[CODE] 2008-08-19,09:48:54 System Repair Engineer 2.6.12.1018 Smallfrogs (http://www.KZTechs.com) Windows 2000 Advanced Server Service Pack 4 (Build 2195) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [Microsoft Corporation] <"E:\Program Files\Ahead\Nero BackItUp\NBJ.exe"> [Ahead Software AG] [(Verified)Synacast Corp.] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [Ahead Software Gmbh] <"e:\Program Files\DAEMON Tools\daemon.exe" -lang 1033> [(Verified)DAEMON Tools Code Signing Services] <"e:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s> [SlySoft, Inc.] [(Verified)Microsoft Windows 2000 Publisher] <"D:\Program Files\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Information Technology Corporation Limited] [Gemplus] [] [] <"D:\Program Files\GridService\peer.exe" -n Grid> [Mercury] <"D:\Program Files\Rising\AntiSpyware\rstray.exe" /startup> [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows 2000 Publisher] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}> [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows 2000 Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] [(Verified)Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] <%SystemRoot%\system32\updcrl.exe -e -u %SystemRoot%\system32\verisignpub1.crl> [File is missing] [HKEY_CURRENT_USER\Control Panel\Desktop] [(Verified)Microsoft Windows 2000 Publisher] ================================== 启动文件夹 [Adobe Reader Speed Launch] D:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [Adobe Systems Incorporated]> [EPSON Status Monitor 3 Environment Check(3)] D:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.EXE [SEIKO EPSON CORPORATION]> [服务管理器] D:\PROGRA~1\MI6841~1\80\Tools\Binn\sqlmangr.exe [Microsoft Corporation]> ================================== 服务 [Adobe LM Service / Adobe LM Service][Stopped/Manual Start] <"D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"> [C-DillaCdaC11BA / C-DillaCdaC11BA][Running/Auto Start] [Crypkey License / Crypkey License][Stopped/Disabled] [Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start] [Microsoft Search / MSSEARCH][Running/Manual Start] <"D:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe"> [MSSQLSERVER / MSSQLSERVER][Running/Manual Start] [NVIDIA Display Driver Service / NVSvc][Running/Auto Start] [Rising Process Communication Center / RsCCenter][Running/Auto Start] <"D:\Program Files\Rising\Rav\CCenter.exe"> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] <"D:\PROGRAM FILES\RISING\RAV\Ravmond.exe"> [SQLSERVERAGENT / SQLSERVERAGENT][Stopped/Manual Start] [User Profile Hive Cleanup / UPHClean][Running/Auto Start] [Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start] D:\WINNT\system32\mspmsnsv.dll> ================================== 驱动程序 [Rising TDI Base Driver / BaseTDI][Running/Auto Start] [CdaC15BA / CdaC15BA][Running/Auto Start] <\??\D:\WINNT\system32\drivers\CDAC15BA.SYS> [dmboot / dmboot][Stopped/Disabled] [Logical Disk Manager Driver / dmio][Running/Boot Start] <\SystemRoot\System32\drivers\dmio.sys> [dmload / dmload][Running/Boot Start] <\SystemRoot\System32\drivers\dmload.sys> [MEMIO / DOSMEMIO][Running/Auto Start] <\??\D:\WINNT\system32\MEMIO.SYS> [dtscsi / dtscsi][Running/Manual Start] <\SystemRoot\System32\Drivers\dtscsi.sys> [3Com EtherLink XL B/C Adapter Driver / EL90BC][Running/Manual Start] <3Com Corporation> [ElbyCDFL / ElbyCDFL][Running/Manual Start] [ElbyCDIO Driver / ElbyCDIO][Running/Auto Start] [VIA Rhine-Family Fast Ethernet Adapter Driver Service / FETND5BV][Stopped/Manual Start] [VIA Rhine Family Fast Ethernet Adapter Driver Service / FETNDISB][Stopped/Manual Start] [%FLASHREADER.SvcDesc% / FLASHREADER][Stopped/Manual Start] [GKeyUSB / GKeyUSB][Stopped/Manual Start] [GMSIPCI / GMSIPCI][Stopped/Manual Start] <\??\H:\INSTALL\GMSIPCI.SYS> [HookCont / HookCont][Running/System Start] <\SystemRoot\system32\drivers\HookCont.sys> [HookNtos / HookNtos][Running/System Start] <\SystemRoot\system32\drivers\HookNtos.sys> [HookReg / HookReg][Running/System Start] <\SystemRoot\system32\drivers\HookReg.sys> [HookSys / HookSys][Running/System Start] <\SystemRoot\system32\drivers\HookSys.sys> [HWACCESS / HWACCESS][Stopped/Manual Start] <\??\D:\WINNT\SYSTEM32\HWACCESS.SYS> [MSICPL / MSICPL][Stopped/Manual Start] <\??\H:\install4\MSICPL.sys> [NetworkX / NetworkX][Running/System Start] <\SystemRoot\system32\ckldrv.sys> [nv / nv][Running/Manual Start] [NVIDIA PORT IO Control Driver / nvport][Stopped/System Start] <\??\D:\WINNT\system32\Drivers\nvport.sys> [AVstar Dual Mode USB Camera Plus / OVT511Plus][Stopped/Manual Start] [Padus ASPI Shell / pfc][Running/Manual Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [USB SmartCard Reader Device 1000 / Reader_1000][Stopped/Manual Start] [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [S3Psddr / S3Psddr][Stopped/Manual Start] [SmartAVS / SmartAVS][Stopped/Manual Start] <\??\D:\WINNT\system32\drivers\SmartAVS.sys> [Sony Memory Stick Driver(SONYPVM1) / SONYPVM1][Running/Boot Start] <\SystemRoot\system32\DRIVERS\SONYPVM1.SYS> [Sony Digital Imaging Video2 / sonypvs1][Stopped/Manual Start] [Sony USB Filter Driver (SONYPVU1) / SONYPVU1][Stopped/Manual Start] [sptd / sptd][Running/Boot Start] <\SystemRoot\System32\Drivers\sptd.sys> [usb driver for epass1k / token1k][Stopped/Manual Start] [VIA AGP Filter / viaagp1][Running/Boot Start] <\SystemRoot\system32\DRIVERS\viaagp1.sys> [VIA USB Filter / viafilter][Stopped/Manual Start] <\SystemRoot\System32\Drivers\viausb.sys> [viaide / viaide][Running/Boot Start] <\SystemRoot\system32\DRIVERS\viaide.sys> [Vinyl AC'97 Audio Controller (WDM) / VIAudio][Running/Manual Start] [videX32 / videX32][Running/Boot Start] <\SystemRoot\system32\DRIVERS\videX32.sys> [vmfilter303 / vmfilter303][Stopped/Manual Start] [xAntiArpSpoof Service / xAntiArp][Stopped/Manual Start] [VIMICRO USB PC Camera / ZSMC302][Running/Manual Start] [VIMICRO USB PC Camera (ZC0301PLH) / ZSMC303][Stopped/Manual Start] ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [AcroIEHlprObj Class] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [Download_Bho Class] {A986E409-30CC-4185-89BB-AB212C104524} [启动迅雷5] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} [PPLive] {95B3F550-91C4-4627-BCC4-521288C52977} [Office Genuine Advantage Validation Tool] {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} [IkeyCheckClient Class] {0C9D30AB-1840-463F-BD45-E4BB5AAD4342} [Windows Genuine Advantage Validation Tool] {17492023-C23A-453E-A040-C7C580BBF700} [InstallHelper Class] {1DABF8D5-8430-4985-9B7F-A30E53D709B3} [GSCell Control] {1EAB7671-2630-408A-865C-DC967AB2FBF8} [iWebOffice Control] {23739A7E-5741-4D1C-88D5-D50B18F7C347} [DrvCert Class] {2FD68643-4BCE-4EF5-B7B8-F0F1192FDE86} [WebEditor] {33739A7E-2004-4D1C-88D5-D50B18F7C347} [XeCtrl Control] {348EA76C-CCCE-4E43-B4F8-6C9EAF708587} [PzExpImp Control] {3881112A-5570-48DE-BCAB-2AA653AF0B66} [GDGetTokenInfo Class] {3AA9CF07-DF20-48FF-98BE-DED276E40146} [GetClientMsg Control] {3FA80982-FC6D-45E2-A399-96057D99C6D1} [InfoSecNetSign Class] {5CB840B5-A94E-4AD9-B785-4866E3B04476} [Windows Live Safety Center Base Module] {5ED80217-570B-4DA9-BF44-BE107C0EC166} [WUWebControl Class] {6414512B-B978-451D-A0D8-FCFDF33E833C} [CmpFileImExportSvr Control] {67458B66-75FF-4F1C-B4EB-C9440D0D5FC5} [CCtInf Class] {6DBB2904-082D-4DB0-944A-21C22BA121F4} [AxInputControl Class] {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} [ICBCOCX Public Key Check] {7AEA10C5-B38F-4D72-A8F0-ED2D43D2A59E} [PrjGenerRpt.GenerRpt] {86A2938F-A71B-4521-81C4-1727B7B6201B} [GsBiTyGlXzCtl Control] {88003CA6-68A9-45CC-ACB1-6CAFFAF37CF4} [Filetran Control] {88734439-46D0-42C0-A13F-7E881EE550CF} [ActiveFormX Control] {89AF7F33-300E-4AFB-8DEA-D375FCE398B4} [ClientManager Object] {8B4B2DC6-8372-4675-A8EF-D634FE8CF1E4} [] {9242BB35-0DB0-43AC-8DFC-8EA07E63B92A} <, > [DataImportActiveFormX Control] {A8D078FE-C5A0-40B8-A751-1B746DBC3503} [Settings Class] {A996E48C-D3DC-4244-89F7-AFA33EC60679} [CCTVUpdateInstall] {AC414988-E5BB-4C2C-873B-EA53D2F3D23A} [NCFunction Class] {B5DD3A64-98A0-40C8-9EC3-7F2C3B0C12E3} [WMCtr Control] {B859020D-FC48-4DF7-ADC1-F095A4729894} [] {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} <, > [] {BA7C4B25-19D5-4F32-831D-BEAF1A402827} <, > [scanpic Control] {BC47B00B-BBA8-41ED-86F5-8674F18DF53D} [KooPlayer Control] {C728DAB8-FDF5-4CD7-89DD-879D25794C77} [NTKO OFFICE文档控件] {C9BC4DFF-4248-4A3C-8A49-63A7D317F404} [ReportClient Control] {D191DCC3-09F7-463B-83B9-2C4DBD260BD1} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [CreMediaClient Class] {D95D2D4B-74F0-4C00-AC6B-7FC596F72986} [gsJSC.gsJSCCenter] {DCAB29D0-0819-4299-A76D-C05D354A503F} [Cell Control 3.3] {DD44C0EA-B2CF-11D1-8DD3-444553540000} [LocalLauncher Class] {E22BFF56-39F3-11D8-A0C7-000C6E7BB5AB} [AxUSBKey Class] {E4BFF825-2E50-4BCC-8497-6EFDFB6C9B3D} [IcbcSslCacheCleanerCtrl Class] {E9707834-5BF7-4CFF-A639-398427DE1991} [GerneralPeerID Class] {0A47E819-F82E-4D5D-B806-6A9EA94D68CD} [Recorder Control] {2423AB16-9F42-457B-A337-FE3B11964DB0} [BlueskyVideo Control] {2EA6D939-4445-43F1-A12B-8CB3DDA8B855} [Ppd Control] {2F2BA87D-385E-4922-B41C-06E190B06AA9} [Share Control] {3072B1F1-0C4D-4E76-A7C6-FBAF129DBCC9} [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [Traceppd Control] {5910C66C-F9BA-4306-8175-C098B7F0ED62} [PP Control] {616DACC1-C5E6-4646-B36A-3FA4FC726BAD} [XMP Class] {6483F145-A768-4C41-AACC-52D4D7845851} [XDRM] {693571CB-54A3-4E90-9D52-EEAE1334E2D3} [] {7005341F-8E42-47E3-987B-3DBE6288048C} <, > [Videohelp Control] {75B75D86-D88B-4BEA-BC59-BFD9D7300518} [MediaComm Class] {7670648D-461B-42AF-BDFE-46D26AF5EFF2} [Filetran Control] {88734439-46D0-42C0-A13F-7E881EE550CF} [Chat Control] {94EFE58C-E678-4808-AD65-24CE4B94C1FE} [Blueskyvoice Control] {991481A7-4669-4e15-8C24-100404E1F5CB} [Display Control] {A1D97DB3-E564-4743-B2E7-6F5182CBF406} [Tracechat Control] {A40335C4-D3D1-4E7B-9130-039CDA5B603C} [RMGetLicense Class] {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} [Imgsend Control] {AA1561BF-D290-4060-919B-499849629205} [DapCtrl Class] {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} [PPChat Control] {AFB97F16-B7E8-4EB1-8133-FBD5AA2EBB3B} [Blueskyvoice Control] {BA0F088C-72C1-475a-92F8-42391DEF6961} [Client Control] {C7B0C764-5D4E-433E-A854-591F28520577} [Play Control] {CC20DDA1-9A21-4DEC-B5BE-E61E0351FCA9} [Thunder DapPlayer] {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} [XPPlayer Class] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} [&U使用纳米机器人下载并收藏] [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] [添加到QQ表情] [用比特精灵下载(&B)] ================================== 正在运行的进程 [PID: 236][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.00.2195.6601] [PID: 264][\??\D:\WINNT\system32\csrss.exe] [Microsoft Corporation, 5.00.2195.6601] [PID: 284][\??\D:\WINNT\system32\winlogon.exe] [Microsoft Corporation, 5.00.2195.6997] [D:\WINNT\system32\wdmaud.drv] [Microsoft Corporation, 5.00.2195.6673] [D:\WINNT\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] [D:\WINNT\system32\msacm32.drv] [Microsoft Corporation, 5.00.2134.1] [PID: 316][D:\WINNT\system32\services.exe] [Microsoft Corporation, 5.00.2195.7035] [D:\WINNT\system32\dmserver.dll] [VERITAS Software Corp., 2195.6605.297.3] [PID: 328][D:\WINNT\system32\lsass.exe] [Microsoft Corporation, 5.00.2195.7011] [PID: 456][D:\WINNT\System32\SCardSvr.exe] [Microsoft Corporation, 5.00.2195.6609] [PID: 564][D:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1] [PID: 612][D:\WINNT\system32\spoolsv.exe] [Microsoft Corporation, 5.00.2195.7059] [D:\WINNT\system32\CNAB4LMK.DLL] [CANON INC., 3.00.0.003] [D:\WINNT\system32\CNAB4SMK.DLL] [CANON INC., 3.00.0.003] [D:\WINNT\system32\CNAB4PTU.DLL] [CANON INC., 3.00.0.003] [D:\WINNT\system32\mdimon.dll] [Microsoft Corporation, 11.3.1897.0] [D:\WINNT\system32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.1897.0] [D:\WINNT\system32\CNAB4EMU.DLL] [CANON INC., 3.00.0.003] [PID: 712][D:\WINNT\system32\drivers\CDAC11BA.EXE] [Macrovision, 4.20.020] [PID: 788][D:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1] [PID: 808][D:\WINNT\system32\hidserv.exe] [Microsoft Corporation, 5.00.2195.6655] [PID: 844][D:\PROGRAM FILES\RISING\RAV\RavStub.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.10] [D:\PROGRAM FILES\RISING\RAV\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\PROGRAM FILES\RISING\RAV\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [PID: 876][D:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe] [Microsoft Corporation, 2005.090.1399.00] [D:\WINNT\system32\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.1433] [D:\WINNT\system32\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.1433] [D:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\opends60.dll] [Microsoft Corporation, 2005.090.1399.00] [D:\Program Files\Microsoft SQL Server\90\Shared\instapi.dll] [Microsoft Corporation, 2005.090.1399.00] [D:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\Resources\1033\sqlevn70.RLL] [Microsoft Corporation, 2005.090.1399.00] [D:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\Resources\2052\sqlevn70.RLL] [Microsoft Corporation, 2005.090.1399.00] [D:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLOS.DLL] [Microsoft Corporation, 2005.090.1399.00] [D:\WINNT\system32\AUTHZ.DLL] [Microsoft Corporation, 5.00.2195.7028] [D:\WINNT\system32\MSCOREE.DLL] [Microsoft Corporation, 2.0.50727.1433 (REDBITS.050727-1400)] [PID: 504][D:\WINNT\system32\CNAB4RPK.EXE] [CANON INC., 3.00.0.003] [PID: 1028][D:\WINNT\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.8195] [D:\WINNT\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] [PID: 1048][D:\WINNT\system32\regsvc.exe] [Microsoft Corporation, 5.00.2195.6701] [PID: 1152][D:\WINNT\system32\MSTask.exe] [Microsoft Corporation, 4.71.2195.6972] [PID: 1216][D:\WINNT\system32\stisvc.exe] [Microsoft Corporation, 5.00.2195.6656] [D:\WINNT\system32\VM31bSTI.dll] [VM, 4.2.510.21] [PID: 764][E:\Program Files\UPHClean\uphclean.exe] [Microsoft Corporation, 1.6.30.0] [D:\WINNT\system32\MSVCP60.dll] [Microsoft Corporation, 6.05.2144.0] [PID: 1312][D:\WINNT\Explorer.EXE] [Microsoft Corporation, 5.00.3700.6690] [D:\WINNT\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] [D:\WINNT\system32\AcSignIcon.dll] [Autodesk, 16.0.0.86] [D:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] [Autodesk, 16.0.0.86] [D:\WINNT\system32\wdmaud.drv] [Microsoft Corporation, 5.00.2195.6673] [D:\WINNT\system32\msacm32.drv] [Microsoft Corporation, 5.00.2134.1] [D:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N] [D:\WINNT\mui\fallback\0804\msctf.dll.mui] [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N] [D:\WINNT\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.18] [D:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [D:\Program Files\WinRAR\rarext.dll] [N/A, ] [E:\PROGRA~2\Tencent\RTXC\RTXShl.dll] [Tencent, 1, 0, 0, 1] [e:\Program Files\NamiRobot\Data\NamipanExt.dll] [N/A, ] [D:\WINNT\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [D:\WINNT\system32\mp3infp.dll] [win32lab.com, 2.53.37.0] [E:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29] [D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.0.2004121400] [E:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [E:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20] [D:\WINNT\system32\MSVCP60.dll] [Microsoft Corporation, 6.05.2144.0] [E:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [D:\WINNT\system32\msimtf.dll] [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N] [E:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510] [D:\WINNT\system32\nvshell.dll] [, ] [PID: 1328][D:\WINNT\System32\WBEM\WinMgmt.exe] [Microsoft Corporation, 1.50.1085.0100] [PID: 1348][D:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1] [PID: 1388][D:\WINNT\system32\inetsrv\inetinfo.exe] [Microsoft Corporation, 5.00.0984] [d:\WINNT\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll] [Microsoft Corporation, 2.0.50727.1433 (REDBITS.050727-1400)] [D:\WINNT\system32\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.1433] [PID: 1644][E:\Program Files\DAEMON Tools\daemon.exe] [DT Soft Ltd., 4.03.0.0] [e:\Program Files\DAEMON Tools\daemon.dll] [DT Soft Ltd., 4.03.0.0] [e:\Program Files\DAEMON Tools\PFCTOC.DLL] [Padus(R), Inc., 1, 0, 0, 12] [e:\Program Files\DAEMON Tools\Plugins\Images\bw5mount.dll] [, 1.0.6.0] [e:\Program Files\DAEMON Tools\Plugins\Images\ccdmount.dll] [GENERIC, 1.10.0.0] [e:\Program Files\DAEMON Tools\Plugins\Images\mdsmount.dll] [GENERIC, 1.12.0.0] [e:\Program Files\DAEMON Tools\Plugins\Images\nrgmount.dll] [GENERIC, 1.11.0.0] [e:\Program Files\DAEMON Tools\Plugins\Images\pdimount.dll] [GENERIC, 1.01.0.0] [D:\WINNT\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] [D:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N] [PID: 1692][D:\WINNT\System32\svchost.exe] [Microsoft Corporation, 5.00.2134.1] [D:\WINNT\System32\unimdm.tsp] [Microsoft Corporation, 5.00.2195.6601] [D:\WINNT\System32\kmddsp.tsp] [Microsoft Corporation, 5.00.2150.1] [D:\WINNT\System32\ndptsp.tsp] [Microsoft Corporation, 5.00.2143.1] [D:\WINNT\System32\ipconf.tsp] [Microsoft Corporation, 5.00.2143.1] [D:\WINNT\System32\h323.tsp] [Microsoft Corporation, 5.00.2195.6901] [PID: 1724][D:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.24] [D:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [D:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [D:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [D:\WINNT\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] [D:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N] [PID: 1748][D:\Program Files\Gemplus\GemSafe Libraries\BIN\Regtool.exe] [, 3, 0, 9, 0] [D:\Program Files\Gemplus\GemSafe Libraries\BIN\GemPPM.dll] [Gemplus, 3, 0, 2, 0] [D:\WINNT\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [D:\WINNT\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [D:\Program Files\Gemplus\Common\Resources\LocHub.dll] [GEMPLUS, 1, 0, 8, 0] [D:\WINNT\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] [D:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N] [PID: 1928][D:\Program Files\GridService\peer.exe] [Mercury, 2, 0, 10, 7348] [D:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N] [D:\WINNT\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] [PID: 1944][D:\Program Files\Rising\AntiSpyware\rstray.exe] [Beijing Rising Information Technology Co., Ltd., 21.0.0.15] [D:\Program Files\Rising\AntiSpyware\rsmginfo.dll] [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 8] [D:\Program Files\Rising\AntiSpyware\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [D:\Program Files\Rising\AntiSpyware\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [D:\Program Files\Rising\AntiSpyware\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [D:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N] [D:\WINNT\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] [D:\Program Files\Rising\AntiSpyware\ComServ.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.31] [D:\Program Files\Rising\AntiSpyware\Syslay.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.6] [D:\Program Files\Rising\AntiSpyware\rscommon.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.1.1] [D:\Program Files\Rising\AntiSpyware\comx3.dll] [Beijing Rising Information Technology Co., Ltd., 21.0.0.24] [D:\Program Files\Rising\AntiSpyware\pngdll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [D:\Program Files\Rising\AntiSpyware\runiep.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.32] [D:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [D:\WINNT\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.18] [D:\WINNT\system32\AcSignIcon.dll] [Autodesk, 16.0.0.86] [D:\WINNT\mui\fallback\0804\msctf.dll.mui] [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N] [D:\Program Files\Rising\AntiSpyware\pscan.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.52] [D:\Program Files\Rising\AntiSpyware\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [D:\Program Files\Rising\AntiSpyware\NComm.dll] [Beijing Rising Information Technology Co., Ltd., 6.0.0.6] [PID: 1952][D:\WINNT\system32\ctfmon.exe] [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N] [D:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N] [D:\WINNT\system32\MSUTB.dll] [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N] [D:\WINNT\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] [D:\WINNT\mui\fallback\0804\msutb.dll.mui] [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N] [D:\WINNT\mui\fallback\0804\msctf.dll.mui] [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N] [PID: 512][D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe] [Microsoft Corporation, 2000.080.0194.00] [D:\Program Files\Microsoft SQL Server\80\Tools\Binn\W95SCM.dll] [Microsoft Corporation, 2000.080.0194.00] [D:\WINNT\system32\SQLUNIRL.dll] [Microsoft Corporation, 2000.080.0728.00] [D:\Program Files\Microsoft SQL Server\80\Tools\Binn\SQLSVC.dll] [Microsoft Corporation, 2000.080.0194.00] [D:\WINNT\system32\odbcbcp.dll] [Microsoft Corporation, 2000.085.1128.00 built by: xpsp(_sqlbld)] [D:\Program Files\Microsoft SQL Server\80\Tools\Binn\SQLRESLD.dll] [Microsoft Corporation, 2000.080.0194.00] [D:\Program Files\Microsoft SQL Server\80\Tools\Binn\Resources\2052\SQLSVC.RLL] [Microsoft Corporation, 2000.080.0194.00] [D:\Program Files\Microsoft SQL Server\80\Tools\Binn\Resources\2052\sqlmangr.RLL] [Microsoft Corporation, 2000.080.0194.00] [D:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N] [D:\WINNT\system32\AcSignIcon.dll] [Autodesk, 16.0.0.86] [D:\WINNT\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] [D:\WINNT\mui\fallback\0804\msctf.dll.mui] [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N] [PID: 2316][D:\WINNT\system32\conime.exe] [Microsoft Corporation, 5.00.2195.6655] [D:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N] [D:\WINNT\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] [PID: 2152][D:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2800.1106] [D:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N] [D:\WINNT\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] [D:\WINNT\system32\AcSignIcon.dll] [Autodesk, 16.0.0.86] [E:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29] [D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.0.2004121400] [D:\WINNT\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [E:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [E:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20] [D:\WINNT\system32\MSVCP60.dll] [Microsoft Corporation, 6.05.2144.0] [E:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [D:\WINNT\system32\urlFilter.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 15] [D:\Program Files\Rising\AntiSpyware\UrlRule.dll] [Beijing Rising Information Technology Co., Ltd., 1.0.0.15] [D:\Program Files\PPLiveVA\DownloaderManager.dll] [, 1.0.0.5] [D:\WINNT\system32\msratelc.dll] [Microsoft Corporation, 6.00.2800.1106] [D:\WINNT\mui\fallback\0804\msctf.dll.mui] [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N] [D:\WINNT\system32\msimtf.dll] [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N] [E:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510] [D:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [D:\WINNT\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0] [D:\WINNT\system32\wdmaud.drv] [Microsoft Corporation, 5.00.2195.6673] [D:\WINNT\system32\msacm32.drv] [Microsoft Corporation, 5.00.2134.1] [D:\WINNT\system32\winabc.ime] [Microsoft Corporation, 5.00.2195.6601] [D:\WINNT\system32\winsp.ime] [Microsoft Corporation, 5.00.2195.6601] [D:\WINNT\system32\winpy.ime] [Microsoft Corporation, 5.00.2195.6601] [D:\WINNT\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527] [D:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] [Autodesk, 16.0.0.86] [D:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL] [Microsoft Corporation, 9.0.5510.0] [PID: 1804][D:\WINNT\system32\notepad.exe] [Microsoft Corporation, 5.00.2140.1] [D:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N] [D:\WINNT\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] [D:\WINNT\system32\winabc.ime] [Microsoft Corporation, 5.00.2195.6601] [D:\WINNT\system32\winsp.ime] [Microsoft Corporation, 5.00.2195.6601] [D:\WINNT\system32\winpy.ime] [Microsoft Corporation, 5.00.2195.6601] [D:\WINNT\system32\IMSC40A.IME] [Microsoft Corporation, 6.0.0.2527] [PID: 2304][e:\PROGRA~2\MICROS~4\MSSQL\binn\sqlservr.exe] [Microsoft Corporation, 2000.080.0194.00] [e:\PROGRA~2\MICROS~4\MSSQL\binn\OPENDS60.DLL] [Microsoft Corporation, 2000.080.0194.00] [e:\PROGRA~2\MICROS~4\MSSQL\binn\UMS.DLL] [Microsoft Corporation, 2000.080.0194.00] [e:\PROGRA~2\MICROS~4\MSSQL\binn\SQLSORT.DLL] [Microsoft Corporation, 2000.080.0194.00] [e:\PROGRA~2\MICROS~4\MSSQL\binn\Resources\2052\sqlevn70.RLL] [Microsoft Corporation, 2000.080.0194.00] [e:\PROGRA~2\MICROS~4\MSSQL\binn\SSNETLIB.dll] [Microsoft Corporation, 2000.080.0194.00] [e:\PROGRA~2\MICROS~4\MSSQL\binn\SSNMPN70.dll] [Microsoft Corporation, 2000.080.0194.00] [e:\PROGRA~2\MICROS~4\MSSQL\binn\SSmsLPCn.dll] [Microsoft Corporation, 2000.080.0194.00] [e:\PROGRA~2\MICROS~4\MSSQL\binn\SQLFTQRY.DLL] [Microsoft Corporation, 2000.080.0194.00] [D:\Program Files\Common Files\System\OLE DB\sqloledb.dll] [Microsoft Corporation, 2000.085.1128.00 built by: xpsp(_sqlbld)] [D:\WINNT\system32\MSDART.DLL] [Microsoft Corporation, 2.81.1117.0 built by: (_sqlbld)] [D:\Program Files\Common Files\System\OLE DB\MSDATL3.dll] [Microsoft Corporation, 2.81.1117.0 built by: (_sqlbld)] [PID: 1888][D:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe] [Microsoft Corporation, 9.107.5512.0] [D:\Program Files\Common Files\System\MSSearch\Bin\mssws.dll] [Microsoft Corporation, 9.107.5512.0] [D:\PROGRA~1\COMMON~1\System\MSSearch\Bin\mssrch.dll] [Microsoft Corporation, 9.107.5512.0] [D:\Program Files\Common Files\System\MSSearch\Bin\tquery.dll] [Microsoft Corporation, 9.107.5512.0] [D:\PROGRA~1\COMMON~1\System\MSSearch\Bin\propdefs.dll] [Microsoft Corporation, 9.107.5512.0] [D:\PROGRA~1\COMMON~1\System\MSSearch\Bin\srchidx.dll] [Microsoft Corporation, 9.107.5512.0] [PID: 1776][D:\WINNT\system32\msdtc.exe] [Microsoft Corporation, 1999.9.3421.3] [PID: 2696][D:\Documents and Settings\Administrator\桌面\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.6.12.1018] [PID: 2704][D:\Documents and Settings\Administrator\桌面\sreng2\SRE116e8da0.EXE] [Smallfrogs Studio, 2.6.12.1018] [D:\WINNT\system32\MSCTF.dll] [Microsoft Corporation, 1.00.2409.34 built by: Lab06_N] [D:\WINNT\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] [D:\WINNT\mui\fallback\0804\msctf.dll.mui] [Microsoft Corporation, 1.00.2409.7 built by: Lab06_N] [D:\Documents and Settings\Administrator\桌面\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [D:\WINNT\system32\AcSignIcon.dll] [Autodesk, 16.0.0.86] [D:\WINNT\system32\MSISIP.DLL] [Microsoft Corporation, 3.1.4000.1823] [D:\WINNT\system32\wshCHS.DLL] [Microsoft Corporation, 5.6.0.6626] [E:\PROGRA~2\MICROS~1\OFFICE11\MCPS.DLL] [Microsoft Corporation, 11.0.5510] ================================== 文件关联 .TXT Error. [D:\WINNT\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [D:\WINNT\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 0.0.0.0 welcome.ah.vnet.cn 0.0.0.0 clickeye.cn 0.0.0.0 www.clickeye.cn 0.0.0.0 www230.clickeye.cn 0.0.0.0 www228.clickeye.cn 0.0.0.0 www227.clickeye.cn 0.0.0.0 www.3527.com 0.0.0.0 www3.131377.com 0.0.0.0 zhenai.com ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 764, E:\PROGRAM FILES\UPHCLEAN\UPHCLEAN.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1748, D:\PROGRAM FILES\GEMPLUS\GEMSAFE LIBRARIES\BIN\REGTOOL.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1928, D:\PROGRAM FILES\GRIDSERVICE\PEER.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1952, D:\WINNT\SYSTEM32\CTFMON.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 512, D:\PROGRAM FILES\MICROSOFT SQL SERVER\80\TOOLS\BINN\SQLMANGR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2304, E:\PROGRA~2\MICROS~4\MSSQL\BINN\SQLSERVR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 1888, D:\PROGRAM FILES\COMMON FILES\SYSTEM\MSSEARCH\BIN\MSSEARCH.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2696, D:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\SRENG2\SRENGLDR.EXE] ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]