2010-01-21,17:38:53
System Repair Engineer 2.8.2.1321
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
计划任务
Windows 安全更新检查
API HOOK
隐藏进程
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{AEB6717E-7E19-11d0-97EE-00C04FD91972}>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [Microsoft Corporation]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
<浏览器自定义组件>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
==================================
启动文件夹
N/A
==================================
服务
[Alerter / Alerter][Stopped/Disabled]
[Application Layer Gateway Service / ALG][Running/Manual Start]
[Application Management / AppMgmt][Stopped/Manual Start]
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
[Windows Audio / AudioSrv][Running/Auto Start]
[Background Intelligent Transfer Service / BITS][Stopped/Manual Start]
[Computer Browser / Browser][Running/Auto Start]
[Indexing Service / CiSvc][Stopped/Disabled]
[ClipBook / ClipSrv][Stopped/Disabled]
[COM+ System Application / COMSysApp][Stopped/Manual Start]
[Cryptographic Services / CryptSvc][Running/Auto Start]
[DCOM Server Process Launcher / DcomLaunch][Running/Auto Start]
[DHCP Client / Dhcp][Running/Auto Start]
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
[Logical Disk Manager / dmserver][Running/Auto Start]
[DNS Client / Dnscache][Running/Auto Start]
[Wired AutoConfig / Dot3svc][Stopped/Manual Start]
[Extensible Authentication Protocol Service / EapHost][Stopped/Manual Start]
[Error Reporting Service / ERSvc][Running/Auto Start]
[Event Log / Eventlog][Running/Auto Start]
[COM+ Event System / EventSystem][Running/Manual Start]
[Fast User Switching Compatibility / FastUserSwitchingCompatibility][Running/Manual Start]
[Help and Support / helpsvc][Stopped/Disabled]
[HID Input Service / HidServ][Stopped/Auto Start]
[Health Key and Certificate Management Service / hkmsvc][Stopped/Manual Start]
[HTTP SSL / HTTPFilter][Stopped/Manual Start]
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe">
[IMAPI CD-Burning COM Service / ImapiService][Stopped/Manual Start]
[Kingsoft Rescue Service / Kingsoft Rescue Service][Running/Auto Start]
[Kingsoft Antivirus XEngine Service(Beta) / KxEServBeta][Running/Auto Start]
[Server / LanmanServer][Running/Auto Start]
[Workstation / lanmanworkstation][Running/Auto Start]
[TCP/IP NetBIOS Helper / LmHosts][Running/Auto Start]
[Messenger / Messenger][Stopped/Disabled]
[NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]
[Distributed Transaction Coordinator / MSDTC][Stopped/Manual Start]
[Windows Installer / MSIServer][Stopped/Manual Start]
[Network Access Protection Agent / napagent][Stopped/Manual Start]
[Network DDE / NetDDE][Stopped/Disabled]
[Network DDE DSDM / NetDDEdsdm][Stopped/Disabled]
[Net Logon / Netlogon][Stopped/Manual Start]
[Network Connections / Netman][Running/Manual Start]
[Network Location Awareness (NLA) / Nla][Running/Manual Start]
[NT LM Security Support Provider / NtLmSsp][Stopped/Manual Start]
[Removable Storage / NtmsSvc][Stopped/Manual Start]
[Plug and Play / PlugPlay][Running/Auto Start]
[IPSEC Services / PolicyAgent][Running/Auto Start]
[Protected Storage / ProtectedStorage][Running/Auto Start]
[Remote Access Auto Connection Manager / RasAuto][Stopped/Manual Start]
[Remote Access Connection Manager / RasMan][Running/Manual Start]
[Remote Desktop Help Session Manager / RDSessMgr][Stopped/Manual Start]
[Routing and Remote Access / RemoteAccess][Stopped/Disabled]
[Remote Registry / RemoteRegistry][Stopped/Disabled]
[Remote Procedure Call (RPC) Locator / RpcLocator][Stopped/Manual Start]
[Remote Procedure Call (RPC) / RpcSs][Running/Auto Start]
[Rav Service / RsRavMon][Running/Auto Start]
<"C:\Program Files\Rising\Rav\RavMonD.exe">
[RFW Service / RsRFWMon][Running/Auto Start]
<"C:\Program Files\Rising\RFW\RavMonD.exe">
[QoS RSVP / RSVP][Stopped/Manual Start]
[Security Accounts Manager / SamSs][Running/Auto Start]
[Smart Card / SCardSvr][Stopped/Manual Start]
[Task Scheduler / Schedule][Stopped/Disabled]
[Secondary Logon / seclogon][Running/Auto Start]
[System Event Notification / SENS][Running/Auto Start]
[Windows Firewall/Internet Connection Sharing (ICS) / SharedAccess][Running/Auto Start]
[Shell Hardware Detection / ShellHWDetection][Running/Auto Start]
[Print Spooler / Spooler][Running/Auto Start]
[System Restore Service / srservice][Running/Auto Start]
[SSDP Discovery Service / SSDPSRV][Running/Manual Start]
[Windows Image Acquisition (WIA) / stisvc][Stopped/Manual Start]
[MS Software Shadow Copy Provider / SwPrv][Stopped/Manual Start]
[Performance Logs and Alerts / SysmonLog][Stopped/Manual Start]
[Telephony / TapiSrv][Running/Manual Start]
[Terminal Services / TermService][Running/Manual Start]
[Themes / Themes][Running/Auto Start]
[Telnet / TlntSvr][Stopped/Disabled]
[Distributed Link Tracking Client / TrkWks][Running/Auto Start]
[Windows User Mode Driver Framework / UMWdf][Running/Auto Start]
[Universal Plug and Play Device Host / upnphost][Stopped/Manual Start]
[Uninterruptible Power Supply / UPS][Stopped/Manual Start]
[Volume Shadow Copy / VSS][Stopped/Manual Start]
[Windows Time / W32Time][Running/Auto Start]
[WatchData ccb V3.2 / WDMonitorCCB][Running/Auto Start]
[WebClient / WebClient][Running/Auto Start]
[Windows Management Instrumentation / winmgmt][Running/Auto Start]
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
[Windows Management Instrumentation Driver Extensions / Wmi][Stopped/Manual Start]
[WMI Performance Adapter / WmiApSrv][Stopped/Manual Start]
[Security Center / wscsvc][Running/Auto Start]
[Automatic Updates / wuauserv][Running/Auto Start]
[Wireless Zero Configuration / WZCSVC][Running/Auto Start]
[Network Provisioning Service / xmlprov][Stopped/Manual Start]
[主动防御 / ZhuDongFangYu][Stopped/Manual Start]
<"C:\Program Files\360\360safe\deepscan\zhudongfangyu.exe"><360.cn>
==================================
驱动程序
[360SelfProtection / 360SelfProtection][Running/System Start]
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
[Microsoft ACPI Driver / ACPI][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\ACPI.sys>
[Microsoft Kernel Acoustic Echo Canceller / aec][Stopped/Manual Start]
[AFD / AFD][Running/System Start]
<\SystemRoot\System32\drivers\afd.sys>
[Intel AGP Bus Filter / agp440][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\agp440.sys>
[AmdK8 Compatible Device / AmdK8][Stopped/Manual Start]
