[WOW]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SYSTEM\CurrentControlSet\Control\WOW
1_Name=cmdline
1_Value=%SystemRoot%\system32\ntvdm.exe -o
1_Filename=C:\WINDOWS\SYSTEM32\NTVDM.EXE
1_FileSize=417280
1_FileDate=2004-8-17 12:00:00
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SYSTEM\CurrentControlSet\Control\WOW
2_Name=wowcmdline
2_Value=%SystemRoot%\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386
2_Filename=C:\WINDOWS\SYSTEM32\NTVDM.EXE
2_FileSize=417280
2_FileDate=2004-8-17 12:00:00
Max=2
[ShellExecuteHooks]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
1_Name={AEB6717E-7E19-11d0-97EE-00C04FD91972}
1_ClsidName=URL 执行挂钩
1_FileName=C:\WINDOWS\system32\shell32.dll
1_FileSize=8311296
1_FileDate=2006-7-13 21:34:56
Max=1
[ShellService
ObjectDelayLoad]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
1_Name=PostBootReminder
1_Value={7849596a-48ea-486e-8937-a2a3009f31a9}
1_ClsidName=PostBootReminder 对象
1_FileName=%SystemRoot%\system32\SHELL32.dll
1_FileSize=8311296
1_FileDate=2006-7-13 21:34:56
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
2_Name=CDBurn
2_Value={fbeb8a05-beee-4442-804e-409d6c4515e9}
2_ClsidName=烧 CD 的 ShellFolder
2_FileName=%SystemRoot%\system32\SHELL32.dll
2_FileSize=8311296
2_FileDate=2006-7-13 21:34:56
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
3_Name=WebCheck
3_Value={E6FB5E20-DE35-11CF-9C87-00AA005127ED}
3_ClsidName=WebCheck
3_FileName=%SystemRoot%\system32\webcheck.dll
3_FileSize=265728
3_FileDate=2004-8-17 12:00:00
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
4_Name=SysTray
4_Value={35CEC8A3-2BE6-11D2-8773-92E220524153}
4_ClsidName=SysTray
4_FileName=C:\WINDOWS\system32\st
object.dll
4_FileSize=121344
4_FileDate=2004-8-17 12:00:00
Max=4
[SharedTaskScheduler]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
1_Name={438755C2-A8BA-11D1-B96B-00A0C90312E1}
1_Value=Browseui 预加载程序
1_FileName=%SystemRoot%\system32\browseui.dll
1_FileSize=1022464
1_FileDate=2006-9-14 16:38:30
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
2_Name={8C7461EF-2B13-11d2-BE35-3078302C2030}
2_Value=组件类别缓存程序
2_FileName=%SystemRoot%\system32\browseui.dll
2_FileSize=1022464
2_FileDate=2006-9-14 16:38:30
Max=2
[ProtocolDefaults]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
1_Name=http
1_Value=3
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
2_Name=https
2_Value=3
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
3_Name=ftp
3_Value=3
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
4_Name=file
4_Value=3
5_HKey=HKEY_LOCAL_MACHINE
5_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
5_Name=@ivt
5_Value=1
6_HKey=HKEY_LOCAL_MACHINE
6_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
6_Name=shell
6_Value=0
Max=6
[BootExecute]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SYSTEM\CurrentControlSet\Control\Session Manager
1_Name=BootExecute
1_Value=autocheck autochk *
Max=1
[Startup]
1_LnkFile=C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\ADSL.lnk
1_ExeFile=ADSL
Max=1
[AutoRun]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=Software\Microsoft\Windows\CurrentVersion\Run
1_Name=NvCplDaemon
1_Value=; rundll32.exe c:\windows\system32\nvcpl.dll,nvstartup
1_FileSize=5537792
1_FileDate=2005-2-24 7:32:00
1_FileVersion=6.14.10.7184
2_HKey=HKEY_LOCAL_MACHINE
2_Key=Software\Microsoft\Windows\CurrentVersion\Run
2_Name=TkBellExe
2_Value="c:\program files\common files\real\update_ob\realsched.exe" -osboot
2_FileSize=185896
2_FileDate=2006-11-23 16:05:36
2_FileVersion=0.1.0.3760
3_HKey=HKEY_LOCAL_MACHINE
3_Key=Software\Microsoft\Windows\CurrentVersion\Run
3_Name=RavTask
3_Value="c:\program files\rising\rav\ravtask.exe" -system
3_FileSize=114688
3_FileDate=2006-11-23 16:40:48
3_FileVersion=18.0.0.22
4_HKey=HKEY_LOCAL_MACHINE
4_Key=Software\Microsoft\Windows\CurrentVersion\Run
4_Name=RfwMain
4_Value="d:\rising\rfw\rfwmain.exe" -startup
4_FileSize=454656
4_FileDate=2006-11-27 14:38:06
4_FileVersion=5.0.0.56
5_HKey=HKEY_LOCAL_MACHINE
5_Key=Software\Microsoft\Windows\CurrentVersion\RunOnce
5_Name=RavStub
5_Value="c:\program files\rising\rav\ravstub.exe" /runonce
5_FileSize=90112
5_FileDate=2006-11-23 16:26:46
5_FileVersion=18.0.0.16
6_HKey=HKEY_LOCAL_MACHINE
6_Key=Software\Microsoft\Windows\CurrentVersion\RunOnce
6_Name=KKDelay
6_Value=d:\kaka\runonce.exe
6_FileSize=61440
6_FileDate=2006-11-23 17:03:42
6_FileVersion=19.0.0.2
7_HKey=HKEY_LOCAL_MACHINE
7_Key=Software\Microsoft\Windows\CurrentVersion\RunOnce
7_Name=Super Rabbit SRCK
7_Value="d:\超级兔子\magicset\srck.exe" /autokill:245
7_FileSize=1789952
7_FileDate=2006-11-23 22:14:14
7_FileVersion=7.90.0.1
8_HKey=HKEY_LOCAL_MACHINE
8_Key=Software\Microsoft\Windows NT\CurrentVersion\Windows
8_Name=load
8_Value=
9_HKey=HKEY_CURRENT_USER
9_Key=Software\Microsoft\Windows\CurrentVersion\Run
9_Name=ctfmon.exe
9_Value=c:\windows\system32\ctfmon.exe
9_FileSize=15360
9_FileDate=2004-8-17 12:00:00
9_FileVersion=5.1.2600.2180
10_HKey=HKEY_CURRENT_USER
10_Key=Software\Microsoft\Windows NT\CurrentVersion\Windows
10_Name=load
10_Value=
Max=10
[ModuleUsage]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/3DShowVM.ocx
1_Name=.Owner
1_Value={C661F36D-DF85-4EF4-83C7-E107B83D04B1}
1_Clsid=WebActivater Control
1_FileName=C:\WINDOWS\system32\3DShowVM.ocx
1_FileSize=319488
1_FileDate=2006-3-13 14:00:38
1_FileVersion=1.0.200.50
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/mfc42.dll
2_Name=.Owner
2_Value=Unknown Owner
2_Clsid=
2_FileName=C:\WINDOWS\system32\mfc42.dll
2_FileSize=1028096
2_FileDate=2004-8-17 12:00:00
2_FileVersion=6.2.4131.0
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/msvcrt.dll
3_Name=.Owner
3_Value=Unknown Owner
3_Clsid=
3_FileName=C:\WINDOWS\system32\msvcrt.dll
3_FileSize=343040
3_FileDate=2004-8-17 12:00:00
3_FileVersion=7.0.2600.2180
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/olepro32.dll
4_Name=.Owner
4_Value=Unknown Owner
4_Clsid=
4_FileName=C:\WINDOWS\system32\olepro32.dll
4_FileSize=83456
4_FileDate=2004-8-17 12:00:00
4_FileVersion=5.1.2600.2180
5_HKey=HKEY_LOCAL_MACHINE
5_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/wuweb.dll
5_Name=.Owner
5_Value=Unknown Owner
5_Clsid=
5_FileName=C:\WINDOWS\system32\wuweb.dll
5_FileSize=173536
5_FileDate=2005-5-26 4:19:32
5_FileVersion=5.8.0.2469
Max=5
[Process]
1_FileName=C:\WINDOWS\SYSTEM32\SMSS.EXE
1_FileSize=50688
1_FileDate=2004-8-17 12:00:00
1_FileVersion=5.1.2600.2180
2_FileName=C:\WINDOWS\SYSTEM32\WINLOGON.EXE
2_FileSize=487424
2_FileDate=2004-8-17 12:00:00
2_FileVersion=5.1.2600.2180
3_FileName=C:\WINDOWS\SYSTEM32\SERVICES.EXE
3_FileSize=108032
3_FileDate=2004-8-17 12:00:00
3_FileVersion=5.1.2600.2180
4_FileName=C:\WINDOWS\SYSTEM32\LSASS.EXE
4_FileSize=13312
4_FileDate=2004-8-17 12:00:00
4_FileVersion=5.1.2600.2180
5_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
5_FileSize=14336
5_FileDate=2004-8-17 12:00:00
5_FileVersion=5.1.2600.2180
6_FileName=C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
6_FileSize=110592
6_FileDate=2006-11-23 16:40:46
6_FileVersion=18.0.0.3
7_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
7_FileSize=14336
7_FileDate=2004-8-17 12:00:00
7_FileVersion=5.1.2600.2180
8_FileName=C:\PROGRAM FILES\RISING\RAV\RAVMOND.EXE
8_FileSize=266240
8_FileDate=2006-11-23 16:26:54
8_FileVersion=18.0.1.47
9_FileName=C:\WINDOWS\EXPLORER.EXE
9_FileSize=976896
9_FileDate=2004-8-17 12:00:00
9_FileVersion=6.0.2900.2180
10_FileName=C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
10_FileSize=57856
10_FileDate=2005-6-11 7:53:32
10_FileVersion=5.1.2600.2696
11_FileName=C:\PROGRAM FILES\RISING\RAV\RAVSTUB.EXE
11_FileSize=90112
11_FileDate=2006-11-23 16:26:46
11_FileVersion=18.0.0.16
12_FileName=C:\WINDOWS\SYSTEM32\NVSVC32.EXE
12_FileSize=127043
12_FileDate=2005-2-24 7:32:00
12_FileVersion=6.14.10.7184
13_FileName=C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
13_FileSize=185896
13_FileDate=2006-11-23 16:05:36
13_FileVersion=0.1.0.3760
14_FileName=C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE
14_FileSize=114688
14_FileDate=2006-11-23 16:40:48
14_FileVersion=18.0.0.22
15_FileName=C:\PROGRAM FILES\RISING\RAV\RAVMON.EXE
15_FileSize=614400
15_FileDate=2006-11-23 16:26:50
15_FileVersion=18.0.1.39
16_FileName=C:\WINDOWS\SYSTEM32\CTFMON.EXE
16_FileSize=15360
16_FileDate=2004-8-17 12:00:00
16_FileVersion=5.1.2600.2180
17_FileName=D:\QQ\TIMPLATFORM.EXE
17_FileSize=69632
17_FileDate=2006-8-31 20:09:00
17_FileVersion=0.3.1.8
18_FileName=D:\QQ\QQ.EXE
18_FileSize=1454080
18_FileDate=2006-9-7 12:21:06
18_FileVersion=0.0.0.0
19_FileName=D:\RISING\RFW\RFWSRV.EXE
19_FileSize=151552
19_FileDate=2006-11-27 14:38:28
19_FileVersion=5.0.0.30
20_FileName=D:\RISING\RFW\RFWMAIN.EXE
20_FileSize=454656
20_FileDate=2006-11-27 14:38:06
20_FileVersion=5.0.0.56
21_FileName=C:\PROGRAM FILES\MAXTHON\MAXTHON.EXE
21_FileSize=899584
21_FileDate=2006-10-24 23:13:00
21_FileVersion=1.5.8.120
22_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
22_FileSize=14336
22_FileDate=2004-8-17 12:00:00
22_FileVersion=5.1.2600.2180
23_FileName=C:\WINDOWS\SYSTEM32\CONIME.EXE
23_FileSize=27648
23_FileDate=2004-8-17 12:00:00
23_FileVersion=5.1.2600.2180
24_FileName=D:\超级兔子\MAGICSET\SRIEH.EXE
24_FileSize=1368064
24_FileDate=2006-11-23 22:13:58
24_FileVersion=7.90.0.1
25_FileName=[SYSTEM PROCESS]
26_FileName=C:\WINDOWS\system32\CSRSS.EXE
26_FileSize=6144
26_FileDate=2004-8-17 12:00:00
26_FileVersion=5.1.2600.2180
27_FileName=C:\WINDOWS\system32\WDFMGR.EXE
27_FileSize=38912
27_FileDate=2004-8-10 22:05:14
27_FileVersion=5.2.3790.1230
28_FileName=C:\WINDOWS\system32\ALG.EXE
28_FileSize=44544
28_FileDate=2004-8-17 12:00:00
28_FileVersion=5.1.2600.2180
Max=28