.text,.rdata,.data,.rsrc,.reloc,
83 7C 24 08 01 75 05 E8 BA 46 00 00 FF 74 24 04
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{D157330A-9EF3-49F8-9A67-4141AC41ADD4}
[AM] 45. c:\windows\downloaded program files\cnshook.dll
北京三七二一科技有限公司
CnsHook
.text,.rdata,.data,.cnshook,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
{32CD708B-60A7-4C00-9377-D73EAA495F0F}
[AM] 57. c:\windows\system32\ravext.dll
Beijing Rising Technology Co., Ltd.
Rising Shell Ext Module
.text,.rdata,.data,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 62. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
+ Logon
+ HKCU\Software\Microsoft\Windows\CurrentVersion\Run
MsnMsgr
[AM] 63. c:\program files\msn messenger\msnmsgr.exe
Microsoft Corporation
Messenger
.text,.data,.rsrc,
E8 05 00 00 00 E9 A1 11 FF FF 55 8B EC 83 EC 10
updateMgr
[A ] 64. c:\program files\adobe\acrobat 7.0\reader\adobeupdatemanager.exe
Adobe Systems Incorporated
Adobe Update Manager
.text,.rsrc,
B8 68 B3 4A 00 50 64 FF 35 00 00 00 00 64 89 25
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BigDog303
[AM] 65. c:\windows\vm303_sti.exe
Vimicro
Vimicro
.text,.rdata,.data,.rsrc,
55 8B EC 6A FF 68 C0 A2 40 00 68 A8 66 40 00 64
runeip
[AM] 66. c:\program files\rising\antispyware\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
55 8B EC 6A FF 68 E0 6B 40 00 68 40 52 40 00 64
QuickTime Task
[AM] 67. c:\program files\quicktime\qttask.exe
Apple Inc.
QuickTime Task
.text,.rdata,.data,.rsrc,
6A 60 68 D0 4A 43 00 E8 23 1E 00 00 BF 94 00 00
Adobe Photo Downloader
[AM] 68. c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe
Adobe Systems Incorporated
Adobe Photoshop Album Starter Edition 3.0 component
.text,.rdata,.data,.rsrc,
6A 74 68 A8 35 40 00 E8 60 02 00 00 33 DB 89 5D
TkBellExe
[AM] 69. c:\program files\common files\real\update_ob\realsched.exe
RealNetworks, Inc.
RealNetworks Scheduler
.text,.rdata,.data,.rsrc,
55 8B EC 6A FF 68 B0 D4 41 00 68 6C 3E 41 00 64
YLive.exe
[AM] 70. c:\program files\yahoo!\assistant\ylive.exe
Yahoo! China
YLive
.text,.rdata,.data,.rsrc,
55 8B EC 6A FF 68 48 31 40 00 68 90 25 40 00 64
yassistse
[AM] 71. c:\program files\yahoo!\assistant\yassistse.exe
Yahoo! China
AssistSetting
.text,.rdata,.data,.rsrc,
55 8B EC 6A FF 68 48 52 40 00 68 6E 40 40 00 64
iTunesHelper
[AM] 72. e:\11\ituneshelper.exe
Apple Inc.
iTunesHelper Module
.text,.rdata,.data,.rsrc,
E8 B8 6D 00 00 E9 16 FE FF FF CC 68 B0 D6 40 00
RavTask
[A ] 73. c:\program files\rising\rav\ravtask.exe
Beijing Rising Technology Co., Ltd.
RavTimer
.text,.rdata,.data,.rsrc,
55 8B EC 6A FF 68 50 E3 40 00 68 D4 90 40 00 64
+ Boot Execute
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 74. c:\windows\system32\bsmain.exe
Beijing Rising Technology Co., Ltd.
BootScan
.text,.data,.rsrc,.reloc,
55 8B EC 6A FF 68 F0 27 00 01 68 74 9E 00 01 64
+ Image Hijacks
+ HKCR\.html
htmlfile\Edit\Command
[A ] 75. f:\程序\office xp\office10\msohtmed.exe
Microsoft Corporation
Microsoft Office XP component
.text,.data,.rsrc,
55 8B EC 83 EC 18 83 4D FC FF 53 56 57 6A FE 33
htmlfile\Print\Command
[A ] 75. f:\程序\office xp\office10\msohtmed.exe
Microsoft Corporation
Microsoft Office XP component
.text,.data,.rsrc,
55 8B EC 83 EC 18 83 4D FC FF 53 56 57 6A FE 33
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 75. f:\程序\office xp\office10\msohtmed.exe
Microsoft Corporation
Microsoft Office XP component
.text,.data,.rsrc,
55 8B EC 83 EC 18 83 4D FC FF 53 56 57 6A FE 33
htmlfile\Print\Command
[A ] 75. f:\程序\office xp\office10\msohtmed.exe
Microsoft Corporation
Microsoft Office XP component
.text,.data,.rsrc,
55 8B EC 83 EC 18 83 4D FC FF 53 56 57 6A FE 33
+ HKCR\.mp3
RealPlayer.MP3.6\open\Command
[A ] 76. f:\realone\realplay.exe
RealNetworks, Inc.
RealOne Player
.text,.rdata,.data,.rsrc,
55 8B EC 6A FF 68 A0 AA 40 00 68 B0 8D 40 00 64
+ 其他自启动项目
+ C:\Documents and Settings\liYuan\「开始」菜单\程序\启动
腾讯QQ.lnk
[A ] 49. f:\qq\qq.exe
TENCENT
QQ
.text,.rdata,.data,.rsrc,
55 8B EC 6A FF 68 08 54 52 00 68 AE 54 48 00 64
+ C:\Documents and Settings\All Users\「开始」菜单\程序\启动
Adobe Reader Speed Launch.lnk
[A ] 77. c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
Adobe Systems Incorporated
Adobe Acrobat SpeedLauncher
.text,.rdata,.data,.rsrc,
6A 74 68 E0 66 40 00 E8 08 02 00 00 33 DB 89 5D
+ C:\WINDOWS\Tasks
AppleSoftwareUpdate.job
[A ] 78. c:\program files\apple software update\softwareupdate.exe
Apple Computer, Inc.
Software Application
.text,.rdata,.data,.rsrc,
E8 B1 63 00 00 E9 17 FE FF FF 55 8B EC 51 53 8B
+ 系统活动模块
+ 00000084(132) mdm.exe
00400000[00044000]
[AM] 4. c:\program files\common files\microsoft shared\vs7debug\mdm.exe
Microsoft Corporation
Machine Debug Manager
.text,.data,.rsrc,
55 8B EC 6A FF 68 00 5E 40 00 68 70 B0 42 00 64
+ 00000140(320) svchost.exe
+ 00000190(400) wdfmgr.exe
01000000[0000C000]
[AM] 7. c:\windows\system32\wdfmgr.exe
Microsoft Corporation
Windows User Mode Driver Manager
.text,.data,.rsrc,
6A 28 68 30 26 00 01 E8 A5 01 00 00 66 81 3D 00
+ 0000027c(636) smss.exe
+ 000002c0(704) csrss.exe
+ 000002d8(728) winlogon.exe
10000000[00017000]
[AM] 34. c:\windows\system32\ati2evxx.dll
.text,.rdata,.data,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 85 F6 57 8B 7D
72C80000[00008000]
[ M] 79. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
8B 44 24 08 83 E8 00 74 30 48 75 3A 56 8B 74 24
+ 00000304(772) services.exe
+ 00000310(784) lsass.exe
+ 00000354(852) Ras.exe
00400000[0013D000]
[ M] 80. c:\program files\rising\antispyware\ras.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware
.text,.rdata,.data,.rsrc,
55 8B EC 6A FF 68 90 3A 4C 00 68 70 B7 4A 00 64
53000000[0000E000]
[ M] 81. c:\program files\3721\helper.dll
Helper Module
.text,.rdata,.data,.cnshelp,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
00C20000[0000B000]
[ M] 82. c:\program files\yahoo!\assistant\yhelper.dll
Yahoo! China
Helper Module
.text,.rdata,.data,.cnshelp,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
37210000[00086000]
[ M] 83. c:\windows\downloaded program files\cnsmin.dll
国风因特软件(北京)有限公司
CnsMin
.text,.rdata,.data,.cnsdata,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
10000000[000A0000]
[ M] 84. c:\program files\rising\antispyware\rasgui.dll
Beijing Rising Technology Co., Ltd.
RasGUI
.text,.rdata,.data,.rsrc,.reloc,
55 8B EC 53 8B 5D 08 56 8B 75 0C 57 8B 7D 10 85
026D0000[0001B000]
[ M] 85. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
6A 0C 68 00 CD 6D 02 E8 BD 02 00 00 33 C0 40 89
03E60000[0005B000]
[ M] 86. c:\program files\common files\microsoft shared\ink\skchui.dll
Microsoft Corporation
Draw Pen Tip
.text,.rdata,.data,.rsrc,.reloc,
55 8B EC 51 C7 45 FC 01 00 00 00 83 7D 0C 00 75
+ 000003b0(944) Ati2evxx.exe
00400000[00067000]
[AM] 1. c:\windows\system32\ati2evxx.exe
.text,.rdata,.data,.rsrc,
6A 60 68 18 98 45 00 E8 F6 2E 00 00 83 65 FC 00
+ 000003c0(960) svchost.exe
+ 0000040c(1036) svchost.exe
+ 00000468(1128) svchost.exe
50E60000[0000C000]
[ M] 87. c:\windows\system32\wups2.dll
Microsoft Corporation
Windows Update client proxy stub 2
.text,.orpc,.data,.rsrc,.reloc,
8B FF 55 8B EC 83 7D 0C 01 75 05 E8 F9 04 00 00
+ 000004f0(1264) svchost.exe
+ 0000050c(1292) alg.exe
+ 0000055c(1372) svchost.exe
+ 000005cc(1484) iexplore.exe
53000000[0000E000]