2006-09-12,18:44:51
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows 2000 Advanced Server Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><ctfmon.exe> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
<run><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<vptray><C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe> [Symantec Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINNT\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RunServicesOnce]
<WinlogonNotify: RunServicesOnce><C:\WINNT\system32\lv6s09j7e.dll> []
==================================
启动文件夹
服务
[Command Service / cmdService]
<C:\WINNT\bWVuZ25pdS0xMjQ\command.exe><N/A>
[Logical Disk Manager Administrative Service / dmadmin]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Intel Alert Handler / Intel Alert Handler]
<C:\WINNT\system32\ams_ii\hndlrsvc.exe><Intel? Corporation>
[Intel Alert Originator / Intel Alert Originator]
<C:\WINNT\system32\ams_ii\iao.exe><Intel? Corporation>
[Intel File Transfer / Intel File Transfer]
<C:\WINNT\system32\cba\xfr.exe><Intel? Corporation>
[Intel PDS / Intel PDS]
<C:\WINNT\system32\cba\pds.exe><Intel? Corporation>
[Network Monitor / Network Monitor]
<C:\Program Files\Network Monitor\netmon.exe service><N/A>
[Remote Reader Machine / Remote Reader Machine]
<"C:\WINNT\system32\ssmc.exe"><N/A>
[Serv-U FTP Server / Serv-U]
<C:\Program Files\RhinoSoft.com\Serv-U\ServUDaemon.exe><Rhino Software, Inc. +1(262) 560-9627>
[sqldps / sqldps]
<"C:\WINNT\sqldps.exe"><N/A>
[sqlmanagement / sqlmanagement]
<"C:\WINNT\sqlmanagement.exe"><N/A>
==================================
浏览器加载项
正在运行的进程
[PID: 2232][C:\WINNT\system32\MsgSys.EXE] <Intel? Corporation><6.12.0.105 E>
[C:\WINNT\system32\NTS.dll] <Intel? Corporation><6.12.0.105 E>
[C:\WINNT\system32\CBA.DLL] <Intel? Corporation><6.12.0.105 E>
[C:\WINNT\system32\MsgSys.dll] <Intel? Corporation><6.12.0.105 E>
[C:\WINNT\system32\PDS.DLL] <Intel? Corporation><6.12.0.105 E>
[C:\WINNT\system32\NTSU2T.DLL] <Intel Corporation><6.12.0.0000 E>
[PID: 11792][C:\WINNT\system32\rundll32.exe] <Microsoft Corporation><5.00.2134.1>
[C:\WINNT\system32\fgntsub.dll] <N/A><N/A>
[PID: 11884][C:\WINNT\system32\rdpclip.exe] <Microsoft Corporation><5.00.2174.1>
[PID: 11920][C:\WINNT\Explorer.EXE] <Microsoft Corporation><5.00.3700.6690>
[C:\WINNT\system32\fgntsub.dll] <N/A><N/A>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[PID: 12004][C:\dfndrff_17.exe] <...r..tr..rt.r.tr..t.rt...rr.t.rt..t.rt.tr.r.tr><1.00.0212>
[PID: 12032][C:\WINNT\system32\ctfmon.exe] <Microsoft Corporation><1.00.2409.34 built by: Lab06_N>
[PID: 12076][C:\Program Files\WinRAR\WinRAR.exe] <N/A><N/A>
[PID: 12100][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2\Rar$EX00.187\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
求高手帮解释一下这个日志好嘛?