.text
`.rdata
@.data
.rsrc
WPVUj
L$LQRSj
D$(Pj
L$pQj
t$0Vj
\$<Sj
t$ Vj
|$ Wj
t$ Vj
t$ Vj
t$ Vj
t$ Vj
VUWPj
UWSVj
u=WVj
VPQUj
QSVWh
D$8PSj
T$8RSj
D$ Pj
T$ Rj
D$<PQRh
L$$QWWWWWWWh
D$(Pj
L$0Qj
\$(Sj
t$dSj
|$ Qj
T$8Rj
D$4Ph
D$8Pj
D$8Pj
D$8Pj
L$8Qj
SVWUj
WSVPj
wintrust.dll
WTHelperGetProvCertFromChain
WTHelperGetProvSignerFromChain
WTHelperProvDataFromStateData
WinVerifyTrust
CryptCATAdminEnumCatalogFromHash
CryptCATAdminCalcHashFromFileHandle
CryptCATCatalogInfoFromContext
CryptCATAdminReleaseCatalogContext
CryptCATAdminReleaseContext
CryptCATAdminAcquireContext
crypt32.dll
CryptSIPVerifyIndirectData
CryptSIPCreateIndirectData
CryptSIPRetrieveSubjectGuid
CryptMsgGetParam
CryptDecodeObject
CryptQueryObject
1.3.6.1.4.1.311.2.1.4
list<T> too long
vector<T> too long
\\.\PhysicalDrive%d
SCSIDISK
\\.\Scsi%d:
GetAdaptersInfo
Iphlpapi.dll
Lenovo
Nvidia
Ralink
Atheros
Marvell
Intel
Broadcom
Realtek
Broadband Connection
pppoe
Virtual
Windows
Microsoft
VMware
SELECT * FROM Win32_NetworkAdapter WHERE (MACAddress IS NOT NULL) AND (NOT (PNPDeviceID LIKE 'ROOT%')) AND (NOT (PNPDeviceID LIKE 'USB%'))
SELECT * FROM Win32_NetworkAdapter WHERE (MACAddress IS NOT NULL) AND (NOT (PNPDeviceID LIKE 'ROOT%'))
#{ad498944-762f-11d0-8dcb-00c04fc3358c}
b06bdrv
MACAddress
Description
AdapterType
Manufacturer
PhysicalAdapter
00-00-00-00-00-00
%.2x-%.2x-%.2x-%.2x-%.2x-%.2x
%02X-
LOOPBACK
TOKENRING
ETHERNET
OTHER
RsMgrSvc
\Program Files
ProgramFilesDir
Software\Microsoft\Windows\CurrentVersion
ChangeServiceConfig2A
Advapi32.dll
Rsd Service
COM Infrastructure
RpcSs
\Rising\RSD\RsMgrSvc.exe"
DuplicateTokenEx
SetTokenInformation
OpenProcessToken
Explorer.exe
ProcID
%08X%04X%04X%02X%02X%02X%02X%02X%02X%02X%02X
{%08X-%04X-%04X-%02X%02X-%02X%02X%02X%02X%02X%02X}
CLSID\{CAA2D3B1-4BB5-4a45-A17A-122773379D99}
\Rising\RSD
Progman
Program Manager
Shell
Software\Microsoft\Windows NT\CurrentVersion\Winlogon
[%04d-%02d-%02d][%02d:%02d:%02d:%03d]
\Rising
SHFolder.dll
SHGetFolderPathA
Shell32.dll
installpath
SOFTWARE\Rising\%s
datapath
2.log
[%04u]
[0x%08X]
[FATAL]
[ALERT]
[WAINNING]
[ACTION]
[DETAIL]
LOGNAME
DEBUG
RAV.INI
RS_DEBUG_VIEW
LOGSIZE
OUTPUT
LEVEL
WinSessionThread GetPidByName dwPID = %d , name=%s!
NtQuerySystemInformation
NtDll.dll
ProcessIdToSessionId
Kernel32.dll
WTSQueryUserToken Failed! Err Code: %d
WTSQueryUserToken
wtsapi32.DLL
Explorer is not running...
OpenProcess Failed! Err Code: %d
GetProcAddress(OpenProcessToken) Failed! Err Code: %d
OpenProcessToken Failed! Err Code: %d
Explorer is running...
GetLogonUserToken(%d)
>`userinit.exe
GetModuleBaseNameA
EnumProcessModules
EnumProcesses
CRsMgrSvc::WaitForLogonNT:LoadLibrary(_"psapi.dll");err=0x%x
psapi.dll
Cancel to Logon
Sucessed to Logon
m_hWaitLogonEvent == NULL
CRsMgrSvc::WaitForLogonNT()
Fail to OpenProcessToken; 0x%x
Successed to CreateProcessAsUser.
CreateProcessAsUser to change session 0.
Failed to call CreateProcessAsUser again: appname = %s cmd=%s;err=0x%x.
Failed to SetTokenInformation(0):err=0x%x
Failed to call CreateProcessAsUser:cmd=%s;err=0x%x.
Failed to DuplicateTokenEx:err=0x%x
Failed to SetTokenInformation:err=0x%x
SessionId = %d
WinSta0\Default
Failed to LoadLibrary("Wtsapi32.dll"):err=0x
Failed to call WTSEnumerateSessions:err=0x%x
The Terminate Service not running.
WTSFreeMemory
SessionInfo[%d]: SessionId=%d; WinStationName=%s; State=%d.
WTSEnumerateSessionsA
Wtsapi32.dll
Failed to CreateProcess:%s;err=0x%x
RunProcessAsSvc
ThreadRepair success
ThreadCldRsd success
Failed to LoadLibrary("Wtsapi32.dll"):err=0x%x
Failed to WTSEnumerateSessions:err=0x%x
Session\%d\RSD_POP_MESSAGE_INFO
WinSessionThread CreateProcess ret = %d end !
WinSessionThread CreateProcess LoadLibrary Userenv err !
WinSessionThread CreateProcess LoadLibrary GetProcAddress err !
WinSessionThread CreateProcess pid = %d, CreateProcessAsUser err = %d !
WinSessionThread CreateProcess SetTokenInformation return value:4
DestroyEnvironmentBlock
CreateEnvironmentBlock
Userenv.DLL
WinSessionThread CreateProcess begin dwSessionID = %d!
CRsMgrSvc::OnStop()
CRsMgrSvc::OnShutdown()
Failed to LoadLibrary("Userenv.DLL"):err=0x%x
Failed to call CreateProcessAsUser: cmd=%s;err=0x%x.
RunProcessAsSvc...
New Failed to call WTSQueryUserToken, err= 0x%x
RunProcessAsLogon
rsmsg
sguid
%s\rsmsginfo.ini
Failed to open the shell ready event: 0x%x
"%s" /shellrun
%s\RsStub.exe
Session\%d\ShellReadyEvent
LogonRun - session : %d
Failed to call RegOpenKeyEx, err = 0x%x
Failed to call RegSaveKey, err = 0x%x
SYSTEM\CurrentControlSet\Services\RsMgrSvc
Failed to call AdjustTokenPrivileges, err = 0x%x
SeBackupPrivilege
Failed to call OpenPrcessToken, err = 0x%x
%s\RsMgrSvc.dat
GHOST
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
UninstallString
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\%s
BaiduAnSvc.exe
BaiduSdSvc.exe
liebao.exe
liebao
ksafe.exe
{849B7E2B-0551-429C-B317-14B7D374D6EC}_is1
kxescore.exe
Kingsoft Internet Security
QQPCRtp.exe
QQPCMgr
360sd.exe
360SD
360se.exe
{23F3F476-BE34-4f48-9C77-2806A8393EC4}
360Desktop.exe
360Desktop
ZhuDongFangYu.exe
safeboxTray.exe
Failed to Create LogonRunThread Thread, err = 0x%x
SessionChange:EventType=%d; sessionID = %d
VERSION
COMPONENT
\Backup\RSD\RSSetup\RSSetup.xml
rsup10.rising.com.cn
u.suxiazai.com
%s?t=0&info=%s
ver=%s&guid=%s&sguid=%s&state=%s
Switch
MENU/ITEM
http://u.suxiazai.com/menu/info.xml
http://rsup10.rising.com.cn/menu/info.xml
%srsd\info.xml
/logon
/session
/subkey
/lang
/lang
/silence
/silence
/tray
/tray
Failed to Verify the "%s".
/workdir
/highrun
Failed to call vf.Init.
Success to Verify the "%s".
/argument
/binpath
%s\rsbackup.exe
"%s\rsbackup.exe"
/backup
/uc
Update
/subkey
%.4d-%.2d-%.2d %.2d:%.2d:%.2d
%s\RsMgrSvc.ini
%s\updater.exe
"%s\updater.exe"
/update
/rsstub
/exit
CRsMgrSvc::Handle.
DeleteFile: %s.
ITEM%d
DELETEFILE
COUNT
\RsMgrSvc.ini
DeletePath: %s.
DELETEPATH
REBOOTRUN
Clean WillReboot In %s
SETUP
WILLREBOOT
%s\%s\%s.ini
\Data
1971-01-01 00:00:00
%d-%d-%d %d:%d:%d
%s\Data
%s /subkey %s /RsMgrSvc
"%s\Updater.exe" /silence
%s\Updater.exe
TryGetUserGUID param1=%d param2=%d
End RunAfterReboot.
Reboot
BeforeReboot
\Reboot.ini
Begin RunAfterReboot.
m_hTimerThread success
WaitForLogon success
CreateThread ThreadCldRsd
CreateThread dwThreadRepair
CRsMgrSvc::SVC:Failed to m_lpRsStub->Initialize(this)
CRsMgrSvc::SVC:Failed to new CRsStub
CRsMgrSvc::SVC:Failed to CreateEvent-Wait: err=0x%x
RsMgrSvc_Wait
CRsMgrSvc::SVC:Failed to CreateEvent, err=0x%x
-/UPDATE
/UPDATE
YYYIYOUDAO
comx3.dll
RS_ShutDown
RS_FreeCallCenter
RS_AllocateCallCenter
RS_UninitializeCallCenter
RS_InitializeCallCenter
RegisterServiceProcess
KERNEL32.DLL
RegisterServiceCtrlHandlerExA
-DEBUG
/DEBUG
Delete
NoRemove
ForceRemove
kernel32.dll
K.$invalid map/set<T> iterator
map/set<T> too long
DiskSerial
Model
ProcessorId
Win32_NetworkAdapter
Win32_Processor
MSIE %d.%d
WININET.DLL
Windows Me
Windows 98
Windows 95
Windows NT %d.%d
%s:%d
proxy
<local>
Mozilla/4.0 (compatible; %s; %s; Rising)
Content-Type: application/x-www-form-urlencoded
InPost=
HTTP/1.0
close
Range: bytes=%d-
Host:
RstoreDll.dll
SOFTWARE\Rising\
@CRsUseRepairProduct::prstorestart %s Dllpath:%s
@CRsUseRepairProduct::prstorestart %s
StartSpecialRepair
@CRsUseRepairProduct::LoadDllAndForkRepair
Subkey: %s could not find dllPath ,so use rsd path:%s
Subkey: %s Path:%s
\RstoreDll.dll
\rsupdater
@CRsUseRepairProduct::getRestoreDllPath
CldRsd.dll
CRsLoadCloud::InitData...
CRsLoadCloud::LoadCldRsdDll... failed lasterror = %d
CRsLoadCloud::LoadCldRsdDll... success
CRsLoadCloud::LoadCldRsdDll...%s
CRsLoadCloud::StartTask...success
StartTask
CRsLoadCloud::StartTask...
CRsLoadCloud::StopTask... success
StopTask
CRsLoadCloud::StopTask...
CLSID\{CAA2D3B2-4BB5-4a45-A17A-122773379D99}
"result": "%s", "errorcode": "%s", "remark": "%s", "pa": "%s", "pb": "%s"}
http://center.rising.com.cn/urg.asp?v=%s&t=%s&a=%s
%sbase
IsWow64Process
RtlGetVersion
SystemMsg
IsSendWin10Msg
IsSendWin10MsgNew
IsWin10OS
@CRsCheckWin10::DoWork ThisSystem is not Win10.
@CRsCheckWin10::DoWork SendWin10MsgInfo failed. lastError = %d.
@CRsCheckWin10::DoWork SendWin10MsgInfo success.
@CRsCheckWin10::DoWork IsSendWin10MsgNew = true.already has send msg to server.
@CRsCheckWin10::DoWork
isExistReg....failed
isExistReg....success end
RapUrl
Software\rising\lockie
isExistReg....begin
IsEquelToStringRap_25...end success
RAVP_25
PRODUCTUID
%s\data\rav\rav.ini
IsEquelToStringRap_25...begin
isExistFiles....success end
%s\backup\rav\rapbase\rapsetup.dll
Failed isExistFiles %s not exist
%s\rapsetup.dll
%s\xmls\_rap.xml
isExistFiles....begin
Unknown exception
CorExitProcess
mscoree.dll
`h````
(null)
Microsoft Visual C++ Runtime Library
Program:
<program name unknown>
Buffer overrun detected!
Unknown security failure detected!
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
e+000
GAIsProcessorFeaturePresent
KERNEL32
runtime error
Program:
InitializeCriticalSectionAndSpinCount
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
April
March
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
1#QNAN
1#INF
1#IND
1#SNAN
invalid string position
string too long
C:\DistributedAutoLink\Temp\CompileOutputDir\RsMgrSvc.pdb
lstrlenA
RaiseException
InitializeCriticalSection
DeleteCriticalSection
FreeLibrary
LocalFree
LocalAlloc
GetLastError
CloseHandle
GetProcAddress
LoadLibraryA
lstrcatA
lstrcpyA
DeviceIoControl
GetVersionExA
CreateFileA
InterlockedExchange
GetACP
GetLocaleInfoA
GetThreadLocale
WideCharToMultiByte
lstrlenW
lstrcmpiA
InterlockedDecrement
GetCurrentProcess
Sleep
GetTickCount
GetWindowsDirectoryA
SizeofResource
LockResource
LoadResource
FindResourceA
FindResourceExA
GlobalFree
GlobalAlloc
SetLastError
GetModuleFileNameA
GetCommandLineA
MultiByteToWideChar
WaitForSingleObject
OpenProcess
FindNextFileA
FindClose
GetLocalTime
GetFullPathNameA
FindFirstFileA
CreateDirectoryA
DeleteFileA
GetPrivateProfileIntA
GetPrivateProfileStringA
WriteFile
SetFilePointer
MoveFileA
SetFileAttributesA
lstrcpynA
GetFileSize
GetCurrentThreadId
GetCurrentProcessId
OutputDebugStringA
GetModuleHandleA
CreateProcessA
SetEvent
OpenEventA
GetVersion
GetFileAttributesA
Process32Next
Process32First
CreateToolhelp32Snapshot
CreateThread
ResetEvent
GetTempPathA
WritePrivateProfileStringA
TerminateThread
GetExitCodeThread
ResumeThread
CreateEventA
ReadFile
WritePrivateProfileSectionA
CompareStringA
CompareStringW
RemoveDirectoryA
FlushFileBuffers
SetEndOfFile
SetFileTime
SystemTimeToFileTime
FileTimeToSystemTime
GetModuleHandleW
KERNEL32.dll
CharUpperA
FindWindowA
SendMessageA
IsWindow
wsprintfA
USER32.dll
GetTokenInformation
OpenProcessToken
CloseServiceHandle
OpenServiceA
OpenSCManagerA
RegCloseKey
RegQueryValueExA
RegOpenKeyExA
ChangeServiceConfigA
CreateServiceA
RegEnumKeyExA
RegSetValueExA
RegCreateKeyA
RegOpenKeyA
CreateProcessAsUserA
SetTokenInformation
AllocateAndInitializeSid
RegSaveKeyA
AdjustTokenPrivileges
LookupPrivilegeValueA
RegQueryInfoKeyA
SetServiceStatus
RegisterServiceCtrlHandlerA
StartServiceCtrlDispatcherA
ADVAPI32.dll
CoSetProxyBlanket
CoUninitialize
CoCreateInstance
CoInitializeSecurity
CoInitializeEx
CoInitialize
ole32.dll
OLEAUT32.dll
StrStrIA
PathSkipRootA
PathFileExistsA
PathRemoveFileSpecA
SHLWAPI.dll
CryptMsgClose
CertCloseStore
CertGetNameStringW
CertFindCertificateInStore
CRYPT32.dll
UuidCreate
RPCRT4.dll
SetupDiDestroyDeviceInfoList
SetupDiGetDeviceRegistryPropertyA
SetupDiGetDeviceInterfaceDetailA
SetupDiEnumDeviceInterfaces
SetupDiGetClassDevsA
SETUPAPI.dll
GetAdaptersInfo
iphlpapi.dll
InternetCloseHandle
InternetAttemptConnect
InternetConnectA
InternetOpenA
InternetSetOptionA
InternetCrackUrlA
InternetReadFile
HttpQueryInfoA
HttpSendRequestA
HttpOpenRequestA
HttpAddRequestHeadersA
WININET.dll
VerQueryValueA
GetFileVersionInfoA
GetFileVersionInfoSizeA
VERSION.dll
EnterCriticalSection
LeaveCriticalSection
HeapDestroy
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
GetProcessHeap
RtlUnwind
ExitProcess
GetSystemTimeAsFileTime
TerminateProcess
VirtualProtect
VirtualAlloc
GetSystemInfo
VirtualQuery
GetStartupInfoA
HeapCreate
VirtualFree
IsBadWritePtr
SetUnhandledExceptionFilter
QueryPerformanceCounter
TlsAlloc
TlsFree
TlsSetValue
TlsGetValue
GetOEMCP
GetCPInfo
GetTimeZoneInformation
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetStdHandle
UnhandledExceptionFilter
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
GetFileType
IsBadReadPtr
IsBadCodePtr
SetStdHandle
SetEnvironmentVariableA
InterlockedIncrement
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
.?AVCAtlException@ATL@@
.?AVexception@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
welcome Rising*youarelawless!y2a3n4g5Y6U7q8i@S9I0N#A.C%O(M-)<>ABI993JIEM,;'{jkliewaqlsiqomv.z^iwaql}-_=+)_(l;2j2f90aslkjflkasjas32092JKLSJFbASAUI/Z/A[/,./|@~`FS'.Z,MF920SDLAFJKAL9320QFFMmlajfl,.<>//|348q9729|fjlail3jo798,ksafa302-s;akfa;=_++-0-_))0-0-p23is
welcome Rising*youarelawless!y2a$n4g5Y6U7q8i@S9I0N#A.C%O(M-)<>ABI99*JIEM,;'{jkliewaqlsiqomv.z^iwaql}-_=+)_(l;2j@f90aslkjflkasjas6j09kJKLSJFbASAUI/Z/A[/,./|@~`FS'.Z,MF920SDLAFJKAL9320QFFMmlajfl,.<>//|348q9729|fjlail3jo798,ksafa302-s;akfa;=_++-0-_))0-0-p^bis
.?AVout_of_range@std@@
.?AVtype_info@@
Copyright (c) 1992-2001 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AV_com_error@@
PNPDeviceID
LROOT\CIMV2
Beijing Rising Information Technology Co.,Ltd.
Beijing Rising Information Technology Corporation Limited
gunknown
Select * from
root\cimv2
ntdll.dll
(null)
VS_VERSION_INFO
StringFileInfo
080404b0
CompanyName
Beijing Rising Information Technology Co., Ltd.
FileDescription
RsMgrSvc Application
FileVersion
1.0.0.69
InternalName
Beijing Rising Information Technology Co., Ltd.
LegalCopyright
Copyright(C) 2016-2017 Beijing Rising Information Technology Co., Ltd. All Rights Reserved.
OriginalFilename
RsMgrSvc.exe
ProductName
Rising Software Distribute System
ProductVersion
SpecialBuild
20160812152415890
VarFileInfo
Translation