+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
Exec
[A ] 32. c:\program files\thunder network\thunder\thunder.exe
Thunder Networking Technologies,LTD
.text,.rdata,.data,.rsrc,
Exec
[A ] 33. c:\program files\messenger\msmsgs.exe
Microsoft Corporation
Windows Messenger
.text,.data,.rsrc,
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
application/octet-stream
[A ] 34. c:\windows\system32\mscoree.dll
Microsoft Corporation
Microsoft .NET Runtime Execution Engine
.text,.data,.rsrc,.reloc,
application/x-complus
[A ] 34. c:\windows\system32\mscoree.dll
Microsoft Corporation
Microsoft .NET Runtime Execution Engine
.text,.data,.rsrc,.reloc,
application/x-msdownload
[A ] 34. c:\windows\system32\mscoree.dll
Microsoft Corporation
Microsoft .NET Runtime Execution Engine
.text,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 35. c:\windows\system32\hticons.dll
Hilgraeve, Inc.
HyperTerminal Applet Library
.text,.data,.rsrc,.reloc,
Portable Media Devices
[A ] 36. c:\windows\system32\audiodev.dll
Microsoft Corporation
便携媒体设备命令行解释器扩展
.text,.data,.rsrc,.reloc,
Portable Media Devices Menu
[A ] 36. c:\windows\system32\audiodev.dll
Microsoft Corporation
便携媒体设备命令行解释器扩展
.text,.data,.rsrc,.reloc,
WinRAR shell extension
[A ] 37. c:\tools\winrar\rarext.dll
.text,.data,.tls,.idata,.edata,.rsrc,.reloc,
RISING
[AM] 38. c:\windows\system32\ravext.dll
Beijing Rising Technology Co., Ltd.
Rising Shell Ext Module
.text,.rdata,.data,.rsrc,.reloc,
ShellLink for Application References
[A ] 39. c:\windows\system32\dfshim.dll
Microsoft Corporation
Application Deployment Support Library
.text,.data,.rsrc,.reloc,
Shell Icon Handler for Application References
[A ] 39. c:\windows\system32\dfshim.dll
Microsoft Corporation
Application Deployment Support Library
.text,.data,.rsrc,.reloc,
Catalyst Context Menu extension
[A ] 40. c:\program files\ati technologies\ati.ace\core-static\atiacmxx.dll
ACE Context Menu
.text,.rdata,.data,.rsrc,.reloc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{32CD708B-60A7-4C00-9377-D73EAA495F0F}
[AM] 38. c:\windows\system32\ravext.dll
Beijing Rising Technology Co., Ltd.
Rising Shell Ext Module
.text,.rdata,.data,.rsrc,.reloc,
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 41. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,
+ 用户登陆自运行项目
+ HKCU\Software\Microsoft\Windows\CurrentVersion\Run
bgswitch
[A ] 42. c:\windows\system32\bgswitch.exe
.text,.data,.rsrc,
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
RavTask
[A ] 43. c:\tools\rising\rav\ravtask.exe
Beijing Rising Technology Co., Ltd.
RavTimer
.text,.rdata,.data,.rsrc,
RfwMain
[AM] 44. c:\tools\rising\rfw\rfwmain.exe
Beijing Rising Technology Co., Ltd.
Rising Personal FireWall Main Program
.text,.rdata,.data,.rsrc,
runeip
[AM] 45. c:\program files\rising\antispyware\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
SoundMan
[AM] 46. c:\windows\soundman.exe
Realtek Semiconductor Corp.
Realtek Sound Manager
.text,.rdata,.data,.sxdata,.rsrc,
IMSCMIG40W
[A ] 47. c:\program files\common files\microsoft shared\ime\imsc40w\imscmig.exe
Microsoft Corporation
微软拼音输入法安装工具
.text,.rdata,.data,.rsrc,
DAEMON Tools-2052
[AM] 48. c:\program files\d-tools\daemon.exe
DAEMON'S HOME
Virtual DAEMON Manager
.text,.rdata,.data,.rsrc,
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 49. c:\windows\system32\bsmain.exe
Beijing Rising Technology Co., Ltd.
BootScan
.text,.data,.rsrc,.reloc,
+ 正在运行的进程
+ 000001c4(452) smss.exe
+ 00000204(516) csrss.exe
+ 00000220(544) winlogon.exe
10000000[0001F000]
[AM] 28. c:\windows\system32\ati2evxx.dll
ATI Technologies Inc.
ATI External Event Utility DLL Module
.text,.rdata,.data,.rsrc,.reloc,
72C80000[00008000]
[ M] 50. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
+ 0000024c(588) services.exe
+ 00000258(600) lsass.exe
+ 000002f0(752) Ati2evxx.exe
00400000[0007B000]
[AM] 2. c:\windows\system32\ati2evxx.exe
ATI Technologies Inc.
ATI External Event Utility EXE Module
.text,.rdata,.data,.rsrc,
00D70000[00010000]
[ M] 51. c:\windows\system32\ati2edxx.dll
ATI Technologies, Inc.
ati2edxx
.text,.data,.SHAREDS,.rsrc,.reloc,
10000000[00025000]
[ M] 52. c:\windows\system32\atipdlxx.dll
ATI Technologies, Inc.
ATI Desktop CWDDEDI DLL
.text,.rdata,.data,.rsrc,.reloc,
+ 000002fc(764) svchost.exe
+ 00000344(836) svchost.exe
+ 0000039c(924) svchost.exe
+ 000003c8(968) svchost.exe
+ 00000430(1072) svchost.exe
+ 0000044c(1100) Ati2evxx.exe
00400000[0007B000]
[AM] 2. c:\windows\system32\ati2evxx.exe
ATI Technologies Inc.
ATI External Event Utility EXE Module
.text,.rdata,.data,.rsrc,
00DC0000[00010000]
[ M] 51. c:\windows\system32\ati2edxx.dll
ATI Technologies, Inc.
ati2edxx
.text,.data,.SHAREDS,.rsrc,.reloc,
10000000[00025000]
[ M] 52. c:\windows\system32\atipdlxx.dll
ATI Technologies, Inc.
ATI Desktop CWDDEDI DLL
.text,.rdata,.data,.rsrc,.reloc,
00DF0000[0001F000]
[AM] 28. c:\windows\system32\ati2evxx.dll
ATI Technologies Inc.
ATI External Event Utility DLL Module
.text,.rdata,.data,.rsrc,.reloc,
+ 0000056c(1388) spoolsv.exe
+ 000005b8(1464) RavStub.exe
00400000[00018000]
[ M] 53. c:\tools\rising\rav\ravstub.exe
Beijing Rising Technology Co., Ltd.
Rising RavStub
.text,.rdata,.data,.rsrc,
10000000[0001B000]
[ M] 54. c:\tools\rising\rav\rscommx.dll
rising
RsCommX
.text,.rdata,.data,.rsrc,.reloc,
23700000[0001A000]
[ M] 55. c:\tools\rising\rav\rscommon.dll
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
+ 000006c4(1732) Explorer.EXE
10000000[0001B000]
[AM] 38. c:\windows\system32\ravext.dll
Beijing Rising Technology Co., Ltd.
Rising Shell Ext Module
.text,.rdata,.data,.rsrc,.reloc,
00F30000[00011000]
[AM] 41. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,
01580000[0001B000]
[ M] 56. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
72C80000[00008000]
[ M] 50. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
+ 000006e8(1768) alg.exe
+ 00000730(1840) RfwMain.exe
00400000[00073000]
[AM] 44. c:\tools\rising\rfw\rfwmain.exe
Beijing Rising Technology Co., Ltd.
Rising Personal FireWall Main Program
.text,.rdata,.data,.rsrc,
26600000[0007D000]
[ M] 57. c:\tools\rising\rfw\rsguilib.dll
Beijing Rising Technology Co., Ltd.
Rising GUI Library Loader
.text,.rdata,.data,.rsrc,.reloc,
23700000[0001A000]
[ M] 58. c:\tools\rising\rfw\rscommon.dll
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
10000000[0000F000]
[ M] 59. c:\tools\rising\rfw\rfwctrl.dll
Beijing Rising Technology Co., Ltd.
RfwCtrl DLL
.text,.rdata,.data,.rsrc,.reloc,