+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 53. c:\windows\system32\bsmain.exe
[A ] 54. c:\windows\system32\kknative.exe
+ 映像劫持
+ HKCR\Folder\shell
Super Rabbit CDROM Eject
[A ] 55. c:\program files\super rabbit\magicset\srcd2.exe
+ HKCR\.html
htmlfile\Edit\Command
[A ] 56. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 56. c:\program files\microsoft office\office11\msohtmed.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 56. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 56. c:\program files\microsoft office\office11\msohtmed.exe
+ 打印机监控
+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
Microsoft Document Imaging Writer Monitor
[AM] 57. c:\windows\system32\mdimon.dll
+ 正在运行的进程
+ 000000bc(188) runiep.exe
00400000[00013000]
[AM] 51. c:\program files\rising\antispyware\runiep.exe
10000000[0006E000]
[ M] 58. c:\windows\system32\freewb.ime
00DC0000[00008000]
[ M] 59. c:\program files\freewb\plugin\date.plg
00F00000[0001B000]
[ M] 60. c:\program files\rising\antispyware\ieprot.dll
+ 000000f0(240) SOUNDMAN.EXE
00400000[00015000]
[AM] 48. c:\windows\soundman.exe
10000000[0006E000]
[ M] 58. c:\windows\system32\freewb.ime
00D80000[00008000]
[ M] 59. c:\program files\freewb\plugin\date.plg
00FA0000[0001B000]
[ M] 60. c:\program files\rising\antispyware\ieprot.dll
+ 00000148(328) alg.exe
+ 000001d0(464) wscntfy.exe
10000000[0006E000]
[ M] 58. c:\windows\system32\freewb.ime
00BC0000[00008000]
[ M] 59. c:\program files\freewb\plugin\date.plg
00BD0000[0001B000]
[ M] 60. c:\program files\rising\antispyware\ieprot.dll
+ 000001f8(504) srshut.EXE
00400000[00073000]
[ M] 61. c:\program files\super rabbit\magicset\srshut.exe
73390000[00154000]
[ M] 62. c:\windows\system32\msvbvm60.dll
66630000[0001C000]
[ M] 63. c:\windows\system32\vb6chs.dll
10000000[0006E000]
[ M] 58. c:\windows\system32\freewb.ime
00FC0000[00008000]
[ M] 59. c:\program files\freewb\plugin\date.plg
019C0000[0001B000]
[ M] 60. c:\program files\rising\antispyware\ieprot.dll
+ 0000021c(540) smss.exe
+ 00000224(548) ctfmon.exe
10000000[0006E000]
[ M] 58. c:\windows\system32\freewb.ime
00CA0000[00008000]
[ M] 59. c:\program files\freewb\plugin\date.plg
00CF0000[0001B000]
[ M] 60. c:\program files\rising\antispyware\ieprot.dll
+ 0000027c(636) csrss.exe
+ 00000294(660) winlogon.exe
10000000[0006E000]
[ M] 58. c:\windows\system32\freewb.ime
01520000[00008000]
[ M] 59. c:\program files\freewb\plugin\date.plg
72C80000[00008000]
[ M] 64. c:\windows\system32\msacm32.drv
+ 000002c0(704) services.exe
+ 000002cc(716) lsass.exe
+ 0000036c(876) svchost.exe
+ 000003ac(940) svchost.exe
+ 0000042c(1068) svchost.exe
+ 00000498(1176) svchost.exe
+ 00000524(1316) svchost.exe
+ 000005c4(1476) Explorer.EXE
10000000[0006E000]
[ M] 58. c:\windows\system32\freewb.ime
00D40000[00008000]
[ M] 59. c:\program files\freewb\plugin\date.plg
72C80000[00008000]
[ M] 64. c:\windows\system32\msacm32.drv
01C90000[0001B000]
[ M] 60. c:\program files\rising\antispyware\ieprot.dll
+ 000006f0(1776) spoolsv.exe
00AE0000[00008000]
[AM] 57. c:\windows\system32\mdimon.dll
00AF0000[00008000]
[ M] 65. c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
+ 00000768(1896) RfwMain.exe
00400000[00073000]
[AM] 50. c:\program files\rising\rfw\rfwmain.exe
26600000[0007D000]
[ M] 66. c:\program files\rising\rfw\rsguilib.dll
23700000[0001A000]
[ M] 67. c:\program files\rising\rfw\rscommon.dll
10000000[0000F000]
[ M] 68. c:\program files\rising\rfw\rfwctrl.dll
23800000[0001A000]
[ M] 69. c:\program files\rising\rfw\rsxml.dll
23900000[00031000]
[ M] 70. c:\program files\rising\rfw\pngdll.dll
731B0000[0000A000]
[ M] 71. c:\program files\rising\rfw\psapi.dll
01070000[0001B000]
[ M] 60. c:\program files\rising\antispyware\ieprot.dll
+ 0000085c(2140) svchost.exe
+ 00000950(2384) RsAgent.exe
00400000[0003A000]
[ M] 72. d:\瑞星杀毒\rising\rav\rsagent.exe
10000000[0001B000]
[ M] 73. d:\瑞星杀毒\rising\rav\rscommx.dll
00B60000[0006E000]
[ M] 58. c:\windows\system32\freewb.ime
00E50000[00008000]
[ M] 59. c:\program files\freewb\plugin\date.plg
00F70000[0001B000]
[ M] 60. c:\program files\rising\antispyware\ieprot.dll
+ 00000b40(2880) AgentSvr.exe
10000000[0006E000]
[ M] 58. c:\windows\system32\freewb.ime
00C30000[00008000]
[ M] 59. c:\program files\freewb\plugin\date.plg
72C80000[00008000]
[ M] 64. c:\windows\system32\msacm32.drv
00C90000[0001B000]
[ M] 60. c:\program files\rising\antispyware\ieprot.dll
+ 00000ba8(2984) Ras.exe
00400000[00160000]
[ M] 74. c:\program files\rising\antispyware\ras.exe
10000000[00013000]
[ M] 75. c:\program files\rising\antispyware\topsoft.dll
7C140000[00103000]
[ M] 76. c:\program files\rising\antispyware\mfc71.dll
7C340000[00056000]
[ M] 77. c:\program files\rising\antispyware\msvcr71.dll
7C3A0000[0007B000]
[ M] 78. c:\program files\rising\antispyware\msvcp71.dll
5D360000[0000A000]
[ M] 79. c:\windows\system32\mfc71chs.dll
00F20000[000BD000]
[ M] 80. c:\program files\rising\antispyware\rasgui.dll
01480000[0006E000]
[ M] 58. c:\windows\system32\freewb.ime
01770000[00008000]
[ M] 59. c:\program files\freewb\plugin\date.plg
01A30000[00011000]
[AM] 47. c:\windows\system32\shlhook.dll
01B90000[0001B000]
[ M] 60. c:\program files\rising\antispyware\ieprot.dll
02D30000[0002F000]
[ M] 81. c:\program files\rising\antispyware\engine.dll
02D60000[00012000]
[ M] 82. c:\program files\rising\antispyware\zip.dll
+ 00000f58(3928) RavStub.exe
00400000[00018000]
[ M] 83. d:\瑞星杀毒\rising\rav\ravstub.exe
10000000[0001B000]
[ M] 73. d:\瑞星杀毒\rising\rav\rscommx.dll
23700000[0001A000]
[ M] 84. d:\瑞星杀毒\rising\rav\rscommon.dll