|
2#

楼主 |
发表于 2008-10-31 11:57
|
只看该作者
==================================
启动文件夹
N/A
==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:WINDOWSSystem32svchost.exe -k netsvcs-->%SystemRoot%System32hidserv.dll><N/A>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
<C:WINDOWSsystem32nvsvc32.exe><NVIDIA Corporation>
[Remote Access / Remote Access][Stopped/Auto Start]
<C:WINDOWSsystem32mmutilse.exe runsrv /name:"Remote Access" /prinum:"32" /cmdline:"C:WINDOWSsystem32mcvcea.exe"><(File is missing)>
==================================
驱动程序
[AMD Processor Driver / AmdK8][Running/System Start]
<system32DRIVERSAmdK8.sys><Advanced Micro Devices>
[AMD Low Level Device Driver / AmdLLD][Running/Manual Start]
<system32DRIVERSAmdLLD.sys><AMD, Inc.>
[TP-LINK Wireless Network Adapter Service / AR5211][Stopped/Manual Start]
<system32DRIVERSar5211.sys><Atheros Communications, Inc.>
[713x TV Card Capture / Cap7134][Running/Manual Start]
<system32DRIVERSCap7134.sys><Philips Semiconductors>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
<system32DRIVERSfetnd5.sys><VIA Technologies, Inc.>
[nv / nv][Running/Manual Start]
<system32DRIVERSnv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32DRIVERSptilink.sys><Parallel Technologies, Inc.>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32DRIVERSsecdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[SATALink driver accelerator / SiFilter][Running/Boot Start]
<SystemRootsystem32driversSiWinAcc.sys><Silicon Image, Inc.>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
<system32DRIVERStcpip.sys><Microsoft Corporation>
[VIA AGP Filter / viaagp1][Running/Boot Start]
<SystemRootsystem32DRIVERSviaagp1.sys><VIA Technologies, Inc.>
[viamraid / viamraid][Running/Boot Start]
<SystemRootsystem32driversviamraid.sys><VIA Technologies inc,.ltd>
[Vinyl AC'97 Audio Controller (WDM) / VIAudio][Stopped/Manual Start]
<system32driversvinyl97.sys><VIA Technologies, Inc.>
[videX32 / videX32][Running/Boot Start]
<SystemRootsystem32DRIVERSvideX32.sys><VIA Technologies, Inc.>
[NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller / yukonwxp][Running/Manual Start]
<system32DRIVERSyk51x86.sys><Marvell>
[VIMICRO USB PC Camera (ZC030X) / ZSMC303][Running/Manual Start]
<System32DriversusbVM303.sys><VM>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32driversALCXWDM.SYS><Realtek Semiconductor Corp.>
[10Moons TV Master2, WDM TVTuner / PhTVTune][Running/Manual Start]
<system32DRIVERSPhTVTune.sys><Philips Semiconductors>
==================================
浏览器加载项
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:Program FilesMessengermsmsgs.exe, (Signed) Microsoft Corporation>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:Program FilesCommon FilesMicrosoft SharedTrieditdhtmled.ocx, (Signed) Microsoft Corporation>
[XML Document]
{48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:WINDOWSsystem32msxml3.dll, (Signed) Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:WINDOWSsystem32MacromedFlashFlash9f.ocx, (Signed) Adobe Systems, Inc.>
[]
{E2E2DD38-D088-4134-82B7-F2BA38496583} <, >
[]
{FB5F1910-F110-11D2-BB9E-00C04F795683} <, >
==================================
正在运行的进程
[PID: 568 / SYSTEM][SystemRootSystem32smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 624 / SYSTEM][??C:WINDOWSsystem32csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 648 / SYSTEM][??C:WINDOWSsystem32winlogon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:WINDOWSsystem32uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 692 / SYSTEM][C:WINDOWSsystem32services.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:WINDOWSsystem32uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 704 / SYSTEM][C:WINDOWSsystem32lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:WINDOWSsystem32UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 880 / SYSTEM][C:WINDOWSsystem32svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:WINDOWSsystem32UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 952 / NETWORK SERVICE][C:WINDOWSsystem32svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:WINDOWSsystem32UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1048 / SYSTEM][C:WINDOWSSystem32svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:WINDOWSSystem32UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1140 / NETWORK SERVICE][C:WINDOWSsystem32svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:WINDOWSsystem32UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1524 / Administrator][C:WINDOWSExplorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:WINDOWSsystem32UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1668 / Administrator][C:WINDOWSsystem32ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:WINDOWSsystem32UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1720 / SYSTEM][C:WINDOWSsystem32nvsvc32.exe] [NVIDIA Corporation, 6.14.11.6921]
[C:WINDOWSsystem32nvapi.dll] [NVIDIA Corporation, 6.14.11.6921]
[C:WINDOWSsystem32uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1744 / SYSTEM][C:WINDOWSsystem32svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:WINDOWSsystem32UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 328 / LOCAL SERVICE][C:WINDOWSsystem32svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:WINDOWSsystem32UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 464 / LOCAL SERVICE][C:WINDOWSSystem32alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[C:WINDOWSSystem32UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1220 / Administrator][C:WINDOWSsystem32taskmgr.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:WINDOWSsystem32UxTheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 1500 / Administrator][C:Documents and SettingsAdministrator桌面sreng2SREngLdr.EXE] [Smallfrogs Studio, 2.7.0.1210]
[PID: 1212 / Administrator][C:Documents and SettingsAdministrator桌面sreng2SREe74ccbd6.EXE] [Smallfrogs Studio, 2.7.0.1210]
[C:WINDOWSsystem32uxtheme.dll] [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:Documents and SettingsAdministrator桌面sreng2Upload3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%system32NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:WINDOWShh.exe" %1]
.HLP OK. [%SystemRoot%System32winhlp32.exe %1]
.INI OK. [%SystemRoot%System32NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%System32NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%System32WScript.exe "%1" %*]
.JS OK. [%SystemRoot%System32WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1500, C:DOCUMENTS AND SETTINGSADMINISTRATOR桌面SRENG2SRENGLDR.EXE]
==================================
计划任务
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE] |
|