F3 - REG:win.ini: load=C:\WINDOWS\system32\checksys.exe
F3 - REG:win.ini: run=C:\WINDOWS\system32\checksys.exe;
O2 - BHO: Eye Class - {41BE3A3D-6E4B-43F4-AAEB-5B4E95971968} - C:\WINDOWS\system32\xmqqguan.dll;
O2 - BHO: BhoObj Class - {9C7BC48C-6EE7-43C4-A931-91F8DE3CD0D0} - C:\WINDOWS\system32\qzuxdaps.dll;
O4 - 启动项HKLM\\Run: [C:\WINDOWS\SetupCmd029.exe] C:\WINDOWS\SetupCmd029.exe;
O4 - 启动项HKLM\\Run: [SoundMam] C:\WINDOWS\system32\SVOHOST.exe
O4 - 启动项HKLM\\Run: [System] C:\WINDOWS\TEMP\\setup.exe
O4 - 启动项HKLM\\Run: [AntiArpSniffer] E:\软件\ARP\AntiArpSniffer;
O4 - 启动项HKLM\\Run: [C:\WINDOWS\SetupCmd029.exe] C:\WINDOWS\SetupCmd029.exe
O4 - 启动项HKLM\\Run: [C:\WINDOWS\1023.exe] C:\WINDOWS\1023.exe
O4 - 启动项HKLM\\Run: [svhoost] C:\WINDOWS\system32\checksys.exe
O4 - HKCU\..\Run: [updatereal] C:\WINDOWS\realupdate.exe other
O4 - HKCU\..\Run: [msnnt] C:\WINDOWS\winampb.exe
O4 - HKCU\..\Run: [MyShares] c:\program Files\忆多多\MyShares.exe /tray
O4 - HKCU\..\Run: [Syss] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\setup;16 - DPF: {7A38130D-BEB7-4D60-BE7A-4C4AB6A85CD1} - http://bar.souhuu.com/vcbar1.cab
O16 - DPF: {9242BB35-0DB0-43AC-8DFC-8EA07E63B92A} - http://dl_dir.qq.com/qqtv/QQLiveOcxSetup.exe
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O23 - NT 服务: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
大多是,还有流氓,没看完,懒得看了。