+ 正在运行的进程
+ 00000144(324) MemorySaviour.exe
00400000[00094000]
[AM] 34. d:\内存\memorysaviour\memorysaviour.exe
UPX0,UPX1,.rsrc,
00EF0000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
10000000[0001B000]
[ M] 38. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 0000018c(396) ctfmon.exe
10000000[0001B000]
[ M] 38. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
00BC0000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
+ 000001bc(444) svchost.exe
00EA0000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
+ 000001c8(456) smss.exe
+ 0000020c(524) csrss.exe
03770000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
+ 00000224(548) winlogon.exe
72C80000[00008000]
[ M] 39. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
011A0000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
+ 00000250(592) services.exe
00050000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
+ 0000025c(604) lsass.exe
00CD0000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
+ 000002ec(748) alg.exe
00920000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
+ 000002f0(752) svchost.exe
00E90000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
+ 0000032c(812) svchost.exe
00B40000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
+ 0000038c(908) svchost.exe
00970000[00009000]
[ M] 40. c:\windows\system32\normaliz.dll
Microsoft Corporation
Unicode Normalization DLL
.text,.data,.rsrc,.reloc,
6E850000[00045000]
[ M] 41. c:\windows\system32\iertutil.dll
Microsoft Corporation
Run time utility for Internet Explorer
.text,.data,.rsrc,.reloc,
028E0000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
50E60000[0000C000]
[ M] 42. c:\windows\system32\wups2.dll
Microsoft Corporation
Windows Update client proxy stub 2
.text,.orpc,.data,.rsrc,.reloc,
+ 000003c4(964) svchost.exe
009A0000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
+ 0000040c(1036) svchost.exe
00800000[00009000]
[ M] 40. c:\windows\system32\normaliz.dll
Microsoft Corporation
Unicode Normalization DLL
.text,.data,.rsrc,.reloc,
6E850000[00045000]
[ M] 41. c:\windows\system32\iertutil.dll
Microsoft Corporation
Run time utility for Internet Explorer
.text,.data,.rsrc,.reloc,
01530000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
+ 00000514(1300) spoolsv.exe
00BA0000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
+ 000005ec(1516) Explorer.EXE
00400000[00009000]
[ M] 40. c:\windows\system32\normaliz.dll
Microsoft Corporation
Unicode Normalization DLL
.text,.data,.rsrc,.reloc,
6E850000[00045000]
[ M] 41. c:\windows\system32\iertutil.dll
Microsoft Corporation
Run time utility for Internet Explorer
.text,.data,.rsrc,.reloc,
10000000[00011000]
[AM] 29. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,
00EE0000[0001B000]
[AM] 26. c:\windows\system32\ravext.dll
Beijing Rising Technology Co., Ltd.
Rising Shell Ext Module
.text,.rdata,.data,.rsrc,.reloc,
7E1E0000[005CA000]
[AM] 22. c:\windows\system32\ieframe.dll
Microsoft Corporation
Internet Explorer
.text,.data,.rsrc,.reloc,
01B30000[0001B000]
[ M] 38. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
72C80000[00008000]
[ M] 39. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
019E0000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
+ 00000628(1576) RavStub.exe
00400000[00018000]
[ M] 43. d:\新建文件夹\rising\rav\ravstub.exe
Beijing Rising Technology Co., Ltd.
Rising RavStub
.text,.rdata,.data,.rsrc,
10000000[0001B000]
[ M] 44. d:\新建文件夹\rising\rav\rscommx.dll
rising
RsCommX
.text,.rdata,.data,.rsrc,.reloc,
23700000[0001A000]
[ M] 45. d:\新建文件夹\rising\rav\rscommon.dll
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00C30000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
+ 000006c4(1732) runiep.exe
00400000[00012000]
[AM] 31. c:\program files\rising\antispyware\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
00C00000[0001B000]
[ M] 38. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
00E30000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
+ 000006d8(1752) SOUNDMAN.EXE
00400000[0000D000]
[AM] 30. c:\windows\soundman.exe
Avance Logic, Inc.
Avance Sound Manager
.text,.rdata,.data,.rsrc,
72C80000[00008000]
[ M] 39. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
10000000[0001B000]
[ M] 38. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
01470000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
+ 0000070c(1804) RfwMain.exe
00400000[00073000]
[AM] 33. d:\新建文件夹\rising\rfw\rfwmain.exe
Beijing Rising Technology Co., Ltd.
Rising Personal FireWall Main Program
.text,.rdata,.data,.rsrc,
26600000[0007D000]
[ M] 46. d:\新建文件夹\rising\rfw\rsguilib.dll
Beijing Rising Technology Co., Ltd.
Rising GUI Library Loader
.text,.rdata,.data,.rsrc,.reloc,
23700000[0001A000]
[ M] 47. d:\新建文件夹\rising\rfw\rscommon.dll
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
10000000[0000F000]
[ M] 48. d:\新建文件夹\rising\rfw\rfwctrl.dll
Beijing Rising Technology Co., Ltd.
RfwCtrl DLL
.text,.rdata,.data,.rsrc,.reloc,
23800000[0001A000]
[ M] 49. d:\新建文件夹\rising\rfw\rsxml.dll
Beijing Rising Technology Co., Ltd.
RsXML
.text,.rdata,.data,.rsrc,.reloc,
23900000[00031000]
[ M] 50. d:\新建文件夹\rising\rfw\pngdll.dll
Beijing Rising Technology Co., Ltd.
Rising .Png File Loader Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
01320000[0001B000]
[ M] 38. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
01580000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,
+ 00000c38(3128) Ras.exe
00400000[0013F000]
[ M] 51. c:\program files\rising\antispyware\ras.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware
.text,.rdata,.data,.rsrc,
00380000[00009000]
[ M] 40. c:\windows\system32\normaliz.dll
Microsoft Corporation
Unicode Normalization DLL
.text,.data,.rsrc,.reloc,
6E850000[00045000]
[ M] 41. c:\windows\system32\iertutil.dll
Microsoft Corporation
Run time utility for Internet Explorer
.text,.data,.rsrc,.reloc,
10000000[000A3000]
[ M] 52. c:\program files\rising\antispyware\rasgui.dll
Beijing Rising Technology Co., Ltd.
RasGUI
.text,.rdata,.data,.rsrc,.reloc,
01900000[0001B000]
[ M] 38. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
7E1E0000[005CA000]
[AM] 22. c:\windows\system32\ieframe.dll
Microsoft Corporation
Internet Explorer
.text,.data,.rsrc,.reloc,
02400000[00012000]
[ M] 37. d:\内存\memorysaviour\clnmem.dll
UPX0,UPX1,.rsrc,