\drivers\ac97intc.sys><Intel Corporation>
[adpu160m / adpu160m]
<\SystemRoot\System32\DRIVERS\adpu160m.sys><Microsoft Corporation>
[aeaudio / aeaudio]
<system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[Agere Systems Soft Modem / AgereSoftModem]
<System32\DRIVERS\AGRSM.sys><Agere Systems>
[Aha154x / Aha154x]
<\SystemRoot\System32\DRIVERS\aha154x.sys><Microsoft Corporation>
[aic78u2 / aic78u2]
<\SystemRoot\System32\DRIVERS\aic78u2.sys><Microsoft Corporation>
[aic78xx / aic78xx]
<\SystemRoot\System32\DRIVERS\aic78xx.sys><Microsoft Corporation>
[AliIde / AliIde]
<\SystemRoot\System32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AMD AGP Bus Filter Driver / amdagp]
<\SystemRoot\System32\DRIVERS\amdagp.sys><Advanced Micro Devices, Inc.>
[asc / asc]
<\SystemRoot\System32\DRIVERS\asc.sys><Advanced System Products, Inc.>
[asc3350p / asc3350p]
<\SystemRoot\System32\DRIVERS\asc3350p.sys><Microsoft Corporation>
[asc3550 / asc3550]
<\SystemRoot\System32\DRIVERS\asc3550.sys><Advanced System Products, Inc.>
[ati2mtag / ati2mtag]
<System32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[cd20xrnt / cd20xrnt]
<\SystemRoot\System32\DRIVERS\cd20xrnt.sys><Microsoft Corporation>
[CmdIde / CmdIde]
<\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[dac2w2k / dac2w2k]
<\SystemRoot\System32\DRIVERS\dac2w2k.sys><Mylex Corporation>
[dpti2o / dpti2o]
<\SystemRoot\System32\DRIVERS\dpti2o.sys><Microsoft Corporation>
[drvmcdb / drvmcdb]
<\SystemRoot\system32\drivers\drvmcdb.sys><VERITAS Software, Inc.>
[drvnddm / drvnddm]
<system32\drivers\drvnddm.sys><VERITAS Software, Inc.>
[Intel(R) PRO Adapter Driver / E100B]
<System32\DRIVERS\e100b325.sys><Intel Corporation>
[IBMPMDRV / IBMPMDRV]
<System32\DRIVERS\ibmpmdrv.sys><N/A>
[IBMTPCHK / IBMTPCHK]
<System32\drivers\IBMBLDID.SYS><N/A>
[ini910u / ini910u]
<\SystemRoot\System32\DRIVERS\ini910u.sys><Microsoft Corporation>
[Lucent Technologies Soft Modem / LucentSoftModem]
<System32\DRIVERS\LTSM.sys><Lucent Technologies>
[mraid35x / mraid35x]
<\SystemRoot\System32\DRIVERS\mraid35x.sys><American Megatrends Inc.>
[NAVENG / NAVENG]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061206.016\NAVENG.Sys><Symantec Corporation>
[NAVEX15 / NAVEX15]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061206.016\NavEx15.Sys><Symantec Corporation>
[NSC Infrared Device Driver / NSCIRDA]
<System32\DRIVERS\nscirda.sys><National Semiconductor Corporation>
[PMEM / PMEM]
<\??\C:\WINDOWS\system32\drivers\PMEMNT.SYS><Microsoft Corporation>
[Direct Parallel Link Driver / Ptilink]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20]
<\SystemRoot\System32\DRIVERS\PxHelp20.sys><VERITAS Software, Inc.>
[ql1080 / ql1080]
<\SystemRoot\System32\DRIVERS\ql1080.sys><QLogic Corporation>
[Ql10wnt / Ql10wnt]
<\SystemRoot\System32\DRIVERS\ql10wnt.sys><Microsoft Corporation>
[ql12160 / ql12160]
<\SystemRoot\System32\DRIVERS\ql12160.sys><QLogic Corporation>
[ql1280 / ql1280]
<\SystemRoot\System32\DRIVERS\ql1280.sys><QLogic Corporation>
[WLAN Transport / s24trans]
<System32\DRIVERS\s24trans.sys><Intel Corporation>
[S3SSavage / S3SSavage]
<System32\DRIVERS\s3ssavm.sys><S3 Graphics, Inc.>
[SAVRT / SAVRT]
<\??\C:\Program Files\Norton AntiVirus\SAVRT.SYS><Symantec Corporation>
[SAVRTPEL / SAVRTPEL]
<\??\C:\Program Files\Norton AntiVirus\SAVRTPEL.SYS><Symantec Corporation>
[Secdrv / Secdrv]
<System32\DRIVERS\secdrv.sys><N/A>
[SIS AGP Bus Filter / sisagp]
<\SystemRoot\System32\DRIVERS\sisagp.sys><Silicon Integrated Systems Corporation>
[Smapint / Smapint]
<System32\drivers\Smapint.sys><Microsoft Corporation>
[smwdm / smwdm]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[Sparrow / Sparrow]
<\SystemRoot\System32\DRIVERS\sparrow.sys><Adaptec, Inc.>
[sscdbhk5 / sscdbhk5]
<system32\drivers\sscdbhk5.sys><VERITAS Software, Inc.>
[ssrtln / ssrtln]
<system32\drivers\ssrtln.sys><VERITAS Software, Inc.>
[symc810 / symc810]
<\SystemRoot\System32\DRIVERS\symc810.sys><Symbios Logic Inc.>
[symc8xx / symc8xx]
<\SystemRoot\System32\DRIVERS\symc8xx.sys><LSI Logic>
[SymEvent / SymEvent]
<\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
[SYMREDRV / SYMREDRV]
<\SystemRoot\System32\Drivers\SYMREDRV.SYS><Symantec Corporation>
[SYMTDI / SYMTDI]
<\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
[sym_hi / sym_hi]
<\SystemRoot\System32\DRIVERS\sym_hi.sys><LSI Logic>
[sym_u3 / sym_u3]
<\SystemRoot\System32\DRIVERS\sym_u3.sys><LSI Logic>
[Synaptics TouchPad Driver / SynTP]
<System32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[TDSMAPI / TDSMAPI]
<System32\drivers\TDSMAPI.SYS><N/A>
[tfsnboio / tfsnboio]
<system32\dla\tfsnboio.sys><VERITAS Software, Inc.>
[tfsncofs / tfsncofs]
<system32\dla\tfsncofs.sys><VERITAS Software, Inc.>
[tfsndrct / tfsndrct]
<system32\dla\tfsndrct.sys><VERITAS Software, Inc.>
[tfsndres / tfsndres]
<system32\dla\tfsndres.sys><VERITAS Software, Inc.>
[tfsnifs / tfsnifs]
<system32\dla\tfsnifs.sys><VERITAS Software, Inc.>
[tfsnopio / tfsnopio]
<system32\dla\tfsnopio.sys><VERITAS Software, Inc.>
[tfsnpool / tfsnpool]
<system32\dla\tfsnpool.sys><VERITAS Software, Inc.>
[tfsnudf / tfsnudf]
<system32\dla\tfsnudf.sys><VERITAS Software, Inc.>
[tfsnudfa / tfsnudfa]
<system32\dla\tfsnudfa.sys><VERITAS Software, Inc.>
[TosIde / TosIde]
<\SystemRoot\System32\DRIVERS\toside.sys><Microsoft Corporation>
[TPHKDRV / TPHKDRV]
<C:\WINDOWS\SYSTEM32\DRIVERS\TPHKDRV.SYS><IBM Corporation>
[TPPWR / TPPWR]
<System32\drivers\Tppwr.sys><IBM Corp.>
[TSMAPIP / TSMAPIP]
<System32\drivers\TSMAPIP.SYS><N/A>
[IBM PS/2 TrackPoint Filter Driver / TwoTrack]
<System32\DRIVERS\TwoTrack.sys><IBM Corporation>
[ultra / ultra]
<\SystemRoot\System32\DRIVERS\ultra.sys><Promise Technology, Inc.>
sdlily - 2006-12-15 10:41:00
==================================
浏览器加载项
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Flashget Catch Url Class]
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <C:\PROGRA~1\FlashGet\jccatch.dll, www.flashget.com>
[IEHandle Class]
{31EBA2E2-58B2-4980-9C41-F12F5F1422C5} <C:\WINDOWS\System32\TPHANDLE.dll, 江苏科建教育软件有限责任公司>
[DriveLetterAccess]
{5CA3D70E-1895-11CF-8E15-001234567890} <C:\WINDOWS\system32\dla\tfswshx.dll, VERITAS Software, Inc.>
[]
{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} <C:\WINDOWS\system32\iifffda.dll, N/A>
[]
{91EA3723-B170-45CC-B7D7-1626225DD510} <C:\WINDOWS\System32\cbaxv.dll, N/A>
[Google Toolbar Helper]
{AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[CNavExtBho Class]
{BDF3E430-B101-42AD-A544-FADC6B084872} <C:\Program Files\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[gFlash Class]
{F156768E-81EF-470C-9057-481BA8380DBA} <C:\Program Files\FlashGet\getflash.dll, >
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[快车]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FlashGet\flashget.exe, FlashGet.com>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[Norton AntiVirus]
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} <C:\Program Files\Norton AntiVirus\NavShExt.dll, Symantec Corporation>
[快车(FlashGet)]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\Program Files\FlashGet\fgiebar.dll, Amaze Soft>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[AutoLive]
{7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2} <C:\Program Files\3721\Autolive.dll, >
[&使用快车(FlashGet)下载]
<C:\PROGRA~1\FlashGet\jc_link.htm, N/A>
[&使用快车(FlashGet)下载全部链接]
<C:\PROGRA~1\FlashGet\jc_all.htm, N/A>
[导出到 Microsoft Excel(&x)]
<res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000, N/A>
==================================
正在运行的进程
[PID: 816][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 872][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 896][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\System32\cbaxv.dll] [N/A, N/A]
[C:\WINDOWS\system32\iifffda.dll] [N/A, N/A]
[PID: 940][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 952][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1128][C:\WINDOWS\System32\ibmpmsvc.exe] [N/A, N/A]
[PID: 1188][C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe] [N/A, N/A]
[C:\Program Files\ThinkPad\Utilities\TpKmapHk.dll] [N/A, N/A]
[PID: 1196][C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe] [N/A, N/A]
[C:\Program Files\ThinkPad\Utilities\TpKmapHk.dll] [N/A, N/A]
[PID: 1224][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1372][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1460][C:\WINDOWS\System32\S24EvMon.exe] [Intel Corporation , 3.1.8.0]
[PID: 1672][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 188][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\System32\cbaxv.dll] [N/A, N/A]
[C:\WINDOWS\system32\iifffda.dll] [N/A, N/A]
[C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll] [IBM Corp., 1, 0, 0, 0]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[C:\Program Files\Support.com\bin\sdcidle.dll] [SupportSoft, 1, 0, 0, 4]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\PROGRA~1\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.0.2004121400]
[C:\PROGRA~1\FlashGet\jccatch.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\WINDOWS\system32\dla\tfswshx.dll] [VERITAS Software, Inc., 3.50.21a]
[C:\WINDOWS\System32\tfswapi.dll] [VERITAS Software, Inc., 3.50.21a]
[C:\WINDOWS\system32\dla\tfswcres.dll] [VERITAS Software, Inc., 3.50.21a]
[C:\Program Files\Norton AntiVirus\NavShExt.dll] [Symantec Corporation, 10.00.13]
[C:\PROGRA~1\WINZIP\WZSHLSTB.DLL] [WinZip Computing LP, 4.1 (32-bit)]
[PID: 584][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 916][C:\Program Files\Synaptics\SynTP\SynTPLpr.exe] [Synaptics, Inc., 7.2.3 29Jan03]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[PID: 1024][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] [Synaptics, Inc., 7.2.3 29Jan03]
[C:\WINDOWS\System32\SynTPAPI.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[PID: 1268][C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe] [N/A, N/A]
[C:\WINDOWS\system32\iifffda.dll] [N/A, N/A]
[C:\Program Files\ThinkPad\PkgMgr\HOTKEY_2\tphk_2k.dll] [N/A, N/A]
[C:\WINDOWS\System32\Oemdspif.dll] [ATI Technologies, Inc., 4.12.0007]
[PID: 1276][C:\WINDOWS\System32\RunDll32.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll] [IBM Corp., 1, 0, 0, 0]
[C:\PROGRA~1\ThinkPad\UTILIT~1\tppwrw32.dll] [IBM Corp., 1, 0, 0, 0]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[PID: 1296][C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe] [N/A, N/A]
[C:\Program Files\ThinkPad\Utilities\TpKmapHk.dll] [N/A, N/A]
[PID: 1304][C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe] [IBM Corp., 1, 0, 0, 0]
[PID: 1316][C:\WINDOWS\AGRSMMSG.exe] [Agere Systems, 2.1.20 2.1.20 10/18/2002 10:07:17]
[PID: 1400][C:\Program Files\Support.com\bin\tgcmd.exe] [SupportSoft, Inc., 5,8,136,0]
[C:\Program Files\Support.com\bin\2052\tglocale.dll] [N/A, N/A]
[C:\Program Files\Support.com\bin\sdcmon.dll] [SupportSoft, Inc., 5,8,136,0]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[C:\Program Files\Support.com\bin\sdcidle.dll] [SupportSoft, 1, 0, 0, 4]
[PID: 1432][C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe] [N/A, N/A]
[PID: 1484][C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe] [IBM Corporation, 1.06]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[PID: 1488][C:\WINDOWS\system32\dla\tfswctrl.exe] [VERITAS Software, Inc., 3.50.21a]
[C:\WINDOWS\System32\tfswapi.dll] [VERITAS Software, Inc., 3.50.21a]
[C:\WINDOWS\system32\dla\tfswcres.dll] [VERITAS Software, Inc., 3.50.21a]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[PID: 1528][C:\Program Files\IBM\Messages By IBM\ibmmessages.exe] [IBM, 1.058]
[C:\WINDOWS\System32\AIBMRUNL.dll] [N/A, N/A]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[PID: 1664][C:\Program Files\Common Files\Symantec Shared\ccApp.exe] [Symantec Corporation, 2.1.10.2]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[C:\Program Files\Symantec\LiveUpdate\ProductRegCom.DLL] [Symantec Corporation, 1.90.14.0]
[C:\Program Files\Symantec\LiveUpdate\LuComServerPS.DLL] [Symantec Corporation, 1.90.14.0]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 2.1.10.2]
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCALERT.DLL] [Symantec Corporation, 2.1.10.2]
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCEMLPXY.DLL] [Symantec Corporation, 2.1.10.2]
[C:\WINDOWS\System32\SYMREDIR.dll] [Symantec Corporation, 5.5.1.6]
[C:\PROGRA~1\NORTON~1\CCIMSCAN.DLL] [Symantec Corporation, 10.0.2.610]
[C:\PROGRA~1\NORTON~1\DEFALERT.DLL] [Symantec Corporation, 10.00.13]
[C:\PROGRA~1\NORTON~1\NAVAPW32.DLL] [Symantec Corporation, 10.00.13]
[C:\PROGRA~1\NORTON~1\apwutil.dll] [Symantec Corporation, 10.00.13]
[C:\PROGRA~1\NORTON~1\SAVRT32.DLL] [Symantec Corporation, ]
[C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 2.1.10.2]
[C:\Program Files\Norton AntiVirus\NAVOPTRF.DLL] [Symantec Corporation, 10.00.2]
[C:\Program Files\Common Files\Symantec Shared\ccProSub.dll] [Symantec Corporation, 2.1.10.2]
[C:\Program Files\Norton AntiVirus\apwcmdnt.dll] [Symantec Corporation, 10.00.13]
[C:\Program Files\Norton AntiVirus\NavEmail.dll] [Symantec Corporation, 10.0.2.610]
[C:\Program Files\Common Files\Symantec Shared\LiveReg\iraLSCl2.dll] [Symantec Corporation, 2.4.0.2044]
[C:\Program Files\Common Files\Symantec Shared\LiveReg\IraVcLc3.dll] [Symantec Corporation, 2.4.0.2044]
[C:\WINDOWS\system32\iifffda.dll] [N/A, N/A]
[C:\Program Files\Support.com\bin\sdcidle.dll] [SupportSoft, 1, 0, 0, 4]
[C:\PROGRA~1\NORTON~1\NAVOpts.dll] [Symantec Corporation, 10.00.13]
[C:\PROGRA~1\NORTON~1\N32Exclu.dll] [Symantec Corporation, 10.00.13]
[C:\PROGRA~1\NORTON~1\S32NAVO.DLL] [Symantec Corporation, 5.3.0.182]
[C:\Program Files\Norton AntiVirus\NAVError.dll] [Symantec Corporation, 10.00.13]
[C:\Program Files\Norton AntiVirus\NAVAPSCR.dll] [Symantec Corporation, 10.00.13]
sdlily - 2006-12-15 10:42:00
[C:\PROGRA~1\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\Program Files\Common Files\Symantec Shared\Script Blocking\scrauth.dll] [Symantec Corporation, 1, 1, 1, 131]
[C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll] [Symantec Corporation, 1, 1, 1, 131]
[PID: 1880][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3208]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[PID: 1912][C:\WINDOWS\System32\cdqz.exe] [N/A, N/A]
[PID: 1928][C:\WINDOWS\System32\mysvcc.exe] [N/A, N/A]
[C:\PROGRA~1\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[C:\WINDOWS\system32\iifffda.dll] [N/A, N/A]
[PID: 1936][C:\WINDOWS\System32\svcchost.exe] [N/A, N/A]
[PID: 2016][C:\WINDOWS\system32\mfcee.exe] [N/A, N/A]
[PID: 176][C:\DOCUME~1\li_ping\LOCALS~1\Temp\ztt.exe] [N/A, N/A]
[C:\DOCUME~1\li_ping\LOCALS~1\Temp\zts2.dll] [N/A, N/A]
[PID: 1216][C:\WINDOWS\system32\sysem.exe] [N/A, N/A]
[PID: 532][C:\WINDOWS\system32\ssrvc.exe] [N/A, N/A]
[PID: 660][C:\WINDOWS\System32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[C:\PROGRA~1\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[PID: 1236][C:\Program Files\Messenger\msmsgs.exe] [Microsoft Corporation, 4.7.0041]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[C:\WINDOWS\System32\msdmo.dll] [N/A, N/A]
[C:\PROGRA~1\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[PID: 840][C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe] [Google Inc., 1, 2, 908, 5008]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\res_zh-CN.dll] [Google Inc., 1, 2, 908, 5008]
[C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\swg.dll] [Google Inc., 1, 2, 908, 5008]
[PID: 1968][C:\WINDOWS\system32\mfcee.exe] [N/A, N/A]
[PID: 1984][C:\WINDOWS\system32\sysem.exe] [N/A, N/A]
[PID: 356][C:\WINDOWS\system32\ssrvc.exe] [N/A, N/A]
[PID: 752][C:\Program Files\WinZip\WZQKPICK.EXE] [WinZip Computing LP, 1.0 (32-bit)]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[PID: 2324][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2364][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 2380][C:\WINDOWS\System32\Ati2evxx.exe] [N/A, N/A]
[PID: 2412][C:\Program Files\Norton AntiVirus\navapsvc.exe] [Symantec Corporation, 10.00.2]
[C:\Program Files\Norton AntiVirus\SAVRT32.DLL] [Symantec Corporation, ]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 2.1.10.2]
[PID: 3712][C:\WINDOWS\System32\QCONSVC.EXE] [N/A, N/A]
[PID: 3980][C:\WINDOWS\System32\RegSrvc.exe] [Intel Corporation, 4, 0, 0, 1]
[PID: 2592][C:\Program Files\Norton AntiVirus\SAVScan.exe] [Symantec Corporation, ]
[C:\Program Files\Norton AntiVirus\SAVRT32.DLL] [Symantec Corporation, ]
[C:\Program Files\Common Files\Symantec Shared\ccScan.dll] [Symantec Corporation, 2.1.10.2]
[C:\Program Files\Common Files\Symantec Shared\ecmldr32.DLL] [Symantec Corporation, 51.2.0.12]
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061206.016\ecmsvr32.dll] [Symantec Corporation, 61.3.0.18]
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061206.016\NAVEX32a.DLL] [Symantec Corporation, 20061.3.0.12]
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061206.016\NAVENG32.DLL] [Symantec Corporation, 20061.3.0.12]
[C:\Program Files\Norton AntiVirus\NAVAP32.DLL] [Symantec Corporation, ]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\DECSDK.DLL] [Symantec Corporation, 3.02.14.08]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll] [Symantec Corporation, 3.02.14.08]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll] [Symantec Corporation, 3.02.14.08]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll] [Symantec Corporation, 3.02.14.08]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll] [Symantec Corporation, 3.02.14.08]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll] [Symantec Corporation, 3.02.14.08]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll] [Symantec Corporation, 3.02.14.08]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll] [Symantec Corporation, 3.02.14.08]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll] [Symantec Corporation, 3.02.14.08]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll] [Symantec Corporation, 3.02.14.08]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll] [Symantec Corporation, 3.02.14.08]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll] [Symantec Corporation, 3.02.14.08]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll] [Symantec Corporation, 3.02.14.08]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll] [Symantec Corporation, 3.02.14.08]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll] [Symantec Corporation, 3.02.14.08]
[C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll] [Symantec Corporation, 3.02.14.08]
[PID: 3104][C:\WINDOWS\System32\conime.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\PROGRA~1\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[PID: 2644][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[C:\PROGRA~1\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1020, 3054]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.0.2004121400]
[C:\PROGRA~1\FlashGet\jccatch.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\WINDOWS\System32\TPHANDLE.dll] [江苏科建教育软件有限责任公司, 5, 0, 10, 10]
[C:\WINDOWS\system32\dla\tfswshx.dll] [VERITAS Software, Inc., 3.50.21a]
[C:\WINDOWS\System32\tfswapi.dll] [VERITAS Software, Inc., 3.50.21a]
[C:\WINDOWS\system32\dla\tfswcres.dll] [VERITAS Software, Inc., 3.50.21a]
[C:\WINDOWS\system32\iifffda.dll] [N/A, N/A]
[C:\WINDOWS\System32\cbaxv.dll] [N/A, N/A]
[C:\Program Files\Norton AntiVirus\NavShExt.dll] [Symantec Corporation, 10.00.13]
[C:\Program Files\FlashGet\getflash.dll] [, 1, 0, 0, 1]
[C:\Program Files\Support.com\bin\sdcidle.dll] [SupportSoft, 1, 0, 0, 4]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\Program Files\Common Files\Symantec Shared\Script Blocking\scrauth.dll] [Symantec Corporation, 1, 1, 1, 131]
[C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll] [Symantec Corporation, 1, 1, 1, 131]
[C:\WINDOWS\System32\PUTIWBX.IME] [中华佛典宝库, 6.0.2005.02]
[C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[PID: 2456][C:\WINDOWS\System32\cmd.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 300][C:\WINDOWS\system32\ftp.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 2284][C:\WINDOWS\system32\notepad.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\PROGRA~1\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[C:\Program Files\Support.com\bin\sdcidle.dll] [SupportSoft, 1, 0, 0, 4]
[PID: 1728][C:\WINDOWS\System32\taskmgr.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\PROGRA~1\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[PID: 4044][C:\WINDOWS\System32\taskmgr.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\PROGRA~1\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[PID: 684][C:\WINDOWS\System32\taskmgr.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\PROGRA~1\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[PID: 2188][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 3100][C:\Documents and Settings\li_ping\My Documents\日志文件\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\PROGRA~1\FlashGet\fgmgr.dll] [www.flashget.com, 1, 8, 0, 1001]
[C:\WINDOWS\System32\SynTPFcs.dll] [Synaptics, Inc., 7.2.3 29Jan03]
[C:\Program Files\Support.com\bin\sdcidle.dll] [SupportSoft, 1, 0, 0, 4]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
© 2000 - 2026 Rising Corp. Ltd.