驱动程序
[cdrblock / cdrblock][Running/System Start]
<system32\DRIVERS\cdrblock.sys><Canopus Co,. Ltd.>
[cdrport / cdrport][Running/System Start]
<system32\DRIVERS\cdrport.sys><Canopus Co,. Ltd.>
[Hardlock / Hardlock][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\hardlock.sys><Aladdin Knowledge Systems Ltd.>
[VMware hcmon / hcmon][Running/Auto Start]
<\??\C:\WINDOWS\system32\Drivers\hcmon.sys><VMware, Inc.>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
<system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[nvata / nvata][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\nvata.sys><NVIDIA Corporation>
[NVIDIA nForce Networking Controller Driver / NVENETFD][Running/Manual Start]
<system32\DRIVERS\NVENETFD.sys><NVIDIA Corporation>
[NVIDIA Network Bus Enumerator / nvnetbus][Running/Manual Start]
<system32\DRIVERS\nvnetbus.sys><NVIDIA Corporation>
[PGPmemlock / PGPmemlock][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\PGPmemlock.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\PxHelp20.sys><Sonic Solutions>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[ULCDRHlp / ULCDRHlp][Running/Manual Start]
<System32\Drivers\ULCDRHlp.sys><Ulead Systems, Inc.>
[USIUDF / USIUDF][Running/System Start]
<System32\Drivers\USIUDF.sys><Ulead Systems, Inc.>
[vax347b / vax347b][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\vax347b.sys><>
[vax347s / vax347s][Running/Boot Start]
<\SystemRoot\System32\Drivers\vax347s.sys><>
[VMware Virtual Ethernet Adapter Driver / VMnetAdapter][Running/Manual Start]
<system32\DRIVERS\vmnetadapter.sys><VMware, Inc.>
[VMware Bridge Protocol / VMnetBridge][Running/Auto Start]
<system32\DRIVERS\vmnetbridge.sys><VMware, Inc.>
[VMware Network Application Interface / VMnetuserif][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\vmnetuserif.sys><VMware, Inc.>
[VMware VMparport / VMparport][Running/Auto Start]
<\??\C:\WINDOWS\system32\Drivers\VMparport.sys><VMware, Inc.>
[VMware vmx86 / vmx86][Running/Auto Start]
<\??\C:\WINDOWS\system32\Drivers\vmx86.sys><VMware, Inc.>
[Vstor2 Virtual Storage Driver / vstor2][Running/Auto Start]
<\??\C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys><VMware, Inc.>
==================================
浏览器加载项
[Create Mobile Favorite]
{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} <C:\PROGRA~1\MICROS~3\INetRepl.dll, Microsoft Corporation>
[Create Mobile Favorite]
{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} <C:\PROGRA~1\MICROS~3\INetRepl.dll, Microsoft Corporation>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\Flash.ocx, Macromedia, Inc.>
[导出到 Microsoft Excel(&x)]
<res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000, N/A>
==================================
正在运行的进程
[PID: 900 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 948 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 972 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1016 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1028 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1208 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1264 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1912 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 228 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 572 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 764 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1420 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.10.9371]
[C:\WINDOWS\system32\nvapi.dll] [N/A, ]
[C:\Program Files\Microsoft Office\Office10\msohev.dll] [Microsoft Corporation, 10.0.2609]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[PID: 1532 / Administrator][C:\WINDOWS\system32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\DrvTrNTm.dll] [High Criteria inc., 6.0]
[C:\WINDOWS\system32\DrvTrNTl.dll] [High Criteria inc., 6.0]
[C:\WINDOWS\system32\NvMcTray.dll] [NVIDIA Corporation, 6.14.10.9371]
[C:\WINDOWS\system32\nvapi.dll] [N/A, ]
[PID: 1540 / Administrator][C:\WINDOWS\RTHDCPL.EXE] [Realtek Semiconductor Corp., 2.1.1.1]
[C:\WINDOWS\system32\DrvTrNTm.dll] [High Criteria inc., 6.0]
[C:\WINDOWS\system32\DrvTrNTl.dll] [High Criteria inc., 6.0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1584 / Administrator][D:\Program Files\QuickTime\qttask.exe] [Apple Computer, Inc., 7.1.3]
[PID: 1872 / Administrator][C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe] [Ulead Systems, 1, 0, 1, 15]
[PID: 1880 / Administrator][C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe] [High Criteria inc., 6.0]
[C:\WINDOWS\system32\DrvTrNTm.dll] [High Criteria inc., 6.0]
[C:\WINDOWS\system32\DrvTrNTl.dll] [High Criteria inc., 6.0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1888 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\DrvTrNTm.dll] [High Criteria inc., 6.0]
[C:\WINDOWS\system32\DrvTrNTl.dll] [High Criteria inc., 6.0]
[PID: 1964 / Administrator][C:\PROGRA~1\MICROS~3\wcescomm.exe] [Microsoft Corporation, 4.2.4876.0]
[C:\WINDOWS\system32\CEUTIL.dll] [Microsoft Corporation, 4.2.4876.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\RAPI.dll] [Microsoft Corporation, 4.2.4876.0]
[C:\PROGRA~1\MICROS~3\TCP2UDP.dll] [Microsoft Corporation, 4.2.4876.0]
[C:\WINDOWS\system32\DrvTrNTm.dll] [High Criteria inc., 6.0]
[C:\WINDOWS\system32\DrvTrNTl.dll] [High Criteria inc., 6.0]
[C:\Program Files\Microsoft ActiveSync\rapiproxystub.dll] [N/A, ]
[C:\PROGRA~1\MICROS~3\dtptdns.dll] [Microsoft Corporation, 4.2.4876.0]
[PID: 148 / Administrator][C:\PROGRA~1\MICROS~3\rapimgr.exe] [Microsoft Corporation, 4.2.4876.0]
[C:\WINDOWS\system32\CEUTIL.dll] [Microsoft Corporation, 4.2.4876.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\PROGRA~1\MICROS~3\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Microsoft ActiveSync\rapiproxystub.dll] [N/A, ]
[PID: 608 / Administrator][C:\WINDOWS\ALCFDRTM.EXE] [Realtek Semiconductor Corp., 1, 3, 0, 1]
[C:\WINDOWS\system32\DrvTrNTm.dll] [High Criteria inc., 6.0]
[C:\WINDOWS\system32\DrvTrNTl.dll] [High Criteria inc., 6.0]
[PID: 788 / SYSTEM][C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe] [InterVideo Inc., 1.0.0.1]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 916 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.9371]
[C:\WINDOWS\system32\nvapi.dll] [N/A, ]
[PID: 1380 / SYSTEM][C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe] [Ulead Systems, Inc., 1, 0, 0, 5]
[PID: 1728 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 388 / SYSTEM][C:\Program Files\VMware\VMware Workstation\vmware-authd.exe] [VMware, Inc., 5.5.1 build-19175]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 1620 / SYSTEM][C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe] [VMware, Inc., 5.5.1 build-19175]
[C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmxScsiLib.dll] [VMware, Inc., 5.5.1 build-19175]
[C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[PID: 1640 / SYSTEM][C:\WINDOWS\system32\vmnat.exe] [VMware, Inc., 5.5.1 build-19175]
[PID: 1440 / SYSTEM][C:\WINDOWS\system32\vmnetdhcp.exe] [VMware, Inc., 5.5.1 build-19175]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 2712 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3968 / Administrator][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\DrvTrNTm.dll] [High Criteria inc., 6.0]
[C:\WINDOWS\system32\DrvTrNTl.dll] [High Criteria inc., 6.0]
[D:\Program Files\QuickTime\QTSystem\QuickTime.qts] [Apple Computer, Inc., 7.1.3]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[D:\Program Files\QuickTime\QTSystem\CoreVideo.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTime3GPP.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTimeCapture.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTimeEffects.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTimeH264.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTimeImage.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.qtx] [Apple Computer, Inc, 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTimeMusic.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.qtx] [Apple Computer, Inc., 7.1.3]
[D:\Program Files\QuickTime\QTSystem\QuickTimeVR.qtx] [Apple Computer, Inc, 7.1.3]
[C:\WINDOWS\system32\cseuvec.dll] [Canopus Co., Ltd., 1.02]
[C:\WINDOWS\system32\csellc.dll] [Canopus Co., Ltd., 1.10]
[C:\WINDOWS\system32\csedvh.dll] [Canopus Co., Ltd., 4.04]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\WINDOWS\system32\WMVADVE.DLL] [Microsoft Corporation, 10.00.00.3802]
[C:\WINDOWS\system32\imaadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msadp32.acm] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msg711.acm] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\msgsm32.acm] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\tssoft32.acm] [DSP GROUP, INC., 1.01]
[C:\WINDOWS\system32\tsd32.dll] [, ]
[C:\WINDOWS\system32\msg723.acm] [Microsoft Corporation, 4.4.3400]
[C:\WINDOWS\system32\msaud32.acm] [Microsoft Corporation, 8.00.00.4487]
[C:\WINDOWS\system32\sl_anet.acm] [Sipro Lab Telecom Inc., 3.02]
[C:\WINDOWS\system32\iac25_32.ax] [Intel Corporation, 2.05.53]
[C:\WINDOWS\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
[C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm] [InterVideo Digital Technology Corporation, 8.0.0.0]
[PID: 2288 / Administrator][F:\9.6\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\WINDOWS\system32\DrvTrNTm.dll] [High Criteria inc., 6.0]
[C:\WINDOWS\system32\DrvTrNTl.dll] [High Criteria inc., 6.0]
[F:\9.6\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1880, C:\PROGRAM FILES\HIGHCRITERIA\TOTALRECORDER\TOTRECSCHED.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 608, C:\WINDOWS\ALCFDRTM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 916, C:\WINDOWS\SYSTEM32\NVSVC32.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1620, C:\PROGRAM FILES\COMMON FILES\VMWARE\VMWARE VIRTUAL IMAGE EDITING\VMOUNT2.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2396, K:\DOWNLOADS\DVD专题\20060818_TMPGENC3.0\TMPGENC 3.0 XPRESS\TMPGENC3XP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2204, K:\DOWNLOADS\DVD专题\20060818_TMPGENC3.0\TMPGENC 3.0 XPRESS\VFAPIFRAMESERVER.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
[ 本帖最后由 txdx2008 于 2007-10-10 16:06 编辑 ] |