{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 47. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,
{28907901-1416-3389-9981-372178569982}
[AM] 48. c:\windows\system32\kawdbzy.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
{E418E9ED-9221-4661-B1F3-4AA35BD83832}
[AM] 49. c:\program files\internet explorer\plugins\winsys88.sys
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
{4859245F-345D-BC13-AC4F-145D47DA34F4}
[AM] 50. c:\windows\system32\avzxdmn.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 用户登陆自运行项目
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
High Definition Audio Property Page Shortcut
[A ] 51. c:\windows\system32\hdashcut.exe
Windows (R) Server 2003 DDK provider
High Definition Audio Property Page Shortcut v1.0a
.text,.data,.rsrc,
ATIPTA
[AM] 52. c:\program files\ati technologies\ati control panel\atiptaxx.exe
ATI Technologies, Inc.
ATI Desktop Control Panel
.text,.rdata,.data,.rsrc,
SoundMan
[AM] 53. c:\windows\soundman.exe
Realtek Semiconductor Corp.
Realtek Sound Manager
.text,.rdata,.data,.rsrc,
AlcWzrd
[AM] 54. c:\windows\alcwzrd.exe
RealTek Semicoductor Corp.
RealTek AlcWzrd Application
.text,.data,.tls,.rdata,.idata,.edata,.rsrc,.reloc,
Alcmtr
[A ] 55. c:\windows\alcmtr.exe
Realtek Semiconductor Corp.
Realtek Azalia Audio - Event Monitor
.text,.rdata,.data,.rsrc,
RavTask
[A ] 56. d:\program files\rising\rav\ravtask.exe
Beijing Rising Technology Co., Ltd.
RavTimer
.text,.rdata,.data,.rsrc,
runeip
[AM] 57. c:\program files\rising\antispyware\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
RfwMain
[AM] 58. d:\program files\rising\rfw\rfwmain.exe
Beijing Rising Technology Co., Ltd.
Rising Personal FireWall Main Program
.text,.rdata,.data,.rsrc,
GenProtect
[A ] 59. c:\windows\ozqyjz.exe
UPX0,UPX1,.rsrc,
DbgHlp32
[A ] 60. c:\windows\dbghlp32.exe
UPX0,UPX1,.rsrc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay
[A ] 61. c:\program files\rising\antispyware\runonce.exe
Beijing Rising Technology Co., Ltd.
RunOnce Application
.text,.rdata,.data,.rsrc,
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
MSDEG32
[A ] 62. c:\windows\system32\lyloader.exe
VL橸谚?_Y??G,QV?褤瑒,
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 63. c:\windows\system32\bsmain.exe
Beijing Rising Technology Co., Ltd.
BootScan
.text,.data,.rsrc,.reloc,
[A ] 64. c:\windows\system32\kknative.exe
Beijing Rising Technology Co., Ltd.
NativeAp
.text,.data,.rsrc,.reloc,
+ 映像劫持
+ HKCR\.html
htmlfile\Edit\Command
[A ] 65. c:\program files\microsoft office\office11\msohtmed.exe
Microsoft Corporation
Microsoft Office 2003 component
.text,.data,.rsrc,
htmlfile\Edit.VisualStudio.html.7.1\Command
[A ] 66. d:\program files\.net\common7\ide\devenv.exe
Microsoft Corporation
Microsoft Visual Studio .NET 2003
.text,.data,.rsrc,
htmlfile\Print\Command
[A ] 65. c:\program files\microsoft office\office11\msohtmed.exe
Microsoft Corporation
Microsoft Office 2003 component
.text,.data,.rsrc,
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 65. c:\program files\microsoft office\office11\msohtmed.exe
Microsoft Corporation
Microsoft Office 2003 component
.text,.data,.rsrc,
htmlfile\Edit.VisualStudio.html.7.1\Command
[A ] 66. d:\program files\.net\common7\ide\devenv.exe
Microsoft Corporation
Microsoft Visual Studio .NET 2003
.text,.data,.rsrc,
htmlfile\Print\Command
[A ] 65. c:\program files\microsoft office\office11\msohtmed.exe
Microsoft Corporation
Microsoft Office 2003 component
.text,.data,.rsrc,
+ HKCR\.vbs
VBSFile\Edit.VisualStudio.vbs.7.1\Command
[A ] 66. d:\program files\.net\common7\ide\devenv.exe
Microsoft Corporation
Microsoft Visual Studio .NET 2003
.text,.data,.rsrc,
+ HKCR\.js
JSFile\Edit.VisualStudio.js.7.1\Command
[A ] 66. d:\program files\.net\common7\ide\devenv.exe
Microsoft Corporation
Microsoft Visual Studio .NET 2003
.text,.data,.rsrc,
+ 程序初始化和已知动态连接库
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
[AM] 50. c:\windows\system32\avzxdmn.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 其他自启动项目
+ c:\autorun.inf
open
[A ] 67. c:\msn.exe
CODE,DATA,BSS,.idata,.tls,.rdata,.reloc,.rsrc,
shellexecute
[A ] 67. c:\msn.exe
CODE,DATA,BSS,.idata,.tls,.rdata,.reloc,.rsrc,
shell\Auto\command
[A ] 67. c:\msn.exe
CODE,DATA,BSS,.idata,.tls,.rdata,.reloc,.rsrc,
+ d:\autorun.inf
open
[A ] 68. d:\msn.exe
CODE,DATA,BSS,.idata,.tls,.rdata,.reloc,.rsrc,
shellexecute
[A ] 68. d:\msn.exe
CODE,DATA,BSS,.idata,.tls,.rdata,.reloc,.rsrc,
shell\Auto\command
[A ] 68. d:\msn.exe
CODE,DATA,BSS,.idata,.tls,.rdata,.reloc,.rsrc,
+ e:\autorun.inf
open
[A ] 69. e:\msn.exe
CODE,DATA,BSS,.idata,.tls,.rdata,.reloc,.rsrc,
shellexecute
[A ] 69. e:\msn.exe
CODE,DATA,BSS,.idata,.tls,.rdata,.reloc,.rsrc,
shell\Auto\command
[A ] 69. e:\msn.exe
CODE,DATA,BSS,.idata,.tls,.rdata,.reloc,.rsrc,
+ f:\autorun.inf
open
[A ] 70. f:\msn.exe
CODE,DATA,BSS,.idata,.tls,.rdata,.reloc,.rsrc,
shellexecute
[A ] 70. f:\msn.exe
CODE,DATA,BSS,.idata,.tls,.rdata,.reloc,.rsrc,
shell\Auto\command
[A ] 70. f:\msn.exe
CODE,DATA,BSS,.idata,.tls,.rdata,.reloc,.rsrc,
+ 正在运行的进程
+ 00000134(308) RavStub.exe
00400000[00018000]
[ M] 71. d:\program files\rising\rav\ravstub.exe
Beijing Rising Technology Co., Ltd.
Rising RavStub
.text,.rdata,.data,.rsrc,
10000000[0001B000]
[ M] 72. d:\program files\rising\rav\rscommx.dll
rising
RsCommX
.text,.rdata,.data,.rsrc,.reloc,
23700000[0001A000]
[ M] 73. d:\program files\rising\rav\rscommon.dll
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
+ 0000022c(556) wmiprvse.exe
003C0000[0000C000]
[AM] 50. c:\windows\system32\avzxdmn.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 00000284(644) alg.exe
10000000[00006000]
[ M] 74. c:\windows\system32\sqmapi32.dll
.text,.rdata,.data,.reloc,
+ 00000290(656) smss.exe
+ 000002d8(728) csrss.exe
+ 000002f0(752) winlogon.exe
004D0000[0000C000]
[AM] 50. c:\windows\system32\avzxdmn.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
10000000[00010000]
[AM] 34. c:\windows\system32\ati2evxx.dll
ATI Technologies Inc.
ATI External Event Utility DLL Module
.text,.rdata,.data,.rsrc,.reloc,
72C80000[00008000]
[ M] 75. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
+ 00000320(800) services.exe
003C0000[0000C000]
[AM] 50. c:\windows\system32\avzxdmn.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 00000324(804) RfwMain.exe
00400000[00073000]
[AM] 58. d:\program files\rising\rfw\rfwmain.exe
Beijing Rising Technology Co., Ltd.
Rising Personal FireWall Main Program
.text,.rdata,.data,.rsrc,
26600000[0007D000]
[ M] 76. d:\program files\rising\rfw\rsguilib.dll
Beijing Rising Technology Co., Ltd.
Rising GUI Library Loader
.text,.rdata,.data,.rsrc,.reloc,
23700000[0001A000]
[ M] 77. d:\program files\rising\rfw\rscommon.dll
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
10000000[0000F000]
[ M] 78. d:\program files\rising\rfw\rfwctrl.dll
Beijing Rising Technology Co., Ltd.
RfwCtrl DLL
.text,.rdata,.data,.rsrc,.reloc,
23800000[0001A000]
[ M] 79. d:\program files\rising\rfw\rsxml.dll
Beijing Rising Technology Co., Ltd.
RsXML
.text,.rdata,.data,.rsrc,.reloc,
23900000[00031000]
[ M] 80. d:\program files\rising\rfw\pngdll.dll
Beijing Rising Technology Co., Ltd.
Rising .Png File Loader Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,