+ 网络和拨号连接Network Connections ShellMicrosoft Corporationc:\winnt\system32\netshell.dll
+ 微缩图图像Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 文件夹快捷方式Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ 我的电脑Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ 下载状态Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 已装好的卷Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ 用户(&P)...Find PeopleMicrosoft Corporationc:\program files\outlook express\wabfind.dll
+ 用户帮助Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 预订文件夹Web Site MonitorMicrosoft Corporationc:\winnt\system32\webcheck.dll
+ 摘要信息缩略图处理程序(DOCFILES)Thumbnail View ExtensionMicrosoft Corporationc:\winnt\system32\thumbvw.dll
+ 注册数目路选项实用程序Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 自定义 MRU 自动完成列表Shell Browser UI LibraryMicrosoft Corporationc:\winnt\system32\browseui.dll
+ 字体Windows Font FolderMicrosoft Corporationc:\winnt\system32\fontext.dll
+ 浏览器栏Shell Doc
Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
HKLM\Software\Classes\Folder\Shellex\ColumnHandlers
+ Fax Tiff Data Column ProviderFax Tiff Data Column ProviderMicrosoft Corporationc:\winnt\system32\faxshell.dll
+ ShAVColumnProvider classDocProp2Microsoft Corporationc:\winnt\system32\docprop2.dll
+ Version Column ProviderDocProp2Microsoft Corporationc:\winnt\system32\docprop2.dll
+ {0D2E74C4-3C34-11d2-A27E-00C04FC30871}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ {24F14F01-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ {24F14F02-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ BandIE ClassBaiduBar ModuleBaidu.com, Inc.c:\program files\baidu\bar\baidubar.dll
+ CdnForIE ClassCdnForIECNNICc:\program files\cnnic\cdn\cdnforie.dll
+ QQBrowserHelper
Object ClassQQIEHelper Module深圳市腾讯计算机系统有限公司c:\program files\tencent\qq\qqiehelper.dll
+ Thunder Browser HelperXunLeiBHOThunder Networking Technologies,LTDc:\program files\thunder network\thunder\comdlls\xunleibho_002.dll
+ WMHlprObj ClassCNNIC Web Mail for WindowsCNNICc:\program files\cnnic\cdn\wmhlpr.dll
+ {81D1B74C-9531-4D2B-9F49-A236F4930609}showbar Modulec:\program files\common files\yygamenet\showbar.dll
+ 上网助手CoolBar3721c:\program files\3721\assist\asbar.dll
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
+ coolbarCoolBar3721c:\program files\3721\assist\asbar.dll
+ shdocvw.dllShell Doc
Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ BitComet工具栏BitComet Toolbar for IEc:\program files\bitcomet\bitcometbar\bitcometbar0.6.dll
+ ietoolforleft.dllIELeftToolBar Modulec:\program files\common files\yygamenet\ietoolforleft.dll
+ 上网助手CoolBar3721c:\program files\3721\assist\asbar.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ @shdoclc.dll,-864c:\winnt\web\related.htm
+ Yahoo! Messengerc:\program files\yahoo!\messenger\ypager.exe
+ 腾讯QQQQTENCENTc:\program files\tencent\qq\qq.exe
Task Scheduler
+ DM_Install_Program.jobdmremotesetup1000 Oaksc:\documents and settings\administrator\local settings\temp\102084.exe
HKLM\System\CurrentControlSet\Services
+ Browser维护网络上计算机的最新列表以及提供这个列表给请求的程序。Microsoft Corporationc:\winnt\system32\services.exe
+ Dhcp通过注册和更改 IP 地址以及 DNS 名称来管理网络配置。Microsoft Corporationc:\winnt\system32\services.exe
+ dmserver逻辑磁盘管理器监视狗服务Microsoft Corporationc:\winnt\system32\services.exe
+ Dnscache解析和缓冲域名系统 (DNS) 名称。Microsoft Corporationc:\winnt\system32\services.exe
+ Eventlog记录程序和 Windows 发送的事件消息。事件日志包含对诊断问题有所帮助的信息。您可以在“事件查看器”中查看报告。Microsoft Corporationc:\winnt\system32\services.exe
+ lanmanserver提供 RPC 支持、文件、打印以及命名管道共享。Microsoft Corporationc:\winnt\system32\services.exe
+ lanmanworkstation提供网络链结和通讯。Microsoft Corporationc:\winnt\system32\services.exe
+ LmHosts允许对“TCP/IP 上 NetBIOS (NetBT)”服务以及 NetBIOS 名称解析的支持。Microsoft Corporationc:\winnt\system32\services.exe
+ NtmsSvc管理可移动媒体、驱动程序和库。Microsoft Corporationc:\winnt\system32\svchost.exe
+ PlugPlay管理设备安装以及配置,并且通知程序关于设备更改的情况。Microsoft Corporationc:\winnt\system32\services.exe
+ PolicyAgent管理 IP 安全策略以及启动 ISAKMP/Oakley (IKE) 和 IP 安全驱动程序。Microsoft Corporationc:\winnt\system32\lsass.exe
+ ProtectedStorage提供对敏感数据(如私钥)的保护性存储,以便防止未授权的服务,过程或用户对其的非法访问。Microsoft Corporationc:\winnt\system32\services.exe
+ RemoteRegistry允许远程注册表操作。Microsoft Corporationc:\winnt\system32\regsvc.exe
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwsrv.exe
+ RpcSs提供终结点映射程序 (endpoint mapper) 以及其它 RPC 服务。Microsoft Corporationc:\winnt\system32\svchost.exe
+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe
+ SamSs存储本地用户帐户的安全信息。Microsoft Corporationc:\winnt\system32\lsass.exe
+ Schedule允许程序在指定时间运行。Microsoft Corporationc:\winnt\system32\mstask.exe
+ seclogon在不同凭据下启用启动过程Microsoft Corporationc:\winnt\system32\services.exe
+ SENS跟踪系统事件,如登录 Windows,网络以及电源事件等。将这些事件通知给 COM+ 事件系统 “订阅者(subscriber)”。Microsoft Corporationc:\winnt\system32\svchost.exe
+ Spooler将文件加载到内存中以便迟后打印。Microsoft Corporationc:\winnt\system32\spoolsv.exe
+ svchost从 Windows Update 启用重要的 Windows 更新的下载和安装。如果禁用该服务,操作系统将无法升级c:\winnt\svchost.exe
+ TrkWks当文件在网络域的 NTFS 卷中移动时发送通知。Microsoft Corporationc:\winnt\system32\services.exe
+ WinMgmt提供系统管理信息。Microsoft Corporationc:\winnt\system32\wbem\winmgmt.exe
+ wuauserv从 Windows Update 启用重要的 Windows 更新的下载和安装。如果禁用该服务,操作系统可以在 Windows Update 网站手动更新。Microsoft Corporationc:\winnt\system32\svchost.exe
HKLM\System\CurrentControlSet\Services
+ ACPIACPI Driver for NTMicrosoft Corporationc:\winnt\system32\drivers\acpi.sys
+ AFDAncillary Function Driver for WinSockMicrosoft Corporationc:\winnt\system32\drivers\afd.sys
+ ALCXWDMAvance AC'97 Audio Driver (WDM)Avance Logic, Inc.c:\winnt\system32\drivers\alcxwdm.sys
+ AsyncMacRAS Asynchronous Media DriverMicrosoft Corporationc:\winnt\system32\drivers\asyncmac.sys
+ atapiIDE/ATAPI Port DriverMicrosoft Corporationc:\winnt\system32\drivers\atapi.sys
+ AtmarpcATM ARP Client ProtocolMicrosoft Corporationc:\winnt\system32\drivers\atmarpc.sys
+ audstubAudStub DriverMicrosoft Corporationc:\winnt\system32\drivers\audstub.sys
+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\winnt\system32\drivers\basetdi.sys
+ ccdecodeWDM Closed Caption VBI CodecMicrosoft Corporationc:\winnt\system32\drivers\ccdecode.sys
+ cdnprot中国互联网络信息中心(CNNIC)c:\winnt\system32\drivers\cdnprot.sys
+ cdntrancdntranCNNICc:\winnt\system32\drivers\cdntran.sys
+ CdromSCSI CD-ROM DriverMicrosoft Corporationc:\winnt\system32\drivers\cdrom.sys
+ DiskPnP Disk DriverMicrosoft Corporationc:\winnt\system32\drivers\disk.sys
+ dmioNT Disk Manager I/O DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmio.sys
+ dmloadNT Disk Manager Startup DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmload.sys
+ DMusicMicrosoft DirectMusic Software Synthesizer (WDM)Microsoft Corporationc:\winnt\system32\drivers\dmusic.sys
+ eehgefee中国互联网络信息中心(CNNIC)c:\winnt\system32\drivers\eehgefee.sys
+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys
+ FdcFloppy Disk Controller DriverMicrosoft Corporationc:\winnt\system32\drivers\fdc.sys
+ FsVgaFull Screen Video DriverMicrosoft Corporationc:\winnt\system32\drivers\fsvga.sys
+ FtdiskFT Disk DriverMicrosoft Corporationc:\winnt\system32\drivers\ftdisk.sys
+ gameenumGame Port EnumeratorMicrosoft Corporationc:\winnt\system32\drivers\gameenum.sys
+ GpcGeneric Packet ClassifierMicrosoft Corporationc:\winnt\system32\drivers\msgpc.sys
+ hacfbjbc中国互联网络信息中心(CNNIC)c:\winnt\system32\drivers\hacfbjbc.sys
+ HidUsbUSB Miniport Driver for Input DevicesMicrosoft Corporationc:\winnt\system32\drivers\hidusb.sys
+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys
+ HookRegc:\program files\rising\rav\hookreg.sys
+ HookSysHooksysRisingc:\program files\rising\rav\hooksys.sys
+ HookUrlHookUrlBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\hookurl.sys
+ i8042prti8042 Port DriverMicrosoft Corporationc:\winnt\system32\drivers\i8042prt.sys
+ i81xMiniport Driver for Intel Graphics DriverIntel(R) Corporationc:\winnt\system32\drivers\i81xnt5.sys
+ IntelIdeIntel PCI IDE DriverMicrosoft Corporationc:\winnt\system32\drivers\intelide.sys
+ IpFilterDriverIP Traffic Filter DriverMicrosoft Corporationc:\winnt\system32\drivers\ipfltdrv.sys
+ IpInIpIP in IP Tunnel DriverMicrosoft Corporationc:\winnt\system32\drivers\ipinip.sys
+ IpNatIP Network Address TranslatorMicrosoft Corporationc:\winnt\system32\drivers\ipnat.sys
+ IPSECIPSEC driverMicrosoft Corporationc:\winnt\system32\drivers\ipsec.sys
+ IRENUMInfra-Red Bus EnumeratorMicrosoft Corporationc:\winnt\system32\drivers\irenum.sys
+ isapnpPNP ISA Bus DriverMicrosoft Corporationc:\winnt\system32\drivers\isapnp.sys
+ KbdclassKeyboard Class DriverMicrosoft Corporationc:\winnt\system32\drivers\kbdclass.sys
+ kmixerKernel Mode Audio MixerMicrosoft Corporationc:\winnt\system32\drivers\kmixer.sys
+ kmsinputc:\winnt\system32\drivers\kmsinput.sys