15_HKey=HKEY_LOCAL_MACHINE
15_Key=SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015
15_Name=PackedCatalogItem
15_FileName=C:\WINDOWS\system32\quartz32.dll
15_Value=洀睳潳正搮汬琀椀漀渀渀愀洀攀攀瘀攀渀琀 ???匀??瘀攀渀琀?漀漀琀?爀爀漀爀 ???匀??甀渀挀琀椀漀渀一愀洀攀?瘀攀渀琀? ? asffunctionnameevent1 ??ASFEventFanProblem 潃??f 釽?????篲?? MSTCP Provider ??矜???矚 ??粓 ? ??粓 錿??洀錅??退??? ???勌 ?汷?? 员 ?尀錍|??粓??粓咀呠古 员?瀀??粓?怀??粒??鈐? ??? ?ā
Max=15
[WinSock2Winsock]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=System\CurrentControlSet\Services\Winsock2\Winsock
1_Name=PathName
1_Value=
1_Found=0
Max=1
[WOW]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SYSTEM\CurrentControlSet\Control\WOW
1_Name=cmdline
1_Value=%SystemRoot%\system32\ntvdm.exe -o
1_Filename=C:\WINDOWS\SYSTEM32\NTVDM.EXE
1_FileSize=417280
1_FileDate=2004-8-17 12:00:00
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SYSTEM\CurrentControlSet\Control\WOW
2_Name=wowcmdline
2_Value=%SystemRoot%\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386
2_Filename=C:\WINDOWS\SYSTEM32\NTVDM.EXE
2_FileSize=417280
2_FileDate=2004-8-17 12:00:00
Max=2
[ShellExecuteHooks]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
1_Name={AEB6717E-7E19-11d0-97EE-00C04FD91972}
1_ClsidName=URL 执行挂钩
1_FileName=C:\WINDOWS\system32\shell32.dll
1_FileSize=8311296
1_FileDate=2006-7-13 21:34:56
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
2_Name={D157330A-9EF3-49F8-9A67-4141AC41ADD4}
2_ClsidName=CnsHook Class
2_FileName=C:\WINDOWS\DOWNLO~1\CnsHook.dll
2_FileSize=73728
2_FileDate=2005-10-26 13:10:48
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
3_Name={32CD708B-60A7-4C00-9377-D73EAA495F0F}
3_ClsidName=ShlExecHack Class
3_FileName=C:\WINDOWS\system32\RavExt.dll
3_FileSize=98304
3_FileDate=2006-8-7 13:23:36
Max=3
[ShellService
ObjectDelayLoad]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
1_Name=PostBootReminder
1_Value={7849596a-48ea-486e-8937-a2a3009f31a9}
1_ClsidName=PostBootReminder 对象
1_FileName=%SystemRoot%\system32\SHELL32.dll
1_FileSize=8311296
1_FileDate=2006-7-13 21:34:56
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
2_Name=CDBurn
2_Value={fbeb8a05-beee-4442-804e-409d6c4515e9}
2_ClsidName=烧 CD 的 ShellFolder
2_FileName=%SystemRoot%\system32\SHELL32.dll
2_FileSize=8311296
2_FileDate=2006-7-13 21:34:56
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
3_Name=WebCheck
3_Value={E6FB5E20-DE35-11CF-9C87-00AA005127ED}
3_ClsidName=WebCheck
3_FileName=%SystemRoot%\system32\webcheck.dll
3_FileSize=265728
3_FileDate=2004-8-17 12:00:00
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
4_Name=SysTray
4_Value={35CEC8A3-2BE6-11D2-8773-92E220524153}
4_ClsidName=SysTray
4_FileName=C:\WINDOWS\system32\st
object.dll
4_FileSize=121344
4_FileDate=2004-8-17 12:00:00
5_HKey=HKEY_LOCAL_MACHINE
5_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
5_Name=SysTime
5_Value={724C75F1-B757-408D-A50A-4CF99DA35D73}
5_ClsidName=88Dog.Kalendar
5_FileName=C:\PROGRA~1\WinKld\WinKld.dll
6_HKey=HKEY_LOCAL_MACHINE
6_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
6_Name=DelayRun
6_Value={5A6F2F95-3191-433B-8533-EB0B596A7BAC}
6_ClsidName=LoadRun Class
6_FileName=C:\WINDOWS\system\9a8d0f70.dll
7_HKey=HKEY_LOCAL_MACHINE
7_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
7_Name=webwork
7_Value={4C611512-2C1D-44b2-A044-872AD2AD5A61}
7_ClsidName=Windows Webwork Theme
7_FileName=C:\WINDOWS\webwork\webwork.dll
7_FileSize=94208
7_FileDate=2006-8-11 9:44:48
8_HKey=HKEY_LOCAL_MACHINE
8_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
8_Name=themeadp
8_Value={64274C93-3CE7-4663-9C8D-CD2DC8A3590B}
8_ClsidName=Windows Push Theme
8_FileName=C:\WINDOWS\system32\themeadp.dll
8_FileSize=45056
8_FileDate=2006-8-16 23:48:54
Max=8
[SharedTaskScheduler]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
1_Name={438755C2-A8BA-11D1-B96B-00A0C90312E1}
1_Value=Browseui 预加载程序
1_FileName=%SystemRoot%\system32\browseui.dll
1_FileSize=1022464
1_FileDate=2006-6-23 19:11:20
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
2_Name={8C7461EF-2B13-11d2-BE35-3078302C2030}
2_Value=组件类别缓存程序
2_FileName=%SystemRoot%\system32\browseui.dll
2_FileSize=1022464
2_FileDate=2006-6-23 19:11:20
Max=2
[ProtocolDefaults]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
1_Name=http
1_Value=3
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
2_Name=https
2_Value=3
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
3_Name=ftp
3_Value=3
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
4_Name=file
4_Value=3
5_HKey=HKEY_LOCAL_MACHINE
5_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
5_Name=@ivt
5_Value=1
6_HKey=HKEY_LOCAL_MACHINE
6_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
6_Name=shell
6_Value=0
Max=6
[BootExecute]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SYSTEM\CurrentControlSet\Control\Session Manager
1_Name=BootExecute
1_Value=autocheck autochk /k:C /k:D /k:E /k:F /k:G /k:H /k:I *
Max=1
[AutoRun]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=Software\Microsoft\Windows\CurrentVersion\Run
1_Name=CnsMin
1_Value=rundll32.exe c:\windows\downlo~1\cnsmin.dll,rundll32
1_FileSize=274432
1_FileDate=2006-8-10 10:27:18
1_FileVersion=1.5.3.6
2_HKey=HKEY_LOCAL_MACHINE
2_Key=Software\Microsoft\Windows\CurrentVersion\Run
2_Name=SoundMan
2_Value=soundman.exe
2_FileSize=577536
2_FileDate=2006-1-11 15:08:36
2_FileVersion=5.1.0.51
3_HKey=HKEY_LOCAL_MACHINE
3_Key=Software\Microsoft\Windows\CurrentVersion\Run
3_Name=NvCplDaemon
3_Value=rundll32.exe c:\windows\system32\nvcpl.dll,nvstartup
3_FileSize=7561216
3_FileDate=2006-3-9 15:29:00
3_FileVersion=6.14.10.8421
4_HKey=HKEY_LOCAL_MACHINE
4_Key=Software\Microsoft\Windows\CurrentVersion\Run
4_Name=nwiz
4_Value=nwiz.exe /install
4_FileSize=1519616
4_FileDate=2006-3-9 15:29:00
4_FileVersion=6.14.10.11026
5_HKey=HKEY_LOCAL_MACHINE
5_Key=Software\Microsoft\Windows\CurrentVersion\Run
5_Name=NvMediaCenter
5_Value=rundll32.exe c:\windows\system32\nvmctray.dll,nvtaskbarinit
5_FileSize=86016
5_FileDate=2006-3-9 15:29:00
5_FileVersion=6.14.10.8421
6_HKey=HKEY_LOCAL_MACHINE
6_Key=Software\Microsoft\Windows\CurrentVersion\Run
6_Name=FixCamera
6_Value=c:\windows\fixcamera.exe
6_FileSize=20480
6_FileDate=2005-12-6 13:08:42
6_FileVersion=1.0.0.3
7_HKey=HKEY_LOCAL_MACHINE
7_Key=Software\Microsoft\Windows\CurrentVersion\Run
7_Name=tsnp2std
7_Value=c:\windows\tsnp2std.exe
7_FileSize=106496
7_FileDate=2005-11-24 17:01:06
7_FileVersion=1.1.2.4
8_HKey=HKEY_LOCAL_MACHINE
8_Key=Software\Microsoft\Windows\CurrentVersion\Run
8_Name=snp2std
8_Value=c:\windows\vsnp2std.exe
8_FileSize=344064
8_FileDate=2005-11-23 22:00:20
8_FileVersion=1.0.3.5
9_HKey=HKEY_LOCAL_MACHINE
9_Key=Software\Microsoft\Windows\CurrentVersion\Run
9_Name=poco
9_Value=g:\poco\poco2006.exe
9_FileVersion=
10_HKey=HKEY_LOCAL_MACHINE
10_Key=Software\Microsoft\Windows\CurrentVersion\Run
10_Name=TuoTu
10_Value=g:\tuotu\tuotu.exe /m
10_FileVersion=
11_HKey=HKEY_LOCAL_MACHINE
11_Key=Software\Microsoft\Windows\CurrentVersion\Run
11_Name=YLive.exe
11_Value=c:\progra~1\yahoo!\assist~1\ylive.exe
11_FileSize=57344
11_FileDate=2006-9-1 14:48:36
11_FileVersion=3.0.5.1011
12_HKey=HKEY_LOCAL_MACHINE
12_Key=Software\Microsoft\Windows\CurrentVersion\Run
12_Name=yassistse
12_Value="c:\progra~1\yahoo!\assistant\yassistse.exe"
12_FileSize=73728
12_FileDate=2006-8-4 11:49:04
12_FileVersion=3.0.0.1001
13_HKey=HKEY_LOCAL_MACHINE
13_Key=Software\Microsoft\Windows\CurrentVersion\Run
13_Name=RavTask
13_Value="d:\瑞星杀毒\rising\rav\ravtask.exe" -system
13_FileSize=114688
13_FileDate=2005-12-14 17:28:37
13_FileVersion=18.0.0.22
14_HKey=HKEY_LOCAL_MACHINE
14_Key=Software\Microsoft\Windows NT\CurrentVersion\Windows
14_Name=load
14_Value=
15_HKey=HKEY_CURRENT_USER
15_Key=Software\Microsoft\Windows\CurrentVersion\Run
15_Name=ctfmon.exe
15_Value=c:\windows\system32\ctfmon.exe
15_FileSize=15360
15_FileDate=2004-8-17 12:00:00
15_FileVersion=5.1.2600.2180
16_HKey=HKEY_CURRENT_USER
16_Key=Software\Microsoft\Windows\CurrentVersion\Run
16_Name=bgswitch
16_Value=c:\windows\system32\壁纸自动换.exe
16_FileSize=19520
16_FileDate=2004-2-22 16:01:52
16_FileVersion=
17_HKey=HKEY_CURRENT_USER
17_Key=Software\Microsoft\Windows NT\CurrentVersion\Windows
17_Name=load
17_Value=
Max=17