[PID: 2408][C:\Program Files\Rising\Rav\RsAgent.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
[C:\WINDOWS\system32\nview.dll] [, ]
[C:\WINDOWS\system32\NVWRSZHC.DLL] [NVIDIA Corporation, 6.14.10.11025]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[PID: 2892][C:\WINDOWS\msagent\AgentSvr.exe] [Microsoft Corporation, 2.00.0.3424]
[C:\WINDOWS\system32\nview.dll] [, ]
[C:\WINDOWS\system32\NVWRSZHC.DLL] [NVIDIA Corporation, 6.14.10.11025]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2804][C:\Program Files\WinRAR\WinRAR.exe] [N/A, ]
[C:\WINDOWS\system32\nview.dll] [, ]
[C:\WINDOWS\system32\NVWRSZHC.DLL] [NVIDIA Corporation, 6.14.10.11025]
[C:\WINDOWS\system32\wpdshext.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16414 (vista_gdr.070108-1520)]
[C:\WINDOWS\system32\nvwddi.dll] [NVIDIA Corporation, 6.14.10.8415]
[C:\WINDOWS\system32\nvwimg.dll] [, ]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16414 (vista_gdr.070108-1520)]
[PID: 1876][C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX00.500\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16414 (vista_gdr.070108-1520)]
[C:\WINDOWS\system32\nview.dll] [, ]
[C:\WINDOWS\system32\NVWRSZHC.DLL] [NVIDIA Corporation, 6.14.10.11025]
[C:\WINDOWS\system32\nvwddi.dll] [NVIDIA Corporation, 6.14.10.8415]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
203.171.230.35 www.zgxts.com
219.136.253.180 www.amway.com.cn
218.202.218.30 www.xjklmy.com
61.128.99.68 www.xj.cninfo.net
61.156.238.77 youcheng.net
222.83.0.80 vod.56567.com
218.31.79.200 klmy.xjvod.net
219.239.195.11 www.lenovo.com.cn
129.42.60.213 www.lenovo.com
61.172.250.100 www.eastmoney.com
219.129.20.134 fund.cfi.net.cn
219.142.91.11 www.icbc.com.cn
202.109.75.193 www.cnstock.com
59.37.8.42 www.fscinda.com
218.75.76.205 www.10jqka.com.cn
202.109.75.193 www.cnstock.com
202.104.106.50 www.boshi.com.cn
219.153.56.53 www.stockstar.com
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================