HKLM\Software\Classes\Folder\Shellex\ColumnHandlers
+ Fax Tiff Data Column ProviderFax Tiff Data Column ProviderMicrosoft Corporationc:\winnt\system32\faxshell.dll
+ PDF Shell ExtensionPDF Shell ExtensionAdobe Systems, Inc.e:\program files\adobe\acrobat 7.0\activex\pdfshell.dll
+ ShAVColumnProvider classDocProp2Microsoft Corporationc:\winnt\system32\docprop2.dll
+ Version Column ProviderDocProp2Microsoft Corporationc:\winnt\system32\docprop2.dll
+ {0D2E74C4-3C34-11d2-A27E-00C04FC30871}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ {24F14F01-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
+ {24F14F02-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationc:\winnt\system32\shell32.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ bho Class万能五笔接口程序深圳世强软件开发部c:\program files\common files\wnwb\wnwbio.dll
+ IeCatch2 Classjccatch ModuleAmaze Softc:\program files\flashget\jccatch.dll
+ PrjZKBaiduBHO.ZKBaiduBHOzcomc:\winnt\system32\zkbaidubho.dll
+ VnetCookie ClassVnetTransfer Modulec:\program files\vnetclient1.6\vnettransfer.dll
+ 珊瑚虫超级搜索toolbar.dllYOK.Comc:\program files\yok\toolbar.dll
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
+ toolbar.dlltoolbar.dllYOK.Comc:\program files\yok\toolbar.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ msdxm.ocxWindows Media Player 2 ActiveX ControlMicrosoft Corporationc:\winnt\system32\msdxm.ocx
+ 珊瑚虫超级搜索toolbar.dllYOK.Comc:\program files\yok\toolbar.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ &FlashGetFlashGetAmaze Softc:\program files\flashget\flashget.exe
+ 腾讯QQQQTENCENTe:\program files\tencent\qq\qq.exe
+ 易趣购物File not found: http://click2.ad4all.net/url2/urlmanage/url.asp?id=1
Task Scheduler
+ DDD_Install_Program.jobFile not found: C:\DOCUME~1\JOAN~1.JOA\LOCALS~1\Temp\miniddd.exe
HKLM\System\CurrentControlSet\Services
+ Dhcp通过注册和更改 IP 地址以及 DNS 名称来管理网络配置。Microsoft Corporationc:\winnt\system32\services.exe
+ dmserver逻辑磁盘管理器监视狗服务Microsoft Corporationc:\winnt\system32\services.exe
+ Dnscache解析和缓冲域名系统 (DNS) 名称。Microsoft Corporationc:\winnt\system32\services.exe
+ Eventlog记录程序和 Windows 发送的事件消息。事件日志包含对诊断问题有所帮助的信息。您可以在“事件查看器”中查看报告。Microsoft Corporationc:\winnt\system32\services.exe
+ HidServHID Audio ServiceMicrosoft Corporationc:\winnt\system32\hidserv.exe
+ kavsvcKaspersky Anti-Virus ServiceKaspersky Labc:\program files\kaspersky lab\kaspersky anti-virus personal\kavsvc.exe
+ lanmanworkstation提供网络链结和通讯。Microsoft Corporationc:\winnt\system32\services.exe
+ LmHosts允许对“TCP/IP 上 NetBIOS (NetBT)”服务以及 NetBIOS 名称解析的支持。Microsoft Corporationc:\winnt\system32\services.exe
+ NtmsSvc管理可移动媒体、驱动程序和库。Microsoft Corporationc:\winnt\system32\svchost.exe
+ PlugPlay管理设备安装以及配置,并且通知程序关于设备更改的情况。Microsoft Corporationc:\winnt\system32\services.exe
+ PolicyAgent管理 IP 安全策略以及启动 ISAKMP/Oakley (IKE) 和 IP 安全驱动程序。Microsoft Corporationc:\winnt\system32\lsass.exe
+ ProtectedStorage提供对敏感数据(如私钥)的保护性存储,以便防止未授权的服务,过程或用户对其的非法访问。Microsoft Corporationc:\winnt\system32\services.exe
+ RemoteRegistry允许远程注册表操作。Microsoft Corporationc:\winnt\system32\regsvc.exe
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwsrv.exe
+ RpcSs提供终结点映射程序 (endpoint mapper) 以及其它 RPC 服务。Microsoft Corporationc:\winnt\system32\svchost.exe
+ SamSs存储本地用户帐户的安全信息。Microsoft Corporationc:\winnt\system32\lsass.exe
+ Schedule允许程序在指定时间运行。Microsoft Corporationc:\winnt\system32\mstask.exe
+ seclogon在不同凭据下启用启动过程Microsoft Corporationc:\winnt\system32\services.exe
+ SENS跟踪系统事件,如登录 Windows,网络以及电源事件等。将这些事件通知给 COM+ 事件系统 “订阅者(subscriber)”。Microsoft Corporationc:\winnt\system32\svchost.exe
+ SharedAccess为通过拨号网络连接的家庭网络中所有计算机提供网络地址转换、定址以及名称解析服务。Microsoft Corporationc:\winnt\system32\svchost.exe
+ Spooler将文件加载到内存中以便迟后打印。Microsoft Corporationc:\winnt\system32\spoolsv.exe
+ stisvcStill Image Devices MonitorMicrosoft Corporationc:\winnt\system32\stisvc.exe
+ TrkWks当文件在网络域的 NTFS 卷中移动时发送通知。Microsoft Corporationc:\winnt\system32\services.exe
+ WinMgmt提供系统管理信息。Microsoft Corporationc:\winnt\system32\wbem\winmgmt.exe
+ wuauserv从 Windows Update 启用重要的 Windows 更新的下载和安装。如果禁用该服务,操作系统可以在 Windows Update Web 网站手动更新。Microsoft Corporationc:\winnt\system32\svchost.exe
HKLM\System\CurrentControlSet\Services
+ ACPIACPI Driver for NTMicrosoft Corporationc:\winnt\system32\drivers\acpi.sys
+ actserActser filter driver for Windows 2000/XPSiemens AGc:\winnt\system32\drivers\actser.sys
+ actvcommActVComm driverSiemens AGc:\winnt\system32\drivers\actvcomm.sys
+ AFDAncillary Function Driver for WinSockMicrosoft Corporationc:\winnt\system32\drivers\afd.sys
+ AppleTalkAppleTalk ProtocolMicrosoft Corporationc:\winnt\system32\drivers\sfmatalk.sys
+ AsyncMacRAS Asynchronous Media DriverMicrosoft Corporationc:\winnt\system32\drivers\asyncmac.sys
+ atapiIDE/ATAPI Port DriverMicrosoft Corporationc:\winnt\system32\drivers\atapi.sys
+ AtmarpcATM ARP Client ProtocolMicrosoft Corporationc:\winnt\system32\drivers\atmarpc.sys
+ audstubAudStub DriverMicrosoft Corporationc:\winnt\system32\drivers\audstub.sys
+ baagdy14File not found: system32\drivers\baagdy14.sys
+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\winnt\system32\drivers\basetdi.sys
+ C-DillaFile not found: C:\WINNT\System32\drivers\CDANT.SYS
+ ccdecodeWDM Closed Caption VBI CodecMicrosoft Corporationc:\winnt\system32\drivers\ccdecode.sys
+ CdaC15BAMacrovision SECURITY DriverMacrovision Europe Ltdc:\winnt\system32\drivers\cdac15ba.sys
+ CdromSCSI CD-ROM DriverMicrosoft Corporationc:\winnt\system32\drivers\cdrom.sys
+ d347busPnP BIOS Extension c:\winnt\system32\drivers\d347bus.sys
+ d347prtSCSI miniport c:\winnt\system32\drivers\d347prt.sys
+ DiskPnP Disk DriverMicrosoft Corporationc:\winnt\system32\drivers\disk.sys
+ DlcDLC ProtocolMicrosoft Corporationc:\winnt\system32\drivers\dlc.sys
+ dmioNT Disk Manager I/O DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmio.sys
+ dmloadNT Disk Manager Startup DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmload.sys
+ DMusicMicrosoft DirectMusic Software Synthesizer (WDM)Microsoft Corporationc:\winnt\system32\drivers\dmusic.sys
+ FdcFloppy Disk Controller DriverMicrosoft Corporationc:\winnt\system32\drivers\fdc.sys
+ ferdrc:\winnt\system32\drivers\ferdr.sys
+ FETNDISNDIS 5.0 miniport driverVIA Technologies, Inc. c:\winnt\system32\drivers\fetnd5b.sys
+ FETNDISBNDIS 5.0 miniport driverVIA Technologies, Inc. c:\winnt\system32\drivers\fetnd5b.sys
+ FlpydiskFloppy DriverMicrosoft Corporationc:\winnt\system32\drivers\flpydisk.sys
+ FsVgaFull Screen Video DriverMicrosoft Corporationc:\winnt\system32\drivers\fsvga.sys
+ FtdiskFT Disk DriverMicrosoft Corporationc:\winnt\system32\drivers\ftdisk.sys
+ girntolpNetwork DriverMicrosoft Corporationc:\winnt\system32\drivers\girntolp.sys
+ GMSIPCIFile not found: G:\INSTALL\GMSIPCI.SYS
+ GNetPPPoEIntermediate Miniport Driver For PPP over Ethernet ProtocolGuangdong Data Communications Network Co.Ltd.c:\winnt\system32\drivers\pppoe.sys
+ GpcGeneric Packet ClassifierMicrosoft Corporationc:\winnt\system32\drivers\msgpc.sys
+ HidUsbUSB Miniport Driver for Input DevicesMicrosoft Corporationc:\winnt\system32\drivers\hidusb.sys
+ HOOKAPIFile not found: C:\PROGRAM FILES\RISING\RAV\HOOKAPI.SYS
+ HookUrlHookUrlBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\hookurl.sys
+ i8042prti8042 Port DriverMicrosoft Corporationc:\winnt\system32\drivers\i8042prt.sys
+ ids0004CFile not found: C:\Documents and Settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids0004C.sys
+ IpFilterDriverIP Traffic Filter DriverMicrosoft Corporationc:\winnt\system32\drivers\ipfltdrv.sys
+ IpInIpIP in IP Tunnel DriverMicrosoft Corporationc:\winnt\system32\drivers\ipinip.sys
+ IpNatIP Network Address TranslatorMicrosoft Corporationc:\winnt\system32\drivers\ipnat.sys
+ IPSECIPSEC driverMicrosoft Corporationc:\winnt\system32\drivers\ipsec.sys
+ IRENUMInfra-Red Bus EnumeratorMicrosoft Corporationc:\winnt\system32\drivers\irenum.sys
+ isapnpPNP ISA Bus DriverMicrosoft Corporationc:\winnt\system32\drivers\isapnp.sys
+ KbdclassKeyboard Class DriverMicrosoft Corporationc:\winnt\system32\drivers\kbdclass.sys
+ kbdhidHID Mouse Filter DriverMicrosoft Corporationc:\winnt\system32\drivers\kbdhid.sys
+ Kl1Kaspersky Anti-Hacker Only DriverKaspersky Labc:\winnt\system32\drivers\kl1.sys
+ Klifspuper-ptorKaspersky Labsc:\winnt\system32\drivers\klif.sys
+ KlmcKaspersky Anti-Virus Mail Checker ProxyKaspersky Labc:\winnt\system32\drivers\klmc.sys
+ kmixerKernel Mode Audio MixerMicrosoft Corporationc:\winnt\system32\drivers\kmixer.sys
+ kmsinputc:\winnt\system32\drivers\kmsinput.sys
+ MouclassMouse Class DriverMicrosoft Corporationc:\winnt\system32\drivers\mouclass.sys
+ MPEMicrosoft MPE to IP FilterMicrosoft Corporationc:\winnt\system32\drivers\mpe.sys
+ mProcRsRising Personal FireWall mprocrs.sysBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\mprocrs.sys
+ MSKSSRVMS KS ServerMicrosoft Corporationc:\winnt\system32\drivers\mskssrv.sys
+ MSPCLOCKMS Proxy ClockMicrosoft Corporationc:\winnt\system32\drivers\mspclock.sys
+ MSPQMMS Proxy Quality ManagerMicrosoft Corporationc:\winnt\system32\drivers\mspqm.sys
+ MSTEEWDM Tee/Communication Transform Filter Microsoft Corporationc:\winnt\system32\drivers\mstee.sys
+ NABTSFECWDM NABTS/FEC VBI CodecMicrosoft Corporationc:\winnt\system32\drivers\nabtsfec.sys
+ NdisTapiRemote Access NDIS TAPI DriverMicrosoft Corporationc:\winnt\system32\drivers\ndistapi.sys
+ NdisuioNDIS 用户模式 I/O 协议Microsoft Corporationc:\winnt\system32\drivers\ndisuio.sys
+ NdisWanRemote Access NDIS WAN DriverMicrosoft Corporationc:\winnt\system32\drivers\ndiswan.sys
+ NetBTNetBios over TcpipMicrosoft Corporationc:\winnt\system32\drivers\netbt.sys
+ NetDetectNetwork Card Detection driverMicrosoft Corporationc:\winnt\system32\drivers\netdtect.sys
+ New0c:\winnt\system32\new.sys