病毒还没启动时才能用你上面哪个程序 还好程序运行快
未知家族病毒分析
扫描结果:
无可疑文件
系统活动进程
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.DLL
C:\WINDOWS\SYSTEM32\WGALOGON.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM32\ATI2EDXX.DLL
C:\WINDOWS\SYSTEM32\ATIPDLXX.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\IMON.DLL
C:\PROGRAM FILES\ESET\PR_IMON.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\IMON.DLL
C:\PROGRAM FILES\ESET\PR_IMON.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM32\ATI2EDXX.DLL
C:\WINDOWS\SYSTEM32\ATIPDLXX.DLL
C:\WINDOWS\SYSTEM32\ATI2EVXX.DLL
C:\WINDOWS\SYSTEM32\USERINIT.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\1234.EXE
普通自启动项
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = C:\WINDOWS\notepad.exe %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> WordPad.Document.1 = "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"
其它启动项
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
SCRNSAVE.EXE = C:\WINDOWS\system32\aurora.scr
Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
AtiExtEvent = ATI2EVXX.DLL
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
ScCertProp = WLNOTIFY.DLL
Schedule = WLNOTIFY.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
termsrv = WLNOTIFY.DLL
WgaLogon = WGALOGON.DLL
wlballoon = WLNOTIFY.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = C:\WINDOWS\SYSTEM32\USERINIT.EXE,
shell = EXPLORER.EXE
IE - BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{00000000-12C9-4305-82F9-43058F20E8D2} = C:\Program Files\Tencent\QQDownload\QQIEHelper01.dll
{01443AEC-0FD1-40fd-9C87-E93D1494C233} = C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll
{3049C3E9-B461-4BC5-8870-4C09146192CA} = C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
{889D2FEB-5411-4565-8998-1DD2C5261283} = C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} = C:\Program Files\360safe\safemon\safemon.dll
{E5A1691B-D188-4419-AD02-90002030B8EE} = C:\PROGRA~1\FlashFXP\IEFlash.dll
Winsock SPI
NOD32 protected [MSAFD Tcpip [TCP/IP]] = C:\WINDOWS\SYSTEM32\IMON.DLL
NOD32 protected [MSAFD Tcpip [UDP/IP]] = C:\WINDOWS\SYSTEM32\IMON.DLL
NOD32 protected [MSAFD Tcpip [RAW/IP]] = C:\WINDOWS\SYSTEM32\IMON.DLL
NOD32 protected [RSVP UDP Service Provider] = C:\WINDOWS\SYSTEM32\IMON.DLL
NOD32 protected [RSVP TCP Service Provider] = C:\WINDOWS\SYSTEM32\IMON.DLL
MSAFD Tcpip [TCP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [UDP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [RAW/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
RSVP UDP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
RSVP TCP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
NOD32 = C:\WINDOWS\SYSTEM32\IMON.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{AC69FF0E-D54C-467B-A05B-6D40F8BB1550}] SEQPACKET 5 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{AC69FF0E-D54C-467B-A05B-6D40F8BB1550}] DATAGRAM 5 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{66EF0B2E-BB24-4850-96B5-2A91776527A3}] SEQPACKET 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{66EF0B2E-BB24-4850-96B5-2A91776527A3}] DATAGRAM 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{062F929F-6F28-4E13-A4E8-B83021660110}] SEQPACKET 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{062F929F-6F28-4E13-A4E8-B83021660110}] DATAGRAM 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{241D4D37-C0F1-4584-B1BD-87EED6D0F1FC}] SEQPACKET 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{241D4D37-C0F1-4584-B1BD-87EED6D0F1FC}] DATAGRAM 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{99B4C189-4FB8-4511-8424-BA511927880C}] SEQPACKET 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{99B4C189-4FB8-4511-8424-BA511927880C}] DATAGRAM 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{5BFB67D3-CD47-4B5B-8226-5F5E3246DC2D}] SEQPACKET 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{5BFB67D3-CD47-4B5B-8226-5F5E3246DC2D}] DATAGRAM 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
系统服务项
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
03TV2 = C:\WINDOWS\03TV2.EXE -C4ESO47MY1F
07J94V0UONKH = C:\WINDOWS\07J94V0UONKH.EXE -PNFT41
0BQQR6J5OUI = C:\WINDOWS\0BQQR6J5OUI.EXE -4A2W4UMK2JA0
0OVWSWE = C:\WINDOWS\SYSTEM32\0OVWSWE.EXE -BVUM5D5SRS2P
1NIOK = C:\WINDOWS\1NIOK.EXE -VPXP8
1P8TR0ISQEWJ = C:\WINDOWS\SYSTEM32\1P8TR0ISQEWJ.EXE -5GZMLWD2
1YB767L3TYB = C:\WINDOWS\1YB767L3TYB.EXE -S15HZD0
2ALHNBPX = C:\WINDOWS\2ALHNBPX.EXE -W71LCUPU8TK2
3M123XPH19 = C:\WINDOWS\SYSTEM32\3M123XPH19.EXE -6Z744H24
409XEUZUBV9 = C:\WINDOWS\SYSTEM32\409XEUZUBV9.EXE -UUDEF
40B3W6 = C:\WINDOWS\40B3W6.EXE -I91B36GCZ8
48SH2RD = C:\WINDOWS\SYSTEM32\48SH2RD.EXE -AYKJ82
4ASLYQ = C:\WINDOWS\4ASLYQ.EXE -V0QBUF93KP2
4JMJ0HG15 = C:\WINDOWS\4JMJ0HG15.EXE -NZVEXA
4LQPGL0IRA89 = C:\WINDOWS\SYSTEM32\4LQPGL0IRA89.EXE -NVUAPHADL
50R72 = C:\WINDOWS\SYSTEM32\50R72.EXE -265XXDH8
56XJJYNH8P31 = C:\WINDOWS\SYSTEM32\56XJJYNH8P31.EXE -7ZHD9L4
5BKJ03 = C:\WINDOWS\5BKJ03.EXE -LP3QNEO3S
5HT8IQQB1JF = C:\WINDOWS\5HT8IQQB1JF.EXE -YRBDUAYN6
5WFCPU76H6Q2 = C:\WINDOWS\SYSTEM32\5WFCPU76H6Q2.EXE -IL9B7GH6B
6OOCECELAA5 = C:\WINDOWS\SYSTEM32\6OOCECELAA5.EXE -O4Z1DD2X0MBE
6QLXXK9CY1E = C:\WINDOWS\6QLXXK9CY1E.EXE -D7GKPZ5I9K
6YRDEZP1NTZ = C:\WINDOWS\6YRDEZP1NTZ.EXE -5HXXSY0LEE
76UEDINM = C:\WINDOWS\76UEDINM.EXE -QP73QP
7BTG94UHJP1W = C:\WINDOWS\7BTG94UHJP1W.EXE -SYX2VP0P
7K6NXM7HK1K = C:\WINDOWS\SYSTEM32\7K6NXM7HK1K.EXE -CR5U5
7M5J9X3UB = C:\WINDOWS\SYSTEM32\7M5J9X3UB.EXE -Y2WD2NPOEMVF
7TXJH28 = C:\WINDOWS\SYSTEM32\7TXJH28.EXE -91EGV
89NXI = C:\WINDOWS\SYSTEM32\89NXI.EXE -MEUKB7U6EORD
8G3390CGAKD9 = C:\WINDOWS\8G3390CGAKD9.EXE -8VFPHR8PF
8X0PSV1 = C:\WINDOWS\8X0PSV1.EXE -M98FFY
9TINC = C:\WINDOWS\9TINC.EXE -K633R5RN
Alerter = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
ALG = C:\WINDOWS\SYSTEM32\ALG.EXE
AppMgmt = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
Ati HotKey Poller = C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
AudioSrv = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
BCSG5DQ2 = C:\WINDOWS\SYSTEM32\BCSG5DQ2.EXE -RARFF
BITS = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
Browser = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
BUU6XBO7J9I = C:\WINDOWS\BUU6XBO7J9I.EXE -DZTA12
BYYDH7AJ41 = C:\WINDOWS\BYYDH7AJ41.EXE -5SJBRH
C32OFK8 = C:\WINDOWS\C32OFK8.EXE -18OMWUK9
ccosm = C:\PROGRAM FILES\STORMII\STORMLIV.EXE /ASSERVICE
CDK1R7IL = C:\WINDOWS\CDK1R7IL.EXE -YSWA8CEYWC
CiSvc = C:\WINDOWS\SYSTEM32\CISVC.EXE
CIZ4WMGDC2JA = C:\WINDOWS\SYSTEM32\CIZ4WMGDC2JA.EXE -3JT0ZQB9UYOS
ClipSrv = C:\WINDOWS\SYSTEM32\CLIPSRV.EXE
COMSysApp = C:\WINDOWS\SYSTEM32\DLLHOST.EXE /PROCESSID:{02D4B3F1-FD88-11D1-960D-00805FC79235}
CryptSvc = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
D30C0L = C:\WINDOWS\SYSTEM32\D30C0L.EXE -K3LKII1J
D3WZXKT = C:\WINDOWS\D3WZXKT.EXE -9YJW0K3PU
DcomLaunch = C:\WINDOWS\SYSTEM32\SVCHOST -K DCOMLAUNCH
Dhcp = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
dmadmin = C:\WINDOWS\SYSTEM32\DMADMIN.EXE /COM
dmserver = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
Dnscache = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
E1PCLSF4G3YE = C:\WINDOWS\E1PCLSF4G3YE.EXE -K97V97A7
E1RK4K = C:\WINDOWS\E1RK4K.EXE -VGIDSA2
EHBMJ3E = C:\WINDOWS\EHBMJ3E.EXE -45SQNBEGU3
EJBIXQXTR0EK = C:\WINDOWS\EJBIXQXTR0EK.EXE -4CMC9YPZRU9
EM41HNVBJKAX = C:\WINDOWS\EM41HNVBJKAX.EXE -VD7GOQSFKSG7
ERSvc = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
Eventlog = C:\WINDOWS\SYSTEM32\SERVICES.EXE
EventSystem = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
F5SP82E20 = C:\WINDOWS\SYSTEM32\F5SP82E20.EXE -ZOTN6O
FastUserSwitchingCompatibility = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
FTIHOCQSS1 = C:\WINDOWS\FTIHOCQSS1.EXE -42VQ25DUPTNE
GJ2AV = C:\WINDOWS\GJ2AV.EXE -GOXV7PTTWUZC
H93PAN6HB = C:\WINDOWS\H93PAN6HB.EXE -OKNHO0E6087C
helpsvc = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
HidServ = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
HTTPFilter = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K HTTPFILTER
ImapiService = C:\WINDOWS\SYSTEM32\IMAPI.EXE
IPN7QWA0F = C:\WINDOWS\IPN7QWA0F.EXE -PVAONIA
IQMDP = C:\WINDOWS\IQMDP.EXE -ZQX2FIWXVIQN
JA0MA4T = C:\WINDOWS\JA0MA4T.EXE -3V8M0KSV0
JNMZUO = C:\WINDOWS\JNMZUO.EXE -UKTV5LSTTY2
JS7AA = C:\WINDOWS\JS7AA.EXE -SY6HHNP
K0B9X3JTMB = C:\WINDOWS\SYSTEM32\K0B9X3JTMB.EXE -JWXTTUE
L04C8 = C:\WINDOWS\SYSTEM32\L04C8.EXE -98Z9A
lanmanserver = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
lanmanworkstation = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
LEB2QNZF2 = C:\WINDOWS\SYSTEM32\LEB2QNZF2.EXE -AX2150
LIEOW = C:\WINDOWS\LIEOW.EXE -Q8CU8
LmHosts = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
LQ0UAE2CBDI = C:\WINDOWS\LQ0UAE2CBDI.EXE -MAVBZV7P
M4YY3L8P = C:\WINDOWS\SYSTEM32\M4YY3L8P.EXE -P78H6W6
Messenger = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
mnmsrvc = C:\WINDOWS\SYSTEM32\MNMSRVC.EXE
MSDTC = C:\WINDOWS\SYSTEM32\MSDTC.EXE
MSIServer = C:\WINDOWS\SYSTEM32\MSIEXEC.EXE /V
NetDDE = C:\WINDOWS\SYSTEM32\NETDDE.EXE
NetDDEdsdm = C:\WINDOWS\SYSTEM32\NETDDE.EXE
Netlogon = C:\WINDOWS\SYSTEM32\LSASS.EXE
Netman = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
Nla = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
NOD32krn = "C:\PROGRAM FILES\ESET\NOD32KRN.EXE"
NOYIT2OLLNW4 = C:\WINDOWS\NOYIT2OLLNW4.EXE -E5FSUDCA80V
NtLmSsp = C:\WINDOWS\SYSTEM32\LSASS.EXE
NtmsSvc = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
OOBS6EUG = C:\WINDOWS\SYSTEM32\OOBS6EUG.EXE -H4UAF3LGT3ED
OOQQAM = C:\WINDOWS\SYSTEM32\OOQQAM.EXE -S91898RPETN
P4P Service = C:\PROGRAM FILES\COMMON FILES\SOGOU PXP\P2PSVR.EXE
P9BIBNIBBEGP = C:\WINDOWS\P9BIBNIBBEGP.EXE -3XR6KX6M5
PBO7D19 = C:\WINDOWS\PBO7D19.EXE -GRWKHTG1
PlugPlay = C:\WINDOWS\SYSTEM32\SERVICES.EXE
PO1D8360RU2 = C:\WINDOWS\SYSTEM32\PO1D8360RU2.EXE -0Z883WL
PolicyAgent = C:\WINDOWS\SYSTEM32\LSASS.EXE
ProtectedStorage = C:\WINDOWS\SYSTEM32\LSASS.EXE
PWPXL2RS = C:\WINDOWS\PWPXL2RS.EXE -Y3KGA1QL95
QIBSDK11Q8Q = C:\WINDOWS\QIBSDK11Q8Q.EXE -00PNI
QXS5PP9BW284 = C:\WINDOWS\QXS5PP9BW284.EXE -PNB1J3Y73SAU
RasAuto = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
RasMan = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
RDSessMgr = C:\WINDOWS\SYSTEM32\SESSMGR.EXE
RemoteAccess = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
RemoteRegistry = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
RNN7H6YL96 = C:\WINDOWS\RNN7H6YL96.EXE -MYZENS4W6SKT
RpcLocator = C:\WINDOWS\SYSTEM32\LOCATOR.EXE
RpcSs = C:\WINDOWS\SYSTEM32\SVCHOST -K RPCSS
RSVP = C:\WINDOWS\SYSTEM32\RSVP.EXE
RYOK66HGX = C:\WINDOWS\SYSTEM32\RYOK66HGX.EXE -D6MVM5
SamSs = C:\WINDOWS\SYSTEM32\LSASS.EXE
SCardSvr = C:\WINDOWS\SYSTEM32\SCARDSVR.EXE
Schedule = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
seclogon = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
SENS = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
SGCBPA44X = C:\WINDOWS\SGCBPA44X.EXE -47E6XL18HD
SharedAccess = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
ShellHWDetection = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
Spooler = C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
srservice = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
SSDPSRV = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
stisvc = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K IMGSVC
SwPrv = C:\WINDOWS\SYSTEM32\DLLHOST.EXE /PROCESSID:{AE46E88E-DF39-40D6-8995-E4D74EC975B8}
SysmonLog = C:\WINDOWS\SYSTEM32\SMLOGSVC.EXE
T4BU891 = C:\WINDOWS\T4BU891.EXE -4QUIL4D
TapiSrv = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
TermService = C:\WINDOWS\SYSTEM32\SVCHOST -K DCOMLAUNCH
Themes = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
TIYLVX7UA = C:\WINDOWS\TIYLVX7UA.EXE -KIEHI5
TlntSvr = C:\WINDOWS\SYSTEM32\TLNTSVR.EXE
TrkWks = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
U3I80YV751 = C:\WINDOWS\U3I80YV751.EXE -WWPDPQIF
UMWdf = C:\WINDOWS\SYSTEM32\WDFMGR.EXE
UODCYJ = C:\WINDOWS\UODCYJ.EXE -7G6QD4AIJN
upnphost = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
UPS = C:\WINDOWS\SYSTEM32\UPS.EXE
VAK8W = C:\WINDOWS\VAK8W.EXE -AX76A2Z
VAMUWBCBS8 = C:\WINDOWS\SYSTEM32\VAMUWBCBS8.EXE -GK87ZF7TC
VNOF8MCFTPL = C:\WINDOWS\VNOF8MCFTPL.EXE -CFEDG
VO5TV = C:\WINDOWS\VO5TV.EXE -WMW14KLO44B
VSS = C:\WINDOWS\SYSTEM32\VSSVC.EXE
W32Time = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
WebClient = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
winmgmt = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
WmdmPmSN = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
Wmi = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
WmiApSrv = C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE
wscsvc = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
WT397ODPS5 = C:\WINDOWS\WT397ODPS5.EXE -X4XB0ZN16MS9
wuauserv = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
WUFGGR1J447G = C:\WINDOWS\WUFGGR1J447G.EXE -8JZ41C16
WZCSVC = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
X7KUFEOR = C:\WINDOWS\X7KUFEOR.EXE -92OQ5YDB
XDH7R = C:\WINDOWS\XDH7R.EXE -RWF7AZWKPQ8Y
xmlprov = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
XQVHU = C:\WINDOWS\XQVHU.EXE -RFUGICCM
YDYN9B4I = C:\WINDOWS\YDYN9B4I.EXE -GMJ2IZBPGJA
YQ5CJDAKC = C:\WINDOWS\SYSTEM32\YQ5CJDAKC.EXE -D9EUO
Z41O5ZI2 = C:\WINDOWS\SYSTEM32\Z41O5ZI2.EXE -1FHJ30TIAI
文件驱动
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
FltMgr = C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS
MRxDAV = C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS
MRxSmb = C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
NetBIOS = C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS
Rdbss = C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS
sr = C:\WINDOWS\SYSTEM32\DRIVERS\SR.SYS
Srv = C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS
系统驱动项
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
2X4S1 = C:\WINDOWS\5FICEKYQN9R.TXT
569C0DA25K = C:\WINDOWS\BJPR21FNSY.TXT
ACPI = C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS
aec = C:\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS
AFD = C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS
ALCXWDM = C:\WINDOWS\SYSTEM32\DRIVERS\ALCXWDM.SYS
AMON = C:\WINDOWS\SYSTEM32\DRIVERS\AMON.SYS
AsyncMac = C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS
atapi = C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS
ati2mtag = C:\WINDOWS\SYSTEM32\DRIVERS\ATI2MTAG.SYS
Atmarpc = C:\WINDOWS\SYSTEM32\DRIVERS\ATMARPC.SYS
audstub = C:\WINDOWS\SYSTEM32\DRIVERS\AUDSTUB.SYS
CCDECODE = C:\WINDOWS\SYSTEM32\DRIVERS\CCDECODE.SYS
Cdrom = C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS
Disk = C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS
dmboot = C:\WINDOWS\SYSTEM32\DRIVERS\DMBOOT.SYS
dmio = C:\WINDOWS\SYSTEM32\DRIVERS\DMIO.SYS
dmload = C:\WINDOWS\SYSTEM32\DRIVERS\DMLOAD.SYS
DMusic = C:\WINDOWS\SYSTEM32\DRIVERS\DMUSIC.SYS
drmkaud = C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS
Fdc = C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS
Flpydisk = C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS
FsVga = C:\WINDOWS\SYSTEM32\DRIVERS\FSVGA.SYS
Ftdisk = C:\WINDOWS\SYSTEM32\DRIVERS\FTDISK.SYS
Gpc = C:\WINDOWS\SYSTEM32\DRIVERS\MSGPC.SYS
HTTP = C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS
i8042prt = C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS
Imapi = C:\WINDOWS\SYSTEM32\DRIVERS\IMAPI.SYS
intelppm = C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS
Ip6Fw = C:\WINDOWS\SYSTEM32\DRIVERS\IP6FW.SYS
IpFilterDriver = C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS
IpInIp = C:\WINDOWS\SYSTEM32\DRIVERS\IPINIP.SYS
IpNat = C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS
IPSec = C:\WINDOWS\SYSTEM32\DRIVERS\IPSEC.SYS
IRENUM = C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.SYS
isapnp = C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS
J08EDAE8 = C:\WINDOWS\DR9C3XW.TXT
Kbdclass = C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS
kmixer = C:\WINDOWS\SYSTEM32\DRIVERS\KMIXER.SYS
LXFWBLL6F = C:\WINDOWS\7C35UI.TXT
LZ7CGFV8 = C:\WINDOWS\LY66LS01A4A.TXT
Mouclass = C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS
MSKSSRV = C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS
MSPCLOCK = C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS
MSPQM = C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS
mssmbios = C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS
MSTEE = C:\WINDOWS\SYSTEM32\DRIVERS\MSTEE.SYS
NABTSFEC = C:\WINDOWS\SYSTEM32\DRIVERS\NABTSFEC.SYS
NdisIP = C:\WINDOWS\SYSTEM32\DRIVERS\NDISIP.SYS
NdisTapi = C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS
Ndisuio = C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS
NdisWan = C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
NESCU0FF4 = C:\WINDOWS\GKOVDOB4NPY.TXT
NetBT = C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS
nod32drv = C:\WINDOWS\SYSTEM32\DRIVERS\NOD32DRV.SYS
npkcrypt = C:\WINDOWS\SYSTEM32\NPKCRYPT.SYS
npkycryp = C:\WINDOWS\SYSTEM32\NPKYCRYP.SYS
NwlnkFlt = C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKFLT.SYS
NwlnkFwd = C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKFWD.SYS
O3XM4U8V9H9 = C:\WINDOWS\J3VNG26ANIEY.TXT
Parport = C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS
PCI = C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS
PCIIde = C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS
PptpMiniport = C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS
PSched = C:\WINDOWS\SYSTEM32\DRIVERS\PSCHED.SYS
Ptilink = C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS
QT0P7I6OS9UW = C:\WINDOWS\KDN7V2VOBEH.TXT
RasAcd = C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS
Rasl2tp = C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS
RasPppoe = C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS
Raspti = C:\WINDOWS\SYSTEM32\DRIVERS\RASPTI.SYS
RDPCDD = C:\WINDOWS\SYSTEM32\DRIVERS\RDPCDD.SYS
rdpdr = C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS
redbook = C:\WINDOWS\SYSTEM32\DRIVERS\REDBOOK.SYS
rtl8139 = C:\WINDOWS\SYSTEM32\DRIVERS\RTL8139.SYS
Secdrv = C:\WINDOWS\SYSTEM32\DRIVERS\SECDRV.SYS
serenum = C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS
Serial = C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS
SLIP = C:\WINDOWS\SYSTEM32\DRIVERS\SLIP.SYS
splitter = C:\WINDOWS\SYSTEM32\DRIVERS\SPLITTER.SYS
streamip = C:\WINDOWS\SYSTEM32\DRIVERS\STREAMIP.SYS
swenum = C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS
swmidi = C:\WINDOWS\SYSTEM32\DRIVERS\SWMIDI.SYS
sysaudio = C:\WINDOWS\SYSTEM32\DRIVERS\SYSAUDIO.SYS
Tcpip = C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
TermDD = C:\WINDOWS\SYSTEM32\DRIVERS\TERMDD.SYS
TesSafe = C:\WINDOWS\SYSTEM32\TESSAFE.SYS
Update = C:\WINDOWS\SYSTEM32\DRIVERS\UPDATE.SYS
usbehci = C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS
usbhub = C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS
USBSTOR = C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS
usbuhci = C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS
V8ZDSBZH1 = C:\WINDOWS\O35KY.TXT
VgaSave = C:\WINDOWS\SYSTEM32\DRIVERS\VGA.SYS
Wanarp = C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
wdmaud = C:\WINDOWS\SYSTEM32\DRIVERS\WDMAUD.SYS
WS2IFSL = C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS
WSTCODEC = C:\WINDOWS\SYSTEM32\DRIVERS\WSTCODEC.SYS
Z9Y07EG3 = C:\WINDOWS\DH4PBOMQPM.TXT
ZSMC0305 = C:\WINDOWS\SYSTEM32\DRIVERS\USBVM305.SYS