HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ jetAudioShell Extension for jetAudioJetAudio, Inc.d:\program files\jetaudio\jetflext.dll
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt\system32\ravext.dll
+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realone player\rpshell.dll
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ Web 文件夹c:\program files\common files\microsoft shared\web folders\msonsext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ Google Toolbar HelperGoogle IE 客户端工具栏Google Inc.c:\program files\google\googletoolbar2.dll
+ IeCatch2 Classjccatch ModuleAmaze Softc:\program files\flashget\jccatch.dll
+ IEHlprObj ClassIEHelper Modulec:\winnt\system32\qylhelper.dll
+ Infofo 工具栏珊瑚虫 Infofo 工具栏珊瑚虫工作室 泰格工作室c:\program files\infofo bar\infofobar.dll
+ ThunderIEHelper Classxunleibho Modulec:\winnt\system32\xunleibho_v4.dll
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
+ shdocvw.dllShell Doc
Object and Control LibraryMicrosoft Corporationc:\winnt\system32\shdocvw.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ FlashGet BarFlashGet IE BarAmaze Softc:\program files\flashget\fgiebar.dll
+ 新浪点点通\
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ &FlashGetFlashGetAmaze Softc:\program files\flashget\flashget.exe
+ 豪杰超级解霸V8c:\herosoft\herov8\sthsdvd.exe
+ 浩方对战平台浩方对战平台上海浩方在线信息技术有限公司d:\program files\浩方对战平台\gameclient.exe
+ 网址大全File not found: http://www.coc.cc
+ 易趣购物File not found: http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-195?cn=song;icon;hp&mpro=http://www.ebay.com.cn
+ 易趣购物File not found: http://click2.ad4all.net/url2/urlmanage/url.asp?id=5
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
+ autocheck autochk *Auto Check UtilityMicrosoft Corporationc:\winnt\system32\autochk.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
+ Your Image File Name Here without a pathSymbolic Debugger for Windows 2000Microsoft Corporationc:\winnt\system32\ntsd.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls
+ apihookdll.dllc:\winnt\system32\apihookdll.dll
HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls
+ advapi32Advanced Windows 32 Base APIMicrosoft Corporationc:\winnt\system32\advapi32.dll
+ comdlg32Common Dialogs DLLMicrosoft Corporationc:\winnt\system32\comdlg32.dll
+ DllDirectoryc:\winnt\system32
+ gdi32GDI Client DLLMicrosoft Corporationc:\winnt\system32\gdi32.dll
+ imagehlpWindows NT Image HelperMicrosoft Corporationc:\winnt\system32\imagehlp.dll
+ kernel32Windows NT BASE API Client DLLMicrosoft Corporationc:\winnt\system32\kernel32.dll
+ lz32LZ Expand/Compress API DLLMicrosoft Corporationc:\winnt\system32\lz32.dll
+ ole32Microsoft OLE for WindowsMicrosoft Corporationc:\winnt\system32\ole32.dll
+ oleaut32Microsoft Corporationc:\winnt\system32\oleaut32.dll
+ olecli32
Object Linking and Embedding Client LibraryMicrosoft Corporationc:\winnt\system32\olecli32.dll
+ olecnv32Microsoft OLE for WindowsMicrosoft Corporationc:\winnt\system32\olecnv32.dll
+ olesvr32
Object Linking and Embedding Server LibraryMicrosoft Corporationc:\winnt\system32\olesvr32.dll
+ olethk32Microsoft OLE for WindowsMicrosoft Corporationc:\winnt\system32\olethk32.dll
+ rpcrt4Remote Procedure Call RuntimeMicrosoft Corporationc:\winnt\system32\rpcrt4.dll
+ shell32Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ urlInternet Shortcut Shell Extension DLLMicrosoft Corporationc:\winnt\system32\url.dll
+ urlmonOLE32 Extensions for Win32Microsoft Corporationc:\winnt\system32\urlmon.dll
+ user32Windows 2000 USER API Client DLLMicrosoft Corporationc:\winnt\system32\user32.dll
+ versionVersion Checking and File Installation LibrariesMicrosoft Corporationc:\winnt\system32\version.dll
+ wininetInternet Extensions for Win32Microsoft Corporationc:\winnt\system32\wininet.dll
+ wldap32Win32 LDAP API DLLMicrosoft Corporationc:\winnt\system32\wldap32.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
+ cscdllOffline Network AgentMicrosoft Corporationc:\winnt\system32\cscdll.dll
+ SensLognCommon DLL to receive Winlogon notificationsMicrosoft Corporationc:\winnt\system32\wlnotify.dll
+ wzcnotifWireless Zero Configuration Service UIMicrosoft Corporationc:\winnt\system32\wzcdlg.dll
HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{6BC583E6-FF85-48B8-AFC1-67824E03F7C9}] DATAGRAM 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{6BC583E6-FF85-48B8-AFC1-67824E03F7C9}] SEQPACKET 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{ACBB62D2-9844-4B2C-809E-C7082A4D9C5A}] DATAGRAM 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{ACBB62D2-9844-4B2C-809E-C7082A4D9C5A}] SEQPACKET 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{ADD91916-50F7-4F76-BEB2-585378D9DC6C}] DATAGRAM 4Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{ADD91916-50F7-4F76-BEB2-585378D9DC6C}] SEQPACKET 4Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{B653099E-CF14-4715-817C-29A902B2194F}] DATAGRAM 3Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{B653099E-CF14-4715-817C-29A902B2194F}] SEQPACKET 3Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{E88FD801-A696-47A0-BD73-13B83E53AAB2}] DATAGRAM 5Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{E88FD801-A696-47A0-BD73-13B83E53AAB2}] SEQPACKET 5Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{F1D493F6-E495-4C10-B9AD-651D1A9F8DF4}] DATAGRAM 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{F1D493F6-E495-4C10-B9AD-651D1A9F8DF4}] SEQPACKET 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD Tcpip [RAW/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD Tcpip [TCP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ MSAFD Tcpip [UDP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationc:\winnt\system32\msafd.dll
+ RSVP TCP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\winnt\system32\rsvpsp.dll
+ RSVP UDP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationc:\winnt\system32\rsvpsp.dll