[C:\WINDOWS\downlo~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 6]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\System32\Macromed\Flash\Flash8.ocx] [Macromedia, Inc., 8,0,22,0]
[C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\TIMHost.dll] [N/A, ]
[C:\WINDOWS\System32\upxdnd.dll] [N/A, ]
[PID: 2316][C:\WINDOWS\System32\wuauclt.exe] [Microsoft Corporation, 5.4.3630.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\downlo~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 6]
[PID: 3672][F:\qi\Maxthon2\Maxthon.exe] [Maxthon International ltd., 2, 0, 2, 615]
[F:\qi\Maxthon2\mxpp.dll] [Maxthon, 1, 0, 0, 50]
[F:\qi\Maxthon2\MxSk.dll] [Maxthon, 1, 0, 0, 119]
[F:\qi\Maxthon2\MxProxy2.dll] [, 1, 0, 0, 3115]
[C:\WINDOWS\downlo~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 6]
[F:\qi\Maxthon2\MxFav.dll] [Maxthon, 1, 0, 0, 186]
[F:\qi\Maxthon2\maxzlib.dll] [, 1.2.3]
[F:\qi\Maxthon2\mxtool.dll] [, 1, 0, 0, 1]
[F:\qi\Maxthon2\mxfeedU.dll] [, 1, 0, 45, 45]
[C:\WINDOWS\System32\msxml4.dll] [Microsoft Corporation, 4.10.9404.0]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\Macromed\Flash\Flash8.ocx] [Macromedia, Inc., 8,0,22,0]
[C:\WINDOWS\System32\TIMHost.dll] [N/A, ]
[C:\WINDOWS\System32\upxdnd.dll] [N/A, ]
[PID: 1240][C:\WINDOWS\System32\conime.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\downlo~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 6]
[PID: 396][C:\WINDOWS\system32\cmd.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2508][C:\WINDOWS\Logo1_.exe] [, 1.0.0.0]
[C:\WINDOWS\downlo~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 6]
[PID: 2524][C:\Program Files\Microsoft Office\Office\EXCEL.EXE] [Microsoft Corporation, 9.0.2823]
[C:\Program Files\Microsoft Office\Office\MSO9.DLL] [Microsoft Corporation, 9.0.2812]
[C:\WINDOWS\downlo~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 6]
[C:\PROGRA~1\MICROS~2\Office\2052\OBALLOON.DLL] [Microsoft Corporation, 9.0.2720]
[C:\PROGRA~1\MICROS~2\Office\BLNMGRPS.DLL] [, ]
[C:\PROGRA~1\MICROS~2\Office\Addins\SYMINPUT.DLL] [Microsoft Corporation, 1.00]
[C:\WINDOWS\System32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9782]
[C:\Program Files\Microsoft Office\Office\msohev.dll] [Microsoft Corporation, 9.0.2626]
[C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL] [, ]
[C:\PROGRA~1\COMMON~1\System\OLEDB~1\MSDAIPP.DLL] [Microsoft Corporation, 8.103.5219.0]
[C:\WINDOWS\downlo~1\CnsHook.dll] [北京三七二一科技有限公司, 2.5.1.5]
[C:\Program Files\Rising\Rav\RsPlugIn.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
[C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL] [Microsoft Corporation, 6.00.8435]
[C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\2052\VBE6INTL.DLL] [Microsoft Corporation, 6.00.8435]
[C:\WINDOWS\System32\TIMHost.dll] [N/A, ]
[C:\WINDOWS\System32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1200][C:\WINDOWS\msagent\AgentSvr.exe] [Microsoft Corporation, 2.00.0.3422]
[C:\WINDOWS\downlo~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 6]
[C:\Program Files\Microsoft Office\Office\BLNMGR.DLL] [, ]
[C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\msadp32.acm] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\System32\TIMHost.dll] [N/A, ]
[C:\WINDOWS\System32\upxdnd.dll] [N/A, ]
[PID: 356][C:\WINDOWS\System32\nslookupi.exe] [N/A, ]
[C:\WINDOWS\System32\msdebug.dll] [N/A, ]
[C:\WINDOWS\System32\RemoteDbg.dll] [N/A, ]
[C:\WINDOWS\System32\windhcp.ocx] [N/A, ]
[C:\WINDOWS\System32\WPCAP.DLL] [CACE Technologies, 3, 1, 0, 27]
[C:\WINDOWS\System32\packet.dll] [CACE Technologies, 3, 1, 0, 27]
[C:\WINDOWS\System32\WanPacket.dll] [CACE Technologies, 3, 1, 0, 27]
[C:\WINDOWS\downlo~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 6]
[PID: 2268][C:\Program Files\Rising\Rav\RsAgent.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
[C:\WINDOWS\System32\msdebug.dll] [N/A, ]
[C:\WINDOWS\System32\RemoteDbg.dll] [N/A, ]
[C:\WINDOWS\System32\WMIApiSrv.dll] [N/A, ]
[C:\WINDOWS\System32\windhcp.ocx] [N/A, ]
[C:\WINDOWS\System32\windds32.dll] [N/A, ]
[C:\WINDOWS\System32\netsrvcs.dll] [N/A, ]
[C:\WINDOWS\downlo~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 6]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[PID: 2432][C:\Program Files\WinRAR\WinRAR.exe] [N/A, ]
[C:\WINDOWS\System32\msdebug.dll] [N/A, ]
[C:\WINDOWS\System32\RemoteDbg.dll] [N/A, ]
[C:\WINDOWS\System32\WMIApiSrv.dll] [N/A, ]
[C:\WINDOWS\System32\windhcp.ocx] [N/A, ]
[C:\WINDOWS\System32\windds32.dll] [N/A, ]
[C:\WINDOWS\System32\netsrvcs.dll] [N/A, ]
[C:\WINDOWS\downlo~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 6]
[C:\WINDOWS\System32\TIMHost.dll] [N/A, ]
[C:\WINDOWS\System32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\WINDOWS\downlo~1\CnsHook.dll] [北京三七二一科技有限公司, 2.5.1.5]
[PID: 2976][C:\DOCUME~1\lenovo\LOCALS~1\Temp\Rar$EX01.656\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\WINDOWS\System32\msdebug.dll] [N/A, ]
[C:\WINDOWS\System32\RemoteDbg.dll] [N/A, ]
[C:\WINDOWS\System32\WMIApiSrv.dll] [N/A, ]
[C:\WINDOWS\System32\windhcp.ocx] [N/A, ]
[C:\WINDOWS\System32\windds32.dll] [N/A, ]
[C:\WINDOWS\System32\netsrvcs.dll] [N/A, ]
[C:\WINDOWS\downlo~1\CnsMin.dll] [北京三七二一科技有限公司, 2, 5, 0, 6]
[C:\WINDOWS\System32\TIMHost.dll] [N/A, ]
[C:\WINDOWS\System32\upxdnd.dll] [N/A, ]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
[E:\]
[AutoRun]
open=SysAuto.exe
shellexecute=SysAuto.exe
shell\打开(&O)\command=SysAuto.exe
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
隐藏进程
N/A