第五部分日志
[PID: 1640][E:\Program Files\Rising\Rfw\rfwmain.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 56]
[E:\Program Files\Rising\Rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
[E:\Program Files\Rising\Rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[E:\Program Files\Rising\Rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[E:\Program Files\Rising\Rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[E:\Program Files\Rising\Rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[C:\DOCUME~1\sailor\LOCALS~1\Temp\Ztgx.dll] [N/A, N/A]
[C:\DOCUME~1\sailor\LOCALS~1\Temp\Mhgx.dll] [N/A, N/A]
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] [CNNIC, 2, 1, 0, 3]
[C:\WINDOWS\system32\dllwm.dll] [N/A, N/A]
[PID: 1676][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[PID: 1244][E:\Program Files\TM\TMDlls\TM.exe] [N/A, N/A]
[E:\Program Files\TM\CoralAssist.DLL] [Coral Team, 4.5.0 build 20060515]
[E:\Program Files\TM\CoralQQ.DLL] [Coral Team, 4.5.4 Build 20061001]
[E:\Program Files\TM\ipsearcher.dll] [N/A, 1.0.0.4]
[E:\Program Files\TM\TMDlls\BasicCtrlDll.dll] [Tencent, 0, 3, 3, 9]
[E:\Program Files\TM\TMDlls\QQHelperDll.dll] [, 1, 0, 0, 1]
[E:\Program Files\TM\TMDlls\QQZip.dll] [tencent, 0, 3, 2, 4]
[E:\Program Files\TM\TMDlls\QQBaseClassInDll.dll] [, 1, 0, 0, 1]
[E:\Program Files\TM\TMDlls\BaseUIClass.dll] [, 1, 0, 0, 1]
[E:\Program Files\TM\TMDlls\ImageOle.dll] [TODO: <Company name>, 1.0.0.1]
[E:\Program Files\TM\TMDlls\QQAPI.dll] [, 1, 0, 0, 1]
[E:\Program Files\TM\TMDlls\QQRes.dll] [N/A, N/A]
[E:\Program Files\TM\TMDlls\LoginCtrl.dll] [, 1, 0, 0, 1]
[E:\Program Files\TM\TMDlls\npkcntc.dll] [INCA Internet Co., Ltd., 2005, 9, 1, 1]
[E:\Program Files\TM\TMDlls\npkpdb.dll] [INCA Internet Co., Ltd., 2003, 10, 1, 1]
[E:\Program Files\TM\TMDlls\HostingMgr.dll] [, 1, 0, 0, 1]
[E:\Program Files\TM\TMDlls\WizardCtrl.dll] [Tencent, 1, 0, 0, 1]
[E:\Program Files\TM\TMDlls\QQMainFrame.dll] [TENCENT, 1, 0, 0, 1]
[E:\Program Files\TM\TMDlls\NewSkin.dll] [, 1, 0, 0, 1]
[E:\Program Files\TM\TMDlls\CQQApplication.dll] [N/A, N/A]
[E:\Program Files\TM\TMDlls\FrameBar.dll] [, 1, 0, 0, 1]
[E:\Program Files\TM\TMDlls\UserRelationWeight.dll] [, 1, 0, 0, 1]
[E:\Program Files\TM\TMDlls\QQConfigPlugin.dll] [, 1, 0, 0, 1]
[E:\Program Files\TM\TMDlls\CameraDll.dll] [, 1, 0, 0, 1]
[E:\Program Files\TM\TMDlls\QQGroupMng.dll] [, 1, 0, 0, 1]
[E:\Program Files\TM\TMDlls\QQAllInOne.dll] [N/A, N/A]
[E:\Program Files\TM\TMDlls\CommercesMng.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[E:\Program Files\TM\TMDlls\MiscCtrl.dll] [, 1, 0, 0, 1]
[E:\Program Files\TM\TMDlls\LongConnection.dll] [tencent, 0, 3, 3, 8]
[E:\Program Files\TM\TMDlls\QQSpace.dll] [, 1, 0, 0, 1]
[E:\Program Files\TM\TMDlls\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 0, 3, 0, 43]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 1, 5, 0, 0]
[E:\安装文件\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31]
[E:\Program Files\TM\TMDlls\GroupConnection.dll] [Tencent, 0, 3, 3, 5]
[E:\Program Files\TM\TMDlls\VqqModule.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[E:\Program Files\TM\TMDlls\RemoteHelp.dll] [, 1, 0, 0, 1]
[E:\Program Files\TM\TMDlls\QQFileTransfer.dll] [Tencent, 0, 3, 3, 5]
[E:\Program Files\TM\TMDlls\inplus.dll] [Tencent, 1.5.0.0]
[E:\Program Files\TM\TMDlls\ShareFiles.dll] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] [CNNIC, 2, 1, 0, 3]
[C:\DOCUME~1\sailor\LOCALS~1\Temp\Ztgx.dll] [N/A, N/A]
[C:\DOCUME~1\sailor\LOCALS~1\Temp\Mhgx.dll] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] [CNNIC, 2, 1, 0, 3]
[PID: 1956][C:\DOCUME~1\sailor\LOCALS~1\Temp\MjjiIs.exe] [N/A, N/A]
[PID: 852][C:\DOCUME~1\sailor\LOCALS~1\Temp\xnhuQD.exe] [N/A, N/A]
[PID: 1852][C:\DOCUME~1\sailor\LOCALS~1\Temp\esMOrT.exe] [N/A, N/A]
[C:\DOCUME~1\sailor\LOCALS~1\Temp\wlzs.dll] [N/A, N/A]
[PID: 372][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[PID: 1628][C:\DOCUME~1\sailor\LOCALS~1\Temp\KatWIR.exe] [N/A, N/A]
[PID: 1336][C:\DOCUME~1\sailor\LOCALS~1\Temp\xvYMql.exe] [N/A, N/A]
[PID: 860][C:\DOCUME~1\sailor\LOCALS~1\Temp\XtKJLD.exe] [N/A, N/A]
[PID: 1984][C:\DOCUME~1\sailor\LOCALS~1\Temp\mh2\iexpl0re.EXE] [N/A, N/A]
[C:\DOCUME~1\sailor\LOCALS~1\Temp\Mhgx.dll] [N/A, N/A]
[PID: 940][C:\DOCUME~1\sailor\LOCALS~1\Temp\Zt2\SVCH0ST.EXE] [N/A, N/A]
[C:\DOCUME~1\sailor\LOCALS~1\Temp\Ztgx.dll] [N/A, N/A]
[PID: 1432][C:\DOCUME~1\sailor\LOCALS~1\Temp\vJXWOj.exe] [N/A, N/A]
[PID: 412][C:\DOCUME~1\sailor\LOCALS~1\Temp\nfrBxX.exe] [N/A, N/A]
[PID: 492][C:\DOCUME~1\sailor\LOCALS~1\Temp\UVlppo.exe] [N/A, N/A]
[PID: 1584][C:\Program Files\CNNIC\Cdn\cdnup.exe] [CNNIC, 2, 5, 0, 6]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[C:\Program Files\CNNIC\Cdn\cdnuplib.dll] [CNNIC, 2, 5, 0, 5]
[C:\Program Files\CNNIC\Cdn\cdnprh.dll] [CNNIC, 2, 4, 0, 3]
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] [CNNIC, 2, 1, 0, 3]
[PID: 308][C:\WINDOWS\system32\NOTEPAD.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] [CNNIC, 2, 1, 0, 3]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[C:\DOCUME~1\sailor\LOCALS~1\Temp\Ztgx.dll] [N/A, N/A]
[C:\DOCUME~1\sailor\LOCALS~1\Temp\Mhgx.dll] [N/A, N/A]
[PID: 1264][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] [CNNIC, 2, 1, 0, 3]
[C:\Program Files\CNNIC\Cdn\cdnuplib.dll] [CNNIC, 2, 5, 0, 5]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[e:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_006.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 3]
[C:\DOCUME~1\sailor\LOCALS~1\Temp\Ztgx.dll] [N/A, N/A]
[C:\DOCUME~1\sailor\LOCALS~1\Temp\Mhgx.dll] [N/A, N/A]
[e:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\SOGOUPY.IME] [Sohu.com Inc., 1, 5, 0, 0]
[E:\安装文件\SogouInput\Plugin\SgImeWord.dll] [, 1, 0, 0, 31]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[C:\WINDOWS\system32\dllwm.dll] [N/A, N/A]
[PID: 1248][C:\DOCUME~1\sailor\LOCALS~1\Temp\EhgfUx.exe] [N/A, N/A]
[C:\DOCUME~1\sailor\LOCALS~1\Temp\zts2.dll] [N/A, N/A]
[PID: 368][C:\DOCUME~1\sailor\LOCALS~1\Temp\ApUHYG.exe] [N/A, N/A]
[C:\DOCUME~1\sailor\LOCALS~1\Temp\mhs2.dll] [N/A, N/A]
[PID: 1492][C:\DOCUME~1\sailor\LOCALS~1\Temp\xoZnxx.exe] [N/A, N/A]
[C:\DOCUME~1\sailor\LOCALS~1\Temp\rxzs.dll] [N/A, N/A]
[PID: 1176][C:\DOCUME~1\sailor\LOCALS~1\Temp\PYRYAD.exe] [N/A, N/A]
[PID: 3184][C:\DOCUME~1\sailor\LOCALS~1\Temp\HNmDWh.exe] [N/A, N/A]
[PID: 3192][C:\DOCUME~1\sailor\LOCALS~1\Temp\CMxPUP.exe] [N/A, N/A]
[PID: 3200][C:\DOCUME~1\sailor\LOCALS~1\Temp\XUnHLt.exe] [N/A, N/A]
[PID: 3216][C:\DOCUME~1\sailor\LOCALS~1\Temp\shWZct.exe] [N/A, N/A]
[PID: 2004][C:\DOCUME~1\sailor\LOCALS~1\Temp\KlPLSq.exe] [N/A, N/A]
[PID: 1552][C:\DOCUME~1\sailor\LOCALS~1\Temp\nwHfDA.exe] [N/A, N/A]
[PID: 2416][C:\DOCUME~1\sailor\LOCALS~1\Temp\uZcNbz.exe] [N/A, N/A]
[PID: 2260][C:\DOCUME~1\sailor\LOCALS~1\Temp\dpqIyl.exe] [N/A, N/A]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[PID: 2304][C:\Program Files\svhost32.exe] [N/A, N/A]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\DOCUME~1\sailor\LOCALS~1\Temp\g.dll] [N/A, N/A]
[C:\WINDOWS\system32\dllwm.dll] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[PID: 3544][C:\Documents and Settings\sailor\桌面\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] [CNNIC, 2, 1, 0, 3]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[C:\WINDOWS\system32\dllwm.dll] [N/A, N/A]
[C:\DOCUME~1\sailor\LOCALS~1\Temp\Ztgx.dll] [N/A, N/A]
[C:\DOCUME~1\sailor\LOCALS~1\Temp\Mhgx.dll] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]