viaagp1
[A ] 121. c:\windows\system32\drivers\viaagp1.sys
ViaIde
[A ] 122. c:\windows\system32\drivers\viaidexp.sys
VIAMRAID
[A ] 123. c:\windows\system32\bird\viamraid.sys
W2KADV
[A ] 124. c:\windows\system32\bird\w2kadv.sys
WD7296A
[A ] 125. c:\windows\system32\bird\wd7296a.sys
+ 文件系统驱动
+ HKLM\System\CurrentControlSet\Services
BdGuard
[A ] 126. c:\windows\system32\drivers\bdguard.sys
+ IE浏览器加载模块
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{B580CF65-E151-49C3-B73F-70B13FCA8E86}
[AM] 127. c:\program files\baidu\bar\baidubar.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{54EBD53A-9BC1-480B-966A-843A333CA162}
[A ] 128. c:\program files\tencent\qq\qqiehelper.dll
{77FEF28E-EB96-44FF-B511-3185DEA48697}
[AM] 127. c:\program files\baidu\bar\baidubar.dll
{889D2FEB-5411-4565-8998-1DD2C5261283}
[AM] 129. c:\program files\thunder network\thunder\comdlls\xunleibho_001.dll
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
Exec
[A ] 130. c:\program files\tencent\qq\qq.exe
Exec
[A ] 131. c:\program files\messenger\msmsgs.exe
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
text/xml
[A ] 132. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
+ HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers
{0561EC90-CE54-4f0c-9C55-E226110A740C}
[AM] 133. c:\program files\media player classic\codecs\mmfinfo.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 134. c:\windows\system32\hticons.dll
Portable Media Devices
[A ] 135. c:\windows\system32\audiodev.dll
Portable Media Devices Menu
[A ] 135. c:\windows\system32\audiodev.dll
WinRAR shell extension
[AM] 136. c:\program files\winrar\rarext.dll
Haali Column Provider
[AM] 133. c:\program files\media player classic\codecs\mmfinfo.dll
Microsoft Office HTML Icon Handler
[A ] 137. c:\program files\microsoft office\office11\msohev.dll
Web Folders
[A ] 138. c:\program files\common files\microsoft shared\web folders\msonsext.dll
NvCpl DesktopContext Class
[AM] 139. c:\windows\system32\nvcpl.dll
Play on my TV helper
[AM] 139. c:\windows\system32\nvcpl.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{51351752-5628-1547-FFAB-BADC13512AF5}
[AM] 140. c:\windows\system32\ztepri.dll
{12311A42-AC1B-158F-FD32-5674345F23A1}
[AM] 141. c:\windows\system32\dhapri.dll
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[A ] 142. c:\windows\system32\shlhook.dll
+ 用户登陆自运行项目
+ HKCU\Software\Microsoft\Windows\CurrentVersion\Run
bgswitch
[A ] 143. c:\windows\system32\bgswitch.exe
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
SunJavaUpdateSched
[AM] 144. c:\program files\java\jre1.5.0\bin\jusched.exe
tlsa
[A ] 145. c:\documents and settings\administrator\local settings\temp\tlso.exe
Microsoft Autorun7
[A ] 146. c:\windows\system32\nwizqjsj.exe
wdsa
[A ] 147. c:\documents and settings\administrator\local settings\temp\wdso.exe
cmdbcs
[A ] 148. c:\windows\cmdbcs.exe
KVP
[A ] 149. c:\windows\system32\drivers\svchost.exe
runeip
[AM] 150. c:\program files\rising\antispyware\runiep.exe
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay
[A ] 151. c:\program files\rising\antispyware\runonce.exe
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
MSDEG32
[A ] 152. c:\windows\system32\lyloader.exe
MSDMG32
[A ] 153. c:\windows\system32\lyloadmr.exe
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 154. c:\windows\system32\kknative.exe
+ 映像劫持
+ HKCR\.html
htmlfile\Edit\Command
[A ] 155. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 155. c:\program files\microsoft office\office11\msohtmed.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 155. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 155. c:\program files\microsoft office\office11\msohtmed.exe
+ 程序初始化和已知动态连接库
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
[AM] 141. c:\windows\system32\dhapri.dll
+ 打印机监控
+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
Canon BJ Language Monitor iP1600
[AM] 156. c:\windows\system32\cnmlm75.dll
+ 正在运行的进程
+ 00000114(276) ctfmon.exe
003D0000[0000B000]
[AM] 140. c:\windows\system32\ztepri.dll
10000000[0001B000]
[ M] 157. c:\program files\rising\antispyware\ieprot.dll
+ 00000130(304) calc.exe
003D0000[0000B000]
[AM] 140. c:\windows\system32\ztepri.dll
+ 00000190(400) smss.exe
+ 000001c8(456) csrss.exe
+ 000001e0(480) winlogon.exe
004D0000[0000B000]
[AM] 140. c:\windows\system32\ztepri.dll
72C80000[00008000]
[ M] 158. c:\windows\system32\msacm32.drv
+ 00000210(528) services.exe
003C0000[0000B000]
[AM] 140. c:\windows\system32\ztepri.dll
+ 0000021c(540) lsass.exe
003C0000[0000B000]
[AM] 140. c:\windows\system32\ztepri.dll
+ 0000027c(636) runiep.exe
00400000[00012000]
[AM] 150. c:\program files\rising\antispyware\runiep.exe
00C40000[0001B000]
[ M] 157. c:\program files\rising\antispyware\ieprot.dll
+ 000002b4(692) svchost.exe
003C0000[0000B000]
[AM] 140. c:\windows\system32\ztepri.dll
+ 0000031c(796) svchost.exe
003C0000[0000B000]
[AM] 140. c:\windows\system32\ztepri.dll
+ 00000368(872) svchost.exe
003C0000[0000B000]
[AM] 140. c:\windows\system32\ztepri.dll
+ 000003a8(936) svchost.exe
003C0000[0000B000]
[AM] 140. c:\windows\system32\ztepri.dll
+ 0000040c(1036) svchost.exe
003C0000[0000B000]
[AM] 140. c:\windows\system32\ztepri.dll
+ 00000444(1092) alg.exe
+ 000004b0(1200) Explorer.EXE
003D0000[0000B000]
[AM] 140. c:\windows\system32\ztepri.dll
00FB0000[0000A000]
[AM] 141. c:\windows\system32\dhapri.dll
10000000[0001B000]
[ M] 159. c:\windows\system32\ravext.dll
00C00000[0000E000]
[ M] 160. c:\windows\system32\lymangr.dll
00C30000[0000E000]
[ M] 161. c:\windows\system32\shqmangr.dll
00D30000[00005000]
[ M] 162. c:\documents and settings\administrator\local settings\temp\tlso0.dll
00D60000[00006000]
[ M] 163. c:\windows\system32\nwizqjsj.dll
00D70000[00006000]
[ M] 164. c:\documents and settings\administrator\local settings\temp\wdso0.dll
72C80000[00008000]
[ M] 158. c:\windows\system32\msacm32.drv
01330000[00009000]
[ M] 165. c:\windows\system32\cmdbcs.dll
02050000[0000F000]
[AM] 133. c:\program files\media player classic\codecs\mmfinfo.dll
02070000[0000B000]
[ M] 166. c:\program files\media player classic\codecs\mkunicode.dll
02970000[00555000]
[AM] 139. c:\windows\system32\nvcpl.dll
03BF0000[00137000]
[AM] 127. c:\program files\baidu\bar\baidubar.dll
03EB0000[0000C000]
[AM] 129. c:\program files\thunder network\thunder\comdlls\xunleibho_001.dll
02180000[0002B000]
[AM] 136. c:\program files\winrar\rarext.dll
01230000[0001B000]
[ M] 157. c:\program files\rising\antispyware\ieprot.dll
+ 00000528(1320) spoolsv.exe
003C0000[0000B000]
[AM] 140. c:\windows\system32\ztepri.dll
66F40000[00026000]
[AM] 156. c:\windows\system32\cnmlm75.dll
00AF0000[00008000]
[ M] 167. c:\windows\system32\spool\prtprocs\w32x86\cnmpd75.dll
+ 0000058c(1420) Ras.exe
00400000[0013F000]
[ M] 168. c:\program files\rising\antispyware\ras.exe
003D0000[0000B000]
[AM] 140. c:\windows\system32\ztepri.dll
10000000[000A3000]
[ M] 169. c:\program files\rising\antispyware\rasgui.dll
015E0000[0001B000]
[ M] 157. c:\program files\rising\antispyware\ieprot.dll
01D50000[00009000]
[ M] 165. c:\windows\system32\cmdbcs.dll
01D60000[00006000]
[ M] 164. c:\documents and settings\administrator\local settings\temp\wdso0.dll
01D70000[00005000]
[ M] 162. c:\documents and settings\administrator\local settings\temp\tlso0.dll
01D90000[0000A000]
[AM] 141. c:\windows\system32\dhapri.dll
02B50000[0002F000]
[ M] 170. c:\program files\rising\antispyware\engine.dll
02B80000[00012000]
[ M] 171. c:\program files\rising\antispyware\zip.dll
+ 000005d8(1496) jusched.exe
00400000[00009000]
[AM] 144. c:\program files\java\jre1.5.0\bin\jusched.exe
003C0000[0000B000]
[AM] 140. c:\windows\system32\ztepri.dll
+ 000006cc(1740) taskmgr.exe
003D0000[0000A000]
[AM] 141. c:\windows\system32\dhapri.dll
10000000[00009000]
[ M] 165. c:\windows\system32\cmdbcs.dll
00CA0000[00006000]
[ M] 164. c:\documents and settings\administrator\local settings\temp\wdso0.dll
00CB0000[00005000]
[ M] 162. c:\documents and settings\administrator\local settings\temp\tlso0.dll
00CC0000[0000B000]
[AM] 140. c:\windows\system32\ztepri.dll
00DF0000[0001B000]
[ M] 157. c:\program files\rising\antispyware\ieprot.dll
+ 00000724(1828) IEXPLORE.EXE
003C0000[0000B000]
[AM] 140. c:\windows\system32\ztepri.dll
+ 0000074c(1868) nvsvc32.exe
00400000[00021000]
[AM] 2. c:\windows\system32\nvsvc32.exe
+ 000007e8(2024) wdfmgr.exe
01000000[0000C000]
[AM] 4. c:\windows\system32\wdfmgr.exe
00560000[0000B000]
[AM] 140. c:\windows\system32\ztepri.dll