Web Folders
[A ] 87. c:\program files\common files\microsoft shared\web folders\msonsext.dll
Microsoft Corporation
Microsoft Web Folders
.text,.data,.rsrc,.reloc,
Microsoft Office Outlook Desktop Icon Handler
[A ] 88. c:\program files\microsoft office\office11\mlshext.dll
Microsoft Corporation
Microsoft Shell Extension Library
.text,.data,.rsrc,.reloc,
Microsoft Office Outlook Custom Icon Handler
[A ] 89. c:\program files\microsoft office\office11\olkfstub.dll
Microsoft Corporation
Outlook Shell Hook for Start/Find
.text,.data,.rsrc,.reloc,
Microsoft Office HTML Icon Handler
[AM] 90. c:\program files\microsoft office\office11\msohev.dll
Microsoft Corporation
Microsoft Office 2003 component
.text,.data,.rsrc,.reloc,
Desktop Explorer
[AM] 91. c:\windows\system32\nvshell.dll
.text,.rdata,.data,.idata,.shared,.rsrc,.reloc,
Desktop Explorer Menu
[AM] 91. c:\windows\system32\nvshell.dll
.text,.rdata,.data,.idata,.shared,.rsrc,.reloc,
nView Desktop Context Menu
[AM] 91. c:\windows\system32\nvshell.dll
.text,.rdata,.data,.idata,.shared,.rsrc,.reloc,
RISING
[AM] 92. c:\windows\system32\ravext.dll
Beijing Rising Technology Co., Ltd.
Rising Shell Ext Module
.text,.rdata,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{32CD708B-60A7-4C00-9377-D73EAA495F0F}
[AM] 92. c:\windows\system32\ravext.dll
Beijing Rising Technology Co., Ltd.
Rising Shell Ext Module
.text,.rdata,.data,.rsrc,.reloc,
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 93. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
WPDShServiceObj
[AM] 94. c:\windows\system32\wpdshserviceobj.dll
Microsoft Corporation
Windows Portable Device Shell Service
Object .text,.data,.rsrc,.reloc,
+ 用户登陆自运行项目
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
TkBellExe
[AM] 95. c:\program files\common files\real\update_ob\realsched.exe
RealNetworks, Inc.
RealNetworks Scheduler
.text,.rdata,.data,.rsrc,
Thunder
[A ] 96. c:\program files\thunder network\thunder\thundershell.exe
CODE,DATA,BSS,.idata,.tls,.rdata,.reloc,.rsrc,
DAEMON Tools-2052
[A ] 97. f:\新建文件夹 (5)\daemon.exe
DAEMON'S HOME
Virtual DAEMON Manager
.text,.rdata,.data,.rsrc,
WebThunder
[A ] 98. d:\qijieshijie\webthunder.exe
深圳市迅雷网络技术有限公司
Web 迅雷
.text,.rdata,.data,.rsrc,
System
[A ] 99. c:\program files\common files\system\updaterun.exe
.text,.rdata,.data,
RavTask
[A ] 100. c:\program files\rising\rav\ravtask.exe
Beijing Rising Technology Co., Ltd.
RavTimer
.text,.rdata,.data,.rsrc,
IdnSvr
[AM] 101. c:\program files\ocins\idnsvr.exe
中国互联网信息中心(CNNIC)
国际化域名支持模块
.text,.rdata,.data,.rsrc,
tekcdke
[A ] 102. c:\program files\via\tekcdke.exe
.text,.rdata,.data,
MoveSearch
[A ] 103. c:\program files\huaci\huaci\zsearch.exe
中搜在线
划词搜索
.text,.rdata,.data,.rsrc,
runeip
[AM] 104. c:\program files\rising\antispyware\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
RavStub
[AM] 105. c:\program files\rising\rav\ravstub.exe
Beijing Rising Technology Co., Ltd.
Rising RavStub
.text,.rdata,.data,.rsrc,
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 106. c:\windows\system32\bsmain.exe
Beijing Rising Technology Co., Ltd.
BootScan
.text,.data,.rsrc,.reloc,
+ 映像劫持
+ HKCR\.html
htmlfile\Edit\Command
[A ] 107. c:\program files\microsoft office\office11\msohtmed.exe
Microsoft Corporation
Microsoft Office 2003 component
.text,.data,.rsrc,
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 107. c:\program files\microsoft office\office11\msohtmed.exe
Microsoft Corporation
Microsoft Office 2003 component
.text,.data,.rsrc,
+ HKCR\.mp3
RealPlayer.MP3.6\open\Command
[A ] 108. c:\program files\real\realplayer\realplay.exe
RealNetworks, Inc.
RealPlayer
.text,.rdata,.data,.rsrc,
+ 打印机监控
+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
Microsoft Document Imaging Writer Monitor
[AM] 109. c:\windows\system32\mdimon.dll
Microsoft Corporation
Microsoft? Document Imaging
.text,.data,.rsrc,.reloc,
+ 其他自启动项目
+ C:\Documents and Settings\All Users\「开始」菜单\程序\启动
ycdgfg.lnk
[A ] 110. c:\program files\realtek\ycdgfgl.exe
.text,.rdata,.data,
+ C:\WINDOWS\Tasks
OJ8WRm.job
[A ] 111. c:\windows\system32\zheekme.exe
.text,.rdata,.data,
egaNJJZlwjMTg5HT2kz9B.job
[A ] 111. c:\windows\system32\zheekme.exe
.text,.rdata,.data,
h.job
[A ] 111. c:\windows\system32\zheekme.exe
.text,.rdata,.data,
qenNh2bj6rZi9wnEebTN4Y.job
[A ] 111. c:\windows\system32\zheekme.exe
.text,.rdata,.data,
NaHZCir.job
[A ] 111. c:\windows\system32\zheekme.exe
.text,.rdata,.data,
AkBefuOnxrKSVi.job
[A ] 111. c:\windows\system32\zheekme.exe
.text,.rdata,.data,
Ew8wQE5hDVjAK45KWpNjuk.job
[A ] 111. c:\windows\system32\zheekme.exe
.text,.rdata,.data,
OtQAbHsbeb.job
[A ] 111. c:\windows\system32\zheekme.exe
.text,.rdata,.data,
tbQPDo989k3KuOQTsFqDRehdbH3GEG.job
[A ] 111. c:\windows\system32\zheekme.exe
.text,.rdata,.data,
bhbhd9ZPZzNYCb.job
[A ] 111. c:\windows\system32\zheekme.exe
.text,.rdata,.data,
qa.job
[A ] 111. c:\windows\system32\zheekme.exe
.text,.rdata,.data,
Klcbv.job
[A ] 111. c:\windows\system32\zheekme.exe
.text,.rdata,.data,
2HC2o.job
[A ] 111. c:\windows\system32\zheekme.exe
.text,.rdata,.data,
+ 正在运行的进程
+ 0000023c(572) idnsvr.exe
00400000[00016000]
[AM] 101. c:\program files\ocins\idnsvr.exe
中国互联网信息中心(CNNIC)
国际化域名支持模块
.text,.rdata,.data,.rsrc,
3B030000[000A9000]
[ M] 112. c:\windows\system32\imsc40a.ime
Microsoft Corporation
微软拼音输入法 2003
.text,.data,.rsrc,.reloc,
10000000[0002C000]
[ M] 113. c:\program files\ocins\idnsvr.dll
中国互联网信息中心(CNNIC)
国际化域名支持模块
.text,.rdata,.data,.rsrc,.reloc,
00C50000[00009000]
[ M] 114. c:\windows\system32\normaliz.dll
Microsoft Corporation
Unicode Normalization DLL
.text,.data,.rsrc,.reloc,
41D50000[00045000]
[ M] 115. c:\windows\system32\iertutil.dll
Microsoft Corporation
Run time utility for Internet Explorer
.text,.data,.rsrc,.reloc,
067C0000[0001B000]
[ M] 116. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 000002a4(676) ctfmon.exe
3B030000[000A9000]
[ M] 112. c:\windows\system32\imsc40a.ime
Microsoft Corporation
微软拼音输入法 2003
.text,.data,.rsrc,.reloc,
10000000[0001B000]
[ M] 116. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 000002c4(708) smss.exe
+ 00000314(788) csrss.exe
+ 0000032c(812) winlogon.exe
3B030000[000A9000]
[ M] 112. c:\windows\system32\imsc40a.ime
Microsoft Corporation
微软拼音输入法 2003
.text,.data,.rsrc,.reloc,
72C80000[00008000]
[ M] 117. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
01BD0000[00009000]
[ M] 114. c:\windows\system32\normaliz.dll
Microsoft Corporation
Unicode Normalization DLL
.text,.data,.rsrc,.reloc,
41D50000[00045000]
[ M] 115. c:\windows\system32\iertutil.dll
Microsoft Corporation
Run time utility for Internet Explorer
.text,.data,.rsrc,.reloc,
+ 00000358(856) services.exe
47260000[0000F000]
[ M] 118. c:\windows\apppatch\acadproc.dll
Microsoft Corporation
Windows Compatibility DLL
.text,.data,.rsrc,.reloc,
+ 00000364(868) lsass.exe
+ 00000400(1024) svchost.exe
+ 00000450(1104) svchost.exe
+ 000004c0(1216) svchost.exe
00D70000[00009000]
[ M] 114. c:\windows\system32\normaliz.dll
Microsoft Corporation
Unicode Normalization DLL
.text,.data,.rsrc,.reloc,
41D50000[00045000]
[ M] 115. c:\windows\system32\iertutil.dll
Microsoft Corporation
Run time utility for Internet Explorer
.text,.data,.rsrc,.reloc,
+ 0000051c(1308) svchost.exe
+ 00000548(1352) realsched.exe
00400000[0002F000]
[AM] 95. c:\program files\common files\real\update_ob\realsched.exe
RealNetworks, Inc.
RealNetworks Scheduler
.text,.rdata,.data,.rsrc,