********** 日志开始 **********
[键]HKEY_CLASSES_ROOT\CLSID\{0002DF01-0000-0000-C000-000000000046}\LOCALSERVER32
[值]@
[类型]REG_SZ
[内容]"c:\program files\internet explorer\iexplore.exe"
[键]HKEY_CLASSES_ROOT\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\DEFAULTICON
[值]@
[类型]REG_SZ
[内容]c:\program files\internet explorer\iexplore.exe,-17
[键]HKEY_CLASSES_ROOT\CLSID\{3050F3D9-98B5-11CF-BB82-00AA00BDCE0B}\DEFAULTICON
[值]@
[类型]REG_SZ
[内容]c:\program files\internet explorer\iexplore.exe,-17
[键]HKEY_CLASSES_ROOT\CLSID\{42042206-2D85-11D3-8CFF-005004838597}\OLD ICON\HTMLFILE\DEFAULTICON
[值]@
[类型]REG_SZ
[内容]%programfiles%\internet explorer\iexplore.exe,-17
[键]HKEY_CLASSES_ROOT\CLSID\{42042206-2D85-11D3-8CFF-005004838597}\OLD ICON\MHTMLFILE\DEFAULTICON
[值]@
[类型]REG_SZ
[内容]%programfiles%\internet explorer\iexplore.exe,-32554
[键]HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\NOADDONS\COMMAND
[值]@
[类型]REG_EXPAND_SZ
[内容]"%programfiles%\internet explorer\iexplore.exe" -extoff
[键]HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE
[值]COMMAND
[类型]REG_SZ
[内容]%programfiles%\internet explorer\iexplore.exe
[键]HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND
[值]@
[类型]REG_EXPAND_SZ
[内容]%programfiles%\internet explorer\iexplore.exe
[键]HKEY_CLASSES_ROOT\CLSID\{AE24FDAE-03C6-11D1-8B76-0080C744F389}\TOOLBOXBITMAP32
[值]@
[类型]REG_SZ
[内容]c:\program files\internet explorer\iexplore.exe,-17
[键]HKEY_CLASSES_ROOT\CLSID\{D5E8041D-920F-45E9-B8FB-B1DEB82C6E5E}\LOCALSERVER32
[值]@
[类型]REG_EXPAND_SZ
[内容]"%programfiles%\internet explorer\iexplore.exe" -startmediumtab
[键]HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{0002DF01-0000-0000-C000-000000000046}\LOCALSERVER32
[值]@
[类型]REG_SZ
[内容]"c:\program files\internet explorer\iexplore.exe"
[键]HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\DEFAULTICON
[值]@
[类型]REG_SZ
[内容]c:\program files\internet explorer\iexplore.exe,-17
[键]HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{3050F3D9-98B5-11CF-BB82-00AA00BDCE0B}\DEFAULTICON
[值]@
[类型]REG_SZ
[内容]c:\program files\internet explorer\iexplore.exe,-17
[键]HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{42042206-2D85-11D3-8CFF-005004838597}\OLD ICON\HTMLFILE\DEFAULTICON
[值]@
[类型]REG_SZ
[内容]%programfiles%\internet explorer\iexplore.exe,-17
[键]HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{42042206-2D85-11D3-8CFF-005004838597}\OLD ICON\MHTMLFILE\DEFAULTICON
[值]@
[类型]REG_SZ
[内容]%programfiles%\internet explorer\iexplore.exe,-32554
[键]HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\NOADDONS\COMMAND
[值]@
[类型]REG_EXPAND_SZ
[内容]"%programfiles%\internet explorer\iexplore.exe" -extoff
[键]HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE
[值]COMMAND
[类型]REG_SZ
[内容]%programfiles%\internet explorer\iexplore.exe
[键]HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELL\OPENHOMEPAGE\COMMAND
[值]@
[类型]REG_EXPAND_SZ
[内容]%programfiles%\internet explorer\iexplore.exe
[键]HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{AE24FDAE-03C6-11D1-8B76-0080C744F389}\TOOLBOXBITMAP32
[值]@
[类型]REG_SZ
[内容]c:\program files\internet explorer\iexplore.exe,-17
[键]HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{D5E8041D-920F-45E9-B8FB-B1DEB82C6E5E}\LOCALSERVER32
[值]@
[类型]REG_EXPAND_SZ
[内容]"%programfiles%\internet explorer\iexplore.exe" -startmediumtab
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\DESKTOP\NAMESPACE\{1F4DE370-D627-11D1-BA4F-00A0C91EEDBA}
[值]@
[类型]REG_SZ
[内容]computer search results folder
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\DESKTOP\NAMESPACE\{450D8FBA-AD25-11D0-98A8-0800361B1103}
[值]@
[类型]REG_SZ
[内容]空
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\DESKTOP\NAMESPACE\{450D8FBA-AD25-11D0-98A8-0800361B1103}
[值]REMOVAL MESSAGE
[类型]REG_SZ
[内容]@mydocs.dll,-900
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\DESKTOP\NAMESPACE\{645FF040-5081-101B-9F08-00AA002F954E}
[值]@
[类型]REG_SZ
[内容]recycle bin
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\DESKTOP\NAMESPACE\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}
[值]@
[类型]REG_SZ
[内容]dxp
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\DESKTOP\NAMESPACE\{E17D4FC0-5564-11D1-83F2-00A0C90DC849}
[值]@
[类型]REG_SZ
[内容]search results folder
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\DESKTOP\NAMESPACE\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}
[值]REMOVAL MESSAGE
[类型]REG_SZ
[内容]@gameux.dll,-10038
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\CLASSICSTARTMENU
[值]{871C5380-42A0-1069-A2EA-08002B30309D}.DEFAULT
[类型]REG_SZ
[内容]0
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\CLASSICSTARTMENU
[值]{9343812E-1C37-4A49-A12E-4B2D810D956B}
[类型]REG_DWORD
[内容]0x00000001
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\CLASSICSTARTMENU
[值]{871C5380-42A0-1069-A2EA-08002B30309D}
[类型]REG_DWORD
[内容]0x00000000
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\NEWSTARTPANEL
[值]{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}
[类型]REG_DWORD
[内容]0x00000001
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\NEWSTARTPANEL
[值]{20D04FE0-3AEA-1069-A2D8-08002B30309D}
[类型]REG_DWORD
[内容]0x00000001
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\NEWSTARTPANEL
[值]{208D2C60-3AEA-1069-A2D7-08002B30309D}
[类型]REG_DWORD
[内容]0x00000001
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\NEWSTARTPANEL
[值]{871C5380-42A0-1069-A2EA-08002B30309D}
[类型]REG_DWORD
[内容]0x00000000
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\NEWSTARTPANEL
[值]{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}
[类型]REG_DWORD
[内容]0x00000001
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\NEWSTARTPANEL
[值]{59031A47-3F72-44A7-89C5-5595FE6B30EE}
[类型]REG_DWORD
[内容]0x00000001
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\NEWSTARTPANEL
[值]{031E4825-7B94-4DC3-B131-E946B44C8DD5}
[类型]REG_DWORD
[内容]0x00000001
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\NEWSTARTPANEL
[值]{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}
[类型]REG_DWORD
[内容]0x00000001
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\NEWSTARTPANEL
[值]{9343812E-1C37-4A49-A12E-4B2D810D956B}
[类型]REG_DWORD
[内容]0x00000001
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\NEWSTARTPANEL
[值]{450D8FBA-AD25-11D0-98A8-0800361B1103}
[类型]REG_DWORD
[内容]0x00000001
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\CLASSICSTARTMENU
[值]{20D04FE0-3AEA-1069-A2D8-08002B30309D}
[类型]REG_DWORD
[内容]0x00000001
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\CLASSICSTARTMENU
[值]{871C5380-42A0-1069-A2EA-08002B30309D}.DEFAULT
[类型]REG_DWORD
[内容]0x00000000
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\CLASSICSTARTMENU
[值]{871C5380-42A0-1069-A2EA-08002B30309D}
[类型]REG_DWORD
[内容]0x00000000
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\NEWSTARTPANEL
[值]{20D04FE0-3AEA-1069-A2D8-08002B30309D}
[类型]REG_DWORD
[内容]0x00000000
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\NEWSTARTPANEL
[值]{871C5380-42A0-1069-A2EA-08002B30309D}
[类型]REG_DWORD
[内容]0x00000000
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\NEWSTARTPANEL
[值]{450D8FBA-AD25-11D0-98A8-0800361B1103}
[类型]REG_DWORD
[内容]0x00000000
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\HIDEDESKTOPICONS\NEWSTARTPANEL
[值]{208D2C60-3AEA-1069-A2D7-08002B30309D}
[类型]REG_DWORD
[内容]0x00000000
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM
[值]NODISPCPL
[类型]REG_DWORD
[内容]0x00000000
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM
[值]NODISPBACKGROUNDPAGE
[类型]REG_DWORD
[内容]0x00000000
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM
[值]NODISPSCRSAVPAGE
[类型]REG_DWORD
[内容]0x00000000
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM
[值]NODISPAPPEARANCEPAGE
[类型]REG_DWORD
[内容]0x00000000
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM
[值]NODISPSETTINGSPAGE
[类型]REG_DWORD
[内容]0x00000000
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM
[值]DISABLETASKMGR
[类型]REG_DWORD
[内容]0x00000000
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM
[值]DISABLEREGISTRYTOOLS
[类型]REG_DWORD
[内容]0x00000000
[键]HKEY_CLASSES_ROOT\HTTP\SHELL\OPEN\COMMAND
[值]@
[类型]REG_EXPAND_SZ
[内容]"c:\program files\internet explorer\iexplore.exe" -nohome
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN
[值]START PAGE
[类型]REG_SZ
[内容]about:blank
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN
[值]DEFAULT_PAGE_URL
[类型]REG_SZ
[内容]about:blank
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN
[值]SEARCH PAGE
[类型]REG_SZ
[内容]http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN
[值]DEFAULT_PAGE_URL
[类型]REG_SZ
[内容]about:blank
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN
[值]SEARCH PAGE
[类型]REG_SZ
[内容]http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN
[值]START PAGE
[类型]REG_SZ
[内容]about:blank
[键]HKEY_LOCAL_MACHINE\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND
[值]@
[类型]REG_SZ
[内容]c:\program files\internet explorer\iexplore.exe
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{01443AEC-0FD1-40FD-9C87-E93D1494C233}
[值]@
[类型]REG_SZ
[内容]thunder atonce
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}
[值]@
[类型]REG_SZ
[内容]scriptproxy
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DEFAULTICON
[值]@
[类型]REG_EXPAND_SZ
[内容]%systemroot%\system32\imageres.dll,-54
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DEFAULTICON
[值]FULL
[类型]REG_EXPAND_SZ
[内容]%systemroot%\system32\imageres.dll,-54
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DEFAULTICON
[值]EMPTY
[类型]REG_EXPAND_SZ
[内容]%systemroot%\system32\imageres.dll,-55
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH
[值]CUSTOMIZESEARCH
[类型]REG_SZ
[内容]http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchcust.htm
[键]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH
[值]SEARCHASSISTANT
[类型]REG_SZ
[内容]http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchasst.htm
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED
[值]HIDDEN
[类型]REG_DWORD
[内容]0x00000002
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED
[值]HIDEFILEEXT
[类型]REG_DWORD
[内容]0x00000030
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED
[值]SUPERHIDDEN
[类型]REG_DWORD
[内容]0x00000001
[键]HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED
[值]SHOWSUPERHIDDEN
[类型]REG_DWORD
[内容]0x00000001
[键]HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\KINGSOFT ANTIVIRUS WEBSHIELD SERVICE
[值]TYPE
[类型]REG_DWORD
[内容]0x00000110
[键]HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\KINGSOFT ANTIVIRUS WEBSHIELD SERVICE
[值]START
[类型]REG_DWORD
[内容]0x00000002
[键]HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\KINGSOFT ANTIVIRUS WEBSHIELD SERVICE
[值]ERRORCONTROL
[类型]REG_DWORD
[内容]0x00000001
[键]HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\KINGSOFT ANTIVIRUS WEBSHIELD SERVICE
[值]IMAGEPATH
[类型]REG_EXPAND_SZ
[内容]c:\programdata\microsoft\microsoft.exe
[键]HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\KINGSOFT ANTIVIRUS WEBSHIELD SERVICE
[值]DISPLAYNAME
[类型]REG_SZ
[内容]kingsoft antivirus webshield service
[键]HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\KINGSOFT ANTIVIRUS WEBSHIELD SERVICE
[值]GROUP
[类型]REG_SZ
[内容]schedulergroup
[键]HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\KINGSOFT ANTIVIRUS WEBSHIELD SERVICE
[值]OBJECTNAME
[类型]REG_SZ
[内容]localsystem
[键]HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\KINGSOFT ANTIVIRUS WEBSHIELD SERVICE
[值]DESCRIPTION
[类型]REG_SZ
[内容]kingsoft antivirus webshield service