上传了 ..帮我研究下,,,..谢谢谢谢
+ 用户登陆自运行项目
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
StartCCC
[A ] 36. c:\program files\ati technologies\ati.ace\core-static\clistart.exe
.text,.rdata,.data,.rsrc,
BigDogPath
[AM] 37. c:\windows\vm_sti.exe
VM.
Still Image (STI) Driver
.text,.rdata,.data,.rsrc,
RavTask
[AM] 38. d:\rising\rav\ravtask.exe
Beijing Rising Technology Co., Ltd.
RavTimer
.text,.rdata,.data,.rsrc,
RfwMain
[AM] 39. d:\rising\rfw\rfwmain.exe
Beijing Rising Technology Co., Ltd.
Rising Personal FireWall Main Program
.text,.rdata,.data,.rsrc,
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay
[A ] 40. c:\program files\rising\antispyware\runonce.exe
Beijing Rising Technology Co., Ltd.
RunOnce Application
.text,.rdata,.data,.rsrc,
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 41. c:\windows\system32\bsmain.exe
Beijing Rising Technology Co., Ltd.
Rising Antivirus 2008
.text,.rdata,.data,.rsrc,.reloc,
[A ] 42. c:\windows\system32\kknative.exe
Beijing Rising Technology Co., Ltd.
NativeAp
.text,.data,.rsrc,.reloc,
+ 正在运行的进程
+ 000000dc(220) spoolsv.exe
10000000[00016000]
[ M] 43. d:\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
00A60000[0000F000]
[ M] 44. d:\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
+ 0000016c(364) conime.exe
10000000[0001B000]
[ M] 45. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 000001c4(452) ns71.tmp
10000000[00005000]
[ M] 46. c:\documents and settings\ts\local settings\temp\nsq70.tmp\ns71.tmp
.text,.rdata,.data,.reloc,
008B0000[00016000]
[ M] 43. d:\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
00910000[0000F000]
[ M] 44. d:\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
+ 000001e0(480) CCenter.exe
00400000[00029000]
[AM] 7. d:\rising\rav\ccenter.exe
Beijing Rising Technology Co., Ltd.
CCenter
.text,.rdata,.data,.rsrc,
+ 000001f4(500) Explorer.EXE
00400000[00009000]
[ M] 47. c:\windows\system32\normaliz.dll
Microsoft Corporation
Unicode Normalization DLL
.text,.data,.rsrc,.reloc,
41D50000[00045000]
[ M] 48. c:\windows\system32\iertutil.dll
Microsoft Corporation
Run time utility for Internet Explorer
.text,.data,.rsrc,.reloc,
10000000[0001C000]
[AM] 35. c:\windows\system32\ravext.dll
Beijing Rising Technology Co., Ltd.
Rising Shell Ext Module
.text,.rdata,.data,.rsrc,.reloc,
422B0000[005CD000]
[AM] 27. c:\windows\system32\ieframe.dll
Microsoft Corporation
Internet Explorer
.text,.data,.rsrc,.reloc,
013C0000[00016000]
[ M] 43. d:\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
01440000[0000F000]
[ M] 44. d:\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
72C80000[00008000]
[ M] 49. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
如过扫描错了..请告诉我..我重新再扫 ~~~~`谢谢[用户系统信息]Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)