HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
+ 1File not found: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ NvCplDaemonNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll
+ QQQQTENCENTd:\program files\tencent\qq\qq.exe
+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe
+ Torjan ProgramqiuSCaKc:\windows\winlogon.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
+ CheckFaultKernelc:\windows\system32\mswdm.exe
+ KernelFaultCheckc:\windows\system32\mswdm.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
+ pyjj加加输入法 4.0 作者:孙百川加加开发组c:\program files\jj4\jjsvr4.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
+ ntldr.dllc:\ntldr.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ Desktop ExplorerNVIDIA Desktop Explorer, Version 110.14 NVIDIA Corporationc:\windows\system32\nvshell.dll
+ Desktop Explorer MenuNVIDIA Desktop Explorer, Version 110.14 NVIDIA Corporationc:\windows\system32\nvshell.dll
+ HyperTerminal Icon ExtHyperTerminal Applet LibraryHilgraeve, Inc.c:\windows\system32\hticons.dll
+ Image Cutterc:\program files\imagecutter\contextmenu.dll
+ nView Desktop Context MenuNVIDIA Desktop Explorer, Version 110.14 NVIDIA Corporationc:\windows\system32\nvshell.dll
+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realplayer\rpshell.dll
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ Web 文件夹c:\program files\common files\microsoft shared\web folders\msonsext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ QQBrowserHelper
Object ClassQQIEHelper Module深圳市腾讯计算机系统有限公司d:\program files\tencent\qq\qqiehelper.dll
+ ThunderIEHelper ClassXunLei BHOThunder Networking Technologies,LTDc:\windows\system32\xunleibho_v14.dll
+ 超级兔子上网精灵HaoKanBar Toolbar ModuleXiang Feng Technologyd:\program files\super rabbit\magicset\haokanbar.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ FlashGet BarFlashGet IE BarAmaze Softd:\program files\flashget\fgiebar.dll
+ 超级兔子上网精灵HaoKanBar Toolbar ModuleXiang Feng Technologyd:\program files\super rabbit\magicset\haokanbar.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ FlashGetFlashGetAmaze Softd:\program files\flashget\flashget.exe
+ QQQQTENCENTd:\program files\tencent\qq\qq.exe
+ 百度首页File not found: http://baidu.com/index.php?tn=bainiudg
+ 浩方对战平台浩方对战平台上海浩方在线信息技术有限公司f:\program files\浩方对战平台\gameclient.exe
HKLM\System\CurrentControlSet\Services
+ NVSvcProvides system and desktop level support to the NVIDIA display driverNVIDIA Corporationc:\windows\system32\nvsvc32.exe
+ Remote SQL在局域网以及广域网环境中为企业提供路由服务。c:\windows\system32\su.exe
HKLM\System\CurrentControlSet\Services
+ admjoyVortex AU8820 WDM Joystick DriverAureal, Inc.c:\windows\system32\drivers\admjoy.sys
+ aeaudioAndrea Audio Stub DriverAndrea Electronics Corporationc:\windows\system32\drivers\aeaudio.sys
+ AN983ADMtek AN983/AN985/ADM951X NDIS5 DriverADMtek Incorporated.c:\windows\system32\drivers\an983.sys
+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\windows\system32\drivers\basetdi.sys
+ EagleNTFile not found: C:\WINDOWS\system32\drivers\EagleNT.sys
+ ExpScanerFile not found: C:\Program Files\Rising\Rav\ExpScan.sys
+ GOOD05File not found: C:\WINDOWS\system32\vqpn6hhl.sys
+ HookContFile not found: C:\Program Files\Rising\Rav\HOOKCONT.sys
+ HookRegFile not found: C:\Program Files\Rising\Rav\HookReg.sys
+ HookSysFile not found: C:\Program Files\Rising\Rav\HookSys.sys
+ ialmFile not found: system32\DRIVERS\ialmnt5.sys
+ MEMSCANFile not found: C:\Program Files\Rising\Rav\MEMSCAN.sys
+ NPFnpfCACE Technologiesc:\windows\system32\drivers\npf.sys
+ npkcryptnProtect KeyCrypt DriverINCA Internet Co., Ltd.d:\program files\tencent\qq\npkcrypt.sys
+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 81.98 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys
+ oreans32c:\windows\system32\drivers\oreans32.sys
+ prcmondrvProcess Monitor driverIgor Nysc:\windows\system32\drivers\prcmondrv1041.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys
+ safemonSystem Safety Monitor 2.0 extension for Windows security layerSystem Safety Limitedc:\windows\system32\drivers\safemon.sys
+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys
+ smwdmSoundMAX Integrated Digital Audio Analog Devices, Inc.c:\windows\system32\drivers\smwdm.sys
+ XPROTECTORc:\windows\system32\drivers\xprotector.sys
+ ZSMC301bVideo streaming and Capture Device DriverVMc:\windows\system32\drivers\usbvm31b.sys
+ {6080A529-897E-4629-A488-ABA0C29B635E}File not found: system32\drivers\ialmsbw.sys
+ {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}File not found: system32\drivers\ialmkchw.sys