[BootExecute]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SYSTEM\CurrentControlSet\Control\Session Manager
1_Name=BootExecute
1_Value=autocheck autochk *
Max=1
[Startup]
Max=0
[AutoRun]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=Software\Microsoft\Windows\CurrentVersion\Run
1_Name=PHIME2002ASync
1_Value=c:\windows\system32\ime\tintlgnt\tintsetp.exe /sync
1_FileSize=455168
1_FileDate=2005-4-14 8:00:00
1_FileVersion=5.2.0.2801
1_FileCompanyName=Microsoft Corporation
2_HKey=HKEY_LOCAL_MACHINE
2_Key=Software\Microsoft\Windows\CurrentVersion\Run
2_Name=PHIME2002A
2_Value=c:\windows\system32\ime\tintlgnt\tintsetp.exe /imename
2_FileSize=455168
2_FileDate=2005-4-14 8:00:00
2_FileVersion=5.2.0.2801
2_FileCompanyName=Microsoft Corporation
3_HKey=HKEY_LOCAL_MACHINE
3_Key=Software\Microsoft\Windows\CurrentVersion\Run
3_Name=RavTask
3_Value="d:\rising\rav\ravtask.exe" -system
3_FileSize=118784
3_FileDate=2005-6-26 14:00:30
3_FileVersion=19.0.0.9
3_FileCompanyName=Beijing Rising Technology Co., Ltd.
4_HKey=HKEY_LOCAL_MACHINE
4_Key=Software\Microsoft\Windows\CurrentVersion\RunOnce
4_Name=mspora
4_Value=%systemroot%\system32\rundll32.exe %systemroot%\system32\mspora.dll,dllunregisterserver
4_FileSize=40960
4_FileDate=2005-6-26 17:47:56
4_FileVersion=5.1.2600.2945
4_FileCompanyName=Microsoft Corporation
5_HKey=HKEY_LOCAL_MACHINE
5_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
5_Name=MSDWG32
5_Value=lyloadbr.exe
6_HKey=HKEY_LOCAL_MACHINE
6_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
6_Name=MSDCG32
6_Value=lyleador.exe
7_HKey=HKEY_LOCAL_MACHINE
7_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
7_Name=MSDOG32
7_Value=lyloador.exe
8_HKey=HKEY_LOCAL_MACHINE
8_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
8_Name=MSDSG32
8_Value=lyloadar.exe
9_HKey=HKEY_LOCAL_MACHINE
9_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
9_Name=MSDHG32
9_Value=lyloadhr.exe
10_HKey=HKEY_LOCAL_MACHINE
10_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
10_Name=MSDQG32
10_Value=lyloadqr.exe
11_HKey=HKEY_LOCAL_MACHINE
11_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
11_Name=visin
11_Value=c:\windows\system32\visin.exe
11_FileSize=25625
11_FileDate=2007-3-8 23:37:22
11_FileVersion=5.1.2600.0
11_FileCompanyName=Microsoft Corporation
12_HKey=HKEY_LOCAL_MACHINE
12_Key=Software\Microsoft\Windows NT\CurrentVersion\Windows
12_Name=load
12_Value=
13_HKey=HKEY_LOCAL_MACHINE
13_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
13_Name=run
13_Value=
14_HKey=HKEY_CURRENT_USER
14_Key=Software\Microsoft\Windows\CurrentVersion\Run
14_Name=ctfmon.exe
14_Value=c:\windows\system32\ctfmon.exe
14_FileSize=15360
14_FileDate=2005-4-14
14_FileVersion=5.1.2600.2180
14_FileCompanyName=Microsoft Corporation
15_HKey=HKEY_CURRENT_USER
15_Key=Software\Microsoft\Windows NT\CurrentVersion\Windows
15_Name=load
15_Value=
Max=15
[Process]
1_FileName=C:\WINDOWS\SYSTEM32\SMSS.EXE
1_FileSize=50688
1_FileDate=2005-4-14
1_FileVersion=5.1.2600.2180
1_FileCompanyName=Microsoft Corporation
2_FileName=C:\WINDOWS\SYSTEM32\CSRSS.EXE
2_FileSize=6144
2_FileDate=2005-4-14
2_FileVersion=5.1.2600.2180
2_FileCompanyName=Microsoft Corporation
3_FileName=C:\WINDOWS\SYSTEM32\WINLOGON.EXE
3_FileSize=487424
3_FileDate=2005-4-14
3_FileVersion=5.1.2600.2180
3_FileCompanyName=Microsoft Corporation
4_FileName=C:\WINDOWS\SYSTEM32\SERVICES.EXE
4_FileSize=108032
4_FileDate=2005-4-14
4_FileVersion=5.1.2600.2180
4_FileCompanyName=Microsoft Corporation
5_FileName=C:\WINDOWS\SYSTEM32\LSASS.EXE
5_FileSize=13312
5_FileDate=2005-4-14
5_FileVersion=5.1.2600.2180
5_FileCompanyName=Microsoft Corporation
6_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
6_FileSize=14336
6_FileDate=2005-4-14
6_FileVersion=5.1.2600.2180
6_FileCompanyName=Microsoft Corporation
7_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
7_FileSize=14336
7_FileDate=2005-4-14
7_FileVersion=5.1.2600.2180
7_FileCompanyName=Microsoft Corporation
8_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
8_FileSize=14336
8_FileDate=2005-4-14
8_FileVersion=5.1.2600.2180
8_FileCompanyName=Microsoft Corporation
9_FileName=C:\WINDOWS\EXPLORER.EXE
9_FileSize=976896
9_FileDate=2005-4-14
9_FileVersion=6.0.2900.2180
9_FileCompanyName=Microsoft Corporation
10_FileName=C:\PROGRAM FILES\SUPER RABBIT\MAGICSET\SRIEH.EXE
10_FileSize=792576
10_FileDate=2007-6-3 22:45:42
10_FileVersion=7.99.0.0
10_FileCompanyName=Super Rabbit Soft
11_FileName=[SYSTEM PROCESS]
Max=11
[Hosts]
HostsFile=C:\WINDOWS\system32\Drivers\Etc\Hosts
1_Host=127.0.0.1 localhost
Max=1
[Service]
1_ServiceName=5181C0A4
1_DisplayName=5181C0A4
1_Description=29886D40
1_Status=停止
1_StartType=已禁用
1_ServiceDll=
1_ImagePath=C:\WINDOWS\SYSTEM32\6EC8C0F0.EXE -K
2_ServiceName=919mm
2_DisplayName=Provisioning Transaction Service
2_Description=客户端和服务器之间的 NET SEND 和 Alerter 服务消息。此服务与 Windows Messenger 无关。如果服务停止,Alerter 消息不会被传输。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。
2_Status=停止
2_StartType=已禁用
2_ServiceDll=
2_ImagePath=
3_ServiceName=AAA30D10
3_DisplayName=AAA30D10
3_Description=101132D8
3_Status=停止
3_StartType=自动
3_ServiceDll=
3_ImagePath=C:\WINDOWS\SYSTEM32\D4A5AA90.EXE -P
4_ServiceName=BRC_Services
4_DisplayName=BlackHole Remote Control Services
4_Description=BlackHole Remote Control Services
4_Status=停止
4_StartType=已禁用
4_ServiceDll=
4_ImagePath="C:\WINDOWS\SYSTEM32\BRC_SERVER.EXE" /SERVICE
5_ServiceName=kusn33sd
5_DisplayName=kusn33sd
5_Description=k1
5_Status=停止
5_StartType=自动
5_ServiceDll=
5_ImagePath=C:\WINDOWS\SYSTEM32\KUSN33SD.EXE -J
6_ServiceName=MSDebugsvc
6_DisplayName=Win32 Debug Service
6_Description=为计算机系统提供32位调试服务。如果此服务被禁用,所有明确依赖它的服务都将不能启动。
6_Status=停止
6_StartType=自动
6_ServiceDll=
6_ImagePath=C:\WINDOWS\SYSTEM32\RUNDLL32.EXE MSDEBUG.DLL,INPUT
7_ServiceName=msdmo
7_DisplayName=ms dmo
7_Description=msdmo
7_Status=停止
7_StartType=已禁用
7_ServiceDll=
7_ImagePath=C:\WINDOWS\SYSTEM32\MSDMO.EXE
8_ServiceName=ms_2fax
8_DisplayName=Fax 2Client
8_Description=
8_Status=停止
8_StartType=已禁用
8_ServiceDll=
8_ImagePath=
9_ServiceName=ose
9_DisplayName=Office Source Engine
9_Description=可保存用于更新和修复的安装文件,并且在下载安装程序更新和 Watson 错误报告时必须使用。
9_Status=停止
9_StartType=已禁用
9_ServiceDll=
9_ImagePath="C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\SOURCE ENGINE\OSE.EXE"
10_ServiceName=Plug Connection
10_DisplayName=Windows Connection Manager
10_Description=
10_Status=停止
10_StartType=已禁用
10_ServiceDll=
10_ImagePath=C:\WINDOWS\SYSTEM32\K11197779332.EXE
11_ServiceName=RsCCenter
11_DisplayName=Rising Process Communication Center
11_Description=
11_Status=停止
11_StartType=自动
11_ServiceDll=
11_ImagePath="D:\RISING\RAV\CCENTER.EXE"
12_ServiceName=RsRavMon
12_DisplayName=Rising RealTime Monitor
12_Description=
12_Status=停止
12_StartType=自动
12_ServiceDll=
12_ImagePath="D:\RISING\RAV\RAVMOND.EXE"
13_ServiceName=WinWLServiceNow
13_DisplayName=WinWLServiceNow
13_Description=
13_Status=停止
13_StartType=已禁用
13_ServiceDll=
13_ImagePath=
14_ServiceName=WinWMServiceNow
14_DisplayName=WinWMServiceNow
14_Description=
14_Status=停止
14_StartType=已禁用
14_ServiceDll=
14_ImagePath=
Max=14
[Driver]
1_ServiceName=BaseTDI
1_DisplayName=Rising TDI Base Driver
1_Description=
1_ServiceDll=
1_ImagePath=SYSTEM32\DRIVERS\BASETDI.SYS
2_ServiceName=bconusb
2_DisplayName=bconusb
2_Description=
2_ServiceDll=
2_ImagePath=C:\WINDOWS\SYSTEM32\MSCACHE\DISKMAN.SYS
3_ServiceName=Bluesky
3_DisplayName=Bluesky
3_Description=
3_ServiceDll=
3_ImagePath=C:\WINDOWS\SYSTEM32\WINCAB.SYS
4_ServiceName=CmBatt
4_DisplayName=Microsoft AC Adapter Driver
4_Description=
4_ServiceDll=
4_ImagePath=SYSTEM32\DRIVERS\CMBATT.SYS
5_ServiceName=E100B
5_DisplayName=Intel(R) PRO Adapter Driver
5_Description=
5_ServiceDll=
5_ImagePath=SYSTEM32\DRIVERS\E100B325.SYS
6_ServiceName=ev19x8mp
6_DisplayName=Creative SB AudioPCI Audio Driver (WDM)
6_Description=
6_ServiceDll=
6_ImagePath=SYSTEM32\DRIVERS\EV19X8MP.SYS
7_ServiceName=ExpScaner
7_DisplayName=ExpScaner
7_Description=
7_ServiceDll=
7_ImagePath=D:\RISING\RAV\EXPSCAN.SYS
8_ServiceName=HookCont
8_DisplayName=HookCont
8_Description=
8_ServiceDll=
8_ImagePath=D:\RISING\RAV\HOOKCONT.SYS
9_ServiceName=HookReg
9_DisplayName=HookReg
9_Description=
9_ServiceDll=
9_ImagePath=D:\RISING\RAV\HOOKREG.SYS
10_ServiceName=HookSys
10_DisplayName=HookSys
10_Description=
10_ServiceDll=
10_ImagePath=D:\RISING\RAV\HOOKSYS.SYS
11_ServiceName=MEMSCAN
11_DisplayName=MEMSCAN
11_Description=
11_ServiceDll=
11_ImagePath=D:\RISING\RAV\MEMSCAN.SYS
12_ServiceName=mspora
12_DisplayName=
12_Description=
12_ServiceDll=
12_ImagePath=SYSTEM32\DRIVERS\MSPORA.SYS
13_ServiceName=NPF
13_DisplayName=Netgroup Packet Filter
13_Description=
13_ServiceDll=
13_ImagePath=SYSTEM32\DRIVERS\NPF.SYS
14_ServiceName=npkycryp
14_DisplayName=npkycryp
14_Description=
14_ServiceDll=
14_ImagePath=C:\WINDOWS\SYSTEM32\NPKYCRYP.SYS
15_ServiceName=P3
15_DisplayName=Intel PentiumIII Processor Driver
15_Description=
15_ServiceDll=
15_ImagePath=SYSTEM32\DRIVERS\P3.SYS
16_ServiceName=RsAntiSpyware
16_DisplayName=RsAntiSpyware
16_Description=
16_ServiceDll=
16_ImagePath=SYSTEM32\DRIVERS\RSBOOT.SYS
17_ServiceName=RsNTGDI
17_DisplayName=RsNTGDI
17_Description=
17_ServiceDll=
17_ImagePath=SYSTEM32\DRIVERS\RSNTGDI.SYS
18_ServiceName=RSPPSYS
18_DisplayName=RSPPSYS
18_Description=
18_ServiceDll=
18_ImagePath=D:\RISING\RAV\RSPPSYS.SYS
19_ServiceName=smimini
19_DisplayName=
19_Description=
19_ServiceDll=
19_ImagePath=SYSTEM32\DRIVERS\SMIMINIB.SYS
Max=19
[END]
Max=1
Å¡ÕXÒª<bbs.ikaka.comÖ½mó:J