瑞星卡卡安全论坛
灵光静z - 2006-5-23 18:03:00
Dyn5E.tmp 这个是什么啊 瑞星杀不到
拿反间谍工具可以杀到 在TMEP文件夹下 一直杀有几十个```
杀完之后 没多久他有自己出来了 ```
扫描完成,发现 1 个恶意代码!
1个Trojan-Downloader.Win32.Agent.uf_1
位置: C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\Dyn5E.tmp
里面不止这一个 还有 Dyn7E.tmp 类似的很多
哪位高手帮帮啊
轩辕小聪 - 2006-5-23 18:08:00
安全模式下清空C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\文件夹
另外,反间谍专家充其量只是一个查毒的小工具,并不是专业杀软,存在误报的可能(上次把瑞星防火墙都报为蠕虫了)。
灵光静z - 2006-5-23 18:13:00
谢谢 我去试试
轩辕小聪 - 2006-5-23 18:14:00
还有,不要看到tmp文件就怕,它本身是程序产生的临时文件,不一定都是病毒。
灵光静z - 2006-5-23 18:41:00
大哥不是我怕啊```我什么都没装跟原来一模一样
它就多出这个文件,我要是结束进程的话 我玩的游戏就自己没响应了,肯定不是游戏本身产生的零时文件,以前从来没有的```
我按照2楼的说法,进安全模式下 把TEMP整个文件夹都删除了,开机的时候没有,但是没多久他就运行了。
到底是怎么回事啊,我以前从来没有这个进程的```
灵光静z - 2006-5-23 18:48:00
谁帮帮我这个菜鸟咯
灵光静z - 2006-5-23 18:49:00
刚刚内存里是 Dym5E.tmp
现在不见了 换成 Dyn1B.tmp
这到底是什么啊 我郁闷
灵光静z - 2006-5-23 19:00:00
现在又变了
Dyn1E.tmp 了
我郁闷死了
轩辕小聪 - 2006-5-23 19:06:00
你的意思是这个文件可以在进程里看到吗?
灵光静z - 2006-5-23 19:10:00
恩 能看到
灵光静z - 2006-5-23 19:11:00
好象是无限止的一直换下去 一直生成 tmp文件
轩辕小聪 - 2006-5-23 19:26:00
http://forum.ikaka.com/topic.asp?board=28&artid=6979213第5楼下载System Repair Engineer 2.0.12.350导出全部日志。
灵光静z - 2006-5-23 19:49:00
下是下了
但是里面没有导出日志那一个功能啊
能说的详细点吗 先谢过了
轩辕小聪 - 2006-5-23 19:52:00
点智能扫描
灵光静z - 2006-5-23 22:46:00
2006-05-23,22:37:20
System Repair Engineer 2.0.12.350 (2.0 RC 1)
Windows XP Professional Service Pack 2 - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<run><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"g:\Program Files\Rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ATICCC><; ; ; "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ATIPTA><; ; ; "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe">
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<BigDogPath><; ; ; C:\WINDOWS\VM_STI.EXE USB PC Camera 301P>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<Cmaudio><; ; ; RunDll32 cmicnfg.cpl,CMICtrlWnd>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<DAEMON Tools-2052><; ; ; ; "G:\Program Files\D-Tools\daemon.exe" -lang 1033>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<DigiTray><; ; ; >
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<KernelFaultCheck><; ; ; %systemroot%\system32\dumprep 0 -k>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><; ; ; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<PhMain><; ; ; >
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<Prizone.exe><; ; ; >
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<RfwMain><; ; ; "g:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<Shareaza><; ; ; "G:\Program Files\超级BT下载软件\Shareaza.exe" -tray>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<StormCodec_Helper><; ; ; "g:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<TkBellExe><; ; ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<vstat><; ; ; C:\Program Files\Outlook Express\kel.exe>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<YLive.exe><; ; ; >
灵光静z - 2006-5-23 22:46:00
启动文件夹
服务
[Adobe LM Service / Adobe LM Service]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><N/A>
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart]
<C:\WINDOWS\system32\ati2sgag.exe><>
[Autodesk Licensing Service / Autodesk Licensing Service]
<"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><N/A>
[InstallDriver Table Manager / IDriverT]
<"C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"><Macrovision Corporation>
[npkcsvc / npkcsvc]
<C:\WINDOWS\system32\npkcsvc.exe><INCA Internet Co., Ltd.>
[Rising Proxy Service / RfwProxySrv]
<><N/A>
[Rising Personal Firewall Service / RfwService]
<g:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
<"g:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"g:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[StarWind iSCSI Service / StarWindService]
<G:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe><Rocket Division Software>
==================================
浏览器加载项
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <G:\Program Files\Tencent\qq\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[OfficeScan Corp Edition Web-Deployment SetupINICtrl Class]
{08D75BB0-D2B5-11D1-88FC-0080C859833B} <, N/A>
[OfficeScan Corp Edition Web-Deployment SetupCtrl Class]
{08D75BC1-D2B5-11D1-88FC-0080C859833B} <, N/A>
[IMCv1 Control]
{6924091F-CD97-41E1-B1D4-D9079409D413} <, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[ChajianHelper Class]
{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} <C:\WINDOWS\system32\SYSREA~1.DLL, Kmedia>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corp.>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[XML DOM Document]
{2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\System32\msxml3.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[HHCtrl Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <G:\Program Files\Tencent\qq\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\ieframe.dll, N/A>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\System32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[MediaComm Class]
{7670648D-461B-42AF-BDFE-46D26AF5EFF2} <g:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin04.dll, Thunder Networking Technologies,LTD>
[Status Class]
{7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} <, N/A>
[Microsoft Web Browser]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\ieframe.dll, Microsoft Corporation>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <, N/A>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\System32\shdocvw.dll, N/A>
[WebActivater Control]
{C661F36D-DF85-4EF4-83C7-E107B83D04B1} <C:\WINDOWS\system32\3DShowVM.ocx, QQ>
[NPX Control]
{CFCB7308-782F-11D4-BE27-000102598CE4} <C:\WINDOWS\system32\npx.ocx, INCA Internet Co., Ltd.>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[NPKCX Control]
{D6FCA8ED-4715-43DE-9BD2-2789778A5B09} <C:\WINDOWS\system32\NPKCX.ocx, INCA Internet Co., Ltd.>
[TencentVmpCtl Class]
{D9819BD5-422B-4281-8523-726466ED692B} <C:\Program Files\Tencent\Viewpoint Media Player\AxMetaStream.dll, Viewpoint Corporation>
[XML HTTP Request]
{ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\System32\msxml3.dll, N/A>
[XML DOM Document]
{F6D90F11-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, N/A>
[XML HTTP]
{F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, N/A>
[&使用迅雷下载]
<g:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<g:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
<G:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<G:\Program Files\Tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<G:\Program Files\Tencent\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<G:\Program Files\Tencent\qq\SendMMS.htm, N/A>
灵光静z - 2006-5-23 22:48:00
正在运行的进程
[PID: 388][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 440][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 468][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\Ati2evxx.dll] <ATI Technologies Inc.><6.14.10.4119>
[PID: 516][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 528][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 680][C:\WINDOWS\system32\Ati2evxx.exe] <ATI Technologies Inc.><6.14.10.4119>
[C:\WINDOWS\system32\Ati2edxx.dll] <ATI Technologies, Inc.><6, 14, 10, 2497>
[PID: 704][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 764][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 820][g:\Program Files\Rising\Rav\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 836][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 996][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1036][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1052][g:\Program Files\Rising\Rav\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 22>
[g:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[g:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[g:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[g:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[g:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[g:\Program Files\Rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
[g:\Program Files\Rising\Rav\HOOKSYS.dll] <Rising><18, 1, 0, 9>
[g:\Program Files\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
[g:\Program Files\Rising\Rav\libload.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[g:\Program Files\Rising\Rav\VirusLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[g:\Program Files\Rising\Rav\regmon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[g:\Program Files\Rising\Rav\HookWeb.dll] <rising><18, 0, 0, 1>
[g:\Program Files\Rising\Rav\MemMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
[g:\Program Files\Rising\Rav\expscan.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[g:\Program Files\Rising\Rav\mPorts.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[g:\Program Files\Rising\Rav\MailMon.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[g:\Program Files\Rising\Rav\SpamEng.dll] <N/A><18, 0, 0, 6>
[g:\Program Files\Rising\Rav\engine.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
[g:\Program Files\Rising\Rav\PostTrt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
[g:\Program Files\Rising\Rav\UnExe.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[g:\Program Files\Rising\Rav\ScanExec.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[g:\Program Files\Rising\Rav\ScanEx.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
[g:\Program Files\Rising\Rav\NvFile.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[g:\Program Files\Rising\Rav\ScanMac.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
[g:\Program Files\Rising\Rav\ScanSct.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 15>
[g:\Program Files\Rising\Rav\Unpacker.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[g:\Program Files\Rising\Rav\ExtOLE.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[g:\Program Files\Rising\Rav\ScanNet.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1100][g:\program files\rising\rfw\rfwsrv.exe] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 32>
[g:\program files\rising\rfw\RfwRule.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
[g:\program files\rising\rfw\rfwlog.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
[g:\program files\rising\rfw\Rfwdrv.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
[g:\program files\rising\rfw\MonDrv.dll] <rs><1, 0, 0, 4>
[g:\program files\rising\rfw\ProcLib.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[PID: 1240][g:\Program Files\Rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[g:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[g:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1344][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll] <Windows (R) 2000 DDK provider><5.00.2195.1620>
[PID: 1580][C:\WINDOWS\system32\Ati2evxx.exe] <ATI Technologies Inc.><6.14.10.4119>
[C:\WINDOWS\system32\Ati2edxx.dll] <ATI Technologies, Inc.><6, 14, 10, 2497>
[PID: 1656][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1668][g:\program files\rising\rfw\RfwMain.exe] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 51>
灵光静z - 2006-5-23 22:48:00
[g:\program files\rising\rfw\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
[g:\program files\rising\rfw\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[g:\program files\rising\rfw\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1768][G:\Program Files\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[G:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[G:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[G:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[G:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[PID: 1792][G:\Program Files\Rising\Rav\Ravmon.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 19>
[G:\Program Files\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
[G:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
[G:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[G:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[G:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[G:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[G:\Program Files\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 344][C:\WINDOWS\system32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 1848][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2264][G:\Program Files\DrCOM\Dr.COM 宽带登录客户端\ishare_user.exe] <N/A><N/A>
[PID: 3316][C:\WINDOWS\system32\conime.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3364][F:\Program Files\Shanda\Woool\woool.exe] <><1.7.2.47>
[g:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[F:\Program Files\Shanda\Woool\data\woool.dat] <N/A><N/A>
[F:\Program Files\Shanda\Woool\data\MercenarySystem.dll] <N/A><N/A>
[F:\Program Files\Shanda\Woool\data\python24.dll] <ActiveState Corporation><2.4>
[F:\Program Files\Shanda\Woool\data\SDOle.dll] <TODO: <Company name>><1.0.0.1>
[F:\Program Files\Shanda\Woool\data\Mir2File.dll] <SHANDA><1, 0, 1, 6>
[F:\Program Files\Shanda\Woool\data\TjBin.dll] <上海盛大网络(Shanda Interactive Entertainment Ltd.)><1.0.1.66>
[F:\Program Files\Shanda\Woool\data\CheckUpdate.dll] <上海盛大网络发展有限公司 <www.snda.com>><2, 2, 12, 9>
[F:\Program Files\Shanda\Woool\Data\wooolasstool.dat] <N/A><N/A>
[PID: 2084][G:\Program Files\Tencent\qq\QQ.exe] <TENCENT><0, 0, 0, 0>
[G:\Program Files\Tencent\qq\QQBaseClassInDll.dll] <><1, 0, 0, 1>
[G:\Program Files\Tencent\qq\QQHelperDll.dll] <><1, 0, 0, 1>
[G:\Program Files\Tencent\qq\BasicCtrlDll.dll] <Tencent><5, 0, 200, 160>
[G:\Program Files\Tencent\qq\QQAPI.dll] <><1, 0, 0, 1>
[G:\Program Files\Tencent\qq\LoginCtrl.dll] <><1, 0, 0, 1>
[G:\Program Files\Tencent\qq\npkcntc.dll] <INCA Internet Co., Ltd.><2006, 3, 2, 1>
[G:\Program Files\Tencent\qq\npkpdb.dll] <INCA Internet Co., Ltd.><2003, 10, 1, 1>
[G:\Program Files\Tencent\qq\QQRes.dll] <tencent><1, 0, 0, 1>
[G:\Program Files\Tencent\qq\QQMainFrame.dll] <N/A><N/A>
[G:\Program Files\Tencent\qq\CQQApplication.dll] <N/A><N/A>
[G:\Program Files\Tencent\qq\NewSkin.dll] <><1, 0, 0, 1>
[G:\Program Files\Tencent\qq\HostingMgr.dll] <><1, 0, 0, 1>
[G:\Program Files\Tencent\qq\CameraDll.dll] <><1, 0, 0, 1>
[G:\Program Files\Tencent\qq\MailSummary.dll] <><1, 0, 0, 1>
[G:\Program Files\Tencent\qq\QQSpace.dll] <><1, 0, 0, 1>
[C:\WINDOWS\system32\msdmo.dll] <N/A><N/A>
[G:\Program Files\Tencent\qq\QQGroupMng.dll] <><1, 0, 0, 1>
[G:\Program Files\Tencent\qq\GroupLive.dll] <N/A><N/A>
[G:\Program Files\Tencent\qq\QQSysMsgMng.dll] <N/A><N/A>
[G:\Program Files\Tencent\qq\UserDefinedHead.dll] <><1, 0, 0, 1>
[G:\Program Files\Tencent\qq\QQPlugin.dll] <N/A><N/A>
[G:\Program Files\Tencent\qq\QQConfigPlugin.dll] <><1, 0, 0, 1>
[G:\Program Files\Tencent\qq\QRingMng.dll] <N/A><N/A>
[G:\Program Files\Tencent\qq\PhoneAPI.dll] <><1, 0, 0, 1>
[G:\Program Files\Tencent\qq\DialerAllinOne.dll] <tencent><1, 4, 0, 0>
[G:\Program Files\Tencent\qq\LongConnection.dll] <tencent><5, 0, 200, 160>
[G:\Program Files\Tencent\qq\QQPet.dll] <><1, 0, 0, 1>
[G:\Program Files\Tencent\qq\QQAvatar.dll] <N/A><N/A>
[G:\Program Files\Tencent\qq\FlashAvatarDll.dll] <><1, 4, 0, 1>
[G:\Program Files\Tencent\qq\BQQApplication.dll] <N/A><N/A>
[G:\Program Files\Tencent\qq\CommercesMng.dll] <><1, 0, 0, 1>
[G:\Program Files\Tencent\qq\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
[G:\Program Files\Tencent\qq\QQAddr.dll] <深圳市腾讯计算机系统有限公司><5, 0, 101, 200>
[G:\Program Files\Tencent\qq\OEMApplication.dll] <><1, 0, 0, 1>
[G:\Program Files\Tencent\qq\QQAllInOne.dll] <N/A><N/A>
[G:\Program Files\Tencent\qq\SCCore.dll] <N/A><N/A>
[G:\Program Files\Tencent\qq\QQCustomFace.dll] <N/A><N/A>
[C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[G:\Program Files\Tencent\qq\QQSceneMng.dll] <N/A><N/A>
[G:\Program Files\Tencent\qq\GroupConnection.dll] <Tencent><5, 0, 202, 170>
[G:\Program Files\Tencent\qq\QQPhoneHelper.dll] <腾讯科技(深圳)有限公司><2, 0, 3, 30>
[PID: 1436][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Dyn7.tmp] <N/A><N/A>
[PID: 276][G:\downloads\System Repair Engineer\SREng.exe] <Smallfrogs Studio><2.0.12.350>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
灵光静z - 2006-5-23 22:51:00
高手看看啊
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Dyn7.tmp] <N/A><N/A>
就是这个吧`我也不知道是什么。无限生成,杀了就没了,不杀就一直生成```
灵光静z - 2006-5-23 22:53:00
瑞星不知道为什么杀不到也监控不到
搞完之后从新启动 过会又有
烦死了。。。。
灵光静z - 2006-5-23 22:56:00
一直有,好郁闷啊 弄完开机还是有
灵光静z - 2006-5-23 22:58:00
一直有,好郁闷啊 弄完开机还是有~~~~~~~~~~~
轩辕小聪 - 2006-5-23 23:13:00
用System Repair Engineer在“启动项目”-“注册表”中删除如下项目:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<vstat><; ; ; C:\Program Files\Outlook Express\kel.exe>
删除C:\Program Files\Outlook Express\kel.exe(如果有的话)
重启到安全模式下清空temp文件夹。
如果还搞不定,http://forum.ikaka.com/topic.asp?board=28&artid=6979213下载Autoruns导出全部日志,注意先选Options-Hide Microsoft Entries,再选Files-Save。
灵光静z - 2006-5-24 13:59:00
谢谢 小聪哥哥 我去试下
灵光静z - 2006-5-24 15:19:00
按第一次的方法没用 又出来了
我按你说的 下载了 保存了 麻烦大哥在帮我看看
灵光静z - 2006-5-24 15:21:00
HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms
+ rdpclipRDP Clip MonitorMicrosoft Corporationc:\windows\system32\rdpclip.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
+ C:\WINDOWS\system32\userinit.exeUserinit Logon ApplicationMicrosoft Corporationc:\windows\system32\userinit.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
+ Explorer.exeWindows ExplorerMicrosoft Corporationc:\windows\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ ATICCCFile not found: ;
+ ATIPTAFile not found: ;
+ BigDogPathFile not found: ;
+ CmaudioFile not found: ;
+ DAEMON Tools-2052File not found: ;
+ DigiTrayFile not found: ;
+ KernelFaultCheckFile not found: ;
+ NvCplDaemonFile not found: ;
+ Prizone.exeFile not found: ;
+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.g:\program files\rising\rav\ravtask.exe
+ RfwMainFile not found: ;
+ StormCodec_HelperFile not found: ;
+ TkBellExeFile not found: ;
+ YLive.exeFile not found: ;
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
+ PhMainFile not found: ;
+ Super Rabbit IEProFile not found: ;
HKLM\SOFTWARE\Classes\Protocols\Filter
+ application/octet-streamMicrosoft .NET Runtime Execution EngineMicrosoft Corporationc:\windows\system32\mscoree.dll
+ application/x-complusMicrosoft .NET Runtime Execution EngineMicrosoft Corporationc:\windows\system32\mscoree.dll
+ application/x-msdownloadMicrosoft .NET Runtime Execution EngineMicrosoft Corporationc:\windows\system32\mscoree.dll
+ Class Install HandlerOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ deflateOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ gzipOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ lzdhtmlOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ text/webviewhtmlWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
HKLM\SOFTWARE\Classes\Protocols\Handler
+ aboutMicrosoft (R) HTML ViewerMicrosoft Corporationc:\windows\system32\mshtml.dll
+ cdlOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ dvdActiveX control for streaming videoMicrosoft Corporationc:\windows\system32\msvidctl.dll
+ fileOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ ftpOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ gopherOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ httpOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ httpsOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ itsMicrosoft? InfoTech Storage System LibraryMicrosoft Corporationc:\windows\system32\itss.dll
+ javascriptMicrosoft (R) HTML ViewerMicrosoft Corporationc:\windows\system32\mshtml.dll
+ localOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ mailtoMicrosoft (R) HTML ViewerMicrosoft Corporationc:\windows\system32\mshtml.dll
+ mhtmlMicrosoft Internet Messaging APIMicrosoft Corporationc:\windows\system32\inetcomm.dll
+ mkOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ ms-itsMicrosoft? InfoTech Storage System LibraryMicrosoft Corporationc:\windows\system32\itss.dll
+ resMicrosoft (R) HTML ViewerMicrosoft Corporationc:\windows\system32\mshtml.dll
+ sysimageMicrosoft (R) HTML ViewerMicrosoft Corporationc:\windows\system32\mshtml.dll
+ tvActiveX control for streaming videoMicrosoft Corporationc:\windows\system32\msvidctl.dll
+ vbscriptMicrosoft (R) HTML ViewerMicrosoft Corporationc:\windows\system32\mshtml.dll
+ wiaWIA Scripting LayerMicrosoft Corporationc:\windows\system32\wiascr.dll
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
+ Browser CustomizationsIEAK brandingMicrosoft Corporationc:\windows\system32\iedkcs32.dll
+ Internet ExplorerInternet ExplorerMicrosoft Corporationc:\program files\internet explorer\iexplore.exe
+ Internet Explorer 7IE 5.0 Per-User Install UtilityMicrosoft Corporationc:\windows\system32\ie4uinit.exe
+ Microsoft Outlook Express 6Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe
+ Microsoft Windows Media PlayerADVPACKMicrosoft Corporationc:\windows\system32\advpack.dll
+ NetMeeting 3.01ADVPACKMicrosoft Corporationc:\windows\system32\advpack.dll
+ Outlook ExpressWindows NT User Data Migration ToolMicrosoft Corporationc:\windows\system32\shmgrate.exe
+ Themes SetupMicrosoft(C) Register ServerMicrosoft Corporationc:\windows\system32\regsvr32.exe
+ Windows Media PlayerMicrosoft Windows Media Player 安装实用程序Microsoft Corporationc:\windows\inf\unregmp2.exe
+ Windows Messenger 4.7ADVPACKMicrosoft Corporationc:\windows\system32\advpack.dll
+ Windows 桌面更新Microsoft(C) Register ServerMicrosoft Corporationc:\windows\system32\regsvr32.exe
+ 通讯簿 6Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe
+ 浏览器自定义组件IEAK brandingMicrosoft Corporationc:\windows\system32\iedkcs32.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
+ Browseui 预加载程序Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ IE Component Categories cache daemonInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ 组件类别缓存程序Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ CDBurnWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ PostBootReminderWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ SysTraySystray shell service objectMicrosoft Corporationc:\windows\system32\stobject.dll
+ WebCheckWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
+ shell32.dllWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ &LinksInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ ActiveX Cache FolderObject Control ViewerMicrosoft Corporationc:\windows\system32\occache.dll
+ Code Download AgentWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ Explorer Search BandInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ Explorer Travel BandInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ Extensions Manager FolderExtensions ManagerMicrosoft Corporationc:\windows\system32\extmgr.dll
+ HistoryInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE &AddressInternet Explorer Browser UI LibraryMicrosoft Corporation
灵光静z - 2006-5-24 16:13:00
HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms
+ rdpclipRDP Clip MonitorMicrosoft Corporationc:\windows\system32\rdpclip.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
+ C:\WINDOWS\system32\userinit.exeUserinit Logon ApplicationMicrosoft Corporationc:\windows\system32\userinit.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
+ Explorer.exeWindows ExplorerMicrosoft Corporationc:\windows\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ ATICCCFile not found: ;
+ ATIPTAFile not found: ;
+ BigDogPathFile not found: ;
+ CmaudioFile not found: ;
+ DAEMON Tools-2052File not found: ;
+ DigiTrayFile not found: ;
+ KernelFaultCheckFile not found: ;
+ NvCplDaemonFile not found: ;
+ Prizone.exeFile not found: ;
+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.g:\program files\rising\rav\ravtask.exe
+ RfwMainFile not found: ;
+ StormCodec_HelperFile not found: ;
+ TkBellExeFile not found: ;
+ YLive.exeFile not found: ;
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
+ PhMainFile not found: ;
+ Super Rabbit IEProFile not found: ;
HKLM\SOFTWARE\Classes\Protocols\Filter
+ application/octet-streamMicrosoft .NET Runtime Execution EngineMicrosoft Corporationc:\windows\system32\mscoree.dll
+ application/x-complusMicrosoft .NET Runtime Execution EngineMicrosoft Corporationc:\windows\system32\mscoree.dll
+ application/x-msdownloadMicrosoft .NET Runtime Execution EngineMicrosoft Corporationc:\windows\system32\mscoree.dll
+ Class Install HandlerOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ deflateOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ gzipOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ lzdhtmlOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ text/webviewhtmlWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
HKLM\SOFTWARE\Classes\Protocols\Handler
+ aboutMicrosoft (R) HTML ViewerMicrosoft Corporationc:\windows\system32\mshtml.dll
+ cdlOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ dvdActiveX control for streaming videoMicrosoft Corporationc:\windows\system32\msvidctl.dll
+ fileOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ ftpOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ gopherOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ httpOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ httpsOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ itsMicrosoft? InfoTech Storage System LibraryMicrosoft Corporationc:\windows\system32\itss.dll
+ javascriptMicrosoft (R) HTML ViewerMicrosoft Corporationc:\windows\system32\mshtml.dll
+ localOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ mailtoMicrosoft (R) HTML ViewerMicrosoft Corporationc:\windows\system32\mshtml.dll
+ mhtmlMicrosoft Internet Messaging APIMicrosoft Corporationc:\windows\system32\inetcomm.dll
+ mkOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ ms-itsMicrosoft? InfoTech Storage System LibraryMicrosoft Corporationc:\windows\system32\itss.dll
+ resMicrosoft (R) HTML ViewerMicrosoft Corporationc:\windows\system32\mshtml.dll
+ sysimageMicrosoft (R) HTML ViewerMicrosoft Corporationc:\windows\system32\mshtml.dll
+ tvActiveX control for streaming videoMicrosoft Corporationc:\windows\system32\msvidctl.dll
+ vbscriptMicrosoft (R) HTML ViewerMicrosoft Corporationc:\windows\system32\mshtml.dll
+ wiaWIA Scripting LayerMicrosoft Corporationc:\windows\system32\wiascr.dll
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
+ Browser CustomizationsIEAK brandingMicrosoft Corporationc:\windows\system32\iedkcs32.dll
+ Internet ExplorerInternet ExplorerMicrosoft Corporationc:\program files\internet explorer\iexplore.exe
+ Internet Explorer 7IE 5.0 Per-User Install UtilityMicrosoft Corporationc:\windows\system32\ie4uinit.exe
+ Microsoft Outlook Express 6Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe
+ Microsoft Windows Media PlayerADVPACKMicrosoft Corporationc:\windows\system32\advpack.dll
+ NetMeeting 3.01ADVPACKMicrosoft Corporationc:\windows\system32\advpack.dll
+ Outlook ExpressWindows NT User Data Migration ToolMicrosoft Corporationc:\windows\system32\shmgrate.exe
+ Themes SetupMicrosoft(C) Register ServerMicrosoft Corporationc:\windows\system32\regsvr32.exe
+ Windows Media PlayerMicrosoft Windows Media Player 安装实用程序Microsoft Corporationc:\windows\inf\unregmp2.exe
+ Windows Messenger 4.7ADVPACKMicrosoft Corporationc:\windows\system32\advpack.dll
+ Windows 桌面更新Microsoft(C) Register ServerMicrosoft Corporationc:\windows\system32\regsvr32.exe
+ 通讯簿 6Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe
+ 浏览器自定义组件IEAK brandingMicrosoft Corporationc:\windows\system32\iedkcs32.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
+ Browseui 预加载程序Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ IE Component Categories cache daemonInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ 组件类别缓存程序Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ CDBurnWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ PostBootReminderWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ SysTraySystray shell service objectMicrosoft Corporationc:\windows\system32\stobject.dll
+ WebCheckWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
+ shell32.dllWindows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ &LinksInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ ActiveX Cache FolderObject Control ViewerMicrosoft Corporationc:\windows\system32\occache.dll
+ Code Download AgentWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ Explorer Search BandInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ Explorer Travel BandInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ Extensions Manager FolderExtensions ManagerMicrosoft Corporationc:\windows\system32\extmgr.dll
+ HistoryInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE &AddressInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Address EditBoxInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE AutoCompleteInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE BandProxyInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Custom MRU AutoCompleted ListInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Fade TaskInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Global Folder SettingsInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE IShellFolderBandInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Menu BandInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Menu Desk BarInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Menu SiteInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Microsoft BrowserBandInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Microsoft History AutoComplete ListInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Microsoft Internet ToolbarInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Microsoft Multiple AutoComplete List ContainerInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Microsoft Shell Folder AutoComplete ListInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE MRU AutoComplete ListInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Navigation BarInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Registry Tree Options UtilityInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
灵光静z - 2006-5-24 16:22:00
+ IE Search BandInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Search ControlInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Shell Band Site MenuInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Shell Rebar BandSiteInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE Tracking Shell MenuInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ IE User AssistInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ Internet Name SpaceInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ InternetShortcutInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ Microsoft Browser ArchitectureInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ Microsoft Url History ServiceInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ Microsoft Url Search HookInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
+ Shell DocObject ViewerInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ Shell Search BandShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Subscription FolderWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ Subscription MgrWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ Temporary Internet FilesInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ Temporary Internet FilesInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ The InternetInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
+ WebCheckWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ WebCheck SyncMgr HandlerWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ WebCheckWebCrawlerWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ Windows Media Player Add to Playlist Context Menu HandlerWindows Media Player LauncherMicrosoft Corporationc:\windows\system32\wmpshell.dll
+ Windows Media Player Burn Audio CD Context Menu HandlerWindows Media Player LauncherMicrosoft Corporationc:\windows\system32\wmpshell.dll
+ Windows Media Player Play as Playlist Context Menu HandlerWindows Media Player LauncherMicrosoft Corporationc:\windows\system32\wmpshell.dll
+ Yahoo Trojan Cleannerg:\program files\3721\ske\contmenu.dll
HKLM\Software\Classes\Folder\Shellex\ColumnHandlers
+ {0D2E74C4-3C34-11d2-A27E-00C04FC30871}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ {24F14F01-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ {24F14F02-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ {66742402-F9B9-11D1-A202-0000F81FEDEE}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
+ ieframe.dllInternet Explorer Browser UI LibraryMicrosoft Corporationc:\windows\system32\ieframe.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ 浩方对战平台浩方对战平台上海浩方在线信息技术有限公司f:\program files\浩方对战平台\gameclient.exe
+ 腾讯QQQQTENCENTg:\program files\tencent\qq\qq.exe
HKLM\System\CurrentControlSet\Services
+ Alerter通知所选用户和计算机有关系统管理级警报。如果服务停止,使用管理警报的程序将不会受到它们。如果此服务被禁用,任何直接依赖它的服务都将不能启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ Ati HotKey PollerATI External Event Utility EXE ModuleATI Technologies Inc.c:\windows\system32\ati2evxx.exe
+ ATI SmartATI Smartc:\windows\system32\ati2sgag.exe
+ AudioSrv管理基于 Windows 的程序的音频设备。如果此服务被终止,音频设备及其音效将不能正常工作。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ Autodesk Licensing ServiceAnchor service for Autodesk products licensed with SafeCastc:\program files\common files\autodesk shared\service\adskscsrv.exe
+ Browser维护网络上计算机的更新列表,并将列表提供给计算机指定浏览。如果服务停止,列表不会被更新或维护。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ CryptSvc提供三种管理服务: 编录数据库服务,它确定 Windows 文件的签字; 受保护的根服务,它从此计算机添加和删除受信根证书机构的证书;和密钥(Key)服务,它帮助注册此计算机获取证书。如果此服务被终止,这些管理服务将无法正常运行。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ DcomLaunch为 DCOM 服务提供加载功能。Microsoft Corporationc:\windows\system32\svchost.exe
+ Dhcp通过注册和更改 IP 地址以及 DNS 名称来管理网络配置。Microsoft Corporationc:\windows\system32\svchost.exe
+ dmserver监测和监视新硬盘驱动器并向逻辑磁盘管理器管理服务发送卷的信息以便配置。如果此服务被终止,动态磁盘状态和配置信息会过时。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ Dnscache为此计算机解析和缓冲域名系统 (DNS) 名称。如果此服务被停止,计算机将不能解析 DNS 名称并定位 Active Directory 域控制器。如果此服务被禁用,任何明确依赖它的服务将不能启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ Eventlog启用在事件查看器查看基于 Windows 的程序和组件颁发的事件日志消息。无法终止此服务。Microsoft Corporationc:\windows\system32\services.exe
+ helpsvc启用在此计算机上运行帮助和支持中心。如果停止服务,帮助和支持中心将不可用。如果禁用服务,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ lanmanserver支持此计算机通过网络的文件、打印、和命名管道共享。如果服务停止,这些功能不可用。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ lanmanworkstation创建和维护到远程服务的客户端网络连接。如果服务停止,这些连接将不可用。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ LmHosts允许对“TCP/IP 上 NetBIOS (NetBT)”服务以及 NetBIOS 名称解析的支持。Microsoft Corporationc:\windows\system32\svchost.exe
+ npkcsvcnProtect KeyCrypt ServiceINCA Internet Co., Ltd.c:\windows\system32\npkcsvc.exe
+ PlugPlay使计算机在极少或没有用户输入的情况下能识别并适应硬件的更改。终止或禁用此服务会造成系统不稳定。Microsoft Corporationc:\windows\system32\services.exe
+ PolicyAgent管理 IP 安全策略以及启动 ISAKMP/Oakley (IKE) 和 IP 安全驱动程序。Microsoft Corporationc:\windows\system32\lsass.exe
+ ProtectedStorage提供对敏感数据(如私钥)的保护性存储,以便防止未授权的服务,过程或用户对其的非法访问。Microsoft Corporationc:\windows\system32\lsass.exe
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Co., Ltd.g:\program files\rising\rfw\rfwsrv.exe
+ RpcSs提供终结点映射程序 (endpoint mapper) 以及其它 RPC 服务。Microsoft Corporationc:\windows\system32\svchost.exe
+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.g:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.g:\program files\rising\rav\ravmond.exe
+ SamSs存储本地用户帐户的安全信息。Microsoft Corporationc:\windows\system32\lsass.exe
+ Schedule使用户能在此计算机上配置和制定自动任务的日程。如果此服务被终止,这些任务将无法在日程时间里运行。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ seclogon启用替换凭据下的启用进程。如果此服务被终止,此类型登录访问将不可用。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ SENS跟踪系统事件,如登录 Windows,网络以及电源事件等。将这些事件通知给 COM+ 事件系统 “订阅者(subscriber)”。Microsoft Corporationc:\windows\system32\svchost.exe
+ SharedAccess为家庭或小型办公网络提供网络地址转换,定址以及名称解析和/或防止入侵服务。Microsoft Corporationc:\windows\system32\svchost.exe
+ ShellHWDetectionGeneric Host Process for Win32 ServicesMicrosoft Corporationc:\windows\system32\svchost.exe
+ Spooler将文件加载到内存中以便迟后打印。Microsoft Corporationc:\windows\system32\spoolsv.exe
+ srservice执行系统还原功能。 要停止服务,请从“我的电脑”的属性中的系统还原选项卡关闭系统还原Microsoft Corporationc:\windows\system32\svchost.exe
+ StarWindServiceEnables network access to local devices via iSCSI protocol.
灵光静z - 2006-5-24 16:25:00
Rocket Division Softwareg:\program files\alcohol soft\alcohol 120\starwind\starwindservice.exe
+ Themes为用户提供使用主题管理的经验。Microsoft Corporationc:\windows\system32\svchost.exe
+ TrkWks在计算机内 NTFS 文件之间保持链接或在网络域中的计算机之间保持链接。Microsoft Corporationc:\windows\system32\svchost.exe
+ UMWdf启用 Windows 用户模式驱动程序。Microsoft Corporationc:\windows\system32\wdfmgr.exe
+ W32Time维护在网络上的所有客户端和服务器的时间和日期同步。如果此服务被停止,时间和日期的同步将不可用。如果此服务被禁用,任何明确依赖它的服务都将不能启动。
Microsoft Corporationc:\windows\system32\svchost.exe
+ WebClient使基于 Windows 的程序能创建、访问和修改基于 Internet 的文件。如果此服务被终止,将会失去这些功能。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ winmgmt提供共同的界面和对象模式以便访问有关操作系统、设备、应用程序和服务的管理信息。如果此服务被终止,多数基于 Windows 的软件将无法正常运行。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
+ wscsvc监视系统安全设置和配置。Microsoft Corporationc:\windows\system32\svchost.exe
+ wuauserv允许下载并安装 Windows 更新。如果此服务被禁用,计算机将不能使用 Windows Update 网站的自动更新功能。Microsoft Corporationc:\windows\system32\svchost.exe
+ WZCSVC为您的 802.11 适配器提供自动配置Microsoft Corporationc:\windows\system32\svchost.exe
HKLM\System\CurrentControlSet\Services
+ a320raidAdaptec HostRAID for Ultra320 SCSIAdaptec, Inc.c:\windows\system32\drivers\a320raid.sys
+ aar1210Adaptec HostRAID for Serial ATAAdaptec, Inc.c:\windows\system32\drivers\aar1210.sys
+ abp480n5AdvanSys SCSI Controller DriverMicrosoft Corporationc:\windows\system32\drivers\abp480n5.sys
+ ac97intcIntel(r) Integrated Controller Hub Audio DriverIntel Corporationc:\windows\system32\drivers\ac97intc.sys
+ ACPIACPI Driver for NTMicrosoft Corporationc:\windows\system32\drivers\acpi.sys
+ adpu160mAdaptec Ultra160 SCSI miniportMicrosoft Corporationc:\windows\system32\drivers\adpu160m.sys
+ adpu320Adaptec Win2K/XP/Server2003 Ultra320 SCSI DriverAdaptec, Inc.c:\windows\system32\drivers\adpu320.sys
+ aecMicrosoft Acoustic Echo CancellerMicrosoft Corporationc:\windows\system32\drivers\aec.sys
+ aec6210ACARD Technology Corp.c:\windows\system32\drivers\aec6210.sys
+ aec6260ID=0006, 0007ACARD Technology Corp.c:\windows\system32\drivers\aec6260.sys
+ aec6280AEC6280 Miniport DriverACARD Technology Corp.c:\windows\system32\drivers\aec6280.sys
+ AEC6890AEC6880/90 PCI Ultra ATA133 RAID Adapter DriverACARD Technology Corp.c:\windows\system32\drivers\aec6890.sys
+ aec68x5AEC6885/95/96 PCI ATA133 4 Channel RAID Adapter DriverACARD Technology Corp.c:\windows\system32\drivers\aec68x5.sys
+ AFDAFD 网络支持环境Microsoft Corporationc:\windows\system32\drivers\afd.sys
+ agp440440 NT AGP FilterMicrosoft Corporationc:\windows\system32\drivers\agp440.sys
+ Aha154xAdaptec AHA-154x series SCSI miniportMicrosoft Corporationc:\windows\system32\drivers\aha154x.sys
+ aic78u2Adaptec Ultra2 SCSI miniportMicrosoft Corporationc:\windows\system32\drivers\aic78u2.sys
+ aic78xxAdaptec Ultra SCSI miniportMicrosoft Corporationc:\windows\system32\drivers\aic78xx.sys
+ AliIdeALi mini IDE DriverAcer Laboratories Inc.c:\windows\system32\drivers\aliide.sys
+ AmdK7Processor Device DriverMicrosoft Corporationc:\windows\system32\drivers\amdk7.sys
+ amsintAMD SCSI/NET ControllerMicrosoft Corporationc:\windows\system32\drivers\amsint.sys
+ ascAdvanSys SCSI Controller DriverAdvanced System Products, Inc.c:\windows\system32\drivers\asc.sys
+ asc3550AdvanSys Ultra-Wide PCI SCSI DriverAdvanced System Products, Inc.c:\windows\system32\drivers\asc3550.sys
+ AsyncMacRAS Asynchronous Media DriverMicrosoft Corporationc:\windows\system32\drivers\asyncmac.sys
+ atapiIDE/ATAPI Port DriverMicrosoft Corporationc:\windows\system32\drivers\atapi.sys
+ ati2mtagATI Radeon WindowsNT Miniport DriverATI Technologies Inc.c:\windows\system32\drivers\ati2mtag.sys
+ AtmarpcATM ARP Client ProtocolMicrosoft Corporationc:\windows\system32\drivers\atmarpc.sys
+ audstubAudStub DriverMicrosoft Corporationc:\windows\system32\drivers\audstub.sys
+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\windows\system32\drivers\basetdi.sys
+ BridgeMAC Bridge DriverMicrosoft Corporationc:\windows\system32\drivers\bridge.sys
+ BridgeMPMAC Bridge DriverMicrosoft Corporationc:\windows\system32\drivers\bridge.sys
+ cbidfCardBus/PCMCIA IDE Miniport DriverMicrosoft Corporationc:\windows\system32\drivers\cbidf2k.sys
+ CCDECODEWDM Closed Caption VBI CodecMicrosoft Corporationc:\windows\system32\drivers\ccdecode.sys
+ CdromSCSI CD-ROM DriverMicrosoft Corporationc:\windows\system32\drivers\cdrom.sys
+ CmdIdeCMD PCI IDE Bus DriverCMD Technology, Inc.c:\windows\system32\drivers\cmdide.sys
+ cmudaC-Media Audio WDM DriverC-Media Incc:\windows\system32\drivers\cmuda.sys
+ CpqarrayCompaq Drive Array Controllers SCSI Miniport DriverMicrosoft Corporationc:\windows\system32\drivers\cpqarray.sys
+ dac2w2kMylex Disk Array Controller DriverMylex Corporationc:\windows\system32\drivers\dac2w2k.sys
+ dac960ntMylex Disk Array Controller DriverMicrosoft Corporationc:\windows\system32\drivers\dac960nt.sys
+ DiskPnP Disk DriverMicrosoft Corporationc:\windows\system32\drivers\disk.sys
+ dmioNT Disk Manager I/O DriverMicrosoft Corp., Veritas Softwarec:\windows\system32\drivers\dmio.sys
+ dmloadNT Disk Manager Startup DriverMicrosoft Corp., Veritas Software.c:\windows\system32\drivers\dmload.sys
+ DMusicMicrosoft Kernel DLS SynthesizerMicrosoft Corporationc:\windows\system32\drivers\dmusic.sys
+ dpti2oFile not found: System32\DRIVERS\dpti2o.sys
+ drmkaudMicrosoft Kernel DRM Audio Descrambler FilterMicrosoft Corporationc:\windows\system32\drivers\drmkaud.sys
+ dtscsic:\windows\system32\drivers\dtscsi.sys
+ EagleNTFile not found: C:\WINDOWS\system32\drivers\EagleNT.sys
+ EL90XBC3Com EtherLink PCI Driver3Com Corporationc:\windows\system32\drivers\el90xbc5.sys
+ ExpScanerExpScan.sysg:\program files\rising\rav\expscan.sys
+ fasttrakPromise FastTrak Series Driver for WinXPPromise Technology, Inc.c:\windows\system32\drivers\fasttrak.sys
+ fasttx2kPromise Driver for Windows XPPromise Technology, Inc.c:\windows\system32\drivers\fasttx2k.sys
+ fasttx2k2Promise FastTrak Series Driver for WindowsXPPromise Technology, Inc.c:\windows\system32\drivers\fasttx2k2.sys
+ FdcFloppy Disk Controller DriverMicrosoft Corporationc:\windows\system32\drivers\fdc.sys
灵光静z - 2006-5-24 16:26:00
+ FlpydiskFloppy DriverMicrosoft Corporationc:\windows\system32\drivers\flpydisk.sys
+ FsVgaFull Screen Video DriverMicrosoft Corporationc:\windows\system32\drivers\fsvga.sys
+ FtdiskFT Disk DriverMicrosoft Corporationc:\windows\system32\drivers\ftdisk.sys
+ gameenumGame Port EnumeratorMicrosoft Corporationc:\windows\system32\drivers\gameenum.sys
+ GpcGeneric Packet ClassifierMicrosoft Corporationc:\windows\system32\drivers\msgpc.sys
+ hidusbUSB Miniport Driver for Input DevicesMicrosoft Corporationc:\windows\system32\drivers\hidusb.sys
+ HookContTDI HOOK DriverRising tech Co. ltdg:\program files\rising\rav\hookcont.sys
+ HookRegg:\program files\rising\rav\hookreg.sys
+ HookSysHooksysRisingg:\program files\rising\rav\hooksys.sys
+ HookUrlHookUrlBeijing Rising Technology Co., Ltd.g:\program files\rising\rfw\hookurl.sys
+ hpnNetRAID-4M Miniport DriverMicrosoft Corporationc:\windows\system32\drivers\hpn.sys
+ Hpt366ATAPI IDE Miniport DriverMicrosoft Corporationc:\windows\system32\drivers\hpt366.sys
+ HPT371HPT3xx Miniport DriverHighPoint Technologies, Inc.c:\windows\system32\drivers\hpt371.sys
+ hpt374HPT374 Miniport DriverHighPoint Technologies, Inc.c:\windows\system32\drivers\hpt374.sys
+ hpt3xxHPT3xx Miniport DriverHighPoint Technologies, Inc.c:\windows\system32\drivers\hpt3xx.sys
+ hptmvhptmv Miniport DriverHighPoint Technologies, Inc.c:\windows\system32\drivers\hptmv.sys
+ hptproHptproHighPoint Technologies, Inc.c:\windows\system32\drivers\hptpro.sys
+ HTTP此服务实现超文本传送协议(HTTP)。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\drivers\http.sys
+ i2ompI2O Miniport DriverMicrosoft Corporationc:\windows\system32\drivers\i2omp.sys
+ i8042prti8042 Port DriverMicrosoft Corporationc:\windows\system32\drivers\i8042prt.sys
+ iaStorIntel Application Accelerator driverIntel Corporationc:\windows\system32\drivers\iastor.sys
+ ImapiIMAPI Kernel DriverMicrosoft Corporationc:\windows\system32\drivers\imapi.sys
+ ini910uINITIO ini910u SCSI miniportMicrosoft Corporationc:\windows\system32\drivers\ini910u.sys
+ IntelIdeIntel PCI IDE DriverMicrosoft Corporationc:\windows\system32\drivers\intelide.sys
+ intelppmProcessor Device DriverMicrosoft Corporationc:\windows\system32\drivers\intelppm.sys
+ Ip6Fw为家庭或小型办公网络提供入侵保护服务。Microsoft Corporationc:\windows\system32\drivers\ip6fw.sys
+ IpFilterDriverIP Traffic Filter DriverMicrosoft Corporationc:\windows\system32\drivers\ipfltdrv.sys
+ IpInIpIP in IP Tunnel DriverMicrosoft Corporationc:\windows\system32\drivers\ipinip.sys
+ IpNatIP Network Address TranslatorMicrosoft Corporationc:\windows\system32\drivers\ipnat.sys
+ IPSecIPSEC driverMicrosoft Corporationc:\windows\system32\drivers\ipsec.sys
+ IRENUMInfra-Red Bus EnumeratorMicrosoft Corporationc:\windows\system32\drivers\irenum.sys
+ isapnpPNP ISA Bus DriverMicrosoft Corporationc:\windows\system32\drivers\isapnp.sys
+ iteioc:\windows\system32\drivers\iteio.sys
+ iteraidITE IT8212 ATA RAID SCSI miniportIntegrated Technology Express, Inc.c:\windows\system32\drivers\iteraid.sys
+ JiaoCapFile not found: system32\DRIVERS\JiaoCap.sys
+ KbdclassKeyboard Class DriverMicrosoft Corporationc:\windows\system32\drivers\kbdclass.sys
+ kmixerKernel Mode Audio MixerMicrosoft Corporationc:\windows\system32\drivers\kmixer.sys
+ kmsinputc:\windows\system32\drivers\kmsinput.sys
+ m5228M5228 ATA RAID Controller DriverALi Corporation.c:\windows\system32\drivers\m5228.sys
+ m5281M5281 SATA RAID Controller DriverALi Corporationc:\windows\system32\drivers\m5281.sys
+ MegaIDELSI MegaRAID IDE DriverLSI Logic Corporation.c:\windows\system32\drivers\megaide.sys
+ MEMSCANMemScan Driver瑞星软件有限公司g:\program files\rising\rav\memscan.sys
+ MouclassMouse Class DriverMicrosoft Corporationc:\windows\system32\drivers\mouclass.sys
+ mouhidHID Mouse Filter DriverMicrosoft Corporationc:\windows\system32\drivers\mouhid.sys
+ mProcRsRising Personal FireWall mprocrs.sysBeijing Rising Technology Co., Ltd.g:\program files\rising\rfw\mprocrs.sys
+ mraid2kMEGARAID SCSI Controller Driver for Windows 2000 PAEAmerican Megatrends, Inc.c:\windows\system32\drivers\mraid2k.sys
+ mraid35xMegaRAID RAID Controller Driver for Windows Whistler 32American Megatrends Inc.c:\windows\system32\drivers\mraid35x.sys
+ ms_mpu401MPU401 Adapter DriverMicrosoft Corporationc:\windows\system32\drivers\msmpu401.sys
+ MSKSSRVMS KS ServerMicrosoft Corporationc:\windows\system32\drivers\mskssrv.sys
+ MSPCLOCKMS Proxy ClockMicrosoft Corporationc:\windows\system32\drivers\mspclock.sys
+ MSPQMMS Proxy Quality ManagerMicrosoft Corporationc:\windows\system32\drivers\mspqm.sys
+ mssmbiosSystem Management BIOS DriverMicrosoft Corporationc:\windows\system32\drivers\mssmbios.sys
+ MSTEEWDM Tee/Communication Transform Filter Microsoft Corporationc:\windows\system32\drivers\mstee.sys
+ NABTSFECWDM NABTS/FEC VBI CodecMicrosoft Corporationc:\windows\system32\drivers\nabtsfec.sys
+ NdisIPMicrosoft IP DriverMicrosoft Corporationc:\windows\system32\drivers\ndisip.sys
+ NdisTapiRemote Access NDIS TAPI DriverMicrosoft Corporationc:\windows\system32\drivers\ndistapi.sys
+ NdisuioNDIS 用户模式 I/O 协议Microsoft Corporationc:\windows\system32\drivers\ndisuio.sys
+ NdisWanRemote Access NDIS WAN DriverMicrosoft Corporationc:\windows\system32\drivers\ndiswan.sys
+ NetBTNetBios over TcpipMicrosoft Corporationc:\windows\system32\drivers\netbt.sys
+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.g:\program files\tencent\qq\npkcrypt.sys
+ npkycrypFile not found: G:\Program Files\Tencent\qq\npkycryp.sys
+ NwlnkFltIPX Traffic Filter DriverMicrosoft Corporationc:\windows\system32\drivers\nwlnkflt.sys
+ NwlnkFwdIPX Traffic Forwarder DriverMicrosoft Corporationc:\windows\system32\drivers\nwlnkfwd.sys
+ NwlnkIpxNWLink IPX/SPX/NetBIOS Compatible Transport ProtocolMicrosoft Corporationc:\windows\system32\drivers\nwlnkipx.sys
+ NwlnkNbNWLink NetBIOSMicrosoft Corporationc:\windows\system32\drivers\nwlnknb.sys
+ NwlnkSpxNWLink SPX/SPXII ProtocolMicrosoft Corporationc:\windows\system32\drivers\nwlnkspx.sys
+ P3Processor Device DriverMicrosoft Corporationc:\windows\system32\drivers\p3.sys
+ ParportParallel Port DriverMicrosoft Corporationc:\windows\system32\drivers\parport.sys
+ PCINT Plug and Play PCI EnumeratorMicrosoft Corporationc:\windows\system32\drivers\pci.sys
+ PCIIdeGeneric PCI IDE Bus DriverMicrosoft Corporationc:\windows\system32\drivers\pciide.sys
+ perc2PERC 2 Miniport DriverMicrosoft Corporationc:\windows\system32\drivers\perc2.sys
+ perc2hibPERC 2 Hibernate DriverMicrosoft Corporationc:\windows\system32\drivers\perc2hib.sys
+ Pnp680DMA capable ATA miniport driverSilicon Image, Inc.c:\windows\system32\drivers\pnp680.sys
+ Pnp680rDMA capable ATA RAID miniport driver Silicon Image, Incc:\windows\system32\drivers\pnp680r.sys
+ PptpMiniportWAN Miniport (PPTP)Microsoft Corporationc:\windows\system32\drivers\raspptp.sys
+ ProcessorProcessor Device DriverMicrosoft Corporationc:\windows\system32\drivers\processr.sys
+ prodrv06StarForce Protection Environment DriverProtection Technologyc:\windows\system32\drivers\prodrv06.sys
+ prohlp02StarForce Protection Helper DriverProtection Technologyc:\windows\system32\drivers\prohlp02.sys
+ prosync1StarForce Protection Synchronization DriverProtection Technologyc:\windows\system32\drivers\prosync1.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.
© 2000 - 2026 Rising Corp. Ltd.