Wireless Console 2
[A ] 68. c:\program files\wireless console 2\wcourier.exe
IntelZeroConfig
[AM] 69. c:\program files\intel\wireless\bin\zcfgsvc.exe
EOUApp
[AM] 70. c:\program files\intel\wireless\bin\eouwiz.exe
360Safebox
[A ] 71. c:\program files\360safebox\safeboxtray.exe
Adobe Reader Speed Launcher
[A ] 72. c:\program files\adobe\reader 8.0\reader\reader_sl.exe
StormCodec_Helper
[A ] 73. c:\program files\ringz studio\storm codec\stormset.exe
RavTask
[AM] 74. f:\新建文件夹 (4)\rising\rav\ravtask.exe
runeip
[AM] 75. c:\program files\rising\antispyware\rstray.exe
TkBellExe
[AM] 76. c:\program files\common files\real\update_ob\realsched.exe
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay
[A ] 77. c:\program files\rising\antispyware\runonce.exe
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 78. c:\windows\system32\bsmain.exe
[A ] 79. c:\windows\system32\kknative.exe
+ 映像劫持
+ HKCR\.html
htmlfile\Edit\Command
[A ] 80. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 80. c:\program files\microsoft office\office11\msohtmed.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 80. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 80. c:\program files\microsoft office\office11\msohtmed.exe
+ 程序初始化和已知动态连接库
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
[AM] 81. c:\windows\system32\kmon.dll
+ 正在运行的进程
+ 000000c8(200) svchost.exe
+ 00000104(260) ravmond.exe
00400000[00069000]
[AM] 7. f:\新建文件夹 (4)\rising\rav\ravmond.exe
10000000[00042000]
[ M] 82. f:\新建文件夹 (4)\rising\rav\bwlist.dll
7C140000[00103000]
[ M] 83. c:\windows\system32\mfc71.dll
7C340000[00056000]
[ M] 84. c:\windows\system32\msvcr71.dll
7C3A0000[0007B000]
[ M] 85. c:\windows\system32\msvcp71.dll
5D360000[0000A000]
[ M] 86. c:\windows\system32\mfc71chs.dll
00A30000[0000E000]
[ M] 87. f:\新建文件夹 (4)\rising\rav\rsappmgr.dll
00A50000[00030000]
[ M] 88. f:\新建文件夹 (4)\rising\rav\cfgdll.dll
00CC0000[00067000]
[ M] 89. f:\新建文件夹 (4)\rising\rav\rslog.dll
00D30000[0001F000]
[ M] 90. f:\新建文件夹 (4)\rising\rav\proccom.dll
00D50000[00024000]
[ M] 91. f:\新建文件夹 (4)\rising\rav\rscommx2.dll
00DE0000[00075000]
[ M] 92. f:\新建文件夹 (4)\rising\rav\monrule.dll
00E70000[00013000]
[ M] 93. f:\新建文件夹 (4)\rising\rav\hooksys.dll
00FD0000[00013000]
[ M] 94. f:\新建文件夹 (4)\rising\rav\hookreg.dll
01030000[00013000]
[ M] 95. f:\新建文件夹 (4)\rising\rav\hookntos.dll
01090000[0001D000]
[ M] 96. f:\新建文件夹 (4)\rising\rav\rswalmon.dll
01EC0000[00035000]
[ M] 97. f:\新建文件夹 (4)\rising\rav\recomp.dll
01F10000[00036000]
[ M] 98. f:\新建文件夹 (4)\rising\rav\refs.dll
01F60000[00023000]
[ M] 99. f:\新建文件夹 (4)\rising\rav\ffr.dll
01FA0000[00020000]
[ M] 100. f:\新建文件夹 (4)\rising\rav\rsstore.dll
01FD0000[00013000]
[ M] 101. f:\新建文件夹 (4)\rising\rav\hookcont.dll
02000000[00028000]
[ M] 102. f:\新建文件夹 (4)\rising\rav\fakescan.dll
02040000[00022000]
[ M] 103. f:\新建文件夹 (4)\rising\rav\scanner.dll
02680000[0002F000]
[ M] 104. f:\新建文件夹 (4)\rising\rav\viruslib.dll
027C0000[00028000]
[ M] 105. f:\新建文件夹 (4)\rising\rav\relibldr.dll
02CF0000[00012000]
[ M] 106. f:\新建文件夹 (4)\rising\rav\hookweb.dll
044F0000[00021000]
[ M] 107. f:\新建文件夹 (4)\rising\rav\nvfile.dll
13AB0000[0004A000]
[ M] 108. f:\新建文件夹 (4)\rising\rav\scanexec.dll
05DF0000[002DC000]
[ M] 109. f:\新建文件夹 (4)\rising\rav\unexe.dll
060E0000[000D4000]
[ M] 110. f:\新建文件夹 (4)\rising\rav\scanex.dll
06550000[00027000]
[ M] 111. f:\新建文件夹 (4)\rising\rav\pearc.dll
09B90000[000DC000]
[ M] 112. f:\新建文件夹 (4)\rising\rav\extfile.dll
03CB0000[00036000]
[ M] 113. f:\新建文件夹 (4)\rising\rav\scanpack.dll
04ED0000[000B7000]
[ M] 114. f:\新建文件夹 (4)\rising\rav\revm.dll
03D30000[00020000]
[ M] 115. f:\新建文件夹 (4)\rising\rav\urutils.dll
03D60000[00018000]
[ M] 116. f:\新建文件夹 (4)\rising\rav\ur000.dat
04E10000[00038000]
[ M] 117. f:\新建文件夹 (4)\rising\rav\scriptci.dll
04E60000[0001D000]
[ M] 118. f:\新建文件夹 (4)\rising\rav\ur001.dat
14210000[00038000]
[ M] 119. f:\新建文件夹 (4)\rising\rav\extmail.dll
04EA0000[00023000]
[ M] 120. f:\新建文件夹 (4)\rising\rav\scansct.dll
+ 0000020c(524) RavStub.exe
00400000[00021000]
[ M] 121. f:\新建文件夹 (4)\rising\rav\ravstub.exe
10000000[0001F000]
[ M] 90. f:\新建文件夹 (4)\rising\rav\proccom.dll
00620000[00024000]
[ M] 91. f:\新建文件夹 (4)\rising\rav\rscommx2.dll
23700000[00028000]
[ M] 122. f:\新建文件夹 (4)\rising\rav\rscommon.dll
+ 00000344(836) spoolsv.exe
+ 00000360(864) Explorer.EXE
60000000[00074000]
[AM] 81. c:\windows\system32\kmon.dll
72C80000[00008000]
[ M] 123. c:\windows\system32\msacm32.drv
02020000[00031000]
[AM] 45. f:\thunder\comdlls\xunleibho_now.dll
031E0000[00029000]
[AM] 47. c:\program files\360safe\safemon\safemon.dll
01100000[0005B000]
[AM] 52. c:\program files\common files\adobe\acrobat\activex\pdfshell.dll
01160000[0004C000]
[ M] 124. c:\program files\common files\adobe\acrobat\activex\pdfshell.chs
03900000[00748000]
[AM] 57. c:\windows\system32\nvcpl.dll
00E00000[00036000]
[ M] 125. c:\windows\system32\nvrszhc.dll
011B0000[00073000]
[AM] 58. c:\windows\system32\nvshell.dll
01250000[00138000]
[ M] 126. c:\windows\system32\sogoupy.ime
01B70000[00042000]
[ M] 127. c:\program files\sogouinput\plugin\sgimeword.dll
36D30000[0001A000]
[ M] 128. c:\program files\microsoft office\office11\mcps.dll
+ 00000380(896) smss.exe
+ 000003c8(968) csrss.exe
+ 000003e0(992) winlogon.exe
01F70000[0003B000]
[AM] 42. c:\windows\system32\wgalogon.dll
72C80000[00008000]
[ M] 123. c:\windows\system32\msacm32.drv
+ 0000040c(1036) services.exe
+ 00000418(1048) lsass.exe
+ 000004b8(1208) svchost.exe
+ 00000508(1288) svchost.exe
+ 00000584(1412) CCenter.exe
00400000[0002A000]
[AM] 6. f:\新建文件夹 (4)\rising\rav\ccenter.exe
+ 00000598(1432) svchost.exe
+ 00000604(1540) AntiARPClientLoader.exe
00400000[0000B000]
[AM] 1. c:\program files\彩影软件\arp防火墙单机版\antiarpclientloader.exe
+ 0000062c(1580) nvsvc32.exe
00400000[00027000]
[AM] 3. c:\windows\system32\nvsvc32.exe
60000000[00074000]
[AM] 81. c:\windows\system32\kmon.dll
+ 00000640(1600) RegSrvc.exe
00400000[00038000]
[AM] 5. c:\program files\intel\wireless\bin\regsrvc.exe
60000000[00074000]
[AM] 81. c:\windows\system32\kmon.dll
+ 00000678(1656) svchost.exe
+ 00000694(1684) alg.exe
60000000[00074000]
[AM] 81. c:\windows\system32\kmon.dll
+ 000006a8(1704) EvtEng.exe
00400000[0001E000]
[AM] 2. c:\program files\intel\wireless\bin\evteng.exe
50740000[00044000]
[ M] 129. c:\program files\intel\wireless\bin\psregapi.dll
50830000[0002A000]
[ M] 130. c:\program files\intel\wireless\bin\traceapi.dll
60000000[00074000]
[AM] 81. c:\windows\system32\kmon.dll
+ 000006fc(1788) S24EvMon.exe
00400000[00092000]
[AM] 8. c:\program files\intel\wireless\bin\s24evmon.exe
50830000[0002A000]
[ M] 130. c:\program files\intel\wireless\bin\traceapi.dll
50740000[00044000]
[ M] 129. c:\program files\intel\wireless\bin\psregapi.dll
50490000[000D9000]
[ M] 131. c:\program files\intel\wireless\bin\libeay32.dll
50320000[0000D000]
[ M] 132. c:\program files\intel\wireless\bin\intstngs.dll
50410000[00036000]
[ M] 133. c:\program files\intel\wireless\bin\iwmsprov.dll
60000000[00074000]
[AM] 81. c:\windows\system32\kmon.dll
+ 00000714(1812) ImeUtil.exe
00400000[00069000]
[ M] 134. c:\program files\sogouinput\imeutil.exe
60000000[00074000]
[AM] 81. c:\windows\system32\kmon.dll
10000000[0002E000]
[ M] 135. c:\program files\rising\antispyware\comx3.dll
00980000[00019000]
[ M] 136. c:\program files\rising\antispyware\syslay.dll
+ 00000730(1840) wdfmgr.exe
01000000[0000C000]
[AM] 9. c:\windows\system32\wdfmgr.exe
60000000[00074000]
[AM] 81. c:\windows\system32\kmon.dll
+ 00000768(1896) svchost.exe
+ 00000a04(2564) RUNDLL32.EXE
60000000[00074000]
[AM] 81. c:\windows\system32\kmon.dll
10000000[00017000]
[ M] 137. c:\windows\system32\nvmctray.dll
00B40000[00036000]
[ M] 125. c:\windows\system32\nvrszhc.dll
+ 00000a0c(2572) HControl.exe
00400000[0001C000]
[AM] 65. c:\windows\atk0100\hcontrol.exe
10000000[0000E000]
[ M] 138. c:\windows\atk0100\cmssc.dll
00390000[0000C000]
[ M] 139. c:\windows\atk0100\inter_f2.dll
1C200000[00016000]
[ M] 140. c:\windows\atk0100\atkwlioc.dll
003A0000[0004B000]
[ M] 141. c:\windows\atk0100\sispkt.dll
60000000[00074000]
[AM] 81. c:\windows\system32\kmon.dll
50630000[00047000]
[ M] 142. c:\program files\intel\wireless\bin\murocapi.dll
50790000[00017000]
[ M] 143. c:\program files\intel\wireless\bin\s24mudll.dll
50740000[00044000]
[ M] 129. c:\program files\intel\wireless\bin\psregapi.dll
50830000[0002A000]
[ M] 130. c:\program files\intel\wireless\bin\traceapi.dll
50320000[0000D000]
[ M] 132. c:\program files\intel\wireless\bin\intstngs.dll
50490000[000D9000]
[ M] 131. c:\program files\intel\wireless\bin\libeay32.dll
72C80000[00008000]
[ M] 123. c:\windows\system32\msacm32.drv
+ 00000a14(2580) sm56hlpr.exe
00400000[00089000]
[AM] 66. c:\windows\sm56hlpr.exe
60000000[00074000]
[AM] 81. c:\windows\system32\kmon.dll
10000000[00011000]
[ M] 144. c:\windows\sm56eng.dll
00A80000[0000F000]
[ M] 145. c:\windows\sm56fra.dll
00A90000[00011000]
[ M] 146. c:\windows\sm56brz.dll
00AB0000[0000C000]
[ M] 147. c:\windows\sm56chs.dll
00BD0000[0000C000]
[ M] 148. c:\windows\sm56cht.dll
00BE0000[0000F000]
[ M] 149. c:\windows\sm56ger.dll
00BF0000[00011000]
[ M] 150. c:\windows\sm56itl.dll
00C10000[0000D000]
[ M] 151. c:\windows\sm56jpn.dll
00C20000[00011000]
[ M] 152. c:\windows\sm56spn.dll
+ 00000a98(2712) ZCfgSvc.exe
00400000[000A7000]
[AM] 69. c:\program files\intel\wireless\bin\zcfgsvc.exe
50680000[0009E000]
[ M] 153. c:\program files\intel\wireless\bin\pfmgrapi.dll
50830000[0002A000]
[ M] 130. c:\program files\intel\wireless\bin\traceapi.dll
50740000[00044000]
[ M] 129. c:\program files\intel\wireless\bin\psregapi.dll
502E0000[0003D000]
[ M] 154. c:\program files\intel\wireless\bin\dbengine.dll
50490000[000D9000]
[ M] 131. c:\program files\intel\wireless\bin\libeay32.dll
50320000[0000D000]
[ M] 132. c:\program files\intel\wireless\bin\intstngs.dll
50630000[00047000]
[ M] 142. c:\program files\intel\wireless\bin\murocapi.dll
50790000[00017000]
[ M] 143. c:\program files\intel\wireless\bin\s24mudll.dll
60000000[00074000]
[AM] 81. c:\windows\system32\kmon.dll
10000000[0000B000]
[ M] 155. c:\program files\intel\wireless\bin\zcsvcchs.dll
+ 00000b9c(2972) EOUWiz.exe
00400000[00090000]
[AM] 70. c:\program files\intel\wireless\bin\eouwiz.exe
50740000[00044000]
[ M] 129. c:\program files\intel\wireless\bin\psregapi.dll
50630000[00047000]
[ M] 142. c:\program files\intel\wireless\bin\murocapi.dll
50790000[00017000]
[ M] 143. c:\program files\intel\wireless\bin\s24mudll.dll
50830000[0002A000]
[ M] 130. c:\program files\intel\wireless\bin\traceapi.dll
50320000[0000D000]
[ M] 132. c:\program files\intel\wireless\bin\intstngs.dll
50490000[000D9000]
[ M] 131. c:\program files\intel\wireless\bin\libeay32.dll
50680000[0009E000]
[ M] 153. c:\program files\intel\wireless\bin\pfmgrapi.dll
502E0000[0003D000]
[ M] 154. c:\program files\intel\wireless\bin\dbengine.dll
60000000[00074000]
[AM] 81. c:\windows\system32\kmon.dll
10000000[0001B000]
[ M] 156. c:\program files\intel\wireless\bin\eouwzchs.dll
+ 00000c24(3108) ATKOSD.exe
00400000[00212000]
[ M] 157. c:\windows\atk0100\atkosd.exe
60000000[00074000]
[AM] 81. c:\windows\system32\kmon.dll
+ 00000c80(3200) knownsvr.exe
00400000[00072000]
[ M] 158. c:\program files\rising\antispyware\knownsvr.exe
10000000[0002F000]
[ M] 159. c:\program files\rising\antispyware\ncomm.dll
60000000[00074000]
[AM] 81. c:\windows\system32\kmon.dll
009A0000[0002E000]
[ M] 135. c:\program files\rising\antispyware\comx3.dll
009D0000[00019000]
[ M] 136. c:\program files\rising\antispyware\syslay.dll
+ 00000d7c(3452) RavTask.exe
00400000[00034000]
[AM] 74. f:\新建文件夹 (4)\rising\rav\ravtask.exe
10000000[0001F000]
[ M] 90. f:\新建文件夹 (4)\rising\rav\proccom.dll
00940000[00024000]
[ M] 91. f:\新建文件夹 (4)\rising\rav\rscommx2.dll
23700000[00028000]
[ M] 122. f:\新建文件夹 (4)\rising\rav\rscommon.dll
00BA0000[0000E000]
[ M] 87. f:\新建文件夹 (4)\rising\rav\rsappmgr.dll
08BC0000[00030000]
[ M] 88. f:\新建文件夹 (4)\rising\rav\cfgdll.dll
+ 00000dac(3500) Ravmon.exe
00400000[00067000]
[ M] 160. f:\新建文件夹 (4)\rising\rav\ravmon.exe
7C140000[00103000]
[ M] 83. c:\windows\system32\mfc71.dll
7C340000[00056000]
[ M] 84. c:\windows\system32\msvcr71.dll
7C3A0000[0007B000]
[ M] 85. c:\windows\system32\msvcp71.dll
5D360000[0000A000]
[ M] 86. c:\windows\system32\mfc71chs.dll
10000000[0001F000]
[ M] 90. f:\新建文件夹 (4)\rising\rav\proccom.dll