KAMAO - 2007-2-20 17:25:00
[CODE]
2007-02-20,17:06:00
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<internat.exe><internat.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
==================================
启动文件夹
[OFF]
<C:\Documents and Settings\WangJiWei\「开始」菜单\程序\启动\OFF.lnk --> C:\PROGRA~1\ARP绑~1\offarp.EXE [常州诚信网络技术联盟 QQ:535495 QQ群:1577517 ]><N>
==================================
服务
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[McAfee Framework 服务 / McAfeeFramework][Stopped/Manual Start]
<C:\Program Files\Network Associates\Common Framework\FrameworkService.exe /ServiceStart><Network Associates, Inc.>
[Network Associates McShield / McShield][Stopped/Manual Start]
<"C:\Program Files\Network Associates\VirusScan\mcshield.exe"><Network Associates, Inc.>
[Network Associates Task Manager / McTaskManager][Stopped/Manual Start]
<"C:\Program Files\Network Associates\VirusScan\vstskmgr.exe"><Network Associates, Inc.>
[Remote Administrator Service / r_server][Running/Auto Start]
<"C:\Program Files\radmin3.2\r_server.exe" /service><N/A>
[WatcherService / WatcherService][Running/Auto Start]
<C:\Watcher\WATCHE~1.EXE><N/A>
KAMAO - 2007-2-20 17:26:00
==================================
驱动程序
[ADI UAA Function Driver for High Definition Audio Service / ADIHdAudAddService][Running/Manual Start]
<system32\drivers\ADIHdAud.sys><Analog Devices, Inc.>
[AEAudio Service / AEAudioService][Running/Manual Start]
<system32\drivers\AEAudio.sys><Andrea Electronics Corporation>
[ati2mtag / ati2mtag][Running/Manual Start]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Broadcom 440x 10/100 Integrated Controller XP Driver / bcm4sbxp][Stopped/Manual Start]
<system32\DRIVERS\bcm4sbxp.sys><Broadcom Corporation>
[genfs / genfs][Running/Boot Start]
<2 - 系统找不到指定的文件。
><N/A>
[Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService][Stopped/Manual Start]
<system32\drivers\HdAudio.sys><Windows (R) Server 2003 DDK provider>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[NaiAvFilter1 / NaiAvFilter1][Stopped/Manual Start]
<system32\drivers\naiavf5x.sys><Network Associates, Inc.>
[NaiAvTdi1 / NaiAvTdi1][Running/System Start]
<system32\drivers\mvstdi5x.sys><Network Associates, Inc.>
[Netgroup Packet Filter / NPF][Running/Manual Start]
<system32\drivers\npf.sys><CACE Technologies>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\E:\Program Files\IPQQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Running/Manual Start]
<system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[SenFilt Service / SenFiltService][Running/Manual Start]
<system32\drivers\Senfilt.sys><Sensaura>
[sptd / sptd][Running/Boot Start]
<\SystemRoot\System32\Drivers\sptd.sys><N/A>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[VIMICRO USB PC Camera / ZSMC302][Stopped/Manual Start]
<System32\Drivers\usbVM31b.sys><VM>
[VIMICRO USB PC Camera (ZC0301PLH) / ZSMC303][Running/Manual Start]
<System32\Drivers\usbVM303.sys><Vimicro Corporation>
==================================
浏览器加载项
[BHOImp Class]
{70AFF2CB-9DA2-499C-8D15-900729FCE83D} <C:\WINDOWS\system32\YHBO.dll, YHBO>
[ThunderMini Browser Helper]
{8E6C1C49-F9CE-4311-9FB4-D70E8B0AEAEB} <C:\Program Files\Thunder Network\ThunderMini\ComDlls\XunLeiMiniBHO_001.dll, Thunder Networking Technologies,LTD>
[金山快译(&K)]
{6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <D:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll, 金山软件股份有限公司>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[BHOImp Class]
{70AFF2CB-9DA2-499C-8D15-900729FCE83D} <C:\WINDOWS\system32\YHBO.dll, YHBO>
[ThunderMini Browser Helper]
{8E6C1C49-F9CE-4311-9FB4-D70E8B0AEAEB} <C:\Program Files\Thunder Network\ThunderMini\ComDlls\XunLeiMiniBHO_001.dll, Thunder Networking Technologies,LTD>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[&使用迷你迅雷下载]
<C:\Program Files\Thunder Network\ThunderMini\Program\GetUrl.htm, N/A>
[上传到QQ网络硬盘]
<E:\Program Files\IPQQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<E:\Program Files\IPQQ\AddPanel.htm, N/A>
[添加到QQ表情]
<E:\Program Files\IPQQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<E:\Program Files\IPQQ\SendMMS.htm, N/A>
KAMAO - 2007-2-20 17:26:00
==================================
正在运行的进程
[PID: 432][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 480][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 508][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4132]
[C:\Watcher\APIHook_Dll.dll] [N/A, N/A]
[PID: 552][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 564][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 704][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4132]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2500]
[C:\Watcher\APIHook_Dll.dll] [N/A, N/A]
[PID: 732][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 804][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 988][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1424][C:\Program Files\radmin3.2\r_server.exe] [N/A, N/A]
[C:\Program Files\radmin3.2\ADMDLL.dll] [N/A, N/A]
[PID: 1444][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1464][C:\Watcher\WATCHE~1.EXE] [N/A, N/A]
[PID: 1496][C:\Watcher\ClientOfWatcher.exe] [N/A, N/A]
[C:\Watcher\ProgDataEngine.dll] [, 1, 0, 0, 1]
[C:\Watcher\APIHook_Dll.dll] [N/A, N/A]
[PID: 1544][C:\Watcher\ClientPro.exe] [, 1, 0, 0, 1]
[C:\Watcher\APIHook_Dll.dll] [N/A, N/A]
[PID: 1868][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 980][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4132]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2500]
[C:\Watcher\APIHook_Dll.dll] [N/A, N/A]
[PID: 1264][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Watcher\APIHook_Dll.dll] [N/A, N/A]
[C:\Program Files\Thunder Network\ThunderMini\ComDlls\XunLeiMiniBHO_001.dll] [Thunder Networking Technologies,LTD, 2, 0, 0, 1]
[PID: 1916][C:\WINDOWS\system32\internat.exe] [Microsoft Corporation, 5.00.2920.0000]
[C:\Watcher\APIHook_Dll.dll] [N/A, N/A]
[PID: 1736][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Watcher\APIHook_Dll.dll] [N/A, N/A]
[PID: 240][\\mingyun\tools\工具\sreng2\SREng.EXE] [N/A, N/A]
[C:\Watcher\APIHook_Dll.dll] [N/A, N/A]
[\\mingyun\tools\工具\sreng2\Plugins\SRECXTMG.SRE] [N/A, N/A]
[PID: 1072][C:\Program Files\xpmanager5.0_psgl\WinXP Manager.exe] [Yamicsoft, 5.0.0.0]
[C:\Program Files\xpmanager5.0_psgl\PCL.dll] [ , 1.0.0.0]
[C:\Watcher\APIHook_Dll.dll] [N/A, N/A]
[C:\Program Files\xpmanager5.0_psgl\BalloonTip.dll] [ , 1.0.1787.15773]
[C:\Program Files\xpmanager5.0_psgl\DevComponents.DotNetBar.dll] [DevComponents.com, 5.0.0.0]
[PID: 1696][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1344][C:\Program Files\xpmanager5.0_psgl\ProcessManager.exe] [Yamicsoft, 6.1.0.0]
[C:\Program Files\xpmanager5.0_psgl\DevComponents.DotNetBar.dll] [DevComponents.com, 5.0.0.0]
[C:\Program Files\xpmanager5.0_psgl\DevExpress.XtraTreeList3.dll] [Developer Express Inc., 1.11.1.0]
[C:\Program Files\xpmanager5.0_psgl\DevExpress.XtraEditors3.dll] [Developer Express Inc., 3.2.1.0]
[C:\Program Files\xpmanager5.0_psgl\DevExpress.Utils3.dll] [Developer Express Inc., 3.2.1.0]
[C:\Program Files\xpmanager5.0_psgl\Tracker.dll] [ , 1.0.844.28400]
[C:\Program Files\xpmanager5.0_psgl\PCL.dll] [ , 1.0.0.0]
[C:\Watcher\APIHook_Dll.dll] [N/A, N/A]
[PID: 952][C:\Program Files\xpmanager5.0_psgl\ServiceManager.exe] [Yamicsoft, 5.0.0.0]
[C:\Program Files\xpmanager5.0_psgl\DevComponents.DotNetBar.dll] [DevComponents.com, 5.0.0.0]
[C:\Program Files\xpmanager5.0_psgl\PCL.dll] [ , 1.0.0.0]
[C:\Watcher\APIHook_Dll.dll] [N/A, N/A]
[C:\Program Files\xpmanager5.0_psgl\ServiceControllerEx.dll] [ , 1.0.1673.22953]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS Error. ["d:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe" "%1"]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1download.3721.com
127.0.0.1cn.download.yahoo.com
127.0.0.1cn.download.zs.yahoo.com
127.0.0.1download.yisou.com127.0.0.1download.3721.com
127.0.0.1cn.download.yahoo.com
127.0.0.1cn.download.zs.yahoo.com
127.0.0.1download.yisou.com
==================================
API HOOK
N/A
==================================
[/CODE]
© 2000 - 2026 Rising Corp. Ltd.