日志
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<BitComet><; "e:\Program Files\BitComet\BitComet.exe">
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<HTpatch><C:\WINDOWS\htpatch.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SiSUSBRG><C:\WINDOWS\SiSUSBrg.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<nwiz><nwiz.exe /install>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Microsoft Update Machine><Winreg32.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ats><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<eEVGV1Ew><C:\PROGRA~1\wwrvsxww\aEwDH8BM.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Cmaudio><RunDll32 cmicnfg.cpl,CMICtrlWnd>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<TkBellExe><C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<MSPY2002><C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMEKRMIG6.1><C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SKYNET Personal FireWall><E:\PROGRA~1\SKYNET\FIREWALL\pfw.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<BootSkin Startup Jobs><; "E:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<bwFGTo1x><; C:\PROGRA~1\wwrvsxww\aEwDH8BM.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<cFosSpeed><; E:\Program Files\cfosspeed\cFosSpeed.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<cgVGVcUw><; C:\PROGRA~1\wwrvsxww\aEwDH8BM.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<DAEMON Tools-2052><; "E:\Program Files\D-Tools\daemon.exe" -lang 2052>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<helper.dll><; C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NeroCheck><; C:\WINDOWS\System32\\NeroCheck.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<QgpHYsUw><; C:\PROGRA~1\wwrvsxww\aEwDH8BM.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RQ0HQ9Ux><; C:\PROGRA~1\wwrvsxww\aEwDH8BM.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<VirtualDrive><; E:\Program Files\FarStone\VirtualDrive\vdtask.exe /AutoRestore /Silence>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<winnet><; C:\PROGRA~1\COMMON~2\ADDRES~1\winnet.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<Microsoft Update Machine><Winreg32.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
==================================
启动文件夹
服务
[cFosSpeed System Service / cFosSpeedS]
<"E:\Program Files\cfosspeed\spd.exe" -service><cFos Software GmbH>
[CPUCooLServer Service / CPUCooLServer]
<"E:\Program Files\CPUCooL\CooLSrv.exe"><N/A>
[kavsvc / kavsvc]
<e:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe><Kaspersky Lab>
[NVIDIA Display Driver Service / NVSvc]
<C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[PC-cillin PersonalFirewall / PCCPFW]
<E:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe><N/A>
[Trend NT Realtime Service / Tmntsrv]
<"E:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe"><N/A>
==================================
浏览器加载项
[BabeIE]
{00000000-0000-0000-0000-000000000000} <C:\Program Files\CommonName\AddressBar\CNBabe.dll, N/A>
[MyWay Search Assistant BHO]
{04079851-5845-4dea-848C-3ECD647AA554} <C:\Program Files\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL, N/A>
[myBar BHO]
{0494D0D1-F8E0-41ad-92A3-14154ECE70AC} <C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL, N/A>
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <E:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[]
{724d43a9-0d85-11d4-9908-00400523e39a} <C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll, Siber Systems>
[IeCatch2 Class]
{A5366673-E8CA-11D3-9CD9-0090271D075B} <E:\PROGRA~1\FLASHGET\jccatch.dll, Amaze Soft>
[填写表单]
{320AF880-6646-11D3-ABEE-C5DBF3571F46} <, N/A>
[保存]
{320AF880-6646-11D3-ABEE-C5DBF3571F49} <, N/A>
[RoboForm]
{724d43aa-0d85-11d4-9908-00400523e39a} <, N/A>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\MSMSGS.EXE, Microsoft Corporation>
[&RoboForm]
{724d43a0-0d85-11d4-9908-00400523e39a} <C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll, Siber Systems>
[&SearchBar]
{0494D0D9-F8E0-41ad-92A3-14154ECE70AC} <C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL, N/A>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[BitCometBar]
{3F1ABCDB-A875-46c1-8345-B72A4567E486} <e:\Program Files\BitComet\BitCometBar\BitCometBar0.2.dll, N/A>
[PowerPlr Control]
{2354A44B-3CEB-4829-9940-545B03103538} <C:\WINDOWS\DOWNLO~1\PowerPlr.ocx, Powerise Digital>
[WebActivater Control]
{3D8F74EE-8692-4F8F-B8D2-7522E732519E} <C:\WINDOWS\DOWNLO~1\WEBACT~1.OCX, QQ>
[AxInputControl Class]
{73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL, >
[Shockwave Flash
Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\macromed\flash\Flash.ocx, Macromedia, Inc.>
[PowerDld Control]
{DF6FE46D-1D23-4668-AD3A-CDEA1262B282} <C:\WINDOWS\DOWNLO~1\PowerDld.ocx, Powerise Digital>
[!搜一搜(&S)]
<res://C:\Program Files\yisou\yisou.dll/232, N/A>
[保存表单(&[)]
<
file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html, N/A>
[填写表单(&])]
<
file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html, N/A>
[自定义菜单 &M]
<
file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html, N/A>