Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RSDTRAY' = '"%PROGRAM_FILES%\Rising\RSD\popwndexe.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\rsutils] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\Defense] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\sysmon] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\RsMgrSvc] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\rsdsys] 'Start' = '00000002'
- '%PROGRAM_FILES%\Rising\RSD\popwndexe.exe'
- '%PROGRAM_FILES%\Rising\RSD\RsMgrSvc.exe'
- '%TEMP%\RsdSfxTmp\Setup.exe' /S
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVMON\mondcoms.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVMON\RAVMON.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSDK\RSDK.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVMON\mond.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\MONBASEDUI\rscombas.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\MONBASEDUI\ravmond.exe
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\MONBASEDUI\MONBASEDUI.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\MONBASEDUI\moncomm.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\MONBASEDUI\rssrv.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSDK\rsxml3a.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\MSCRT9\MSCRT9.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSDK\rscom.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\MSCRT9\msvcp90.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\MSCRT9\msvcr90.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSDK\procenv.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSDK\comx3.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSDK\rsxml3w.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSDK\traywnd.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSDK\dfw.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAV936\lics936.txt
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVBASE\Repair.url
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVBASE\rspalvd.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVBASE\setup.dat
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVBASE\url.ini
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVBASE\pngdll.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVCONFIG\ravcfg.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVCONFIG\mergexml.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVBASE\RsSmall.bmp
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVBASE\RAVBASE.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVBASE\rstask.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVBASE\RavSetup.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVBASE\RsTray.ico
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAV936\chs.lag
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAV936\RAV936.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVBASE\Rising.ico
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVBASE\LogAc.bmp
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVBASE\LogDc.bmp
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVBASE\RsMain.ico
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVBASE\RAV.ico
- %PROGRAM_FILES%\Rising\RSD\popwndexe.exe
- %PROGRAM_FILES%\Rising\RSD\localopt.dll
- %PROGRAM_FILES%\Rising\RSD\RSD1252\Eng.lag
- %PROGRAM_FILES%\Rising\RSD\RSD932\Jpn.lag
- %PROGRAM_FILES%\Rising\RSD\rsmginfo.dll
- %PROGRAM_FILES%\Rising\RSD\XMLS\RSSetup.xml
- %PROGRAM_FILES%\Rising\RSD\RsMgrsvc.ini
- %PROGRAM_FILES%\Rising\RSD\rsdk.dll
- %PROGRAM_FILES%\Rising\RSD\ui\snin.htm
- %PROGRAM_FILES%\Rising\RSD\RSD950\CHT.lag
- %PROGRAM_FILES%\Rising\RSD\setup.dat
- %PROGRAM_FILES%\Rising\RSD\comx3.dll
- %PROGRAM_FILES%\Rising\RSD\RsMgrSvc.exe
- %PROGRAM_FILES%\Rising\RSD\RsBackup.exe
- %PROGRAM_FILES%\Rising\RSD\syslay.dll
- %PROGRAM_FILES%\Rising\RSD\rsdinfo.dll
- %PROGRAM_FILES%\Rising\RSD\RSD936\CHS.lag
- <DRIVERS>\protreg.sys
- %PROGRAM_FILES%\Rising\RSD\update.xml
- %PROGRAM_FILES%\Rising\RSD\RsMgrSvc.dat
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\HOOKBASE\hookbase.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\HOOKBASE\HOOKBASE.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\HOOKBASE\64\rsndisp.sys
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\HOOKBASE\rsndisp.sys
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\LICENSE\12345678.000
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\MSCRT9\Microsoft.VC90.ATL.manifest
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\MSCRT9\Microsoft.VC90.CRT.manifest
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\LICENSE\LICENSE.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\MSCRT9\atl90.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\HOOKBASE\rsutils_if.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\_RAV\_RAV.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\HOOKBASE\mondrv.dll
- %PROGRAM_FILES%\Rising\RSD\Data\RAV\RAV.ini
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\_RAV\setup.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\HOOKBASE\64\sysmon.sys
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\HOOKBASE\64\rsutils.sys
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\HOOKBASE\rsutils.sys
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\HOOKBASE\sysmon_if.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\HOOKBASE\sysmon.sys
- <DRIVERS>\rsndisp.sys
- %PROGRAM_FILES%\Rising\RZC\hookbase.dll
- <DRIVERS>\rsutils.sys
- %PROGRAM_FILES%\Rising\RZC\rsutils_if.dll
- %PROGRAM_FILES%\Rising\RZC\XMLS\HOOKBASE.xml
- %PROGRAM_FILES%\Rising\RZC\atl90.dll
- %PROGRAM_FILES%\Rising\RZC\Microsoft.VC90.ATL.manifest
- %PROGRAM_FILES%\Rising\RZC\12345678.000
- %PROGRAM_FILES%\Rising\RZC\XMLS\LICENSE.xml
- <DRIVERS>\sysmon.sys
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\CompsVer.inf
- %PROGRAM_FILES%\Rising\RZC\Label.dat
- %TEMP%\RsPcVer12.xml.rs
- %PROGRAM_FILES%\Rising\RZC\CompsVer.inf
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\Label.dat
- %PROGRAM_FILES%\Rising\RZC\mondrv.dll
- %PROGRAM_FILES%\Rising\RZC\sysmon_if.dll
- %PROGRAM_FILES%\Rising\RZC\XMLS\setup.xml
- %PROGRAM_FILES%\Rising\RZC\XMLS\_RAV.xml
- %PROGRAM_FILES%\Rising\RZC\Microsoft.VC90.CRT.manifest
- %PROGRAM_FILES%\Rising\RZC\cfgxml\mondcoms.xml
- %PROGRAM_FILES%\Rising\RZC\XMLS\RAVMON.xml
- %PROGRAM_FILES%\Rising\RZC\XMLS\RSDK.xml
- %PROGRAM_FILES%\Rising\RZC\cfgxml\mond.xml
- %PROGRAM_FILES%\Rising\RZC\rscombas.dll
- %PROGRAM_FILES%\Rising\RZC\rsDefense.exe
- %PROGRAM_FILES%\Rising\RZC\XMLS\MONBASEDUI.xml
- %PROGRAM_FILES%\Rising\RZC\moncomm.dll
- %PROGRAM_FILES%\Rising\RZC\rssrv.dll
- %PROGRAM_FILES%\Rising\RZC\rsxml3a.dll
- %PROGRAM_FILES%\Rising\RZC\XMLS\MSCRT9.xml
- %PROGRAM_FILES%\Rising\RZC\rscom.dll
- %PROGRAM_FILES%\Rising\RZC\msvcp90.dll
- %PROGRAM_FILES%\Rising\RZC\msvcr90.dll
- %PROGRAM_FILES%\Rising\RZC\procenv.dll
- %PROGRAM_FILES%\Rising\RZC\comx3.dll
- %PROGRAM_FILES%\Rising\RZC\rsxml3w.dll
- %PROGRAM_FILES%\Rising\RZC\traywnd.dll
- %PROGRAM_FILES%\Rising\RZC\dfw.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSCOMM\syslay.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSCOMM\moncom08.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSCOMM\Proccom.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSCOMM\Proccomm.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSCOMM\rscommx2.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSCOMM\RSCOMM.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVXP\ravxp.exe
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSCOMM\rssqlite.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSCOMM\RsBaseNetWrapper.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSCOMM\cnt08.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSCFG\RSCFG.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVLOG\rslog.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVCONFIG\RAVCONFIG.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSCFG\rscfg.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVLOG\RAVLOG.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVMAINDUI\RAVMAINDUI.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSCOMM\cnt09.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVMAINDUI\rsmain.exe
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVMAINDUI\rsmain.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVXP\RAVXP.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSMONDEF\bawhite.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSMONDEF\bawhite.dat
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSMONDEF\x64\adefmon.mond
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSMONDEF\monrule.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSMONDEF\RSMONDEF.xml
- %ALLUSERSPROFILE%\Application Data\Rising\RZC\language.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\RsPcVer12[1].xml
- %PROGRAM_FILES%\Rising\RZC\NetConfig.ini
- %ALLUSERSPROFILE%\Application Data\Rising\RZC\RAV.ini
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSMONDEF\adefmon.mond
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVDEFDB\mondef.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVDEFDB\uprsmon.dat
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVDEFDB\rsmon.db1
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVDEFDB\rsuser.db1
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVDEFDB\uprsuser.dat
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSMONDEF\bacore.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSMONDEF\defmon.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RAVDEFDB\RAVDEFDB.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RAV\RSMONDEF\selfmon.dll
- %TEMP%\RsdSfxTmp\rav936\chs.lag
- %TEMP%\RsdSfxTmp\RSD950\CHT.lag
- %TEMP%\RsdSfxTmp\CompsVer.inf
- %TEMP%\RsdSfxTmp\RSD936\CHS.lag
- %TEMP%\RsdSfxTmp\RSD1252\Eng.lag
- %TEMP%\RsdSfxTmp\rsmondef\x64\adefmon.mond
- %TEMP%\RsdSfxTmp\ravbase\Repair.url
- %TEMP%\RsdSfxTmp\RSD932\Jpn.lag
- %TEMP%\RsdSfxTmp\rsmondef\adefmon.mond
- %TEMP%\RsdSfxTmp\ravdefdb\rsuser.db1
- %TEMP%\RsdSfxTmp\rsmondef\bawhite.dat
- %TEMP%\RsdSfxTmp\label.dat
- %TEMP%\RsdSfxTmp\ravbase\url.ini
- %TEMP%\RsdSfxTmp\license\12345678.000
- %TEMP%\RsdSfxTmp\setup.dat
- %TEMP%\RsdSfxTmp\ravdefdb\uprsuser.dat
- %TEMP%\RsdSfxTmp\ravdefdb\rsmon.db1
- %TEMP%\RsdSfxTmp\ravbase\setup.dat
- %TEMP%\RsdSfxTmp\ravdefdb\uprsmon.dat
- %TEMP%\RsdSfxTmp\popwndexe.exe
- %TEMP%\RsdSfxTmp\rscomm\cnt08.dll
- %TEMP%\RsdSfxTmp\rscomm\cnt09.dll
- %TEMP%\RsdSfxTmp\rsmondef\bawhite.dll
- %TEMP%\RsdSfxTmp\CfgDll.dll
- %TEMP%\RsdSfxTmp\comx3.dll
- %TEMP%\RsdSfxTmp\rsdk\dfw.dll
- %TEMP%\RsdSfxTmp\hookbase\hookbase.dll
- %TEMP%\RsdSfxTmp\rsdk\comx3.dll
- %TEMP%\RsdSfxTmp\rsmondef\defmon.dll
- %TEMP%\RsdSfxTmp\rsmondef\bacore.dll
- %TEMP%\RsdSfxTmp\RsBackup.exe
- %TEMP%\RsdSfxTmp\ravmaindui\rsmain.exe
- %TEMP%\RsdSfxTmp\monbasedui\ravmond.exe
- %TEMP%\RsdSfxTmp\ravxp\ravxp.exe
- %TEMP%\RsdSfxTmp\RsMgrSvc.exe
- %TEMP%\RsdSfxTmp\updater.exe
- %TEMP%\RsdSfxTmp\mscrt9\atl90.dll
- %TEMP%\RsdSfxTmp\RsStub.exe
- %TEMP%\RsdSfxTmp\Setup.exe
- %TEMP%\RsdSfxTmp\license\license.xml
- %TEMP%\RsdSfxTmp\monbasedui\monbasedui.xml
- %TEMP%\RsdSfxTmp\Custom.xml
- %TEMP%\RsdSfxTmp\hookbase\hookbase.xml
- %TEMP%\RsdSfxTmp\ravmon\mond.xml
- %TEMP%\RsdSfxTmp\os.xml
- %TEMP%\RsdSfxTmp\rav936\rav936.xml
- %TEMP%\RsdSfxTmp\ravmon\mondcoms.xml
- %TEMP%\RsdSfxTmp\mscrt9\mscrt9.xml
- %TEMP%\RsdSfxTmp\mscrt9\Microsoft.VC90.CRT.manifest
- %TEMP%\RsdSfxTmp\ravbase\LogDc.bmp
- %TEMP%\RsdSfxTmp\ravbase\RsSmall.bmp
- %TEMP%\RsdSfxTmp\Rav.7z
- %TEMP%\RsdSfxTmp\ravbase\LogAc.bmp
- %TEMP%\RsdSfxTmp\ravbase\RAV.ico
- %TEMP%\RsdSfxTmp\ravbase\RsTray.ico
- %TEMP%\RsdSfxTmp\mscrt9\Microsoft.VC90.ATL.manifest
- %TEMP%\RsdSfxTmp\ravbase\Rising.ico
- %TEMP%\RsdSfxTmp\ravbase\RsMain.ico
- %TEMP%\RsdSfxTmp\ravbase\ravbase.xml
- %TEMP%\RsdSfxTmp\ravbase\rstask.xml
- %TEMP%\RsdSfxTmp\_rav\setup.xml
- %TEMP%\RsdSfxTmp\rsmondef\rsmondef.xml
- %TEMP%\RsdSfxTmp\RSSETUP.xml
- %TEMP%\RsdSfxTmp\update.xml
- %TEMP%\RsdSfxTmp\rav936\lics936.txt
- %TEMP%\RsdSfxTmp\Auto.ini
- %TEMP%\RsdSfxTmp\_rav\_rav.xml
- %TEMP%\RsdSfxTmp\ui\snin.htm
- %TEMP%\RsdSfxTmp\rsdk\rsdk.xml
- %TEMP%\RsdSfxTmp\ravdefdb\ravdefdb.xml
- %TEMP%\RsdSfxTmp\ravlog\ravlog.xml
- %TEMP%\RsdSfxTmp\ravconfig\ravcfg.xml
- %TEMP%\RsdSfxTmp\ravconfig\ravconfig.xml
- %TEMP%\RsdSfxTmp\ravmaindui\ravmaindui.xml
- %TEMP%\RsdSfxTmp\rscfg\rscfg.xml
- %TEMP%\RsdSfxTmp\rscomm\rscomm.xml
- %TEMP%\RsdSfxTmp\ravmon\ravmon.xml
- %TEMP%\RsdSfxTmp\ravxp\ravxp.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\updater.exe
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\RsStub.exe
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\CfgDll.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\Setup.exe
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\RsMgrSvc.exe
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\comx3.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\syslay.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\RsBackup.exe
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\setup.dat
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\RsAppMgr.dll
- %TEMP%\RsdSfxTmp\hookbase\rsutils.sys
- %TEMP%\RsdSfxTmp\hookbase\64\sysmon.sys
- %TEMP%\RsdSfxTmp\hookbase\rsndisp.sys
- %TEMP%\RsdSfxTmp\hookbase\64\rsutils.sys
- %TEMP%\RsdSfxTmp\hookbase\sysmon.sys
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\os.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\rslang.dll
- %PROGRAM_FILES%\RsTest.ini
- %TEMP%\RAV.cfg
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\protreg.sys
- %PROGRAM_FILES%\Rising\RSD\os.xml
- %PROGRAM_FILES%\Rising\RSD\rslang.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\ui\snin.htm
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\RSSetup.xml
- %PROGRAM_FILES%\Rising\RSD\RsAppMgr.dll
- %PROGRAM_FILES%\Rising\RSD\updater.exe
- %PROGRAM_FILES%\Rising\RSD\RsStub.exe
- %PROGRAM_FILES%\Rising\RSD\CfgDll.dll
- %PROGRAM_FILES%\Rising\RSD\Setup.exe
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\rsdk.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\RSD936\CHS.lag
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\RSD950\CHT.lag
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\update.xml
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\rsdinfo.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\RSD1252\Eng.lag
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\localopt.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\rsmginfo.dll
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\RSD932\Jpn.lag
- %PROGRAM_FILES%\Rising\RSD\Backup\RSD\RSSetup\popwndexe.exe
- %TEMP%\RsdSfxTmp\rsdk\procenv.dll
- %TEMP%\RsdSfxTmp\ravbase\RavSetup.dll
- %TEMP%\RsdSfxTmp\rscomm\Proccom.dll
- %TEMP%\RsdSfxTmp\rscomm\Proccomm.dll
- %TEMP%\RsdSfxTmp\RsAppMgr.dll
- %TEMP%\RsdSfxTmp\rsdk\rscom.dll
- %TEMP%\RsdSfxTmp\monbasedui\rscombas.dll
- %TEMP%\RsdSfxTmp\rscomm\RsBaseNetWrapper.dll
- %TEMP%\RsdSfxTmp\rscfg\rscfg.dll
- %TEMP%\RsdSfxTmp\ravbase\pngdll.dll
- %TEMP%\RsdSfxTmp\rscomm\moncom08.dll
- %TEMP%\RsdSfxTmp\monbasedui\moncomm.dll
- %TEMP%\RsdSfxTmp\localopt.dll
- %TEMP%\RsdSfxTmp\ravconfig\mergexml.dll
- %TEMP%\RsdSfxTmp\ravdefdb\mondef.dll
- %TEMP%\RsdSfxTmp\mscrt9\msvcp90.dll
- %TEMP%\RsdSfxTmp\mscrt9\msvcr90.dll
- %TEMP%\RsdSfxTmp\hookbase\mondrv.dll
- %TEMP%\RsdSfxTmp\rsmondef\monrule.dll
- %TEMP%\RsdSfxTmp\rscomm\rscommx2.dll
- %TEMP%\RsdSfxTmp\rsmondef\selfmon.dll
- %TEMP%\RsdSfxTmp\syslay.dll
- %TEMP%\RsdSfxTmp\rsdk\rsxml3a.dll
- %TEMP%\RsdSfxTmp\rsdk\rsxml3w.dll
- %TEMP%\RsdSfxTmp\rscomm\syslay.dll
- %TEMP%\RsdSfxTmp\protreg.sys
- %TEMP%\RsdSfxTmp\hookbase\64\rsndisp.sys
- %TEMP%\RsdSfxTmp\hookbase\sysmon_if.dll
- %TEMP%\RsdSfxTmp\rsdk\traywnd.dll
- %TEMP%\RsdSfxTmp\hookbase\rsutils_if.dll
- %TEMP%\RsdSfxTmp\rslang.dll
- %TEMP%\RsdSfxTmp\ravlog\rslog.dll
- %TEMP%\RsdSfxTmp\rsdinfo.dll
- %TEMP%\RsdSfxTmp\rsdk.dll
- %TEMP%\RsdSfxTmp\ravmaindui\rsmain.dll
- %TEMP%\RsdSfxTmp\rscomm\rssqlite.dll
- %TEMP%\RsdSfxTmp\monbasedui\rssrv.dll
- %TEMP%\RsdSfxTmp\rsmginfo.dll
- %TEMP%\RsdSfxTmp\ravbase\rspalvd.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\RsPcVer12[1].xml
- %TEMP%\RsPcVer12.xml
- %TEMP%\RAV.cfg
- %TEMP%\RsdSfxTmp\Rav.7z
- %PROGRAM_FILES%\RsTest.ini
- from %TEMP%\RAV.cfg.tmp to %TEMP%\RAV.cfg
- from %TEMP%\RsPcVer12.xml.rs to %TEMP%\RsPcVer12.xml
- from %TEMP%\RsdSfxTmp\license\12345678.000 to %TEMP%\RsdSfxTmp\license\12345678.000.bak
- from %TEMP%\RAV.cfg to %TEMP%\RAV.cfg.bak
- 'rs####.rising.com.cn':80
- 'ce####.rising.com.cn':80
- rs####.rising.com.cn/rs2012/RsPcVer12.xml
- ce####.rising.com.cn/LogCenter.asp?in###############################################################################################################
- DNS ASK rs####.rising.com.cn
- DNS ASK ce####.rising.com.cn