2007-01-30,10:54:39
System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)
Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><ctfmon.exe> [Microsoft Corporation]
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [Microsoft Corporation]
<sysemls><*C:\WINNT\system32\sysem.exe> [N/A]
<Skype><"D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized> [(Verified)Skype Technologies S.A.]
<swg><C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.8472\GoogleToolbarNotifier.exe> [(Verified)Google Inc.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Synchronization Manager><mobsync.exe /logon> [Microsoft Corporation]
<IgfxTray><C:\WINNT\System32\igfxtray.exe> [Intel Corporation]
<HotKeysCmds><C:\WINNT\System32\hkcmd.exe> [Intel Corporation]
<SoundMan><*SOUNDMAN.EXE> [N/A]
<Windows木马防火墙><*D:\Program files\ftc_cleanTrojanHorse\Trojanwall.exe> [N/A]
<WinampAgent><*d:\Program Files\Winamp\winampa.exe> [N/A]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<DAEMON Tools-1033><"C:\Program Files\D-Tools\daemon.exe" -lang 1033> [DAEMON'S HOME]
<sysemls><*C:\WINNT\system32\sysem.exe> [N/A]
<qmrkps><*C:\WINNT\system32\mpdxho.exe> [N/A]
<ccApp><"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"> [(Verified)Symantec Corporation]
<vptray><C:\PROGRA~1\SYMANT~1\VPTray.exe> [(Verified)Symantec Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINNT\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{1A404685-7563-4d02-B0F6-58B308A406A9}><c:\matlab6p5\webserver\bin\win32\xyxffpzz.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
<WinlogonNotify: NavLogon><C:\WINNT\system32\NavLogon.dll> [(Verified)Symantec Corporation]
==================================
启动文件夹
N/A
==================================
服务
[Alerter / Alerter]
<C:\WINNT\System32\services.exe><Microsoft Corporation>
[Application Management / AppMgmt]
<C:\WINNT\system32\services.exe><Microsoft Corporation>
[Computer Browser / Browser]
<C:\WINNT\System32\services.exe><Microsoft Corporation>
[Symantec Event Manager / ccEvtMgr]
<"C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc]
<"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr]
<"C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[Indexing Service / cisvc]
<C:\WINNT\System32\cisvc.exe><Microsoft Corporation>
[ClipBook / ClipSrv]
<C:\WINNT\system32\clipsrv.exe><Microsoft Corporation>
[Symantec AntiVirus Definition Watcher / DefWatch]
<"C:\Program Files\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[DHCP Client / Dhcp]
<C:\WINNT\System32\services.exe><Microsoft Corporation>
[Logical Disk Manager Administrative Service / dmadmin]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Logical Disk Manager / dmserver]
<C:\WINNT\System32\services.exe><Microsoft Corporation>
[DNS Client / Dnscache]
<C:\WINNT\System32\services.exe><Microsoft Corporation>
[Event Log / Eventlog]
<C:\WINNT\system32\services.exe><Microsoft Corporation>
[COM+ Event System / EventSystem]
<C:\WINNT\System32\svchost.exe -k netsvcs-->C:\WINNT\System32\es.dll><Microsoft Corporation>
[Fax Service / Fax]
<C:\WINNT\system32\faxsvc.exe><Microsoft Corporation>
[HID Input Service / HidServ]
<C:\WINNT\system32\hidserv.exe><Microsoft Corporation>
[Server / lanmanserver]
<C:\WINNT\System32\services.exe><Microsoft Corporation>
[Workstation / lanmanworkstation]
<C:\WINNT\System32\services.exe><Microsoft Corporation>
[TCP/IP NetBIOS Helper Service / LmHosts]
<C:\WINNT\System32\services.exe><Microsoft Corporation>
[MATLAB Server / matlabserver]
<C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe><N/A>
[Messenger / Messenger]
<C:\WINNT\System32\services.exe><Microsoft Corporation>
[NetMeeting Remote Desktop Sharing / mnmsrvc]
<C:\WINNT\System32\mnmsrvc.exe><Microsoft Corporation>
[Distributed Transaction Coordinator / MSDTC]
<C:\WINNT\System32\msdtc.exe><Microsoft Corporation>
[Network DDE / NetDDE]
<C:\WINNT\system32\netdde.exe><Microsoft Corporation>
[Network DDE DSDM / NetDDEdsdm]
<C:\WINNT\system32\netdde.exe><Microsoft Corporation>
[Network Connections / Netman]
<C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\netman.dll><Microsoft Corporation>
[Removable Storage / NtmsSvc]
<C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\NtmsSvc.dll><Microsoft Corporation>
[Plug and Play / PlugPlay]
<C:\WINNT\system32\services.exe><Microsoft Corporation>
[Protected Storage / ProtectedStorage]
<C:\WINNT\system32\services.exe><Microsoft Corporation>
[Remote Access Auto Connection Manager / RasAuto]
<C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\rasauto.dll><Microsoft Corporation>
[Remote Access Connection Manager / RasMan]
<C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\rasmans.dll><Microsoft Corporation>
[Routing and Remote Access / RemoteAccess]
<C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\mprdim.dll><Microsoft Corporation>
[Remote Registry Service / RemoteRegistry]
<C:\WINNT\system32\regsvc.exe><Microsoft Corporation>
[Remote Procedure Call (RPC) Locator / RpcLocator]
<C:\WINNT\System32\locator.exe><Microsoft Corporation>
[Remote Procedure Call (RPC) / RpcSs]
<C:\WINNT\system32\svchost -k rpcss-->%SystemRoot%\system32\rpcss.dll><Microsoft Corporation>
[QoS RSVP / RSVP]
<C:\WINNT\System32\rsvp.exe -s><Microsoft Corporation>
[SavRoam / SavRoam]
<"C:\Program Files\Symantec AntiVirus\SavRoam.exe"><symantec>
[Smart Card Helper / SCardDrv]
<C:\WINNT\System32\SCardSvr.exe><Microsoft Corporation>
[Smart Card / SCardSvr]
<C:\WINNT\System32\SCardSvr.exe><Microsoft Corporation>
[Task Scheduler / Schedule]
<C:\WINNT\system32\MSTask.exe><Microsoft Corporation>
[RunAs Service / seclogon]
<C:\WINNT\system32\services.exe><Microsoft Corporation>
[System Event Notification / SENS]
<C:\WINNT\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\sens.dll><Microsoft Corporation>
[Symantec Network Drivers Service / SNDSrvc]
<"C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Print Spooler / Spooler]
<C:\WINNT\system32\spoolsv.exe><Microsoft Corporation>
[Symantec AntiVirus / Symantec AntiVirus]
<"C:\Program Files\Symantec AntiVirus\Rtvscan.exe"><Symantec Corporation>
[Performance Logs and Alerts / SysmonLog]
<C:\WINNT\system32\smlogsvc.exe><Microsoft Corporation>
[Telephony / TapiSrv]
<C:\WINNT\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\tapisrv.dll><Microsoft Corporation>
[Telnet / TlntSvr]
<C:\WINNT\system32\tlntsvr.exe><Microsoft Corporation>
[Distributed Link Tracking Client / TrkWks]
<C:\WINNT\system32\services.exe><Microsoft Corporation>
[Uninterruptible Power Supply / UPS]
<C:\WINNT\System32\ups.exe><Microsoft Corporation>
[Utility Manager / UtilMan]
<C:\WINNT\System32\UtilMan.exe><Microsoft Corporation>
[Windows Time / W32Time]
<C:\WINNT\System32\services.exe><Microsoft Corporation>
[Windows DHCP Service / WinDHCPsvc]
<C:\WINNT\system32\rundll32.exe windhcp.ocx,start><Microsoft Corporation>
[Windows Management Instrumentation / WinMgmt]
<C:\WINNT\System32\WBEM\WinMgmt.exe><Microsoft Corporation>
[Windows Management Instrumentation Driver Extensions / Wmi]
<C:\WINNT\system32\Services.exe><Microsoft Corporation>