2006-12-05,19:37:33
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
<SOUNDM><win32smd.exe> [N/A]
<mhsystem><C:\DOCUME~1\lcc\LOCALS~1\Temp\2.exe> [N/A]
<Desktop><C:\WINDOWS\system32\rundll32.exe "C:\WINDOWS\system32\NTService32.dll" ,Run> [N/A]
<RavTask><"D:\瑞星\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<xy><C:\WINDOWS\Download\svhost32.exe> [N/A]
<ms><C:\Program Files\Microsoft\svhost32.exe> [N/A]
<sys><C:\WINDOWS\Intel\rundll32.exe> [N/A]
<r><C:\WINDOWS\down\rundll32.exe> [N/A]
<wl><C:\WINDOWS\Download\svhost32.exe> [N/A]
<!AVG Anti-Spyware><"D:\木马\AVG Anti-Spyware 7.5\avgas.exe" /minimized> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<RavStub><"D:\瑞星\Rising\Rav\ravstub.exe" /RUNONCE> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE> [(Verified)Microsoft Corporation]
<Userinit><userinit.exe,> [(Verified)Microsoft Corporation]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
<{1A404685-7563-4d02-B0F6-58B308A406A9}><d:\瑞星\rising\rav\pwkvulgz.dll> []
<{729B6C61-BDC5-4C09-A1DE-A296BA0B89EC}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp> [N/A]
<{9C0CFA58-3A6F-51ba-9EFE-5320F4F62FB1}><C:\WINDOWS\system32\bdscheca100.dll> [N/A]
<{6E44887F-5214-41F2-AB46-4728735C4CC6}><C:\Program Files\Internet Explorer\PLUGINS\system16.sys> [N/A]
<{06A48AD9-FF57-4E73-937B-B493E72F4226}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\WinInfo.rxk> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad]
<CDBurner><C:\WINDOWS\Downloaded Program Files\jaasnt.dll> [N/A]
<AdobePDF><d:\tools\theworld\PLUGINS\nppdf.dll> [N/A]
==================================
启动文件夹
N/A
==================================
服务
[Adobe LM Service / Adobe LM Service]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[AllAdsWinIe / AllAdsWinIe]
<><N/A>
[FA5CA985 / FA5CA985]
<><N/A>
[Distributed Console Manager / Framework]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\ixpdcj91.dll><N/A>
[Human Interface Device Access / HidServ]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[kavsvc / kavsvc]
<"D:\tools\新建文件夹 (2)\Kaspersky Anti-Virus Personal\kavsvc.exe"><N/A>
[Network Notification / Network Notification]
<C:\WINDOWS\system32\ShellUninstall\scvhcot.exe><Microsoft Corporation>
[Registry Protector / NHLscA]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\CYHBBR04.DLL,Export 1087><N/A>
[RestoreService / RestoreService]
<C:\WINDOWS\system32\Svchost.exe -k RestoreService-->C:\WINDOWS\system32\drivers\service.dll><N/A>
[Rising Process Communication Center / RsCCenter]
<"D:\瑞星\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon]
<"D:\瑞星\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Windows DHCP Service / WinDHCPsvc]
<C:\WINDOWS\system32\rundll32.exe windhcp.ocx,start><Microsoft Corporation>
[Windows IntelligentStart / Windows IntelligentStart]
<C:\Windows\system32\rpeCache\servrpe.exe><Microsoft Corporation>
[Windows NT Service32 / Windows NT Service32]
<"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Start><Microsoft Corporation>
[WinXP DHCP Service / WinXPDHCPsvc]
<C:\WINDOWS\system32\rundll32.exe xpdhcp.dll,start><Microsoft Corporation>
==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc]
<system32\drivers\ac97intc.sys><Intel Corporation>
[Rising TDI Base Driver / BaseTDI]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[cdnprot / cdnprot]
<\SystemRoot\system32\drivers\cdnprot.sys><中国互联网络信息中心(CNNIC)>
[cdntran / cdntran]
<system32\drivers\cdntran.sys><CNNIC>
[Sundance ST201 based Adapter NT Driver / DLH5X]
<system32\DRIVERS\DLH5XND5.sys><D-Link Corporation>
[EagleNT / EagleNT]
<\??\C:\WINDOWS\system32\drivers\EagleNT.sys><N/A>
[ExpScaner / ExpScaner]
<\??\D:\瑞星\Rising\Rav\ExpScan.sys><>
[HookCont / HookCont]
<\??\D:\瑞星\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg]
<\??\D:\瑞星\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
<\??\D:\瑞星\Rising\Rav\HookSys.sys><Rising>
[kgbzquj / kgbzqujh]
<\SystemRoot\System32\DRIVERS\kgbzqujh.sys><N/A>
[MEMSCAN / MEMSCAN]
<\??\D:\瑞星\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[NetGroup Packet Filter Driver / Npf]
<system32\drivers\npf.sys><CACE Technologies>
[nv / nv]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RSPPSYS / RSPPSYS]
<\??\D:\瑞星\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[SecDrv / SecDrv]
<\??\C:\WINDOWS\system32\drivers\SECDRV.SYS><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[SkyProcs / SkyProcs]
<\??\D:\tools\FIREWALL\SkyProcs.sys><N/A>
[Samsung Mobile USB Device II 1.0 driver (WDM) / ssm_bus]
<system32\DRIVERS\ssm_bus.sys><MCCI>
[Samsung Mobile USB Modem II 1.0 Filter / ssm_mdfl]
<system32\DRIVERS\ssm_mdfl.sys><MCCI>
[Samsung Mobile USB Modem II 1.0 Drivers / ssm_mdm]
<system32\DRIVERS\ssm_mdm.sys><MCCI>
==================================
浏览器加载项
N/A
==================================
正在运行的进程
N/A
==================================
文件关联
N/A
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================