yswant - 2006-12-12 16:40:00
==================================
正在运行的进程
[PID: 572][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 628][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 652][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 704][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 716][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 872][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 928][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1024][C:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 1040][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 1080][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1144][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1164][C:\Program Files\Rising\Rav\Ravmond.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 1, 47]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RsPPsys.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\RsLog.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\HOOKSYS.dll] [Beijing Rising Technology Co., Ltd., 18, 1, 0, 12]
[C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 33]
[C:\Program Files\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
[C:\Program Files\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\regmon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\HookWeb.dll] [rising, 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\MemMon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
[C:\Program Files\Rising\Rav\expscan.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[C:\Program Files\Rising\Rav\MailMon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\SpamEng.dll] [N/A, 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\engine.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 35]
[C:\Program Files\Rising\Rav\PostTrt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 18]
[C:\Program Files\Rising\Rav\UnExe.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
[C:\Program Files\Rising\Rav\ScanExec.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 16]
[C:\Program Files\Rising\Rav\ScanEx.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 33]
[C:\Program Files\Rising\Rav\RSUnpack.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 21]
[C:\Program Files\Rising\Rav\ExtFile.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 24]
[C:\Program Files\Rising\Rav\NvFile.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 7]
[C:\Program Files\Rising\Rav\ScanMac.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
[C:\Program Files\Rising\Rav\ScanSct.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\Unpacker.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 1356][c:\program files\rising\rfw\rfwsrv.exe] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 33]
[c:\program files\rising\rfw\RfwRule.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 13]
[c:\program files\rising\rfw\rfwlog.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 6]
[c:\program files\rising\rfw\Rfwdrv.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 21]
[c:\program files\rising\rfw\MonDrv.dll] [rs, 1, 0, 0, 4]
[c:\program files\rising\rfw\ProcLib.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 9]
[c:\program files\rising\rfw\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[PID: 1560][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\drivers\uia2q.sys] [N/A, N/A]
[C:\WINDOWS\system32\rf7zn.dll] [N/A, N/A]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[C:\PROGRA~1\3721\alrex.dll] [, 1, 0, 1, 1001]
[f:\Tencent\QQ\80og.dll] [N/A, N/A]
[C:\PROGRA~1\3721\autolive.dll] [, 1, 1, 9, 1329]
[C:\PROGRA~1\3721\alLiveEx.dll] [ , 1, 0, 3, 1006]
[C:\Program Files\BitComet\tools\BitCometBHO.dll] [BitComet, 20061116]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[C:\PROGRA~1\3721\ske\contmenu.dll] [N/A, N/A]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\mp3infp.dll] [win32lab.com, 2.50.5.0]
[PID: 1672][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1864][C:\Program Files\Rising\Rav\RavStub.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 16]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 168][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5.1.0.39]
[f:\Tencent\QQ\80og.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\uia2q.sys] [N/A, N/A]
[C:\WINDOWS\system32\rf7zn.dll] [N/A, N/A]
[PID: 188][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.9291]
[C:\WINDOWS\system32\nvapi.dll] [N/A, N/A]
[PID: 224][C:\Program Files\Rising\Rfw\rfwmain.exe] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 52]
[C:\Program Files\Rising\Rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 23]
[C:\Program Files\Rising\Rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[C:\WINDOWS\system32\rf7zn.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\uia2q.sys] [N/A, N/A]
[f:\Tencent\QQ\80og.dll] [N/A, N/A]
[PID: 308][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 22]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[f:\Tencent\QQ\80og.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\uia2q.sys] [N/A, N/A]
[C:\WINDOWS\system32\rf7zn.dll] [N/A, N/A]
[PID: 336][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\rf7zn.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\uia2q.sys] [N/A, N/A]
[f:\Tencent\QQ\80og.dll] [N/A, N/A]
[PID: 368][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[C:\WINDOWS\system32\rf7zn.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\uia2q.sys] [N/A, N/A]
[C:\PROGRA~1\3721\autolive.dll] [, 1, 1, 9, 1329]
[C:\PROGRA~1\3721\alLiveEx.dll] [ , 1, 0, 3, 1006]
[f:\Tencent\QQ\80og.dll] [N/A, N/A]
[PID: 388][C:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 1, 39]
[C:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 26]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\WINDOWS\system32\rf7zn.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\uia2q.sys] [N/A, N/A]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[f:\Tencent\QQ\80og.dll] [N/A, N/A]
yswant - 2006-12-12 16:41:00
[PID: 496][F:\Kingsoft\Powerword 2006\xdict.exe] [Kingsoft Co, Ltd., 9, 0, 0, 0]
[F:\Kingsoft\Powerword 2006\DicMngr.dll] [Kingsoft, 2, 0, 0, 0]
[F:\Kingsoft\Powerword 2006\doshow.dll] [N/A, N/A]
[F:\Kingsoft\Powerword 2006\ITextOut.dll] [Kingsoft, 1, 1, 0, 0]
[F:\Kingsoft\Powerword 2006\KPic10.dll] [N/A, N/A]
[F:\Kingsoft\Powerword 2006\ijl11.dll] [Intel Corporation, 1.1.2]
[F:\Kingsoft\Powerword 2006\NormGrab.DLL] [Kingsoft Co, Ltd., 6, 0, 0, 0]
[F:\Kingsoft\Powerword 2006\toTTSEngine50.dll] [Kingsoft Corporation, 1, 0, 0, 1]
[F:\Kingsoft\Powerword 2006\xfile.dll] [N/A, N/A]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[f:\Tencent\QQ\80og.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\uia2q.sys] [N/A, N/A]
[C:\WINDOWS\system32\rf7zn.dll] [N/A, N/A]
[F:\Kingsoft\Powerword 2006\DBCore10.dll] [Kingsoft Corp., 1, 0, 0, 0]
[F:\Kingsoft\Powerword 2006\XdictGrb.dll] [Kingsoft Co, Ltd., 9, 0, 0, 0]
[F:\Kingsoft\Powerword 2006\KAVPassport.DLL] [Kingsoft Corporation, 2005, 4, 7, 25]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 964][C:\WINDOWS\system32\sysresrv.exe] [N/A, N/A]
[PID: 988][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 2196][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2352][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[f:\Tencent\QQ\80og.dll] [N/A, N/A]
[C:\WINDOWS\system32\rf7zn.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\uia2q.sys] [N/A, N/A]
[PID: 2552][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[PID: 2972][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[C:\PROGRA~1\3721\scrblock.dll] [3721, 1, 0, 1, 1000]
[C:\PROGRA~1\3721\alrex.dll] [, 1, 0, 1, 1001]
[f:\Tencent\QQ\80og.dll] [N/A, N/A]
[C:\WINDOWS\system32\rf7zn.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\uia2q.sys] [N/A, N/A]
[C:\PROGRA~1\3721\autolive.dll] [, 1, 1, 9, 1329]
[C:\PROGRA~1\3721\alLiveEx.dll] [ , 1, 0, 3, 1006]
[C:\Program Files\BitComet\tools\BitCometBHO.dll] [BitComet, 20061116]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[PID: 1100][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[C:\PROGRA~1\3721\scrblock.dll] [3721, 1, 0, 1, 1000]
[C:\PROGRA~1\3721\alrex.dll] [, 1, 0, 1, 1001]
[f:\Tencent\QQ\80og.dll] [N/A, N/A]
[C:\WINDOWS\system32\rf7zn.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\uia2q.sys] [N/A, N/A]
[C:\PROGRA~1\3721\autolive.dll] [, 1, 1, 9, 1329]
[C:\PROGRA~1\3721\alLiveEx.dll] [ , 1, 0, 3, 1006]
[C:\Program Files\BitComet\tools\BitCometBHO.dll] [BitComet, 20061116]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 200][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[C:\PROGRA~1\3721\scrblock.dll] [3721, 1, 0, 1, 1000]
[C:\PROGRA~1\3721\alrex.dll] [, 1, 0, 1, 1001]
[f:\Tencent\QQ\80og.dll] [N/A, N/A]
[C:\WINDOWS\system32\rf7zn.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\uia2q.sys] [N/A, N/A]
[C:\PROGRA~1\3721\autolive.dll] [, 1, 1, 9, 1329]
[C:\PROGRA~1\3721\alLiveEx.dll] [ , 1, 0, 3, 1006]
[C:\Program Files\BitComet\tools\BitCometBHO.dll] [BitComet, 20061116]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[C:\Documents and Settings\Administrator\桌面\SREng【teyqiu】.com] [Smallfrogs Studio, 2.2.6.605]
[C:\PROGRA~1\3721\helper.dll] [, 1, 1, 1, 1327]
[f:\Tencent\QQ\80og.dll] [N/A, N/A]
[C:\WINDOWS\system32\rf7zn.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\uia2q.sys] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
61.141.31.11 www.kzdh.com
61.141.31.11 www.7255.com
61.141.31.11 www.7322.com
61.141.31.11 www.7939.com
61.141.31.11 www.piaoxue.com
61.141.31.11 www.feixu.net
61.141.31.11 www.6781.com
61.141.31.11 www.7b.com.cn
61.141.31.11 7b.com.cn
61.141.31.11 www.918188.com
61.141.31.11 hao.allxue.com
61.141.31.11 good.allxue.com
61.141.31.11 baby.allxue.com
61.141.31.11 www.allxue.com
61.141.31.11 about.lank.la
61.141.31.11 www.x114x.com
61.141.31.11 www.37ss.com
61.141.31.11 www.7k.cc
61.141.31.11 www.73ss.com
61.141.31.11 www.hao123.com
61.141.31.11 www.81915.com
61.141.31.11 222.88.90.22
61.141.31.11 www.9991.com
61.141.31.11 www.my123.com
61.141.31.11 www.haokan123.com
61.141.31.11 www.5566.net
61.141.31.11 www.gjj.cc
61.141.31.11 www.2345.com
127.0.0.1 dl.hao318.com
61.141.31.11 www.123wa.com
61.141.31.11 www.ku886.com
61.141.31.11 www.5icrack.com
61.141.31.11 www.jjol.cn
127.0.0.1 www.rising.com.cn
127.0.0.1 tool.ikaka.com
127.0.0.1 www.ikaka.com
127.0.0.1 update.rising.com.cn
127.0.0.1 online.rising.com.cn
127.0.0.1 up.rising.com.cn
127.0.0.1 go.rising.com.cn
127.0.0.1 it.rising.com.cn
127.0.0.1 rising.com.cn
127.0.0.1 ikaka.com
127.0.0.1 www.360safe.com
61.141.31.11 www.xinhai168.com
61.141.31.11 ooooos.com
61.141.31.11 www.ooooos.com
61.141.31.11 www.8757.com
61.141.31.11 4199.5009.com
61.141.31.11 220.181.34.241
==================================
© 2000 - 2026 Rising Corp. Ltd.