Directory
Object Find
[A ] 294. c:\windows\system32\dsquery.dll
Microsoft Corporation
Directory Service Find
.text,.data,.rsrc,.reloc,
Directory Start/Search Find
[A ] 294. c:\windows\system32\dsquery.dll
Microsoft Corporation
Directory Service Find
.text,.data,.rsrc,.reloc,
Directory Property UI
[A ] 295. c:\windows\system32\dsuiext.dll
Microsoft Corporation
Directory Service Common UI
.text,.data,.rsrc,.reloc,
Directory Context Menu Verbs
[A ] 295. c:\windows\system32\dsuiext.dll
Microsoft Corporation
Directory Service Common UI
.text,.data,.rsrc,.reloc,
MyDocs Copy Hook
[A ] 296. c:\windows\system32\mydocs.dll
Microsoft Corporation
My Documents Folder UI
.text,.data,.rsrc,.reloc,
MyDocs Drop Target
[A ] 296. c:\windows\system32\mydocs.dll
Microsoft Corporation
My Documents Folder UI
.text,.data,.rsrc,.reloc,
MyDocs Properties
[A ] 296. c:\windows\system32\mydocs.dll
Microsoft Corporation
My Documents Folder UI
.text,.data,.rsrc,.reloc,
Offline Files Menu
[AM] 297. c:\windows\system32\cscui.dll
Microsoft Corporation
Client Side Caching UI
.text,.data,.rsrc,.reloc,
Offline Files Folder Options
[AM] 297. c:\windows\system32\cscui.dll
Microsoft Corporation
Client Side Caching UI
.text,.data,.rsrc,.reloc,
脱机文件夹
[AM] 297. c:\windows\system32\cscui.dll
Microsoft Corporation
Client Side Caching UI
.text,.data,.rsrc,.reloc,
DfsShell
[A ] 298. c:\windows\system32\dfsshlex.dll
Microsoft Corporation
Distributed File System shell extension
.text,.data,.rsrc,.reloc,
%DESC_PublishDropTarget%
[A ] 299. c:\windows\system32\photowiz.dll
Microsoft Corporation
Photo Printing Wizard
.text,.data,.rsrc,.reloc,
MMC Icon Handler
[A ] 300. c:\windows\system32\mmcshext.dll
Microsoft Corporation
MMC Shell Extension DLL
.text,.data,.rsrc,.reloc,
.CAB file viewer
[A ] 301. c:\windows\system32\cabview.dll
Microsoft Corporation
Cabinet File Viewer Shell Extension
.text,.data,.rsrc,.reloc,
用户(&P)...
[A ] 302. c:\program files\outlook express\wabfind.dll
Microsoft Corporation
Find People
.text,.data,.rsrc,.reloc,
Windows Media Player Play as Playlist Context Menu Handler
[A ] 303. c:\windows\system32\wmpshell.dll
Microsoft Corporation
Windows Media Player Launcher
.text,.data,.rsrc,.reloc,
Windows Media Player Burn Audio CD Context Menu Handler
[A ] 303. c:\windows\system32\wmpshell.dll
Microsoft Corporation
Windows Media Player Launcher
.text,.data,.rsrc,.reloc,
Windows Media Player Add to Playlist Context Menu Handler
[A ] 303. c:\windows\system32\wmpshell.dll
Microsoft Corporation
Windows Media Player Launcher
.text,.data,.rsrc,.reloc,
WinRAR shell extension
[A ] 304. c:\program files\winrar\rarext.dll
.text,.data,.tls,.idata,.edata,.rsrc,.reloc,
Portable Media Devices
[A ] 305. c:\windows\system32\audiodev.dll
Microsoft Corporation
便携媒体设备命令行解释器扩展
.text,.data,.rsrc,.reloc,
Portable Media Devices Menu
[A ] 305. c:\windows\system32\audiodev.dll
Microsoft Corporation
便携媒体设备命令行解释器扩展
.text,.data,.rsrc,.reloc,
Shell Search Band
[AM] 238. c:\windows\system32\browseui.dll
Microsoft Corporation
Shell Browser UI Library
.text,.data,.rsrc,.reloc,
Shell Extensions for RealOne Player
[A ] 306. c:\program files\real\realplayer\rpshell.dll
RealNetworks, Inc.
RealPlayer Shell Extensions
.text,.rdata,.data,.rsrc,.reloc,
PicaView
[A ] 307. c:\program files\acdsee\plugins\picaview.dll
ACD Systems, Ltd.
PicaView 资源管理器扩展 DLL
.text,.rdata,.data,.tls,.rsrc,.reloc,
Photo Resizing PowerToy
[A ] 308. c:\program files\acdsee\plugins\phototoys.dll
Microsoft Corporation
Windows XP PowerToys
.text,.data,.rsrc,.reloc,
Microsoft Office HTML Icon Handler
[AM] 309. c:\program files\microsoft office\office11\msohev.dll
Microsoft Corporation
Microsoft Office 2003 component
.text,.data,.rsrc,.reloc,
Web Folders
[A ] 310. c:\program files\common files\microsoft shared\web folders\msonsext.dll
Microsoft Corporation
Microsoft Web Folders
.text,.data,.rsrc,.reloc,
Fusion Cache
[A ] 240. c:\windows\system32\mscoree.dll
Microsoft Corporation
Microsoft .NET Runtime Execution Engine
.text,.data,.rsrc,.reloc,
Autodesk DWF Preview
[A ] 311. c:\program files\common files\autodesk shared\thumbnail\acdwfthmbprxy16.dll
Autodesk
AcThumbnail Module
.text,.rdata,.data,.rsrc,.reloc,
AutoCAD Digital Signatures Icon Overlay Handler
[AM] 312. c:\windows\system32\acsignicon.dll
Autodesk
AcSignIcon Module
.text,.rdata,.data,.rsrc,.reloc,
Autodesk Drawing Preview
[A ] 313. c:\program files\common files\autodesk shared\thumbnail\acthumbnail16.dll
Autodesk
AcThumbnail Module
.text,.rdata,.data,.rsrc,.reloc,
RISING
[A ] 314. c:\windows\system32\ravext.dll
Beijing Rising Technology Co., Ltd.
Rising Shell Ext Module
.text,.rdata,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 315. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
Browseui 预加载程序
[AM] 238. c:\windows\system32\browseui.dll
Microsoft Corporation
Shell Browser UI Library
.text,.data,.rsrc,.reloc,
组件类别缓存程序
[AM] 238. c:\windows\system32\browseui.dll
Microsoft Corporation
Shell Browser UI Library
.text,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
PostBootReminder
[AM] 239. c:\windows\system32\shell32.dll
Microsoft Corporation
Windows Shell Common Dll
.text,.data,.rsrc,.reloc,
CDBurn
[AM] 239. c:\windows\system32\shell32.dll
Microsoft Corporation
Windows Shell Common Dll
.text,.data,.rsrc,.reloc,
WebCheck
[AM] 285. c:\windows\system32\webcheck.dll
Microsoft Corporation
Web Site Monitor
.text,.data,.rsrc,.reloc,
SysTray
[AM] 316. c:\windows\system32\st
object.dll
Microsoft Corporation
Systray shell service
object .text,.data,.rsrc,.reloc,
+ 用户登陆自运行项目
+ HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds
StartupPrograms
[A ] 317. c:\windows\system32\rdpclip.exe
Microsoft Corporation
RDP Clip Monitor
.text,.data,.rsrc,
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
[A ] 318. c:\windows\system32\userinit.exe
Microsoft Corporation
Userinit Logon Application
.text,.data,.rsrc,
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
[AM] 319. c:\windows\explorer.exe
Microsoft Corporation
Windows Explorer
.text,.data,.rsrc,.reloc,
文件名和"iexplore.exe"类似;
+ HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe
[AM] 320. c:\windows\system32\ctfmon.exe
Microsoft Corporation
CTF Loader
.text,.data,.rsrc,
bgswitch
[A ] 321. c:\windows\system32\bgswitch.exe
.text,.data,.rsrc,
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
SkyTel
[A ] 322. c:\windows\skytel.exe
Realtek Semiconductor Corp.
Realtek Voice Manager
.text,.data,.tls,.rdata,.idata,.edata,.rsrc,.reloc,
RTHDCPL
[AM] 323. c:\windows\rthdcpl.exe
Realtek Semiconductor Corp.
Realtek HD Audio Control Panel
.text,.data,.tls,.rdata,.idata,.edata,.rsrc,.reloc,
Alcmtr
[A ] 324. c:\windows\alcmtr.exe
Realtek Semiconductor Corp.
Realtek Azalia Audio - Event Monitor
.text,.rdata,.data,.rsrc,
RavTask
[A ] 325. c:\program files\rising\rav\ravtask.exe
Beijing Rising Technology Co., Ltd.
RavTimer
.text,.rdata,.data,.rsrc,
Samsung PanelMgr
[A ] 326. c:\windows\samsung\panelmgr\ssmmgr.exe
Status Monitor Manager
.text,.rdata,.data,.rsrc,
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 327. c:\windows\system32\autochk.exe
Microsoft Corporation
Auto Check Utility
.text,.data,.rsrc,.reloc,
[A ] 328. c:\windows\system32\bsmain.exe
Beijing Rising Technology Co., Ltd.
BootScan
.text,.data,.rsrc,.reloc,
+ 映像劫持
+ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
Your Image File Name Here without a path
[A ] 329. c:\windows\system32\ntsd.exe
Microsoft Corporation
Symbolic Debugger for Windows 2000
.text,.data,.rsrc,