日志2
+ 用户登陆自运行项目
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
RTHDCPL
[AM] 32. c:\windows\rthdcpl.exe
Realtek Semiconductor Corp.
Realtek HD Audio Control Panel
.text,.data,.tls,.rdata,.idata,.edata,.rsrc,.reloc,
Alcmtr
[A ] 33. c:\windows\alcmtr.exe
Realtek Semiconductor Corp.
Realtek Azalia Audio - Event Monitor
.text,.rdata,.data,.rsrc,
HP Software Update
[AM] 34. c:\program files\hp\hp software update\hpwuschd2.exe
Hewlett-Packard
hpwuSchd Application
.text,.rdata,.data,.rsrc,
nwiz
[A ] 35. c:\windows\system32\nwiz.exe
.text,.rdata,.data,.rsrc,
runeip
[AM] 36. c:\program files\rising\antispyware\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
stup.exe
[A ] 37. c:\program files\tencent\adplus\stup.exe
Tencent
.text,.rdata,.data,.rsrc,
RfwMain
[AM] 38. d:\program. files\rising\rfw\rfwmain.exe
Beijing Rising Technology Co., Ltd.
Rising Personal FireWall Main Program
.text,.rdata,.data,.rsrc,
RavTask
[AM] 39. d:\program. files\rising\rav\ravtask.exe
Beijing Rising Technology Co., Ltd.
RavTimer
.text,.rdata,.data,.rsrc,
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 40. c:\windows\system32\bsmain.exe
Beijing Rising Technology Co., Ltd.
Rising Antivirus 2008
.text,.rdata,.data,.rsrc,.reloc,
+ 映像劫持
+ HKCR\.html
htmlfile\open\Command
[AM] 41. d:\program. files\tencent\tt\ttraveler.exe
Tencent
Tencent Traveler
.text,.rdata,.data,.rsrc,
htmlfile\TencentTraveler\Command
[AM] 41. d:\program. files\tencent\tt\ttraveler.exe
Tencent
Tencent Traveler
.text,.rdata,.data,.rsrc,
+ HKCR\.htm
htmlfile\open\Command
[AM] 41. d:\program. files\tencent\tt\ttraveler.exe
Tencent
Tencent Traveler
.text,.rdata,.data,.rsrc,
htmlfile\TencentTraveler\Command
[AM] 41. d:\program. files\tencent\tt\ttraveler.exe
Tencent
Tencent Traveler
.text,.rdata,.data,.rsrc,
+ 正在运行的进程
+ 000000d0(208) RavStub.exe
00400000[00021000]
[ M] 42. d:\program. files\rising\rav\ravstub.exe
Beijing Rising Technology Co., Ltd.
Rising RavStub
.text,.rdata,.data,.rsrc,
10000000[0001F000]
[ M] 43. d:\program. files\rising\rav\proccom.dll
Beijing Rising Technology Co., Ltd.
ProcessC Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00620000[00024000]
[ M] 44. d:\program. files\rising\rav\rscommx2.dll
Beijing Rising Technology Co., Ltd.
RsCommX2
.text,.rdata,.data,.rsrc,.reloc,
23700000[00028000]
[ M] 45. d:\program. files\rising\rav\rscommon.dll
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
009C0000[00016000]
[ M] 46. d:\program. files\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
00B10000[0000F000]
[ M] 47. d:\program. files\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
+ 0000013c(316) RfwMain.exe
00400000[0008D000]
[AM] 38. d:\program. files\rising\rfw\rfwmain.exe
Beijing Rising Technology Co., Ltd.
Rising Personal FireWall Main Program
.text,.rdata,.data,.rsrc,
7C140000[00103000]
[ M] 48. c:\windows\system32\mfc71.dll
Microsoft Corporation
MFCDLL Shared Library - Retail Version
.text,.data,.rsrc,.reloc,
7C340000[00056000]
[ M] 49. c:\windows\system32\msvcr71.dll
Microsoft Corporation
Microsoft? C Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
7C3A0000[0007B000]
[ M] 50. c:\windows\system32\msvcp71.dll
Microsoft Corporation
Microsoft? C++ Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
26600000[000B5000]
[ M] 51. d:\program. files\rising\rfw\rsguilib.dll
Beijing Rising Technology Co., Ltd.
Rising GUI Library Loader
.text,.rdata,.data,.rsrc,.reloc,
10000000[0001F000]
[ M] 52. d:\program. files\rising\rfw\proccom.dll
Beijing Rising Technology Co., Ltd.
ProcessC Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00B40000[00024000]
[ M] 53. d:\program. files\rising\rfw\rscommx2.dll
Beijing Rising Technology Co., Ltd.
RsCommX2
.text,.rdata,.data,.rsrc,.reloc,
00C80000[0000E000]
[ M] 54. d:\program. files\rising\rfw\rsappmgr.dll
Beijing Rising Technology Co., Ltd.
Rising Application Manager
.text,.rdata,.data,.rsrc,.reloc,
00CA0000[00030000]
[ M] 55. d:\program. files\rising\rfw\cfgdll.dll
Beijing Rising Technology Co., Ltd.
CfgDll
.text,.rdata,.data,.rsrc,.reloc,
23700000[00028000]
[ M] 56. d:\program. files\rising\rfw\rscommon.dll
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00EE0000[00014000]
[ M] 57. d:\program. files\rising\rfw\rfwctrl.dll
Beijing Rising Technology Co., Ltd.
RfwCtrl DLL
.text,.rdata,.data,.rsrc,.reloc,
23800000[00018000]
[ M] 58. d:\program. files\rising\rfw\rsxml.dll
Beijing Rising Technology Co., Ltd.
RsXML
.text,.rdata,.data,.rsrc,.reloc,
23900000[00040000]
[ M] 59. d:\program. files\rising\rfw\pngdll.dll
Beijing Rising Technology Co., Ltd.
Rising .Png File Loader Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
01CB0000[0001B000]
[ M] 60. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 000001a4(420) spoolsv.exe
+ 000001b8(440) Ras.exe
00400000[00160000]
[ M] 61. c:\program files\rising\antispyware\ras.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware
.text,.rdata,.data,.rsrc,
10000000[00013000]
[ M] 62. c:\program files\rising\antispyware\topsoft.dll
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware TopSoft
.text,.rdata,.data,.rsrc,.reloc,
7C140000[00103000]
[ M] 63. c:\program files\rising\antispyware\mfc71.dll
Microsoft Corporation
MFCDLL Shared Library - Retail Version
.text,.data,.rsrc,.reloc,
7C340000[00056000]
[ M] 64. c:\program files\rising\antispyware\msvcr71.dll
Microsoft Corporation
Microsoft? C Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
7C3A0000[0007B000]
[ M] 65. c:\program files\rising\antispyware\msvcp71.dll
Microsoft Corporation
Microsoft? C++ Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
00D90000[00170000]
[ M] 66. c:\windows\system32\nview.dll
.text,.rdata,.data,.idata,.rsrc,.reloc,
00FC0000[00028000]
[ M] 67. c:\windows\system32\nvwrszhc.dll
NVIDIA Corporation
NVIDIA nView Desktop and Window Manager
.rsrc,.reloc,
01040000[0001F000]
[ M] 43. d:\program. files\rising\rav\proccom.dll
Beijing Rising Technology Co., Ltd.
ProcessC Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
01060000[00024000]
[ M] 44. d:\program. files\rising\rav\rscommx2.dll
Beijing Rising Technology Co., Ltd.
RsCommX2
.text,.rdata,.data,.rsrc,.reloc,
011B0000[000BD000]
[ M] 68. c:\program files\rising\antispyware\rasgui.dll
Beijing Rising Technology Co., Ltd.
RasGUI
.text,.rdata,.data,.rsrc,.reloc,
01180000[0001B000]
[ M] 60. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 00000274(628) smss.exe
+ 000002a4(676) RTHDCPL.EXE
00400000[01027000]
[AM] 32. c:\windows\rthdcpl.exe
Realtek Semiconductor Corp.
Realtek HD Audio Control Panel
.text,.data,.tls,.rdata,.idata,.edata,.rsrc,.reloc,
72C80000[00008000]
[ M] 69. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
10000000[0001B000]
[ M] 60. c:\program files\rising\antispyware\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
027E0000[00170000]
[ M] 66. c:\windows\system32\nview.dll
.text,.rdata,.data,.idata,.rsrc,.reloc,
02A10000[00028000]
[ M] 67. c:\windows\system32\nvwrszhc.dll
NVIDIA Corporation
NVIDIA nView Desktop and Window Manager
.rsrc,.reloc,
+ 000002c8(712) csrss.exe
10000000[00016000]
[ M] 46. d:\program. files\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
035E0000[0000F000]
[ M] 47. d:\program. files\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
+ 000002e0(736) winlogon.exe
10000000[00016000]
[ M] 46. d:\program. files\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
01370000[0000F000]
[ M] 47. d:\program. files\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
72C80000[00008000]
[ M] 69. c:\windows\system32\msacm32.drv
Microsoft Corporation