1   1  /  1  页   跳转

分析下System Repair Engineer扫描结果

分析下System Repair Engineer扫描结果

2006-06-25,10:07:13

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows 98 SE  -

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <ScanRegistry><C:\WINDOWS\scanregw.exe /autorun>  [Microsoft Corporation]
    <TaskMonitor><C:\WINDOWS\taskmon.exe>  [Microsoft Corporation]
    <internat.exe><internat.exe>  [Microsoft Corporation]
    <SystemTray><SysTray.Exe>  [Microsoft Corporation]
    <NMGameX_AutoRun><C:\WINDOWS\Rundll32.exe NMGAMEX.DLL,LiveProcess /aa>  []
    <RavTask><"g:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
    <RsCcenter><"g:\Program Files\Rising\Rav\CCenter.exe">  [Beijing Rising Technology Co., Ltd.]
    <RavMond><"g:\Program Files\Rising\Rav\RavMond.exe">  [Beijing Rising Technology Co., Ltd.]
    <RavMon><"g:\Program Files\Rising\Rav\RavMon.exe" -system>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]

==================================
启动文件夹
[星空极速]
  <C:\WINDOWS\Start Menu\Programs\启动\星空极速.lnk><N>

==================================
服务

==================================
浏览器加载项
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRAM FILES\FLASHGET\JCCATCH.DLL, Amaze Soft>
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\SYSTEM\XUNLEIBHO_V13.DLL, Thunder Networking Technologies,LTD>
[IDDTInitObj Class]
  {15DDE989-CD45-4561-BF99-D22C0D5C2B74} <C:\PROGRA~1\SINA\UC\UCDDT\DDTINIT.DLL, 北京新浪信息技术有限公司>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_001.DLL, Thunder Networking Technologies,LTD>
[KillObj Class]
  {66C28884-4E5D-494B-80C9-CAA27528FD6D} <C:\PROGRA~1\SINA\UC\UCDDT\DDTKILLW.OCX, 北京新浪信息技术有限公司>
[VnetCookie Class]
  {4E83D567-4697-4F7B-B1F0-A513B01DB89A} <C:\PROGRA~1\CHINANET\VNETTR~1.DLL, (>
[珊瑚虫 工具栏]
  {D74EC18E-3DDD-4174-B1B1-949FE3B8366D} <C:\PROGRAM FILES\INFOFO BAR\INFOFOBAR.DLL, 珊瑚虫工作室 泰格工作室>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[FlashGet]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRAM FILES\FLASHGET\FLASHGET.EXE, Amaze Soft>
[新浪UC]
  {2253922F-1B26-4C74-8B57-E3AEE748DBB8} <C:\Program Files\sina\UC\UC.exe, 北京新浪信息技术有限公司>
[新浪点点通]
  {F60C7D81-8471-4D40-AAFE-56D318F34C2D} <C:\PROGRA~1\SINA\UC\UCDDT\DDTONG~1.DLL, 北京新浪信息技术有限公司>
[珊瑚虫 工具栏]
  {8507326C-B5C1-4559-BB91-0919E753836F} <C:\PROGRAM FILES\INFOFO BAR\INFOFOBAR.DLL, 珊瑚虫工作室 泰格工作室>
[新浪点点通阅读器]
  {F0646DC8-58CD-4C64-8F6B-525043914685} <C:\PROGRAM FILES\SINA\UC\UCDDT\RSSBAND.DLL, 北京新浪信息技术有限公司>
[]
  {974AD624-EA50-4831-A6C0-3040F6665396} <C:\PROGRAM FILES\SINA\UC\UCDDT\RSSBAND.DLL, 北京新浪信息技术有限公司>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH8B.OCX, Macromedia, Inc.>
[photo_uploader Control]
  {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} <C:\PROGRA~1\NETEASE\POPO2004\PHOTO_~1.OCX, N/A>
[Ppinstall Control]
  {CF051549-EDE1-40F5-B440-BCD646CF2C25} <C:\WINDOWS\DOWNLO~1\PPINST~1.OCX, 网易 NetEase>
[&使用迅雷下载]
  <C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\Program\GetAllUrl.htm, N/A>

==================================
正在运行的进程
[PID: 4294948915][C:\WINDOWS\SYSTEM\MPREXE.EXE]  <Microsoft Corporation><4.10.1998>
[PID: 4294864159][G:\PROGRAM FILES\RISING\RAV\CCENTER.EXE]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [G:\PROGRAM FILES\RISING\RAV\EXTOLE.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [G:\PROGRAM FILES\RISING\RAV\UNPACKER.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [G:\PROGRAM FILES\RISING\RAV\SCANEXEC.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [G:\PROGRAM FILES\RISING\RAV\SCANSCT.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 15>
    [G:\PROGRAM FILES\RISING\RAV\SCANMAC.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
    [G:\PROGRAM FILES\RISING\RAV\NVFILE.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [G:\PROGRAM FILES\RISING\RAV\SCANEX.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [G:\PROGRAM FILES\RISING\RAV\UNEXE.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [G:\PROGRAM FILES\RISING\RAV\POSTTRT.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [G:\PROGRAM FILES\RISING\RAV\ENGINE.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [G:\PROGRAM FILES\RISING\RAV\SPAMENG.DLL]  <N/A><18, 0, 0, 6>
    [G:\PROGRAM FILES\RISING\RAV\MAILMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [G:\PROGRAM FILES\RISING\RAV\MEMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [G:\PROGRAM FILES\RISING\RAV\HOOKWEB.DLL]  <rising><18, 0, 0, 1>
    [G:\PROGRAM FILES\RISING\RAV\REGMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [G:\PROGRAM FILES\RISING\RAV\VIRUSLIB.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [G:\PROGRAM FILES\RISING\RAV\LIBLOAD.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [G:\PROGRAM FILES\RISING\RAV\SCANNER.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [G:\PROGRAM FILES\RISING\RAV\HOOKSYS.DLL]  <Rising><18, 1, 0, 9>
    [G:\PROGRAM FILES\RISING\RAV\RSLOG.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
    [G:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [G:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [G:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [G:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL]  <rising><18, 0, 0, 1>
[PID: 4294867123][G:\PROGRAM FILES\RISING\RAV\RAVMOND.EXE]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 26>
    [G:\PROGRAM FILES\RISING\RAV\BWLIST.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [G:\PROGRAM FILES\RISING\RAV\PNGDLL.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [G:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL]  <rising><18, 0, 0, 1>
    [G:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [G:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [G:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[PID: 4294863387][G:\PROGRAM FILES\RISING\RAV\RAVMON.EXE]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 26>
    [G:\PROGRAM FILES\RISING\RAV\BWLIST.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [G:\PROGRAM FILES\RISING\RAV\RSGUILIB.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
    [C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WEB FOLDERS\MSONSEXT.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\VIRUS CHASER\SHELLEXE.DLL]  <New Technology Wave Inc.><5, 0, 0, 0>
    [G:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\PROGRAM FILES\WINRAR\RAREXT.DLL]  <N/A><N/A>
    [G:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
]=¥/<βbbs.ikaka.comq¢ß´Á­€i‘
最后编辑2006-06-25 10:15:35
分享到:
gototop
 

[C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_001.DLL]  <Thunder Networking Technologies,LTD><5, 0, 0, 1>
    [C:\WINDOWS\SYSTEM\DHCPCSVC.DLL]  <N/A><N/A>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\WINDOWS\SYSTEM\RAVEXT.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[PID: 4294889263][C:\WINDOWS\EXPLORER.EXE]  <Microsoft Corporation><4.72.3110.1>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
[PID: 4294826855][C:\WINDOWS\SYSTEM\RPCSS.EXE]  <Microsoft Corporation><4.71.2900>
[PID: 4294753823][C:\WINDOWS\TASKMON.EXE]  <Microsoft Corporation><4.10.1998>
[PID: 4294740383][C:\WINDOWS\SYSTEM\INTERNAT.EXE]  <Microsoft Corporation><4.10.2222>
[PID: 4294739439][C:\WINDOWS\SYSTEM\SYSTRAY.EXE]  <Microsoft Corporation><4.10.2222>
    [G:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL]  <rising><18, 0, 0, 1>
    [G:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [G:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [G:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 4294649971][G:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH8B.OCX]  <Macromedia, Inc.><8,0,24,0>
    [G:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\PROGRAM FILES\CHINANET\DLGSKIN.OCX]  <4><2005, 11, 14, 1>
    [C:\PROGRAM FILES\CHINANET\ALLFUNCTIONS.DLL]  <GDCN><2005, 10, 9, 1>
    [C:\PROGRAM FILES\CHINANET\VNETOPTLOG.DLL]  <$><2005, 9, 13, 9>
    [C:\PROGRAM FILES\CHINANET\VNETONLINEUPDATE.OCX]  <<><2005, 3, 2, 1>
    [C:\PROGRAM FILES\CHINANET\STATNUM.DLL]  <$><2004, 11, 18, 1>
    [C:\PROGRAM FILES\CHINANET\VNETLOG.OCX]  <8><2005, 10, 9, 1>
    [C:\PROGRAM FILES\CHINANET\ALLINTERFACE.DLL]  <(><2004, 11, 23, 1>
    [C:\PROGRAM FILES\CHINANET\PLUGPUSH.DLL]  <$><2004, 12, 21, 1>
    [C:\WINDOWS\SYSTEM\WPCAP.DLL]  <Politecnico di Torino><3, 0, 0, 18>
    [C:\WINDOWS\SYSTEM\PACKET.DLL]  <Politecnico di Torino><3, 0, 0, 18>
    [C:\WINDOWS\SYSTEM\PTHREADVC.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\CHINANET\PASSCTRL.DLL]  <$><1, 0, 0, 1>
    [C:\PROGRAM FILES\CHINANET\NEWMESSAGE.DLL]  <(><2005, 8, 26, 1>
    [C:\PROGRAM FILES\CHINANET\PLUGINMAN.OCX]  <8><2005, 2, 24, 1>
    [C:\PROGRAM FILES\CHINANET\TIMER.OCX]  <4><2005, 10, 9, 14>
    [C:\PROGRAM FILES\CHINANET\VNETSKIN.OCX]  <GDDC><2005, 11, 14, 1>
    [C:\PROGRAM FILES\CHINANET\DIALOGSTYLE.DLL]  <$><1, 0, 0, 1>
    [C:\PROGRAM FILES\CHINANET\ACCOUNTPAGE.DLL]  <(><2005, 11, 14, 1>
    [C:\PROGRAM FILES\CHINANET\ACCOUNTMGR.DLL]  <$><2005, 11, 14, 17>
    [C:\PROGRAM FILES\CHINANET\VNETBS.OCX]  <4><2004, 11, 18, 1>
    [C:\PROGRAM FILES\CHINANET\GIF89A.DLL]  <$><2005, 6, 21, 1>
    [C:\PROGRAM FILES\CHINANET\ADVERTISE.OCX]  <8><2005, 10, 13, 1>
    [C:\PROGRAM FILES\CHINANET\POSTPLUG.DLL]  <$><2004, 12, 16, 2>
    [C:\PROGRAM FILES\CHINANET\WEBPLUGIN.DLL]  <(><2005, 8, 18, 1>
    [C:\PROGRAM FILES\CHINANET\PLUGINCONTAINER.OCX]  <<><2005, 7, 27, 1>
    [C:\PROGRAM FILES\CHINANET\SIGN.DLL]  <0><2004, 12, 1, 1>
    [C:\PROGRAM FILES\CHINANET\CLIENTAPI.DLL]  <(><2004, 2, 28, 1>
[PID: 4294747579][C:\PROGRAM FILES\CHINANET\VNETCLIENT.EXE]  <4><2005, 11, 14, 1>
    [C:\PROGRAM FILES\CHINANET\DIALMODULE.DLL]  <GDCN><2005, 11, 15, 1>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\CHINANET\COMMUNICATE.DLL]  <0><2005, 3, 3, 1>
[PID: 4294600183][C:\WINDOWS\SYSTEM\WMIEXE.EXE]  <Microsoft Corporation><5.00.1755.1>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
[PID: 4294624527][C:\PROGRAM FILES\SKYNET\FIREWALL\PFW.EXE]  <广州众达天网技术有限公司><2.7.7.1004>
    [C:\PROGRAM FILES\SKYNET\FIREWALL\COMPRESSWRAP.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\SKYNET\FIREWALL\REGCOMMONPRJ.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\SKYNET\FIREWALL\SKYMISC.DLL]  <N/A><N/A>
[PID: 4294562823][C:\WINDOWS\SYSTEM\RNAAPP.EXE]  <Microsoft Corporation><4.10.2222>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH8B.OCX]  <Macromedia, Inc.><8,0,24,0>
    [G:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
    [C:\PROGRAM FILES\TENCENT\TT\PERSONALDESKTOP.DLL]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
[PID: 4294549095][C:\PROGRAM FILES\TENCENT\TT\TTRAVELER.EXE]  <腾讯公司><2, 2, 0, 224>
[PID: 4294549303][C:\WINDOWS\SYSTEM\TAPISRV.EXE]  <Microsoft Corporation><4.10.2222>
[PID: 4294392971][C:\WINDOWS\SYSTEM\PSTORES.EXE]  <Microsoft Corporation><5.00.1877.3>
    [C:\WINDOWS\SYSTEM\NVDD32.DLL]  <NVidia Corporation><4.13.01.3140>
    [C:\WINDOWS\SYSTEM\NVARCH32.DLL]  <NVIDIA Corporation><4.13.01.3140>
[PID: 4294391039][C:\WINDOWS\SYSTEM\DDHELP.EXE]  <Microsoft Corporation><4.09.00.0900>
    [C:\WINDOWS\SYSTEM\NETBIOS.DLL]  <N/A><N/A>
[PID: 4294121283][E:\SYSTEM REPAIR ENGINEER V2.0.21.505\SRENG.EXE]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [C:\WINDOWS\winhlp32.exe %1]
.INI  OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF  OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS  OK. [C:\WINDOWS\WScript.exe "%1" %*]
.JS  OK. [C:\WINDOWS\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
]=¥/<βbbs.ikaka.comq¢ß´Á­€i‘
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT