sreng2扫描
启动项目
注册表
[hkey_current_user\software\microsoft\windows\currentversion\run]
<ctfmon.exe><c:\windows\system32\ctfmon.exe> [(verified)microsoft windows publisher]
<bgswitch><c:\windows\system32\bgswitch.exe> []
<nokia.pcsync><"c:\program files\nokia\nokia pc suite 6\pcsync2.exe" /nodialog> [time information services ltd.]
<pc suite tray><"c:\program files\nokia\nokia pc suite 6\pcsuite.exe" -onlytray> [nokia]
[hkey_current_user\software\microsoft\windows\currentversion\runonce]
<flashplayerupdate><c:\windows\system32\macromed\flash\flashutil9e.exe> [(verified)adobe systems incorporated]
[hkey_local_machine\software\microsoft\windows\currentversion\run]
<ravtask><"d:\瑞星\rising\rav\ravtask.exe" -system> [(verified)beijing rising science and technology corporation limited]
<rfwmain><"d:\瑞星\rising\rfw\rfwmain.exe" -startup> [(verified)beijing rising science and technology corporation limited]
<runeip><"c:\program files\rising\antispyware\runiep.exe" /startup> [beijing rising technology co., ltd.]
<tkbellexe><"c:\program files\common files\real\update_ob\realsched.exe" -osboot> [(verified)"realnetworks, inc."]
<bigdogpath><c:\windows\vm_sti.exe vimicro usb pc camera> [n/a]
<zssnp211><c:\windows\zssnp211.exe> [zsmc]
<domino><c:\windows\domino.exe> []
<msprint32d><c:\windows\msprint32d.exe> [n/a]
<grid service><"c:\program files\gridservice\peer.exe" -n grid> [mercury]
[hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon]
<shell><explorer.exe> [(verified)microsoft windows publisher]
<userinit><c:\windows\system32\userinit.exe,> [(verified)microsoft windows publisher]
[hkey_local_machine\software\microsoft\windows nt\currentversion\windows]
<appinit_dlls><womsoy.dll,yzztkmsn.dll,arjreler.dll,tisqatyu.dll,nhmxcjkl.dll,ietzbpaq.dll,akjsdkaq.dll> []
[hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon]
<uihost><logonui.exe> [(verified)microsoft windows publisher]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
<{32cd708b-60a7-4c00-9377-d73eaa495f0f}><c:\windows\system32\ravext.dll> [(verified)beijing rising science and technology corporation limited]
<{ac2dc2ef-5165-40a3-8cdf-41dca1b0901a}><c:\windows\system32\shlhook.dll> [beijing rising technology co., ltd.]
<{fd561258-45f3-a451-f908-a258458226df}><c:\windows\fonts\kvdxsoma.dll> [n/a]
<{a8907901-1416-3389-9981-37217856998a}><c:\windows\fonts\kawdjzy.dll> [n/a]
<{a9895933-6636-4281-bc58-ee6de2af96e3}><c:\windows\system32\ddserh.dll> []
<{c0595a7e-2e2f-4b34-a83a-019270a0a464}><c:\windows\system32\tdffdl.dll> []
<{dc3d30ae-0380-4151-8934-ee98a34b0370}><c:\windows\system32\mfdesy.dll> []
<{eb71e0b3-e97d-4d30-8733-e28266467617}><c:\windows\system32\wyhesm.dll> []
<{00010001-0001-0001-0001-00010001bb15}><c:\windows\system32\adsntzt.dll> []
<{6e6ca8a1-81bc-4707-a54c-f4903dd70bad}><c:\windows\system32\zgxfdx.dll> []
<{45aadfaa-dd36-42ab-83ad-0521bbf58c24}><c:\windows\system32\zgrjdx.dll> []
<{8c41b7f7-3168-400d-a702-0e7efe0ba304}><c:\windows\system32\sgdewg.dll> []
<{17dfd111-bf3a-4cb4-adb0-88fcbfe69821}><c:\windows\system32\hhrdxd.dll> []
<{841529cb-7f77-4b99-a895-b5441e0d302f}><c:\windows\system32\jfrwdh.dll> []
<{7c8d1401-a58d-a81c-cd24-a5915c4517c7}><c:\windows\system32\mnmhgsrv.dll> []
<{f99defdd-200b-4410-b572-e90883d527d2}><c:\windows\system32\wrqszl.dll> []
<{461d2ab4-29a5-45c2-9134-d52272d3de38}><c:\windows\system32\rfdswc.dll> []
<{011db9b9-44b4-44d9-b17e-bc7608f2e549}><c:\windows\system32\cdwqfs.dll> []
<{caed0f3b-df8b-4dbf-bb20-8dfbc3199068}><c:\windows\system32\jggtsr.dll> []
<{84143967-b645-4bff-b873-da1dc886e9a7}><c:\windows\system32\cedafb.dll> []
<{73ae86e6-7f03-4c3b-8980-fb1da157d3c7}><c:\windows\system32\fmcvxy.dll> []
<{81af1cf6-d1c9-4c6a-ac01-ede54e71945b}><c:\windows\system32\jfdses.dll> []
<{b490415f-65f8-b5c5-d8ba-9405fb12054b}><c:\windows\system32\yzztkmsn.dll> []
<{b629ff4f-acdb-5c90-a098-facb3456a26b}><c:\windows\system32\hdf453d.dll> []
<{528df602-9541-a985-210a-984a698c6f25}><c:\windows\system32\ptjhehlp.dll> []
<{7a041f13-a111-12a3-b0cf-f99818aa68a7}><c:\windows\system32\zxmsdwin.dll> []
<{aa59145f-315d-bc23-ac1f-145df81a34aa}><c:\windows\system32\zyzxjime.dll> []
<{6c648541-1025-9650-9057-6541258720c6}><c:\windows\system32\mndhfdwd.dll> []
<{50940f85-f015-14f1-a05f-f69858ac6d05}><c:\windows\system32\zptlcsys.dll> []
<{5a069845-2036-6084-9054-6087502480a5}><c:\windows\system32\ozfyebyt.dll> []
<{37a924af-1a5f-cf21-ab1d-1d5cf82a8a73}><c:\windows\system32\zywlcime.dll> []
<{7c69034a-f45f-d34d-a33a-c33c4d324fc7}><c:\windows\system32\arjreler.dll> []
<{7fd45a54-9875-698f-e56e-65102358fdf7}><c:\windows\system32\apsggjba.dll> []
<{5b1aef69-ddae-fdad-dcab-698f026abdb5}><c:\windows\system32\oohxdbyt.dll> []
<{35671234-7890-abcd-cdef-567801237653}><c:\windows\system32\yxcschlp.dll> []
<{1a698452-c5d8-c584-c256-c264c987c5a1}><c:\windows\system32\ijdyapaw.dll> []
<{43512378-9874-5641-1025-985420368734}><c:\windows\system32\oswxdttb.dll> []
<{18093456-9012-4568-9076-908765467181}><c:\windows\system32\tisqatyu.dll> []
<{25fd6584-698f-bcd2-602c-698745210352}><c:\windows\system32\rijxbkin.dll> []
<{4a698102-5904-afd0-20df-cd1a65829ca4}><c:\windows\system32\zycbdime.dll> []
<{91698482-6555-3666-1222-954784129019}><c:\windows\system32\zxptejpg.dll> []
<{3d698451-2015-6358-9871-2015987452d3}><c:\windows\system32\apzhctde.dll> []
<{37ac9076-c898-b098-d098-a18319080973}><c:\windows\system32\nhmxcjkl.dll> []
<{7c954872-1230-6541-9548-6541025884c7}><c:\windows\system32\fd233ds4f3.dll> []
<{2b69874a-c58c-458d-69f0-698f874e41b2}><c:\windows\system32\lassaplo.dll> []
<{29109876-7619-9101-7012-901938475192}><c:\windows\system32\ietzbpaq.dll> []
<{14698742-2059-3025-9058-954023874141}><c:\windows\system32\jkhxaklo.dll> []
<{4a908760-8000-4000-a000-9000322145a4}><c:\windows\system32\akjsdkaq.dll> []
<{20909876-4567-3908-4056-909834565102}><c:\windows\system32\erxybloe.dll> []
<{60a345cd-abcd-efab-cdef-abcd01020306}><c:\windows\system32\pqzfajke.dll> []
[hkey_local_machine\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
<adsntzt.dll><c:\windows\system32\adsntzt.dll> []
[hkey_local_machine\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<internet explorer><%systemroot%\system32\shmgrate.exe ocinstalluserconfigie> [n/a]
[hkey_local_machine\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<outlook express><%systemroot%\system32\shmgrate.exe ocinstalluserconfigoe> [n/a]
[hkey_local_machine\software\microsoft\active setup\installed components\{2c7339cf-2b09-4501-b3f3-f3508c9228ed}]
<themes setup><%systemroot%\system32\regsvr32.exe /s /n /i:/userinstall %systemroot%\system32\themeui.dll> [n/a]
[hkey_local_machine\software\microsoft\active setup\installed components\{44bba840-cc51-11cf-aafa-00aa00b6015c}]
<microsoft outlook express 6><"%programfiles%\outlook express\setup50.exe" /app:oe /caller:winnt /user /install> [n/a]
[hkey_local_machine\software\microsoft\active setup\installed components\{44bba842-cc51-11cf-aafa-00aa00b6015b}]
<netmeeting 3.01><rundll32.exe advpack.dll,launchinfsection c:\windows\inf\msnetmtg.inf,netmtg.remove.peruser.nt> [(verified)microsoft windows publisher]
[hkey_local_machine\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<windows messenger 4.7><rundll32.exe advpack.dll,launchinfsection c:\windows\inf\msmsgs.inf,blc.quietinstall.peruser> [(verified)microsoft windows publisher]
[hkey_local_machine\software\microsoft\active setup\installed components\{6bf52a52-394a-11d3-b153-00c04f79faa6}]
<microsoft windows media player><rundll32.exe advpack.dll,launchinfsection c:\windows\inf\wmp10.inf,peruserstub> [(verified)microsoft windows component publisher]
[hkey_local_machine\software\microsoft\active setup\installed components\{7790769c-0471-11d2-af11-00c04fa35d02}]
<通讯簿 6><"%programfiles%\outlook express\setup50.exe" /app:wab /caller:winnt /user /install> [n/a]
==================================
启动文件夹
[explorer]
<c:\documents and settings\all users\「开始」菜单\程序\启动\explorer.exe --> [n/a]><n>
[qq游戏启动加速程序]
<c:\documents and settings\administrator\「开始」菜单\程序\启动\qq游戏启动加速程序.lnk --> d:\qq\qqgame\accel.exe [深圳市腾讯计算机系统有限公司]><n>
==================================
服务
[adobe lm service / adobe lm service][stopped/manual start]
<"c:\program files\common files\adobe systems shared\service\adobelmsvc.exe"><adobe systems>
[dfservex / dfservex][running/auto start]
<c:\program files\hypertechnologies\deep freeze\dfservex.exe><hyper technologies inc.>
[help and support / helpsvc][stopped/disabled]
<c:\windows\system32\svchost.exe -k netsvcs-->%windir%\pchealth\helpctr\binaries\pchsvc.dll><n/a>
[human interface device access / hidserv][stopped/disabled]
<c:\windows\system32\svchost.exe -k netsvcs-->%systemroot%\system32\hidserv.dll><n/a>
[netmeeting remote desktop sharing / mnmsrvc][stopped/manual start]
<><n/a>
[rising proxy service / rfwproxysrv][running/auto start]
<d:\瑞星\rising\rfw\rfwproxy.exe><beijing rising technology co., ltd.>
[rising personal firewall service / rfwservice][running/auto start]
<d:\瑞星\rising\rfw\rfwsrv.exe><beijing rising technology co., ltd.>
[remote packet capture protocol v.0 (experimental) / rpcapd][stopped/manual start]
<"c:\program files\winpcap\rpcapd.exe" -d -f "c:\program files\winpcap\rpcapd.ini"><n/a>
[rising process communication center / rsccenter][running/auto start]
<"d:\瑞星\rising\rav\ccenter.exe"><beijing rising technology co., ltd.>
[rising realtime monitor / rsravmon][stopped/auto start]
<"d:\瑞星\rising\rav\ravmond.exe"><n/a>
[servicelayer / servicelayer][running/manual start]
<"c:\program files\pc connectivity solution\servicelayer.exe"><nokia.>
==================================
驱动程序
[294296e014ff6e51 / 294296e014ff6e51][stopped/manual start]
<\??\c:\294296e014ff6e51.dat><n/a>
[aha154x / aha154x][running/boot start]
<\systemroot\system32\drivers\aha154x.sys><microsoft corporation>
[ahci8086 / ahci8086][running/boot start]
<\systemroot\system32\drivers\ahci8086.sys><ati technologies inc.>
[aliide / aliide][stopped/boot start]
<\systemroot\system32\drivers\aliide.sys><n/a>
[amdk8 compatible device / amdk8][stopped/manual start]
<system32\drivers\amdk8.sys><advanced micro devices>
[arcsas / arcsas][stopped/boot start]
<\systemroot\system32\drivers\arcsas.sys><n/a>
[rising tdi base driver / basetdi][running/auto start]
<system32\drivers\basetdi.sys><beijing rising technology co., ltd.>
[cmdide / cmdide][stopped/boot start]
<\systemroot\system32\drivers\cmdide.sys><n/a>
[c-media wdm audio interface / cmuda][running/manual start]
<system32\drivers\cmuda.sys><c-media inc>
[via rhine-family fast ethernet adapter driver service / fetnd5bv][running/manual start]
<system32\drivers\fetnd5bv.sys><via technologies, inc.>
[microsoft hid class driver / hidusb][stopped/manual start]
<system32\drivers\hidusb.sys><n/a>
[hookcont / hookcont][running/system start]
<\systemroot\system32\drivers\hookcont.sys><beijing rising technology co., ltd>
[hookntos / hookntos][running/system start]
<\systemroot\system32\drivers\hookntos.sys><beijing rising technology co., ltd>
[hookreg / hookreg][running/system start]
<\systemroot\system32\drivers\hookreg.sys><beijing rising technology co., ltd>
[hooksys / hooksys][running/system start]
<\systemroot\system32\drivers\hooksys.sys><beijing rising technology co., ltd>
[hookurl / hookurl][running/auto start]
<\??\d:\瑞星\rising\rfw\hookurl.sys><beijing rising technology co., ltd.>
[iis manager / iis manager ][running/manual start]
<\??\c:\docume~1\admini~1\locals~1\temp\1.tmp><n/a>
[keyboard hid driver / kbdhid][stopped/system start]
<system32\drivers\kbdhid.sys><n/a>
[mouse hid driver / mouhid][stopped/manual start]
<system32\drivers\mouhid.sys><n/a>
[mseqsy / mseqsy][stopped/auto start]
<system32\drivers\msacpe.sys><n/a>
[netgroup packet filter / npf][stopped/manual start]
<system32\drivers\npf.sys><n/a>
[npkcrypt / npkcrypt][stopped/manual start]
<\??\c:\windows\system32\npkcrypt.sys><n/a>
[npkycryp / npkycryp][stopped/manual start]
<\??\c:\windows\system32\npkycryp.sys><n/a>
[pccs mode change filter driver / pccsmcfd][stopped/manual start]
<system32\drivers\pccsmcfd.sys><nokia>
[direct parallel link driver / ptilink][running/manual start]
<system32\drivers\ptilink.sys><parallel technologies, inc.>
[rising rfwbase driver / rfwbase][running/auto start]
<system32\drivers\rfwbase.sys><beijing rising technology co., ltd.>
[rsantispyware / rsantispyware][running/boot start]
<\systemroot\system32\drivers\rsboot.sys><beijing rising technology co., ltd.>
[rsfwdrv / rsfwdrv][running/system start]
<\??\d:\瑞星\rising\rfw\rsfwdrv.sys><beijing rising technology co., ltd.>
[rsntgdi / rsntgdi][running/boot start]
<\systemroot\system32\drivers\rsntgdi.sys><beijing rising technology co., ltd.>
[secdrv / secdrv][stopped/manual start]
<system32\drivers\secdrv.sys><n/a>
[serial mouse driver / sermouse][stopped/manual start]
<system32\drivers\sermouse.sys><n/a>
[sparrow / sparrow][running/boot start]
<\systemroot\system32\drivers\sparrow.sys><adaptec, inc.>
[system restore filter driver / sr][stopped/boot start]
<\systemroot\system32\drivers\sr.sys><n/a>
[syshostsvc / syshostsvc][running/auto start]
<\??\c:\windows\system32\drivers\guihelp.sys><microsoft corporation>
[sp-cable / usb2vcom][stopped/manual start]
<system32\drivers\usb2vcom.sys><speed science&technology electronic co. ltd>
[microsoft usb generic parent driver / usbccgp][stopped/manual start]
<\systemroot\system32\drivers\usbccgp.sys><n/a>
[microsoft usb open host controller miniport driver / usbohci][stopped/boot start]
<\systemroot\system32\drivers\usbohci.sys><n/a>
[viagfx / viagfx][running/manual start]
<system32\drivers\vtmini.sys><copyright (c) via/s3 graphics co, ltd.>
[viaide / viaide][running/boot start]
<\systemroot\system32\drivers\viaide.sys><microsoft corporation>
[viamraid / viamraid][running/boot start]
<\systemroot\system32\drivers\viamraid.sys><via technologies inc,.ltd>
[world standard teletext codec / wstcodec][stopped/manual start]
<system32\drivers\wstcodec.sys><microsoft corporation>
[usb pc camera (zs0211) / zsmc211][running/manual start]
<system32\drivers\zs211.sys><zsmc corporation>
[vimicro usb pc camera / zsmc302][stopped/manual start]
<system32\drivers\usbvm31b.sys><vm>
用户系统信息:mozilla/4.0 (compatible; msie 6.0; windows nt 5.1; sv1)附件:
SREngLOG.log