启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation]
<Skype><"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized> [(Verified)N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<Apoint><C:\Program Files\Apoint\Apoint.exe> [(Verified)Alps Electric Co., Ltd.]
<SunJavaUpdateSched><C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe> [N/A]
<IntelWireless><C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless> [N/A]
<ATIPTA><C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe> [ATI Technologies, Inc.]
<Dell QuickSet><C:\Program Files\Dell\QuickSet\quickset.exe> [Dell Inc]
<DVDLauncher><"C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"> [CyberLink Corp.]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<KillTrojanMaster><C:\木马专杀大师\木马专杀大师.exe> [N/A]
<UpdateManager><"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r> [Sonic Solutions]
<BigDog305><C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)> [N/A]
<New.net Startup><rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s> [N/A]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [(Verified)RealNetworks, Inc.]
<QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.]
<iTunesHelper><"C:\Program Files\iTunes\iTunesHelper.exe"> [(Verified)Apple Computer, Inc.]
<runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe> [Beijing Rising Technology Co., Ltd.]
<WebThunder><C:\Program Files\Thunder Network\WebThunder\WebThunder.exe> [深圳市迅雷网络技术有限公司]
<winboot><wscript.exe /E:vbs C:\WINDOWS\boot.ini> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><> [N/A]
<{F584A094-D920-4010-9EE3-940A4396A4F8}><C:\WINDOWS\system32\Hheiqz.dll> [N/A]
<{3C62C6CB-6D88-460B-AB6A-F8372BDA515F}><C:\WINDOWS\system32\Gnyhg.dll> [N/A]
<{19C2B337-A55F-49AC-9D64-558C91850C03}><C:\WINDOWS\system32\Oefnfa.dll> [N/A]
<{395AECB8-C9F2-4E89-85D9-B0282548EA2F}><C:\WINDOWS\system32\Gyngi.dll> [N/A]
<{331B49D8-8FDD-486D-909D-71423C9B7935}><C:\WINDOWS\system32\Enpmlj.dll> [N/A]
<{E772756B-1C95-4427-B8BE-5A464FBAB241}><C:\WINDOWS\system32\Sivjc.dll> [N/A]
<{25C5AD02-DA3C-4464-B704-E107F22990A2}><C:\WINDOWS\system32\Dxfmx.dll> [N/A]
<{C871091E-1FF2-408E-A85B-B935B23E4748}><C:\WINDOWS\system32\Yxni.dll> [N/A]
<{60748CD7-1076-46DC-84C9-7976F4721E89}><C:\WINDOWS\system32\Kkcwc.dll> [N/A]
<{343BE343-BD8F-4BFF-9914-546DB443E111}><C:\WINDOWS\system32\Mvpp.dll> [N/A]
<{BF0BF363-CF72-402F-95E4-762A433E1E39}><C:\WINDOWS\system32\Araita.dll> [N/A]
<{A6685A0F-143D-4019-A638-DCE165B845AF}><C:\WINDOWS\system32\Oabshi.dll> [N/A]
<{054058EF-6E7A-4D0B-8C17-560883BF6846}><C:\WINDOWS\system32\Qpko.dll> [N/A]
<{B5626087-DFB4-43A5-873D-59F204946663}><C:\WINDOWS\system32\Xceaje.dll> [N/A]
<{77045EE4-BC55-4755-8AC5-ADFB3238DFCF}><C:\WINDOWS\system32\Qipcs.dll> [N/A]
<{E0139903-139E-4FCC-9A96-747397B0D896}><C:\WINDOWS\system32\Qmzwf.dll> [N/A]
<{DAD633F7-E1B4-433D-8733-D9CA4200E8B4}><C:\WINDOWS\system32\Xnpev.dll> [N/A]
<{49DB541D-A9B1-49EA-AEFC-D3D77707AEED}><C:\WINDOWS\system32\Ktqcef.dll> [N/A]
<{2E802E9F-DEA5-4477-8153-27F15BD2C933}><C:\WINDOWS\system32\Nmso.dll> [N/A]
<{B9E4D1CA-6CAF-4E2A-9F79-60A1F2EE1951}><C:\WINDOWS\system32\Ltcv.dll> [N/A]
<{83C77F8D-B379-4793-837F-C71EFAE8ADD0}><C:\WINDOWS\system32\Xlabuh.dll> [N/A]
<{72B7250F-4FB3-4791-863F-E594198F0921}><C:\WINDOWS\system32\Mkavo.dll> [N/A]
<{A6CD8965-EF1B-4C6D-9064-2546986DD5F5}><C:\WINDOWS\system32\Iyup.dll> [N/A]
<{0A9BDF42-4C06-4183-BAC9-D86F0967C9BF}><C:\WINDOWS\system32\Qdspuo.dll> [N/A]
<{0693FAEC-616C-48DF-8755-17ACB64C89F6}><C:\WINDOWS\system32\Mxklr.dll> [N/A]
<{83F0734B-649F-4C70-9D24-70481DE76C81}><C:\WINDOWS\system32\Mcplxm.dll> [N/A]
<{B9A3F6F0-7B1B-4FB8-B743-81FD968D0C63}><C:\WINDOWS\system32\Alff.dll> [N/A]
<{63518800-8987-4ADD-962E-926E71212846}><C:\WINDOWS\system32\Okvpjb.dll> [N/A]
<{7F16BFB7-A28A-4DFB-A6A1-59B038396840}><C:\WINDOWS\system32\Kfrkrx.dll> [N/A]
<{B7C0D325-0D91-438C-809B-E085C507F1A3}><C:\WINDOWS\system32\Iuxkez.dll> [N/A]
<{ED5CC319-3AA8-42A5-BDEF-3B434F8EDD69}><C:\WINDOWS\system32\Rywxjv.dll> [N/A]
<{EE994066-0BEA-4E25-A0C7-55DACC6DC943}><C:\WINDOWS\system32\Ekxm.dll> [N/A]
<{6212930C-0848-4509-9C9D-5C8847904591}><C:\WINDOWS\system32\Uzhqrm.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad]
<WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\IntelWireless]
<WinlogonNotify: IntelWireless><C:\Program Files\Intel\Wireless\Bin\LgNotify.dll> [Intel Corporation]
==================================
启动文件夹
[Adobe Reader Speed Launch]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk --> C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [Adobe Systems Incorporated]><N>
[Microsoft Office]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk --> C:\PROGRA~1\MICROS~2\Office10\OSA.EXE [Microsoft Corporation]><N>
[Cyber-shot Viewer 媒体检查工具]
<C:\Documents and Settings\liang\「开始」菜单\程序\启动\Cyber-shot Viewer 媒体检查工具.lnk --> C:\PROGRA~1\Sony\SONYPI~1\VOLUME~1\SPUVOL~1.EXE [Sony Corporation]><N>
[QQ游戏启动加速程序]
<C:\Documents and Settings\liang\「开始」菜单\程序\启动\QQ游戏启动加速程序.lnk --> C:\PROGRA~1\Tencent\QQGame\Accel.exe [深圳市腾讯计算机系统有限公司]><N>
==================================