+ 系统登陆自运行
+ HKCU\Control Panel\Desktop
Scrnsave.exe
[A ] 22. c:\windows\system32\ravss.scr
Rising Corp.
Rising Screen Saver
CODE,DATA,BSS,.idata,.tls,.rdata,.reloc,.rsrc,
+ IE浏览器加载模块
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C}
[AM] 23. c:\windows\system32\kakatool.dll
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Toolbar
.text,.rdata,.data,MonitorS,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{01443AEC-0FD1-40fd-9C87-E93D1494C233}
[AM] 24. d:\迅雷\comdlls\tdatonce_now.dll
Thunder Networking Technologies,LTD
迅雷浏览器高级特性支持模块
.text,.rdata,.data,.rsrc,.reloc,
{889D2FEB-5411-4565-8998-1DD2C5261283}
[AM] 25. d:\迅雷\comdlls\xunleibho_now.dll
Thunder Networking Technologies,LTD
XunLeiBHO
.text,.rdata,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
Exec
[A ] 26. d:\迅雷\thunder.exe
Thunder Networking Technologies,LTD
.text,.rdata,.data,.rsrc,
Exec
[A ] 27. c:\program files\messenger\msmsgs.exe
Microsoft Corporation
Windows Messenger
.text,.data,.rsrc,
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 28. c:\windows\system32\hticons.dll
Hilgraeve, Inc.
HyperTerminal Applet Library
.text,.data,.rsrc,.reloc,
RISING
[AM] 29. c:\windows\system32\ravext.dll
Beijing Rising Technology Co., Ltd.
Rising Shell Ext Module
.text,.rdata,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{32CD708B-60A7-4C00-9377-D73EAA495F0F}
[AM] 29. c:\windows\system32\ravext.dll
Beijing Rising Technology Co., Ltd.
Rising Shell Ext Module
.text,.rdata,.data,.rsrc,.reloc,
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 30. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,
{525AB2F3-234A-7469-2F43-E341713ABFA5}
[AM] 31. c:\windows\system32\wgepri.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
{36368135-64FA-BC34-DA32-DCF4FD431C93}
[A ] 32. c:\windows\system32\qhcpri.dll
+ 用户登陆自运行项目
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
VTTimer
[AM] 33. c:\windows\system32\vttimer.exe
S3 Graphics, Inc.
.text,.rdata,.data,.rsrc,
VTTrayp
[AM] 34. c:\windows\system32\vttrayp.exe
S3 Graphics Co., Ltd.
s3contrl (32-bit)
.text,.rdata,.data,.rsrc,
SoundMan
[AM] 35. c:\windows\soundman.exe
Realtek Semiconductor Corp.
Realtek Sound Manager
.text,.rdata,.data,.sxdata,.rsrc,
RavTask
[A ] 36. d:\rising\rav\ravtask.exe
Beijing Rising Technology Co., Ltd.
RavTimer
.text,.rdata,.data,.rsrc,
runeip
[AM] 37. d:\rising\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
BigDog303
[AM] 38. c:\windows\vm303_sti.exe
Vimicro
Vimicro
.text,.rdata,.data,.sxdata,.rsrc,
RfwMain
[AM] 39. d:\rising\rising\rfw\rfwmain.exe
Beijing Rising Technology Co., Ltd.
Rising Personal FireWall Main Program
.text,.rdata,.data,.rsrc,
Thunder
[A ] 26. d:\迅雷\thunder.exe
Thunder Networking Technologies,LTD
.text,.rdata,.data,.rsrc,
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 40. c:\windows\system32\bsmain.exe
Beijing Rising Technology Co., Ltd.
BootScan
.text,.data,.rsrc,.reloc,
+ 程序初始化和已知动态连接库
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
[AM] 31. c:\windows\system32\wgepri.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 其他自启动项目
+ C:\Documents and Settings\Owner\「开始」菜单\程序\启动
腾讯QQ.lnk
[A ] 41. d:\qq\qq.exe
TENCENT
QQ
.text,.rdata,.data,.rsrc,
+ 正在运行的进程
+ 0000020c(524) smss.exe
+ 00000244(580) VTTimer.exe
00400000[0000D000]
[AM] 33. c:\windows\system32\vttimer.exe
S3 Graphics, Inc.
.text,.rdata,.data,.rsrc,
003D0000[0000C000]
[AM] 31. c:\windows\system32\wgepri.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
10000000[0001B000]
[ M] 42. d:\rising\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 00000248(584) VTtrayp.exe
00400000[00027000]
[AM] 34. c:\windows\system32\vttrayp.exe
S3 Graphics Co., Ltd.
s3contrl (32-bit)
.text,.rdata,.data,.rsrc,
6BB00000[0007B000]
[ M] 43. c:\windows\system32\vtdisply.dll
S3 Graphics Co., Ltd.
S3 multi-chip display switch utility (32-bit)
.text,.rdata,.data,.rsrc,.reloc,
6BE00000[0005A000]
[ M] 44. c:\windows\system32\vtgamma2.dll
S3 Graphics Co., Ltd.
S3Gamma Plus (32-bit)
.text,.rdata,.data,.rsrc,.reloc,
6C000000[00043000]
[ M] 45. c:\windows\system32\vtinfo2.dll
S3 Graphics Co., Ltd.
S3 Graphics Display Adapter Information Utility (32-bit)
.text,.rdata,.data,.rsrc,.reloc,
6C200000[00065000]
[ M] 46. c:\windows\system32\vtovrlay.dll
S3 Graphics Co., Ltd.
S3ColorPus/S3Overlay Utility
.text,.rdata,.data,.rsrc,.reloc,
10000000[0001B000]
[ M] 42. d:\rising\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
00C10000[0000C000]
[AM] 31. c:\windows\system32\wgepri.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 00000254(596) SOUNDMAN.EXE
00400000[0008F000]
[AM] 35. c:\windows\soundman.exe
Realtek Semiconductor Corp.
Realtek Sound Manager
.text,.rdata,.data,.sxdata,.rsrc,
10000000[0001B000]
[ M] 42. d:\rising\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
00E50000[0000C000]
[AM] 31. c:\windows\system32\wgepri.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 0000025c(604) csrss.exe
+ 00000274(628) winlogon.exe
004C0000[0000C000]
[AM] 31. c:\windows\system32\wgepri.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
72C80000[00008000]
[ M] 47. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
+ 000002a4(676) services.exe
003B0000[0000C000]
[AM] 31. c:\windows\system32\wgepri.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 000002b8(696) lsass.exe
003B0000[0000C000]
[AM] 31. c:\windows\system32\wgepri.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 000002fc(764) runiep.exe
00400000[00013000]
[AM] 37. d:\rising\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
00BE0000[0001B000]
[ M] 42. d:\rising\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
00BD0000[0000C000]
[AM] 31. c:\windows\system32\wgepri.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 00000344(836) VM303_STI.EXE
00400000[00010000]
[AM] 38. c:\windows\vm303_sti.exe
Vimicro
Vimicro
.text,.rdata,.data,.sxdata,.rsrc,
10000000[0003A000]
[ M] 48. c:\windows\system32\vm303prp.ax
Vimicro
DirectShow Extension Page
.text,.rdata,.data,.idata,.CRT,.rsrc,.reloc,
00BF0000[0001B000]
[ M] 42. d:\rising\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
00D10000[0000C000]
[AM] 31. c:\windows\system32\wgepri.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 00000358(856) svchost.exe
003A0000[0000C000]
[AM] 31. c:\windows\system32\wgepri.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 0000039c(924) svchost.exe
003A0000[0000C000]
[AM] 31. c:\windows\system32\wgepri.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 0000040c(1036) svchost.exe
003A0000[0000C000]
[AM] 31. c:\windows\system32\wgepri.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,