[PID: 1764][C:\Program Files\Rising\Rav\RavStub.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1904][c:\program files\rising\rfw\RfwMain.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 70]
[c:\program files\rising\rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 31]
[c:\program files\rising\rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[c:\program files\rising\rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[c:\program files\rising\rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[c:\program files\rising\rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 956][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.8195]
[PID: 996][C:\WINDOWS\system32\muplay.exe] [N/A, N/A]
[PID: 1136][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 208][C:\WINDOWS\system32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\NvMcTray.dll] [NVIDIA Corporation, 6.14.10.8195]
[C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.10.8195]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 220][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 260][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 4]
[C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 316][C:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
[C:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 328][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3427]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 380][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1960][E:\超级兔子\MagicSet\SRIECLI.EXE] [Super Rabbit Soft, 7.93]
[E:\超级兔子\MagicSet\shlobj71.ocx] [Sky Software (http://www.ssware.com), 7, 1, 0, 0]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 1312][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3716][C:\Program Files\QQ2005\QQ.exe] [TENCENT, 0, 0, 0, 0]
[C:\Program Files\QQ2005\QQBaseClassInDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2005\QQHelperDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2005\BasicCtrlDll.dll] [Tencent, 5, 0, 200, 370]
[C:\Program Files\QQ2005\QQAPI.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2005\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\QQ2005\LoginCtrl.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2005\npkcntc.dll] [INCA Internet Co., Ltd., 2006, 6, 27, 1]
[C:\Program Files\QQ2005\npkpdb.dll] [INCA Internet Co., Ltd., 2003, 10, 1, 1]
[C:\Program Files\QQ2005\QQRes.dll] [tencent, 1, 0, 0, 1]
[C:\Program Files\QQ2005\QQMainFrame.dll] [N/A, N/A]
[C:\Program Files\QQ2005\CQQApplication.dll] [N/A, N/A]
[C:\Program Files\QQ2005\NewSkin.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2005\HostingMgr.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2005\CameraDll.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2005\MailSummary.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2005\QQSpace.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[C:\Program Files\QQ2005\QQGroupMng.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2005\GroupLive.dll] [N/A, N/A]
[C:\Program Files\QQ2005\LongConnection.dll] [tencent, 5, 0, 200, 160]
[C:\Program Files\QQ2005\UserDefinedHead.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2005\QQPlugin.dll] [N/A, N/A]
[C:\Program Files\QQ2005\QQAllInOne.dll] [N/A, N/A]
[C:\Program Files\QQ2005\SCCore.dll] [TENCENT, 2, 0, 0, 1]
[C:\Program Files\QQ2005\QQCustomFace.dll] [N/A, N/A]
[C:\Program Files\QQ2005\QQPet.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2005\QQSysMsgMng.dll] [N/A, N/A]
[C:\Program Files\QQ2005\QQConfigPlugin.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2005\QRingMng.dll] [N/A, N/A]
[C:\Program Files\QQ2005\PhoneAPI.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2005\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[C:\Program Files\QQ2005\VPortal.dll] [, 1, 0, 0, 4]
[C:\Program Files\QQ2005\QQAvatar.dll] [N/A, N/A]
[C:\Program Files\QQ2005\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\Program Files\QQ2005\QQMagicFace.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2005\QQSceneMng.dll] [N/A, N/A]
[C:\Program Files\QQ2005\BQQApplication.dll] [N/A, N/A]
[C:\Program Files\QQ2005\CommercesMng.dll] [, 1, 0, 0, 1]
[C:\Program Files\QQ2005\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
[C:\Program Files\QQ2005\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 240]
[C:\Program Files\QQ2005\QQPhoneHelper.dll] [腾讯科技(深圳)有限公司, 2, 1, 3, 30]
[PID: 3776][C:\Program Files\QQ2005\TIMPlatform.exe] [tencent, 0, 3, 1, 8]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\QQ2005\TIMProxy.dll] [tencent, 0, 3, 2, 4]
[PID: 2868][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[E:\超级兔子\MagicSet\haokanbar.dll] [Xiang Feng Technology, 2, 2, 0, 1612]
[C:\WINDOWS\system32\xunleibho_v11.dll] [Thunder Networking Technologies,LTD, 4, 6, 0, 48]
[C:\Program Files\QQ2005\QQIEHelper.dll] [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[PID: 3520][C:\Program Files\TTPlayer\TTPlayer.exe] [Alen Soft, 4, 6, 0, 0]
[C:\Program Files\TTPlayer\ttpcomm.dll] [N/A, N/A]
[C:\Program Files\TTPlayer\ttpres.dll] [Alen Soft, 4, 6, 5, 0]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 3996][E:\日志扫描工具\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
60.191.176.248 www.1aa
60.191.176.248 sd.muxy.net
60.191.176.248 qjsf.muxy.net
60.191.176.248 www.bjlmu.com
60.191.176.248 bjlmu.com
60.191.176.248 sd.muxy.net
127.0.0.1 www.idcmu.com
127.0.0.1 idcmu.com
127.0.0.1 www.123pkmu.com
127.0.0.1 www.57zt.com
127.0.0.1 www.zh-mu.com
127.0.0.1 www.1988mu.com
127.0.0.1 www.see4f.net
127.0.0.1 www.1aa
127.0.0.1 xz.1aa
127.0.0.1 www.lay0.com
127.0.0.1 bbs.vzkj.com
127.0.0.1 vzkj.com
127.0.0.1 www.vzkj.com
127.0.0.1 ww218.com
127.0.0.1 idc.ww218.com
127.0.0.1 www.ww218.com
127.0.0.1 bbs.ww218.com
127.0.0.1 bbs.dandanweb.com
127.0.0.1 mu.dandanweb.com
127.0.0.1 www.dandanweb.com
127.0.0.1 see.tgmu.com
127.0.0.1 mu.7jtop.com
127.0.0.1 www.2345w.com
127.0.0.1 www.musfw.com
127.0.0.1 www.18mu.com
127.0.0.1 18mu.com
127.0.0.1 www.350w.com
60.191.176.248 www.753mu.com
127.0.0.1 www.1943mu.com
60.191.176.248 www.852sf.com
60.191.176.248 www.951mu.com
127.0.0.1 www.zh91.com
127.0.0.1 www.1999mu.com
60.191.176.248 www.muxy.net
60.191.176.248 sf.muxy.net
60.191.176.248 muxy.net
127.0.0.1 www.xnidc.cn
127.0.0.1 xnidc.cn
127.0.0.1 www.khwl.cn
127.0.0.1 khwl.cn
60.191.176.248 1aa
60.191.176.248 753mu.com
60.191.176.248 852sf.com
60.191.176.248 951mu.com
==================================
API HOOK
N/A
==================================
[/CODE]