失去才懂紾惜 - 2007-10-4 11:26:00
一开始开机的时候我的瑞星2008的监控总是自动关闭,手动开启之后就好了,我也没当什么回事.后来我的QQ号和问道帐号都被盗了,用瑞星和360安全卫士扫描什么都扫描不出来,请各位专家帮我看看,下面是我的诊断报告.
[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)附件:
9013592007104111526.txt
失去才懂紾惜 - 2007-10-4 11:29:00
+ 注册表自运行项目
+ 系统服务
+ HKLM\System\CurrentControlSet\Services
LexBceS
[AM] 1. c:\windows\system32\lexbces.exe
NVSvc
[A ] 2. c:\windows\system32\nvsvc32.exe
ose
[A ] 3. c:\program files\common files\microsoft shared\source engine\ose.exe
RfwProxySrv
[AM] 4. c:\rising\rfw\rfwproxy.exe
RfwService
[AM] 5. c:\rising\rfw\rfwsrv.exe
RsCCenter
[AM] 6. c:\rising\rav\ccenter.exe
RsRavMon
[AM] 7. c:\rising\rav\ravmond.exe
WudfSvc
[A ] 8. c:\windows\system32\wudfsvc.dll
+ 内核驱动
+ HKLM\System\CurrentControlSet\Services
ALCXWDM
[A ] 9. c:\windows\system32\drivers\alcxwdm.sys
ATSpy
[A ] 10. c:\windows\system32\atspy.sys
FETND5BV
[A ] 11. c:\windows\system32\drivers\fetnd5bv.sys
FixDrv
[A ] 12. c:\windows\system32\drivers\fixdrv.sys
HookCont
[A ] 13. c:\windows\system32\drivers\hookcont.sys
HookNtos
[A ] 14. c:\windows\system32\drivers\hookntos.sys
HookReg
[A ] 15. c:\windows\system32\drivers\hookreg.sys
HookSys
[A ] 16. c:\windows\system32\drivers\hooksys.sys
HookUrl
[A ] 17. c:\rising\rfw\hookurl.sys
HpaFilt
[A ] 18. c:\windows\system32\drivers\hpafilt.sys
HpaLower
[A ] 19. c:\windows\system32\drivers\hpalower.sys
NTSIM
[A ] 20. c:\windows\system32\ntsim.sys
pciidey
[A ] 21. c:\windows\system32\drivers\pciidey.sys
RfwBase
[A ] 22. c:\windows\system32\drivers\rfwbase.sys
RsAntiSpyware
[A ] 23. c:\windows\system32\drivers\rsboot.sys
RsFwDrv
[A ] 24. c:\rising\rfw\rsfwdrv.sys
RsNTGDI
[A ] 25. c:\windows\system32\drivers\rsntgdi.sys
Secdrv
[A ] 26. c:\windows\system32\drivers\secdrv.sys
viagfx
[A ] 27. c:\windows\system32\drivers\vtmini.sys
WudfPf
[A ] 28. c:\windows\system32\drivers\wudfpf.sys
WudfRd
[A ] 29. c:\windows\system32\drivers\wudfrd.sys
+ IE浏览器加载模块
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C}
[AM] 30. c:\windows\system32\kakatool.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{00000000-12BF-4305-82F9-43058F20E8D2}
[AM] 31. c:\program files\tencent\qqdownload\qqiehelper02.dll
{00000000-12C0-4305-82F9-43058F20E8D2}
[AM] 32. d:\thunder5\comdlls\xunleibho_now.dll
{01443AEC-0FD1-40fd-9C87-E93D1494C233}
[AM] 33. d:\thunder5\comdlls\tdatonce_now.dll
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
[AM] 34. c:\program files\acrobatchs\activex\acroiehelper.dll
{B69F34DD-F0F9-42DC-9EDD-957187DA688D}
[AM] 35. d:\360safe\safemon\safemon.dll
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
Exec
[A ] 36. d:\thunder5\thunder.exe
Exec
[A ] 37. c:\program files\messenger\msmsgs.exe
+ 资源管理器加载模块
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
text/xml
[A ] 38. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
mso-offdap
[A ] 39. c:\program files\common files\microsoft shared\web components\10\owc10.dll
mso-offdap11
[A ] 40. c:\program files\common files\microsoft shared\web components\11\owc11.dll
+ HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers
{F9DB5320-233E-11D1-9F84-707F02C10627}
[AM] 41. c:\program files\acrobatchs\activex\pdfshell.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 42. c:\windows\system32\hticons.dll
NvCpl DesktopContext Class
[AM] 43. c:\windows\system32\nvcpl.dll
Play on my TV helper
[AM] 43. c:\windows\system32\nvcpl.dll
WinRAR shell extension
[A ] 44. c:\program files\winrar\rarext.dll
Shell Extensions for RealOne Player
[A ] 45. c:\program files\real\realplayer\rpshell.dll
Web Folders
[A ] 46. c:\program files\common files\microsoft shared\web folders\msonsext.dll
Microsoft Office Outlook Desktop Icon Handler
[A ] 47. c:\program files\microsoft office\office11\mlshext.dll
Microsoft Office Outlook Custom Icon Handler
[A ] 48. c:\program files\microsoft office\office11\olkfstub.dll
Microsoft Office HTML Icon Handler
[AM] 49. c:\program files\microsoft office\office11\msohev.dll
RISING
[AM] 50. c:\windows\system32\ravext.dll
Portable Media Devices
[A ] 51. c:\windows\system32\audiodev.dll
Portable Devices
[A ] 52. c:\windows\system32\wpdshext.dll
Portable Devices Menu
[A ] 52. c:\windows\system32\wpdshext.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{32CD708B-60A7-4C00-9377-D73EAA495F0F}
[AM] 50. c:\windows\system32\ravext.dll
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 53. c:\windows\system32\shlhook.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
WPDShServiceObj
[AM] 54. c:\windows\system32\wpdshserviceobj.dll
失去才懂紾惜 - 2007-10-4 11:30:00
+ 用户登陆自运行项目
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
VTTimer
[AM] 55. c:\windows\system32\vttimer.exe
VTTrayp
[AM] 56. c:\windows\system32\vttrayp.exe
SoundMan
[AM] 57. c:\windows\soundman.exe
LHotkey
[AM] 58. c:\windows\lhotkey.exe
IMSCMig
[A ] 59. c:\program files\common files\microsoft shared\ime\imsc40a\imscmig.exe
RavTask
[AM] 60. c:\rising\rav\ravtask.exe
RfwMain
[AM] 61. c:\rising\rfw\rfwmain.exe
360Safetray
[AM] 62. d:\360safe\safemon\360tray.exe
runeip
[AM] 63. c:\rising\runiep.exe
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
KKDelay
[A ] 64. c:\rising\runonce.exe
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 65. c:\windows\system32\bsmain.exe
[A ] 66. c:\windows\system32\kknative.exe
+ 映像劫持
+ HKCR\.html
htmlfile\Edit\Command
[A ] 67. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 67. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\TencentTraveler\Command
[A ] 68. d:\tt\ttraveler.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 67. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\Print\Command
[A ] 67. c:\program files\microsoft office\office11\msohtmed.exe
htmlfile\TencentTraveler\Command
[A ] 68. d:\tt\ttraveler.exe
+ 打印机监控
+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
Lenovo Network Port
[AM] 69. c:\windows\system32\lexlmpm.dll
Microsoft Document Imaging Writer Monitor
[AM] 70. c:\windows\system32\mdimon.dll
+ 其他自启动项目
+ C:\Documents and Settings\lenovo\「开始」菜单\程序\启动
腾讯QQ.lnk
[AM] 71. d:\qq\qq.exe
+ C:\Documents and Settings\All Users\「开始」菜单\程序\启动
Adobe Reader Speed Launch.lnk
[A ] 72. c:\program files\acrobatchs\reader\reader_sl.exe
+ 正在运行的进程
+ 00000098(152) LEXBCES.EXE
00400000[0004E000]
[AM] 1. c:\windows\system32\lexbces.exe
10000000[00012000]
[ M] 73. c:\rising\rfw\ijt_base.dll
00B30000[0000F000]
[ M] 74. c:\rising\rfw\olemon.dll
01170000[00039000]
[ M] 75. c:\windows\system32\lexp2p32.dll
011F0000[00036000]
[ M] 76. c:\windows\system32\lex2kusb.dll
+ 0000009c(156) RfwMain.exe
00400000[0008C000]
[AM] 61. c:\rising\rfw\rfwmain.exe
7C140000[00103000]
[ M] 77. c:\windows\system32\mfc71.dll
7C340000[00056000]
[ M] 78. c:\windows\system32\msvcr71.dll
7C3A0000[0007B000]
[ M] 79. c:\windows\system32\msvcp71.dll
26600000[000B5000]
[ M] 80. c:\rising\rfw\rsguilib.dll
10000000[0001F000]
[ M] 81. c:\rising\rfw\proccom.dll
00B40000[00024000]
[ M] 82. c:\rising\rfw\rscommx2.dll
00C80000[0000E000]
[ M] 83. c:\rising\rfw\rsappmgr.dll
00CA0000[0002F000]
[ M] 84. c:\rising\rfw\cfgdll.dll
23700000[00028000]
[ M] 85. c:\rising\rfw\rscommon.dll
00EE0000[00014000]
[ M] 86. c:\rising\rfw\rfwctrl.dll
23800000[00018000]
[ M] 87. c:\rising\rfw\rsxml.dll
23900000[00040000]
[ M] 88. c:\rising\rfw\pngdll.dll
013D0000[0001B000]
[ M] 89. c:\rising\ieprot.dll
+ 00000124(292) spoolsv.exe
10000000[00012000]
[ M] 73. c:\rising\rfw\ijt_base.dll
00A60000[0000F000]
[ M] 74. c:\rising\rfw\olemon.dll
00EF0000[00038000]
[AM] 69. c:\windows\system32\lexlmpm.dll
63800000[00026000]
[ M] 90. c:\windows\system32\lexbce.dll
00FB0000[00008000]
[AM] 70. c:\windows\system32\mdimon.dll
01410000[00018000]
[ M] 91. c:\windows\system32\spool\prtprocs\w32x86\lvdapp5c.dll
01430000[00008000]
[ M] 92. c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
00C40000[00012000]
[ M] 93. c:\windows\system32\lvdapwr.dll
+ 0000013c(316) LEXPPS.EXE
00400000[00031000]
[ M] 94. c:\windows\system32\lexpps.exe
10000000[00012000]
[ M] 73. c:\rising\rfw\ijt_base.dll
00E50000[0000F000]
[ M] 74. c:\rising\rfw\olemon.dll
63800000[00026000]
[ M] 90. c:\windows\system32\lexbce.dll
+ 00000214(532) smss.exe
+ 00000228(552) Ras.exe
00400000[00160000]
[ M] 95. c:\rising\ras.exe
10000000[00013000]
[ M] 96. c:\rising\topsoft.dll
7C140000[00103000]
[ M] 97. c:\rising\mfc71.dll
7C340000[00056000]
[ M] 98. c:\rising\msvcr71.dll
7C3A0000[0007B000]
[ M] 99. c:\rising\msvcp71.dll
00C40000[0001E000]
[AM] 35. d:\360safe\safemon\safemon.dll
00E20000[0001F000]
[ M] 100. c:\rising\rav\proccom.dll
00E40000[00024000]
[ M] 101. c:\rising\rav\rscommx2.dll
00F90000[000BD000]
[ M] 102. c:\rising\rasgui.dll
00F60000[0001B000]
[ M] 89. c:\rising\ieprot.dll
+ 0000025c(604) csrss.exe
10000000[00012000]
[ M] 73. c:\rising\rfw\ijt_base.dll
03510000[0000F000]
[ M] 74. c:\rising\rfw\olemon.dll
+ 00000274(628) winlogon.exe
10000000[00012000]
[ M] 73. c:\rising\rfw\ijt_base.dll
01360000[0000F000]
[ M] 74. c:\rising\rfw\olemon.dll
72C80000[00008000]
[ M] 103. c:\windows\system32\msacm32.drv
+ 00000290(656) iexplore.exe
10000000[0001E000]
[AM] 35. d:\360safe\safemon\safemon.dll
00FA0000[00057000]
[AM] 30. c:\windows\system32\kakatool.dll
076F0000[0003E000]
[AM] 31. c:\program files\tencent\qqdownload\qqiehelper02.dll
07760000[00019000]
[AM] 32. d:\thunder5\comdlls\xunleibho_now.dll
223F0000[00009000]
[ M] 104. d:\thunder5\components\resworker\dsbho_00.dll
223C0000[0000C000]
[ M] 105. d:\thunder5\components\resworker\dataprocessor_00.dll
077D0000[00022000]
[AM] 33. d:\thunder5\comdlls\tdatonce_now.dll
07800000[0000E000]
[AM] 34. c:\program files\acrobatchs\activex\acroiehelper.dll
7C340000[00056000]
[ M] 78. c:\windows\system32\msvcr71.dll
07950000[0001B000]
[ M] 89. c:\rising\ieprot.dll
325C0000[00012000]
[AM] 49. c:\program files\microsoft office\office11\msohev.dll
1C000000[00006000]
[ M] 106. c:\windows\hkntdll.dll
109B0000[007E0000]
[ M] 107. c:\windows\system32\unispim6.ime
+ 000002a0(672) services.exe
47260000[0000F000]
[ M] 108. c:\windows\apppatch\acadproc.dll
失去才懂紾惜 - 2007-10-4 11:31:00
10000000[00012000]
[ M] 73. c:\rising\rfw\ijt_base.dll
00C40000[0000F000]
[ M] 74. c:\rising\rfw\olemon.dll
+ 000002ac(684) lsass.exe
10000000[00012000]
[ M] 73. c:\rising\rfw\ijt_base.dll
00D90000[0000F000]
[ M] 74. c:\rising\rfw\olemon.dll
+ 00000344(836) svchost.exe
10000000[00012000]
[ M] 73. c:\rising\rfw\ijt_base.dll
008E0000[0000F000]
[ M] 74. c:\rising\rfw\olemon.dll
+ 00000390(912) svchost.exe
10000000[00012000]
[ M] 73. c:\rising\rfw\ijt_base.dll
009B0000[0000F000]
[ M] 74. c:\rising\rfw\olemon.dll
+ 000003ec(1004) CCenter.exe
00400000[00028000]
[AM] 6. c:\rising\rav\ccenter.exe
10000000[00012000]
[ M] 73. c:\rising\rfw\ijt_base.dll
00A70000[0000F000]
[ M] 74. c:\rising\rfw\olemon.dll
+ 00000404(1028) svchost.exe
10000000[00012000]
[ M] 73. c:\rising\rfw\ijt_base.dll
009E0000[0000F000]
[ M] 74. c:\rising\rfw\olemon.dll
+ 0000043c(1084) svchost.exe
10000000[00012000]
[ M] 73. c:\rising\rfw\ijt_base.dll
007A0000[0000F000]
[ M] 74. c:\rising\rfw\olemon.dll
+ 000004ac(1196) svchost.exe
10000000[00012000]
[ M] 73. c:\rising\rfw\ijt_base.dll
00820000[0000F000]
[ M] 74. c:\rising\rfw\olemon.dll
+ 000004c8(1224) rfwsrv.exe
00400000[00035000]
[AM] 5. c:\rising\rfw\rfwsrv.exe
7C140000[00103000]
[ M] 77. c:\windows\system32\mfc71.dll
7C340000[00056000]
[ M] 78. c:\windows\system32\msvcr71.dll
7C3A0000[0007B000]
[ M] 79. c:\windows\system32\msvcp71.dll
10000000[0000E000]
[ M] 83. c:\rising\rfw\rsappmgr.dll
00870000[0002F000]
[ M] 84. c:\rising\rfw\cfgdll.dll
00980000[0000F000]
[ M] 109. c:\rising\rfw\rfwrule.dll
00990000[0000C000]
[ M] 110. c:\rising\rfw\rfwlog.dll
009A0000[00018000]
[ M] 111. c:\rising\rfw\rfwdrv.dll
731B0000[0000A000]
[ M] 112. c:\rising\rfw\psapi.dll
00AC0000[0000E000]
[ M] 113. c:\rising\rfw\ijt_ctrl.dll
00D00000[00012000]
[ M] 73. c:\rising\rfw\ijt_base.dll
00C00000[00016000]
[ M] 114. c:\rising\rfw\unvdet.dll
00C30000[0000F000]
[ M] 74. c:\rising\rfw\olemon.dll
00C70000[00013000]
[ M] 115. c:\rising\rfw\mports.dll
+ 000004f0(1264) Ravmond.exe
00400000[00068000]
[AM] 7. c:\rising\rav\ravmond.exe
10000000[00042000]
[ M] 116. c:\rising\rav\bwlist.dll
7C140000[00103000]
[ M] 77. c:\windows\system32\mfc71.dll
7C340000[00056000]
[ M] 78. c:\windows\system32\msvcr71.dll
7C3A0000[0007B000]
[ M] 79. c:\windows\system32\msvcp71.dll
00B20000[0000E000]
[ M] 117. c:\rising\rav\rsappmgr.dll
00B40000[0002F000]
[ M] 118. c:\rising\rav\cfgdll.dll
00EE0000[00065000]
[ M] 119. c:\rising\rav\rslog.dll
00B80000[0001F000]
[ M] 100. c:\rising\rav\proccom.dll
00F50000[00024000]
[ M] 101. c:\rising\rav\rscommx2.dll
00F90000[00075000]
[ M] 120. c:\rising\rav\monrule.dll
01020000[00013000]
[ M] 121. c:\rising\rav\hooksys.dll
01290000[00012000]
[ M] 73. c:\rising\rfw\ijt_base.dll
01190000[0000F000]
[ M] 74. c:\rising\rfw\olemon.dll
011B0000[00013000]
[ M] 122. c:\rising\rav\hookreg.dll
01210000[00013000]
[ M] 123. c:\rising\rav\hookntos.dll
01270000[0001B000]
[ M] 124. c:\rising\rav\rswalmon.dll
023E0000[00020000]
[ M] 125. c:\rising\rav\rsstore.dll
02610000[00013000]
[ M] 126. c:\rising\rav\hookcont.dll
02640000[00027000]
[ M] 127. c:\rising\rav\fakescan.dll
02680000[00021000]
[ M] 128. c:\rising\rav\scanner.dll
026B0000[00027000]
[ M] 129. c:\rising\rav\recomp.dll
026F0000[0002E000]
[ M] 130. c:\rising\rav\refs.dll
02730000[0002C000]
[ M] 131. c:\rising\rav\viruslib.dll
02870000[00027000]
[ M] 132. c:\rising\rav\relibldr.dll
02D60000[0000D000]
[ M] 133. c:\rising\rav\hookweb.dll
03DB0000[0001A000]
[ M] 134. c:\rising\rav\ffr.dll
03DE0000[00020000]
[ M] 135. c:\rising\rav\nvfile.dll
13AB0000[00043000]
[ M] 136. c:\rising\rav\scanexec.dll
05070000[002DC000]
[ M] 137. c:\rising\rav\unexe.dll
05360000[00045000]
[ M] 138. c:\rising\rav\scanex.dll
05700000[00026000]
[ M] 139. c:\rising\rav\pearc.dll
04260000[00035000]
[ M] 140. c:\rising\rav\scanpack.dll
042B0000[000B4000]
[ M] 141. c:\rising\rav\revm.dll
045A0000[000F5000]
[ M] 142. c:\rising\rav\uroutine.dll
02E90000[00037000]
[ M] 143. c:\rising\rav\scriptci.dll
02F10000[00022000]
[ M] 144. c:\rising\rav\scansct.dll
14210000[00034000]
[ M] 145. c:\rising\rav\extmail.dll
04150000[0003F000]
[ M] 146. c:\rising\rav\extole.dll
+ 0000050c(1292) rfwproxy.exe
00400000[0023D000]
[AM] 4. c:\rising\rfw\rfwproxy.exe
7C140000[00103000]
[ M] 77. c:\windows\system32\mfc71.dll
7C340000[00056000]
[ M] 78. c:\windows\system32\msvcr71.dll
731B0000[0000A000]
[ M] 112. c:\rising\rfw\psapi.dll
10000000[0000F000]
[ M] 109. c:\rising\rfw\rfwrule.dll
01090000[00012000]
[ M] 73. c:\rising\rfw\ijt_base.dll
00F90000[0000F000]
[ M] 74. c:\rising\rfw\olemon.dll
00FB0000[00016000]
[ M] 147. c:\rising\rfw\monmid.dll
+ 00000620(1568) Explorer.EXE
164A0000[00023000]
[AM] 54. c:\windows\system32\wpdshserviceobj.dll
72C80000[00008000]
[ M] 103. c:\windows\system32\msacm32.drv
109C0000[0002C000]
[ M] 148. c:\windows\system32\portabledevicetypes.dll
10930000[00049000]
[ M] 149. c:\windows\system32\portabledeviceapi.dll
01F70000[0001B000]
[ M] 89. c:\rising\ieprot.dll
10000000[0001E000]
[AM] 35. d:\360safe\safemon\safemon.dll
00F20000[0001C000]
[AM] 41. c:\program files\acrobatchs\activex\pdfshell.dll
02270000[00557000]
[AM] 43. c:\windows\system32\nvcpl.dll
01C80000[0001C000]
[AM] 50. c:\windows\system32\ravext.dll
02C30000[00011000]
[AM] 53. c:\windows\system32\shlhook.dll
+ 000006a8(1704) rfwstub.exe
00400000[00017000]
[ M] 150. c:\rising\rfw\rfwstub.exe
7C3A0000[0007B000]
[ M] 79. c:\windows\system32\msvcp71.dll
7C340000[00056000]
[ M] 78. c:\windows\system32\msvcr71.dll
23700000[00028000]
[ M] 85. c:\rising\rfw\rscommon.dll
+ 000007ac(1964) RavStub.exe
00400000[00021000]
[ M] 151. c:\rising\rav\ravstub.exe
10000000[00012000]
[ M] 73. c:\rising\rfw\ijt_base.dll
00630000[0000F000]
[ M] 74. c:\rising\rfw\olemon.dll
00660000[0001F000]
[ M] 100. c:\rising\rav\proccom.dll
00680000[00024000]
[ M] 101. c:\rising\rav\rscommx2.dll
23700000[00028000]
[ M] 152. c:\rising\rav\rscommon.dll
+ 000008c0(2240) alg.exe
+ 00000a18(2584) QQ.exe
00400000[001B6000]
[AM] 71. d:\qq\qq.exe
10000000[00022000]
[ M] 153. d:\qq\coralassist.dll
005D0000[0007E000]
[ M] 154. d:\qq\coralqq.dll
003B0000[00029000]
[ M] 155. d:\qq\kql.dll
7C420000[00087000]
[ M] 156. d:\qq\msvcp80.dll
78130000[0009B000]
[ M] 157. d:\qq\msvcr80.dll
60A80000[000F2000]
[ M] 158. d:\qq\mfc42.dll
003F0000[00009000]
[ M] 159. d:\qq\ipsearcher.dll
00660000[00261000]
[ M] 160. d:\qq\qqbaseclassindll.dll
61740000[000A7000]
[ M] 161. d:\qq\qqhelperdll.dll
600A0000[00072000]
[ M] 162. d:\qq\basicctrldll.dll
01C80000[0000B000]
[ M] 163. d:\qq\nodisturbfilter.cqx
01D10000[00006000]
[ M] 164. d:\qq\confighotkey.cqx
62250000[00005000]
[ M] 165. d:\qq\riched32.dll
621E0000[00068000]
[ M] 166. d:\qq\riched20.dll
61310000[0003A000]
[ M] 167. d:\qq\qqapi.dll
623A0000[00007000]
[ M] 168. d:\qq\timproxy.dll
02590000[0001B000]
[ M] 89. c:\rising\ieprot.dll
02730000[00006000]
[ M] 169. d:\qq\autoreconnect.cqx
60890000[00038000]
[ M] 170. d:\qq\loginctrl.dll
608D0000[00099000]
[ M] 171. d:\qq\loginctrlres.dll
02F90000[004DE000]
[ M] 172. d:\qq\qqres.dll
61840000[00093000]
[ M] 173. d:\qq\qqmainframe.dll
603C0000[001A3000]
[ M] 174. d:\qq\gdiplus.dll
60200000[00123000]
[ M] 175. d:\qq\cqqapplication.dll
60380000[0003F000]
[ M] 176. d:\qq\flashavatardll.dll
60C20000[0005E000]
[ M] 177. d:\qq\newskin.dll
606B0000[000BD000]
[ M] 178. d:\qq\hostingmgr.dll
60140000[00034000]
[ M] 179. d:\qq\cameradll.dll
60A40000[00032000]
[ M] 180. d:\qq\mailsummary.dll
03EA0000[0000F000]
[ M] 181. d:\qq\coralhotkey.cqx
617F0000[00017000]
[ M] 182. d:\qq\qqknowledgesearch.dll
61110000[001F4000]
[ M] 183. d:\qq\qqallinone.dll
62280000[0002B000]
[ M] 184. d:\qq\sccore.dll
62090000[00024000]
[ M] 185. d:\qq\qqspace.dll
623F0000[00071000]
[ M] 186. d:\qq\vbscript.dll
616C0000[00071000]
失去才懂紾惜 - 2007-10-4 11:32:00
[ M] 187. d:\qq\qqgroupmng.dll
623D0000[00017000]
[ M] 188. d:\qq\userdefinedhead.dll
61A10000[000D7000]
[ M] 189. d:\qq\qqplugin.dll
03CC0000[00050000]
[ M] 190. d:\qq\qqcustomface.dll
72C80000[00008000]
[ M] 103. c:\windows\system32\msacm32.drv
619E0000[0002A000]
[ M] 191. d:\qq\qqpet.dll
72C60000[00007000]
[ M] 192. c:\windows\system32\msadp32.acm
61600000[0000C000]
[ M] 193. d:\qq\qqconfigplugin.dll
61350000[0003D000]
[ M] 194. d:\qq\qqavatar.dll
621C0000[00016000]
[ M] 195. d:\qq\qringmng.dll
60970000[000A8000]
[ M] 196. d:\qq\longconnection.dll
61810000[00015000]
[ M] 197. d:\qq\qqliveqmng.dll
60770000[0001A000]
[ M] 198. d:\qq\imageole.dll
61830000[0000E000]
[ M] 199. d:\qq\qqmagicface.dll
61FD0000[0002C000]
[ M] 200. d:\qq\qqscenemng.dll
60D20000[00026000]
[ M] 201. d:\qq\phoneapi.dll
60330000[0000D000]
[ M] 202. d:\qq\dialerallinone.dll
60680000[00024000]
[ M] 203. d:\qq\groupconnection.dll
07E70000[00028000]
[ M] 204. c:\rising\rav\ravscrch.dll
62000000[00072000]
[ M] 205. d:\qq\qqsettingctrl.dll
620C0000[0003D000]
[ M] 206. d:\qq\qqsysmsgmng.dll
62160000[0005B000]
[ M] 207. d:\qq\qqzip.dll
60120000[0001F000]
[ M] 208. d:\qq\bqqapplication.dll
60CA0000[0000F000]
[ M] 209. d:\qq\personaldesktop.dll
099E0000[007E0000]
[ M] 107. c:\windows\system32\unispim6.ime
60180000[0004F000]
[ M] 210. d:\qq\commercesmng.dll
0A9C0000[00286000]
[ M] 211. d:\qq\qqaddr.dll
02290000[0002B000]
[ M] 212. d:\qq\addrsearch.dll
+ 00000abc(2748) TIMPlatform.exe
00400000[00013000]
[ M] 213. d:\qq\timplatform.exe
10000000[0001E000]
[AM] 35. d:\360safe\safemon\safemon.dll
00AC0000[0001B000]
[ M] 89. c:\rising\ieprot.dll
623A0000[00007000]
[ M] 168. d:\qq\timproxy.dll
+ 00000acc(2764) VTTimer.exe
00400000[0000D000]
[AM] 55. c:\windows\system32\vttimer.exe
10000000[0001B000]
[ M] 89. c:\rising\ieprot.dll
+ 00000ad4(2772) VTtrayp.exe
00400000[00027000]
[AM] 56. c:\windows\system32\vttrayp.exe
6BB00000[0007B000]
[ M] 214. c:\windows\system32\vtdisply.dll
6BE00000[0005A000]
[ M] 215. c:\windows\system32\vtgamma2.dll
6C000000[00043000]
[ M] 216. c:\windows\system32\vtinfo2.dll
6C200000[00065000]
[ M] 217. c:\windows\system32\vtovrlay.dll
10000000[0001B000]
[ M] 89. c:\rising\ieprot.dll
00FF0000[0001E000]
[AM] 35. d:\360safe\safemon\safemon.dll
+ 00000adc(2780) SOUNDMAN.EXE
00400000[00016000]
[AM] 57. c:\windows\soundman.exe
10000000[0001B000]
[ M] 89. c:\rising\ieprot.dll
+ 00000ae4(2788) LHotkey.exe
00400000[0000A000]
[AM] 58. c:\windows\lhotkey.exe
1C000000[00006000]
[ M] 106. c:\windows\hkntdll.dll
10000000[0001B000]
[ M] 89. c:\rising\ieprot.dll
+ 00000af4(2804) RavTask.exe
00400000[00034000]
[AM] 60. c:\rising\rav\ravtask.exe
10000000[0001F000]
[ M] 100. c:\rising\rav\proccom.dll
00A30000[00024000]
[ M] 101. c:\rising\rav\rscommx2.dll
23700000[00028000]
[ M] 152. c:\rising\rav\rscommon.dll
00C90000[0000E000]
[ M] 117. c:\rising\rav\rsappmgr.dll
08CB0000[0002F000]
[ M] 118. c:\rising\rav\cfgdll.dll
08FA0000[0001B000]
[ M] 89. c:\rising\ieprot.dll
+ 00000b08(2824) 360Tray.exe
00400000[00028000]
[AM] 62. d:\360safe\safemon\360tray.exe
10000000[0001E000]
[AM] 35. d:\360safe\safemon\safemon.dll
00B40000[0000C000]
[ M] 218. d:\360safe\safemon\safekrnl.dll
00B50000[00022000]
[ M] 219. d:\360safe\antiadwa.dll
00B80000[0001B000]
[ M] 89. c:\rising\ieprot.dll
00BC0000[0001C000]
[ M] 220. d:\360safe\live.dll
+ 00000b14(2836) Ravmon.exe
00400000[00093000]
[ M] 221. c:\rising\rav\ravmon.exe
7C140000[00103000]
[ M] 77. c:\windows\system32\mfc71.dll
7C340000[00056000]
[ M] 78. c:\windows\system32\msvcr71.dll
7C3A0000[0007B000]
[ M] 79. c:\windows\system32\msvcp71.dll
10000000[0001F000]
[ M] 100. c:\rising\rav\proccom.dll
00C50000[00024000]
[ M] 101. c:\rising\rav\rscommx2.dll
23700000[00028000]
[ M] 152. c:\rising\rav\rscommon.dll
00EA0000[00027000]
[ M] 129. c:\rising\rav\recomp.dll
00EE0000[0002E000]
[ M] 130. c:\rising\rav\refs.dll
01030000[0002C000]
[ M] 131. c:\rising\rav\viruslib.dll
01380000[00027000]
[ M] 132. c:\rising\rav\relibldr.dll
01400000[0000E000]
[ M] 117. c:\rising\rav\rsappmgr.dll
01420000[0002F000]
[ M] 118. c:\rising\rav\cfgdll.dll
01580000[00075000]
[ M] 120. c:\rising\rav\monrule.dll
23900000[00040000]
[ M] 222. c:\rising\rav\pngdll.dll
26600000[000B5000]
[ M] 223. c:\rising\rav\rsguilib.dll
23800000[00018000]
[ M] 224. c:\rising\rav\rsxml.dll
02B90000[0001B000]
[ M] 89. c:\rising\ieprot.dll
+ 00000b2c(2860) runiep.exe
00400000[00013000]
[AM] 63. c:\rising\runiep.exe
00CB0000[0001B000]
[ M] 89. c:\rising\ieprot.dll
+ 00000b38(2872) ctfmon.exe
10000000[0001B000]
[ M] 89. c:\rising\ieprot.dll
© 2000 - 2026 Rising Corp. Ltd.