(上接6楼)
2006-06-19,16:41:00
System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)
Windows 2000 Professional Service Pack 3 (Build 2195)
- 非管理权限用户 - 受限功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Internat.exe><internat.exe> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Synchronization Manager><mobsync.exe /logon> [Microsoft Corporation]
<KnightIII><> []
<MS-4011 Memory Patch><C:\Documents and Settings\user.LULIN-1\桌面\RavSasser.exe -Patch> []
<OfficeScanNT Monitor><"C:\OfficeScan NT\pccntmon.exe" -HideWindow> [Trend Micro Inc.]
<Uninstall0001><"C:\Program Files\Common Files\Totem Shared\Uninstall0001\upd.exe" LASTCALL!adverts.stripsaver.com!StatsStripSaver> []
<StormCodec_Helper><"D:\tools\Storm Codec\StormSet.exe" /S /opti> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<Super Rabbit Winspeed><"D:\tools\MagicSet\winspeed.exe" /autokill:81,119,118,117,116,115,114,113,112,111,110,109,108,107,106,105,104,103,102,101,100,99,98,97,96,95,94,93,92,91,90,89,88,87,86,85,84,83,82,80,79,78,77,76,75,74,73,72,71,70,69,68,67,66,65,64,63,62,61,60,59,58,57,56,55,54,53,52,51,50,49,48,47,46,45,44,43,42,41,40,39,38,37,36,35,34,33,32,31,30,29,28,27,26,25,24,23,22,21,20,19,18,17,16,15,14,13,12,11,10,9,8,7,6,5,4,3,2,1> [Super Rabbit Soft]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINNT\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
==================================
启动文件夹
[Acrobat Assistant]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Acrobat Assistant.lnk><N>
[OfficeScanNT Monitor]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\OfficeScanNT Monitor.lnk><N>
[金山词霸 2003]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\金山词霸 2003.lnk><N>
==================================
服务
[Logical Disk Manager Administrative Service / dmadmin]
<C:\Winnt\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Intel(R) NMS / NMSSvc]
<C:\Winnt\System32\NMSSvc.exe><Intel Corporation>
[OfficeScanNT RealTime Scan / ntrtscan]
<C:\OfficeScan NT\ntrtscan.exe><Trend Micro Inc.>
[OfficeScanNT Listener / tmlisten]
<C:\OfficeScan NT\tmlisten.exe><N/A>
[UCManSvc / UCManSvc]
<C:\Winnt\UCharge\UCManSvc.exe><Paltiosoft Inc.>
[Unigraphics Plot Server (ugiipqd) / ugiipqd]
<C:\Winnt\System32\spool\ugplot\ugiipqd.exe><N/A>
[Unigraphics License Server (uglmd) / Unigraphics License Server (uglmd)]
<D:\Program Files\EDS\License Servers\UGNXFLEXlm\lmgrd.exe><GLOBEtrotter Software Inc.>
==================================
浏览器加载项
[NetAnts]
{57E91B47-F40A-11D1-B792-444553540000} <D:\PROGRA~1\NetAnts\NetAnts.exe, >
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <d:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <d:\Program Files\Tencent\QQ\QQIEHelper.dll, N/A>
[@msdxmLC.dll,-1@2052,电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\System32\msdxm.ocx, Microsoft Corporation>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, N/A>
[搜刮音乐]
{902DF477-B757-44DD-9430-2EE942187BEC} <C:\PROGRA~1\Sogua\SOGUAT~1.DLL, >
[OfficeScan Corp Edition Web-Deployment SetupIniCtrl Class]
{08D75BB0-D2B5-11D1-88FC-0080C859833B} <C:\WINNT\Downloaded Program Files\OfficeScanSetupIni.dll, Trend Micro Inc.>
[OfficeScan Corp Edition Web-Deployment SetupCtrl Class]
{08D75BC1-D2B5-11D1-88FC-0080C859833B} <C:\WINNT\Downloaded Program Files\OfficeScanSetup.dll, Trend Micro Inc.>
[Mediachip ADPlayer Control]
{2D0C7226-747E-11D6-83F0-00E04C4A2F90} <C:\Winnt\System32\MEDIAC~1\ADPlayer\MCADPL~1.OCX, Mediachip>
[CEditCtrl
Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\Winnt\system32\aliedit\AliEdit.dll, www.alipay.com>
[OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class]
{5EFE8CB1-D095-11D1-88FC-0080C859833B} <C:\WINNT\Downloaded Program Files\OfficeScanRemoveCtrl.dll, Trend Micro Inc.>
[趋势科技在线扫毒程序]
{74D05D43-3236-11D4-BDCD-00C04F9A3B61} <C:\Winnt\DOWNLO~1\xscan53.ocx, Trend Micro Inc.>
[Windchill Bootstrap]
{76FFDFB5-04C4-11D3-893A-00505682087D} <C:\Winnt\System32\MSJAVA.DLL, Microsoft Corporation>
[Shockwave Flash
Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\Winnt\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[&使用迷你迅雷下载]
<D:\Program Files\Maxthon\Thundermini\geturl.htm, N/A>
[Save Flash with Flash Catcher]
<res://C:\Program Files\Common Files\justDo\IECatcher.DLL/FlashCatcher.htm, N/A>
[使用影音传送带下载]
<D:\Program Files\Xi\NetTransport 2\NTAddLink.html, N/A>
[使用影音传送带下载全部链接]
<D:\Program Files\Xi\NetTransport 2\NTAddList.html, N/A>
[使用网际快车下载]
<D:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<D:\Program Files\FlashGet\jc_all.htm, N/A>
==================================
正在运行的进程
[PID: 1080][C:\Winnt\Explorer.EXE] <Microsoft Corporation><5.00.3502.5321>
[D:\Program Files\Kingsoft\Powerword 2003\Cjktl32.dll] <N/A><N/A>
[d:\Program Files\全能音频转换通\ShellEx.dll] <><1, 0, 0, 1>
[D:\Program Files\Tencent\QQ\qdshm.dll] <><1, 0, 1, 2>
[D:\PROGRA~1\WINZIP\WZSHLSTB.DLL] <WinZip Computing, Inc.><4.1 (32-bit)>
[C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL] <N/A><N/A>
[D:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[d:\Program Files\IDM Computer Solutions\UltraEdit-32\ue32ctmn.dll] <><1, 0, 0, 1>
[C:\OfficeScan NT\tmdshell.dll] <Trend Micro Inc.><N/A>
[d:\PROGRA~1\AUDIOC~1\acshext.dll] <Ultimate Shareware Ltd><5, 0, 62, 0>
[d:\PROGRA~1\AUDIOC~1\audconv.dll] <Ultimate Shareware Ltd><5, 0, 664, 0>
[d:\PROGRA~1\AUDIOC~1\audiocd.dll] <AKSoft><1.0rc2>
[C:\Winnt\system32\WNASPI32.DLL] <Adaptec><4.60 (1021)>
[PID: 1180][C:\Program Files\Common Files\Totem Shared\Uninstall0001\upd.exe] <N/A><N/A>
[C:\Program Files\Common Files\Totem Shared\Uninstall0001\Stats.dll] <N/A><N/A>
[C:\Program Files\Common Files\Totem Shared\Uninstall0001\Network.dll] <N/A><N/A>
[C:\Program Files\Common Files\Totem Shared\Uninstall0001\System.dll] <N/A><N/A>
[C:\Program Files\Common Files\Totem Shared\Uninstall0001\Windows.dll] <N/A><N/A>
[C:\Program Files\Common Files\Totem Shared\Uninstall0001\Update.dll] <N/A><N/A>
[PID: 1248][C:\Winnt\system32\internat.exe] <Microsoft Corporation><5.00.2920.0000>
[D:\Program Files\Kingsoft\Powerword 2003\Cjktl32.dll] <N/A><N/A>
[PID: 1256][D:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe] <Adobe Systems Inc.><5, 0, 0, 0>
[PID: 1264][C:\OfficeScan NT\PccNTMon.exe] <Trend Micro Inc.><5.58.0.1063>
[C:\OfficeScan NT\PWD.dll] <Trend Micro Inc.><5.58.0.1063>
[C:\OfficeScan NT\dBAllDat.dll] <Trend Micro Inc.><5.58.0.1063>
[C:\OfficeScan NT\tmdbg20.dll] <trend_company_name><1, 0, 0, 1>
[C:\OfficeScan NT\dballcfg.dll] <Trend Micro Inc.><5.58.0.1063>
[C:\OfficeScan NT\c4dll.dll] <N/A><N/A>
[C:\OfficeScan NT\dBAllLog.dll] <Trend Micro Inc.><5.58.0.1063>
[C:\OfficeScan NT\loadhttp.dll] <Trend Micro Inc.><5.58.0.1063>
[C:\OfficeScan NT\ntmonres.dll] <Trend Micro Inc.><5.58.0.1063>
[D:\Program Files\Kingsoft\Powerword 2003\Cjktl32.dll] <N/A><N/A>
[PID: 1272][D:\Program Files\Kingsoft\Powerword 2003\XDICT.EXE] <Kingsoft Co, Ltd.><6, 0, 0, 0>
[D:\Program Files\Kingsoft\Powerword 2003\ITextOut.dll] <Kingsoft><1, 1, 0, 0>
[D:\Program Files\Kingsoft\Powerword 2003\CJKTAB32.dll] <N/A><N/A>
[D:\Program Files\Kingsoft\Powerword 2003\XImage32.dll] <N/A><N/A>
[D:\Program Files\Kingsoft\Powerword 2003\xfile.dll] <N/A><N/A>
[D:\Program Files\Kingsoft\Powerword 2003\KPic10.dll] <N/A><N/A>
[D:\Program Files\Kingsoft\Powerword 2003\ijl11.dll] <Intel Corporation><1.1.2>
[D:\Program Files\Kingsoft\Powerword 2003\toTTSEngine50.dll] <Kingsoft Corporation><1, 0, 0, 1>
[D:\Program Files\Kingsoft\Powerword 2003\NormGrab.DLL] <Kingsoft Co, Ltd.><6, 0, 0, 0>
[D:\Program Files\Kingsoft\Powerword 2003\DicMngr.dll] <Kingsoft><1, 0, 0, 0>
[D:\Program Files\Kingsoft\Powerword 2003\DBCore10.dll] <Kingsoft ><1, 0, 0, 0>
[D:\Program Files\Kingsoft\Powerword 2003\XdictGrb.dll] <Kingsoft Co, Ltd.><6, 0, 0, 0>
[D:\Program Files\Kingsoft\Powerword 2003\Cjktl32.dll] <N/A><N/A>
[PID: 372][D:\tools\sreng2-System Repair Engineer\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[D:\Program Files\Kingsoft\Powerword 2003\Cjktl32.dll] <N/A><N/A>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR Error. [AutoCADScript]
.CHM OK. ["C:\Winnt\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS Error. [C:\Winnt\system32\WScript.exe "%1" %*]
.JS Error. [C:\Winnt\system32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================