kjsgdhe - 2006-10-6 9:12:00
小M菜鸟一名,自知已身陷毒窝,可小M我不会重装系统呀=~0~= 哪位大侠可以先让 我的瑞星正常运行呀(现在一打开就跳没了,只留下一只小狮子坐在一边)

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<svc><C:\WINDOWS\svchost.exe> [N/A]
<updatereal><C:\WINDOWS\realupdate.exe other> [N/A]
<msnnt><C:\WINDOWS\winampc.exe> []
<Xplus_spy><"C:\Documents and Settings\hgy\桌面\Q素材\新建文件夹\xvcclip.exe" /min> [N/A]
<Google Desktop Search><; "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup> [N/A]
<MSMSGS><; "C:\Program Files\Messenger\msmsgs.exe" /background> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<{FCFB4D75-0A70-2052-0930-030309120056}><"C:\Program Files\Common Files\{FCFB4D75-0A70-2052-0930-030309120056}\Update.exe" te-110-12-0000001> [N/A]
<rx><C:\WINDOWS\system32\explore.exe> [N/A]
<zz><C:\WINDOWS\system32\intenet.exe> [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><C:\WINDOWS\rundl132.exe> [N/A]
<run><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon><ctfmon.exe> [(Verified)Microsoft Corporation]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<supdate2.dll><RUNDLL32.EXE C:\WINDOWS\system32\supdate2.dll,Run> [N/A]
<Desktop><C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll> [N/A]
<RichMedia><C:\WINDOWS\system32\Rundll32.exe "C:\PROGRA~1\pcast\hbcast.dll",WaitWindows> [Shanghai Henbang Technology Co., Ltd]
<svc><C:\WINDOWS\svchost.exe> [N/A]
<spoolsv><C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer> [广州傲讯信息科技有限公司]
<SoundMam><C:\WINDOWS\system32\SVOHOST.exe> [N/A]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
<Update><C:\Program Files\Common Files\UPDATE2\Update.exe> [N/A]
<realtpsk><C:\WINDOWS\system\realsched.exe> [N/A]
<IntelFile><C:\WINDOWS\system32\IntelFile.exe> [N/A]
<5476721><C:\WINDOWS\system32\5476721.exe> [N/A]
<-249901><C:\WINDOWS\system32\-249901.exe> [N/A]
<helper.dll><; C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32> []
<Cmaudio><; RunDll32 cmicnfg.cpl,CMICtrlWnd> [N/A]
<RfwMain><; C:\Program Files\Rising\Rfw\rfwmain.exe> [N/A]
<SoundMan><; SOUNDMAN.EXE> [(Verified)Realtek Semiconductor Corp.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<kokv><C:\WINDOWS\system\122i580.exe> [N/A]
<DTService><rundll32.exe C:\WINDOWS\system32\soundmix.dll,Load> []
<CONFIGURATION><rundll32.exe C:\WINDOWS\system32\tapidef.dll,Start> []
<DEFAULT><rundll32.exe C:\WINDOWS\system32\SYSPOL~1.DLL,Start> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><C:\WINDOWS\system32\SoDAHK.DLL> [Sogou.com Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINDOWS\DOWNLO~1\CnsHook.dll> [北京三七二一科技有限公司]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad]
<DelayRun><C:\WINDOWS\122d5800.dll> [N/A]
==================================
启动文件夹
[-50639]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\-50639.lnk --> C:\WINDOWS\system32\-50639.exe [N/A]><N>
[-67416]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\-67416.lnk --> C:\WINDOWS\system32\-67416.exe [N/A]><N>
[IE-Bar]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\IE-Bar.lnk --> C:\PROGRA~1\COMMON~1\IE-Bar\iebar.exe [N/A]><N>
[腾讯QQ]
<C:\Documents and Settings\hgy\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\PROGRA~1\TENCENT\QQ\qqCfg.exe [Microsoft Corporation. All rights reserved.]><N>
==================================
服务
[ASP.NET Work State Service / aspwstate]
<C:\WINDOWS\System32\svchost.exe -k aspwstate-->c:\windows\system32\aspwswin.dll><Microsoft Corporation>
[Network IPSEC Connections / BKMARKS]
<C:\WINDOWS\SYSTEM32\RUNDLL.EXE C:\WINDOWS\SYSTEM32\WBEM\SMTPCONFS.DLL,Export 1087><Microsoft Corporation>
[Network Engine / Hardware]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\mssapi.dll><Microsoft Corporation>
[Human Interface Device Access / HidServ]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Spectrum24 Events Monitor / IPRIP]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\acss.dll><LINKMEDIA Tech>
[Network Logons / NetWorkLogons]
<rundll32.exe KB27861001.log,start><Microsoft Corporation>
[NetFrame Wireless Configuration / NFSWZCSVC]
<C:\WINDOWS\System32\svchost.exe -k NFSWZCSVC-->c:\windows\system32\nfswzwin32.dll><Microsoft Corporation>
[NetMeeting Remote Desktop Agent / Nwsapagent]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\Nwsapagent.dll><LINKMEDIA Tech>
[P4P Service / P4P Service]
<C:\Program Files\Common Files\Sogou PXP\p2psvr.exe><Sohu.com Inc.>
[Rising Personal Firewall Service / RfwService]
<c:\program files\rising\rfw\rfwsrv.exe><N/A>
[Rising Process Communication Center / RsCCenter]
<"C:\我的下载\瑞兴杀毒\Rising\Rav\CCenter.exe"><N/A>
[RsRavMon Service / RsRavMon]
<"C:\我的下载\瑞兴杀毒\Rising\Rav\Ravmond.exe"><N/A>
[Logical Disk Manager Amdinistrative Service / Service27332]
<c:\windows\system\taskmgr.exe><>
[System / System]
<C:\WINDOWS\System.exe><N/A>
kjsgdhe - 2006-10-6 9:51:00
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[MMCPlayer Class]
{05C1004E-2596-48E5-8E26-39362985EEB9} <C:\WINDOWS\Downloaded Program Files\MMCShell.dll, Sohu.com Inc.>
[InstallProxy Class]
{57F5485B-9F32-42CB-BE9C-FDDAD250ECB7} <C:\WINDOWS\Downloaded Program Files\Kctl.dll, Kuho.com>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[Installer Class]
{E055C02E-6258-40FF-80A7-3BDA52FACAD7} <C:\WINDOWS\Downloaded Program Files\speedtest2.dll, TODO: <Company name>>
[Google Script Object]
{00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <, N/A>
[ActiveMovieControl Object]
{05589FA1-C356-11CE-BF01-00AA0055595A} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[MMCPlayer Class]
{05C1004E-2596-48E5-8E26-39362985EEB9} <C:\WINDOWS\Downloaded Program Files\MMCShell.dll, Sohu.com Inc.>
[IEMonitor Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\Program Files\DeskAdTop\deskipn.dll, >
[CPub Object]
{0CA51D02-7739-43EA-8D9A-1E8AD4327B03} <C:\Program Files\P4P\sodaie.dll, Sogou.com Inc.>
[PeerDraw Class]
{10072CEC-8CC1-11D1-986E-00A0C955B42E} <C:\Program Files\Common Files\Microsoft Shared\VGX\vgx.dll, Microsoft Corporation>
[MyIEHelper Class]
{16B770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5003.dll, Microsoft Corporation>
[XLink Class]
{18F57D30-EF36-4C0E-9343-7BFA6DF79B4A} <C:\WINDOWS\system32\wshcon32.dll, >
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} <, N/A>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[XML DOM Document]
{2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\system32\msxml3.dll, N/A>
[]
{2A4956FD-BE98-4104-ABEB-97029B3175BB} <C:\WINDOWS\system32\sys32dev.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[google bar]
{3020C3F1-744B-4C9E-8404-DBCD3705D6A9} <C:\WINDOWS\Win32ef.dll, N/A>
[SYM]
{36BF6929-DCBC-4CCD-A620-C5E3BBA77B95} <C:\WINDOWS\system32\usercrd.dll, >
[雅虎助手]
{406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[超级兔子上网精灵]
{43869BB3-22FD-4F15-9B46-238106BA2F4E} <C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll, Xiang Feng Technology>
[raObject Class]
{46F194EB-B7DB-4B7A-BD42-5FF39FD17664} <C:\PROGRA~1\pcast\hbcast.dll, Shanghai Henbang Technology Co., Ltd>
[HHCtrl Object]
{52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <, N/A>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Yahoo!Live]
{57421194-58FB-49AE-9B4F-FD48869B9AD4} <C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll, >
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[]
{669751ED-D558-49AE-B01A-3B374CC7910E} <C:\WINDOWS\system32\ssup.dll, N/A>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Kuaiso Toolsbar]
{6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89} <C:\Program Files\Kuaiso Toolsbar\Kuaiso_06003.dll, IE Toolbar>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[我的订阅]
{8755CE6E-0BF7-4441-8751-FB728941B0B4} <C:\Program Files\P4P\rss.dll, Sohu.com Inc.>
[Microsoft Web 浏览器]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[IeCatch2 Class]
{A5366673-E8CA-11D3-9CD9-0090271D075B} <, N/A>
[Google Toolbar Helper]
{AA58ED58-01DD-4D91-8333-CF10577473F7} <, N/A>
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[ToolBar888]
{CBCC61FA-0221-4CCC-B409-CEE865CACA3A} <C:\Program Files\ToolBar888\MyToolBar.dll, N/A>
[AUDIO__MP3 Moniker Class]
{CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_ASF Moniker Class]
{CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
{CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[信息检索]
{CE7C3CF0-98A8-474D-B2B5-1ED7E2E3B004} <C:\WINDOWS\system32\IEHelper.dll, N/A>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[CnsHook Class]
{D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\DOWNLO~1\CnsHook.dll, 北京三七二一科技有限公司>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[搜狗工具条]
{DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} <C:\Program Files\P4P\ToolBar.dll, Sogou.com Inc.>
[Installer Class]
{E055C02E-6258-40FF-80A7-3BDA52FACAD7} <C:\WINDOWS\Downloaded Program Files\speedtest2.dll, TODO: <Company name>>
[IEHlpObj Class]
{EFBCA345-14DC-4640-994E-4AF1DFDEB4FD} <C:\Program Files\Riptide\Plugin\Plugin.dll, >
[BHelper Class]
{F2E37336-BFDB-409B-8D0E-6F013C438B20} <C:\WINDOWS\122o5800.dll, N/A>
[WMHlprObj Class]
{F5824EFB-728A-4726-A5A5-85A68B20EDC3} <C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll, N/A>
[&_找本网页音视频链接_]
<C:\Program Files\Riptide\Plugin\Monitor.htm, N/A>
[>>彩信发送<<]
<res://C:\Program Files\MMSAssist\Mmsass~1.dll/mms.htm, N/A>
[Google 搜索(&G)]
<res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html, N/A>
[上传到QQ网络硬盘]
<c:\program files\tencent\qq\AddToNetDisk.htm, N/A>
[使用搜狗直通车下载]
<C:\Program Files\P4P\dl.htm, N/A>
[加入POCO网摘(&K)]
<http://my.poco.cn/fav/rightClick.php, N/A>
[反向链接]
<res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html, N/A>
[发送图片到手机]
<C:\Program Files\P4P\cx.htm, N/A>
[我的POCO网摘(&O)]
<http://my.poco.cn/fav/open_myfav.php, N/A>
[易趣购物]
<C:\Program Files\AD4All\link1\ebaylink.htm, N/A>
[添加到QQ自定义面板]
<c:\program files\tencent\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<c:\program files\tencent\qq\AddEmotion.htm, N/A>
[添加到“我的订阅”]
<C:\Program Files\P4P\rss.htm, N/A>
[用QQ彩信发送该图片]
<c:\program files\tencent\qq\SendMMS.htm, N/A>
[类似网页]
<res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html, N/A>
[缓存的网页快照]
<res://c:\program files\google\GoogleToolbar1.dll/cmcache.html, N/A>
[翻译英文字词(&T)]
<res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html, N/A>
[访问通用网址]
<C:\Program Files\CNNIC\Cdn\cnnic.htm, N/A>
[雅虎搜索]
<res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246, N/A>
[+订阅RSS到POCO RSS在线阅读器(&S)]
<http://my.poco.cn/rssr/rightclick.php, N/A>
kjsgdhe - 2006-10-6 9:53:00
正在运行的进程
[PID: 452][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 500][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 524][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\tapidef.dll] [, 1, 0, 0, 1]
[PID: 568][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 580][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 756][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 800][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[PID: 872][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\windows\system32\acss.dll] [LINKMEDIA Tech, 1, 5, 0, 4]
[c:\windows\system32\nwsapagent.dll] [LINKMEDIA Tech, 1, 5, 0, 4]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[PID: 940][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1036][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1244][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\WINDOWS\system32\KB27861001.log] [N/A, N/A]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\tapidef.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\vDll.dll] [N/A, N/A]
[C:\WINDOWS\system32\soundmix.dll] [, 1, 4, 0, 0]
[C:\WINDOWS\system32\msicn\msibm.dll] [广州傲讯信息科技有限公司, 2, 0, 0, 1]
[C:\WINDOWS\system32\winscok.dll] [N/A, N/A]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[C:\WINDOWS\system32\SystemInput.dll] [N/A, N/A]
[C:\WINDOWS\system32\msicn\plugins\as.dll] [广州傲讯信息科技有限公司, 2, 0, 0, 1]
[C:\WINDOWS\system32\msicn\plugins\bm.dll] [广州傲讯信息科技有限公司, 2, 0, 0, 1]
[C:\WINDOWS\system32\msicn\plugins\bse.dll] [广州傲讯信息科技有限公司, 2, 0, 0, 1]
[C:\WINDOWS\system32\msicn\plugins\lup.dll] [广州傲讯信息科技有限公司, 2, 0, 0, 1]
[C:\WINDOWS\system32\msicn\plugins\navangel.dll] [广州傲讯信息科技有限公司, 2, 0, 0, 1]
[C:\Program Files\DeskAdTop\fshook.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\myrx.dll] [N/A, N/A]
[C:\WINDOWS\system32\myztr.dll] [N/A, N/A]
[C:\WINDOWS\system32\sys32dev.dll] [N/A, N/A]
[C:\WINDOWS\Win32ef.dll] [N/A, N/A]
[C:\WINDOWS\system32\usercrd.dll] [, 1, 0, 0, 1]
[C:\Program Files\ToolBar888\MyToolBar.dll] [N/A, 1, 0, 0, 1]
[C:\WINDOWS\system32\IEHelper.dll] [N/A, 1, 0, 0, 1]
[C:\WINDOWS\122o5800.dll] [N/A, N/A]
[C:\WINDOWS\DOWNLO~1\CnsHook.dll] [北京三七二一科技有限公司, 1, 0, 3, 7]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
[PID: 1304][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[PID: 1480][C:\WINDOWS\system32\Rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SoDAHK.DLL] [Sogou.com Inc., 1, 0, 1, 5]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\WINDOWS\DOWNLO~1\CnsMinIO.dll] [北京三七二一科技有限公司, 1, 0, 3, 7]
[C:\WINDOWS\DOWNLO~1\cnsio.dll] [北京三七二一科技有限公司, 1, 0, 2, 8]
[C:\WINDOWS\DOWNLO~1\CnsMinEx.dll] [国风因特软件(北京)有限公司, 1, 0, 3, 4]
[PID: 1556][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[PID: 1572][C:\WINDOWS\SYSTEM32\RUNDLL.EXE] [Microsoft Corporation, 5.00.2134.1]
[PID: 1648][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1684][C:\Program Files\Common Files\Sogou PXP\p2psvr.exe] [Sohu.com Inc., 2, 0, 0, 24]
[C:\Program Files\P4P\tbupdate.dll] [Sogou.com Inc., 1, 0, 1, 1]
[C:\Program Files\P4P\p4pipc.dll] [Sogou.com Inc., 1, 0, 0, 13]
[C:\Program Files\Sogou PXP\vodsvr.dll] [Sohu.com Inc., 2, 0, 0, 21]
[C:\Program Files\Sogou PXP\pxpnet.dll] [Sohu.com Inc., 1, 0, 0, 3]
[C:\Program Files\Sogou PXP\p2pclient.dll] [Sohu.com Inc., 1, 0, 0, 6]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[PID: 1792][c:\windows\system\taskmgr.exe] [, 1.0.0.0]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 216][c:\windows\system32\wbem\winlogon.exe] [Microsoft, 1.0.0.0]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[PID: 340][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SoDAHK.DLL] [Sogou.com Inc., 1, 0, 1, 5]
[C:\WINDOWS\system32\sdmAgent22.dll] [LINKMEDIA Tech, 1, 5, 0, 7]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[PID: 952][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SoDAHK.DLL] [Sogou.com Inc., 1, 0, 1, 5]
[C:\DOCUME~1\hgy\TEMPLA~1\ca883d3\1.dll] [千橡互联, 3, 0, 2, 0]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\DOCUME~1\hgy\TEMPLA~1\ca883d3\3.dll] [千橡互联, 3, 0, 2, 8]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\DOCUME~1\hgy\TEMPLA~1\ca883d3\4.dll] [千橡互联, 3, 0, 2, 8]
[C:\WINDOWS\system32\tapidef.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\winscok.dll] [N/A, N/A]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[PID: 1148][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\WINDOWS\system32\msicn\msibm.dll] [广州傲讯信息科技有限公司, 2, 0, 0, 1]
[PID: 1372][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3018]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\WINDOWS\system32\msicn\msibm.dll] [广州傲讯信息科技有限公司, 2, 0, 0, 1]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[PID: 1424][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SoDAHK.DLL] [Sogou.com Inc., 1, 0, 1, 5]
[C:\Program Files\DeskAdTop\Run.dll] [, 1, 0, 0, 1]
[C:\Program Files\DeskAdTop\GetCPMWord.dll] [N/A, N/A]
[C:\Program Files\DeskAdTop\WebPageParser.dll] [N/A, N/A]
[C:\Program Files\DeskAdTop\Charset.dll] [N/A, N/A]
[C:\Program Files\DeskAdTop\CreateDomTree.dll] [N/A, N/A]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\Program Files\DeskAdTop\fshook.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\tapidef.dll] [, 1, 0, 0, 1]
kjsgdhe - 2006-10-6 9:53:00
[C:\WINDOWS\system32\winscok.dll] [N/A, N/A]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[PID: 1076][C:\WINDOWS\system32\Rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SoDAHK.DLL] [Sogou.com Inc., 1, 0, 1, 5]
[C:\PROGRA~1\pcast\hbcast.dll] [Shanghai Henbang Technology Co., Ltd, 1, 1, 3, 8]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\WINDOWS\system32\winscok.dll] [N/A, N/A]
[C:\WINDOWS\system32\tapidef.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[PID: 1064][C:\WINDOWS\svchost.exe] [N/A, N/A]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\WINDOWS\system32\winscok.dll] [N/A, N/A]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[C:\WINDOWS\system32\tapidef.dll] [, 1, 0, 0, 1]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\DeskAdTop\fshook.dll] [, 1, 0, 0, 1]
[PID: 1532][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\WINDOWS\system32\winscok.dll] [N/A, N/A]
[PID: 2008][C:\WINDOWS\system32\SVOHOST.exe] [N/A, N/A]
[C:\WINDOWS\system32\winscok.dll] [N/A, N/A]
[C:\WINDOWS\system32\tapidef.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[PID: 2320][C:\Program Files\Common Files\UPDATE2\Update.exe] [N/A, N/A]
[C:\WINDOWS\system32\tapidef.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\WINDOWS\system32\winscok.dll] [N/A, N/A]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[PID: 2416][C:\WINDOWS\system\realsched.exe] [N/A, N/A]
[C:\WINDOWS\system32\tapidef.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\WINDOWS\system32\winscok.dll] [N/A, N/A]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[C:\WINDOWS\system\vp_VM.dll] [N/A, N/A]
[PID: 2528][C:\WINDOWS\system32\5476721.exe] [N/A, N/A]
[PID: 3020][C:\WINDOWS\system32\-249901.exe] [N/A, N/A]
[PID: 3384][C:\Program Files\Common Files\{FCFB4D75-0A70-2052-0930-030309120056}\Update.exe] [N/A, N/A]
[C:\Program Files\Common Files\{FCFB4D75-0A70-2052-0930-030309120056}\services.dll] [N/A, N/A]
[C:\WINDOWS\system32\tapidef.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\WINDOWS\system32\winscok.dll] [N/A, N/A]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[PID: 3600][C:\WINDOWS\system32\-67416.exe] [N/A, N/A]
[PID: 2020][C:\WINDOWS\Temp\run.exe] [N/A, N/A]
[PID: 1472][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SoDAHK.DLL] [Sogou.com Inc., 1, 0, 1, 5]
[C:\WINDOWS\system32\A4SOFT\baisoc\dllhostc.dll] [N/A, N/A]
[C:\WINDOWS\system32\tapidef.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\WINDOWS\system32\winscok.dll] [N/A, N/A]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[PID: 2868][C:\WINDOWS\system32\RUNDLL32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SoDAHK.DLL] [Sogou.com Inc., 1, 0, 1, 5]
[C:\PROGRA~1\P4P\Feed.dll] [Sohu.com Inc., 1, 1, 0, 0]
[C:\WINDOWS\system32\tapidef.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\WINDOWS\system32\winscok.dll] [N/A, N/A]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[C:\PROGRA~1\P4P\Toolbar.dll] [Sogou.com Inc., 1, 4, 8, 5]
[PID: 4684][C:\WINDOWS\system32\RUNDLL32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SoDAHK.DLL] [Sogou.com Inc., 1, 0, 1, 5]
[C:\PROGRA~1\P4P\ToolBar.dll] [Sogou.com Inc., 1, 4, 8, 5]
[C:\WINDOWS\system32\tapidef.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\WINDOWS\system32\winscok.dll] [N/A, N/A]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[PID: 5012][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SoDAHK.DLL] [Sogou.com Inc., 1, 0, 1, 5]
[C:\WINDOWS\system32\tapidef.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\WINDOWS\DOWNLO~1\CnsHint.dll] [3721, 1, 0, 1, 1]
[C:\WINDOWS\system32\winscok.dll] [N/A, N/A]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[C:\Program Files\DeskAdTop\fshook.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\cnsplus.dll] [3721, 1, 0, 0, 2]
[C:\Program Files\P4P\ToolBar.dll] [Sogou.com Inc., 1, 4, 8, 5]
[C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll] [Xiang Feng Technology, 2, 2, 0, 1612]
[C:\Program Files\DeskAdTop\deskipn.dll] [, 1, 0, 0, 1]
[C:\Program Files\P4P\sodaie.dll] [Sogou.com Inc., 1, 2, 0, 9]
[C:\Program Files\P4P\autolink.dll] [Sohu.com Inc., 1, 0, 2, 3]
[C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5003.dll] [Microsoft Corporation, 1, 3, 5, 0]
[C:\WINDOWS\system32\sys32dev.dll] [N/A, N/A]
[C:\WINDOWS\Win32ef.dll] [N/A, N/A]
[C:\WINDOWS\system32\usercrd.dll] [, 1, 0, 0, 1]
[C:\PROGRA~1\pcast\hbcast.dll] [Shanghai Henbang Technology Co., Ltd, 1, 1, 3, 8]
[C:\Program Files\ToolBar888\MyToolBar.dll] [N/A, 1, 0, 0, 1]
[C:\WINDOWS\system32\IEHelper.dll] [N/A, 1, 0, 0, 1]
[C:\Program Files\Riptide\Plugin\Plugin.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\122o5800.dll] [N/A, N/A]
[C:\WINDOWS\DOWNLO~1\CnsHook.dll] [北京三七二一科技有限公司, 1, 0, 3, 7]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] [Macromedia, Inc., 8,0,22,0]
[PID: 11392][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SoDAHK.DLL] [Sogou.com Inc., 1, 0, 1, 5]
[C:\WINDOWS\system32\tapidef.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\WINDOWS\DOWNLO~1\CnsHint.dll] [3721, 1, 0, 1, 1]
[C:\WINDOWS\system32\winscok.dll] [N/A, N/A]
[C:\WINDOWS\system32\cdnns.dll] [CNNIC, 2, 0, 0, 0]
[C:\Program Files\DeskAdTop\fshook.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\DOWNLO~1\cnsplus.dll] [3721, 1, 0, 0, 2]
[C:\Program Files\P4P\ToolBar.dll] [Sogou.com Inc., 1, 4, 8, 5]
[C:\Program Files\Super Rabbit\MagicSet\haokanbar.dll] [Xiang Feng Technology, 2, 2, 0, 1612]
[C:\Program Files\DeskAdTop\deskipn.dll] [, 1, 0, 0, 1]
[C:\Program Files\P4P\sodaie.dll] [Sogou.com Inc., 1, 2, 0, 9]
[C:\Program Files\P4P\autolink.dll] [Sohu.com Inc., 1, 0, 2, 3]
[C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5003.dll] [Microsoft Corporation, 1, 3, 5, 0]
[C:\WINDOWS\system32\sys32dev.dll] [N/A, N/A]
[C:\WINDOWS\Win32ef.dll] [N/A, N/A]
[C:\WINDOWS\system32\usercrd.dll] [, 1, 0, 0, 1]
[C:\PROGRA~1\pcast\hbcast.dll] [Shanghai Henbang Technology Co., Ltd, 1, 1, 3, 8]
[C:\Program Files\ToolBar888\MyToolBar.dll] [N/A, 1, 0, 0, 1]
[C:\WINDOWS\system32\IEHelper.dll] [N/A, 1, 0, 0, 1]
[C:\Program Files\Riptide\Plugin\Plugin.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\122o5800.dll] [N/A, N/A]
[C:\WINDOWS\DOWNLO~1\CnsHook.dll] [北京三七二一科技有限公司, 1, 0, 3, 7]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\DOWNLO~1\CnsMinIO.dll] [北京三七二一科技有限公司, 1, 0, 3, 7]
[C:\WINDOWS\DOWNLO~1\cnsio.dll] [北京三七二一科技有限公司, 1, 0, 2, 8]
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] [Macromedia, Inc., 8,0,22,0]
[PID: 15952][C:\我的下载\新建文件夹\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\WINDOWS\system32\tapidef.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\SYSPOL~1.DLL] [, 1, 0, 0, 1]
© 2000 - 2026 Rising Corp. Ltd.