+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 32. c:\windows\system32\bsmain.exe
Beijing Rising Technology Co., Ltd.
BootScan
.text,.data,.rsrc,.reloc,
[A ] 33. c:\windows\system32\kknative.exe
Beijing Rising Technology Co., Ltd.
NativeAp
.text,.data,.rsrc,.reloc,
+ 打印机监控
+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
EPSON V3 2KMonitor59
[AM] 34. c:\windows\system32\e_sl2059.dll
SEIKO EPSON CORPORATION
EPSON Bidirectional Monitor
.text,.data,.rsrc,.reloc,
EPSON V3 2KMonitor60
[AM] 35. c:\windows\system32\e_sl2060.dll
SEIKO EPSON CORPORATION
EPSON Bidirectional Monitor
.text,.data,.rsrc,.reloc,
EPSON V5 2KMonitor
[AM] 36. c:\windows\system32\ebpmon2.dll
SEIKO EPSON CORPORATION
EPSON Bidirectional Monitor
.text,.data,.rsrc,.reloc,
+ 其他自启动项目
+ C:\Documents and Settings\All Users\「开始」菜单\程序\启动
EPSON Status Monitor 3 Environment Check(3).lnk
[A ] 37. c:\windows\system32\spool\drivers\w32x86\3\e_srcv03.exe
SEIKO EPSON CORPORATION
StatusMonitor3 Environment Check
.text,.rdata,.data,.rsrc,
+ 正在运行的进程
+ 0000010c(268) wdfmgr.exe
01000000[0000C000]
[AM] 4. c:\windows\system32\wdfmgr.exe
Microsoft Corporation
Windows User Mode Driver Manager
.text,.data,.rsrc,
+ 00000198(408) smss.exe
+ 000001d8(472) ctfmon.exe
10000000[0001B000]
[ M] 38. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 0000020c(524) Ras.exe
00400000[00160000]
[ M] 39. c:\program files\rising\antispyware\ras.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware
.text,.rdata,.data,.rsrc,
10000000[00013000]
[ M] 40. c:\program files\rising\antispyware\topsoft.dll
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware TopSoft
.text,.rdata,.data,.rsrc,.reloc,
7C140000[00103000]
[ M] 41. c:\program files\rising\antispyware\mfc71.dll
Microsoft Corporation
MFCDLL Shared Library - Retail Version
.text,.data,.rsrc,.reloc,
7C340000[00056000]
[ M] 42. c:\program files\rising\antispyware\msvcr71.dll
Microsoft Corporation
Microsoft? C Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
7C3A0000[0007B000]
[ M] 43. c:\program files\rising\antispyware\msvcp71.dll
Microsoft Corporation
Microsoft? C++ Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
00E10000[000BD000]
[ M] 44. c:\program files\rising\antispyware\rasgui.dll
Beijing Rising Technology Co., Ltd.
RasGUI
.text,.rdata,.data,.rsrc,.reloc,
01510000[00011000]
[AM] 28. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,
01540000[0001B000]
[AM] 26. c:\windows\system32\ravext.dll
Beijing Rising Technology Co., Ltd.
Rising Shell Ext Module
.text,.rdata,.data,.rsrc,.reloc,
015D0000[0001B000]
[ M] 38. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
02DD0000[0002F000]
[ M] 45. c:\program files\rising\antispyware\engine.dll
Beijing Rising Technology Co., Ltd.
kaka engine
.text,.rdata,.data,.rsrc,.reloc,
01A60000[00012000]
[ M] 46. c:\program files\rising\antispyware\zip.dll
rising
zip
UPX0,UPX1,.rsrc,
022A0000[00019000]
[ M] 47. c:\program files\rising\rav\ravscrch.dll
Beijing Rising Technology Co., Ltd.
RavScrCh Module
.text,.rdata,.data,.rsrc,.reloc,
+ 0000029c(668) csrss.exe
+ 000002b8(696) winlogon.exe
10000000[00010000]
[AM] 21. c:\windows\system32\ati2evxx.dll
ATI Technologies Inc.
ATI External Event Utility DLL Module
.text,.rdata,.data,.rsrc,.reloc,
72C80000[00008000]
[ M] 48. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
+ 000002e8(744) services.exe
+ 000002f4(756) lsass.exe
+ 00000390(912) Ati2evxx.exe
00400000[00061000]
[AM] 1. c:\windows\system32\ati2evxx.exe
ATI Technologies Inc.
ATI External Event Utility EXE Module
.text,.rdata,.data,.rsrc,
003E0000[0000F000]
[ M] 49. c:\windows\system32\ati2edxx.dll
ATI Technologies, Inc.
ati2edxx
.text,.data,.SHAREDS,.rsrc,.reloc,
+ 0000039c(924) svchost.exe
+ 000003ec(1004) svchost.exe
+ 00000464(1124) alg.exe
+ 00000470(1136) svchost.exe
50E60000[0000C000]
[ M] 50. c:\windows\system32\wups2.dll
Microsoft Corporation
Windows Update client proxy stub 2
.text,.orpc,.data,.rsrc,.reloc,
+ 000004d4(1236) svchost.exe
+ 00000510(1296) svchost.exe
+ 00000630(1584) Ati2evxx.exe
00400000[00061000]
[AM] 1. c:\windows\system32\ati2evxx.exe
ATI Technologies Inc.
ATI External Event Utility EXE Module
.text,.rdata,.data,.rsrc,
003E0000[0000F000]
[ M] 49. c:\windows\system32\ati2edxx.dll
ATI Technologies, Inc.
ati2edxx
.text,.data,.SHAREDS,.rsrc,.reloc,
10000000[0001B000]
[ M] 38. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 00000678(1656) Explorer.EXE
72C80000[00008000]
[ M] 48. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
018C0000[0005B000]
[AM] 23. c:\program files\common files\adobe\acrobat\activex\pdfshell.dll
Adobe Systems, Inc.
PDF Shell Extension
.text,.orpc,.rdata,.data,.rsrc,.reloc,
01940000[0004C000]
[ M] 51. c:\program files\common files\adobe\acrobat\activex\pdfshell.chs
Adobe Systems, Inc.
PDF Shell Extension
.rsrc,.reloc,
019D0000[0001B000]
[ M] 38. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
015D0000[0001B000]
[AM] 26. c:\windows\system32\ravext.dll
Beijing Rising Technology Co., Ltd.
Rising Shell Ext Module
.text,.rdata,.data,.rsrc,.reloc,
01110000[0002E000]
[AM] 25. c:\program files\winrar\rarext.dll
.text,.data,.tls,.idata,.edata,.rsrc,.reloc,
23700000[0001A000]
[ M] 52. c:\program files\rising\rav\rscommon.dll
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
10000000[00011000]
[AM] 28. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,
+ 000006f4(1780) spoolsv.exe
50400000[00011000]
[AM] 34. c:\windows\system32\e_sl2059.dll
SEIKO EPSON CORPORATION
EPSON Bidirectional Monitor
.text,.data,.rsrc,.reloc,
00AE0000[00011000]
[AM] 35. c:\windows\system32\e_sl2060.dll
SEIKO EPSON CORPORATION
EPSON Bidirectional Monitor
.text,.data,.rsrc,.reloc,
00B00000[00012000]
[AM] 36. c:\windows\system32\ebpmon2.dll
SEIKO EPSON CORPORATION
EPSON Bidirectional Monitor
.text,.data,.rsrc,.reloc,
+ 000007e4(2020) RavStub.exe
00400000[00018000]
[ M] 53. c:\program files\rising\rav\ravstub.exe
Beijing Rising Technology Co., Ltd.
Rising RavStub
.text,.rdata,.data,.rsrc,
10000000[0001B000]
[ M] 54. c:\program files\rising\rav\rscommx.dll
rising
RsCommX
.text,.rdata,.data,.rsrc,.reloc,
23700000[0001A000]
[ M] 52. c:\program files\rising\rav\rscommon.dll
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
+ 00000c2c(3116) runiep.exe
00400000[00013000]
[AM] 29. c:\program files\rising\antispyware\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
00C50000[0001B000]
[ M] 38. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,