瑞星卡卡电脑诊断日志 v1.30 (2008-6-29 11:35:56) 北京瑞星科技股份有限公司 注释: [A]表示该文件存在自启动关联; [M]表示该文件在内存中; + 注册表自运行项目 + 系统服务 + HKLM\System\CurrentControlSet\Services NVSvc [AM] 1. c:\windows\system32\nvsvc32.exe NVIDIA Corporation NVIDIA Driver Helper Service, Version 81.98 .text,.rdata,.data,.rsrc, ose [A ] 2. c:\program files\common files\microsoft shared\source engine\ose.exe Microsoft Corporation Office Source Engine .text,.data,.rsrc, RfwProxySrv [A ] 3. c:\program files\rising\rfw\rfwproxy.exe Beijing Rising Technology Co., Ltd. Rising Personal Proxy Service .text,.rdata,.data,.rsrc, RfwService [A ] 4. c:\program files\rising\rfw\rfwsrv.exe Beijing Rising Technology Co., Ltd. Rising Personal FireWall Service .text,.rdata,.data,.rsrc, RsCCenter [AM] 5. c:\program files\rising\rav\ccenter.exe Beijing Rising Technology Co., Ltd. CCenter .text,.rdata,.data,.rsrc, RsRavMon [AM] 6. c:\program files\rising\rav\ravmond.exe Beijing Rising Technology Co., Ltd. Rising Realtime Moniter .text,.rdata,.data,.rsrc, UMWdf [AM] 7. c:\windows\system32\wdfmgr.exe Microsoft Corporation Windows User Mode Driver Manager .text,.data,.rsrc, + 内核驱动 + HKLM\System\CurrentControlSet\Services a320raid [A ] 8. c:\windows\system32\drivers\a320raid.sys Adaptec, Inc. Adaptec HostRAID for Ultra320 SCSI .text,.rdata,.data,INIT,.rsrc,.reloc, AAC [A ] 9. c:\windows\system32\drivers\aac.sys Adaptec, Inc. Adaptec RAID Miniport Driver .text,.rdata,.data,INIT,.rsrc,.reloc, aar1210 [A ] 10. c:\windows\system32\drivers\aar1210.sys Adaptec, Inc. Adaptec HostRAID for Serial ATA .text,.rdata,.data,INIT,.rsrc,.reloc, adpu320 [A ] 11. c:\windows\system32\drivers\adpu320.sys Adaptec, Inc. Adaptec Win2K/XP/Server2003 Ultra320 SCSI Driver .text,.rdata,.data,INIT,.rsrc,.reloc, aec6210 [A ] 12. c:\windows\system32\drivers\aec6210.sys ACARD Technology Corp. .text,.data,.idata,.rsrc,.reloc, aec6260 [A ] 13. c:\windows\system32\drivers\aec6260.sys ACARD Technology Corp. ID=0006, 0007 .text,.rdata,.data,INIT,.rsrc,.reloc, aec6280 [A ] 14. c:\windows\system32\drivers\aec6280.sys ACARD Technology Corp. AEC6280 Miniport Driver .text,.rdata,.data,INIT,.rsrc,.reloc, AEC6290 [A ] 15. c:\windows\system32\drivers\aec6290.sys ACARD Technology Corp. AEC6280 Miniport Driver .text,.rdata,.data,INIT,.rsrc,.reloc, AEC67160 [A ] 16. c:\windows\system32\drivers\aec67160.sys ACARD Technology Corp. AEC67160 PCI Ultra3 LVD/SE Adapter Driver .text,.rdata,INIT,.rsrc,.reloc, AEC671X [A ] 17. c:\windows\system32\drivers\aec671x.sys ACARD Technology Corp. AEC671X PCI Ultra/W SCSI3 Adapter Driver .text,.rdata,INIT,.rsrc,.reloc, AEC6880 [A ] 18. c:\windows\system32\drivers\aec6880.sys ACARD Technology Corp. AEC6880/90 PCI Ultra ATA133 RAID Adapter Driver .text,.rdata,INIT,.rsrc,.reloc, AEC6890 [A ] 19. c:\windows\system32\drivers\aec6890.sys ACARD Technology Corp. AEC6880/90 PCI Ultra ATA133 RAID Adapter Driver .text,.rdata,INIT,.rsrc,.reloc, aec68x5 [A ] 20. c:\windows\system32\drivers\aec68x5.sys ACARD Technology Corp. AEC6885/95/96 PCI ATA133 4 Channel RAID Adapter Driver .text,.rdata,INIT,.rsrc,.reloc, ahghggca [A ] 21. c:\windows\system32\drivers\ahghggca.sys ALCXWDM [A ] 22. c:\windows\system32\drivers\alcxwdm.sys Realtek Semiconductor Corp. Realtek AC'97 Audio Driver (WDM) .text,CODE,.rdata,.data,.data1,PAGE,INIT,.rsrc,.reloc, AmdK8 [A ] 23. c:\windows\system32\drivers\amdk8.sys Microsoft Corporation Processor Device Driver .text,.rdata,.data,PAGE,PAGELK,INIT,.rsrc,.reloc, arc [A ] 24. c:\windows\system32\drivers\arc.sys Adaptec, Inc. Adaptec RAID Storport Driver .text,.rdata,.data,INIT,.rsrc,.reloc, elxstor [A ] 25. c:\windows\system32\drivers\elxstor.sys Emulex Storport Miniport Driver for LightPulse HBAs .text,.rdata,.data,INIT,.rsrc,.reloc, FASTSX [A ] 26. c:\windows\system32\drivers\fastsx.sys Promise Technology, Inc. Promise FastTRAK SX4/SX4000 Driver for WindowsXP .text,.rdata,.data,INIT,.rsrc,.reloc, fasttrak [A ] 27. c:\windows\system32\drivers\fasttrak.sys Promise Technology, Inc. Promise FastTrak Series Driver for WinXP .text,.rdata,.data,INIT,.rsrc,.reloc, fasttx2k [A ] 28. c:\windows\system32\drivers\fasttx2k.sys Promise Technology, Inc. Promise Driver for Windows XP .text,.rdata,.data,INIT,.rsrc,.reloc, fasttx2k2 [A ] 29. c:\windows\system32\drivers\fasttx2k2.sys Promise Technology, Inc. Promise FastTrak Series Driver for WindowsXP .text,.rdata,.data,INIT,.rsrc,.reloc, HookCont [A ] 30. c:\windows\system32\drivers\hookcont.sys Beijing Rising Technology Co., Ltd HookCont .text,.rdata,.data,INIT,.rsrc,.reloc, HookNtos [A ] 31. c:\windows\system32\drivers\hookntos.sys Beijing Rising Technology Co., Ltd HookNtos .text,.rdata,.data,INIT,.rsrc,.reloc, HookReg [A ] 32. c:\windows\system32\drivers\hookreg.sys Beijing Rising Technology Co., Ltd HookReg .text,.rdata,.data,INIT,.rsrc,.reloc, HookSys [A ] 33. c:\windows\system32\drivers\hooksys.sys Beijing Rising Technology Co., Ltd Hooksys .text,.rdata,.data,INIT,.rsrc,.reloc, HookUrl [A ] 34. c:\program files\rising\rfw\hookurl.sys Beijing Rising Technology Co., Ltd. URL Filter Driver .text,.rdata,.data,INIT,.rsrc,.reloc, HpCISSs [A ] 35. c:\windows\system32\drivers\hpcisss.sys Hewlett-Packard Company Smart Array 5x and 6x Controllers Storport Driver .text,.rdata,.data,INIT,.rsrc,.reloc, Hpt366 [A ] 36. c:\windows\system32\drivers\hpt366.sys Microsoft Corporation ATAPI IDE Miniport Driver .text,.data,INIT,.rsrc,.reloc, HPT371 [A ] 37. c:\windows\system32\drivers\hpt371.sys HighPoint Technologies, Inc. HPT3xx Miniport Driver .text,.rdata,.data,INIT,.rsrc,.reloc, hpt374 [A ] 38. c:\windows\system32\drivers\hpt374.sys HighPoint Technologies, Inc. HPT374 Miniport Driver .text,.rdata,.data,INIT,.rsrc,.reloc, hpt3xx [A ] 39. c:\windows\system32\drivers\hpt3xx.sys HighPoint Technologies, Inc. HPT3xx Miniport Driver .text,.rdata,.data,INIT,.rsrc,.reloc, hptmv [A ] 40. c:\windows\system32\drivers\hptmv.sys HighPoint Technologies, Inc. hptmv Miniport Driver .text,.rdata,.data,INIT,.rsrc,.reloc, hptpro [A ] 41. c:\windows\system32\drivers\hptpro.sys HighPoint Technologies, Inc. Hptpro .text,.rdata,.data,PAGE,INIT,.rsrc,.reloc, iaStor [A ] 42. c:\windows\system32\drivers\iastor.sys Intel Corporation Intel Application Accelerator driver .text,.rdata,.data,INIT,.rsrc,.reloc, iirsp [A ] 43. c:\windows\system32\drivers\iirsp.sys Intel Corp./ICP vortex GmbH Intel/ICP Raid Storport Driver .text,.rdata,.data,INIT,.rsrc,.reloc, iteraid [A ] 44. c:\windows\system32\drivers\iteraid.sys Integrated Technology Express, Inc. ITE IT8212 ATA RAID SCSI miniport .text,.rdata,.data,INIT,.rsrc,.reloc, LSI_FC [A ] 45. c:\windows\system32\drivers\lsi_fc.sys LSI Logic LSI Logic Fusion-MPT FC Driver (StorPort) .text,.rdata,.data,INIT,.rsrc,.reloc, LSI_SAS [A ] 46. c:\windows\system32\drivers\lsi_sas.sys LSI Logic LSI Logic Fusion-MPT SAS Driver (StorPort) .text,.rdata,.data,INIT,.rsrc,.reloc, LSI_SCSI [A ] 47. c:\windows\system32\drivers\lsi_scsi.sys LSI Logic LSI Logic Fusion-MPT SCSI Driver (StorPort) .text,.rdata,.data,INIT,.rsrc,.reloc, m5228 [A ] 48. c:\windows\system32\drivers\m5228.sys ALi Corporation. M5228 ATA RAID Controller Driver .text,.rdata,.data,INIT,.rsrc,.reloc, m5281 [A ] 49. c:\windows\system32\drivers\m5281.sys ALi Corporation M5281 SATA RAID Controller Driver .text,.rdata,.data,INIT,.rsrc,.reloc, MegaIDE [A ] 50. c:\windows\system32\drivers\megaide.sys LSI Logic Corporation. LSI MegaRAID IDE Driver .text,.rdata,.data,INIT,.rsrc,.reloc, megasas [A ] 51. c:\windows\system32\drivers\megasas.sys LSI Logic Corporation MEGASAS RAID Controller Driver for Windows for x86 .text,.rdata,.data,INIT,.rsrc,.reloc, mraid2k [A ] 52. c:\windows\system32\drivers\mraid2k.sys American Megatrends, Inc. MEGARAID SCSI Controller Driver for Windows 2000 PAE .text,.rdata,.data,INIT,.rsrc,.reloc, nfrd960 [A ] 53. c:\windows\system32\drivers\nfrd960.sys IBM Corporation IBM ServeRAID Controller Driver .text,.rdata,.data,INIT,.rsrc,.reloc, npkcrypt [A ] 54. c:\windows\npkcrypt.sys INCA Internet Co., Ltd. nProtect KeyCrypt Driver .text,.rdata,.data,INIT,.rsrc,.reloc, npkycryp [A ] 55. c:\windows\npkycryp.sys NvAtaBus [A ] 56. c:\windows\system32\drivers\nvatabus.sys NVIDIA Corporation NVIDIA? nForce(TM) IDE Performance Driver .text,.rdata,.data,PAGE,INIT,.rsrc,.reloc, nvraid [A ] 57. c:\windows\system32\drivers\nvraid.sys NVIDIA Corporation NVIDIA? nForce(TM) RAID Driver .text,.rdata,.data,PAGE,INIT,DUMPDATA,.rsrc,.reloc, PNP649R [A ] 58. c:\windows\system32\drivers\pnp649r.sys CMD Technology, Inc. IDE RAID miniport driver .text,.rdata,.data,PAGE,INIT,.rsrc,.reloc, Pnp680 [A ] 59. c:\windows\system32\drivers\pnp680.sys Silicon Image, Inc. DMA capable ATA miniport driver .text,.rdata,.data,PAGE,INIT,.rsrc,.reloc, Pnp680r [A ] 60. c:\windows\system32\drivers\pnp680r.sys Silicon Image, Inc DMA capable ATA RAID miniport driver .text,.rdata,.data,PAGE,INIT,.rsrc,.reloc, ql2300 [A ] 61. c:\windows\system32\drivers\ql2300.sys QLogic Corporation QLogic Fibre Channel Stor Miniport Driver .text,.rdata,.data,INIT,.rsrc,.reloc, RAIDSRC [A ] 62. c:\windows\system32\drivers\raidsrc.sys Intel/ICP Intel(r)/ICP Miniport Driver .text,.rdata,.data,INIT,.rsrc,.reloc, RfwBase [A ] 63. c:\windows\system32\drivers\rfwbase.sys Beijing Rising Technology Co., Ltd. net base driver .text,.rdata,.data,INIT,.rsrc,.reloc, RsAntiSpyware [A ] 64. c:\windows\system32\drivers\rsboot.sys Beijing Rising Technology Co., Ltd. Anti-RootKit Driver .text,.rdata,.data,INIT,.rsrc,.reloc, RsFwDrv [A ] 65. c:\program files\rising\rfw\rsfwdrv.sys Beijing Rising Technology Co., Ltd. Rules Driver .text,.rdata,.data,INIT,.rsrc,.reloc, RsNTGDI [A ] 66. c:\windows\system32\drivers\rsntgdi.sys Beijing Rising Technology Co., Ltd. RsNTGDI .text,.rdata,INIT,.rsrc,.reloc, RTL8023xp [A ] 67. c:\windows\system32\drivers\rtnicxp.sys Realtek Semiconductor Corporation Realtek 10/100/1000 NDIS 5.1 Driver .text,.rdata,.data,PAGE,INIT,.rsrc,.reloc, S150SX8 [A ] 68. c:\windows\system32\drivers\s150sx8.sys Promise Technology, Inc. Promise SATAII150 SX8 Driver for WindowsXP .text,.rdata,.data,INIT,.rsrc,.reloc, Secdrv [A ] 69. c:\windows\system32\drivers\secdrv.sys Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. Macrovision SECURITY Driver .text,.rdata,.data,PAGE,INIT,.rsrc,.reloc, SI3112 [A ] 70. c:\windows\system32\drivers\si3112.sys Silicon Image, Inc. Serial ATA miniport driver .text,.rdata,.data,PAGE,INIT,.rsrc,.reloc, SI3112r [A ] 71. c:\windows\system32\drivers\si3112r.sys Silicon Image, Inc Serial ATA RAID Miniport Driver .text,.rdata,.data,PAGE,INIT,.rsrc,.reloc, SI3114 [A ] 72. c:\windows\system32\drivers\si3114.sys Silicon Image, Inc. Serial ATA miniport driver .text,.rdata,.data,PAGE,INIT,.rsrc,.reloc, SI3114r [A ] 73. c:\windows\system32\drivers\si3114r.sys Silicon Image, Inc SATARAID Miniport Driver .text,.rdata,.data,PAGE,INIT,.rsrc,.reloc, SI3124 [A ] 74. c:\windows\system32\drivers\si3124.sys Silicon Image, Inc. Serial ATA miniport driver .text,.rdata,.data,PAGE,INIT,.rsrc,.reloc, SI3124r [A ] 75. c:\windows\system32\drivers\si3124r.sys Silicon Image, Inc SATARAID miniport driver (PRE-RELEASE) .text,.rdata,.data,PAGE,INIT,.rsrc,.reloc, SiFilter [A ] 76. c:\windows\system32\drivers\siwinacc.sys Silicon Image, Inc. Windows Accelerator Driver .text,.rdata,.data,INIT,.rsrc,.reloc, SISIDE [A ] 77. c:\windows\system32\drivers\siside.sys Silicon Integrated Systems Corp. SiS PCI Mini IDE Driver .text,.rdata,INIT,.rsrc,.reloc, SiSRaid [A ] 78. c:\windows\system32\drivers\sisraid.sys Silicon Integrated Systems SiS RAID Miniport Driver .text,.rdata,.data,INIT,.rsrc,.reloc, SiSRaid1 [A ] 79. c:\windows\system32\drivers\sisraid1.sys Silicon Integrated Systems SiS RAID Miniport Driver .text,.rdata,.data,INIT,.rsrc,.reloc, SISRAIDS [A ] 80. c:\windows\system32\drivers\sisraids.sys Silicon Integrated Systems Corp SiS RAID Miniport Driver .text,.rdata,.data,INIT,.rsrc,.reloc, SKNFW [A ] 81. c:\windows\system32\drivers\sknfw.sys .text,.rdata,.data,INIT,.reloc, sptrak [A ] 82. c:\windows\system32\drivers\sptrak.sys Promise Technology, Inc. Promise SuperTrak Family Driver for WindowsNT .text,.rdata,.data,INIT,.rsrc,.reloc, SYMMPI [A ] 83. c:\windows\system32\drivers\symmpi.sys LSI Logic LSI Logic Fusion-MPT MiniPort Driver (ScsiPort) .text,.rdata,.data,INIT,.rsrc,.reloc, UlSata [A ] 84. c:\windows\system32\drivers\ulsata.sys Promise Technology, Inc. Promise Ultra/Sata Series Driver for WinXP .text,.rdata,.data,INIT,.rsrc,.reloc, ULSATAS [A ] 85. c:\windows\system32\drivers\ulsatas.sys Promise Technology, Inc. Promise SATAII150 Series Driver for Win2003 .text,.rdata,.data,INIT,.rsrc,.reloc, viamraid [A ] 86. c:\windows\system32\drivers\viamraid.sys VIA Technologies inc,.ltd VIA RAID DRIVER FOR WIN 2000/XP/2003IA32 .text,.rdata,.data,INIT,.rsrc,.reloc, viapdsk [A ] 87. c:\windows\system32\drivers\viapdsk.sys VIA Technologies, Inc. VIA VT4149 PATA Driver .text,.rdata,.data,INIT,.rsrc,.reloc, viaraid [A ] 88. c:\windows\system32\drivers\viaraid.sys VIA Technologies inc,.ltd VT6410 RAID DRIVER FOR WINXP .text,.rdata,.data,INIT,.rsrc,.reloc, viasraid [A ] 89. c:\windows\system32\drivers\viasraid.sys VIA Technologies inc,.ltd VIA SATA RAID DRIVER FOR WINXP .text,.rdata,.data,INIT,.rsrc,.reloc, vmscsi [A ] 90. c:\windows\system32\drivers\vmscsi.sys VMware, Inc. VMware SCSI Controller .text,.rdata,.data,INIT,.rsrc,.reloc, XPROTECTOR [A ] 91. c:\windows\system32\drivers\xprotector.sys .text,.rdata,.data,INIT,.reloc, ZSMC301b [A ] 92. c:\windows\system32\drivers\usbvm31b.sys VM Video streaming and Capture Device Driver .text,.data,PAGECONS,INIT,.rsrc,.reloc, + 系统登陆自运行 + HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify WgaLogon [AM] 93. c:\windows\system32\wgalogon.dll Microsoft Corporation Windows 正版增值计划通知 .text,.data,.rsrc,.reloc, + HKCU\Control Panel\Desktop Scrnsave.exe [A ] 94. c:\windows\system32\热带鱼屏保.scr .text,.rdata,.data,.rsrc, + IE浏览器加载模块 + HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects {01443AEC-0FD1-40fd-9C87-E93D1494C233} [A ] 95. c:\program files\thunder network\thunder\comdlls\tdatonce_now.dll Thunder Networking Technologies,LTD 迅雷浏览器高级特性支持模块 .text,.rdata,.data,.rsrc,.reloc, {24F06550-65E3-4D1C-8CFE-839C296B5530} [A ] 96. c:\program files\eread6.0\eread6.0\ieeread.dll IEeREAD Module .text,.rdata,.data,.rsrc,.reloc, {6A19C29D-ED45-4483-8999-9F939C8161F2} [A ] 97. c:\program files\eread6.0\eread6.0\webhook.dll IEeREAD Module .text,.rdata,.data,.rsrc,.reloc, {889D2FEB-5411-4565-8998-1DD2C5261283} [AM] 98. c:\program files\thunder network\thunder\comdlls\xunleibho_now.dll Thunder Networking Technologies,LTD XunLeiBHO .text,.rdata,.data,.rsrc,.reloc, {ED863792-FADB-4D21-8B20-409DA940B7A2} [A ] 99. c:\windows\system\pdfaid.dll adobe system adobe plugin .text,.rdata,.data,.rsrc,.reloc, + HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions Exec [A ] 100. c:\program files\thunder network\thunder\thunder.exe Thunder Networking Technologies,LTD .text,.rdata,.data,.rsrc, + 资源管理器加载模块 + HKLM\SOFTWARE\Classes\PROTOCOLS\Filter text/xml [A ] 101. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll Microsoft Corporation Microsoft Office XML MIME Filter .text,.data,.rsrc,.reloc, + HKLM\SOFTWARE\Classes\PROTOCOLS\Handler KuGoo [A ] 102. c:\windows\system32\kugoo3downxcontrol.ocx 酷狗 酷狗音乐控件 CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc, KuGoo3 [A ] 102. c:\windows\system32\kugoo3downxcontrol.ocx 酷狗 酷狗音乐控件 CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc, + HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved HyperTerminal Icon Ext [A ] 103. c:\windows\system32\hticons.dll Hilgraeve, Inc. HyperTerminal Applet Library .text,.data,.rsrc,.reloc, Portable Media Devices [A ] 104. c:\windows\system32\audiodev.dll Microsoft Corporation 便携媒体设备命令行解释器扩展 .text,.data,.rsrc,.reloc, Portable Media Devices Menu [A ] 104. c:\windows\system32\audiodev.dll Microsoft Corporation 便携媒体设备命令行解释器扩展 .text,.data,.rsrc,.reloc, WinRAR shell extension [A ] 105. c:\program files\winrar\rarext.dll .text,.data,.tls,.idata,.edata,.rsrc,.reloc, Shell Extensions for RealOne Player [A ] 106. c:\program files\real\realplayer\rpshell.dll RealNetworks, Inc. RealPlayer Shell Extensions .text,.rdata,.data,.rsrc,.reloc, PicaView [A ] 107. c:\program files\picaview\picaview.dll ACD Systems, Ltd. PicaView 资源管理器扩展 DLL .text,.rdata,.data,.tls,.rsrc,.reloc, Photo Resizing PowerToy [A ] 108. c:\program files\picaview\phototoys.dll Microsoft Corporation Windows XP PowerToys .text,.data,.rsrc,.reloc, Web Folders [A ] 109. c:\program files\common files\microsoft shared\web folders\msonsext.dll Microsoft Corporation Microsoft Web Folders .text,.data,.rsrc,.reloc, Microsoft Office HTML Icon Handler [A ] 110. c:\program files\microsoft office\office11\msohev.dll Microsoft Corporation Microsoft Office 2003 component .text,.data,.rsrc,.reloc, NvCpl DesktopContext Class [A ] 111. c:\windows\system32\nvcpl.dll NVIDIA Corporation NVIDIA Display Properties Extension .text,.rdata,.data,.rsrc,.reloc, Play on my TV helper [A ] 111. c:\windows\system32\nvcpl.dll NVIDIA Corporation NVIDIA Display Properties Extension .text,.rdata,.data,.rsrc,.reloc, Desktop Explorer [A ] 112. c:\windows\system32\nvshell.dll .text,.rdata,.data,.idata,.shared,.rsrc,.reloc, Desktop Explorer Menu [A ] 112. c:\windows\system32\nvshell.dll .text,.rdata,.data,.idata,.shared,.rsrc,.reloc, nView Desktop Context Menu [A ] 112. c:\windows\system32\nvshell.dll .text,.rdata,.data,.idata,.shared,.rsrc,.reloc, RISING [AM] 113. c:\windows\system32\ravext.dll Beijing Rising Technology Co., Ltd. Rising Shell Ext Module .text,.rdata,.data,.rsrc,.reloc, + HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A} [AM] 114. c:\windows\system32\shlhook.dll Beijing Rising Technology Co., Ltd. shlhook Module .text,.rdata,.data,.rsrc,.reloc, {32CD708B-60A7-4C00-9377-D73EAA495F0F} [AM] 113. c:\windows\system32\ravext.dll Beijing Rising Technology Co., Ltd. Rising Shell Ext Module .text,.rdata,.data,.rsrc,.reloc, + 用户登陆自运行项目 + HKCU\Software\Microsoft\Windows\CurrentVersion\Run bgswitch [A ] 115. c:\windows\system32\bgswitch.exe .text,.data,.rsrc, TudouVAStart [AM] 116. c:\program files\tudou\飞速tudou\tudouva.exe 土豆网(www.tudou.com) 飞速Tudou .text,.rdata,.data,.rsrc, + HKLM\Software\Microsoft\Windows\CurrentVersion\Run nwiz [A ] 117. c:\windows\system32\nwiz.exe .text,.rdata,.data,.rsrc, BigDogPath [AM] 118. c:\windows\vm_sti.exe Vimicro Vimicro .text,.rdata,.data,.sxdata,.rsrc, runeip [AM] 119. c:\program files\rising\antispyware\runiep.exe Beijing Rising Technology Co., Ltd. Rising AntiSpyware Monitor .text,.rdata,.data,.rsrc, RavTask [AM] 120. c:\program files\rising\rav\ravtask.exe Beijing Rising Technology Co., Ltd. RavTimer .text,.rdata,.data,.rsrc, SKYNET Personal FireWall [AM] 121. c:\program files\skynet\firewall\pfw.exe 广州众达天网技术有限公司 天网防火墙个人版 .text,.data,.tls,.rdata,.idata,.edata,.rsrc,.reloc, + HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce KKDelay [A ] 122. c:\program files\rising\antispyware\runonce.exe Beijing Rising Technology Co., Ltd. RunOnce Application .text,.rdata,.data,.rsrc, + 开机执行 + HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order BootExecute [A ] 123. c:\windows\system32\bsmain.exe Beijing Rising Technology Co., Ltd. Rising Antivirus 2008 .text,.rdata,.data,.rsrc,.reloc, [A ] 124. c:\windows\system32\kknative.exe Beijing Rising Technology Co., Ltd. NativeAp .text,.data,.rsrc,.reloc, + 映像劫持 + HKCR\.html htmlfile\Edit\Command [A ] 125. c:\program files\microsoft office\office11\msohtmed.exe Microsoft Corporation Microsoft Office 2003 component .text,.data,.rsrc, htmlfile\Maxthon\Command [AM] 126. c:\program files\maxthon\maxthon.exe Maxthon International Ltd. Maxthon Web Browser .text,.rdata,.data,.rsrc, htmlfile\open\Command [AM] 126. c:\program files\maxthon\maxthon.exe Maxthon International Ltd. Maxthon Web Browser .text,.rdata,.data,.rsrc, htmlfile\Print\Command [A ] 125. c:\program files\microsoft office\office11\msohtmed.exe Microsoft Corporation Microsoft Office 2003 component .text,.data,.rsrc, + HKCR\.htm htmlfile\Edit\Command [A ] 125. c:\program files\microsoft office\office11\msohtmed.exe Microsoft Corporation Microsoft Office 2003 component .text,.data,.rsrc, htmlfile\Maxthon\Command [AM] 126. c:\program files\maxthon\maxthon.exe Maxthon International Ltd. Maxthon Web Browser .text,.rdata,.data,.rsrc, htmlfile\open\Command [AM] 126. c:\program files\maxthon\maxthon.exe Maxthon International Ltd. Maxthon Web Browser .text,.rdata,.data,.rsrc, htmlfile\Print\Command [A ] 125. c:\program files\microsoft office\office11\msohtmed.exe Microsoft Corporation Microsoft Office 2003 component .text,.data,.rsrc, + 打印机监控 + HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors Microsoft Document Imaging Writer Monitor [AM] 127. c:\windows\system32\mdimon.dll Microsoft Corporation Microsoft? Document Imaging .text,.data,.rsrc,.reloc, + 其他自启动项目 + C:\Documents and Settings\Administrator\「开始」菜单\程序\启动 腾讯QQ.lnk [AM] 128. c:\program files\tencent\qq\qq.exe TENCENT QQ .text,.rdata,.data,.rsrc, QQ游戏启动加速程序.lnk [A ] 129. c:\qqgame\accel.exe 深圳市腾讯计算机系统有限公司 QQ游戏 .text,.rdata,.data,.rsrc, 启动飞速土豆.lnk [AM] 116. c:\program files\tudou\飞速tudou\tudouva.exe 土豆网(www.tudou.com) 飞速Tudou .text,.rdata,.data,.rsrc, + 正在运行的进程 + 000000ac(172) TudouVA.exe 00400000[000F4000] [AM] 116. c:\program files\tudou\飞速tudou\tudouva.exe 土豆网(www.tudou.com) 飞速Tudou .text,.rdata,.data,.rsrc, 10000000[0000E000] [ M] 130. c:\program files\tudou\飞速tudou\upnpdll.dll .text,.rdata,.data,.rsrc,.reloc, 7C420000[00087000] [ M] 131. c:\program files\tudou\飞速tudou\msvcp80.dll Microsoft Corporation Microsoft? C++ Runtime Library .text,.rdata,.data,.rsrc,.reloc, 78130000[0009B000] [ M] 132. c:\program files\tudou\飞速tudou\msvcr80.dll Microsoft Corporation Microsoft? C Runtime Library .text,.rdata,.data,.rsrc,.reloc, 781D0000[0010D000] [ M] 133. c:\program files\tudou\飞速tudou\mfc80.dll Microsoft Corporation MFCDLL Shared Library - Retail Version .text,.data,.rsrc,.reloc, 00CB0000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc, 05870000[00028000] [ M] 135. c:\program files\rising\rav\ravscrch.dll Beijing Rising Technology Co., Ltd. RavScrCh Module .text,.rdata,.data,.rsrc,.reloc, + 00000164(356) nvsvc32.exe 00400000[00022000] [AM] 1. c:\windows\system32\nvsvc32.exe NVIDIA Corporation NVIDIA Driver Helper Service, Version 81.98 .text,.rdata,.data,.rsrc, 10000000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc, + 000001f8(504) Maxthon.exe 00400000[0021B000] [AM] 126. c:\program files\maxthon\maxthon.exe Maxthon International Ltd. Maxthon Web Browser .text,.rdata,.data,.rsrc, 10000000[00015000] [ M] 136. c:\program files\maxthon\maxzlib.dll maxzlib .text,.rdata,.data,.idata,.rsrc,.reloc, 00D90000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc, 03EF0000[00009000] [ M] 137. c:\program files\maxthon\plugin\viewsource\viewsrc.dll ViewSrc Module .text,.rdata,.data,.rsrc,.reloc, 03F40000[0002A000] [AM] 98. c:\program files\thunder network\thunder\comdlls\xunleibho_now.dll Thunder Networking Technologies,LTD XunLeiBHO .text,.rdata,.data,.rsrc,.reloc, 23450000[0000D000] [ M] 138. c:\program files\thunder network\thunder\components\resworker\dsbho_01.dll DsBho .text,.rdata,.data,.rsrc,.reloc, 23420000[0000D000] [ M] 139. c:\program files\thunder network\thunder\components\resworker\dataprocessor_01.dll Thunder Networking Technologies,LTD DataProcessor .text,.rdata,.data,.rsrc,.reloc, 4B4F0000[00006000] [ M] 140. c:\windows\system32\odbcbcp.dll Microsoft Corporation Microsoft BCP for ODBC .text,.data,.rsrc,.reloc, 04960000[0000B000] [ M] 141. c:\program files\maxthon\services\realtime\real_time.dll RealTime Module .text,.rdata,.data,.rsrc,.reloc, 049A0000[00028000] [ M] 135. c:\program files\rising\rav\ravscrch.dll Beijing Rising Technology Co., Ltd. RavScrCh Module .text,.rdata,.data,.rsrc,.reloc, 72C80000[00008000] [ M] 142. c:\windows\system32\msacm32.drv Microsoft Corporation Microsoft Sound Mapper .text,.data,.rsrc,.reloc, + 00000230(560) smss.exe + 00000278(632) csrss.exe + 00000290(656) winlogon.exe 013C0000[0003B000] [AM] 93. c:\windows\system32\wgalogon.dll Microsoft Corporation Windows 正版增值计划通知 .text,.data,.rsrc,.reloc, 10000000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc, 72C80000[00008000] [ M] 142. c:\windows\system32\msacm32.drv Microsoft Corporation Microsoft Sound Mapper .text,.data,.rsrc,.reloc, + 000002bc(700) services.exe + 000002c8(712) lsass.exe + 00000344(836) QQ.exe 00400000[001F5000] [AM] 128. c:\program files\tencent\qq\qq.exe TENCENT QQ .text,.rdata,.data,.rsrc, 61440000[00315000] [ M] 143. c:\program files\tencent\qq\qqbaseclassindll.dll TENCENT QQBaseClassInDll DLL .text,.rdata,.data,.rsrc,.reloc, 618A0000[000E8000] [ M] 144. c:\program files\tencent\qq\qqhelperdll.dll TENCENT QQHelperDll DLL .text,.rdata,.data,.rsrc,.reloc, 600A0000[00070000] [ M] 145. c:\program files\tencent\qq\basicctrldll.dll TENCENT BasicCtrlDll DLL .text,.rdata,.data,.rsrc,.reloc, 60A70000[000F2000] [ M] 146. c:\program files\tencent\qq\mfc42.dll Microsoft Corporation MFCDLL Shared Library - Retail Version .text,.rdata,.data,.rsrc,.reloc, 10000000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc, 60450000[001A3000] [ M] 147. c:\program files\tencent\qq\gdiplus.dll Microsoft Corporation Microsoft GDI+ .text,.data,Shared,.rsrc,.reloc, 62580000[00005000] [ M] 148. c:\program files\tencent\qq\riched32.dll Microsoft Corporation Wrapper Dll for Richedit 1.0 .text,.data,.rsrc,.reloc, 62510000[00068000] [ M] 149. c:\program files\tencent\qq\riched20.dll Microsoft Corporation Rich Text Edit Control, v3.1 .text,.data,.rsrc,.reloc, 613B0000[0003C000] [ M] 150. c:\program files\tencent\qq\qqapi.dll TENCENT ModuleSample DLL .text,.rdata,.data,.rsrc,.reloc, 608A0000[00046000] [ M] 151. c:\program files\tencent\qq\loginctrl.dll TENCENT NewSkin .text,.rdata,.data,.rsrc,.reloc, 608F0000[0009D000] [ M] 152. c:\program files\tencent\qq\loginctrlres.dll TENCENT LoginCtrl DLL .rdata,.rsrc,.reloc, 61D50000[0062F000] [ M] 153. c:\program files\tencent\qq\qqres.dll TENCENT QQRes .rsrc,.reloc, 62C70000[00021000] [ M] 154. c:\program files\tencent\qq\wizardctrl.dll TENCENT WizardCtrl DLL .text,.rdata,.data,.rsrc,.reloc, 619E0000[000D5000] [ M] 155. c:\program files\tencent\qq\qqmainframe.dll .text,.rdata,.data,.reloc, 61C10000[00131000] [ M] 156. c:\program files\tencent\qq\qqplugin.dll .text,.rdata,.data,.reloc, 62790000[00021000] [ M] 157. c:\program files\tencent\qq\unreadmsgmgr.dll .text,.rdata,.data,.reloc, 60240000[0017A000] [ M] 158. c:\program files\tencent\qq\cqqapplication.dll .text,.rdata,.data,.reloc, 60410000[00040000] [ M] 159. c:\program files\tencent\qq\flashavatardll.dll FlashAvatarDll DLL .text,.rdata,.data,.rsrc,.reloc, 60C60000[0005F000] [ M] 160. c:\program files\tencent\qq\newskin.dll TENCENT NewSkin Module .text,.rdata,.data,.rsrc,.reloc, 049F0000[00036000] [ M] 161. c:\program files\tencent\qq\mailsummary.dll TENCENT MailSummary DLL .text,.rdata,.data,.rsrc,.reloc, 62430000[00027000] [ M] 162. c:\program files\tencent\qq\qqspace.dll TENCENT QQSpace DLL .text,.rdata,.data,.rsrc,.reloc, 050A0000[00071000] [ M] 163. c:\program files\tencent\qq\vbscript.dll Microsoft Corporation Microsoft (r) VBScript .text,.rdata,.data,.rsrc,.reloc, 61990000[00018000] [ M] 164. c:\program files\tencent\qq\qqknowledgesearch.dll TENCENT QQKnowledgeSearch DLL .text,.rdata,.data,.rsrc,.reloc, 60CC0000[00015000] [ M] 165. c:\program files\tencent\qq\oemapplication.dll TENCENT OEMApplication DLL .text,.rdata,.data,.rsrc,.reloc, 04830000[00075000] [ M] 166. c:\program files\tencent\qq\qqgroupmng.dll TENCENT QQGroupMng DLL .text,.rdata,.data,.rsrc,.reloc, 61150000[00260000] [ M] 167. c:\program files\tencent\qq\qqallinone.dll TENCENT NewSkin .text,.rdata,.data,.rsrc,.reloc, 62630000[0002B000] [ M] 168. c:\program files\tencent\qq\sccore.dll TENCENT SCCore.dll .text,.rdata,.data,.shareds,.rsrc,.reloc, 60130000[00036000] [ M] 169. c:\program files\tencent\qq\cameradll.dll TENCENT CameraDll DLL .text,.rdata,.data,.MYSHARE,.rsrc,.reloc, 055A0000[0002B000] [ M] 170. c:\program files\tencent\qq\qqpet.dll TENCENT QQPet DLL .text,.rdata,.data,.rsrc,.reloc, 62460000[0004C000] [ M] 171. c:\program files\tencent\qq\qqsysmsgmng.dll .text,.rdata,.data,.reloc, 627C0000[00017000] [ M] 172. c:\program files\tencent\qq\userdefinedhead.dll TENCENT UserDefinedHead DLL .text,.rdata,.data,.rsrc,.reloc, 61760000[0000E000] [ M] 173. c:\program files\tencent\qq\qqconfigplugin.dll TENCENT QQConfigPlugin DLL .text,.rdata,.data,.rsrc,.reloc, 61770000[00054000] [ M] 174. c:\program files\tencent\qq\qqcustomface.dll .text,.rdata,.data,.reloc, 02F70000[00016000] [ M] 175. c:\program files\tencent\qq\qringmng.dll .text,.rdata,.data,.reloc, 60990000[000CC000] [ M] 176. c:\program files\tencent\qq\longconnection.dll TENCENT LongConnection .text,.rdata,.data,.rsrc,.reloc, 617E0000[0002C000] [ M] 177. c:\program files\tencent\qq\qqfiletransfer.dll TENCENT QQFileTransfer DLL .text,.rdata,.data,.rsrc,.reloc, 613F0000[00042000] [ M] 178. c:\program files\tencent\qq\qqavatar.dll .text,.rdata,.data,.reloc, 60D60000[00027000] [ M] 179. c:\program files\tencent\qq\phoneapi.dll TENCENT PhoneAPI DLL .text,.rdata,.data,.rsrc,.reloc, 603C0000[0000D000] [ M] 180. c:\program files\tencent\qq\dialerallinone.dll tencent DialerAllInOne .text,.rdata,.data,Shared,.rsrc,.reloc, 72C80000[00008000] [ M] 142. c:\windows\system32\msacm32.drv Microsoft Corporation Microsoft Sound Mapper .text,.data,.rsrc,.reloc, 60110000[0001F000] [ M] 181. c:\program files\tencent\qq\bqqapplication.dll .text,.rdata,.data,.reloc, 02F40000[00011000] [AM] 114. c:\windows\system32\shlhook.dll Beijing Rising Technology Co., Ltd. shlhook Module .text,.rdata,.data,.rsrc,.reloc, 02F90000[0001C000] [AM] 113. c:\windows\system32\ravext.dll Beijing Rising Technology Co., Ltd. Rising Shell Ext Module .text,.rdata,.data,.rsrc,.reloc, 04740000[0004B000] [ M] 182. c:\program files\tencent\qq\qqdoctor\tsfscan.dat TENCENT TSFSCAN DLL UPX0,UPX1,.rsrc, 60170000[0004F000] [ M] 183. c:\program files\tencent\qq\commercesmng.dll TENCENT CommercesMng DLL .text,.rdata,.data,.rsrc,.reloc, 60CE0000[0000F000] [ M] 184. c:\program files\tencent\qq\personaldesktop.dll TENCENT QQ个人桌面 .text,.rdata,.data,.rsrc,.reloc, 05CD0000[00287000] [ M] 185. c:\program files\tencent\qq\qqaddr.dll 深圳市腾讯计算机系统有限公司 腾讯通讯录 .text,.rdata,.data,.rsrc,.reloc, 62380000[0002C000] [ M] 186. c:\program files\tencent\qq\qqscenemng.dll .text,.rdata,.data,.reloc, 026C0000[00037000] [ M] 187. c:\program files\tencent\qq\addrsearch.dll 腾讯科技(深圳)有限公司 AddrSearch UPX0,UPX1,.rsrc, + 00000348(840) TXPlatform.exe 00400000[00025000] [ M] 188. c:\program files\tencent\qq\txplatform.exe Tencent Tencent Instant Messaging Platform .text,.rdata,.data,.rsrc, + 00000368(872) svchost.exe + 00000378(888) svchost.exe + 000003b4(948) svchost.exe + 00000414(1044) CCenter.exe 00400000[00029000] [AM] 5. c:\program files\rising\rav\ccenter.exe Beijing Rising Technology Co., Ltd. CCenter .text,.rdata,.data,.rsrc, + 00000434(1076) svchost.exe 50E60000[0000C000] [ M] 189. c:\windows\system32\wups2.dll Microsoft Corporation Windows Update client proxy stub 2 .text,.orpc,.data,.rsrc,.reloc, + 00000464(1124) svchost.exe + 00000478(1144) rundll32.exe 01010000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc, + 000004d8(1240) svchost.exe + 00000520(1312) Setup.exe 00400000[000A0000] [ M] 190. c:\program files\rising\rav\update\setup.exe Beijing Rising Technology Co., Ltd. Rising Installation Program .text,.rdata,.data,.rsrc, 10000000[00020000] [ M] 191. c:\program files\rising\rav\update\rscommx.dll rising RsCommX .text,.rdata,.data,.rsrc,.reloc, 00B80000[0001F000] [ M] 192. c:\program files\rising\rav\update\proccom.dll Beijing Rising Technology Co., Ltd. ProcessC Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 00BA0000[00024000] [ M] 193. c:\program files\rising\rav\update\rscommx2.dll Beijing Rising Technology Co., Ltd. RsCommX2 .text,.rdata,.data,.rsrc,.reloc, 00D90000[00029000] [ M] 194. c:\program files\rising\rav\update\setup.dll Beijing Rising Technology Co., Ltd. Module install implement .text,.rdata,.data,.rsrc,.reloc, 23700000[00028000] [ M] 195. c:\program files\rising\rav\update\rscommon.dll Beijing Rising Technology Co., Ltd. Rising Common Function Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, + 00000538(1336) ravmond.exe 00400000[00069000] [AM] 6. c:\program files\rising\rav\ravmond.exe Beijing Rising Technology Co., Ltd. Rising Realtime Moniter .text,.rdata,.data,.rsrc, 10000000[00042000] [ M] 196. c:\program files\rising\rav\bwlist.dll Beijing Rising Technology Co., Ltd. BWList DLL .text,.rdata,.data,.rsrc,.reloc, 7C140000[00103000] [ M] 197. c:\windows\system32\mfc71.dll Microsoft Corporation MFCDLL Shared Library - Retail Version .text,.data,.rsrc,.reloc, 7C340000[00056000] [ M] 198. c:\windows\system32\msvcr71.dll Microsoft Corporation Microsoft? C Runtime Library .text,.rdata,.data,.rsrc,.reloc, 7C3A0000[0007B000] [ M] 199. c:\windows\system32\msvcp71.dll Microsoft Corporation Microsoft? C++ Runtime Library .text,.rdata,.data,.rsrc,.reloc, 5D360000[0000A000] [ M] 200. c:\windows\system32\mfc71chs.dll Microsoft Corporation MFC Language Specific Resources .rsrc,.reloc, 00AE0000[0000E000] [ M] 201. c:\program files\rising\rav\rsappmgr.dll Beijing Rising Technology Co., Ltd. Rising Application Manager .text,.rdata,.data,.rsrc,.reloc, 00B00000[00030000] [ M] 202. c:\program files\rising\rav\cfgdll.dll Beijing Rising Technology Co., Ltd. CfgDll .text,.rdata,.data,.rsrc,.reloc, 00DA0000[00067000] [ M] 203. c:\program files\rising\rav\rslog.dll Beijing Rising Technology Co., Ltd. RsLog DLL .text,.rdata,.data,.rsrc,.reloc, 00B40000[0001F000] [ M] 204. c:\program files\rising\rav\proccom.dll Beijing Rising Technology Co., Ltd. ProcessC Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 00E10000[00024000] [ M] 205. c:\program files\rising\rav\rscommx2.dll Beijing Rising Technology Co., Ltd. RsCommX2 .text,.rdata,.data,.rsrc,.reloc, 00E90000[00075000] [ M] 206. c:\program files\rising\rav\monrule.dll Beijing Rising Technology Co., Ltd. MonRule .text,.rdata,.data,.rsrc,.reloc, 00F20000[00013000] [ M] 207. c:\program files\rising\rav\hooksys.dll Beijing Rising Technology Co., Ltd Hooksys Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 01080000[00013000] [ M] 208. c:\program files\rising\rav\hookreg.dll Beijing Rising Technology Co., Ltd HookReg Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 010E0000[00013000] [ M] 209. c:\program files\rising\rav\hookntos.dll Beijing Rising Technology Co., Ltd SysMon Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 01140000[0001C000] [ M] 210. c:\program files\rising\rav\rswalmon.dll Beijing Rising Technology Co., Ltd. Rising WAL Monitor DLL .text,.rdata,.data,.rsrc,.reloc, 01AA0000[00027000] [ M] 211. c:\program files\rising\rav\fakescan.dll Beijing Rising Technology Co., Ltd. FakeScan Module .text,.rdata,.data,.rsrc,.reloc, 01AE0000[00022000] [ M] 212. c:\program files\rising\rav\scanner.dll Beijing Rising Technology Co., Ltd. RsScanner Module .text,.rdata,.data,.rsrc,.reloc, 01A70000[0000D000] [ M] 213. c:\program files\rising\rav\hookweb.dll Beijing Rising Technology Co., Ltd. Rising HookWeb Dll .text,.rdata,.data,.rsrc,.reloc, 01B10000[00035000] [ M] 214. c:\program files\rising\rav\recomp.dll Beijing Rising Technology Co., Ltd. component manager Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 01B50000[00036000] [ M] 215. c:\program files\rising\rav\refs.dll Beijing Rising Technology Co., Ltd. filesystem Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 01DB0000[0002F000] [ M] 216. c:\program files\rising\rav\viruslib.dll Beijing Rising Technology Co., Ltd. VirusLib Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 01EF0000[00028000] [ M] 217. c:\program files\rising\rav\relibldr.dll Beijing Rising Technology Co., Ltd. libloader Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 02290000[00023000] [ M] 218. c:\program files\rising\rav\ffr.dll Beijing Rising Technology Co., Ltd. ffr Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 02640000[00021000] [ M] 219. c:\program files\rising\rav\nvfile.dll Beijing Rising Technology Co., Ltd. NVFile .text,.rdata,.data,.rsrc,.reloc, 03F00000[00023000] [ M] 220. c:\program files\rising\rav\scansct.dll Beijing Rising Technology Co., Ltd. ScanSct Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, + 00000598(1432) RavStub.exe 00400000[00021000] [ M] 221. c:\program files\rising\rav\ravstub.exe Beijing Rising Technology Co., Ltd. Rising RavStub .text,.rdata,.data,.rsrc, 10000000[0001F000] [ M] 204. c:\program files\rising\rav\proccom.dll Beijing Rising Technology Co., Ltd. ProcessC Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 00620000[00024000] [ M] 205. c:\program files\rising\rav\rscommx2.dll Beijing Rising Technology Co., Ltd. RsCommX2 .text,.rdata,.data,.rsrc,.reloc, 23700000[00028000] [ M] 222. c:\program files\rising\rav\rscommon.dll Beijing Rising Technology Co., Ltd. Rising Common Function Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, + 000005f8(1528) wdfmgr.exe 01000000[0000C000] [AM] 7. c:\windows\system32\wdfmgr.exe Microsoft Corporation Windows User Mode Driver Manager .text,.data,.rsrc, + 00000634(1588) spoolsv.exe 00AF0000[00008000] [AM] 127. c:\windows\system32\mdimon.dll Microsoft Corporation Microsoft? Document Imaging .text,.data,.rsrc,.reloc, 00B00000[00008000] [ M] 223. c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll Microsoft Corporation Microsoft? Document Imaging .text,.data,.rsrc,.reloc, + 00000720(1824) Explorer.EXE 10000000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc, 00C70000[00011000] [AM] 114. c:\windows\system32\shlhook.dll Beijing Rising Technology Co., Ltd. shlhook Module .text,.rdata,.data,.rsrc,.reloc, 00FE0000[0001C000] [AM] 113. c:\windows\system32\ravext.dll Beijing Rising Technology Co., Ltd. Rising Shell Ext Module .text,.rdata,.data,.rsrc,.reloc, 72C80000[00008000] [ M] 142. c:\windows\system32\msacm32.drv Microsoft Corporation Microsoft Sound Mapper .text,.data,.rsrc,.reloc, + 000007a4(1956) RUNDLL32.EXE 01010000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc, + 000007ac(1964) VM_STI.EXE 00400000[00010000] [AM] 118. c:\windows\vm_sti.exe Vimicro Vimicro .text,.rdata,.data,.sxdata,.rsrc, 60AC0000[000F2000] [ M] 224. c:\windows\mfc42.dll Microsoft Corporation MFCDLL Shared Library - Retail Version .text,.rdata,.data,.rsrc,.reloc, 10000000[00037000] [ M] 225. c:\windows\system32\vm31bprp.ax Vimicro DirectShow Extension Page .text,.rdata,.data,.idata,.CRT,.rsrc,.reloc, + 000007b4(1972) runiep.exe 00400000[00020000] [AM] 119. c:\program files\rising\antispyware\runiep.exe Beijing Rising Technology Co., Ltd. Rising AntiSpyware Monitor .text,.rdata,.data,.rsrc, 7C140000[00103000] [ M] 226. c:\program files\rising\antispyware\mfc71.dll Microsoft Corporation MFCDLL Shared Library - Retail Version .text,.data,.rsrc,.reloc, 7C340000[00056000] [ M] 227. c:\program files\rising\antispyware\msvcr71.dll Microsoft Corporation Microsoft? C Runtime Library .text,.rdata,.data,.rsrc,.reloc, 5D360000[0000A000] [ M] 200. c:\windows\system32\mfc71chs.dll Microsoft Corporation MFC Language Specific Resources .rsrc,.reloc, 00C40000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc, 01520000[00020000] [ M] 228. c:\windows\system32\ieprot.dll Beijing Rising Technology Co., Ltd. IE Protector .text,.rdata,.data,.rsrc,.reloc, + 000007c0(1984) RavTask.exe 00400000[00034000] [AM] 120. c:\program files\rising\rav\ravtask.exe Beijing Rising Technology Co., Ltd. RavTimer .text,.rdata,.data,.rsrc, 10000000[0001F000] [ M] 204. c:\program files\rising\rav\proccom.dll Beijing Rising Technology Co., Ltd. ProcessC Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 00A30000[00024000] [ M] 205. c:\program files\rising\rav\rscommx2.dll Beijing Rising Technology Co., Ltd. RsCommX2 .text,.rdata,.data,.rsrc,.reloc, 23700000[00028000] [ M] 222. c:\program files\rising\rav\rscommon.dll Beijing Rising Technology Co., Ltd. Rising Common Function Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 00C90000[0000E000] [ M] 201. c:\program files\rising\rav\rsappmgr.dll Beijing Rising Technology Co., Ltd. Rising Application Manager .text,.rdata,.data,.rsrc,.reloc, 08CB0000[00030000] [ M] 202. c:\program files\rising\rav\cfgdll.dll Beijing Rising Technology Co., Ltd. CfgDll .text,.rdata,.data,.rsrc,.reloc, 08E80000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc, + 000007cc(1996) PFW.exe 00400000[00303000] [AM] 121. c:\program files\skynet\firewall\pfw.exe 广州众达天网技术有限公司 天网防火墙个人版 .text,.data,.tls,.rdata,.idata,.edata,.rsrc,.reloc, 10000000[0001E000] [ M] 229. c:\program files\skynet\firewall\skymisc.dll .text,.rdata,.data,.idata,.reloc, 00370000[0006E000] [ M] 230. c:\program files\skynet\firewall\compresswrap.dll .text,.rdata,.data,.reloc, 012D0000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc, 048C0000[00028000] [ M] 135. c:\program files\rising\rav\ravscrch.dll Beijing Rising Technology Co., Ltd. RavScrCh Module .text,.rdata,.data,.rsrc,.reloc, + 000007e0(2016) ctfmon.exe 10000000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc, + 00000910(2320) Ras.exe 00400000[001FF000] [ M] 231. c:\program files\rising\antispyware\ras.exe Beijing Rising Technology Co., Ltd. Rising AntiSpyware .text,.rdata,.data,.rsrc, 7C140000[00103000] [ M] 226. c:\program files\rising\antispyware\mfc71.dll Microsoft Corporation MFCDLL Shared Library - Retail Version .text,.data,.rsrc,.reloc, 7C340000[00056000] [ M] 227. c:\program files\rising\antispyware\msvcr71.dll Microsoft Corporation Microsoft? C Runtime Library .text,.rdata,.data,.rsrc,.reloc, 7C3A0000[0007B000] [ M] 232. c:\program files\rising\antispyware\msvcp71.dll Microsoft Corporation Microsoft? C++ Runtime Library .text,.rdata,.data,.rsrc,.reloc, 10000000[00013000] [ M] 233. c:\program files\rising\antispyware\topsoft.dll Beijing Rising Technology Co., Ltd. Rising AntiSpyware TopSoft .text,.rdata,.data,.rsrc,.reloc, 00370000[00032000] [ M] 234. c:\program files\rising\antispyware\ncomm.dll Beijing Rising Technology Co., Ltd. Rising AntiSpyware .text,.rdata,.data,.rsrc,.reloc, 5D360000[0000A000] [ M] 200. c:\windows\system32\mfc71chs.dll Microsoft Corporation MFC Language Specific Resources .rsrc,.reloc, 00D10000[0001F000] [ M] 204. c:\program files\rising\rav\proccom.dll Beijing Rising Technology Co., Ltd. ProcessC Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 00EE0000[00024000] [ M] 205. c:\program files\rising\rav\rscommx2.dll Beijing Rising Technology Co., Ltd. RsCommX2 .text,.rdata,.data,.rsrc,.reloc, 01020000[0014D000] [ M] 235. c:\program files\rising\antispyware\rasgui.dll Beijing Rising Technology Co., Ltd. RasGUI .text,.rdata,.data,.rsrc,.reloc, 23800000[00022000] [ M] 236. c:\program files\rising\antispyware\rsxml.dll Beijing Rising Technology Co., Ltd. RsXML .text,.rdata,.data,.rsrc,.reloc, 01970000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc, 03D60000[00018000] [ M] 237. c:\program files\rising\antispyware\ktrojan.dll Beijing Rising Technology Co., Ltd. Rising AntiSpyware .text,.rdata,.data,.rsrc,.reloc, 03D80000[0002F000] [ M] 238. c:\program files\rising\antispyware\engine.dll Beijing Rising Technology Co., Ltd. kaka engine .text,.rdata,.data,.rsrc,.reloc, 05320000[00041000] [ M] 239. c:\program files\rising\antispyware\rsdialog.dll Beijing Rising Technology Co., Ltd. Rsdiaglo DLL .text,.rdata,.data,.rsrc,.reloc, 053E0000[00024000] [ M] 240. c:\program files\rising\antispyware\scanunv.dll Beijing Rising Technology Co., Ltd. .text,.rdata,.data,.rsrc,.reloc, 05420000[0001F000] [ M] 241. c:\program files\rising\antispyware\secscan.dll Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited SecScan Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 05820000[00015000] [ M] 242. c:\program files\rising\antispyware\secex.dll Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited SecScanE Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 05C20000[00012000] [ M] 243. c:\program files\rising\antispyware\zip.dll rising zip UPX0,UPX1,.rsrc, 06420000[00028000] [ M] 135. c:\program files\rising\rav\ravscrch.dll Beijing Rising Technology Co., Ltd. RavScrCh Module .text,.rdata,.data,.rsrc,.reloc, 30000000[003AE000] [ M] 244. c:\windows\system32\macromed\flash\flash9e.ocx Adobe Systems, Inc. Adobe Flash Player 9.0 r115 .text,.rdata,.data,.rodata,.rsrc,.reloc, 72C80000[00008000] [ M] 142. c:\windows\system32\msacm32.drv Microsoft Corporation Microsoft Sound Mapper .text,.data,.rsrc,.reloc, + 00000940(2368) WgaTray.exe 01000000[00052000] [ M] 245. c:\windows\system32\wgatray.exe Microsoft Corporation Windows 正版增值计划通知 .text,.data,.rsrc, 10000000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc, + 000009f8(2552) alg.exe + 00000b90(2960) RavCopy.exe 00400000[00018000] [ M] 246. c:\program files\rising\rav\copyrun\ravcopy.exe Beijing Rising Technology Co., Ltd. RavCopy .text,.rdata,.data,.rsrc, 10000000[00063000] [ M] 247. c:\program files\rising\rav\copyrun\update.dll Beijing Rising Technology Co., Ltd. Update Module .text,.rdata,.data,.rsrc,.reloc, 00AD0000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc, + 00000cbc(3260) RsAgent.exe 00400000[00045000] [ M] 248. c:\program files\rising\rav\rsagent.exe Beijing Rising Technology Co., Ltd. RsAgent Application .text,.rdata,.data,.rsrc, 7C140000[00103000] [ M] 197. c:\windows\system32\mfc71.dll Microsoft Corporation MFCDLL Shared Library - Retail Version .text,.data,.rsrc,.reloc, 7C340000[00056000] [ M] 198. c:\windows\system32\msvcr71.dll Microsoft Corporation Microsoft? C Runtime Library .text,.rdata,.data,.rsrc,.reloc, 7C3A0000[0007B000] [ M] 199. c:\windows\system32\msvcp71.dll Microsoft Corporation Microsoft? C++ Runtime Library .text,.rdata,.data,.rsrc,.reloc, 5D360000[0000A000] [ M] 200. c:\windows\system32\mfc71chs.dll Microsoft Corporation MFC Language Specific Resources .rsrc,.reloc, 10000000[0001F000] [ M] 204. c:\program files\rising\rav\proccom.dll Beijing Rising Technology Co., Ltd. ProcessC Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 00B50000[00024000] [ M] 205. c:\program files\rising\rav\rscommx2.dll Beijing Rising Technology Co., Ltd. RsCommX2 .text,.rdata,.data,.rsrc,.reloc, 00CB0000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc, + 00000cd8(3288) AgentSvr.exe 10000000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc, 72C80000[00008000] [ M] 142. c:\windows\system32\msacm32.drv Microsoft Corporation Microsoft Sound Mapper .text,.data,.rsrc,.reloc, + 00000eb4(3764) wuauclt.exe 50E60000[0000C000] [ M] 189. c:\windows\system32\wups2.dll Microsoft Corporation Windows Update client proxy stub 2 .text,.orpc,.data,.rsrc,.reloc, + 00000f00(3840) Setup.exe 00400000[000A0000] [ M] 190. c:\program files\rising\rav\update\setup.exe Beijing Rising Technology Co., Ltd. Rising Installation Program .text,.rdata,.data,.rsrc, 10000000[00020000] [ M] 191. c:\program files\rising\rav\update\rscommx.dll rising RsCommX .text,.rdata,.data,.rsrc,.reloc, 00B80000[0001F000] [ M] 192. c:\program files\rising\rav\update\proccom.dll Beijing Rising Technology Co., Ltd. ProcessC Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 00BA0000[00024000] [ M] 193. c:\program files\rising\rav\update\rscommx2.dll Beijing Rising Technology Co., Ltd. RsCommX2 .text,.rdata,.data,.rsrc,.reloc, 00D90000[00029000] [ M] 194. c:\program files\rising\rav\update\setup.dll Beijing Rising Technology Co., Ltd. Module install implement .text,.rdata,.data,.rsrc,.reloc, 23700000[00028000] [ M] 195. c:\program files\rising\rav\update\rscommon.dll Beijing Rising Technology Co., Ltd. Rising Common Function Dynamic Link Library .text,.rdata,.data,.rsrc,.reloc, 011F0000[00882000] [ M] 134. c:\windows\system32\unispim6.ime 北京紫光华宇软件股份有限公司 紫光华宇拼音输入法V6.1 .text,.rdata,.data,.upim_sh,.rsrc,.reloc,