月黑风高夜 - 2007-1-29 9:10:00
以下是扫描后的文档:
[CODE]
2007-01-29,08:42:06
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<TrackPointSrv><tp4serv.exe> [(Verified)IBM Corporation]
<AtiPTA><Atiptaxx.exe> [(Verified)ATI Technologies, Inc.]
<DAEMON Tools-2052><"C:\Program Files\D-Tools\daemon.exe" -lang 2052> [DAEMON'S HOME]
<runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe> [Beijing Rising Technology Co., Ltd.]
<wsttr><C:\WINDOWS\wsttr.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{1A404685-7563-4d02-B0F6-58B308A406A9}><c:\program files\d-tools\umolxfwz.dll> [N/A]
==================================
启动文件夹
[AutoCAD 启动加速器]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\AutoCAD 启动加速器.lnk --> C:\PROGRA~1\COMMON~1\AUTODE~1\ACSTAR~1.EXE [Autodesk, Inc]><N>
[EPSON Status Monitor 3 Environment Check(3)]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\EPSON Status Monitor 3 Environment Check(3).lnk --> C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE [SEIKO EPSON CORPORATION]><N>
[Microsoft Office]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk --> D:\PROGRA~1\MICROS~1\Office10\OSA.EXE [Microsoft Corporation]><N>
==================================
服务
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
<C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
<C:\WINDOWS\System32\ati2evxx.exe><N/A>
[Autodesk Licensing Service / Autodesk Licensing Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><Autodesk, Inc.>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[IMAPI CD-Burning COM Service / ImapiService][Stopped/Manual Start]
<C:\WINDOWS\System32\imapi.exe><Microsoft Corporation>
[Win32 Display Driver / Win32DDS][Stopped/Auto Start]
<C:\WINDOWS\System32\\rundll32.exe windds32.dll,input><Microsoft Corporation>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<C:\WINDOWS\System32\\rundll32.exe windhcp.ocx,input><Microsoft Corporation>
[WinXP DHCP Service / WinXPDHCPsvc][Stopped/Auto Start]
<C:\WINDOWS\System32\\rundll32.exe xpdhcp.dll,input><Microsoft Corporation>
==================================
驱动程序
[ati2mpab / ati2mpab][Running/Manual Start]
<System32\DRIVERS\ati2mpab.sys><ATI Technologies Inc.>
[atimpab / atimpab][Stopped/Manual Start]
<System32\DRIVERS\atimpab.sys><ATI Technologies Inc.>
[d347bus / d347bus][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\d347bus.sys><>
[d347prt / d347prt][Running/Boot Start]
<\SystemRoot\System32\Drivers\d347prt.sys><>
[Intel(R) PRO Adapter Driver / E100B][Running/Manual Start]
<System32\DRIVERS\e100b325.sys><Intel Corporation>
[LT Modem Driver / ltmodem5][Running/Manual Start]
<System32\DRIVERS\ltmdmnt.sys><LT>
[ESS Maestro2E Audio Driver (WDM) / Maestro][Running/Manual Start]
<system32\drivers\maestro.sys><ESS Technology, Inc.>
[StarForce Protection Environment Driver v6 / prodrv06][Running/System Start]
<\SystemRoot\System32\drivers\prodrv06.sys><Protection Technology>
[StarForce Protection Helper Driver v2 / prohlp02][Running/Boot Start]
<\SystemRoot\System32\drivers\prohlp02.sys><Protection Technology>
[StarForce Protection Synchronization Driver v1 / prosync1][Running/Boot Start]
<\SystemRoot\System32\drivers\prosync1.sys><Protection Technology>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Secdrv / Secdrv][Stopped/Manual Start]
<System32\DRIVERS\secdrv.sys><N/A>
[StarForce Protection Helper Driver / sfhlp01][Running/Boot Start]
<\SystemRoot\System32\drivers\sfhlp01.sys><Protection Technology>
[SMC IrCC Miniport Device Driver / SMCIRDA][Running/Manual Start]
<System32\DRIVERS\smcirda.sys><SMC>
[EasyPoint IV Driver / Tp4Track][Running/Manual Start]
<System32\DRIVERS\tp4track.sys><IBM Corporation>
==================================
浏览器加载项
[]
{A692062A-11A1-461B-BE99-B520F01F9DAE} <c:\baidu.ini, N/A>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[导出到 Microsoft Excel(&x)]
<res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000, N/A>
月黑风高夜 - 2007-1-29 9:11:00
==================================
正在运行的进程
[PID: 408][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 472][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 496][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.149 (xpclnt_qfe.021108-2107)]
[c:\program files\d-tools\umolxfwz.dll] [, 1, 0, 0, 11]
[PID: 540][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 552][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 716][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 752][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 832][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 844][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1068][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 1164][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1184][C:\WINDOWS\System32\ati2evxx.exe] [N/A, N/A]
[PID: 2032][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2600.0000 (xpclient.010817-1148)]
[C:\WINDOWS\System32\windds32.dll] [N/A, N/A]
[C:\WINDOWS\System32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\System32\xpdhcp.dll] [N/A, N/A]
[C:\WINDOWS\System32\AcSignIcon.dll] [Autodesk, 16.1.63.0]
[c:\program files\d-tools\umolxfwz.dll] [, 1, 0, 0, 11]
[C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] [Autodesk, 16.1.63.0]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\WINDOWS\System32\wsttr.dll] [N/A, N/A]
[d:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[c:\baidu.ini] [N/A, N/A]
[PID: 356][C:\WINDOWS\System32\tp4serv.exe] [IBM Corporation, 2.05]
[C:\WINDOWS\System32\windds32.dll] [N/A, N/A]
[C:\WINDOWS\System32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\System32\xpdhcp.dll] [N/A, N/A]
[C:\WINDOWS\System32\tp4uires.dll] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 368][C:\WINDOWS\System32\Atiptaxx.exe] [ATI Technologies, Inc., 6.13.2518]
[C:\WINDOWS\System32\windds32.dll] [N/A, N/A]
[C:\WINDOWS\System32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\System32\xpdhcp.dll] [N/A, N/A]
[C:\WINDOWS\System32\ATRPUIXX.CHS] [ATI Technologies, Inc., 6.13.2518]
[C:\WINDOWS\System32\atipdsxx.dll] [ATI Technologies, Inc., 6.13.2518]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 380][C:\Program Files\D-Tools\daemon.exe] [DAEMON'S HOME, 3.47.0.0]
[C:\WINDOWS\System32\windds32.dll] [N/A, N/A]
[C:\WINDOWS\System32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\System32\xpdhcp.dll] [N/A, N/A]
[C:\WINDOWS\daemon.dll] [N/A, 3.47.0.0]
[C:\Program Files\D-Tools\PFCTOC.DLL] [Padus(R), Inc., 1, 0, 0, 12]
[C:\Program Files\D-Tools\Plugins\Images\bw5mount.dll] [N/A, 1.0.2.0]
[C:\Program Files\D-Tools\Plugins\Images\ccdmount.dll] [GENERIC, 1.02.0.0]
[C:\Program Files\D-Tools\Plugins\Images\mdsmount.dll] [GENERIC, 1.01.0.0]
[C:\Program Files\D-Tools\Plugins\Images\nrgmount.dll] [GENERIC, 1.02.0.0]
[C:\Program Files\D-Tools\Plugins\Images\pdimount.dll] [GENERIC, 1.01.0.0]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 392][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
[C:\WINDOWS\System32\windds32.dll] [N/A, N/A]
[C:\WINDOWS\System32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\System32\xpdhcp.dll] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 192][C:\WINDOWS\System32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\windds32.dll] [N/A, N/A]
[C:\WINDOWS\System32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\System32\xpdhcp.dll] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 456][D:\TdxWRemote_Huatai\TDXW.EXE] [, ]
[D:\TdxWRemote_Huatai\TCalc.dll] [, 1, 0, 0, 1]
[D:\TdxWRemote_Huatai\Viewthem.dll] [, 1, 0, 0, 1]
[D:\TdxWRemote_Huatai\invest.dll] [, 1.15]
[D:\TdxWRemote_Huatai\Dbf.dll] [N/A, N/A]
[D:\TdxWRemote_Huatai\Secure.dll] [通达信, 1.00.00]
[D:\TdxWRemote_Huatai\TList.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\System32\windds32.dll] [N/A, N/A]
[C:\WINDOWS\System32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\System32\xpdhcp.dll] [N/A, N/A]
[D:\TdxWRemote_Huatai\calcer.dll] [, 1, 0, 0, 1]
[D:\TdxWRemote_Huatai\Advhq.dll] [, 1, 0, 0, 1]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[D:\TdxWRemote_Huatai\commdll.dll] [杭州核新软件技术有限公司, 2001, 10, 15, 2]
[D:\TdxWRemote_Huatai\tcpip.dll] [杭州核新软件技术有限公司, 2005, 8, 18, 0]
[D:\TdxWRemote_Huatai\xiadan.dll] [核新软件技术有限公司, 2006, 7, 24, 0]
[D:\TdxWRemote_Huatai\VirusScan.dll] [上海核新软件技术有限公司, 2006, 3, 8, 0]
[PID: 1584][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2600.0000 (xpclient.010817-1148)]
[C:\WINDOWS\System32\windds32.dll] [N/A, N/A]
[C:\WINDOWS\System32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\System32\xpdhcp.dll] [N/A, N/A]
[C:\WINDOWS\System32\AcSignIcon.dll] [Autodesk, 16.1.63.0]
[c:\baidu.ini] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\WINDOWS\System32\UNISPIM.IME] [北京清华紫光软件股份有限公司, 3.0.0.3045]
[C:\WINDOWS\System32\upengine.dll] [北京清华紫光软件股份有限公司, 3.0.0.3045]
[D:\PROGRA~1\CHINAG~1\iGame\flash.ocx] [Macromedia, Inc., 7,0,19,0]
[C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] [Autodesk, 16.1.63.0]
[PID: 1852][E:\hacker\sreng2\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\WINDOWS\System32\windds32.dll] [N/A, N/A]
[C:\WINDOWS\System32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\System32\xpdhcp.dll] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
[/CODE]
月黑风高夜 - 2007-1-31 10:18:00
感谢秋日里的蓝天!
昨天经过处理后,今天依旧弹出秀逗。老实说机器的运行速度快了点。
再次扫描上传:
[CODE]
2007-01-31,09:58:11
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<TrackPointSrv><tp4serv.exe> [(Verified)IBM Corporation]
<AtiPTA><Atiptaxx.exe> [(Verified)ATI Technologies, Inc.]
<DAEMON Tools-2052><"C:\Program Files\D-Tools\daemon.exe" -lang 2052> [DAEMON'S HOME]
<runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
==================================
启动文件夹
[AutoCAD 启动加速器]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\AutoCAD 启动加速器.lnk --> C:\PROGRA~1\COMMON~1\AUTODE~1\ACSTAR~1.EXE [Autodesk, Inc]><N>
[EPSON Status Monitor 3 Environment Check(3)]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\EPSON Status Monitor 3 Environment Check(3).lnk --> C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE [SEIKO EPSON CORPORATION]><N>
[Microsoft Office]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk --> D:\PROGRA~1\MICROS~1\Office10\OSA.EXE [Microsoft Corporation]><N>
==================================
服务
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
<C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
<C:\WINDOWS\System32\ati2evxx.exe><N/A>
[Autodesk Licensing Service / Autodesk Licensing Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><Autodesk, Inc.>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[IMAPI CD-Burning COM Service / ImapiService][Stopped/Manual Start]
<C:\WINDOWS\System32\imapi.exe><Microsoft Corporation>
==================================
驱动程序
[ati2mpab / ati2mpab][Running/Manual Start]
<System32\DRIVERS\ati2mpab.sys><ATI Technologies Inc.>
[atimpab / atimpab][Stopped/Manual Start]
<System32\DRIVERS\atimpab.sys><ATI Technologies Inc.>
[d347bus / d347bus][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\d347bus.sys><>
[d347prt / d347prt][Running/Boot Start]
<\SystemRoot\System32\Drivers\d347prt.sys><>
[Intel(R) PRO Adapter Driver / E100B][Running/Manual Start]
<System32\DRIVERS\e100b325.sys><Intel Corporation>
[LT Modem Driver / ltmodem5][Running/Manual Start]
<System32\DRIVERS\ltmdmnt.sys><LT>
[ESS Maestro2E Audio Driver (WDM) / Maestro][Running/Manual Start]
<system32\drivers\maestro.sys><ESS Technology, Inc.>
[StarForce Protection Environment Driver v6 / prodrv06][Running/System Start]
<\SystemRoot\System32\drivers\prodrv06.sys><Protection Technology>
[StarForce Protection Helper Driver v2 / prohlp02][Running/Boot Start]
<\SystemRoot\System32\drivers\prohlp02.sys><Protection Technology>
[StarForce Protection Synchronization Driver v1 / prosync1][Running/Boot Start]
<\SystemRoot\System32\drivers\prosync1.sys><Protection Technology>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Secdrv / Secdrv][Stopped/Manual Start]
<System32\DRIVERS\secdrv.sys><N/A>
[StarForce Protection Helper Driver / sfhlp01][Running/Boot Start]
<\SystemRoot\System32\drivers\sfhlp01.sys><Protection Technology>
[SMC IrCC Miniport Device Driver / SMCIRDA][Running/Manual Start]
<System32\DRIVERS\smcirda.sys><SMC>
[EasyPoint IV Driver / Tp4Track][Running/Manual Start]
<System32\DRIVERS\tp4track.sys><IBM Corporation>
月黑风高夜 - 2007-1-31 10:19:00
==================================
浏览器加载项
[]
{A692062A-11A1-461B-BE99-B520F01F9DAE} <c:\baidu.ini, N/A>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[导出到 Microsoft Excel(&x)]
<res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000, N/A>
==================================
正在运行的进程
[PID: 408][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 464][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 488][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.149 (xpclnt_qfe.021108-2107)]
[PID: 532][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 544][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 704][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 740][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 820][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 832][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1052][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 1148][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1164][C:\WINDOWS\System32\ati2evxx.exe] [N/A, N/A]
[PID: 144][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2600.0000 (xpclient.010817-1148)]
[C:\WINDOWS\System32\AcSignIcon.dll] [Autodesk, 16.1.63.0]
[C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] [Autodesk, 16.1.63.0]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\WINDOWS\System32\UNISPIM.IME] [北京清华紫光软件股份有限公司, 3.0.0.3045]
[C:\WINDOWS\System32\upengine.dll] [北京清华紫光软件股份有限公司, 3.0.0.3045]
[c:\baidu.ini] [N/A, N/A]
[PID: 332][C:\WINDOWS\System32\tp4serv.exe] [IBM Corporation, 2.05]
[C:\WINDOWS\System32\tp4uires.dll] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 344][C:\WINDOWS\System32\Atiptaxx.exe] [ATI Technologies, Inc., 6.13.2518]
[C:\WINDOWS\System32\ATRPUIXX.CHS] [ATI Technologies, Inc., 6.13.2518]
[C:\WINDOWS\System32\atipdsxx.dll] [ATI Technologies, Inc., 6.13.2518]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 352][C:\Program Files\D-Tools\daemon.exe] [DAEMON'S HOME, 3.47.0.0]
[C:\WINDOWS\daemon.dll] [N/A, 3.47.0.0]
[C:\Program Files\D-Tools\PFCTOC.DLL] [Padus(R), Inc., 1, 0, 0, 12]
[C:\Program Files\D-Tools\Plugins\Images\bw5mount.dll] [N/A, 1.0.2.0]
[C:\Program Files\D-Tools\Plugins\Images\ccdmount.dll] [GENERIC, 1.02.0.0]
[C:\Program Files\D-Tools\Plugins\Images\mdsmount.dll] [GENERIC, 1.01.0.0]
[C:\Program Files\D-Tools\Plugins\Images\nrgmount.dll] [GENERIC, 1.02.0.0]
[C:\Program Files\D-Tools\Plugins\Images\pdimount.dll] [GENERIC, 1.01.0.0]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 368][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
[C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 376][C:\WINDOWS\System32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 988][E:\hacker\sreng2\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
[/CODE]
© 2000 - 2026 Rising Corp. Ltd.