进程:
System Idle Process
System
C:\WINNT\system32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Program Files\Rising\Rfw\rfwsrv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\RavMonD.exe
C:\WINNT\system32\SPOOLSV.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\mstask.exe
C:\WINNT\system32\wbem\winmgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINNT\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Rising\Rfw\rfwmain.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\CJC提醒小精灵\Reminder.exe
C:\Program Files\Rising\Rav\RavMon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\conime.exe
C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\ross\桌面\IceSword1.18\cn\IceSword.exe
启动组:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Synchronization Manager
mobsync.exe /logon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
RavTask
"C:\Program Files\Rising\Rav\RavTask.exe" -system
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
RfwMain
"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YOKAssiant
Rundll32.exe C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll,YOKAssiant
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
RegDoctor
C:\Program Files\RegDoctor\RegDoctor.exe -Quick
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Reminder.exe
"C:\Program Files\CJC提醒小精灵\Reminder.exe"