瑞星卡卡安全论坛
990410xl - 2006-5-21 15:28:00
我已经解决了!谢谢大家~~~非常感谢
我无邪 - 2006-5-21 15:32:00
呵呵,真有趣
请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,不要修改
990410xl - 2006-5-21 15:32:00
还有哦!过一会还会出现“起驾回宫”我都快疯了~
2120058 - 2006-5-21 15:35:00
重装不行,重新作WINDOSW目录文件
或者劝你把C盘格式化,在作还原
990410xl - 2006-5-21 15:39:00
2006-05-21,15:37:36
System Repair Engineer 2.0.12.350 (2.0 RC 1)
Windows XP Professional Service Pack 1 - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><APIHookDll.dll>
==================================
启动文件夹
服务
[InstallDriver Table Manager / IDriverT]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[NVIDIA Display Driver Service / NVSvc]
<C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[Rising Personal Firewall Service / RfwService]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
==================================
浏览器加载项
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, N/A>
[IeCatch2 Class]
{A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~1\FLASHGET\jccatch.dll, Amaze Soft>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[FlashGet]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, N/A>
[FlashGet Bar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\fgiebar.dll, Amaze Soft>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[Qzone Media Tools]
{A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} <C:\PROGRA~1\Tencent\QQ\QZone\QZONEM~1.OCX, Tencent Technology (Shenzhen) Company Limited>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[Download Using &BitSpirit]
<, N/A>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用网际快车下载]
<C:\PROGRA~1\FLASHGET\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<C:\PROGRA~1\FLASHGET\jc_all.htm, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
[用比特精灵下载(&B)]
<, N/A>
==================================
正在运行的进程
[PID: 372][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 524][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 548][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 592][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 604][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 768][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 820][C:\Program Files\Rising\Rav\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 836][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 948][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1020][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1036][C:\Program Files\Rising\Rav\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 19>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[C:\Program Files\Rising\Rav\HOOKSYS.dll] <Rising><18, 1, 0, 9>
[C:\Program Files\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
[C:\Program Files\Rising\Rav\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\regmon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\HookWeb.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\MemMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
[C:\Program Files\Rising\Rav\expscan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[C:\Program Files\Rising\Rav\MailMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Rising\Rav\SpamEng.dll] <N/A><18, 0, 0, 6>
[C:\Program Files\Rising\Rav\engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
[C:\Program Files\Rising\Rav\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[C:\Program Files\Rising\Rav\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\Program Files\Rising\Rav\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\Program Files\Rising\Rav\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[C:\Program Files\Rising\Rav\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\Program Files\Rising\Rav\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\Program Files\Rising\Rav\ExtOLE.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\Program Files\Rising\Rav\RsStore.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\ScanNet.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1068][c:\program files\rising\rfw\rfwsrv.exe] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 32>
[c:\program files\rising\rfw\RfwRule.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 12>
[c:\program files\rising\rfw\rfwlog.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
[c:\program files\rising\rfw\Rfwdrv.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
990410xl - 2006-5-21 15:41:00
[c:\program files\rising\rfw\MonDrv.dll] <rs><1, 0, 0, 4>
[c:\program files\rising\rfw\ProcLib.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[c:\program files\rising\rfw\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[PID: 1328][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.0 (XPClient.010817-1148)>
[PID: 1420][C:\Program Files\Rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1624][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\WINDOWS\System32\nvcpl.dll] <NVIDIA Corporation><6.14.10.8198>
[C:\WINDOWS\System32\NVRSZHC.DLL] <NVIDIA Corporation><6.14.10.8198>
[C:\WINDOWS\System32\nvshell.dll] <N/A><N/A>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[C:\PROGRA~1\FLASHGET\jccatch.dll] <Amaze Soft><1, 1, 4, 0>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1704][c:\program files\rising\rfw\RfwMain.exe] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 48>
[c:\program files\rising\rfw\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
[c:\program files\rising\rfw\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[c:\program files\rising\rfw\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1824][C:\WINDOWS\System32\nvsvc32.exe] <NVIDIA Corporation><6.14.10.8198>
[PID: 192][C:\Program Files\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[PID: 232][C:\Program Files\Rising\Rav\Ravmon.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 17>
[C:\Program Files\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 260][C:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1764][C:\Program Files\Tencent\QQ\QQ.exe] <TENCENT><0, 0, 0, 0>
[C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQHelperDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\BasicCtrlDll.dll] <Tencent><5, 0, 200, 160>
[C:\Program Files\Tencent\QQ\QQAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\TIMProxy.dll] <tencent><0, 3, 2, 4>
[C:\Program Files\Tencent\QQ\LoginCtrl.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\npkcntc.dll] <INCA Internet Co., Ltd.><2006, 3, 2, 1>
[C:\Program Files\Tencent\QQ\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[C:\Program Files\Tencent\QQ\QQRes.dll] <tencent><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQMainFrame.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\CQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\NewSkin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\HostingMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\CameraDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\MailSummary.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQSpace.dll] <><1, 0, 0, 1>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQGroupMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\GroupLive.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\UserDefinedHead.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQPlugin.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQConfigPlugin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQSysMsgMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QRingMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\PhoneAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\DialerAllinOne.dll] <tencent><1, 4, 0, 0>
[C:\Program Files\Tencent\QQ\QQAvatar.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\FlashAvatarDll.dll] <><1, 4, 0, 1>
[C:\Program Files\Tencent\QQ\LongConnection.dll] <tencent><5, 0, 200, 160>
[C:\Program Files\Tencent\QQ\QQPet.dll] <><1, 0, 0, 1>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\Program Files\Tencent\QQ\QQSettingCtrl.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\BQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQAllInOne.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\SCCore.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\CommercesMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
990410xl - 2006-5-21 15:43:00
[C:\Program Files\Tencent\QQ\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 200>
[C:\Program Files\Tencent\QQ\QQSceneMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQPhoneHelper.dll] <腾讯科技(深圳)有限公司><2, 0, 3, 30>
[PID: 1864][C:\Program Files\Tencent\QQ\QQ.exe] <TENCENT><0, 0, 0, 0>
[C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQHelperDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\BasicCtrlDll.dll] <Tencent><5, 0, 200, 160>
[C:\Program Files\Tencent\QQ\QQAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\TIMProxy.dll] <tencent><0, 3, 2, 4>
[C:\Program Files\Tencent\QQ\LoginCtrl.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\npkcntc.dll] <INCA Internet Co., Ltd.><2006, 3, 2, 1>
[C:\Program Files\Tencent\QQ\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[C:\Program Files\Tencent\QQ\QQRes.dll] <tencent><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQMainFrame.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\CQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\NewSkin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\HostingMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\CameraDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\MailSummary.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQSpace.dll] <><1, 0, 0, 1>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQGroupMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\GroupLive.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\UserDefinedHead.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQPlugin.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQConfigPlugin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQSysMsgMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QRingMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\PhoneAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\DialerAllinOne.dll] <tencent><1, 4, 0, 0>
[C:\Program Files\Tencent\QQ\QQAvatar.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\FlashAvatarDll.dll] <><1, 4, 0, 1>
[C:\Program Files\Tencent\QQ\LongConnection.dll] <tencent><5, 0, 200, 160>
[C:\Program Files\Tencent\QQ\QQPet.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\BQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQAllInOne.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\SCCore.dll] <N/A><N/A>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\Program Files\Tencent\QQ\CommercesMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[C:\Program Files\Tencent\QQ\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 200>
[C:\Program Files\Tencent\QQ\QQSceneMng.dll] <N/A><N/A>
[PID: 1952][C:\Program Files\Tencent\QQ\QQ.exe] <TENCENT><0, 0, 0, 0>
[C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQHelperDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\BasicCtrlDll.dll] <Tencent><5, 0, 200, 160>
[C:\Program Files\Tencent\QQ\QQAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\TIMProxy.dll] <tencent><0, 3, 2, 4>
[C:\Program Files\Tencent\QQ\LoginCtrl.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\npkcntc.dll] <INCA Internet Co., Ltd.><2006, 3, 2, 1>
[C:\Program Files\Tencent\QQ\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[C:\Program Files\Tencent\QQ\QQRes.dll] <tencent><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQMainFrame.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\CQQApplication.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\NewSkin.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\HostingMgr.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\CameraDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\MailSummary.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQSpace.dll] <><1, 0, 0, 1>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQGroupMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\GroupLive.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQSysMsgMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\UserDefinedHead.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQPlugin.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQAllInOne.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\SCCore.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQCustomFace.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\QQPet.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQConfigPlugin.dll] <><1, 0, 0, 1>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\Program Files\Tencent\QQ\QRingMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\PhoneAPI.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\DialerAllinOne.dll] <tencent><1, 4, 0, 0>
[C:\Program Files\Tencent\QQ\QQAvatar.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\FlashAvatarDll.dll] <><1, 4, 0, 1>
[C:\Program Files\Tencent\QQ\LongConnection.dll] <tencent><5, 0, 200, 160>
[C:\Program Files\Tencent\QQ\BQQApplication.dll] <N/A><N/A>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\Program Files\Tencent\QQ\QQMagicFace.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQSceneMng.dll] <N/A><N/A>
[C:\Program Files\Tencent\QQ\GroupConnection.dll] <Tencent><0, 3, 3, 5>
[C:\Program Files\Tencent\QQ\CommercesMng.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[C:\Program Files\Tencent\QQ\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 200>
[C:\Program Files\Tencent\QQ\videodevice.dll] <Tencent><1.5.0.0>
[C:\Program Files\Tencent\QQ\inplus.dll] <Tencent><1.5.0.0>
[C:\WINDOWS\System32\l3codeca.acm] <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
[C:\Program Files\Tencent\QQ\ImageOle.dll] <TODO: <Company name>><1.0.0.1>
[PID: 2276][C:\Program Files\Tencent\QQ\qqpet\qqpet.exe] <腾讯公司><2, 38, 101, 55>
[C:\Program Files\Tencent\QQ\qqpet\QQPetResDownload.dll] <><6, 1, 101, 55>
[C:\Program Files\Tencent\QQ\qqpet\QQPetCommunity.dll] <><6, 1, 101, 55>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 2352][C:\Program Files\Tencent\QQ\qqpet\qqpet.exe] <腾讯公司><2, 38, 101, 55>
[C:\Program Files\Tencent\QQ\qqpet\QQPetResDownload.dll] <><6, 1, 101, 55>
[C:\Program Files\Tencent\QQ\qqpet\QQPetCommunity.dll] <><6, 1, 101, 55>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 3660][C:\Program Files\Tencent\QQ\qqpet\qqpet.exe] <腾讯公司><2, 38, 101, 55>
[C:\Program Files\Tencent\QQ\qqpet\QQPetResDownload.dll] <><6, 1, 101, 55>
[C:\Program Files\Tencent\QQ\qqpet\QQPetCommunity.dll] <><6, 1, 101, 55>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 3892][D:\经典工具\QQ保姆\QQPetNurse0511(2.11SP1)[2006]\QQPetNurse.exe] <永恒E网><2.1.1.1>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[PID: 3108][C:\Program Files\Tencent\QQ\QQexternal.exe] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\BasicCtrlDll.dll] <Tencent><5, 0, 200, 160>
[C:\Program Files\Tencent\QQ\QQHelperDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[C:\Program Files\Tencent\QQ\QQRes.dll] <tencent><1, 0, 0, 1>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[PID: 3908][C:\Program Files\Tencent\TT\TTraveler.exe] <腾讯公司><3.0.0.250>
[C:\Program Files\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll] <腾讯公司><1, 1, 0, 5>
990410xl - 2006-5-21 15:44:00
[C:\Program Files\Tencent\TT\Plugins\TWeather\TWeather.dll] <><1, 0, 0, 3>
[C:\Program Files\Tencent\TT\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[PID: 3208][C:\PROGRA~1\FLASHGET\flashget.exe] <Amaze Soft><1, 7, 1, 0>
[PID: 3944][C:\Program Files\Iparmor\Iparmor.exe] <luosoft.com><5.5.0.0>
[C:\Program Files\Iparmor\getportlistxp.dll] <><1, 0, 0, 1>
[C:\Program Files\Iparmor\hookhookdll.dll] <N/A><N/A>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1612][C:\Downloads\sreng2\SREng.exe] <Smallfrogs Studio><2.0.12.350>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
990410xl - 2006-5-21 15:49:00
我已经把C盘格式2次了~~~
我无邪 - 2006-5-21 15:51:00
很无奈看不出问题来
你能在你系统中找到可疑的文件吗?
另外,建议下载autoruns.exe,扫个报告粘上来。
下载地址不知,可以百度一下。
我无邪 - 2006-5-21 15:52:00
你把C盘格式两次还有这种声音??
请问你确定是格式化或不是覆盖安装吗?
查看一下,除C盘外,其它盘中可以可疑的文件
双击我的电脑--工具---文件夹选项--查看--单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示您确定更改时,单击“是”
990410xl - 2006-5-21 15:59:00
我是格式化2次了!
会不会被人远程监控了?还有怎么知道自己电脑被人监控了?
990410xl - 2006-5-21 16:01:00
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
+ C:\WINDOWS\system32\userinit.exeUserinit Logon ApplicationMicrosoft Corporationc:\windows\system32\userinit.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
+ Explorer.exeWindows ExplorerMicrosoft Corporationc:\windows\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ PHIME2002A微軟新注音輸入法 2002aMicrosoft Corporationc:\windows\system32\ime\tintlgnt\tintsetp.exe
+ PHIME2002ASync微軟新注音輸入法 2002aMicrosoft Corporationc:\windows\system32\ime\tintlgnt\tintsetp.exe
+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe
+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwmain.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
+ ctfmon.exeCTF LoaderMicrosoft Corporationc:\windows\system32\ctfmon.exe
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
+ Internet ExplorerWindows NT User Data Migration ToolMicrosoft Corporationc:\windows\system32\shmgrate.exe
+ Internet Explorer 6IE 5.0 Per-User Install UtilityMicrosoft Corporationc:\windows\system32\ie4uinit.exe
+ Microsoft Outlook Express 6Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe
+ Microsoft Windows Media PlayerMicrosoft Windows Media Player 安装实用程序Microsoft Corporationc:\windows\inf\unregmp2.exe
+ Microsoft Windows Media PlayerADVPACKMicrosoft Corporationc:\windows\system32\advpack.dll
+ NetMeeting 3.01ADVPACKMicrosoft Corporationc:\windows\system32\advpack.dll
+ Outlook ExpressWindows NT User Data Migration ToolMicrosoft Corporationc:\windows\system32\shmgrate.exe
+ Themes SetupMicrosoft(C) Register ServerMicrosoft Corporationc:\windows\system32\regsvr32.exe
+ Windows Messenger 4.7ADVPACKMicrosoft Corporationc:\windows\system32\advpack.dll
+ Windows 桌面更新Microsoft(C) Register ServerMicrosoft Corporationc:\windows\system32\regsvr32.exe
+ 通讯簿 6Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe
+ 浏览器自定义组件Microsoft Internet Explorer Customization DLLMicrosoft Corporationc:\windows\system32\iedkcs32.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
+ Browseui 预加载程序Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 组件类别缓存程序Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ CDBurnWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ PostBootReminderWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ SysTraySystray shell service objectMicrosoft Corporationc:\windows\system32\stobject.dll
+ WebCheckWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
+ Rising Execute File Exts hookRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
+ shell32.dllWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ %DESC_PublishDropTarget%Photo Printing WizardMicrosoft Corporationc:\windows\system32\photowiz.dll
+ .CAB file viewerCabinet File Viewer Shell ExtensionMicrosoft Corporationc:\windows\system32\cabview.dll
+ ActiveX 高速缓存文件夹Object Control ViewerMicrosoft Corporationc:\windows\system32\occache.dll
+ Audio Media Properties HandlerMedia File Property Extractor Shell ExtensionMicrosoft Corporationc:\windows\system32\shmedia.dll
+ Auto Update Property Sheet ExtensionWindows Update AutoUpdate EngineMicrosoft Corporationc:\windows\system32\wuaueng.dll
+ Avi Properties HandlerMedia File Property Extractor Shell ExtensionMicrosoft Corporationc:\windows\system32\shmedia.dll
+ BandProxyShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ CDF Extension Copy HookShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Channel MenuChannel Definition File ViewerMicrosoft Corporationc:\windows\system32\cdfview.dll
+ Channel PropertiesChannel Definition File ViewerMicrosoft Corporationc:\windows\system32\cdfview.dll
+ Code Download AgentWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ Compatibility PageCompatibility Tab Shell Extension DLLMicrosoft Corporationc:\windows\system32\slayerxp.dll
+ Compressed (zipped) Folder Right Drag HandlerCompressed (zipped) FoldersMicrosoft Corporationc:\windows\system32\zipfldr.dll
+ Compressed (zipped) Folder SendTo TargetCompressed (zipped) FoldersMicrosoft Corporationc:\windows\system32\zipfldr.dll
+ ConnectionAgentWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ Crypto PKO ExtensionCrypto Shell ExtensionsMicrosoft Corporationc:\windows\system32\cryptext.dll
+ Crypto Sign ExtensionCrypto Shell ExtensionsMicrosoft Corporationc:\windows\system32\cryptext.dll
+ Darwin App PublisherShell Application ManagerMicrosoft Corporationc:\windows\system32\appwiz.cpl
+ Desktop ExplorerNVIDIA Desktop Explorer, Version 110.14 NVIDIA Corporationc:\windows\system32\nvshell.dll
+ Desktop Explorer MenuNVIDIA Desktop Explorer, Version 110.14 NVIDIA Corporationc:\windows\system32\nvshell.dll
+ DfsShellDistributed File System shell extensionMicrosoft Corporationc:\windows\system32\dfsshlex.dll
+ Directory Context Menu VerbsDirectory Service Common UIMicrosoft Corporationc:\windows\system32\dsuiext.dll
+ Directory Object FindDirectory Service FindMicrosoft Corporationc:\windows\system32\dsquery.dll
+ Directory Property UIDirectory Service Common UIMicrosoft Corporationc:\windows\system32\dsuiext.dll
+ Directory Query UIDirectory Service FindMicrosoft Corporationc:\windows\system32\dsquery.dll
+ Directory Start/Search FindDirectory Service FindMicrosoft Corporationc:\windows\system32\dsquery.dll
+ Disk Copy ExtensionWindows DiskCopyMicrosoft Corporationc:\windows\system32\diskcopy.dll
+ Disk Quota UIWindows Shell Disk Quota UI DLLMicrosoft Corporationc:\windows\system32\dskquoui.dll
+ Display Adapter CPL ExtensionAdvanced display adapter propertiesMicrosoft Corporationc:\windows\system32\deskadp.dll
+ Display Monitor CPL ExtensionAdvanced display monitor propertiesMicrosoft Corporationc:\windows\system32\deskmon.dll
+ Display Panning CPL ExtensionFile not found: deskpan.dll
+ Display TroubleShoot CPL ExtensionAdvanced display performance propertiesMicrosoft Corporationc:\windows\system32\deskperf.dll
+ DS Security PageDirectory Service Security UIMicrosoft Corporationc:\windows\system32\dssec.dll
+ Favorites BandShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ FTP Folders WebviewMicrosoft Internet Explorer FTP Folder Shell ExtensionMicrosoft Corporationc:\windows\system32\msieftp.dll
+ GDI+ 文件缩略图解压缩程序Windows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll
+ HTML 缩略图的解压缩程序Windows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll
+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\windows\system32\hticons.dll
+ ICC 配置文件Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\windows\system32\icmui.dll
+ ICM 打印机管理Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\windows\system32\icmui.dll
+ ICM 监视器管理Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\windows\system32\icmui.dll
+ ICM 扫描仪管理Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\windows\system32\icmui.dll
+ IE4 套件初始屏幕Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Installed Apps EnumeratorShell Application ManagerMicrosoft Corporationc:\windows\system32\appwiz.cpl
+ InternetShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ InternetShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Internet Name SpaceShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Internet 临时文件Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Internet 临时文件Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ InternetShortcutShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ ISFBand OCShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Microsoft Agent Character Property Sheet HandlerMicrosoft Agent Property Sheet HandlerMicrosoft Corporationc:\windows\msagent\agentpsh.dll
+ Microsoft AutoCompleteShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Microsoft Browser ArchitectureShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Microsoft BrowserBandShell Browser UI LibraryMicrosoft Corporation
990410xl - 2006-5-21 16:03:00
c:\windows\system32\browseui.dll
+ Microsoft DocProp Inplace Calendar ControlMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll
+ Microsoft DocProp Inplace Droplist Combo ControlMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll
+ Microsoft DocProp Inplace Edit Box ControlMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll
+ Microsoft DocProp Inplace ML Edit Box ControlMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll
+ Microsoft DocProp Inplace Time ControlMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll
+ Microsoft DocProp Shell ExtMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll
+ Microsoft Internet 工具栏Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Microsoft Url History 服务Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Microsoft Url 搜索挂接Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Microsoft 多个自动完成列表容器Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Microsoft 历史自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Microsoft 数据链接Microsoft Data Access - OLE DB Core ServicesMicrosoft Corporationc:\program files\common files\system\ole db\oledb32.dll
+ Microsoft 外壳文件夹自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Midi Properties HandlerMedia File Property Extractor Shell ExtensionMicrosoft Corporationc:\windows\system32\shmedia.dll
+ MMC Icon HandlerMMC Shell Extension DLLMicrosoft Corporationc:\windows\system32\mmcshext.dll
+ MRU 自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Multimedia File Property SheetControl Panel Drivers AppletMicrosoft Corporationc:\windows\system32\mmsys.cpl
+ MyDocs Copy HookMy Documents Folder UIMicrosoft Corporationc:\windows\system32\mydocs.dll
+ MyDocs Drop TargetMy Documents Folder UIMicrosoft Corporationc:\windows\system32\mydocs.dll
+ MyDocs PropertiesMy Documents Folder UIMicrosoft Corporationc:\windows\system32\mydocs.dll
+ NTFS Security PageSecurity Shell ExtensionMicrosoft Corporationc:\windows\system32\rshx32.dll
+ NvCpl DesktopContext ClassNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll
+ nView Desktop Context MenuNVIDIA Desktop Explorer, Version 110.14 NVIDIA Corporationc:\windows\system32\nvshell.dll
+ Offline Files Folder OptionsClient Side Caching UIMicrosoft Corporationc:\windows\system32\cscui.dll
+ Offline Files MenuClient Side Caching UIMicrosoft Corporationc:\windows\system32\cscui.dll
+ OLE Docfile Property PageOLE DocFile Property PageMicrosoft Corporationc:\windows\system32\docprop.dll
+ Play on my TV helperNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll
+ PlayerShlExctmenu Modulec:\program files\bofulnetworks\tmplayer\ctmenu.dll
+ PlusPack CPL ExtensionWindows Theme APIMicrosoft Corporationc:\windows\system32\themeui.dll
+ Portable Media Devices便携媒体设备命令行解释器扩展Microsoft Corporationc:\windows\system32\audiodev.dll
+ Portable Media Devices Menu便携媒体设备命令行解释器扩展Microsoft Corporationc:\windows\system32\audiodev.dll
+ PostAgentWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ Printers Security PageSecurity Shell ExtensionMicrosoft Corporationc:\windows\system32\rshx32.dll
+ Remote Sessions CPL ExtensionRemote Sessions CPL ExtensionMicrosoft Corporationc:\windows\system32\remotepg.dll
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
+ Search Assistant OCShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Sendmail serviceSend MailMicrosoft Corporationc:\windows\system32\sendmail.dll
+ Sendmail serviceSend MailMicrosoft Corporationc:\windows\system32\sendmail.dll
+ Shell Application ManagerShell Application ManagerMicrosoft Corporationc:\windows\system32\appwiz.cpl
+ Shell Automation Inproc ServiceShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Shell Band Site MenuShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Shell DocObject ViewerShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Shell extensions for Microsoft Windows Network objectsNetwork object shell UIMicrosoft Corporationc:\windows\system32\ntlanui2.dll
+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realplayer\rpshell.dll
+ Shell extensions for sharingShell extensions for sharingMicrosoft Corporationc:\windows\system32\ntshrui.dll
+ Shell extensions for sharingShell extensions for sharingMicrosoft Corporationc:\windows\system32\ntshrui.dll
+ Shell Image Data FactoryWindows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll
+ Shell Image Property HandlerWindows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll
+ Shell Image VerbsWindows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll
+ Shell properties for a DS objectDirectory Service FindMicrosoft Corporationc:\windows\system32\dsquery.dll
+ Shell Scrap DataHandlerShell scrap object handlerMicrosoft Corporationc:\windows\system32\shscrap.dll
+ Subscription MgrWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ Tasks Folder Icon HandlerTask Scheduler interface DLLMicrosoft Corporationc:\windows\system32\mstask.dll
+ Tasks Folder Shell ExtensionTask Scheduler interface DLLMicrosoft Corporationc:\windows\system32\mstask.dll
+ TrayAgentWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ TridentImageExtractorShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Video Media Properties HandlerMedia File Property Extractor Shell ExtensionMicrosoft Corporationc:\windows\system32\shmedia.dll
+ Video Thumbnail ExtractorMedia File Property Extractor Shell ExtensionMicrosoft Corporationc:\windows\system32\shmedia.dll
+ Wav Properties HandlerMedia File Property Extractor Shell ExtensionMicrosoft Corporationc:\windows\system32\shmedia.dll
+ Web Printer Shell ExtensionPrint UI DLLMicrosoft Corporationc:\windows\system32\printui.dll
+ Web 搜索Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ WebCheckWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ WebCheck SyncMgr HandlerWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ WebCheckChannelAgentWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ WebCheckWebCrawlerWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ Windows Media Player Add to Playlist Context Menu HandlerWindows Media Player LauncherMicrosoft Corporationc:\windows\system32\wmpshell.dll
+ Windows Media Player Burn Audio CD Context Menu HandlerWindows Media Player LauncherMicrosoft Corporationc:\windows\system32\wmpshell.dll
+ Windows Media Player Play as Playlist Context Menu HandlerWindows Media Player LauncherMicrosoft Corporationc:\windows\system32\wmpshell.dll
+ Windows Script Host 的 Shell extensionsMicrosoft (r) Shell Extension for Windows Script HostMicrosoft Corporationc:\windows\system32\wshext.dll
+ WinRAR shell extensionc:\program files\winrar\rarext.dll
+ 帮助和支持Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ 帮助和支持Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ 补充的外壳文件夹Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 补充的外壳文件夹 2Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 窗格中的搜索Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 地址 EditBoxShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 地址(&A)Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 地址条解析程序Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 电子邮件Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ 跟踪弹出栏Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 公文包Windows BriefcaseMicrosoft Corporationc:\windows\system32\syncui.dll
+ 管理工具Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ 获取 Passport 向导Map Network Drives/Network Places WizardMicrosoft Corporationc:\windows\system32\netplwiz.dll
+ 可访问的Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 历史记录Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ 媒体区Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 频道句柄对象Channel Definition File ViewerMicrosoft Corporationc:\windows\system32\cdfview.dll
+ 频道快捷方式Channel Definition File ViewerMicrosoft Corporationc:\windows\system32\cdfview.dll
+ 频道文件Channel Definition File ViewerMicrosoft Corporationc:\windows\system32\cdfview.dll
+ 全局文件夹设置Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 任务计划Task Scheduler interface DLLMicrosoft Corporationc:\windows\system32\mstask.dll
+ 任务栏和「开始」菜单Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ 扫描仪和照相机Imaging Devices Shell Folder UIMicrosoft Corporationc:\windows\system32\wiashext.dll
+ 扫描仪和照相机Imaging Devices Shell Folder UIMicrosoft Corporationc:\windows\system32\wiashext.dll
+ 扫描仪和照相机Imaging Devices Shell Folder UIMicrosoft Corporationc:\windows\system32\wiashext.dll
+ 扫描仪和照相机Imaging Devices Shell Folder UIMicrosoft Corporationc:\windows\system32\wiashext.dll
+ 扫描仪和照相机Imaging Devices Shell Folder UIMicrosoft Corporationc:\windows\system32\wiashext.dll
+ 搜索Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
990410xl - 2006-5-21 16:05:00
+ 搜索区Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 通过 Web 订购照片Map Network Drives/Network Places WizardMicrosoft Corporationc:\windows\system32\netplwiz.dll
+ 脱机文件夹Client Side Caching UIMicrosoft Corporationc:\windows\system32\cscui.dll
+ 外壳 DeskBarShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 外壳 DeskBarAppShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 外壳 Rebar BandSiteShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 外壳出版向导对象Map Network Drives/Network Places WizardMicrosoft Corporationc:\windows\system32\netplwiz.dll
+ 网络出版向导Map Network Drives/Network Places WizardMicrosoft Corporationc:\windows\system32\netplwiz.dll
+ 网络连接Network Connections ShellMicrosoft Corporationc:\windows\system32\netshell.dll
+ 网络连接Network Connections ShellMicrosoft Corporationc:\windows\system32\netshell.dll
+ 下载状态Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 压缩(zipped)文件夹Compressed (zipped) FoldersMicrosoft Corporationc:\windows\system32\zipfldr.dll
+ 用户(&P)...Find PeopleMicrosoft Corporationc:\program files\outlook express\wabfind.dll
+ 用户帮助Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 用户帐户Map Network Drives/Network Places WizardMicrosoft Corporationc:\windows\system32\netplwiz.dll
+ 预订文件夹Web Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ 运行...Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ 摘要信息缩略图处理程序(DOCFILES)Windows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll
+ 注册数目路选项实用程序Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 自定义 MRU 自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 字体Windows Font FolderMicrosoft Corporationc:\windows\system32\fontext.dll
+ 字体Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ 浏览器栏Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
HKLM\Software\Classes\Folder\Shellex\ColumnHandlers
+ {0D2E74C4-3C34-11d2-A27E-00C04FC30871}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ {24F14F01-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ {24F14F02-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ {66742402-F9B9-11D1-A202-0000F81FEDEE}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ IeCatch2 Classjccatch ModuleAmaze Softc:\program files\flashget\jccatch.dll
+ QQBrowserHelperObject ClassFile not found: C:\Program Files\Tencent\QQ\QQIEHelper.dll
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
+ shdocvw.dllShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ FlashGet BarFlashGet IE BarAmaze Softc:\program files\flashget\fgiebar.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ FlashGetFlashGetAmaze Softc:\program files\flashget\flashget.exe
+ QQQQTENCENTc:\program files\tencent\qq\qq.exe
HKLM\System\CurrentControlSet\Services
+ AudioSrv管理基于 Windows 的程序的音频设备。如果此服务被终止,音频设备及其音效将不能正常工作。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ Browser维护网络上计算机的更新列表,并将列表提供给计算机指定浏览。如果服务停止,列表不会被更新或维护。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ CryptSvc提供三种管理服务: 编录数据库服务,它确定 Windows 文件的签字; 受保护的根服务,它从此计算机添加和删除受信根证书机构的证书;和密钥(Key)服务,它帮助注册此计算机获取证书。如果此服务被终止,这些管理服务将无法正常运行。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ Dhcp通过注册和更改 IP 地址以及 DNS 名称来管理网络配置。Microsoft Corporationc:\windows\system32\svchost.exe
+ dmserver监测和监视新硬盘驱动器并向逻辑磁盘管理器管理服务发送卷的信息以便配置。如果此服务被终止,动态磁盘状态和配置信息会过时。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ Dnscache为此计算机解析和缓冲域名系统 (DNS) 名称。如果此服务被停止,计算机将不能解析 DNS 名称并定位 Active Directory 域控制器。如果此服务被禁用,任何明确依赖它的服务将不能启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ Eventlog启用在事件查看器查看基于 Windows 的程序和组件颁发的事件日志消息。无法终止此服务。Microsoft Corporationc:\windows\system32\services.exe
+ helpsvc启用在此计算机上运行帮助和支持中心。如果停止服务,帮助和支持中心将不可用。如果禁用服务,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ lanmanserver支持此计算机通过网络的文件、打印、和命名管道共享。如果服务停止,这些功能不可用。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ lanmanworkstation创建和维护到远程服务的客户端网络连接。如果服务停止,这些连接将不可用。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ LmHosts允许对“TCP/IP 上 NetBIOS (NetBT)”服务以及 NetBIOS 名称解析的支持。Microsoft Corporationc:\windows\system32\svchost.exe
+ NVSvcProvides system and desktop level support to the NVIDIA display driverNVIDIA Corporationc:\windows\system32\nvsvc32.exe
+ PlugPlay使计算机在极少或没有用户输入的情况下能识别并适应硬件的更改。终止或禁用此服务会造成系统不稳定。Microsoft Corporationc:\windows\system32\services.exe
+ PolicyAgent管理 IP 安全策略以及启动 ISAKMP/Oakley (IKE) 和 IP 安全驱动程序。Microsoft Corporationc:\windows\system32\lsass.exe
+ ProtectedStorage提供对敏感数据(如私钥)的保护性存储,以便防止未授权的服务,过程或用户对其的非法访问。Microsoft Corporationc:\windows\system32\lsass.exe
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwsrv.exe
+ RpcSs提供终结点映射程序 (endpoint mapper) 以及其它 RPC 服务。Microsoft Corporationc:\windows\system32\svchost.exe
+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe
+ SamSs存储本地用户帐户的安全信息。Microsoft Corporationc:\windows\system32\lsass.exe
+ Schedule使用户能在此计算机上配置和制定自动任务的日程。如果此服务被终止,这些任务将无法在日程时间里运行。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ seclogon启用替换凭据下的启用进程。如果此服务被终止,此类型登录访问将不可用。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ SENS跟踪系统事件,如登录 Windows,网络以及电源事件等。将这些事件通知给 COM+ 事件系统 “订阅者(subscriber)”。Microsoft Corporationc:\windows\system32\svchost.exe
+ ShellHWDetectionGeneric Host Process for Win32 ServicesMicrosoft Corporationc:\windows\system32\svchost.exe
+ Spooler将文件加载到内存中以便迟后打印。Microsoft Corporationc:\windows\system32\spoolsv.exe
+ srservice执行系统还原功能。 要停止服务,请从“我的电脑”的属性中的系统还原选项卡关闭系统还原Microsoft Corporationc:\windows\system32\svchost.exe
+ Themes为用户提供使用主题管理的经验。Microsoft Corporationc:\windows\system32\svchost.exe
+ TrkWks在计算机内 NTFS 文件之间保持链接或在网络域中的计算机之间保持链接。Microsoft Corporationc:\windows\system32\svchost.exe
+ UMWdf启用 Windows 用户模式驱动程序。Microsoft Corporationc:\windows\system32\wdfmgr.exe
+ uploadmgr管理网络上客户端和服务器之间同步和异步文件传输。如果停止服务,网络上客户端和服务器之间同步和异步文件传输不会发生。如果禁用服务,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ W32Time维护在网络上的所有客户端和服务器的时间和日期同步。如果此服务被停止,时间和日期的同步将不可用。如果此服务被禁用,任何明确依赖它的服务都将不能启动。
Microsoft Corporationc:\windows\system32\svchost.exe
+ WebClient使基于 Windows 的程序能创建、访问和修改基于 Internet 的文件。如果此服务被终止,将会失去这些功能。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ winmgmt提供共同的界面和对象模式以便访问有关操作系统、设备、应用程序和服务的管理信息。如果此服务被终止,多数基于 Windows 的软件将无法正常运行。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ wuauserv从 Windows Update 启用重要的 Windows 更新的下载和安装。如果禁用该服务,操作系统可以在 Windows Update 网站手动更新。Microsoft Corporationc:\windows\system32\svchost.exe
+ WZCSVC为您的 802.11 适配器提供自动配置Microsoft Corporationc:\windows\system32\svchost.exe
HKLM\System\CurrentControlSet\Services
+ ACPIACPI Driver for NTMicrosoft Corporationc:\windows\system32\drivers\acpi.sys
+ aecMicrosoft Acoustic Echo CancellerMicrosoft Corporationc:\windows\system32\drivers\aec.sys
+ AFDAncillary Function Driver for WinSockMicrosoft Corporationc:\windows\system32\drivers\afd.sys
+ AsyncMacRAS Asynchronous Media DriverMicrosoft Corporationc:\windows\system32\drivers\asyncmac.sys
+ atapiIDE/ATAPI Port DriverMicrosoft Corporationc:\windows\system32\drivers\atapi.sys
+ AtmarpcATM ARP Client ProtocolMicrosoft Corporationc:\windows\system32\drivers\atmarpc.sys
+ audstubAudStub DriverMicrosoft Corporationc:\windows\system32\drivers\audstub.sys
+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\windows\system32\drivers\basetdi.sys
990410xl - 2006-5-21 16:09:00
\drivers\basetdi.sys
+ CdromSCSI CD-ROM DriverMicrosoft Corporationc:\windows\system32\drivers\cdrom.sys
+ DiskPnP Disk DriverMicrosoft Corporationc:\windows\system32\drivers\disk.sys
+ dmioNT Disk Manager I/O DriverMicrosoft Corp., Veritas Softwarec:\windows\system32\drivers\dmio.sys
+ dmloadNT Disk Manager Startup DriverMicrosoft Corp., Veritas Software.c:\windows\system32\drivers\dmload.sys
+ DMusicMicrosoft Kernel DLS SynthesizerMicrosoft Corporationc:\windows\system32\drivers\dmusic.sys
+ drmkaudMicrosoft Kernel DRM Audio Descrambler FilterMicrosoft Corporationc:\windows\system32\drivers\drmkaud.sys
+ ds1Yamaha PCI(x) Audio System (WDM)[1013]Yamaha Corp.c:\windows\system32\drivers\ds1wdm.sys
+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys
+ FsVgaFull Screen Video DriverMicrosoft Corporationc:\windows\system32\drivers\fsvga.sys
+ FtdiskFT Disk DriverMicrosoft Corporationc:\windows\system32\drivers\ftdisk.sys
+ gameenumGame Port EnumeratorMicrosoft Corporationc:\windows\system32\drivers\gameenum.sys
+ GpcGeneric Packet ClassifierMicrosoft Corporationc:\windows\system32\drivers\msgpc.sys
+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys
+ HookRegc:\program files\rising\rav\hookreg.sys
+ HookSysHooksysRisingc:\program files\rising\rav\hooksys.sys
+ i8042prti8042 Port DriverMicrosoft Corporationc:\windows\system32\drivers\i8042prt.sys
+ ImapiIMAPI Kernel DriverMicrosoft Corporationc:\windows\system32\drivers\imapi.sys
+ IpFilterDriverIP Traffic Filter DriverMicrosoft Corporationc:\windows\system32\drivers\ipfltdrv.sys
+ IpInIpIP in IP Tunnel DriverMicrosoft Corporationc:\windows\system32\drivers\ipinip.sys
+ IpNatIP Network Address TranslatorMicrosoft Corporationc:\windows\system32\drivers\ipnat.sys
+ IPSecIPSEC driverMicrosoft Corporationc:\windows\system32\drivers\ipsec.sys
+ IRENUMInfra-Red Bus EnumeratorMicrosoft Corporationc:\windows\system32\drivers\irenum.sys
+ isapnpPNP ISA Bus DriverMicrosoft Corporationc:\windows\system32\drivers\isapnp.sys
+ KbdclassKeyboard Class DriverMicrosoft Corporationc:\windows\system32\drivers\kbdclass.sys
+ kmixerKernel Mode Audio MixerMicrosoft Corporationc:\windows\system32\drivers\kmixer.sys
+ MEMSCANMemScan Driver瑞星软件有限公司c:\program files\rising\rav\memscan.sys
+ MouclassMouse Class DriverMicrosoft Corporationc:\windows\system32\drivers\mouclass.sys
+ mProcRsRising Personal FireWall mprocrs.sysBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\mprocrs.sys
+ MSKSSRVMS KS ServerMicrosoft Corporationc:\windows\system32\drivers\mskssrv.sys
+ MSPCLOCKMS Proxy ClockMicrosoft Corporationc:\windows\system32\drivers\mspclock.sys
+ MSPQMMS Proxy Quality ManagerMicrosoft Corporationc:\windows\system32\drivers\mspqm.sys
+ NdisTapiRemote Access NDIS TAPI DriverMicrosoft Corporationc:\windows\system32\drivers\ndistapi.sys
+ NdisuioNDIS 用户模式 I/O 协议Microsoft Corporationc:\windows\system32\drivers\ndisuio.sys
+ NdisWanRemote Access NDIS WAN DriverMicrosoft Corporationc:\windows\system32\drivers\ndiswan.sys
+ NetBTNetBios over TcpipMicrosoft Corporationc:\windows\system32\drivers\netbt.sys
+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.c:\program files\tencent\qq\npkcrypt.sys
+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 81.98 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys
+ NwlnkFltIPX Traffic Filter DriverMicrosoft Corporationc:\windows\system32\drivers\nwlnkflt.sys
+ NwlnkFwdIPX Traffic Forwarder DriverMicrosoft Corporationc:\windows\system32\drivers\nwlnkfwd.sys
+ ParportParallel Port DriverMicrosoft Corporationc:\windows\system32\drivers\parport.sys
+ PCINT Plug and Play PCI EnumeratorMicrosoft Corporationc:\windows\system32\drivers\pci.sys
+ PCIIdeGeneric PCI IDE Bus DriverMicrosoft Corporationc:\windows\system32\drivers\pciide.sys
+ PptpMiniportWAN Miniport (PPTP)Microsoft Corporationc:\windows\system32\drivers\raspptp.sys
+ ProcessorProcessor Device DriverMicrosoft Corporationc:\windows\system32\drivers\processr.sys
+ PSchedQoS Packet SchedulerMicrosoft Corporationc:\windows\system32\drivers\psched.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys
+ RasAcdRemote Access Auto Connection DriverMicrosoft Corporationc:\windows\system32\drivers\rasacd.sys
+ Rasl2tpWAN Miniport (L2TP)Microsoft Corporationc:\windows\system32\drivers\rasl2tp.sys
+ RasPppoe远程访问 PPPOE 驱动程序Microsoft Corporationc:\windows\system32\drivers\raspppoe.sys
+ RasptiDirect ParallelMicrosoft Corporationc:\windows\system32\drivers\raspti.sys
+ RDPCDDRDP MiniportMicrosoft Corporationc:\windows\system32\drivers\rdpcdd.sys
+ rdpdrMicrosoft RDP Device redirectorMicrosoft Corporationc:\windows\system32\drivers\rdpdr.sys
+ redbookRedbook Audio Filter DriverMicrosoft Corporationc:\windows\system32\drivers\redbook.sys
+ RsFwDrvnt_fwdrvBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rsfwdrv.sys
+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys
+ serenumSerial Port EnumeratorMicrosoft Corporationc:\windows\system32\drivers\serenum.sys
+ SerialSerial Device DriverMicrosoft Corporationc:\windows\system32\drivers\serial.sys
+ SISNICSiS PCI Fast Ethernet Adapter DriverSiS Corporationc:\windows\system32\drivers\sisnic.sys
+ splitterMicrosoft Kernel Audio SplitterMicrosoft Corporationc:\windows\system32\drivers\splitter.sys
+ swenumPlug and Play Software Device EnumeratorMicrosoft Corporationc:\windows\system32\drivers\swenum.sys
+ swmidiMicrosoft GS Wavetable SynthesizerMicrosoft Corporationc:\windows\system32\drivers\swmidi.sys
+ sysaudioSystem Audio WDM FilterMicrosoft Corporationc:\windows\system32\drivers\sysaudio.sys
+ TcpipTCP/IP Protocol DriverMicrosoft Corporationc:\windows\system32\drivers\tcpip.sys
+ TermDDTerminal Server DriverMicrosoft Corporationc:\windows\system32\drivers\termdd.sys
+ UpdateUpdate DriverMicrosoft Corporationc:\windows\system32\drivers\update.sys
+ usbehciEHCI eUSB Miniport DriverMicrosoft Corporationc:\windows\system32\drivers\usbehci.sys
+ usbhubDefault Hub Driver for USBMicrosoft Corporationc:\windows\system32\drivers\usbhub.sys
+ usbohciOHCI USB Miniport DriverMicrosoft Corporationc:\windows\system32\drivers\usbohci.sys
+ VgaSaveVGA/Super VGA Video DriverMicrosoft Corporationc:\windows\system32\drivers\vga.sys
+ WanarpRemote Access IP ARP DriverMicrosoft Corporationc:\windows\system32\drivers\wanarp.sys
+ wdmaudMMSYSTEM Wave/Midi API mapperMicrosoft Corporationc:\windows\system32\drivers\wdmaud.sys
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
+ autocheck autochk *Auto Check UtilityMicrosoft Corporationc:\windows\system32\autochk.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
+ Your Image File Name Here without a pathSymbolic Debugger for Windows 2000Microsoft Corporationc:\windows\system32\ntsd.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls
+ APIHookDll.dllFile not found: APIHookDll.dll
HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls
+ advapi32Advanced Windows 32 Base APIMicrosoft Corporationc:\windows\system32\advapi32.dll
+ comdlg32Common Dialogs DLLMicrosoft Corporationc:\windows\system32\comdlg32.dll
+ gdi32GDI Client DLLMicrosoft Corporationc:\windows\system32\gdi32.dll
+ imagehlpWindows NT Image HelperMicrosoft Corporationc:\windows\system32\imagehlp.dll
+ kernel32Windows NT BASE API Client DLLMicrosoft Corporationc:\windows\system32\kernel32.dll
+ lz32LZ Expand/Compress API DLLMicrosoft Corporationc:\windows\system32\lz32.dll
+ ole32Microsoft OLE for WindowsMicrosoft Corporationc:\windows\system32\ole32.dll
+ oleaut32Microsoft OLE 3.50 for Windows NT(TM) and Windows 95(TM) Operating SystemsMicrosoft Corporationc:\windows\system32\oleaut32.dll
+ olecli32Object Linking and Embedding Client LibraryMicrosoft Corporationc:\windows\system32\olecli32.dll
990410xl - 2006-5-21 16:11:00
+ olecnv32Microsoft OLE for WindowsMicrosoft Corporationc:\windows\system32\olecnv32.dll
+ olesvr32Object Linking and Embedding Server LibraryMicrosoft Corporationc:\windows\system32\olesvr32.dll
+ olethk32Microsoft OLE for WindowsMicrosoft Corporationc:\windows\system32\olethk32.dll
+ rpcrt4Remote Procedure Call RuntimeMicrosoft Corporationc:\windows\system32\rpcrt4.dll
+ shell32Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ urlInternet Shortcut Shell Extension DLLMicrosoft Corporationc:\windows\system32\url.dll
+ urlmonOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ user32Windows XP USER API Client DLLMicrosoft Corporationc:\windows\system32\user32.dll
+ versionVersion Checking and File Installation LibrariesMicrosoft Corporationc:\windows\system32\version.dll
+ wininetInternet Extensions for Win32Microsoft Corporationc:\windows\system32\wininet.dll
+ wldap32Win32 LDAP API DLLMicrosoft Corporationc:\windows\system32\wldap32.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
+ crypt32chainCrypto API32Microsoft Corporationc:\windows\system32\crypt32.dll
+ cryptnetCrypto Network Related APIMicrosoft Corporationc:\windows\system32\cryptnet.dll
+ cscdllOffline Network AgentMicrosoft Corporationc:\windows\system32\cscdll.dll
+ ScCertPropCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll
+ ScheduleCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll
+ sclgntfySecondary Logon Service Notification DLLMicrosoft Corporationc:\windows\system32\sclgntfy.dll
+ SensLognCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll
+ termsrvCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll
+ wlballoonCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll
HKCU\Control Panel\Desktop\Scrnsave.exe
+ C:\WINDOWS\System32\logon.scrLogon Screen SaverMicrosoft Corporationc:\windows\system32\logon.scr
HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{2B60B3F5-4BF1-4BB9-81CB-2660B146615D}] DATAGRAM 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{2B60B3F5-4BF1-4BB9-81CB-2660B146615D}] SEQPACKET 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{5C41434C-EA31-4624-B43C-2746057F2B76}] DATAGRAM 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{5C41434C-EA31-4624-B43C-2746057F2B76}] SEQPACKET 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{7B643AEA-9BA8-4547-B578-01E834FB9906}] DATAGRAM 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{7B643AEA-9BA8-4547-B578-01E834FB9906}] SEQPACKET 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD Tcpip [RAW/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD Tcpip [TCP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD Tcpip [UDP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ RSVP TCP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\windows\system32\rsvpsp.dll
+ RSVP UDP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\windows\system32\rsvpsp.dll
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
+ BJ Language MonitorLangage Monitor for Canon Bubble-Jet PrinterMicrosoft Corporationc:\windows\system32\cnbjmon.dll
+ Local PortLocal Spooler DLLMicrosoft Corporationc:\windows\system32\localspl.dll
+ PJL Language MonitorPJL Language monitorMicrosoft Corporationc:\windows\system32\pjlmon.dll
+ Standard TCP/IP PortStandard TCP/IP Port Monitor DLLMicrosoft Corporationc:\windows\system32\tcpmon.dll
+ USB MonitorStandard Dynamic Printing Port Monitor DLLMicrosoft Corporationc:\windows\system32\usbmon.dll
990410xl - 2006-5-21 16:16:00
非常感谢朋友们帮我,我终于找到原因了~
我无邪 - 2006-5-21 20:15:00
拜托把原因告诉我
1
© 2000 - 2026 Rising Corp. Ltd.