[CODE]
2007-01-25,12:23:24
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<WSockDrv32><C:\WINDOWS\muqhbj.exe> [N/A]
<PTSShell><C:\WINDOWS\PTSShell.exe> []
<LotusHlp><C:\WINDOWS\LotusHlp.exe> []
<NAVMon32><C:\WINDOWS\NAVMon32.exE> []
<WINSvr32><C:\WINDOWS\WINSvr32.exE> []
<SHAProc><C:\WINDOWS\SHAProc.exe> []
<RegSrv64D><C:\WINDOWS\ubcdpf.exe> []
<Kvsc3><C:\WINDOWS\Kvsc3.exE> []
<mppds><C:\WINDOWS\mppds.exe> []
<upxdnd><C:\WINDOWS\upxdnd.exe> []
<DbgHlp32><C:\WINDOWS\DbgHlp32.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<MsIMMs32><C:\WINDOWS\MsIMMs32.exE> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<NVDispDrv><C:\WINDOWS\NVDispDRV.EXE> []
<WinSysW><C:\WINDOWS\49400L.exe> [N/A]
<AVPSrv><C:\WINDOWS\AVPSrv.exE> []
<Vmlist><regsvr32 /s apphelps.dll> [N/A]
<WinForm><C:\WINDOWS\WinForm.exE> []
<SSLDyn><C:\WINDOWS\SSLDyn.exE> []
<MsPrint32D><C:\WINDOWS\MsPrint32D.exe> []
<WinSysM><C:\WINDOWS\49400M.exe> [N/A]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<yfmy7t><rundll32 "C:\WINDOWS\Downlo~1\yfmy7t.dll",start> [Microsoft Corporation]
<pbwhs35k><rundll32 "C:\WINDOWS\Downlo~1\pbwhs35k.dll",Run> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe vchelp.exe> []
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><utgnehz.dll,nauhgnem.dll,auhad.dll,nuygnef.dll,uohsom.dll,uyom.dll,gnolnait.dll,ijiq.dll,ijougiemnaw.dll,iemnaw.dll,niluw.dll,naixuhz.dll,xhtd.dll,oadgnohiac.dll,iqnauhc.dll,nahzij.dll,gnefnaib.dll,gsqq.dll,3auhad.dll,naijoad.dll,aixauh.dll,xhqq.dll,QQ.dll,hjxr.dll,zqhs.dll,oadnew.dll,dgzg.dll,hz.dll,2ty.dll,jsfg.dll,rj.dll,fmxh.dll,jmx.dll,wtwx.dll,ddtj.dll,fz.dll,gnaixnauhuoyizqq.dll,gnaixnauhqq.dll,2nauygniqaixnaij.dll,naijihzeuyouhz.dll,uyomielnux.dll,vlihzouhgnfe.dll,sfhx.dll,eve.dll,jsqc.dll,wtiemnaw.dll,dqncj.dll> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
<WinlogonNotify: WgaLogon><WgaLogon.dll> [(Verified)Microsoft Corporation]
2007-01-25,12:23:24
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<WSockDrv32><C:\WINDOWS\muqhbj.exe> [N/A]
<PTSShell><C:\WINDOWS\PTSShell.exe> []
<LotusHlp><C:\WINDOWS\LotusHlp.exe> []
<NAVMon32><C:\WINDOWS\NAVMon32.exE> []
<WINSvr32><C:\WINDOWS\WINSvr32.exE> []
<SHAProc><C:\WINDOWS\SHAProc.exe> []
<RegSrv64D><C:\WINDOWS\ubcdpf.exe> []
<Kvsc3><C:\WINDOWS\Kvsc3.exE> []
<mppds><C:\WINDOWS\mppds.exe> []
<upxdnd><C:\WINDOWS\upxdnd.exe> []
<DbgHlp32><C:\WINDOWS\DbgHlp32.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<MsIMMs32><C:\WINDOWS\MsIMMs32.exE> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<NVDispDrv><C:\WINDOWS\NVDispDRV.EXE> []
<WinSysW><C:\WINDOWS\49400L.exe> [N/A]
<AVPSrv><C:\WINDOWS\AVPSrv.exE> []
<Vmlist><regsvr32 /s apphelps.dll> [N/A]
<WinForm><C:\WINDOWS\WinForm.exE> []
<SSLDyn><C:\WINDOWS\SSLDyn.exE> []
<MsPrint32D><C:\WINDOWS\MsPrint32D.exe> []
<WinSysM><C:\WINDOWS\49400M.exe> [N/A]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<yfmy7t><rundll32 "C:\WINDOWS\Downlo~1\yfmy7t.dll",start> [Microsoft Corporation]
<pbwhs35k><rundll32 "C:\WINDOWS\Downlo~1\pbwhs35k.dll",Run> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe vchelp.exe> []
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><utgnehz.dll,nauhgnem.dll,auhad.dll,nuygnef.dll,uohsom.dll,uyom.dll,gnolnait.dll,ijiq.dll,ijougiemnaw.dll,iemnaw.dll,niluw.dll,naixuhz.dll,xhtd.dll,oadgnohiac.dll,iqnauhc.dll,nahzij.dll,gnefnaib.dll,gsqq.dll,3auhad.dll,naijoad.dll,aixauh.dll,xhqq.dll,QQ.dll,hjxr.dll,zqhs.dll,oadnew.dll,dgzg.dll,hz.dll,2ty.dll,jsfg.dll,rj.dll,fmxh.dll,jmx.dll,wtwx.dll,ddtj.dll,fz.dll,gnaixnauhuoyizqq.dll,gnaixnauhqq.dll,2nauygniqaixnaij.dll,naijihzeuyouhz.dll,uyomielnux.dll,vlihzouhgnfe.dll,sfhx.dll,eve.dll,jsqc.dll,wtiemnaw.dll,dqncj.dll> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
<WinlogonNotify: WgaLogon><WgaLogon.dll> [(Verified)Microsoft Corporation]