123456   2  /  6  页   跳转

【求助】

难道只有20来位会员浏览此版吗?

附件附件:

下载次数:159
文件类型:application/octet-stream
文件大小:
上传时间:2006-7-2 10:48:24
描述:



gototop
 

2006-07-02,10:50:22

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
    <Yahoo! Pager><"F:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet>  []
    <Super Rabbit IEPro><F:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD>  [Super Rabbit Soft]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
    <run><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [Microsoft Corporation]
    <SoundMan><SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <hxgame-update><C:\Program Files\hxupdate\hxgame-update.exe>  []
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  []
    <SKYNET Personal FireWall><F:\PROGRA~1\SKYNET\FIREWALL\pfw.exe>  [广州众达天网技术有限公司]
    <RfwMain><"F:\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  []
    <SunJavaUpdateSched><C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe>  []
    <Thunder><"F:\迅雷5\ThunderShell.exe" /s>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <RavStub><"C:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]

==================================
启动文件夹
[卡巴斯基反黑客]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\卡巴斯基反黑客.lnk><N>
[WinZip Quick Pick]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\WinZip Quick Pick.lnk><N>
[adsl]
  <C:\Documents and Settings\liu\「开始」菜单\程序\启动\adsl.lnk><N>

==================================
服务
[Rising Proxy  Service / RfwProxySrv]
  <f:\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
  <f:\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[wint / wint]
  <C:\WINDOWS\system32\RunDLL32.exe "C:\WINDOWS\system32\wint\wint.dll",Run -r><N/A>

==================================
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v8.dll, >
[超级兔子上网精灵]
  {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <F:\PROGRA~1\SUPERR~1\MAGICSET\haokanbar.dll, Xiang Feng Technology>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <G:\新建文件夹\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <F:\PROGRA~1\FLASHGET\fgiebar.dll, Amaze Soft>
[超级兔子上网精灵]
  {43869BB3-22FD-4F15-9B46-238106BA2F4E} <F:\PROGRA~1\SUPERR~1\MAGICSET\haokanbar.dll, Xiang Feng Technology>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[Shockwave ActiveX Control]
  {166B1BCA-3F9C-11CF-8075-444553540000} <C:\WINDOWS\system32\macromed\Shockwave 10\Download.dll, Macromedia, Inc.>
[GolfInstallCheck2 Class]
  {3F618E1F-D981-4905-A757-4D237441B5B3} <C:\WINDOWS\Downloaded Program Files\CONFLICT.1\GolfInstallCheck2.dll, N/A>
[Java Plug-in 1.4.2_05]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll, JavaSoft / Sun Microsystems, Inc.>
[TV Stream Source]
  {BE9535B7-76FB-4572-AD20-B32BADB3643B} <C:\WINDOWS\system32\FAggr.ax, www.sina.com.cn>
[Java Plug-in 1.4.2_05]
  {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} <C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll, JavaSoft / Sun Microsystems, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8a.ocx, Macromedia, Inc.>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[VqqSpeedDlProxy Class]
  {F138084D-84D7-48CD-BEA8-04772457516E} <C:\WINDOWS\vqqsdl.dll, Tencent>
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v8.dll, >
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[超级兔子上网精灵]
  {43869BB3-22FD-4F15-9B46-238106BA2F4E} <F:\PROGRA~1\SUPERR~1\MAGICSET\haokanbar.dll, Xiang Feng Technology>
[超级兔子上网精灵]
  {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} <F:\PROGRA~1\SUPERR~1\MAGICSET\haokanbar.dll, Xiang Feng Technology>
[卡卡上网安全助手]
  {AFF6E516-CBE5-4F8A-9C2F-38A68013E766} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8a.ocx, Macromedia, Inc.>
[MessengerChecker Class]
  {DA4F543C-C8A9-4E88-9A79-548CBB46F18F} <F:\Program Files\Yahoo!\Messenger\YPagerChecker.dll, TODO: <Company name>>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <F:\PROGRA~1\FLASHGET\fgiebar.dll, Amaze Soft>
[&使用迅雷下载]
  <F:\迅雷5\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <F:\迅雷5\getallurl.htm, N/A>
[上传到QQ网络硬盘]
  <G:\新建文件夹\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <F:\Program Files\FLASHGET\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <F:\Program Files\FLASHGET\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <G:\新建文件夹\AddPanel.htm, N/A>
[添加到QQ表情]
  <G:\新建文件夹\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <G:\新建文件夹\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 468][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 524][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 548][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 592][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 604][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 748][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 812][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 872][C:\Program Files\Rising\Rav\CCenter.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 892][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 952][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1064][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1080][C:\Program Files\Rising\Rav\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 26>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsLog.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
    [C:\Program Files\Rising\Rav\HOOKSYS.dll]  <Rising><18, 1, 0, 9>
    [C:\Program Files\Rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [C:\Program Files\Rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\regmon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\HookWeb.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\MemMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\expscan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
    [C:\Program Files\Rising\Rav\MailMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Rising\Rav\SpamEng.dll]  <N/A><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
gototop
 

[C:\Program Files\Rising\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 8>
    [C:\Program Files\Rising\Rav\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 17>
    [C:\Program Files\Rising\Rav\Unpacker.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\Program Files\Rising\Rav\ExtFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\ScanNet.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Rising\Rav\ExtMail.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[PID: 1196][f:\rising\rfw\rfwproxy.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 14>
    [f:\rising\rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
    [f:\rising\rfw\MonMid.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 2>
[PID: 1252][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [F:\Program Files\Yahoo!\Messenger\idle.dll]  <Yahoo! Inc.><1, 0, 0, 2>
    [F:\WINZIP\WZSHLSTB.DLL]  <WinZip Computing, Inc.><4.1 (32-bit)>
    [F:\刘召港专用文档\rarext.dll]  <N/A><N/A>
    [F:\刘召港专用文档\ske\contmenu.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Real\RealPlayer\rpshell.dll]  <RealNetworks, Inc.><1.0.1.2021>
    [C:\WINDOWS\system32\PNCRT.dll]  <Real Networks, Inc><6.0.0.0>
    [C:\Program Files\Real\RealPlayer\lang\rpext_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [C:\WINDOWS\system32\xunleibho_v8.dll]  <><4, 5, 1, 33>
[PID: 1300][f:\rising\rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 32>
    [f:\rising\rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
    [f:\rising\rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [f:\rising\rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
    [f:\rising\rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [f:\rising\rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
    [f:\rising\rfw\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[PID: 1508][C:\Program Files\Rising\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1628][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
    [C:\WINDOWS\system32\OLFMNT40.DLL]  <Microsoft Corporation><9.0.98.0105>
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\olfpnt40.dll]  <Microsoft Corporation><9.0.98.0105>
[PID: 1704][f:\rising\rfw\RfwMain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 51>
    [f:\rising\rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [f:\rising\rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [f:\rising\rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [F:\Program Files\Yahoo!\Messenger\idle.dll]  <Yahoo! Inc.><1, 0, 0, 2>
[PID: 1928][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 188][C:\WINDOWS\SOUNDMAN.EXE]  <Realtek Semiconductor Corp.><5.1.0.24>
[PID: 256][C:\Program Files\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
[PID: 272][C:\Program Files\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 28>
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [F:\Program Files\Yahoo!\Messenger\idle.dll]  <Yahoo! Inc.><1, 0, 0, 2>
[PID: 388][F:\PROGRA~1\SKYNET\FIREWALL\pfw.exe]  <广州众达天网技术有限公司><2.7.7.1004>
    [F:\PROGRA~1\SKYNET\FIREWALL\SKYMISC.DLL]  <N/A><N/A>
    [F:\PROGRA~1\SKYNET\FIREWALL\COMPRESSWRAP.DLL]  <N/A><N/A>
    [F:\Program Files\Yahoo!\Messenger\idle.dll]  <Yahoo! Inc.><1, 0, 0, 2>
[PID: 424][C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe]  <N/A><N/A>
[PID: 492][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 920][F:\迅雷5\Thunder.exe]  <Thunder Networking Technologies,LTD><5.0.3.86>
    [F:\迅雷5\UpdateDownload.dll]  <N/A><N/A>
    [F:\迅雷5\download_interface.dll]  <N/A><N/A>
    [F:\迅雷5\log4cplus.dll]  <N/A><N/A>
    [F:\迅雷5\stlport_vc646.dll]  <STLport Consulting, Inc.><4.6.2003.1031>
    [F:\迅雷5\historyinfo_manage.dll]  <N/A><N/A>
    [F:\迅雷5\iThunder.dll]  <迅雷网络><1, 0, 0, 30>
    [F:\迅雷5\RegisterDll.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8a.ocx]  <Macromedia, Inc.><8,0,24,0>
    [F:\Program Files\Yahoo!\Messenger\idle.dll]  <Yahoo! Inc.><1, 0, 0, 2>
[PID: 1116][F:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE]  <Super Rabbit Soft><7.66>
    [F:\PROGRA~1\SUPERR~1\MagicSet\shlobj71.ocx]  <Sky Software (http://www.ssware.com)><7, 1, 0, 0>
    [F:\Program Files\Yahoo!\Messenger\idle.dll]  <Yahoo! Inc.><1, 0, 0, 2>
[PID: 1744][F:\Kaspersky Anti-Hacker\KAVPF.exe]  <Kaspersky Lab><1.8.0.180>
    [F:\Kaspersky Anti-Hacker\BCGCB59.dll]  <BCGSoft Ltd><5, 84, 0, 0>
    [F:\Kaspersky Anti-Hacker\perfiloc.dll]  <Kaspersky Lab><1.5.0.0>
    [F:\Kaspersky Anti-Hacker\BCGCBRes.dll]  <BCGSoft Ltd><5, 84, 0, 0>
    [F:\Kaspersky Anti-Hacker\wcswmi.dll]  <Kaspersky Lab><5.0.201.1>
[PID: 2088][F:\WinZip\WZQKPICK.EXE]  <WinZip Computing, Inc.><1.0 (32-bit)>
[PID: 2272][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3592][F:\Program Files\Yahoo!\Messenger\ypager.exe]  <N/A><N/A>
    [F:\Program Files\Yahoo!\Messenger\idle.dll]  <Yahoo! Inc.><1, 0, 0, 2>
    [F:\Program Files\Yahoo!\Messenger\ygxa_2.dll]  <Yahoo! Inc.><2004, 2, 19, 1>
    [F:\Program Files\Yahoo!\Messenger\pcre.dll]  <Pcre><3.9>
    [F:\Program Files\Yahoo!\Messenger\YML.dll]  <N/A><3, 0, 0, 2>
    [F:\Program Files\Yahoo!\Messenger\YImage.dll]  <Yahoo! Inc.><1, 0, 0, 1>
    [F:\Program Files\Yahoo!\Messenger\xmlparse.dll]  <N/A><N/A>
    [F:\Program Files\Yahoo!\Messenger\xmltok.dll]  <N/A><N/A>
    [F:\Program Files\Yahoo!\Messenger\ft60.dll]  <Yahoo! Inc.><1.0.0.4>
    [F:\Program Files\Yahoo!\Messenger\res_msgr.dll]  <Yahoo! Inc.><6, 0, 0, 1610>
    [C:\Program Files\Yahoo!\Shared\YbSkin2.dll]  <Yahoo! Inc.><2005, 6, 3, 1>
    [F:\Program Files\Yahoo!\Messenger\MyYahoo.dll]  <Yahoo! Inc.><6, 0, 0, 600>
    [F:\Program Files\Yahoo!\Messenger\D32-FW.DLL]  <Distinct Corporation><3.4.6>
    [C:\WINDOWS\system32\icm32.dll]  <Microsoft Corporation><5.1.2600.2709 (xpsp_sp2_gdr.050628-1518)>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8a.ocx]  <Macromedia, Inc.><8,0,24,0>
    [F:\Program Files\Yahoo!\Messenger\stock.dll]  <N/A><2, 0, 0, 1>
    [F:\Program Files\Yahoo!\Messenger\yvoicesm.dll]  <N/A><1, 0, 201, 1>
    [F:\Program Files\Yahoo!\Messenger\yvoiceui.dll]  <N/A><N/A>
gototop
 

[F:\Program Files\Yahoo!\Messenger\yaudiomgr.dll]  <N/A><1, 0, 200, 1>
    [F:\Program Files\Yahoo!\Messenger\yxtldr.dll]  <N/A><1, 0, 200, 1>
    [F:\Program Files\Yahoo!\Messenger\rvsip.dll]  <RADVISION><3.1.1.30>
    [F:\Program Files\Yahoo!\Messenger\rvcommon.dll]  <RADVISION><1.0.18>
    [F:\Program Files\Yahoo!\Messenger\rvads.dll]  <RADVISION><3.1.1.30>
    [F:\Program Files\Yahoo!\Messenger\rvsdp.dll]  <RADVISION><>
    [F:\Program Files\Yahoo!\Messenger\yv_res.dll]  <N/A><N/A>
    [F:\Program Files\Yahoo!\Messenger\eyeBeamAsDLL.dll]  <N/A><N/A>
    [F:\Program Files\Yahoo!\Messenger\AEC_PC_DLL.dll]  <N/A><N/A>
    [C:\Program Files\Yahoo!\Shared\YAlertCenter.dll]  <Yahoo! Inc.><2004, 10, 20, 1>
[PID: 3696][F:\Program Files\FLASHGET\flashget.exe]  <Amaze Soft><1, 7, 1, 0>
    [F:\Program Files\Yahoo!\Messenger\idle.dll]  <Yahoo! Inc.><1, 0, 0, 2>
[PID: 3180][F:\Program Files\TTPlayer\TTPlayer.exe]  <Alen Soft><4, 5, 3, 0>
    [F:\Program Files\TTPlayer\ttpcomm.dll]  <N/A><N/A>
    [F:\Program Files\TTPlayer\ttpres.dll]  <Alen Soft><4, 5, 3, 0>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [F:\Program Files\TTPlayer\AddIn\ttp_asf.dll]  <N/A><N/A>
    [F:\Program Files\TTPlayer\AddIn\ttp_lrcsh.dll]  <N/A><N/A>
    [F:\Program Files\Yahoo!\Messenger\idle.dll]  <Yahoo! Inc.><1, 0, 0, 2>
    [F:\Program Files\TTPlayer\mp3PRO.dll]  <Ahead Software AG><2, 0, 0, 16>
    [F:\Program Files\TTPlayer\AddIn\ttp_rm.dll]  <N/A><N/A>
[PID: 1900][F:\刘召港专用文档\ske\TrojanAssistant.exe]  <Yahoo! CN><2.1.2.1003>
    [F:\刘召港专用文档\ske\fsk.dll]  <3721.com><2, 1, 2, 1030>
    [F:\刘召港专用文档\ske\wmpns.dll]  <---><1, 1, 8, 1324>
    [F:\Program Files\Yahoo!\Messenger\idle.dll]  <Yahoo! Inc.><1, 0, 0, 2>
[PID: 2864][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3332][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [F:\PROGRA~1\SUPERR~1\MAGICSET\haokanbar.dll]  <Xiang Feng Technology><2, 1, 0, 1463>
    [C:\WINDOWS\system32\xunleibho_v8.dll]  <><4, 5, 1, 33>
    [F:\Program Files\Yahoo!\Messenger\idle.dll]  <Yahoo! Inc.><1, 0, 0, 2>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8a.ocx]  <Macromedia, Inc.><8,0,24,0>
[PID: 3324][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 568][C:\Documents and Settings\liu\桌面\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [F:\Program Files\Yahoo!\Messenger\idle.dll]  <Yahoo! Inc.><1, 0, 0, 2>
    [C:\Documents and Settings\liu\桌面\SREng2\Plugins\SREngPluginDemo.SRE]  <Smallfrogs Studio><1, 1, 1, 0>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 




未知家族病毒分析
扫描结果:
无可疑文件


系统活动进程
C:\WINDOWS\SOUNDMAN.EXE
F:\PROGRA~1\SKYNET\FIREWALL\PFW.EXE
F:\PROGRA~1\SKYNET\FIREWALL\SKYMISC.DLL
F:\PROGRA~1\SKYNET\FIREWALL\COMPRESSWRAP.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\IDLE.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV

C:\PROGRAM FILES\JAVA\J2RE1.4.2_05\BIN\JUSCHED.EXE
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV

C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
F:\迅雷5\THUNDER.EXE
F:\迅雷5\UPDATEDOWNLOAD.DLL
F:\迅雷5\DOWNLOAD_INTERFACE.DLL
F:\迅雷5\LOG4CPLUS.DLL
F:\迅雷5\STLPORT_VC646.DLL
F:\迅雷5\HISTORYINFO_MANAGE.DLL
F:\迅雷5\ITHUNDER.DLL
F:\迅雷5\REGISTERDLL.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH8A.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
F:\PROGRAM FILES\YAHOO!\MESSENGER\IDLE.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\MSVCR71.DLL

C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
F:\PROGRAM FILES\SUPER RABBIT\MAGICSET\SRIECLI.EXE
C:\WINDOWS\SYSTEM32\MSVBVM60.DLL
C:\WINDOWS\SYSTEM32\VB6CHS.DLL
F:\PROGRA~1\SUPERR~1\MAGICSET\SHLOBJ71.OCX
F:\PROGRAM FILES\YAHOO!\MESSENGER\IDLE.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\MSVCR71.DLL

F:\RISING\RFW\RFWPROXY.EXE
F:\RISING\RFW\RFWRULE.DLL
F:\RISING\RFW\MONMID.DLL

C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\MSACM32.DRV
F:\PROGRAM FILES\YAHOO!\MESSENGER\IDLE.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\MSVCR71.DLL
F:\WINZIP\WZSHLSTB.DLL
F:\刘召港专用文档\RAREXT.DLL
F:\刘召港专用文档\SKE\CONTMENU.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\WINDOWS\SYSTEM32\AUDIODEV.DLL
C:\WINDOWS\SYSTEM32\MSADP32.ACM
C:\WINDOWS\SYSTEM32\MSCOREE.DLL
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\SHFUSION.DLL
C:\PROGRAM FILES\REAL\REALPLAYER\RPSHELL.DLL
C:\WINDOWS\SYSTEM32\PNCRT.DLL
C:\PROGRAM FILES\REAL\REALPLAYER\LANG\RPEXT_CN.DLL

F:\RISING\RFW\RFWSRV.EXE
F:\RISING\RFW\RFWRULE.DLL
F:\RISING\RFW\RFWLOG.DLL
F:\RISING\RFW\RFWDRV.DLL
F:\RISING\RFW\PSAPI.DLL
F:\RISING\RFW\MONDRV.DLL
F:\RISING\RFW\PROCLIB.DLL
F:\RISING\RFW\MPORTS.DLL

C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\OLFMNT40.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\OLFPNT40.DLL

F:\RISING\RFW\RFWMAIN.EXE
F:\RISING\RFW\RSGUILIB.DLL
F:\RISING\RFW\RSCOMMON.DLL
F:\RISING\RFW\PNGDLL.DLL
F:\RISING\RFW\PSAPI.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\IDLE.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\MSVCR71.DLL

F:\KASPERSKY ANTI-HACKER\KAVPF.EXE
F:\KASPERSKY ANTI-HACKER\BCGCB59.DLL
F:\KASPERSKY ANTI-HACKER\PERFILOC.DLL
F:\KASPERSKY ANTI-HACKER\BCGCBRES.DLL
F:\KASPERSKY ANTI-HACKER\WCSWMI.DLL

F:\刘召港专用文档\SKE\TROJANASSISTANT.EXE
F:\刘召港专用文档\SKE\FSK.DLL
F:\刘召港专用文档\SKE\WMPNS.DLL
C:\WINDOWS\SYSTEM32\AUDIODEV.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\IDLE.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\MSVCR71.DLL

C:\WINDOWS\SYSTEM32\WDFMGR.EXE
F:\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\DOCUMENTS AND SETTINGS\LIU\桌面\RSDETECT.EXE
F:\PROGRAM FILES\YAHOO!\MESSENGER\IDLE.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\MSVCR71.DLL

C:\WINDOWS\SYSTEM32\CONIME.EXE
F:\PROGRAM FILES\TTPLAYER\TTPLAYER.EXE
F:\PROGRAM FILES\TTPLAYER\TTPCOMM.DLL
F:\PROGRAM FILES\TTPLAYER\TTPRES.DLL
F:\PROGRAM FILES\TTPLAYER\ADDIN\TTP_ASF.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
F:\PROGRAM FILES\TTPLAYER\ADDIN\TTP_LRCSH.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\IDLE.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\MSVCR71.DLL
F:\PROGRAM FILES\TTPLAYER\MP3PRO.DLL
C:\WINDOWS\SYSTEM32\AUDIODEV.DLL
F:\PROGRAM FILES\TTPLAYER\ADDIN\TTP_RM.DLL

C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
F:\PROGRA~1\SUPERR~1\MAGICSET\HAOKANBAR.DLL
C:\WINDOWS\SYSTEM32\XUNLEIBHO_V8.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\IDLE.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH8A.OCX
C:\WINDOWS\SYSTEM32\XPSP3RES.DLL
F:\PROGRA~1\FLASHGET\JCCATCH.DLL

F:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
F:\PROGRAM FILES\YAHOO!\MESSENGER\IDLE.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\MSVCR71.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\YGXA_2.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\PCRE.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\YML.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\YIMAGE.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\XMLPARSE.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\XMLTOK.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\MSVCP71.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\FT60.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\RES_MSGR.DLL
C:\PROGRAM FILES\YAHOO!\SHARED\YBSKIN2.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\MYYAHOO.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\D32-FW.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH8A.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
F:\PROGRAM FILES\YAHOO!\MESSENGER\STOCK.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\YVOICESM.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\YVOICEUI.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\YAUDIOMGR.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\YXTLDR.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\RVSIP.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\RVCOMMON.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\RVADS.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\RVSDP.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\YV_RES.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\EYEBEAMASDLL.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\AEC_PC_DLL.DLL
C:\WINDOWS\SYSTEM32\ODBCBCP.DLL
C:\PROGRAM FILES\YAHOO!\SHARED\YALERTCENTER.DLL

F:\PROGRAM FILES\FLASHGET\FLASHGET.EXE
F:\PROGRAM FILES\YAHOO!\MESSENGER\IDLE.DLL
F:\PROGRAM FILES\YAHOO!\MESSENGER\MSVCR71.DLL


普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE" /SPOIL /REMADVDEF /MIGRATION32
PHIME2002ASync = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME
SoundMan = SOUNDMAN.EXE
RavTask = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
hxgame-update = C:\PROGRAM FILES\HXUPDATE\HXGAME-UPDATE.EXE
TkBellExe = "C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE" -OSBOOT
SKYNET Personal FireWall = F:\PROGRA~1\SKYNET\FIREWALL\PFW.EXE
RfwMain = "F:\RISING\RFW\RFWMAIN.EXE" -STARTUP
KernelFaultCheck = C:\WINDOWS\SYSTEM32\DUMPREP 0 -K
SunJavaUpdateSched = C:\PROGRAM FILES\JAVA\J2RE1.4.2_05\BIN\JUSCHED.EXE
Thunder = "F:\迅雷5\THUNDERSHELL.EXE" /S

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
RavStub = "C:\PROGRAM FILES\RISING\RAV\RAVSTUB.EXE" /RUNONCE

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
Yahoo! Pager = "F:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE" -QUIET
Super Rabbit IEPro = F:\PROGRAM FILES\SUPER RABBIT\MAGICSET\SRIECLI.EXE /LOAD


AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =


系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\Office\WINWORD.EXE" /n

其它启动项
WIN.INI
无信息

SYSTEM.INI
SHELL = explorer.exe


Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
ScCertProp = WLNOTIFY.DLL
Schedule = WLNOTIFY.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
termsrv = WLNOTIFY.DLL
wlballoon = WLNOTIFY.DLL

gototop
 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = C:\WINDOWS\SYSTEM32\USERINIT.EXE
shell = EXPLORER.EXE


IE - BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{0005A87D-D626-4B3A-84F9-1D9571695F55} = C:\WINDOWS\system32\xunleibho_v8.dll
{62EED7C6-9F02-42f9-B634-98E2899E147B} = NULL
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} = F:\PROGRA~1\SUPERR~1\MAGICSET\haokanbar.dll
{A5366673-E8CA-11D3-9CD9-0090271D075B} = NULL


Winsock SPI
MSAFD Tcpip [TCP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [UDP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [RAW/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
RSVP UDP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
RSVP TCP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{AC4A1CAA-002D-47AB-A397-2D51986EAC19}] SEQPACKET 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{AC4A1CAA-002D-47AB-A397-2D51986EAC19}] DATAGRAM 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{BF04643A-4F9A-475A-B6B9-C06CCB2EE31E}] SEQPACKET 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{BF04643A-4F9A-475A-B6B9-C06CCB2EE31E}] DATAGRAM 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{6806EB78-1C71-44DE-8AA8-8B4C0E155801}] SEQPACKET 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{6806EB78-1C71-44DE-8AA8-8B4C0E155801}] DATAGRAM 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{B905DD58-F4C6-4FD7-9535-208AC91F988B}] SEQPACKET 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{B905DD58-F4C6-4FD7-9535-208AC91F988B}] DATAGRAM 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{523EDB29-7DC8-4231-92EE-AA0BA82A8AEF}] SEQPACKET 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{523EDB29-7DC8-4231-92EE-AA0BA82A8AEF}] DATAGRAM 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL

系统服务项
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
Alerter = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
ALG = C:\WINDOWS\SYSTEM32\ALG.EXE
AppMgmt = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
aspnet_state = C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\ASPNET_STATE.EXE
AudioSrv = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
BITS = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
Browser = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
CiSvc = C:\WINDOWS\SYSTEM32\CISVC.EXE
ClipSrv = C:\WINDOWS\SYSTEM32\CLIPSRV.EXE
COMSysApp = C:\WINDOWS\SYSTEM32\DLLHOST.EXE /PROCESSID:{02D4B3F1-FD88-11D1-960D-00805FC79235}
CryptSvc = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
DcomLaunch = C:\WINDOWS\SYSTEM32\SVCHOST -K DCOMLAUNCH
Dhcp = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
dmadmin = C:\WINDOWS\SYSTEM32\DMADMIN.EXE /COM
dmserver = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
Dnscache = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE
ERSvc = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
Eventlog = C:\WINDOWS\SYSTEM32\SERVICES.EXE
EventSystem = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
FastUserSwitchingCompatibility = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
helpsvc = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
HidServ = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
HTTPFilter = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K HTTPFILTER
ImapiService = C:\WINDOWS\SYSTEM32\IMAPI.EXE
lanmanserver = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
lanmanworkstation = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
LmHosts = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
Messenger = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
mnmsrvc = C:\WINDOWS\SYSTEM32\MNMSRVC.EXE
MSDTC = C:\WINDOWS\SYSTEM32\MSDTC.EXE
MSIServer = C:\WINDOWS\SYSTEM32\MSIEXEC.EXE /V
NetDDE = C:\WINDOWS\SYSTEM32\NETDDE.EXE
NetDDEdsdm = C:\WINDOWS\SYSTEM32\NETDDE.EXE
Netlogon = C:\WINDOWS\SYSTEM32\LSASS.EXE
Netman = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
Nla = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
NtLmSsp = C:\WINDOWS\SYSTEM32\LSASS.EXE
NtmsSvc = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
PlugPlay = C:\WINDOWS\SYSTEM32\SERVICES.EXE
PolicyAgent = C:\WINDOWS\SYSTEM32\LSASS.EXE
ProtectedStorage = C:\WINDOWS\SYSTEM32\LSASS.EXE
RasAuto = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
RasMan = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
RDSessMgr = C:\WINDOWS\SYSTEM32\SESSMGR.EXE
RemoteAccess = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
RemoteRegistry = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
RfwProxySrv = F:\RISING\RFW\RFWPROXY.EXE
RfwService = F:\RISING\RFW\RFWSRV.EXE
RpcLocator = C:\WINDOWS\SYSTEM32\LOCATOR.EXE
RpcSs = C:\WINDOWS\SYSTEM32\SVCHOST -K RPCSS
RsCCenter = "C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE"
RsRavMon = "C:\PROGRAM FILES\RISING\RAV\RAVMOND.EXE"
RSVP = C:\WINDOWS\SYSTEM32\RSVP.EXE
SamSs = C:\WINDOWS\SYSTEM32\LSASS.EXE
SCardSvr = C:\WINDOWS\SYSTEM32\SCARDSVR.EXE
Schedule = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
seclogon = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
SENS = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
SharedAccess = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
ShellHWDetection = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
Spooler = C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
srservice = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
SSDPSRV = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
stisvc = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K IMGSVC
SwPrv = C:\WINDOWS\SYSTEM32\DLLHOST.EXE /PROCESSID:{5882E77F-9FB0-4C60-BF14-C871FCA8977F}
SysmonLog = C:\WINDOWS\SYSTEM32\SMLOGSVC.EXE
TapiSrv = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
TermService = C:\WINDOWS\SYSTEM32\SVCHOST -K DCOMLAUNCH
Themes = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
TlntSvr = C:\WINDOWS\SYSTEM32\TLNTSVR.EXE
TrkWks = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
UMWdf = C:\WINDOWS\SYSTEM32\WDFMGR.EXE
upnphost = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
UPS = C:\WINDOWS\SYSTEM32\UPS.EXE
VSS = C:\WINDOWS\SYSTEM32\VSSVC.EXE
W32Time = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
WebClient = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE
winmgmt = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
wint = C:\WINDOWS\SYSTEM32\RUNDLL32.EXE "C:\WINDOWS\SYSTEM32\WINT\WINT.DLL",RUN -R
WMConnectCDS = C:\PROGRAM FILES\WINDOWS MEDIA CONNECT 2\WMCCDS.EXE
WmdmPmSN = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
Wmi = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
WmiApSrv = C:\WINDOWS\SYSTEM32\WBEM\WMIAPSRV.EXE
wscsvc = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
wuauserv = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
WZCSVC = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS
xmlprov = C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS


文件驱动
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
FltMgr = C:\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS
MRxDAV = C:\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS
MRxSmb = C:\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
NetBIOS = C:\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS
Rdbss = C:\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS
sr = C:\WINDOWS\SYSTEM32\DRIVERS\SR.SYS
Srv = C:\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS


gototop
 

系统驱动项
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
ACPI = C:\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS
aec = C:\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS
AFD = C:\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS
agp440 = C:\WINDOWS\SYSTEM32\DRIVERS\AGP440.SYS
ALCXSENS = C:\WINDOWS\SYSTEM32\DRIVERS\ALCXSENS.SYS
ALCXWDM = C:\WINDOWS\SYSTEM32\DRIVERS\ALCXWDM.SYS
AsyncMac = C:\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS
atapi = C:\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS
Atmarpc = C:\WINDOWS\SYSTEM32\DRIVERS\ATMARPC.SYS
audstub = C:\WINDOWS\SYSTEM32\DRIVERS\AUDSTUB.SYS
BaseTDI = C:\WINDOWS\SYSTEM32\DRIVERS\BASETDI.SYS
Cdrom = C:\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS
Disk = C:\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS
dmboot = C:\WINDOWS\SYSTEM32\DRIVERS\DMBOOT.SYS
dmio = C:\WINDOWS\SYSTEM32\DRIVERS\DMIO.SYS
dmload = C:\WINDOWS\SYSTEM32\DRIVERS\DMLOAD.SYS
DMusic = C:\WINDOWS\SYSTEM32\DRIVERS\DMUSIC.SYS
drmkaud = C:\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS
ExpScaner = C:\PROGRAM FILES\RISING\RAV\EXPSCAN.SYS
Fdc = C:\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS
Flpydisk = C:\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS
FsVga = C:\WINDOWS\SYSTEM32\DRIVERS\FSVGA.SYS
Ftdisk = C:\WINDOWS\SYSTEM32\DRIVERS\FTDISK.SYS
gameenum = C:\WINDOWS\SYSTEM32\DRIVERS\GAMEENUM.SYS
Gpc = C:\WINDOWS\SYSTEM32\DRIVERS\MSGPC.SYS
HidUsb = C:\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS
HookCont = C:\PROGRAM FILES\RISING\RAV\HOOKCONT.SYS
HookReg = C:\PROGRAM FILES\RISING\RAV\HOOKREG.SYS
HookSys = C:\PROGRAM FILES\RISING\RAV\HOOKSYS.SYS
HookUrl = F:\RISING\RFW\HOOKURL.SYS
HTTP = C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS
i8042prt = C:\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS
Imapi = C:\WINDOWS\SYSTEM32\DRIVERS\IMAPI.SYS
IntelIde = C:\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS
intelppm = C:\WINDOWS\SYSTEM32\DRIVERS\INTELPPM.SYS
Ip6Fw = C:\WINDOWS\SYSTEM32\DRIVERS\IP6FW.SYS
IpFilterDriver = C:\WINDOWS\SYSTEM32\DRIVERS\IPFLTDRV.SYS
IpInIp = C:\WINDOWS\SYSTEM32\DRIVERS\IPINIP.SYS
IpNat = C:\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS
IPSec = C:\WINDOWS\SYSTEM32\DRIVERS\IPSEC.SYS
IRENUM = C:\WINDOWS\SYSTEM32\DRIVERS\IRENUM.SYS
isapnp = C:\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS
Kbdclass = C:\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS
Klif = C:\WINDOWS\SYSTEM32\DRIVERS\KLIF.SYS
Klpf = C:\WINDOWS\SYSTEM32\DRIVERS\KLPF.SYS
Klpid = C:\WINDOWS\SYSTEM32\DRIVERS\KLPID.SYS
kmixer = C:\WINDOWS\SYSTEM32\DRIVERS\KMIXER.SYS
MEMSCAN = C:\PROGRAM FILES\RISING\RAV\MEMSCAN.SYS
Mouclass = C:\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS
mouhid = C:\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS
mProcRs = F:\RISING\RFW\MPROCRS.SYS
MSKSSRV = C:\WINDOWS\SYSTEM32\DRIVERS\MSKSSRV.SYS
MSPCLOCK = C:\WINDOWS\SYSTEM32\DRIVERS\MSPCLOCK.SYS
MSPQM = C:\WINDOWS\SYSTEM32\DRIVERS\MSPQM.SYS
mssmbios = C:\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS
ms_mpu401 = C:\WINDOWS\SYSTEM32\DRIVERS\MSMPU401.SYS
NdisTapi = C:\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS
Ndisuio = C:\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS
NdisWan = C:\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS
NetBT = C:\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS
New0 = C:\WINDOWS\SYSTEM32\NEW.SYS
npkcrypt = G:\新建文件夹\NPKCRYPT.SYS
nv = C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS
NwlnkFlt = C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKFLT.SYS
NwlnkFwd = C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKFWD.SYS
Parport = C:\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS
PCI = C:\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS
PCIIde = C:\WINDOWS\SYSTEM32\DRIVERS\PCIIDE.SYS
PptpMiniport = C:\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS
PSched = C:\WINDOWS\SYSTEM32\DRIVERS\PSCHED.SYS
Ptilink = C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS
RasAcd = C:\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS
Rasl2tp = C:\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS
RasPppoe = C:\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS
Raspti = C:\WINDOWS\SYSTEM32\DRIVERS\RASPTI.SYS
RDPCDD = C:\WINDOWS\SYSTEM32\DRIVERS\RDPCDD.SYS
rdpdr = C:\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS
redbook = C:\WINDOWS\SYSTEM32\DRIVERS\REDBOOK.SYS
RsFwDrv = F:\RISING\RFW\RSFWDRV.SYS
rtl8139 = C:\WINDOWS\SYSTEM32\DRIVERS\RTL8139.SYS
Secdrv = C:\WINDOWS\SYSTEM32\DRIVERS\SECDRV.SYS
serenum = C:\WINDOWS\SYSTEM32\DRIVERS\SERENUM.SYS
Serial = C:\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS
SKNFW = C:\WINDOWS\SYSTEM32\DRIVERS\SKNFW.SYS
splitter = C:\WINDOWS\SYSTEM32\DRIVERS\SPLITTER.SYS
SSIKRNL = C:\PROGRAM FILES\DFVSX\NET\SSIKRNL.SYS
swenum = C:\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS
swmidi = C:\WINDOWS\SYSTEM32\DRIVERS\SWMIDI.SYS
sysaudio = C:\WINDOWS\SYSTEM32\DRIVERS\SYSAUDIO.SYS
Tcpip = C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
TermDD = C:\WINDOWS\SYSTEM32\DRIVERS\TERMDD.SYS
Update = C:\WINDOWS\SYSTEM32\DRIVERS\UPDATE.SYS
usbehci = C:\WINDOWS\SYSTEM32\DRIVERS\USBEHCI.SYS
usbhub = C:\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS
USBSTOR = C:\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS
usbuhci = C:\WINDOWS\SYSTEM32\DRIVERS\USBUHCI.SYS
VgaSave = C:\WINDOWS\SYSTEM32\DRIVERS\VGA.SYS
Wanarp = C:\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS
wdmaud = C:\WINDOWS\SYSTEM32\DRIVERS\WDMAUD.SYS
WS2IFSL = C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS

gototop
 

急~这么多东西,就没人来给我分析。
gototop
 

55555555555555555555555555555555
gototop
 

找不到显示隐藏文件或文件夹选项

附件附件:

下载次数:162
文件类型:application/octet-stream
文件大小:
上传时间:2006-7-2 12:00:12
描述:



gototop
 
123456   2  /  6  页   跳转
页面顶部
Powered by Discuz!NT