魔盾安全分析报告 分析类型 开始时间 结束时间 持续时间 分析引擎版本 FILE 2016-05-10 02:06:00 2016-05-10 02:08:20 140 秒 1.4-Maldun 虚拟机机器名 标签 虚拟机管理 开机时间 关机时间 win7-sp1-x64-1 win7-sp1-x64-1 KVM 2016-05-10 02:06:00 2016-05-10 02:08:20 魔盾分数 2.65 可疑的 文件详细信息 文件名 文件大小 文件类型 CRC32 MD5 SHA1 SHA256 SHA512 Ssdp PEiD LivUpdat.dll 115552 字节 PE32 xcutabl (DLL) (consol) Intl 80386 Mono/.Nt assmbly, for MS Windows 105DE691 69b93f587b93f51fdcdf7d1a47f907f 37020d05a32309a2832c1c548942857d467141 3dbf04147ff48aa8989645af49c34dc583c1424fbac5107c89b57f0b0c 71116955b5678c97574c30f2d44dcf9fc6a5148d6809959284961c1d92c2048f3c40d0873d169a11a6004f65118aa0f4c52a71b322bc1402c32af41f4 b 3072:ZI9jy0ckvHuN+xon7ubPX9lzU1XlJTqJLRObUphjWybRkp+moOv9Xc/8CI:ZI9SkvqMmz9TRkp+moOg 无匹配 Yara NET () NETDLLM () VirusTotal VirusTotal 链接 VirusTotal 扫描时间 : 2015-09-28 20:42:15 扫描结果 : 1/57 特征 提供一个 Authnticod 数字签名 md5_fingrprint: bcc52ab63517bb88cb083991371900 sha1_fingrprint: 0cbd73ddf1f571ab175b15462d524bc1a46ad sn: 168532130770536242911532824608984938739 cn: r Incorporatd 文件已被至少一个 VirusTotal 上的反病毒引擎检测为病毒 VBA32: suspctd of ZIP.MailBb 发起了一些 TP 请求 url: http://www.download.windowsupdat.c/msdownload/updat/v3/static/trustdr/n/authrootstl.cab url: http://s2.b.c/mfewtzbnmeswstajbrdgmcgabbs56bkhaoudboylb0lhpg9jxyqm4gquf9nlp8ld7lvwmanzqzn6aq8zmtmced141fl2swcyyx308b7khio%3d url: http://s1.b.c/pca3-g5.crl url: http://sv.d.c/mfewtzbnmeswstajbrdgmcgabbq6lndjdqxbjop7hvgtagfjfcqgquljtt8hkzl699gb8uk8zkt4ycmyceh7kg5pqxyimj6auftibopm%3d url: http://sv.b.c/sv.crl 检测到网络活动但没有显示在 API 日志中 运行截图 网络分析 访问主机记录 直接访问 IP 地址 国家名 是 74.125.23.138 Unitd Stats 是 74.125.23.113 Unitd Stats 是 74.125.23.102 Unitd Stats 是 74.125.23.101 Unitd Stats 是 74.125.23.100 Unitd Stats
否 23.44.155.27 Unitd Stats 否 23.44.149.163 Unitd Stats 否 116.224.86.43 China 域名解析 域名 响应 www.download.windowsupdat.c A 116.224.86.43 CNAME fg.download.windowsupdat.c.mwcnam.c CNAME nor1100.dlmix.ourdvs.c A 116.224.86.42 CNAME 2-01-3cf7-0009.cdx.cdxis.nt s2.b.c CNAME ocsp-ds.ws.mantc.c.dgky.nt CNAME 8218.dscb1.akamaidg.nt A 23.44.155.27 s1.b.c A 23.44.149.163 CNAME 6845.dscb1.akamaidg.nt CNAME crl-ds.ws.mantc.c.dgky.nt sv.d.c sv.b.c TCP 连接 IP 地址 端口 116.224.86.43 80 23.44.149.163 80 23.44.149.163 80 23.44.155.27 80 23.44.155.27 80 UDP 连接 IP 地址 端口 192.168.122.255 138 TP 请求 URL http://www.download.windowsupdat.c/msdownload/updat/v3/static/trustdr/n/authrootstl.cab TP 数据 ms do wn loa d/u pd at /v3 /st ati c/tr ust dr /n /au thr oot stl. ca b H TT P/1.1 Ca ch -C ont rol: m axag =
86 40 0 ct c If- Mo difi d- Sin c: Th u, 14 Jan 20 16 00: 22: 10 GM T If- No n- Ma tch : "0 5 9c 9b 61 4 d1 1:0 " r- nt ww w. do wn loa d. wi nd ow su pd at.co m http://s2.b.c/mfewtzbnmeswstajbrdgmcgabbs56bkhaoudboylb0lhpg9jxyqm4gquf9nlp8ld7lvwmanzqzn6aq8zmtmced141fl2swcyyx308b7khio%3d MF Ew Tz BN ME sw ST AJB rd gm CG AB BS 56 bk
HA ou D% 2B Oyl B0 Lh Pg 9Jx yq m4 gq Uf 9Nl p8 Ld 7L vw MA nz Qz n6 Aq 8z MT MC ED 14 1% 2Fl 2S WC yy X3 08 B7 Khi o% 3D ct c r- nt s2. b.c http://s2.b.c/mfewtzbnmeswstajbrdgmcgabbs56bkhaoudboylb0lhpg9jxyqm4gquf9nlp8ld7lvwmanzqzn6aq8zmtmced141fl2swcyyx308b7khio%3d MF Ew Tz BN ME sw ST AJB rd gm CG AB BS 56 bk
HA ou D% 2B Oyl B0 Lh Pg 9Jx yq m4 gq Uf 9Nl p8 Ld 7L vw MA nz Qz n6 Aq 8z MT MC ED 14 1% 2Fl 2S WC yy X3 08 B7 Khi o% 3D Ca ch -C ont rol: no -ca ch ct Pra gm a: nocac h c r- nt s2. b.c http://s1.b.c/pca3-g5.crl pc a3-
g5. crl ct c r- nt s1. b.c http://sv.d.c/mfewtzbnmeswstajbrdgmcgabbq6lndjdqxbjop7hvgtagfjfcqgquljtt8hkzl699gb8uk8zkt4ycmyceh7kg5pqxyimj6auftibopm%3d MF Ew Tz BN ME sw ST AJB rd gm CG AB BQ 6 LN DJd qx BJ Op 7h Vg T ag FJ FC Qg QU ljtt 8H kzl 69 9g B8 uk 8z Kt4 Y cm YC EH 7K G5 PQ xyi mj 6a Uf TI BO
PM %3 D ct c r- nt sv. d.c http://sv.d.c/mfewtzbnmeswstajbrdgmcgabbq6lndjdqxbjop7hvgtagfjfcqgquljtt8hkzl699gb8uk8zkt4ycmyceh7kg5pqxyimj6auftibopm%3d MF Ew Tz BN ME sw ST AJB rd gm CG AB BQ 6 LN DJd qx BJ Op 7h Vg T ag FJ FC Qg QU ljtt 8H kzl 69 9g B8 uk 8z Kt4 Y cm YC EH 7K G5 PQ xyi mj 6a Uf TI
BO PM %3 D Ca ch -C ont rol: no -ca ch ct Pra gm a: nocac h c r- nt sv. d.c http://sv.b.c/sv.crl sv. crl ct c r- nt sv. b.c
静态分析 PE 信息 初始地址 入口地址 声明校验值 实际校验值 0x10000000 0x1001bda 0x0001d01 0x0001d01 最低操作系统版本要求 4.0 PDB 路径 d:\actc_2.0\rcarcntr\livupdat\obj\rlas\livupdat.pdb 编译时间 2015-06-22 17:10:56 版本信息 Translat: Lgalpyright: Assmbly Vrs: IntrnalNam: 0x0000 0x04b0 (C) All rights rsrvd 2.1.3103.0 LivUpdat.dll FilVrs: 2.01.3103.0 mmnts: ProductNam: LivUpdat Car Cntr ProductVrs: 2.01.3103.0 FilDscri OriginalFilnam: LivUpdat LivUpdat.dll PE 数据组成 名称 虚拟地址 虚拟大小 原始数据大小 特征 熵 (Entropy).txt 0x00002000 0x00019db4 0x0001900 IMA_SCN_CNT_CODE IMA_SCN_MEM_EXECUTE IMA_SCN_MEM_READ 5.61.rsrc 0x0001c000 0x00000370 0x00000400 IMA_SCN_CNT_INITIALIZED_DATA IMA_SCN_MEM_READ 2.87.rloc 0x0001000 0x0000000c 0x00000200 IMA_SCN_CNT_INITIALIZED_DATA IMA_SCN_MEM_DISCARDABLE IMA_SCN_MEM_READ 0.10 覆盖 偏移量 : 大小 : 0x0001a600 0x00001d60 资源 名称 偏移量 大小 语言 子语言熵 (Entropy) 文件类型 RT_VERSION 0x0001c058 0x00000314 LANG_NEUTRAL SUBLANG_NEUTRAL 3.37 data 导入 库 mscor.dll: 0x10002000 - _rdllmain 投放文件 无信息 行为分析 互斥量 (Mutxs) Local\MSCTF.Asm.MutxDfault1 执行的命令无信息 创建的服务无信息 启动的服务无信息 进程 rundll32.x PID: 2664, 上一级进程 PID: 2152
访问的文件 C:\rs\tst\AppData\Local\Tmp\LivUpdat.dll C:\rs\tst\AppData\Local\Tmp\LivUpdat.dll.123.Manifst C:\rs\tst\AppData\Local\Tmp\LivUpdat.dll.124.Manifst C:\rs\tst\AppData\Local\Tmp\LivUpdat.dll.2.Manifst C:\Windows\SysWOW64\rundll32.x C:\Windows\Fonts\staticcach.dat \Dvic\KscDD C:\Windows\Globalizat\Sorting\sortdfault.nls 读取的文件 C:\rs\tst\AppData\Local\Tmp\LivUpdat.dll C:\rs\tst\AppData\Local\Tmp\LivUpdat.dll.123.Manifst C:\rs\tst\AppData\Local\Tmp\LivUpdat.dll.124.Manifst C:\rs\tst\AppData\Local\Tmp\LivUpdat.dll.2.Manifst C:\Windows\SysWOW64\rundll32.x C:\Windows\Fonts\staticcach.dat \Dvic\KscDD C:\Windows\Globalizat\Sorting\sortdfault.nls 修改的文件无信息 删除的文件无信息 注册表键 HKEY_LOCAL_MACHINE\Swar\M\Windows\CurrntVrs\SidBySid HKEY_CURRENT_USER\Swar\M\.NETFramwork HKEY_LOCAL_MACHINE\Swar\M\.NETFramwork HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Nod\M\.NETFramwork\IJWEntrypointmpatMod HKEY_LOCAL_MACHINE\Swar\M\Windows\Windows Error Rporting\WMR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Nod\M\Windows\Windows Error Rporting\WMR\Disabl HKEY_LOCAL_MACHINE\Systm\CurrntntrolSt\ntrol\Nls\Local HKEY_LOCAL_MACHINE\Systm\CurrntntrolSt\ntrol\Nls\Local\Altrnat Sorts HKEY_LOCAL_MACHINE\Systm\CurrntntrolSt\ntrol\Nls\Languag Groups HKEY_LOCAL_MACHINE\SYSTEM\ntrolSt001\ntrol\Nls\Local\00000804 HKEY_LOCAL_MACHINE\SYSTEM\ntrolSt001\ntrol\Nls\Languag Groups\a HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\FontLink\SystmLink HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\DataStor_V1.0 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\DataStor_V1.0\Disabl HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\DataStor_V1.0\DataFilPath HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan1 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan2 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan3 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan4 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan5 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan6 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan7 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan8 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan9 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan10 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan11 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan12 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan13 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan14 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan15 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan16 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\\x5\xb\xa\x8\xbd\xaf\x9\x9b\x85\x9\xbb\x91 HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\mpatibility\rundll32.x HKEY_LOCAL_MACHINE\Swar\M\CTF\TIP\{0000897b-83df-4b96-b07-0fb58b01c4a4}\LanguagProfil\0x00000000\{0001ba3-d56-483d-a22-aa25577436} HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{0000897b-83df-4b96-b07-0fb58b01c4a4}\LanguagProfil\0x00000000\{0001ba3-d56-483d-a22- aa25577436}\enabl HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\ HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{0000897b-83df-4b96-b07-0fb58b01c4a4}\Catgory\Catgory\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Catgory\Catgory\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Catgory\Catgory\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Catgory\Catgory\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{3FC47A08-E5C9-4BCA-A2C7-BC9A282AED14}\Catgory\Catgory\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Catgory\Catgory\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Catgory\Catgory\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Catgory\Catgory\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Catgory\Catgory\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Catgory\Catgory\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Catgory\Catgory\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Catgory\Catgory\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Catgory\Catgory\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Catgory\Catgory\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Catgory\Catgory\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Catgory\Catgory\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{FA445657-9379-11D6-B41A-00065B83EE53}\Catgory\Catgory\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_CURRENT_USER HKEY_CURRENT_USER\Kyboard Layout\Toggl HKEY_CURRENT_USER\Kyboard Layout\Toggl\Languag tky HKEY_CURRENT_USER\Kyboard Layout\Toggl\tky HKEY_CURRENT_USER\Kyboard Layout\Toggl\Layout tky HKEY_CURRENT_USER\Swar\M\CTF\DirctSwitchtkys HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Nod\M\CTF\EnablAnchorntxt 读取的注册表键 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Nod\M\.NETFramwork\IJWEntrypointmpatMod HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Nod\M\Windows\Windows Error Rporting\WMR\Disabl
HKEY_LOCAL_MACHINE\SYSTEM\ntrolSt001\ntrol\Nls\Local\00000804 HKEY_LOCAL_MACHINE\SYSTEM\ntrolSt001\ntrol\Nls\Languag Groups\a HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\DataStor_V1.0\Disabl HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\DataStor_V1.0\DataFilPath HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan1 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan2 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan3 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan4 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan5 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan6 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan7 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan8 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan9 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan10 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan11 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan12 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan13 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan14 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan15 HKEY_LOCAL_MACHINE\SOFTWARE\M\Windows NT\CurrntVrs\LanguagPack\SurrogatFallback\Plan16 HKEY_LOCAL_MACHINE\SOFTWARE\M\CTF\TIP\{0000897b-83df-4b96-b07-0fb58b01c4a4}\LanguagProfil\0x00000000\{0001ba3-d56-483d-a22- aa25577436}\enabl HKEY_CURRENT_USER\Kyboard Layout\Toggl\Languag tky HKEY_CURRENT_USER\Kyboard Layout\Toggl\tky HKEY_CURRENT_USER\Kyboard Layout\Toggl\Layout tky HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Nod\M\CTF\EnablAnchorntxt 修改的注册表键无信息 删除的注册表键无信息 API 解析 mscor.dll._rexmain mscor.dll._rimanloading mscor.dll._rvalidatimag advapi32.dll.rgopnkyexw advapi32.dll.rgquryvaluexw advapi32.dll.rgclky gdi32.dll.gtlayout gdi32.dll.gdiralizatinfo gdi32.dll.fontislinkd advapi32.dll.rgquryinfokyw gdi32.dll.gttxtfacaliasw advapi32.dll.rgenumvaluw advapi32.dll.rgquryvaluexa advapi32.dll.rgenumkyexw uxthm.dll.thminitapiok usr32.dll.isprocssdpiawar dwmapi.dll.dwmismpitenabld gdi32.dll.gdiismtaprintdc ol32.dll.initializex ol32.dll.uninitializ crbas.dll.systmfunct036 ol32.dll.rgistrinitializspy ol32.dll.rvokinitializspy krnl32.dll.sortgthandl krnl32.dll.sortclhandl 2016 上海魔盾信息科技有限公司