2006-03-14,10:35:38
System Repair Engineer 2.0.12.350 (2.0 RC 1)
Windows 2000 Professional Service Pack 4 - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<run><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<CAP3ON><C:\WINNT\system32\spool\drivers\w32x86\3\CAP3ONN.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"C:\Program Files\rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Synchronization Manager><mobsync.exe /logon>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINNT\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
==================================
启动文件夹
[Adobe Gamma Loader]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>
[Service Manager]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Service Manager.lnk><N>
==================================
服务
[Logical Disk Manager Administrative Service / dmadmin]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Indesing Agent / Indesing PolicyAgent]
<C:\WINNT\wscmtfy.com><N/A>
[RsRavMon Service / RsRavMon]
<"C:\Program Files\rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Network DDE Management / r_server]
<"C:\WINNT\system32\WBEM\services.exe" /service><N/A>
==================================
浏览器加载项
[FlashGet Bar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\PROGRA~1\FlashGet\fgiebar.dll, Amaze Soft>
[@msdxmLC.dll,-1@2052,电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\System32\msdxm.ocx, Microsoft Corporation>
[使用网际快车下载]
<C:\PROGRA~1\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<C:\PROGRA~1\FlashGet\jc_all.htm, N/A>
[导出到 Microsoft Excel(&x)]
<res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 144][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.00.2195.6601>
[PID: 168][\??\C:\WINNT\system32\csrss.exe] <Microsoft Corporation><5.00.2195.6601>
[PID: 188][\??\C:\WINNT\system32\winlogon.exe] <Microsoft Corporation><5.00.2195.6714>
[PID: 220][C:\WINNT\system32\services.exe] <Microsoft Corporation><5.00.2195.6700>
[C:\WINNT\system32\dmserver.dll] <VERITAS Software Corp.><2195.6605.297.3>
[PID: 232][C:\WINNT\system32\lsass.exe] <Microsoft Corporation><5.00.2195.6695>
[PID: 428][C:\WINNT\system32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[PID: 456][C:\WINNT\system32\spoolsv.exe] <Microsoft Corporation><5.00.2195.6659>
[C:\WINNT\system32\spool\DRIVERS\W32X86\3\SDNT5UI.DLL] <Zenographics, Inc.><5.50.1811.0>
[C:\WINNT\system32\spool\DRIVERS\W32X86\3\SDDM32.DLL] <Zenographics, Inc.><5, 52, 1023, 0>
[C:\WINNT\system32\spool\DRIVERS\W32X86\3\ZSPOOL.dll] <Zenographics, Inc.><5, 51, 709, 0>
[C:\WINNT\system32\spool\DRIVERS\W32X86\3\ZGDI32.dll] <Zenographics, Inc.><5, 51, 628, 0>
[C:\WINNT\system32\spool\DRIVERS\W32X86\3\ZTAG32.dll] <Zenographics, Inc.><5, 50, 1725, 0>
[C:\WINNT\system32\spool\DRIVERS\W32X86\3\SDDMUI.DLL] <Zenographics, Inc.><5, 51, 1211, 0>
[C:\WINNT\system32\spool\DRIVERS\W32X86\3\ZLANG.dll] <Zenographics, Inc.><1, 2, 1414, 0>
[C:\WINNT\system32\spool\DRIVERS\W32X86\3\SR32.dll] <Zenographics, Inc.><5, 54, 315, 0>
[C:\WINNT\system32\spool\DRIVERS\W32X86\3\CNMUI6e.DLL] <CANON INC.><1.80.2.50>
[C:\WINNT\system32\icm32.dll] <Microsoft Corporation><5.00>
[PID: 504][C:\WINNT\System32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[PID: 556][C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe] <Microsoft Corporation><7.00.9064.9150>
[PID: 600][d:\PROGRA~1\MICROS~1\MSSQL\binn\sqlservr.exe] <Microsoft Corporation><2000.080.0194.00>
[PID: 728][C:\WINNT\system32\regsvc.exe] <Microsoft Corporation><5.00.2195.6701>
[PID: 744][C:\WINNT\system32\WBEM\services.exe] <N/A><N/A>
[C:\WINNT\system32\WBEM\ADMDLL.dll] <N/A><N/A>
[PID: 756][C:\WINNT\system32\MSTask.exe] <Microsoft Corporation><4.71.2195.6704>
[PID: 796][d:\PROGRA~1\MICROS~1\MSSQL\binn\sqlagent.exe] <Microsoft Corporation><2000.080.0194.00>
[PID: 840][C:\WINNT\System32\WBEM\WinMgmt.exe] <Microsoft Corporation><1.50.1085.0100>
[PID: 852][C:\WINNT\system32\mspmspsv.exe] <Microsoft Corporation><7.01.00.3055>
[PID: 864][C:\WINNT\system32\svchost.exe] <Microsoft Corporation><5.00.2134.1>
[PID: 980][C:\WINNT\System32\dmadmin.exe] <VERITAS Software Corp.><2195.6624.297.3>
[C:\WINNT\System32\dmutil.dll] <VERITAS Software Corp.><2195.6605.297.3>
[C:\WINNT\System32\dmconfig.dll] <VERITAS Software Corp.><2195.6605.297.3>
[PID: 1148][C:\WINNT\Explorer.EXE] <Microsoft Corporation><5.00.3700.6690>
[C:\WINNT\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 2, 8>
[C:\WINNT\downlo~1\CnsHook.dll] <北京三七二一科技有限公司><1, 0, 2, 7>
[C:\WINNT\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[PID: 1544][C:\WINNT\system32\Rundll32.exe] <Microsoft Corporation><5.00.2134.1>
[C:\WINNT\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 2, 8>
[PID: 1652][C:\Program Files\rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\Program Files\rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\WINNT\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 2, 8>
[PID: 492][C:\WINNT\system32\ctfmon.exe] <Microsoft Corporation><1.00.2409.7 built by: Lab06_N>
[C:\WINNT\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 2, 8>
[PID: 1700][C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe] <Microsoft Corporation><2000.080.0194.00>
[C:\WINNT\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 2, 8>
[PID: 1472][E:\yy\System Repair Engineer 2.0.12.350 RC1版\SREng.exe] <Smallfrogs Studio><2.0.12.350>
[C:\WINNT\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 2, 8>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者