C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\DOWNLO~1\SPVXK.DLL
C:\PROGRAM FILES\ACROBATCHS\ACTIVEX\PDFSHELL.DLL
C:\WINDOWS\DOWNLO~1\TTZJW.DLL
C:\WINDOWS\SYSTEM32\XUNLEIBHO_V14.DLL
C:\PROGRAM FILES\ACROBATCHS\ACTIVEX\ACROIEHELPER.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\LOCKFILE2007\SYSHOOK.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\PROGRA~1\MICROS~2\OFFICE11\MCPS.DLL
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\CDNNS.DLL
C:\WINDOWS\LOCKFILE2007\SERVICES.EXE
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\CDNNS.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\VTTIMER.EXE
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
C:\WINDOWS\SYSTEM32\CDNNS.DLL
C:\WINDOWS\SYSTEM32\VTTRAYP.EXE
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\WINDOWS\SYSTEM32\VTDISPLY.DLL
C:\WINDOWS\SYSTEM32\VTGAMMA2.DLL
C:\WINDOWS\SYSTEM32\VTINFO2.DLL
C:\WINDOWS\SYSTEM32\VTOVRLAY.DLL
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
F:\新建文件夹 (2)\RSDETECT.EXE
C:\WINDOWS\DOWNLO~1\SPVXK.DLL
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\DOWNLO~1\SPVXK.DLL
C:\WINDOWS\DOWNLO~1\TTZJW.DLL
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL
C:\WINDOWS\SYSTEM32\KAKATOOL.DLL
C:\WINDOWS\SYSTEM32\XUNLEIBHO_V14.DLL
C:\PROGRAM FILES\ACROBATCHS\ACTIVEX\ACROIEHELPER.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\LOCKFILE2007\SYSHOOK.DLL
C:\PROGRA~1\CHINANET\VNETTR~1.DLL
C:\PROGRA~1\CHINANET\COMMUNICATE.DLL
C:\PROGRA~1\CHINANET\CLIENT~1.DLL
F:\新建文件夹 (2)\新建文件夹 (2)\QQIEHELPER.DLL
C:\WINDOWS\SYSTEM32\SSUP.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\DOWNLO~1\SPVXK.DLL
C:\WINDOWS\DOWNLO~1\TTZJW.DLL
C:\WINDOWS\SYSTEM32\IMSC40A.IME
C:\PROGRA~1\COMMON~1\MICROS~1\IME\SHARED2.0\MSCAND20.DLL
C:\WINDOWS\SYSTEM32\KAKATOOL.DLL
C:\WINDOWS\SYSTEM32\XUNLEIBHO_V14.DLL
C:\PROGRAM FILES\ACROBATCHS\ACTIVEX\ACROIEHELPER.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\LOCKFILE2007\SYSHOOK.DLL
C:\PROGRA~1\CHINANET\VNETTR~1.DLL
C:\PROGRA~1\CHINANET\COMMUNICATE.DLL
C:\PROGRA~1\CHINANET\CLIENT~1.DLL
F:\新建文件夹 (2)\新建文件夹 (2)\QQIEHELPER.DLL
C:\WINDOWS\SYSTEM32\SSUP.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\CDNNS.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH8B.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\RMOC3260.DLL
C:\WINDOWS\SYSTEM32\PNCRT.DLL
C:\PROGRAM FILES\COMMON FILES\REAL\COMMON\PNRS3260.DLL
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE" /SPOIL /REMADVDEF /MIGRATION32
PHIME2002ASync = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME
MSPY2002 = C:\WINDOWS\SYSTEM32\IME\PINTLGNT\IMSCINST.EXE /SYNC
SoundMan = SOUNDMAN.EXE
VTTimer = VTTIMER.EXE
VTTrayp = VTTRAYP.EXE
IMSCMig = C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /PRELOAD
KernelFaultCheck = C:\WINDOWS\SYSTEM32\DUMPREP 0 -K
TkBellExe = "C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE" -OSBOOT
RavTask = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
stup.exe = C:\PROGRA~1\TENCENT\ADPLUS\STUP.EXE
sysHook = C:\WINDOWS\LOCKFILE2007\SERVICES.EXE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde
其它启动项
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe C:\WINDOWS\LockFile2007\SERVICES.EXE
SCRNSAVE.EXE = C:\WINDOWS\system32\ss3dfo.scr
Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
ScCertProp = WLNOTIFY.DLL
Schedule = WLNOTIFY.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
termsrv = WLNOTIFY.DLL
wlballoon = WLNOTIFY.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = C:\WINDOWS\SYSTEM32\USERINIT.EXE
shell = EXPLORER.EXE C:\WINDOWS\LOCKFILE2007\SERVICES.EXE
IE - BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{0005A87D-D626-4B3A-84F9-1D9571695F55} = C:\WINDOWS\system32\xunleibho_v14.dll
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} = C:\Program Files\Acrobatchs\ActiveX\AcroIEHelper.dll
{0C7C23EF-A848-485B-873C-0ED954731014} = C:\Program Files\TENCENT\Adplus\SSAddr.dll
{49E0E0F0-5C30-11D4-945D-000000088168} = C:\WINDOWS\LockFile2007\sysHook.dll
{4E83D567-4697-4F7B-B1F0-A513B01DB89A} = c:\PROGRA~1\chinanet\VNETTR~1.DLL
{54EBD53A-9BC1-480B-966A-843A333CA162} = F:\新建文件夹 (2)\新建文件夹 (2)\QQIEHelper.dll
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} = C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
{62EED7C6-9F02-42f9-B634-98E2899E147B} = C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
{669751ED-D558-49AE-B01A-3B374CC7910E} = C:\WINDOWS\system32\ssup.dll
{944864A5-3916-46E2-96A9-A2E84F3F1208} = C:\Program Files\Accoona\ASearchAssist.dll
{F5824EFB-728A-4726-A5A5-85A68B20EDC3} = C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll
Winsock SPI
MSAFD Tcpip [TCP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [UDP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [RAW/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
RSVP UDP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
RSVP TCP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{5693533D-2B86-4F83-A4A8-D52A3AF6BD7E}] SEQPACKET 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{5693533D-2B86-4F83-A4A8-D52A3AF6BD7E}] DATAGRAM 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{AFD1A054-3160-4911-BBF2-2FFDB3D65451}] SEQPACKET 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{AFD1A054-3160-4911-BBF2-2FFDB3D65451}] DATAGRAM 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{27D2AB6D-1C0D-4D41-A036-0E957CC930B1}] SEQPACKET 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{27D2AB6D-1C0D-4D41-A036-0E957CC930B1}] DATAGRAM 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{828065E3-7428-4591-BEB6-86CD658E28E1}] SEQPACKET 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{828065E3-7428-4591-BEB6-86CD658E28E1}] DATAGRAM 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{1B24C8A6-25DC-4008-AA3E-DE9D7E28942B}] SEQPACKET 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{1B24C8A6-25DC-4008-AA3E-DE9D7E28942B}] DATAGRAM 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL