HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ assistseFile not found: C:\Program Files\3721\assistse.exe
+ CnsMin3721北京三七二一科技有限公司c:\winnt\downloaded program files\cnsmin.dll
+ EPSON Stylus C65 SeriesFile not found: ;
+ gemstrmwFile not found: ;
+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe
+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwmain.exe
+ SmappFile not found: ;
+ StormCodec_Helperc:\program files\ringz studio\storm codec\stormset.exe
+ Super Rabbit Desktop SetFile not found: ;
+ ThunderupdaterFile not found: ;
+ yassistseAssistSettingYahoo!c:\program files\yahoo!\assistant\yassistse.exe
+ YLive.exeYLive c:\program files\yahoo!\assistant\ylive.exe
C:\Documents and Settings\xiehai\「开始」菜单\程序\启动
+ 腾讯TM.lnkTM腾讯公司f:\program files\tencent\qq\tmshell.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
+ cnshook.dll3721 CNS Module北京三七二一科技有限公司c:\winnt\downloaded program files\cnshook.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt\system32\ravext.dll
+ ssaddr.dllTencentc:\program files\tencent\adplus\ssaddr.dll
+ ssaddr.dllTencentc:\program files\tencent\adplus\ssaddr.dll
+ ssaddr.dllTencentc:\program files\tencent\adplus\ssaddr.dll
+ WinRAR shell extensionf:\program files\winrar\rarext.dll
+ Yahoo!PhotoyPhtbYahoo! Chinac:\program files\yahoo!\assistant\assist\yphtb.dll
+ 粉碎文件Wiper 动态链接库c:\program files\yahoo!\assistant\assist\ywiper.dll
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ Web 文件夹c:\program files\common files\microsoft shared\web folders\msonsext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ CnsHook Class3721 CNS Module北京三七二一科技有限公司c:\winnt\downloaded program files\cnshook.dll
+ std softwarec:\winnt\system32\stdup.dll
+ Yahoo!PhotoyPhtbYahoo! Chinac:\program files\yahoo!\assistant\assist\yphtb.dll
+ 雅虎助手ToolBarYahoo!c:\program files\yahoo!\assistant\assist\yasbar.dll
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
+ coolbarToolBarYahoo!c:\program files\yahoo!\assistant\assist\yasbar.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ 雅虎助手ToolBarYahoo!c:\program files\yahoo!\assistant\assist\yasbar.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ Yahoo 1G电邮File not found: http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail
+ 清理上网记录File not found: http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean
+ 情景聊天File not found: http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg
+ 腾讯QQQQTENCENTf:\program files\tencent\qq\qq.exe
+ 修复浏览器File not found: http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair
+ 寻宝乐趣多File not found: http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao
+ 雅虎助手File not found: http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist
HKLM\System\CurrentControlSet\Services
+ BQQ_AdminBQQ_Adminc:\program files\bqqserver\bin\adminserver.exe
+ BQQ_DirectoryBQQ_Directoryc:\program files\bqqserver\bin\directory.exe
+ BQQ_EventBQQ_Eventc:\program files\bqqserver\bin\event.exe
+ BQQ_InformationBQQ_Information深圳腾讯科技有限公司c:\program files\bqqserver\bin\infoserver.exe
+ BQQ_MeetingBQQ_Meetingc:\program files\bqqserver\bin\meetsvr.exe
+ BQQ_ServerBQQ_Server深圳腾讯科技有限公司c:\program files\bqqserver\bin\bqqserver.exe
+ C-DillaCdaC11BAMacrovision RTS ServiceMacrovisionc:\winnt\system32\drivers\cdac11ba.exe
+ GrayPigeonServer灰鸽子服务端程序。远程监控管理.c:\winnt\g_server1.2.exe
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwsrv.exe
+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe
+ StdServicec:\winnt\system32\stdsver.dll
HKLM\System\CurrentControlSet\Services
+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\winnt\system32\drivers\basetdi.sys
+ C-DillaFile not found: C:\WINNT\System32\drivers\CDANT.SYS
+ CdaC15BAMacrovision SECURITY DriverMacrovision Europe Ltdc:\winnt\system32\drivers\cdac15ba.sys
+ CdsysFile not found: C:\WINNT\System32\cdcd.sys
+ dmioNT Disk Manager I/O DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmio.sys
+ dmloadNT Disk Manager Startup DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmload.sys
+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys
+ GKeyUSBUSB Key Smart Card Reader DriverGemplusc:\winnt\system32\drivers\gkeyusb.sys
+ hardlockHardlock Device Driver for Windows NTAladdin Knowledge Systemsc:\winnt\system32\drivers\hardlock.sys
+ HaspntHASP Kernel Device Driver for Windows NTAladdin Knowledge Systemsc:\winnt\system32\drivers\haspnt.sys
+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys
+ HookRegc:\program files\rising\rav\hookreg.sys
+ HookSysHooksysRisingc:\program files\rising\rav\hooksys.sys
+ kmsinputc:\winnt\system32\drivers\kmsinput.sys
+ MEMSCANMemScan Driver瑞星软件有限公司c:\program files\rising\rav\memscan.sys
+ mProcRsRising Personal FireWall mprocrs.sysBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\mprocrs.sys
+ New0c:\winnt\system32\new.sys
+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.f:\program files\tencent\qq\npkcrypt.sys
+ nv4NVIDIA Compatible Windows 2000 Miniport Driver, Version 12.60 NVIDIA Corporationc:\winnt\system32\drivers\nv4_mini.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\winnt\system32\drivers\ptilink.sys
+ ROCKEYNTRockey Device DriverFeiTian Tech Co.,Ltdc:\winnt\system32\drivers\rockeynt.sys
+ RsFwDrvnt_fwdrvBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rsfwdrv.sys
+ rtl8139Realtek RTL8139/810x Family NDIS 5.0 DrvRealtek Semiconductor Corporationc:\winnt\system32\drivers\r8139n5.sys
+ Sense3SENSE3 Driver for NTBeijing Senselockc:\winnt\system32\drivers\sense3.sys
+ smwdmSoundMAX Integrated Digital Audio Analog Devices, Inc.c:\winnt\system32\drivers\smwdm.sys
+ SVKPSVKP driver for NTAntiCrackingc:\winnt\system32\svkp.sys
+ WFsysWinFox Control I/O DriverLeadtek Research Inc.c:\winnt\system32\drivers\wfsys.sys
+ ZSMC301bVideo streaming and Capture Device DriverVMc:\winnt\system32\drivers\usbvm31b.sys
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
+ Bluebeam PDF Monitorc:\winnt\system32\bbpdfportmon.dll
+ EPSON V5 2KMonitorEPSON Bidirectional MonitorSEIKO EPSON CORPORATIONc:\winnt\system32\ebpmon2.dll
+ EPSON V6 2KMonitorEPSON Bi-directional MonitorSEIKO EPSON CORPORATIONc:\winnt\system32\ebpmon24.dll