2007-07-03,22:15:15
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 1 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><D:\WINDOWS\System32\ctfmon.exe> [(Verified)Microsoft Windows XP Publisher]
<wsctf.exe><wsctf.exe> [Microsoft Corporation]
<KavPFW><"D:\KAV2005\KAVPFW.EXE"> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup> [NVIDIA Corporation]
<nwiz><nwiz.exe /install> [NVIDIA Corporation]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
<PHIME2002ASync><D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows XP Publisher]
<Microsoft (R) Windows Protocol Deployment Manager><D:\WINDOWS\system32\3.tmp> [N/A]
<Windows Explorer><D:\WINDOWS\System32\explorer.exe> [N/A]
<stup.exe><D:\PROGRA~1\TENCENT\Adplus\stup.exe> [Tencent]
<supdate2.dll><; RUNDLL32.EXE D:\WINDOWS\System32\supdate2.dll,Run> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows XP Publisher]
<Userinit><D:\WINDOWS\System32\userinit.exe,> [(Verified)Microsoft Windows XP Publisher]
<UIHost><logonui.exe> [(Verified)Microsoft Windows XP Publisher]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><D:\DOCUME~1\abcd\桌面\WATER.SCR> []
==================================
启动文件夹
N/A
==================================
服务
[aucup / aucup][Stopped/Auto Start]
<><N/A>
[aukld / aukld][Stopped/Auto Start]
<><N/A>
[aumms / aumms][Stopped/Auto Start]
<><N/A>
[CoolWare / CoolWare][Running/Auto Start]
<D:\WINDOWS\System32\svchost.exe -k netsvcs-->D:\WINDOWS\System32\main.dll><>
[gkazgj / gkazgj][Stopped/Auto Start]
<D:\WINDOWS\System32\svchost.exe -k netsvcs-->D:\PROGRA~1\mkazgj\mkazgj.dll><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<D:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[iPod Service / iPod Service][Stopped/Manual Start]
<"D:\Program Files\iPod\bin\iPodService.exe"><N/A>
[jkuowmr / jkuowmr][Stopped/Auto Start]
<D:\WINDOWS\System32\svchost.exe -k netsvcs-->D:\PROGRA~1\COMMON~1\pkuocmr\pkuocmr.dll><N/A>
[Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
<D:\KAV2005\KWatch.EXE><Kingsoft Corporation>
[LightScribeService Direct Disc Labeling Service / LightScribeService][Running/Auto Start]
<"D:\Program Files\Common Files\LightScribe\LSSrvc.exe"><Hewlett-Packard Company>
[Network helper Service / MSDisk][Stopped/Auto Start]
<"D:\WINDOWS\System32\irdvxc.exe" /service><N/A>
[NVIDIA Driver Helper Service / NVSvc][Stopped/Auto Start]
<D:\WINDOWS\System32\nvsvc32.exe><N/A>
[PDEngine / PDEngine][Stopped/Manual Start]
<D:\Program Files\Raxco\PerfectDisk\PDEngine.exe><Raxco Software, Inc.>
[Windows Protocol Deployment Manager / PDM][Stopped/Auto Start]
<D:\WINDOWS\system32\3.tmp><N/A>
[PDScheduler / PDSched][Stopped/Auto Start]
<D:\Program Files\Raxco\PerfectDisk\PDSched.exe><Raxco Software, Inc.>
[qjfqrh / qjfqrh][Running/Auto Start]
<D:\WINDOWS\System32\rundll32.exe D:\PROGRA~1\COMMON~1\wjfqxh\wjfqxh.dll,Service -s><Microsoft Corporation>
[winaua / winaua][Stopped/Auto Start]
<><N/A>
[winmum / winmum][Stopped/Auto Start]
<><N/A>
[Windows Service Monitor / winsvcmon][Stopped/Auto Start]
<D:\WINDOWS\System32\winsvcmon.exe><N/A>
[WMDM PMSP Service / WMDM PMSP Service][Stopped/Auto Start]
<D:\WINDOWS\System32\MsPMSPSv.exe><N/A>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
<D:\WINDOWS\System32\svchost.exe -k netsvcs-->D:\WINDOWS\System32\mspmsnsv.dll><Microsoft Corporation>
==================================
驱动程序
[00002a2d / 00002a2d][Stopped/Boot Start]
<\SystemRoot\System32\drivers\00002a2d.SYS><N/A>
[a347bus / a347bus][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\a347bus.sys><>
[a347scsi / a347scsi][Running/Boot Start]
<\SystemRoot\System32\Drivers\a347scsi.sys><>
[aahacahg / aahacahg][Stopped/System Start]
<\??\D:\WINDOWS\system32\drivers\aahacahg.sys><N/A>
[ADProt / ADProt][Stopped/System Start]
<\SystemRoot\system32\drivers\ADProt.sys><N/A>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[标准 IDE/ESDI 硬盘控制器 / atapi][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\atapi.sys><N/A>
[basic2 / basic2][Running/Manual Start]
<System32\DRIVERS\HSF_BSC2.sys><Conexant>
[Copystar / Copystar][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\copystar.sys><An Chen Computer>
[d346bus / d346bus][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\d346bus.sys><>
[d346prt / d346prt][Running/Boot Start]
<\SystemRoot\System32\Drivers\d346prt.sys><>
[ehbheecc / ehbheecc][Stopped/System Start]
<\??\D:\WINDOWS\system32\drivers\ehbheecc.sys><N/A>
[ENTECH / ENTECH][Stopped/Manual Start]
<\??\D:\WINDOWS\System32\DRIVERS\ENTECH.SYS><EnTech Taiwan>
[ExpScaner / ExpScaner][Stopped/Auto Start]
<\??\D:\Program Files\Rising\Rav\ExpScan.sys><N/A>
[Fallback / Fallback][Running/Auto Start]
<System32\DRIVERS\HSF_FALL.sys><Conexant>
[Fsks / Fsks][Running/Auto Start]
<System32\DRIVERS\HSF_FSKS.sys><Conexant>
[HOOKAPI / HOOKAPI][Stopped/Auto Start]
<\??\D:\PROGRAM FILES\RISING\RAV\HOOKAPI.SYS><N/A>
[HookCont / HookCont][Stopped/Auto Start]
<\??\D:\Program Files\Rising\Rav\HOOKCONT.sys><N/A>
[HookReg / HookReg][Stopped/Auto Start]
<\??\D:\Program Files\Rising\Rav\HookReg.sys><N/A>
[HookSys / HookSys][Stopped/Auto Start]
<\??\D:\Program Files\Rising\Rav\HookSys.sys><N/A>
[hsf_msft / hsf_msft][Running/Manual Start]
<System32\DRIVERS\HSF_MSFT.sys><Conexant>
[K56 / K56][Running/Auto Start]
<System32\DRIVERS\HSF_K56K.sys><Conexant>
[kmsinput / kmsinput][Stopped/Manual Start]
<\??\D:\WINDOWS\System32\drivers\kmsinput.sys><N/A>
[KNetWch / KNetWch][Running/System Start]
<\??\D:\KAV2005\KNetWch.SYS><金山电脑公司>
[KWatch3 / KWatch3][Running/System Start]
<\??\D:\WINDOWS\System32\drivers\KWatch3.SYS><Kingsoft Corporation>
[MEMSCAN / MEMSCAN][Stopped/Auto Start]
<\??\D:\Program Files\Rising\Rav\MEMSCAN.sys><N/A>
[New0 / New0][Running/Auto Start]
<\??\D:\WINDOWS\System32\new.sys><N/A>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
<System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[nwupspx / nwupspx][Stopped/Boot Start]
<\SystemRoot\System32\drivers\nwupspx.sys><N/A>
[StarForce Protection Environment Driver v6 / prodrv06][Running/System Start]
<\SystemRoot\System32\drivers\prodrv06.sys><Protection Technology>
[StarForce Protection Helper Driver v2 / prohlp02][Running/Boot Start]
<\SystemRoot\System32\drivers\prohlp02.sys><Protection Technology>
[StarForce Protection Synchronization Driver v1 / prosync1][Running/Boot Start]
<\SystemRoot\System32\drivers\prosync1.sys><Protection Technology>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Rksample / Rksample][Running/Manual Start]
<System32\DRIVERS\HSF_SAMP.sys><Conexant>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
<\SystemRoot\System32\drivers\RsBoot.sys><Beijing Rising>
[Realtek RTL8139/810x Family Fast Ethernet NIC NT Driver / rtl8139][Running/Manual Start]
<System32\DRIVERS\R8139n51.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Running/Auto Start]
<System32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[StarForce Protection Helper Driver / sfhlp01][Running/Boot Start]
<\SystemRoot\System32\drivers\sfhlp01.sys><Protection Technology>
[SoftFax / SoftFax][Running/Auto Start]
<System32\DRIVERS\HSF_FAXX.sys><Conexant>
[Tones / Tones][Running/Auto Start]
<System32\DRIVERS\HSF_TONE.sys><Conexant>
[V124 / V124][Running/Auto Start]
<System32\DRIVERS\HSF_V124.sys><Conexant>
[37687 / 37687][Running/Disabled]
<2 - 系统找不到指定的文件。
><N/A>