D:\RISING\RISING\RAV\RAVSTUB.EXE
D:\RISING\RISING\RAV\PROCCOM.DLL
D:\RISING\RISING\RAV\RSCOMMX2.DLL
D:\RISING\RISING\RAV\RSCOMMON.DLL
D:\RISING\RISING\RFW\IJT_BASE.DLL
D:\RISING\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\CTFMON.EXE
D:\RISING\RISING\RFW\IJT_BASE.DLL
D:\RISING\RISING\RFW\OLEMON.DLL
E:\QQ\TXPLATFORM.EXE
D:\RISING\RISING\RFW\IJT_BASE.DLL
D:\RISING\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\ALG.EXE
F:\新建文件夹 (2)\RSDETECT.EXE
D:\RISING\RISING\RFW\IJT_BASE.DLL
D:\RISING\RISING\RFW\OLEMON.DLL
D:\新建文件夹 (7)\360SAFE\SAFEMON\SAFEMON.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\RAS.EXE
C:\WINDOWS\SYSTEM32\NORMALIZ.DLL
C:\WINDOWS\SYSTEM32\IERTUTIL.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\MFC71.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\MSVCR71.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\MSVCP71.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\TOPSOFT.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\NCOMM.DLL
D:\RISING\RISING\RAV\PROCCOM.DLL
D:\RISING\RISING\RAV\RSCOMMX2.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\RASGUI.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\RSXML.DLL
C:\WINDOWS\SYSTEM32\IEFRAME.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\KTROJAN.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\ENGINE.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\RSDIALOG.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\SCANUNV.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\SECSCAN.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\SECEX.DLL
C:\PROGRAM FILES\RISING\ANTISPYWARE\ZIP.DLL
D:\RISING\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9F.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\PROGRAM FILES\INTERNET EXPLORER\IEPROXY.DLL
D:\RISING\RISING\RFW\RFWCFG.EXE
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
D:\RISING\RISING\RFW\RSGUILIB.DLL
D:\RISING\RISING\RFW\PROCCOM.DLL
D:\RISING\RISING\RFW\RSCOMMX2.DLL
D:\RISING\RISING\RFW\RSAPPMGR.DLL
D:\RISING\RISING\RFW\CFGDLL.DLL
D:\RISING\RISING\RFW\RSCOMMON.DLL
D:\RISING\RISING\RFW\RFWCTRL.DLL
D:\RISING\RISING\RFW\PROXYCTR.DLL
D:\RISING\RISING\RFW\RSXML.DLL
D:\RISING\RISING\RFW\PNGDLL.DLL
D:\RISING\RISING\RFW\RFWRULE.DLL
C:\WINDOWS\SYSTEM32\ACSIGNICON.DLL
C:\WINDOWS\SYSTEM32\NORMALIZ.DLL
C:\WINDOWS\SYSTEM32\IERTUTIL.DLL
C:\WINDOWS\SYSTEM32\IEFRAME.DLL
C:\PROGRAM FILES\COMMON FILES\AUTODESK SHARED\ACSIGNCORE16.DLL
C:\WINDOWS\SYSTEM32\WPDSHEXT.DLL
C:\WINDOWS\SYSTEM32\PORTABLEDEVICEAPI.DLL
C:\WINDOWS\SYSTEM32\AUDIODEV.DLL
D:\RISING\RISING\RAV\RAV.EXE
C:\WINDOWS\SYSTEM32\NORMALIZ.DLL
C:\WINDOWS\SYSTEM32\IERTUTIL.DLL
D:\RISING\RISING\RAV\PROCCOM.DLL
D:\RISING\RISING\RAV\RSCOMMX2.DLL
D:\RISING\RISING\RAV\RSGUILIB.DLL
C:\WINDOWS\SYSTEM32\MFC71.DLL
C:\WINDOWS\SYSTEM32\MSVCR71.DLL
C:\WINDOWS\SYSTEM32\MSVCP71.DLL
D:\RISING\RISING\RAV\RSXML.DLL
D:\RISING\RISING\RAV\PNGDLL.DLL
D:\RISING\RISING\RAV\RSCOMMON.DLL
D:\RISING\RISING\RAV\RAVPAGEM.DLL
D:\RISING\RISING\RAV\HTMLLIB.DLL
D:\RISING\RISING\RAV\RSAPPMGR.DLL
D:\RISING\RISING\RAV\CFGDLL.DLL
D:\RISING\RISING\RAV\RAVPAGEW.DLL
C:\WINDOWS\SYSTEM32\ACSIGNICON.DLL
D:\RISING\RISING\RAV\FAKESCAN.DLL
D:\RISING\RISING\RAV\SCANNER.DLL
D:\RISING\RISING\RAV\BWLIST.DLL
D:\RISING\RISING\RAV\SYSMAIL.DLL
C:\WINDOWS\SYSTEM32\IEFRAME.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM32\IERTUTIL.DLL
D:\RISING\RISING\RFW\IJT_BASE.DLL
D:\RISING\RISING\RFW\OLEMON.DLL
C:\WINDOWS\SYSTEM32\IEFRAME.DLL
D:\新建文件夹 (7)\360SAFE\SAFEMON\SAFEMON.DLL
C:\WINDOWS\SYSTEM32\IEUI.DLL
C:\WINDOWS\SYSTEM32\XMLLITE.DLL
C:\WINDOWS\SYSTEM32\ACSIGNICON.DLL
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
C:\PROGRAM FILES\INTERNET EXPLORER\IEPROXY.DLL
C:\WINDOWS\SYSTEM32\NORMALIZ.DLL
D:\新建文件夹 (2)\新建文件夹\MAGICSET\HAOKANBAR.DLL
C:\PROGRAM FILES\TENCENT\QQTOOLBAR\IEBAR.DLL
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\TENCENT\QQTOOLBAR\BUTTONS\TOOLBAR.DLL
C:\WINDOWS\SYSTEM32\IEAPFLTR.DLL
D:\RISING\RISING\RAV\RAVSCRCH.DLL
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH9F.OCX
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\WINWB86.IME
C:\WINDOWS\SYSTEM32\MSCOREE.DLL
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V2.0.50727\MSCORIE.DLL
C:\WINDOWS\SYSTEM32\PORTABLEDEVICEAPI.DLL
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ATICCC = "C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CLISTART.EXE"
runeip = "C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE" /STARTUP
RfwMain = "D:\RISING\RISING\RFW\RFWMAIN.EXE" -STARTUP
RavTask = "D:\RISING\RISING\RAV\RAVTASK.EXE" -SYSTEM
360Safetray = D:\新建文件夹 (7)\360SAFE\SAFEMON\360TRAY.EXE /START
360Safebox = "C:\PROGRAM FILES\360SAFEBOX\SAFEBOXTRAY.EXE" /R
KernelFaultCheck = C:\WINDOWS\SYSTEM32\DUMPREP 0 -K
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = C:\WINDOWS\notepad.exe %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> Word.Document.8 = "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde
其它启动项
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
SCRNSAVE.EXE = C:\WINDOWS\system32\ravss.scr
Winlogon 启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
crypt32chain = CRYPT32.DLL
cryptnet = CRYPTNET.DLL
cscdll = CSCDLL.DLL
ScCertProp = WLNOTIFY.DLL
Schedule = WLNOTIFY.DLL
sclgntfy = SCLGNTFY.DLL
SensLogn = WLNOTIFY.DLL
termsrv = WLNOTIFY.DLL
WgaLogon = WGALOGON.DLL
wlballoon = WLNOTIFY.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = C:\WINDOWS\SYSTEM32\USERINIT.EXE,
shell = EXPLORER.EXE
IE - BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{7369D35A-5B70-4A5B-B789-B25FE09B4AF3} = D:\新建文件夹 (2)\新建文件夹\MagicSet\haokanbar.dll
{B69F34DD-F0F9-42DC-9EDD-957187DA688D} = D:\新建文件夹 (7)\360safe\safemon\safemon.dll
Winsock SPI
MSAFD Tcpip [TCP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [UDP/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD Tcpip [RAW/IP] = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
RSVP UDP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
RSVP TCP Service Provider = C:\WINDOWS\SYSTEM32\RSVPSP.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{02FA5DC7-C7A0-4385-8893-FFD6FAF36CFD}] SEQPACKET 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{02FA5DC7-C7A0-4385-8893-FFD6FAF36CFD}] DATAGRAM 0 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{FCD4B0C8-53FA-44D6-A408-6C7060274ED9}] SEQPACKET 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{FCD4B0C8-53FA-44D6-A408-6C7060274ED9}] DATAGRAM 1 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{980B5A24-5754-498C-AE73-EBFAA6E25AE8}] SEQPACKET 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{980B5A24-5754-498C-AE73-EBFAA6E25AE8}] DATAGRAM 2 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{169350DC-F4AA-48D9-A593-AE410A12C7A4}] SEQPACKET 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{169350DC-F4AA-48D9-A593-AE410A12C7A4}] DATAGRAM 3 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{AF58BE0F-967E-4DD1-B40E-9FFE97166A13}] SEQPACKET 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL
MSAFD NetBIOS [\Device\NetBT_Tcpip_{AF58BE0F-967E-4DD1-B40E-9FFE97166A13}] DATAGRAM 4 = C:\WINDOWS\SYSTEM32\MSWSOCK.DLL