[C:\WINDOWS\system32\ctagent.dll] [Creative Technology Ltd, 1, 0, 0, 3]
[C:\WINDOWS\system32\ctspkhlp.dll] [Creative Technology Ltd, 1, 0, 0, 2]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\46FBE524.DLL] [Microsoft Corporation, ]
[PID: 432][C:\Program Files\Rising\KakaToolBar\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
[C:\Program Files\Rising\KakaToolBar\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\lihmdjad.dll] [Microsoft Corporation, 5, 2, 2265, 3211]
[C:\WINDOWS\system32\46FBE524.DLL] [Microsoft Corporation, ]
[PID: 484][C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE] [Creative Technology Ltd, 2.0.0.3]
[C:\WINDOWS\system32\lihmdjad.dll] [Microsoft Corporation, 5, 2, 2265, 3211]
[C:\PROGRA~1\Creative\ShareDLL\PFMOD.DLL] [Creative Technology Ltd., 6.3.11]
[C:\WINDOWS\system32\46FBE524.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\SYSTEM32\CTDEVCON.DLL] [Creative Technology Ltd, 5.12.01.0244-1.31.0040]
[C:\WINDOWS\SYSTEM32\ctosuser.dll] [Creative Technology Ltd, 5.12.01.0244-1.31.0040]
[C:\WINDOWS\SYSTEM32\PIAPROXY.DLL] [Creative Technology Ltd, 5.12.01.0244-1.31.0040]
[C:\WINDOWS\SYSTEM32\CTDPROXY.DLL] [Creative Technology Ltd, 5.12.01.0244-1.31.0040]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.CRL] [Creative Technology Ltd, 2.0.0.0]
[C:\Program Files\Creative\MediaSource\RemoteControl\RCRx\rcks1k.dll] [Creative Technology Ltd., 1.40.23]
[C:\Program Files\Creative\MediaSource\RemoteControl\RCRx\iR2000.dll] [Creative Technology Ltd., 1.30.25]
[C:\Program Files\Creative\MediaSource\RemoteControl\RCRx\rm-1000.dll] [Creative Technology Ltd., 1.40.11]
[C:\Program Files\Creative\MediaSource\RemoteControl\OSDDisp.DLL] [Creative Technology Ltd, 2.0.0.1]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 520][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\lihmdjad.dll] [Microsoft Corporation, 5, 2, 2265, 3211]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\46FBE524.DLL] [Microsoft Corporation, ]
[PID: 256][C:\Program Files\jj4\jiajiasr.exe] [加加工作组, 4, 1, 0, 43]
[C:\WINDOWS\system32\lihmdjad.dll] [Microsoft Corporation, 5, 2, 2265, 3211]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\46FBE524.DLL] [Microsoft Corporation, ]
[PID: 1616][C:\WINDOWS\system32\40776494.exe] [N/A, ]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9690]
[C:\WINDOWS\system32\lihmdjad.dll] [Microsoft Corporation, 5, 2, 2265, 3211]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\46FBE524.DLL] [Microsoft Corporation, ]
[PID: 3180][D:\软\MYIE2\MyIE.exe] [MY Soft Technology, 0, 9, 26, 30]
[C:\WINDOWS\system32\lihmdjad.dll] [Microsoft Corporation, 5, 2, 2265, 3211]
[D:\软\MYIE2\Plugin\ViewSource\ViewSrc.dll] [, 1, 0, 0, 1]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[D:\软\MYIE2\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[D:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\WBJJU.IME] [北京六合源软件技术有限公司, 2, 8, 1, 0]
[C:\WINDOWS\system32\WbCodeU.dll] [, 2, 8, 1, 0]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[PID: 2532][D:\软\迅雷\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5.3.0.220]
[D:\软\迅雷\Program\UpdateDownload.dll] [Thunder Networking Technologies,LTD, 1, 0, 1, 8]
[D:\软\迅雷\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 71]
[D:\软\迅雷\Program\log4cplus.dll] [, 1, 0, 2, 1]
[D:\软\迅雷\Program\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031]
[D:\软\迅雷\Program\asyn_dns.dll] [N/A, ]
[D:\软\迅雷\Program\msgmanage.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 15]
[D:\软\迅雷\Program\historyinfo_manage.dll] [Thunder Networking Technologies,LTD, 5, 2, 0, 148]
[C:\WINDOWS\system32\lihmdjad.dll] [Microsoft Corporation, 5, 2, 2265, 3211]
[D:\软\迅雷\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 1, 0, 18]
[D:\软\迅雷\Program\FloatBar.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
[D:\软\迅雷\Components\InMedia\iEmbedShell.dll] [ , 1, 0, 0, 11]
[D:\软\迅雷\Components\InMedia\iEmbed04.dll] [ , 2, 3, 0, 37]
[D:\软\迅雷\Components\P4PClient\P4PClient.dll] [Thunder Networking Technologies,LTD, 1, 0, 3, 8]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[D:\软\迅雷\Program\iTargetAd.dll] [Thunder Networking Technologies,LTD, 1, 0, 1, 55]
[D:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\PROGRA~1\OCINS\srchsp.dll] [中国互联网络信息中心(CNNIC), 2, 6, 0, 0]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[PID: 3500][C:\Program Files\WinRAR\WinRAR.exe] [N/A, ]
[C:\WINDOWS\system32\lihmdjad.dll] [Microsoft Corporation, 5, 2, 2265, 3211]
[C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.3790.3646 built by: DNSRV(bld4act)]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 3132][C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX02.594\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\WINDOWS\system32\lihmdjad.dll] [Microsoft Corporation, 5, 2, 2265, 3211]
[C:\Program Files\Rising\KakaToolBar\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
[C:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe
[D:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe
[E:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
隐藏进程
[600] C:\Program Files\Common Files\VideoCap10.exe
[2980] C:\Program Files\Internet Explorer\IEXPLORE.EXE
!R@y?T4öbbs.ikaka.comÚ_bÊk)èS¼v