+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay
[A ] 38. c:\program files\rising\antispyware\runonce.exe
Beijing Rising Technology Co., Ltd.
RunOnce Application
.text,.rdata,.data,.rsrc,
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 39. c:\windows\system32\bsmain.exe
Beijing Rising Technology Co., Ltd.
Rising Antivirus 2008
.text,.rdata,.data,.rsrc,.reloc,
[A ] 40. c:\windows\system32\kknative.exe
Beijing Rising Technology Co., Ltd.
NativeAp
.text,.data,.rsrc,.reloc,
+ 映像劫持
+ HKCR\.html
htmlfile\Edit\Command
[A ] 41. c:\program files\microsoft office\office\msohtmed.exe
Microsoft Corporation
Microsoft Office 2000 component
.text,.data,.idata,.rsrc,
htmlfile\Print\Command
[A ] 41. c:\program files\microsoft office\office\msohtmed.exe
Microsoft Corporation
Microsoft Office 2000 component
.text,.data,.idata,.rsrc,
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 41. c:\program files\microsoft office\office\msohtmed.exe
Microsoft Corporation
Microsoft Office 2000 component
.text,.data,.idata,.rsrc,
htmlfile\Print\Command
[A ] 41. c:\program files\microsoft office\office\msohtmed.exe
Microsoft Corporation
Microsoft Office 2000 component
.text,.data,.idata,.rsrc,
+ 打印机监控
+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
OLFax Ports
[AM] 42. c:\windows\system32\olfmnt40.dll
Microsoft Corporation
Symantec Fax Starter Edition Monitor DLL
.text,.data,.edata,.rsrc,.reloc,
+ 其他自启动项目
+ C:\Documents and Settings\user1\「开始」菜单\程序\启动
QQ游戏启动加速程序.lnk
[A ] 43. f:\qq游戏\qqgame\accel.exe
深圳市腾讯计算机系统有限公司
QQ游戏
.text,.rdata,.data,.rsrc,
+ 正在运行的进程
+ 000000cc(204) SOUNDMAN.EXE
00400000[00014000]
[AM] 32. c:\windows\soundman.exe
Realtek Semiconductor Corp.
Realtek Sound Manager
.text,.rdata,.data,.rsrc,
10000000[0001B000]
[ M] 44. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
01260000[00011000]
[ M] 45. c:\herosoft\herov8\vcvtshell.dll
herosoft
VCvtShell
.text,.rdata,.data,.rsrc,.reloc,
+ 00000110(272) SYSEXPLR.EXE
00400000[00015000]
[AM] 34. c:\herosoft\herov8\sysexplr.exe
.text,.rdata,.data,.idata,.rsrc,.reloc,
00370000[00022000]
[ M] 46. c:\herosoft\herov8\avcdrom.dll
.text,.rdata,.data,.idata,.reloc,
10000000[00014000]
[ M] 47. c:\herosoft\herov8\coolmenu.dll
.text,.rdata,.data,.idata,.rsrc,.reloc,
016C0000[00006000]
[ M] 48. c:\herosoft\herov8\sys936.dll
.rsrc,.reloc,
018A0000[0001B000]
[ M] 44. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
01A00000[00011000]
[ M] 45. c:\herosoft\herov8\vcvtshell.dll
herosoft
VCvtShell
.text,.rdata,.data,.rsrc,.reloc,
+ 00000178(376) runiep.exe
00400000[00013000]
[AM] 36. c:\program files\rising\antispyware\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
00DA0000[0001B000]
[ M] 44. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
10000000[0001E000]
[AM] 22. c:\program files\360safe\safemon\safemon.dll
360安全卫士实时保护模块
.text,.rdata,.data,.share,.rsrc,.reloc,
00D70000[00011000]
[ M] 45. c:\herosoft\herov8\vcvtshell.dll
herosoft
VCvtShell
.text,.rdata,.data,.rsrc,.reloc,
+ 000001a0(416) RavTask.exe
00400000[00034000]
[AM] 37. c:\program files\rising\rav\ravtask.exe
Beijing Rising Technology Co., Ltd.
RavTimer
.text,.rdata,.data,.rsrc,
10000000[0001F000]
[ M] 49. c:\program files\rising\rav\proccom.dll
Beijing Rising Technology Co., Ltd.
ProcessC Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00A40000[00024000]
[ M] 50. c:\program files\rising\rav\rscommx2.dll
Beijing Rising Technology Co., Ltd.
RsCommX2
.text,.rdata,.data,.rsrc,.reloc,
23700000[00028000]
[ M] 51. c:\program files\rising\rav\rscommon.dll
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00CA0000[0000E000]
[ M] 52. c:\program files\rising\rav\rsappmgr.dll
Beijing Rising Technology Co., Ltd.
Rising Application Manager
.text,.rdata,.data,.rsrc,.reloc,
08CC0000[0002F000]
[ M] 53. c:\program files\rising\rav\cfgdll.dll
Beijing Rising Technology Co., Ltd.
CfgDll
.text,.rdata,.data,.rsrc,.reloc,
08FB0000[0001B000]
[ M] 44. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 000001b0(432) smss.exe
+ 000001d4(468) Ravmon.exe
00400000[0008B000]
[ M] 54. c:\program files\rising\rav\ravmon.exe
Beijing Rising Technology Co., Ltd.
Rising realtime monitor shell
.text,.rdata,.data,.rsrc,
7C140000[00103000]
[ M] 55. c:\windows\system32\mfc71.dll
Microsoft Corporation
MFCDLL Shared Library - Retail Version
.text,.data,.rsrc,.reloc,
7C340000[00056000]
[ M] 56. c:\windows\system32\msvcr71.dll
Microsoft Corporation
Microsoft? C Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
7C3A0000[0007B000]
[ M] 57. c:\windows\system32\msvcp71.dll
Microsoft Corporation
Microsoft? C++ Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
10000000[0001F000]
[ M] 49. c:\program files\rising\rav\proccom.dll
Beijing Rising Technology Co., Ltd.
ProcessC Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00B80000[00024000]
[ M] 50. c:\program files\rising\rav\rscommx2.dll
Beijing Rising Technology Co., Ltd.
RsCommX2
.text,.rdata,.data,.rsrc,.reloc,
23700000[00028000]
[ M] 51. c:\program files\rising\rav\rscommon.dll
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00DD0000[00027000]
[ M] 58. c:\program files\rising\rav\recomp.dll
Beijing Rising Technology Co., Ltd.
component manager Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00E10000[0002E000]
[ M] 59. c:\program files\rising\rav\refs.dll
Beijing Rising Technology Co., Ltd.
filesystem Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00E50000[0002C000]
[ M] 60. c:\program files\rising\rav\viruslib.dll
Beijing Rising Technology Co., Ltd.
VirusLib Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00E90000[00027000]
[ M] 61. c:\program files\rising\rav\relibldr.dll
Beijing Rising Technology Co., Ltd.
libloader Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00F10000[0000E000]
[ M] 52. c:\program files\rising\rav\rsappmgr.dll
Beijing Rising Technology Co., Ltd.
Rising Application Manager
.text,.rdata,.data,.rsrc,.reloc,
00F30000[0002F000]
[ M] 53. c:\program files\rising\rav\cfgdll.dll
Beijing Rising Technology Co., Ltd.
CfgDll
.text,.rdata,.data,.rsrc,.reloc,
01090000[00075000]
[ M] 62. c:\program files\rising\rav\monrule.dll
Beijing Rising Technology Co., Ltd.
MonRule
.text,.rdata,.data,.rsrc,.reloc,
23900000[00040000]
[ M] 63. c:\program files\rising\rav\pngdll.dll
Beijing Rising Technology Co., Ltd.
Rising .Png File Loader Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
26600000[000B4000]
[ M] 64. c:\program files\rising\rav\rsguilib.dll
Beijing Rising Technology Co., Ltd.
Rising GUI Library Loader
.text,.rdata,.data,.rsrc,.reloc,
23800000[00018000]
[ M] 65. c:\program files\rising\rav\rsxml.dll
Beijing Rising Technology Co., Ltd.
RsXML
.text,.rdata,.data,.rsrc,.reloc,
026E0000[0001B000]
[ M] 44. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,