autoruns853 扫描 的
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ NvCplDaemonNVIDIA Display Properties ExtensionNVIDIA Corporationc:\winnt.0\system32\nvcpl.dll
+ NvMediaCenterNVIDIA Media Center LibraryNVIDIA Corporationc:\winnt.0\system32\nvmctray.dll
+ nwizNVIDIA nView Wizard, Version 66.93 NVIDIA Corporationc:\winnt.0\system32\nwiz.exe
+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.d:\program files\rising\rav\ravtask.exe
+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Co., Ltd.d:\program files\rising\rfw\rfwmain.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
+ KKDelayRunOnce ApplicationBeijing Rising Technology Co., Ltd.c:\program files\rising\antispyware\runonce.exe
C:\Documents and Settings\Administrator\「开始」菜单\程序\启动
+ ADSL拨号王.lnkADSL ShellHelloNetd:\program files\hellonet\hellonet.exe
HKLM\SOFTWARE\Classes\Protocols\Handler
+ ic32ppc:\winnt.0\wc98pp.dll
HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components
+ 0文件未找到:
About:Home
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ AlcoholShellExAXShlEx.dllAlcohol Soft Development Teamd:\program files\alcohol soft\alcohol 120\axshlex.dll
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt.0\system32\ravext.dll
+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.d:\program files\real\realplayer\rpshell.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ ThunderIEHelper Classxunleibho BHOThunder Networking Technologies,LTDc:\winnt.0\system32\xunleibho_v13.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ kakatool.dllRising AntiSpyware ToolbarBeijing Rising Technology Co., Ltd.c:\winnt.0\system32\kakatool.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ 启动Web迅雷文件未找到: http://my.xunlei.com
+ 启动迅雷5Thunder Networking Technologies,LTDd:\program files\thunder network\thunder\thunder.exe
+ 腾讯QQQQTENCENTd:\program files\tencent\qq\qq.exe
+ 相关站点c:\winnt.0\web\related.htm
HKLM\System\CurrentControlSet\Services
+ NVSvcNVIDIA Driver Helper Service, Version 66.93NVIDIA Corporationc:\winnt.0\system32\nvsvc32.exe
+ RfwServiceRising Personal FireWall ServiceBeijing Rising Technology Co., Ltd.d:\program files\rising\rfw\rfwsrv.exe
+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.d:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.d:\program files\rising\rav\ravmond.exe
HKLM\System\CurrentControlSet\Services
+ a347busPlug and Play BIOS Extension c:\winnt.0\system32\drivers\a347bus.sys
+ a347scsiSCSI miniport c:\winnt.0\system32\drivers\a347scsi.sys
+ ALCXWDMRealtek AC'97 Audio Driver (WDM)Realtek Semiconductor Corp.c:\winnt.0\system32\drivers\alcxwdm.sys
+ atapic:\winnt.0\system32\drivers\atapi.sys
+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\winnt.0\system32\drivers\basetdi.sys
+ bbcapMirror Miniport DriverWindows (R) 2000 DDK providerc:\winnt.0\system32\drivers\bbcap.sys
+ BRPPPOEc:\winnt.0\system32\drivers\brpppoe.sys
+ dmioNT Disk Manager I/O DriverVERITAS Software Corp.c:\winnt.0\system32\drivers\dmio.sys
+ dmloadNT Disk Manager Startup DriverVERITAS Software Corp.c:\winnt.0\system32\drivers\dmload.sys
+ ExpScanerExpScan.sysd:\program files\rising\rav\expscan.sys
+ HookContHookContRisingd:\program files\rising\rav\hookcont.sys
+ HookRegd:\program files\rising\rav\hookreg.sys
+ HookSysHooksysRisingd:\program files\rising\rav\hooksys.sys
+ HookUrlHookUrlBeijing Rising Technology Co., Ltd.d:\program files\rising\rfw\hookurl.sys
+ IntcAzAudAddService文件未找到: system32\drivers\RtkHDAud.sys
+ kmsinputc:\winnt.0\system32\drivers\kmsinput.sys
+ mdbqta53c:\winnt.0\system32\drivers\mdbqta53.sys
+ MEMSCANMemScan Driver瑞星软件有限公司d:\program files\rising\rav\memscan.sys
+ mProcRsRising Personal FireWall mprocrs.sysBeijing Rising Technology Co., Ltd.d:\program files\rising\rfw\mprocrs.sys
+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.d:\program files\tencent\qq\npkcrypt.sys
+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 66.93 NVIDIA Corporationc:\winnt.0\system32\drivers\nv4_mini.sys
+ oreans32c:\winnt.0\system32\drivers\oreans32.sys
+ prodrv06StarForce Protection Environment DriverProtection Technologyc:\winnt.0\system32\drivers\prodrv06.sys
+ prohlp02StarForce Protection Helper DriverProtection Technologyc:\winnt.0\system32\drivers\prohlp02.sys
+ prosync1StarForce Protection Synchronization DriverProtection Technologyc:\winnt.0\system32\drivers\prosync1.sys
+ PtilinkParallel Technologies DirectParallel IO LibraryParallel Technologies, Inc.c:\winnt.0\system32\drivers\ptilink.sys
+ QuakeDRV文件未找到: system32\DRIVERS\quakedrv.sys
+ RsAntiSpywareRsBootBeijing Risingc:\winnt.0\system32\drivers\rsboot.sys
+ RsFwDrvnt_fwdrvBeijing Rising Technology Co., Ltd.d:\program files\rising\rfw\rsfwdrv.sys
+ RsNTGDIRsNTGDIBeijing Rising Technology Co., Ltd.c:\winnt.0\system32\drivers\rsntgdi.sys
+ RSPPSYSRSPPSYSRisingd:\program files\rising\rav\rsppsys.sys
+ sfhlp01StarForce Protection Helper DriverProtection Technologyc:\winnt.0\system32\drivers\sfhlp01.sys
+ sptdc:\winnt.0\system32\drivers\sptd.sys
+ TSP文件未找到: C:\WINNT.0\system32\drivers\klif.sys
+ vaxscsiSCSI miniportAlcohol Soft Co., Ltd.c:\winnt.0\system32\drivers\vaxscsi.sys
+ xinstallc:\winnt.0\system32\drivers\xinstall.sys
+ yukonw2kNDIS5 Miniport Driver for Marvell Yukon Gigabit Ethernet AdapterMarvell Semiconductor Inc.c:\winnt.0\system32\drivers\yukonw2k.sys
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
+ KKNative.exeNativeApBeijing Rising Technology Co., Ltd.c:\winnt.0\system32\kknative.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UIHost
+ %windir%\Resources\PalTheme\logonui.exeWindows Logon UI极限主题c:\winnt.0\resources\paltheme\logonui.exe
+ logonui.exe文件未找到: logonui.exe
HKCU\Control Panel\Desktop\Scrnsave.exe
+ C:\WINNT.0\pal3a.scrc:\winnt.0\pal3a.scr
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
+ LIDIL Language MonitorLanguageMonitorHewlett-Packard Companyc:\winnt.0\system32\hpzll3xu.dll