IE - BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} = C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
{08A312BB-5409-49FC-9347-54BB7D069AC6} = C:\PROGRA~1\DESKAD~1\deskipn.dll
{16A770A0-0E87-4278-B748-2460D64A8386} = C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4767.dll
{54EBD53A-9BC1-480B-966A-843A333CA162} = D:\Program Files\Tencent\QQ\QQIEHelper.dll
{63C55A7F-6E29-8D4F-5C76-4F850F28D13A} = C:\Progra~1\DoDoorRSSFinder\ActiveBand
Object.dll
{8B316DA1-9950-4926-B9EA-1AEC124AFA45} = C:\WINNT\system32\sscli.dll
{999ADFA2-8AD1-47ff-97FC-69FB847458F4} = C:\Progra~1\NetMeeting\nmview.dll
{9ACEEE31-1440-471B-AA46-72B061FE7D61} = C:\WINNT\system32\WinSC.dll
{A697BC46-BC93-4833-93F5-1E365011E88A} = C:\WINNT\DBINT.dll
Winsock SPI
WinSock Proxy [tcp] = C:\WINNT\SYSTEM32\CN_SPI.DLL
WinSock Proxy [udp] = C:\WINNT\SYSTEM32\CN_SPI.DLL
WinSock Proxy for RSVP [tcp] = C:\WINNT\SYSTEM32\CN_SPI.DLL
WinSock Proxy for RSVP [udp] = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD Tcpip [TCP/IP] = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD Tcpip [UDP/IP] = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD Tcpip [RAW/IP] = C:\WINNT\SYSTEM32\CN_SPI.DLL
RSVP UDP Service Provider = C:\WINNT\SYSTEM32\CN_SPI.DLL
RSVP TCP Service Provider = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD nwlnkipx [IPX] = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD nwlnkspx [SPX] = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD nwlnkspx [SPX] [Pseudo Stream] = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD nwlnkspx [SPX II] = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD nwlnkspx [SPX II] [Pseudo Stream] = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\NwlnkNb] SEQPACKET 5 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\NwlnkNb] DATAGRAM 5 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\Nbf_{7FD09211-E7A5-43AD-B87D-B3E9A44296C2}] SEQPACKET 3 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\Nbf_{7FD09211-E7A5-43AD-B87D-B3E9A44296C2}] DATAGRAM 3 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{F58C8F33-BF45-44D1-89FC-6026E866FB82}] SEQPACKET 4 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{F58C8F33-BF45-44D1-89FC-6026E866FB82}] DATAGRAM 4 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{E4C1DAB9-1B95-477C-9F03-BA1D41ECB64D}] SEQPACKET 6 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{E4C1DAB9-1B95-477C-9F03-BA1D41ECB64D}] DATAGRAM 6 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{20F202BD-286D-4C20-8134-E6E49623748A}] SEQPACKET 7 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{20F202BD-286D-4C20-8134-E6E49623748A}] DATAGRAM 7 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{B76D9D2C-A9BF-4066-B8B7-E1B34A3A03F2}] SEQPACKET 8 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfIn{B76D9D2C-A9BF-4066-B8B7-E1B34A3A03F2}] DATAGRAM 8 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{54F81560-3C4C-421B-B006-7A93B54D0434}] SEQPACKET 9 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{54F81560-3C4C-421B-B006-7A93B54D0434}] DATAGRAM 9 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{507D986E-5575-4609-ADBD-DD46641880B2}] SEQPACKET 10 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\Nbf_NdisWanNbfOut{507D986E-5575-4609-ADBD-DD46641880B2}] DATAGRAM 10 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{7FD09211-E7A5-43AD-B87D-B3E9A44296C2}] SEQPACKET 0 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{7FD09211-E7A5-43AD-B87D-B3E9A44296C2}] DATAGRAM 0 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{5E2472B3-D786-4C99-86B4-F04CECFA64CD}] SEQPACKET 1 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{5E2472B3-D786-4C99-86B4-F04CECFA64CD}] DATAGRAM 1 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{9803F437-A490-41BB-B8C9-5A6BAC02DCD4}] SEQPACKET 2 = C:\WINNT\SYSTEM32\CN_SPI.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{9803F437-A490-41BB-B8C9-5A6BAC02DCD4}] DATAGRAM 2 = C:\WINNT\SYSTEM32\CN_SPI.DLL
系统服务项
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
Alerter = C:\WINNT\SYSTEM32\SERVICES.EXE
AppMgmt = C:\WINNT\SYSTEM32\SERVICES.EXE
AutoUpgrade = C:\WINNT\SYSTEM32\SVCHOST.EXE -K AUTOUPGRADE
BITS = C:\WINNT\SYSTEM32\SVCHOST.EXE -K BITSGROUP
Browser = C:\WINNT\SYSTEM32\SERVICES.EXE
C-DillaCdaC11BA = C:\WINNT\SYSTEM32\DRIVERS\CDAC11BA.EXE
C-DillaSrv = C:\WINNT\SYSTEM32\DRIVERS\CDANTSRV.EXE
cisvc = C:\WINNT\SYSTEM32\CISVC.EXE
ClipSrv = C:\WINNT\SYSTEM32\CLIPSRV.EXE
Dhcp = C:\WINNT\SYSTEM32\SERVICES.EXE
dmadmin = C:\WINNT\SYSTEM32\DMADMIN.EXE /COM
dmserver = C:\WINNT\SYSTEM32\SERVICES.EXE
Dnscache = C:\WINNT\SYSTEM32\SERVICES.EXE
Eventlog = C:\WINNT\SYSTEM32\SERVICES.EXE
EventSystem = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
Fax = C:\WINNT\SYSTEM32\FAXSVC.EXE
lanmanserver = C:\WINNT\SYSTEM32\SERVICES.EXE
lanmanworkstation = C:\WINNT\SYSTEM32\SERVICES.EXE
LmHosts = C:\WINNT\SYSTEM32\SERVICES.EXE
Messenger = C:\WINNT\SYSTEM32\SERVICES.EXE
mnmsrvc = C:\WINNT\SYSTEM32\MNMSRVC.EXE
MSDTC = C:\WINNT\SYSTEM32\MSDTC.EXE
MSIServer = C:\WINNT\SYSTEM32\MSIEXEC.EXE /V
MSmassacre = C:\WINNT\HELP\MSPASS.EXE
NetDDE = C:\WINNT\SYSTEM32\NETDDE.EXE
NetDDEdsdm = C:\WINNT\SYSTEM32\NETDDE.EXE
Netlogon = C:\WINNT\SYSTEM32\LSASS.EXE
Netman = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
NtLmSsp = C:\WINNT\SYSTEM32\LSASS.EXE
NtmsSvc = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
NVSvc = C:\WINNT\SYSTEM32\NVSVC32.EXE
PlugPlay = C:\WINNT\SYSTEM32\SERVICES.EXE
PolicyAgent = C:\WINNT\SYSTEM32\LSASS.EXE
ProtectedStorage = C:\WINNT\SYSTEM32\SERVICES.EXE
RasAuto = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
RasMan = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
RemoteAccess = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
RemoteRegistry = C:\WINNT\SYSTEM32\REGSVC.EXE
RpcLocator = C:\WINNT\SYSTEM32\LOCATOR.EXE
RpcSs = C:\WINNT\SYSTEM32\SVCHOST -K RPCSS
RsRavMon = "D:\PROGRAM FILES\RISING\RAV\RAVMOND.EXE"
RSVP = C:\WINNT\SYSTEM32\RSVP.EXE -S
SamSs = C:\WINNT\SYSTEM32\LSASS.EXE
SCardDrv = C:\WINNT\SYSTEM32\SCARDSVR.EXE
SCardSvr = C:\WINNT\SYSTEM32\SCARDSVR.EXE
Schedule = C:\WINNT\SYSTEM32\MSTASK.EXE
seclogon = C:\WINNT\SYSTEM32\SERVICES.EXE
SENS = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
SharedAccess = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
Spooler = C:\WINNT\SYSTEM32\SPOOLSV.EXE
SysmonLog = C:\WINNT\SYSTEM32\SMLOGSVC.EXE
TapiSrv = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
TlntSvr = C:\WINNT\SYSTEM32\TLNTSVR.EXE
TrkWks = C:\WINNT\SYSTEM32\SERVICES.EXE
UPS = C:\WINNT\SYSTEM32\UPS.EXE
UtilMan = C:\WINNT\SYSTEM32\UTILMAN.EXE
W32Time = C:\WINNT\SYSTEM32\SERVICES.EXE
WinMgmt = C:\WINNT\SYSTEM32\WBEM\WINMGMT.EXE
WmdmPmSN = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
Wmi = C:\WINNT\SYSTEM32\SERVICES.EXE
wuauserv = C:\WINNT\SYSTEM32\SVCHOST.EXE -K WUGROUP
WZCSVC = C:\WINNT\SYSTEM32\SVCHOST.EXE -K NETSVCS
ZTmassacre = C:\WINNT\HELP\ZTPASS.EXE
文件驱动
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
MRxSmb = C:\WINNT\SYSTEM32\DRIVERS\MRXSMB.SYS
NetBIOS = C:\WINNT\SYSTEM32\DRIVERS\NETBIOS.SYS
Rdbss = C:\WINNT\SYSTEM32\DRIVERS\RDBSS.SYS
Srv = C:\WINNT\SYSTEM32\DRIVERS\SRV.SYS