[CODE]
2011-10-27,19:32:25
System Repair Engineer 2.8.4.1331
Smallfrogs (http://www.KZTechs.com)
Windows Vista Home Basic Edition Service Pack 1 (Build 6001) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
计划任务
Windows 安全更新检查
API HOOK
隐藏进程
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<360sd><"C:\Program Files\360\360sdrun.exe"> [(Verified)360.cn]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<360Safetray><"C:\Program Files\360\360safe\safemon\360Tray.exe" /start> [(Verified)360.cn]
<360DeskTop><"C:\360\360DeskTop\Bin\360Desktop.exe"> [(Verified)360.cn]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
[HKEY_CURRENT_USER\Control Panel\Desktop]
==================================
启动文件夹
N/A
==================================
服务
[360 杀毒实时防护服务 / 360rp][Running/Auto Start]
<"C:\Program Files\360\360rps.exe"><360.cn>
[Andrea ST Filters Service / AESTFilters][Stopped/Manual Start]
[Array SSL VPN Service 8,4,0,264 / ArraySSL_VPN_Service8.4.0.264][Running/Auto Start]
[Array Utility Service 8,4,0,264 / Array_Utility_Service8.4.0.264][Running/Auto Start]
[Ati External Event Utility / Ati External Event Utility][Running/Auto Start]
[Autodesk Licensing Service / Autodesk Licensing Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe">
[Baidu Updater / BaiduUpdater][Stopped/Manual Start]
[Bluetooth Service / btwdins][Running/Auto Start]
[eSafe DeviceNotification service / DeviceNotice][Running/Auto Start]
[Dock Login Service / DockLoginService][Stopped/Manual Start]
[eLive Security Service / eLiveSafe][Stopped/Manual Start]
<"C:\Program Files\ChinaTelecom\eLive\PlugIns\Safe\elivesafe.exe"><贝壳网际(北京)安全技术有限公司>
[FAService / FAService][Stopped/Manual Start]
<"C:\Program Files\Sensible Vision\Fast Access\FAService.exe">
[FLEXnet Licensing Service / FLEXnet Licensing Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe">
[GoToAssist / GoToAssist][Stopped/Manual Start]
<"C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe" Start=service>
[H3C iNode Service / H3C_SVR_MNG_SERVICE][Stopped/Manual Start]
<"C:\Program Files\H3C\iNode Client\AuthenMngService.exe" -startService>
[ICBC Daemon Service / ICBC Daemon Service][Running/Auto Start]
[Lookout Citadel Server / LkCitadelServer][Running/Auto Start]
[National Instruments PSP Server Locator / lkClassAds][Running/Auto Start]
[National Instruments Time Synchronization / lkTimeSync][Running/Auto Start]
[Machine Debug Manager / MDM][Stopped/Manual Start]
<"C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe">
[NI Configuration Manager / mxssvr][Running/Auto Start]
<"C:\Program Files\National Instruments\MAX\nimxs.exe">
[Nero BackItUp Scheduler 3 / Nero BackItUp Scheduler 3][Stopped/Manual Start]
[NI Application Web Server / NIApplicationWebServer][Running/Auto Start]
<"C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe" -user>
[NI Device Loader / nidevldu][Running/Auto Start]
[National Instruments Domain Service / NIDomainService][Running/Auto Start]
<"C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe">
[NILM License Manager / NILM License Manager][Stopped/Disabled]
<"C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe">
[National Instruments LXI Discovery Service / niLXIDiscovery][Stopped/Manual Start]
<"C:\Program Files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe">
[National Instruments mDNS Responder Service / nimDNSResponder][Stopped/Manual Start]
<"C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe">
[NI PXI Resource Manager / nipxirmu][Stopped/Manual Start]
[NI System Web Server / niSvcLoc][Running/Auto Start]
<"C:\Program Files\National Instruments\Shared\NI WebServer\SystemWebServer.exe" -system>
[National Instruments Variable Engine / NITaggerService][Running/Auto Start]
<"C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe">
[NMIndexingService / NMIndexingService][Stopped/Manual Start]
<"C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe">
[OpcEnum / OpcEnum][Stopped/Manual Start]
[PLFlash DeviceIoControl Service / PLFlash DeviceIoControl Service][Stopped/Manual Start]
[SupportSoft Sprocket Service (DellSupportCenter) / sprtsvc_DellSupportCenter][Stopped/Manual Start]
<"C:\Program Files\Dell Support Center\bin\sprtsvc.exe" /service /P DellSupportCenter>
[Audio Service / STacSV][Running/Auto Start]
[stllssvr / stllssvr][Stopped/Manual Start]
<"C:\Program Files\Common Files\SureThing Shared\stllssvr.exe">
[UGS 许可证服务器 (ugslmd) / UGS License Server (ugslmd)][Stopped/Manual Start]
<"C:\Program Files\UGS\UGSLicensing\lmgrd.exe">
[Dell Wireless WLAN Tray Service / wltrysvc][Running/Auto Start]
[主动防御 / ZhuDongFangYu][Running/Auto Start]
<"C:\Program Files\360\360safe\deepscan\zhudongfangyu.exe"><360.cn>
[Sinfor Ingress Updater / zrupdate][Stopped/Manual Start]
==================================
驱动程序
[360AvFlt mini-filter driver / 360AvFlt][Running/System Start]
[360netmon / 360netmon][Running/System Start]
[360SelfProtection / 360SelfProtection][Running/System Start]
[adp94xx / adp94xx][Stopped/Disabled]
<\SystemRoot\system32\drivers\adp94xx.sys>
[adpahci / adpahci][Stopped/Disabled]
<\SystemRoot\system32\drivers\adpahci.sys>
[adpu160m / adpu160m][Stopped/Disabled]
<\SystemRoot\system32\drivers\adpu160m.sys>
[adpu320 / adpu320][Stopped/Disabled]
<\SystemRoot\system32\drivers\adpu320.sys>
[aic78xx / aic78xx][Stopped/Disabled]
<\SystemRoot\system32\drivers\djsvs.sys>
[aliide / aliide][Stopped/Disabled]
<\SystemRoot\system32\drivers\aliide.sys>
[altio / altio][Running/Auto Start]
<\??\C:\Program Files\Altium Designer Summer 09\System\Drivers\altio.sys>
[arc / arc][Stopped/Disabled]
<\SystemRoot\system32\drivers\arc.sys>
[arcsas / arcsas][Stopped/Disabled]
<\SystemRoot\system32\drivers\arcsas.sys>
[atikmdag / atikmdag][Running/Manual Start]
[Array Networks SSL VPN Driver / ATP][Stopped/Manual Start]
[BAPIDRV / BAPIDRV][Running/System Start]
<\??\C:\Windows\system32\drivers\BAPIDRV.SYS><360.cn>
[BCM42RLY / BCM42RLY][Running/Manual Start]
[DELL 无线网卡驱动程序 / BCM43XX][Running/Manual Start]
[Brother USB Mass-Storage Lower Filter Driver / BrFiltLo][Stopped/Manual Start]
<\SystemRoot\system32\drivers\brfiltlo.sys>
[Brother USB Mass-Storage Upper Filter Driver / BrFiltUp][Stopped/Manual Start]
<\SystemRoot\system32\drivers\brfiltup.sys>
[Brother MFC Serial Port Interface Driver (WDM) / Brserid][Stopped/Disabled]
<\SystemRoot\system32\drivers\brserid.sys>
[Brother WDM Serial driver / BrSerWdm][Stopped/Disabled]
<\SystemRoot\system32\drivers\brserwdm.sys>
[Brother MFC USB Fax Only Modem / BrUsbMdm][Stopped/Disabled]
<\SystemRoot\system32\drivers\brusbmdm.sys>
[Brother MFC USB Serial WDM Driver / BrUsbSer][Stopped/Manual Start]
<\SystemRoot\system32\drivers\brusbser.sys>
[蓝牙音频设备 / btwaudio][Running/Manual Start]
[Bluetooth AVDT / btwavdt][Running/Manual Start]
[Bluetooth L2CAP Service / btwl2cap][Running/Manual Start]
[btwrchid / btwrchid][Running/Manual Start]
[CH341SER / CH341SER][Stopped/Manual Start]
[cmdide / cmdide][Stopped/Disabled]
<\SystemRoot\system32\drivers\cmdide.sys>
[Intel(R) PRO/1000 PCI Express Network Connection Driver / e1express][Stopped/Manual Start]
[Intel(R) PRO/1000 NDIS 6 Adapter Driver / E1G60][Stopped/Manual Start]
[EfiSystemMon / EfiMon][Running/System Start]
[elxstor / elxstor][Stopped/Disabled]
<\SystemRoot\system32\drivers\elxstor.sys>
[Virtual Serial Ports Driver (Eltima Softwate) / evserial][Running/Manual Start]
[facap, FastAccess Video Capture / FACAP][Stopped/Manual Start]
[HookPort / HookPort][Running/Boot Start]
<\SystemRoot\System32\Drivers\Hookport.sys><360安全中心>
[HpCISSs / HpCISSs][Stopped/Disabled]
<\SystemRoot\system32\drivers\hpcisss.sys>
[HWiNFO32 Kernel Driver / HWiNFO32][Stopped/System Start]
<\??\C:\Program Files\MyDrivers\DriverGenius2011\Mydrivers32.SYS>
[Intel RAID Controller Vista / iaStorV][Stopped/Disabled]
<\SystemRoot\system32\drivers\iastorv.sys>
[iirsp / iirsp][Stopped/Disabled]
<\SystemRoot\system32\drivers\iirsp.sys>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
[ITEATAPI_Service_Install / iteatapi][Stopped/Disabled]
<\SystemRoot\system32\drivers\iteatapi.sys>
[ITERAID_Service_Install / iteraid][Stopped/Disabled]
<\SystemRoot\system32\drivers\iteraid.sys>
[Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0 / k57nd60x][Running/Manual Start]
[Driver for lero Device / lero][Stopped/Manual Start]
[LSI_FC / LSI_FC][Stopped/Disabled]
<\SystemRoot\system32\drivers\lsi_fc.sys>
[LSI_SAS / LSI_SAS][Stopped/Disabled]
<\SystemRoot\system32\drivers\lsi_sas.sys>
[LSI_SCSI / LSI_SCSI][Stopped/Disabled]
<\SystemRoot\system32\drivers\lsi_scsi.sys>
[lvalarmk / lvalarmk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\lvalarmk.sys>
[megasas / megasas][Stopped/Disabled]
<\SystemRoot\system32\drivers\megasas.sys>
[MegaSR / MegaSR][Stopped/Disabled]
<\SystemRoot\system32\drivers\megasr.sys>
[Mraid35x / Mraid35x][Stopped/Disabled]
<\SystemRoot\system32\drivers\mraid35x.sys>
[Driver for netfilter Device / netfilter][Running/Manual Start]
[nfrd960 / nfrd960][Stopped/Disabled]
<\SystemRoot\system32\drivers\nfrd960.sys>
[NI PXI-1006 Chassis Pilot / ni1006k][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\ni1006k.sys>
[NI PXI-1045 Chassis Pilot / ni1045k][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\ni1045kl.sys>
[NI PXIe-1065 Chassis Pilot / ni1065k][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\ni1065k.sys>
[nicanpk / nicanpk][Running/Auto Start]
[NI-CAN Driver / nicanpkw][Stopped/Manual Start]
[nicdrk / nicdrk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\nicdrkl.sys>
[nicsrk / nicsrk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\nicsrkl.sys>
[nidimk / nidimk][Running/Manual Start]
<\??\C:\Windows\system32\drivers\nidimkl.sys>
[nidmxfk / nidmxfk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\nidmxfkl.sys>
[nidsark / nidsark][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\nidsarkl.sys>
[niemrk / niemrk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\niemrkl.sys>
[niesrk / niesrk][Running/Manual Start]
<\??\C:\Windows\system32\drivers\niesrkl.sys>
[nifslk / nifslk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\nifslkl.sys>
[nimdbgk / nimdbgk][Running/Manual Start]
<\??\C:\Windows\system32\drivers\nimdbgkl.sys>
[nimru2k / nimru2k][Running/Manual Start]
<\??\C:\Windows\system32\drivers\nimru2kl.sys>
[nimsdrk / nimsdrk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\nimsdrkl.sys>
[nimslk / nimslk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\nimslk.dll>
[nimsrlk / nimsrlk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\nimsrlk.dll>
[nimstsk / nimstsk][Running/Manual Start]
<\??\C:\Windows\system32\drivers\nimstskl.sys>
[nimxdfk / nimxdfk][Running/Manual Start]
<\??\C:\Windows\system32\drivers\nimxdfkl.sys>
[nimxpk / nimxpk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\nimxpkl.sys>
[ninshsdk / ninshsdk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\ninshsdkl.sys>
[niorbk / niorbk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\niorbkl.sys>
[nipalfwedl / nipalfwedl][Stopped/Manual Start]
[NIPALK / NIPALK][Running/Boot Start]
<\SystemRoot\System32\drivers\nipalk.sys>
[nipalusbedl / nipalusbedl][Stopped/Manual Start]
[National Instruments Class Upper Filter Driver / nipbcfk][Running/Boot Start]
<\SystemRoot\System32\drivers\nipbcfk.sys>
[NI PXI Generic Chassis Pilot / nipxigpk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\nipxigpk.sys>
[nipxirmk / nipxirmk][Running/Auto Start]
<\??\C:\Windows\system32\drivers\nipxirmkl.sys>
[niscdk / niscdk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\niscdkl.sys>
[nisdigk / nisdigk][Running/Manual Start]
<\??\C:\Windows\system32\drivers\nisdigkl.sys>
[nisftk / nisftk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\nisftkl.sys>
[nispdk / nispdk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\nispdkl.sys>
[nissrk / nissrk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\nissrkl.sys>
[nistc2k / nistc2k][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\nistc2kl.sys>
[nistcrk / nistcrk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\nistcrkl.sys>
[niswdk / niswdk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\niswdkl.sys>
[nitiork / nitiork][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\nitiorkl.sys>
[niufurk / niufurk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\niufurkl.sys>
[niufurkw / niufurkw][Stopped/Manual Start]
[NI-VISA FireWire Driver / NiViFWK][Stopped/Manual Start]
[NI-VISA PCI Driver / NiViPciK][Stopped/Manual Start]
[NI-VISA PXI Driver / NiViPxiK][Running/Auto Start]
[niwfrk / niwfrk][Stopped/Manual Start]
<\??\C:\Windows\system32\drivers\niwfrkl.sys>
[nixsrk / nixsrk][Running/Manual Start]
<\??\C:\Windows\system32\drivers\nixsrkl.sys>
[nixsrkw / nixsrkw][Stopped/Manual Start]
[N-trig HID Tablet Driver / ntrigdigi][Stopped/Disabled]
<\SystemRoot\system32\drivers\ntrigdigi.sys>
[NVIDIA nForce RAID Driver / nvraid][Stopped/Disabled]
<\SystemRoot\system32\drivers\nvraid.sys>
[nvstor / nvstor][Stopped/Disabled]
<\SystemRoot\system32\drivers\nvstor.sys>
[IPX Traffic Filter Driver / NwlnkFlt][Stopped/Manual Start]
[IPX Traffic Forwarder Driver / NwlnkFwd][Stopped/Manual Start]
[NWLink IPX/SPX/NetBIOS Compatible Transport Protocol / NwlnkIpx][Stopped/Auto Start]
[Creative Camera OA008 Upper Filter Driver / OA008Ufd][Running/Manual Start]
[Creative Camera OA008 Function Driver / OA008Vid][Running/Manual Start]
[PCAMp50 NDIS Protocol Driver / PCAMp50][Running/Auto Start]
[PCAN-USB Device Driver / Pcan_usb][Stopped/Manual Start]
[PCASp50 NDIS Protocol Driver / PCASp50][Running/Auto Start]
[PCD5SRVC{F6CE0040-33AA1442-05040104} - PCDR Kernel Mode Service Helper Driver / PCD5SRVC{F6CE0040-33AA1442-05040104}][Stopped/Manual Start]
<\??\C:\PROGRA~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms>
[Protector / Protector][Running/System Start]
[ProtectorA / ProtectorA][Running/System Start]
<\??\C:\Windows\system32\drivers\ProtectorA.sys>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys>
[QLogic Fibre Channel Miniport Driver / ql2300][Stopped/Disabled]
<\SystemRoot\system32\drivers\ql2300.sys>
[QLogic iSCSI Miniport Driver / ql40xx][Stopped/Disabled]
<\SystemRoot\system32\drivers\ql40xx.sys>
[Quantum DeepScanner Servers / qutmdserv][Running/System Start]
<\??\C:\Windows\system32\drivers\qutmdrv.sys><360.cn>
[qutmipc / qutmipc][Running/System Start]
<\??\C:\Windows\system32\drivers\qutmipc.sys><360.cn>
[R300 / R300][Stopped/Manual Start]
[rimmptsk / rimmptsk][Running/Auto Start]
[rimsptsk / rimsptsk][Running/Auto Start]
[Ricoh xD-Picture Card Driver / rismxdp][Running/Auto Start]
[Feitian ROCKEY4 Device Service / ROCKEYNT][Running/Manual Start]