[D:\RISING\RAV\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[D:\RISING\RAV\RsCommX.dll] [rising, 18, 0, 0, 1]
[D:\RISING\RAV\rfwctrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[D:\RISING\RAV\RsPPsys.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[D:\RISING\RAV\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[D:\RISING\RAV\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[D:\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[D:\RISING\RAV\RsLog.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
[D:\RISING\RAV\HOOKSYS.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
[d:\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
[d:\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[d:\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
[D:\RISING\RAV\regmon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[D:\RISING\RAV\psapi.dll] [Microsoft Corporation, 4.00]
[D:\RISING\RAV\HookWeb.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
[D:\RISING\RAV\MemMon.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 14]
[D:\RISING\RAV\expscan.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[D:\RISING\RAV\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[D:\RISING\RAV\HookCont.dll] [Rising, 19, 0, 0, 0]
[d:\Rising\Rav\SpamEng.dll] [, 18, 0, 0, 6]
[d:\Rising\Rav\engine.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 30]
[d:\Rising\Rav\PostTrt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[d:\Rising\Rav\UnExe.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[d:\Rising\Rav\ScanExec.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[d:\Rising\Rav\ScanEx.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 66]
[d:\Rising\Rav\ExtFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
[d:\Rising\Rav\NvFile.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[d:\Rising\Rav\ScanMac.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
[d:\Rising\Rav\ScanSct.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
[d:\Rising\Rav\ExtOLE.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
[PID: 1604 / SYSTEM][d:\rising\rfw\rfwsrv.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 35]
[d:\rising\rfw\RfwRule.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 3]
[d:\rising\rfw\rfwlog.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 2]
[d:\rising\rfw\Rfwdrv.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 10]
[d:\rising\rfw\psapi.dll] [Microsoft Corporation, 4.00]
[d:\rising\rfw\MonDrv.dll] [rs, 1, 0, 0, 4]
[d:\rising\rfw\ProcLib.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 5]
[d:\rising\rfw\mPorts.dll] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[PID: 1732 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1956 / Administrator][d:\rising\rfw\RfwMain.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 72]
[d:\rising\rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[d:\rising\rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[d:\rising\rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[d:\rising\rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[d:\rising\rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[D:\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 160 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.8265]
[PID: 192 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 292 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 1376 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1340 / Administrator][D:\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[D:\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[D:\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[D:\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[D:\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[D:\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2052 / Administrator][D:\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 45]
[D:\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[D:\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[D:\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[D:\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[D:\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[D:\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[D:\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[D:\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[D:\360safe\safemon\safemon.dll] [, 3, 5, 0, 1001]
[D:\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2084 / Administrator][D:\360safe\safemon\360Tray.exe] [奇虎网, 3, 5, 2, 1001]
[D:\360safe\safemon\safemon.dll] [, 3, 5, 0, 1001]
[D:\360safe\safemon\SafeKrnl.dll] [奇虎网, 3, 5, 0, 1001]
[D:\360safe\AntiAdwa.dll] [360Safe.com, 3, 5, 1, 1001]
[D:\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2168 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 212 / Administrator][d:\Rising\KakaToolBar\runiep.exe] [Beijing Rising Technology Co., Ltd., 4.0.0.15]
[D:\360safe\safemon\safemon.dll] [, 3, 5, 0, 1001]
[d:\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1320 / Administrator][d:\Rising\KakaToolBar\Ras.exe] [Beijing Rising Technology Co., Ltd., 4.0.0.51]
[D:\360safe\safemon\safemon.dll] [, 3, 5, 0, 1001]
[d:\Rising\KakaToolBar\RasGui.dll] [Beijing Rising Technology Co., Ltd., 2, 0, 0, 11]
[D:\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[d:\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 2888 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\360safe\safemon\safemon.dll] [, 3, 5, 0, 1001]
[d:\Tencent\QQDownload\QQIEHelper02.dll] [腾讯公司, 1, 1, 0, 5]
[C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 1]
[D:\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[d:\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx] [Macromedia, Inc., 8,0,24,0]
[PID: 2536 / Administrator][F:\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[D:\360safe\safemon\safemon.dll] [, 3, 5, 0, 1001]
[D:\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[F:\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
59.54.54.169 www.178rxjh.com
59.54.54.169 178rxjh.com
59.54.54.169 www.molisf.com
59.54.54.169 molisf.com
59.54.54.169 www.1717rxjh.cn
59.54.54.169 1717rxjh.cn
59.54.54.169 www.73473.com
59.54.54.169 73473.com
59.54.54.169 www.7rxjh.com
59.54.54.169 7rxjh.com
59.54.54.169 www.9i45.com
59.54.54.169 9i45.com
59.54.54.169 ww.rxjh4f.com.cn
59.54.54.169 rxjh4f.com.cn
59.54.54.169 www.uc177.com
59.54.54.169 uc177.com
59.54.54.169 www.496529.cn
59.54.54.169 496529.cn
59.54.54.169 www.999rxjh.com
59.54.54.169 999rxjh.com
59.54.54.169 www.52rxsf.com
59.54.54.169 52rxsf.com
59.54.54.169 www.jhsss.com
59.54.54.169 jhsss.com
59.54.54.169 www.wanrxjh.com
59.54.54.169 wanrxjh.com
59.54.54.169 www.920rxjh.com
59.54.54.169 920rxjh.com
59.54.54.169 www.sf377.com
59.54.54.169 sf377.com
59.54.54.169 www.xksf888.com
59.54.54.169 xksf888.com
59.54.54.169 www.14455.com
59.54.54.169 www.97wow.com
59.54.54.169 97wow.com
59.54.54.169 www.173woool.com.cn
59.54.54.169 73woool.com.cn
59.54.54.169 73woool.com.cn
59.54.54.169 ww.sfmir2.com
59.54.54.169 sfmir2.com
59.54.54.169 www.rx592.com
59.54.54.169 rx592.com
59.54.54.169 www.yxdao.net
59.54.54.169 yxdao.net
59.54.54.169 www.molisf.com
59.54.54.169 molisf.com
59.54.54.169 www.molisf.com
59.54.54.169 molisf.com
59.54.54.169 变态热血江湖
59.54.54.169 热血江湖
59.54.54.169 热血江湖私服
59.54.54.169 热血江湖SF
59.54.54.169 热血江湖发布
59.54.54.169 送元宝热血江湖
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 2084, D:\360SAFE\SAFEMON\360TRAY.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 212, D:\RISING\KAKATOOLBAR\RUNIEP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 212, D:\RISING\KAKATOOLBAR\RUNIEP.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1320, D:\RISING\KAKATOOLBAR\RAS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1320, D:\RISING\KAKATOOLBAR\RAS.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]