启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINXP\System32\CTFMON.EXE> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><rem C:\WINXP\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002ASync><C:\WINXP\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><C:\WINXP\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<CTStartup><rem C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run> []
<TkBellExe><rem "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> []
<NVMixerTray><rem "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"> []
<ff><rem kjh.exe> []
<helper.dll><C:\WINXP\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32> []
<YLive.exe><rem C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe> [ ]
<yassistse><rem "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"> [Yahoo!]
<DAEMON Tools-1033><"C:\Program Files\D-Tools\daemon.exe" -lang 1033> [DAEMON'S HOME]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<StormCodec_Helper><rem "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> []
<NvCplDaemon><rem RUNDLL32.EXE C:\WINXP\System32\NvCpl.dll,NvStartup> [NVIDIA Corporation]
<nwiz><rem nwiz.exe /install> []
<NvMediaCenter><rem RUNDLL32.EXE C:\WINXP\System32\NvMcTray.dll,NvTaskbarInit> [NVIDIA Corporation]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<ff><kjh.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE> [Microsoft Corporation]
<Userinit><C:\WINXP\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{B48F6409-4740-475B-A474-651F54CCE460}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\MsInfo.Dll> []
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINXP\downlo~1\CnsHook.dll> [北京三七二一科技有限公司]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINXP\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad]
<SysTime><C:\PROGRA~1\WinKld\WinKld.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\reset5]
<WinlogonNotify: reset5><reset5.dll> []
==================================
启动文件夹
服务
[InstallDriver Table Manager / IDriverT]
<C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe><Macrovision Corporation>
[IMAPI CD-Burning COM Service / ImapiService]
<C:\WINXP\System32\imapi.exe><Microsoft Corporation>
[JMediaService / JMediaService]
<C:\WINXP\System32\rundll32.exe C:\PROGRA~1\MMSASS~1\MMSSVER.DLL,Service><N/A>
[NVIDIA Display Driver Service / NVSvc]
<C:\WINXP\System32\nvsvc32.exe><NVIDIA Corporation>
[Reset 5 / Reset 5]
<C:\WINXP\system32\srvany.exe><N/A>
[Rising Proxy Service / RfwProxySrv]
<c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
<C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[StdService / StdService]
<C:\WINXP\System32\rundll32.exe C:\WINXP\System32\STDSVER.DLL,Service><N/A>
[Windows svchost / Windows svchost]
<C:\Program Files\Common Files\Microsoft Shared\MSINFO\svchost.exe><N/A>