+ 文件系统驱动
+ HKLM\System\CurrentControlSet\Services
drvnddm
[A ] 50. c:\windows\system32\drivers\drvnddm.sys
Sonic Solutions
Device Driver Manager
.text,.rdata,.data,.edata,INIT,.rsrc,.reloc,
sscdbhk5
[A ] 51. c:\windows\system32\drivers\sscdbhk5.sys
Sonic Solutions
Shared Driver Component
.text,.rdata,.data,INIT,.rsrc,.reloc,
ssrtln
[A ] 52. c:\windows\system32\drivers\ssrtln.sys
Sonic Solutions
Shared Driver Component
.text,.rdata,.data,.edata,INIT,.rsrc,.reloc,
tfsnboio
[A ] 53. c:\windows\system32\dla\tfsnboio.sys
Sonic Solutions
Drive Letter Access Component
.text,.rdata,.data,INIT,.rsrc,.reloc,
tfsncofs
[A ] 54. c:\windows\system32\dla\tfsncofs.sys
Sonic Solutions
Drive Letter Access Component
.text,.rdata,.data,INIT,.rsrc,.reloc,
tfsndrct
[A ] 55. c:\windows\system32\dla\tfsndrct.sys
Sonic Solutions
Drive Letter Access Component
.text,.rdata,.data,INIT,.rsrc,.reloc,
tfsndres
[A ] 56. c:\windows\system32\dla\tfsndres.sys
Sonic Solutions
Drive Letter Access Component
.text,.rdata,.data,.edata,INIT,.rsrc,.reloc,
tfsnifs
[A ] 57. c:\windows\system32\dla\tfsnifs.sys
Sonic Solutions
Drive Letter Access Component
.text,.rdata,.data,.edata,INIT,.rsrc,.reloc,
tfsnopio
[A ] 58. c:\windows\system32\dla\tfsnopio.sys
Sonic Solutions
Drive Letter Access Component
.text,.rdata,.data,INIT,.rsrc,.reloc,
tfsnpool
[A ] 59. c:\windows\system32\dla\tfsnpool.sys
Sonic Solutions
Drive Letter Access Component
.text,.rdata,.data,.edata,INIT,.rsrc,.reloc,
tfsnudf
[A ] 60. c:\windows\system32\dla\tfsnudf.sys
Sonic Solutions
Drive Letter Access Component
.text,.rdata,.data,INIT,.rsrc,.reloc,
tfsnudfa
[A ] 61. c:\windows\system32\dla\tfsnudfa.sys
Sonic Solutions
Drive Letter Access Component
.text,.rdata,.data,INIT,.rsrc,.reloc,
+ 系统登陆自运行
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
UIHost
[A ] 62. c:\documents and settings\all users\application data\tuneup software\tuneup utilities\winstyler\tu_logonui.exe
Microsoft Corporation
Windows Logon UI
.text,.data,.rsrc,
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
AtiExtEvent
[AM] 63. c:\windows\system32\ati2evxx.dll
ATI Technologies Inc.
ATI External Event Utility DLL Module
.text,.rdata,.data,.rsrc,.reloc,
IntelWireless
[AM] 64. c:\program files\intel\wireless\bin\lgnotify.dll
Intel Corporation
LogonNotify DLL
.text,.rdata,.data,.rsrc,.reloc,
WBSrv
[AM] 65. d:\program files\stardock\
object desktop\windowblinds\wbsrv.dll
Stardock
WBSrv.dll
.text,.rdata,.data,.rsrc,.reloc,
+ IE浏览器加载模块
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C}
[A ] 66. c:\windows\system32\kakatool.dll
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Toolbar
.text,.rdata,.data,MonitorS,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{5CA3D70E-1895-11CF-8E15-001234567890}
[A ] 67. c:\windows\system32\dla\tfswshx.dll
Sonic Solutions
Drive Letter Access Component
.text,.rdata,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
Exec
[A ] 68. d:\program files\tencent\qq\qq.exe
TENCENT
QQ
.text,.rdata,.data,.rsrc,
Exec
[A ] 69. c:\program files\messenger\msmsgs.exe
Microsoft Corporation
Windows Messenger
.text,.data,.rsrc,
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
application/octet-stream
[A ] 70. c:\windows\system32\mscoree.dll
Microsoft Corporation
Microsoft .NET Runtime Execution Engine
.text,.data,.rsrc,.reloc,
application/x-complus
[A ] 70. c:\windows\system32\mscoree.dll
Microsoft Corporation
Microsoft .NET Runtime Execution Engine
.text,.data,.rsrc,.reloc,
application/x-msdownload
[A ] 70. c:\windows\system32\mscoree.dll
Microsoft Corporation
Microsoft .NET Runtime Execution Engine
.text,.data,.rsrc,.reloc,
text/xml
[A ] 71. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
Microsoft Corporation
Microsoft Office XML MIME Filter
.text,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
livecall
[A ] 72. c:\program files\msn messenger\msgrapp.8.0.0792.00.dll
Microsoft Corporation
MSN Messenger Protocol Handler
.text,.data,.rsrc,.reloc,
msnim
[A ] 72. c:\program files\msn messenger\msgrapp.8.0.0792.00.dll
Microsoft Corporation
MSN Messenger Protocol Handler
.text,.data,.rsrc,.reloc,
mso-offdap
[A ] 73. c:\program files\common files\microsoft shared\web components\10\owc10.dll
Microsoft Corporation
Microsoft Office XP Web Components
.text,.data,.rtext,.bootdat,msoconst,Shared,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
{2bf41073-b2b1-21c1-b5c1-0701f4155588}
[A ] 74. c:\program files\common files\services\svchost.exe
CODE,.rsrc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 75. c:\windows\system32\hticons.dll
Hilgraeve, Inc.
HyperTerminal Applet Library
.text,.data,.rsrc,.reloc,
DriveLetterAccess
[A ] 67. c:\windows\system32\dla\tfswshx.dll
Sonic Solutions
Drive Letter Access Component
.text,.rdata,.data,.rsrc,.reloc,
RecordNow! SendToExt
[A ] 76. c:\program files\sonic\sonic solutions product cd\recordnow!\shlext.dll
Shell Extensions
.text,.rdata,.data,.rsrc,.reloc,
WinRAR shell extension
[A ] 77. c:\program files\winrar\rarext.dll
.text,.data,.tls,.idata,.edata,.rsrc,.reloc,
MSNShell
[A ] 78. c:\windows\system32\contmenu.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
WindowBlinds CPL Extension
[A ] 79. d:\program files\stardock\
object desktop\windowblinds\wbui.dll
Stardock.Net, Inc
WindowBlinds 5.0 UI
.text,.rdata,.data,.rsrc,.reloc,
Microsoft Office HTML Icon Handler
[A ] 80. d:\program files\microsoft office\office11\msohev.dll
Microsoft Corporation
Microsoft Office 2003 component
.text,.data,.rsrc,.reloc,
Web Folders
[A ] 81. c:\program files\common files\microsoft shared\web folders\msonsext.dll
Microsoft Corporation
Microsoft Web Folders
.text,.data,.rsrc,.reloc,
Microsoft Office Outlook Custom Icon Handler
[A ] 82. d:\program files\microsoft office\office11\olkfstub.dll
Microsoft Corporation
Outlook Shell Hook for Start/Find
.text,.data,.rsrc,.reloc,
Microsoft Office Outlook Desktop Icon Handler
[A ] 83. d:\program files\microsoft office\office11\mlshext.dll
Microsoft Corporation
Microsoft Shell Extension Library
.text,.data,.cdata,.rsrc,.reloc,
TuneUp 碎纸机
[A ] 84. d:\program files\tuneup utilities 2006\sdshelex.dll
TuneUp Software GmbH
TuneUp Shredder Shell Extension
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
Fusion Cache
[A ] 70. c:\windows\system32\mscoree.dll
Microsoft Corporation
Microsoft .NET Runtime Execution Engine
.text,.data,.rsrc,.reloc,
Autodesk Drawing Preview
[A ] 85. c:\program files\common files\autodesk shared\thumbnail\acthumbnail16.dll
Autodesk
AcThumbnail Module
.text,.rdata,.data,.rsrc,.reloc,
AutoCAD 数字签名图标覆盖处理程序
[AM] 86. c:\windows\system32\acsignicon.dll
Autodesk
AcSignIcon Module
.text,.rdata,.data,.rsrc,.reloc,
Autodesk DWF Preview
[A ] 87. c:\program files\common files\autodesk shared\thumbnail\acdwfthmbprxy16.dll
Autodesk
AcThumbnail Module
.text,.rdata,.data,.rsrc,.reloc,
Messenger Sharing Folders
[AM] 88. c:\program files\msn messenger\fsshext.8.0.0792.00.dll
Microsoft Corporation
Messenger File Sharing Shell Extensions
.text,.data,.rsrc,.reloc,
RISING
[A ] 89. c:\windows\system32\ravext.dll
Beijing Rising Technology Co., Ltd.
Rising Shell Ext Module
.text,.rdata,.data,.rsrc,.reloc,