瑞星卡卡安全论坛

首页 » 技术交流区 » 系统软件 » 【求助】杀毒软件也杀不了的病毒
leeguoxian - 2006-8-17 9:31:00
中了"Trojan.WOW.fc"和"Rootkit.Vanti.di"病毒
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BlueSoleil\BTNtService.exe
C:\Program Files\cFosSpeed\spd.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Raxco\PerfectDisk\PDSched.exe
C:\WINDOWS\system32\msime.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\cFosSpeed\cFosSpeed.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\李国贤\桌面\HijackThis V1[1].99.1汉化版\HijackThis.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\Launcher.exe
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - (no file)
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O3 - Toolbar: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - E:\金山快译\IEBand.dll
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [cFosSpeed] C:\Program Files\cFosSpeed\cFosSpeed.exe
O4 - HKLM\..\Run: [NvCplDaemon] ; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: 使用迅雷下载 - C:\Program Files\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: 使用迅雷下载全部链接 - C:\Program Files\Thunder\Program\GetAllUrl.htm
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263}? - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O20 - AppInit_DLLs: KB235780M.LOG
O21 - SSODL: DVDBurn - {790448C3-4239-45AF-C98B-367991A8B103} - C:\WINDOWS\Downloaded Program Files\AfxEdit.dll (file missing)
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\BlueSoleil\BTNtService.exe
O23 - Service: cFosSpeed System Service (cFosSpeedS) - Unknown owner - C:\Program Files\cFosSpeed\spd.exe" -service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
闪电风暴 - 2006-8-17 9:42:00
魔兽木马和ROOKIT??
闪电风暴 - 2006-8-17 9:43:00
http://forum.ikaka.com/topic.asp?board=28&artid=7538008


按这个帖所说方法,帖Autoruns日志上来
leeguoxian - 2006-8-17 11:00:00
【回复“闪电风暴”的帖子】
大哥要全部贴吗?
leeguoxian - 2006-8-17 11:10:00
本来想贴图的,但是太多了~
HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms           

+ rdpclip    RDP Clip Monitor    Microsoft Corporation    c:\windows\system32\rdpclip.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit           

+ C:\WINDOWS\system32\Launcher.exe            c:\windows\system32\launcher.exe

+ C:\WINDOWS\system32\userinit.exe    Userinit Logon Application    Microsoft Corporation    c:\windows\system32\userinit.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell           

+ Explorer.exe    Windows Explorer    Microsoft Corporation    c:\windows\explorer.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run           

+ !ewido    ewido anti-spyware    Anti-Malware Development a.s.    c:\program files\ewido anti-spyware 4.0\ewido.exe

+ cFosSpeed    cFosSpeed Window    cFos Software GmbH    c:\program files\cfosspeed\cfosspeed.exe

+ NvCplDaemon    Run a DLL as an App    Microsoft Corporation    c:\windows\system32\rundll32.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run           

+ CheckFaultKernel            c:\windows\system32\mswdm.exe

+ KernelFaultCheck            c:\windows\system32\msime.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run           

+ ctfmon.exe    CTF Loader    Microsoft Corporation    c:\windows\system32\ctfmon.exe
leeguoxian - 2006-8-17 11:19:00
HKLM\SOFTWARE\Classes\Protocols\Filter           

+ Class Install Handler    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll

+ deflate    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll

+ gzip    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll

+ lzdhtml    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll

+ text/webviewhtml    Windows Shell Common Dll    Microsoft Corporation    c:\windows\system32\shell32.dll

+ text/xml    Microsoft Office XML MIME Filter    Microsoft Corporation    c:\program files\common files\microsoft shared\office11\msoxmlmf.dll

HKLM\SOFTWARE\Classes\Protocols\Handler           

+ about    Microsoft (R) HTML Viewer    Microsoft Corporation    c:\windows\system32\mshtml.dll

+ cdl    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll

+ dvd    ActiveX control for streaming video    Microsoft Corporation    c:\windows\system32\msvidctl.dll

+ file    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll

+ ftp    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll

+ gopher    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll

+ http    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll

+ https    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll

+ its    Microsoft? InfoTech Storage System Library    Microsoft Corporation    c:\windows\system32\itss.dll

+ javascript    Microsoft (R) HTML Viewer    Microsoft Corporation    c:\windows\system32\mshtml.dll

+ local    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll

+ mailto    Microsoft (R) HTML Viewer    Microsoft Corporation    c:\windows\system32\mshtml.dll

+ mhtml    Microsoft Internet Messaging API    Microsoft Corporation    c:\windows\system32\inetcomm.dll

+ mk    OLE32 Extensions for Win32    Microsoft Corporation    c:\windows\system32\urlmon.dll

+ ms-its    Microsoft? InfoTech Storage System Library    Microsoft Corporation    c:\windows\system32\itss.dll

+ mso-offdap11    Microsoft Office Web Components 2003    Microsoft Corporation    c:\program files\common files\microsoft shared\web components\11\owc11.dll

+ res    Microsoft (R) HTML Viewer    Microsoft Corporation    c:\windows\system32\mshtml.dll

+ sysimage    Microsoft (R) HTML Viewer    Microsoft Corporation    c:\windows\system32\mshtml.dll

+ tv    ActiveX control for streaming video    Microsoft Corporation    c:\windows\system32\msvidctl.dll

+ vbscript    Microsoft (R) HTML Viewer    Microsoft Corporation    c:\windows\system32\mshtml.dll

+ wia    WIA Scripting Layer    Microsoft Corporation    c:\windows\system32\wiascr.dll
leeguoxian - 2006-8-17 11:24:00
HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components           

+ 0            找不到文件:About:Home

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components           

+ Internet Explorer    Windows NT User Data Migration Tool    Microsoft Corporation    c:\windows\system32\shmgrate.exe

+ Internet Explorer 6    IE 5.0 Per-User Install Utility    Microsoft Corporation    c:\windows\system32\ie4uinit.exe

+ Microsoft Outlook Express 6    Outlook Express Setup Library    Microsoft Corporation    c:\program files\outlook express\setup50.exe

+ Microsoft Windows Media Player    Microsoft Windows Media Player 安装实用程序    Microsoft Corporation    c:\windows\inf\unregmp2.exe

+ Microsoft Windows Media Player    ADVPACK    Microsoft Corporation    c:\windows\system32\advpack.dll

+ NetMeeting 3.01    ADVPACK    Microsoft Corporation    c:\windows\system32\advpack.dll

+ Outlook Express    Windows NT User Data Migration Tool    Microsoft Corporation    c:\windows\system32\shmgrate.exe

+ Themes Setup    Microsoft(C) Register Server    Microsoft Corporation    c:\windows\system32\regsvr32.exe

+ Windows Messenger 4.7    ADVPACK    Microsoft Corporation    c:\windows\system32\advpack.dll

+ Windows 桌面更新    Microsoft(C) Register Server    Microsoft Corporation    c:\windows\system32\regsvr32.exe

+ 通讯簿 6    Outlook Express Setup Library    Microsoft Corporation    c:\program files\outlook express\setup50.exe

+ 浏览器自定义组件    Microsoft Internet Explorer Customization DLL    Microsoft Corporation    c:\windows\system32\iedkcs32.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler           

+ Browseui 预加载程序    Shell Browser UI Library    Microsoft Corporation    c:\windows\system32\browseui.dll

+ 组件类别缓存程序    Shell Browser UI Library    Microsoft Corporation    c:\windows\system32\browseui.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad           

+ CDBurn    Windows Shell Common Dll    Microsoft Corporation    c:\windows\system32\shell32.dll

+ DVDBurn            找不到文件:C:\WINDOWS\Downloaded Program Files\AfxEdit.dll

+ PostBootReminder    Windows Shell Common Dll    Microsoft Corporation    c:\windows\system32\shell32.dll

+ SysTray    Systray shell service object    Microsoft Corporation    c:\windows\system32\stobject.dll

+ WebCheck    Web Site Monitor    Microsoft Corporation    c:\windows\system32\webcheck.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks           

+ ewido anti-spyware 4.0    ewido anti-spyware guard    Anti-Malware Development a.s.    c:\program files\ewido anti-spyware 4.0\shellexecutehook.dll

+ shell32.dll    Windows Shell Common Dll    Microsoft Corporation    c:\windows\system32\shell32.dll

+ system.sys            c:\program files\internet explorer\plugins\system.sys
leeguoxian - 2006-8-17 11:27:00
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved           

+ %DESC_PublishDropTarget%    Photo Printing Wizard    Microsoft Corporation    c:\windows\system32\photowiz.dll

+ .CAB file viewer    Cabinet File Viewer Shell Extension    Microsoft Corporation    c:\windows\system32\cabview.dll

+ ActiveX 高速缓存文件夹    Object Control Viewer    Microsoft Corporation    c:\windows\system32\occache.dll

+ Audio Media Properties Handler    Media File Property Extractor Shell Extension    Microsoft Corporation    c:\windows\system32\shmedia.dll

+ Auto Update Property Sheet Extension    Automatic Updates Control Panel    Microsoft Corporation    c:\windows\system32\wuaucpl.cpl

+ Avi Properties Handler    Media File Property Extractor Shell Extension    Microsoft Corporation    c:\windows\system32\shmedia.dll

+ BandProxy    Shell Browser UI Library    Microsoft Corporation    c:\windows\system32\browseui.dll

+ CDF Extension Copy Hook    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll

+ Channel Menu    Channel Definition File Viewer    Microsoft Corporation    c:\windows\system32\cdfview.dll

+ Channel Properties    Channel Definition File Viewer    Microsoft Corporation    c:\windows\system32\cdfview.dll

+ Code Download Agent    Web Site Monitor    Microsoft Corporation    c:\windows\system32\webcheck.dll

+ Compatibility Page    Compatibility Tab Shell Extension DLL    Microsoft Corporation    c:\windows\system32\slayerxp.dll

+ Compressed (zipped) Folder Right Drag Handler    Compressed (zipped) Folders    Microsoft Corporation    c:\windows\system32\zipfldr.dll

+ Compressed (zipped) Folder SendTo Target    Compressed (zipped) Folders    Microsoft Corporation    c:\windows\system32\zipfldr.dll

+ ConnectionAgent    Web Site Monitor    Microsoft Corporation    c:\windows\system32\webcheck.dll

+ Crypto PKO Extension    Crypto Shell Extensions    Microsoft Corporation    c:\windows\system32\cryptext.dll

+ Crypto Sign Extension    Crypto Shell Extensions    Microsoft Corporation    c:\windows\system32\cryptext.dll

+ Darwin App Publisher    Shell Application Manager    Microsoft Corporation    c:\windows\system32\appwiz.cpl

+ Desktop Explorer    NVIDIA Desktop Explorer, Version 110.38     NVIDIA Corporation    c:\windows\system32\nvshell.dll

+ Desktop Explorer Menu    NVIDIA Desktop Explorer, Version 110.38     NVIDIA Corporation    c:\windows\system32\nvshell.dll

+ DfsShell    Distributed File System shell extension    Microsoft Corporation    c:\windows\system32\dfsshlex.dll

+ Directory Context Menu Verbs    Directory Service Common UI    Microsoft Corporation    c:\windows\system32\dsuiext.dll

+ Directory Object Find    Directory Service Find    Microsoft Corporation    c:\windows\system32\dsquery.dll

+ Directory Property UI    Directory Service Common UI    Microsoft Corporation    c:\windows\system32\dsuiext.dll

+ Directory Query UI    Directory Service Find    Microsoft Corporation    c:\windows\system32\dsquery.dll

+ Directory Start/Search Find    Directory Service Find    Microsoft Corporation    c:\windows\system32\dsquery.dll

+ Disk Copy Extension    Windows DiskCopy    Microsoft Corporation    c:\windows\system32\diskcopy.dll

+ Disk Quota UI    Windows Shell Disk Quota UI DLL    Microsoft Corporation    c:\windows\system32\dskquoui.dll

+ Display Adapter CPL Extension    Advanced display adapter properties    Microsoft Corporation    c:\windows\system32\deskadp.dll

+ Display Monitor CPL Extension    Advanced display monitor properties    Microsoft Corporation    c:\windows\system32\deskmon.dll

+ Display Panning CPL Extension            找不到文件:deskpan.dll

+ Display TroubleShoot CPL Extension    Advanced display performance properties    Microsoft Corporation    c:\windows\system32\deskperf.dll

+ DS Security Page    Directory Service Security UI    Microsoft Corporation    c:\windows\system32\dssec.dll

+ Extensions Manager Folder    Extensions Manager    Microsoft Corporation    c:\windows\system32\extmgr.dll

+ Favorites Band    Shell Doc Object and Control Library    Microsoft Corporation    c:\windows\system32\shdocvw.dll

+ FTP Folders Webview    Microsoft Internet Explorer FTP Folder Shell Extension    Microsoft Corporation    c:\windows\system32\msieftp.dll
leeguoxian - 2006-8-17 11:44:00
GDI+ 文件缩略图解压缩程序Windows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll

+ HTML 缩略图的解压缩程序Windows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll

+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\windows\system32\hticons.dll

+ ICC 配置文件Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\windows\system32\icmui.dll

+ ICM 打印机管理Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\windows\system32\icmui.dll

+ ICM 监视器管理Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\windows\system32\icmui.dll

+ ICM 扫描仪管理Microsoft Color Matching System User Interface DLLMicrosoft Corporationc:\windows\system32\icmui.dll

+ IE4 套件初始屏幕Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ Installed Apps EnumeratorShell Application ManagerMicrosoft Corporationc:\windows\system32\appwiz.cpl

+ InternetShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ InternetShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ Internet Name SpaceShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ Internet 临时文件Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ Internet 临时文件Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ InternetShortcutShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ ISFBand OCShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ Microsoft Agent Character Property Sheet HandlerMicrosoft Agent Property Sheet HandlerMicrosoft Corporationc:\windows\msagent\agentpsh.dll

+ Microsoft AutoCompleteShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ Microsoft Browser ArchitectureShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ Microsoft BrowserBandShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ Microsoft DocProp Inplace Calendar ControlMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll

+ Microsoft DocProp Inplace Droplist Combo ControlMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll

+ Microsoft DocProp Inplace Edit Box ControlMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll

+ Microsoft DocProp Inplace ML Edit Box ControlMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll

+ Microsoft DocProp Inplace Time ControlMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll

+ Microsoft DocProp Shell ExtMicrosoft DocProp Shell ExtMicrosoft Corporationc:\windows\system32\docprop2.dll

+ Microsoft Internet 工具栏Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ Microsoft Office HTML Icon HandlerMicrosoft Office 2003 componentMicrosoft Corporationc:\program files\microsoft office\office11\msohev.dll

+ Microsoft Url History 服务Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ Microsoft Url 搜索挂接Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ Microsoft 多个自动完成列表容器Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ Microsoft 历史自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ Microsoft 数据链接Microsoft Data Access - OLE DB Core ServicesMicrosoft Corporationc:\program files\common files\system\ole db\oledb32.dll

+ Microsoft 外壳文件夹自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ Midi Properties HandlerMedia File Property Extractor Shell ExtensionMicrosoft Corporationc:\windows\system32\shmedia.dll

+ MMC Icon HandlerMMC Shell Extension DLLMicrosoft Corporationc:\windows\system32\mmcshext.dll

+ MRU 自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ Multimedia File Property SheetControl Panel Drivers AppletMicrosoft Corporationc:\windows\system32\mmsys.cpl

+ MyDocs Copy HookMy Documents Folder UIMicrosoft Corporationc:\windows\system32\mydocs.dll

+ MyDocs Drop TargetMy Documents Folder UIMicrosoft Corporationc:\windows\system32\mydocs.dll

+ MyDocs PropertiesMy Documents Folder UIMicrosoft Corporationc:\windows\system32\mydocs.dll

+ NTFS Security PageSecurity Shell ExtensionMicrosoft Corporationc:\windows\system32\rshx32.dll

+ NvCpl DesktopContext ClassNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll

+ nView Desktop Context MenuNVIDIA Desktop Explorer, Version 110.38 NVIDIA Corporationc:\windows\system32\nvshell.dll

+ Offline Files Folder OptionsClient Side Caching UIMicrosoft Corporationc:\windows\system32\cscui.dll

+ Offline Files MenuClient Side Caching UIMicrosoft Corporationc:\windows\system32\cscui.dll

+ OLE Docfile Property PageOLE DocFile Property PageMicrosoft Corporationc:\windows\system32\docprop.dll

+ Play on my TV helperNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll

+ PlusPack CPL ExtensionWindows Theme APIMicrosoft Corporationc:\windows\system32\themeui.dll

+ PostAgentWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll

+ Printers Security PageSecurity Shell ExtensionMicrosoft Corporationc:\windows\system32\rshx32.dll

+ Remote Sessions CPL ExtensionRemote Sessions CPL ExtensionMicrosoft Corporationc:\windows\system32\remotepg.dll

+ Search Assistant OCShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ Sendmail serviceSend MailMicrosoft Corporationc:\windows\system32\sendmail.dll

+ Sendmail serviceSend MailMicrosoft Corporationc:\windows\system32\sendmail.dll

+ Set Program Access and DefaultsShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ Shell Application ManagerShell Application ManagerMicrosoft Corporationc:\windows\system32\appwiz.cpl

+ Shell Automation Inproc ServiceShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ Shell Band Site MenuShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ Shell DocObject ViewerShell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ Shell extensions for Microsoft Windows Network objectsNetwork object shell UIMicrosoft Corporationc:\windows\system32\ntlanui2.dll

+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realplayer\rpshell.dll
leeguoxian - 2006-8-17 11:45:00
+ Shell extensions for sharingShell extensions for sharingMicrosoft Corporationc:\windows\system32\ntshrui.dll

+ Shell extensions for sharingShell extensions for sharingMicrosoft Corporationc:\windows\system32\ntshrui.dll

+ Shell Image Data FactoryWindows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll

+ Shell Image Property HandlerWindows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll

+ Shell Image VerbsWindows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll

+ Shell properties for a DS objectDirectory Service FindMicrosoft Corporationc:\windows\system32\dsquery.dll

+ Shell Scrap DataHandlerShell scrap object handlerMicrosoft Corporationc:\windows\system32\shscrap.dll

+ Subscription MgrWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll

+ Tasks Folder Icon HandlerTask Scheduler interface DLLMicrosoft Corporationc:\windows\system32\mstask.dll

+ Tasks Folder Shell ExtensionTask Scheduler interface DLLMicrosoft Corporationc:\windows\system32\mstask.dll

+ TrayAgentWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll

+ TridentImageExtractorShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ Video Media Properties HandlerMedia File Property Extractor Shell ExtensionMicrosoft Corporationc:\windows\system32\shmedia.dll

+ Video Thumbnail ExtractorMedia File Property Extractor Shell ExtensionMicrosoft Corporationc:\windows\system32\shmedia.dll

+ Wav Properties HandlerMedia File Property Extractor Shell ExtensionMicrosoft Corporationc:\windows\system32\shmedia.dll

+ Web FoldersMicrosoft Web FoldersMicrosoft Corporationc:\program files\common files\microsoft shared\web folders\msonsext.dll

+ Web Printer Shell ExtensionPrint UI DLLMicrosoft Corporationc:\windows\system32\printui.dll

+ Web 搜索Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ WebCheckWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll

+ WebCheck SyncMgr HandlerWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll

+ WebCheckChannelAgentWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll

+ WebCheckWebCrawlerWeb Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll

+ Windows Media Player Add to Playlist Context Menu HandlerWindows Media Player LauncherMicrosoft Corporationc:\windows\system32\wmpshell.dll

+ Windows Media Player Burn Audio CD Context Menu HandlerWindows Media Player LauncherMicrosoft Corporationc:\windows\system32\wmpshell.dll

+ Windows Media Player Play as Playlist Context Menu HandlerWindows Media Player LauncherMicrosoft Corporationc:\windows\system32\wmpshell.dll

+ Windows Script Host 的 Shell extensionsMicrosoft (r) Shell Extension for Windows Script HostMicrosoft Corporationc:\windows\system32\wshext.dll

+ WinRAR shell extensionc:\program files\winrar\rarext.dll

+ 帮助和支持Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ 帮助和支持Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ 补充的外壳文件夹Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ 补充的外壳文件夹 2Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ 窗格中的搜索Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ 地址 EditBoxShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ 地址(&A)Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ 电子邮件Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ 跟踪弹出栏Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ 公文包Windows BriefcaseMicrosoft Corporationc:\windows\system32\syncui.dll

+ 管理工具Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ 获取 Passport 向导Map Network Drives/Network Places WizardMicrosoft Corporationc:\windows\system32\netplwiz.dll

+ 可访问的Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ 历史记录Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ 频道句柄对象Channel Definition File ViewerMicrosoft Corporationc:\windows\system32\cdfview.dll

+ 频道快捷方式Channel Definition File ViewerMicrosoft Corporationc:\windows\system32\cdfview.dll

+ 频道文件Channel Definition File ViewerMicrosoft Corporationc:\windows\system32\cdfview.dll

+ 全局文件夹设置Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ 任务计划Task Scheduler interface DLLMicrosoft Corporationc:\windows\system32\mstask.dll

+ 任务栏和「开始」菜单Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll

+ 扫描仪和照相机Imaging Devices Shell Folder UIMicrosoft Corporationc:\windows\system32\wiashext.dll

+ 扫描仪和照相机Imaging Devices Shell Folder UIMicrosoft Corporationc:\windows\system32\wiashext.dll

+ 扫描仪和照相机Imaging Devices Shell Folder UIMicrosoft Corporationc:\windows\system32\wiashext.dll

+ 扫描仪和照相机Imaging Devices Shell Folder UIMicrosoft Corporationc:\windows\system32\wiashext.dll

+ 扫描仪和照相机Imaging Devices Shell Folder UIMicrosoft Corporationc:\windows\system32\wiashext.dll

+ 搜索Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ 搜索区Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ 通过 Web 订购照片Map Network Drives/Network Places WizardMicrosoft Corporationc:\windows\system32\netplwiz.dll

+ 脱机文件夹Client Side Caching UIMicrosoft Corporationc:\windows\system32\cscui.dll

+ 外壳 DeskBarShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ 外壳 DeskBarAppShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ 外壳 Rebar BandSiteShell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ 外壳出版向导对象Map Network Drives/Network Places WizardMicrosoft Corporationc:\windows\system32\netplwiz.dll

+ 网络出版向导Map Network Drives/Network Places WizardMicrosoft Corporationc:\windows\system32\netplwiz.dll

+ 网络连接Network Connections ShellMicrosoft Corporationc:\windows\system32\netshell.dll

+ 网络连接Network Connections ShellMicrosoft Corporationc:\windows\system32\netshell.dll

+ 下载状态Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ 压缩(zipped)文件夹Compressed (zipped) FoldersMicrosoft Corporationc:\windows\system32\zipfldr.dll

+ 以前的版本Previous Versions property pageMicrosoft Corporationc:\windows\system32\twext.dll

+ 以前的版本属性页Previous Versions property pageMicrosoft Corporationc:\windows\system32\twext.dll

+ 用户(&P)...Find PeopleMicrosoft Corporationc:\program files\outlook express\wabfind.dll

+ 用户帮助Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ 用户帐户Map Network Drives/Network Places WizardMicrosoft Corporationc:\windows\system32\netplwiz.dll

+ 预订文件夹Web Site MonitorMicrosoft Corporationc:\windows\system32\webcheck.dll

+ 运行...Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ 摘要信息缩略图处理程序(DOCFILES)Windows 图片和传真查看器Microsoft Corporationc:\windows\system32\shimgvw.dll

+ 注册数目路选项实用程序Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ 自定义 MRU 自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\windows\system32\browseui.dll

+ 字体Windows Font FolderMicrosoft Corporationc:\windows\system32\fontext.dll

+ 字体Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll

+ 浏览器栏Shell Doc Object and Control LibraryMicrosoft Corporationc:\windows\system32\shdocvw.dll
leeguoxian - 2006-8-17 11:47:00
HKLM\Software\Classes\Folder\Shellex\ColumnHandlers

+ Haali Column Providere:\暴风影音\codecs\mmfinfo.dll

+ {0D2E74C4-3C34-11d2-A27E-00C04FC30871}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll

+ {24F14F01-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll

+ {24F14F02-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll

+ {66742402-F9B9-11D1-A202-0000F81FEDEE}Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ kakatool.dllBeijing Rising Technology Co., Ltd.c:\windows\system32\kakatool.dll

HKLM\System\CurrentControlSet\Services

+ AudioSrv管理基于 Windows 的程序的音频设备。如果此服务被终止,音频设备及其音效将不能正常工作。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ BlueSoleil Hid Servicec:\program files\bluesoleil\btntservice.exe

+ cFosSpeedSPerforms latency measurement and privileged operations for cFosSpeedcFos Software GmbHc:\program files\cfosspeed\spd.exe

+ DcomLaunch为 DCOM 服务提供加载功能。Microsoft Corporationc:\windows\system32\svchost.exe

+ dmserver监测和监视新硬盘驱动器并向逻辑磁盘管理器管理服务发送卷的信息以便配置。如果此服务被终止,动态磁盘状态和配置信息会过时。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ Eventlog启用在事件查看器查看基于 Windows 的程序和组件颁发的事件日志消息。无法终止此服务。Microsoft Corporationc:\windows\system32\services.exe

+ ewido anti-spyware 4.0 guardewido anti-spyware guardAnti-Malware Development a.s.c:\program files\ewido anti-spyware 4.0\guard.exe

+ lanmanworkstation创建和维护到远程服务的客户端网络连接。如果服务停止,这些连接将不可用。如果服务被禁用,任何直接依赖于此服务的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ NVSvcProvides system and desktop level support to the NVIDIA display driverNVIDIA Corporationc:\windows\system32\nvsvc32.exe

+ PDSchedPDSched ModuleRaxco Software, Inc.c:\program files\raxco\perfectdisk\pdsched.exe

+ PlugPlay使计算机在极少或没有用户输入的情况下能识别并适应硬件的更改。终止或禁用此服务会造成系统不稳定。Microsoft Corporationc:\windows\system32\services.exe

+ ProtectedStorage提供对敏感数据(如私钥)的保护性存储,以便防止未授权的服务,过程或用户对其的非法访问。Microsoft Corporationc:\windows\system32\lsass.exe

+ RpcSs提供终结点映射程序 (endpoint mapper) 以及其它 RPC 服务。Microsoft Corporationc:\windows\system32\svchost.exe

+ SamSs存储本地用户帐户的安全信息。Microsoft Corporationc:\windows\system32\lsass.exe

+ Schedule使用户能在此计算机上配置和制定自动任务的日程。如果此服务被终止,这些任务将无法在日程时间里运行。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ seclogon启用替换凭据下的启用进程。如果此服务被终止,此类型登录访问将不可用。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe

+ SENS跟踪系统事件,如登录 Windows,网络以及电源事件等。将这些事件通知给 COM+ 事件系统 “订阅者(subscriber)”。Microsoft Corporationc:\windows\system32\svchost.exe

+ SharedAccess为家庭和小型办公网络提供网络地址转换、寻址、名称解析和/或入侵保护服务。Microsoft Corporationc:\windows\system32\svchost.exe

+ ShellHWDetection为自动播放硬件事件提供通知。Microsoft Corporationc:\windows\system32\svchost.exe

+ Themes为用户提供使用主题管理的经验。Microsoft Corporationc:\windows\system32\svchost.exe

+ winmgmt提供共同的界面和对象模式以便访问有关操作系统、设备、应用程序和服务的管理信息。如果此服务被终止,多数基于 Windows 的软件将无法正常运行。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\svchost.exe
leeguoxian - 2006-8-17 11:47:00
HKLM\System\CurrentControlSet\Services

+ ACPIACPI Driver for NTMicrosoft Corporationc:\windows\system32\drivers\acpi.sys

+ aecMicrosoft Acoustic Echo CancellerMicrosoft Corporationc:\windows\system32\drivers\aec.sys

+ AFDAFD 网络支持环境Microsoft Corporationc:\windows\system32\drivers\afd.sys

+ agp440440 NT AGP FilterMicrosoft Corporationc:\windows\system32\drivers\agp440.sys

+ ALCXWDMAvance AC'97 Audio Driver (WDM)Avance Logic, Inc.c:\windows\system32\drivers\alcxwdm.sys

+ AsyncMacRAS Asynchronous Media DriverMicrosoft Corporationc:\windows\system32\drivers\asyncmac.sys

+ atapiIDE/ATAPI Port DriverMicrosoft Corporationc:\windows\system32\drivers\atapi.sys

+ AtmarpcATM ARP Client ProtocolMicrosoft Corporationc:\windows\system32\drivers\atmarpc.sys

+ audstubAudStub DriverMicrosoft Corporationc:\windows\system32\drivers\audstub.sys

+ BlueletAudioBluelet Audio DriverIVT Corporationc:\windows\system32\drivers\blueletaudio.sys

+ BTBluetooth PAN Network Adapter DriverIVT Corporationc:\windows\system32\drivers\btnetdrv.sys

+ BtcsrusbBluetooth USB Device DriverIVT Corporationc:\windows\system32\drivers\btcusb.sys

+ BTHidEnumc:\windows\system32\drivers\vbtenum.sys

+ BTHidMgrBluetooth HID Manager driverIVT Corporationc:\windows\system32\drivers\bthidmgr.sys

+ CCDECODEWDM Closed Caption VBI CodecMicrosoft Corporationc:\windows\system32\drivers\ccdecode.sys

+ CdromSCSI CD-ROM DriverMicrosoft Corporationc:\windows\system32\drivers\cdrom.sys

+ cFosSpeedcFosSpeed DrivercFos Software GmbHc:\windows\system32\drivers\cfosspeed.sys

+ DiskPnP Disk DriverMicrosoft Corporationc:\windows\system32\drivers\disk.sys

+ dmioNT Disk Manager I/O DriverMicrosoft Corp., Veritas Softwarec:\windows\system32\drivers\dmio.sys

+ dmloadNT Disk Manager Startup DriverMicrosoft Corp., Veritas Software.c:\windows\system32\drivers\dmload.sys

+ DMusicMicrosoft Kernel DLS SynthesizerMicrosoft Corporationc:\windows\system32\drivers\dmusic.sys

+ drmkaudMicrosoft Kernel DRM Audio Descrambler FilterMicrosoft Corporationc:\windows\system32\drivers\drmkaud.sys

+ dtscsic:\windows\system32\drivers\dtscsi.sys

+ ewido anti-spyware 4.0 driverc:\program files\ewido anti-spyware 4.0\guard.sys

+ FdcFloppy Disk Controller DriverMicrosoft Corporationc:\windows\system32\drivers\fdc.sys

+ FlpydiskFloppy DriverMicrosoft Corporationc:\windows\system32\drivers\flpydisk.sys

+ FsVgaFull Screen Video DriverMicrosoft Corporationc:\windows\system32\drivers\fsvga.sys

+ FtdiskFT Disk DriverMicrosoft Corporationc:\windows\system32\drivers\ftdisk.sys

+ gameenumGame Port EnumeratorMicrosoft Corporationc:\windows\system32\drivers\gameenum.sys

+ GpcGeneric Packet ClassifierMicrosoft Corporationc:\windows\system32\drivers\msgpc.sys

+ hidusbUSB Miniport Driver for Input DevicesMicrosoft Corporationc:\windows\system32\drivers\hidusb.sys

+ HTTP此服务实现超文本传送协议(HTTP)。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationc:\windows\system32\drivers\http.sys

+ i8042prti8042 Port DriverMicrosoft Corporationc:\windows\system32\drivers\i8042prt.sys

+ ImapiIMAPI Kernel DriverMicrosoft Corporationc:\windows\system32\drivers\imapi.sys

+ IntelIdeIntel PCI IDE DriverMicrosoft Corporationc:\windows\system32\drivers\intelide.sys

+ intelppmProcessor Device DriverMicrosoft Corporationc:\windows\system32\drivers\intelppm.sys

+ Ip6Fw为家庭和小型办公网络提供入侵保护服务。Microsoft Corporationc:\windows\system32\drivers\ip6fw.sys

+ IpFilterDriverIP Traffic Filter DriverMicrosoft Corporationc:\windows\system32\drivers\ipfltdrv.sys

+ IpInIpIP in IP Tunnel DriverMicrosoft Corporationc:\windows\system32\drivers\ipinip.sys

+ IpNatIP Network Address TranslatorMicrosoft Corporationc:\windows\system32\drivers\ipnat.sys

+ IPSecIPSEC driverMicrosoft Corporationc:\windows\system32\drivers\ipsec.sys

+ IRENUMInfra-Red Bus EnumeratorMicrosoft Corporationc:\windows\system32\drivers\irenum.sys

+ isapnpPNP ISA Bus DriverMicrosoft Corporationc:\windows\system32\drivers\isapnp.sys

+ KbdclassKeyboard Class DriverMicrosoft Corporationc:\windows\system32\drivers\kbdclass.sys

+ kmixerKernel Mode Audio MixerMicrosoft Corporationc:\windows\system32\drivers\kmixer.sys

+ MouclassMouse Class DriverMicrosoft Corporationc:\windows\system32\drivers\mouclass.sys

+ MSKSSRVMS KS ServerMicrosoft Corporationc:\windows\system32\drivers\mskssrv.sys

+ MSPCLOCKMS Proxy ClockMicrosoft Corporationc:\windows\system32\drivers\mspclock.sys

+ MSPQMMS Proxy Quality ManagerMicrosoft Corporationc:\windows\system32\drivers\mspqm.sys

+ mssmbiosSystem Management BIOS DriverMicrosoft Corporationc:\windows\system32\drivers\mssmbios.sys

+ MSTEEWDM Tee/Communication Transform Filter Microsoft Corporationc:\windows\system32\drivers\mstee.sys

+ NABTSFECWDM NABTS/FEC VBI CodecMicrosoft Corporationc:\windows\system32\drivers\nabtsfec.sys

+ NdisIPMicrosoft IP DriverMicrosoft Corporationc:\windows\system32\drivers\ndisip.sys

+ NdisTapiRemote Access NDIS TAPI DriverMicrosoft Corporationc:\windows\system32\drivers\ndistapi.sys

+ NdisuioNDIS 用户模式 I/O 协议Microsoft Corporationc:\windows\system32\drivers\ndisuio.sys

+ NdisWanRemote Access NDIS WAN DriverMicrosoft Corporationc:\windows\system32\drivers\ndiswan.sys

+ NetBTNetBios over TcpipMicrosoft Corporationc:\windows\system32\drivers\netbt.sys

+ NPFnpfCACE Technologiesc:\windows\system32\drivers\npf.sys

+ npkcrypt找不到文件:E:\TM\TMDlls\npkcrypt.sys

+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 91.31 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys

+ NwlnkFltIPX Traffic Filter DriverMicrosoft Corporationc:\windows\system32\drivers\nwlnkflt.sys

+ NwlnkFwdIPX Traffic Forwarder DriverMicrosoft Corporationc:\windows\system32\drivers\nwlnkfwd.sys

+ oreans32c:\windows\system32\drivers\oreans32.sys

+ ParportParallel Port DriverMicrosoft Corporationc:\windows\system32\drivers\parport.sys

+ PCINT Plug and Play PCI EnumeratorMicrosoft Corporationc:\windows\system32\drivers\pci.sys

+ PCIIdeGeneric PCI IDE Bus DriverMicrosoft Corporationc:\windows\system32\drivers\pciide.sys

+ PptpMiniportWAN Miniport (PPTP)Microsoft Corporationc:\windows\system32\drivers\raspptp.sys

+ PSchedQoS Packet SchedulerMicrosoft Corporationc:\windows\system32\drivers\psched.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys

+ RasAcdRemote Access Auto Connection DriverMicrosoft Corporationc:\windows\system32\drivers\rasacd.sys

+ Rasl2tpWAN Miniport (L2TP)Microsoft Corporationc:\windows\system32\drivers\rasl2tp.sys

+ RasPppoe远程访问 PPPOE 驱动程序Microsoft Corporationc:\windows\system32\drivers\raspppoe.sys

+ RasptiDirect ParallelMicrosoft Corporationc:\windows\system32\drivers\raspti.sys

+ RDPCDDRDP MiniportMicrosoft Corporationc:\windows\system32\drivers\rdpcdd.sys

+ rdpdrMicrosoft RDP Device redirectorMicrosoft Corporationc:\windows\system32\drivers\rdpdr.sys

+ redbookRedbook Audio Filter DriverMicrosoft Corporationc:\windows\system32\drivers\redbook.sys

+ ROOTMODEMLegacy Non-Pnp Modem Device DriverMicrosoft Corporationc:\windows\system32\drivers\rootmdm.sys

+ rtl8139Realtek RTL8139 NDIS 5.0 DriverRealtek Semiconductor Corporationc:\windows\system32\drivers\rtl8139.sys

+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys

+ serenumSerial Port EnumeratorMicrosoft Corporationc:\windows\system32\drivers\serenum.sys

+ SerialSerial Device DriverMicrosoft Corporationc:\windows\system32\drivers\serial.sys

+ SLIPMicrosoft Slip Deframing Filter MinidriverMicrosoft Corporationc:\windows\system32\drivers\slip.sys

+ splitterMicrosoft Kernel Audio SplitterMicrosoft Corporationc:\windows\system32\drivers\splitter.sys

+ sptdc:\windows\system32\drivers\sptd.sys

+ streamipMicrosoft IP Test DriverMicrosoft Corporationc:\windows\system32\drivers\streamip.sys

+ swenumPlug and Play Software Device EnumeratorMicrosoft Corporationc:\windows\system32\drivers\swenum.sys

+ swmidiMicrosoft GS Wavetable SynthesizerMicrosoft Corporationc:\windows\system32\drivers\swmidi.sys

+ sysaudioSystem Audio WDM FilterMicrosoft Corporationc:\windows\system32\drivers\sysaudio.sys

+ TcpipTCP/IP Protocol DriverMicrosoft Corporationc:\windows\system32\drivers\tcpip.sys

+ TermDDTerminal Server DriverMicrosoft Corporationc:\windows\system32\drivers\termdd.sys

+ TrojanFindDriverNT找不到文件:C:\WINDOWS\system32\NtDriver.sys

+ UpdateUpdate DriverMicrosoft Corporationc:\windows\system32\drivers\update.sys

+ usbehciEHCI eUSB Miniport DriverMicrosoft Corporationc:\windows\system32\drivers\usbehci.sys

+ usbhubDefault Hub Driver for USBMicrosoft Corporationc:\windows\system32\drivers\usbhub.sys

+ usbuhciUHCI USB Miniport DriverMicrosoft Corporationc:\windows\system32\drivers\usbuhci.sys

+ VCommBluetooth Serial Port DriverIVT Corporationc:\windows\system32\drivers\vcomm.sys

+ VcommMgrBluetooth VcommMgr driverIVT Corporationc:\windows\system32\drivers\vcommmgr.sys

+ VgaSaveVGA/Super VGA Video DriverMicrosoft Corporationc:\windows\system32\drivers\vga.sys

+ WanarpRemote Access IP ARP DriverMicrosoft Corporationc:\windows\system32\drivers\wanarp.sys

+ wdmaudMMSYSTEM Wave/Midi API mapperMicrosoft Corporationc:\windows\system32\drivers\wdmaud.sys

+ WSTCODECWDM WST Codec DriverMicrosoft Corporationc:\windows\system32\drivers\wstcodec.sys
leeguoxian - 2006-8-17 11:47:00
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options

+ Your Image File Name Here without a pathSymbolic Debugger for Windows 2000Microsoft Corporationc:\windows\system32\ntsd.exe

HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls

+ advapi32Advanced Windows 32 Base APIMicrosoft Corporationc:\windows\system32\advapi32.dll

+ comdlg32Common Dialogs DLLMicrosoft Corporationc:\windows\system32\comdlg32.dll

+ gdi32GDI Client DLLMicrosoft Corporationc:\windows\system32\gdi32.dll

+ imagehlpWindows NT Image HelperMicrosoft Corporationc:\windows\system32\imagehlp.dll

+ kernel32Windows NT BASE API Client DLLMicrosoft Corporationc:\windows\system32\kernel32.dll

+ lz32LZ Expand/Compress API DLLMicrosoft Corporationc:\windows\system32\lz32.dll

+ ole32Microsoft OLE for WindowsMicrosoft Corporationc:\windows\system32\ole32.dll

+ oleaut32Microsoft Corporationc:\windows\system32\oleaut32.dll

+ olecli32Object Linking and Embedding Client LibraryMicrosoft Corporationc:\windows\system32\olecli32.dll

+ olecnv32Microsoft OLE for WindowsMicrosoft Corporationc:\windows\system32\olecnv32.dll

+ olesvr32Object Linking and Embedding Server LibraryMicrosoft Corporationc:\windows\system32\olesvr32.dll

+ olethk32Microsoft OLE for WindowsMicrosoft Corporationc:\windows\system32\olethk32.dll

+ rpcrt4Remote Procedure Call RuntimeMicrosoft Corporationc:\windows\system32\rpcrt4.dll

+ shell32Windows Shell Common DllMicrosoft Corporationc:\windows\system32\shell32.dll

+ urlInternet Shortcut Shell Extension DLLMicrosoft Corporationc:\windows\system32\url.dll

+ urlmonOLE32 Extensions for Win32Microsoft Corporationc:\windows\system32\urlmon.dll

+ user32Windows XP USER API Client DLLMicrosoft Corporationc:\windows\system32\user32.dll

+ versionVersion Checking and File Installation LibrariesMicrosoft Corporationc:\windows\system32\version.dll

+ wininetInternet Extensions for Win32Microsoft Corporationc:\windows\system32\wininet.dll

+ wldap32Win32 LDAP API DLLMicrosoft Corporationc:\windows\system32\wldap32.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UIHost

+ logonui.exeWindows Logon UIMicrosoft Corporationc:\windows\system32\logonui.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ crypt32chainCrypto API32Microsoft Corporationc:\windows\system32\crypt32.dll

+ cryptnetCrypto Network Related APIMicrosoft Corporationc:\windows\system32\cryptnet.dll

+ cscdllOffline Network AgentMicrosoft Corporationc:\windows\system32\cscdll.dll

+ ScCertPropCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll

+ ScheduleCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll

+ sclgntfySecondary Logon Service Notification DLLMicrosoft Corporationc:\windows\system32\sclgntfy.dll

+ SensLognCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll

+ termsrvCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll

+ wlballoonCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\windows\system32\wlnotify.dll

HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{223D172F-0643-4694-816C-DDDA07D619A9}] DATAGRAM 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{223D172F-0643-4694-816C-DDDA07D619A9}] SEQPACKET 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{3BDA0955-5294-44D5-995B-B8299290B4B6}] DATAGRAM 5Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{3BDA0955-5294-44D5-995B-B8299290B4B6}] SEQPACKET 5Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{6CAFE8F8-6785-477F-A589-D1EC3B13E223}] DATAGRAM 3Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{6CAFE8F8-6785-477F-A589-D1EC3B13E223}] SEQPACKET 3Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{ABF61ABE-B64F-47D5-A09B-787EF2722EF1}] DATAGRAM 6Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{ABF61ABE-B64F-47D5-A09B-787EF2722EF1}] SEQPACKET 6Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{B14CA6D3-3CE0-4E2A-A665-42FB0D53CABC}] DATAGRAM 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{B14CA6D3-3CE0-4E2A-A665-42FB0D53CABC}] SEQPACKET 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{C99DEDBA-BD06-4E84-8174-70083FD92F9F}] DATAGRAM 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{C99DEDBA-BD06-4E84-8174-70083FD92F9F}] SEQPACKET 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{F624D23C-AEEC-4803-9031-BE45CABEFC9E}] DATAGRAM 4Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{F624D23C-AEEC-4803-9031-BE45CABEFC9E}] SEQPACKET 4Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD Tcpip [RAW/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD Tcpip [TCP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ MSAFD Tcpip [UDP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\windows\system32\mswsock.dll

+ RSVP TCP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\windows\system32\rsvpsp.dll

+ RSVP UDP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\windows\system32\rsvpsp.dll

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors

+ BJ Language MonitorLangage Monitor for Canon Bubble-Jet PrinterMicrosoft Corporationc:\windows\system32\cnbjmon.dll

+ Local PortLocal Spooler DLLMicrosoft Corporationc:\windows\system32\localspl.dll

+ PJL Language MonitorPJL Language monitorMicrosoft Corporationc:\windows\system32\pjlmon.dll

+ Standard TCP/IP PortStandard TCP/IP Port Monitor DLLMicrosoft Corporationc:\windows\system32\tcpmon.dll

+ USB MonitorStandard Dynamic Printing Port Monitor DLLMicrosoft Corporationc:\windows\system32\usbmon.dll

HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages

+ msv1_0Microsoft Authentication Package v1.0Microsoft Corporationc:\windows\system32\msv1_0.dll

HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages

+ scecliWindows Security Configuration Editor Client EngineMicrosoft Corporationc:\windows\system32\scecli.dll

HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages

+ kerberosKerberos Security PackageMicrosoft Corporationc:\windows\system32\kerberos.dll

+ msv1_0Microsoft Authentication Package v1.0Microsoft Corporationc:\windows\system32\msv1_0.dll

+ schannelTLS / SSL Security ProviderMicrosoft Corporationc:\windows\system32\schannel.dll

+ wdigestMicrosoft Digest AccessMicrosoft Corporationc:\windows\system32\wdigest.dll

闪电风暴 - 2006-8-17 15:57:00
请详细看了帖子再贴日志.
我要求的options-hide microsoft enryies选上了没??/
闪电风暴 - 2006-8-17 15:58:00
引用:
【闪电风暴的贴子】http://forum.ikaka.com/topic.asp?board=28&artid=7538008


按这个帖所说方法,帖Autoruns日志上来………………




............
leeguoxian - 2006-8-17 22:18:00
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit

+ C:\WINDOWS\system32\Launcher.exec:\windows\system32\launcher.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ !ewidoewido anti-spywareAnti-Malware Development a.s.c:\program files\ewido anti-spyware 4.0\ewido.exe

+ cFosSpeedcFosSpeed WindowcFos Software GmbHc:\program files\cfosspeed\cfosspeed.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

+ CheckFaultKernelc:\windows\system32\mswdm.exe

+ KernelFaultCheckc:\windows\system32\msime.exe

HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components

+ 0找不到文件:About:Home

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

+ DVDBurn找不到文件:C:\WINDOWS\Downloaded Program Files\AfxEdit.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ ewido anti-spyware 4.0ewido anti-spyware guardAnti-Malware Development a.s.c:\program files\ewido anti-spyware 4.0\shellexecutehook.dll

+ system.sysc:\program files\internet explorer\plugins\system.sys

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Desktop ExplorerNVIDIA Desktop Explorer, Version 110.38 NVIDIA Corporationc:\windows\system32\nvshell.dll

+ Desktop Explorer MenuNVIDIA Desktop Explorer, Version 110.38 NVIDIA Corporationc:\windows\system32\nvshell.dll

+ Display Panning CPL Extension找不到文件:deskpan.dll

+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\windows\system32\hticons.dll

+ NvCpl DesktopContext ClassNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll

+ nView Desktop Context MenuNVIDIA Desktop Explorer, Version 110.38 NVIDIA Corporationc:\windows\system32\nvshell.dll

+ Play on my TV helperNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll

+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realplayer\rpshell.dll

+ WinRAR shell extensionc:\program files\winrar\rarext.dll
leeguoxian - 2006-8-17 22:18:00
HKLM\Software\Classes\Folder\Shellex\ColumnHandlers

+ Haali Column Providere:\暴风影音\codecs\mmfinfo.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ kakatool.dllBeijing Rising Technology Co., Ltd.c:\windows\system32\kakatool.dll

HKLM\System\CurrentControlSet\Services

+ BlueSoleil Hid Servicec:\program files\bluesoleil\btntservice.exe

+ cFosSpeedSPerforms latency measurement and privileged operations for cFosSpeedcFos Software GmbHc:\program files\cfosspeed\spd.exe

+ ewido anti-spyware 4.0 guardewido anti-spyware guardAnti-Malware Development a.s.c:\program files\ewido anti-spyware 4.0\guard.exe

+ NVSvcProvides system and desktop level support to the NVIDIA display driverNVIDIA Corporationc:\windows\system32\nvsvc32.exe

+ PDSchedPDSched ModuleRaxco Software, Inc.c:\program files\raxco\perfectdisk\pdsched.exe

HKLM\System\CurrentControlSet\Services

+ ALCXWDMAvance AC'97 Audio Driver (WDM)Avance Logic, Inc.c:\windows\system32\drivers\alcxwdm.sys

+ BlueletAudioBluelet Audio DriverIVT Corporationc:\windows\system32\drivers\blueletaudio.sys

+ BTBluetooth PAN Network Adapter DriverIVT Corporationc:\windows\system32\drivers\btnetdrv.sys

+ BtcsrusbBluetooth USB Device DriverIVT Corporationc:\windows\system32\drivers\btcusb.sys

+ BTHidEnumc:\windows\system32\drivers\vbtenum.sys

+ BTHidMgrBluetooth HID Manager driverIVT Corporationc:\windows\system32\drivers\bthidmgr.sys

+ cFosSpeedcFosSpeed DrivercFos Software GmbHc:\windows\system32\drivers\cfosspeed.sys

+ dtscsic:\windows\system32\drivers\dtscsi.sys

+ ewido anti-spyware 4.0 driverc:\program files\ewido anti-spyware 4.0\guard.sys

+ NPFnpfCACE Technologiesc:\windows\system32\drivers\npf.sys

+ npkcrypt找不到文件:E:\TM\TMDlls\npkcrypt.sys

+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 91.31 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys

+ oreans32c:\windows\system32\drivers\oreans32.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys

+ rtl8139Realtek RTL8139 NDIS 5.0 DriverRealtek Semiconductor Corporationc:\windows\system32\drivers\rtl8139.sys

+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys

+ sptdc:\windows\system32\drivers\sptd.sys

+ TrojanFindDriverNT找不到文件:C:\WINDOWS\system32\NtDriver.sys

+ VCommBluetooth Serial Port DriverIVT Corporationc:\windows\system32\drivers\vcomm.sys

+ VcommMgrBluetooth VcommMgr driverIVT Corporationc:\windows\system32\drivers\vcommmgr.sys

落叶飘泪 - 2006-8-17 22:46:00
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\Launcher.exe
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - (no file)
O21 - SSODL: DVDBurn - {790448C3-4239-45AF-C98B-367991A8B103} - C:\WINDOWS\Downloaded Program Files\AfxEdit.dll (file missing)
O23 - Service: cFosSpeed System Service (cFosSpeedS) - Unknown owner - C:\Program Files\cFosSpeed\spd.exe" -service (file missing)
修复~~~!
删除文件:C:\WINDOWS\system32\Launcher.exe
cxlymb - 2006-8-17 23:07:00
你就不能在智能扫描时少运行点东西吗?一扫描就是几页
leeguoxian - 2006-8-18 9:21:00
求大哥帮帮我啊~~~
1
查看完整版本: 【求助】杀毒软件也杀不了的病毒