Параметры автозапуска HIPS Касперского, которые не отслеживаются или частичное контролируются в Malware Defender
*\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon; VmApplet
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WOW\boot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WOW\NonWindowsApp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WOW\standard
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA\Monitors\*\CLSID
*\Control Panel\Desktop; SCRNSAVE.EXE
*\Software\Microsoft\Windows NT\CurrentVersion\Winlogon; UserInit
*\Software\Microsoft\Windows NT\CurrentVersion\Winlogon; System
*\Software\Microsoft\Windows NT\CurrentVersion\AEDebug; Debugger
*\Software\Microsoft\Windows NT\CurrentVersion\Winlogon; UIHost
*\Software\Microsoft\Windows NT\CurrentVersion\Winlogon; AppSetup
*\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\*; DllName
*\Software\Microsoft\Windows*\CurrentVersion\Run*
*\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
*\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\*\*
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\*\*
*\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon; Taskman
*\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\*
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MPRServices\*; DLLName
*\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\*Shell Folders\Common Startup
*\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\*Shell Folders\Start Menu
*\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\*Shell Folders\Common Start Menu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet???\Control\Session Manager\Environment
*\Software\Microsoft\Windows NT\CurrentVersion\Winlogon; GinaDLL
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers; VDD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet???\Control\SafeBoot; AlternateShell
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet???\Control\SafeBoot\Minimal\*; ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet???\Control\SafeBoot\Network\*; ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet???\Control\SafeBoot\Minimal\*\Parameters; ServiceDll
*\Software\Microsoft\Windows NT\CurrentVersion\Windows; load
*\Software\Microsoft\Windows NT\CurrentVersion\Windows; run
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet???\Control\SafeBoot\Network\*\Parameters; ServiceDll
*\SYSTEM\CONTROLSET???\CONTROL\SESSION MANAGER\SUBSYSTEMS; windows
*\SOFTWARE\MICROSOFT\INTERNET EXPLORER\PLUGINS\EXTENSION; location
*\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\TERMINAL SERVER\INSTALL\*
*\SOFTWARE\MICROSOFT\INTERNET EXPLORER\DESKTOP\COMPONENTS\*\*
*\SOFTWARE\MICROSOFT\INTERNET EXPLORER\PLUGINS\EXTENSION\*; location
*\Software\Microsoft\Windows NT\CurrentVersion\Extensions\*
*\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\*\Shell\*\command\*
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom; AutoRun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\CancelAutoplay\Files\*
*\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\*\*
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders^Common Startup%\*
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders^Common Startup%\*
%HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders^Startup%\*
%HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders^Startup%\*
%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SchedulingAgent^TasksFolder%\*
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet???\Control\Keyboard Layouts\*\*
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet???\Control\Session Manager\AppCertDlls\*
*\Software\Mirabilis\ICQ\Agent\Apps\*
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\ICQ*; Path
Добавлено: Итого получилось 67 дополнительных правил от Касперского+правила предложенные уважаемым xChe
http://dl.dropbox.com/u/39341929/Rules/autoruns_register.dat