R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page=http://www.yahoo.com.cn
R3 - Default URLSearchHook is missing
F0 - system.ini: Shell=Explorer.exe 1
O2 - BHO: CPub
Object - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - C:\Program Files\P4P\sodaie.dll
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - (file missing)
O2 - BHO: CnsHook Class - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\cnshook.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SysExplr] C:\Herosoft\HeroV8\SYSEXPLR.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [GameGuard] C:\WINDOWS\system32\GameGuard.exe
O4 - HKLM\..\Run: [RavTask] "D:\瑞星杀毒\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
O4 - HKLM\..\RunOnce: [RavStub] "D:\瑞星杀毒\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKLM\..\RunOnce: [GameGuard] C:\WINDOWS\system32\GameGuard.exe
O4 - HKLM\..\RunOnce: [CnsHook.dll] regsvr32 /s C:\WINDOWS\downlo~1\CnsHook.dll
O4 - HKLM\..\RunOnce: [cnshint.dll] regsvr32 /s C:\WINDOWS\downlo~1\cnshint.dll
O4 - HKLM\..\RunOnce: [CnsMinEx.dll] regsvr32.exe /s
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O9 - Extra Button: 雅虎WIDGET - {6354ABE6-05F1-49ed-B850-E423120EC338} - http://cn.widget.yahoo.com/index.htm?source=Cns (file missing)
O9 - Extra Button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg (file missing)
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\WINSTD.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\WINSTD.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\WINSTD.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\WINSTD.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\WINSTD.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\WINSTD.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\WINSTD.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\WINSTD.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\WINSTD.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\WINSTD.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\WINSTD.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\WINSTD.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\WINSTD.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\WINSTD.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\WINSTD.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\WINSTD.dll
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\WINSTD.dll