HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ ALi5289ALiRAID Applicationc:\program files\uli5289\ali5289.exe
+ ATIPTAATI Desktop Control PanelATI Technologies, Inc.c:\program files\ati technologies\ati control panel\atiptaxx.exe
+ BigDogPathBIGDOGBIGDOGc:\windows\vm_sti.exe
+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.d:\program files\rising\rav\ravmon.exe
+ RavTimerRavTimerBeijing Rising Technology Co., Ltd.d:\program files\rising\rav\ravtimer.exe
+ SoundManRealtek Sound ManagerRealtek Semiconductor Corp.C:\WINDOWS\soundman.exe
+ SysExplrd:\program files\herosoft\hero 9\sysexplr.exe
+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
+ RavStubRising Rav StubBeijing Rising Technology Co., Ltd.d:\program files\rising\rav\ravstub.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\windows\system32\hticons.dll
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.d:\program files\real\realplayer\rpshell.dll
+ UnlockerShellExtensiond:\program files\unlocker\unlockercom.dll
+ WinRAR shell extensiond:\program files\winrar\rarext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ ThunderIEHelper Classxunleibho BHOc:\windows\system32\xunleibho_v8.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ 豪杰超级解霸9Hero Super Player 9Herosoftd:\program files\herosoft\hero 9\sthsdvd.exe
HKLM\System\CurrentControlSet\Services
+ Ati HotKey Pollerc:\windows\system32\ati2evxx.exe
+ ATI SmartATI Smartc:\windows\system32\ati2sgag.exe
+ DriveHealthHard disk S.M.A.R.T. monitoring and failure predicting service.Helexis Software Developmentd:\program files\helexis\drive health\dhcore.exe
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Corporation Limitedd:\program files\rising\rfw\rfwsrv.exe
+ RsCCenterCCenterrisingd:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.d:\program files\rising\rav\ravmond.exe
+ SSMSSM 可实时追踪系统活动以阻止有害软件的恼人操作。System Safetyd:\program files\system safety monitor\ssmservice.exe
HKLM\System\CurrentControlSet\Services
+ ALCXWDMRealtek AC'97 Audio Driver (WDM)Realtek Semiconductor Corp.c:\windows\system32\drivers\alcxwdm.sys
+ AliIdeALi mini IDE DriverAcer Laboratories Inc.c:\windows\system32\drivers\aliide.sys
+ ati2mtagATI Radeon Miniport DriverATI Technologies Inc.c:\windows\system32\drivers\ati2mtag.sys
+ BaseTDIbasetdiRisingc:\windows\system32\drivers\basetdi.sys
+ d347busPnP BIOS Extension c:\windows\system32\drivers\d347bus.sys
+ d347prtSCSI miniport c:\windows\system32\drivers\d347prt.sys
+ ExpScanerExpScan.sysd:\program files\rising\rav\expscan.sys
+ HookContTDI HOOK DriverRising tech Co. ltdd:\program files\rising\rav\hookcont.sys
+ HookRegd:\program files\rising\rav\hookreg.sys
+ HookSys瑞星d:\program files\rising\rav\hooksys.sys
+ ip100xpIC Plus Corp. c:\windows\system32\drivers\ipfnd51.sys
+ m5289ULi SATA RAID Controller DriverULi Electronics Inc.c:\windows\system32\drivers\m5289.sys
+ mcnahook.sysNative API Filter driver for System Safety MonitorSystem Safetyd:\program files\system safety monitor\mcnahook.sys
+ NPFNPF Driver - TME extensionsPolitecnico di Torinoc:\windows\system32\drivers\npf.sys
+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.d:\program files\tencent\qq\npkcrypt.sys
+ oreans32c:\windows\system32\drivers\oreans32.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys
+ RsFwDrvnt_fwdrvRisingd:\program files\rising\rfw\rsfwdrv.sys
+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys
+ uliagpkxULi AGPv3.0 Filter for K8/9 Processor PlatformsULi Electronics Inc.c:\windows\system32\drivers\agpkx.sys
+ ZSMC301bVideo streaming and Capture Device DriverVMc:\windows\system32\drivers\usbvm31b.sys
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
+ AtiExtEventc:\windows\system32\ati2evxx.dll
+ System Safety MonitorSystem Safety Winlogon NotificationSystem Safetyc:\windows\system32\ssmwinlogonex.dll