启动文件夹
服务
[Logical Disk Manager Administrative Service / dmadmin]
<C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[Rising Process Communication Center / RsCCenter]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
==================================
浏览器加载项
[google bar]
{607E95A1-8F89-4343-B9BC-2EFC2B291BB4} <C:\WINNT\system32\googlebar.dll, Google Inc.>
[RMAHelper Class]
{B4657940-1439-4CF3-A910-C687E388D9D5} <C:\WINNT\system32\RMA\RMAHelper\svchost.dll, N/A>
[启动迅雷]
{0062C9BD-B349-40DE-91A0-755F37ACD559} <C:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[开心溜溜娱乐门户网,电影、音乐、DJ、相声、小品、FLASH等等应有尽有]
{3BB4D05E-9D5F-41A2-A214-8F69461A920A} <http://www.kx66.com/, N/A>
[雅虎WIDGET]
{6354ABE6-05F1-49ed-B850-E423120EC338} <http://cn.widget.yahoo.com/index.htm?source=Cns, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <E:\qq\QQ.EXE, TENCENT>
[情景聊天]
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg, N/A>
[@msdxmLC.dll,-1@2052,电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
[FlashGet Bar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\PROGRA~1\FLASHGET\fgiebar.dll, Amaze Soft>
[TT33定向搜索]
{D940F380-49C7-4A05-9E33-53930AF5768F} <C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tbu6\Toolbar.dll, N/A>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <D:\SUPERR~1\MAGICSET\haokanbar.dll, Xiang Feng Technology>
[LOGIN Control]
{6F4D96B4-40F1-4CE7-A28B-076981926B39} <C:\WINNT\DOWNLO~1\CWADMIN.ocx, >
[&使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
<E:\qq\AddToNetDisk.htm, N/A>
[使用网际快车下载]
<C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
<C:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
<E:\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<E:\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<E:\qq\SendMMS.htm, N/A>
==================================
正在运行的进程
[PID: 416][C:\WINNT\Explorer.EXE] <Microsoft Corporation><5.00.3700.6690>
[C:\WINNT\system32\igfxpph.dll] <Intel Corporation><3.0.0.3751>
[C:\WINNT\system32\hccutils.DLL] <Intel Corporation><3.0.0.3751>
[C:\WINNT\system32\igfxres.dll] <Intel Corporation><3.0.0.3751>
[C:\WINNT\system32\igfxsrvc.dll] <Intel Corporation><3.0.0.3751>
[C:\WINNT\system32\igfxdev.dll] <Intel Corporation><3.0.0.3751>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[F:\adobe\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[PID: 1008][C:\Program Files\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[PID: 1440][C:\WINNT\system32\RMAServer.exe] <N/A><N/A>
[PID: 1588][D:\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\WINNT\system32\SrvDll04.dll] <N/A><N/A>
==================================