[CODE]
2007-03-12,16:38:52
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<kav><"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"> [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<KKDelay><C:\Program Files\Rising\AntiSpyware\RunOnce.exe> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<SoundMix><C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\soudmax.dll,St> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{4ED6E0B5-F47A-4609-A940-11CF60FDC3C3}><C:\WINDOWS\system32\trtbc.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptimg]
<WinlogonNotify: cryptimg><cryptimg.dll> [N/A]
==================================
启动文件夹
N/A
==================================
服务
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[卡巴斯基反病毒6.0 / AVP][Running/Auto Start]
<"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r><Kaspersky Lab>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Logical Disk Manager Administrator Service / Logical Disk Manager Administrator Service][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\ntxml.dll><>
[Indexing Data / MOBILL][Stopped/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\KFEAS.DLL,Export 1087><N/A>
[SQLServer Supports / sqlservech][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k sqlservech-->c:\windows\system32\sqlservech.dll><Microsoft Corporation>
[Provisioning Transaction Service / ttt_14][Stopped/Auto Start]
<C:\WINDOWS\system32\win.exe><N/A>
[WinXP DHCP Service / WinXPDHCPsvc][Stopped/Auto Start]
<C:\WINDOWS\system32\\rundll32.exe xpdhcp.dll,input><Microsoft Corporation>
[Windows Media Connect Service / WmdmPmSp][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\WmdmPmSp.dll><N/A>
[WMI Performance Adapter / WmiApSrv][Stopped/Manual Start]
<C:\WINDOWS\system32\wbem\wmiapsrv.exe><Microsoft Corporation>
==================================
驱动程序
[ADProt / ADProt][Running/System Start]
<\SystemRoot\system32\drivers\ADProt.sys><腾讯科技(深圳)有限公司>
[adpu64 / adpu64][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\adpu64.sys><N/A>
[ast / ast][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\ast.sys><N/A>
[BIOS / BIOS][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\BIOS.sys><BIOSTAR Group>
[C-Media WDM Audio Interface / cmuda][Running/Manual Start]
<system32\drivers\cmuda.sys><C-Media Inc>
[fdyqmml / fdyqmml][Running/Boot Start]
<\SystemRoot\system32\drivers\fdyqmml.sys><N/A>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Running/Manual Start]
<system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[gwiopm / gwiopm][Stopped/Manual Start]
<\??\D:\y优化大师\gwiopm.sys><N/A>
[hidproc / hidproc][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\hidproc.sys><N/A>
[https / https][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\https.sys><N/A>
[kl1 / kl1][Running/Boot Start]
<\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
[klif / klif][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[KSKNIGHT / KSKNIGHT][Stopped/Manual Start]
<\??\E:\上古传说\KSKNIGHT.SYS><Kingsoft>
[lahlxui / lahlxui][Running/Boot Start]
<\SystemRoot\system32\drivers\lahlxui.sys><>
[lanfs / lanfs][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\lanfs.sys><N/A>
[lenfpgjj / lenfpgjj][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\lenfpgjj.sys><N/A>
[ndcia / ndcia][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\ndcia.sys><Microsoft Corporation>
[nnkbpbd / nnkbpbd][Stopped/Boot Start]
<\SystemRoot\system32\drivers\nnkbpbd.sys><N/A>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\D:\qq\npkcrypt.sys><INCA Internet Co., Ltd.>
[npkycryp / npkycryp][Stopped/Manual Start]
<\??\D:\qq\npkycryp.sys><N/A>
[PANTECH GSM Handset USB Device driver (WDM) / pan_bus][Stopped/Manual Start]
<system32\DRIVERS\pan_bus.sys><MCCI>
[PANTECH GSM Handset EMMI Drivers (WDM) / pan_emmi][Stopped/Manual Start]
<system32\DRIVERS\pan_emmi.sys><MCCI>
[PANTECH GSM Handset Filter / pan_mdfl][Stopped/Manual Start]
<system32\DRIVERS\pan_mdfl.sys><MCCI>
[PANTECH GSM Handset Drivers / pan_mdm][Stopped/Manual Start]
<system32\DRIVERS\pan_mdm.sys><MCCI>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Samsung Mobile USB Device II 1.0 driver (WDM) / ssm_bus][Stopped/Manual Start]
<system32\DRIVERS\ssm_bus.sys><MCCI>
[Samsung Mobile USB Modem II 1.0 Filter / ssm_mdfl][Stopped/Manual Start]
<system32\DRIVERS\ssm_mdfl.sys><MCCI>
[Samsung Mobile USB Modem II 1.0 Drivers / ssm_mdm][Stopped/Manual Start]
<system32\DRIVERS\ssm_mdm.sys><MCCI>
[SVKP / SVKP][Running/Auto Start]
<\??\C:\WINDOWS\system32\SVKP.sys><AntiCracking>
[TSP / TSP][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
[Virtual CD-ROM Device Driver / vcdrom][Stopped/System Start]
<\??\I:\MSVCD\VCDROM.SYS><N/A>
[ViaIde / ViaIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
==================================