正在运行的进程
[C:\WINDOWS\SYSTEM\HPZS9X14.DLL] [HP, 14.00.00.43730]
[C:\WINDOWS\SYSTEM\ADIMON.DLL] [Autodesk, Inc., 3,0,14,177]
[C:\WINDOWS\SYSTEM\HEIDI3.DLL] [Autodesk, Inc., 3,0,14,177]
[PID: 4294963533][C:\WINDOWS\SYSTEM\SPOOL32.EXE] [Microsoft Corporation, 4.10.1998]
[PID: 4294958201][C:\WINDOWS\SYSTEM\MPREXE.EXE] [Microsoft Corporation, 4.10.1998]
[C:\WINDOWS\SYSTEM\DHCPCSVC.DLL] [N/A, N/A]
[C:\PROGRAM FILES\RISING\RFW\MPORTS.DLL] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[C:\PROGRAM FILES\RISING\RFW\PROCLIB.DLL] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 5]
[C:\PROGRAM FILES\RISING\RFW\RFWAPI.DLL] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 5]
[C:\PROGRAM FILES\RISING\RFW\RFWDRV.DLL] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 9]
[C:\PROGRAM FILES\RISING\RFW\RFWLOG.DLL] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 2]
[C:\PROGRAM FILES\RISING\RFW\RFWRULE.DLL] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 3]
[PID: 4294874157][C:\PROGRAM FILES\RISING\RFW\RFWSRV.EXE] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 30]
[C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\WINDOWS\SYSTEM\DHCPCSVC.DLL] [N/A, N/A]
[PID: 4294650945][C:\WINDOWS\EXPLORER.EXE] [Microsoft Corporation, 4.72.3110.1]
[PID: 4294649793][C:\WINDOWS\SYSTEM\RPCSS.EXE] [Microsoft Corporation, 4.71.2900]
[PID: 4294703749][C:\WINDOWS\SYSTEM\INTERNAT.EXE] [Microsoft Corporation, 4.10.2222]
[PID: 4294690441][C:\WINDOWS\TASKMON.EXE] [Microsoft Corporation, 4.10.1998]
[PID: 4294693001][C:\WINDOWS\SYSTEM\SYSTRAY.EXE] [Microsoft Corporation, 4.10.2222]
[PID: 4294579777][C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE] [RealNetworks, Inc., 0.1.0.3292]
[PID: 4294576021][C:\WINDOWS\SYSTEM\STIMON.EXE] [Microsoft Corporation, 4.10.2222]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPODVD09.DLL] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPODDCOMM09.DLL] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\UNLOAD\HPNKHTA.DLL] [Hewlett-Packard, 7.0.0.229]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPODIO08.DLL] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQCOB08.DLL] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPOCXI08.DLL] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPHTRA09.DLL] [Hewlett-Packard, 60,0,114,000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPOTRADD.DLL] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQTAO08.DLL] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQTRA08.RSC] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQUIO08.DLL] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQCXM08.DLL] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[PID: 4294577729][C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQTRA08.EXE] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[PID: 4294824749][C:\WINDOWS\SYSTEM\WMIEXE.EXE] [Microsoft Corporation, 5.00.1755.1]
[C:\PROGRAM FILES\RISING\RFW\PNGDLL.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\PROGRAM FILES\RISING\RFW\RSXML.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\PROGRAM FILES\RISING\RFW\RFWCTRL.DLL] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[C:\PROGRAM FILES\RISING\RFW\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 4294635277][C:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 56]
[C:\PROGRAM FILES\RISING\RFW\RSGUILIB.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\CRM\HPQCRMCM.DLL] [Hewlett-Packard Company, 70.0.78.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\CRM\XMLPARSE.DLL] [N/A, 1, 0, 0, 1]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\CRM\XMLTOK.DLL] [N/A, 1, 0, 0, 1]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPOCXI08.DLL] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQSEM08.RSC] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQSTV08.DLL] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQCOB08.DLL] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQSTI08.DLL] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQSTE08.RSC] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQCXM08.DLL] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[PID: 4294770193][C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQSTE08.EXE] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQMFC09.DLL] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQTAP08.DLL] [Hewlett-Packard Development Company, L.P., 70.0.170.000]
[C:\WINDOWS\SYSTEM\DCIMAN32.DLL] [Intel(R) Corp., Microsoft Corp., 4.03.1998]
[C:\WINDOWS\SYSTEM\NVDD32.DLL] [NVidia Corporation, 4.13.01.1241]
[C:\WINDOWS\SYSTEM\NVARCH32.DLL] [NVidia Corporation, 4.13.01.1241]
[PID: 4294009713][C:\WINDOWS\SYSTEM\DDHELP.EXE] [Microsoft Corporation, 4.06.03.0518]
[C:\PROGRAM FILES\RISING\RAV\PNGDLL.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\PROGRAM FILES\RISING\RAV\RSXML.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL] [rising, 18, 0, 0, 1]
[C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[PID: 4293948565][C:\PROGRAM FILES\RISING\RAV\RAVMON.EXE] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 45]
[C:\PROGRAM FILES\RISING\RAV\BWLIST.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[C:\PROGRAM FILES\RISING\RAV\RSGUILIB.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH9B.OCX] [Adobe Systems, Inc., 9,0,28,0]
[C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\DOWNLOADED PROGRAM FILES\BARHELP24.0.DLL] [HDT, Inc., 1, 9, 5, 0]
[E:\PROGRAM FILES\TENCENT\QQIEHELPER.DLL] [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
[C:\WINDOWS\SYSTEM\OLEACC.DLL] [Microsoft Corporation, 4.2.2209.0]
[C:\PROGRAM FILES\XI\NETTRANSPORT 2\NTIEHELPER.DLL] [Xi, 1.60.11]
[C:\PROGRAM FILES\FLASHGET\JCCATCH.DLL] [Amaze Soft, 1, 1, 4, 0]
[PID: 4294726809][C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINDOWS\SYSTEM\GDIFONT3.HDI] [Autodesk, Inc., 3,0,14,177]
[C:\PROGRAM FILES\AUTOCAD R14\RBLAST3.HDI] [Autodesk, Inc., 3,0,14,177]
[C:\PROGRAM FILES\AUTOCAD R14\LFB3.HDI] [Autodesk, Inc., 3,0,14,177]
[C:\PROGRAM FILES\AUTOCAD R14\GDI3.HDI] [Autodesk, Inc., 3,0,14,177]
[C:\PROGRAM FILES\AUTOCAD R14\BONUS\CADTOOLS\AC_BONUS.DLL] [N/A, N/A]
[C:\PROGRAM FILES\AUTOCAD R14\ACADAPP.ARX] [N/A, N/A]
[C:\PROGRAM FILES\AUTOCAD R14\ACMTED.ARX] [Autodesk, 1, 0, 0, 1]
[C:\PROGRAM FILES\AUTOCAD R14\OLEAPROT.ARX] [N/A, N/A]
[C:\PROGRAM FILES\AUTOCAD R14\DRV\PLPHPLP.DLL] [N/A, N/A]
[C:\PROGRAM FILES\AUTOCAD R14\DRV\PLSYS.DLL] [N/A, N/A]
[C:\PROGRAM FILES\AUTOCAD R14\ACADBTN.DLL] [N/A, N/A]
[C:\PROGRAM FILES\AUTOCAD R14\ACADRES.DLL] [N/A, N/A]
[PID: 4294589157][C:\PROGRAM FILES\AUTOCAD R14\ACAD.EXE] [Autodesk, Inc., R14.0.01]
[C:\PROGRAM FILES\AUTOCAD R14\ADCTRLS.DLL] [ , 1, 0, 0, 1]
[C:\PROGRAM FILES\AUTOCAD R14\LIBACGE.DLL] [Autodesk, Inc., P.0.33]
[C:\PROGRAM FILES\AUTOCAD R14\ACW32S32.DLL] [N/A, N/A]
[C:\PROGRAM FILES\AUTOCAD R14\DSWHIP.DLL] [Autodesk, Inc., I3.0]
[C:\PROGRAM FILES\AUTOCAD R14\DLINT3.DLL] [Autodesk, Inc., 3,0,14,177]
[C:\WINDOWS\SYSTEM\HEIDI3.DLL] [Autodesk, Inc., 3,0,14,177]
[C:\PROGRAM FILES\AUTOCAD R14\UCLIB32.DLL] [Autodesk Inc., 1, 0, 1, 6]
[C:\PROGRAM FILES\AUTOCAD R14\ACFIRST.DLL] [N/A, N/A]
[C:\PROGRAM FILES\AUTOCAD R14\SH31W32.DLL] [N/A, N/A]
[PID: 4161865021][C:\PROGRAM FILES\WINRAR\WINRAR.EXE] [N/A, N/A]
[PID: 4294538637][C:\WINDOWS\TEMP\RAR$EX01.514\SRENG.EXE] [Smallfrogs Studio, 2.3.13.690]
--------------------------------------------------------------------------------
文件关联
.TXT OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [C:\WINDOWS\winhlp32.exe %1]
.INI OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF OK. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS OK. [C:\WINDOWS\WScript.exe "%1" %*]
.JS OK. [C:\WINDOWS\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
--------------------------------------------------------------------------------
Winsock 提供者
MS.w95.spi.osp
C:\WINDOWS\SYSTEM\mswsosp.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.tcp
C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.udp
C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.raw
C:\WINDOWS\SYSTEM\msafd.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.rsvptcp
C:\WINDOWS\SYSTEM\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
MS.w95.spi.rsvpudp
C:\WINDOWS\SYSTEM\rsvpsp.dll(Microsoft Corporation, Microsoft Windows Rsvp 1.0 Service Provider)
--------------------------------------------------------------------------------
Autorun.inf
[D:\]
[AutoRun]
open=OSO.exe
shellexecute=OSO.exe
shell\Auto\command=OSO.exe
[E:\]
[AutoRun]
open=OSO.exe
shellexecute=OSO.exe
shell\Auto\command=OSO.exe
--------------------------------------------------------------------------------
HOSTS 文件
N/A
--------------------------------------------------------------------------------
API HOOK
N/A
--------------------------------------------------------------------------------