HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
+ Explorer.exec:\winnt\system32\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ HotKeysCmdshkcmd ModuleIntel Corporationc:\winnt\system32\hkcmd.exe
+ IgfxTrayigfxTray ModuleIntel Corporationc:\winnt\system32\igfxtray.exe
+ NEC e-Border CredentialSOCKS5 Credential Cache ManagerNEC Corporationc:\program files\nec\e-border client\s5credmgr.exe
+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe
+ RfwMainRising Personal FireWall Main ProgramBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwmain.exe
+ Soundc:\winnt\system32\explorer.exe
+ SoundManRealtek Sound ManagerRealtek Semiconductor Corp.c:\winnt\soundman.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
+ Rising Execute File Exts hookRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt\system32\ravext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt\system32\ravext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ T2BHO ClassDownloadBHO ModuleHDT, Inc.c:\winnt\downloaded program files\barhelp24.0.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ 天下搜索HDTBar Modulec:\winnt\downloaded program files\iebar23.0.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ @shdoclc.dll,-864c:\winnt\web\related.htm
HKLM\System\CurrentControlSet\Services
+ RfwServiceRising Personal Firewall ServiceBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rfwsrv.exe
+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe
+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe
HKLM\System\CurrentControlSet\Services
+ ALCXWDMRealtek AC'97 Audio Driver (WDM)Realtek Semiconductor Corp.c:\winnt\system32\drivers\alcxwdm.sys
+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\winnt\system32\drivers\basetdi.sys
+ DCN530DigitalChina DCN-530TX Fast Ethernet Adapter NDIS5 DriverDigitalchina Networks Limited.c:\winnt\system32\drivers\dcn530n5.sys
+ dmioNT Disk Manager I/O DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmio.sys
+ dmloadNT Disk Manager Startup DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmload.sys
+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys
+ HOOKAPIHOOKAPI Driver瑞星软件有限公司c:\program files\rising\rav\hookapi.sys
+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys
+ HookRegc:\program files\rising\rav\hookreg.sys
+ HookSysHooksysRisingc:\program files\rising\rav\hooksys.sys
+ ialmIntel Graphics Miniport DriverIntel Corporationc:\winnt\system32\drivers\ialmnt5.sys
+ MEMSCANMemScan Driver瑞星软件有限公司c:\program files\rising\rav\memscan.sys
+ mProcRsRising Personal FireWall mprocrs.sysBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\mprocrs.sys
+ oreans32c:\winnt\system32\drivers\oreans32.sys
+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\winnt\system32\drivers\ptilink.sys
+ RsFwDrvnt_fwdrvBeijing Rising Technology Co., Ltd.c:\program files\rising\rfw\rsfwdrv.sys
+ WINIOc:\winnt\downloaded program files\winio.sys
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
+ igfxcuiigfxsrvc ModuleIntel Corporationc:\winnt\system32\igfxsrvc.dll
HKCU\Control Panel\Desktop\Scrnsave.exe
+ (无)File not found: (无)
HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
+ NEC e-Border Layered Service ProviderSOCKS5 EZClient service provider hooksNEC Corporationc:\program files\nec\e-border client\s5spi.dll
+ NEC e-Border MSAFD Tcpip [TCP/IP]SOCKS5 EZClient service provider hooksNEC Corporationc:\program files\nec\e-border client\s5spi.dll