+ Explorer
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
text/xml
[A ] 28. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
mso-offdap
[A ] 29. c:\program files\common files\microsoft shared\web components\10\owc10.dll
mso-offdap11
[A ] 30. c:\program files\common files\microsoft shared\web components\11\owc11.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 31. c:\windows\system32\hticons.dll
Portable Media Devices
[A ] 32. c:\windows\system32\audiodev.dll
Portable Media Devices Menu
[A ] 32. c:\windows\system32\audiodev.dll
NvCpl DesktopContext Class
[A ] 33. c:\windows\system32\nvcpl.dll
Play on my TV helper
[A ] 33. c:\windows\system32\nvcpl.dll
Desktop Explorer
[A ] 34. c:\windows\system32\nvshell.dll
Desktop Explorer Menu
[A ] 34. c:\windows\system32\nvshell.dll
nView Desktop Context Menu
[A ] 34. c:\windows\system32\nvshell.dll
Microsoft Office HTML Icon Handler
[AM] 35. c:\program files\microsoft office\office11\msohev.dll
Web Folders
[A ] 36. c:\program files\common files\microsoft shared\web folders\msonsext.dll
WinRAR shell extension
[AM] 37. c:\program files\winrar\rarext.dll
RISING
[AM] 38. c:\windows\system32\ravext.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{32CD708B-60A7-4C00-9377-D73EAA495F0F}
[AM] 38. c:\windows\system32\ravext.dll
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 39. c:\windows\system32\shlhook.dll
+ Logon
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
RTHDCPL
[AM] 40. c:\windows\rthdcpl.exe
SkyTel
[A ] 41. c:\windows\skytel.exe
Alcmtr
[A ] 42. c:\windows\alcmtr.exe
nwiz
[A ] 43. c:\windows\system32\nwiz.exe
IMSCMig
[A ] 44. c:\program files\common files\microsoft shared\ime\imsc40a\imscmig.exe
RavTask
[A ] 45. c:\program files\rising\rav\ravtask.exe
RfwMain
[AM] 46. c:\program files\rising\rfw\rfwmain.exe
runeip
[AM] 47. c:\program files\rising\antispyware\runiep.exe
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay
[A ] 48. c:\program files\rising\antispyware\runonce.exe