启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><; C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<HuaShanTGEUSBKbd><C:\Program Files\联想\联想键盘驱动\hidSevice.exe> []
<HuaShanTGEUSBKbd1><C:\Program Files\联想\联想键盘驱动\usbkbdriver.exe> []
<FAhid><C:\FWRITE\Fahid.exe> []
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Corporation Limited]
<NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit> [NVIDIA Corporation]
<RavTask><"C:\Program Files\rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup> [NVIDIA Corporation]
<stup.exe><C:\PROGRA~1\TENCENT\Adplus\stup.exe> [Tencent]
<RavScanBD><"C:\Program Files\rising\Rav\ScanBD.exe" /INST> [Beijing Rising Technology Co., Ltd.]
<KnightIII><; C:\Program Files\PP\PP.exe /A> [北京正乐佳公司]
<PP><; C:\Program Files\PP\PP.exe /A> [北京正乐佳公司]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\System32\Userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINDOWS\downlo~1\CnsHook.dll> [北京三七二一科技有限公司]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
<{1F6C0785-7225-4E1D-A783-723657076B66}><C:\WINDOWS\System32\Crogf.dll> []
<{ED1651B9-496F-4E83-9C1B-160307895439}><C:\WINDOWS\System32\Ivla.dll> []
<{352FBDA8-0A9B-4D91-9ED6-5BBC74B959B1}><C:\WINDOWS\System32\Pdrsmo.dll> []
<{2467B883-F0DF-4E07-AC44-CD9482941F73}><C:\WINDOWS\System32\Pwecbv.dll> []
<{E12E8A8F-DAC6-4AEC-90A8-0768DE14C24A}><C:\WINDOWS\System32\Rbrz.dll> []
<{36C61244-64A1-4928-A2F8-CEE23E68A945}><C:\WINDOWS\System32\Oasx.dll> []
<{A75F231C-FEE2-4FC9-A867-F0118F7CD38A}><C:\WINDOWS\System32\Begyyc.dll> []
<{CB346812-DF45-4744-A21E-3478FE0E2F04}><C:\WINDOWS\System32\Mxjln.dll> []
<{3E0CD483-211C-4128-8B32-378957606768}><C:\WINDOWS\System32\Rmcgms.dll> []
<{ED493F0C-411D-4F62-A557-276EE0422583}><C:\WINDOWS\System32\Ludj.dll> []
<{475E80C8-AF67-462E-A9E1-25447065FFA3}><C:\WINDOWS\System32\Ctgsed.dll> []
<{48584A93-7221-44DA-94C7-AD8682AC652D}><C:\WINDOWS\System32\Zaedu.dll> []
<{545FE59B-533D-449C-AD21-A4AA767267F3}><C:\WINDOWS\System32\Qbci.dll> []
<{F4730ABB-4773-45DE-8740-3A68F6F10319}><C:\WINDOWS\System32\Adqzle.dll> []
<{DC66257F-9321-450F-8481-C8A3D0859B8A}><C:\WINDOWS\System32\Taglk.dll> []
<{771E9CB8-616F-429B-B291-E41A136CF3EB}><C:\WINDOWS\System32\Eznqqc.dll> []
<{A16EEC82-5E73-4E58-99FC-5686523AF78B}><C:\WINDOWS\System32\Qyfiw.dll> []
<{8F48DAB7-9BD6-494F-BC88-9BFAE3E70560}><C:\WINDOWS\System32\Hymzy.dll> []
<{95BF9254-C972-4A47-AD85-96D0564186EB}><C:\WINDOWS\System32\Vnco.dll> []
<{4BB72A31-A63B-4A22-B02A-E4270B395657}><C:\WINDOWS\System32\Fljg.dll> []
<{360848FA-D48E-4CE2-97E1-1EBC8EEB5163}><C:\WINDOWS\System32\Etjfus.dll> []
<{D04887CA-1B12-4C8A-95FE-6C2C9028F283}><C:\WINDOWS\System32\Cvakg.dll> []
<{91AF748F-325A-4082-886D-479553F8C2B4}><C:\WINDOWS\System32\Dwnsze.dll> []
<{2CBB27BB-119E-4DAF-ACBE-86D3CC9988BE}><C:\WINDOWS\System32\Tnshgh.dll> []
<{FA55448F-F859-418F-B3E6-BF80C476D33B}><C:\WINDOWS\System32\Sriec.dll> []
<{E3558F33-788C-42FE-A045-F2AE28FEF364}><C:\WINDOWS\System32\Qlec.dll> []
<{8D824FA1-548B-4E87-9B62-36120CDFF9C4}><C:\WINDOWS\System32\Mapjpm.dll> []
<{81918E29-D5F6-43BA-8856-6AB7C6B718D9}><C:\WINDOWS\System32\Xxomy.dll> []
<{0CB2BDAA-61A0-4248-A4BB-F552CE70C348}><C:\WINDOWS\System32\Ubcwfh.dll> []
<{295A675D-559B-4065-BABF-6DD2E6C60CAD}><C:\WINDOWS\System32\Azlc.dll> []
<{AF288D47-8525-4971-ACEC-81C38A73D6A7}><C:\WINDOWS\System32\Wqjdf.dll> []
<{9978C77B-9764-4A1E-8E53-ADCB94AA8B9A}><C:\WINDOWS\System32\Xeipv.dll> []
<{36C56882-938B-439F-81E5-DEC22DDAACB8}><C:\WINDOWS\System32\Wjnsx.dll> []
<{82585B2E-20EF-48EF-BBAD-A06B201FC54F}><C:\WINDOWS\System32\Hsaka.dll> []
<{EB8A265B-278C-4F2B-BF30-16124327649B}><C:\WINDOWS\System32\Tsmu.dll> []
<{77C41EED-C074-44A5-80FA-7126BDACBF78}><C:\WINDOWS\System32\Qbfpe.dll> []
<{DEDDCF54-4748-46AA-9977-101955D56C0E}><C:\WINDOWS\System32\Rvrp.dll> []
<{8C5F7127-7FA8-4988-A7DE-179474B23790}><C:\WINDOWS\System32\Yumjc.dll> []
<{8D68EEF1-CB1D-4A1B-A43F-9F4EB4692F41}><C:\WINDOWS\System32\Dxsod.dll> []
<{2B526B9D-2CAF-4CB6-A892-21A1F3372591}><C:\WINDOWS\System32\Fhwy.dll> []
<{5D3D7B71-1145-4811-8A6F-5414AB93181B}><C:\WINDOWS\System32\Hwacgt.dll> []
<{456F3BB3-786E-4E9E-8DA4-6BA80406C068}><C:\WINDOWS\System32\Ucixod.dll> []
<{D7494F09-A3DE-48F1-87BF-DFCCB5707505}><C:\WINDOWS\System32\Xfbgv.dll> []
<{56D75C3B-AF8F-4411-8971-8D89C28A8B02}><C:\WINDOWS\System32\Aqdeqy.dll> []
<{503FBF1A-B8E7-402C-8F83-DC8FFBF49189}><C:\WINDOWS\System32\Ihwq.dll> []
<{264E86E5-3F1A-41E1-82ED-913F03537AF6}><C:\WINDOWS\System32\Dxci.dll> []
<{89C1B8E0-88EC-47A6-AF4C-C0C5F72D8F54}><C:\WINDOWS\System32\Qkfzgm.dll> []
<{FDFD90AD-C1BF-42BB-8E29-5B61D4C4B69C}><C:\WINDOWS\System32\Xkxzk.dll> []
<{B6C7E28D-BC7C-480D-89C9-5B32F9AA28B6}><C:\WINDOWS\System32\Extmxv.dll> []
<{4615A185-CADB-4E97-87D8-E6F6890B9B34}><C:\WINDOWS\System32\Gpahep.dll> []
<{64DD8931-BD32-477B-A42C-91C978A9F0E0}><C:\WINDOWS\System32\Qmpx.dll> []
<{192F92F2-6EE4-4DFE-B980-A11D574E1075}><C:\WINDOWS\System32\Kpzz.dll> []
<{4FB2D527-41EE-4682-A5FC-1EA7925F7E04}><C:\WINDOWS\System32\Szev.dll> []
<{83FE3298-60CA-4117-926D-F0847BAEEA3A}><C:\WINDOWS\System32\Dvgdl.dll> []
<{57F6CD5E-6A0A-4A7A-B383-C08FC46381C8}><C:\WINDOWS\System32\Kbuso.dll> []
<{3C6E5031-DE64-4334-8968-D06929A3BE8D}><C:\WINDOWS\System32\Uzaqrd.dll> []
<{FCB41E1F-45FA-4470-840D-42EF01FD5A97}><C:\WINDOWS\System32\Jiaiig.dll> []
<{FACBF952-7E3E-46F2-8370-382B44C6AA41}><C:\WINDOWS\System32\Vacd.dll> []
<{370DD67F-CF86-4205-A58B-8685BB7BB64A}><C:\WINDOWS\System32\Zodpum.dll> []
<{C8C7E3B3-7DBD-47DE-B7A9-41D737D56F32}><C:\WINDOWS\System32\Rjsiqe.dll> []
<{757E187D-6025-4C95-A347-B0CA067547E2}><C:\WINDOWS\System32\Hfvb.dll> []
<{821AFD11-1A2D-449A-BB4F-C04E350762BB}><C:\WINDOWS\System32\Cxmsvo.dll> []
<{A177E46E-F01D-463E-8A2A-4D13E8BF23F4}><C:\WINDOWS\System32\Mpmth.dll> []
<{7D08F07A-9B8F-452E-AC32-DAA10A6A9865}><C:\WINDOWS\System32\Rycc.dll> []
<{224E6ECC-D1B9-4B29-AD44-5836B5DCFA2B}><C:\WINDOWS\System32\Riqm.dll> []
<{CA1EECBA-7C71-42E6-930B-EF421BFCA1D1}><C:\WINDOWS\System32\Uyspn.dll> []
<{C0E670A4-F17C-457D-9B35-BE597E704857}><C:\WINDOWS\System32\Fheqjh.dll> []
<{100FD1A5-756B-4C73-9BC5-F1CDF49FA80B}><C:\WINDOWS\System32\Tdmnk.dll> []
<{75FC7DE8-081B-49A9-BB78-AB03F50A697F}><C:\WINDOWS\System32\Vnqq.dll> []
<{0FE6CCF1-086C-4C66-BFC6-7F63244DBB7D}><C:\WINDOWS\System32\Rdjspy.dll> []
<{E2D231AA-CB2F-4C65-B932-B3B10F951AB8}><C:\WINDOWS\System32\Exhhg.dll> []
<{C195A0B4-E90B-4C7C-9090-E4E4AEA54448}><C:\WINDOWS\System32\Rwkcvq.dll> []
<{43ACD31E-81C2-40D2-9C05-B306242F5577}><C:\WINDOWS\System32\Ntgo.dll> []
<{E3AEC09A-EE96-4E37-9998-E8CAFE0267EA}><C:\WINDOWS\System32\Pdlna.dll> []
<{8F2D7B9D-D167-402E-A362-2C0035EB388F}><C:\WINDOWS\System32\Pzqyo.dll> []
<{D1DFBAD5-EC2E-4F35-B99B-71D19DD829A8}><C:\WINDOWS\System32\Qknjc.dll> []
<{FFA5E5C0-DC5D-4A38-A3FC-B32F91C73D84}><C:\WINDOWS\System32\Ubjwg.dll> []
<{92E2940A-BC42-42D7-A9F4-3FF603CC606D}><C:\WINDOWS\System32\Apbl.dll> []
<{F8354710-CB9B-410E-A58A-E5145296A34A}><C:\WINDOWS\System32\Umxyyo.dll> []
<{C4B90DB8-6585-4EB4-AFB8-1F3AF2867044}><C:\WINDOWS\System32\Rfug.dll> []
<{92FF7B12-7694-45BF-A0C8-EE147A71F3F2}><C:\WINDOWS\System32\Rpkaqq.dll> []
<{84200AA1-288A-42B2-A6A7-D80DC9EA9DC5}><C:\WINDOWS\System32\Dhxoy.dll> []
<{9D528598-A588-4021-AC6C-88CD3F26CB6C}><C:\WINDOWS\System32\Hwacvi.dll> []
<{680C6495-95C6-4B4E-B904-63B2842A1436}><C:\WINDOWS\System32\Dkwcvw.dll> []
<{CB9405FA-CBEA-4205-9113-CF62BDD654CF}><C:\WINDOWS\System32\Jznckk.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ZGNotify]
<WinlogonNotify: ZGNotify><MyNotification.dll> []
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><D:\DOWNLO~1\_欧洲_~1\_欧洲_~1.SCR> []