+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 66. c:\windows\system32\bsmain.exe
+ 映像劫持
+ HKCR\Folder\shell
Super Rabbit CDROM Eject
[A ] 67. c:\program files\super rabbit\magicset\srcd2.exe
+ HKCR\.exe
exefile\启用/禁用数字签名图标\Command
[A ] 68. c:\windows\system32\acsignopt.exe
+ HKCR\.html
htmlfile\Edit\Command
[A ] 69. c:\program files\microsoft office\office\msohtmed.exe
htmlfile\Print\Command
[A ] 69. c:\program files\microsoft office\office\msohtmed.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 69. c:\program files\microsoft office\office\msohtmed.exe
htmlfile\Print\Command
[A ] 69. c:\program files\microsoft office\office\msohtmed.exe
+ 其他自启动项目
+ C:\Documents and Settings\All Users\「开始」菜单\程序\启动
AutoCAD 启动加速器.lnk
[A ] 70. c:\program files\common files\autodesk shared\acstart17.exe
+ 正在运行的进程
+ 000001a8(424) Ras.exe
00400000[00170000]
[ M] 71. c:\program files\rising\antispyware\ras.exe
00370000[00009000]
[ M] 72. c:\windows\system32\normaliz.dll
41D50000[00045000]
[ M] 73. c:\windows\system32\iertutil.dll
780C0000[00061000]
[ M] 74. c:\program files\rising\antispyware\msvcp60.dll
10000000[00013000]
[ M] 75. c:\program files\rising\antispyware\topsoft.dll
7C140000[00103000]
[ M] 76. c:\program files\rising\antispyware\mfc71.dll
7C340000[00056000]
[ M] 77. c:\program files\rising\antispyware\msvcr71.dll
7C3A0000[0007B000]
[ M] 78. c:\program files\rising\antispyware\msvcp71.dll
00E60000[0001F000]
[ M] 79. c:\program files\rising\rav\proccom.dll
00FF0000[00024000]
[ M] 80. c:\program files\rising\rav\rscommx2.dll
01130000[000BD000]
[ M] 81. c:\program files\rising\antispyware\rasgui.dll
73900000[0002D000]
[ M] 82. c:\windows\system32\jpwb.ime
01100000[0001B000]
[ M] 83. c:\program files\rising\antispyware\ieprot.dll
422B0000[005CD000]
[AM] 41. c:\windows\system32\ieframe.dll
+ 000001e0(480) Explorer.EXE
00400000[00009000]
[ M] 72. c:\windows\system32\normaliz.dll
41D50000[00045000]
[ M] 73. c:\windows\system32\iertutil.dll
73900000[0002D000]
[ M] 82. c:\windows\system32\jpwb.ime
60560000[00033000]
[AM] 54. c:\windows\system32\acsignicon.dll
10000000[00016000]
[ M] 84. c:\program files\rising\rfw\ijt_base.dll
01B80000[0000F000]
[ M] 85. c:\program files\rising\rfw\olemon.dll
60610000[00061000]
[ M] 86. c:\program files\common files\autodesk shared\acsigncore16.dll
422B0000[005CD000]
[AM] 41. c:\windows\system32\ieframe.dll
00ED0000[0001B000]
[ M] 83. c:\program files\rising\antispyware\ieprot.dll
22EC0000[0000D000]
[ M] 87. c:\program files\thunder network\thunder\components\resworker\dsbho_00.dll
22E90000[0000D000]
[ M] 88. c:\program files\thunder network\thunder\components\resworker\dataprocessor_00.dll
72C80000[00008000]
[ M] 89. c:\windows\system32\msacm32.drv
23700000[00028000]
[ M] 90. c:\program files\rising\rav\rscommon.dll
+ 00000204(516) smss.exe
+ 00000240(576) wdfmgr.exe
01000000[0000C000]
[AM] 8. c:\windows\system32\wdfmgr.exe
10000000[00016000]
[ M] 84. c:\program files\rising\rfw\ijt_base.dll
005F0000[0000F000]
[ M] 85. c:\program files\rising\rfw\olemon.dll
+ 00000254(596) csrss.exe
10000000[00016000]
[ M] 84. c:\program files\rising\rfw\ijt_base.dll
034E0000[0000F000]
[ M] 85. c:\program files\rising\rfw\olemon.dll
+ 0000026c(620) winlogon.exe
10000000[00016000]
[ M] 84. c:\program files\rising\rfw\ijt_base.dll
00FD0000[0000F000]
[ M] 85. c:\program files\rising\rfw\olemon.dll
73900000[0002D000]
[ M] 82. c:\windows\system32\jpwb.ime
72C80000[00008000]
[ M] 89. c:\windows\system32\msacm32.drv
+ 0000029c(668) services.exe
10000000[00016000]
[ M] 84. c:\program files\rising\rfw\ijt_base.dll
00D20000[0000F000]
[ M] 85. c:\program files\rising\rfw\olemon.dll
+ 000002a8(680) lsass.exe
10000000[00016000]
[ M] 84. c:\program files\rising\rfw\ijt_base.dll
00D10000[0000F000]
[ M] 85. c:\program files\rising\rfw\olemon.dll
+ 000002ac(684) RavMon.exe
00400000[00061000]
[ M] 91. c:\program files\rising\rav\ravmon.exe