【回复“carabe”的帖子】
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<CnsM.dll><Rundll32.exe C:\PROGRA~1\3721\CnsM.dll,Rundll32> [N/A]
<360Safetray><C:\Program Files\360safe\safemon\360tray.exe /start> [奇虎网]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<explorer><C:\WINDOWS\explorer.exe > [(Verified)Microsoft Corporation]
<IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<stup.exe><; C:\PROGRA~1\TENCENT\Adplus\stup.exe> [N/A]
<WebThunder><; D:\新建文件夹\WebThunder.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad]
<WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll> [(Verified)Microsoft Corporation]
<emau><C:\PROGRA~1\dlst\emau.dll> [N/A]
<wbwk><C:\PROGRA~1\dlst\emau.dll> [N/A]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><C:\WINDOWS\system32/SSDINE~1.SCR> [N/A]
==================================
启动文件夹
N/A
==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Vsn pxlc Service / pxlc][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\vari\shvp.dll,Service><Microsoft Corporation>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[smService / smService][Running/Auto Start]
<C:\WINDOWS\system32\smService.exe><N/A>
[yjsgts / yjsgts][Others/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\ljsgts\ljsgts.dll>< >
==================================
驱动程序
[ADProt / ADProt][Stopped/System Start]
<\SystemRoot\system32\drivers\ADProt.sys><腾讯科技(深圳)有限公司>
[Albus / Albus][Stopped/Boot Start]
<\SystemRoot\system32\drivers\Albus.SYS><N/A>
[cdnprot / cdnprot][Stopped/]
<2 - 系统找不到指定的文件。
><N/A>
[Crystal SoundFusion(tm) Driver / cwcspud][Running/Manual Start]
<system32\drivers\cwcspud.sys><Crystal Semiconductor Corp.>
[Crystal SoundFusion(tm) WDM Driver / cwcwdm][Running/Manual Start]
<system32\drivers\cwcwdm.sys><Crystal Semiconductor Corp.>
[decziib / decziib][Running/Boot Start]
<\SystemRoot\system32\drivers\decziib.sys><>
[3Com 10/100 MiniPCI Ethernet Adapter Driver / EL556ND5][Running/Manual Start]
<system32\DRIVERS\EL556ND5.sys><3Com Corporation>
[kmsinput / kmsinput][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[mjohnj / mjohnj][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\mjohnj.sys><N/A>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[npkycryp / npkycryp][Stopped/Manual Start]
<\??\C:\Program Files\Tencent\QQ\npkycryp.sys><N/A>
[NSC Infrared Device Driver / NSCIRDA][Running/Manual Start]
<system32\DRIVERS\nscirda.sys><National Semiconductor Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[S3SavageMX / S3SavageMX][Running/Manual Start]
<system32\DRIVERS\s3savmxm.sys><S3 Graphics, Inc.>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
<system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[IBM PS/2 TrackPoint Filter Driver / TwoTrack][Running/Manual Start]
<system32\DRIVERS\TwoTrack.sys><IBM Corporation>
[WDHAALBAMiniPCI Winmodem / WDHAALBA][Running/Manual Start]
<system32\DRIVERS\WDHAALBA.sys><3Com Corporation>
[zcnsicuo / zcnsicuo][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\zcnsicuo.sys><Yahoo! China Corporation>