安全模式下扫的LOG
2006-10-02,23:42:11
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows 2000 Professional (Build 2195)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Internat.exe><internat.exe> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<rx><C:\WINNT\System32\explore.exe> [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><C:\WINNT\rundl132.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Synchronization Manager><mobsync.exe /logon> [Microsoft Corporation]
<SoundMan><SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<NvCplDaemon><RUNDLL32.EXE NvQTwk,NvCplDaemon initialize> [N/A]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<Tray><; C:\WINNT\command\rundll32.exe> [N/A]
<CdnCtr><C:\Program Files\CNNIC\Cdn\cdnup.exe> [N/A]
<Application Layer Gateway Service><C:\WINNT\System32\algs.exe> [N/A]
<Client Server Runtime Process><C:\WINNT\System32\csrs.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<My Program><> [N/A]
<My Program1><C:\Program Files\Digital Video Recorder\drv.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<9><C:\WINNT\System32\Ravdm.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINNT\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<GinaDLL><GinaStub.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad]
<Network.ConnectionTray><C:\WINNT\system32\NETSHELL.dll> [(Verified)Microsoft Corporation]
<WebCheck><%SystemRoot%\System32\webcheck.dll> [(Verified)Microsoft Corporation]
<SysTray><st
object.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
<WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
<WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
<WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
<WinlogonNotify: sclgntfy><sclgntfy.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
<WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\System32\browseui.dll> [(Verified)Microsoft Corporation]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\System32\browseui.dll> [(Verified)Microsoft Corporation]
==================================
启动文件夹
N/A
==================================
服务
[Indexing Service / cisvc]
<C:\WINNT\System32\cisvc.exe><Microsoft Corporation>
[ClipBook / ClipSrv]
<C:\WINNT\system32\clipsrv.exe><Microsoft Corporation>
[Logical Disk Manager Administrative Service / dmadmin]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Fax Service / Fax]
<C:\WINNT\system32\faxsvc.exe><Microsoft Corporation>
[GrayPigeonServer / GrayPigeonServer]
<C:\WINNT\G_Server2006.exe><N/A>
[Microsoft Security Login Service / Microsoft Security Login Service]
<"C:\WINNT\System32\dllcache\mssecure32.exe"><N/A>
[NetMeeting Remote Desktop Sharing / mnmsrvc]
<C:\WINNT\System32\mnmsrvc.exe><Microsoft Corporation>
[Distributed Transaction Coordinator / MSDTC]
<C:\WINNT\System32\msdtc.exe><Microsoft Corporation>
[Windows Installer / MSIServer]
<C:\WINNT\System32\MsiExec.exe /V><Microsoft Corporation>
[Network DDE / NetDDE]
<C:\WINNT\system32\netdde.exe><Microsoft Corporation>
[Network DDE DSDM / NetDDEdsdm]
<C:\WINNT\system32\netdde.exe><Microsoft Corporation>
[NVIDIA Driver Helper Service / NVSvc]
<C:\WINNT\System32\nvsvc32.exe><NVIDIA Corporation>
[Remote Registry Service / RemoteRegistry]
<C:\WINNT\system32\regsvc.exe><Microsoft Corporation>
[Remote Procedure Call (RPC) Locator / RpcLocator]
<C:\WINNT\System32\locator.exe><Microsoft Corporation>
[QoS RSVP / RSVP]
<C:\WINNT\System32\rsvp.exe -s><Microsoft Corporation>
[Smart Card Helper / SCardDrv]
<C:\WINNT\System32\SCardSvr.exe><Microsoft Corporation>
[Smart Card / SCardSvr]
<C:\WINNT\System32\SCardSvr.exe><Microsoft Corporation>
[Task Scheduler / Schedule]
<C:\WINNT\system32\MSTask.exe><Microsoft Corporation>
[Print Spooler / Spooler]
<C:\WINNT\system32\spoolsv.exe><Microsoft Corporation>
[Performance Logs and Alerts / SysmonLog]
<C:\WINNT\system32\smlogsvc.exe><Microsoft Corporation>
[Telnet / TlntSvr]
<C:\WINNT\system32\tlntsvr.exe><Microsoft Corporation>
[Uninterruptible Power Supply / UPS]
<C:\WINNT\System32\ups.exe><Microsoft Corporation>
[Utility Manager / UtilMan]
<C:\WINNT\System32\UtilMan.exe><Microsoft Corporation>
[Windows Management Instrumentation / WinMgmt]
<C:\WINNT\System32\WBEM\WinMgmt.exe><Microsoft Corporation>
[Portable Media Serial Number Service / WmdmPmSN]
<C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\System32\mspmsnsv.dll><Microsoft Corporation>
==================================
驱动程序
[Service for WDM 3D Audio Driver / ALCXSENS]
<system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[ARGUS / ARGUS]
<system32\drivers\ARGUS.sys><N/A>
[cdnprot / cdnprot]
<\SystemRoot\system32\drivers\cdnprot.sys><中国互联网络信息中心(CNNIC)>
[cdntran / cdntran]
<system32\drivers\cdntran.sys><CNNIC>
[Cdr4_2K / Cdr4_2K]
<C:\WINNT\SYSTEM32\DRIVERS\Cdr4_2K.SYS><Roxio>
[Cdralw2k / Cdralw2k]
<C:\WINNT\SYSTEM32\DRIVERS\Cdralw2k.SYS><Roxio>
[dmboot / dmboot]
<System32\drivers\dmboot.sys><VERITAS Software Corp.>
[Logical Disk Manager Driver / dmio]
<\SystemRoot\System32\drivers\dmio.sys><VERITAS Software Corp.>
[dmload / dmload]
<\SystemRoot\System32\drivers\dmload.sys><VERITAS Software Corp.>
[ecfhagfc / ecfhagfc]
<\SystemRoot\system32\drivers\ecfhagfc.sys><N/A>
[fiidbeii / fiidbeii]
<C:\WINNT\SYSTEM32\DRIVERS\fiidbeii.SYS><中国互联网络信息中心(CNNIC)>
[hhgjfdgd / hhgjfdgd]
<\SystemRoot\system32\drivers\hhgjfdgd.sys><N/A>
[hikDrv4000 / hikDrv4000]
<System32\DRIVERS\hikDrv4000.sys><HangZhou Hikvision Digital technology Co.,Ltd>
[jhhhcejg / jhhhcejg]
<C:\WINNT\SYSTEM32\DRIVERS\jhhhcejg.SYS><中国互联网络信息中心(CNNIC)>
[nv / nv]
<System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
<System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[TDDI / TDDI]
<\??\C:\WINNT\System32\drivers\tddi.sys><SafeNet China Ltd.>