ST8350
[A ] 109. c:\windows\system32\drivers\st8350.sys
SYMMPI
[A ] 110. c:\windows\system32\drivers\symmpi.sys
TRM3X5
[A ] 111. c:\windows\system32\drivers\trm3x5.sys
ULSATA
[A ] 112. c:\windows\system32\drivers\ulsata.sys
ULSATA2
[A ] 113. c:\windows\system32\drivers\ulsata2.sys
ULTIMA
[A ] 114. c:\windows\system32\drivers\ultima.sys
ULTIMARX
[A ] 115. c:\windows\system32\drivers\ultimarx.sys
VIAMRAID
[A ] 116. c:\windows\system32\drivers\viamraid.sys
viapdsk
[A ] 117. c:\windows\system32\drivers\viapdsk.sys
vmscsi
[A ] 118. c:\windows\system32\drivers\vmscsi.sys
WD7296A
[A ] 119. c:\windows\system32\drivers\wd7296a.sys
WINIO
[A ] 120. h:\winio.sys
+ IE浏览器加载模块
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{2318C2B1-4965-11d4-9B18-009027A5CD4F}
[AM] 121. c:\program files\google\googletoolbar1.dll
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C}
[AM] 122. c:\windows\system32\kakatool.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
{AA58ED58-01DD-4d91-8333-CF10577473F7}
[AM] 121. c:\program files\google\googletoolbar1.dll
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
text/xml
[A ] 123. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 124. c:\windows\system32\hticons.dll
Portable Media Devices
[A ] 125. c:\windows\system32\audiodev.dll
Portable Media Devices Menu
[A ] 125. c:\windows\system32\audiodev.dll
Microsoft Office HTML Icon Handler
[AM] 126. c:\program files\microsoft office\office11\msohev.dll
Web Folders
[A ] 127. c:\program files\common files\microsoft shared\web folders\msonsext.dll
WinRAR shell extension
[A ] 128. c:\program files\winrar\rarext.dll
Shell Extensions for RealOne Player
[A ] 129. c:\program files\real\realplayer\rpshell.dll
NvCpl DesktopContext Class
[AM] 130. c:\windows\system32\nvcpl.dll
Play on my TV helper
[AM] 130. c:\windows\system32\nvcpl.dll
Desktop Explorer
[AM] 131. c:\windows\system32\nvshell.dll
Desktop Explorer Menu
[AM] 131. c:\windows\system32\nvshell.dll
nView Desktop Context Menu
[AM] 131. c:\windows\system32\nvshell.dll
RISING
[AM] 132. c:\windows\system32\ravext.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{32CD708B-60A7-4C00-9377-D73EAA495F0F}
[AM] 132. c:\windows\system32\ravext.dll
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 133. c:\windows\system32\shlhook.dll
+ 用户登陆自运行项目
+ HKCU\Software\Microsoft\Windows\CurrentVersion\Run
swg
[AM] 134. c:\program files\google\googletoolbarnotifier\1.2.1128.5462\googletoolbarnotifier.exe
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
RTHDCPL
[AM] 135. c:\windows\rthdcpl.exe
SkyTel
[A ] 136. c:\windows\skytel.exe
Alcmtr
[A ] 137. c:\windows\alcmtr.exe
nwiz
[A ] 138. c:\windows\system32\nwiz.exe
RfwMain
[AM] 139. c:\program files\rising\rfw\rfwmain.exe
RavTask
[A ] 140. c:\program files\rising\rav\ravtask.exe
runeip
[AM] 141. c:\program files\rising\kakatoolbar\runiep.exe
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
RavStub
[AM] 142. c:\program files\rising\rav\ravstub.exe
KKDelay
[A ] 143. c:\program files\rising\kakatoolbar\runonce.exe
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 144. c:\windows\system32\bsmain.exe
[A ] 145. c:\windows\system32\kknative.exe
+ 映像劫持
+ HKCR\.html
htmlfile\Edit\Command
[A ] 146. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 146. c:\program files\microsoft office\office11\msohtmed.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 146. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 146. c:\program files\microsoft office\office11\msohtmed.exe
+ 正在运行的进程
+ 000000c4(196) runiep.exe
00400000[00012000]
[AM] 141. c:\program files\rising\kakatoolbar\runiep.exe
00C00000[0001B000]
[ M] 147. c:\program files\rising\kakatoolbar\ieprot.dll
+ 000000f0(240) ctfmon.exe
10000000[0001B000]
[ M] 147. c:\program files\rising\kakatoolbar\ieprot.dll
+ 0000015c(348) GoogleToolbarNotifier.exe
00400000[0002C000]
[AM] 134. c:\program files\google\googletoolbarnotifier\1.2.1128.5462\googletoolbarnotifier.exe
10000000[0000E000]
[ M] 148. c:\program files\google\googletoolbarnotifier\1.2.1128.5462\res_zh-cn.dll
00DF0000[00042000]
[ M] 149. c:\program files\google\googletoolbarnotifier\1.2.1128.5462\swg.dll
01150000[0001B000]
[ M] 147. c:\program files\rising\kakatoolbar\ieprot.dll
+ 00000264(612) smss.exe
+ 000002a8(680) csrss.exe
+ 000002c0(704) winlogon.exe
72C80000[00008000]
[ M] 150. c:\windows\system32\msacm32.drv
+ 000002ec(748) services.exe
+ 000002f8(760) lsass.exe
+ 00000388(904) svchost.exe
+ 000003e0(992) svchost.exe
+ 00000450(1104) svchost.exe
50E60000[0000C000]
[ M] 151. c:\windows\system32\wups2.dll
+ 00000484(1156) svchost.exe
+ 000004f4(1268) svchost.exe
+ 00000614(1556) Explorer.EXE
10000000[0001B000]
[AM] 132. c:\windows\system32\ravext.dll
01120000[00011000]
[AM] 133. c:\windows\system32\shlhook.dll
01730000[0001B000]
[ M] 147. c:\program files\rising\kakatoolbar\ieprot.dll
72C80000[00008000]
[ M] 150. c:\windows\system32\msacm32.drv
01B40000[0082E000]
[AM] 130. c:\windows\system32\nvcpl.dll
02370000[00037000]
[ M] 152. c:\windows\system32\nvrszhc.dll
023F0000[00056000]
[ M] 153. c:\windows\system32\nvapi.dll
02460000[00073000]
[AM] 131. c:\windows\system32\nvshell.dll
23700000[0001A000]
[ M] 154. c:\program files\rising\rav\rscommon.dll
+ 00000690(1680) spoolsv.exe
+ 000006d4(1748) nvsvc32.exe
00400000[0002D000]
[AM] 2. c:\windows\system32\nvsvc32.exe
009F0000[00056000]
[ M] 153. c:\windows\system32\nvapi.dll
+ 000006fc(1788) RavStub.exe
00400000[00018000]
[AM] 142. c:\program files\rising\rav\ravstub.exe
10000000[0001B000]
[ M] 155. c:\program files\rising\rav\rscommx.dll
23700000[0001A000]
[ M] 154. c:\program files\rising\rav\rscommon.dll
+ 000007a8(1960) RTHDCPL.EXE
00400000[01035000]
[AM] 135. c:\windows\rthdcpl.exe
72C80000[00008000]
[ M] 150. c:\windows\system32\msacm32.drv
10000000[0001B000]
[ M] 147. c:\program files\rising\kakatoolbar\ieprot.dll
+ 000007c4(1988) RfwMain.exe
00400000[00068000]
[AM] 139. c:\program files\rising\rfw\rfwmain.exe
26600000[0007F000]
[ M] 156. c:\program files\rising\rfw\rsguilib.dll
23700000[0001B000]
[ M] 157. c:\program files\rising\rfw\rscommon.dll
23900000[00031000]
[ M] 158. c:\program files\rising\rfw\pngdll.dll
10000000[0001B000]
[ M] 147. c:\program files\rising\kakatoolbar\ieprot.dll
+ 000007e8(2024) RUNDLL32.EXE
10000000[00016000]
[ M] 159. c:\windows\system32\nvmctray.dll
00AE0000[00056000]
[ M] 153. c:\windows\system32\nvapi.dll
00B60000[00037000]
[ M] 152. c:\windows\system32\nvrszhc.dll
00A60000[0001B000]
[ M] 147. c:\program files\rising\kakatoolbar\ieprot.dll
+ 00000864(2148) alg.exe
+ 00000a1c(2588) iexplore.exe
10000000[00057000]
[AM] 122. c:\windows\system32\kakatool.dll
06E90000[0037F000]
[AM] 121. c:\program files\google\googletoolbar1.dll
08AE0000[0001B000]
[ M] 147. c:\program files\rising\kakatoolbar\ieprot.dll
325C0000[00012000]
[AM] 126. c:\program files\microsoft office\office11\msohev.dll
08CD0000[00019000]
[ M] 160. c:\program files\rising\rav\ravscrch.dll
+ 00000a8c(2700) IEXPLORE.EXE
10000000[00057000]
[AM] 122. c:\windows\system32\kakatool.dll
06EB0000[0037F000]
[AM] 121. c:\program files\google\googletoolbar1.dll
08C10000[0001B000]
[ M] 147. c:\program files\rising\kakatoolbar\ieprot.dll
325C0000[00012000]
[AM] 126. c:\program files\microsoft office\office11\msohev.dll
+ 00000f6c(3948) Ras.exe
00400000[0013F000]
[ M] 161. c:\program files\rising\kakatoolbar\ras.exe
10000000[000A3000]
[ M] 162. c:\program files\rising\kakatoolbar\rasgui.dll
01590000[0001B000]
[ M] 147. c:\program files\rising\kakatoolbar\ieprot.dll
02580000[0002F000]
[ M] 163. c:\program files\rising\kakatoolbar\engine.dll
026B0000[00012000]
[ M] 164. c:\program files\rising\kakatoolbar\zip.dll