- 2007-05-07,16:45:54
- System Repair Engineer 2.4.12.806
- Smallfrogs ([url]http://www.KZTechs.com[/url])
- Windows XP Professional Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed
- Follow item(s) have been choosed:
- All Boot Items (Including Registry, Startup Folders, Services and so on)
- Browser Add-ons
- Runing Processes (Including process model information)
- File Associations
- Winsock Provider
- Autorun.Inf
- HOSTS File
- Boot Items
- Registry
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
- <ShStatEXE><"C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE> [(Verified)"McAfee, Inc."]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
- <Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)Microsoft Windows Publisher]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
- <AppInit_DLLs><> [N/A]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
- <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
- ==================================
- Startup Folders
- N/A
- ==================================
- Services
- [Human Interface Device Access / HidServ][Stopped/Disabled]
- <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
- [McAfee Framework Service / McAfeeFramework][Stopped/Manual Start]
- <"C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart><McAfee, Inc.>
- [McAfee McShield / McShield][Running/Auto Start]
- <"C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe"><McAfee, Inc.>
- [McAfee Task Manager / McTaskManager][Stopped/Manual Start]
- <"C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe"><McAfee, Inc.>
- [Win32 Debug Service / MSDebugsvc][Stopped/Disabled]
- <C:\WINDOWS\system32\\rundll32.exe msdebug.dll,input><Microsoft Corporation>
- [SoundMAX Agent Service / SoundMAX Agent Service (default)][Stopped/Manual Start]
- <><N/A>
- [Windows / Windows][Stopped/Disabled]
- <C:\WINDOWS\system32\Server.exe><N/A>
- [WinWLServiceNow / WinWLServiceNow][Stopped/Disabled]
- <><N/A>
- [WinWMService / WinWMService][Stopped/Disabled]
- <><N/A>
- ==================================
- Drivers
- [aeaudio / aeaudio][Running/Manual Start]
- <system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
- [ati2mtag / ati2mtag][Running/Manual Start]
- <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
- [atitray / atitray][Running/System Start]
- <\??\C:\Program Files\Radeon Omega Drivers\v3.8.231\ATI Tray Tools\atitray.sys><N/A>
- [ENTECH / ENTECH][Stopped/Manual Start]
- <\??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys><EnTech Taiwan>
- [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Running/Manual Start]
- <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
- [McAfee Inc. / mfeapfk][Running/Manual Start]
- <system32\drivers\mfeapfk.sys><McAfee, Inc.>
- [McAfee Inc. / mfeavfk][Running/Manual Start]
- <system32\drivers\mfeavfk.sys><McAfee, Inc.>
- [McAfee Inc. / mfebopk][Running/Manual Start]
- <system32\drivers\mfebopk.sys><McAfee, Inc.>
- [McAfee Inc. / mfehidk][Running/Manual Start]
- <system32\drivers\mfehidk.sys><McAfee, Inc.>
- [McAfee Inc. / mfetdik][Running/System Start]
- <system32\drivers\mfetdik.sys><McAfee, Inc.>
- [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
- <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
- [Secdrv / Secdrv][Stopped/Manual Start]
- <system32\DRIVERS\secdrv.sys><N/A>
- [smwdm / smwdm][Running/Manual Start]
- <system32\drivers\smwdm.sys><Analog Devices, Inc.>
- [ViaIde / ViaIde][Running/Boot Start]
- <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
- [videX32 / videX32][Running/Boot Start]
- <\SystemRoot\system32\DRIVERS\videX32.sys><VIA Technologies, Inc.>
- ==================================
- Browser Add-ons
- [scriptproxy]
- {7DB2D5A0-7241-4E79-B68D-6309F01C5231} <C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll, McAfee, Inc.>
- [Thunder Browser Helper]
- {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\downloads\Thunder\Thunder.v5.5.2.252.NoAD-Ayu\Thunder\ComDlls\XunLeiBHO_006.dll, Thunder Networking Technologies,LTD>
- [MUWebControl Class]
- {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\system32\muweb.dll, Microsoft Corporation>
- [Active Desktop Mover]
- {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
- [scriptproxy]
- {7DB2D5A0-7241-4E79-B68D-6309F01C5231} <C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll, McAfee, Inc.>
- [Thunder Browser Helper]
- {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\downloads\Thunder\Thunder.v5.5.2.252.NoAD-Ayu\Thunder\ComDlls\XunLeiBHO_006.dll, Thunder Networking Technologies,LTD>
- [SearchAssistantOC]
- {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
- [Shockwave Flash Object]
- {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\flash.ocx, Macromedia, Inc.>
- [Download all by Thunder]
- <D:\downloads\Thunder\Thunder.v5.5.2.252.NoAD-Ayu\Thunder\Program\getallurl.htm, N/A>
- [Download by Thunder]
- <D:\downloads\Thunder\Thunder.v5.5.2.252.NoAD-Ayu\Thunder\Program\geturl.htm, N/A>
- ==================================
- Running Processes
- [PID: 576][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 636][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [PID: 664][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4129]
- [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 708][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
- [PID: 720][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
- [PID: 904][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
- [PID: 1096][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
- [PID: 1344][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
- [C:\WINDOWS\system32\msdmo.dll] [, ]
- [D:\downloads\Thunder\Thunder.v5.5.2.252.NoAD-Ayu\Thunder\ComDlls\XunLeiBHO_006.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 3]
- [C:\Program Files\Microsoft Office\Office10\msohev.dll] [Microsoft Corporation, 10.0.2609]
- [PID: 1464][C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe] [McAfee, Inc., VSCORE.13.3.2.101.x86]
- [C:\Program Files\McAfee\VirusScan Enterprise\LockDown.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
- [C:\Program Files\McAfee\VirusScan Enterprise\mytilus.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
- [C:\Program Files\McAfee\VirusScan Enterprise\mytilus2.dll] [McAfee, Inc., VSCORE.13.3.2.101.x86]
- [C:\Program Files\McAfee\VirusScan Enterprise\RES0900\McShield.dll] [McAfee, Inc., VSCORE.13.3.1.101]
- [C:\Program Files\McAfee\VirusScan Enterprise\FTL.Dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
- [C:\Program Files\McAfee\VirusScan Enterprise\naiann.dll] [McAfee, Inc., 8.5.0.781]
- [C:\Program Files\McAfee\VirusScan Enterprise\VsEvntUI.dll] [N/A, ]
- [C:\Program Files\McAfee\VirusScan Enterprise\NAEvent.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
- [C:\Program Files\McAfee\VirusScan Enterprise\shutil.dll] [McAfee, Inc., 8.5.0.830]
- [C:\Program Files\McAfee\VirusScan Enterprise\wmain.dll] [McAfee, Inc., 8.5.0.781]
- [C:\Program Files\McAfee\Common Framework\GenEvtInf.dll] [McAfee, Inc., 3.6.0.453]
- [C:\Program Files\McAfee\Common Framework\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
- [C:\Program Files\McAfee\Common Framework\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
- [C:\Program Files\McAfee\Common Framework\SecureFrameworkFactory.dll] [McAfee, Inc., 3.6.0.453]
- [C:\Program Files\McAfee\VirusScan Enterprise\scriptsv.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
- [C:\Program Files\Common Files\McAfee\Engine\mcscan32.dll] [McAfee, Inc., 5.1.00]
- [C:\Program Files\McAfee\VirusScan Enterprise\mfebopa.dll] [McAfee, Inc., SYSCORE.13.3.0.116.x86]
- [C:\Program Files\McAfee\VirusScan Enterprise\mfehida.dll] [McAfee, Inc., SYSCORE.13.3.0.116.x86]
- [C:\Program Files\McAfee\VirusScan Enterprise\mfeapfa.dll] [McAfee, Inc., SYSCORE.13.3.0.116.x86]
- [C:\Program Files\McAfee\VirusScan Enterprise\mfeavfa.dll] [McAfee, Inc., SYSCORE.13.3.0.116.x86]
- [PID: 1652][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
- [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
- [PID: 1564][D:\Sofewares\miranda-v\miranda32.exe] [ , 0.4.3 alpha build #36]
- [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
- [D:\Sofewares\miranda-v\Plugins\dbx_3x.dll] [N/A, ]
- [D:\Sofewares\miranda-v\Plugins\clist_mw.dll] [ , 0.3.4 alpha]
- [D:\Sofewares\miranda-v\Plugins\chat.dll] [N/A, ]
- [D:\Sofewares\miranda-v\Plugins\import.dll] [ , 0.9.2]
- [D:\Sofewares\miranda-v\Plugins\srmm.dll] [N/A, ]
- [D:\Sofewares\miranda-v\Plugins\msn.dll] [ , 0.4.1.2]
- [D:\Sofewares\miranda-v\Plugins\icq.dll] [, 0, 3, 7, 0]
- [D:\Sofewares\miranda-v\Plugins\mirandaqq.dll] [, 0.1.0.34]
- [PID: 956][C:\Program Files\foobar2000\foobar2000.exe] [N/A, ]
- [C:\Program Files\foobar2000\utf8api.dll] [N/A, ]
- [C:\Program Files\foobar2000\components\foo_albumlist.dll] [N/A, ]
- [C:\Program Files\foobar2000\components\foo_ape.dll] [N/A, ]
- [C:\Program Files\foobar2000\components\foo_cdda.dll] [N/A, ]
- [C:\Program Files\foobar2000\components\foo_console.dll] [N/A, ]
- [C:\Program Files\foobar2000\components\foo_diskwriter.dll] [N/A, ]
- [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
- [C:\Program Files\foobar2000\components\foo_dsp_extra.dll] [N/A, ]
- [C:\Program Files\foobar2000\components\foo_flac.dll] [N/A, ]
- [C:\Program Files\foobar2000\components\foo_input_std.dll] [N/A, ]
- [C:\Program Files\foobar2000\components\foo_masstag.dll] [N/A, ]
- [C:\Program Files\foobar2000\components\foo_output_std.dll] [N/A, ]
- [C:\Program Files\foobar2000\components\foo_read_http.dll] [N/A, ]
- [C:\Program Files\foobar2000\components\foo_rgscan.dll] [N/A, ]
- [C:\Program Files\foobar2000\components\foo_speex.dll] [N/A, ]
- [C:\Program Files\foobar2000\components\foo_ui_std.dll] [N/A, ]
- [C:\Program Files\foobar2000\components\foo_vis_manager.dll] [N/A, ]
- [C:\Program Files\foobar2000\components\foo_wavpack.dll] [N/A, ]
- [C:\Program Files\foobar2000\components\foo_wma.dll] [, 1.0.9]
- [C:\WINDOWS\system32\msdmo.dll] [, ]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 1148][D:\Sofewares\flashfxp\FlashFXP.exe] [IniCom Networks, Inc., 3.4.0.1140]
- [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
- [PID: 1920][D:\Sofewares\MPlayer-SVN-22870-KK\mplayer.exe] [, SVN-r22870]
- [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
- [D:\Sofewares\MPlayer-SVN-22870-KK\unrar.dll] [N/A, ]
- [D:\Sofewares\MPlayer-SVN-22870-KK\codecs\drvc.dll] [RealNetworks, Inc., 10.0.0.1466]
- [C:\WINDOWS\system32\PNCRT.dll] [Real Networks, Inc, 6.0.0.0]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [PID: 608][D:\Sofewares\GreenBrowser\GreenBrowser.exe] [MoreQuick, 1, 0, 0, 0]
- [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
- [C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll] [McAfee, Inc., VSCORE.13.3.1.100.x86]
- [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
- [C:\WINDOWS\system32\macromed\flash\flash.ocx] [Macromedia, Inc., 6,0,79,0]
- [D:\downloads\免疫插件\sreng2\SREng.com] [Smallfrogs Studio, 2.4.12.806]
- [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
- ==================================
- File Associations
- .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
- .EXE OK. ["%1" %*]
- .COM OK. ["%1" %*]
- .PIF OK. ["%1" %*]
- .REG OK. [regedit.exe "%1"]
- .BAT OK. ["%1" %*]
- .SCR OK. ["%1" /S]
- .CHM OK. ["C:\WINDOWS\hh.exe" %1]
- .HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
- .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
- .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
- .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
- .LNK OK. [{00021401-0000-0000-C000-000000000046}]
- ==================================
- Winsock Provider
- N/A
- ==================================
- Autorun.Inf
- N/A
- ==================================
- HOSTS File
- 127.0.0.1 localhost
- ==================================
- API HOOK
- N/A
- ==================================
- Hidden Process
- N/A
- ==================================
复制代码 |