+ 用户登陆自运行项目
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
RavTask
[A ] 72. c:\program files\rising\rav\ravtask.exe
runeip
[AM] 73. c:\program files\rising\kakatoolbar\runiep.exe
BigDog303
[AM] 74. c:\windows\vm303_sti.exe
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay
[A ] 75. c:\program files\rising\kakatoolbar\runonce.exe
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 76. c:\windows\system32\bsmain.exe
[A ] 77. c:\windows\system32\kknative.exe
+ 映像劫持
+ HKCR\.exe
exefile\启用/禁用数字签名图标\Command
[A ] 78. c:\windows\system32\acsignopt.exe
+ HKCR\.html
htmlfile\Edit\Command
[A ] 79. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 79. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\TencentTraveler\Command
[A ] 80. c:\program files\tencent\tt\ttraveler.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 79. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 79. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\TencentTraveler\Command
[A ] 80. c:\program files\tencent\tt\ttraveler.exe
+ 打印机监控
+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
Microsoft Document Imaging Writer Monitor
[AM] 81. c:\windows\system32\mdimon.dll
+ 正在运行的进程
+ 00000178(376) RavStub.exe
00400000[00018000]
[ M] 82. c:\program files\rising\rav\ravstub.exe
10000000[0001B000]
[ M] 83. c:\program files\rising\rav\rscommx.dll
23700000[0001A000]
[ M] 84. c:\program files\rising\rav\rscommon.dll
+ 00000308(776) CDAC11BA.EXE
00400000[00012000]
[AM] 3. c:\windows\system32\drivers\cdac11ba.exe
+ 00000354(852) nvsvc32.exe
00400000[00027000]
[AM] 7. c:\windows\system32\nvsvc32.exe
+ 0000035c(860) smss.exe
+ 000003a0(928) csrss.exe
+ 000003b8(952) winlogon.exe
72C80000[00008000]
[ M] 85. c:\windows\system32\msacm32.drv
+ 000003e4(996) services.exe
47260000[0000F000]
[ M] 86. c:\windows\apppatch\acadproc.dll
+ 000003f0(1008) lsass.exe
+ 00000488(1160) svchost.exe
+ 000004c4(1220) svchost.exe
+ 000004e8(1256) p2psvr.exe
00400000[00016000]
[AM] 9. c:\program files\common files\sogou pxp\p2psvr.exe
10000000[00062000]
[ M] 87. c:\program files\sogou pxp\vodsvr.dll
65100000[00029000]
[ M] 88. c:\program files\sogou pxp\pxpnet.dll
00BC0000[00040000]
[ M] 89. c:\program files\sogou pxp\p2pclient.dll
+ 0000052c(1324) svchost.exe
+ 000005b4(1460) svchost.exe
+ 000005bc(1468) svchost.exe
+ 00000624(1572) svchost.exe
+ 000006d4(1748) Ras.exe
00400000[0013F000]
[ M] 90. c:\program files\rising\kakatoolbar\ras.exe
10000000[000A3000]
[ M] 91. c:\program files\rising\kakatoolbar\rasgui.dll
015E0000[0001B000]
[ M] 92. c:\program files\rising\kakatoolbar\ieprot.dll
02880000[00019000]
[ M] 93. c:\program files\rising\rav\ravscrch.dll
73900000[0002D000]
[ M] 94. c:\windows\system32\jpwb.ime
+ 0000075c(1884) spoolsv.exe
00D60000[00008000]
[AM] 81. c:\windows\system32\mdimon.dll
00DF0000[00008000]
[ M] 95. c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
+ 000007a4(1956) VM303_STI.EXE
00400000[00013000]
[AM] 74. c:\windows\vm303_sti.exe
10000000[0001B000]
[ M] 92. c:\program files\rising\kakatoolbar\ieprot.dll
+ 0000080c(2060) svchost.exe
00AA0000[00090000]
[AM] 13. c:\windows\system32\iqxdm.dll
+ 00000b00(2816) alg.exe
+ 00000b2c(2860) Explorer.EXE
62830000[00026000]
[AM] 68. c:\windows\system32\acsignicon.dll
10000000[0001B000]
[AM] 65. c:\windows\system32\ravext.dll
00DE0000[00011000]
[AM] 70. c:\windows\system32\shlhook.dll
00F30000[00014000]
[ M] 96. c:\windows\system32\735q9kccj.dll
60D00000[00039000]
[ M] 97. c:\program files\common files\autodesk shared\acsigncore16.dll
01D90000[0000C000]
[AM] 48. c:\program files\adobe\acrobat 6.0\reader\activex\acroiehelper.dll
01DA0000[00106000]
[AM] 51. c:\windows\system32\lsyfmu.dll
025D0000[0001B000]
[ M] 92. c:\program files\rising\kakatoolbar\ieprot.dll
164A0000[00023000]
[AM] 71. c:\windows\system32\wpdshserviceobj.dll
109C0000[0002C000]
[ M] 98. c:\windows\system32\portabledevicetypes.dll
10930000[00049000]
[ M] 99. c:\windows\system32\portabledeviceapi.dll
72C80000[00008000]
[ M] 85. c:\windows\system32\msacm32.drv
03620000[00721000]
[AM] 63. c:\windows\system32\nvcpl.dll
01410000[00036000]
[ M] 100. c:\windows\system32\nvrszhc.dll
01490000[00073000]
[AM] 64. c:\windows\system32\nvshell.dll
+ 00000bf0(3056) runiep.exe
00400000[00012000]
[AM] 73. c:\program files\rising\kakatoolbar\runiep.exe
00C00000[0001B000]
[ M] 92. c:\program files\rising\kakatoolbar\ieprot.dll
+ 00000c0c(3084) ctfmon.exe
10000000[0001B000]
[ M] 92. c:\program files\rising\kakatoolbar\ieprot.dll
+ 00000c84(3204) iexplore.exe
62830000[00026000]
[AM] 68. c:\windows\system32\acsignicon.dll
10000000[0037F000]
[AM] 45. c:\program files\google\googletoolbar1.dll
10930000[00049000]
[ M] 99. c:\windows\system32\portabledeviceapi.dll
01D70000[00019000]
[AM] 46. c:\program files\thunder network\webthunder\webthunderbho_now.dll
01DA0000[00015000]
[AM] 47. c:\windows\system32\xunleibho_v11.dll
01DC0000[0000C000]
[AM] 48. c:\program files\adobe\acrobat 6.0\reader\activex\acroiehelper.dll
01DD0000[0002B000]
[AM] 49. c:\program files\common files\cpush\cpush.dll
02150000[0002B000]
[AM] 50. c:\documents and settings\all users\application data\microsoft\pctools\pctools.dll
02290000[00106000]
[AM] 51. c:\windows\system32\lsyfmu.dll
04400000[0001B000]
[ M] 92. c:\program files\rising\kakatoolbar\ieprot.dll
325C0000[00012000]
[AM] 62. c:\program files\microsoft office\office11\msohev.dll
05120000[00019000]
[ M] 93. c:\program files\rising\rav\ravscrch.dll
73900000[0002D000]
[ M] 94. c:\windows\system32\jpwb.ime
30000000[002EF000]
[ M] 101. c:\windows\system32\macromed\flash\flash9c.ocx
72C80000[00008000]
[ M] 85. c:\windows\system32\msacm32.drv
090E0000[00035000]
[ M] 102. c:\windows\system32\xpsp3res.dll
+ 00000e94(3732) GoogleToolbarNotifier.exe
00400000[0002C000]
[ M] 103. c:\program files\google\googletoolbarnotifier\1.2.1128.5462\googletoolbarnotifier.exe
00F00000[00042000]
[ M] 104. c:\program files\google\googletoolbarnotifier\1.2.1128.5462\swg.dll
01160000[0001B000]
[ M] 92. c:\program files\rising\kakatoolbar\ieprot.dll
10000000[0000E000]
[ M] 105. c:\program files\google\googletoolbarnotifier\1.2.1128.5462\res_zh-tw.dll
"A.ûekp@bbs.ikaka.comµ¡Ýí<¾)