引用 | 編輯
傲鷹
2008-01-08 01:25 |
樓主
▼ |
||
x0
班級電腦發生問題,D槽原有的內容全部都看不到了,可是空間卻還是原本那樣,檔案並沒有被刪除, 如果直接在網址列輸入檔名或資料夾都還是可以使用的, 麻煩大大幫忙看一下.. 以下是報表: -------------------------------------- 複製程式 2008-01-07,11:17:58 System Repair Engineer 2.5.16.900 Smallfrogs ([url]http://www.KZTechs.com[/url]) Windows XP Professional Service Pack 2 (Build 2600) - 管理許可權用戶 - 完整功能 以下內容被選中: 所有的啟動項目(包括註冊表、開機檔案夾、服務等) 流覽器載入項 正在運行的進程(包括進程模組資訊) 文件關聯 Winsock 提供者 Autorun.inf HOSTS 文件 進程特權掃描 啟動專案 註冊表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <load><> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher] <PROMon.exe><PROMon.exe> [Intel Corporation] <Smapp><C:\Program Files\Analog Devices\SoundMAX\SMTray.exe> [Analog Devices, Inc.] <IgfxTray><C:\WINDOWS\system32\igfxtray.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher] <HotKeysCmds><C:\WINDOWS\system32\hkcmd.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher] <CJIMETIPSYNC><C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSync> [(Verified)Microsoft Corporation] <PHIMETIPSYNC><C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSync> [(Verified)Microsoft Corporation] <QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.] <WinVNC><"C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper> [UltraVNC] <nod32kui><"C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE> [Eset ] <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.] <CPTWinCtrl><C:\Program files\QBack\WinCtrl.exe> [] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] <shell><Explorer.exe> [(Verified)Microsoft Windows Publisher] <Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <AppInit_DLLs><> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] <UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <Address Book 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A] ================================== 開機檔案夾 [Adobe Reader Speed Launch] <C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\Adobe Reader Speed Launch.lnk --> C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [Adobe Systems Incorporated]><N> [InterVideo WinCinema Manager] <C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\InterVideo WinCinema Manager.lnk --> C:\PROGRA~1\INTERV~1\Common\Bin\WINCIN~1.EXE []><N> [網管中心公告_班級電腦] <C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\網管中心公告_班級電腦.htm --> [N/A]><N> ================================== 服務 [Human Interface Device Access / HidServ][Stopped/Disabled] <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A> [Intel(R) NMS / NMSSvc][Running/Auto Start] <C:\WINDOWS\system32\NMSSvc.exe><Intel Corporation> [NOD32 Kernel Service / NOD32krn][Running/Auto Start] <"C:\Program Files\Eset\nod32krn.exe"><Eset> [SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start] <C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.> [OfficeScanNT Listener / tmlisten][Stopped/Auto Start] <C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe><N/A> [VNC Server / winvnc][Running/Auto Start] <"C:\Program Files\UltraVNC\WinVNC.exe" -service><UltraVNC> ================================== 驅動程式 [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start] <system32\drivers\ac97intc.sys><Intel Corporation> [aeaudio / aeaudio][Stopped/Manual Start] <system32\drivers\aeaudio.sys><Andrea Electronics Corporation> [AMON / AMON][Running/Auto Start] <\SystemRoot\system32\drivers\amon.sys><Eset> [Broadcom 440x 10/100 Integrated Controller XP Driver / bcm4sbxp][Stopped/Manual Start] <system32\DRIVERS\bcm4sbxp.sys><Broadcom Corporation> [Intel(R) PRO Adapter Driver / E100B][Running/Manual Start] <system32\DRIVERS\e100b325.sys><Intel Corporation> [ESS 1969 Audio Driver (WDM) / es1969][Stopped/Manual Start] <system32\drivers\es1969.sys><ESS Technology Inc.> [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start] <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.> [i81x / i81x][Stopped/Manual Start] <system32\DRIVERS\i81xnt5.sys><Intel(R) Corporation> [iAimFP0 / iAimFP0][Stopped/Manual Start] <system32\DRIVERS\wADV01nt.sys><Intel(R) Corporation> [iAimFP1 / iAimFP1][Stopped/Manual Start] <system32\DRIVERS\wADV02NT.sys><Intel(R) Corporation> [iAimFP2 / iAimFP2][Stopped/Manual Start] <system32\DRIVERS\wADV05NT.sys><Intel(R) Corporation> [iAimFP3 / iAimFP3][Stopped/Manual Start] <system32\DRIVERS\wSiINTxx.sys><Intel(R) Corporation> [iAimFP4 / iAimFP4][Stopped/Manual Start] <system32\DRIVERS\wVchNTxx.sys><Intel(R) Corporation> [iAimFP5 / iAimFP5][Stopped/Manual Start] <system32\DRIVERS\wADV07nt.sys><Intel(R) Corporation> [iAimFP6 / iAimFP6][Stopped/Manual Start] <system32\DRIVERS\wADV08nt.sys><Intel(R) Corporation> [iAimFP7 / iAimFP7][Stopped/Manual Start] <system32\DRIVERS\wADV09nt.sys><Intel(R) Corporation> [iAimTV0 / iAimTV0][Stopped/Manual Start] <system32\DRIVERS\wATV01nt.sys><Intel(R) Corporation> [iAimTV1 / iAimTV1][Stopped/Manual Start] <system32\DRIVERS\wATV02NT.sys><Intel(R) Corporation> [iAimTV3 / iAimTV3][Stopped/Manual Start] <system32\DRIVERS\wATV04nt.sys><Intel(R) Corporation> [iAimTV4 / iAimTV4][Stopped/Manual Start] <system32\DRIVERS\wCh7xxNT.sys><Intel(R) Corporation> [iAimTV5 / iAimTV5][Stopped/Manual Start] <system32\DRIVERS\wATV10nt.sys><Intel(R) Corporation> [iAimTV6 / iAimTV6][Stopped/Manual Start] <system32\DRIVERS\wATV06nt.sys><Intel(R) Corporation> [ialm / ialm][Running/Manual Start] <system32\DRIVERS\ialmnt5.sys><Intel Corporation> [nod32drv / nod32drv][Running/System Start] <\SystemRoot\system32\drivers\nod32drv.sys><N/A> [nv / nv][Stopped/Manual Start] <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation> [Padus ASPI Shell / pfc][Running/Manual Start] <system32\drivers\pfc.sys><Padus, Inc.> [直接平行連接埠連結驅動程式 / Ptilink][Running/Manual Start] <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.> [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start] <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation> [s3m / s3m][Stopped/Manual Start] <system32\DRIVERS\s3m.sys><S3 Incorporated> [Secdrv / Secdrv][Stopped/Manual Start] <system32\DRIVERS\secdrv.sys><N/A> [SiS300i / SiS300i][Stopped/Manual Start] <system32\DRIVERS\sis300ip.sys><Silicon Integrated Systems Corporation> [SiSV / SiSV][Stopped/Manual Start] <system32\DRIVERS\SiSV.sys><Silicon Integrated Systems Corporation> [smwdm / smwdm][Stopped/Manual Start] <system32\drivers\smwdm.sys><Analog Devices, Inc.> [Audio Driver (WDM) - SigmaTel CODEC / STAC97][Running/Manual Start] <system32\drivers\STAC97.sys><SigmaTel, Inc.> [ViaIde / ViaIde][Running/Boot Start] <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation> [VIA ACྜྷ Audio Controller (WDM) / VIAudio][Stopped/Manual Start] <system32\drivers\ac97via.sys><VIA Technologies, Inc.> [vnccom / vnccom][Running/Auto Start] <System32\Drivers\vnccom.SYS><RDV Soft> [vncdrv / vncdrv][Running/Manual Start] <system32\DRIVERS\vncdrv.sys><RDV Soft> [Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/Manual Start] <system32\drivers\ialmsbw.sys><Intel Corporation> [Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start] <system32\drivers\ialmkchw.sys><Intel Corporation> [NIC Management Service Configuration Driver / NMSCFG][Running/Manual Start] <\??\C:\WINDOWS\system32\drivers\NMSCFG.SYS><Intel Corporation> ================================== 流覽器載入項 [AcroIEHlprObj Class] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated> [參考資料(&R)] {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation> [Messenger] {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation> [WUWebControl Class] {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation> [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.> [AcroIEHlprObj Class] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated> [Windows Genuine Advantage Validation Tool] {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation> [WUWebControl Class] {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation> [Microsoft Web Browser] {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation> [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.> [匯出至 Microsoft Office Excel(&X)] <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A> ================================== 正在運行的進程 [PID: 568 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 632 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 656 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 700 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 712 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 876 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 924 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 1028 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 1072 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 1124 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 1456 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.1897.0] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.1897.0] [PID: 1780 / SYSTEM][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE] [Microsoft Corporation, 7.00.9466] [C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\1028\mdmui.dll] [Microsoft Corporation, 7.00.9466] [PID: 1824 / SYSTEM][C:\WINDOWS\system32\NMSSvc.exe] [Intel Corporation, 2.2.9.0] [C:\WINDOWS\system32\NMSSvcPS.DLL] [Intel Corporation, 2.2.9.0] [PID: 1920 / ckuser_001][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.0.2004121400] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [PID: 1976 / SYSTEM][C:\Program Files\Eset\nod32krn.exe] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\nod32krr.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\ps_amon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_amon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\ps_dmon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_dmon.dll] [N/A, ] [C:\Program Files\Eset\ps_emon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_emon.dll] [N/A, ] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [C:\Program Files\Eset\ps_nod32.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_nod32.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\ps_upd.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_upd.dll] [N/A, ] [PID: 2044 / SYSTEM][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] [Analog Devices, Inc., 3, 2, 6, 0] [PID: 268 / SYSTEM][C:\Program Files\UltraVNC\WinVNC.exe] [UltraVNC, 1.1.0.2] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 452 / ckuser_001][C:\WINDOWS\system32\PROMon.exe] [Intel Corporation, 5.3.42.0] [C:\WINDOWS\system32\NMSAPI.DLL] [Intel Corporation, 2.2.9.0] [C:\WINDOWS\system32\NMSSvcPS.DLL] [Intel Corporation, 2.2.9.0] [PID: 460 / ckuser_001][C:\Program Files\Analog Devices\SoundMAX\SMTray.exe] [Analog Devices, Inc., 3, 2, 17, 0] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 500 / ckuser_001][C:\Program Files\QuickTime\qttask.exe] [Apple Computer, Inc., 6.3] [C:\WINDOWS\system32\QuickTime.qts] [Apple Computer, Inc., 6.3] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\WINDOWS\system32\QuickTime\QuickTimeAuthoring.qtx] [Apple Computer, Inc., 6.3] [C:\WINDOWS\system32\QuickTime\QuickTimeCapture.qtx] [Apple Computer, Inc., 6.3] [C:\WINDOWS\system32\QuickTime\QuickTimeEffects.qtx] [Apple Computer, Inc., 6.3] [C:\WINDOWS\system32\QuickTime\QuickTimeEssentials.qtx] [Apple Computer, Inc., 6.3] [C:\WINDOWS\system32\QuickTime\QuickTimeImage.qtx] [Apple Computer, Inc., 6.3] [C:\WINDOWS\system32\QuickTime\QuickTimeInternetExtras.qtx] [Apple Computer, Inc., 6.3] [C:\WINDOWS\system32\QuickTime\QuickTimeMPEG.qtx] [Apple Computer, Inc, 6.3] [C:\WINDOWS\system32\QuickTime\QuickTimeMPEG4.qtx] [Apple Computer, Inc., 6.3] [C:\WINDOWS\system32\QuickTime\QuickTimeMPEG4Authoring.qtx] [Apple Computer, Inc., 6.3] [C:\WINDOWS\system32\QuickTime\QuickTimeMusic.qtx] [Apple Computer, Inc., 6.3] [C:\WINDOWS\system32\QuickTime\QuickTimeStreaming.qtx] [Apple Computer, Inc., 6.3] [C:\WINDOWS\system32\QuickTime\QuickTimeStreamingAuthoring.qtx] [Apple Computer, Inc., 6.3] [C:\WINDOWS\system32\QuickTime\QuickTimeStreamingExtras.qtx] [Apple Computer, Inc., 6.3] [PID: 516 / ckuser_001][C:\Program Files\Eset\nod32kui.exe] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\nod32rui.dll] [N/A, ] [C:\Program Files\Eset\pu_amon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_amon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pu_dmon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_dmon.dll] [N/A, ] [C:\Program Files\Eset\pu_emon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_emon.dll] [N/A, ] [C:\Program Files\Eset\pu_imon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [C:\Program Files\Eset\pu_nod32.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_nod32.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pu_upd.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_upd.dll] [N/A, ] [PID: 524 / ckuser_001][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3510] [PID: 536 / ckuser_001][C:\Program files\QBack\WinCtrl.exe] [N/A, ] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 544 / ckuser_001][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 560 / ckuser_001][C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe] [, 1.0] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [PID: 1844 / ckuser_001][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 2220 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [PID: 3984 / ckuser_001][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.0.2004121400] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [C:\Program Files\Common Files\Microsoft Shared\INK\PENCHT.DLL] [Microsoft Corporation, 1.0.1038.0] [C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx] [Adobe Systems, Inc., 9,0,47,0] [PID: 2428 / ckuser_001][D:\MyDocuments\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900] [C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3] [D:\MyDocuments\sreng2\Lang\1028.DLL] [System Repair Engineer, 2.5.16.900] [D:\MyDocuments\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [C:\WINDOWS\system32\imon.dll] [Eset , 2, 70, 39 ] [C:\Program Files\Eset\pr_imon.dll] [N/A, ] [D:\MyDocuments\sreng2\Plugins\NTFSTREAM.SRE] [Smallfrogs Studio, 1, 0, 0, 5] ================================== 文件關聯 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\system32\winhlp32.exe %1] .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 NOD32 protected [MSAFD Tcpip [TCP/IP]] C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) NOD32 protected [MSAFD Tcpip [UDP/IP]] C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) NOD32 protected [MSAFD Tcpip [RAW/IP]] C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) NOD32 protected [RSVP UDP Service Provider] C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) NOD32 protected [RSVP TCP Service Provider] C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) NOD32 C:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support) ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost ================================== 進程特權掃描 特殊特權被允許: SeLoadDriverPrivilege [PID = 1824, C:\WINDOWS\SYSTEM32\NMSSVC.EXE] 特殊特權被允許: SeLoadDriverPrivilege [PID = 452, C:\WINDOWS\SYSTEM32\PROMON.EXE] 特殊特權被允許: SeLoadDriverPrivilege [PID = 460, C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMTRAY.EXE] 特殊特權被允許: SeLoadDriverPrivilege [PID = 500, C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE] 特殊特權被允許: SeLoadDriverPrivilege [PID = 516, C:\PROGRAM FILES\ESET\NOD32KUI.EXE] 特殊特權被允許: SeLoadDriverPrivilege [PID = 524, C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE] 特殊特權被允許: SeLoadDriverPrivilege [PID = 536, C:\PROGRAM FILES\QBACK\WINCTRL.EXE] 特殊特權被允許: SeLoadDriverPrivilege [PID = 560, C:\PROGRAM FILES\INTERVIDEO\COMMON\BIN\WINCINEMAMGR.EXE] ================================== API HOOK N/A ================================== 隱藏進程 N/A ================================== x0
|