$马后炮$ - 2006-8-24 11:41:00
大家好!
我刚开机每3分钟弹出8次以上的程序错误报告“WinMgmt.exe产生了错误,会被Windows关闭。您需要重新启动程序。”毫无疑问中毒了。升级瑞星杀毒软件到最新版本(18.41.30)。在安全模式下查杀,没发现病毒。另我意想不到的事 在查毒中查到路径(Harddisk2\Msin Boot)时软件停了下来。搞什么?自动弹出安装界面“(Outlook 2003启动)欢迎使用Outlook 2003启动向导,您完成Outlook 2003的配置过程。”在安全模式下结果一样。
请问这是什么病毒?
以下是我用了瑞星公司提供的(autoruns。exe)软件,提取出可疑文件并生成扫描日志。请大家帮忙看看。
$马后炮$ - 2006-8-24 11:43:00
gon\Userinit
+ C:\WINNT\system32\userinit.exeUserinit Logon ApplicationMicrosoft Corporationc:\winnt\system32\userinit.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
+ Explorer.exeWindows ExplorerMicrosoft Corporationc:\winnt\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ CdnCtrLiveUpdate Modulec:\program files\cnnic\cdn\cdnup.exe
+ HotKeysCmdshkcmd ModuleIntel Corporationc:\winnt\system32\hkcmd.exe
+ IgfxTrayigfxTray ModuleIntel Corporationc:\winnt\system32\igfxtray.exe
+ IMSCMig微软拼音输入法安装工具Microsoft Corporationc:\program files\common files\microsoft shared\ime\imsc40a\imscmig.exe
+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe
+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwmain.exe
+ SoundManAvance Sound ManagerAvance Logic, Inc.C:\WINNT\soundman.exe
+ Synchronization ManagerMicrosoft Synchronization ManagerMicrosoft Corporationc:\winnt\system32\mobsync.exe
C:\Documents and Settings\Administrator\「开始」菜单\程序\启动
+ Rc:\documents and settings\administrator\「开始」菜单\程序\启动\rsautorunsdisabled
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
+ ctfmon.exeCicero LoaderMicrosoft Corporationc:\winnt\system32\ctfmon.exe
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
+ Address Book 5Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe
+ CRLUpdateUPDCRLMicrosoft Corporationc:\winnt\system32\updcrl.exe
+ EnableRevocationMicrosoft(C) Register ServerMicrosoft Corporationc:\winnt\system32\regsvr32.exe
+ Internet Explorer 6IE 5.0 Per-User Install UtilityMicrosoft Corporationc:\winnt\system32\ie4uinit.exe
+ Internet Explorer 访问Windows NT User Data Migration ToolMicrosoft Corporationc:\winnt\system32\shmgrate.exe
+ Microsoft Outlook Express 6Outlook Express Setup LibraryMicrosoft Corporationc:\program files\outlook express\setup50.exe
+ Microsoft Windows Media PlayerMicrosoft Windows Media Player 安装实用程序Microsoft Corporationc:\winnt\inf\unregmp2.exe
+ Microsoft Windows Media PlayerADVPACKMicrosoft Corporationc:\winnt\system32\advpack.dll
+ NetMeeting 3.01ADVPACKMicrosoft Corporationc:\winnt\system32\advpack.dll
+ Outlook Express 访问Windows NT User Data Migration ToolMicrosoft Corporationc:\winnt\system32\shmgrate.exe
+ Windows 桌面更新Microsoft(C) Register ServerMicrosoft Corporationc:\winnt\system32\regsvr32.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
+ Browseui 预加载程序Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 组件类别缓存程序Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
+ DVDBurnFile not found: C:\WINNT\Downloaded Program Files\AfxEdit.dll
+ Network.ConnectionTrayNetwork Connections ShellMicrosoft Corporationc:\winnt\system32\netshell.dll
+ SysTraySystray shell service objectMicrosoft Corporationc:\winnt\system32\stobject.dll
+ WebCheckWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
+ jhcmd2.dllFile not found: C:\WINNT\system32\jhcmd2.dll
+ Rising Execute File Exts hookRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt\system32\ravext.dll
+ svchost.dllFile not found: C:\WINNT\system32\svchost.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ .CAB file viewerCabinet File Viewer Shell ExtensionMicrosoft Corporationc:\winnt\system32\cabview.dll
+ ActiveDesktopWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ ActiveX 高速缓存文件夹Object Control ViewerMicrosoft Corporationc:\winnt\system32\occache.dll
+ aKooWoMenuKooWoMenu DLLc:\program files\koowo\mp3partner\rbm.dll
+ BandProxyShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ Briefcase FolderWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ CDF Extension Copy HookShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
+ Channel MenuChannel Definition File ViewerMicrosoft Corporationc:\winnt\system32\cdfview.dll
+ Channel PropertiesChannel Definition File ViewerMicrosoft Corporationc:\winnt\system32\cdfview.dll
+ CmdFileIconWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ Code Download AgentWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll
+ ConnectionAgentWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll
+ Crypto PKO ExtensionCrypto Shell ExtensionsMicrosoft Corporationc:\winnt\system32\cryptext.dll
+ Crypto Sign ExtensionCrypto Shell ExtensionsMicrosoft Corporationc:\winnt\system32\cryptext.dll
+ Darwin App PublisherShell Application ManagerMicrosoft Corporationc:\winnt\system32\appwiz.cpl
+ Directory Context Menu VerbsDirectory Service Common UIMicrosoft Corporationc:\winnt\system32\dsuiext.dll
+ Directory NamespaceDirectory Service UIMicrosoft Corporationc:\winnt\system32\dsfolder.dll
+ Directory Object FindDirectory Service FindMicrosoft Corporationc:\winnt\system32\dsquery.dll
+ Directory Property UIDirectory Service Common UIMicrosoft Corporationc:\winnt\system32\dsuiext.dll
+ Directory Query UIDirectory Service FindMicrosoft Corporationc:\winnt\system32\dsquery.dll
+ Directory Start/Search FindDirectory Service FindMicrosoft Corporationc:\winnt\system32\dsquery.dll
+ Disk Copy ExtensionWindows DiskCopyMicrosoft Corporationc:\winnt\system32\diskcopy.dll
+ Disk Quota UIWindows Shell Disk Quota UI DLLMicrosoft Corporationc:\winnt\system32\dskquoui.dll
+ Display Adapter CPL ExtensionAdvanced display adapter propertiesMicrosoft Corporationc:\winnt\system32\deskadp.dll
+ Display Control Panel HTML ExtensionsWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ Display Monitor CPL ExtensionAdvanced display monitor propertiesMicrosoft Corporationc:\winnt\system32\deskmon.dll
+ Display Panning CPL ExtensionFile not found: deskpan.dll
+ Display TroubleShoot CPL ExtensionAdvanced display performance propertiesMicrosoft Corporationc:\winnt\system32\deskperf.dll
+ DS Security PageDirectory Service Security UIMicrosoft Corporationc:\winnt\system32\dssec.dll
+ Favorites BandShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
+ File Property Page ExtensionWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ File Types PageWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ Folder Options Property Page ExtensionWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ Fusion CacheMicrosoft .NET Runtime Execution EngineMicrosoft Corporationc:\winnt\system32\mscoree.dll
+ HTML 缩略图的解压缩程序Thumbnail View ExtensionMicrosoft Corporationc:\winnt\system32\thumbvw.dll
+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\winnt\system32\hticons.dll
+ ICC 配置文件Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\winnt\system32\icmui.dll
+ ICM 打印机管理Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\winnt\system32\icmui.dll
+ ICM 监视器管理Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\winnt\system32\icmui.dll
+ ICM 扫描仪管理Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\winnt\system32\icmui.dll
+ IE4 套件初始屏幕Shell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
+ Installed Apps EnumeratorShell Application ManagerMicrosoft Corporationc:\winnt\system32\appwiz.cpl
+ InternetShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
+ Internet Name SpaceShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
+ Internet 临时文件Shell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
+ Internet 临时文件Shell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
+ InternetShortcutShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
+ ISFBand OCShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
+ IShellFolderBandShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ LNK 文件缩略图接口代理程序Thumbnail View ExtensionMicrosoft Corporationc:\winnt\system32\thumbvw.dll
+ Microsoft AutoCompleteShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ Microsoft Browser ArchitectureShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
+ Microsoft BrowserBandShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ Microsoft CopyTo ServiceWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ Microsoft Internet 工具栏Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ Microsoft MoveTo ServiceWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ Microsoft New Object ServiceWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
$马后炮$ - 2006-8-24 11:44:00
+ Microsoft Office HTML Icon HandlerMicrosoft Office 2003 componentMicrosoft Corporationc:\program files\microsoft office\office11\msohev.dll
+ Microsoft Office Outlook Custom Icon HandlerOutlook Shell Hook for Start/FindMicrosoft Corporationc:\program files\microsoft office\office11\olkfstub.dll
+ Microsoft Office Outlook Desktop Icon HandlerMicrosoft Shell Extension LibraryMicrosoft Corporationc:\program files\microsoft office\office11\mlshext.dll
+ Microsoft SendTo ServiceWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ Microsoft Url History 服务Shell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
+ Microsoft Url 搜索挂接Shell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
+ Microsoft 多个自动完成列表容器Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ Microsoft 历史自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ Microsoft 数据链接Microsoft Data Access - OLE DB Core ServicesMicrosoft Corporationc:\program files\common files\system\ole db\oledb32.dll
+ Microsoft 外壳文件夹自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ MIME File Types HookWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ MMC Icon HandlerMMC Shell Extension DLLMicrosoft Corporationc:\winnt\system32\mmcshext.dll
+ MRU 自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ Multimedia File Property SheetControl Panel Drivers AppletMicrosoft Corporationc:\winnt\system32\mmsys.cpl
+ MyDocs Copy HookMy Documents Folder UIMicrosoft Corporationc:\winnt\system32\mydocs.dll
+ MyDocs Drop TargetMy Documents Folder UIMicrosoft Corporationc:\winnt\system32\mydocs.dll
+ MyDocs FolderMy Documents Folder UIMicrosoft Corporationc:\winnt\system32\mydocs.dll
+ MyDocs PropertiesMy Documents Folder UIMicrosoft Corporationc:\winnt\system32\mydocs.dll
+ NTFS Security PageSecurity Shell ExtensionMicrosoft Corporationc:\winnt\system32\rshx32.dll
+ Office 图形筛选器缩略图的解压缩程序Thumbnail View ExtensionMicrosoft Corporationc:\winnt\system32\thumbvw.dll
+ Offline Files Folder OptionsClient Side Caching UIMicrosoft Corporationc:\winnt\system32\cscui.dll
+ Offline Files MenuClient Side Caching UIMicrosoft Corporationc:\winnt\system32\cscui.dll
+ OLE Docfile Property PageOLE DocFile Property PageMicrosoft Corporationc:\winnt\system32\docprop.dll
+ Open With Context Menu HandlerWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ PlusPack CPL ExtensionEffects Control Panel extensionMicrosoft Corporationc:\winnt\system32\plustab.dll
+ PostAgentWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll
+ Printers Security PageSecurity Shell ExtensionMicrosoft Corporationc:\winnt\system32\rshx32.dll
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt\system32\ravext.dll
+ Search Assistant OCShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
+ Sendmail serviceSend MailMicrosoft Corporationc:\winnt\system32\sendmail.dll
+ Sendmail serviceSend MailMicrosoft Corporationc:\winnt\system32\sendmail.dll
+ Shell Application ManagerShell Application ManagerMicrosoft Corporationc:\winnt\system32\appwiz.cpl
+ Shell Automation Folder ViewWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ Shell Automation Inproc ServiceShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
+ Shell Automation ServiceWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ Shell Band Site MenuShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ Shell DocObject ViewerShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
+ Shell Drag and Drop helperWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ Shell extensions for Microsoft Windows Network objectsNetwork object shell UIMicrosoft Corporationc:\winnt\system32\ntlanui2.dll
+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realplayer\rpshell.dll
+ Shell extensions for sharingShell extensions for sharingMicrosoft Corporationc:\winnt\system32\ntshrui.dll
+ Shell extensions for sharingShell extensions for sharingMicrosoft Corporationc:\winnt\system32\ntshrui.dll
+ Shell Favorite FolderWindows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ Shell properties for a DS objectDirectory Service UIMicrosoft Corporationc:\winnt\system32\dsfolder.dll
+ Shell Scrap DataHandlerShell scrap object handlerMicrosoft Corporationc:\winnt\system32\shscrap.dll
+ Subscription MgrWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll
+ Tasks Folder Icon HandlerTask Scheduler interface DLLMicrosoft Corporationc:\winnt\system32\mstask.dll
+ Tasks Folder Shell ExtensionTask Scheduler interface DLLMicrosoft Corporationc:\winnt\system32\mstask.dll
+ TrayAgentWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll
+ TridentImageExtractorShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ Web FoldersMicrosoft Web FoldersMicrosoft Corporationc:\program files\common files\microsoft shared\web folders\msonsext.dll
+ Web Printer Shell ExtensionPrint UI DLLMicrosoft Corporationc:\winnt\system32\printui.dll
+ Web 搜索Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ WebCheckWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll
+ WebCheck SyncMgr HandlerWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll
+ WebCheckChannelAgentWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll
+ WebCheckWebCrawlerWeb Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll
+ Windows Script Host 的 Shell extensionsMicrosoft (R) Shell Extension for Windows 脚本宿主Microsoft Corporationc:\winnt\system32\wshext.dll
+ WinRAR shell extensionc:\program files\winrar\rarext.dll
+ 补充的外壳文件夹Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 补充的外壳文件夹 2Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 菜单条Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 菜单外壳文件夹Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 菜单站点Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 菜单桌面栏Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 窗格中的搜索Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 地址 EditBoxShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 地址(&A)Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 地址条解析程序Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 跟踪弹出栏Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 跟踪外壳菜单Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 公文包Windows BriefcaseMicrosoft Corporationc:\winnt\system32\syncui.dll
+ 将加密项添加到资源管理器的上下文菜单中Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ 开始菜单Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ 可访问的Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 历史记录Shell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
+ 链接(&L)Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 媒体区Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 频道句柄对象Channel Definition File ViewerMicrosoft Corporationc:\winnt\system32\cdfview.dll
+ 频道快捷方式Channel Definition File ViewerMicrosoft Corporationc:\winnt\system32\cdfview.dll
+ 频道文件Channel Definition File ViewerMicrosoft Corporationc:\winnt\system32\cdfview.dll
+ 全局文件夹设置Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 任务计划Task Scheduler interface DLLMicrosoft Corporationc:\winnt\system32\mstask.dll
+ 搜索区Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 缩略图Thumbnail View ExtensionMicrosoft Corporationc:\winnt\system32\thumbvw.dll
+ 脱机文件夹Client Side Caching UIMicrosoft Corporationc:\winnt\system32\cscui.dll
+ 外壳 DeskBarShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 外壳 DeskBarAppShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 外壳 Rebar BandSiteShell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
$马后炮$ - 2006-8-24 11:46:00
+ 网络和拨号连接Network Connections ShellMicrosoft Corporationc:\winnt\system32\netshell.dll
+ 微缩图图像Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 文件夹快捷方式Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ 我的电脑Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ 下载状态Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 已装好的卷Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ 用户(&P)...Find PeopleMicrosoft Corporationc:\program files\outlook express\wabfind.dll
+ 用户帮助Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 预订文件夹Web Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll
+ 摘要信息缩略图处理程序(DOCFILES)Thumbnail View ExtensionMicrosoft Corporationc:\winnt\system32\thumbvw.dll
+ 注册数目路选项实用程序Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 自定义 MRU 自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 字体Windows Font FolderMicrosoft Corporationc:\winnt\system32\fontext.dll
+ 浏览器栏Shell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
HKLM\Software\Classes\Folder\Shellex\ColumnHandlers
+ Fax Tiff Data Column ProviderFax Tiff Data Column ProviderMicrosoft Corporationc:\winnt\system32\faxshell.dll
+ ShAVColumnProvider classDocProp2Microsoft Corporationc:\winnt\system32\docprop2.dll
+ Version Column ProviderDocProp2Microsoft Corporationc:\winnt\system32\docprop2.dll
+ {0D2E74C4-3C34-11d2-A27E-00C04FC30871}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ {24F14F01-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ {24F14F02-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ BandIE ClassBaiduBar ModuleBaidu.com, Inc.c:\program files\baidu\bar\baidubar.dll
+ CdnForIE ClassCdnForIECNNICc:\program files\cnnic\cdn\cdnforie.dll
+ QQBrowserHelperObject ClassQQIEHelper Module深圳市腾讯计算机系统有限公司c:\program files\tencent\qq\qqiehelper.dll
+ Thunder Browser HelperXunLeiBHOThunder Networking Technologies,LTDc:\program files\thunder network\thunder\comdlls\xunleibho_002.dll
+ WMHlprObj ClassCNNIC Web Mail for WindowsCNNICc:\program files\cnnic\cdn\wmhlpr.dll
+ {81D1B74C-9531-4D2B-9F49-A236F4930609}showbar Modulec:\program files\common files\yygamenet\showbar.dll
+ 上网助手CoolBar3721c:\program files\3721\assist\asbar.dll
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
+ coolbarCoolBar3721c:\program files\3721\assist\asbar.dll
+ shdocvw.dllShell Doc Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ BitComet工具栏BitComet Toolbar for IEc:\program files\bitcomet\bitcometbar\bitcometbar0.6.dll
+ ietoolforleft.dllIELeftToolBar Modulec:\program files\common files\yygamenet\ietoolforleft.dll
+ 上网助手CoolBar3721c:\program files\3721\assist\asbar.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ @shdoclc.dll,-864c:\winnt\web\related.htm
+ Yahoo! Messengerc:\program files\yahoo!\messenger\ypager.exe
+ 腾讯QQQQTENCENTc:\program files\tencent\qq\qq.exe
Task Scheduler
+ DM_Install_Program.jobdmremotesetup1000 Oaksc:\documents and settings\administrator\local settings\temp\102084.exe
HKLM\System\CurrentControlSet\Services
+ Browser维护网络上计算机的最新列表以及提供这个列表给请求的程序。Microsoft Corporationc:\winnt\system32\services.exe
+ Dhcp通过注册和更改 IP 地址以及 DNS 名称来管理网络配置。Microsoft Corporationc:\winnt\system32\services.exe
+ dmserver逻辑磁盘管理器监视狗服务Microsoft Corporationc:\winnt\system32\services.exe
+ Dnscache解析和缓冲域名系统 (DNS) 名称。Microsoft Corporationc:\winnt\system32\services.exe
+ Eventlog记录程序和 Windows 发送的事件消息。事件日志包含对诊断问题有所帮助的信息。您可以在“事件查看器”中查看报告。Microsoft Corporationc:\winnt\system32\services.exe
+ lanmanserver提供 RPC 支持、文件、打印以及命名管道共享。Microsoft Corporationc:\winnt\system32\services.exe
+ lanmanworkstation提供网络链结和通讯。Microsoft Corporationc:\winnt\system32\services.exe
+ LmHosts允许对“TCP/IP 上 NetBIOS (NetBT)”服务以及 NetBIOS 名称解析的支持。Microsoft Corporationc:\winnt\system32\services.exe
+ NtmsSvc管理可移动媒体、驱动程序和库。Microsoft Corporationc:\winnt\system32\svchost.exe
+ PlugPlay管理设备安装以及配置,并且通知程序关于设备更改的情况。Microsoft Corporationc:\winnt\system32\services.exe
+ PolicyAgent管理 IP 安全策略以及启动 ISAKMP/Oakley (IKE) 和 IP 安全驱动程序。Microsoft Corporationc:\winnt\system32\lsass.exe
+ ProtectedStorage提供对敏感数据(如私钥)的保护性存储,以便防止未授权的服务,过程或用户对其的非法访问。Microsoft Corporationc:\winnt\system32\services.exe
+ RemoteRegistry允许远程注册表操作。Microsoft Corporationc:\winnt\system32\regsvc.exe
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwsrv.exe
+ RpcSs提供终结点映射程序 (endpoint mapper) 以及其它 RPC 服务。Microsoft Corporationc:\winnt\system32\svchost.exe
+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe
+ SamSs存储本地用户帐户的安全信息。Microsoft Corporationc:\winnt\system32\lsass.exe
+ Schedule允许程序在指定时间运行。Microsoft Corporationc:\winnt\system32\mstask.exe
+ seclogon在不同凭据下启用启动过程Microsoft Corporationc:\winnt\system32\services.exe
+ SENS跟踪系统事件,如登录 Windows,网络以及电源事件等。将这些事件通知给 COM+ 事件系统 “订阅者(subscriber)”。Microsoft Corporationc:\winnt\system32\svchost.exe
+ Spooler将文件加载到内存中以便迟后打印。Microsoft Corporationc:\winnt\system32\spoolsv.exe
+ svchost从 Windows Update 启用重要的 Windows 更新的下载和安装。如果禁用该服务,操作系统将无法升级c:\winnt\svchost.exe
+ TrkWks当文件在网络域的 NTFS 卷中移动时发送通知。Microsoft Corporationc:\winnt\system32\services.exe
+ WinMgmt提供系统管理信息。Microsoft Corporationc:\winnt\system32\wbem\winmgmt.exe
+ wuauserv从 Windows Update 启用重要的 Windows 更新的下载和安装。如果禁用该服务,操作系统可以在 Windows Update 网站手动更新。Microsoft Corporationc:\winnt\system32\svchost.exe
HKLM\System\CurrentControlSet\Services
+ ACPIACPI Driver for NTMicrosoft Corporationc:\winnt\system32\drivers\acpi.sys
+ AFDAncillary Function Driver for WinSockMicrosoft Corporationc:\winnt\system32\drivers\afd.sys
+ ALCXWDMAvance AC'97 Audio Driver (WDM)Avance Logic, Inc.c:\winnt\system32\drivers\alcxwdm.sys
+ AsyncMacRAS Asynchronous Media DriverMicrosoft Corporationc:\winnt\system32\drivers\asyncmac.sys
+ atapiIDE/ATAPI Port DriverMicrosoft Corporationc:\winnt\system32\drivers\atapi.sys
+ AtmarpcATM ARP Client ProtocolMicrosoft Corporationc:\winnt\system32\drivers\atmarpc.sys
+ audstubAudStub DriverMicrosoft Corporationc:\winnt\system32\drivers\audstub.sys
+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\winnt\system32\drivers\basetdi.sys
+ ccdecodeWDM Closed Caption VBI CodecMicrosoft Corporationc:\winnt\system32\drivers\ccdecode.sys
+ cdnprot中国互联网络信息中心(CNNIC)c:\winnt\system32\drivers\cdnprot.sys
+ cdntrancdntranCNNICc:\winnt\system32\drivers\cdntran.sys
+ CdromSCSI CD-ROM DriverMicrosoft Corporationc:\winnt\system32\drivers\cdrom.sys
+ DiskPnP Disk DriverMicrosoft Corporationc:\winnt\system32\drivers\disk.sys
+ dmioNT Disk Manager I/O DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmio.sys
+ dmloadNT Disk Manager Startup DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmload.sys
+ DMusicMicrosoft DirectMusic Software Synthesizer (WDM)Microsoft Corporationc:\winnt\system32\drivers\dmusic.sys
+ eehgefee中国互联网络信息中心(CNNIC)c:\winnt\system32\drivers\eehgefee.sys
+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys
+ FdcFloppy Disk Controller DriverMicrosoft Corporationc:\winnt\system32\drivers\fdc.sys
+ FsVgaFull Screen Video DriverMicrosoft Corporationc:\winnt\system32\drivers\fsvga.sys
+ FtdiskFT Disk DriverMicrosoft Corporationc:\winnt\system32\drivers\ftdisk.sys
+ gameenumGame Port EnumeratorMicrosoft Corporationc:\winnt\system32\drivers\gameenum.sys
+ GpcGeneric Packet ClassifierMicrosoft Corporationc:\winnt\system32\drivers\msgpc.sys
+ hacfbjbc中国互联网络信息中心(CNNIC)c:\winnt\system32\drivers\hacfbjbc.sys
+ HidUsbUSB Miniport Driver for Input DevicesMicrosoft Corporationc:\winnt\system32\drivers\hidusb.sys
+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys
+ HookRegc:\program files\rising\rav\hookreg.sys
+ HookSysHooksysRisingc:\program files\rising\rav\hooksys.sys
+ HookUrlHookUrlBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\hookurl.sys
+ i8042prti8042 Port DriverMicrosoft Corporationc:\winnt\system32\drivers\i8042prt.sys
+ i81xMiniport Driver for Intel Graphics DriverIntel(R) Corporationc:\winnt\system32\drivers\i81xnt5.sys
+ IntelIdeIntel PCI IDE DriverMicrosoft Corporationc:\winnt\system32\drivers\intelide.sys
+ IpFilterDriverIP Traffic Filter DriverMicrosoft Corporationc:\winnt\system32\drivers\ipfltdrv.sys
+ IpInIpIP in IP Tunnel DriverMicrosoft Corporationc:\winnt\system32\drivers\ipinip.sys
+ IpNatIP Network Address TranslatorMicrosoft Corporationc:\winnt\system32\drivers\ipnat.sys
+ IPSECIPSEC driverMicrosoft Corporationc:\winnt\system32\drivers\ipsec.sys
+ IRENUMInfra-Red Bus EnumeratorMicrosoft Corporationc:\winnt\system32\drivers\irenum.sys
+ isapnpPNP ISA Bus DriverMicrosoft Corporationc:\winnt\system32\drivers\isapnp.sys
+ KbdclassKeyboard Class DriverMicrosoft Corporationc:\winnt\system32\drivers\kbdclass.sys
+ kmixerKernel Mode Audio MixerMicrosoft Corporationc:\winnt\system32\drivers\kmixer.sys
+ kmsinputc:\winnt\system32\drivers\kmsinput.sys
$马后炮$ - 2006-8-24 11:47:00
+ MEMSCANMemScan Driver瑞星软件有限公司c:\program files\rising\rav\memscan.sys
+ MouclassMouse Class DriverMicrosoft Corporationc:\winnt\system32\drivers\mouclass.sys
+ mouhidHID Mouse Filter DriverMicrosoft Corporationc:\winnt\system32\drivers\mouhid.sys
+ MPEMicrosoft MPE to IP FilterMicrosoft Corporationc:\winnt\system32\drivers\mpe.sys
+ mProcRsRising Personal FireWall mprocrs.sysBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\mprocrs.sys
+ ms_mpu401MPU401 Adapter DriverMicrosoft Corporationc:\winnt\system32\drivers\msmpu401.sys
+ MSKSSRVMS KS ServerMicrosoft Corporationc:\winnt\system32\drivers\mskssrv.sys
+ MSPCLOCKMS Proxy ClockMicrosoft Corporationc:\winnt\system32\drivers\mspclock.sys
+ MSPQMMS Proxy Quality ManagerMicrosoft Corporationc:\winnt\system32\drivers\mspqm.sys
+ MSTEEWDM Tee/Communication Transform Filter Microsoft Corporationc:\winnt\system32\drivers\mstee.sys
+ NABTSFECWDM NABTS/FEC VBI CodecMicrosoft Corporationc:\winnt\system32\drivers\nabtsfec.sys
+ NdisTapiRemote Access NDIS TAPI DriverMicrosoft Corporationc:\winnt\system32\drivers\ndistapi.sys
+ NdisuioNDIS 用户模式 I/O 协议Microsoft Corporationc:\winnt\system32\drivers\ndisuio.sys
+ NdisWanRemote Access NDIS WAN DriverMicrosoft Corporationc:\winnt\system32\drivers\ndiswan.sys
+ NetBTNetBios over TcpipMicrosoft Corporationc:\winnt\system32\drivers\netbt.sys
+ NetDetectNetwork Card Detection driverMicrosoft Corporationc:\winnt\system32\drivers\netdtect.sys
+ NPFnpfCACE Technologiesc:\winnt\system32\drivers\npf.sys
+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.c:\program files\tencent\qq\npkcrypt.sys
+ NwlnkFltIPX Traffic Filter DriverMicrosoft Corporationc:\winnt\system32\drivers\nwlnkflt.sys
+ NwlnkFwdIPX Traffic Forwarder DriverMicrosoft Corporationc:\winnt\system32\drivers\nwlnkfwd.sys
+ ParallelParallel Printer DriverMicrosoft Corporationc:\winnt\system32\drivers\parallel.sys
+ ParportParallel Port DriverMicrosoft Corporationc:\winnt\system32\drivers\parport.sys
+ PCINT Plug and Play PCI EnumeratorMicrosoft Corporationc:\winnt\system32\drivers\pci.sys
+ PCIIdeGeneric PCI IDE Bus DriverMicrosoft Corporationc:\winnt\system32\drivers\pciide.sys
+ PptpMiniportWAN Miniport (PPTP)Microsoft Corporationc:\winnt\system32\drivers\raspptp.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\winnt\system32\drivers\ptilink.sys
+ RasAcdRemote Access Auto Connection DriverMicrosoft Corporationc:\winnt\system32\drivers\rasacd.sys
+ Rasl2tpWAN Miniport (L2TP)Microsoft Corporationc:\winnt\system32\drivers\rasl2tp.sys
+ RasptiDirect ParallelMicrosoft Corporationc:\winnt\system32\drivers\raspti.sys
+ RCARCA filterMicrosoft Corporationc:\winnt\system32\drivers\rca.sys
+ redbookRedbook Audio Filter DriverMicrosoft Corporationc:\winnt\system32\drivers\redbook.sys
+ RsFwDrvnt_fwdrvBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rsfwdrv.sys
+ rtl8139NDIS 5.0 driver Realtek Semiconductor Corporation c:\winnt\system32\drivers\rtl8139.sys
+ serenumSerial Port EnumeratorMicrosoft Corporationc:\winnt\system32\drivers\serenum.sys
+ SerialSerial Device DriverMicrosoft Corporationc:\winnt\system32\drivers\serial.sys
+ SLIPMicrosoft Slip Deframing Filter MinidriverMicrosoft Corporationc:\winnt\system32\drivers\slip.sys
+ streamipMicrosoft IP DriverMicrosoft Corporationc:\winnt\system32\drivers\streamip.sys
+ swenumPlug and Play Software Device EnumeratorMicrosoft Corporationc:\winnt\system32\drivers\swenum.sys
+ swmidiMicrosoft GS Wavetable SynthesizerMicrosoft Corporationc:\winnt\system32\drivers\swmidi.sys
+ sysaudioSystem Audio WDM FilterMicrosoft Corporationc:\winnt\system32\drivers\sysaudio.sys
+ TcpipTCP/IP Protocol DriverMicrosoft Corporationc:\winnt\system32\drivers\tcpip.sys
+ uhcdUniversal Host Controller DriverMicrosoft Corporationc:\winnt\system32\drivers\uhcd.sys
+ UpdateUpdate DriverMicrosoft Corporationc:\winnt\system32\drivers\update.sys
+ usbhubDefault Hub Driver for USBMicrosoft Corporationc:\winnt\system32\drivers\usbhub.sys
+ USBSTORUSB Mass Storage Class DriverMicrosoft Corporationc:\winnt\system32\drivers\usbstor.sys
+ VgaSaveVGA/Super VGA Video DriverMicrosoft Corporationc:\winnt\system32\drivers\vga.sys
+ voodoo33Dfx Voodoo 3 Miniport Driver3Dfx Interactive, Inc.c:\winnt\system32\drivers\voodoo3.sys
+ WanarpRemote Access IP ARP DriverMicrosoft Corporationc:\winnt\system32\drivers\wanarp.sys
+ wdmaudMMSYSTEM Wave/Midi API mapperMicrosoft Corporationc:\winnt\system32\drivers\wdmaud.sys
+ WSTCODECWDM WST Codec DriverMicrosoft Corporationc:\winnt\system32\drivers\wstcodec.sys
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
+ autocheck autochk *Auto Check UtilityMicrosoft Corporationc:\winnt\system32\autochk.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
+ Your Image File Name Here without a pathSymbolic Debugger for Windows 2000Microsoft Corporationc:\winnt\system32\ntsd.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls
+ KB914847M.LOGFile not found: KB914847M.LOG
HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls
+ advapi32Advanced Windows 32 Base APIMicrosoft Corporationc:\winnt\system32\advapi32.dll
+ comdlg32Common Dialogs DLLMicrosoft Corporationc:\winnt\system32\comdlg32.dll
+ gdi32GDI Client DLLMicrosoft Corporationc:\winnt\system32\gdi32.dll
+ imagehlpWindows NT Image HelperMicrosoft Corporationc:\winnt\system32\imagehlp.dll
+ kernel32Windows NT BASE API Client DLLMicrosoft Corporationc:\winnt\system32\kernel32.dll
+ lz32LZ Expand/Compress API DLLMicrosoft Corporationc:\winnt\system32\lz32.dll
+ ole32Microsoft OLE for WindowsMicrosoft Corporationc:\winnt\system32\ole32.dll
+ oleaut32Microsoft Corporationc:\winnt\system32\oleaut32.dll
+ olecli32Object Linking and Embedding Client LibraryMicrosoft Corporationc:\winnt\system32\olecli32.dll
+ olecnv32Microsoft OLE for WindowsMicrosoft Corporationc:\winnt\system32\olecnv32.dll
+ olesvr32Object Linking and Embedding Server LibraryMicrosoft Corporationc:\winnt\system32\olesvr32.dll
+ olethk32Microsoft OLE for WindowsMicrosoft Corporationc:\winnt\system32\olethk32.dll
+ rpcrt4Remote Procedure Call RuntimeMicrosoft Corporationc:\winnt\system32\rpcrt4.dll
+ shell32Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ urlInternet Shortcut Shell Extension DLLMicrosoft Corporationc:\winnt\system32\url.dll
+ urlmonOLE32 Extensions for Win32Microsoft Corporationc:\winnt\system32\urlmon.dll
+ user32Windows 2000 USER API Client DLLMicrosoft Corporationc:\winnt\system32\user32.dll
+ versionVersion Checking and File Installation LibrariesMicrosoft Corporationc:\winnt\system32\version.dll
+ wininetInternet Extensions for Win32Microsoft Corporationc:\winnt\system32\wininet.dll
+ wldap32Win32 LDAP API DLLMicrosoft Corporationc:\winnt\system32\wldap32.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
+ crypt32chainCrypto API32Microsoft Corporationc:\winnt\system32\crypt32.dll
+ cryptnetCrypto Network Related APIMicrosoft Corporationc:\winnt\system32\cryptnet.dll
+ cscdllOffline Network AgentMicrosoft Corporationc:\winnt\system32\cscdll.dll
+ sclgntfySecondary Logon Service Notification DLLMicrosoft Corporationc:\winnt\system32\sclgntfy.dll
+ SensLognCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\winnt\system32\wlnotify.dll
+ wzcnotifWireless Zero Configuration Service UIMicrosoft Corporationc:\winnt\system32\wzcdlg.dll
$马后炮$ - 2006-8-24 11:48:00
HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{3FD0C2B5-7047-4828-A14D-6B687427ECE5}] DATAGRAM 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{3FD0C2B5-7047-4828-A14D-6B687427ECE5}] SEQPACKET 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{49309037-EF81-4BBF-B6DF-4A37404BD4FD}] DATAGRAM 3Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{49309037-EF81-4BBF-B6DF-4A37404BD4FD}] SEQPACKET 3Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{5F1CC7A6-5305-4D30-842E-CD831A85FE53}] DATAGRAM 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{5F1CC7A6-5305-4D30-842E-CD831A85FE53}] SEQPACKET 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{5F339C35-DEDD-4EEB-80A8-693D44B7400E}] DATAGRAM 5Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{5F339C35-DEDD-4EEB-80A8-693D44B7400E}] SEQPACKET 5Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{ADC58DA1-071E-4863-8C78-7E8B40D47BFA}] DATAGRAM 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{ADC58DA1-071E-4863-8C78-7E8B40D47BFA}] SEQPACKET 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{D7603D3D-A9EE-4CD7-B342-4D3E552FCCD6}] DATAGRAM 4Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{D7603D3D-A9EE-4CD7-B342-4D3E552FCCD6}] SEQPACKET 4Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD Tcpip [RAW/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD Tcpip [TCP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD Tcpip [UDP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ RSVP TCP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\winnt\system32\rsvpsp.dll
+ RSVP UDP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\winnt\system32\rsvpsp.dll
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
+ BJ Language MonitorLangage Monitor for Canon Bubble-Jet PrinterMicrosoft Corporationc:\winnt\system32\cnbjmon.dll
+ Local PortLocal Spooler DLLMicrosoft Corporationc:\winnt\system32\localspl.dll
+ Microsoft Document Imaging Writer MonitorMicrosoft? Document ImagingMicrosoft Corporationc:\winnt\system32\mdimon.dll
+ PJL Language MonitorSpooler Setup DLLMicrosoft Corporationc:\winnt\system32\pjlmon.dll
+ Standard TCP/IP PortStandard TCP/IP Port Monitor DLLMicrosoft Corporationc:\winnt\system32\tcpmon.dll
+ USB MonitorStandard USB printing Port Monitor DLLMicrosoft Corporationc:\winnt\system32\usbmon.dll
© 2000 - 2026 Rising Corp. Ltd.