注释:[A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
+ Win32 Services
+ HKLM\System\CurrentControlSet\Services
aspnet_state
[A ] 1. c:\windows\microsoft.net\framework\v2.0.50727\aspnet_state.exe
Ati HotKey Poller
[AM] 2. c:\windows\system32\ati2evxx.exe
ATI Smart
[A ] 3. c:\windows\system32\ati2sgag.exe
clr_optimization_v2.0.50727_32
[A ] 4. c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe
EPSONStatusAgent2
[AM] 5. c:\program files\common files\epson\ebapi\sagent2.exe
ForceWare Intelligent Application Manager (IAM)
[AM] 6. c:\program files\nvidia corporation\networkaccessmanager\bin\nsvcappflt.exe
ForcewareWebInterface
[AM] 7. c:\program files\nvidia corporation\networkaccessmanager\apache group\apache2\bin\apache.exe
gusvc
[A ] 8. c:\program files\google\common\google updater\googleupdaterservice.exe
nSvcIp
[AM] 9. c:\program files\nvidia corporation\networkaccessmanager\bin\nsvcip.exe
nSvcLog
[AM] 10. c:\program files\nvidia corporation\networkaccessmanager\bin\nsvclog.exe
ose
[A ] 11. c:\program files\common files\microsoft shared\source engine\ose.exe
RsCCenter
[A ] 12. c:\program files\rising\rav\ccenter.exe
RsRavMon
[A ] 13. c:\program files\rising\rav\ravmond.exe
+ Kernel Drivers
+ HKLM\System\CurrentControlSet\Services
BaseTDI
[A ] 14. c:\windows\system32\drivers\basetdi.sys
ENTECH
[A ] 15. c:\windows\system32\drivers\entech.sys
ExpScaner
[A ] 16. c:\program files\rising\rav\expscan.sys
HDAudBus
[A ] 17. c:\windows\system32\drivers\hdaudbus.sys
HookCont
[A ] 18. c:\program files\rising\rav\hookcont.sys
HookReg
[A ] 19. c:\program files\rising\rav\hookreg.sys
HookSys
[A ] 20. c:\program files\rising\rav\hooksys.sys
IntcAzAudAddService
[A ] 21. c:\windows\system32\drivers\rtkhdaud.sys
MEMSCAN
[A ] 22. c:\program files\rising\rav\memscan.sys
nvata
[A ] 23. c:\windows\system32\drivers\nvata.sys
NVENETFD
[A ] 24. c:\windows\system32\drivers\nvenetfd.sys
nvnetbus
[A ] 25. c:\windows\system32\drivers\nvnetbus.sys
NVTCP
[A ] 26. c:\windows\system32\drivers\nvtcp.sys
RsAntiSpyware
[A ] 27. c:\windows\system32\drivers\rsboot.sys
RsNTGDI
[A ] 28. c:\windows\system32\drivers\rsntgdi.sys
RSPPSYS
[A ] 29. c:\program files\rising\rav\rsppsys.sys
Secdrv
[A ] 30. c:\windows\system32\drivers\secdrv.sys
Tcpip
[A ] 31. c:\windows\system32\drivers\tcpip.sys
TesSafe
[A ] 32. c:\windows\system32\tessafe.sys
WINIO
[A ] 33. g:\winio.sys
+ Winlogon
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
AtiExtEvent
[AM] 34. c:\windows\system32\ati2evxx.dll
+ HKCU\Control Panel\Desktop
Scrnsave.exe
[A ] 35. c:\windows\system32\夜光时钟屏保.scr
+ Internet Explorer
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C}
[A ] 36. c:\windows\system32\kakatool.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{00000AAA-A363-466E-BEF5-9BB68697AA7F}
[AM] 37. e:\program files\thunder network\webthunder\webthunderbho_now.dll
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
Exec
[A ] 38. e:\program files\浩方对战平台\gameclient.exe
+ Explorer
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
application/octet-stream
[AM] 39. c:\windows\system32\mscoree.dll
application/x-complus
[AM] 39. c:\windows\system32\mscoree.dll
application/x-msdownload
[AM] 39. c:\windows\system32\mscoree.dll
text/xml
[A ] 40. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 41. c:\windows\system32\hticons.dll
ContextBG
[AM] 42. c:\windows\system32\contextbg.dll
ShellLink for Application References
[A ] 43. c:\windows\system32\dfshim.dll
Shell Icon Handler for Application References
[A ] 43. c:\windows\system32\dfshim.dll
Catalyst Context Menu extension
[AM] 44. c:\program files\ati technologies\ati.ace\core-static\atiacmxx.dll
WinRAR shell extension
[AM] 45. c:\program files\winrar\rarext.dll
Microsoft Office HTML Icon Handler
[AM] 46. c:\program files\microsoft office\office11\msohev.dll
Web Folders
[A ] 47. c:\program files\common files\microsoft shared\web folders\msonsext.dll
RISING
[AM] 48. c:\windows\system32\ravext.dll
Shell Extensions for RealOne Player
[AM] 49. e:\program files\real\realplayer\rpshell.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 50. c:\windows\system32\shlhook.dll
{32CD708B-60A7-4C00-9377-D73EAA495F0F}
[AM] 48. c:\windows\system32\ravext.dll
+ Logon
+ HKCU\Software\Microsoft\Windows\CurrentVersion\Run
StartCCC
[A ] 51. c:\program files\ati technologies\ati.ace\core-static\clistart.exe
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Vistadrv
[A ] 52. c:\windows\resources\themes\vistadrv\vsdrv.exe
RTHDCPL
[AM] 53. c:\windows\rthdcpl.exe
Alcmtr
[A ] 54. c:\windows\alcmtr.exe
RavTask
[A ] 55. c:\program files\rising\rav\ravtask.exe
runeip
[AM] 56. c:\program files\rising\antispyware\runiep.exe
StormCodec_Helper
[A ] 57. e:\program files\ringz studio\storm codec\stormset.exe
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay
[A ] 58. c:\program files\rising\antispyware\runonce.exe
+ Boot Execute
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 59. c:\windows\system32\bsmain.exe
[A ] 60. c:\windows\system32\kknative.exe
+ Image Hijacks
+ HKCR\.html
htmlfile\Edit\Command
[A ] 61. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 61. c:\program files\microsoft office\office11\msohtmed.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 61. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 61. c:\program files\microsoft office\office11\msohtmed.exe
+ HKCR\.mp3
RealPlayer.MP3.6\open\Command
[A ] 62. e:\program files\real\realplayer\realplay.exe
+ Print Monitor
+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
EPSON V5 2KMonitor
[AM] 63. c:\windows\system32\ebpmon2.dll
+ 其他自启动项目
+ C:\Documents and Settings\sss\「开始」菜单\程序\启动
腾讯QQ.lnk
[AM] 64. e:\program files\tencent\qq\qq.exe
+ C:\Documents and Settings\All Users\「开始」菜单\程序\启动
EPSON Status Monitor 3 Environment Check 2.lnk
[A ] 65. c:\windows\system32\spool\drivers\w32x86\3\e_srcv02.exe
Microtek 扫描仪探测器.lnk
[AM] 66. c:\program files\microtek\scanwizard 5\scannerfinder.exe