正常注册表、服务、驱动项收集贴 LastUpdate:20070719.2303
<strong><font face="宋体" color="#0000ff">一、注册表项目</font></strong><p><font face="宋体" size="3">1.01 <strong><font color="#ff0000">透明网关认证程序</font></strong><br/><br/><renzheng><C:\renzheng\webaClient.exe> [] </font></p><p><font size="3"><font face="宋体"><font color="#ff0000">1.02 如下三项为Nvida显卡相关<br/></font><br/> <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> <br/> <NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit> <br/> <nwiz><nwiz.exe /install> </font></font></p><p><font color="#0000ff"><font face="宋体" color="#ff0000" size="3">1.03 如下几项均为IBM笔记本系列的正常组件的启动 当然可以考虑屏蔽不建议删除。<br/></font><font size="3"><font face="宋体"><font color="#000000"><br/> <WinlogonNotify: tpfnf2><notifyf2.dll> []<br/><br/> <WinlogonNotify: tphotkey><tphklock.dll>[]</font></font></font></font></p><p><font size="3"><font face="宋体" color="#ff0000"><strong>1.04 壁纸自动换<br/></strong></font></font><font color="#0000ff"><font size="3"><font face="宋体"><font color="#000000"><br/> <switch><c:\windows\system32\壁纸自动换.exe> []<br/> <switch><c:\windows\system32\bgswitch.exe> []<br/><br/><strong><font color="#ff0000">1.05 摄像头</font></strong><br/><br/><BigDogPath><C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera> <br/><br/></font><font color="#ff0000"><strong>1.06 windows致命错误修复</strong><br/></font><font color="#000000"><br/><KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> </font></font></font></font></p><p><font color="#0000ff"><font size="3"><font face="宋体"><font color="#000000"><strong><font color="#ff0000">1.07 木马克星软件</font></strong><br/></font></font></font></font><font color="#0000ff"><font size="3"><font face="宋体"><font color="#000000"><br/> <AppInit_DLLs><APIHookDll.dll> </font><br/><br/><font color="#ff0000"><strong>1.08 某摄像头</strong></font><br/><font color="#000000"><domino><C:\WINDOWS\domino.exe> <br/></font></font></font></font><font color="#0000ff"><font size="3"><font face="宋体"><font color="#000000"><br/><font color="#ff0000"><strong>1.09 "htpatch.exe" is a component for SiS AGP patch</strong></font><br/><br/><HTpatch><C:\WINDOWS\htpatch.exe> </font></font></font></font></p><p><font color="#ff0000" size="3"><strong>1.10 SRENG 2.5后日志扫出来的如下项目 都<font color="#0000ff">不是</font>问题项。</strong></font></p><p><font size="3"><br/> <IE7 Uninstall Stub><C:\WINDOWS\system32\ieudinit.exe> [(Verified)Microsoft Windows Component Publisher]<br/><br/><br/> <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> <br/><br/><br/> <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> <br/><br/><br/> <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> <br/><br/><br/> <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> [(Verified)Microsoft Windows Publisher]<br/><br/><br/> <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]<br/><br/><br/> <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> </font></p><p><font color="#0000ff"><font size="3"><font face="宋体"><strong><br/>二、服务</strong></font></font></font></p><p><font face="宋体"><font size="3"><strong>2.01 XP 人机接口设备</strong><br/><br/> <C:\windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A><br/><strong><br/>2.02 Windows帮助中心</strong><br/><br/> <C:\windows\System32\svchost.exe -k netsvcs-->%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll><N/A><br/><br/><strong>2.03 如下为IBM笔记本的正常组件的服务启动 可根据需要屏蔽部分但不建议删除。</strong><br/><br/> <C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe><N/A><br/><br/> <C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe><Lenovo><br/><br/> <C:\WINDOWS\system32\ibmpmsvc.exe><><br/><br/> <C:\WINDOWS\system32\TpKmpSVC.exe><N/A></font></font></p><p><font face="宋体"><font size="3"><strong>2.04 ATI显卡</strong><br/><br/><C:\WINDOWS\system32\ati2sgag.exe><></font></font></p><p><font face="宋体"><font size="3"><strong>2.05 用友财务软件</strong><br/><br/> <C:\WINDOWS\system32\UfAutoLoadService.exe><><br/><br/> <C:\WINDOWS\system32\MsgGhost.exe><><br/><br/> <C:\WINDOWS\system32\ServerNT.exe><N/A><br/></font></font><font face="宋体"><br/><font size="3"><strong>2.06 某摄像头的服务</strong><br/><br/> <C:\WINDOWS\System32\PAStiSvc.exe><N/A><br/><br/><strong>2.07 <font face="Arial">时创网络动态域名系统</font></strong><br/><br/> <G:\itsys\CyberIP.exe><><br/><br/> <"D:\Program Files\Cyberlink\Shared Files\RichVideo.exe"><><br/><br/><strong>2.08 影子系统powershadow</strong><br/></font></font><font face="宋体"><font size="3"><br/> <D:\WINDOWS\system32\shadow\ShadowService.exe><N/A><br/><br/><strong>2.09 某读卡器</strong><br/><br/> <C:\WINDOWS\system32\<span style="COLOR: #ee6600; BACKGROUND-COLOR: yellow;">o2flash.exe</span>><N/A><br/></font><br/></font><font size="3"><font face="宋体"><strong><font color="#0000ff"><br/>三、驱动</font></strong><br/>3.01 </font></font><font size="3"><font face="宋体"><font color="#ff0000"><strong>ALi mini IDE Driver provided by Acer Laboratories Inc<br/></strong></font><br/> <\SystemRoot\System32\DRIVERS\aliide.sys><N/A><br/><br/> <\??\e:\NGOATI~1.3\ATT\atitray.sys><N/A><br/></font></font><font color="#ff0000"><strong><br/><font face="宋体" size="3">3.02 </font></strong></font><a href="http://www.google.com/search?q=%22Macrovision SECURITY Driver%22"><font face="宋体" color="#ff0000" size="3"><strong>Macrovision SECURITY Driver</strong></font></a><br/><font size="3"><font face="宋体"><br/> <system32\DRIVERS\secdrv.sys><N/A><br/><br/><strong><font color="#ff0000">3.03 VIA AC'97 Audio Controller</font></strong>
<br/><br/> <system32\drivers\viaudio.sys><N/A><br/><strong><font color="#ff0000">3.04 天网防火墙</font></strong><br/><br/> <\??\C:\WINDOWS\system32\Drivers\SKNFW.sys><N/A><br/><br/> <\??\C:\PROGRA~1\SkyNet\Firewall\SkyProcs.sys><N/A><br/></font><strong><font color="#ff0000"><br/><font face="宋体">3.05 USB摄像头<br/></font></font></strong><font face="宋体"><br/> <system32\DRIVERS\snpstd3.sys><><br/><br/> <System32\Drivers\usbVM31b.sys><VM><br/><br/> <System32\Drivers\usbVM31b.sys><VM><br/><br/> <System32\Drivers\usbVM31b.sys><VM><br/><br/> <system32\DRIVERS\usb2vcom.sys><><br/><br/></font></font><strong><font color="#ff0000"><br/><font face="宋体" size="3">3.06 </font></font></strong><font size="3"><font face="宋体"><strong><font color="#ff0000">sptd.sys是daemon tools虚拟光驱的一个文件</font></strong><br/><br/><\SystemRoot\System32\Drivers\sptd.sys><N/A><br/><br/><\SystemRoot\System32\Drivers\dtscsi.sys><N/A><br/><br/> <\SystemRoot\system32\DRIVERS\d347bus.sys><><br/><br/> <\SystemRoot\System32\Drivers\d347prt.sys><></font></font></p><p><font size="3"><font face="宋体"><strong><font color="#ff0000">3.07 QQ加密键盘的几个驱动</font></strong><br/><br/> <\??\C:\Program files\Tencent\QQ\npkcrypt.sys><N/A><br/> <br/> <\??\C:\Program files\Tencent\QQ\npkcusb.sys><N/A><br/><br/> <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.></font></font></p><p></p><p><font size="3"><font face="宋体"></font></font></p><p><font size="3"><font face="宋体"><strong><font color="#ff0000">3.08 </font></strong><font face="Arial" size="2"><font face="宋体" color="#ff0000" size="3"><strong>The SCSI/RAID Host Controller driver by Microtek Lab</strong></font>
</font><br/><br/> <\SystemRoot\System32\drivers\SMPLSCSI.SYS><N/A></font></font>
</p><p><font size="3"><font color="#ff0000"><strong>3.09 招商银行网上银行大众版登录插件<br/></strong></font><br/> <\??\D:\WINDOWS\system32\Drivers\CMBProtector.dat><N/A><br/><br/><strong><font color="#ff0000">3.10 某主板驱动</font></strong><br/><br/> <\SystemRoot\System32\DRIVERS\3WAREDRV.SYS><N/A><br/><br/> <\SystemRoot\System32\DRIVERS\3waregsm.sys><N/A><br/><br/> <\SystemRoot\System32\DRIVERS\3WDRV100.SYS><N/A><br/><br/><font color="#ff0000"><strong>3.11 AntiARP Sniffer的驱动<br/></strong></font></font><font face="宋体" size="4"><br/> <\??\<font color="#ff0000">C:\WINDOWS\system32\drivers\oreans32.sys</font>><N/A></font></p><p><font face="宋体" size="4"><strong><font color="#ff0000">3.12 NTPort.Library:</font></strong>
<font size="2"><font face="Comic Sans MS"><strong>NTPort Library</strong>
</font>允许你的Win32程序实时直接访问PC机的I/O端口而无须使用<font face="Comic Sans MS">Windows Drivers Development Kit(DDK) 或其他工具。NTPort Library非常容易使用:在Windows NT/2000/XP下,NTPort Library 驱动程序可以动态地加载和卸载,你不需要做任何设置工作。NTPort Library也是BASIC的INP或OUT命令的替代品。NTPort Library还可以获得LPT端口的基地址。</font></font><br/><br/> <\??\<font color="#ff0000">C:\WINDOWS\system32\zntport.sys</font>><N/A></font></p><p><font size="3"><font face="宋体"><strong><font color="#ff0000">3.13 某读卡器</font></strong><br/></font><br/> <\SystemRoot\system32\DRIVERS\o2media.sys><O2Micro><br/><br/> <\SystemRoot\system32\DRIVERS\o2sd.sys><O2Micro><br/><br/><strong><font color="#ff0000">3.14 Lenovo的驱动</font></strong><br/><br/><C:\WINDOWS\fsp.exe><N/A><br/><br/><C:\WINDOWS\usblogon.exe><N/A></font></p><p><font size="3"><strong><font color="#ff0000">3.15 蓝牙设备驱动</font></strong><br/><br/> <system32\DRIVERS\blueletaudio.sys><N/A><br/><br/> <system32\DRIVERS\btnetdrv.sys><N/A><br/><br/> <system32\DRIVERS\vbtenum.sys><N/A><br/><br/> <\SystemRoot\System32\Drivers\BTHidMgr.sys><N/A><br/><br/> <System32\Drivers\VcommMgr.sys><N/A></font></p><p><font size="3"><strong><font color="#ff0000">3.16 某ADSL Modem驱动</font></strong><br/><br/> <system32\DRIVERS\PPPoEWin.SYS><N/A></font></p><p><font size="3"><strong><font color="#ff0000">3.16 Lenovo的IBM笔记本某驱动<br/></font></strong><font face="宋体"><br/> <System32\drivers\TDSMAPI.SYS><N/A><br/><br/> <System32\DRIVERS\TPInput.sys><IBM Corporation><br/><br/> <System32\drivers\Tppwrif.sys><N/A><br/><br/> <System32\drivers\TSMAPIP.SYS><N/A></font></font></p><p><font size="3"><font color="#ff0000"><font face="宋体"><strong>3.17 </strong></font><font face="Arial"><strong><span style="COLOR: #ee6600; BACKGROUND-COLOR: yellow;">ASIO.SYS</span> is a system service.</strong> Manufacturer: ASUS http://support.asus.com.tw/.</font></font></font></p><p><font size="3"><br/> <system32\drivers\AsIO.sys><N/A></font></p><p><font size="3">sptd.sys是daemon tools虚拟光驱的一个文件<br/>c:\windows\system32\sptd.sys <N/A><br/><br/><br/></font><font face="宋体"><font size="3"><br/></font></font></p><p><font face="宋体" size="3"></font></p><p><font face="宋体" color="#0000ff" size="3"><strong>四、其他(BHO、启动文件夹等)</strong></font></p><p><font face="宋体" color="#0000ff" size="3"><strong><font color="#993300">4.01 如下为惠普打印机的驱动</font><br/><font color="#3366ff">正在运行的进程中可以看到注入:</font><br/></strong><font color="#000000"> <br/> <br/> <br/> <br/> [Hewlett-Packard Corporation, 60.041.41.</font></font></p>
页:
[1]