CODE]
2006-12-30,13:03:08
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows Server 2003 Enterprise Edition (Build 3790)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<xysecond><D:\tem\VRV2005\VRV2005\vrv2005\vrvmon.exe> [vrv]
<RavTask><"D:\Program Files\Rising\Rav1\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><D:\WINDOWS\system32\userinit.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><235780M.BMP> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><%SystemRoot%\system32\logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{9C0CFA58-3A6F-51ba-9EFE-5320F4F62FB1}><D:\WINDOWS\system32\bdscheca100.dll> [N/A]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><D:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<csrss><; D:\WINDOWS\csrss.exe> [N/A]
<System><; D:\Program Files\Common Files\System\Updaterun.exe> [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<Windows installer><; C:\winstall.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<{202718E6-0957-2052-1008-030207290056}><; "D:\Program Files\Common Files\{202718E6-0957-2052-1008-030207290056}\Update.exe" te-110-12-0000175> [N/A]
<{202718E6-0958-2052-1008-030207290056}><; "D:\Program Files\Common Files\{202718E6-0958-2052-1008-030207290056}\Update.exe" te-110-12-0000175> [N/A]
==================================
启动文件夹
N/A
==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
<D:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"D:\Program Files\Rising\Rav1\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon][Stopped/Auto Start]
<"D:\Program Files\Rising\Rav1\Ravmond.exe"><N/A>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<D:\WINDOWS\system32\rundll32.exe windhcp.ocx,start><Microsoft Corporation>
==================================
驱动程序
[ati2mpad / ati2mpad][Running/Manual Start]
<system32\DRIVERS\ati2mpad.sys><ATI Technologies Inc.>
[BaseTDI / BaseTDI][Running/Auto Start]
<\??\D:\WINDOWS\system32\drivers\basetdi.sys><Beijing Rising Technology Co., Ltd.>
[Intel(R) PRO/1000 Device Driver / E1000][Running/Manual Start]
<system32\DRIVERS\e1000325.sys><Intel Corporation>
[ExpScaner / ExpScaner][Running/Auto Start]
<\??\D:\Program Files\Rising\Rav1\ExpScan.sys><>
[HookCont / HookCont][Running/Auto Start]
<\??\D:\Program Files\Rising\Rav1\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
<\??\D:\Program Files\Rising\Rav1\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\D:\Program Files\Rising\Rav1\HookSys.sys><Rising>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
<system32\DRIVERS\ipinip.sys><N/A>
[MicroSoft Media Services / MediaDrver][Stopped/Manual Start]
<\??\D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\YpOCalLH.sys><N/A>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\D:\Program Files\Rising\Rav1\MEMSCAN.sys><瑞星软件有限公司>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
<system32\DRIVERS\npf.sys><CACE Technologies>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
<\??\D:\Program Files\Rising\Rav1\RSPPSYS.sys><Rising>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1][Stopped/Manual Start]
<system32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[SVKP / SVKP][Running/Auto Start]
<\??\D:\WINDOWS\system32\SVKP.sys><AntiCracking>
[symmpi / symmpi][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\symmpi.sys><LSI Logic>
[xyfilemon / xyantivirus][Running/Auto Start]
<\??\D:\tem\VRV2005\VRV2005\vrv2005\filemon.sys><BXY>
==================================
浏览器加载项
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[上传到QQ网络硬盘]
<D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 404][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 464][\??\D:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 488][\??\D:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 540][D:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 552][D:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 748][D:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 796][D:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 916][D:\Program Files\Rising\Rav1\CCenter.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 980][D:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 1080][D:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 1120][D:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 1344][D:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 1380][D:\WINDOWS\system32\msdtc.exe] [Microsoft Corporation, 2001.12.4720.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 1492][D:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 1568][D:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1912][D:\WINDOWS\system32\Dfssvc.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[D:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[PID: 2044][D:\tem\VRV2005\VRV2005\vrv2005\vrvmon.exe] [vrv, 1, 0, 0, 1]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[D:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[D:\tem\VRV2005\VRV2005\vrv2005\vrvmonsc.dll] [BeiXinYuan, 1, 0, 0, 1]
[D:\tem\VRV2005\VRV2005\vrv2005\vrvcfg.dll] [N/A, N/A]
[D:\tem\VRV2005\VRV2005\vrv2005\vrvdll.dll] [N/A, N/A]
[D:\tem\VRV2005\VRV2005\vrv2005\UNARJ.dll] [N/A, N/A]
[D:\tem\VRV2005\VRV2005\vrv2005\UNZIP.dll] [N/A, N/A]
[D:\WINDOWS\system32\bdscheca100.dll] [N/A, N/A]
[PID: 216][D:\Program Files\Rising\Rav1\RavTask.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[D:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[D:\Program Files\Rising\Rav1\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[D:\Program Files\Rising\Rav1\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[D:\Program Files\Rising\Rav1\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[D:\Program Files\Rising\Rav1\RsCommX.dll] [rising, 18, 0, 0, 1]