估计应该是这个报告吧?
- 2007-02-06,07:48:07
- System Repair Engineer 2.3.13.690
- Smallfrogs (http://www.KZTechs.com)
- Windows XP Professional Service Pack 2 (Build 2600)
- - 管理权限用户 - 完整功能
- 以下内容被选中:
- 所有的启动项目(包括注册表、启动文件夹、服务等)
- 浏览器加载项
- 正在运行的进程(包括进程模块信息)
- 文件关联
- Winsock 提供者
- Autorun.inf
- HOSTS 文件
- 启动项目
- 注册表
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
- [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <load><> [N/A]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
- <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
- <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [NVIDIA Corporation]
- <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
- <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
- <SoundMan><SOUNDMAN.EXE> [N/A]
- <kav><"D:\新建文件夹\avp.exe"> [Kaspersky Lab]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <shell><Explorer.exe> [(Verified)Microsoft Corporation]
- <Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <AppInit_DLLs><> [N/A]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <UIHost><logonui.exe> [(Verified)Microsoft Corporation]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
- <WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll> [Kaspersky Lab]
- ==================================
- 启动文件夹
- N/A
- ==================================
- 服务
- [卡巴斯基反病毒6.0 / AVP][Running/Auto Start]
- <D:\新建文件夹\avp.exe -r><Kaspersky Lab>
- [NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
- <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
- ==================================
- 驱动程序
- [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
- <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
- [AMDMSRIO / AMDMSRIO][Stopped/Manual Start]
- <\??\C:\DOCUME~1\XHT\LOCALS~1\Temp\{55638DD9-D5A9-11D3-B74B-204C4F4F5020}\AMDMSRIO.sys><N/A>
- [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
- <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
- [kl1 / kl1][Running/Boot Start]
- <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
- [klif / klif][Running/System Start]
- <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
- [ESS Maestro Audio Driver (WDM) / maestro][Stopped/Manual Start]
- <system32\drivers\maestro.sys><ESS Technology, Inc.>
- [ATK0110 ACPI UTILITY / MTsensor][Running/Manual Start]
- <system32\DRIVERS\ASACPI.sys><>
- [npkcrypt / npkcrypt][Running/Auto Start]
- <\??\D:\cmqqfinalv151\qq151\npkcrypt.sys><INCA Internet Co., Ltd.>
- [nv / nv][Running/Manual Start]
- <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
- [NVIDIA nForce Networking Controller Driver / NVENETFD][Running/Manual Start]
- <system32\DRIVERS\NVENETFD.sys><NVIDIA Corporation>
- [NVIDIA Network Bus Enumerator / nvnetbus][Running/Manual Start]
- <system32\DRIVERS\nvnetbus.sys><NVIDIA Corporation>
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
- <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
- [WAN Miniport (PPP over Ethernet Protocol) / RMSPPPOE][Running/Manual Start]
- <system32\DRIVERS\RMSPPPOE.SYS><Robert Schlabbach>
- [Secdrv / Secdrv][Stopped/Manual Start]
- <system32\DRIVERS\secdrv.sys><N/A>
- ==================================
- 浏览器加载项
- [Thunder Browser Helper]
- {889D2FEB-5411-4565-8998-1DD2C5261283} <F:\Thunder555269_diy2\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
- [NavigatMon Class]
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <F:\软件\360\360safe\safemon\safemon.dll, N/A>
- [Web反病毒保护]
- {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <D:\新建文件夹\scieplugin.dll, Kaspersky Lab>
- [Thunder Browser Helper]
- {889D2FEB-5411-4565-8998-1DD2C5261283} <F:\Thunder555269_diy2\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
- [NavigatMon Class]
- {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <F:\软件\360\360safe\safemon\safemon.dll, N/A>
- [Shockwave Flash Object]
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash6.ocx, Macromedia, Inc.>
- [上传到QQ网络硬盘]
- <D:\cmqqfinalv151\qq151\AddToNetDisk.htm, N/A>
- [使用迅雷下载]
- <F:\Thunder555269_diy2\Program\geturl.htm, N/A>
- [使用迅雷下载全部链接]
- <F:\Thunder555269_diy2\Program\getallurl.htm, N/A>
- [添加到QQ自定义面板]
- <D:\cmqqfinalv151\qq151\AddPanel.htm, N/A>
- [添加到QQ表情]
- <D:\cmqqfinalv151\qq151\AddEmotion.htm, N/A>
- [用QQ彩信发送该图片]
- <D:\cmqqfinalv151\qq151\SendMMS.htm, N/A>
- ==================================
- 正在运行的进程
- [PID: 744][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 820][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 852][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\klogon.dll] [Kaspersky Lab, 6.0.0.299]
- [PID: 896][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 908][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1072][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1120][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1216][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1260][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1348][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 1736][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.10.8195]
- [C:\WINDOWS\system32\nvshell.dll] [N/A, N/A]
- [C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
- [D:\新建文件夹\shellex.dll] [Kaspersky Lab, 6.0.0.299]
- [F:\Thunder555269_diy2\ComDlls\XunLeiBHO_007.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
- [PID: 1764][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
- [PID: 1928][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 356][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.8195]
- [PID: 1484][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 524][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
- [F:\Thunder555269_diy2\ComDlls\XunLeiBHO_007.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
- [D:\新建文件夹\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299]
- [D:\新建文件夹\klscav.dll] [Kaspersky Lab, 6.0.0.299]
- [D:\新建文件夹\pr_remote.dll] [Kaspersky Lab, 6.0.0.299]
- [D:\新建文件夹\prloader.dll] [Kaspersky Lab, 6.0.0.299]
- [D:\新建文件夹\prkernel.ppl] [Kaspersky Lab, 6.0.0.299]
- [d:\新建文件夹\params.ppl] [Kaspersky Lab, 6.0.0.299]
- [d:\新建文件夹\pxstub.ppl] [Kaspersky Lab, 6.0.0.299]
- [d:\新建文件夹\tempfile.ppl] [Kaspersky Lab, 6.0.0.299]
- [d:\新建文件夹\nfio.ppl] [Kaspersky Lab, 6.0.0.299]
- [d:\新建文件夹\fsdrvplgn.ppl] [Kaspersky Lab, 6.0.0.299]
- [PID: 760][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
- [F:\Thunder555269_diy2\ComDlls\XunLeiBHO_007.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
- [D:\新建文件夹\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299]
- [D:\新建文件夹\klscav.dll] [Kaspersky Lab, 6.0.0.299]
- [D:\新建文件夹\pr_remote.dll] [Kaspersky Lab, 6.0.0.299]
- [D:\新建文件夹\prloader.dll] [Kaspersky Lab, 6.0.0.299]
- [D:\新建文件夹\prkernel.ppl] [Kaspersky Lab, 6.0.0.299]
- [d:\新建文件夹\params.ppl] [Kaspersky Lab, 6.0.0.299]
- [d:\新建文件夹\pxstub.ppl] [Kaspersky Lab, 6.0.0.299]
- [d:\新建文件夹\tempfile.ppl] [Kaspersky Lab, 6.0.0.299]
- [d:\新建文件夹\nfio.ppl] [Kaspersky Lab, 6.0.0.299]
- [d:\新建文件夹\fsdrvplgn.ppl] [Kaspersky Lab, 6.0.0.299]
- [PID: 4020][C:\Documents and Settings\XHT\桌面\sreng2\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
- ==================================
- 文件关联
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .EXE OK. ["%1" %*]
- .COM OK. ["%1" %*]
- .PIF OK. ["%1" %*]
- .REG OK. [regedit.exe "%1"]
- .BAT OK. ["%1" %*]
- .SCR OK. ["%1" /S]
- .CHM OK. ["C:\WINDOWS\hh.exe" %1]
- .HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
- .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
- ==================================
- Winsock 提供者
- N/A
- ==================================
- Autorun.inf
- N/A
- ==================================
- HOSTS 文件
- 127.0.0.1 localhost
- ==================================
- API HOOK
- 警告!System Repair Engineer 提醒
- 你下面的函数内容与预期值不符,他
- 们可能被一些恶意的软件所修改:
- RVA 错误: LoadLibraryA
- RVA 错误: LoadLibraryExA
- RVA 错误: LoadLibraryExW
- RVA 错误: LoadLibraryW
- ==================================
复制代码 |