[PID: 4294897121][C:\WINDOWS\SYSTEM\RPCLTCCM.DLL] [Microsoft Corporation, 4.71.3328]
[C:\WINDOWS\SYSTEM\DHCPCSVC.DLL] [N/A, ]
[C:\WINDOWS\SYSTEM\SVRAPI.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\MSPWL32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\NETAPI32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] [N/A, ]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.90.3000]
[PID: 4294783865][C:\WINDOWS\SYSTEM\MSIDLE.DLL] [Microsoft Corporation, 5.50.4134.100]
[C:\WINDOWS\SYSTEM\CABINET.DLL] [Microsoft Corporation, 5.00.2147.1]
[PID: 4294813989][C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.90.1000.0]
[PID: 4294828577][C:\WINDOWS\TASKMON.EXE] [Microsoft Corporation, 4.90.3000]
[PID: 4294825349][C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.90.1000.0]
[C:\WINDOWS\SYSTEM\SYSTRAY.EXE] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\BATMETER.DLL] [Microsoft Corporation, 4.90.3000.1]
[C:\WINDOWS\SYSTEM\POWRPROF.DLL] [Microsoft Corporation, 4.90.3000.1]
[C:\WINDOWS\SYSTEM\CFGMGR32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\CABINET.DLL] [Microsoft Corporation, 5.00.2147.1]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\LZ32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\WINMM.DLL] [Microsoft Corporation, 4.90.3000]
[PID: 4294662049][C:\WINDOWS\SYSTEM\NVDD32.DLL] [NVidia Corporation, 4.14.10.5664]
[C:\WINDOWS\SYSTEM\NVARCH32.DLL] [NVIDIA Corporation, 4.14.10.5664]
[C:\WINDOWS\SYSTEM\WINMM.DLL] [Microsoft Corporation, 4.90.3000]
[PID: 4294667713][C:\WINDOWS\SYSTEM\WMIEXE.EXE] [Microsoft Corporation, 4.90.2452.1]
[PID: 4294697545][C:\WINDOWS\SYSTEM\MSI.DLL] [Microsoft Corporation, 1.20.1410.0]
[C:\PROGRAM FILES\CHINANET\DLGSKIN.OCX] [4, 1, 0, 0, 1]
[C:\WINDOWS\SYSTEM\MSADP32.ACM] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\MSACM32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\MACROMED\FLASH\SWFLASH.OCX] [Macromedia, Inc., 4,0,28,0]
[C:\WINDOWS\SYSTEM\WINMM.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\DHCPCSVC.DLL] [N/A, ]
[C:\PROGRAM FILES\CHINANET\VNETSKIN.OCX] [GDDC, 1, 0, 0, 1]
[C:\PROGRAM FILES\CHINANET\TIMER.OCX] [4, 2005, 4, 30, 1]
[C:\PROGRAM FILES\CHINANET\ALLFUNCTIONS.DLL] [(, 2005, 6, 15, 1]
[C:\PROGRAM FILES\CHINANET\DIALOGSTYLE.DLL] [$, 1, 0, 0, 1]
[C:\PROGRAM FILES\CHINANET\VNETOPTLOG.DLL] [$, 2004, 11, 23, 1]
[C:\PROGRAM FILES\CHINANET\VNETONLINEUPDATE.OCX] [<, 2005, 3, 2, 1]
[C:\PROGRAM FILES\CHINANET\STATNUM.DLL] [$, 2004, 11, 18, 1]
[C:\PROGRAM FILES\CHINANET\VNETLOGIN.OCX] [8, 2005, 6, 16, 1]
[C:\PROGRAM FILES\CHINANET\ALLINTERFACE.DLL] [(, 2004, 11, 23, 1]
[C:\PROGRAM FILES\CHINANET\PLUGPUSH.DLL] [$, 2004, 12, 21, 1]
[C:\WINDOWS\SYSTEM\WPCAP.DLL] [Politecnico di Torino, 3, 0, 0, 18]
[C:\WINDOWS\SYSTEM\PACKET.DLL] [Politecnico di Torino, 3, 0, 0, 18]
[C:\WINDOWS\SYSTEM\PTHREADVC.DLL] [N/A, ]
[C:\PROGRAM FILES\CHINANET\PASSCTRL.DLL] [$, 1, 0, 0, 1]
[C:\PROGRAM FILES\CHINANET\NEWMESSAGE.DLL] [(, 2004, 11, 25, 0]
[C:\PROGRAM FILES\CHINANET\PLUGINMAN.OCX] [8, 2005, 2, 24, 1]
[C:\PROGRAM FILES\CHINANET\ACCOUNTPAGE.DLL] [(, 2005, 3, 3, 1]
[C:\PROGRAM FILES\CHINANET\ACCOUNTMGR.DLL] [$, 2005, 6, 16, 1]
[C:\PROGRAM FILES\CHINANET\VNETBS.OCX] [4, 2004, 11, 18, 1]
[C:\PROGRAM FILES\CHINANET\ADVERTISE.OCX] [P, 2005, 4, 27, 2]
[C:\PROGRAM FILES\CHINANET\POSTPLUG.DLL] [$, 2004, 12, 16, 2]
[C:\PROGRAM FILES\CHINANET\PLUGINCONTAINER.OCX] [<, 2005, 3, 7, 1]
[C:\PROGRAM FILES\CHINANET\SIGN.DLL] [0, 2004, 12, 1, 1]
[C:\PROGRAM FILES\CHINANET\CLIENTAPI.DLL] [(, 2004, 2, 28, 1]
[C:\PROGRAM FILES\CHINANET\VNETCLIENT.EXE] [4, 2005, 3, 7, 1]
[C:\PROGRAM FILES\CHINANET\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[C:\PROGRAM FILES\CHINANET\DIALMODULE.DLL] [$, 2005, 3, 22, 1]
[C:\WINDOWS\SYSTEM\SVRAPI.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\MSPWL32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\NETAPI32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] [N/A, ]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.90.3000]
[C:\PROGRAM FILES\CHINANET\COMMUNICATE.DLL] [0, 2005, 3, 3, 1]
[PID: 4294627761][C:\WINDOWS\SYSTEM\RNAUI.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\SVRAPI.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\MSPWL32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\NETAPI32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] [N/A, ]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.90.3000]
[PID: 4294517937][C:\WINDOWS\SYSTEM\ISDNUI.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\WOW32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\SVRAPI.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\MSPWL32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\NETAPI32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] [N/A, ]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.90.3000]
[PID: 4294531217][C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.90.1000.0]
[PID: 4294557305][C:\WINDOWS\SYSTEM\PSBASE.DLL] [Microsoft Corporation, 5.00.2133.2]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.90.3000]
[PID: 4294331393][C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.90.1000.0]
[PID: 4294334741][C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.90.1000.0]
[PID: 4294335961][C:\WINDOWS\SYSTEM\MSAFD.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\LOGO1_.EXE] [, 1.0.0.0]
[C:\WINDOWS\SYSTEM\SVRAPI.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\MSPWL32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\NETAPI32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] [N/A, ]
[C:\WINDOWS\SYSTEM\WINMM.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.90.3000]
[PID: 4294332625][C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.90.1000.0]
[PID: 4294329557][C:\WINDOWS\SYSTEM\INDICDLL.DLL] [Microsoft Corporation, 4.90.1000.0]
[PID: 4294440637][C:\WINDOWS\SYSTEM\PINTLGNT.IME] [Microsoft Corporation, 4.2.32]
[C:\WINDOWS\SYSTEM\IME\PINTLGNT\PINTIME.DLL] [Microsoft Corporation, 4.2.32]
[C:\WINDOWS\SYSTEM\MACROMED\COMMON\SWSUPPORT.DLL] [Macromedia, Inc., 8.0r196]
[C:\WINDOWS\SYSTEM\WINABC.IME] [Microsoft Corporation, 5.00.1636.1]
[C:\WINDOWS\SYSTEM\WINZM.IME] [Microsoft Corporation, 4.00.950]
[C:\WINDOWS\SYSTEM\WINWB86.IME] [Microsoft Corporation, 4.00.950]
[C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH9D.OCX] [Adobe Systems, Inc., 9,0,47,0]
[C:\WINDOWS\SYSTEM\RICHED32.DLL] [Microsoft Corporation, 5.0.1462.7]
[C:\WINDOWS\SYSTEM\GAPI32.DLL] [Microsoft Corporation, 5.0.1457.3]
[C:\WINDOWS\SYSTEM\MSADP32.ACM] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\MSACM32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\PROGRAM FILES\CHINANET\CLIENTAPI.DLL] [(, 2004, 2, 28, 1]
[C:\WINDOWS\SYSTEM\SVRAPI.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\MSPWL32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\NETAPI32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] [N/A, ]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.90.3000]
[C:\PROGRAM FILES\CHINANET\VNETTRANSFER.DLL] [(, 2005, 4, 6, 1]
[C:\WINDOWS\SYSTEM\WINMM.DLL] [Microsoft Corporation, 4.90.3000]
[C:\PROGRAM FILES\CHINANET\COMMUNICATE.DLL] [0, 2005, 3, 3, 1]
[C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE] [Microsoft Corporation, 5.50.4134.100]
[PID: 4294542649][C:\WINDOWS\SYSTEM\LINKINFO.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\RICHED20.DLL] [Microsoft Corporation, 5.30.23.1203]
[C:\WINDOWS\DESKTOP\SRENG2\SRENGPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\WINDOWS\SYSTEM\SVRAPI.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\MSPWL32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\NETAPI32.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] [N/A, ]
[C:\WINDOWS\SYSTEM\MPR.DLL] [Microsoft Corporation, 4.90.3000]
[C:\WINDOWS\SYSTEM\WINMM.DLL] [Microsoft Corporation, 4.90.3000]
==================================
文件关联
.TXT OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [C:\WINDOWS\winhlp32.exe %1]
.INI OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS OK. [C:\WINDOWS\WScript.exe "%1" %*]
.JS OK. [C:\WINDOWS\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================
进程特权扫描
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
我用的系统是WINME