[C:\WINDOWS\system32\NvMcTray.dll] [NVIDIA Corporation, 6.14.10.8198]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 2]
[C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.10.8198]
[C:\Program Files\KV2005\KVMonXP.kxp] [JiangMin Co.Ltd, 9, 2, 0, 60118]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 2]
[C:\Program Files\KV2005\UpdateX.dll] [JiangMin Ltd., 8, 0, 0, 0]
[C:\Program Files\KV2005\lang\Kvxp0804_1.lng] [N/A, N/A]
[C:\Program Files\KV2005\GUIExt.dll] [JiangMin Ltd., 9.0.0.501]
[C:\Program Files\KV2005\lang\GUIExt0804.lng] [JiangMin Ltd., 7, 1, 0, 200]
[C:\Program Files\KV2005\KVEnhP_1.dll] [JiangMin Ltd., 9, 0, 5, 405]
[C:\Program Files\KV2005\KvSpiPS.dll] [JiangMin Ltd., 9.0.0.501]
[C:\Program Files\KV2005\KvOffice.dll] [JiangMin New Tech., 9.0.0.1213]
[C:\Program Files\KV2005\lang\KVOffice0804.lng] [N/A, N/A]
[C:\Program Files\KV2005\VirusUpload.dll] [N/A, 2, 0, 0, 0]
[C:\Program Files\KV2005\lang\PrivateCfg0804.lng] [TODO: <Company name>, 1.0.0.1]
[C:\Program Files\KV2005\PProtect.dll] [北京江民新科技术公司, 1.0.121]
[PID: 1108][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 2]
[PID: 1112][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\KvWspXp_1.dll] [JiangMin Ltd., 9, 0, 5, 324]
[C:\Program Files\KV2005\TrojDie.kxp] [Jiangmin Co.Ltd, 9, 0, 5, 916]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 2]
[C:\Program Files\KV2005\UpdateX.dll] [JiangMin Ltd., 8, 0, 0, 0]
[C:\Program Files\KV2005\lang\TrojDie0804.lng] [N/A, N/A]
[C:\Program Files\KV2005\GUIExt.dll] [JiangMin Ltd., 9.0.0.501]
[C:\Program Files\KV2005\lang\GUIExt0804.lng] [JiangMin Ltd., 7, 1, 0, 200]
[C:\Program Files\KV2005\PProtect.dll] [北京江民新科技术公司, 1.0.121]
[C:\Program Files\KV2005\ComUIPS.dll] [N/A, 9. 5. 5. 20]
[PID: 1852][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\PROGRA~1\3721\scrblock.dll] [3721, 1, 0, 1, 1000]
[C:\PROGRA~1\3721\alrex.dll] [, 1, 0, 1, 1001]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 2]
[C:\WINDOWS\DOWNLO~1\CnsHint.dll] [3721, 2, 5, 0, 2]
[C:\PROGRA~1\3721\autolive.dll] [, 2, 5, 0, 1002]
[C:\PROGRA~1\3721\alLiveEx.dll] [ , 1, 0, 3, 1006]
[C:\WINDOWS\DOWNLO~1\cnsplus.dll] [3721, 2, 5, 0, 2]
[C:\WINDOWS\system32\IETool.dll] [N/A, N/A]
[C:\WINDOWS\system32\KvWspXp_1.dll] [JiangMin Ltd., 9, 0, 5, 324]
[C:\Program Files\LtUcx\1002\c0.dll] [北京莲塘软件技术有限公司, 1, 8, 0, 60]
[C:\Program Files\LtUcx\ucx0.dll] [北京莲塘软件技术有限公司, 1, 0, 3, 21]
[C:\Program Files\KV2005\KvShell_1.dll] [JiangMin Lmt, 9, 0, 5, 1205]
[C:\Program Files\KV2005\UpdateX.dll] [JiangMin Ltd., 8, 0, 0, 0]
[C:\Program Files\KV2005\lang\Kvxp0804_1.lng] [N/A, N/A]
[C:\Program Files\KV2005\APIImpl.dll] [JiangMin Ltd., 9.0.0.500]
[C:\Program Files\Thunder\ComDlls\XunLeiBHO_002.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
[C:\WINDOWS\DOWNLO~1\CnsHook.dll] [北京三七二一科技有限公司, 2, 5, 0, 2]
[C:\WINDOWS\DOWNLO~1\CnsMinIO.dll] [北京三七二一科技有限公司, 1, 0, 3, 7]
[C:\WINDOWS\DOWNLO~1\cnsio.dll] [北京三七二一科技有限公司, 1, 0, 2, 8]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\Program Files\Thunder\ComDlls\ThunderAgent_003.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 10]
[PID: 1464][C:\Program Files\KV2005\KRegEx.exe] [Jiangmin, 1.0.1.0413]
[C:\Program Files\KV2005\KRegEx.dll] [N/A, N/A]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 2]
[C:\Program Files\KV2005\KRegTrust.dll] [Jiangmin Co. Ltd., 9.0.0.825]
[PID: 1744][C:\WINDOWS\system32\DllHost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 2]
[C:\Program Files\KV2005\ComUI.dll] [Jiangmin Ltd., 9. 5. 5. 20]
[C:\Program Files\KV2005\UpdateX.dll] [JiangMin Ltd., 8, 0, 0, 0]
[C:\Program Files\KV2005\ComUIPS.dll] [N/A, 9. 5. 5. 20]
[C:\Program Files\KV2005\GUIExt.dll] [JiangMin Ltd., 9.0.0.501]
[C:\Program Files\KV2005\lang\GUIExt0804.lng] [JiangMin Ltd., 7, 1, 0, 200]
[PID: 2116][C:\Program Files\Thunder\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5.4.0.226]
[C:\Program Files\Thunder\Program\UpdateDownload.dll] [N/A, N/A]
[C:\Program Files\Thunder\Program\msgmanage.dll] [N/A, N/A]
[C:\Program Files\Thunder\Program\historyinfo_manage.dll] [Thunder Networking Technologies,LTD, 5, 2, 0, 148]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 2]
[C:\Program Files\Thunder\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 2, 0, 0, 1]
[C:\Program Files\Thunder\Program\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031]
[C:\Program Files\Thunder\Program\log4cplus.dll] [, 1, 0, 2, 1]
[C:\Program Files\Thunder\Program\asyn_dns.dll] [N/A, N/A]
[C:\Program Files\Thunder\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 1, 0, 18]
[C:\Program Files\Thunder\Program\FloatBar.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
[C:\WINDOWS\system32\KvWspXp_1.dll] [JiangMin Ltd., 9, 0, 5, 324]
[C:\WINDOWS\DOWNLO~1\CnsHook.dll] [北京三七二一科技有限公司, 2, 5, 0, 2]
[C:\Program Files\Thunder\Program\iTargetAd.dll] [N/A, N/A]
[PID: 3668][C:\Documents and Settings\Administrator\桌面\sreng2\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\PROGRA~1\3721\helper.dll] [, 2, 5, 0, 1003]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 2]
[C:\WINDOWS\system32\KvWspXp_1.dll] [JiangMin Ltd., 9, 0, 5, 324]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
C:\WINDOWS\system32\KvWspXp_1.dll(JiangMin Ltd., KVWspXP)
MSAFD Tcpip [UDP/IP]
C:\WINDOWS\system32\KvWspXp_1.dll(JiangMin Ltd., KVWspXP)
MSAFD Tcpip [RAW/IP]
C:\WINDOWS\system32\KvWspXp_1.dll(JiangMin Ltd., KVWspXP)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
0.0.0.0 182838.com
0.0.0.0 204.177.92.68
0.0.0.0 asiafriendfinder.com
0.0.0.0 asqin123.51.net
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
0.0.0.0 www.jpbeauty.com
0.0.0.0 beautishow.com
0.0.0.0 goodmovies88.com
0.0.0.0 hothack.home.chinaren.com
0.0.0.0 hualiao.net
0.0.0.0 iplus.allyes.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 asqin123.51.net
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
==================================
API HOOK
N/A
==================================
[/CODE]