HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ ATIPTAATI Desktop Control PanelATI Technologies, Inc.c:\program files\ati technologies\ati control panel\atiptaxx.exe
+ DAEMON ToolsVirtual DAEMON ManagerDT Soft Ltd.d:\program files\daemon tools\daemon.exe
+ Knight VFile not found: ;
+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.d:\program files\rising\rav\ravtask.exe
+ SoundManRealtek Sound ManagerRealtek Semiconductor Corp.c:\windows\soundman.exe
+ StormCodec_Helperd:\program files\ringz studio\storm codec\stormset.exe
+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe
C:\Documents and Settings\All Users\「开始」菜单\程序\启动
+ Adobe Reader Speed Launch.lnkAdobe Acrobat SpeedLauncherAdobe Systems Incorporatedd:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
C:\Documents and Settings\Administrator\「开始」菜单\程序\启动
+ reboot.exeReboot Setupc:\documents and settings\administrator\「开始」菜单\程序\启动\autorunsdisabled\reboot.exe
+ 腾讯QQ.lnkQQTENCENTd:\program files\tencent\qq\qq.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
+ bgswitchc:\windows\system32\bgswitch.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
+ Rising Execute File Exts hookRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ Display Panning CPL ExtensionFile not found: deskpan.dll
+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\windows\system32\hticons.dll
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
+ RTX Shell MenuRTX Shell MenuTencentf:\games\tencent\rtx\rtxshl.dll
+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.d:\program files\ringz studio\storm codec\rpshell.dll
+ WinRAR shell extensiond:\program files\winrar\rarext.dll
HKLM\Software\Classes\Folder\Shellex\ColumnHandlers
+ PDF Shell ExtensionPDF Shell ExtensionAdobe Systems, Inc.d:\program files\adobe\acrobat 7.0\activex\pdfshell.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ AcroIEHlprObj ClassAdobe Acrobat IE Helper Version 7.0 for ActiveXAdobe Systems Incorporatedd:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
+ DragSearch BHODragSearchc:\program files\yisou\yisoub.dll
+ HB
Object ClassHBHelper ModuleShanghai Henbang Technology Co., Ltdc:\program files\hbclient\hbhelper.dll
+ IeCatch2 Classjccatch ModuleAmaze Softd:\program files\flashget\jccatch.dll
+ QQBrowserHelper
Object ClassQQIEHelper Module深圳市腾讯计算机系统有限公司d:\program files\tencent\qq\qqiehelper.dll
+ {3E422F49-1566-40D3-B43D-077EF739AC32}File not found: C:\WINDOWS\system32\NaviHelper.dll
+ 雅虎助手ToolBarYahoo!c:\program files\yahoo!\assistant\assist\yasbar.dll
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
+ yok_supersearch.dllwww.yok.comc:\program files\yok.com\supersearch\yok_supersearch.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ FlashGet BarFlashGet IE BarAmaze Softd:\program files\flashget\fgiebar.dll
+ YOK Searchwww.yok.comc:\program files\yok.com\supersearch\yok_supersearch.dll
+ 雅虎助手ToolBarYahoo!c:\program files\yahoo!\assistant\assist\yasbar.dll
+ 一搜YiSou ToolBar 3721c:\program files\yisou\yisou.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ &FlashGetFlashGetAmaze Softd:\program files\flashget\flashget.exe
+ 番茄花园File not found: http://www.tomatolei.com
+ 浩方对战平台浩方对战平台上海浩方在线信息技术有限公司f:\games\浩方对战平台\gameclient.exe
+ 腾讯QQQQTENCENTd:\program files\tencent\qq\qq.exe
+ 易趣购物File not found: http://click2.ad4all.net/url2/urlmanage/url.asp?id=5
HKLM\System\CurrentControlSet\Services
+ Ati HotKey PollerATI External Event Utility EXE ModuleATI Technologies Inc.c:\windows\system32\ati2evxx.exe
+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.d:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.d:\program files\rising\rav\ravmond.exe
HKLM\System\CurrentControlSet\Services
+ ALCXWDMRealtek AC'97 Audio Driver (WDM)Realtek Semiconductor Corp.c:\windows\system32\drivers\alcxwdm.sys
+ ati2mtagATI Radeon WindowsNT Miniport DriverATI Technologies Inc.c:\windows\system32\drivers\ati2mtag.sys
+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\windows\system32\drivers\basetdi.sys
+ dtscsic:\windows\system32\drivers\dtscsi.sys
+ ExpScanerExpScan.sysd:\program files\rising\rav\expscan.sys
+ HookContTDI HOOK DriverRising tech Co. ltdd:\program files\rising\rav\hookcont.sys
+ HookRegd:\program files\rising\rav\hookreg.sys
+ HookSysHooksysRisingd:\program files\rising\rav\hooksys.sys
+ MEMSCANMemScan Driver瑞星软件有限公司d:\program files\rising\rav\memscan.sys
+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.d:\program files\tencent\qq\npkcrypt.sys
+ nvatabusNVIDIA? nForce(TM) IDE Performance DriverNVIDIA Corporationc:\windows\system32\drivers\nvatabus.sys
+ NVENETFDNVIDIA Networking Function Driver.NVIDIA Corporationc:\windows\system32\drivers\nvenetfd.sys
+ nvnetbusNVIDIA Networking Bus Driver.NVIDIA Corporationc:\windows\system32\drivers\nvnetbus.sys
+ paasweqFile not found: C:\WINDOWS\system32\27j08kbh.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys
+ QuakeDRVc:\windows\system32\drivers\quakedrv.sys
+ SecdrvSafeDisc driverMacrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.c:\windows\system32\drivers\secdrv.sys
+ sfdrv01StarForce Protection Environment DriverProtection Technologyc:\windows\system32\drivers\sfdrv01.sys
+ sfhlp02StarForce Protection Helper DriverProtection Technologyc:\windows\system32\drivers\sfhlp02.sys
+ sfsync03StarForce Protection Synchronization DriverProtection Technologyc:\windows\system32\drivers\sfsync03.sys
+ sfvfs02StarForce Protection VFS DriverProtection Technologyc:\windows\system32\drivers\sfvfs02.sys
+ sptdc:\windows\system32\drivers\sptd.sys
+ SSHDRV85Direct Port Access - Helper Driverc:\windows\system32\drivers\sshdrv85.sys
+ vbppdryuFile not found: C:\WINDOWS\system32\bwmxk.sys
+ vcddevVirtual Native Network DriverVNN B.J.c:\windows\system32\drivers\vcdvnic.sys
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
+ AtiExtEventATI External Event Utility DLL ModuleATI Technologies Inc.c:\windows\system32\ati2evxx.dll
已经hide microsoft entries