系统活动进程
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\PROGRAM FILES\LENOVO\联想键盘驱动\KBDRIVER.EXE
C:\PROGRAM FILES\LENOVO\联想键盘驱动\TGEKB.DLL
C:\PROGRAM FILES\LENOVO\联想键盘驱动\LXKEYLED.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\PROGRAM FILES\LENOVO\REMOTECONTROLCENTER\CONTROLCENTER.EXE
C:\PROGRAM FILES\LENOVO\REMOTECONTROLCENTER\SK_OSD.DLL
C:\PROGRAM FILES\LENOVO\REMOTECONTROLCENTER\VOLUMEOSD.DLL
C:\PROGRAM FILES\LENOVO\REMOTECONTROLCENTER\SCROSD32.DLL
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\PROGRAM FILES\联想(北京)有限公司\幸福飞梭\SHUTTLE.EXE
C:\PROGRAM FILES\联想(北京)有限公司\幸福飞梭\SK_OSD.DLL
C:\PROGRAM FILES\联想(北京)有限公司\幸福飞梭\VOLUMEOSD.DLL
C:\PROGRAM FILES\联想(北京)有限公司\幸福飞梭\SCROSD32.DLL
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\PROGRAM FILES\NEWREMOTECONTROL\NEWRMTSERVICE.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\COMMON FILES\LENOVO\HAPPYHOME\COMMONDLL\MYDEVICE.EXE
C:\PROGRAM FILES\COMMON FILES\LENOVO\HAPPYHOME\COMMONDLL\BURN.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WUPS.DLL
C:\WINDOWS\SYSTEM32\WUPS2.DLL
C:\PROGRAM FILES\LENOVO\TIMERSERVICE\TIMERCLIENT.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEP_CTRL.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RISING\RAV\RAVMOND.EXE
C:\PROGRAM FILES\RISING\RAV\BWLIST.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL
C:\PROGRAM FILES\RISING\RAV\RFWCTRL.DLL
C:\PROGRAM FILES\RISING\RAV\RSPPSYS.DLL
C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RAV\RSLOG.DLL
C:\PROGRAM FILES\RISING\RAV\HOOKSYS.DLL
C:\PROGRAM FILES\RISING\RAV\SCANNER.DLL
C:\PROGRAM FILES\RISING\RAV\LIBLOAD.DLL
C:\PROGRAM FILES\RISING\RAV\VIRUSLIB.DLL
C:\PROGRAM FILES\RISING\RAV\REGMON.DLL
C:\PROGRAM FILES\RISING\RAV\PSAPI.DLL
C:\PROGRAM FILES\RISING\RAV\HOOKWEB.DLL
C:\PROGRAM FILES\RISING\RAV\MEMMON.DLL
C:\PROGRAM FILES\RISING\RAV\EXPSCAN.DLL
C:\PROGRAM FILES\RISING\RAV\MPORTS.DLL
C:\PROGRAM FILES\RISING\RAV\HOOKCONT.DLL
C:\PROGRAM FILES\RISING\RAV\SPAMENG.DLL
C:\PROGRAM FILES\RISING\RAV\ENGINE.DLL
C:\PROGRAM FILES\RISING\RAV\POSTTRT.DLL
C:\PROGRAM FILES\RISING\RAV\UNEXE.DLL
C:\PROGRAM FILES\RISING\RAV\SCANEXEC.DLL
C:\PROGRAM FILES\RISING\RAV\SCANEX.DLL
C:\PROGRAM FILES\RISING\RAV\EXTFILE.DLL
C:\PROGRAM FILES\RISING\RAV\NVFILE.DLL
C:\PROGRAM FILES\RISING\RAV\SCANMAC.DLL
C:\PROGRAM FILES\RISING\RAV\SCANSCT.DLL
C:\PROGRAM FILES\RISING\RAV\UNPACKER.DLL
C:\PROGRAM FILES\RISING\RAV\SCANPACK.DLL
C:\PROGRAM FILES\RISING\RAV\RSVM.DLL
C:\PROGRAM FILES\RISING\RAV\UROUTINE.DLL
C:\PROGRAM FILES\RISING\RAV\EXTOLE.DLL
C:\PROGRAM FILES\RISING\RAV\SCANNET.DLL
C:\PROGRAM FILES\RISING\RFW\RFWSRV.EXE
C:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL
C:\PROGRAM FILES\RISING\RFW\RFWLOG.DLL
C:\PROGRAM FILES\RISING\RFW\RFWDRV.DLL
C:\PROGRAM FILES\RISING\RFW\PSAPI.DLL
C:\PROGRAM FILES\RISING\RFW\MONDRV.DLL
C:\PROGRAM FILES\RISING\RFW\PROCLIB.DLL
C:\PROGRAM FILES\RISING\RFW\MPORTS.DLL
C:\PROGRAM FILES\RISING\RAV\RAVMON.EXE
C:\PROGRAM FILES\RISING\RAV\RSGUILIB.DLL
C:\PROGRAM FILES\RISING\RAV\BWLIST.DLL
C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL
C:\PROGRAM FILES\RISING\RAV\RSXML.DLL
C:\PROGRAM FILES\RISING\RAV\PNGDLL.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\SYSTEM32\NVMCTRAY.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\PROGRAM FILES\RISING\RAV\RAVSTUB.EXE
C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL
C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\PROGRAM FILES\LENOVO\TIMERSERVICE\LENOVOTIMER.EXE
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE
C:\PROGRAM FILES\RISING\RFW\RSGUILIB.DLL
C:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL
C:\PROGRAM FILES\RISING\RFW\RFWCTRL.DLL
C:\PROGRAM FILES\RISING\RFW\RSXML.DLL
C:\PROGRAM FILES\RISING\RFW\PNGDLL.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
D:\Q\QQ.EXE
D:\Q\QQBASECLASSINDLL.DLL
D:\Q\QQHELPERDLL.DLL
D:\Q\BASICCTRLDLL.DLL
D:\Q\MFC42.DLL
D:\Q\RICHED32.DLL
D:\Q\RICHED20.DLL
D:\Q\QQAPI.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
D:\Q\TIMPROXY.DLL
D:\Q\LOGINCTRL.DLL
D:\Q\NPKCNTC.DLL
D:\Q\NPKPDB.DLL
D:\Q\QQRES.DLL
D:\Q\WIZARDCTRL.DLL
D:\Q\QQMAINFRAME.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9.OCX
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\Q\CQQAPPLICATION.DLL
D:\Q\NEWSKIN.DLL
D:\Q\HOSTINGMGR.DLL
D:\Q\CAMERADLL.DLL
D:\Q\MAILSUMMARY.DLL
D:\Q\QQKNOWLEDGESEARCH.DLL
D:\Q\QQALLINONE.DLL
D:\Q\GROUPLIVE.DLL
D:\Q\SCCORE.DLL
D:\Q\GDIPLUS.DLL
D:\Q\QQSPACE.DLL
D:\Q\VBSCRIPT.DLL
D:\Q\QQGROUPMNG.DLL
D:\Q\LONGCONNECTION.DLL
D:\Q\QQPLUGIN.DLL
D:\Q\USERDEFINEDHEAD.DLL
D:\Q\QQCONFIGPLUGIN.DLL
D:\Q\QQCUSTOMFACE.DLL
D:\Q\QRINGMNG.DLL
D:\Q\QQPET.DLL
D:\Q\QQAVATAR.DLL
D:\Q\FLASHAVATARDLL.DLL
D:\Q\PHONEAPI.DLL
D:\Q\DIALERALLINONE.DLL
D:\Q\QQSYSMSGMNG.DLL
D:\Q\QQFILETRANSFER.DLL
D:\Q\BQQAPPLICATION.DLL
D:\Q\GROUPCONNECTION.DLL
D:\Q\COMMERCESMNG.DLL
D:\Q\PERSONALDESKTOP.DLL
D:\Q\QQADDR.DLL
D:\Q\QQONECLICK.DLL
D:\Q\QQSCENEMNG.DLL
D:\Q\QQPHONEHELPER.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
D:\Q\TIMPLATFORM.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
D:\Q\TIMPROXY.DLL
D:\Q\TTRAVELER.EXE
D:\Q\PLUGINS\TWEATHER\TWEATHER.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
D:\Q\PERSONALDESKTOP.DLL
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9.OCX
C:\WINDOWS\SYSTEM32\WUAUCLT.EXE
C:\WINDOWS\SYSTEM32\WUAUCPL.CPL
C:\WINDOWS\SYSTEM32\WUPS.DLL
C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
C:\DOCUMENTS AND SETTINGS\LX\桌面\RSDETECT.EXE
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
C:\WINDOWS\SYSTEM32\WUAUCLT.EXE
C:\WINDOWS\SYSTEM32\WUAUCPL.CPL
C:\WINDOWS\SYSTEM32\WUPS.DLL
C:\WINDOWS\SYSTEM32\WUPS2.DLL
C:\WINDOWS\SYSTEM32\MUCLTUI.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\IEPROT.DLL
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE" /SPOIL /REMADVDEF /MIGRATION32
PHIME2002ASync = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME
SoundMan = SOUNDMAN.EXE
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\SYSTEM32\NVCPL.DLL,NVSTARTUP
nwiz = NWIZ.EXE /INSTALL
Lskbdrv = C:\PROGRAM FILES\LENOVO\联想键盘驱动\KBDRIVER.EXE
Shuttle.exe = C:\PROGRAM FILES\联想(北京)有限公司\幸福飞梭\SHUTTLE.EXE
ControlCenter.exe = "C:\PROGRAM FILES\LENOVO\REMOTECONTROLCENTER\CONTROLCENTER.EXE"
NewRmtService = C:\PROGRAM FILES\NEWREMOTECONTROL\NEWRMTSERVICE.EXE
MyDevice.exe = "C:\PROGRAM FILES\COMMON FILES\LENOVO\HAPPYHOME\COMMONDLL\MYDEVICE.EXE"
TimerClient.exe = "C:\PROGRAM FILES\LENOVO\TIMERSERVICE\TIMERCLIENT.EXE"
TkBellExe = "C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE" -OSBOOT
runeip = C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE
RfwMain = "C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE" -STARTUP
RavTask = "C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
mss3 = C:\WINDOWS\MSS3.EXE
wgs3 = C:\WINDOWS\WGS3.EXE
wms3 = C:\WINDOWS\WMS3.EXE
rxs3 = C:\WINDOWS\RXS3.EXE
mhs3 = C:\WINDOWS\MHS3.EXE
wls3 = C:\WINDOWS\WLS3.EXE
mys3 = C:\WINDOWS\MYS3.EXE
jts3 = C:\WINDOWS\JTS3.EXE
zts3 = C:\WINDOWS\ZTS3.EXE
wos3 = C:\WINDOWS\WOS3.EXE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\SYSTEM32\NVMCTRAY.DLL,NVTASKBARINIT
AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =