瑞星卡卡安全论坛
⒏ヤFēn掱 - 2007-2-2 16:32:00
偶最近开机慢,瑞星监控自动转入后台处理,用8月专杀发现一病毒,名字忘记了,现在杀完了,斑竹高手看下日志吧
.[CODE]
2007-02-02,16:11:58
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe> [(Verified)Microsoft Corporation]
<RegBar><regsvr32.exe /u C:\progra~1\blogmark\bocaitoolbar.dll /s /i /n> [N/A]
<bsx><C:\WINDOWS\iexpl0re.exe> [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<MSAboutDialog><regsvr32.exe xadowner1.dll /s> [N/A]
<AboutSys><regsvr32.exe msaddon.dll /s> [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<IgfxTray><C:\WINDOWS\System32\igfxtray.exe> [(Verified)Intel Corporation]
<HotKeysCmds><C:\WINDOWS\System32\hkcmd.exe> [(Verified)Intel Corporation]
<PmProxy><C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe> [adi]
<00THotkey><C:\WINDOWS\System32\00THotkey.exe> [东芝公司]
<000StTHK><000StTHK.exe> [N/A]
<LTSMMSG><LTSMMSG.exe> [LT]
<Tpwrtray><TPWRTRAY.EXE> [东芝公司]
<TFNF5><TFNF5.exe> [Toshiba Corp.]
<Apoint><C:\Program Files\Apoint2K\Apoint.exe> [(Verified)Alps Electric Co., Ltd.]
<TouchED><C:\Program Files\TOSHIBA\TouchED\TouchED.Exe> [东芝公司]
<ezShieldProtector for Px><C:\WINDOWS\System32\ezSP_Px.exe> [Easy Systems Japan Ltd.]
<Drag'n Drop CD+DVD><C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe /StartUp> [N/A]
<MSPY2002><C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC> [(Verified)N/A]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
<StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> [N/A]
<stup.exe><C:\PROGRA~1\TENCENT\Adplus\stup.exe> [Tencent]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<runeip><C:\Program Files\Rising\KakaToolBar\runiep.exe> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<RavStub><"C:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<INET><C:\WINDOWS\System32\INETSRV\inetsync.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\System32\userinit.exe,> [(Verified)Microsoft Corporation]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
<{B8A170A8-7AD3-4678-B2FE-F2D7381CC1B5}><C:\Program Files\Internet Explorer\Connection Wizard\isignup.sys> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Updatenm]
<WinlogonNotify: Updatenm><upern.dll> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xyzDown]
<WinlogonNotify: xyzDown><xyzDown.dll> [N/A]
⒏ヤFēn掱 - 2007-2-2 16:33:00
=================================
启动文件夹
[腾讯QQ]
<C:\WINDOWS\Html\腾讯QQ.lnk --> C:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><N>
==================================
服务
[Application Management / AppMgmt][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[Logical Disk Manager / dmserver][Stopped/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\pwkbypkr.d1l><N/A>
[DVD-RAM_Service / DVD-RAM_Service][Running/Auto Start]
<C:\WINDOWS\System32\DVDRAMSV.exe><Matsushita Electric Industrial Co., Ltd.>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Rising Proxy Service / RfwProxySrv][Stopped/Manual Start]
<c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon][Running/Auto Start]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
==================================
驱动程序
[ADProt / ADProt][Stopped/System Start]
<system32\drivers\ADProt.sys><腾讯科技(深圳)有限公司>
[aeaudio / aeaudio][Running/Manual Start]
<system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[Alps Pointing-device Filter Driver / ApfiltrService][Running/Manual Start]
<System32\DRIVERS\Apfiltr.sys><Alps Electric Co., Ltd.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[Cdsys / Cdsys][Stopped/Manual Start]
<\??\C:\WINDOWS\System32\cdcd.sys><N/A>
[Intel(R) PRO Adapter Driver / E100B][Running/Manual Start]
<System32\DRIVERS\e100b325.sys><Intel Corporation>
[ExpScaner / ExpScaner][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[fsjajkr / fsjajkr][Running/Boot Start]
<\SystemRoot\system32\drivers\fsjajkr.sys><>
[HookCont / HookCont][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl][Running/Auto Start]
<\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[ialm / ialm][Running/Manual Start]
<System32\DRIVERS\ialmnt5.sys><Intel Corporation>
[kmsinput / kmsinput][Stopped/Manual Start]
<\??\C:\WINDOWS\System32\drivers\kmsinput.sys><N/A>
[KWatch3 / KWatch3][Running/System Start]
<\??\C:\WINDOWS\System32\drivers\KWatch3.SYS><Kingsoft Corporation>
[meiudf / meiudf][Running/System Start]
<System32\Drivers\meiudf.sys><Matsushita Electric Industrial Co.,Ltd.>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs][Running/Auto Start]
<\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[New0 / New0][Running/Auto Start]
<\??\C:\WINDOWS\System32\new.sys><N/A>
[npkycryp / npkycryp][Stopped/Manual Start]
<\??\C:\Program Files\Tencent\QQ\npkycryp.sys><N/A>
[PSSdk21 / PSSdk21][Stopped/Manual Start]
<\??\C:\WINDOWS\System32\Drivers\HNPsSdk.drv><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[pwkbypkr / pwkbypkr][Stopped/Manual Start]
<\??\C:\WINDOWS\System32\drivers\pwkbypkr.sys><N/A>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\PxHelp20.sys><VERITAS Software, Inc.>
[RsAntiSpyware / RsAntiSpyware][Stopped/Disabled]
<\SystemRoot\System32\drivers\RsBoot.sys><Beijing Rising>
[RsFwDrv / RsFwDrv][Running/Auto Start]
<\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\System32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Secdrv / Secdrv][Stopped/Manual Start]
<System32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[smwdm / smwdm][Running/Manual Start]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1][Stopped/Manual Start]
<System32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[STEC3 / STEC3][Running/Auto Start]
<\??\C:\WINDOWS\System32\STEC3.sys><AntiCracking>
[SVKP / SVKP][Running/Auto Start]
<\??\C:\WINDOWS\System32\SVKP.sys><AntiCracking>
[TOSHIBA Software Modem / TOSHIBASoftModem][Running/Manual Start]
<System32\DRIVERS\LTSM.sys><LT>
⒏ヤFēn掱 - 2007-2-2 16:34:00
=================================
启动文件夹
[腾讯QQ]
<C:\WINDOWS\Html\腾讯QQ.lnk --> C:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><N>
==================================
服务
[Application Management / AppMgmt][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[Logical Disk Manager / dmserver][Stopped/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\pwkbypkr.d1l><N/A>
[DVD-RAM_Service / DVD-RAM_Service][Running/Auto Start]
<C:\WINDOWS\System32\DVDRAMSV.exe><Matsushita Electric Industrial Co., Ltd.>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Rising Proxy Service / RfwProxySrv][Stopped/Manual Start]
<c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon][Running/Auto Start]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
==================================
驱动程序
[ADProt / ADProt][Stopped/System Start]
<system32\drivers\ADProt.sys><腾讯科技(深圳)有限公司>
[aeaudio / aeaudio][Running/Manual Start]
<system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[Alps Pointing-device Filter Driver / ApfiltrService][Running/Manual Start]
<System32\DRIVERS\Apfiltr.sys><Alps Electric Co., Ltd.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[Cdsys / Cdsys][Stopped/Manual Start]
<\??\C:\WINDOWS\System32\cdcd.sys><N/A>
[Intel(R) PRO Adapter Driver / E100B][Running/Manual Start]
<System32\DRIVERS\e100b325.sys><Intel Corporation>
[ExpScaner / ExpScaner][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[fsjajkr / fsjajkr][Running/Boot Start]
<\SystemRoot\system32\drivers\fsjajkr.sys><>
[HookCont / HookCont][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl][Running/Auto Start]
<\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[ialm / ialm][Running/Manual Start]
<System32\DRIVERS\ialmnt5.sys><Intel Corporation>
[kmsinput / kmsinput][Stopped/Manual Start]
<\??\C:\WINDOWS\System32\drivers\kmsinput.sys><N/A>
[KWatch3 / KWatch3][Running/System Start]
<\??\C:\WINDOWS\System32\drivers\KWatch3.SYS><Kingsoft Corporation>
[meiudf / meiudf][Running/System Start]
<System32\Drivers\meiudf.sys><Matsushita Electric Industrial Co.,Ltd.>
[MEMSCAN / MEMSCAN][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs][Running/Auto Start]
<\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[New0 / New0][Running/Auto Start]
<\??\C:\WINDOWS\System32\new.sys><N/A>
[npkycryp / npkycryp][Stopped/Manual Start]
<\??\C:\Program Files\Tencent\QQ\npkycryp.sys><N/A>
[PSSdk21 / PSSdk21][Stopped/Manual Start]
<\??\C:\WINDOWS\System32\Drivers\HNPsSdk.drv><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[pwkbypkr / pwkbypkr][Stopped/Manual Start]
<\??\C:\WINDOWS\System32\drivers\pwkbypkr.sys><N/A>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\PxHelp20.sys><VERITAS Software, Inc.>
[RsAntiSpyware / RsAntiSpyware][Stopped/Disabled]
<\SystemRoot\System32\drivers\RsBoot.sys><Beijing Rising>
[RsFwDrv / RsFwDrv][Running/Auto Start]
<\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
<\SystemRoot\System32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[RSPPSYS / RSPPSYS][Running/Auto Start]
<\??\C:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Secdrv / Secdrv][Stopped/Manual Start]
<System32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[smwdm / smwdm][Running/Manual Start]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1][Stopped/Manual Start]
<System32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[STEC3 / STEC3][Running/Auto Start]
<\??\C:\WINDOWS\System32\STEC3.sys><AntiCracking>
[SVKP / SVKP][Running/Auto Start]
<\??\C:\WINDOWS\System32\SVKP.sys><AntiCracking>
[TOSHIBA Software Modem / TOSHIBASoftModem][Running/Manual Start]
<System32\DRIVERS\LTSM.sys><LT>
⒏ヤFēn掱 - 2007-2-2 16:35:00
[Toshiba ACPI-Based Value Added Logical Device Driver / TVALD][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\TVALD.SYS><Toshiba Corporation>
[Toshiba Value Added Logical and General Purpose Device Driver / TVALG][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\TVALG.SYS><TOSHIBA Corporation>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[NTPort Library Driver / zntport][Stopped/Auto Start]
<\??\C:\WINDOWS\System32\zntport.sys><N/A>
[VIMICRO USB PC Camera 301x / ZSMC301b][Running/Manual Start]
<System32\Drivers\usbVM31b.sys><VM>
[Intel(R) Graphics Platform (SoftBIOS) Driver / {6080A529-897E-4629-A488-ABA0C29B635E}][Running/Manual Start]
<system32\drivers\ialmsbw.sys><Intel Corporation>
[Intel(R) Graphics Chipset (KCH) Driver / {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}][Running/Manual Start]
<system32\drivers\ialmkchw.sys><Intel Corporation>
[AIM 3.0 Part 01 Codec Driver CH-7009-A/CH-7011 / {E2B953A6-195A-44F9-9BA3-3D5F4E32BB55}][Stopped/Manual Start]
<system32\drivers\wA301a.sys><Intel Corporation>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
==================================
浏览器加载项
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[访问瑞星网站]
{FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444} <http://www.rising.com.cn/?u=RSTB, N/A>
[访问卡卡社区]
{FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} <http://www.ikaka.com/?u=RSTB, N/A>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[GDHidCtrl Class]
{220ED87A-CB03-45A8-A81E-1C5597E11186} <C:\WINDOWS\System32\GDHidUsr\GDHidUsr.dll, >
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\System32\aliedit\AliEdit.dll, www.alipay.com>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[CPasswordEditCtrl Object]
{E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\System32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
[&使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[上传到QQ网络硬盘]
<C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
<C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
⒏ヤFēn掱 - 2007-2-2 16:35:00
正在运行的进程
[PID: 520][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 592][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 616][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.1557 (xpsp2_gdr.040517-1325)]
[C:\WINDOWS\System32\plug.dll] [Bokee, 2, 1, 0, 1]
[PID: 660][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 672][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 836][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 936][C:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 956][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1104][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1164][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1176][C:\Program Files\Rising\Rav\Ravmond.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 43]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\rfwctrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[C:\Program Files\Rising\Rav\RsPPsys.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RsLog.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[C:\Program Files\Rising\Rav\HOOKSYS.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
[C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
[C:\Program Files\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[C:\Program Files\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[C:\Program Files\Rising\Rav\regmon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\HookWeb.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[C:\Program Files\Rising\Rav\MemMon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
[C:\Program Files\Rising\Rav\expscan.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[C:\Program Files\Rising\Rav\HookCont.dll] [Rising, 19, 0, 0, 0]
[C:\Program Files\Rising\Rav\SpamEng.dll] [N/A, 18, 0, 0, 6]
[C:\Program Files\Rising\Rav\engine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 24]
[C:\Program Files\Rising\Rav\PostTrt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[C:\Program Files\Rising\Rav\UnExe.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Rising\Rav\ScanExec.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[C:\Program Files\Rising\Rav\ScanEx.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
[C:\Program Files\Rising\Rav\ExtFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 25]
[C:\Program Files\Rising\Rav\NvFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[C:\Program Files\Rising\Rav\ScanMac.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
[C:\Program Files\Rising\Rav\ScanSct.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[C:\Program Files\Rising\Rav\Unpacker.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
[C:\Program Files\Rising\Rav\ScanPack.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[C:\Program Files\Rising\Rav\RsVM.dll] [N/A, 19, 0, 0, 15]
[C:\Program Files\Rising\Rav\Uroutine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 21]
[C:\Program Files\Rising\Rav\ExtOLE.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[C:\Program Files\Rising\Rav\ScanNet.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\Uscript.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 18]
[PID: 1240][c:\program files\rising\rfw\rfwsrv.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 30]
[c:\program files\rising\rfw\RfwRule.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 3]
[c:\program files\rising\rfw\rfwlog.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 2]
[c:\program files\rising\rfw\Rfwdrv.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 10]
[c:\program files\rising\rfw\MonDrv.dll] [rs, 1, 0, 0, 4]
[c:\program files\rising\rfw\ProcLib.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 5]
[c:\program files\rising\rfw\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[PID: 1416][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\WINDOWS\System32\LgSym.dll] [N/A, N/A]
[C:\Program Files\TENCENT\Adplus\SSAddr.dll] [Tencent, 4, 4, 1, 15]
[C:\WINDOWS\System32\igfxpph.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\System32\hccutils.DLL] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\System32\igfxres.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\System32\igfxsrvc.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\System32\igfxdev.dll] [Intel Corporation, 3,0,0,2104]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[PID: 1564][C:\Program Files\Rising\Rav\RavStub.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1664][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.1699 (xpsp2.050610-1533)]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll] [Windows (R) 2000 DDK provider, 5.00.2195.1620]
⒏ヤFēn掱 - 2007-2-2 16:36:00
[PID: 1860][C:\WINDOWS\System32\igfxtray.exe] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\System32\hccutils.DLL] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\System32\igfxdev.dll] [Intel Corporation, 3,0,0,2104]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\WINDOWS\System32\igfxsrvc.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\System32\igfxres.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\System32\igfxress.dll] [Intel Corporation, 3,0,0,2104]
[PID: 1868][C:\WINDOWS\System32\hkcmd.exe] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\System32\hccutils.DLL] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\System32\igfxdev.dll] [Intel Corporation, 3,0,0,2104]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[C:\WINDOWS\System32\igfxsrvc.dll] [Intel Corporation, 3,0,0,2104]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\WINDOWS\System32\igfxhk.dll] [Intel Corporation, 3,0,0,2104]
[C:\WINDOWS\System32\igfxres.dll] [Intel Corporation, 3,0,0,2104]
[PID: 1872][c:\program files\rising\rfw\RfwMain.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 70]
[c:\program files\rising\rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 31]
[c:\program files\rising\rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[c:\program files\rising\rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[c:\program files\rising\rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[c:\program files\rising\rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\WINDOWS\System32\LgSym.dll] [N/A, N/A]
[PID: 1892][C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe] [adi, 1, 0, 0, 18]
[C:\Program Files\Analog Devices\SoundMAX\PMCPL.cpl] [Analog Devices, 1, 0, 0, 19]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[PID: 2040][C:\WINDOWS\System32\00THotkey.exe] [东芝公司, 1, 0, 0, 21]
[C:\WINDOWS\system32\TSCI.DLL] [Toshiba, 1.0.0.0]
[C:\WINDOWS\system32\THCI.DLL] [Toshiba, 1.0.0.0]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[PID: 364][C:\WINDOWS\LTSMMSG.exe] [LT, 3.1.118.2 04/18/2003 10:06:28]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[PID: 432][C:\WINDOWS\System32\TPWRTRAY.EXE] [东芝公司, 6.00.21]
[C:\WINDOWS\System32\TPwrReg.dll] [东芝公司, 6.00.10]
[C:\WINDOWS\System32\Tdevdetect.dll] [东芝公司, 6.00.21]
[C:\WINDOWS\system32\TSCI.DLL] [Toshiba, 1.0.0.0]
[C:\WINDOWS\system32\THCI.DLL] [Toshiba, 1.0.0.0]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[PID: 444][C:\WINDOWS\System32\TFNF5.exe] [Toshiba Corp., 1. 0. 1. 0]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 508][C:\Program Files\Apoint2K\Apoint.exe] [Alps Electric Co., Ltd., 6.0.1.159]
[C:\WINDOWS\System32\VXDIF.DLL] [Alps Electric Co., Ltd., 6.0.1.59]
[C:\Program Files\Apoint2K\ApMain.DLL] [Alps Electric Co., Ltd., 6.0.1.10]
[C:\Program Files\Apoint2K\ApCommon.dll] [Alps Electric Co., Ltd., 6.0.2.16]
[C:\Program Files\Apoint2K\ApDual.dll] [Alps Electric Co., Ltd., 6.0.1.14]
[C:\Program Files\Apoint2K\ApPad.dll] [Alps Electric Co., Ltd., 6.0.1.35]
[C:\Program Files\Apoint2K\EzCapt.dll] [Alps Electric Co., Ltd., 6.0.1.14]
[C:\Program Files\Apoint2K\EzLaunch.dll] [Alps Electric Co., Ltd., 6.0.1.25]
[C:\Program Files\Apoint2K\ApStick.dll] [ALPS Electric Co., Ltd., 6.0.1.28]
[C:\Program Files\Apoint2K\ApOthers.dll] [Alps Electric Co., Ltd., 6.0.1.15]
[C:\Program Files\Apoint2K\ApMouse.dll] [ALPS Electric Co., Ltd., 6.0.1.25]
[C:\Program Files\Apoint2K\EzAuto.dll] [Alps Electric Co., Ltd., 4.5.1.83]
[C:\Program Files\Apoint2K\ApString.dll] [Alps Electric Co., Ltd., 6.0.301.27]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 536][C:\Program Files\TOSHIBA\TouchED\TouchED.Exe] [东芝公司, 2, 5, 0, 0]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[PID: 568][C:\WINDOWS\System32\ezSP_Px.exe] [Easy Systems Japan Ltd., 1, 0, 0, 0]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[PID: 572][C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe] [, 3, 0, 0, 0]
[C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DGSSTRM.DLL] [DigiOn,Inc., 2.01]
[C:\Program Files\Drag'n Drop CD+DVD\BinFiles\PRIMOSDK.dll] [VERITAS Software Corp., 1, 1, 0, 370]
[C:\WINDOWS\System32\PX.dll] [VERITAS Software Corp., 1, 1, 0, 370]
[C:\Program Files\Drag'n Drop CD+DVD\BinFiles\ezCDmker.dll] [Easy Systems Japan, 3, 0, 0, 0]
[C:\Program Files\Drag'n Drop CD+DVD\BinFiles\ezID3.dll] [, 1, 0, 0, 1]
[C:\Program Files\Drag'n Drop CD+DVD\BinFiles\TRANSWIN.dll] [Easy Systems Japan, 1, 0, 0, 0]
[C:\Program Files\Drag'n Drop CD+DVD\BinFiles\ezLICEN.dll] [Easy Systems Japan, 2, 6, 3, 0]
[C:\Program Files\Drag'n Drop CD+DVD\BinFiles\ezLICEN1.dll] [, 1, 0, 0, 1]
[C:\Program Files\Drag'n Drop CD+DVD\BinFiles\Wmp7Chk.dll] [Easy Systems Japan Ltd., 1, 0, 0, 100]
[C:\Program Files\Drag'n Drop CD+DVD\BinFiles\RegRcvry.dll] [Easy Systems Japan Ltd., 1, 0, 0, 0]
⒏ヤFēn掱 - 2007-2-2 16:36:00
[C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DDCDRES.DLL] [, 3, 0, 0, 0]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[C:\WINDOWS\System32\PXDRV.DLL] [VERITAS Software Corp., 1.00.17a]
[C:\WINDOWS\System32\PXMAS.DLL] [ VERITAS Software Corp., 1, 5, 0, 112]
[C:\WINDOWS\System32\PXWAVE.DLL] [ VERITAS Software Corp., 1, 2, 0, 86]
[C:\Program Files\Drag'n Drop CD+DVD\BinFiles\TRANS.DLL] [Easy Systems Japan, 1, 0, 0, 0]
[C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DGID3LIB.dll] [DigiOn Inc., 1.00]
[C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DGWAVOT.DLL] [DigiOn Inc., 2.00]
[C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DGWAVRD.DLL] [DigiOn Inc., 1.03]
[C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DGWAVWT.DLL] [DigiOn Inc., 1.10]
[C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DGWMFRD.DLL] [DigiOn,Inc., 1.04b]
[C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DGWMFWT.DLL] [DigiOn,Inc., 1.04b]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 744][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3292]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[PID: 920][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[PID: 1008][C:\Program Files\Rising\KakaToolBar\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
[C:\Program Files\Rising\KakaToolBar\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[PID: 1268][C:\WINDOWS\System32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1288][C:\Program Files\Apoint2K\Apntex.exe] [Alps Electric Co., Ltd., 5.0.1.13]
[C:\WINDOWS\System32\VXDIF.DLL] [Alps Electric Co., Ltd., 6.0.1.59]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1248][C:\WINDOWS\iexpl0re.exe] [N/A, N/A]
[C:\WINDOWS\System32\LgSym.dll] [N/A, N/A]
[PID: 1332][C:\WINDOWS\System32\conime.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1764][C:\Program Files\Tencent\QQ\QQ.exe] [TENCENT, 0, 0, 0, 0]
[C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQHelperDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\BasicCtrlDll.dll] [Tencent, 5, 0, 200, 14]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[C:\Program Files\Tencent\QQ\QQAPI.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\Tencent\QQ\LoginCtrl.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\npkcntc.dll] [INCA Internet Co., Ltd., 2005, 9, 1, 1]
[C:\Program Files\Tencent\QQ\npkpdb.dll] [INCA Internet Co., Ltd., 2003, 10, 1, 1]
[C:\WINDOWS\System32\LgSym.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQRes.dll] [tencent, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\WizardCtrl.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQMainFrame.dll] [N/A, N/A]
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] [Macromedia, Inc., 8,0,24,0]
[C:\Program Files\Tencent\QQ\CQQApplication.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\NewSkin.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\HostingMgr.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\CameraDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\MailSummary.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQSpace.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\System32\msdmo.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQGroupMng.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QQSysMsgMng.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQConfigPlugin.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\UserDefinedHead.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\QRingMng.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\PhoneAPI.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[C:\Program Files\Tencent\QQ\QQAllInOne.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\SCCore.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQCustomFace.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQAvatar.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[C:\Program Files\Tencent\QQ\LongConnection.dll] [tencent, 0, 3, 3, 8]
[C:\Program Files\Tencent\QQ\QQPet.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\BQQApplication.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQPlugin.dll] [N/A, N/A]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
⒏ヤFēn掱 - 2007-2-2 16:37:00
[C:\Program Files\Tencent\QQ\CommercesMng.dll] [, 1, 0, 0, 1]
[C:\Program Files\Tencent\QQ\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
[C:\Program Files\Tencent\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 141]
[C:\Program Files\Tencent\QQ\QQSceneMng.dll] [N/A, N/A]
[C:\Program Files\Tencent\QQ\QQPhoneHelper.dll] [腾讯科技(深圳)有限公司, 2, 1, 3, 30]
[C:\Program Files\Tencent\QQ\ImageOle.dll] [TODO: <Company name>, 1.0.0.1]
[C:\Program Files\Tencent\QQ\QQMagicFace.dll] [, 1, 0, 0, 1]
[PID: 1972][C:\Program Files\Tencent\QQ\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\Tencent\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 204][C:\WINDOWS\System32\DVDRAMSV.exe] [Matsushita Electric Industrial Co., Ltd., 2, 0, 6, 0]
[PID: 256][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] [Analog Devices, Inc., 3, 2, 6, 0]
[PID: 356][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 388][C:\WINDOWS\System32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
[PID: 3580][C:\Program Files\Rising\Rav\RavMon.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
[C:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\WINDOWS\System32\LgSym.dll] [N/A, N/A]
[PID: 3168][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[C:\Program Files\TENCENT\Adplus\SSAddr.dll] [Tencent, 4, 4, 1, 15]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] [Macromedia, Inc., 8,0,24,0]
[C:\WINDOWS\System32\LgSym.dll] [N/A, N/A]
[PID: 2308][C:\系统工具\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\Program Files\TENCENT\Adplus\Adplus.dll] [Tencent, 4, 4, 1, 14]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\WINDOWS\System32\LgSym.dll] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP Error. [winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
⒏ヤFēn掱 - 2007-2-2 16:37:00
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1localhost
127.0.0.1update1.legendofmir.com.cn
127.0.0.1update2.legendofmir.com.cn
127.0.0.1update3.legendofmir.com.cn
127.0.0.1update4.legendofmir.com.cn
127.0.0.1update5.legendofmir.com.cn
127.0.0.1update6.legendofmir.com.cn
127.0.0.1update7.legendofmir.com.cn
127.0.0.1update8.legendofmir.com.cn
127.0.0.1update9.legendofmir.com.cn
127.0.0.1update10.legendofmir.com.cn
127.0.0.1update11.legendofmir.com.cn
127.0.0.1update12.legendofmir.com.cn
127.0.0.1update13.legendofmir.com.cn
127.0.0.1update14.legendofmir.com.cn
127.0.0.1update15.legendofmir.com.cn
127.0.0.1update16.legendofmir.com.cn
127.0.0.1update17.legendofmir.com.cn
127.0.0.1update18.legendofmir.com.cn
127.0.0.1update19.legendofmir.com.cn
127.0.0.1update20.legendofmir.com.cn
127.0.0.1update21.legendofmir.com.cn
127.0.0.1update22.legendofmir.com.cn
127.0.0.1update23.legendofmir.com.cn
127.0.0.1update24.legendofmir.com.cn
127.0.0.1update25.legendofmir.com.cn
127.0.0.1update26.legendofmir.com.cn
127.0.0.1update27.legendofmir.com.cn
127.0.0.1update28.legendofmir.com.cn
127.0.0.1update29.legendofmir.com.cn
127.0.0.1update30.legendofmir.com.cn
127.0.0.1update31.legendofmir.com.cn
127.0.0.1update32.legendofmir.com.cn
127.0.0.1update33.legendofmir.com.cn
127.0.0.1update34.legendofmir.com.cn
127.0.0.1update35.legendofmir.com.cn
127.0.0.1update36.legendofmir.com.cn
127.0.0.1update37.legendofmir.com.cn
127.0.0.1update38.legendofmir.com.cn
127.0.0.1update39.legendofmir.com.cn
127.0.0.1update40.legendofmir.com.cn
127.0.0.1update41.legendofmir.com.cn
127.0.0.1update42.legendofmir.com.cn
127.0.0.1update43.legendofmir.com.cn
127.0.0.1update44.legendofmir.com.cn
127.0.0.1update45.legendofmir.com.cn
127.0.0.1update46.legendofmir.com.cn
127.0.0.1update47.legendofmir.com.cn
127.0.0.1update48.legendofmir.com.cn
127.0.0.1update49.legendofmir.com.cn
127.0.0.1update50.legendofmir.com.cn
127.0.0.1update51.legendofmir.com.cn
127.0.0.1update52.legendofmir.com.cn
127.0.0.1update53.legendofmir.com.cn
127.0.0.1update54.legendofmir.com.cn
127.0.0.1update55.legendofmir.com.cn
127.0.0.1update56.legendofmir.com.cn
127.0.0.1update57.legendofmir.com.cn
127.0.0.1update58.legendofmir.com.cn
127.0.0.1update59.legendofmir.com.cn
127.0.0.1update60.legendofmir.com.cn
127.0.0.1update61.legendofmir.com.cn
127.0.0.1update62.legendofmir.com.cn
127.0.0.1update63.legendofmir.com.cn
127.0.0.1update64.legendofmir.com.cn
127.0.0.1update65.legendofmir.com.cn
127.0.0.1update66.legendofmir.com.cn
127.0.0.1update67.legendofmir.com.cn
127.0.0.1update68.legendofmir.com.cn
127.0.0.1update69.legendofmir.com.cn
127.0.0.1update70.legendofmir.com.cn
127.0.0.1update71.legendofmir.com.cn
127.0.0.1update72.legendofmir.com.cn
127.0.0.1update73.legendofmir.com.cn
127.0.0.1update74.legendofmir.com.cn
127.0.0.1update75.legendofmir.com.cn
127.0.0.1update76.legendofmir.com.cn
127.0.0.1update77.legendofmir.com.cn
127.0.0.1update78.legendofmir.com.cn
127.0.0.1update79.legendofmir.com.cn
127.0.0.1update80.legendofmir.com.cn
127.0.0.1update81.legendofmir.com.cn
127.0.0.1update82.legendofmir.com.cn
127.0.0.1update83.legendofmir.com.cn
127.0.0.1update84.legendofmir.com.cn
127.0.0.1update85.legendofmir.com.cn
127.0.0.1update86.legendofmir.com.cn
127.0.0.1update87.legendofmir.com.cn
127.0.0.1update88.legendofmir.com.cn
127.0.0.1update89.legendofmir.com.cn
127.0.0.1update90.legendofmir.com.cn
127.0.0.1update91.legendofmir.com.cn
127.0.0.1update92.legendofmir.com.cn
127.0.0.1update93.legendofmir.com.cn
127.0.0.1update94.legendofmir.com.cn
127.0.0.1update95.legendofmir.com.cn
127.0.0.1update96.legendofmir.com.cn
127.0.0.1update97.legendofmir.com.cn
127.0.0.1update98.legendofmir.com.cn
127.0.0.1update99.legendofmir.com.cn
127.0.0.1update100.legendofmir.com.cn
127.0.0.1update101.legendofmir.com.cn
127.0.0.1update102.legendofmir.com.cn
127.0.0.1update103.legendofmir.com.cn
127.0.0.1update104.legendofmir.com.cn
127.0.0.1update105.legendofmir.com.cn
127.0.0.1update106.legendofmir.com.cn
127.0.0.1update107.legendofmir.com.cn
127.0.0.1update108.legendofmir.com.cn
127.0.0.1update109.legendofmir.com.cn
127.0.0.1update110.legendofmir.com.cn
127.0.0.1update111.legendofmir.com.cn
127.0.0.1update112.legendofmir.com.cn
127.0.0.1update113.legendofmir.com.cn
127.0.0.1update114.legendofmir.com.cn
127.0.0.1update115.legendofmir.com.cn
127.0.0.1update116.legendofmir.com.cn
127.0.0.1update117.legendofmir.com.cn
127.0.0.1update118.legendofmir.com.cn
127.0.0.1update119.legendofmir.com.cn
127.0.0.1update120.legendofmir.com.cn
127.0.0.1update95.legendofmir.com.cn
127.0.0.1update96.legendofmir.com.cn
219.153.18.212www.2345sf.com
219.153.18.212web772.jsy666.com
219.153.18.212769web.mir666.com
219.153.18.212www.8qwsf.com
219.153.18.212www.917ww.com
==================================
API HOOK
N/A
==================================
[/CODE]
1
© 2000 - 2026 Rising Corp. Ltd.