[BootExecute]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SYSTEM\CurrentControlSet\Control\Session Manager
1_Name=BootExecute
1_Value=autocheck autochk *
Max=1
[AutoRun]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=Software\Microsoft\Windows\CurrentVersion\Run
1_Name=NvCplDaemon
1_Value=rundll32.exe c:\windows\system32\nvcpl.dll,nvstartup
1_FileSize=7311360
1_FileDate=2005-12-10 AM 03:06:00
1_FileVersion=6.14.10.8198
2_HKey=HKEY_LOCAL_MACHINE
2_Key=Software\Microsoft\Windows\CurrentVersion\Run
2_Name=KernelFaultCheck
2_Value=%systemroot%\system32\dumprep 0 -k
3_HKey=HKEY_LOCAL_MACHINE
3_Key=Software\Microsoft\Windows\CurrentVersion\Run
3_Name=TkBellExe
3_Value="c:\program files\common files\real\update_ob\realsched.exe" -osboot
3_FileSize=180269
3_FileDate=2006-4-4 AM 11:45:48
3_FileVersion=0.1.0.3510
4_HKey=HKEY_LOCAL_MACHINE
4_Key=Software\Microsoft\Windows\CurrentVersion\Run
4_Name=Torjan Program
4_Value=c:\windows\winlogon.exe
4_FileSize=46211
4_FileDate=2005-7-22 PM 02:23:12
4_FileVersion=0.0.0.83
5_HKey=HKEY_LOCAL_MACHINE
5_Key=Software\Microsoft\Windows\CurrentVersion\RunOnce
5_Name=Super Rabbit Winspeed
5_Value="d:\program files\super rabbit\magicset\winspeed.exe" /autokill:3
5_FileSize=912384
5_FileDate=2006-6-27 AM 12:06:00
5_FileVersion=7.67.0.1
6_HKey=HKEY_LOCAL_MACHINE
6_Key=Software\Microsoft\Windows NT\CurrentVersion\Windows
6_Name=load
6_Value=
7_HKey=HKEY_CURRENT_USER
7_Key=Software\Microsoft\Windows\CurrentVersion\Run
7_Name=ctfmon.exe
7_Value=c:\windows\system32\ctfmon.exe
7_FileSize=15360
7_FileDate=2004-8-12
7_FileVersion=5.1.2600.2180
8_HKey=HKEY_CURRENT_USER
8_Key=Software\Microsoft\Windows\CurrentVersion\Run
8_Name=pyjj
8_Value=c:\program files\jj4\jjsvr4.exe
8_FileSize=454656
8_FileDate=2006-1-17 PM 05:00:04
8_FileVersion=4.0.0.20
9_HKey=HKEY_CURRENT_USER
9_Key=Software\Microsoft\Windows NT\CurrentVersion\Windows
9_Name=load
9_Value=
Max=9
[ModuleUsage]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/dddmsp.dll
1_Name=.Owner
1_Value={EF9F1C48-1A63-495A-9317-B7B71B34A9CF}
1_Clsid=Msp Class
1_FileName=C:\WINDOWS\Downloaded Program Files\dddmsp.dll
1_FileSize=118784
1_FileDate=2005-4-26 PM 03:16:28
1_FileVersion=1.0.0.1
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/OL2005.dll
2_Name=.Owner
2_Value={E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153}
2_Clsid=Rising Web Scan
Object2_FileName=C:\WINDOWS\Downloaded Program Files\OL2005.dll
2_FileSize=278528
2_FileDate=2006-2-13 PM 03:57:38
2_FileVersion=18.0.0.6
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/YAlive.dll
3_Name=.Owner
3_Value={57421194-58FB-49AE-9B4F-FD48869B9AD4}
3_Clsid=
3_FileName=C:\WINDOWS\Downloaded Program Files\YAlive.dll
3_FileVersion=
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/3DShowVM.ocx
4_Name=.Owner
4_Value={C661F36D-DF85-4EF4-83C7-E107B83D04B1}
4_Clsid=WebActivater Control
4_FileName=C:\WINDOWS\system32\3DShowVM.ocx
4_FileSize=319488
4_FileDate=2006-3-13 PM 02:00:38
4_FileVersion=1.0.200.50
5_HKey=HKEY_LOCAL_MACHINE
5_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/iMopDl.dll
5_Name=.Owner
5_Value={5932517A-3326-4439-A708-1C98EDB5C549}
5_Clsid=
5_FileName=C:\WINDOWS\system32\iMopDl.dll
5_FileVersion=
6_HKey=HKEY_LOCAL_MACHINE
6_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/LegitCheckControl.DLL
6_Name=.Owner
6_Value=Unknown Owner
6_Clsid=
6_FileName=C:\WINDOWS\system32\LegitCheckControl.DLL
6_FileVersion=
7_HKey=HKEY_LOCAL_MACHINE
7_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/mfc42.dll
7_Name=.Owner
7_Value=Unknown Owner
7_Clsid=
7_FileName=C:\WINDOWS\system32\mfc42.dll
7_FileSize=1028096
7_FileDate=2004-8-12
7_FileVersion=6.2.4131.0
8_HKey=HKEY_LOCAL_MACHINE
8_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/msvcrt.dll
8_Name=.Owner
8_Value=Unknown Owner
8_Clsid=
8_FileName=C:\WINDOWS\system32\msvcrt.dll
8_FileSize=343040
8_FileDate=2004-8-12
8_FileVersion=7.0.2600.2180
9_HKey=HKEY_LOCAL_MACHINE
9_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/olepro32.dll
9_Name=.Owner
9_Value=Unknown Owner
9_Clsid=
9_FileName=C:\WINDOWS\system32\olepro32.dll
9_FileSize=83456
9_FileDate=2004-8-12
9_FileVersion=5.1.2600.2180
10_HKey=HKEY_LOCAL_MACHINE
10_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/wuweb.dll
10_Name=.Owner
10_Value=Unknown Owner
10_Clsid=
10_FileName=C:\WINDOWS\system32\wuweb.dll
10_FileSize=173536
10_FileDate=2005-5-26 AM 04:19:32
10_FileVersion=5.8.0.2469
Max=10
[Process]
1_FileName=C:\WINDOWS\SYSTEM32\SMSS.EXE
1_FileSize=50688
1_FileDate=2004-8-12
1_FileVersion=5.1.2600.2180
2_FileName=C:\WINDOWS\SYSTEM32\CSRSS.EXE
2_FileSize=6144
2_FileDate=2004-8-12
2_FileVersion=5.1.2600.2180
3_FileName=C:\WINDOWS\SYSTEM32\WINLOGON.EXE
3_FileSize=487424
3_FileDate=2004-8-12
3_FileVersion=5.1.2600.2180
4_FileName=C:\WINDOWS\SYSTEM32\SERVICES.EXE
4_FileSize=108032
4_FileDate=2004-8-12
4_FileVersion=5.1.2600.2180
5_FileName=C:\WINDOWS\SYSTEM32\LSASS.EXE
5_FileSize=13312
5_FileDate=2004-8-12
5_FileVersion=5.1.2600.2180
6_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
6_FileSize=14336
6_FileDate=2004-8-12
6_FileVersion=5.1.2600.2180
7_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
7_FileSize=14336
7_FileDate=2004-8-12
7_FileVersion=5.1.2600.2180
8_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
8_FileSize=14336
8_FileDate=2004-8-12
8_FileVersion=5.1.2600.2180
9_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
9_FileSize=14336
9_FileDate=2004-8-12
9_FileVersion=5.1.2600.2180
10_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
10_FileSize=14336
10_FileDate=2004-8-12
10_FileVersion=5.1.2600.2180
11_FileName=C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
11_FileSize=57856
11_FileDate=2004-8-12
11_FileVersion=5.1.2600.2180
12_FileName=C:\WINDOWS\SYSTEM32\NVSVC32.EXE
12_FileSize=131139
12_FileDate=2005-12-10 AM 03:06:00
12_FileVersion=6.14.10.8198
13_FileName=C:\WINDOWS\SYSTEM32\WDFMGR.EXE
13_FileSize=38912
13_FileDate=2004-8-10 PM 10:05:14
13_FileVersion=5.2.3790.1230
14_FileName=C:\WINDOWS\EXPLORER.EXE
14_FileSize=976896
14_FileDate=2004-8-12
14_FileVersion=6.0.2900.2180
15_FileName=C:\WINDOWS\SYSTEM32\ALG.EXE
15_FileSize=44544
15_FileDate=2004-8-12
15_FileVersion=5.1.2600.2180
16_FileName=C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
16_FileSize=180269
16_FileDate=2006-4-4 AM 11:45:48
16_FileVersion=0.1.0.3510
17_FileName=C:\WINDOWS\SYSTEM32\CTFMON.EXE
17_FileSize=15360
17_FileDate=2004-8-12
17_FileVersion=5.1.2600.2180
18_FileName=C:\PROGRAM FILES\JJ4\JJSVR4.EXE
18_FileSize=454656
18_FileDate=2006-1-17 PM 05:00:04
18_FileVersion=4.0.0.20
19_FileName=C:\WINDOWS\WINLOGON.EXE
19_FileSize=46211
19_FileDate=2005-7-22 PM 02:23:12
19_FileVersion=0.0.0.83
20_FileName=D:\PROGRAM FILES\TENCENT\TT\TTRAVELER.EXE
20_FileSize=3022848
20_FileDate=2006-4-20 PM 05:51:34
20_FileVersion=3.0.0.250
21_FileName=C:\WINDOWS\SYSTEM32\WUAUCLT.EXE
21_FileSize=124184
21_FileDate=2005-5-26 AM 04:16:36
21_FileVersion=5.8.0.2469
22_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
22_FileSize=14336
22_FileDate=2004-8-12
22_FileVersion=5.1.2600.2180
23_FileName=D:\PROGRAM FILES\SUPER RABBIT\MAGICSET\MAGICSET.EXE
23_FileSize=569344
23_FileDate=2006-6-27 AM 12:19:10
23_FileVersion=7.67.0.0
24_FileName=D:\PROGRAM FILES\SUPER RABBIT\MAGICSET\IEHELP.EXE
24_FileSize=704000
24_FileDate=2006-6-27 AM 12:04:32
24_FileVersion=7.67.0.1
25_FileName=C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
25_FileSize=218112
25_FileDate=2004-8-12 AM 08:00:00
25_FileVersion=5.1.2600.2180
26_FileName=[SYSTEM PROCESS]
Max=26
[Hosts]
HostsFile=C:\WINDOWS\system32\Drivers\Etc\Hosts
1_Host=127.0.0.1 localhost
Max=1