启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<Internat.exe><internat.exe> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Synchronization Manager><mobsync.exe /logon> [(Verified)Microsoft Corporation]
<iamapp><C:\Program Files\Norton Internet Security\IAMAPP.EXE> [(Verified)Symantec Corporation]
<KAVRUN><D:\KAV6\KAVRUN.EXE> [kingsoft]
<helper.dll><C:\WINNT\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32> []
<CnsMin><Rundll32.exe C:\WINNT\downlo~1\CnsMin.dll,Rundll32> [北京三七二一科技有限公司]
<Symantec NetDriver Monitor><C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer> [(Verified)Symantec Corporation]
<YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe> [ ]
<RavTask><"D:\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINNT\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINNT\downlo~1\CnsHook.dll> [北京三七二一科技有限公司]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINNT\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
<WinlogonNotify: NavLogon><C:\WINNT\System32\NavLogon.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\PCANotify]
<WinlogonNotify: PCANotify><PCANotify.dll> [Symantec Corporation]
==================================
启动文件夹
[Microsoft Office]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk --> D:\program\office2k\Office\OSA9.EXE [Microsoft Corporation]><N>
[Service Manager]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Service Manager.lnk --> C:\MSSQL7\Binn\sqlmangr.exe [Microsoft Corporation]><N>
[alarmProc]
<C:\Documents and Settings\administrator\「开始」菜单\程序\启动\alarmProc.lnk --> D:\110视~1\接警台\ALARMP~1.EXE [浙江师大计海新技术有限公司]><N>
==================================
服务
[pcAnywhere Host Service / awhost32]
<C:\Program Files\Symantec\pcAnywhere\awhost32.exe><Symantec Corporation>
[Logical Disk Manager Administrative Service / dmadmin]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[MSSQLServer / MSSQLServer]
<C:\MSSQL7\binn\sqlservr.exe><Microsoft Corporation>
[Norton Internet Security Service / NISSERV]
<C:\Program Files\Norton Internet Security\NISSERV.EXE><Symantec Corporation>
[Norton Internet Security Accounts Manager / NISUM]
<C:\Program Files\Norton Internet Security\NISUM.EXE><Symantec Corporation>
[Rising Process Communication Center / RsCCenter]
<"D:\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"D:\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Symantec Network Drivers Service / SNDSrvc]
<C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe><Symantec Corporation>
[SQLServerAgent / SQLServerAgent]
<C:\MSSQL7\binn\sqlagent.exe><Microsoft Corporation>
[Norton Internet Security Proxy Service / SymProxySvc]
<C:\Program Files\Norton Internet Security\SymProxySvc.exe><Symantec Corporation>