+ 资源管理器加载模块
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
text/xml
[A ] 46. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
Microsoft Corporation
Microsoft Office XML MIME Filter
.text,.data,.cdata,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 47. c:\windows\system32\hticons.dll
Hilgraeve, Inc.
HyperTerminal Applet Library
.text,.data,.rsrc,.reloc,
Shell Extensions for RealOne Player
[A ] 48. d:\program files\realplay\rpshell.dll
RealNetworks, Inc.
RealPlayer Shell Extensions
.text,.rdata,.data,.rsrc,.reloc,
Web Folders
[A ] 49. c:\program files\common files\microsoft shared\web folders\msonsext.dll
Microsoft Corporation
Microsoft Web Folders
.text,.data,.rsrc,.reloc,
Portable Media Devices
[A ] 50. c:\windows\system32\audiodev.dll
Microsoft Corporation
Portable Media Devices Shell Extension
.text,.data,.rsrc,.reloc,
Portable Devices
[A ] 51. c:\windows\system32\wpdshext.dll
Microsoft Corporation
Portable Devices Shell Extension
.text,.data,.rsrc,.reloc,
Portable Devices Menu
[A ] 51. c:\windows\system32\wpdshext.dll
Microsoft Corporation
Portable Devices Shell Extension
.text,.data,.rsrc,.reloc,
WinRAR shell extension
[A ] 52. c:\program files\winrar\rarext.dll
.text,.data,.tls,.idata,.edata,.rsrc,.reloc,
Microsoft Office HTML Icon Handler
[A ] 53. c:\program files\microsoft office\office11\msohev.dll
Microsoft Corporation
Microsoft Office 2003 component
.text,.data,.rsrc,.reloc,
RISING
[A ] 54. c:\windows\system32\ravext.dll
Beijing Rising Information Technology Co., Ltd.
Rising Shell Ext Module
.text,.rdata,.data,.rsrc,.reloc,
YouKuDesktop Shell Extension
[A ] 55. c:\windows\system32\youkudesktopshell.dll
www.youku.com YouKuDesktop Shell Extension Library
.text,.rdata,.data,.rsrc,.reloc,
DllRegShlExt extension
[A ] 56. c:\windows\system32\tudouupload.dll
www.Tudou.com DLL registration shell extension
.text,.rdata,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
WPDShServiceObj
[AM] 57. c:\windows\system32\wpdshserviceobj.dll
Microsoft Corporation
Windows Portable Device Shell Service Object
.text,.data,.rsrc,.reloc,
+ 用户登陆自运行项目
+ HKCU\Software\Microsoft\Windows\CurrentVersion\Run
52hxw
[A ] 58. d:\新建文件夹\52hxw\52hxw.exe
www.52hxw.com 火星文输入法2009
.text,.rdata,.data,.rsrc,
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
RavTray
[AM] 59. c:\program files\rising\rav\rstray.exe
Beijing Rising Information Technology Co., Ltd.
Rising tray framework
.text,.rdata,.data,.rsrc,
RFWTray
[AM] 60. c:\program files\rising\rfw\rstray.exe
Beijing Rising Information Technology Co., Ltd.
Rising tray framework
.text,.rdata,.data,.rsrc,
TkBellExe
[AM] 61. c:\program files\common files\real\update_ob\realsched.exe
RealNetworks, Inc.
RealNetworks Scheduler
.text,.rdata,.data,.rsrc,
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 62. c:\windows\system32\bsmain.exe
Beijing Rising Information Technology Co., Ltd.
Rising Antivirus 2008
.text,.rdata,.data,.rsrc,.reloc,
+ 映像劫持
+ HKCR\.html
htmlfile\360SE\Command
[A ] 63. d:\program files\新建文件夹 (2)\360safe\360se\360se.exe
360安全中心
360安全浏览器
.text,.rdata,.data,.rsrc,
htmlfile\Edit\Command
[A ] 64. c:\program files\microsoft office\office11\msohtmed.exe
Microsoft Corporation
Microsoft Office 2003 component
.text,.data,.cdata,.rsrc,
htmlfile\open\Command
[A ] 63. d:\program files\新建文件夹 (2)\360safe\360se\360se.exe
360安全中心
360安全浏览器
.text,.rdata,.data,.rsrc,
htmlfile\Print\Command
[A ] 64. c:\program files\microsoft office\office11\msohtmed.exe
Microsoft Corporation
Microsoft Office 2003 component
.text,.data,.cdata,.rsrc,
+ HKCR\.htm
htmlfile\360SE\Command
[A ] 63. d:\program files\新建文件夹 (2)\360safe\360se\360se.exe
360安全中心
360安全浏览器
.text,.rdata,.data,.rsrc,
htmlfile\Edit\Command
[A ] 64. c:\program files\microsoft office\office11\msohtmed.exe
Microsoft Corporation
Microsoft Office 2003 component
.text,.data,.cdata,.rsrc,
htmlfile\open\Command
[A ] 63. d:\program files\新建文件夹 (2)\360safe\360se\360se.exe
360安全中心
360安全浏览器
.text,.rdata,.data,.rsrc,
htmlfile\Print\Command
[A ] 64. c:\program files\microsoft office\office11\msohtmed.exe
Microsoft Corporation
Microsoft Office 2003 component
.text,.data,.cdata,.rsrc,
+ 其他自启动项目
+ C:\WINDOWS\Tasks
SogouImeMgr.job
[A ] 65. c:\program files\sogouinput\4.2.2.2732\pinyinrepair.exe
Sogou.com Inc.
搜狗拼音输入法 输入法修复程序
.text,.rdata,.data,.rsrc,
+ 正在运行的进程
+ 00000104(260) RsTray.exe
00400000[00023000]
[AM] 59. c:\program files\rising\rav\rstray.exe
Beijing Rising Information Technology Co., Ltd.
Rising tray framework
.text,.rdata,.data,.rsrc,
10000000[0020C000]
[ M] 66. c:\windows\system32\sogoupy.ime
Sogou.com Inc.
搜狗拼音输入法
UPX0,UPX1,.rsrc,
00C40000[00032000]
[ M] 67. c:\program files\sogouinput\4.2.2.2732\resource.dll
Sogou.com Inc.
搜狗拼音输入法
.rsrc,.reloc,
01100000[00023000]
[ M] 68. c:\program files\rising\rav\comserv.dll
Beijing Rising Information Technology Co., Ltd.
Rising tray common service
.text,.rdata,.data,.rsrc,.reloc,
7C3A0000[0007B000]
[ M] 69. c:\windows\system32\msvcp71.dll
Microsoft Corporation
Microsoft? C++ Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
7C340000[00056000]
[ M] 70. c:\windows\system32\msvcr71.dll
Microsoft Corporation
Microsoft? C Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
23700000[00023000]
[ M] 71. c:\program files\rising\rav\rslang.dll
Beijing Rising Information Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
01150000[0002D000]
[ M] 72. c:\program files\rising\rav\comx3.dll
Beijing Rising Information Technology Co., Ltd.
comx3 Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
01180000[00019000]
[ M] 73. c:\program files\rising\rav\syslay.dll
Beijing Rising Information Technology Co., Ltd.
Syslay
.text,.rdata,.data,.rsrc,.reloc,
23800000[00025000]
[ M] 74. c:\program files\rising\rav\rsxml.dll
Beijing Rising Information Technology Co., Ltd.
RsXML
.text,.rdata,.data,.rsrc,.reloc,
03450000[00010000]
[ M] 75. c:\program files\rising\rav\proccomm.dll
Beijing Rising Information Technology Co., Ltd.
ProcComm Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
03660000[00013000]
[ M] 76. c:\program files\rising\rav\monstate.dll
Beijing Rising Information Technology Co., Ltd.
MonState
.text,.rdata,.data,.rsrc,.reloc,
03690000[0000B000]
[ M] 77. c:\program files\rising\rav\scanevnt.dll
Beijing Rising Information Technology Co., Ltd.
Rising Scan Service Event Handler
.text,.rdata,.data,.rsrc,.reloc,
26600000[000C3000]
[ M] 78. c:\program files\rising\rav\rsguilib.dll
Beijing Rising Information Technology Co., Ltd.
Rising GUI Library Loader
.text,.rdata,.data,.rsrc,.reloc,
7C140000[00103000]
[ M] 79. c:\windows\system32\mfc71.dll
Microsoft Corporation
MFCDLL Shared Library - Retail Version
.text,.data,.rsrc,.reloc,
037E0000[00017000]
[ M] 80. c:\program files\rising\rav\rsconf.dll
Beijing Rising Information Technology Co., Ltd.
rsconf Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
03810000[0000E000]
[ M] 81. c:\program files\rising\rav\rsappmgr.dll
Beijing Rising Information Technology Co., Ltd.
Rising Application Manager
.text,.rdata,.data,.rsrc,.reloc,
03830000[00031000]
[ M] 82. c:\program files\rising\rav\cfgdll.dll
Beijing Rising Information Technology Co., Ltd.
CfgDll
.text,.rdata,.data,.rsrc,.reloc,
03970000[00030000]
[ M] 83. c:\program files\rising\rav\rspalvd.dll
Beijing Rising Information Technology Co., Ltd.
rspalvd
.text,.rdata,.data,.rsrc,.reloc,
33000000[00025000]
[ M] 84. c:\program files\rising\rav\ravbintl.dll
Beijing Rising Information Technology Co., Ltd.
ravbintl Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
039C0000[0006C000]
[ M] 85. c:\program files\rising\rav\mruleui.dll
Beijing Rising Information Technology Co., Ltd.
mruleui
.text,.rdata,.data,.rsrc,.reloc,
03A60000[0006D000]
[ M] 86. c:\program files\rising\rav\montray.dll
Beijing Rising Information Technology Co., Ltd.
Rising AntiVirus 2009
.text,.rdata,.data,.rsrc,.reloc,
23900000[00040000]
[ M] 87. c:\program files\rising\rav\pngdll.dll
Beijing Rising Information Technology Co., Ltd.
Rising .Png File Loader Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
34500000[00020000]
[ M] 88. c:\program files\rising\rav\ravitray.dll
Beijing Rising Information Technology Co., Ltd.
ravitray Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
03F20000[00059000]
[ M] 89. c:\program files\rising\rav\scanprxy.dll
Beijing Rising Information Technology Co., Ltd.
ScanPrxy Module
.text,.rdata,.data,.rsrc,.reloc,
03F80000[00044000]
[ M] 90. c:\program files\rising\rav\rsmginfo.dll
Beijing Rising Information Technology Co., Ltd.
rsmginfo
.text,.rdata,.data,.rsrc,.reloc,
16080000[00025000]
[ M] 91. c:\program files\bonjour\mdnsnsp.dll
Apple Inc.
Bonjour Namespace Provider
.text,.rdata,.data,.rsrc,.reloc,
+ 0000011c(284) RsTray.exe
00400000[00023000]
[AM] 60. c:\program files\rising\rfw\rstray.exe
Beijing Rising Information Technology Co., Ltd.
Rising tray framework
.text,.rdata,.data,.rsrc,
10000000[0020C000]
[ M] 66. c:\windows\system32\sogoupy.ime
Sogou.com Inc.
搜狗拼音输入法
UPX0,UPX1,.rsrc,
00C40000[00032000]
[ M] 67. c:\program files\sogouinput\4.2.2.2732\resource.dll
Sogou.com Inc.
搜狗拼音输入法
.rsrc,.reloc,
01100000[00023000]
[ M] 92. c:\program files\rising\rfw\comserv.dll
Beijing Rising Information Technology Co., Ltd.
Rising tray common service
.text,.rdata,.data,.rsrc,.reloc,
7C3A0000[0007B000]
[ M] 69. c:\windows\system32\msvcp71.dll
Microsoft Corporation
Microsoft? C++ Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
7C340000[00056000]
[ M] 70. c:\windows\system32\msvcr71.dll
Microsoft Corporation
Microsoft? C Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
23700000[00023000]
[ M] 93. c:\program files\rising\rfw\rslang.dll
Beijing Rising Information Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
01150000[0002D000]
[ M] 94. c:\program files\rising\rfw\comx3.dll
Beijing Rising Information Technology Co., Ltd.
comx3 Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
01180000[00019000]
[ M] 95. c:\program files\rising\rfw\syslay.dll
Beijing Rising Information Technology Co., Ltd.
Syslay
.text,.rdata,.data,.rsrc,.reloc,
23800000[00025000]
[ M] 96. c:\program files\rising\rfw\rsxml.dll
Beijing Rising Information Technology Co., Ltd.
RsXML
.text,.rdata,.data,.rsrc,.reloc,
03450000[00010000]
[ M] 97. c:\program files\rising\rfw\proccomm.dll
Beijing Rising Information Technology Co., Ltd.
ProcComm Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
03760000[00013000]
[ M] 98. c:\program files\rising\rfw\monstate.dll
Beijing Rising Information Technology Co., Ltd.
MonState
.text,.rdata,.data,.rsrc,.reloc,
03790000[0000C000]
[ M] 99. c:\program files\rising\rfw\rfwrule.dll
Beijing Rising Information Technology Co., Ltd.
TODO: <File description>
.text,.rdata,.data,.rsrc,.reloc,
037A0000[00017000]
[ M] 100. c:\program files\rising\rfw\rsconf.dll
Beijing Rising Information Technology Co., Ltd.
rsconf Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
037D0000[0000E000]
[ M] 101. c:\program files\rising\rfw\rsappmgr.dll
Beijing Rising Information Technology Co., Ltd.
Rising Application Manager
.text,.rdata,.data,.rsrc,.reloc,
037F0000[00031000]
[ M] 102. c:\program files\rising\rfw\cfgdll.dll
Beijing Rising Information Technology Co., Ltd.
CfgDll
.text,.rdata,.data,.rsrc,.reloc,
03910000[00030000]
[ M] 103. c:\program files\rising\rfw\rspalvd.dll
Beijing Rising Information Technology Co., Ltd.
rspalvd
.text,.rdata,.data,.rsrc,.reloc,
26600000[000C3000]
[ M] 104. c:\program files\rising\rfw\rsguilib.dll
Beijing Rising Information Technology Co., Ltd.
Rising GUI Library Loader
.text,.rdata,.data,.rsrc,.reloc,
7C140000[00103000]
[ M] 79. c:\windows\system32\mfc71.dll
Microsoft Corporation
MFCDLL Shared Library - Retail Version
.text,.data,.rsrc,.reloc,
33000000[00025000]
[ M] 105. c:\program files\rising\rfw\ravbintl.dll
Beijing Rising Information Technology Co., Ltd.
ravbintl Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
01010000[00067000]
[ M] 106. c:\program files\rising\rfw\rsnetsvr.dll
Beijing Rising Information Technology Co., Ltd.
rsnetsvr
.text,.rdata,.data,.rsrc,.reloc,
010B0000[00044000]
[ M] 107. c:\program files\rising\rfw\rsmginfo.dll
Beijing Rising Information Technology Co., Ltd.
rsmginfo
.text,.rdata,.data,.rsrc,.reloc,
03990000[0004B000]
[ M] 108. c:\program files\rising\rfw\rfwtray.dll
Beijing Rising Information Technology Co., Ltd.
rfwtray Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
23900000[00040000]
[ M] 109. c:\program files\rising\rfw\pngdll.dll
Beijing Rising Information Technology Co., Ltd.
Rising .Png File Loader Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
04150000[00064000]
[ M] 110. c:\program files\rising\rfw\rfwlog.dll
Beijing Rising Information Technology Co., Ltd.
rfwlog Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
16080000[00025000]
[ M] 91. c:\program files\bonjour\mdnsnsp.dll
Apple Inc.
Bonjour Namespace Provider
.text,.rdata,.data,.rsrc,.reloc,
+ 00000128(296) realsched.exe
00400000[0002F000]
[AM] 61. c:\program files\common files\real\update_ob\realsched.exe
RealNetworks, Inc.
RealNetworks Scheduler
.text,.rdata,.data,.rsrc,
10000000[0020C000]
[ M] 66. c:\windows\system32\sogoupy.ime
Sogou.com Inc.
搜狗拼音输入法
UPX0,UPX1,.rsrc,
00CB0000[00032000]
[ M] 67. c:\program files\sogouinput\4.2.2.2732\resource.dll
Sogou.com Inc.
搜狗拼音输入法
.rsrc,.reloc,
+ 00000134(308) ctfmon.exe
10000000[0020C000]
[ M] 66. c:\windows\system32\sogoupy.ime
Sogou.com Inc.
搜狗拼音输入法
UPX0,UPX1,.rsrc,
00BD0000[00032000]
[ M] 67. c:\program files\sogouinput\4.2.2.2732\resource.dll
Sogou.com Inc.
搜狗拼音输入法
.rsrc,.reloc,
+ 000001cc(460) svchost.exe
+ 0000021c(540) ScanFrm.exe
00400000[0000B000]
[AM] 10. c:\program files\rising\rav\scanfrm.exe
Beijing Rising Information Technology Co., Ltd.
Rising Scan Service Framework
.text,.rdata,.data,.rsrc,
7C3A0000[0007B000]
[ M] 69. c:\windows\system32\msvcp71.dll
Microsoft Corporation
Microsoft? C++ Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
7C340000[00056000]
[ M] 70. c:\windows\system32\msvcr71.dll
Microsoft Corporation
Microsoft? C Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
10000000[00029000]
[ M] 111. c:\program files\rising\rav\combase.dll
Beijing Rising Information Technology Co., Ltd.
combase
.text,.rdata,.data,.rsrc,.reloc,
003E0000[00019000]
[ M] 112. c:\program files\rising\rav\moncomm.dll
Beijing Rising Information Technology Co., Ltd.
MonComm
.text,.rdata,.data,.rsrc,.reloc,
00900000[00008000]
[ M] 113. c:\program files\rising\rav\scansrvp.dll
Beijing Rising Information Technology Co., Ltd.
ScanSrvP Module
.text,.rdata,.data,.rsrc,.reloc,
00910000[00010000]
[ M] 75. c:\program files\rising\rav\proccomm.dll
Beijing Rising Information Technology Co., Ltd.
ProcComm Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00B20000[0000E000]
[ M] 114. c:\program files\rising\rav\scansrv.dll
Beijing Rising Information Technology Co., Ltd.
ScanSrv Module
.text,.rdata,.data,.rsrc,.reloc,