HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ ATIModeChangeATI 2D Mode componentATI Technologies, Inc.c:\windows\system32\ati2mdxx.exe
+ ccenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe
+ CdnCtrLiveUpdate Modulec:\program files\cnnic\cdn\cdnup.exe
+ MSPY2002c:\windows\system32\ime\pintlgnt\imscinst.exe
+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe
+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe
+ TP4EXIBM TrackPoint Accessibility FeaturesIBM Corporationc:\windows\system32\tp4ex.exe
+ TPHOTKEYc:\program files\thinkpad\pkgmgr\hotkey\tphkmgr.exe
+ TrackPointSrvIBM PS/2 TrackPoint DaemonIBM Corporationc:\windows\system32\tp4serv.exe
C:\Documents and Settings\use\「开始」菜单\程序\启动
+ 腾讯QQ.lnkQQTENCENTc:\program files\tencent\qq\qq.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
+ cnshook.dll3721 CNS Module北京三七二一科技有限公司c:\windows\downloaded program files\cnshook.dll
+ CnsMin.dllFile not found: C:\WINDOWS\DOWNLO~1\CnsMin.dll
+ Rising Execute File Exts hookRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realone player\rpshell.dll
+ Yahoo!PhotoFile not found: C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll
+ 粉碎文件File not found: C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ywiper.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ CNNIC_IDNCndnIEHelper Modulec:\program files\cnnic\cdn\cdniehlp.dll
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
+ cnshook.dll3721 CNS Module北京三七二一科技有限公司c:\windows\downloaded program files\cnshook.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ 浩方对战平台浩方对战平台上海浩方在线信息技术有限公司c:\program files\浩方对战平台\gameclient.exe
+ 清理上网记录File not found: http://assistant.3721.com/clean1.htm?fb=Cns
+ 情景聊天File not found: http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/
+ 上网助手File not found: http://assistant.3721.com/index.htm?fb=Cns
+ 手机短信File not found: http://sms.3721.com/ie/index.htm?pid=209
+ 腾讯QQQQTENCENTc:\program files\tencent\qq\qq.exe
+ 修复浏览器File not found: http://assistant.3721.com/security1.htm?fb=Cns
+ 寻宝乐趣多File not found: http://hot.3721.com/rd/shop_btn.htm
Task Scheduler
+ BMMTask.jobc:\program files\thinkpad\utilities\bmmtask.exe
HKLM\System\CurrentControlSet\Services
+ Ati HotKey Pollerc:\windows\system32\ati2evxx.exe
+ IBMPMSVCc:\windows\system32\ibmpmsvc.exe
+ QCONSVCc:\windows\system32\qconsvc.exe
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwsrv.exe
+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe
+ W32Times为计算机网络提供同步的时间计划服务(NMCT),此服务被终止或禁用,多数基于 Windows 的软件将无法正常运行.c:\windows\system32\timeman32.exe
+ WintimeFile not found: C:\WINDOWS\System32\SVCH0ST.EXE
HKLM\System\CurrentControlSet\Services
+ AgereSoftModemSoftModem Device DriverAgere Systemsc:\windows\system32\drivers\agrsm.sys
+ ati2mtagATI RAGE 6 Miniport DriverATI Technologies Inc.c:\windows\system32\drivers\ati2mtag.sys
+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\windows\system32\drivers\basetdi.sys
+ cdnprotcdnprotCNNICc:\windows\system32\drivers\cdnprot.sys
+ cdntrancdnhookCNNICc:\windows\system32\drivers\cdntran.sys
+ DSMBATTDriver for battery informationc:\windows\system32\drivers\dsmbatt.sys
+ E100BNDIS 5 driverIntel Corporationc:\windows\system32\drivers\e100b325.sys
+ EGATHDRVc:\windows\system32\egathdrv.sys
+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys
+ GT680xFile not found: System32\DRIVERS\GT680x.SYS
+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys
+ HookRegc:\program files\rising\rav\hookreg.sys
+ HookSysHooksysRisingc:\program files\rising\rav\hooksys.sys
+ IBMPMDRVIBM ThinkPad Power Management DriverIBM Corp.c:\windows\system32\drivers\ibmpmdrv.sys
+ IBMTPCHKc:\windows\system32\drivers\ibmbldid.sys
+ k750busSony Ericsson 750 DriverMCCIc:\windows\system32\drivers\k750bus.sys
+ k750mdflSony Ericsson 750 USB WMC Modem FilterMCCIc:\windows\system32\drivers\k750mdfl.sys
+ k750mdmSony Ericsson 750 USB WMC Modem DriversMCCIc:\windows\system32\drivers\k750mdm.sys
+ k750mgmtSony Ericsson 750 USB WMC Device Management DriversMCCIc:\windows\system32\drivers\k750mgmt.sys
+ k750obexSony Ericsson 750 USB WMC OBEX Interface DriversMCCIc:\windows\system32\drivers\k750obex.sys
+ kmsinputc:\windows\system32\drivers\kmsinput.sys
+ MEMSCANMemScan Driver瑞星软件有限公司c:\program files\rising\rav\memscan.sys
+ mProcRsRising Personal FireWall mprocrs.sysBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\mprocrs.sys
+ NETMDUSBNet MD USB DriverSony Corporationc:\windows\system32\drivers\netmdusb.sys
+ New0c:\windows\system32\new.sys
+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.c:\program files\tencent\qq\npkcrypt.sys
+ NPPTNTnProtect NPSC Kernel Mode Driver for NTINCA Internet Co., Ltd.c:\windows\system32\npptnt.sys
+ NSCIRDANSC Fast Infrared Driver.National Semiconductor Corporationc:\windows\system32\drivers\nscirda.sys
+ PCDRDRVFile not found: system32\drivers\PCDRDRV.sys
+ PcdrNtPC-Doctor NT Support DriverPC-Doctor Inc.c:\windows\system32\drivers\pcdrnt.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys
+ RsFwDrvnt_fwdrvBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rsfwdrv.sys
+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys
+ Ser2plUSB-to-Serial Cable DriverProlific Technology Inc.c:\windows\system32\drivers\ser2pl.sys
+ smwdmSoundMAX Integrated Digital Audio Analog Devices, Inc.c:\windows\system32\drivers\smwdm.sys
+ SNPHV71PC Camera driverc:\windows\system32\drivers\snphv71.sys
+ SONYPVU1Sony USB Lower Filter driverSony Corporationc:\windows\system32\drivers\sonypvu1.sys
+ TDSMAPIc:\windows\system32\drivers\tdsmapi.sys
+ Tp4TrackIBM PS/2 TrackPoint Mouse Filter DriverIBM Corporationc:\windows\system32\drivers\tp4track.sys
+ TPPWRIBM ThinkPad Power Management Device DriverIBM Corp.c:\windows\system32\drivers\tppwr.sys
+ TSMAPIPc:\windows\system32\drivers\tsmapip.sys