+ 用户登陆自运行项目
+ HKCU\Software\Microsoft\Windows\CurrentVersion\Run
bgswitch
[A ] 47. c:\windows\system32\bgswitch.exe
MsnMsgr
[A ] 48. c:\program files\msn messenger\msnmsgr.exe
TudouVAStart
[A ] 49. d:\program files\todou\飞速tudou\tudouva.exe
Picasa Media Detector
[A ] 50. d:\program files\picasa\picasa2\picasamediadetector.exe
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
RTHDCPL
[AM] 51. c:\windows\rthdcpl.exe
SkyTel
[A ] 52. c:\windows\skytel.exe
Alcmtr
[A ] 53. c:\windows\alcmtr.exe
StormCodec_Helper
[A ] 54. c:\program files\ringz studio\storm codec\stormset.exe
MINI_BFYY
[AM] 55. c:\program files\ringz studio\storm downloader\stormdownloader.exe
WangWang
[A ] 56. d:\program files\淘宝网\wangwang\wangwang.exe
miniqqlive
[A ] 57. d:\program files\qq软件\miniqqlive.exe
runeip
[AM] 58. d:\program files\kaka\runiep.exe
RavTask
[AM] 59. d:\program files\ruixing\rising\rav\ravtask.exe
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay
[A ] 60. d:\program files\kaka\runonce.exe
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 61. c:\windows\system32\bsmain.exe
[A ] 62. c:\windows\system32\kknative.exe
+ 映像劫持
+ HKCR\.html
htmlfile\Edit\Command
[A ] 63. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 63. c:\program files\microsoft office\office11\msohtmed.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 63. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 63. c:\program files\microsoft office\office11\msohtmed.exe
+ 其他自启动项目
+ C:\Documents and Settings\Administrator\「开始」菜单\程序\启动
Adobe Gamma.lnk
[A ] 64. c:\program files\common files\adobe\calibration\adobe gamma loader.exe
+ 正在运行的进程
+ 000000e0(224) RUNDLL32.EXE
10000000[00017000]
[ M] 65. c:\windows\system32\nvmctray.dll
00A10000[0001B000]
[ M] 66. d:\program files\kaka\ieprot.dll
+ 000000e8(232) RTHDCPL.EXE
00400000[01058000]
[AM] 51. c:\windows\rthdcpl.exe
72C80000[00008000]
[ M] 67. c:\windows\system32\msacm32.drv
10000000[0001D000]
[AM] 33. c:\program files\360safe\safemon\safemon.dll
04A60000[0001B000]
[ M] 66. d:\program files\kaka\ieprot.dll
+ 0000015c(348) StormDownloader.exe
00400000[000B6000]
[AM] 55. c:\program files\ringz studio\storm downloader\stormdownloader.exe
10000000[0000C000]
[ M] 68. c:\program files\ringz studio\storm downloader\boost_thread-vc6-mt-1_31.dll
00A40000[0001B000]
[ M] 66. d:\program files\kaka\ieprot.dll
+ 00000168(360) LaunchApplication.exe
00400000[0003A000]
[ M] 69. d:\program files\pc\nokia pc suite 6\launchapplication.exe
10000000[000A4000]
[ M] 70. d:\program files\pc\nokia pc suite 6\pcscm.dll
7C3A0000[0007B000]
[ M] 71. c:\windows\system32\msvcp71.dll
7C340000[00056000]
[ M] 72. c:\windows\system32\msvcr71.dll
00370000[00015000]
[ M] 73. d:\program files\pc\nokia pc suite 6\pcssupportsetup.dll
00390000[0005F000]
[ M] 74. c:\program files\pc connectivity solution\connapi.dll
00440000[00102000]
[ M] 75. c:\windows\system32\mfc71u.dll
5D360000[0000A000]
[ M] 76. c:\windows\system32\mfc71chs.dll
01330000[00032000]
[ M] 77. c:\program files\pc connectivity solution\confserver.dll
01910000[0001D000]
[AM] 33. c:\program files\360safe\safemon\safemon.dll
01990000[0000B000]
[AM] 34. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
01320000[00004000]
[ M] 78. d:\program files\pc\nokia pc suite 6\lang\launchapplication_chi-sc.nlr
02950000[0001B000]
[ M] 66. d:\program files\kaka\ieprot.dll
+ 000001b0(432) alg.exe
+ 00000268(616) smss.exe
+ 000002a8(680) csrss.exe
+ 000002ac(684) ctfmon.exe
10000000[0001B000]
[ M] 66. d:\program files\kaka\ieprot.dll
+ 000002d0(720) winlogon.exe
013C0000[0003B000]
[AM] 29. c:\windows\system32\wgalogon.dll
72C80000[00008000]
[ M] 67. c:\windows\system32\msacm32.drv
+ 000002fc(764) services.exe
47260000[0000F000]
[ M] 79. c:\windows\apppatch\acadproc.dll
+ 00000308(776) lsass.exe
+ 000003a0(928) svchost.exe
+ 000003f0(1008) svchost.exe
+ 00000450(1104) CCenter.exe
00400000[00028000]
[AM] 5. d:\program files\ruixing\rising\rav\ccenter.exe
+ 00000460(1120) svchost.exe
50E60000[0000C000]
[ M] 80. c:\windows\system32\wups2.dll
+ 00000480(1152) svchost.exe
20D40000[00010000]
[AM] 9. c:\windows\system32\wudfsvc.dll
007B0000[0002B000]
[ M] 81. c:\windows\system32\wudfplatform.dll
+ 000004b0(1200) svchost.exe
+ 000004ec(1260) svchost.exe
+ 000004f8(1272) 360Tray.exe
00400000[0002A000]
[ M] 82. c:\program files\360safe\safemon\360tray.exe
10000000[0001D000]
[AM] 33. c:\program files\360safe\safemon\safemon.dll
00B30000[0000C000]
[ M] 83. c:\program files\360safe\safemon\safekrnl.dll
00B40000[00022000]
[ M] 84. c:\program files\360safe\antiadwa.dll
00BB0000[0001B000]
[ M] 66. d:\program files\kaka\ieprot.dll
+ 0000050c(1292) RavTask.exe
00400000[00034000]
[AM] 59. d:\program files\ruixing\rising\rav\ravtask.exe
10000000[0001F000]
[ M] 85. d:\program files\ruixing\rising\rav\proccom.dll
00A30000[00024000]
[ M] 86. d:\program files\ruixing\rising\rav\rscommx2.dll
23700000[00028000]
[ M] 87. d:\program files\ruixing\rising\rav\rscommon.dll
00C90000[0000E000]
[ M] 88. d:\program files\ruixing\rising\rav\rsappmgr.dll
08CB0000[00030000]
[ M] 89. d:\program files\ruixing\rising\rav\cfgdll.dll
08FE0000[0001B000]
[ M] 66. d:\program files\kaka\ieprot.dll
+ 00000534(1332) Ravmond.exe
00400000[0006C000]
[AM] 6. d:\program files\ruixing\rising\rav\ravmond.exe
10000000[00042000]
[ M] 90. d:\program files\ruixing\rising\rav\bwlist.dll
7C140000[00103000]
[ M] 91. c:\windows\system32\mfc71.dll
7C340000[00056000]
[ M] 72. c:\windows\system32\msvcr71.dll
7C3A0000[0007B000]
[ M] 71. c:\windows\system32\msvcp71.dll
5D360000[0000A000]
[ M] 76. c:\windows\system32\mfc71chs.dll
00B20000[0000E000]
[ M] 88. d:\program files\ruixing\rising\rav\rsappmgr.dll
00B40000[00030000]
[ M] 89. d:\program files\ruixing\rising\rav\cfgdll.dll
00EB0000[00066000]
[ M] 92. d:\program files\ruixing\rising\rav\rslog.dll
00F20000[0001F000]
[ M] 85. d:\program files\ruixing\rising\rav\proccom.dll
00F40000[00024000]
[ M] 86. d:\program files\ruixing\rising\rav\rscommx2.dll
00FD0000[00075000]
[ M] 93. d:\program files\ruixing\rising\rav\monrule.dll
01060000[00013000]
[ M] 94. d:\program files\ruixing\rising\rav\hooksys.dll
011C0000[00013000]
[ M] 95. d:\program files\ruixing\rising\rav\hookreg.dll
01220000[00013000]
[ M] 96. d:\program files\ruixing\rising\rav\hookntos.dll
01280000[0001B000]
[ M] 97. d:\program files\ruixing\rising\rav\rswalmon.dll
022B0000[00020000]
[ M] 98. d:\program files\ruixing\rising\rav\rsstore.dll