HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ NvCplDaemonNVIDIA Display Properties ExtensionNVIDIA Corporationc:\windows\system32\nvcpl.dll
+ RavMonFile not found: E:\SECURITY\RAV2005\RAVMON.EXE
+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.e:\security\rising\rav\ravtask.exe
C:\Documents and Settings\Amazing holy\「开始」菜单\程序\启动
+ HoeKey.lnke:\system\hoekey\hoekey.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
+ SystemSafetyMonitorMaster ModuleSystem Safetye:\security\system safety monitor 2.0\syssafe.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
+ Rising Execute File Exts hookRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ ThunderIEHelper Classxunleibho Modulec:\windows\system32\xunleibho_v4.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ 腾讯QQQQTENCENTe:\net\qq 2005珊瑚虫\qq.exe
Task Scheduler
+ DDD_Install_Program.jobremotesetupduduc:\documents and settings\amazing holy\local settings\temp\remotesetup.exe
HKLM\System\CurrentControlSet\Services
+ NVSvcProvides system and desktop level support to the NVIDIA display driverNVIDIA Corporationc:\windows\system32\nvsvc32.exe
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Co., Ltd.e:\security\rising\rfw\rfwsrv.exe
+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.e:\security\rising\rav\ccenter.exe
+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.e:\security\rising\rav\ravmond.exe
HKLM\System\CurrentControlSet\Services
+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\windows\system32\drivers\basetdi.sys
+ BRPPPOEc:\windows\system32\drivers\brpppoe.sys
+ cwcspudBlackGold II 5.1 Family PCI WDM Audio DriverTOGO Technology Co.,Ltd.c:\windows\system32\drivers\cwcspud.sys
+ cwcwdmBlackGold II 5.1 Family PCI WDM Audio DriverTOGO Technology Co.,Ltd.c:\windows\system32\drivers\cwcwdm.sys
+ dtscsic:\windows\system32\drivers\dtscsi.sys
+ ExpScanerExpScan.syse:\security\rising\rav\expscan.sys
+ HookContTDI HOOK DriverRising tech Co. ltde:\security\rising\rav\hookcont.sys
+ HookRege:\security\rising\rav\hookreg.sys
+ HookSysHooksysRisinge:\security\rising\rav\hooksys.sys
+ kmsinputc:\windows\system32\drivers\kmsinput.sys
+ MEMSCANMemScan Driver瑞星软件有限公司e:\security\rising\rav\memscan.sys
+ mProcRsRising Personal FireWall mprocrs.sysBeijing Rising Technology Co., Ltd.e:\security\rising\rfw\mprocrs.sys
+ nvNVIDIA Compatible Windows 2000 Miniport Driver, Version 77.76 NVIDIA Corporationc:\windows\system32\drivers\nv4_mini.sys
+ pfcPadus(R) ASPI ShellPadus, Inc.c:\windows\system32\drivers\pfc.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys
+ RsFwDrvnt_fwdrvBeijing Rising Technology Co., Ltd.e:\security\rising\rfw\rsfwdrv.sys
+ rtl8139Realtek RTL8139 NDIS 5.0 DriverRealtek Semiconductor Corporationc:\windows\system32\drivers\rtl8139.sys
+ safemonSystem Safety Monitor 2.0 extension for Windows security layerSystem Safetyc:\windows\system32\drivers\safemon.sys
+ SecdrvSafeDisc driverc:\windows\system32\drivers\secdrv.sys
+ sfdrv01StarForce Protection Environment DriverProtection Technologyc:\windows\system32\drivers\sfdrv01.sys
+ sfhlp02StarForce Protection Helper DriverProtection Technologyc:\windows\system32\drivers\sfhlp02.sys
+ sfsync02StarForce Protection Synchronization DriverProtection Technologyc:\windows\system32\drivers\sfsync02.sys
+ sfvfs02StarForce Protection VFS DriverProtection Technologyc:\windows\system32\drivers\sfvfs02.sys
+ sptdc:\windows\system32\drivers\sptd.sys
+ UnlockerDriver4e:\system\unlocker\unlockerdriver4.sys
+ ZSMC301bVideo streaming and Capture Device DriverVMc:\windows\system32\drivers\usbvm31b.sys
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
+ taskmgr.exeSysinternals Process ExplorerSysinternalse:\security\processexplorer\procexp.exe