[2.8.1.8.0815 - 2.8.24.8.1028] 2008-10-30 17:50 [QQ Toolbar] HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\QQTOOLBAR HKEY_LOCAL_MACHINE\SOFTWARE\TENCENT\QQTOOLBAR [2.8.1.8.0815 - 2.8.24.8.1028] 2008-10-30 17:50 [Trojan.meex.avt] HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\ZXSWEEP.EXE [2.8.1.8.0815 - 2.8.24.8.1028] 2008-10-30 17:50 [Eyiruanjian Canliu] HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GUANGD.EXE HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SDGAMES.EXE HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SVCH0ST.EXE HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\TXOMOU.EXE [2.8.1.8.0815 - 2.8.24.8.1028] 2008-10-30 17:50 [Trojan.c0nime] HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\KVFW.EXE [2.8.1.8.0815 - 2.8.24.8.1028] 2008-10-30 17:50 [Trojan.Driver Exden] HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\ARVMON.EXE HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\KILLHIDEPID.EXE HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\RAVT08.EXE HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\TOOLSUP.EXE [2.8.1.8.0815 - 2.8.24.8.1028] 2008-10-30 17:50 [Trojan.xpserve.lsoss] C:\DOCUMENTS AND SETTINGS\ALL USERS\JJDF32.INI [2.8.1.8.0815 - 2.8.24.8.1028] 2008-10-30 17:50 [Maybe Useless object] C:\WINDOWS\SYSTEM32\MFEVTPS.EXE