[ProtocolDefaults]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
1_Name=
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
2_Name=http
2_Value=3
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
3_Name=https
3_Value=3
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
4_Name=ftp
4_Value=3
5_HKey=HKEY_LOCAL_MACHINE
5_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
5_Name=file
5_Value=3
6_HKey=HKEY_LOCAL_MACHINE
6_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
6_Name=@ivt
6_Value=1
7_HKey=HKEY_LOCAL_MACHINE
7_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
7_Name=shell
7_Value=0
Max=7
[BootExecute]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SYSTEM\CurrentControlSet\Control\Session Manager
1_Name=BootExecute
1_Value=autocheck autochk *
Max=1
[AutoRun]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=Software\Microsoft\Windows\CurrentVersion\Run
1_Name=FixCamera
1_Value=c:\windows\fixcamera.exe
1_FileSize=20480
1_FileDate=2005-12-6 13:08:42
1_FileVersion=1.0.0.3
2_HKey=HKEY_LOCAL_MACHINE
2_Key=Software\Microsoft\Windows\CurrentVersion\Run
2_Name=tsnp2std
2_Value=c:\windows\tsnp2std.exe
2_FileSize=106496
2_FileDate=2005-11-24 17:01:06
2_FileVersion=1.1.2.4
3_HKey=HKEY_LOCAL_MACHINE
3_Key=Software\Microsoft\Windows\CurrentVersion\Run
3_Name=snp2std
3_Value=c:\windows\vsnp2std.exe
3_FileSize=344064
3_FileDate=2005-11-23 22:00:20
3_FileVersion=1.0.3.5
4_HKey=HKEY_LOCAL_MACHINE
4_Key=Software\Microsoft\Windows\CurrentVersion\Run
4_Name=RavTask
4_Value="e:\新建文件夹\rising\rav\ravtask.exe" -system
4_FileSize=114688
4_FileDate=2006-8-16 17:12:21
4_FileVersion=18.0.0.22
5_HKey=HKEY_LOCAL_MACHINE
5_Key=Software\Microsoft\Windows\CurrentVersion\Run
5_Name=RfwMain
5_Value="e:\新建文件夹\rising\rfw\rfwmain.exe" -startup
5_FileSize=417792
5_FileDate=2006-10-3 13:32:56
5_FileVersion=4.0.0.52
6_HKey=HKEY_LOCAL_MACHINE
6_Key=Software\Microsoft\Windows\CurrentVersion\Run
6_Name=helper.dll
6_Value=c:\windows\system32\rundll32.exe c:\progra~1\3721\helper.dll,rundll32
6_FileSize=53326
6_FileDate=2006-8-4 19:54:52
6_FileVersion=1.1.0.1325
7_HKey=HKEY_LOCAL_MACHINE
7_Key=Software\Microsoft\Windows\CurrentVersion\RunOnce
7_Name=RavStub
7_Value="e:\新建文件夹\rising\rav\ravstub.exe" /runonce
7_FileSize=90112
7_FileDate=2006-8-16 17:12:17
7_FileVersion=18.0.0.16
8_HKey=HKEY_LOCAL_MACHINE
8_Key=Software\Microsoft\Windows NT\CurrentVersion\Windows
8_Name=load
8_Value=
9_HKey=HKEY_CURRENT_USER
9_Key=Software\Microsoft\Windows\CurrentVersion\Run
9_Name=ctfmon.exe
9_Value=c:\windows\system32\ctfmon.exe
9_FileSize=15360
9_FileDate=2004-8-17 12:00:00
9_FileVersion=5.1.2600.2180
10_HKey=HKEY_CURRENT_USER
10_Key=Software\Microsoft\Windows NT\CurrentVersion\Windows
10_Name=load
10_Value=
Max=10
[ModuleUsage]
1_HKey=HKEY_LOCAL_MACHINE
1_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/Program Files/QQ2006/mfc42.dll
1_Name=.Owner
1_Value=Unknown Owner
1_Clsid=
1_FileName=C:\Program Files\QQ2006\mfc42.dll
1_FileSize=995383
1_FileDate=2006-2-8 11:46:02
1_FileVersion=6.0.8665.0
2_HKey=HKEY_LOCAL_MACHINE
2_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/OL2005.dll
2_Name=.Owner
2_Value={E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153}
2_Clsid=Rising Web Scan
Object2_FileName=C:\WINDOWS\Downloaded Program Files\OL2005.dll
2_FileSize=278528
2_FileDate=2006-8-30 17:14:04
2_FileVersion=18.0.0.7
3_HKey=HKEY_LOCAL_MACHINE
3_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/LegitCheckControl.DLL
3_Name=.Owner
3_Value={17492023-C23A-453E-A040-C7C580BBF700}
3_Clsid=Windows Genuine Advantage Validation Tool
3_FileName=C:\WINDOWS\system32\LegitCheckControl.DLL
3_FileSize=519944
3_FileDate=2005-8-6 15:42:52
3_FileVersion=1.5.530.0
4_HKey=HKEY_LOCAL_MACHINE
4_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/msvcrt.dll
4_Name=.Owner
4_Value=Unknown Owner
4_Clsid=
4_FileName=C:\WINDOWS\system32\msvcrt.dll
4_FileSize=343040
4_FileDate=2004-8-17 12:00:00
4_FileVersion=7.0.2600.2180
5_HKey=HKEY_LOCAL_MACHINE
5_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/olepro32.dll
5_Name=.Owner
5_Value=Unknown Owner
5_Clsid=
5_FileName=C:\WINDOWS\system32\olepro32.dll
5_FileSize=83456
5_FileDate=2004-8-17 12:00:00
5_FileVersion=5.1.2600.2180
6_HKey=HKEY_LOCAL_MACHINE
6_Key=SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/WebActivater.ocx
6_Name=.Owner
6_Value={3D8F74EE-8692-4F8F-B8D2-7522E732519E}
6_Clsid=WebActivater Control
6_FileName=C:\WINDOWS\system32\WebActivater.ocx
6_FileSize=294963
6_FileDate=2005-9-21 10:55:24
6_FileVersion=1.0.0.2
Max=6
[Process]
1_FileName=C:\WINDOWS\SYSTEM32\SMSS.EXE
1_FileSize=50688
1_FileDate=2004-8-17 12:00:00
1_FileVersion=5.1.2600.2180
2_FileName=C:\WINDOWS\SYSTEM32\WINLOGON.EXE
2_FileSize=487424
2_FileDate=2004-8-17 12:00:00
2_FileVersion=5.1.2600.2180
3_FileName=C:\WINDOWS\SYSTEM32\SERVICES.EXE
3_FileSize=108032
3_FileDate=2004-8-17 12:00:00
3_FileVersion=5.1.2600.2180
4_FileName=C:\WINDOWS\SYSTEM32\LSASS.EXE
4_FileSize=13312
4_FileDate=2004-8-17 12:00:00
4_FileVersion=5.1.2600.2180
5_FileName=C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
5_FileSize=393216
5_FileDate=2005-12-12 11:33:44
5_FileVersion=6.14.10.4124
6_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
6_FileSize=14336
6_FileDate=2004-8-17 12:00:00
6_FileVersion=5.1.2600.2180
7_FileName=E:\新建文件夹\RISING\RAV\CCENTER.EXE
7_FileSize=110592
7_FileDate=2006-8-16 17:12:21
7_FileVersion=18.0.0.3
8_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
8_FileSize=14336
8_FileDate=2004-8-17 12:00:00
8_FileVersion=5.1.2600.2180
9_FileName=E:\新建文件夹\RISING\RAV\RAVMOND.EXE
9_FileSize=233472
9_FileDate=2006-10-3 13:25:52
9_FileVersion=18.0.1.35
10_FileName=C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
10_FileSize=393216
10_FileDate=2005-12-12 11:33:44
10_FileVersion=6.14.10.4124
11_FileName=C:\WINDOWS\EXPLORER.EXE
11_FileSize=976896
11_FileDate=2004-8-17 12:00:00
11_FileVersion=6.0.2900.2180
12_FileName=E:\新建文件夹\RISING\RAV\RAVSTUB.EXE
12_FileSize=90112
12_FileDate=2006-8-16 17:12:17
12_FileVersion=18.0.0.16
13_FileName=C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
13_FileSize=57856
13_FileDate=2005-6-11 7:53:32
13_FileVersion=5.1.2600.2696
14_FileName=C:\WINDOWS\FIXCAMERA.EXE
14_FileSize=20480
14_FileDate=2005-12-6 13:08:42
14_FileVersion=1.0.0.3
15_FileName=C:\WINDOWS\TSNP2STD.EXE
15_FileSize=106496
15_FileDate=2005-11-24 17:01:06
15_FileVersion=1.1.2.4
16_FileName=C:\WINDOWS\VSNP2STD.EXE
16_FileSize=344064
16_FileDate=2005-11-23 22:00:20
16_FileVersion=1.0.3.5
17_FileName=E:\新建文件夹\RISING\RAV\RAVTASK.EXE
17_FileSize=114688
17_FileDate=2006-8-16 17:12:21
17_FileVersion=18.0.0.22
18_FileName=E:\新建文件夹\RISING\RAV\RAVMON.EXE
18_FileSize=610304
18_FileDate=2006-10-3 13:25:52
18_FileVersion=18.0.1.33
19_FileName=C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
19_FileSize=32768
19_FileDate=2004-8-17 12:00:00
19_FileVersion=5.1.2600.2180
20_FileName=C:\WINDOWS\SYSTEM32\CTFMON.EXE
20_FileSize=15360
20_FileDate=2004-8-17 12:00:00
20_FileVersion=5.1.2600.2180
21_FileName=C:\WINDOWS\SYSTEM32\SVCHOST.EXE
21_FileSize=14336
21_FileDate=2004-8-17 12:00:00
21_FileVersion=5.1.2600.2180
22_FileName=C:\PROGRA~1\KUREE\KPUPDATE.EXE
22_FileSize=88064
22_FileDate=2006-8-16 19:09:12
22_FileVersion=
23_FileName=C:\WINDOWS\SYSTEM32\REGSVR32.EXE
23_FileSize=13824
23_FileDate=2004-8-17 12:00:00
23_FileVersion=5.1.2600.2180
24_FileName=C:\PROGRA~1\YAHOO!\ASSIST~1\YLIVE.EXE
24_FileSize=65536
24_FileDate=2006-9-29 14:10:16
24_FileVersion=2.0.4.1007
25_FileName=C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\PROGRAM\THUNDER5.EXE
25_FileSize=2100736
25_FileDate=2006-8-10 14:54:10
25_FileVersion=5.3.0.220
26_FileName=E:\新建文件夹\RISING\RAV\RSAGENT.EXE
26_FileSize=106496
26_FileDate=2006-8-16 17:12:14
26_FileVersion=18.0.0.12
27_FileName=C:\WINDOWS\MSAGENT\AGENTSVR.EXE
27_FileSize=256512
27_FileDate=2004-8-17 12:00:00
27_FileVersion=2.0.0.3422
28_FileName=C:\PROGRAM FILES\QQ2006\QQ.EXE
28_FileSize=1364356
28_FileDate=2006-5-9 17:23:22
28_FileVersion=0.0.0.0
29_FileName=C:\PROGRAM FILES\QQ2006\TIMPLATFORM.EXE
29_FileSize=69632
29_FileDate=2006-4-25 16:13:36
29_FileVersion=0.3.1.8
30_FileName=E:\程序\系统优化\IEHELP.EXE
30_FileSize=737792
30_FileDate=2006-8-31 12:39:22
30_FileVersion=7.78.0.0
31_FileName=[SYSTEM PROCESS]
32_FileName=C:\WINDOWS\system32\CSRSS.EXE
32_FileSize=6144
32_FileDate=2004-8-17 12:00:00
32_FileVersion=5.1.2600.2180
33_FileName=C:\WINDOWS\system32\WDFMGR.EXE
33_FileSize=38912
33_FileDate=2005-1-28 1:36:00
33_FileVersion=5.2.3790.1230
34_FileName=C:\WINDOWS\system32\ALG.EXE
34_FileSize=44544
34_FileDate=2004-8-17 12:00:00
34_FileVersion=5.1.2600.2180
Max=34