瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 请高手来看看瑞星听诊器的日志有没有问题

1   1  /  1  页   跳转

请高手来看看瑞星听诊器的日志有没有问题

请高手来看看瑞星听诊器的日志有没有问题

未知家族病毒分析
扫描结果:
E:\Downloads\QQ宠物管家\PetDoctor.exe --> 与 Trojan.QQMSG.MsgSender 40%相似.


系统活动进程
C:\WINNT\SYSTEM32\SMSS.EXE
C:\WINNT\SYSTEM32\WINLOGON.EXE
C:\WINNT\SYSTEM32\WDMAUD.DRV
C:\WINNT\SYSTEM32\MSACM32.DRV

C:\WINNT\SYSTEM32\CSRSS.EXE
C:\WINNT\SYSTEM32\SERVICES.EXE
C:\WINNT\SYSTEM32\LSASS.EXE
C:\WINNT\SYSTEM32\SVCHOST.EXE
C:\WINNT\SYSTEM32\SPOOLSV.EXE
C:\WINNT\SYSTEM32\CNMLM3Y.DLL
C:\WINNT\SYSTEM32\HPBMMON.DLL
C:\WINNT\SYSTEM32\HPDOMON.DLL
C:\WINNT\SYSTEM32\SPOOL\PRTPROCS\W32X86\CNMPD3Y.DLL
C:\WINNT\SYSTEM32\SPOOL\PRTPROCS\W32X86\IMFPRINT.DLL
C:\WINNT\SYSTEM32\IMF32.DLL
C:\WINNT\SYSTEM32\ZTAG32.DLL
C:\WINNT\SYSTEM32\ZSPOOL.DLL
C:\WINNT\SYSTEM32\SPOOL\PRTPROCS\W32X86\VPRPROC.DLL
C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\SDNT5UI.DLL
C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\SDDM32.DLL
C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\ZGDI32.DLL
C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\SDDMUI.DLL
C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\SR32.DLL

C:\WINNT\SYSTEM32\SVCHOST.EXE
C:\WINNT\SYSTEM32\UNIMDM.TSP
C:\WINNT\SYSTEM32\KMDDSP.TSP
C:\WINNT\SYSTEM32\NDPTSP.TSP
C:\WINNT\SYSTEM32\IPCONF.TSP
C:\WINNT\SYSTEM32\H323.TSP

E:\TENCENT\QQ\QQ.EXE
E:\TENCENT\QQ\QQBASECLASSINDLL.DLL
E:\TENCENT\QQ\QQHELPERDLL.DLL
E:\TENCENT\QQ\BASICCTRLDLL.DLL
E:\TENCENT\QQ\MFC42.DLL
C:\WINNT\SYSTEM32\MSVCP60.DLL
E:\TENCENT\QQ\RICHED32.DLL
E:\TENCENT\QQ\RICHED20.DLL
E:\TENCENT\QQ\QQAPI.DLL
E:\TENCENT\QQ\TIMPROXY.DLL
E:\TENCENT\QQ\LOGINCTRL.DLL
E:\TENCENT\QQ\NPKCNTC.DLL
E:\TENCENT\QQ\NPKPDB.DLL
E:\TENCENT\QQ\QQRES.DLL
E:\TENCENT\QQ\QQMAINFRAME.DLL
E:\TENCENT\QQ\CQQAPPLICATION.DLL
E:\TENCENT\QQ\NEWSKIN.DLL
E:\TENCENT\QQ\HOSTINGMGR.DLL
E:\TENCENT\QQ\CAMERADLL.DLL
E:\TENCENT\QQ\MAILSUMMARY.DLL
E:\TENCENT\QQ\QQSPACE.DLL
E:\TENCENT\QQ\VBSCRIPT.DLL
E:\TENCENT\QQ\QQGROUPMNG.DLL
E:\TENCENT\QQ\GROUPLIVE.DLL
E:\TENCENT\QQ\USERDEFINEDHEAD.DLL
E:\TENCENT\QQ\QQPLUGIN.DLL
E:\TENCENT\QQ\QQCONFIGPLUGIN.DLL
E:\TENCENT\QQ\QRINGMNG.DLL
E:\TENCENT\QQ\PHONEAPI.DLL
E:\TENCENT\QQ\DIALERALLINONE.DLL
C:\WINNT\SYSTEM32\WDMAUD.DRV
E:\TENCENT\QQ\VPORTAL.DLL
E:\TENCENT\QQ\QQAVATAR.DLL
E:\TENCENT\QQ\FLASHAVATARDLL.DLL
E:\TENCENT\QQ\LONGCONNECTION.DLL
E:\TENCENT\QQ\COMMERCESMNG.DLL
E:\TENCENT\QQ\QQADDR.DLL
E:\TENCENT\QQ\QQPET.DLL
C:\WINNT\SYSTEM32\MSACM32.DRV
E:\TENCENT\QQ\OEMAPPLICATION.DLL
C:\WINNT\SYSTEM32\MSADP32.ACM
E:\TENCENT\QQ\QQALLINONE.DLL
E:\TENCENT\QQ\SCCORE.DLL
E:\TENCENT\QQ\GDIPLUS.DLL
E:\TENCENT\QQ\QQCUSTOMFACE.DLL
C:\WINNT\SYSTEM32\MACROMED\FLASH\FLASH9.OCX
E:\TENCENT\QQ\IMAGEOLE.DLL
E:\TENCENT\QQ\QQSYSMSGMNG.DLL
E:\TENCENT\QQ\QQSCENEMNG.DLL
E:\TENCENT\QQ\BQQAPPLICATION.DLL
E:\EWIDO ANTI-MALWARE\SHELLHOOK.DLL
C:\WINNT\SYSTEM32\MSVCR71.DLL
E:\TENCENT\QQ\PERSONALDESKTOP.DLL
E:\TENCENT\QQ\QQPHONEHELPER.DLL
C:\WINNT\SYSTEM32\WINWB86.IME
E:\TENCENT\QQ\GROUPCONNECTION.DLL
F:\RISING\RAV\RAVSCRCH.DLL
E:\TENCENT\QQ\QQZIP.DLL
E:\TENCENT\QQ\QQGROUPDISK.DLL
E:\TENCENT\QQ\VIDEODEVICE.DLL
E:\TENCENT\QQ\INPLUS.DLL
C:\WINNT\SYSTEM32\L3CODECA.ACM
E:\TENCENT\QQ\QQMAGICFACE.DLL
E:\TENCENT\QQ\DSHARED.DLL
C:\WINNT\SYSTEM32\WINABC.IME
E:\TENCENT\QQ\QQFILETRANSFER.DLL

E:\EWIDO ANTI-MALWARE\EWIDOCTRL.EXE
E:\EWIDO ANTI-MALWARE\LANG.DLL
C:\WINNT\SYSTEM32\MSVCP71.DLL
C:\WINNT\SYSTEM32\MSVCR71.DLL

C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
E:\TENCENT\QQ\QQIEHELPER.DLL
C:\WINNT\SYSTEM32\WDMAUD.DRV
C:\WINNT\SYSTEM32\MSACM32.DRV
C:\WINNT\SYSTEM32\MSADP32.ACM
F:\RISING\RAV\RAVSCRCH.DLL
C:\WINNT\SYSTEM32\MACROMED\FLASH\FLASH9.OCX

C:\WINNT\SYSTEM32\MSTASK.EXE
C:\WINNT\SYSTEM32\WUAUCLT.EXE
C:\WINNT\SYSTEM32\WUPS.DLL
C:\WINNT\SYSTEM32\WUPS2.DLL
C:\WINNT\SYSTEM32\WUCLTUI.DLL

C:\WINNT\SYSTEM32\SNMP.EXE
C:\WINNT\SYSTEM32\STISVC.EXE
C:\WINNT\SYSTEM32\WBEM\WINMGMT.EXE
C:\WINNT\SYSTEM32\SVCHOST.EXE
C:\WINNT\SYSTEM32\WUPS.DLL
C:\WINNT\SYSTEM32\WUPS2.DLL
C:\WINNT\SYSTEM32\BITSPRX3.DLL
C:\WINNT\SYSTEM32\BITSPRX2.DLL

C:\WINNT\SYSTEM32\INETSRV\INETINFO.EXE
C:\WINNT\MICROSOFT.NET\FRAMEWORK\V1.1.4322\ASPNET_FILTER.DLL
C:\WINNT\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSVCR71.DLL

C:\WINNT\EXPLORER.EXE
C:\WINNT\APPPATCH\ACLAYERS.DLL
C:\WINNT\SYSTEM32\WDMAUD.DRV
C:\WINNT\SYSTEM32\MSACM32.DRV
E:\EWIDO ANTI-MALWARE\SHELLHOOK.DLL
C:\WINNT\SYSTEM32\MSVCR71.DLL
F:\RISING\RAV\RSCOMMON.DLL
C:\WINNT\SYSTEM32\MSADP32.ACM
F:\RISING\RAV\RAVSCRCH.DLL
E:\新建文件夹\ADOBE\ACROBAT 7.0\ACTIVEX\PDFSHELL.DLL

E:\TENCENT\QQ\QQ.EXE
E:\TENCENT\QQ\QQBASECLASSINDLL.DLL
E:\TENCENT\QQ\QQHELPERDLL.DLL
E:\TENCENT\QQ\BASICCTRLDLL.DLL
E:\TENCENT\QQ\MFC42.DLL
C:\WINNT\SYSTEM32\MSVCP60.DLL
E:\TENCENT\QQ\RICHED32.DLL
E:\TENCENT\QQ\RICHED20.DLL
E:\TENCENT\QQ\QQAPI.DLL
E:\TENCENT\QQ\TIMPROXY.DLL
E:\TENCENT\QQ\LOGINCTRL.DLL
E:\TENCENT\QQ\NPKCNTC.DLL
E:\TENCENT\QQ\NPKPDB.DLL
E:\TENCENT\QQ\QQRES.DLL
E:\TENCENT\QQ\QQMAINFRAME.DLL
E:\TENCENT\QQ\CQQAPPLICATION.DLL
E:\TENCENT\QQ\NEWSKIN.DLL
E:\TENCENT\QQ\HOSTINGMGR.DLL
E:\TENCENT\QQ\CAMERADLL.DLL
E:\TENCENT\QQ\MAILSUMMARY.DLL
E:\TENCENT\QQ\QQSPACE.DLL
E:\TENCENT\QQ\VBSCRIPT.DLL
E:\TENCENT\QQ\QQGROUPMNG.DLL
E:\TENCENT\QQ\GROUPLIVE.DLL
E:\TENCENT\QQ\QQSYSMSGMNG.DLL
E:\TENCENT\QQ\USERDEFINEDHEAD.DLL
E:\TENCENT\QQ\QQPLUGIN.DLL
E:\TENCENT\QQ\QQCONFIGPLUGIN.DLL
E:\TENCENT\QQ\QRINGMNG.DLL
E:\TENCENT\QQ\PHONEAPI.DLL
E:\TENCENT\QQ\DIALERALLINONE.DLL
C:\WINNT\SYSTEM32\WDMAUD.DRV
E:\TENCENT\QQ\VPORTAL.DLL
E:\TENCENT\QQ\LONGCONNECTION.DLL
E:\TENCENT\QQ\QQAVATAR.DLL
E:\TENCENT\QQ\FLASHAVATARDLL.DLL
E:\TENCENT\QQ\QQPET.DLL
E:\EWIDO ANTI-MALWARE\SHELLHOOK.DLL
C:\WINNT\SYSTEM32\MSVCR71.DLL
E:\TENCENT\QQ\BQQAPPLICATION.DLL
E:\TENCENT\QQ\COMMERCESMNG.DLL
E:\TENCENT\QQ\PERSONALDESKTOP.DLL
E:\TENCENT\QQ\QQADDR.DLL
E:\TENCENT\QQ\QQSCENEMNG.DLL
E:\TENCENT\QQ\QQPHONEHELPER.DLL

E:\TENCENT\QQ\QQPET\QQPET.EXE
E:\TENCENT\QQ\MFC42.DLL
C:\WINNT\SYSTEM32\MSVCP60.DLL
E:\TENCENT\QQ\QQPET\GDIPLUS.DLL
E:\TENCENT\QQ\QQPET\QQPETRESDOWNLOAD.DLL
E:\TENCENT\QQ\QQPET\QQPETCOMMUNITY.DLL
C:\WINNT\SYSTEM32\MACROMED\FLASH\FLASH9.OCX
C:\WINNT\SYSTEM32\WDMAUD.DRV
C:\WINNT\SYSTEM32\MSACM32.DRV
E:\DOWNLOADS\QQ宠物管家\PETSKINHOOK.DLL
F:\RISING\RAV\RAVSCRCH.DLL
C:\WINNT\SYSTEM32\MSADP32.ACM

C:\WINNT\SYSTEM32\SVCHOST.EXE
C:\WINNT\SYSTEM32\BITSPRX3.DLL
C:\WINNT\SYSTEM32\BITSPRX2.DLL

E:\DOWNLOADS\QQ宠物管家\QQPETSKINMONITOR.EXE
E:\DOWNLOADS\QQ宠物管家\PETDOCTOR.EXE
E:\DOWNLOADS\QQ宠物管家\PETSKINHOOK.DLL
E:\EWIDO ANTI-MALWARE\SHELLHOOK.DLL
C:\WINNT\SYSTEM32\MSVCR71.DLL
F:\RISING\RAV\RAVSCRCH.DLL

C:\DOCUMENTS AND SETTINGS\财务\桌面\RAV18_35_11\RSDETECT.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
E:\TENCENT\QQ\QQIEHELPER.DLL
C:\WINNT\SYSTEM32\WDMAUD.DRV
C:\WINNT\SYSTEM32\MSACM32.DRV
C:\WINNT\SYSTEM32\MSADP32.ACM
F:\RISING\RAV\RAVSCRCH.DLL
C:\WINNT\SYSTEM32\MACROMED\FLASH\FLASH9.OCX
C:\WINNT\SYSTEM32\MSCOREE.DLL
C:\WINNT\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSCORIE.DLL
C:\WINNT\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSVCR71.DLL
C:\WINNT\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSCORLD.DLL

E:\TENCENT\QQ\QQPET\QQPET.EXE
E:\TENCENT\QQ\MFC42.DLL
C:\WINNT\SYSTEM32\MSVCP60.DLL
E:\TENCENT\QQ\QQPET\GDIPLUS.DLL
E:\TENCENT\QQ\QQPET\QQPETRESDOWNLOAD.DLL
E:\TENCENT\QQ\QQPET\QQPETCOMMUNITY.DLL
C:\WINNT\SYSTEM32\MACROMED\FLASH\FLASH9.OCX
C:\WINNT\SYSTEM32\WDMAUD.DRV
C:\WINNT\SYSTEM32\MSACM32.DRV
E:\DOWNLOADS\QQ宠物管家\PETSKINHOOK.DLL
最后编辑2006-10-19 15:31:37
分享到:
gototop
 

普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Synchronization Manager = MOBSYNC.EXE /LOGON


系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "d:\Program Files\Microsoft Office\Office\WINWORD.EXE" /n

其它启动项
WIN.INI
无信息

SYSTEM.INI
SHELL = Explorer.exe


Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
termsrv = WLNOTIFY.DLL
wzcnotif = WZCDLG.DLL

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = C:\WINNT\SYSTEM32\USERINIT.EXE
shell = EXPLORER.EXE


IE - BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{54EBD53A-9BC1-480B-966A-843A333CA162} = e:\Tencent\QQ\QQIEHelper.dll


Winsock SPI
MSAFD Tcpip [TCP/IP] = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD Tcpip [UDP/IP] = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD Tcpip [RAW/IP] = C:\WINNT\SYSTEM32\MSAFD.DLL
RSVP UDP Service Provider = C:\WINNT\SYSTEM32\RSVPSP.DLL
RSVP TCP Service Provider = C:\WINNT\SYSTEM32\RSVPSP.DLL
MSAFD NetBIOS [\Device\Nbf_{C614B431-F228-4286-BA9F-AAB517430808}] SEQPACKET 3 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\Nbf_{C614B431-F228-4286-BA9F-AAB517430808}] DATAGRAM 3 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{16885156-49F9-4EFB-87D2-7551286FD517}] SEQPACKET 4 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{16885156-49F9-4EFB-87D2-7551286FD517}] DATAGRAM 4 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{625DBC3A-39A9-4CC9-9A11-AB959DE3A194}] SEQPACKET 5 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{625DBC3A-39A9-4CC9-9A11-AB959DE3A194}] DATAGRAM 5 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{E7AF44D0-A956-4B7A-85A1-76ACF6E10228}] SEQPACKET 6 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{E7AF44D0-A956-4B7A-85A1-76ACF6E10228}] DATAGRAM 6 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{DBB0EE58-854B-4DAB-ADDA-EAF7E261C5E0}] SEQPACKET 7 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{DBB0EE58-854B-4DAB-ADDA-EAF7E261C5E0}] DATAGRAM 7 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{05FFAC63-6510-4189-AEB1-11167D954B2C}] SEQPACKET 8 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{05FFAC63-6510-4189-AEB1-11167D954B2C}] DATAGRAM 8 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{6D31509A-68C7-40DB-84B0-18286E7FCF80}] SEQPACKET 9 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{6D31509A-68C7-40DB-84B0-18286E7FCF80}] DATAGRAM 9 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{C614B431-F228-4286-BA9F-AAB517430808}] SEQPACKET 0 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{C614B431-F228-4286-BA9F-AAB517430808}] DATAGRAM 0 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{DDC02D4E-D3BC-476F-B621-773301DDF1BC}] SEQPACKET 1 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{DDC02D4E-D3BC-476F-B621-773301DDF1BC}] DATAGRAM 1 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{8C19FCA0-BC55-4BC0-B401-3449C36E8EF4}] SEQPACKET 2 = C:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{8C19FCA0-BC55-4BC0-B401-3449C36E8EF4}] DATAGRAM 2 = C:\WINNT\SYSTEM32\MSAFD.DLL
gototop
 

系统服务项
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
Alerter = C:\WINNT\SYSTEM32\SERVICES.EXE
AppMgmt = C:\WINNT\SYSTEM32\SERVICES.EXE
aspnet_state = C:\WINNT\MICROSOFT.NET\FRAMEWORK\V1.1.4322\ASPNET_STATE.EXE
BITS = C:\WINNT\SYSTEM32\SVCHOST.EXE -K BITSGROUP
Browser = C:\WINNT\SYSTEM32\SERVICES.EXE
cisvc = C:\WINNT\SYSTEM32\CISVC.EXE
ClipSrv = C:\WINNT\SYSTEM32\CLIPSRV.EXE
Dhcp = C:\WINNT\SYSTEM32\SERVICES.EXE
dmadmin = C:\WINNT\SYSTEM32\DMADMIN.EXE /COM
dmserver = C:\WINNT\SYSTEM32\SERVICES.EXE
Dnscache = C:\WINNT\SYSTEM32\SERVICES.EXE
Eventlog = C:\WINNT\SYSTEM32\SERVICES.EXE
EventSystem = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
ewido security suite control = E:\EWIDO ANTI-MALWARE\EWIDOCTRL.EXE
ewido security suite guard = E:\EWIDO ANTI-MALWARE\EWIDOGUARD.EXE
Fax = C:\WINNT\SYSTEM32\FAXSVC.EXE
IISADMIN = C:\WINNT\SYSTEM32\INETSRV\INETINFO.EXE
lanmanserver = C:\WINNT\SYSTEM32\SERVICES.EXE
lanmanworkstation = C:\WINNT\SYSTEM32\SERVICES.EXE
LmHosts = C:\WINNT\SYSTEM32\SERVICES.EXE
Messenger = C:\WINNT\SYSTEM32\SERVICES.EXE
mnmsrvc = C:\WINNT\SYSTEM32\MNMSRVC.EXE
MSDTC = C:\WINNT\SYSTEM32\MSDTC.EXE
MSFTPSVC = C:\WINNT\SYSTEM32\INETSRV\INETINFO.EXE
MSIServer = C:\WINNT\SYSTEM32\MSIEXEC.EXE /V
NetDDE = C:\WINNT\SYSTEM32\NETDDE.EXE
NetDDEdsdm = C:\WINNT\SYSTEM32\NETDDE.EXE
Netlogon = C:\WINNT\SYSTEM32\LSASS.EXE
Netman = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
NtLmSsp = C:\WINNT\SYSTEM32\LSASS.EXE
NtmsSvc = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
PlugPlay = C:\WINNT\SYSTEM32\SERVICES.EXE
PolicyAgent = C:\WINNT\SYSTEM32\LSASS.EXE
ProtectedStorage = C:\WINNT\SYSTEM32\SERVICES.EXE
RasAuto = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
RasMan = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
RemoteAccess = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
RemoteRegistry = C:\WINNT\SYSTEM32\REGSVC.EXE
RpcLocator = C:\WINNT\SYSTEM32\LOCATOR.EXE
RpcSs = C:\WINNT\SYSTEM32\SVCHOST -K RPCSS
RsCCenter = "F:\RISING\RAV\CCENTER.EXE"
RsRavMon = "F:\RISING\RAV\RAVMOND.EXE"
RSVP = C:\WINNT\SYSTEM32\RSVP.EXE -S
SamSs = C:\WINNT\SYSTEM32\LSASS.EXE
SCardDrv = C:\WINNT\SYSTEM32\SCARDSVR.EXE
SCardSvr = C:\WINNT\SYSTEM32\SCARDSVR.EXE
Schedule = C:\WINNT\SYSTEM32\MSTASK.EXE
seclogon = C:\WINNT\SYSTEM32\SERVICES.EXE
SENS = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
SharedAccess = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
SMTPSVC = C:\WINNT\SYSTEM32\INETSRV\INETINFO.EXE
SNMP = C:\WINNT\SYSTEM32\SNMP.EXE
Spooler = C:\WINNT\SYSTEM32\SPOOLSV.EXE
StiSvc = C:\WINNT\SYSTEM32\STISVC.EXE
SysmonLog = C:\WINNT\SYSTEM32\SMLOGSVC.EXE
TapiSrv = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
TlntSvr = C:\WINNT\SYSTEM32\TLNTSVR.EXE
TrkWks = C:\WINNT\SYSTEM32\SERVICES.EXE
UPS = C:\WINNT\SYSTEM32\UPS.EXE
UtilMan = C:\WINNT\SYSTEM32\UTILMAN.EXE
W32Time = C:\WINNT\SYSTEM32\SERVICES.EXE
W3SVC = C:\WINNT\SYSTEM32\INETSRV\INETINFO.EXE
WinMgmt = C:\WINNT\SYSTEM32\WBEM\WINMGMT.EXE
Wmi = C:\WINNT\SYSTEM32\SERVICES.EXE
wuauserv = C:\WINNT\SYSTEM32\SVCHOST.EXE -K WUGROUP
WZCSVC = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS


文件驱动
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
FltMgr = C:\WINNT\SYSTEM32\DRIVERS\FLTMGR.SYS
MRxSmb = C:\WINNT\SYSTEM32\DRIVERS\MRXSMB.SYS
NetBIOS = C:\WINNT\SYSTEM32\DRIVERS\NETBIOS.SYS
Rdbss = C:\WINNT\SYSTEM32\DRIVERS\RDBSS.SYS
Srv = C:\WINNT\SYSTEM32\DRIVERS\SRV.SYS


系统驱动项
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
ACPI = C:\WINNT\SYSTEM32\DRIVERS\ACPI.SYS
AFD = C:\WINNT\SYSTEM32\DRIVERS\AFD.SYS
ALCXSENS = C:\WINNT\SYSTEM32\DRIVERS\ALCXSENS.SYS
ALCXWDM = C:\WINNT\SYSTEM32\DRIVERS\ALCXWDM.SYS
Anfad = C:\WINNT\SYSTEM32\DRIVERS\ANFAD.SYS
AsyncMac = C:\WINNT\SYSTEM32\DRIVERS\ASYNCMAC.SYS
atapi = C:\WINNT\SYSTEM32\DRIVERS\ATAPI.SYS
Atmarpc = C:\WINNT\SYSTEM32\DRIVERS\ATMARPC.SYS
audstub = C:\WINNT\SYSTEM32\DRIVERS\AUDSTUB.SYS
BaseTDI = C:\WINNT\SYSTEM32\DRIVERS\BASETDI.SYS
ccdecode = C:\WINNT\SYSTEM32\DRIVERS\CCDECODE.SYS
Cdrom = C:\WINNT\SYSTEM32\DRIVERS\CDROM.SYS
Disk = C:\WINNT\SYSTEM32\DRIVERS\DISK.SYS
dmboot = C:\WINNT\SYSTEM32\DRIVERS\DMBOOT.SYS
dmio = C:\WINNT\SYSTEM32\DRIVERS\DMIO.SYS
dmload = C:\WINNT\SYSTEM32\DRIVERS\DMLOAD.SYS
DMusic = C:\WINNT\SYSTEM32\DRIVERS\DMUSIC.SYS
ewido anti-spyware 4.0 driver = E:\EWIDO ANTI-SPYWARE 4.0\GUARD.SYS
ewido security suite driver = E:\EWIDO ANTI-MALWARE\GUARD.SYS
ExpScaner = F:\RISING\RAV\EXPSCAN.SYS
FAD = C:\WINNT\SYSTEM32\DRIVERS\FAD.SYS
Fdc = C:\WINNT\SYSTEM32\DRIVERS\FDC.SYS
Flpydisk = C:\WINNT\SYSTEM32\DRIVERS\FLPYDISK.SYS
FsVga = C:\WINNT\SYSTEM32\DRIVERS\FSVGA.SYS
Ftdisk = C:\WINNT\SYSTEM32\DRIVERS\FTDISK.SYS
gameenum = C:\WINNT\SYSTEM32\DRIVERS\GAMEENUM.SYS
Gpc = C:\WINNT\SYSTEM32\DRIVERS\MSGPC.SYS
GPKiller = C:\WINNT\SYSTEM32\DRIVERS\GPKILLER.SYS
hidusb = C:\WINNT\SYSTEM32\DRIVERS\HIDUSB.SYS
HookCont = F:\RISING\RAV\HOOKCONT.SYS
HookReg = F:\RISING\RAV\HOOKREG.SYS
HookSys = F:\RISING\RAV\HOOKSYS.SYS
hwmouser = C:\WINNT\SYSTEM32\DRIVERS\HWPAD_NT.SYS
i8042prt = C:\WINNT\SYSTEM32\DRIVERS\I8042PRT.SYS
ialm = C:\WINNT\SYSTEM32\DRIVERS\IALMNT5.SYS
IntelIde = C:\WINNT\SYSTEM32\DRIVERS\INTELIDE.SYS
IpFilterDriver = C:\WINNT\SYSTEM32\DRIVERS\IPFLTDRV.SYS
IpInIp = C:\WINNT\SYSTEM32\DRIVERS\IPINIP.SYS
IpNat = C:\WINNT\SYSTEM32\DRIVERS\IPNAT.SYS
IPSEC = C:\WINNT\SYSTEM32\DRIVERS\IPSEC.SYS
IRENUM = C:\WINNT\SYSTEM32\DRIVERS\IRENUM.SYS
isapnp = C:\WINNT\SYSTEM32\DRIVERS\ISAPNP.SYS
Kbdclass = C:\WINNT\SYSTEM32\DRIVERS\KBDCLASS.SYS
KLIF = C:\WINNT\SYSTEM32\DRIVERS\KLIF.SYS
Klpf = C:\WINNT\SYSTEM32\DRIVERS\KLPF.SYS
Klpid = C:\WINNT\SYSTEM32\DRIVERS\KLPID.SYS
kmixer = C:\WINNT\SYSTEM32\DRIVERS\KMIXER.SYS
KRegEx = F:\KV2006\KREGEX.SYS
KvMemon = F:\KV2006\KVMEMON.SYS
MEMSCAN = F:\RISING\RAV\MEMSCAN.SYS
Mouclass = C:\WINNT\SYSTEM32\DRIVERS\MOUCLASS.SYS
mouhid = C:\WINNT\SYSTEM32\DRIVERS\MOUHID.SYS
MSKSSRV = C:\WINNT\SYSTEM32\DRIVERS\MSKSSRV.SYS
MSPCLOCK = C:\WINNT\SYSTEM32\DRIVERS\MSPCLOCK.SYS
MSPQM = C:\WINNT\SYSTEM32\DRIVERS\MSPQM.SYS
MSTEE = C:\WINNT\SYSTEM32\DRIVERS\MSTEE.SYS
ms_mpu401 = C:\WINNT\SYSTEM32\DRIVERS\MSMPU401.SYS
NAVAPEL = C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\NAVAPEL.SYS
Nbf = C:\WINNT\SYSTEM32\DRIVERS\NBF.SYS
NdisTapi = C:\WINNT\SYSTEM32\DRIVERS\NDISTAPI.SYS
Ndisuio = C:\WINNT\SYSTEM32\DRIVERS\NDISUIO.SYS
NdisWan = C:\WINNT\SYSTEM32\DRIVERS\NDISWAN.SYS
NetBT = C:\WINNT\SYSTEM32\DRIVERS\NETBT.SYS
NetDetect = C:\WINNT\SYSTEM32\DRIVERS\NETDTECT.SYS
npkcrypt = E:\TENCENT\QQ\NPKCRYPT.SYS
NwlnkFlt = C:\WINNT\SYSTEM32\DRIVERS\NWLNKFLT.SYS
NwlnkFwd = C:\WINNT\SYSTEM32\DRIVERS\NWLNKFWD.SYS
o4a = C:\WINNT\SYSTEM32\DRIVERS\O4A.SYS
oshack20.sys = C:\WINNT\SYSTEM32\DRIVERS\OSHACK20.SYS
Parallel = C:\WINNT\SYSTEM32\DRIVERS\PARALLEL.SYS
Parport = C:\WINNT\SYSTEM32\DRIVERS\PARPORT.SYS
PCI = C:\WINNT\SYSTEM32\DRIVERS\PCI.SYS
PCIIde = C:\WINNT\SYSTEM32\DRIVERS\PCIIDE.SYS
PProtect = F:\KV2006\PPROTECT.SYS
PptpMiniport = C:\WINNT\SYSTEM32\DRIVERS\RASPPTP.SYS
Ptilink = C:\WINNT\SYSTEM32\DRIVERS\PTILINK.SYS
R2A = C:\WINNT\SYSTEM32A2.SYS
RasAcd = C:\WINNT\SYSTEM32\DRIVERS\RASACD.SYS
Rasl2tp = C:\WINNT\SYSTEM32\DRIVERS\RASL2TP.SYS
Raspti = C:\WINNT\SYSTEM32\DRIVERS\RASPTI.SYS
RCA = C:\WINNT\SYSTEM32\DRIVERS\RCA.SYS
redbook = C:\WINNT\SYSTEM32\DRIVERS\REDBOOK.SYS
rtl8139 = C:\WINNT\SYSTEM32\DRIVERS\RTL8139.SYS
serenum = C:\WINNT\SYSTEM32\DRIVERS\SERENUM.SYS
Serial = C:\WINNT\SYSTEM32\DRIVERS\SERIAL.SYS
swenum = C:\WINNT\SYSTEM32\DRIVERS\SWENUM.SYS
swmidi = C:\WINNT\SYSTEM32\DRIVERS\SWMIDI.SYS
sysaudio = C:\WINNT\SYSTEM32\DRIVERS\SYSAUDIO.SYS
Tcpip = C:\WINNT\SYSTEM32\DRIVERS\TCPIP.SYS
TDDI = C:\WINNT\SYSTEM32\DRIVERS\TDDI.SYS
uhcd = C:\WINNT\SYSTEM32\DRIVERS\UHCD.SYS
Update = C:\WINNT\SYSTEM32\DRIVERS\UPDATE.SYS
usbehci = C:\WINNT\SYSTEM32\DRIVERS\USBEHCI.SYS
usbhub = C:\WINNT\SYSTEM32\DRIVERS\USBHUB.SYS
usbhub20 = C:\WINNT\SYSTEM32\DRIVERS\USBHUB20.SYS
usbprint = C:\WINNT\SYSTEM32\DRIVERS\USBPRINT.SYS
USBSTOR = C:\WINNT\SYSTEM32\DRIVERS\USBSTOR.SYS
VgaSave = C:\WINNT\SYSTEM32\DRIVERS\VGA.SYS
Wanarp = C:\WINNT\SYSTEM32\DRIVERS\WANARP.SYS
wdmaud = C:\WINNT\SYSTEM32\DRIVERS\WDMAUD.SYS
WINIO = C:\WINNT\DOWNLOADED PROGRAM FILES\CONFLICT.3\WINIO.SYS
WS2IFSL = C:\WINNT\SYSTEM32\DRIVERS\WS2IFSL.SYS
ZSMC303 = C:\WINNT\SYSTEM32\DRIVERS\USBVM303.SYS
{6080A529-897E-4629-A488-ABA0C29B635E} = C:\WINNT\SYSTEM32\DRIVERS\IALMSBW.SYS
{D31A0762-0CEB-444e-ACFF-B049A1F6FE91} = C:\WINNT\SYSTEM32\DRIVERS\IALMKCHW.SYS
gototop
 

看这个东西没有用,感觉哪里有问题吗?
gototop
 

没用?那弄这个听诊器给谁看的,我的机子前两天中标了,不知道有没有彻底好?
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT