[CODE] 2008-05-04,17:42:21 System Repair Engineer 2.5.16.900 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce] [] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}> [(Verified)Beijing Rising Science and Technology Corporation Limited] <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}> [Beijing Rising Technology Co., Ltd.] <{D0B2F9F8-781C-43EA-AB99-58B9B528417E}> [N/A] <{3E387664-C799-4D62-B196-25776EF35C51}> [N/A] <{77f7e039-7181-4a6d-b1bb-8c81f81e833a}> [] <{3cc67dc4-e953-4b2f-ae22-fcb4dcc3903a}> [] <{e1b85bd5-d0bd-4a39-953e-574d200a53b2}> [] <{9947e423-193f-4fc4-b38d-e76fdd799150}> [] <{3c0a13c5-4df0-4430-9718-bf99ff81334a}> [] <{44a07d49-1e80-46e3-b6b7-aaa9ca462377}> [] <{86ba2ef4-3501-47cf-a71d-8759997a44d0}> [] <{1950369a-7bb1-4235-83a3-054b26f1943b}> [] <{67ba0720-e5a5-4b59-92cc-63faf4816f27}> [] <{b855ec1a-a8f8-4f59-ab45-08de1dae1ae2}> [] <{a580305f-b902-4723-ac26-06e4cb4279a5}> [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safe.exe] [(Verified)Tencent Technology(Shenzhen) Company Limited] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adam.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AgentSvr.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AppSvc32.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ati2evxx.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoruns.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrssvc.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvMonitor.exe] [(Verified)Microsoft Windows XP Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.com] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\esafe.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FileDsty.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FTCleanerShell.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HijackThis.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IceSword.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\idag.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Iparmor.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\isPwdSvc.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kabaload.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kaccore.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KaScrScn.SCR] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASMain.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASTask.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAV32.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVDX.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPF.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPFW.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVSetup.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVStart.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavsvc.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVsvcUI.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KISLnchr.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kissvc.exe] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMailMon.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMFilter.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kpfwsvc.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPPMain.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRegEx.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRepair.com] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KsLoader.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVCenter.kxp] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvDetect.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVFW.EXE] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvfwMcl.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP_1.kxp] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvol.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvolself.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvReport.kxp] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVScan.kxp] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVsrvXP.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVStub.kxp] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvupload.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVwsc.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kwatch.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch9x.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatchX.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MagicSet.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcconsol.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmqczj.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmsk.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapsvc.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapw32.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32krn.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NPFMntor.exe] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OllyDBG.EXE] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OllyICE.EXE] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFW.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFWLiveUpdate.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QHSET.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qqdoctor.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qqkav.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qqsc.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ras.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav.exe] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RAVmon.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RAVmonD.exe] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ravstub.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ravtask.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ravtimer.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ravtool.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegClean.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regtool.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwmain.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwproxy.exeFYFireWall.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwstub.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rising.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rsaupd.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safebank.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeboxtray.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safelive.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shcfg32.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmartUp.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SREng.EXE] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SysSafe.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojanDetector.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Trojanwall.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojDie.kxp] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UIHost.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAgent.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAttachment.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxCfg.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxFwHlp.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxPol.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UpLive.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WinDbg.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WoptiClean.exe] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher] <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [N/A] <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [N/A] ================================== 启动文件夹 [word] C:\WINDOWS\system32\ridiap071227.exe [N/A]> ================================== 服务 [Ati HotKey Poller / Ati HotKey Poller][Stopped/Auto Start] [ATI Smart / ATI Smart][Stopped/Auto Start] <> [CPUSpeed / CPUSpeed][Running/Auto Start] [Windows gbvl RunThem / gbvl][Stopped/Auto Start] C:\PROGRA~1\bwqg\lgaq.dll> [Google Updater Service / gusvc][Stopped/Manual Start] <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"> [Help and Support / helpsvc][Stopped/Auto Start] %WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [Rising Process Communication Center / RsCCenter][Stopped/Auto Start] <"C:\Program Files\Rising\Rav\CCenter.exe"> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe"> [Server Access Manager / Server Access Manager][Stopped/Auto Start] <> ================================== 驱动程序 [0005fefb / 0005fefb][Stopped/Manual Start] <\??\C:\WINDOWS\system32\Drivers\0005fefb.sys> [0016c013 / 0016c013][Stopped/Manual Start] <\??\C:\WINDOWS\system32\Drivers\0016c013.sys> [360AntiArp / 360AntiArp][Stopped/System Start] <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys> [7hd / 7hd4][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\7hd4.sys> [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start] [acpidisk / acpidisk][Running/Auto Start] <\??\C:\WINDOWS\system32\drivers\acpidisk.sys> [AMD K8 Processor Driver / AmdK8][Stopped/Manual Start] [ati2mtag / ati2mtag][Running/Manual Start] [Atixeve2930 / Atixeve2930][Stopped/Manual Start] <\??\C:\WINDOWS\TEMP\~wxp2ins.699.tmp> [BillDriver / BillDriver][Stopped/Manual Start] <\??\D:\Downloads\playBoss\BillDrv.Vxd> [c4wva / c4wvan][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\c4wvan.sys> [eiqodm3 / eiqodm33][Stopped/Boot Start] <\SystemRoot\System32\DRIVERS\eiqodm33.sys> [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start] [fmsq / fmsq][Stopped/Auto Start] <\??\C:\DOCUME~1\user\LOCALS~1\Temp\tmp10.tmp> [HookCont / HookCont][Running/System Start] <\SystemRoot\system32\drivers\HookCont.sys> [HookNtos / HookNtos][Running/System Start] <\SystemRoot\system32\drivers\HookNtos.sys> [HookReg / HookReg][Running/System Start] <\SystemRoot\system32\drivers\HookReg.sys> [HookSys / HookSys][Running/System Start] <\SystemRoot\system32\drivers\HookSys.sys> [Netgroup Packet Filter / NPF][Stopped/Manual Start] [npkcrypt / npkcrypt][Stopped/Manual Start] <\??\C:\WINDOWS\system32\npkcrypt.sys> [npkycryp / npkycryp][Stopped/Manual Start] <\??\C:\WINDOWS\system32\npkycryp.sys> [nv / nv][Stopped/Manual Start] [oreans32 / oreans32][Running/System Start] <\??\C:\WINDOWS\system32\drivers\oreans32.sys> [DDK PACKET Protocol / Packet][Stopped/Manual Start] [ptfs / ptfs][Stopped/Auto Start] <\??\C:\DOCUME~1\user\LOCALS~1\Temp\tmpBE.tmp> [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [QKeyServiceDisplay / QKeyService][Running/Boot Start] <\SystemRoot\system32\KeyCrypt.sys> [RsAntiSpyware / RsAntiSpyware][Running/Boot Start] <\SystemRoot\system32\drivers\RsBoot.sys> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start] [SafeBoxKrnl / SafeBoxKrnl][Stopped/System Start] <\??\C:\Program Files\360Safebox\SafeBoxKrnl.sys> [Secdrv / Secdrv][Stopped/Manual Start] [soxi / soxi][Stopped/Manual Start] <\??\C:\WINDOWS\system32\drivers\soxi.sys> [TesSafe / TesSafe][Stopped/Manual Start] <\??\C:\WINDOWS\system32\TesSafe.sys> [uas8zms / uas8zms][Stopped/Boot Start] <\SystemRoot\system32\drivers\uas8zms.sys> [ViaIde / ViaIde][Running/Boot Start] <\SystemRoot\System32\DRIVERS\viaide.sys> [Vinyl AC'97 Audio Controller (WDM) / VIAudio][Running/Manual Start] [msfpfis64 / msfpfis64][Running/Auto Start] <\??\C:\WINDOWS\system32\drivers\msosmsfpfis64.sys> [dohs / dohs][Stopped/Auto Start] <\??\C:\WINDOWS\TEMP\tmp4.tmp> [ping / ping][Stopped/Auto Start] <\??\C:\WINDOWS\TEMP\tmp6.tmp> [mnsf / mnsf][Stopped/Auto Start] <\??\C:\WINDOWS\TEMP\tmpB.tmp> [cqit / cqit][Stopped/Auto Start] <\??\C:\WINDOWS\TEMP\tmp10.tmp> ================================== 浏览器加载项 [QQCycloneHelper Class] {00000000-12C9-4305-82F9-43058F20E8D2} [RealPlayer Download and Record Plugin for Internet Explorer] {3049C3E9-B461-4BC5-8870-4C09146192CA} [AliAntiFish Class] {38938D50-8A48-44C2-945F-D2F23F771410} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [Google Toolbar Helper] {AA58ED58-01DD-4d91-8333-CF10577473F7} [Google Toolbar Notifier BHO] {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [] {C1BA80EE-2FB8-4C8D-BAC9-938215E539C5} [brush Class] {F92A7C72-B661-40FA-BEFD-9091E597FCE1} [assist] {FE3FCAE7-0A37-4506-8A7D-3CC9A04D2CA8} [知识库] {06926B30-424E-4f1c-8EE3-543CD96573DC} [浩方对战平台] {0A155D3C-68E2-4215-A47A-E800A446447A} [PPLive] {95B3F550-91C4-4627-BCC4-521288C52977} [淘宝工具条] {78B2F60E-AFA5-4d3d-A49E-2BFF013D9D23} [&Google] {2318C2B1-4965-11d4-9B18-009027A5CD4F} [MMCPlayer Class] {05C1004E-2596-48E5-8E26-39362985EEB9} [ULiveCtrl Control] {070CA17A-4BD2-4612-83B4-32B1B9159B47} [Windows Genuine Advantage Validation Tool] {17492023-C23A-453E-A040-C7C580BBF700} [iTrusPTA Class] {1E0DFFCF-27FF-4574-849B-55007349FEDA} [EditCtrl Class] {488A4255-3236-44B3-8F27-FA1AECAA8844} [WUWebControl Class] {6414512B-B978-451D-A0D8-FCFDF33E833C} [DLoader Class] {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} [ScreenCapture Class] {BFB79EE1-04AE-4D4A-B85E-27EE5F30C095} [Tencent Safety Online Base Module] {C09B522F-8AED-4E21-A65C-DC1AB652BAEE} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [QQCycloneHelper Class] {00000000-12C9-4305-82F9-43058F20E8D2} [&Google] {2318C2B1-4965-11D4-9B18-009027A5CD4F} [DHTML Edit Control Safe for Scripting for IE5] {2D360201-FFF5-11D1-8D03-00A0C959BC0A} [RealPlayer Download and Record Plugin for Internet Explorer] {3049C3E9-B461-4BC5-8870-4C09146192CA} [Tabular Data Control] {333C7BC4-460F-11D0-BC04-0080C7055A83} [AliAntiFish Class] {38938D50-8A48-44C2-945F-D2F23F771410} [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [淘宝工具条] {78B2F60E-AFA5-4D3D-A49E-2BFF013D9D23} [Microsoft Web 浏览器] {8856F961-340A-11D0-A96B-00C04FD705A2} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [Google Toolbar Helper] {AA58ED58-01DD-4D91-8333-CF10577473F7} [Microsoft Scriptlet Component] {AE24FDAE-03C6-11D1-8B76-0080C744F389} [Google Toolbar Notifier BHO] {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [SearchAssistantOC] {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A> [RDS.DataSpace] {BD96C556-65A3-11D0-983A-00C04FC29E36} [] {C1BA80EE-2FB8-4C8D-BAC9-938215E539C5} [RealPlayer G2 Control] {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [PasswordEditCtrl Class] {E787FD25-8D7C-4693-AE67-9406BC6E22DF} [brush Class] {F92A7C72-B661-40FA-BEFD-9091E597FCE1} [assist] {FE3FCAE7-0A37-4506-8A7D-3CC9A04D2CA8} [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] ================================== 正在运行的进程 [PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 500 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [PID: 532 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\dnteh.dll] [N/A, ] [C:\WINDOWS\system32\sperls.dll] [N/A, ] [C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4176] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\WINDOWS\system32\winlib .dll] [N/A, ] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [PID: 580 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [PID: 592 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\mfc40u.dll] [N/A, ] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [PID: 772 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [PID: 868 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [PID: 956 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [C:\Program Files\Internet Explorer\PLUGINS\WinSys16.Sys] [N/A, ] [PID: 1024 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [PID: 1160 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [PID: 1424 / user][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\dnteh.dll] [N/A, ] [C:\WINDOWS\system32\sperls.dll] [N/A, ] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17] [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9] [C:\WINDOWS\system32\ttKAFKAF1072.dll] [N/A, ] [C:\WINDOWS\system32\ttNNBNNB1056.dll] [N/A, ] [C:\WINDOWS\system32\dqSADSAD1041.dll] [N/A, ] [C:\WINDOWS\system32\ttMYSMYS1053.dll] [N/A, ] [C:\WINDOWS\system32\dqBAIBAI1067.dll] [N/A, ] [C:\WINDOWS\system32\dqEZZEZZ1056.dll] [N/A, ] [C:\WINDOWS\system32\dqDABDAB1071.dll] [N/A, ] [C:\WINDOWS\system32\dqABCABC1031.dll] [N/A, ] [C:\WINDOWS\system32\dqWLVWLV1014.dll] [N/A, ] [C:\WINDOWS\system32\dqDLQDLQ1007.dll] [N/A, ] [C:\WINDOWS\system32\o9ikt4.dll] [N/A, ] [C:\WINDOWS\system32\anistio.dll] [N/A, ] [C:\WINDOWS\system32\fiosectc.dll] [N/A, ] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\rzysdhbx.dll] [N/A, ] [C:\WINDOWS\system32\dbhlp32.dlL] [N/A, ] [C:\WINDOWS\system32\fmsjhif.dll] [N/A, ] [C:\WINDOWS\system32\ticisms.dll] [N/A, ] [C:\WINDOWS\system32\bincdwsa.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\WINSvr64.dll] [N/A, ] [C:\WINDOWS\system32\yuiabct.dll] [N/A, ] [C:\WINDOWS\system32\ttHADHAD1071.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [C:\WINDOWS\system32\huifitc.dll] [N/A, ] [C:\WINDOWS\system32\fmbiost.dll] [N/A, ] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 2] [PID: 1528 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\system32\dnteh.dll] [N/A, ] [C:\WINDOWS\system32\sperls.dll] [N/A, ] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [PID: 1960 / SYSTEM][C:\WINDOWS\system32\ntd.exe] [N/A, ] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\dnteh.dll] [N/A, ] [C:\WINDOWS\system32\sperls.dll] [N/A, ] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [PID: 324 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)] [C:\WINDOWS\system32\dnteh.dll] [N/A, ] [C:\WINDOWS\system32\sperls.dll] [N/A, ] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [PID: 1680 / user][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\dnteh.dll] [N/A, ] [C:\WINDOWS\system32\sperls.dll] [N/A, ] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [PID: 352 / user][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\dnteh.dll] [N/A, ] [C:\WINDOWS\system32\sperls.dll] [N/A, ] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [PID: 2372 / user][C:\Program Files\Rising\Rav\RsAgent.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.7] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\dnteh.dll] [N/A, ] [C:\WINDOWS\system32\sperls.dll] [N/A, ] [C:\Program Files\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\Program Files\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [PID: 2552 / user][D:\Downloads\新建文件夹\QQ.exe] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\QQBaseClassInDll.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\QQHelperDll.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\BasicCtrlDll.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0] [C:\WINDOWS\system32\dnteh.dll] [N/A, ] [C:\WINDOWS\system32\sperls.dll] [N/A, ] [D:\Downloads\新建文件夹\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1] [D:\Downloads\新建文件夹\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218] [D:\Downloads\新建文件夹\QQAPI.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\LoginCtrl.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\LoginCtrlRes.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\QQRes.dll] [TENCENT, 8,0,713,1791] [D:\Downloads\新建文件夹\WizardCtrl.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\QQMainFrame.dll] [N/A, ] [D:\Downloads\新建文件夹\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)] [D:\Downloads\新建文件夹\QQPlugin.dll] [N/A, ] [D:\Downloads\新建文件夹\UnReadMsgMgr.dll] [N/A, ] [D:\Downloads\新建文件夹\CQQApplication.dll] [N/A, ] [D:\Downloads\新建文件夹\FlashAvatarDll.dll] [, 1, 4, 0, 1] [D:\Downloads\新建文件夹\NewSkin.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\MailSummary.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\QQSpace.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\vbscript.dll] [Microsoft Corporation, 5.6.0.7426] [C:\WINDOWS\system32\msdmo.dll] [, ] [D:\Downloads\新建文件夹\QQKnowledgeSearch.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\OEMApplication.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\QQGroupMng.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\QQAvatar.dll] [N/A, ] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [D:\Downloads\新建文件夹\QQAllInOne.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\SCCore.dll] [TENCENT, 1, 6, 0, 2] [D:\Downloads\新建文件夹\CameraDll.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\QQPet.dll] [TENCENT, 8,0,774,1801] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [D:\Downloads\新建文件夹\QQSysMsgMng.dll] [N/A, ] [C:\WINDOWS\system32\fiosectc.dll] [N/A, ] [C:\WINDOWS\system32\anistio.dll] [N/A, ] [D:\Downloads\新建文件夹\UserDefinedHead.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\QQConfigPlugin.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\QQCustomFace.dll] [N/A, ] [D:\Downloads\新建文件夹\QRingMng.dll] [N/A, ] [D:\Downloads\新建文件夹\LongConnection.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\PhoneAPI.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\DialerAllinOne.dll] [tencent, 1, 4, 0, 0] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [D:\Downloads\新建文件夹\BQQApplication.dll] [N/A, ] [D:\Downloads\新建文件夹\PersonalDesktop.dll] [TENCENT, 8,0,774,1801] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [D:\Downloads\新建文件夹\CommercesMng.dll] [TENCENT, 8,0,774,1801] [D:\Downloads\新建文件夹\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 330] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [C:\WINDOWS\system32\fmbiost.dll] [N/A, ] [C:\WINDOWS\system32\huifitc.dll] [N/A, ] [C:\WINDOWS\system32\yuiabct.dll] [N/A, ] [C:\WINDOWS\system32\WINSvr64.dll] [N/A, ] [C:\WINDOWS\system32\bincdwsa.dll] [N/A, ] [C:\WINDOWS\system32\ticisms.dll] [N/A, ] [C:\WINDOWS\system32\fmsjhif.dll] [N/A, ] [C:\WINDOWS\system32\dbhlp32.dlL] [N/A, ] [C:\WINDOWS\system32\rzysdhbx.dll] [N/A, ] [D:\Downloads\新建文件夹\QQSceneMng.dll] [N/A, ] [C:\WINDOWS\system32\ttKAFKAF1072.dll] [N/A, ] [C:\WINDOWS\system32\ttNNBNNB1056.dll] [N/A, ] [C:\WINDOWS\system32\dqSADSAD1041.dll] [N/A, ] [C:\WINDOWS\system32\ttMYSMYS1053.dll] [N/A, ] [C:\WINDOWS\system32\dqBAIBAI1067.dll] [N/A, ] [C:\WINDOWS\system32\dqEZZEZZ1056.dll] [N/A, ] [C:\WINDOWS\system32\dqDABDAB1071.dll] [N/A, ] [C:\WINDOWS\system32\dqABCABC1031.dll] [N/A, ] [C:\WINDOWS\system32\dqWLVWLV1014.dll] [N/A, ] [C:\WINDOWS\system32\dqDLQDLQ1007.dll] [N/A, ] [C:\WINDOWS\system32\ttHADHAD1071.dll] [N/A, ] [D:\Downloads\新建文件夹\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 2, 1, 13] [PID: 2592 / user][D:\Downloads\新建文件夹\TXPlatform.exe] [Tencent, 1, 0, 170, 0] [C:\WINDOWS\system32\dnteh.dll] [N/A, ] [C:\WINDOWS\system32\sperls.dll] [N/A, ] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [PID: 3556 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\dnteh.dll] [N/A, ] [C:\WINDOWS\system32\sperls.dll] [N/A, ] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [PID: 2892 / SYSTEM][C:\WINDOWS\TEMP\_qosec29.msi] [N/A, ] [C:\WINDOWS\system32\dnteh.dll] [N/A, ] [C:\WINDOWS\system32\sperls.dll] [N/A, ] [C:\Program Files\Internet Explorer\PLUGINS\WinSys16.Sys] [N/A, ] [PID: 3424 / user][C:\Program Files\Tencent\TT\TTraveler.exe] [Tencent, 3, 8, 308, 201] [C:\WINDOWS\system32\dnteh.dll] [N/A, ] [C:\WINDOWS\system32\sperls.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\Program Files\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll] [腾讯公司, 1, 1, 0, 5] [C:\WINDOWS\system32\fmbiost.dll] [N/A, ] [C:\WINDOWS\system32\huifitc.dll] [N/A, ] [C:\WINDOWS\system32\yuiabct.dll] [N/A, ] [C:\WINDOWS\system32\WINSvr64.dll] [N/A, ] [C:\WINDOWS\system32\bincdwsa.dll] [N/A, ] [C:\WINDOWS\system32\ticisms.dll] [N/A, ] [C:\WINDOWS\system32\fmsjhif.dll] [N/A, ] [C:\WINDOWS\system32\dbhlp32.dlL] [N/A, ] [C:\WINDOWS\system32\rzysdhbx.dll] [N/A, ] [C:\WINDOWS\system32\fiosectc.dll] [N/A, ] [C:\WINDOWS\system32\anistio.dll] [N/A, ] [C:\Program Files\Tencent\TT\TTNetFavor.dll] [N/A, ] [C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\WINDOWS\system32\WINABCX.IME] [PKUETI, 5.22.216] [C:\WINDOWS\system32\ttKAFKAF1072.dll] [N/A, ] [C:\WINDOWS\system32\ttNNBNNB1056.dll] [N/A, ] [C:\WINDOWS\system32\dqSADSAD1041.dll] [N/A, ] [C:\WINDOWS\system32\ttMYSMYS1053.dll] [N/A, ] [C:\WINDOWS\system32\dqBAIBAI1067.dll] [N/A, ] [C:\WINDOWS\system32\dqEZZEZZ1056.dll] [N/A, ] [C:\WINDOWS\system32\dqDABDAB1071.dll] [N/A, ] [C:\WINDOWS\system32\dqABCABC1031.dll] [N/A, ] [C:\WINDOWS\system32\dqWLVWLV1014.dll] [N/A, ] [C:\WINDOWS\system32\dqDLQDLQ1007.dll] [N/A, ] [C:\WINDOWS\system32\ttHADHAD1071.dll] [N/A, ] [PID: 3372 / user][D:\Downloads\新建文件夹\qqpet\QQPets3D\QQPets3D.exe] [TENCENT, 1, 0, 1, 1] [D:\Downloads\新建文件夹\qqpet\QQPets3D\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762] [D:\Downloads\新建文件夹\qqpet\QQPets3D\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762] [D:\Downloads\新建文件夹\qqpet\QQPets3D\dbghelp.dll] [Microsoft Corporation, 6.5.0003.7 (vbl_core_fbrel(jshay).050527-1915)] [C:\WINDOWS\system32\dnteh.dll] [N/A, ] [C:\WINDOWS\system32\sperls.dll] [N/A, ] [D:\Downloads\新建文件夹\qqpet\QQPets3D\Tenio\TenFact.dll] [Tencent, 01,01,19,005] [D:\Downloads\新建文件夹\qqpet\QQPets3D\Tenio\UpdateCenter.dll] [Tencent, 01.1.0.0] [D:\Downloads\新建文件夹\qqpet\QQPets3D\Tenio\TenPet2.dll] [Tencent, 01,01,19,005] [D:\Downloads\新建文件夹\qqpet\QQPets3D\lzo1.dll] [Oberhumer , 1.08.1547.37901] [D:\Downloads\新建文件夹\qqpet\QQPets3D\P3DCommonModule.dll] [TENCENT, 1, 0, 1, 1] [D:\Downloads\新建文件夹\qqpet\QQPets3D\P3DQQCommunication.dll] [TODO: , 1.0.0.1] [D:\Downloads\新建文件夹\qqpet\QQPets3D\MFC80.DLL] [Microsoft Corporation, 8.00.50727.762] [D:\Downloads\新建文件夹\qqpet\QQPets3D\MFC80CHS.DLL] [Microsoft Corporation, 8.00.50727.762] [D:\Downloads\新建文件夹\qqpet\QQPets3D\QCodec.dll] [Tencent, 1, 6, 0, 4] [D:\Downloads\新建文件夹\qqpet\QQPets3D\P3DDownloadModule.dll] [N/A, ] [D:\Downloads\新建文件夹\qqpet\QQPets3D\P3DPetActorModule.dll] [TENCENT, 1, 0, 1, 1] [D:\Downloads\新建文件夹\qqpet\QQPets3D\P3DDesktopAnimation.dll] [N/A, ] [D:\Downloads\新建文件夹\qqpet\QQPets3D\P3DMarriageModle.dll] [N/A, ] [D:\Downloads\新建文件夹\qqpet\QQPets3D\P3DDreamSystem.dll] [TENCENT, 1, 0, 1, 1] [D:\Downloads\新建文件夹\qqpet\QQPets3D\P3DBulbSys.dll] [N/A, ] [D:\Downloads\新建文件夹\qqpet\QQPets3D\RightMenuSystem.dll] [N/A, ] [D:\Downloads\新建文件夹\qqpet\QQPets3D\SoundSystem.dll] [N/A, ] [C:\WINDOWS\system32\fmbiost.dll] [N/A, ] [C:\WINDOWS\system32\huifitc.dll] [N/A, ] [C:\WINDOWS\system32\yuiabct.dll] [N/A, ] [C:\WINDOWS\system32\WINSvr64.dll] [N/A, ] [C:\WINDOWS\system32\bincdwsa.dll] [N/A, ] [C:\WINDOWS\system32\ticisms.dll] [N/A, ] [C:\WINDOWS\system32\fmsjhif.dll] [N/A, ] [C:\WINDOWS\system32\dbhlp32.dlL] [N/A, ] [C:\WINDOWS\system32\rzysdhbx.dll] [N/A, ] [C:\WINDOWS\system32\fiosectc.dll] [N/A, ] [C:\WINDOWS\system32\anistio.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx] [Adobe Systems, Inc., 9,0,115,0] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 480 / user][C:\QQDownload\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900] [C:\WINDOWS\system32\dnteh.dll] [N/A, ] [C:\WINDOWS\system32\sperls.dll] [N/A, ] [C:\WINDOWS\system32\msosping00.dll] [N/A, ] [C:\WINDOWS\system32\fmbiost.dll] [N/A, ] [C:\WINDOWS\system32\huifitc.dll] [N/A, ] [C:\WINDOWS\system32\yuiabct.dll] [N/A, ] [C:\WINDOWS\system32\WINSvr64.dll] [N/A, ] [C:\WINDOWS\system32\bincdwsa.dll] [N/A, ] [C:\WINDOWS\system32\ticisms.dll] [N/A, ] [C:\WINDOWS\system32\fmsjhif.dll] [N/A, ] [C:\WINDOWS\system32\dbhlp32.dlL] [N/A, ] [C:\WINDOWS\system32\rzysdhbx.dll] [N/A, ] [C:\WINDOWS\system32\fiosectc.dll] [N/A, ] [C:\WINDOWS\system32\anistio.dll] [N/A, ] [C:\WINDOWS\system32\msosmnsf00.dll] [N/A, ] [C:\QQDownload\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [C:\WINDOWS\system32\msosdohs00.dll] [N/A, ] [C:\WINDOWS\system32\msoscqit00.dll] [N/A, ] [C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 127.0.0.1 update.cpushpop.com 127.0.0.1 gs.chnsystem.com 127.0.0.1 ssl.chnsystem.com 127.0.0.1 down.1024tb.com 127.0.0.1 log.xplayer.coopen.cn 127.0.0.1 loader.smartpv.cn 127.0.0.1 sports.yahoo550.com 127.0.0.1 jump.cnnic.cn 127.0.0.1 adfirefox.cn 127.0.0.1 5.haokandi.cn 127.0.0.1 update.iesuper.com 127.0.0.1 122.770304123.cn 127.0.0.1 343.boolans.com 127.0.0.1 update146.smartpv.cn 127.0.0.1 click2.ad4all.net 127.0.0.1 realname.webbrowser.smartpv.cn 127.0.0.1 www.cnphp5.com 127.0.0.1 zhoupk256.3322.org 127.0.0.1 d4.kkads.cn 127.0.0.1 www.kkads.cn 127.0.0.1 soft.16990.com 127.0.0.1 bak.hjob123.com 127.0.0.1 class.caiyi8.com 127.0.0.1 www.177i.com 127.0.0.1 www.our9988.cn 127.0.0.1 444.916kk.com 127.0.0.1 soft2.86sifu.com 127.0.0.1 lm.9cdn.com 127.0.0.1 adswin.unet.hk 127.0.0.1 cab.borlander.com.cn 127.0.0.1 net.jnnic.com 127.0.0.1 ip.9cdn.com 127.0.0.1 yz.jz173.com 127.0.0.1 www.daydayshop.cn 127.0.0.1 wifayy.51vip.biz 127.0.0.1 stats.ucantv.com 127.0.0.1 x5.ioeruwu.com 127.0.0.1 x4.ioeruwu.com 127.0.0.1 push.cpushpop.com 127.0.0.1 1.ads555.com 127.0.0.1 x6.aooooa.cn 127.0.0.1 44.770304123.cn 127.0.0.1 blog.myspace.cn 127.0.0.1 picer.poco.cn 127.0.0.1 active.borlander.com.cn 127.0.0.1 www.666888ip.cn 127.0.0.1 dd.749571.com 127.0.0.1 author1.cmfu.com 127.0.0.1 author4.cmfu.com 127.0.0.1 author6.cmfu.com 127.0.0.1 author8.cmfu.com 127.0.0.0 wg.16xia.com 127.0.0.1 www.exiao01.com 127.0.0.1 qqq.hao1658.com 127.0.0.1 down.18dd.net 127.0.0.1 1.jopenqc.com 127.0.0.1 3.joppnqq.com 127.0.0.1 1.jopenkk.com 127.0.0.1 new.749571.com 127.0.0.1 cao.kv8.info 127.0.0.1 yu.8s7.net 127.0.0.1 2.joppnqq.com 127.0.0.1 xxx.mmma.biz 127.0.0.1 www.22aaa.com 127.0.0.1 www.exiao01.com 127.0.0.1 www.tomwg.com 127.0.0.1 1.joppnqq.com 127.0.0.1 d2.llsging.com 127.0.0.1 llboss.com 127.0.0.1 my.531jx.cn ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 592, C:\WINDOWS\SYSTEM32\LSASS.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 2892, C:\WINDOWS\TEMP\_QOSEC29.MSI] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3424, C:\PROGRAM FILES\TENCENT\TT\TTRAVELER.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 3372, D:\DOWNLOADS\新建文件夹\QQPET\QQPETS3D\QQPETS3D.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3372, D:\DOWNLOADS\新建文件夹\QQPET\QQPETS3D\QQPETS3D.EXE] ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]