[A ] 76. c:\windows\system32\notepad.exe
txtfile\print\Command
[A ] 76. c:\windows\system32\notepad.exe
txtfile\printto\Command
[A ] 76. c:\windows\system32\notepad.exe
+ HKCR\.txt
txtfile\open\Command
[A ] 76. c:\windows\system32\notepad.exe
txtfile\print\Command
[A ] 76. c:\windows\system32\notepad.exe
txtfile\printto\Command
[A ] 76. c:\windows\system32\notepad.exe
+ HKCR\.cmd
cmdfile\edit\Command
[A ] 76. c:\windows\system32\notepad.exe
cmdfile\print\Command
[A ] 76. c:\windows\system32\notepad.exe
+ HKCR\.reg
regfile\edit\Command
[A ] 76. c:\windows\system32\notepad.exe
regfile\print\Command
[A ] 76. c:\windows\system32\notepad.exe
+ HKCR\.vbs
VBSFile\Edit\Command
[A ] 76. c:\windows\system32\notepad.exe
VBSFile\Print\Command
[A ] 76. c:\windows\system32\notepad.exe
+ HKCR\.js
JSFile\Edit\Command
[A ] 76. c:\windows\system32\notepad.exe
JSFile\Print\Command
[A ] 76. c:\windows\system32\notepad.exe
+ HKCR\.ini
inifile\open\Command
[A ] 76. c:\windows\system32\notepad.exe
inifile\print\Command
[A ] 76. c:\windows\system32\notepad.exe
+ HKCR\.inf
inffile\open\Command
[A ] 76. c:\windows\system32\notepad.exe
inffile\print\Command
[A ] 76. c:\windows\system32\notepad.exe
+ 其他自启动项目
+ C:\Documents and Settings\liu yongjun\「开始」菜单\程序\启动
新浪UC.lnk
[A ] 46. c:\program files\sina\uc\uc.exe
+ C:\Documents and Settings\All Users\「开始」菜单\程序\启动
Adobe Reader Speed Launch.lnk
[A ] 78. c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
+ 系统活动模块
+ 000000dc(220) EabServr.exe
00400000[0001E000]
[ M] 79. c:\program files\compaq\eab\eabservr.exe
10000000[00027000]
[ M] 80. c:\program files\compaq\eab\eabcomn.dll
00930000[00012000]
[ M] 81. c:\program files\compaq\eab\cpqinfo.dll
00BB0000[00014000]
[ M] 82. c:\windows\system32\syntpfcs.dll
01030000[0001B000]
[ M] 83. c:\program files\rising\antispyware\ieprot.dll
+ 000000e8(232) VM_STI.EXE
00400000[0000D000]
[AM] 61. c:\windows\vm_sti.exe
63000000[00014000]
[ M] 82. c:\windows\system32\syntpfcs.dll
6BD00000[0000D000]
[ M] 84. c:\windows\system32\syncor11.dll
10000000[0001B000]
[ M] 83. c:\program files\rising\antispyware\ieprot.dll
+ 00000144(324) realsched.exe
00400000[0002F000]
[AM] 62. c:\program files\common files\real\update_ob\realsched.exe
63000000[00014000]
[ M] 82. c:\windows\system32\syntpfcs.dll
10000000[0001B000]
[ M] 83. c:\program files\rising\antispyware\ieprot.dll
+ 00000184(388) smss.exe
+ 00000200(512) conime.exe
63000000[00014000]
[ M] 82. c:\windows\system32\syntpfcs.dll
10000000[0001B000]
[ M] 83. c:\program files\rising\antispyware\ieprot.dll
+ 00000270(624) csrss.exe
+ 00000288(648) winlogon.exe
6BD00000[0000D000]
[ M] 84. c:\windows\system32\syncor11.dll
72C90000[00009000]
[ M] 85. c:\windows\system32\wdmaud.drv
72C80000[00008000]
[ M] 86. c:\windows\system32\msacm32.drv
10000000[00012000]
[ M] 87. c:\windows\system32\72c0726a.dll
+ 0000029c(668) Ati2evxx.exe
00400000[0001D000]
[AM] 1. c:\windows\system32\ati2evxx.exe
+ 000002b4(692) services.exe
+ 000002c0(704) lsass.exe
+ 00000364(868) svchost.exe
+ 000003dc(988) svchost.exe
6BD00000[0000D000]
[ M] 84. c:\windows\system32\syncor11.dll
+ 00000454(1108) svchost.exe
+ 00000468(1128) svchost.exe
+ 00000628(1576) Explorer.EXE
10000000[0001B000]
[AM] 54. c:\windows\system32\ravext.dll
011D0000[00014000]
[ M] 82. c:\windows\system32\syntpfcs.dll
6BD00000[0000D000]
[ M] 84. c:\windows\system32\syncor11.dll
72C90000[00009000]
[ M] 85. c:\windows\system32\wdmaud.drv
72C80000[00008000]
[ M] 86. c:\windows\system32\msacm32.drv
02B10000[0001B000]
[ M] 83. c:\program files\rising\antispyware\ieprot.dll
02E40000[00012000]
[ M] 87. c:\windows\system32\72c0726a.dll
03350000[00007000]
[ M] 88. c:\windows\system32\nwiztlbb.dll
00F60000[00006000]
[ M] 89. c:\windows\system32\nwizwlwzs.dll
03650000[0001C000]
[AM] 51. c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll
03730000[0002B000]
[AM] 52. c:\program files\winrar\rarext.dll
23700000[0001A000]
[ M] 90. c:\program files\rising\rav\rscommon.dll
03520000[0000E000]
[AM] 45. c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
7C340000[00056000]
[ M] 91. c:\windows\system32\msvcr71.dll
04300000[00005000]
[ M] 92. c:\windows\system32\mosou.dll
15000000[0000F000]
[ M] 93. c:\windows\system32\k11837988414.dat
03240000[00007000]
[ M] 94. c:\windows\system32\avpsrv.dll
039E0000[00006000]
[ M] 95. c:\windows\system32\nwizqjsj.dll
03A00000[00008000]
[ M] 96. c:\windows\system32\winform.dll
045F0000[00005000]
[ M] 97. c:\windows\system32\dh2104.dll
04610000[00009000]
[ M] 98. c:\windows\system32\timhost.dll
04690000[00006000]
[ M] 99. c:\windows\system32\nwizzhuxians.dll
03160000[00007000]
[ M] 100. c:\windows\system32\msimms32.dll
03190000[00008000]
[ M] 101. c:\windows\system32\cmdbcs.dll
+ 00000694(1684) spoolsv.exe
+ 000007b8(1976) ntsd.exe
+ 000007c4(1988) atiptaxx.exe
00400000[0004D000]
[AM] 57. c:\windows\system32\atiptaxx.exe
10000000[0000A000]
[ M] 102. c:\windows\system32\atrpuixx.chs
00A90000[0002B000]
[ M] 103. c:\windows\system32\atipdsxx.dll
00E10000[0001B000]
[ M] 83. c:\program files\rising\antispyware\ieprot.dll
+ 000007cc(1996) SynTPLpr.exe
00400000[0001C000]
[AM] 58. c:\program files\synaptics\syntp\syntplpr.exe
63000000[00014000]
[ M] 82. c:\windows\system32\syntpfcs.dll
10000000[0001B000]
[ M] 83. c:\program files\rising\antispyware\ieprot.dll
+ 000007d4(2004) SynTPEnh.exe
00400000[00073000]
[AM] 59. c:\program files\synaptics\syntp\syntpenh.exe
63010000[0001C000]
[ M] 104. c:\windows\system32\syntpapi.dll
00D30000[00014000]
[ M] 82. c:\windows\system32\syntpfcs.dll
10000000[0001B000]
[ M] 83. c:\program files\rising\antispyware\ieprot.dll
+ 000007d8(2008) RfwMain.exe
00400000[00073000]
[AM] 64. c:\program files\rising\rfw\rfwmain.exe
26600000[0007D000]
[ M] 105. c:\program files\rising\rfw\rsguilib.dll
6BD00000[0000D000]
[ M] 84. c:\windows\system32\syncor11.dll
23700000[0001A000]
[ M] 106. c:\program files\rising\rfw\rscommon.dll
10000000[0000F000]
[ M] 107. c:\program files\rising\rfw\rfwctrl.dll
23800000[0001A000]
[ M] 108. c:\program files\rising\rfw\rsxml.dll
23900000[00031000]
[ M] 109. c:\program files\rising\rfw\pngdll.dll
63000000[00014000]
[ M] 82. c:\windows\system32\syntpfcs.dll
01730000[0001B000]
[ M] 83. c:\program files\rising\antispyware\ieprot.dll
15000000[0000F000]
[ M] 93. c:\windows\system32\k11837988414.dat
+ 00000a8c(2700) Ras.exe
00400000[0013D000]
[ M] 110. c:\program files\rising\antispyware\ras.exe
15000000[0000F000]
[ M] 93. c:\windows\system32\k11837988414.dat
00DA0000[00014000]
[ M] 82. c:\windows\system32\syntpfcs.dll
10000000[000A0000]
[ M] 111. c:\program files\rising\antispyware\rasgui.dll
01820000[0001B000]
[ M] 83. c:\program files\rising\antispyware\ieprot.dll
6BD00000[0000D000]
[ M] 84. c:\windows\system32\syncor11.dll
02EC0000[00008000]
[ M] 96. c:\windows\system32\winform.dll
02EB0000[00007000]
[ M] 94. c:\windows\system32\avpsrv.dll
035B0000[00019000]
[ M] 112. c:\program files\rising\rav\ravscrch.dll
72C90000[00009000]
[ M] 85. c:\windows\system32\wdmaud.drv
72C80000[00008000]
[ M] 86. c:\windows\system32\msacm32.drv
03070000[0002F000]
[ M] 113. c:\program files\rising\antispyware\engine.dll
030A0000[00012000]
[ M] 114. c:\program files\rising\antispyware\zip.dll
+ 00000b40(2880) svchost.exe
+ 00000cec(3308) runiep.exe
00400000[00012000]
[AM] 65. c:\program files\rising\antispyware\runiep.exe
15000000[0000F000]
[ M] 93. c:\windows\system32\k11837988414.dat
10000000[00005000]
[ M] 92. c:\windows\system32\mosou.dll
00B20000[00014000]
[ M] 82. c:\windows\system32\syntpfcs.dll
010D0000[0001B000]
[ M] 83. c:\program files\rising\antispyware\ieprot.dll
+ 00000f7c(3964) ctfmon.exe
63000000[00014000]
[ M] 82. c:\windows\system32\syntpfcs.dll
10000000[0001B000]
[ M] 83. c:\program files\rising\antispyware\ieprot.dll
+ 00000fe8(4072) RavStub.exe
00400000[00018000]
[ M] 115. c:\program files\rising\rav\ravstub.exe
10000000[0001B000]
[ M] 116. c:\program files\rising\rav\rscommx.dll
23700000[0001A000]
[ M] 90. c:\program files\rising\rav\rscommon.dll