注释: [A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
+ 系统服务
+ HKLM\System\CurrentControlSet\Services
RsCCenter
[A ] 1. c:\program files\rising\rav\ccenter.exe
RsRavMon
[A ] 2. c:\program files\rising\rav\ravmond.exe
WMPNetworkSvc
[A ] 3. c:\program files\windows media player\wmpnetwk.exe
WudfSvc
[A ] 4. c:\windows\system32\wudfsvc.dll
+ 内核驱动
+ HKLM\System\CurrentControlSet\Services
BaseTDI
[A ] 5. c:\windows\system32\drivers\basetdi.sys
Cap7134
[A ] 6. c:\windows\system32\drivers\cap7134.sys
cmuda
[A ] 7. c:\windows\system32\drivers\cmuda.sys
EagleNT
[A ] 8. c:\windows\system32\drivers\eaglent.sys
ExpScaner
[A ] 9. c:\program files\rising\rav\expscan.sys
FETNDISB
[A ] 10. c:\windows\system32\drivers\fetnd5b.sys
HookCont
[A ] 11. c:\program files\rising\rav\hookcont.sys
HookReg
[A ] 12. c:\program files\rising\rav\hookreg.sys
HookSys
[A ] 13. c:\program files\rising\rav\hooksys.sys
ialm
[A ] 14. c:\windows\system32\drivers\ialmnt5.sys
kmsinput
[A ] 15. c:\windows\system32\drivers\kmsinput.sys
MEMSCAN
[A ] 16. c:\program files\rising\rav\memscan.sys
npkcrypt
[A ] 17. c:\documents and settings\administrator\my documents\qq\npkcrypt.sys
NTSIM
[A ] 18. c:\windows\system32\ntsim.sys
PhTVTune
[A ] 19. c:\windows\system32\drivers\phtvtune.sys
prodrv06
[A ] 20. c:\windows\system32\drivers\prodrv06.sys
prohlp02
[A ] 21. c:\windows\system32\drivers\prohlp02.sys
prosync1
[A ] 22. c:\windows\system32\drivers\prosync1.sys
QKeyService
[A ] 23. c:\windows\system32\keycrypt.sys
RsAntiSpyware
[A ] 24. c:\windows\system32\drivers\rsboot.sys
RsNTGDI
[A ] 25. c:\windows\system32\drivers\rsntgdi.sys
RSPPSYS
[A ] 26. c:\program files\rising\rav\rsppsys.sys
Secdrv
[A ] 27. c:\windows\system32\drivers\secdrv.sys
SetupNT
[A ] 28. c:\windows\system32\setupnt.sys
sfhlp01
[A ] 29. c:\windows\system32\drivers\sfhlp01.sys
WudfPf
[A ] 30. c:\windows\system32\drivers\wudfpf.sys
WudfRd
[A ] 31. c:\windows\system32\drivers\wudfrd.sys
xltgmy11
[A ] 32. c:\windows\system32\drivers\xltgmy11.sys
ZSMC301b
[A ] 33. c:\windows\system32\drivers\usbvm31b.sys
ztjrmu57
[A ] 34. c:\windows\system32\drivers\ztjrmu57.sys
+ 系统登陆自运行
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
igfxcui
[A ] 35. c:\windows\system32\igfxsrvc.dll
WgaLogon
[AM] 36. c:\windows\system32\wgalogon.dll
+ IE浏览器加载模块
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C}
[A ] 37. c:\windows\system32\kakatool.dll
{43869BB3-22FD-4F15-9B46-238106BA2F4E}
[A ] 38. c:\program files\super rabbit\magicset\haokanbar.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3}
[A ] 38. c:\program files\super rabbit\magicset\haokanbar.dll
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
Exec
[A ] 39. c:\program files\thunder network\thunder\thunder.exe
Exec
[A ] 40. c:\program files\herosoft\herov8\sthsdvd.exe
Exec
[A ] 41. c:\program files\messenger\msmsgs.exe
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
cetihpz
[A ] 42. c:\program files\hp\hpcoretech\comp\hpuiprot.dll
KuGoo3
[A ] 43. c:\program files\kugoo3\inextend\kugoo3downxcontrol.ocx
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 44. c:\windows\system32\hticons.dll
WinRAR shell extension
[AM] 45. c:\program files\winrar\rarext.dll
PicaView
[A ] 46. c:\program files\acdsee\picaview.dll
RISING
[AM] 47. c:\windows\system32\ravext.dll
Portable Media Devices
[A ] 48. c:\windows\system32\audiodev.dll
Portable Devices
[A ] 49. c:\windows\system32\wpdshext.dll
Portable Devices Menu
[A ] 49. c:\windows\system32\wpdshext.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
WPDShServiceObj
[AM] 50. c:\windows\system32\wpdshserviceobj.dll
+ 用户登陆自运行项目
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
IgfxTray
[A ] 51. c:\windows\system32\igfxtray.exe
HotKeysCmds
[A ] 52. c:\windows\system32\hkcmd.exe
RavTask
[A ] 53. c:\program files\rising\rav\ravtask.exe
BigDogPath
[AM] 54. c:\windows\vm_sti.exe
DeviceDiscovery
[AM] 55. c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe
HP Software Update
[AM] 56. c:\program files\hewlett-packard\hp software update\hpwuschd.exe
runeip
[AM] 57. c:\program files\rising\kakatoolbar\runiep.exe
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay
[A ] 58. c:\program files\rising\kakatoolbar\runonce.exe
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 59. c:\windows\system32\bsmain.exe
[A ] 60. c:\windows\system32\kknative.exe
+ 映像劫持
+ HKCR\.html
htmlfile\Edit\Command
[A ] 61. c:\program files\microsoft office\office\msohtmed.exe
htmlfile\open\Command
[A ] 62. c:\program files\tencent\tt\ttraveler.exe
htmlfile\Print\Command
[A ] 61. c:\program files\microsoft office\office\msohtmed.exe
htmlfile\TencentTraveler\Command
[A ] 62. c:\program files\tencent\tt\ttraveler.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 61. c:\program files\microsoft office\office\msohtmed.exe
htmlfile\open\Command
[A ] 62. c:\program files\tencent\tt\ttraveler.exe
htmlfile\Print\Command
[A ] 61. c:\program files\microsoft office\office\msohtmed.exe
htmlfile\TencentTraveler\Command
[A ] 62. c:\program files\tencent\tt\ttraveler.exe
+ 打印机监控
+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
hpzsnt09
[AM] 63. c:\windows\system32\hpzsnt09.dll
+ 其他自启动项目
+ C:\Documents and Settings\Administrator\「开始」菜单\程序\启动
QQ游戏启动加速程序.lnk
[A ] 64. e:\qq\qqgame\accel.exe
腾讯QQ.lnk
[AM] 65. c:\documents and settings\administrator\my documents\qq\qq.exe
+ C:\Documents and Settings\All Users\「开始」菜单\程序\启动
Adobe Gamma Loader.lnk
[A ] 66. c:\program files\common files\adobe\calibration\adobe gamma loader.exe
+ 正在运行的进程
+ 000000e8(232) alg.exe
+ 0000022c(556) VM_STI.EXE
00400000[0000D000]
[AM] 54. c:\windows\vm_sti.exe
10000000[0001B000]
[ M] 67. c:\program files\rising\kakatoolbar\ieprot.dll
+ 00000234(564) smss.exe
+ 00000248(584) hpotdd01.exe
00400000[0003A000]
[AM] 55. c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe
10000000[00048000]
[ M] 68. c:\program files\hewlett-packard\digital imaging\bin\hpodvd08.dll
00CD0000[001D1000]
[ M] 69. c:\windows\system32\unispim5.ime
01190000[0001E000]
[ M] 70. c:\program files\hewlett-packard\digital imaging\bin\hpqcxm08.dll
011C0000[0001B000]
[ M] 67. c:\program files\rising\kakatoolbar\ieprot.dll
+ 00000284(644) csrss.exe
+ 0000029c(668) winlogon.exe
01300000[0003B000]
[AM] 36. c:\windows\system32\wgalogon.dll
10000000[001D1000]
[ M] 69. c:\windows\system32\unispim5.ime
72C80000[00008000]
[ M] 71. c:\windows\system32\msacm32.drv
+ 000002c8(712) services.exe
+ 000002d4(724) lsass.exe
+ 0000033c(828) HPWuSchd.exe
00400000[0000C000]
[AM] 56. c:\program files\hewlett-packard\hp software update\hpwuschd.exe
10000000[001D1000]
[ M] 69. c:\windows\system32\unispim5.ime
00D60000[0001B000]
[ M] 67. c:\program files\rising\kakatoolbar\ieprot.dll
+ 0000036c(876) svchost.exe
+ 00000380(896) runiep.exe
00400000[00012000]
[AM] 57. c:\program files\rising\kakatoolbar\runiep.exe
10000000[001D1000]
[ M] 69. c:\windows\system32\unispim5.ime
00F10000[0001B000]
[ M] 67. c:\program files\rising\kakatoolbar\ieprot.dll