HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ RavMonRavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmon.exe
+ RavTimerRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtimer.exe
+ SoundManRealtek Sound ManagerRealtek Semiconductor Corp.c:\windows\soundman.exe
+ TkBellExeRealNetworks SchedulerRealNetworks, Inc.c:\program files\common files\real\update_ob\realsched.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
+ AlxInitFile not found: C:\WINDOWS\system32\AlxUp.exe
+ UserInitFile not found: C:\WINDOWS\system32\winhelper.exe
HKLM\System\CurrentControlSet\Services
+ Ati HotKey PollerATI External Event Utility EXE ModuleATI Technologies Inc.c:\windows\system32\ati2evxx.exe
+ ATI SmartATI Smartc:\windows\system32\ati2sgag.exe
+ StdServiceAOL Corp.c:\windows\system32\stdsver.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ Advanced JPEG Compressor Context Menu Shell Extension\
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
+ WinRAR shell extensionc:\program files\winrar\rarext.dll
+ Yahoo Trojan Cleanner\
+ Yahoo!Photo\
+ 粉碎文件\
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ BrowserHAP ClassHapbast ModuleShanghai Henbang Technology Co., Ltdc:\program files\hbclient\hapast.dll
+ i&Bar搜索引擎c:\program files\ibar\10002\ibar.dll
+ MMSAssist BHOMMSAssistc:\program files\mmsassist\mmsass~1.dll
+ std softwareAOL Corp.c:\windows\system32\stdup.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ ibar.dllc:\program files\ibar\10002\ibar.dll