用Autoruns保存的日志:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ CBitSpiritThe powerful and easy-to-use BitTorrent ClientLANSPIRIT.NETc:\program files\bitspirit\bitspirit.exe
+ hzcmicliCO-CMI 客户端c:\lotus\cmi\co-cmicli.exe
+ JrRCleane:\ren\电脑消磁圣手\电脑消磁圣手\电脑消磁圣手.exe
+ KvMonXPFile not found: C:\Program Files\KV2005\KVMonXP.kxp
+ MSPY2002c:\windows\system32\ime\pintlgnt\imscinst.exe
+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmon.exe
+ RavTimerRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtimer.exe
+ SKYNET Personal FireWall天网个人版防火墙ChinaECGc:\program files\skynet\firewall\pfw.exe
+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe
+ YDTMain.exeFile not found: C:\PROGRA~1\YDT\YDTMain.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
+ SysTraysc:\windows\system32\dlmain.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realplayer\rpshell.dll
+ Yahoo Trojan Cleannerc:\program files\3721\ske\contmenu.dll
+ Yahoo!PhotoFile not found: C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll
+ 粉碎文件File not found: C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ywiper.dll
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ Web 文件夹c:\program files\common files\microsoft shared\web folders\msonsext.dll
+ 金山毒霸File not found: C:\KAV6\KAVEXT.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ DragSearch BHOFile not found: C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
+ MMSAssist BHOMMSAssistc:\program files\mmsassist\mmsass~1.dll
+ NTIECatcher ClassNet Transport IE Helper ModuleXic:\program files\nettransport 2\ntiehelper.dll
+ Yahoo!PhotoFile not found: C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ @shdoclc.dll,-864c:\windows\web\related.htm
+ Yahoo 1G电邮File not found: http://cn.mail.yahoo.com/promo/rd1
+ 清理上网记录File not found: http://assistant.3721.com/clean1.htm?fb=Cns
+ 情景聊天File not found: http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/
+ 上网助手File not found: http://assistant.3721.com/index.htm?fb=Cns
+ 手机短信File not found: http://sms.3721.com/ie/index.htm?pid=U_3721_assist
+ 腾讯QQQQTENCENTc:\program files\tencent\qq\qq.exe
+ 修复浏览器File not found: http://assistant.3721.com/security1.htm?fb=Cns
+ 寻宝乐趣多File not found: http://hot.3721.com/rd/shop_btn.htm
HKLM\System\CurrentControlSet\Services
+ .Net Boot Servicec:\windows\system32\big5_gb2312.exe
+ Local Network Servicec:\windows\system32\seedserv.exe
+ RsCCenterCCenterrisingc:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMonBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe
HKLM\System\CurrentControlSet\Services
+ ac97intcIntel(r) Integrated Controller Hub Audio DriverIntel Corporationc:\windows\system32\drivers\ac97intc.sys
+ aksusbAladdin USB Key DriverAladdin Knowledge Systemsc:\windows\system32\drivers\aksusb.sys
+ ALCXSENSSensaura WDM 3D Audio DriverSensaura Ltdc:\windows\system32\drivers\alcxsens.sys
+ ALCXWDMRealtek AC'97 Audio Driver (WDM)Realtek Semiconductor Corp.c:\windows\system32\drivers\alcxwdm.sys
+ ati2mtaaATI RAGE 128 Miniport DriverATI Technologies Inc.c:\windows\system32\drivers\ati2mtaa.sys
+ ati2mtagATI Radeon Miniport DriverATI Technologies Inc.c:\windows\system32\drivers\ati2mtag.sys
+ BaseTDIbasetdiRisingc:\windows\system32\drivers\basetdi.sys
+ d347busPnP BIOS Extension c:\windows\system32\drivers\d347bus.sys
+ d347prtSCSI miniport c:\windows\system32\drivers\d347prt.sys
+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys
+ GMSIPCIFile not found: G:\INSTALL\GMSIPCI.SYS
+ hardlockHardlock Device Driver for Windows NTAladdin Knowledge Systemsc:\windows\system32\drivers\hardlock.sys
+ HaspntHASP Kernel Device Driver for Windows NTAladdin Knowledge Systemsc:\windows\system32\drivers\haspnt.sys
+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys
+ HookRegc:\program files\rising\rav\hookreg.sys
+ HookSys瑞星c:\program files\rising\rav\hooksys.sys
+ kmsinputc:\windows\system32\drivers\kmsinput.sys
+ KRegExc:\windows\system32\drivers\kregex.sys
+ PProtectFile not found: C:\WINDOWS\system32\drivers\PProtect.sys
+ prodrv06StarForce Protection Environment DriverProtection Technologyc:\windows\system32\drivers\prodrv06.sys
+ prohlp02StarForce Protection Helper DriverProtection Technologyc:\windows\system32\drivers\prohlp02.sys
+ prosync1StarForce Protection Synchronization DriverProtection Technologyc:\windows\system32\drivers\prosync1.sys
+ PStripPowerStrip support NT kernel-mode driverEnTech Taiwanc:\windows\system32\drivers\pstrip.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys
+ rtl8029NDIS 5.0 driverRealtek Semiconductor Corporationc:\windows\system32\drivers\rtl8029.sys
+ rtl8139NDIS 5.0 driver Realtek Semiconductor Corporation c:\windows\system32\drivers\rtl8139.sys
+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys
+ sfhlp01StarForce Protection Helper DriverProtection Technologyc:\windows\system32\drivers\sfhlp01.sys
+ SkkbdfPS/2 Keyboard Filter Driver for Win2000Silitek Corp.c:\windows\system32\drivers\skkbdf.sys
+ SKNFWc:\windows\system32\drivers\sknfw.sys
+ SONYPVU1Sony USB Lower Filter driverSony Corporationc:\windows\system32\drivers\sonypvu1.sys
+ SQTECH9060Universal Serial Bus Camera DriverService & Quality Technology CO., LTD.c:\windows\system32\drivers\capt9060.sys
+ viaagp1VIA NT AGP FilterVIA Technologies, Inc.c:\windows\system32\drivers\viaagp1.sys
+ VIAudioVIA Audio WDM Driver VIA Technologies, Inc.c:\windows\system32\drivers\ac97via.sys
+ ZSMC302Video streaming and Capture Device DriverVMc:\windows\system32\drivers\usbvm31b.sys
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls
+ KB2357802.LOGFile not found: KB2357802.LOG
HKCU\Control Panel\Desktop\Scrnsave.exe
+ TheSim~1.scrScreensaverShot Incc:\windows\system32\the simpsons.scr
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
+ HP LaserJet 5 Language MonitorWin32 Language Monitor for direct connect HP printersHewlett-Packardc:\windows\system32\hpdcmon.dll