[CODE]
2009-11-06,09:38:34
System Repair Engineer 2.8.1.1279
Smallfrogs (
http://www.KZTechs.com)
Windows 2000 Server Service Pack 4 (Build 2195) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
计划任务
Windows 安全更新检查
API HOOK
隐藏进程
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Internat.exe><internat.exe> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<AtiPTA><Atiptaxx.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows 2000 Publisher]
<Userinit><C:\WINNT\system32\userinit.exe,> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<Network.ConnectionTray><C:\WINNT\system32\NETSHELL.dll> [(Verified)Microsoft Windows 2000 Publisher]
<WebCheck><%SystemRoot%\system32\webcheck.dll> [(Verified)Microsoft Windows Component Publisher]
<SysTray><stobject.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
<WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
<WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
<WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
<WinlogonNotify: sclgntfy><sclgntfy.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
<WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
<WinlogonNotify: termsrv><wlnotify.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
<WinlogonNotify: wzcnotif><wzcdlg.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
<自定义浏览器><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6A5110B5-E14B-4268-A065-EF89FF33C325}]
<EnableRevocation><regsvr32.exe /s /n /i:"S 2 true 3 true 4 true 5 true 6 true 7 true" initpki.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\wmp.inf,PerUserStub> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{735B2C59-7C9F-44CD-93C4-A1D9660F9F17}]
<N/A><C:\WINNT\windower.exe> [Jiangmin Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<Address Book 5><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
<Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll> [(Verified)Microsoft Windows 2000 Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
<Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
<CRLUpdate><%SystemRoot%\system32\updcrl.exe -e -u %SystemRoot%\system32\verisignpub1.crl> [File is missing]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><(无)> [N/A]
==================================
启动文件夹
[服务管理器]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\服务管理器.lnk --> C:\PROGRA~1\MICROS~3\80\Tools\Binn\sqlmangr.exe [Microsoft Corporation]><N>
==================================
服务
[360ver.dll / 360ver.dll][Running/Auto Start]
<C:\WINNT\system32\qrkbin.exe><360安全中心>
[360安全卫士系统漏洞安全更新 / 360安全卫士系统漏洞安全更新][Stopped/Manual Start]
<C:\WINNT\System32\svchost.exe -k "360安全卫士系统漏洞安全更新"-->C:\WINNT\system32\efcebf.dll><Microsoft Corporation>
[360安全卫士系统防御模块 / 360安全卫士系统防御模块][Stopped/Manual Start]
<C:\WINNT\System32\svchost.exe -k "360安全卫士系统防御模块"-->C:\WINNT\system32\bb11f4.dll><Microsoft Corporation>
[360安全卫士自我保护组件 / 360安全卫士自我保护组件][Running/Auto Start]
<C:\WINNT\System32\svchost.exe -k "360安全卫士自我保护组件"-->C:\WINNT\system32\11a9b59.dll><Microsoft Corporation>
[360杀毒全盘文件实时监控 / 360杀毒全盘文件实时监控][Running/Auto Start]
<C:\WINNT\system32\nvscv.exe><360安全中心>
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Microsoft Search / MSSEARCH][Running/Auto Start]
<"C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe"><Microsoft Corporation>
[MSSQLSERVER / MSSQLSERVER][Running/Auto Start]
<d:\MICROS~1\MSSQL\binn\sqlservr.exe><Microsoft Corporation>
[MSSQLServerADHelper / MSSQLServerADHelper][Stopped/Manual Start]
<C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe><Microsoft Corporation>
[Nationalgub Instruments Domain Service / Nationalxjs][Stopped/Auto Start]
<C:\WINNT\system32\eumseg.exe><(File is missing)>
[office升级补丁 / office升级补丁][Running/Auto Start]
<C:\WINNT\system32\lassq.exe><360安全中心>
[SQLSERVERAGENT / SQLSERVERAGENT][Running/Auto Start]
<d:\MICROS~1\MSSQL\binn\sqlagent.exe><Microsoft Corporation>
[Mnnection Sharser / tcways][Running/Auto Start]
<C:\WINNT\System32\svchost.exe -k krnlsrvc-->C:\WINNT\system32\RlmktrC.dll><@ Microsoft Corporation. All rights reserved.>
[Windowskxxgh Help System / WinHelpkxxgh][Stopped/Manual Start]
<C:\WINNT\system32\WinHelpkkxxgh.exe><Beijing Rising Information Technology Co., Ltd.>
[VNC Server Version 4 / WinVNC4][Running/Manual Start]
<"C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service><RealVNC Ltd.>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
<C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\system32\mspmsnsv.dll><Microsoft Corporation>
==================================
驱动程序
[ati2mpad / ati2mpad][Running/Manual Start]
<system32\DRIVERS\ati2mpad.sys><ATI Technologies Inc.>
[atirage3 / atirage3][Stopped/Manual Start]
<system32\DRIVERS\atimpab.sys><ATI Technologies Inc.>
[dmboot / dmboot][Stopped/Disabled]
<System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio][Running/Boot Start]
<\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload][Running/Boot Start]
<\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[Intel(R) PRO/1000 Network Connection Driver / E1000][Running/Manual Start]
<system32\DRIVERS\e1000nt5.sys><Intel Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
==================================
浏览器加载项
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, >
[@msdxmLC.dll,-1@2052,电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, (Signed) Microsoft Corporation>
==================================
正在运行的进程
[PID: 172][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.00.2195.6601]
[PID: 196][\??\C:\WINNT\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.00.2195.6601]
[PID: 216][\??\C:\WINNT\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.00.2195.6898]
[PID: 244][C:\WINNT\system32\services.exe] [(Verified) Microsoft Corporation, 5.00.2195.6700]
[C:\WINNT\system32\dmserver.dll] [VERITAS Software Corp., 2195.6605.297.3]
[PID: 256][C:\WINNT\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.00.2195.6902]
[PID: 448][C:\WINNT\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.00.2134.1]
[PID: 476][C:\WINNT\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.00.2195.6659]
[PID: 504][C:\WINNT\system32\msdtc.exe] [(Verified) Microsoft Corporation, 1999.9.3421.3]
[PID: 628][C:\WINNT\system32\qrkbin.exe] [360安全中心, 1, 0, 0, 1053]
[PID: 648][C:\WINNT\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.00.2134.1]
[c:\winnt\system32\11a9b59.dll] [Microsoft Corporation, 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 660][C:\WINNT\system32\nvscv.exe] [360安全中心, 1, 0, 0, 1053]
[PID: 676][C:\WINNT\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.00.2134.1]
[PID: 720][C:\WINNT\System32\llssrv.exe] [(Verified) Microsoft Corporation, 5.00.2195.6697]
[PID: 752][d:\MICROS~1\MSSQL\binn\sqlservr.exe] [Microsoft Corporation, 2000.080.0194.00]
[d:\MICROS~1\MSSQL\binn\OPENDS60.DLL] [Microsoft Corporation, 2000.080.0194.00]
[d:\MICROS~1\MSSQL\binn\UMS.DLL] [Microsoft Corporation, 2000.080.0194.00]
[d:\MICROS~1\MSSQL\binn\SQLSORT.DLL] [Microsoft Corporation, 2000.080.0194.00]
[d:\MICROS~1\MSSQL\binn\Resources\2052\sqlevn70.RLL] [Microsoft Corporation, 2000.080.0194.00]
[d:\MICROS~1\MSSQL\binn\SSNETLIB.dll] [Microsoft Corporation, 2000.080.0194.00]
[d:\MICROS~1\MSSQL\binn\SSNMPN70.dll] [Microsoft Corporation, 2000.080.0194.00]
[d:\MICROS~1\MSSQL\binn\SSmsLPCn.dll] [Microsoft Corporation, 2000.080.0194.00]
[d:\MICROS~1\MSSQL\binn\SQLFTQRY.DLL] [Microsoft Corporation, 2000.080.0194.00]
[d:\MICROS~1\MSSQL\binn\xpsqlbot.dll] [Microsoft Corporation, 2000.080.0194.00]
[PID: 844][C:\WINNT\system32\lassq.exe] [360安全中心, 1, 0, 0, 1053]
[PID: 872][C:\WINNT\system32\regsvc.exe] [(Verified) Microsoft Corporation, 5.00.2195.6701]
[PID: 352][C:\WINNT\system32\MSTask.exe] [(Verified) Microsoft Corporation, 4.71.2195.6704]
[PID: 928][C:\WINNT\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.00.2134.1]
[c:\winnt\system32\rlmktrc.dll] [@ Microsoft Corporation. All rights reserved., 5.1.2600.2180]
[PID: 992][C:\WINNT\system32\Dfssvc.exe] [(Verified) Microsoft Corporation, 5.00.2195.6664]
[PID: 1012][C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe] [Microsoft Corporation, 9.107.5512.0]
[C:\Program Files\Common Files\System\MSSearch\Bin\mssws.dll] [Microsoft Corporation, 9.107.5512.0]
[C:\PROGRA~1\COMMON~1\System\MSSearch\Bin\mssrch.dll] [Microsoft Corporation, 9.107.5512.0]
[C:\Program Files\Common Files\System\MSSearch\Bin\tquery.dll] [Microsoft Corporation, 9.107.5512.0]
[C:\PROGRA~1\COMMON~1\System\MSSearch\Bin\propdefs.dll] [Microsoft Corporation, 9.107.5512.0]
[C:\PROGRA~1\COMMON~1\System\MSSearch\Bin\srchidx.dll] [Microsoft Corporation, 9.107.5512.0]
[PID: 1040][C:\WINNT\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.00.2134.1]
[PID: 1156][C:\WINNT\Explorer.EXE] [(Verified) Microsoft Corporation, 5.00.3700.6690]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[PID: 1184][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2800.1106]
[PID: 1220][C:\WINNT\system32\Atiptaxx.exe] [ATI Technologies, Inc., 6.13.2523]
[C:\WINNT\system32\ATRPUIXX.CHS] [ATI Technologies, Inc., 6.13.2523]
[C:\WINNT\system32\atipdsxx.dll] [ATI Technologies, Inc., 6.13.2523]
[PID: 1248][C:\WINNT\system32\internat.exe] [(Verified) Microsoft Corporation, 5.00.2920.0000]
[PID: 1260][C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Microsoft SQL Server\80\Tools\Binn\W95SCM.dll] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Microsoft SQL Server\80\Tools\Binn\SQLSVC.dll] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Microsoft SQL Server\80\Tools\Binn\SQLRESLD.dll] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Microsoft SQL Server\80\Tools\Binn\Resources\2052\SQLSVC.RLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Microsoft SQL Server\80\Tools\Binn\Resources\2052\sqlmangr.RLL] [Microsoft Corporation, 2000.080.0194.00]
[PID: 1384][d:\MICROS~1\MSSQL\binn\sqlagent.exe] [Microsoft Corporation, 2000.080.0194.00]
[d:\MICROS~1\MSSQL\binn\SQLRESLD.dll] [Microsoft Corporation, 2000.080.0194.00]
[d:\MICROS~1\MSSQL\binn\SQLSVC.dll] [Microsoft Corporation, 2000.080.0194.00]
[d:\MICROS~1\MSSQL\binn\W95SCM.dll] [Microsoft Corporation, 2000.080.0194.00]
[d:\MICROS~1\MSSQL\binn\SEMMAP.dll] [Microsoft Corporation, 2000.080.0194.00]
[d:\MICROS~1\MSSQL\binn\Resources\2052\SQLSVC.RLL] [Microsoft Corporation, 2000.080.0194.00]
[d:\MICROS~1\MSSQL\binn\Resources\2052\SEMMAP.RLL] [Microsoft Corporation, 2000.080.0194.00]
[d:\MICROS~1\MSSQL\binn\Resources\2052\sqlagent.RLL] [Microsoft Corporation, 2000.080.0194.00]
[d:\MICROS~1\MSSQL\binn\SQLAGENT.DLL] [Microsoft Corporation, 2000.080.0194.00]
[d:\Microsoft SQL Server\MSSQL\BINN\SQLCMDSS.DLL] [Microsoft Corporation, 2000.080.0194.00]
[d:\Microsoft SQL Server\MSSQL\BINN\Resources\2052\SQLCMDSS.RLL] [Microsoft Corporation, 2000.080.0194.00]
[d:\Microsoft SQL Server\MSSQL\BINN\SQLREPSS.DLL] [Microsoft Corporation, 2000.080.0194.00]
[d:\Microsoft SQL Server\MSSQL\BINN\Resources\2052\SQLREPSS.RLL] [Microsoft Corporation, 2000.080.0194.00]
[d:\Microsoft SQL Server\MSSQL\BINN\SQLATXSS.DLL] [Microsoft Corporation, 2000.080.0194.00]
[d:\Microsoft SQL Server\MSSQL\BINN\Resources\2052\SQLATXSS.RLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Microsoft SQL Server\80\Tools\BINN\AXSCPHST.DLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\Program Files\Microsoft SQL Server\80\Tools\BINN\Resources\2052\AXSCPHST.RLL] [Microsoft Corporation, 2000.080.0194.00]
[C:\WINNT\system32\DBmsLPCn.dll] [Microsoft Corporation, 2000.080.0194.00]
[PID: 1192][C:\WINNT\system32\mmc.exe] [(Verified) Microsoft Corporation, 5.00.2195.6601]
[C:\WINNT\System32\dmutil.dll] [VERITAS Software Corp., 2195.6605.297.3]
[C:\WINNT\system32\dfrgsnap.dll] [Executive Software International, Inc., 5.00.2195.6605]
[C:\WINNT\system32\DfrgRes.dll] [Executive Software International, Inc., 5.00.2150.1]
[PID: 1240][C:\WINNT\system32\conime.exe] [(Verified) Microsoft Corporation, 5.00.2195.6655]
[PID: 1488][C:\Program Files\RealVNC\VNC4\WinVNC4.exe] [RealVNC Ltd., 版本 4.0]
[C:\Program Files\RealVNC\VNC4\wm_hooks.dll] [RealVNC Ltd., 4.0]
[PID: 1388][C:\WINNT\system32\cmd.exe] [(Verified) Microsoft Corporation, 5.00.2195.6824]
[PID: 580][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2800.1106]
[PID: 1520][C:\WINNT\regedit.exe] [(Verified) Microsoft Corporation, 5.00.2195.6707]
[PID: 1392][C:\Documents and Settings\Administrator\桌面\sreng2\SREngLdr.EXE] [Smallfrogs Studio, 2.8.1.1279]
[PID: 364][C:\Documents and Settings\Administrator\桌面\sreng2\SREc5e366b1.EXE] [Smallfrogs Studio, 2.8.1.1279]
[C:\Documents and Settings\Administrator\桌面\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)