普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Synchronization Manager = MOBSYNC.EXE /LOGON
NvCplDaemon = RUNDLL32.EXE D:\WINNT\SYSTEM32\NVCPL.DLL,NVSTARTUP
nwiz = NWIZ.EXE /INSTALL
SoundMan = SOUNDMAN.EXE
RavTask = "D:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Internat.exe = INTERNAT.EXE
NvMediaCenter = RUNDLL32.EXE D:\WINNT\SYSTEM32\NVMCTRAY.DLL,NVTASKBARINIT
ServUTrayIcon = D:\PROGRAM FILES\SERV-U\SERVUTRAY.EXE
AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\Office\WINWORD.EXE" /n
其它启动项
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
SCRNSAVE.EXE = D:\WINNT\system32\sstext3d.scr
Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
wzcnotif = WZCDLG.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = D:\WINNT\SYSTEM32\USERINIT.EXE,
shell = EXPLORER.EXE
IE - BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{A5366673-E8CA-11D3-9CD9-0090271D075B} = E:\PROGRA~1\FLASHGET\jccatch.dll
Winsock SPI
MSAFD Tcpip [TCP/IP] = D:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD Tcpip [UDP/IP] = D:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD Tcpip [RAW/IP] = D:\WINNT\SYSTEM32\MSAFD.DLL
RSVP UDP Service Provider = D:\WINNT\SYSTEM32\RSVPSP.DLL
RSVP TCP Service Provider = D:\WINNT\SYSTEM32\RSVPSP.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{6C9BF41C-85D9-4755-A621-E317C94B1180}] SEQPACKET 0 = D:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{6C9BF41C-85D9-4755-A621-E317C94B1180}] DATAGRAM 0 = D:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D86B34BE-7E2E-4EC3-99A5-FF7D0959EFCB}] SEQPACKET 1 = D:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{D86B34BE-7E2E-4EC3-99A5-FF7D0959EFCB}] DATAGRAM 1 = D:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{08964E28-1A67-441C-B64D-7F80D91AE137}] SEQPACKET 2 = D:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{08964E28-1A67-441C-B64D-7F80D91AE137}] DATAGRAM 2 = D:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{FF405D95-C1CF-4FE8-9520-C2C48CB70208}] SEQPACKET 3 = D:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{FF405D95-C1CF-4FE8-9520-C2C48CB70208}] DATAGRAM 3 = D:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{63EB6835-30D5-45B2-BB36-224CED8C1058}] SEQPACKET 4 = D:\WINNT\SYSTEM32\MSAFD.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{63EB6835-30D5-45B2-BB36-224CED8C1058}] DATAGRAM 4 = D:\WINNT\SYSTEM32\MSAFD.DLL
系统服务项
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
Alerter = D:\WINNT\SYSTEM32\SERVICES.EXE
AppMgmt = D:\WINNT\SYSTEM32\SERVICES.EXE
BITS = D:\WINNT\SYSTEM32\SVCHOST.EXE -K BITSGROUP
Browser = D:\WINNT\SYSTEM32\SERVICES.EXE
cisvc = D:\WINNT\SYSTEM32\CISVC.EXE
ClipSrv = D:\WINNT\SYSTEM32\CLIPSRV.EXE
Dhcp = D:\WINNT\SYSTEM32\SERVICES.EXE
dmadmin = D:\WINNT\SYSTEM32\DMADMIN.EXE /COM
dmserver = D:\WINNT\SYSTEM32\SERVICES.EXE
Dnscache = D:\WINNT\SYSTEM32\SERVICES.EXE
Eventlog = D:\WINNT\SYSTEM32\SERVICES.EXE
EventSystem = D:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
Fax = D:\WINNT\SYSTEM32\FAXSVC.EXE
IISADMIN = D:\WINNT\SYSTEM32\INETSRV\INETINFO.EXE
lanmanserver = D:\WINNT\SYSTEM32\SERVICES.EXE
lanmanworkstation = D:\WINNT\SYSTEM32\SERVICES.EXE
LmHosts = D:\WINNT\SYSTEM32\SERVICES.EXE
Messenger = D:\WINNT\SYSTEM32\SERVICES.EXE
mnmsrvc = D:\WINNT\SYSTEM32\MNMSRVC.EXE
MSDTC = D:\WINNT\SYSTEM32\MSDTC.EXE
MSFTPSVC = D:\WINNT\SYSTEM32\INETSRV\INETINFO.EXE
MSIServer = D:\WINNT\SYSTEM32\MSIEXEC.EXE /V
NetDDE = D:\WINNT\SYSTEM32\NETDDE.EXE
NetDDEdsdm = D:\WINNT\SYSTEM32\NETDDE.EXE
Netlogon = D:\WINNT\SYSTEM32\LSASS.EXE
Netman = D:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
NtLmSsp = D:\WINNT\SYSTEM32\LSASS.EXE
NtmsSvc = D:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
NVSvc = D:\WINNT\SYSTEM32\NVSVC32.EXE
PlugPlay = D:\WINNT\SYSTEM32\SERVICES.EXE
PolicyAgent = D:\WINNT\SYSTEM32\LSASS.EXE
ProtectedStorage = D:\WINNT\SYSTEM32\SERVICES.EXE
RasAuto = D:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
RasMan = D:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
RemoteAccess = D:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
RemoteRegistry = D:\WINNT\SYSTEM32\REGSVC.EXE
RpcLocator = D:\WINNT\SYSTEM32\LOCATOR.EXE
RpcSs = D:\WINNT\SYSTEM32\SVCHOST -K RPCSS
RsCCenter = "D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE"
RsRavMon = "D:\PROGRAM FILES\RISING\RAV\RAVMOND.EXE"
RSVP = D:\WINNT\SYSTEM32\RSVP.EXE -S
SamSs = D:\WINNT\SYSTEM32\LSASS.EXE
SCardDrv = D:\WINNT\SYSTEM32\SCARDSVR.EXE
SCardSvr = D:\WINNT\SYSTEM32\SCARDSVR.EXE
Schedule = D:\WINNT\SYSTEM32\MSTASK.EXE
seclogon = D:\WINNT\SYSTEM32\SERVICES.EXE
SENS = D:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
Serv-U = D:\PROGRAM FILES\SERV-U\SERVUDAEMON.EXE
SharedAccess = D:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
SLService = SLSERV.EXE
SMTPSVC = D:\WINNT\SYSTEM32\INETSRV\INETINFO.EXE
Spooler = D:\WINNT\SYSTEM32\SPOOLSV.EXE
SysmonLog = D:\WINNT\SYSTEM32\SMLOGSVC.EXE
TapiSrv = D:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
TlntSvr = D:\WINNT\SYSTEM32\TLNTSVR.EXE
TrkWks = D:\WINNT\SYSTEM32\SERVICES.EXE
UPS = D:\WINNT\SYSTEM32\UPS.EXE
UtilMan = D:\WINNT\SYSTEM32\UTILMAN.EXE
W32Tasks = D:\WINNT\SYSTEM32\TASKMAN32.EXE
W32Time = D:\WINNT\SYSTEM32\SERVICES.EXE
W3SVC = D:\WINNT\SYSTEM32\INETSRV\INETINFO.EXE
WinMgmt = D:\WINNT\SYSTEM32\WBEM\WINMGMT.EXE
WmdmPmSN = D:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
Wmi = D:\WINNT\SYSTEM32\SERVICES.EXE
wuauserv = D:\WINNT\SYSTEM32\SVCHOST.EXE -K WUGROUP
WZCSVC = D:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
文件驱动
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
FltMgr = D:\WINNT\SYSTEM32\DRIVERS\FLTMGR.SYS
MRxSmb = D:\WINNT\SYSTEM32\DRIVERS\MRXSMB.SYS
NetBIOS = D:\WINNT\SYSTEM32\DRIVERS\NETBIOS.SYS
Rdbss = D:\WINNT\SYSTEM32\DRIVERS\RDBSS.SYS
Srv = D:\WINNT\SYSTEM32\DRIVERS\SRV.SYS