注册项
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [(Verified)Beijing Rising Information Technology Co., Ltd., 7.0.1.70, C:2008-02-28 23:28 M:2008-07-25 20:11]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Information Technology Co., Ltd., 20.0.0.24, C:2008-02-28 23:26 M:2008-07-29 13:14]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs]
<wow64><wow64.dll> []
<wow64cpu><wow64cpu.dll> []
<wow64win><wow64win.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [(Verified)Beijing Rising Information Technology Co., Ltd., 20.0.0.18, C:2008-02-29 00:16 M:2008-07-29 13:14]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710), C:2008-02-28 22:41 M:2007-02-17 06:56|(Verified)Microsoft Corporation, 7.00.6000.16735 (vista_gdr.080820-1506), C:2008-08-26 02:06 M:2008-08-26 02:06|(Verified)N/A, C:2003-03-27 20:00 M:2005-04-04 13:38]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> [(Verified)Microsoft Corporation, 5.2.3790.3959 (srv03_sp2_rtm.070216-1710), C:2008-02-28 22:41 M:2007-02-17 06:56|(Verified)Microsoft Corporation, 7.00.6000.16735 (vista_gdr.080820-1506), C:2008-08-26 02:06 M:2008-08-26 02:06|(Verified)N/A, C:2003-03-27 20:00 M:2007-02-17 06:45]