1, 0, 0, 8]
[PID: 2500][F:\ruixing\Rising\Rav\Ravmond.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 43]
[F:\ruixing\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[F:\ruixing\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[F:\ruixing\Rising\Rav\rfwctrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[F:\ruixing\Rising\Rav\RsPPsys.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[F:\ruixing\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[F:\ruixing\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[F:\ruixing\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[F:\ruixing\Rising\Rav\RsLog.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[F:\ruixing\Rising\Rav\HOOKSYS.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
[F:\ruixing\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
[F:\ruixing\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[F:\ruixing\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[F:\ruixing\Rising\Rav\regmon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[F:\ruixing\Rising\Rav\HookWeb.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[F:\ruixing\Rising\Rav\MemMon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
[F:\ruixing\Rising\Rav\expscan.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[F:\ruixing\Rising\Rav\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[F:\ruixing\Rising\Rav\HookCont.dll] [Rising, 19, 0, 0, 0]
[F:\ruixing\Rising\Rav\SpamEng.dll] [N/A, 18, 0, 0, 6]
[F:\ruixing\Rising\Rav\engine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 25]
[F:\ruixing\Rising\Rav\PostTrt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[F:\ruixing\Rising\Rav\UnExe.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[F:\ruixing\Rising\Rav\ScanExec.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[F:\ruixing\Rising\Rav\ScanEx.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 40]
[F:\ruixing\Rising\Rav\ExtFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 25]
[F:\ruixing\Rising\Rav\NvFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[F:\ruixing\Rising\Rav\ScanMac.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
[F:\ruixing\Rising\Rav\ScanSct.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[F:\ruixing\Rising\Rav\Unpacker.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[F:\ruixing\Rising\Rav\ScanPack.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[F:\ruixing\Rising\Rav\RsVM.dll] [N/A, 19, 0, 0, 15]
[F:\ruixing\Rising\Rav\Uroutine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 21]
[F:\ruixing\Rising\Rav\Uscript.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 18]
[F:\ruixing\Rising\Rav\RsStore.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[F:\ruixing\Rising\Rav\ExtOLE.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[PID: 2796][F:\ruixing\Rising\Rav\RavStub.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
[F:\ruixing\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[F:\ruixing\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1792][C:\Program Files\QQ2006\QQ.EXE] [TENCENT, 0, 0, 0, 0]
[C:\Program Files\QQ2006\QQBaseClassInDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2006\QQHelperDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2006\BasicCtrlDll.dll] [Tencent, 5, 0, 200, 370]
[C:\Program Files\QQ2006\PYKer.dll] [飘云 http://www.pyqq.cn, 飘云]
[C:\Program Files\QQ2006\ipsearcher.dll] [, 1.0.0.3]
[C:\Program Files\QQ2006\QQAPI.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2006\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\QQ2006\LoginCtrl.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2006\npkcntc.dll] [INCA Internet Co., Ltd., 2006, 6, 27, 1]
[C:\Program Files\QQ2006\npkpdb.dll] [INCA Internet Co., Ltd., 2003, 10, 1, 1]
[C:\Program Files\QQ2006\QQRes.dll] [tencent, 1, 0, 0, 1]
[C:\Program Files\QQ2006\WizardCtrl.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2006\QQMainFrame.dll] [N/A, N/A]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\Program Files\QQ2006\CQQApplication.dll] [N/A, N/A]
[C:\Program Files\QQ2006\NewSkin.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2006\HostingMgr.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2006\CameraDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2006\MailSummary.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2006\QQSpace.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[C:\Program Files\QQ2006\QQGroupMng.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2006\GroupLive.dll] [N/A, N/A]
[C:\Program Files\QQ2006\UserDefinedHead.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2006\QQPlugin.dll] [N/A, N/A]
[C:\Program Files\QQ2006\QQConfigPlugin.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2006\LongConnection.dll] [tencent, 5, 0, 200, 160]
[C:\Program Files\QQ2006\QRingMng.dll] [N/A, N/A]
[C:\Program Files\QQ2006\PhoneAPI.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2006\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[C:\Program Files\QQ2006\VPortal.dll] [, 1, 0, 0, 4]
[C:\Program Files\QQ2006\QQFileTransfer.dll] [Tencent, 0, 3, 3, 5]
[C:\Program Files\QQ2006\QQAvatar.dll] [N/A, N/A]
[C:\Program Files\QQ2006\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[C:\Program Files\QQ2006\BQQApplication.dll] [N/A, N/A]
[C:\Program Files\QQ2006\QQSysMsgMng.dll] [N/A, N/A]
[C:\Program Files\QQ2006\QQSettingCtrl.dll] [, 1, 0, 0, 1]
[F:\ruixing\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\QQ2006\OEMApplication.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2006\QQAllInOne.dll] [N/A, N/A]
[C:\Program Files\QQ2006\SCCore.dll] [TENCENT, 2, 0, 0, 1]
[C:\Program Files\QQ2006\QQCustomFace.dll] [N/A, N/A]
[C:\Program Files\QQ2006\QQSceneMng.dll] [N/A, N/A]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\QQ2006\CommercesMng.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2006\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
[C:\Program Files\QQ2006\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 240]
[C:\Program Files\QQ2006\GroupConnection.dll] [Tencent, 0, 3, 3, 5]
[C:\Program Files\QQ2006\QQPhoneHelper.dll] [腾讯科技(深圳)有限公司, 2, 1, 4, 40]
[C:\Program Files\QQ2006\ImageOle.dll] [TODO: <Company name>, 1.0.0.1]
[C:\Program Files\QQ2006\qqgroupdisk.dll] [深圳腾讯科技, 2, 1, 101, 40]
[C:\Program Files\QQ2006\QQOneClick.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2006\QQZip.dll] [tencent, 0, 3, 2, 4]
[C:\Program Files\QQ2006\QQMagicFace.dll] [, 1, 0, 0, 1]
[PID: 540][C:\Program Files\QQ2006\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\QQ2006\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 3204][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[F:\ruixing\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[PID: 3456][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 3036][F:\软件 SRENG\sreng2\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
0.0.0.0 182838.com
0.0.0.0 204.177.92.68
0.0.0.0 asiafriendfinder.com
0.0.0.0 asqin123.51.net
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
0.0.0.0 www.jpbeauty.com
0.0.0.0 beautishow.com
0.0.0.0 goodmovies88.com
0.0.0.0 hothack.home.chinaren.com
0.0.0.0 hualiao.net
0.0.0.0 iplus.allyes.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 asqin123.51.net
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com