2006-09-03,16:03:07
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\windows\system32\ctfmon.exe> [Microsoft Corporation]
<Super Rabbit IEPro><C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD> [Super Rabbit Soft]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002ASync><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<MSPY2002><C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC> []
<RunShadowTip><C:\WINDOWS\system32\shadow\ShadowTip.exe> [PowerShadow]
<TkBellExe><; ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> []
<Windows木马防火墙><; C:\Program Files\ftc\Trojanwall.exe> [风云谷]
<Torjan Program><C:\windows\WINLOGON.EXE> [CyFdqHKB3ES8XNIP2Ynm]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<Torjan Program><C:\windows\WINLOGON.EXE> [CyFdqHKB3ES8XNIP2Ynm]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<9><C:\windows\system32\Ravdm.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe 1> []
<Userinit><C:\windows\system32\Userinit.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
==================================
启动文件夹
服务
[Database information combine / DbooInfo]
<><N/A>
[Shadow System Service / ShadowSystemService]
<C:\WINDOWS\system32\shadow\ShadowService.exe><N/A>
==================================
浏览器加载项
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[Schedule Class]
{8B316DA1-9950-4926-B9EA-1AEC124AFA45} <C:\windows\system32\sscli.dll, >
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[QQBrowserHelper
Object Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[超级兔子上网精灵]
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[TjqFshnr Class]
{85693BE7-E6DD-78CB-1074-CF7BD8C04376} <C:\WINDOWS\DOWNLO~1\lkaovc.dll, fiwjksoft>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Schedule Class]
{8B316DA1-9950-4926-B9EA-1AEC124AFA45} <C:\windows\system32\sscli.dll, >
[WAB Importer/Exporter]
{AA158CA5-93B4-4CD4-8D8C-BB6F9F515213} <, N/A>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Shockwave Flash
Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\flash.ocx, Macromedia, Inc.>
[]
{E730189A-9973-4121-B046-AD1C161EC3AF} <C:\WINDOWS\system32\37211.dll, N/A>
[bho Class]
{ED8DFC5C-10EF-45AB-9DC2-0639AFF5A270} <C:\PROGRA~1\COMMON~1\Wnwb\wnwbio.dll, 深圳世强软件开发部>
==================================
正在运行的进程
[PID: 288][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 336][\??\C:\windows\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 360][\??\C:\windows\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 404][C:\windows\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 416][C:\windows\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 572][C:\windows\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 632][C:\windows\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 700][C:\windows\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 768][C:\windows\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 816][C:\windows\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1016][C:\windows\Explorer.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\shadow\pDeskTop.dll] <N/A><N/A>
[C:\windows\system32\sscli.dll] <><5, 0, 2195, 6696>
[PID: 1044][C:\windows\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1332][C:\windows\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1384][C:\windows\WINLOGON.EXE] <CyFdqHKB3ES8XNIP2Ynm><0.00.0097>
[PID: 1496][C:\WINDOWS\system32\shadow\ShadowService.exe] <N/A><N/A>
[PID: 1968][C:\windows\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1840][C:\WINDOWS\system32\shadow\ShadowTip.exe] <PowerShadow><1, 0, 0, 1>
[C:\WINDOWS\system32\shadow\pDeskTop.dll] <N/A><N/A>
[PID: 716][C:\Program Files\Maxthon\Maxthon.exe] <Maxthon International Ltd.><1, 5, 2, 21>
[C:\Program Files\Maxthon\maxzlib.dll] < ><1, 0, 0, 2>
[C:\Program Files\Maxthon\Services\RealTime\real_time.dll] <><1, 0, 0, 1>
[C:\WINDOWS\system32\macromed\flash\flash.ocx] <Macromedia, Inc.><6,0,79,0>
[C:\WINDOWS\system32\PNCRT.dll] <Real Networks, Inc><6.0.0.0>
[C:\Program Files\Common Files\Real\Common\pnrs3260.dll] <RealNetworks, Inc.><6.0.9.3584>
[C:\WINDOWS\system32\rmoc3260.dll] <RealNetworks, Inc.><6.0.9.1860>
[C:\Program Files\Real\RealPlayer\rpplugins\embd3260.dll] <RealNetworks, Inc.><6.0.12.857>
[C:\Program Files\Common Files\Real\Common\pngu3267.dll] <RealNetworks, Inc.><6.7.0.2228>
[C:\Program Files\Common Files\Real\Common\objb3201.dll] <RealNetworks, Inc.><0.1.0.5835>
[C:\Program Files\Real\RealPlayer\rpplugins\rpcl3260.dll] <RealNetworks, Inc.><6.0.9.2622>
[C:\Program Files\Real\RealPlayer\rpplugins\rput3260.dll] <RealNetworks, Inc.><6.0.9.2603>
[C:\Program Files\Common Files\Real\Common\pnen3260.dll] <RealNetworks, Inc.><10.0.0.441>
[C:\Program Files\Common Files\Real\Plugins\vsrlocal.dll] <RealNetworks, Inc.><10.1.0.368>
[C:\Program Files\Common Files\Real\Plugins\zipf3260.dll] <RealNetworks, Inc.><6.0.8.2095>
[C:\Program Files\Common Files\Real\Plugins\vidsite.dll] <RealNetworks, Inc.><10.0.0.440>
[C:\Program Files\Common Files\Real\Plugins\clntxres.dll] <RealNetworks, Inc.><10.0.0.1990>
[C:\Program Files\Real\RealPlayer\lang\cdplay_cn.dll] <RealNetworks, Inc.><6.0.12.261>
[C:\Program Files\Real\RealPlayer\lang\dbcomp_cn.dll]