+ 程序初始化和已知动态连接库
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
[AM] 29. c:\windows\system32\dhapri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
+ 其他自启动项目
+ C:\Documents and Settings\All Users\「开始」菜单\程序\启动
Microsoft Office.lnk
[A ] 49. c:\program files\microsoft office\office\osa9.exe
Microsoft Corporation
Microsoft Office 2000 component
.text,.data,.rsrc,
+ c:\autorun.inf
open
[A ] 50. c:\pagefile.pif
UPX0,UPX1,.rsrc,
shellexecute
[A ] 50. c:\pagefile.pif
UPX0,UPX1,.rsrc,
shell\Auto\command
[A ] 50. c:\pagefile.pif
UPX0,UPX1,.rsrc,
+ d:\autorun.inf
open
[A ] 51. d:\pagefile.pif
UPX0,UPX1,.rsrc,
shellexecute
[A ] 51. d:\pagefile.pif
UPX0,UPX1,.rsrc,
shell\Auto\command
[A ] 51. d:\pagefile.pif
UPX0,UPX1,.rsrc,
+ 正在运行的进程
+ 000000a4(164) taskmgr.exe
10090000[00012000]
[ M] 52. c:\windows\system32\windhcp.ocx
.text,.rsrc,.reloc,
10040000[00012000]
[ M] 53. c:\windows\system32\wmiapisrv.dll
.text,.rsrc,.reloc,
00E10000[00012000]
[ M] 54. c:\windows\system32\netsrvcs.dll
.text,.rsrc,.reloc,
01CF0000[0000F000]
[AM] 28. c:\windows\system32\system1.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
01DA0000[0000A000]
[AM] 29. c:\windows\system32\dhapri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
01E20000[0000A000]
[AM] 30. c:\windows\system32\wdapri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
01E30000[0000A000]
[AM] 31. c:\windows\system32\wlcpri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
01E40000[0000A000]
[AM] 32. c:\windows\system32\qhbpri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
10000000[0001B000]
[ M] 55. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 0000018c(396) smss.exe
+ 000001d4(468) csrss.exe
+ 000001ec(492) winlogon.exe
004D0000[0000A000]
[AM] 29. c:\windows\system32\dhapri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
72C90000[00009000]
[ M] 56. c:\windows\system32\wdmaud.drv
Microsoft Corporation
WDM Audio driver mapper
.text,.data,.rsrc,.reloc,
72C80000[00008000]
[ M] 57. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
+ 0000021c(540) services.exe
00560000[0000A000]
[AM] 29. c:\windows\system32\dhapri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
+ 00000228(552) lsass.exe
00560000[0000A000]
[AM] 29. c:\windows\system32\dhapri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
+ 000002dc(732) svchost.exe
005A0000[0000A000]
[AM] 29. c:\windows\system32\dhapri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
10000000[0001E000]
[ M] 58. c:\windows\system32\mscomm.dll
.Upack,.rsrc,
入口点在最后一个节;
+ 00000320(800) svchost.exe
00540000[0000A000]
[AM] 29. c:\windows\system32\dhapri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
10000000[0001E000]
[ M] 58. c:\windows\system32\mscomm.dll
.Upack,.rsrc,
入口点在最后一个节;
+ 00000394(916) svchost.exe
005A0000[0000A000]
[AM] 29. c:\windows\system32\dhapri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
+ 000003c0(960) svchost.exe
00540000[0000A000]
[AM] 29. c:\windows\system32\dhapri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
+ 000004b0(1200) spoolsv.exe
007E0000[0000A000]
[AM] 29. c:\windows\system32\dhapri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
+ 000004fc(1276) ctfmon.exe
003C0000[0000A000]
[AM] 29. c:\windows\system32\dhapri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
10090000[00012000]
[ M] 52. c:\windows\system32\windhcp.ocx
.text,.rsrc,.reloc,
10040000[00012000]
[ M] 53. c:\windows\system32\wmiapisrv.dll
.text,.rsrc,.reloc,
00C90000[00012000]
[ M] 54. c:\windows\system32\netsrvcs.dll
.text,.rsrc,.reloc,
10000000[0001B000]
[ M] 55. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 0000051c(1308) RavStub.exe
00400000[00018000]
[ M] 59. d:\program files\rising\rav\ravstub.exe
Beijing Rising Technology Co., Ltd.
Rising RavStub
.text,.rdata,.data,.rsrc,
10000000[0001B000]
[ M] 60. d:\program files\rising\rav\rscommx.dll
rising
RsCommX
.text,.rdata,.data,.rsrc,.reloc,
23700000[0001A000]
[ M] 61. d:\program files\rising\rav\rscommon.dll
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
+ 00000634(1588) Rsaupd.exe
00400000[0001E000]
[ M] 62. c:\program files\rising\antispyware\update\rsaupd.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Update
.text,.rdata,.data,.rsrc,
003C0000[0000A000]
[AM] 29. c:\windows\system32\dhapri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
10090000[00012000]
[ M] 52. c:\windows\system32\windhcp.ocx
.text,.rsrc,.reloc,
10040000[00012000]
[ M] 53. c:\windows\system32\wmiapisrv.dll
.text,.rsrc,.reloc,
00F00000[00012000]
[ M] 54. c:\windows\system32\netsrvcs.dll
.text,.rsrc,.reloc,
01430000[0006B000]
[ M] 63. c:\program files\rising\antispyware\temp\rasgui.dll
Beijing Rising Technology Co., Ltd.
RasGUI
.text,.rdata,.data,.rsrc,.reloc,
10000000[0001E000]
[ M] 58. c:\windows\system32\mscomm.dll
.Upack,.rsrc,
入口点在最后一个节;
01B50000[0001B000]
[ M] 55. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
01BD0000[0000F000]
[AM] 28. c:\windows\system32\system1.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
01BE0000[0000A000]
[AM] 30. c:\windows\system32\wdapri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
01BF0000[0000A000]
[AM] 31. c:\windows\system32\wlcpri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
023B0000[0000A000]
[AM] 32. c:\windows\system32\qhbpri.dll
CODE,DATA,BSS,.idata,.reloc,.rsrc,
+ 00000668(1640) runiep.exe
00400000[00012000]
[AM] 38. c:\program files\rising\antispyware\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
10090000[00012000]
[ M] 52. c:\windows\system32\windhcp.ocx
.text,.rsrc,.reloc,
10040000[00012000]
[ M] 53. c:\windows\system32\wmiapisrv.dll
.text,.rsrc,.reloc,
00D90000[00012000]
[ M] 54. c:\windows\system32\netsrvcs.dll
.text,.rsrc,.reloc,