[PID: 1276][C:\WINNT\System32\igfxpers.exe] [Intel Corporation, 3.0.0.4396]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[C:\WINNT\system32\zt.dll] [N/A, N/A]
[C:\WINNT\System32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4396]
[C:\Program Files\CNNIC\Cdn\cdndet.dll] [, 2, 0, 0, 0]
[PID: 1304][C:\Program Files\Analog Devices\Core\smax4pnp.exe] [Analog Devices, Inc., 5, 2, 0, 5]
[C:\Program Files\Analog Devices\Core\SMWDMIF.dll] [Analog Devices, Inc., 5, 2, 3, 000]
[C:\WINNT\system32\EDCrypt.DLL] [Analog Devices Incorporated, 1.0.0.8]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[C:\WINNT\system32\zt.dll] [N/A, N/A]
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] [, 1, 0, 1, 4]
[C:\Program Files\CNNIC\Cdn\imaoe.dll] [cnnic, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\IDNCONV.dll] [CNNIC, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\imaconv.dll] [cnnic, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\cdndet.dll] [, 2, 0, 0, 0]
[PID: 1340][C:\PROGRA~1\CA\ETRUST~1\realmon.exe] [Computer Associates International, Inc., 7.0.139.0]
[C:\PROGRA~1\CA\ETRUST~1\InConfig.dll] [Computer Associates International, Inc., 7.0.139.0]
[C:\PROGRA~1\CA\ETRUST~1\INOCORE.dll] [Computer Associates International, Inc., 7.0.139.0]
[C:\PROGRA~1\CA\ETRUST~1\InoOEM.dll] [Computer Associates International, Inc., 7.0.139.0]
[C:\PROGRA~1\CA\ETRUST~1\InDrvCfg.dll] [Computer Associates International, Inc., 7.0.139.0]
[C:\Program Files\CA\SharedComponents\ScanEngine\DistCfg.dll] [Computer Associates International, Inc., 7.0.139.0]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[C:\PROGRA~1\CA\ETRUST~1\secAPI.dll] [Computer Associates International, Inc., 7.0.139.0]
[C:\WINNT\system32\zt.dll] [N/A, N/A]
[C:\Program Files\CNNIC\Cdn\cdndet.dll] [, 2, 0, 0, 0]
[PID: 1320][C:\Program Files\CNNIC\Cdn\cdnup.exe] [, 2, 0, 0, 0]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[C:\WINNT\system32\zt.dll] [N/A, N/A]
[C:\Program Files\CNNIC\Cdn\cdnglo.dll] [, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\cdndet.dll] [, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\imaoe.dll] [cnnic, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\IDNCONV.dll] [CNNIC, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\imaconv.dll] [cnnic, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] [, 1, 0, 1, 4]
[C:\Program Files\CNNIC\Cdn\cdntdns.dll] [N/A, N/A]
[PID: 1352][C:\WINNT\system32\internat.exe] [Microsoft Corporation, 5.00.2920.0000]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[C:\WINNT\system32\zt.dll] [N/A, N/A]
[C:\Program Files\CNNIC\Cdn\cdndet.dll] [, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] [, 1, 0, 1, 4]
[C:\Program Files\CNNIC\Cdn\imaoe.dll] [cnnic, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\IDNCONV.dll] [CNNIC, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\imaconv.dll] [cnnic, 2, 0, 0, 0]
[D:\Program files\Tencent\RTX\BQQHook.dll] [N/A, N/A]
[D:\Program files\Tencent\RTX\RTXOLAss.dll] [ìú??????óD?T1???, 1, 0, 0, 1]
[PID: 1388][D:\Program files\Tencent\RTX\rtxc.exe] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\RTXDbug.dll] [N/A, N/A]
[D:\Program files\Tencent\RTX\Utility.dll] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\UILib.dll] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\Crypt.dll] [N/A, N/A]
[D:\Program files\Tencent\RTX\BqqZip.dll] [N/A, N/A]
[D:\Program files\Tencent\RTX\QQRes.dll] [N/A, N/A]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] [, 1, 0, 1, 4]
[C:\Program Files\CNNIC\Cdn\imaoe.dll] [cnnic, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\IDNCONV.dll] [CNNIC, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\imaconv.dll] [cnnic, 2, 0, 0, 0]
[C:\WINNT\system32\zt.dll] [N/A, N/A]
[D:\Program files\Tencent\RTX\Core.dll] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\MPBase.dll] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\RTXProxy.dll] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\ProxySock.dll] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\Psr.dll] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\MsgRec.dll] [N/A, N/A]
[D:\Program files\Tencent\RTX\MsgDb.dll] [N/A, N/A]
[D:\Program files\Tencent\RTX\libdb42.dll] [Sleepycat Software, 4.2.52]
[D:\Program files\Tencent\RTX\BQQApi.dll] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\Store.dll] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\ClientAPI.dll] [Tencent, 3,4,0,32]
[C:\Program Files\CNNIC\Cdn\cdndet.dll] [, 2, 0, 0, 0]
[D:\Program files\Tencent\RTX\RtxP2pMgr.dll] [Tencent, 3,4,0,31]
[D:\Program files\Tencent\RTX\P2pMgr.dll] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\QQSkin.dll] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\NewSkin.dll] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\RTXOLAss.dll] [ìú??????óD?T1???, 1, 0, 0, 1]
[D:\Program files\Tencent\RTX\BQQHook.dll] [N/A, N/A]
[D:\Program files\Tencent\RTX\DeptHideSet.dll] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\RTCBuddy.dll] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\MiniRTXPrj.dll] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\RTXInfoComm.dll] [Tencent, 3,4,0,32]
[C:\WINNT\system32\cdnns.dll] [N/A, N/A]
[D:\Program files\Tencent\RTX\IM.dll] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\RecentRecord.dll] [Tencent, 3,4,0,32]
[D:\Program files\Tencent\RTX\BQQAVPlugin.dll] [Tencent, 3,4,0,32]
[C:\WINNT\system32\FREEWB.IME] [Delphi Fan Studio, 5.1]
[C:\Program Files\freewb\plugin\date.plg] [, 1, 0, 0, 1]
[D:\Program files\Tencent\RTX\Envelope.dll] [Tencent, 3,4,0,32]
[D:\PROGRA~1\Tencent\RTX\RTXOle.dll] [Tencent, 3,4,0,32]
[c:\program files\ca\etrust antivirus\atypggmi.dll] [, 1, 0, 0, 11]
[PID: 1184][C:\WINNT\system32\wuauclt.exe] [Microsoft Corporation, 5.4.3630.2554 built by: lab04_n]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] [, 1, 0, 1, 4]
[C:\Program Files\CNNIC\Cdn\imaoe.dll] [cnnic, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\IDNCONV.dll] [CNNIC, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\imaconv.dll] [cnnic, 2, 0, 0, 0]
[C:\WINNT\system32\zt.dll] [N/A, N/A]
[C:\Program Files\CNNIC\Cdn\cdndet.dll] [, 2, 0, 0, 0]
[PID: 1468][C:\WINNT\system32\conime.exe] [Microsoft Corporation, 5.00.2195.6655]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] [, 1, 0, 1, 4]
[C:\Program Files\CNNIC\Cdn\imaoe.dll] [cnnic, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\IDNCONV.dll] [CNNIC, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\imaconv.dll] [cnnic, 2, 0, 0, 0]
[C:\WINNT\system32\zt.dll] [N/A, N/A]
[C:\Program Files\CNNIC\Cdn\cdndet.dll] [, 2, 0, 0, 0]
[PID: 860][C:\Documents and Settings\Administrator\桌面\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[C:\Program Files\CNNIC\Cdn\cdnspie.dll] [, 1, 0, 1, 4]
[C:\Program Files\CNNIC\Cdn\imaoe.dll] [cnnic, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\IDNCONV.dll] [CNNIC, 2, 0, 0, 0]
[C:\Program Files\CNNIC\Cdn\imaconv.dll] [cnnic, 2, 0, 0, 0]
[C:\WINNT\system32\zt.dll] [N/A, N/A]
[C:\Program Files\CNNIC\Cdn\cdndet.dll] [, 2, 0, 0, 0]
[D:\Program files\Tencent\RTX\BQQHook.dll] [N/A, N/A]
[D:\Program files\Tencent\RTX\RTXOLAss.dll] [ìú??????óD?T1???, 1, 0, 0, 1]
[C:\WINNT\system32\cdnns.dll] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
10.200.0.35 app1.hub
10.200.0.34 app2.hub
10.72.0.32 app1.nn
10.72.0.33 nn3.oa.net
10.72.0.33 oa3.nn
10.72.0.65 cxsrv2
10.72.0.56cxcwsrv
10.72.0.37 nncx
10.72.0.60cxsrv1
10.72.0.70 nncpic
10.72.1.88nnyhqz
10.200.7.1 finance.hq.cpic.com finance
10.200.7.3 finapp1.hq.cpic.com finapp1
10.200.7.4 finapp2.hq.cpic.com finapp2
10.200.0.75 p07trn.hq.cpic.com
10.200.14.27 cpicnms1
10.200.14.28 cpicnms2
10.200.14.29 cpicnms3
10.200.14.30 cpicnms4
==================================
API HOOK
N/A
==================================