HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms
+ rdpclip RDP Clip Monitor Microsoft Corporation C:\WINDOWS\system32\RDPCLIP.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
+ C:\WINDOWS\system32\userinit.exe Userinit Logon Application Microsoft Corporation C:\WINDOWS\SYSTEM32\USERINIT.EXE
+ rundll32.exe C:\WINDOWS\system32\winsys16_070118.dll start C:\WINDOWS\SYSTEM32\WINSYS16_070118.DLL
+ rundll32.exe C:\WINDOWS\system32\winsys16_070118.dll start C:\WINDOWS\SYSTEM32\WINSYS16_070118.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
+ Explorer.exe Windows Explorer Microsoft Corporation C:\WINDOWS\EXPLORER.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ IMJPMIG8.1 Microsoft IME Microsoft Corporation C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE
+ PHIME2002ASync 微軟新注音輸入法 2002a Microsoft Corporation C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE
+ PHIME2002A 微軟新注音輸入法 2002a Microsoft Corporation C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE
+ SoundMan Realtek Sound Manager Realtek Semiconductor Corp. C:\WINDOWS\SOUNDMAN.EXE
+ BigDogPath Vimicro Vimicro C:\WINDOWS\VM_STI.EXE
+ TkBellExe RealNetworks Scheduler RealNetworks, Inc. C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
+ ntaskldr C:\WINDOWS\SYSTEM\LOGO_1.EXE
+ IEXPLORER C:\WINDOWS\FEIFEI-2.EXE
+ RavMonHelp C:\WINDOWS\MOYU.EXE
+ cwq6 C:\WINDOWS\IEXPL0RE.EXE
+ runeip Rising AntiSpyware Monitor Beijing Rising Technology Co., Ltd. C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
+ KKDelay RunOnce Application Beijing Rising Technology Co., Ltd. C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNONCE.EXE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ ctfmon.exe CTF Loader Microsoft Corporation C:\WINDOWS\SYSTEM32\CTFMON.EXE
+ svc Windows Calculator application file Microsoft Corporation C:\DOCUME~1\1\LOCALS~1\TEMP\IE888.EXE
+ svcshare C:\WINDOWS\SYSTEM32\DRIVERS\SPPOOLSV.EXE
+ m C:\WINDOWS\WINLOG0N.EXE
+ SymhMy C:\WINDOWS\SYSTEM32\IEXPL0RE.EXE
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load
+ C:\WINDOWS\rundl132.exe C:\WINDOWS\RUNDL132.EXE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
+ ntaskldr C:\WINDOWS\SYSTEM\LOGO_1.EXE
C:\WINDOWS\WIN.INI
+ Load C:\WINDOWS\RUNDL132.EXE
C:\WINDOWS\SYSTEM.INI
+ shell Windows Explorer Microsoft Corporation C:\WINDOWS\EXPLORER.EXE
有人能告诉我这个是毒吗?