启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTask><"D:\下载软件\杀毒工具\瑞星杀毒软件\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<Uninstallieup><D:\下载软件\安全工具\中文官方软件\ieup\Uninstall.exe /S> [N/A]
<!ewido><"C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized> [Anti-Malware Development a.s.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<RavStub><"D:\下载软件\杀毒工具\瑞星杀毒软件\Rising\Rav\ravstub.exe" /RUNONCE> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\SYSTEM32\Userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
==================================
启动文件夹
[河南网通宽带用户客户端]
<C:\Documents and Settings\家\「开始」菜单\程序\启动\河南网通宽带用户客户端.lnk --> C:\PROGRA~1\RACER-~1\racer.exe [Putian Runway]><N>
==================================
服务
[Layer Gateway / Ateway]
<C:\WINDOWS\system32\centat.exe><N/A>
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\system32\Ati2evxx.exe><N/A>
[Crypkey License / Crypkey License]
<crypserv.exe><Kenonic Controls Ltd.>
[ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard]
<C:\Program Files\ewido anti-spyware 4.0\guard.exe><Anti-Malware Development a.s.>
[Human Interface Device Access / HidServ]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Rising Process Communication Center / RsCCenter]
<D:\下载软件\杀毒工具\瑞星杀毒软件\RISING\RAV\CCENTER.EXE><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon]
<"D:\下载软件\杀毒工具\瑞星杀毒软件\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[service / service]
<C:\WINDOWS\schosts.exe><N/A>
[Transaction Coordinator / Transaction Coordinator]
<C:\WINDOWS\system32\bcwin><N/A>
==================================
驱动程序
[ati2mtaa / ati2mtaa]
<system32\DRIVERS\ati2mtaa.sys><ATI Technologies Inc.>
[Rising TDI Base Driver / BaseTDI]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[efibddfc / efibddfc]
<\??\C:\WINDOWS\system32\drivers\efibddfc.sys><N/A>
[ENUS_NDIS_DRIVER / ENUS_NDIS_DRIVER]
<\SystemRoot\system32\enusndis.sys><N/A>
[ExpScaner / ExpScaner]
<\??\D:\下载软件\杀毒工具\瑞星杀毒软件\Rising\Rav\ExpScan.sys><>
[HCF_MSFT / HCF_MSFT]
<system32\DRIVERS\HCF_MSFT.sys><Conexant>
[HookCont / HookCont]
<\??\D:\下载软件\杀毒工具\瑞星杀毒软件\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg]
<\??\D:\下载软件\杀毒工具\瑞星杀毒软件\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
<\??\D:\下载软件\杀毒工具\瑞星杀毒软件\Rising\Rav\HookSys.sys><Rising>
[jicacibc / jicacibc]
<\??\C:\WINDOWS\system32\drivers\jicacibc.sys><N/A>
[Keypro / Keypro]
<C:\WINDOWS\SYSTEM32\DRIVERS\Keypro.SYS><Microsoft Corporation>
[kmsinput / kmsinput]
<\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[MEMSCAN / MEMSCAN]
<\??\D:\下载软件\杀毒工具\瑞星杀毒软件\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[NetworkX / NetworkX]
<\SystemRoot\system32\ckldrv.sys><N/A>
[NetGroup Packet Filter Driver / NPF]
<system32\drivers\npf.sys><NetGroup - Politecnico di Torino>
[npkcrypt / npkcrypt]
<\??\D:\下载软件\常用工具\简体版2000C QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsAntiSpyware / RsAntiSpyware]
<\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[RSPPSYS / RSPPSYS]
<\??\D:\下载软件\杀毒工具\瑞星杀毒软件\RISING\RAV\RSPPSYS.sys><Rising>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
<system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv]
<system32\DRIVERS\secdrv.sys><N/A>
[Service for AC'97 Sample Driver (WDM) / SiS7012]
<system32\drivers\sis7012.sys><Silicon Integrated Systems Corporation>
[SIS AGP Bus Filter / sisagp]
<\SystemRoot\system32\DRIVERS\sisagp.sys><Silicon Integrated Systems Corporation>
[Superk53 / Superk53]
<\SystemRoot\System32\drivers\superk53.sys><Microsoft Corporation>
[Ufkey / Ufkey]
<C:\WINDOWS\SYSTEM32\DRIVERS\Ufkey.SYS><Microsoft Corporation>