sleeppiggy - 2007-7-12 20:27:00
神之子85 - 2007-7-12 20:46:00
用卡卡结束病毒进程,在删去,可能会行.
最好把日志放上来,这样看是很难做的
sleeppiggy - 2007-7-12 21:10:00
星卡卡电脑诊断日志 v1.20 (2007-7-12 20:54:15) 北京瑞星科技股份有限公司
注释:[A]表示该文件存在自启动关联;
[M]表示该文件在内存中;
+ 注册表自运行项目
+ Win32 Services
+ HKLM\System\CurrentControlSet\Services
82485F4E
[A ] 1. c:\windows\system32\d81e5dba.exe
IDriverT
[A ] 2. c:\program files\common files\installshield\driver\11\intel 32\idrivert.exe
iPodService
[AM] 3. c:\program files\ipod\bin\ipodservice.exe
ose
[A ] 4. c:\program files\common files\microsoft shared\source engine\ose.exe
P4P Service
[AM] 5. c:\program files\common files\sogou pxp\p2psvr.exe
RfwProxySrv
[A ] 6. c:\program files\rising\rfw\rfwproxy.exe
RfwService
[A ] 7. c:\program files\rising\rfw\rfwsrv.exe
RsCCenter
[A ] 8. c:\program files\rising\rav\ccenter.exe
RsRavMon
[A ] 9. c:\program files\rising\rav\ravmond.exe
ServiceLayer
[AM] 10. c:\program files\common files\pcsuite\services\servicelayer.exe
usnjsvc
[A ] 11. c:\program files\msn messenger\usnsvc.exe
+ Kernel Drivers
+ HKLM\System\CurrentControlSet\Services
BaseTDI
[A ] 12. c:\windows\system32\drivers\basetdi.sys
EagleNT
[A ] 13. c:\windows\system32\drivers\eaglent.sys
ExpScaner
[A ] 14. c:\program files\rising\rav\expscan.sys
GEARAspiWDM
[A ] 15. c:\windows\system32\drivers\gearaspiwdm.sys
GMSIPCI
[A ] 16. g:\install\gmsipci.sys
HOOKAPI
[A ] 17. c:\program files\rising\rav\hookapi.sys
HookCont
[A ] 18. c:\program files\rising\rav\hookcont.sys
HookReg
[A ] 19. c:\program files\rising\rav\hookreg.sys
HookSys
[A ] 20. c:\program files\rising\rav\hooksys.sys
HookUrl
[A ] 21. c:\program files\rising\rfw\hookurl.sys
kikhlfsd
[A ] 22. c:\windows\system32\drivers\kikhlfsd.sys
kmsinput
[A ] 23. c:\windows\system32\drivers\kmsinput.sys
MEMSCAN
[A ] 24. c:\program files\rising\rav\memscan.sys
mProcRs
[A ] 25. c:\program files\rising\rfw\mprocrs.sys
Nokia USB Generic
[A ] 26. c:\windows\system32\drivers\nmwcdc.sys
Nokia USB Modem
[A ] 27. c:\windows\system32\drivers\nmwcdcm.sys
Nokia USB Phone Parent
[A ] 28. c:\windows\system32\drivers\nmwcd.sys
Nokia USB Port
[A ] 29. c:\windows\system32\drivers\nmwcdcj.sys
NPF
[A ] 30. c:\windows\system32\drivers\npf.sys
npkcrypt
[A ] 31. d:\游戏\qq2005\npkcrypt.sys
npkycryp
[A ] 32. d:\游戏\qq2005\npkycryp.sys
prodrv06
[A ] 33. c:\windows\system32\drivers\prodrv06.sys
prohlp02
[A ] 34. c:\windows\system32\drivers\prohlp02.sys
prosync1
[A ] 35. c:\windows\system32\drivers\prosync1.sys
RsAntiSpyware
[A ] 36. c:\windows\system32\drivers\rsboot.sys
RsFwDrv
[A ] 37. c:\program files\rising\rfw\rsfwdrv.sys
RsNTGDI
[A ] 38. c:\windows\system32\drivers\rsntgdi.sys
RSPPSYS
[A ] 39. c:\program files\rising\rav\rsppsys.sys
Secdrv
[A ] 40. c:\windows\system32\drivers\secdrv.sys
sfdrv01
[A ] 41. c:\windows\system32\drivers\sfdrv01.sys
sfhlp01
[A ] 42. c:\windows\system32\drivers\sfhlp01.sys
sfhlp02
[A ] 43. c:\windows\system32\drivers\sfhlp02.sys
sfsync02
[A ] 44. c:\windows\system32\drivers\sfsync02.sys
sfsync04
[A ] 45. c:\windows\system32\drivers\sfsync04.sys
ssm_bus
[A ] 46. c:\windows\system32\drivers\ssm_bus.sys
ssm_mdfl
[A ] 47. c:\windows\system32\drivers\ssm_mdfl.sys
ssm_mdm
[A ] 48. c:\windows\system32\drivers\ssm_mdm.sys
viaagp1
[A ] 49. c:\windows\system32\drivers\viaagp1.sys
VIAudio
[A ] 50. c:\windows\system32\drivers\vinyl97.sys
+ File System Drivers
+ HKLM\System\CurrentControlSet\Services
ADProt
[A ] 51. c:\windows\system32\drivers\adprot.sys
+ Winlogon
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
WgaLogon
[AM] 52. c:\windows\system32\wgalogon.dll
+ HKCU\Control Panel\Desktop
Scrnsave.exe
[A ] 53. c:\windows\fish.scr
+ Internet Explorer
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{BA440AED-8A58-46A3-B8E5-6AEE4D03A7D8}
[A ] 54. d:\软件\biget\bntoolbar.dll
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C}
[A ] 55. c:\windows\system32\kakatool.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
[AM] 56. c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}
[AM] 57. c:\program files\flashget\jccatch.dll
{9394EDE7-C8B5-483E-8773-474BF36AF6E4}
[AM] 58. c:\program files\msn apps\st\01.02.3000.1001\en-xu\stmain.dll
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
[AM] 59. c:\program files\msn apps\msn toolbar\01.02.5000.1021\zh-cn\msntb.dll
{F156768E-81EF-470C-9057-481BA8380DBA}
[AM] 60. c:\program files\flashget\getflash.dll
+ HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions
Exec
[A ] 61. c:\program files\thunder network\thunder\thunder.exe
Exec
[A ] 62. d:\游戏\浩方对战平台\gameclient.exe
Exec
[A ] 63. c:\program files\herosoft\hero 9\sthsdvd.exe
Exec
[A ] 64. d:\游戏\qq2005\qq.exe
Exec
[A ] 65. c:\program files\flashget\flashget.exe
Exec
[A ] 66. c:\program files\messenger\msmsgs.exe
+ Explorer
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Filter
text/xml
[AM] 67. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
+ HKLM\SOFTWARE\Classes\PROTOCOLS\Handler
livecall
[A ] 68. c:\program files\msn messenger\msgrapp.8.1.0178.00.dll
msnim
[A ] 68. c:\program files\msn messenger\msgrapp.8.1.0178.00.dll
mso-offdap
[A ] 69. c:\program files\common files\microsoft shared\web components\10\owc10.dll
mso-offdap11
[A ] 70. c:\program files\common files\microsoft shared\web components\11\owc11.dll
+ HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
{81716107-A10D-11cf-64CD-11115FE1CF41}
[A ] 71. c:\windows\system32\nwizzhuxians.exe
+ HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers
{F9DB5320-233E-11D1-9F84-707F02C10627}
[AM] 72. c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HyperTerminal Icon Ext
[A ] 73. c:\windows\system32\hticons.dll
Web Folders
[A ] 74. c:\program files\common files\microsoft shared\web folders\msonsext.dll
Microsoft Office Outlook Desktop Icon Handler
[A ] 75. d:\软件\office2000\office11\mlshext.dll
Microsoft Office Outlook Custom Icon Handler
[A ] 76. d:\软件\office2000\office11\olkfstub.dll
Microsoft Office HTML Icon Handler
[AM] 77. d:\软件\office2000\office11\msohev.dll
RISING
[AM] 78. c:\windows\system32\ravext.dll
百纳搜索
[A ] 54. d:\软件\biget\bntoolbar.dll
WinRAR shell extension
[AM] 79. d:\软件\winrar\rarext.dll
iTunes
[A ] 80. c:\program files\itunes\itunesminiplayer.dll
Messenger Sharing Folders
[A ] 81. c:\program files\msn messenger\fsshext.8.1.0178.00.dll
PhoneBrowser
[AM] 82. c:\program files\nokia\nokia pc suite 6\phonebrowser.dll
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{32CD708B-60A7-4C00-9377-D73EAA495F0F}
[AM] 78. c:\windows\system32\ravext.dll
{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 83. c:\windows\system32\shlhook.dll
+ Logon
+ HKCU\Software\Microsoft\Windows\CurrentVersion\Run
MsnMsgr
[A ] 84. c:\program files\msn messenger\msnmsgr.exe
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
RfwMain
[AM] 85. c:\program files\rising\rfw\rfwmain.exe
TkBellExe
[A ] 86. c:\program files\common files\real\update_ob\realsched.exe
IMSCMig
[A ] 87. c:\program files\common files\microsoft shared\ime\imsc40a\imscmig.exe
RavTask
[A ] 88. c:\program files\rising\rav\ravtask.exe
iTunesHelper
[AM] 89. c:\program files\itunes\ituneshelper.exe
runeip
[A ] 90. c:\program files\rising\antispyware\runiep.exe
miniqqlive
[A ] 91. c:\program files\tencent\qqlive\miniqqlive.exe
cmdbcs
[A ] 92. c:\windows\cmdbcs.exe
+ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
RavStub
[AM] 93. c:\program files\rising\rav\ravstub.exe
KKDelay
[A ] 94. c:\program files\rising\antispyware\runonce.exe
+ Boot Execute
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 95. c:\windows\system32\bsmain.exe
[A ] 96. c:\windows\system32\kknative.exe
+ Image Hijacks
+ HKCR\.html
htmlfile\Edit\Command
[A ] 97. d:\软件\office2000\office11\msohtmed.exe
htmlfile\open\Command
[AM] 98. d:\游戏\tt\ttraveler.exe
htmlfile\Print\Command
[A ] 97. d:\软件\office2000\office11\msohtmed.exe
htmlfile\TencentTraveler\Command
[AM] 98. d:\游戏\tt\ttraveler.exe
+ HKCR\.htm
htmlfile\Edit\Command
[A ] 97. d:\软件\office2000\office11\msohtmed.exe
htmlfile\open\Command
[AM] 98. d:\游戏\tt\ttraveler.exe
htmlfile\Print\Command
[A ] 97. d:\软件\office2000\office11\msohtmed.exe
htmlfile\TencentTraveler\Command
[AM] 98. d:\游戏\tt\ttraveler.exe
+ HKCR\.mp3
Winamp.File\Enqueue\Command
[A ] 99. c:\program files\winamp\winamp.exe
Winamp.File\ListBookmark\Command
[A ] 99. c:\program files\winamp\winamp.exe
Winamp.File\open\Command
[A ] 99. c:\program files\winamp\winamp.exe
Winamp.File\Play\Command
[A ] 99. c:\program files\winamp\winamp.exe
+ Print Monitor
+ HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
Microsoft Document Imaging Writer Monitor
[AM] 100. c:\windows\system32\mdimon.dll
sleeppiggy - 2007-7-12 21:11:00
+ 其他自启动项目
+ C:\Documents and Settings\xt\「开始」菜单\程序\启动
腾讯QQ.lnk
[A ] 64. d:\游戏\qq2005\qq.exe
+ C:\Documents and Settings\All Users\「开始」菜单\程序\启动
Adobe Reader Speed Launch.lnk
[A ] 101. c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
+ c:\autorun.inf
open
[A ] 102. c:\auto.exe
shellexecute
[A ] 102. c:\auto.exe
shell\Auto\command
[A ] 102. c:\auto.exe
+ d:\autorun.inf
open
[A ] 103. d:\auto.exe
shellexecute
[A ] 103. d:\auto.exe
shell\Auto\command
[A ] 103. d:\auto.exe
+ e:\autorun.inf
open
[A ] 104. e:\auto.exe
shellexecute
[A ] 104. e:\auto.exe
shell\Auto\command
[A ] 104. e:\auto.exe
+ f:\autorun.inf
open
[A ] 105. f:\auto.exe
shellexecute
[A ] 105. f:\auto.exe
shell\Auto\command
[A ] 105. f:\auto.exe
newcenturymoon - 2007-7-12 21:12:00
下载 System Repair Engineer,
http://download.kztechs.com/files/sreng2.zip
1 解压缩sreng2.zip
2 运行SREngPS.EXE
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
sleeppiggy - 2007-7-12 21:12:00
+ 系统活动模块
+ 000000a0(160) spoolsv.exe
10000000[00012000]
[ M] 106. c:\windows\system32\1fa1892.dll
00B00000[00008000]
[AM] 100. c:\windows\system32\mdimon.dll
00B10000[00008000]
[ M] 107. c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
00C30000[00005000]
[ M] 108. c:\windows\system32\spool\prtprocs\w32x86\vprproc.dll
+ 000000fc(252) ctfmon.exe
10000000[0001B000]
[ M] 109. c:\program files\rising\antispyware\ieprot.dll
+ 00000170(368) RfwMain.exe
00400000[00073000]
[AM] 85. c:\program files\rising\rfw\rfwmain.exe
26600000[0007D000]
[ M] 110. c:\program files\rising\rfw\rsguilib.dll
23700000[0001A000]
[ M] 111. c:\program files\rising\rfw\rscommon.dll
10000000[0000F000]
[ M] 112. c:\program files\rising\rfw\rfwctrl.dll
23800000[0001A000]
[ M] 113. c:\program files\rising\rfw\rsxml.dll
23900000[00031000]
[ M] 114. c:\program files\rising\rfw\pngdll.dll
01020000[00012000]
[ M] 106. c:\windows\system32\1fa1892.dll
00FE0000[0001B000]
[ M] 109. c:\program files\rising\antispyware\ieprot.dll
+ 000001dc(476) svchost.exe
+ 00000264(612) iTunesHelper.exe
00400000[00045000]
[AM] 89. c:\program files\itunes\ituneshelper.exe
10000000[0000C000]
[ M] 115. c:\program files\itunes\ituneshelper.resources\zh_cn.lproj\ituneshelperlocalized.dll
00A30000[0000B000]
[ M] 116. c:\program files\itunes\ituneshelper.resources\ituneshelper.dll
00EC0000[0001B000]
[ M] 109. c:\program files\rising\antispyware\ieprot.dll
00F60000[00012000]
[ M] 106. c:\windows\system32\1fa1892.dll
+ 000002c8(712) smss.exe
+ 00000324(804) csrss.exe
10000000[00012000]
[ M] 106. c:\windows\system32\1fa1892.dll
+ 0000033c(828) winlogon.exe
01300000[0003B000]
[AM] 52. c:\windows\system32\wgalogon.dll
72C80000[00008000]
[ M] 117. c:\windows\system32\msacm32.drv
10000000[00012000]
[ M] 106. c:\windows\system32\1fa1892.dll
+ 00000368(872) services.exe
10000000[00012000]
[ M] 106. c:\windows\system32\1fa1892.dll
+ 00000374(884) lsass.exe
10000000[00012000]
[ M] 106. c:\windows\system32\1fa1892.dll
+ 000003b8(952) p2psvr.exe
00400000[00016000]
[AM] 5. c:\program files\common files\sogou pxp\p2psvr.exe
10000000[00012000]
[ M] 106. c:\windows\system32\1fa1892.dll
00D70000[00062000]
[ M] 118. c:\program files\sogou pxp\vodsvr.dll
65100000[00029000]
[ M] 119. c:\program files\sogou pxp\pxpnet.dll
00810000[00040000]
[ M] 120. c:\program files\sogou pxp\p2pclient.dll
+ 00000410(1040) svchost.exe
10000000[00012000]
[ M] 106. c:\windows\system32\1fa1892.dll
+ 00000450(1104) svchost.exe
10000000[00012000]
[ M] 106. c:\windows\system32\1fa1892.dll
+ 000004d8(1240) svchost.exe
10000000[00012000]
[ M] 106. c:\windows\system32\1fa1892.dll
+ 00000504(1284) svchost.exe
10000000[00012000]
[ M] 106. c:\windows\system32\1fa1892.dll
+ 00000588(1416) svchost.exe
10000000[00012000]
[ M] 106. c:\windows\system32\1fa1892.dll
+ 000006e4(1764) Explorer.EXE
10000000[0001B000]
[AM] 78. c:\windows\system32\ravext.dll
00BD0000[00011000]
[AM] 83. c:\windows\system32\shlhook.dll
013B0000[0001B000]
[ M] 109. c:\program files\rising\antispyware\ieprot.dll
01470000[00012000]
[ M] 106. c:\windows\system32\1fa1892.dll
00B30000[00006000]
[ M] 121. c:\windows\system32\nwizwlwzs.dll
01810000[00005000]
[ M] 122. c:\windows\system32\mosou.dll
72C80000[00008000]
[ M] 117. c:\windows\system32\msacm32.drv
15000000[00010000]
[ M] 123. c:\windows\system32\k11842382474.dat
01D00000[00007000]
[ M] 124. c:\windows\system32\nwizqjsj.dll
00FD0000[00006000]
[ M] 125. c:\windows\system32\nwizzhuxians.dll
02150000[00007000]
[ M] 126. c:\windows\system32\msimms32.dll
02170000[0001C000]
[AM] 72. c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll
23700000[0001A000]
[ M] 127. c:\program files\rising\rav\rscommon.dll
7C340000[00056000]
[ M] 128. c:\windows\system32\msvcr71.dll
041D0000[0002B000]
[AM] 79. d:\软件\winrar\rarext.dll
04A50000[00085000]
[AM] 82. c:\program files\nokia\nokia pc suite 6\phonebrowser.dll
04AE0000[0008C000]
[ M] 129. c:\program files\nokia\nokia pc suite 6\pcscm.dll
046E0000[0003F000]
[ M] 130. c:\windows\system32\connapi.dll
7C3A0000[0007B000]
[ M] 131. c:\windows\system32\msvcp71.dll
033D0000[00008000]
[ M] 132. c:\program files\nokia\nokia pc suite 6\lang\phonebrowser_chi-sc.nlr
04C70000[0008B000]
[ M] 133. c:\program files\nokia\nokia pc suite 6\resource\phonebrowser_nokia.ngr
035F0000[00010000]
[ M] 134. c:\windows\system32\k11842418664.dat
01F70000[00008000]
[ M] 135. c:\windows\system32\cmdbcs.dll
+ 00000798(1944) RavStub.exe
00400000[00018000]
[AM] 93. c:\program files\rising\rav\ravstub.exe
10000000[0001B000]
[ M] 136. c:\program files\rising\rav\rscommx.dll
23700000[0001A000]
[ M] 127. c:\program files\rising\rav\rscommon.dll
00B70000[00012000]
[ M] 106. c:\windows\system32\1fa1892.dll
+ 00000844(2116) iexplore.exe
15000000[00010000]
[ M] 123. c:\windows\system32\k11842382474.dat
10000000[00005000]
[ M] 122. c:\windows\system32\mosou.dll
01A70000[0000E000]
[AM] 56. c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
7C340000[00056000]
[ M] 128. c:\windows\system32\msvcr71.dll
01A90000[00011000]
[AM] 57. c:\program files\flashget\jccatch.dll
01AB0000[00028000]
[AM] 58. c:\program files\msn apps\st\01.02.3000.1001\en-xu\stmain.dll
02020000[00049000]
[AM] 59. c:\program files\msn apps\msn toolbar\01.02.5000.1021\zh-cn\msntb.dll
02070000[00043000]
[ M] 137. c:\program files\msn apps\msn toolbar\01.02.5000.1021\zh-cn\mtbres.dll
020C0000[00029000]
[AM] 60. c:\program files\flashget\getflash.dll
02940000[0001B000]
[ M] 109. c:\program files\rising\antispyware\ieprot.dll
325C0000[00012000]
[AM] 77. d:\软件\office2000\office11\msohev.dll
03830000[00019000]
[ M] 138. c:\program files\rising\rav\ravscrch.dll
30000000[002EE000]
[ M] 139. c:\windows\system32\macromed\flash\flash9b.ocx
72C80000[00008000]
[ M] 117. c:\windows\system32\msacm32.drv
05320000[0000B000]
[AM] 67. c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
02840000[00010000]
[ M] 134. c:\windows\system32\k11842418664.dat
02850000[00008000]
[ M] 135. c:\windows\system32\cmdbcs.dll
02810000[0001C000]
[AM] 72. c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll
+ 00000960(2400) TTraveler.exe
00400000[002E4000]
[AM] 98. d:\游戏\tt\ttraveler.exe
15000000[00010000]
[ M] 134. c:\windows\system32\k11842418664.dat
00D00000[00010000]
[ M] 123. c:\windows\system32\k11842382474.dat
10000000[00005000]
[ M] 122. c:\windows\system32\mosou.dll
01E60000[0002D000]
[ M] 140. d:\游戏\tt\plugins\qqfloatbar\qqfloatbar4tt2.dll
01EA0000[0002E000]
[ M] 141. d:\游戏\tt\plugins\tweather\tweather.dll
01EF0000[0001B000]
[ M] 109. c:\program files\rising\antispyware\ieprot.dll
025F0000[00013000]
[ M] 142. d:\游戏\tt\personaldesktop.dll
02020000[00008000]
[ M] 135. c:\windows\system32\cmdbcs.dll
02CB0000[00019000]
[ M] 138. c:\program files\rising\rav\ravscrch.dll
72C80000[00008000]
[ M] 117. c:\windows\system32\msacm32.drv
+ 00000968(2408) WgaTray.exe
01000000[00052000]
[ M] 143. c:\windows\system32\wgatray.exe
10000000[00005000]
[ M] 122. c:\windows\system32\mosou.dll
01520000[0001B000]
[ M] 109. c:\program files\rising\antispyware\ieprot.dll
+ 00000ab4(2740) Ras.exe
00400000[0013E000]
[ M] 144. c:\program files\rising\antispyware\ras.exe
15000000[00010000]
[ M] 134. c:\windows\system32\k11842418664.dat
00C40000[00010000]
[ M] 123. c:\windows\system32\k11842382474.dat
10000000[00005000]
[ M] 122. c:\windows\system32\mosou.dll
00EB0000[000A3000]
[ M] 145. c:\program files\rising\antispyware\rasgui.dll
016A0000[0001B000]
[AM] 78. c:\windows\system32\ravext.dll
016D0000[00011000]
[AM] 83. c:\windows\system32\shlhook.dll
01740000[0001B000]
[ M] 109. c:\program files\rising\antispyware\ieprot.dll
02080000[00008000]
[ M] 135. c:\windows\system32\cmdbcs.dll
02D70000[0002F000]
[ M] 146. c:\program files\rising\antispyware\engine.dll
029F0000[00012000]
[ M] 147. c:\program files\rising\antispyware\zip.dll
+ 00000b60(2912) iPodService.exe
00400000[00051000]
[AM] 3. c:\program files\ipod\bin\ipodservice.exe
10000000[0000C000]
[ M] 148. c:\program files\ipod\bin\ipodservice.resources\zh_cn.lproj\ipodservicelocalized.dll
003E0000[0000B000]
[ M] 149. c:\program files\ipod\bin\ipodservice.resources\ipodservice.dll
+ 00000be8(3048) ServiceLayer.exe
00400000[0002D000]
[AM] 10. c:\program files\common files\pcsuite\services\servicelayer.exe
10000000[00013000]
[ M] 150. c:\windows\system32\ncltools.dll
7C3A0000[0007B000]
[ M] 131. c:\windows\system32\msvcp71.dll
7C340000[00056000]
[ M] 128. c:\windows\system32\msvcr71.dll
7C120000[00019000]
[ M] 151. c:\windows\system32\atl71.dll
00E80000[00010000]
[ M] 152. c:\program files\common files\pcsuite\transports\nclirdamm.dll
00E90000[00036000]
[ M] 153. c:\program files\common files\pcsuite\transports\nclrsmm.dll
00ED0000[00019000]
[ M] 154. c:\program files\common files\pcsuite\transports\nclusbmm.dll
00EF0000[00017000]
[ M] 155. c:\program files\common files\pcsuite\transports\nclmsbtmm.dll
01B70000[0000D000]
[ M] 156. c:\program files\common files\pcsuite\services\nclds.dll
+ 00000d84(3460) alg.exe
+ 00000e50(3664) emule.exe
00400000[0070A000]
[ M] 157. f:\tpb\emule\emule.exe
10000000[00005000]
[ M] 122. c:\windows\system32\mosou.dll
01280000[0000C000]
[ M] 158. f:\tpb\emule\lang\zh_cn.dll
014A0000[0001B000]
[ M] 109. c:\program files\rising\antispyware\ieprot.dll
15000000[00010000]
[ M] 123. c:\windows\system32\k11842382474.dat
015E0000[00010000]
[ M] 134. c:\windows\system32\k11842418664.dat
017D0000[00008000]
[ M] 135. c:\windows\system32\cmdbcs.dll
+ 00000f50(3920) svchost.exe
© 2000 - 2026 Rising Corp. Ltd.