[CODE]
2007-01-28,15:06:28
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [Microsoft Corporation]
<MSMSGS><"C:\Program Files\Messenger\Msmsgs.exe" /background> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<SoundMan><SOUNDMAN.EXE> [(Verified)Realtek Semiconductor Corp.]
<TrueImageMonitor.exe><C:\Program Files\Acronis\TrueImageServer\TrueImageMonitor.exe> [Acronis]
<AcronisTimounterMonitor><C:\Program Files\Acronis\TrueImageServer\TimounterMonitor.exe> [Acronis]
<Acronis Scheduler2 Service><"C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"> [Acronis]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<SunJavaUpdateSched><C:\Program Files\Java\j2re1.4.2_08\bin\jusched.exe> [N/A]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [(Verified)NVIDIA Corporation]
<nwiz><nwiz.exe /install> [N/A]
<NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit> [(Verified)NVIDIA Corporation]
<UUCallMini><"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.235\UUCall3.exe" -autorun> [N/A]
<RavTask><"D:\新建\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<WebThunder><D:\Program Files\迅雷安装\WebThunder.exe> [N/A]
<KillTrojanMaster><D:\Rising\木马专杀大师\木马专杀大师.exe> [木马专杀大师]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
==================================
启动文件夹
[Adobe Reader Speed Launch]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk --> C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [Adobe Systems Incorporated]><N>
[腾讯QQ]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><N>
==================================
服务
[Acronis Scheduler2 Service / AcrSch2Svc][Running/Auto Start]
<"C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe"><Acronis>
[Vsn lefe Service / lefe][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\COMMON~1\rklk\yrsr.dll,Service><Microsoft Corporation>
[Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[Informix Dynamic Server Message Service / MsgServ][Stopped/Manual Start]
<C:\WINDOWS\system32\msgserv.exe><N/A>
[ISM Server / nsrd][Running/Auto Start]
<C:\ISM\2.20\bin\nsrd><N/A>
[ISM Local Execution / nsrexecd][Running/Auto Start]
<C:\ISM\2.20\bin\nsrexecd><N/A>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Informix IDS - ol_pc549 / ol_pc549][Stopped/Manual Start]
<C:\PROGRA~1\IBM\Informix\bin\onscpah.exe ol_pc549><N/A>
[OracleOraHome90ClientCache / OracleOraHome90ClientCache][Stopped/Manual Start]
<c:\oracle\ora90\BIN\ONRSD.EXE><N/A>
[ISM Portmapper / portmap][Running/Auto Start]
<C:\ISM\2.20\bin\portmap><N/A>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"D:\新建\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
<"D:\新建\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SSJE Sentinel Server / ssjemon][Stopped/Manual Start]
<C:\Program Files\ServerStudioJE\monitor_server\ssjemon.exe><Advanced Global Systems, Ltd.>
[Apache Tomcat / Tomcat5][Stopped/Manual Start]
<"E:\Tomcat 5.0\bin\tomcat5.exe" //RS//Tomcat5><Apache Software Foundation>
==================================
驱动程序
[a347bus / a347bus][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\a347bus.sys><>
[a347scsi / a347scsi][Running/Boot Start]
<\SystemRoot\System32\Drivers\a347scsi.sys><>
[acpidisk / acpidisk][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[BdGuard / BdGuard][Running/Boot Start]
<\SystemRoot\system32\drivers\BDGuard.SYS><N/A>
[ExpScaner / ExpScaner][Running/Auto Start]
<\??\D:\新建\Rising\Rav\ExpScan.sys><>
[HookCont / HookCont][Running/Auto Start]
<\??\D:\新建\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
<\??\D:\新建\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\D:\新建\Rising\Rav\HookSys.sys><Rising>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\D:\新建\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[npkcusb / npkcusb][Running/Auto Start]
<\??\C:\Program Files\Tencent\QQ\npkcusb.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[NVIDIA nForce Networking Controller Driver / NVENETFD][Running/Manual Start]
<system32\DRIVERS\NVENETFD.sys><NVIDIA Corporation>
[NVIDIA Network Bus Enumerator / nvnetbus][Running/Manual Start]
<system32\DRIVERS\nvnetbus.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
<\??\D:\新建\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[Acronis Snapshots Manager / snapman][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\snapman.sys><Acronis>
[SVKP / SVKP][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\SVKP.sys><N/A>
[Acronis True Image FS Filter / tifsfilter][Running/Auto Start]
<system32\DRIVERS\tifsfilt.sys><Acronis>
[Acronis True Image Backup Archive Explorer / timounter][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\timntr.sys><Acronis>
[v / v][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\vunh><N/A>