12   1  /  2  页   跳转

感染病毒,日志是AUTORUNS扫描的

感染病毒,日志是AUTORUNS扫描的

HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms           
+ rdpclip    RDP Clip Monitor    Microsoft Corporation    c:\windows\system32\rdpclip.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit           
+ c:\windows\system32\userinit.exe    Userinit Logon Application    Microsoft Corporation    c:\windows\system32\userinit.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell           
+ Explorer.exe    Windows Explorer    Microsoft Corporation    c:\windows\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run           
+ cmdbcs            File not found: C:\WINDOWS\cmdbcs.exe
+ IMSCMig            File not found: ;
+ kav    Kaspersky Anti-Virus    Kaspersky Lab    c:\program files\kaspersky lab\kaspersky anti-virus 6.0\avp.exe
+ KernelFaultCheck            File not found: ;
+ Kvsc3            c:\windows\kvsc3.exe
+ Microsoft Autorun1            c:\windows\system32\nwizdh.exe
+ Microsoft Autorun10            c:\windows\system32\nwizwmgjs.exe
+ Microsoft Autorun7            c:\windows\system32\nwiztlbu.exe
+ Microsoft Autorun9            c:\windows\system32\ravasktao.exe
+ mppds            File not found: C:\WINDOWS\mppds.exe
+ RavTask    RavTimer    Beijing Rising Technology Co., Ltd.    c:\program files\rising\rav\ravtask.exe
+ runeip    Rising AntiSpyware Monitor    Beijing Rising Technology Co., Ltd.    c:\program files\rising\antispyware\runiep.exe
+ SoundMan    Realtek Sound Manager    Realtek Semiconductor Corp.    c:\windows\soundman.exe
+ ssebyly            c:\program files\common files\system\duvadvm.exe
+ ssebyly            c:\program files\common files\system\duvadvm.exe
+ sxulolg            c:\program files\common files\microsoft shared\cilpnoi.exe
+ TIMHost            File not found: C:\WINDOWS\TIMHost.exe
+ yok.exe    yok.exe    YOK.Com    c:\program files\yok\yok.exe
+ yok.exe    yok.exe    YOK.Com    c:\program files\yok\yok.exe
C:\Documents and Settings\user\「开始」菜单\程序\启动           
+ 腾讯QQ.lnk    QQ    TENCENT    c:\program files\tencent\qq\qq.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run           
+ ctfmon.exe    CTF Loader    Microsoft Corporation    c:\windows\system32\ctfmon.exe
+ jiajiasr    加加输入法 4.01 作者:孙百川    加加工作组    c:\program files\jj4\jiajiasr.exe
+ swg            File not found: C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe
HKLM\SOFTWARE\Classes\Protocols\Filter           
+ Class Install Handler    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll
+ deflate    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll
+ gzip    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll
+ lzdhtml    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll
+ text/webviewhtml    Windows Shell Common Dll    Microsoft Corporation    c:\windows\system32\shell32.dll
+ text/xml    Microsoft Office XML MIME Filter    Microsoft Corporation    c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
HKLM\SOFTWARE\Classes\Protocols\Handler           
+ about    Microsoft (R) HTML Viewer    Microsoft Corporation    c:\windows\system32\mshtml.dll
+ cdl    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll
+ dvd    ActiveX control for streaming video    Microsoft Corporation    c:\windows\system32\msvidctl.dll
+ file    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll
+ ftp    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll
+ gopher    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll
+ http    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll
+ https    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll
+ its    Microsoft? InfoTech Storage System Library    Microsoft Corporation    c:\windows\system32\itss.dll
+ javascript    Microsoft (R) HTML Viewer    Microsoft Corporation    c:\windows\system32\mshtml.dll
+ local    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll
+ mailto    Microsoft (R) HTML Viewer    Microsoft Corporation    c:\windows\system32\mshtml.dll
+ mhtml    Microsoft Internet Messaging API    Microsoft Corporation    c:\windows\system32\inetcomm.dll
+ mk    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll
+ ms-its    Microsoft? InfoTech Storage System Library    Microsoft Corporation    c:\windows\system32\itss.dll
+ mso-offdap11    Microsoft Office Web Components 2003    Microsoft Corporation    c:\program files\common files\microsoft shared\web components\11\owc11.dll
+ res    Microsoft (R) HTML Viewer    Microsoft Corporation    c:\windows\system32\mshtml.dll
+ sysimage    Microsoft (R) HTML Viewer    Microsoft Corporation    c:\windows\system32\mshtml.dll
+ tv    ActiveX control for streaming video    Microsoft Corporation    c:\windows\system32\msvidctl.dll
+ vbscript    Microsoft (R) HTML Viewer    Microsoft Corporation    c:\windows\system32\mshtml.dll
+ wia    WIA Scripting Layer    Microsoft Corporation    c:\windows\system32\wiascr.dll
HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components           
+ 0            File not found: About:Home
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components           
+ Internet Explorer    Windows NT User Data Migration Tool    Microsoft Corporation    c:\windows\system32\shmgrate.exe
+ Internet Explorer 6    IE 5.0 Per-User Install Utility    Microsoft Corporation    c:\windows\system32\ie4uinit.exe
+ Microsoft Outlook Express 6    Outlook Express Setup Library    Microsoft Corporation    c:\program files\outlook express\setup50.exe
+ Microsoft Windows Media Player    Microsoft Windows Media Player 安装实用程序    Microsoft Corporation    c:\windows\inf\unregmp2.exe
+ Microsoft Windows Media Player    ADVPACK    Microsoft Corporation    c:\windows\system32\advpack.dll
+ NetMeeting 3.01    ADVPACK    Microsoft Corporation    c:\windows\system32\advpack.dll
+ Outlook Express    Windows NT User Data Migration Tool    Microsoft Corporation    c:\windows\system32\shmgrate.exe
+ Themes Setup    Microsoft(C) Register Server    Microsoft Corporation    c:\windows\system32\regsvr32.exe
+ Windows 桌面更新    Microsoft(C) Register Server    Microsoft Corporation    c:\windows\system32\regsvr32.exe
+ 通讯簿 6    Outlook Express Setup Library    Microsoft Corporation    c:\program files\outlook express\setup50.exe
+ 浏览器自定义组件    Microsoft Internet Explorer Customization DLL    Microsoft Corporation    c:\windows\system32\iedkcs32.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler           
+ Browseui 预加载程序    Shell Browser UI Library    Microsoft Corporation    c:\windows\system32\browseui.dll
+ 组件类别缓存程序    Shell Browser UI Library    Microsoft Corporation    c:\windows\system32\browseui.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad           
+ CDBurn    Windows Shell Common Dll    Microsoft Corporation    c:\windows\system32\shell32.dll
+ PostBootReminder    Windows Shell Common Dll    Microsoft Corporation    c:\windows\system32\shell32.dll
+ SysTray    Systray shell service object    Microsoft Corporation    c:\windows\system32\stobject.dll
+ WebCheck    Web Site Monitor    Microsoft Corporation    c:\windows\system32\webcheck.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks           
+ Rising Execute File Exts hook    Rising Shell Ext Module    Beijing Rising Technology Co., Ltd.    c:\windows\system32\ravext.dll
+ syswfgqq2.dll            c:\program files\common files\microsoft shared\msinfo\syswfgqq2.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved           
+ %DESC_PublishDropTarget%    Photo Printing Wizard    Microsoft Corporation    c:\windows\system32\photowiz.dll
+ .CAB file viewer    Cabinet File Viewer Shell Extension    Microsoft Corporation    c:\windows\system32\cabview.dll
+ ActiveX 高速缓存文件夹    Object Control Viewer    Microsoft Corporation    c:\windows\system32\occache.dll
+ Audio Media Properties Handler    Media File Property Extractor Shell Extension    Microsoft Corporation    c:\windows\system32\shmedia.dll
+ Auto Update Property Sheet Extension    Automatic Updates Control Panel    Microsoft Corporation    c:\windows\system32\wuaucpl.cpl
+ Avi Properties Handler    Media File Property Extractor Shell Extension    Microsoft Corporation    c:\windows\system32\shmedia.dll
+ BandProxy    Shell Browser UI Library    Microsoft Corporation    c:\windows\system32\browseui.dll
+ CDF Extension Copy Hook    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll
+ Channel Menu    Channel Definition File Viewer    Microsoft Corporation    c:\windows\system32\cdfview.dll
+ Channel Properties    Channel Definition File Viewer    Microsoft Corporation    c:\windows\system32\cdfview.dll
+ Code Download Agent    Web Site Monitor    Microsoft Corporation    c:\windows\system32\webcheck.dll
+ Compatibility Page    Compatibility Tab Shell Extension DLL    Microsoft Corporation    c:\windows\system32\slayerxp.dll
+ Compressed (zipped) Folder Right Drag Handler    Compressed (zipped) Folders    Microsoft Corporation    c:\windows\system32\zipfldr.dll
+ Compressed (zipped) Folder SendTo Target    Compressed (zipped) Folders    Microsoft Corporation    c:\windows\system32\zipfldr.dll
+ ConnectionAgent    Web Site Monitor    Microsoft Corporation    c:\windows\system32\webcheck.dll
+ Context Menu Shell Extension            c:\program files\sanlink\input_ntss\contmenu.dll
+ Crypto PKO Extension    Crypto Shell Extensions    Microsoft Corporation    c:\windows\system32\cryptext.dll
+ Crypto Sign Extension    Crypto Shell Extensions    Microsoft Corporation    c:\windows\system32\cryptext.dll
+ Darwin App Publisher    Shell Application Manager    Microsoft Corporation    c:\windows\system32\appwiz.cpl
+ DfsShell    Distributed File System shell extension    Microsoft Corporation    c:\windows\system32\dfsshlex.dll
+ Directory Context Menu Verbs    Directory Service Common UI    Microsoft Corporation    c:\windows\system32\dsuiext.dll
+ Directory Object Find    Directory Service Find    Microsoft Corporation    c:\windows\system32\dsquery.dll
+ Directory Property UI    Directory Service Common UI    Microsoft Corporation    c:\windows\system32\dsuiext.dll
+ Directory Query UI    Directory Service Find    Microsoft Corporation    c:\windows\system32\dsquery.dll
+ Directory Start/Search Find    Directory Service Find    Microsoft Corporation    c:\windows\system32\dsquery.dll
+ Disk Copy Extension    Windows DiskCopy    Microsoft Corporation    c:\windows\system32\diskcopy.dll
+ Disk Quota UI    Windows Shell Disk Quota UI DLL    Microsoft Corporation    c:\windows\system32\dskquoui.dll
+ Display Adapter CPL Extension    Advanced display adapter properties    Microsoft Corporation    c:\windows\system32\deskadp.dll
+ Display Monitor CPL Extension    Advanced display monitor properties    Microsoft Corporation    c:\windows\system32\deskmon.dll
+ Display Panning CPL Extension            File not found: deskpan.dll
最后编辑2007-06-22 23:07:12
分享到:
gototop
 

+ Display TroubleShoot CPL ExtensionAdvanced display performance propertiesMicrosoft Corporationc:\windows\system32\deskperf.dll
+ DS Security PageDirectory Service Security UIMicrosoft Corporationc:\windows\system32\dssec.dll
+ Extensions Manager FolderExtensions ManagerMicrosoft Corporationc:\windows\system32\extmgr.dll
+ Favorites BandShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ FTP Folders WebviewMicrosoft Internet Explorer FTP Folder Shell ExtensionMicrosoft Corporationc:\windows\system32\msieftp.dll
+ GDI+ 文件缩略图解压缩程序Windows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll
+ HTML 缩略图的解压缩程序Windows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll
+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\windows\system32\hticons.dll
+ ICC 配置文件Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\windows\system32\icmui.dll
+ ICM 打印机管理Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\windows\system32\icmui.dll
+ ICM 监视器管理Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\windows\system32\icmui.dll
+ ICM 扫描仪管理Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\windows\system32\icmui.dll
+ IE4 套件初始屏幕Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Installed Apps EnumeratorShell Application ManagerMicrosoft Corporationc:\windows\system32\appwiz.cpl
+ InternetShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ InternetShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Internet Name SpaceShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Internet 临时文件Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Internet 临时文件Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ InternetShortcutShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ ISFBand OCShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Microsoft Agent Character Property Sheet HandlerMicrosoft Agent Property Sheet HandlerMicrosoft Corporationc:\windows\msagent\agentpsh.dll
+ Microsoft AutoCompleteShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Microsoft Browser ArchitectureShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Microsoft BrowserBandShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Microsoft DocProp Inplace Calendar ControlMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll
+ Microsoft DocProp Inplace Droplist Combo ControlMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll
+ Microsoft DocProp Inplace Edit Box ControlMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll
+ Microsoft DocProp Inplace ML Edit Box ControlMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll
+ Microsoft DocProp Inplace Time ControlMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll
+ Microsoft DocProp Shell ExtMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll
+ Microsoft Internet 工具栏Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Microsoft Office HTML Icon HandlerMicrosoft Office 2003 componentMicrosoft Corporationc:\program files\microsoft office\office11\msohev.dll
+ Microsoft Url History 服务Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Microsoft Url 搜索挂接Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Microsoft 多个自动完成列表容器Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Microsoft 历史自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Microsoft 数据链接Microsoft Data Access - OLE DB Core ServicesMicrosoft Corporationc:\program files\common files\system\ole db\oledb32.dll
+ Microsoft 外壳文件夹自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Midi Properties HandlerMedia File Property Extractor Shell ExtensionMicrosoft Corporationc:\windows\system32\shmedia.dll
+ MMC Icon HandlerMMC Shell Extension DLLMicrosoft Corporationc:\windows\system32\mmcshext.dll
+ MRU 自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Multimedia File Property SheetControl Panel Drivers AppletMicrosoft Corporationc:\windows\system32\mmsys.cpl
+ MyDocs Copy HookMy Documents Folder UIMicrosoft Corporationc:\windows\system32\mydocs.dll
+ MyDocs Drop TargetMy Documents Folder UIMicrosoft Corporationc:\windows\system32\mydocs.dll
+ MyDocs PropertiesMy Documents Folder UIMicrosoft Corporationc:\windows\system32\mydocs.dll
+ NTFS Security PageSecurity Shell ExtensionMicrosoft Corporationc:\windows\system32\rshx32.dll
+ Offline Files Folder OptionsClient Side Caching UIMicrosoft Corporationc:\windows\system32\cscui.dll
+ Offline Files MenuClient Side Caching UIMicrosoft Corporationc:\windows\system32\cscui.dll
+ OLE Docfile Property PageOLE DocFile Property PageMicrosoft Corporationc:\windows\system32\docprop.dll
+ PicaViewPicaView 系统扩展 DLLACD Systems, Ltd.c:\program files\acdsee\picaview.dll
+ PlusPack CPL ExtensionWindows Theme APIMicrosoft Corporationc:\windows\system32\themeui.dll
+ PostAgentWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ Printers Security PageSecurity Shell ExtensionMicrosoft Corporationc:\windows\system32\rshx32.dll
+ Remote Sessions CPL ExtensionRemote Sessions CPL ExtensionMicrosoft Corporationc:\windows\system32\remotepg.dll
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
+ Search Assistant OCShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Sendmail serviceSend MailMicrosoft Corporationc:\windows\system32\sendmail.dll
+ Sendmail serviceSend MailMicrosoft Corporationc:\windows\system32\sendmail.dll
+ Set Program Access and DefaultsShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Shell Application ManagerShell Application ManagerMicrosoft Corporationc:\windows\system32\appwiz.cpl
+ Shell Automation Inproc ServiceShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Shell Band Site MenuShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Shell DocObject ViewerShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ Shell extensions for Microsoft Windows Network objectsNetwork object shell UIMicrosoft Corporationc:\windows\system32\ntlanui2.dll
+ Shell extensions for sharingShell extensions for sharingMicrosoft Corporationc:\windows\system32\ntshrui.dll
+ Shell extensions for sharingShell extensions for sharingMicrosoft Corporationc:\windows\system32\ntshrui.dll
+ Shell Image Data FactoryWindows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll
+ Shell Image Property HandlerWindows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll
+ Shell Image VerbsWindows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll
+ Shell properties for a DS objectDirectory Service FindMicrosoft Corporationc:\windows\system32\dsquery.dll
+ Shell Scrap DataHandlerShell scrap object handlerMicrosoft Corporationc:\windows\system32\shscrap.dll
+ Shell Search BandShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Subscription MgrWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ Tasks Folder Icon HandlerTask Scheduler interface DLLMicrosoft Corporationc:\windows\system32\mstask.dll
+ Tasks Folder Shell ExtensionTask Scheduler interface DLLMicrosoft Corporationc:\windows\system32\mstask.dll
+ TrayAgentWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ TridentImageExtractorShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ Video Media Properties HandlerMedia File Property Extractor Shell ExtensionMicrosoft Corporationc:\windows\system32\shmedia.dll
+ Video Thumbnail ExtractorMedia File Property Extractor Shell ExtensionMicrosoft Corporationc:\windows\system32\shmedia.dll
+ Wav Properties HandlerMedia File Property Extractor Shell ExtensionMicrosoft Corporationc:\windows\system32\shmedia.dll
+ Web FoldersMicrosoft Web FoldersMicrosoft Corporationc:\program files\common files\microsoft shared\web folders\msonsext.dll
+ Web Printer Shell ExtensionPrint UI DLLMicrosoft Corporationc:\windows\system32\printui.dll
+ Web 搜索Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ WebCheckWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
gototop
 

+ WebCheck SyncMgr HandlerWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ WebCheckChannelAgentWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ WebCheckWebCrawlerWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ Web反病毒保护Script Monitor Internet Explorer pluginKaspersky Labc:\program files\kaspersky lab\kaspersky anti-virus 6.0\scieplugin.dll
+ Windows Media Player Add to Playlist Context Menu HandlerWindows Media Player LauncherMicrosoft Corporationc:\windows\system32\wmpshell.dll
+ Windows Media Player Burn Audio CD Context Menu HandlerWindows Media Player LauncherMicrosoft Corporationc:\windows\system32\wmpshell.dll
+ Windows Media Player Play as Playlist Context Menu HandlerWindows Media Player LauncherMicrosoft Corporationc:\windows\system32\wmpshell.dll
+ Windows Script Host 的外壳扩展Microsoft (r) Shell Extension for Windows Script HostMicrosoft Corporationc:\windows\system32\wshext.dll
+ WinRAR shell extensionc:\program files\winrar\rarext.dll
+ 帮助和支持Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ 帮助和支持Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ 补充的外壳文件夹Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 补充的外壳文件夹 2Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 窗格中的搜索Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 地址 EditBoxShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 地址(&A)Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 电子邮件Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ 跟踪弹出栏Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 公文包Windows BriefcaseMicrosoft Corporationc:\windows\system32\syncui.dll
+ 管理工具Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ 获取 Passport 向导Map Network Drives/Network Places WizardMicrosoft Corporationc:\windows\system32\netplwiz.dll
+ 可访问的Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 历史记录Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ 频道句柄对象Channel Definition File ViewerMicrosoft Corporationc:\windows\system32\cdfview.dll
+ 频道快捷方式Channel Definition File ViewerMicrosoft Corporationc:\windows\system32\cdfview.dll
+ 频道文件Channel Definition File ViewerMicrosoft Corporationc:\windows\system32\cdfview.dll
+ 全局文件夹设置Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 任务计划Task Scheduler interface DLLMicrosoft Corporationc:\windows\system32\mstask.dll
+ 任务栏和「开始」菜单Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ 扫描仪和照相机Imaging Devices Shell Folder UIMicrosoft Corporationc:\windows\system32\wiashext.dll
+ 扫描仪和照相机Imaging Devices Shell Folder UIMicrosoft Corporationc:\windows\system32\wiashext.dll
+ 扫描仪和照相机Imaging Devices Shell Folder UIMicrosoft Corporationc:\windows\system32\wiashext.dll
+ 扫描仪和照相机Imaging Devices Shell Folder UIMicrosoft Corporationc:\windows\system32\wiashext.dll
+ 扫描仪和照相机Imaging Devices Shell Folder UIMicrosoft Corporationc:\windows\system32\wiashext.dll
+ 搜索Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ 搜索区Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 通过 Web 订购照片Map Network Drives/Network Places WizardMicrosoft Corporationc:\windows\system32\netplwiz.dll
+ 脱机文件夹Client Side Caching UIMicrosoft Corporationc:\windows\system32\cscui.dll
+ 外壳 DeskBarShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 外壳 DeskBarAppShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 外壳 Rebar BandSiteShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 外壳出版向导对象Map Network Drives/Network Places WizardMicrosoft Corporationc:\windows\system32\netplwiz.dll
+ 网络出版向导Map Network Drives/Network Places WizardMicrosoft Corporationc:\windows\system32\netplwiz.dll
+ 网络连接Network Connections ShellMicrosoft Corporationc:\windows\system32\netshell.dll
+ 网络连接Network Connections ShellMicrosoft Corporationc:\windows\system32\netshell.dll
+ 下载状态Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 压缩(zipped)文件夹Compressed (zipped) FoldersMicrosoft Corporationc:\windows\system32\zipfldr.dll
+ 以前的版本Previous Versions property pageMicrosoft Corporationc:\windows\system32\twext.dll
+ 以前的版本属性页Previous Versions property pageMicrosoft Corporationc:\windows\system32\twext.dll
+ 用户(&P)...Find PeopleMicrosoft Corporationc:\program files\outlook express\wabfind.dll
+ 用户帮助Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 用户帐户Map Network Drives/Network Places WizardMicrosoft Corporationc:\windows\system32\netplwiz.dll
+ 预订文件夹Web Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll
+ 运行...Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ 摘要信息缩略图处理程序(DOCFILES)Windows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll
+ 注册数目路选项实用程序Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 自定义 MRU 自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll
+ 字体Windows Font FolderMicrosoft Corporationc:\windows\system32\fontext.dll
+ 字体Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
+ 浏览器栏Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
HKLM\Software\Classes\Folder\Shellex\ColumnHandlers
+ {0D2E74C4-3C34-11d2-A27E-00C04FC30871}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ {24F14F01-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ {24F14F02-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ {66742402-F9B9-11D1-A202-0000F81FEDEE}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ Cbho Object无忧上网工具条软件CHINA INTERNET NETWORK INFORMATION CENTERc:\program files\ieup\ieupbho.dll
+ Google Toolbar HelperGoogle IE 客户端工具栏Google Inc.c:\program files\google\googletoolbar2.dll
+ IeCatch2 Classjccatch ModuleAmaze Softc:\program files\flashget\jccatch.dll
+ 珊瑚虫超级搜索toolbar.dllYOK.Comc:\program files\yok\toolbar.dll
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
+ toolbar.dlltoolbar.dllYOK.Comc:\program files\yok\toolbar.dll
gototop
 


HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ FlashGet BarFlashGet IE BarAmaze Softc:\program files\flashget\fgiebar.dll
+ googletoolbar2.dllGoogle IE 客户端工具栏Google Inc.c:\program files\google\googletoolbar2.dll
+ 珊瑚虫超级搜索toolbar.dllYOK.Comc:\program files\yok\toolbar.dll
+ 无忧上网工具条无忧上网工具条插件CHINA INTERNET NETWORK INFORMATION CENTERc:\program files\ieup\ieupbar.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ &FlashGetFlashGetAmaze Softc:\program files\flashget\flashget.exe
HKLM\System\CurrentControlSet\Services
+ AudioSrv管理基于 Windows 的程序的音频设备。如果此服务被终止,音频设备及其音效将不能正常工作。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\audiosrv.dll
+ AVP保护计算机远离病毒和间谍软件的威胁。Kaspersky Labc:\program files\kaspersky lab\kaspersky anti-virus 6.0\avp.exe
+ CryptSvc提供三种管理服务: 编录数据库服务,它确定 Windows 文件的签字; 受保护的根服务,它从此计算机添加和删除受信根证书机构的证书;和密钥(Key)服务,它帮助注册此计算机获取证书。如果此服务被终止,这些管理服务将无法正常运行。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\cryptsvc.dll
+ DcomLaunch为 DCOM 服务提供加载功能。Microsoft Corporationc:\windows\system32\rpcss.dll
+ dmserver监测和监视新硬盘驱动器并向逻辑磁盘管理器管理服务发送卷的信息以便配置。如果此服务被终止,动态磁盘状态和配置信息会过时。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corp.c:\windows\system32\dmserver.dll
+ Eventlog启用在事件查看器查看基于 Windows 的程序和组件颁发的事件日志消息。无法终止此服务。Microsoft Corporationc:\windows\system32\services.exe
+ lanmanserver支持此计算机通过网络的文件、打印、和命名管道共享。如果服务停止,这些功能不可用。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\srvsvc.dll
+ lanmanworkstation创建和维护到远程服务的客户端网络连接。如果服务停止,这些连接将不可用。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\wkssvc.dll
+ Netman管理“网络和拨号连接”文件夹中对象,在其中您可以查看局域网和远程连接。Microsoft Corporationc:\windows\system32\netman.dll
+ PlugPlay使计算机在极少或没有用户输入的情况下能识别并适应硬件的更改。终止或禁用此服务会造成系统不稳定。Microsoft Corporationc:\windows\system32\services.exe
+ ProtectedStorage提供对敏感数据(如私钥)的保护性存储,以便防止未授权的服务,过程或用户对其的非法访问。Microsoft Corporationc:\windows\system32\lsass.exe
+ RpcSs提供终结点映射程序 (endpoint mapper) 以及其它 RPC 服务。Microsoft Corporationc:\windows\system32\rpcss.dll
+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe
+ SamSs存储本地用户帐户的安全信息。Microsoft Corporationc:\windows\system32\lsass.exe
+ seclogon启用替换凭据下的启用进程。如果此服务被终止,此类型登录访问将不可用。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\seclogon.dll
+ SENS跟踪系统事件,如登录 Windows,网络以及电源事件等。将这些事件通知给 COM+ 事件系统 “订阅者(subscriber)”。Microsoft Corporationc:\windows\system32\sens.dll
+ ShellHWDetection为自动播放硬件事件提供通知。Microsoft Corporationc:\windows\system32\shsvcs.dll
+ Spooler将文件加载到内存中以便迟后打印。Microsoft Corporationc:\windows\system32\spoolsv.exe
+ TrkWks在计算机内 NTFS 文件之间保持链接或在网络域中的计算机之间保持链接。Microsoft Corporationc:\windows\system32\trkwks.dll
+ winmgmt提供共同的界面和对象模式以便访问有关操作系统、设备、应用程序和服务的管理信息。如果此服务被终止,多数基于 Windows 的软件将无法正常运行。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\wbem\wmisvc.dll
HKLM\System\CurrentControlSet\Services
+ ACPIACPI Driver for NTMicrosoft Corporationc:\windows\system32\drivers\acpi.sys
+ aecMicrosoft Acoustic Echo CancellerMicrosoft Corporationc:\windows\system32\drivers\aec.sys
+ AFDAFD 网络支持环境Microsoft Corporationc:\windows\system32\drivers\afd.sys
+ ALCXWDMRealtek AC'97 Audio Driver (WDM)Realtek Semiconductor Corp.c:\windows\system32\drivers\alcxwdm.sys
+ AliIdeFile not found: System32\DRIVERS\aliide.sys
+ AmdK7Processor Device DriverMicrosoft Corporationc:\windows\system32\drivers\amdk7.sys
+ AsyncMacRAS Asynchronous Media DriverMicrosoft Corporationc:\windows\system32\drivers\asyncmac.sys
+ atapiIDE/ATAPI Port DriverMicrosoft Corporationc:\windows\system32\drivers\atapi.sys
+ AtmarpcATM ARP Client ProtocolMicrosoft Corporationc:\windows\system32\drivers\atmarpc.sys
+ audstubAudStub DriverMicrosoft Corporationc:\windows\system32\drivers\audstub.sys
+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\windows\system32\drivers\basetdi.sys
+ CdromSCSI CD-ROM DriverMicrosoft Corporationc:\windows\system32\drivers\cdrom.sys
+ CIDCUSBCIDC CTL and Interrupt USB Reader DriverCIDC.c:\windows\system32\drivers\cidcusb.sys
+ CmdIdeCMD PCI IDE Bus DriverCMD Technology, Inc.c:\windows\system32\drivers\cmdide.sys
+ DiskPnP Disk DriverMicrosoft Corporationc:\windows\system32\drivers\disk.sys
+ dmioNT Disk Manager I/O DriverMicrosoft Corp., Veritas Softwarec:\windows\system32\drivers\dmio.sys
+ dmloadNT Disk Manager Startup DriverMicrosoft Corp., Veritas Software.c:\windows\system32\drivers\dmload.sys
+ DMusicMicrosoft Kernel DLS SynthesizerMicrosoft Corporationc:\windows\system32\drivers\dmusic.sys
+ dot4One Cool TransportMicrosoft Corporationc:\windows\system32\drivers\dot4.sys
+ Dot4PrintDot4 Printer DriverMicrosoft Corporationc:\windows\system32\drivers\dot4prt.sys
+ dot4usbDOT4USB filter driverMicrosoft Corporationc:\windows\system32\drivers\dot4usb.sys
+ drmkaudMicrosoft Kernel DRM Audio Descrambler FilterMicrosoft Corporationc:\windows\system32\drivers\drmkaud.sys
+ FdcFloppy Disk Controller DriverMicrosoft Corporationc:\windows\system32\drivers\fdc.sys
+ FlpydiskFloppy DriverMicrosoft Corporationc:\windows\system32\drivers\flpydisk.sys
+ FsVgaFull Screen Video DriverMicrosoft Corporationc:\windows\system32\drivers\fsvga.sys
+ FtdiskFT Disk DriverMicrosoft Corporationc:\windows\system32\drivers\ftdisk.sys
+ gameenumGame Port EnumeratorMicrosoft Corporationc:\windows\system32\drivers\gameenum.sys
+ GpcGeneric Packet ClassifierMicrosoft Corporationc:\windows\system32\drivers\msgpc.sys
+ HidUsbUSB Miniport Driver for Input DevicesMicrosoft Corporationc:\windows\system32\drivers\hidusb.sys
+ HTTP此服务实现超文本传送协议(HTTP)。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\drivers\http.sys
+ i8042prti8042 Port DriverMicrosoft Corporationc:\windows\system32\drivers\i8042prt.sys
+ ialmIntel Graphics Miniport DriverIntel Corporationc:\windows\system32\drivers\ialmnt5.sys
+ ImapiIMAPI Kernel DriverMicrosoft Corporationc:\windows\system32\drivers\imapi.sys
+ IntelIdeIntel PCI IDE DriverMicrosoft Corporationc:\windows\system32\drivers\intelide.sys
+ intelppmProcessor Device DriverMicrosoft Corporationc:\windows\system32\drivers\intelppm.sys
+ Ip6Fw为家庭和小型办公网络提供入侵保护服务。Microsoft Corporationc:\windows\system32\drivers\ip6fw.sys
+ IpFilterDriverIP Traffic Filter DriverMicrosoft Corporationc:\windows\system32\drivers\ipfltdrv.sys
+ IpInIpIP in IP Tunnel DriverMicrosoft Corporationc:\windows\system32\drivers\ipinip.sys
+ IpNatIP Network Address TranslatorMicrosoft Corporationc:\windows\system32\drivers\ipnat.sys
+ IPSecIPSEC driverMicrosoft Corporationc:\windows\system32\drivers\ipsec.sys
+ IRENUMInfra-Red Bus EnumeratorMicrosoft Corporationc:\windows\system32\drivers\irenum.sys
+ isapnpPNP ISA Bus DriverMicrosoft Corporationc:\windows\system32\drivers\isapnp.sys
+ KbdclassKeyboard Class DriverMicrosoft Corporationc:\windows\system32\drivers\kbdclass.sys
+ kl1Kaspersky Unified DriverKaspersky Labc:\windows\system32\drivers\kl1.sys
+ klifspuper-ptorKaspersky Labc:\windows\system32\drivers\klif.sys
+ kmixerKernel Mode Audio MixerMicrosoft Corporationc:\windows\system32\drivers\kmixer.sys
+ MouclassMouse Class DriverMicrosoft Corporationc:\windows\system32\drivers\mouclass.sys
+ mouhidHID Mouse Filter DriverMicrosoft Corporationc:\windows\system32\drivers\mouhid.sys
+ ms_mpu401MPU401 Adapter DriverMicrosoft Corporationc:\windows\system32\drivers\msmpu401.sys
+ MSKSSRVMS KS ServerMicrosoft Corporationc:\windows\system32\drivers\mskssrv.sys
+ MSPCLOCKMS Proxy ClockMicrosoft Corporationc:\windows\system32\drivers\mspclock.sys
+ MSPQMMS Proxy Quality ManagerMicrosoft Corporationc:\windows\system32\drivers\mspqm.sys
+ mssmbiosSystem Management BIOS DriverMicrosoft Corporationc:\windows\system32\drivers\mssmbios.sys
+ NdisTapiRemote Access NDIS TAPI DriverMicrosoft Corporationc:\windows\system32\drivers\ndistapi.sys
+ NdisuioNDIS 用户模式 I/O 协议Microsoft Corporationc:\windows\system32\drivers\ndisuio.sys
+ NdisWanRemote Access NDIS WAN DriverMicrosoft Corporationc:\windows\system32\drivers\ndiswan.sys
+ NetBTNetBios over TcpipMicrosoft Corporationc:\windows\system32\drivers\netbt.sys
+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 56.73 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys
+ NwlnkFltIPX Traffic Filter DriverMicrosoft Corporationc:\windows\system32\drivers\nwlnkflt.sys
gototop
 

+ NwlnkFwdIPX Traffic Forwarder DriverMicrosoft Corporationc:\windows\system32\drivers\nwlnkfwd.sys
+ ParportParallel Port DriverMicrosoft Corporationc:\windows\system32\drivers\parport.sys
+ PCINT Plug and Play PCI EnumeratorMicrosoft Corporationc:\windows\system32\drivers\pci.sys
+ PCIIdeGeneric PCI IDE Bus DriverMicrosoft Corporationc:\windows\system32\drivers\pciide.sys
+ PptpMiniportWAN Miniport (PPTP)Microsoft Corporationc:\windows\system32\drivers\raspptp.sys
+ PSchedQoS Packet SchedulerMicrosoft Corporationc:\windows\system32\drivers\psched.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys
+ RasAcdRemote Access Auto Connection DriverMicrosoft Corporationc:\windows\system32\drivers\rasacd.sys
+ Rasl2tpWAN Miniport (L2TP)Microsoft Corporationc:\windows\system32\drivers\rasl2tp.sys
+ RasPppoe远程访问 PPPOE 驱动程序Microsoft Corporationc:\windows\system32\drivers\raspppoe.sys
+ RasptiDirect ParallelMicrosoft Corporationc:\windows\system32\drivers\raspti.sys
+ RDPCDDRDP MiniportMicrosoft Corporationc:\windows\system32\drivers\rdpcdd.sys
+ rdpdrMicrosoft RDP Device redirectorMicrosoft Corporationc:\windows\system32\drivers\rdpdr.sys
+ redbookRedbook Audio Filter DriverMicrosoft Corporationc:\windows\system32\drivers\redbook.sys
+ RsNTGDIRsNTGDIBeijing Rising Technology Co., Ltd.c:\windows\system32\drivers\rsntgdi.sys
+ rtl8139Realtek RTL8139 NDIS 5.0 DriverRealtek Semiconductor Corporationc:\windows\system32\drivers\rtl8139.sys
+ safemonSystem Safety Monitor 2.x extension for Windows security layerSystem Safety Limitedc:\windows\system32\drivers\safemon.sys
+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys
+ serenumSerial Port EnumeratorMicrosoft Corporationc:\windows\system32\drivers\serenum.sys
+ SerialSerial Device DriverMicrosoft Corporationc:\windows\system32\drivers\serial.sys
+ SfloppySCSI Floppy DriverMicrosoft Corporationc:\windows\system32\drivers\sfloppy.sys
+ splitterMicrosoft Kernel Audio SplitterMicrosoft Corporationc:\windows\system32\drivers\splitter.sys
+ swenumPlug and Play Software Device EnumeratorMicrosoft Corporationc:\windows\system32\drivers\swenum.sys
+ swmidiMicrosoft GS Wavetable SynthesizerMicrosoft Corporationc:\windows\system32\drivers\swmidi.sys
+ sysaudioSystem Audio WDM FilterMicrosoft Corporationc:\windows\system32\drivers\sysaudio.sys
+ TcpipTCP/IP Protocol DriverMicrosoft Corporationc:\windows\system32\drivers\tcpip.sys
+ TermDDTerminal Server DriverMicrosoft Corporationc:\windows\system32\drivers\termdd.sys
+ UpdateUpdate DriverMicrosoft Corporationc:\windows\system32\drivers\update.sys
+ usbehciEHCI eUSB Miniport DriverMicrosoft Corporationc:\windows\system32\drivers\usbehci.sys
+ usbhubDefault Hub Driver for USBMicrosoft Corporationc:\windows\system32\drivers\usbhub.sys
+ usbscanUSB Scanner DriverMicrosoft Corporationc:\windows\system32\drivers\usbscan.sys
+ USBSTORUSB Mass Storage Class DriverMicrosoft Corporationc:\windows\system32\drivers\usbstor.sys
+ usbuhciUHCI USB Miniport DriverMicrosoft Corporationc:\windows\system32\drivers\usbuhci.sys
+ VgaSaveVGA/Super VGA Video DriverMicrosoft Corporationc:\windows\system32\drivers\vga.sys
+ viaagpVIA NT AGP FilterMicrosoft Corporationc:\windows\system32\drivers\viaagp.sys
+ WanarpRemote Access IP ARP DriverMicrosoft Corporationc:\windows\system32\drivers\wanarp.sys
+ wdmaudMMSYSTEM Wave/Midi API mapperMicrosoft Corporationc:\windows\system32\drivers\wdmaud.sys
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
+ autocheck autochk *Auto Check UtilityMicrosoft Corporationc:\windows\system32\autochk.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
+ 360rpt.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ 360Safe.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ 360tray.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ adam.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ AgentSvr.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ AppSvc32.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ ArSwp.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ AST.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ autoruns.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ avconsol.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ avgrssvc.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ AvMonitor.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ avp.comc:\program files\common files\microsoft shared\cilpnoi.exe
+ avp.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ CCenter.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ ccSvcHst.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ EGHOST.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ FileDsty.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ FTCleanerShell.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ FYFireWall.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ HijackThis.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ IceSword.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ iparmo.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ Iparmor.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ isPwdSvc.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ kabaload.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KaScrScn.SCRc:\program files\common files\microsoft shared\cilpnoi.exe
+ KASMain.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KASTask.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KAV32.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KAVDX.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KAVPF.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KAVPFW.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KAVSetup.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KAVStart.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KISLnchr.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KMailMon.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KMFilter.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KPFW32.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KPFW32X.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KPfwSvc.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KRegEx.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KRepair.comc:\program files\common files\microsoft shared\cilpnoi.exe
+ KsLoader.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KVCenter.kxpc:\program files\common files\microsoft shared\cilpnoi.exe
+ KvDetect.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KvfwMcl.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KVMonXP.kxpc:\program files\common files\microsoft shared\cilpnoi.exe
+ KVMonXP_1.kxpc:\program files\common files\microsoft shared\cilpnoi.exe
+ kvol.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ kvolself.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KvReport.kxpc:\program files\common files\microsoft shared\cilpnoi.exe
+ KVScan.kxpc:\program files\common files\microsoft shared\cilpnoi.exe
+ KVSrvXP.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KVStub.kxpc:\program files\common files\microsoft shared\cilpnoi.exe
+ kvupload.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ kvwsc.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KvXP.kxpc:\program files\common files\microsoft shared\cilpnoi.exe
+ KvXP_1.kxpc:\program files\common files\microsoft shared\cilpnoi.exe
+ KWatch.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KWatch9x.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KWatchX.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ loaddll.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ MagicSet.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ mcconsol.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ mmqczj.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ mmsk.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ Navapsvc.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ Navapw32.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ nod32.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ nod32krn.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ nod32kui.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ NPFMntor.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ PFW.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ PFWLiveUpdate.exec:\program files\common files\microsoft shared\cilpnoi.exe
gototop
 

+ NwlnkFwdIPX Traffic Forwarder DriverMicrosoft Corporationc:\windows\system32\drivers\nwlnkfwd.sys
+ ParportParallel Port DriverMicrosoft Corporationc:\windows\system32\drivers\parport.sys
+ PCINT Plug and Play PCI EnumeratorMicrosoft Corporationc:\windows\system32\drivers\pci.sys
+ PCIIdeGeneric PCI IDE Bus DriverMicrosoft Corporationc:\windows\system32\drivers\pciide.sys
+ PptpMiniportWAN Miniport (PPTP)Microsoft Corporationc:\windows\system32\drivers\raspptp.sys
+ PSchedQoS Packet SchedulerMicrosoft Corporationc:\windows\system32\drivers\psched.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys
+ RasAcdRemote Access Auto Connection DriverMicrosoft Corporationc:\windows\system32\drivers\rasacd.sys
+ Rasl2tpWAN Miniport (L2TP)Microsoft Corporationc:\windows\system32\drivers\rasl2tp.sys
+ RasPppoe远程访问 PPPOE 驱动程序Microsoft Corporationc:\windows\system32\drivers\raspppoe.sys
+ RasptiDirect ParallelMicrosoft Corporationc:\windows\system32\drivers\raspti.sys
+ RDPCDDRDP MiniportMicrosoft Corporationc:\windows\system32\drivers\rdpcdd.sys
+ rdpdrMicrosoft RDP Device redirectorMicrosoft Corporationc:\windows\system32\drivers\rdpdr.sys
+ redbookRedbook Audio Filter DriverMicrosoft Corporationc:\windows\system32\drivers\redbook.sys
+ RsNTGDIRsNTGDIBeijing Rising Technology Co., Ltd.c:\windows\system32\drivers\rsntgdi.sys
+ rtl8139Realtek RTL8139 NDIS 5.0 DriverRealtek Semiconductor Corporationc:\windows\system32\drivers\rtl8139.sys
+ safemonSystem Safety Monitor 2.x extension for Windows security layerSystem Safety Limitedc:\windows\system32\drivers\safemon.sys
+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys
+ serenumSerial Port EnumeratorMicrosoft Corporationc:\windows\system32\drivers\serenum.sys
+ SerialSerial Device DriverMicrosoft Corporationc:\windows\system32\drivers\serial.sys
+ SfloppySCSI Floppy DriverMicrosoft Corporationc:\windows\system32\drivers\sfloppy.sys
+ splitterMicrosoft Kernel Audio SplitterMicrosoft Corporationc:\windows\system32\drivers\splitter.sys
+ swenumPlug and Play Software Device EnumeratorMicrosoft Corporationc:\windows\system32\drivers\swenum.sys
+ swmidiMicrosoft GS Wavetable SynthesizerMicrosoft Corporationc:\windows\system32\drivers\swmidi.sys
+ sysaudioSystem Audio WDM FilterMicrosoft Corporationc:\windows\system32\drivers\sysaudio.sys
+ TcpipTCP/IP Protocol DriverMicrosoft Corporationc:\windows\system32\drivers\tcpip.sys
+ TermDDTerminal Server DriverMicrosoft Corporationc:\windows\system32\drivers\termdd.sys
+ UpdateUpdate DriverMicrosoft Corporationc:\windows\system32\drivers\update.sys
+ usbehciEHCI eUSB Miniport DriverMicrosoft Corporationc:\windows\system32\drivers\usbehci.sys
+ usbhubDefault Hub Driver for USBMicrosoft Corporationc:\windows\system32\drivers\usbhub.sys
+ usbscanUSB Scanner DriverMicrosoft Corporationc:\windows\system32\drivers\usbscan.sys
+ USBSTORUSB Mass Storage Class DriverMicrosoft Corporationc:\windows\system32\drivers\usbstor.sys
+ usbuhciUHCI USB Miniport DriverMicrosoft Corporationc:\windows\system32\drivers\usbuhci.sys
+ VgaSaveVGA/Super VGA Video DriverMicrosoft Corporationc:\windows\system32\drivers\vga.sys
+ viaagpVIA NT AGP FilterMicrosoft Corporationc:\windows\system32\drivers\viaagp.sys
+ WanarpRemote Access IP ARP DriverMicrosoft Corporationc:\windows\system32\drivers\wanarp.sys
+ wdmaudMMSYSTEM Wave/Midi API mapperMicrosoft Corporationc:\windows\system32\drivers\wdmaud.sys
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
+ autocheck autochk *Auto Check UtilityMicrosoft Corporationc:\windows\system32\autochk.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
+ 360rpt.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ 360Safe.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ 360tray.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ adam.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ AgentSvr.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ AppSvc32.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ ArSwp.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ AST.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ autoruns.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ avconsol.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ avgrssvc.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ AvMonitor.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ avp.comc:\program files\common files\microsoft shared\cilpnoi.exe
+ avp.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ CCenter.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ ccSvcHst.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ EGHOST.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ FileDsty.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ FTCleanerShell.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ FYFireWall.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ HijackThis.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ IceSword.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ iparmo.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ Iparmor.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ isPwdSvc.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ kabaload.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KaScrScn.SCRc:\program files\common files\microsoft shared\cilpnoi.exe
+ KASMain.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KASTask.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KAV32.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KAVDX.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KAVPF.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KAVPFW.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KAVSetup.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KAVStart.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KISLnchr.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KMailMon.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KMFilter.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KPFW32.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KPFW32X.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KPfwSvc.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KRegEx.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KRepair.comc:\program files\common files\microsoft shared\cilpnoi.exe
+ KsLoader.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KVCenter.kxpc:\program files\common files\microsoft shared\cilpnoi.exe
+ KvDetect.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KvfwMcl.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KVMonXP.kxpc:\program files\common files\microsoft shared\cilpnoi.exe
+ KVMonXP_1.kxpc:\program files\common files\microsoft shared\cilpnoi.exe
+ kvol.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ kvolself.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KvReport.kxpc:\program files\common files\microsoft shared\cilpnoi.exe
+ KVScan.kxpc:\program files\common files\microsoft shared\cilpnoi.exe
+ KVSrvXP.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KVStub.kxpc:\program files\common files\microsoft shared\cilpnoi.exe
+ kvupload.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ kvwsc.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KvXP.kxpc:\program files\common files\microsoft shared\cilpnoi.exe
+ KvXP_1.kxpc:\program files\common files\microsoft shared\cilpnoi.exe
+ KWatch.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KWatch9x.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ KWatchX.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ loaddll.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ MagicSet.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ mcconsol.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ mmqczj.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ mmsk.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ Navapsvc.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ Navapw32.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ nod32.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ nod32krn.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ nod32kui.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ NPFMntor.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ PFW.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ PFWLiveUpdate.exec:\program files\common files\microsoft shared\cilpnoi.exe
gototop
 

汗...!...整个社区都没人来看的....!!
gototop
 


+ QHSET.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ QQDoctor.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ QQKav.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ Ras.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ Rav.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ RavMon.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ RavMonD.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ RavStub.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ RavTask.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ RegClean.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ rfwcfg.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ rfwmain.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ rfwsrv.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ RsAgent.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ Rsaupd.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ rstrui.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ runiep.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ safelive.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ scan32.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ shcfg32.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ SmartUp.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ SREng.EXEc:\program files\common files\microsoft shared\cilpnoi.exe
+ symlcsvc.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ SysSafe.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ TrojanDetector.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ Trojanwall.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ TrojDie.kxpc:\program files\common files\microsoft shared\cilpnoi.exe
+ UIHost.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ UmxAgent.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ UmxAttachment.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ UmxCfg.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ UmxFwHlp.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ UmxPol.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ upiea.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ UpLive.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ USBCleaner.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ vsstat.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ webscanx.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ WoptiClean.exec:\program files\common files\microsoft shared\cilpnoi.exe
+ Your Image File Name Here without a pathSymbolic Debugger for Windows 2000Microsoft Corporationc:\windows\system32\ntsd.exe
HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls
+ advapi32Advanced Windows 32 Base APIMicrosoft Corporationc:\windows\system32\advapi32.dll
+ comdlg32Common Dialogs DLLMicrosoft Corporationc:\windows\system32\comdlg32.dll
+ gdi32GDI Client DLLMicrosoft Corporationc:\windows\system32\gdi32.dll
+ imagehlpWindows NT Image HelperMicrosoft Corporationc:\windows\system32\imagehlp.dll
+ kernel32Windows NT BASE API Client DLLMicrosoft Corporationc:\windows\system32\kernel32.dll
+ lz32LZ Expand/Compress API DLLMicrosoft Corporationc:\windows\system32\lz32.dll
+ ole32Microsoft OLE for WindowsMicrosoft Corporationc:\windows\system32\ole32.dll
+ oleaut32Microsoft Corporationc:\windows\system32\oleaut32.dll
+ olecli32Object Linking and Embedding Client LibraryMicrosoft Corporationc:\windows\system32\olecli32.dll
+ olecnv32Microsoft OLE for WindowsMicrosoft Corporationc:\windows\system32\olecnv32.dll
+ olesvr32Object Linking and Embedding Server LibraryMicrosoft Corporationc:\windows\system32\olesvr32.dll
+ olethk32Microsoft OLE for WindowsMicrosoft Corporationc:\windows\system32\olethk32.dll
+ rpcrt4Remote Procedure Call RuntimeMicrosoft Corporationc:\windows\system32\rpcrt4.dll
+ shell32Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll
+ urlInternet Shortcut Shell Extension DLLMicrosoft Corporationc:\windows\system32\url.dll
+ urlmonOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll
+ user32Windows XP USER API Client DLLMicrosoft Corporationc:\windows\system32\user32.dll
+ versionVersion Checking and File Installation LibrariesMicrosoft Corporationc:\windows\system32\version.dll
+ wininetInternet Extensions for Win32Microsoft Corporationc:\windows\system32\wininet.dll
+ wldap32Win32 LDAP API DLLMicrosoft Corporationc:\windows\system32\wldap32.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UIHost
+ \Program Files\Logonui\Royale.exeFile not found: \Program
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
+ crypt32chainCrypto API32Microsoft Corporationc:\windows\system32\crypt32.dll
+ cryptnetCrypto Network Related APIMicrosoft Corporationc:\windows\system32\cryptnet.dll
+ cscdllOffline Network AgentMicrosoft Corporationc:\windows\system32\cscdll.dll
+ igfxcuiigfxsrvc ModuleIntel Corporationc:\windows\system32\igfxsrvc.dll
+ klogonLogon VisualizerKaspersky Labc:\windows\system32\klogon.dll
+ ScCertPropCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll
+ ScheduleCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll
+ sclgntfySecondary Logon Service Notification DLLMicrosoft Corporationc:\windows\system32\sclgntfy.dll
+ SensLognCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll
+ System Safety MonitorSystem Safety ManagerSystem Safety Limitedc:\windows\system32\ssmwinlogonex.dll
+ termsrvCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll
+ wlballoonCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll
HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{1ABCDC76-B23A-4A0A-9B37-CEF0D890EEC4}] DATAGRAM 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{1ABCDC76-B23A-4A0A-9B37-CEF0D890EEC4}] SEQPACKET 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{4DAFA87D-7ED3-4416-99F7-F0CA25413912}] DATAGRAM 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{4DAFA87D-7ED3-4416-99F7-F0CA25413912}] SEQPACKET 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{A15FE80C-B952-4DDD-BCE4-6A00F5695FB2}] DATAGRAM 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{A15FE80C-B952-4DDD-BCE4-6A00F5695FB2}] SEQPACKET 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD Tcpip [RAW/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD Tcpip [TCP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ MSAFD Tcpip [UDP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll
+ RSVP TCP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\windows\system32\rsvpsp.dll
+ RSVP UDP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\windows\system32\rsvpsp.dll
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
+ BJ Language MonitorLangage Monitor for Canon Bubble-Jet PrinterMicrosoft Corporationc:\windows\system32\cnbjmon.dll
+ HP Master MonitorWin32 Master MonitorHewlett-Packardc:\windows\system32\hpbmmon.dll
+ Local PortLocal Spooler DLLMicrosoft Corporationc:\windows\system32\localspl.dll
+ Microsoft Document Imaging Writer MonitorMicrosoft? Document ImagingMicrosoft Corporationc:\windows\system32\mdimon.dll
+ PJL Language MonitorPJL Language monitorMicrosoft Corporationc:\windows\system32\pjlmon.dll
+ Standard TCP/IP PortStandard TCP/IP Port Monitor DLLMicrosoft Corporationc:\windows\system32\tcpmon.dll
+ USB MonitorStandard Dynamic Printing Port Monitor DLLMicrosoft Corporationc:\windows\system32\usbmon.dll
HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders
+ digest.dllDigest SSPI Authentication PackageMicrosoft Corporationc:\windows\system32\digest.dll
+ msapsspc.dllDPA Client for 32 bit platformsMicrosoft Corporationc:\windows\system32\msapsspc.dll
+ msnsspc.dllMSN Internet AccessMicrosoft Corporationc:\windows\system32\msnsspc.dll
+ schannel.dllTLS / SSL Security ProviderMicrosoft Corporationc:\windows\system32\schannel.dll
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages
+ msv1_0Microsoft Authentication Package v1.0Microsoft Corporationc:\windows\system32\msv1_0.dll
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages
+ scecliWindows Security Configuration Editor Client EngineMicrosoft Corporationc:\windows\system32\scecli.dll
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages
+ kerberosKerberos Security PackageMicrosoft Corporationc:\windows\system32\kerberos.dll
+ msv1_0Microsoft Authentication Package v1.0Microsoft Corporationc:\windows\system32\msv1_0.dll
+ schannelTLS / SSL Security ProviderMicrosoft Corporationc:\windows\system32\schannel.dll
+ wdigestMicrosoft Digest AccessMicrosoft Corporationc:\windows\system32\wdigest.dll
HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
+ LanmanWorkstationMicrosoft Windows NetworkMicrosoft Corporationc:\windows\system32\ntlanman.dll
+ RDPNPMicrosoft Terminal ServicesMicrosoft Corporationc:\windows\system32\drprov.dll
+ WebClientWeb Client NetworkMicrosoft Corporationc:\windows\system32\davclnt.dll
gototop
 

汗,用Sreng扫个日志阿
gototop
 

老大,会不会用autoruns扫日志啊...

这谁还帮你看啊...!



引用:
【flyskymlf龙龙的贴子】汗,用Sreng扫个日志阿
………………

同意!!确实不少病毒!!
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT