- 2007-03-09,15:20:23
- System Repair Engineer 2.3.13.690
- Smallfrogs (http://www.KZTechs.com)
- Windows XP Professional Service Pack 1 (Build 2600)
- - 管理权限用户 - 完整功能
- 以下内容被选中:
- 所有的启动项目(包括注册表、启动文件夹、服务等)
- 浏览器加载项
- 正在运行的进程(包括进程模块信息)
- 文件关联
- Winsock 提供者
- Autorun.inf
- HOSTS 文件
- 启动项目
- 注册表
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- <ctfmon.exe><; D:\WINDOWS\System32\ctfmon.exe> [(Verified)Microsoft Corporation]
- <updateMgr><; D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_0_0> [N/A]
- [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <load><> [N/A]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
- <kis><"D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"> [Kaspersky Lab]
- <TkBellExe><; "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
- <ccApp><; "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"> [N/A]
- <Device Detector><; "D:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe" -autorun> [ACD Systems, Ltd.]
- <IMSCMig><; D:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
- <Load><; D:\WINDOWS\uninstall\rundl132.exe> [N/A]
- <mhs2><; D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mhs2.exe> [N/A]
- <Symantec NetDriver Monitor><; D:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer> [(Verified)Symantec Corporation]
- <wlzs2><; D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wlzs2.exe> [N/A]
- <zts2><; D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\zts2.exe> [N/A]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <shell><Explorer.exe> [(Verified)Microsoft Corporation]
- <Userinit><D:\WINDOWS\System32\userinit.exe,> [(Verified)Microsoft Corporation]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <AppInit_DLLs><> [N/A]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <UIHost><logonui.exe> [(Verified)Microsoft Corporation]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
- <{5A15D2F4-A6FF-11E0-9A84-00C04FD8DBD8}><D:\WINDOWS\System32\hA15D2F4.log> [N/A]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
- <WinlogonNotify: klogon><D:\WINDOWS\System32\klogon.dll> [Kaspersky Lab]
- ==================================
- 启动文件夹
- N/A
- ==================================
- 服务
- [ArcGIS License Manager / ArcGIS License Manager][Running/Auto Start]
- <D:\PROGRA~1\ESRI\License\arcgis9x\lmgrd.exe><N/A>
- [Ati HotKey Poller / Ati HotKey Poller][Stopped/Disabled]
- <D:\WINDOWS\System32\Ati2evxx.exe><N/A>
- [ATI Smart / ATI Smart][Stopped/Disabled]
- <D:\WINDOWS\system32\ati2sgag.exe><>
- [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Stopped/Disabled]
- <D:\Documents and Settings\Administrator\桌面\AVG Anti-Spyware 7.5\guard.exe><N/A>
- [卡巴斯基互联网安全套装 6.0 / AVP][Stopped/Auto Start]
- <D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe -r><Kaspersky Lab>
- [DriveHealth / DriveHealth][Running/Auto Start]
- <F:\tang Tools\反病毒类\DriveHealth\Drive Health\dhcore.exe><Helexis Software Development>
- [Human Interface Device Access / HidServ][Stopped/Disabled]
- <D:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
- [Pml Driver HPZ12 / Pml Driver HPZ12][Stopped/Manual Start]
- <D:\WINDOWS\System32\HPZipm12.exe><HP>
- [Symantec Network Drivers Service / SNDSrvc][Stopped/Manual Start]
- <D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe><N/A>
- [Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
- <D:\WINDOWS\System32\rundll32.exe windhcp.ocx,start><Microsoft Corporation>
- ==================================
- 驱动程序
- [Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
- <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
- [ati2mtag / ati2mtag][Running/Manual Start]
- <System32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
- [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Stopped/System Start]
- <\??\D:\Documents and Settings\Administrator\桌面\AVG Anti-Spyware 7.5\guard.sys><N/A>
- [AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
- <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
- [Sundance ST201 based Adapter NT Driver / DLH5X][Running/Manual Start]
- <System32\DRIVERS\DLH5XND5.sys><D-Link Corporation>
- [GMSIPCI / GMSIPCI][Stopped/Manual Start]
- <\??\G:\INSTALL\GMSIPCI.SYS><N/A>
- [kl1 / kl1][Running/Boot Start]
- <\SystemRoot\System32\drivers\kl1.sys><Kaspersky Lab>
- [klif / klif][Running/System Start]
- <\??\D:\WINDOWS\System32\drivers\klif.sys><Kaspersky Lab>
- [npkcrypt / npkcrypt][Stopped/Auto Start]
- <\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><N/A>
- [PCAlertDriver / PCAlertDriver][Stopped/Manual Start]
- <\??\D:\Program Files\MSI\PC Alert 4\NTGLM7X.sys><MICRO-STAR INT'L CO., LTD.>
- [Padus ASPI Shell / pfc][Running/Manual Start]
- <system32\drivers\pfc.sys><Padus, Inc.>
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
- <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
- [PxHelp20 / PxHelp20][Running/Boot Start]
- <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
- [ROCKEYNT / ROCKEYNT][Running/Auto Start]
- <\??\D:\WINDOWS\System32\drivers\Rockeynt.sys><FeiTian Tech Co.,Ltd>
- [Secdrv / Secdrv][Stopped/Manual Start]
- <System32\DRIVERS\secdrv.sys><N/A>
- [Sentinel / Sentinel][Running/Auto Start]
- <\SystemRoot\System32\Drivers\SENTINEL.SYS><Rainbow Technologies, Inc.>
- [SymEvent / SymEvent][Running/Manual Start]
- <\??\D:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>
- [SYMTDI / SYMTDI][Running/System Start]
- <\SystemRoot\System32\Drivers\SYMTDI.SYS><Symantec Corporation>
- [TSP / TSP][Stopped/Manual Start]
- <\??\D:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
- [WINIO / WINIO][Stopped/Manual Start]
- <\??\G:\winio.sys><N/A>
- [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
- <System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
- [VIMICRO USB PC Camera (ZC0301PLH) / ZSMC303][Stopped/Manual Start]
- <System32\Drivers\usbVM303.sys><Vimicro Corporation>
- ==================================
- 浏览器加载项
- [WebThunder Browser Helper]
- {00000AAA-A363-466E-BEF5-9BB68697AA7F} <D:\迅雷\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
- [Adobe PDF Reader Link Helper]
- {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
- [BitComet Helper]
- {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <D:\Program Files\BitComet\tools\BitCometBHO.dll, BitComet>
- [QQBrowserHelperObject Class]
- {54EBD53A-9BC1-480B-966A-843A333CA162} <, N/A>
- [ThunderMini Browser Helper]
- {8E6C1C49-F9CE-4311-9FB4-D70E8B0AEAEB} <, N/A>
- [Adobe PDF Conversion Toolbar Helper]
- {AE7CD045-E861-484f-8273-0445EE161910} <D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
- [Web反病毒保护]
- {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll, Kaspersky Lab>
- [信息检索(&R)]
- {92780B25-18CC-41C8-B9BE-3C9C571A8263} <D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
- [启动Web迅雷]
- {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
- [金山词霸]
- {9A687CA6-D585-4947-9ED9-BE96071F5CD9} <D:\PROGRA~1\Kingsoft\POWERW~1\XDictExB.dll, 金山软件股份有限公司>
- [QQ]
- {c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
- [电台(&R)]
- {8E718888-423F-11D2-876E-00A0C9082467} <D:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
- [Adobe PDF]
- {47833539-D0C5-4125-9FA8-0819E2EAAC93} <D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll, Adobe Systems Incorporated>
- [Shockwave Flash Object]
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <D:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
- [&使用迷你迅雷下载]
- <D:\Program Files\Thunder Network\ThunderMini\Program\GetUrl.htm, N/A>
- [上传到QQ网络硬盘]
- <D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
- [使用Web迅雷下载]
- <D:\迅雷\GetUrl.htm, N/A>
- [使用Web迅雷下载全部链接]
- <D:\迅雷\GetAllUrl.htm, N/A>
- [导出到 Microsoft Office Excel(&X)]
- <res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
- [添加到QQ自定义面板]
- <D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
- [添加到QQ表情]
- <D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
- [用QQ彩信发送该图片]
- <D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
- [转换为 Adobe PDF]
- <res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
- [转换为现有 PDF]
- <res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
- [转换选定的链接为 Adobe PDF]
- <res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html, N/A>
- [转换选定的链接为现有 PDF]
- <res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html, N/A>
- [转换选项为 Adobe PDF]
- <res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
- [转换选项为现有 PDF]
- <res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
- [转换链接目标为 Adobe PDF]
- <res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html, N/A>
- [转换链接目标为现有 PDF]
- <res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html, N/A>
- ==================================
- 正在运行的进程
- [PID: 740][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
- [PID: 808][\??\D:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 832][\??\D:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
- [D:\WINDOWS\System32\klogon.dll] [Kaspersky Lab, 6.0.0.299]
- [D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [PID: 876][D:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 888][D:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
- [PID: 1064][D:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 1112][D:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [PID: 1188][D:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 1312][D:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 1452][D:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
- [D:\WINDOWS\System32\AdobePDF.dll] [Adobe Systems Incorporated., 7.0.0.00]
- [D:\Program Files\Adobe\Acrobat 7.0\Distillr\AdistRes.CHS] [N/A, N/A]
- [D:\WINDOWS\system32\HPBMMON.DLL] [Hewlett-Packard, 10.00.16]
- [D:\WINDOWS\system32\hppamon0.dll] [HP, 5, 0, 5, 0]
- [D:\WINDOWS\system32\hpdomon.dll] [Hewlett-Packard, 03.42.00]
- [D:\WINDOWS\System32\spool\PRTPROCS\W32X86\IMFPrint.DLL] [Zenographics, Inc., 5, 54, 330, 0]
- [D:\WINDOWS\system32\Imf32.dll] [Zenographics, Inc., 5, 60, 1204, 0]
- [D:\WINDOWS\system32\ZTAG32.dll] [Zenographics, Inc., 5, 60, 1210, 0]
- [D:\WINDOWS\system32\ZSPOOL.dll] [Zenographics, Inc., 5, 51, 709, 0]
- [D:\WINDOWS\system32\hppadt40.dll] [HP, 5, 0, 5, 0]
- [D:\WINDOWS\system32\HPZidr12.dll] [HP, 5, 0, 5, 0]
- [D:\WINDOWS\system32\hpbmmjno.dll] [Hewlett-Packard, 00.01.00]
- [PID: 1644][D:\PROGRA~1\ESRI\License\arcgis9x\lmgrd.exe] [N/A, N/A]
- [PID: 1700][F:\tang Tools\反病毒类\DriveHealth\Drive Health\dhcore.exe] [Helexis Software Development, 2.3.0.110]
- [PID: 1732][D:\PROGRA~1\ESRI\License\arcgis9x\ARCGIS.EXE] [N/A, N/A]
- [PID: 1848][D:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 796][D:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
- [D:\WINDOWS\System32\hA15D2F4.log] [N/A, N/A]
- [D:\Program Files\5A15D2F4\4837C9ED.DLL] [N/A, N/A]
- [D:\Program Files\Common Files\ESRI\esriShellExt.dll] [ESRI , 9.0]
- [D:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
- [D:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS] [Adobe Systems, Inc., 7.0.0.0]
- [D:\Program Files\BitComet\tools\BitCometBHO.dll] [BitComet, 20061129]
- [D:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.chs] [Adobe Systems Inc., 7.0.5.2005092300\0]
- [D:\迅雷\WebThunderBHO_016.dll] [Thunder Networking Technologies,LTD, 6, 0, 0, 5]
- [D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.9.2006121800]
- [D:\Program Files\Unlocker\UnlockerCOM.dll] [N/A, N/A]
- [D:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
- [D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\shellex.dll] [Kaspersky Lab, 6.0.0.299]
- [D:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll] [Adobe Systems Inc., 7.0.7.2006011200\0]
- [PID: 1168][D:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [D:\Program Files\Common Files\System\MS5A15D2.DLL] [N/A, N/A]
- [D:\Program Files\5A15D2F4\4837C9ED.DLL] [N/A, N/A]
- [D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [PID: 1328][D:\WINDOWS\System32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
- [D:\Program Files\5A15D2F4\4837C9ED.DLL] [N/A, N/A]
- [PID: 772][D:\Program Files\MSN Messenger\msnmsgr.exe] [Microsoft Corporation, 8.1.0178.00]
- [D:\Program Files\5A15D2F4\4837C9ED.DLL] [N/A, N/A]
- [D:\WINDOWS\System32\msdmo.dll] [N/A, N/A]
- [D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299]
- [D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\klscav.dll] [Kaspersky Lab, 6.0.0.299]
- [D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\prloader.dll] [Kaspersky Lab, 6.0.0.299]
- [PID: 2272][D:\Program Files\Maxthon\Maxthon.exe] [Maxthon International Ltd., 1, 5, 9, 80]
- [D:\Program Files\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
- [D:\Program Files\5A15D2F4\4837C9ED.DLL] [N/A, N/A]
- [D:\迅雷\WebThunderBHO_016.dll] [Thunder Networking Technologies,LTD, 6, 0, 0, 5]
- [D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- [D:\Program Files\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
- [D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scr_ch_pg.dll] [Kaspersky Lab, 1.0.6.299]
- [D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\klscav.dll] [Kaspersky Lab, 6.0.0.299]
- [D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\prloader.dll] [Kaspersky Lab, 6.0.0.299]
- [D:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
- [D:\WINDOWS\System32\UNISPIM5.IME] [北京紫光华宇软件股份有限公司, 5.0.0.5076]
- [D:\WINDOWS\System32\msdmo.dll] [N/A, N/A]
- [D:\Program Files\Ringz Studio\Storm Codec\Codecs\VSFilter.dll] [Gabest, 1, 0, 1, 3]
- [D:\Program Files\Ringz Studio\Storm Codec\Codecs\PmpSplt.ax] [cooleyes, 1, 0, 0, 8]
- [D:\Program Files\Ringz Studio\Storm Codec\Codecs\RMSplt.ax] [Gabest, 1, 0, 1, 1]
- [D:\WINDOWS\System32\ffdshow.ax] [N/A, 1.0.2.2028]
- [PID: 3288][D:\Program Files\MSN Messenger\usnsvc.exe] [Microsoft Corporation, 8.1.0178.00]
- [PID: 2408][D:\Documents and Settings\Administrator\桌面\SREng.exe] [Smallfrogs Studio, 2.3.13.690]
- [D:\Program Files\5A15D2F4\4837C9ED.DLL] [N/A, N/A]
- [D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll] [Kaspersky Lab, 6.0.0.299]
- ==================================
- 文件关联
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .EXE OK. ["%1" %*]
- .COM OK. ["%1" %*]
- .PIF OK. ["%1" %*]
- .REG OK. [regedit.exe "%1"]
- .BAT OK. ["%1" %*]
- .SCR OK. ["%1" /S]
- .CHM Error. ["hh.exe" %1]
- .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
- .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
- .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
- ==================================
- Winsock 提供者
- N/A
- ==================================
- Autorun.inf
- N/A
- ==================================
- HOSTS 文件
- 127.0.0.1 localhost
- 172.31.186.6 erpapp.gyig.arp.cn
- 172.31.186.7 iasapp.gyig.arp.cn
- 172.31.186.8 iasdb.gyig.arp.cn
- ==================================
- API HOOK
- 警告!System Repair Engineer 提醒
- 你下面的函数内容与预期值不符,他
- 们可能被一些恶意的软件所修改:
- RVA 错误: LoadLibraryA
- RVA 错误: LoadLibraryExA
- RVA 错误: LoadLibraryExW
- RVA 错误: LoadLibraryW
- ==================================
复制代码 |