启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
(ctfmon.exe)(; C:\WINDOWS\system32\ctfmon.exe) [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(load)() [N/A]
(run)() [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
(IMJPMIG8.1)(; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32) [(Verified)Microsoft Corporation]
(PHIME2002ASync)(; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC) [(Verified)Microsoft Corporation]
(PHIME2002A)(; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName) [(Verified)Microsoft Corporation]
(Cmaudio)(RunDll32 cmicnfg.cpl,CMICtrlWnd) [N/A]
(ATIPTA)(; C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe) [ATI Technologies, Inc.]
(TkBellExe)("C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot) [RealNetworks, Inc.]
(SKYNET Personal FireWall)(; C:\PROGRA~1\SkyNet\Firewall\pfw.exe) [广州众达天网技术有限公司]
(Install Alitalk)(; C:\WINDOWS\temp\alitalk\alitalk.exe -hideframe) [N/A]
(windowstime.exe)(C:\WINDOWS\system32\windowstime.exe) [N/A]
(kis)("C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe") [Kaspersky Lab]
(wlzs2)(C:\DOCUME~1\JACKIE~1\LOCALS~1\Temp\wlzs2.exe) [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(shell)(Explorer.exe) [(Verified)Microsoft Corporation]
(Userinit)(C:\WINDOWS\system32\userinit.exe,) [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(AppInit_DLLs)(C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll) [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(UIHost)(logonui.exe) [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
(WinlogonNotify: klogon)(C:\WINDOWS\system32\klogon.dll) [Kaspersky Lab]
--------------------------------------------------------------------------------
启动文件夹
[Microsoft Office]
(C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk --) C:\PROGRA~1\MICROS~2\Office\OSA9.EXE [Microsoft Corporation])(N)
--------------------------------------------------------------------------------
服务
[Ati HotKey Poller / Ati HotKey Poller]
(C:\WINDOWS\system32\Ati2evxx.exe)(N/A)
[ATI Smart / ATI Smart]
(C:\WINDOWS\system32\ati2sgag.exe)()
[卡巴斯基互联网安全套装 6.0 / AVP]
("C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r)(Kaspersky Lab)
[ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard]
(C:\Program Files\ewido anti-spyware 4.0\guard.exe)(Anti-Malware Development a.s.)
[Human Interface Device Access / HidServ]
(C:\WINDOWS\System32\svchost.exe -k netsvcs--)%SystemRoot%\System32\hidserv.dll)(N/A)
[Macromedia Licensing Service / Macromedia Licensing Service]
("C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe")(N/A)
--------------------------------------------------------------------------------
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc]
(system32\drivers\ac97intc.sys)(Intel Corporation)
[ati2mtag / ati2mtag]
(system32\DRIVERS\ati2mtag.sys)(ATI Technologies Inc.)
[C-Media WDM Audio Interface / cmuda]
(system32\drivers\cmuda.sys)(C-Media Inc)
[ewido anti-spyware 4.0 driver / ewido anti-spyware 4.0 driver]
(\??\C:\Program Files\ewido anti-spyware 4.0\guard.sys)(N/A)
[kl1 / kl1]
(\SystemRoot\system32\drivers\kl1.sys)(Kaspersky Lab)
[klif / klif]
(\??\C:\WINDOWS\system32\drivers\klif.sys)(Kaspersky Lab)
[npkcrypt / npkcrypt]
(\??\D:\C盘\QQ2003III丐丐版\qq\npkcrypt.sys)(INCA Internet Co., Ltd.)
[Direct Parallel Link Driver / Ptilink]
(system32\DRIVERS\ptilink.sys)(Parallel Technologies, Inc.)
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
(system32\DRIVERS\RTL8139.SYS)(Realtek Semiconductor Corporation)
[Secdrv / Secdrv]
(system32\DRIVERS\secdrv.sys)(N/A)
[SKNFW / SKNFW]
(\??\C:\WINDOWS\system32\Drivers\SKNFW.sys)(N/A)
[SkyProcs / SkyProcs]
(\??\C:\PROGRA~1\SkyNet\Firewall\SkyProcs.sys)(N/A)
--------------------------------------------------------------------------------
浏览器加载项
[Web反病毒保护]
{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} (C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll, Kaspersky Lab)
[FlashGet]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} (C:\PROGRA~1\FlashGet\flashget.exe, Amaze Soft)
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} (C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation)
[FlashGet Bar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} (C:\PROGRA~1\FlashGet\fgiebar.dll, Amaze Soft)
[CEditCtrl
Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} (C:\WINDOWS\system32\aliedit\AliEdit.dll, www.alipay.com)
[AxSubmitControl Class]
{8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (C:\WINDOWS\DOWNLO~1\SUBMIT~1.DLL, )
[Shockwave Flash
Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.)
[上传到QQ网络硬盘]
(D:\C盘\QQ2003III丐丐版\qq\AddToNetDisk.htm, N/A)
[使用网际快车下载]
(C:\PROGRA~1\FlashGet\jc_link.htm, N/A)
[使用网际快车下载全部链接]
(C:\PROGRA~1\FlashGet\jc_all.htm, N/A)
[添加到QQ自定义面板]
(D:\C盘\QQ2003III丐丐版\qq\AddPanel.htm, N/A)
[添加到QQ表情]
(D:\C盘\QQ2003III丐丐版\qq\AddEmotion.htm, N/A)
[用QQ彩信发送该图片]
(D:\C盘\QQ2003III丐丐版\qq\SendMMS.htm, N/A)
--------------------------------------------------------------------------------