续:
019F0000[0000D000]
[AM] 66. c:\windows\system32\avwlgmn.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01A50000[0000C000]
[AM] 67. c:\windows\system32\rarjepi.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01A60000[0000C000]
[AM] 68. c:\windows\system32\kawdfzy.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01B30000[0000D000]
[AM] 69. c:\windows\system32\swjqbzc.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01B40000[0000C000]
[AM] 70. c:\windows\system32\wszjbzx.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01CE0000[00011000]
[AM] 45. c:\program files\internet explorer\plugins\wn_sys8x.sys
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
72C80000[00008000]
[ M] 90. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
017E0000[0000D000]
[AM] 47. c:\program files\internet explorer\iexplore32.sys
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
022D0000[0000E000]
[AM] 48. c:\program files\internet explorer\iexplore32.dat
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
02880000[0000D000]
[AM] 46. c:\program files\internet explorer\iexplore32.win
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
029D0000[0000B000]
[AM] 71. c:\windows\fonts\hookhelp.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
02A00000[0000D000]
[AM] 72. c:\windows\system32\wsmsezx.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
02A10000[0000C000]
[AM] 74. c:\windows\system32\rsmyipm.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
02A70000[0000C000]
[AM] 75. c:\windows\system32\ratbnpi.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
02B50000[0000D000]
[AM] 76. c:\windows\system32\sidjfzy.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
02C30000[0000C000]
[AM] 78. c:\windows\system32\kvdxjma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
02C80000[0000D000]
[AM] 79. c:\windows\system32\okmhbzy.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
02CD0000[0000C000]
[AM] 80. c:\windows\system32\swrcfzc.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
02D20000[0000D000]
[AM] 81. c:\windows\system32\kaqhlzy.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
10000000[0001B000]
[ M] 91. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
03910000[00011000]
[AM] 77. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,
03990000[0001B000]
[AM] 62. c:\windows\system32\ravext.dll
Beijing Rising Technology Co., Ltd.
Rising Shell Ext Module
.text,.rdata,.data,.rsrc,.reloc,
+ 000001f8(504) smss.exe
+ 00000268(616) csrss.exe
+ 00000288(648) winlogon.exe
004D0000[0000C000]
[AM] 73. c:\windows\system32\kvdxskma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
72C80000[00008000]
[ M] 90. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
+ 000002c0(704) services.exe
003C0000[0000C000]
[AM] 73. c:\windows\system32\kvdxskma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 000002cc(716) lsass.exe
003C0000[0000C000]
[AM] 73. c:\windows\system32\kvdxskma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 00000370(880) svchost.exe
003C0000[0000C000]
[AM] 73. c:\windows\system32\kvdxskma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 000003a8(936) svchost.exe
003C0000[0000C000]
[AM] 73. c:\windows\system32\kvdxskma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 00000408(1032) svchost.exe
003C0000[0000C000]
[AM] 73. c:\windows\system32\kvdxskma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
50E60000[0000C000]
[ M] 92. c:\windows\system32\wups2.dll
Microsoft Corporation
Windows Update client proxy stub 2
.text,.orpc,.data,.rsrc,.reloc,
+ 0000043c(1084) svchost.exe
003C0000[0000C000]
[AM] 73. c:\windows\system32\kvdxskma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 000004ec(1260) svchost.exe
003C0000[0000C000]
[AM] 73. c:\windows\system32\kvdxskma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 000004fc(1276) svchost.exe
00400000[00004000]
[AM] 1. c:\windows\system32\ime\svchost.exe
.text,.rdata,.data,
+ 00000578(1400) svchost.exe
003C0000[0000C000]
[AM] 73. c:\windows\system32\kvdxskma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 000005c4(1476) wdfmgr.exe
01000000[0000C000]
[AM] 6. c:\windows\system32\wdfmgr.exe
Microsoft Corporation
Windows User Mode Driver Manager
.text,.data,.rsrc,
00560000[0000C000]
[AM] 73. c:\windows\system32\kvdxskma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 00000684(1668) spoolsv.exe
003C0000[0000C000]
[AM] 73. c:\windows\system32\kvdxskma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
66D00000[0001A000]
[AM] 89. c:\windows\system32\cnmlm2i.dll
CANON INC.
BJ Language Monitor
.text,.data,.rsrc,.reloc,
00B50000[00006000]
[ M] 93. c:\windows\system32\spool\prtprocs\w32x86\cnmpd2i.dll
CANON INC.
Canon BJ Print Processor Dispatcher
.text,.data,.rsrc,.reloc,
+ 000007f4(2036) alg.exe
+ 00000898(2200) Ras.exe
00400000[00170000]
[ M] 94. c:\program files\rising\antispyware\ras.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware
.text,.rdata,.data,.rsrc,
780C0000[00061000]
[ M] 95. c:\program files\rising\antispyware\msvcp60.dll
Microsoft Corporation
Microsoft (R) C++ Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
10000000[00013000]
[ M] 96. c:\program files\rising\antispyware\topsoft.dll
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware TopSoft
.text,.rdata,.data,.rsrc,.reloc,
7C140000[00103000]
[ M] 97. c:\program files\rising\antispyware\mfc71.dll
Microsoft Corporation
MFCDLL Shared Library - Retail Version
.text,.data,.rsrc,.reloc,
7C340000[00056000]
[ M] 98. c:\program files\rising\antispyware\msvcr71.dll
Microsoft Corporation
Microsoft? C Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
7C3A0000[0007B000]
[ M] 99. c:\program files\rising\antispyware\msvcp71.dll
Microsoft Corporation
Microsoft? C++ Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
003D0000[0000C000]
[AM] 73. c:\windows\system32\kvdxskma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
00D70000[00011000]
[AM] 45. c:\program files\internet explorer\plugins\wn_sys8x.sys
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01020000[000BD000]
[ M] 100. c:\program files\rising\antispyware\rasgui.dll
Beijing Rising Technology Co., Ltd.
RasGUI
.text,.rdata,.data,.rsrc,.reloc,
015A0000[0000B000]
[AM] 71. c:\windows\fonts\hookhelp.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01870000[0001B000]
[ M] 91. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
018A0000[0000E000]
[AM] 48. c:\program files\internet explorer\iexplore32.dat
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
018D0000[0000D000]
[AM] 47. c:\program files\internet explorer\iexplore32.sys
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
018F0000[0000C000]
[AM] 63. c:\windows\system32\kapjezy.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01900000[0000D000]
[AM] 64. c:\windows\system32\avwghmn.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01740000[0000D000]
[AM] 65. c:\windows\system32\avzxkmn.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01750000[0000D000]
[AM] 66. c:\windows\system32\avwlgmn.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01760000[0000C000]
[AM] 67. c:\windows\system32\rarjepi.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01770000[0000C000]
[AM] 68. c:\windows\system32\kawdfzy.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01780000[0000D000]
[AM] 69. c:\windows\system32\swjqbzc.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01790000[0000C000]
[AM] 70. c:\windows\system32\wszjbzx.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
017A0000[0000D000]
[AM] 72. c:\windows\system32\wsmsezx.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
017B0000[0000C000]
[AM] 74. c:\windows\system32\rsmyipm.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
017C0000[0000C000]
[AM] 75. c:\windows\system32\ratbnpi.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
017D0000[0000D000]
[AM] 76. c:\windows\system32\sidjfzy.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
017E0000[0000C000]
[AM] 78. c:\windows\system32\kvdxjma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
017F0000[0000D000]
[AM] 79. c:\windows\system32\okmhbzy.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01800000[0000C000]
[AM] 80. c:\windows\system32\swrcfzc.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01810000[0000D000]
[AM] 81. c:\windows\system32\kaqhlzy.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
02F50000[00022000]
[AM] 52. c:\program files\netmeeting\msn2075.dll
msnlive Module
.text,.rdata,.data,.rsrc,.reloc,
+ 0000091c(2332) runiep.exe
00400000[00016000]
[AM] 82. c:\program files\rising\antispyware\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
00AC0000[00011000]
[AM] 45. c:\program files\internet explorer\plugins\wn_sys8x.sys
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
00B20000[0001B000]
[ M] 91. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
00B10000[0000C000]
[AM] 73. c:\windows\system32\kvdxskma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
00B50000[0000B000]
[AM] 71. c:\windows\fonts\hookhelp.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01090000[0000E000]
[AM] 48. c:\program files\internet explorer\iexplore32.dat
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
012A0000[0000D000]
[AM] 47. c:\program files\internet explorer\iexplore32.sys
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 00000934(2356) realsched.exe
00400000[0002F000]
[AM] 84. c:\program files\common files\real\update_ob\realsched.exe
RealNetworks, Inc.
RealNetworks Scheduler
.text,.rdata,.data,.rsrc,
003C0000[0000C000]
[AM] 73. c:\windows\system32\kvdxskma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
00B70000[00011000]
[AM] 45. c:\program files\internet explorer\plugins\wn_sys8x.sys
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
011E0000[0000B000]
[AM] 71. c:\windows\fonts\hookhelp.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
10000000[0001B000]
[ M] 91. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
01210000[0000E000]
[AM] 48. c:\program files\internet explorer\iexplore32.dat
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01220000[0000D000]
[AM] 47. c:\program files\internet explorer\iexplore32.sys
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 0000098c(2444) ctfmon.exe
003D0000[0000C000]
[AM] 73. c:\windows\system32\kvdxskma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
00A30000[00011000]
[AM] 45. c:\program files\internet explorer\plugins\wn_sys8x.sys
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
00BB0000[0000B000]
[AM] 71. c:\windows\fonts\hookhelp.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
10000000[0001B000]
[ M] 91. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
00C60000[0000E000]
[AM] 48. c:\program files\internet explorer\iexplore32.dat
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
00E80000[0000D000]
[AM] 47. c:\program files\internet explorer\iexplore32.sys
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
+ 00000dc4(3524) IEXPLORE.EXE
003D0000[0000C000]
[AM] 73. c:\windows\system32\kvdxskma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
00BD0000[00011000]
[AM] 45. c:\program files\internet explorer\plugins\wn_sys8x.sys
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
10000000[0002A000]
[AM] 41. c:\program files\thunder network\webthunder\webthunderbho_now.dll
Thunder Networking Technologies,LTD
XunLeiBHO
.text,.rdata,.data,.rsrc,.reloc,
01270000[00011000]
[AM] 42. c:\program files\flashget\jccatch.dll
www.flashget.com
Flashget CatchUrl Module
.text,.rdata,.data,.rsrc,.reloc,
01290000[0005F000]
[AM] 43. c:\program files\bitcomet\tools\bitcometbho.dll
.text,.rdata,.data,.rsrc,.reloc,
01AC0000[0001D000]
[AM] 44. c:\program files\thunder network\thunder\comdlls\xunleibho_007.dll
Thunder Networking Technologies,LTD
XunLeiBHO
.text,.rdata,.data,.rsrc,.reloc,
01AF0000[0000D000]
[AM] 46. c:\program files\internet explorer\iexplore32.win
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01C30000[0000D000]
[AM] 47. c:\program files\internet explorer\iexplore32.sys
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01D40000[0000E000]
[AM] 48. c:\program files\internet explorer\iexplore32.dat
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
01E50000[00021000]
[AM] 49. c:\program files\flashget\getflash.dll
www.flashget.com
Flashget GetFlash Module
.text,.rdata,.data,.rsrc,.reloc,
028C0000[00022000]
[AM] 52. c:\program files\netmeeting\msn2075.dll
msnlive Module
.text,.rdata,.data,.rsrc,.reloc,
02D40000[0000B000]
[AM] 71. c:\windows\fonts\hookhelp.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
02E50000[0001B000]
[ M] 91. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
325C0000[00012000]
[AM] 60. c:\program files\microsoft office\office11\msohev.dll
Microsoft Corporation
Microsoft Office 2003 component
.text,.data,.rsrc,.reloc,
02FC0000[0000D000]
[AM] 81. c:\windows\system32\kaqhlzy.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
030D0000[0000C000]
[AM] 80. c:\windows\system32\swrcfzc.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
031E0000[0000D000]
[AM] 79. c:\windows\system32\okmhbzy.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
032F0000[0000C000]
[AM] 78. c:\windows\system32\kvdxjma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
03400000[0000D000]
[AM] 76. c:\windows\system32\sidjfzy.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
03510000[0000C000]
[AM] 75. c:\windows\system32\ratbnpi.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
03620000[0000C000]
[AM] 74. c:\windows\system32\rsmyipm.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
03730000[0000D000]
[AM] 72. c:\windows\system32\wsmsezx.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
03840000[0000C000]
[AM] 70. c:\windows\system32\wszjbzx.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
03950000[0000D000]
[AM] 69. c:\windows\system32\swjqbzc.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
03A60000[0000C000]
[AM] 68. c:\windows\system32\kawdfzy.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
03B70000[0000C000]
[AM] 67. c:\windows\system32\rarjepi.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
03C80000[0000D000]
[AM] 66. c:\windows\system32\avwlgmn.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
03D90000[0000D000]
[AM] 65. c:\windows\system32\avzxkmn.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
03EA0000[0000D000]
[AM] 64. c:\windows\system32\avwghmn.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
03FB0000[0000C000]
[AM] 63. c:\windows\system32\kapjezy.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
72C80000[00008000]
[ M] 90. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
049C0000[00019000]
[ M] 101. c:\program files\rising\rav\ravscrch.dll
Beijing Rising Technology Co., Ltd.
RavScrCh Module
.text,.rdata,.data,.rsrc,.reloc,
30000000[002EE000]
[ M] 102. c:\windows\system32\macromed\flash\flash9b.ocx
Adobe Systems, Inc.
Adobe Flash Player 9.0 r28
.text,.rdata,.data,.rsrc,.reloc,
07B80000[00035000]
[ M] 103. c:\windows\system32\xpsp3res.dll
Microsoft Corporation
Service Pack 3 Messages
.rsrc,
+ 00000f50(3920) wuauclt.exe
003D0000[0000C000]
[AM] 73. c:\windows\system32\kvdxskma.dll
CODE,DATA,BSS,.idata,.edata,.reloc,.rsrc,
50E60000[0000C000]
[ M] 92. c:\windows\system32\wups2.dll
Microsoft Corporation
Windows Update client proxy stub 2
.text,.orpc,.data,.rsrc,.reloc, |