未知家族病毒分析
扫描结果:
无可疑文件
系统活动进程
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\PROGRAM FILES\木马清除大师2008\BTHELPSEVEN.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSTUB.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\RISING\RAV\PROCCOM.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMX2.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\PROGRAM FILES\RISING\RFW\RSGUILIB.DLL
C:\PROGRAM FILES\RISING\RFW\PROCCOM.DLL
C:\PROGRAM FILES\RISING\RFW\RSCOMMX2.DLL
C:\PROGRAM FILES\RISING\RFW\RSAPPMGR.DLL
C:\PROGRAM FILES\RISING\RFW\CFGDLL.DLL
C:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RFW\RFWCTRL.DLL
C:\PROGRAM FILES\RISING\RFW\RSXML.DLL
C:\PROGRAM FILES\RISING\RFW\PNGDLL.DLL
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\桌面\新建文件夹\RSDETECT.EXE
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\COMX3.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\SYSLAY.DLL
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\LSSRVC.EXE
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\LSSPROXY.DLL
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\LSLOG.DLL
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\木马清除大师2008\BTHELPSEVEN.DLL
C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE
C:\PROGRAM FILES\RISING\RAV\PROCCOM.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMX2.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\PROGRAM FILES\RISING\RAV\RAVMON.EXE
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\PROGRAM FILES\RISING\RAV\PROCCOM.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMX2.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RAV\RECOMP.DLL
C:\PROGRAM FILES\RISING\RAV\REFS.DLL
C:\PROGRAM FILES\RISING\RAV\VIRUSLIB.DLL
C:\PROGRAM FILES\RISING\RAV\RELIBLDR.DLL
C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
C:\PROGRAM FILES\RISING\RAV\MONRULE.DLL
C:\PROGRAM FILES\RISING\RAV\PNGDLL.DLL
C:\PROGRAM FILES\RISING\RAV\RSGUILIB.DLL
C:\PROGRAM FILES\RISING\RAV\RSXML.DLL
C:\PROGRAM FILES\木马清除大师2008\BEATTROJANMON.EXE
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\WINDOWS\SYSTEM32\MSVBVM60.DLL
C:\PROGRAM FILES\木马清除大师2008\BTHELPONE.DLL
C:\PROGRAM FILES\木马清除大师2008\EGHELPERONE.DLL
C:\PROGRAM FILES\木马清除大师2008\BTHELPTHREE.DLL
C:\PROGRAM FILES\木马清除大师2008\SYSTEMGUARDDELETE.DLL
C:\PROGRAM FILES\木马清除大师2008\BTHELPEIGHT.DLL
C:\PROGRAM FILES\木马清除大师2008\SYSTEMGUARDHELPER.DLL
C:\PROGRAM FILES\木马清除大师2008\BTHELPTWO.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\RSTRAY.EXE
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\RSMGINFO.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\RSXML.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\MSVCP71.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\MSVCR71.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\COMSERV.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\SYSLAY.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\COMX3.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\PNGDLL.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\NCOMM.DLL
C:\PROGRAM FILES\RISING\RAV\PROCCOM.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMX2.DLL
C:\PROGRAM FILES\木马清除大师2008\BTHELPSEVEN.DLL
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMBGMONITOR.EXE
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\SHARED\NL3\ADVRCNTR3.DLL
C:\PROGRAM FILES\木马清除大师2008\BTHELPSEVEN.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMINDEXINGSERVICEPS.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMINDEXSTORESVRPS.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMDATASERVICES.DLL
C:\WINDOWS\SYSTEM32\PNKBSTRA.EXE
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\木马清除大师2008\BTHELPSEVEN.DLL
C:\PROGRAM FILES\NERO\NERO8\NERO BACKITUP\NBSERVICE.EXE
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\NERO\NERO8\NERO BACKITUP\NB.DLL
C:\PROGRAM FILES\NERO\NERO8\NERO BACKITUP\NEROAPIGLUELAYERUNICODE.DLL
C:\PROGRAM FILES\NERO\NERO8\NERO BACKITUP\LBFC.DLL
C:\PROGRAM FILES\NERO\NERO8\NERO BACKITUP\NBHDMGR.DLL
C:\PROGRAM FILES\木马清除大师2008\BTHELPSEVEN.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\WINS\NQADZDREY.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\OFFICE11\MSOXMLMF.DLL
C:\PROGRAM FILES\RISING\RFW\RFWSRV.EXE
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\PROGRAM FILES\RISING\RFW\RSAPPMGR.DLL
C:\PROGRAM FILES\RISING\RFW\CFGDLL.DLL
C:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL
C:\PROGRAM FILES\RISING\RFW\RFWLOG.DLL
C:\PROGRAM FILES\RISING\RFW\RFWDRV.DLL
C:\PROGRAM FILES\RISING\RFW\PSAPI.DLL
C:\PROGRAM FILES\RISING\RFW\IJT_CTRL.DLL
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\UNVDET.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\RISING\RFW\MPORTS.DLL
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\LIGHTSCRIBECONTROLPANEL.EXE
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\QTCORE4.DLL
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\QTGUI4.DLL
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\PLUGINS\IMAGEFORMATS\QJPEG4.DLL
C:\PROGRAM FILES\木马清除大师2008\BTHELPSEVEN.DLL
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\NVAPI.DLL
C:\PROGRAM FILES\木马清除大师2008\BTHELPSEVEN.DLL
C:\PROGRAM FILES\RISING\RAV\RAVMOND.EXE
C:\PROGRAM FILES\RISING\RAV\BWLIST.DLL
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
C:\PROGRAM FILES\RISING\RAV\RSLOG.DLL
C:\PROGRAM FILES\RISING\RAV\PROCCOM.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMX2.DLL
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RAV\MONRULE.DLL
C:\PROGRAM FILES\RISING\RAV\HOOKSYS.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\RISING\RAV\HOOKREG.DLL
C:\PROGRAM FILES\RISING\RAV\HOOKNTOS.DLL
C:\PROGRAM FILES\RISING\RAV\RSWALMON.DLL
C:\PROGRAM FILES\RISING\RAV\RECOMP.DLL
C:\PROGRAM FILES\RISING\RAV\REFS.DLL
C:\PROGRAM FILES\RISING\RAV\FFR.DLL
C:\PROGRAM FILES\RISING\RAV\RSSTORE.DLL
C:\PROGRAM FILES\RISING\RAV\FAKESCAN.DLL
C:\PROGRAM FILES\RISING\RAV\SCANNER.DLL
C:\PROGRAM FILES\RISING\RAV\EXTFILE.DLL
C:\PROGRAM FILES\RISING\RAV\PEARC.DLL
C:\PROGRAM FILES\RISING\RAV\HOOKWEB.DLL
C:\PROGRAM FILES\RISING\RAV\VIRUSLIB.DLL
C:\PROGRAM FILES\RISING\RAV\RELIBLDR.DLL
C:\PROGRAM FILES\RISING\RAV\NVFILE.DLL
C:\PROGRAM FILES\RISING\RAV\SCANEXEC.DLL
C:\PROGRAM FILES\RISING\RAV\UNEXE.DLL
C:\PROGRAM FILES\RISING\RAV\SCANEX.DLL
C:\PROGRAM FILES\RISING\RAV\SCANSCT.DLL
C:\PROGRAM FILES\RISING\RAV\SCANPACK.DLL
C:\PROGRAM FILES\RISING\RAV\REVM.DLL
C:\PROGRAM FILES\RISING\RAV\URUTILS.DLL
C:\PROGRAM FILES\RISING\RAV\UR000.DAT
C:\PROGRAM FILES\RISING\RAV\SCRIPTCI.DLL
C:\PROGRAM FILES\RISING\RAV\UROUTINE.DLL
C:\PROGRAM FILES\RISING\RFW\RFWSTUB.EXE
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL
C:\WINDOWS\SYSTEM32\CFJMP.EXE
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\木马清除大师2008\BTHELPSEVEN.DLL
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\DHMQU.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\TDATONCE_NOW.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_NOW.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DSBHO_00.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DATAPROCESSOR_00.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\木马清除大师2008\BTHELPSEVEN.DLL
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
C:\PROGRAM FILES\木马清除大师2008\BEATTROJANSHIELDS.EXE
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\MSVBVM60.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMINDEXINGSERVICE.EXE
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMINDEXINGSERVICEPS.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMLOGCXX.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\LOG4CXX.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMDATASERVICES.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMINDEXSTORESVR.EXE
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMSQLDB.DLL
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMLOGCXX.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\LOG4CXX.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMINDEXINGSERVICEPS.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMCOFOUNDATION.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMPLUGINBASE.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMFULLTEXTEXTRACTION.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMSEARCHPLUGINSIMILARIMAGES.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMDATASERVICES.DLL
C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMINDEXSTORESVRPS.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\RFW\IJT_BASE.DLL
C:\PROGRAM FILES\RISING\RFW\OLEMON.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\KNOWNSVR.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\NCOMM.DLL
C:\WINDOWS\SYSTEM32\KMON.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\COMX3.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\SYSLAY.DLL
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\SYSTEM32\NVCPL.DLL,NVSTARTUP
RavTask = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
RfwMain = "C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE" -STARTUP
Hard Disk Sentinel = C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RARSFX0\HDSENTINEL.EXE
NeroFilterCheck = C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NEROCHECK.EXE
Alcmtr = ; ALCMTR.EXE
AlcWzrd = ; ALCWZRD.EXE
amd_dc_opt = ; C:\PROGRAM FILES\AMD\DUAL-CORE OPTIMIZER\AMD_DC_OPT.EXE
IMJPMIG8.1 = ; "C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE" /SPOIL /REMADVDEF /MIGRATION32
NvMediaCenter = ; RUNDLL32.EXE C:\WINDOWS\SYSTEM32\NVMCTRAY.DLL,NVTASKBARINIT
nwiz = ; NWIZ.EXE /INSTALL
PHIME2002A = ; C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME
PHIME2002ASync = ; C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC
RTHDCPL = ; RTHDCPL.EXE
SkyTel = ; SKYTEL.EXE
SoundMan = ; SOUNDMAN.EXE
BeatTrojan = C:\PROGRAM FILES\木马清除大师2008\BEATTROJANMON.EXE
runeip = "C:\PROGRAM FILES\RISING\ANTISPYWARE\RSTRAY.EXE" /STARTUP
HBService32 = SYSTEM.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay = C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNONCE.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
kub12 = KUB12.EXE
dlnjjbdfa = C:\WINDOWS\SYSTEM\LLWZJY080923.EXE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} = "C:\PROGRAM FILES\COMMON FILES\NERO\LIB\NMBGMONITOR.EXE"
LightScribe Control Panel = C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\LIGHTSCRIBECONTROLPANEL.EXE -HIDDEN
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde
其它启动项
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
SCRNSAVE.EXE = C:\WINDOWS\System32\logon.scr
Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
ScCertProp = WLNOTIFY.DLL
Schedule = WLNOTIFY.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
termsrv = WLNOTIFY.DLL
wlballoon = WLNOTIFY.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = C:\WINDOWS\SYSTEM32\USERINIT.EXE,
shell = EXPLORER.EXE
IE - BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{01443AEC-0FD1-40fd-9C87-E93D1494C233} = D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7} = C:\Program Files\FlashGet\jccatch.dll
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} = D:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll
{686488AF-13D5-9DDF-4FEF-9FB88698CFC1} = C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2210.dll
{889D2FEB-5411-4565-8998-1DD2C5261283} = D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll
{F156768E-81EF-470C-9057-481BA8380DBA} = C:\Program Files\FlashGet\getflash.dll
Winsock SPI
MSAPI Tcpip [TCP/IP] = C:\WINDOWS\SYSTEM32\WRM32.DLL
MSAFD Tcpip [TCP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [UDP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [RAW/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
RSVP UDP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
RSVP TCP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{50F37D71-30E2-4F13-9A72-D4B961627749}] SEQPACKET 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{50F37D71-30E2-4F13-9A72-D4B961627749}] DATAGRAM 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{56D1430C-5C3A-4ECD-AB68-A222AC427D2E}] SEQPACKET 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{56D1430C-5C3A-4ECD-AB68-A222AC427D2E}] DATAGRAM 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D2A4FFC9-D262-41A4-A6D8-2C63B75026C5}] SEQPACKET 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D2A4FFC9-D262-41A4-A6D8-2C63B75026C5}] DATAGRAM 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{7E4BCF4E-8CCC-4BFF-839A-C356877DB2F2}] SEQPACKET 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{7E4BCF4E-8CCC-4BFF-839A-C356877DB2F2}] DATAGRAM 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{A939F840-AF12-4360-9E57-AB11641811C5}] SEQPACKET 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{A939F840-AF12-4360-9E57-AB11641811C5}] DATAGRAM 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAPI Tcpip [UDP/IP] = C:\WINDOWS\SYSTEM32\WRM32.DLL