[C:\Documents and Settings\Administrator\桌面\QQ\QQUdpGetFileLib.dll] [tencent, 0, 2, 2, 3]
[C:\Documents and Settings\Administrator\桌面\QQ\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 140]
[C:\Documents and Settings\Administrator\桌面\QQ\QQSceneMng.dll] [N/A, N/A]
[C:\Documents and Settings\Administrator\桌面\QQ\QQPhoneHelper.dll] [腾讯科技(深圳)有限公司, 2, 0, 6, 60]
[C:\Documents and Settings\Administrator\桌面\QQ\ShareFiles.dll] [N/A, N/A]
[C:\Documents and Settings\Administrator\桌面\QQ\QQZip.dll] [tencent, 0, 3, 2, 4]
[C:\Documents and Settings\Administrator\桌面\QQ\QQAllInOne.dll] [N/A, N/A]
[C:\Documents and Settings\Administrator\桌面\QQ\SCCore.dll] [N/A, N/A]
[C:\Documents and Settings\Administrator\桌面\QQ\QQCustomFace.dll] [N/A, N/A]
[C:\Documents and Settings\Administrator\桌面\QQ\ImageOle.dll] [TODO: <Company name>, 1.0.0.1]
[C:\Documents and Settings\Administrator\桌面\QQ\QQMagicFace.dll] [, 1, 0, 0, 1]
[PID: 2312][C:\Documents and Settings\Administrator\桌面\QQ\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[C:\Documents and Settings\Administrator\桌面\QQ\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 2652][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[PID: 2904][C:\Program Files\Rising\Rav\Rav.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 50]
[C:\Program Files\Rising\Rav\PlugIn\RsPgScan.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RavUI.Dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 53]
[C:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 23]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 28]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 16]
[C:\Program Files\Rising\Rav\RavUIMsg.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 23]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[C:\Program Files\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
[C:\Program Files\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
[C:\Program Files\Rising\Rav\MVEngine.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\PostTrt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\engine.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 26]
[C:\Program Files\Rising\Rav\UnExe.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 7]
[C:\Program Files\Rising\Rav\ScanExec.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 7]
[C:\Program Files\Rising\Rav\ScanEx.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\NvFile.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 7]
[C:\Program Files\Rising\Rav\ScanMac.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 7]
[C:\Program Files\Rising\Rav\ScanSct.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\ExtOLE.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\Unpacker.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[C:\Program Files\Rising\Rav\ExtFile.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 16]
[C:\Program Files\Rising\Rav\ScanNet.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\ExtMail.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
[PID: 2940][C:\Program Files\Rising\Rav\RsAgent.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[PID: 2960][C:\WINDOWS\msagent\AgentSvr.exe] [Microsoft Corporation, 2.00.0.3422]
[PID: 1964][C:\Program Files\Kingsoft\FastAIT\FastAIT.exe] [金山软件有限公司, 2.00]
[C:\Program Files\Kingsoft\FastAIT\XImage32.dll] [N/A, N/A]
[C:\Program Files\Kingsoft\FastAIT\Imcs.dll] [N/A, N/A]
[C:\Program Files\Kingsoft\FastAIT\MCSKRL.DLL] [N/A, N/A]
[C:\Program Files\Kingsoft\FastAIT\mcsnt.dll] [N/A, N/A]
[C:\Program Files\Kingsoft\FastAIT\CJKTAB32.dll] [N/A, N/A]
[C:\Program Files\Kingsoft\FastAIT\ECTrans.dll] [N/A, N/A]
[PID: 2096][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\baidu\bar\baidubar.dll] [Baidu.com, Inc., 2, 0, 2, 111]
[C:\Program Files\Infofo Bar\infofobar.dll] [珊瑚虫工作室 泰格工作室, 1, 0, 0, 0]
[c:\program files\google\googletoolbar1.dll] [Google Inc., 3, 0, 131, 0]
[C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_013.dll] [Thunder Networking Technologies,LTD, 6, 0, 0, 4]
[C:\WINDOWS\system32\xunleibho_v8.dll] [Thunder Networking Technologies,LTD, 4, 5, 1, 33]
[C:\Documents and Settings\Administrator\桌面\QQ\QQIEHelper.dll] [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
[C:\Program Files\ICQToolbar\toolbaru.dll] [ICQ Inc., 1, 0, 10, 17]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[PID: 3692][C:\Documents and Settings\Administrator\桌面\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
60.191.60.114 www.1ting.com
60.191.60.114 www.6621.com
60.191.60.114 www.qq163.com
60.191.60.114 www.13139.com
60.191.60.114 www.haoting.com
60.191.60.114 ok.wo99.com
60.191.60.114 www.666ccc.com
60.191.60.114 www.5fad.com
60.191.60.114 www.7t7t.com
60.191.60.114 www.7322.com
60.191.60.114 www.4199.com
218.5.76.175 www.huoche.com.cn
218.5.76.175 www.lieche.cn
218.5.76.175 www.123cha.com
218.5.76.175 train.hepost.com
==================================