IE辅助对象BHO信息:
200 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
<{7369D35A-5B70-4A5B-B789-B25FE09B4AF3}><C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll>
IE右键菜单信息:
201 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<使用WEB迅雷下载><C:\Program Files\Thunder Network\WebThunder\GetUrl.htm>
202 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<使用WEB迅雷下载全部链接><C:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm>
203 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<使用迅雷下载><C:\Program Files\Thunder Network\Thunder\Program\geturl.htm>
204 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<使用迅雷下载全部链接><C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm>
205 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt]
<添加到QQ表情><C:\Program Files\Tencent\QQ\AddEmotion.htm>
IE工具栏项信息:
206 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
<{962EFB8E-2683-42d4-AC74-AAA4C759B9C6}><
http://my.xunlei.com>
ActiveX对象DPF信息:
207 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]
<DirectAnimation Java Classes><>
208 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]
<Microsoft XML Parser for Java><>
209 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]
<{05317530-B882-449D-9421-18D94FA3ED34}><C:\WINDOWS\OSInfo.ocx>
210 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]
<{16095503-786F-4097-AED6-5D567A26D760}><C:\WINDOWS\SiS_OCX.ocx>
211 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]
<{17492023-C23A-453E-A040-C7C580BBF700}><C:\WINDOWS\system32\legitcheckcontrol.dll>
212 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]
<{33564D57-9980-0010-8000-00AA00389B71}><>
213 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]
<{78ABDC59-D8E7-44D3-9A76-9A0918C52B4A}><C:\WINDOWS\Downloaded Program Files\downloader.dll>
214 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]
<{C01170CC-AF05-46C3-88BC-2C120DCEE288}><C:\WINDOWS\DOWNLO~1\IMTVPL~1.OCX>
215 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units]
<{D27CDB6E-AE6D-11CF-96B8-444553540000}><C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx>
网络服务SPI信息:
无可疑
映像劫持IFEO信息:
216 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
<Your Image File Name Here without a path><C:\WINDOWS\system32\ntsd -d>
系统服务信息:
217 [ COM+ System Application | COMSysApp | 停用 ]
c:\windows\system32\dllhost.exe /processid:{02d4b3f1-fd88-11d1-960d-00805fc79235}
218 [ Human Interface Device Access | HidServ | 停用 ]
c:\windows\system32\svchost.exe - c:\windows\system32\hidserv.dll
219 [ Rising Proxy Service | RfwProxySrv | 启动 ]
c:\program files\rising\rfw\rfwproxy.exe
220 [ Rising Personal Firewall Service | RfwService | 启动 ]
c:\program files\rising\rfw\rfwsrv.exe
221 [ Rising Process Communication Center | RsCCenter | 启动 ]
c:\program files\rising\rav\ccenter.exe
222 [ Rising RealTime Monitor | RsRavMon | 停用 ]
c:\program files\rising\rav\ravmond.exe
223 [ MS Software Shadow Copy Provider | SwPrv | 停用 ]
c:\windows\system32\dllhost.exe /processid:{149d4de2-464f-4e0b-890f-e13d41087483}
系统驱动信息:
224 [ Rising TDI Base Driver | BaseTDI | 停用 ]
c:\windows\system32\drivers\basetdi.sys
225 [ BeatTrojanHelperOne | BeatTrojanHelperOne | 停用 ]
c:\program files\beattrojan\beattrojanhelperone.sys
226 [ cqrthuu | cqrthuu6 | 停用 ]
c:\windows\system32\drivers\cqrthuu6.sys
227 [ FTCkillfile | FTCkillfile | 停用 ]
c:\windows\system32\drivers\ftckillfile.sys
228 [ FTCProtect | FTCProtect | 停用 ]
c:\windows\system32\drivers\ftcprotect.sys
229 [ FTCProTime | FTCProTime | 停用 ]
c:\windows\system32\drivers\ftcprotime.sys
230 [ HookCont | HookCont | 启动 ]
C:\WINDOWS\system32\drivers\hookcont.sys
231 [ HookNtos | HookNtos | 启动 ]
C:\WINDOWS\system32\drivers\hookntos.sys
232 [ HookReg | HookReg | 启动 ]
C:\WINDOWS\system32\drivers\hookreg.sys
233 [ hooksys | hooksys | 启动 ]
C:\WINDOWS\system32\drivers\hooksys.sys
234 [ HookUrl | HookUrl | 启动 ]
c:\program files\rising\rfw\hookurl.sys
235 [ New0 | New0 | 停用 ]
c:\windows\system32\new.sys
236 [ npkcrypt | npkcrypt | 停用 ]
c:\windows\system32\npkcrypt.sys
237 [ npkycryp | npkycryp | 停用 ]
c:\windows\system32\npkycryp.sys
238 [ Ntdfdisk | Ntdfdisk | 停用 ]
c:\windows\system32\drivers\ntrapi.sys
239 [ LENOVO USB Serial Driver | PhSerUsb | 停用 ]
c:\windows\system32\drivers\lenovoserusb.sys
240 [ QKeyServiceDisplay | QKeyService | 启动 ]
c:\windows\system32\keycrypt.sys
241 [ Rising Rfwbase Driver | RfwBase | 启动 ]
c:\windows\system32\drivers\rfwbase.sys
242 [ RsAntiSpyware | RsAntiSpyware | 启动 ]
c:\windows\system32\drivers\rsboot.sys
243 [ RsFwDrv | RsFwDrv | 启动 ]
c:\program files\rising\rfw\rsfwdrv.sys
244 [ RsNTGDI | RsNTGDI | 启动 ]
c:\windows\system32\drivers\rsntgdi.sys
245 [ TCP/IP Protocol Driver | Tcpip | 启动 ]
c:\windows\system32\drivers\tcpip.sys
246 [ TesSafe | TesSafe | 停用 ]
c:\windows\system32\tessafe.sys
已经加载的驱动信息:
247 C:\WINDOWS\system32\drivers\rsboot.sys
248 C:\WINDOWS\system32\drivers\rsntgdi.sys
249 C:\WINDOWS\system32\drivers\keycrypt.sys
250 C:\WINDOWS\system32\drivers\tcpip.sys
251 c:\program files\rising\rfw\rsfwdrv.sys
252 c:\program files\rising\rfw\rfwhelp.sys
253 C:\WINDOWS\system32\drivers\hooksys.sys
254 C:\WINDOWS\system32\drivers\hookhelp.sys
255 C:\WINDOWS\system32\drivers\hookreg.sys
256 C:\WINDOWS\system32\drivers\hookntos.sys
257 C:\WINDOWS\system32\drivers\hookcont.sys
258 C:\WINDOWS\system32\drivers\dump_atapi.sys
259 C:\WINDOWS\system32\drivers\dump_wmilib.sys
260 C:\WINDOWS\system32\drivers\rfwbase.sys
261 c:\program files\rising\rfw\hookurl.sys