[CODE] 2008-06-11,19:55:01 System Repair Engineer 2.5.16.900 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [(Verified)Microsoft Windows Component Publisher] <; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit> [(Verified)Microsoft Windows Hardware Compatibility Publisher] [Putian Runway] <"C:\Program Files\Rising\AntiSpyware\runiep.exe" /startup> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}> [Beijing Rising Technology Co., Ltd.] <{4F4F0064-71E0-4f0d-0005-708476C7815F}> [] <{4F4F0064-71E0-4f0d-0001-708476C7815F}> [Microsoft Corporation] <{4F4F0064-71E0-4f0d-0017-708476C7815F}> [] <{4F4F0064-71E0-4f0d-0021-708476C7815F}> [] <{4F4F0064-71E0-4f0d-0012-708476C7815F}> [] <{4F4F0064-71E0-4f0d-0025-708476C7815F}> [] <{55694105-5108-9405-3695-954187462155}> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] [(Verified)Microsoft Windows Publisher] [] [] [Microsoft Corporation] [] [] [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A] ================================== 启动文件夹 N/A ================================== 服务 [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [NVIDIA Display Driver Service / NVSvc][Running/Auto Start] ================================== 驱动程序 [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start] [AliIde / AliIde][Running/Boot Start] <\SystemRoot\System32\DRIVERS\aliide.sys> [AMD K8 Processor Driver / AmdK8][Stopped/Manual Start] [CmdIde / CmdIde][Running/Boot Start] <\SystemRoot\System32\DRIVERS\cmdide.sys> [C-Media WDM Audio Interface / cmuda][Running/Manual Start] [ENUS_NDIS_DRIVER / ENUS_NDIS_DRIVER][Running/Boot Start] <\SystemRoot\system32\enusndis.sys> [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start] [IIS Manager / IIS Manager ][Stopped/Disabled] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1.tmp> [npkcrypt / npkcrypt][Stopped/Auto Start] <\??\C:\Program Files\QQ2006\npkcrypt.sys> [nv / nv][Running/Manual Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [RsAntiSpyware / RsAntiSpyware][Running/Boot Start] <\SystemRoot\system32\drivers\RsBoot.sys> [Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Running/Manual Start] [Secdrv / Secdrv][Stopped/Manual Start] ================================== 浏览器加载项 [] {55694105-5108-9405-3695-954187462155} [卡卡上网安全助手] {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} [MMCPlayer Class] {05C1004E-2596-48E5-8E26-39362985EEB9} [MMCPlayer Class] {05C1004E-2596-48E5-8E26-39362985EEB9} [Windows Media Player] {22D6F312-B0F6-11D0-94AB-0080C74C7E95} [HTML Document] {25336920-03F9-11CF-8FD0-00AA00686F13} [XML DOM Document] {2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\system32\msxml3.dll, N/A> [XML Document] {48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, N/A> [] {55694105-5108-9405-3695-954187462155} [PowerPlayer Control] {5EC7C511-CD0F-42E6-830C-1BD9882F3458} [WUWebControl Class] {6414512B-B978-451D-A0D8-FCFDF33E833C} [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [Active Desktop Mover] {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A> [Microsoft Web Browser] {8856F961-340A-11D0-A96B-00C04FD705A2} [XML DOM 文档 5.0] {88D969E5-F192-11D4-A65F-0040963251E5} [RDS.DataSpace] {BD96C556-65A3-11D0-983A-00C04FC29E36} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [卡卡上网安全助手] {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} [WebViewFolderIcon Class] {E5DF9D10-3B52-11D1-83E8-00A0C90DC849} [XML HTTP Request] {ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\system32\msxml3.dll, N/A> [XML DOM Document 3.0] {F5078F32-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\system32\msxml3.dll, N/A> [XML HTTP 3.0] {F5078F35-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\system32\msxml3.dll, N/A> [XML HTTP] {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\system32\msxml3.dll, N/A> [IERPCtl Class] {FDC7A535-4070-4B92-A0EA-D9994BCC0DC5} [使用迅雷下载] [导出到 Microsoft Office Excel(&X)] ================================== 正在运行的进程 [PID: 424 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 484 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 508 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 552 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 564 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 708 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 768 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 808 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 864 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 912 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1140 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [PID: 1288 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)] [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9] [C:\WINDOWS\system32\midimapzx.dll] [N/A, ] [C:\WINDOWS\system32\midimapzt.dll] [Microsoft Corporation, 5, 1, 2600, 3119] [C:\WINDOWS\system32\midimaptl.dll] [N/A, ] [C:\WINDOWS\system32\midimappt.dll] [N/A, ] [C:\WINDOWS\system32\midimapjr.dll] [N/A, ] [C:\WINDOWS\system32\midimapfs2.dll] [N/A, ] [C:\Program Files\WinRAR\rarext.dll] [N/A, ] [PID: 1348 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.9136] [PID: 1892 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 684 / Administrator][C:\Program Files\racer-ccn-racerpc-ha\racer.exe] [Putian Runway, 3,3,130,306] [C:\WINDOWS\system32\midimapfs2.dll] [N/A, ] [C:\WINDOWS\system32\midimapjr.dll] [N/A, ] [C:\WINDOWS\system32\midimappt.dll] [N/A, ] [C:\WINDOWS\system32\midimaptl.dll] [N/A, ] [C:\WINDOWS\system32\midimapzt.dll] [Microsoft Corporation, 5, 1, 2600, 3119] [C:\WINDOWS\system32\midimapzx.dll] [N/A, ] [C:\Program Files\racer-ccn-racerpc-ha\rwxre.dll] [Putian Runway, 3,3,130,306] [C:\Program Files\racer-ccn-racerpc-ha\nspr4.dll] [Netscape Communications Corporation, 4.6.1] [C:\Program Files\racer-ccn-racerpc-ha\xpcom_core.dll] [Mozilla Foundation, Personal] [C:\Program Files\racer-ccn-racerpc-ha\plc4.dll] [Netscape Communications Corporation, 4.6.1] [C:\Program Files\racer-ccn-racerpc-ha\plds4.dll] [Netscape Communications Corporation, 4.6.1] [C:\Program Files\racer-ccn-racerpc-ha\nss3.dll] [Netscape Communications Corporation, 3.10.2] [C:\Program Files\racer-ccn-racerpc-ha\softokn3.dll] [Netscape Communications Corporation, 3.10.2] [C:\Program Files\racer-ccn-racerpc-ha\js3250.dll] [Netscape Communications Corporation, 4.0] [C:\Program Files\racer-ccn-racerpc-ha\gkgfx.dll] [Mozilla Foundation, Personal] [C:\Program Files\racer-ccn-racerpc-ha\xpcom_compat.dll] [Mozilla Foundation, Personal] [C:\Program Files\racer-ccn-racerpc-ha\smime3.dll] [Netscape Communications Corporation, 3.10.2] [C:\Program Files\racer-ccn-racerpc-ha\ssl3.dll] [Netscape Communications Corporation, 3.10.2] [C:\Program Files\racer-ccn-racerpc-ha\components\racer_base_comp.dll] [Putian Runway, 3,3,130,306] [C:\Program Files\racer-ccn-racerpc-ha\racer_base.dll] [Putian Runway, 3,3,130,306] [C:\Program Files\racer-ccn-racerpc-ha\kbdhook.dll] [Putian Runway, 3,3,130,306] [C:\Program Files\racer-ccn-racerpc-ha\components\jar50.dll] [Mozilla Foundation, Personal] [C:\Program Files\racer-ccn-racerpc-ha\components\gklayout.dll] [Mozilla Foundation, Personal] [C:\Program Files\racer-ccn-racerpc-ha\nssckbi.dll] [Netscape Communications Corporation, 1.53] [C:\Program Files\racer-ccn-racerpc-ha\components\racer_ad_comp.dll] [Putian Runway, 3,3,130,306] [C:\Program Files\racer-ccn-racerpc-ha\components\racer_access_dhcpplus.dll] [Putian Runway, 3,3,130,325] [C:\Program Files\racer-ccn-racerpc-ha\dhcpplus.dll] [北京润汇科技有限公司, 3, 0, 0, 45] [PID: 728 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\midimapfs2.dll] [N/A, ] [C:\WINDOWS\system32\midimapjr.dll] [N/A, ] [C:\WINDOWS\system32\midimappt.dll] [N/A, ] [C:\WINDOWS\system32\midimaptl.dll] [N/A, ] [C:\WINDOWS\system32\midimapzt.dll] [Microsoft Corporation, 5, 1, 2600, 3119] [C:\WINDOWS\system32\midimapzx.dll] [N/A, ] [PID: 840 / Administrator][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)] [C:\WINDOWS\system32\midimapfs2.dll] [N/A, ] [C:\WINDOWS\system32\midimapjr.dll] [N/A, ] [C:\WINDOWS\system32\midimappt.dll] [N/A, ] [C:\WINDOWS\system32\midimaptl.dll] [N/A, ] [C:\WINDOWS\system32\midimapzt.dll] [Microsoft Corporation, 5, 1, 2600, 3119] [C:\WINDOWS\system32\midimapzx.dll] [N/A, ] [PID: 1448 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\midimapfs2.dll] [N/A, ] [C:\WINDOWS\system32\midimapjr.dll] [N/A, ] [C:\WINDOWS\system32\midimappt.dll] [N/A, ] [C:\WINDOWS\system32\midimaptl.dll] [N/A, ] [C:\WINDOWS\system32\midimapzt.dll] [Microsoft Corporation, 5, 1, 2600, 3119] [C:\WINDOWS\system32\midimapzx.dll] [N/A, ] [PID: 1528 / Administrator][D:\sreng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900] [C:\WINDOWS\system32\midimapfs2.dll] [N/A, ] [C:\WINDOWS\system32\midimapjr.dll] [N/A, ] [C:\WINDOWS\system32\midimappt.dll] [N/A, ] [C:\WINDOWS\system32\midimaptl.dll] [N/A, ] [C:\WINDOWS\system32\midimapzt.dll] [Microsoft Corporation, 5, 1, 2600, 3119] [C:\WINDOWS\system32\midimapzx.dll] [N/A, ] [D:\sreng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] ================================== 文件关联 .TXT Error. [C:\WINDOWS\notepad.exe %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM Error. ["hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 219.235.3.16 www.360safe.com 219.235.3.16 www.k369.com 219.235.3.16 www.5566.net 219.235.3.16 360safe.com 202.165.102.243 update.360safe.com 219.235.3.16 dl.360safe.com 219.235.3.16 down.360safe.com 219.235.3.16 bbs.360safe.com 219.235.3.16 kaba.360safe.com 219.235.3.16 baike.360safe.com 219.235.3.16 www.360.cn 219.235.3.16 360.cn 219.235.3.16 wopti.360.cn 202.165.102.243 update.360.cn 219.235.3.16 dl.360.cn 219.235.3.16 down.360.cn 219.235.3.16 bbs.360.cn 219.235.3.16 kaba.360.cn 219.235.3.16 baike.360.cn 219.235.3.16 360.qihoo.com 219.235.3.16 360safe.qihoo.com 219.235.3.16 forum.ikaka.com 219.235.3.16 www.ikaka.com 202.165.102.243 update.ikaka.com 219.235.3.16 forum.jiangmin.com 202.165.102.243 update.jiangmin.com 219.235.3.16 tieba.baidu.com 202.165.102.243 update.rising.com.cn 219.235.3.16 online.rising.com.cn 202.165.102.243 center.rising.com.cn 219.235.3.16 up.duba.net 219.235.3.16 vi.duba.net 219.235.3.16 shadu.baidu.com 219.235.3.16 du.baidu.com 219.235.3.16 security.symantec.com 219.235.3.16 shadu.duba.net 219.235.3.16 bbs.duba.net 219.235.3.16 www.duba.net 219.235.3.16 online.jiangmin.com 219.235.3.16 cn.mcafee.com 219.235.3.16 www.ahn.com.cn 219.235.3.16 www.kaspersky.com.cn 219.235.3.16 www.pcav.cn 219.235.3.16 www.luosoft.com 219.235.3.16 www.im286.com 219.235.3.16 an.baidu.com 219.235.3.16 ma.baidu.com 219.235.3.16 bbs.htmlman.net 202.165.102.243 download.rising.com.cn 202.165.102.243 rsup08.rising.com.cn 219.235.3.16 10000.286er.com 219.235.3.16 im286.net 219.235.3.16 ju.qihoo.com 219.235.3.16 bbs.chinaz.com 219.235.3.16 www.qihoo.com 202.165.102.243 dnl-cn1.kaspersky-labs.com 202.165.102.243 dnl-cn2.kaspersky-labs.com 202.165.102.243 dnl-cn3.kaspersky-labs.com 202.165.102.243 dnl-cn4.kaspersky-labs.com 202.165.102.243 dnl-cn5.kaspersky-labs.com 202.165.102.243 dnl-cn6.kaspersky-labs.com 202.165.102.243 dnl-cn7.kaspersky-labs.com 202.165.102.243 dnl-cn8.kaspersky-labs.com 202.165.102.243 dnl-cn9.kaspersky-labs.com 202.165.102.243 dnl-cn10.kaspersky-labs.com 202.165.102.243 dnl-cn11.kaspersky-labs.com 202.165.102.243 dnl-cn12.kaspersky-labs.com 202.165.102.243 dnl-cn13.kaspersky-labs.com 202.165.102.243 dnl-cn14.kaspersky-labs.com 202.165.102.243 dnl-cn15.kaspersky-labs.com 202.165.102.243 dnl-eu1.kaspersky-labs.com 202.165.102.243 dnl-eu2.kaspersky-labs.com 202.165.102.243 dnl-eu3.kaspersky-labs.com 202.165.102.243 dnl-eu4.kaspersky-labs.com 202.165.102.243 dnl-eu5.kaspersky-labs.com 202.165.102.243 dnl-eu6.kaspersky-labs.com 202.165.102.243 dnl-eu7.kaspersky-labs.com 202.165.102.243 dnl-eu8.kaspersky-labs.com 202.165.102.243 dnl-eu9.kaspersky-labs.com 202.165.102.243 dnl-eu10.kaspersky-labs.com 202.165.102.243 dnl-eu11.kaspersky-labs.com 202.165.102.243 dnl-eu12.kaspersky-labs.com 202.165.102.243 dnl-eu13.kaspersky-labs.com 202.165.102.243 dnl-eu14.kaspersky-labs.com 202.165.102.243 dnl-eu15.kaspersky-labs.com 202.165.102.243 dnl-us1.kaspersky-labs.com 202.165.102.243 dnl-us2.kaspersky-labs.com 202.165.102.243 dnl-us3.kaspersky-labs.com 202.165.102.243 dnl-us4.kaspersky-labs.com 202.165.102.243 dnl-us5.kaspersky-labs.com 202.165.102.243 dnl-us6.kaspersky-labs.com 202.165.102.243 dnl-us7.kaspersky-labs.com 202.165.102.243 dnl-us8.kaspersky-labs.com 202.165.102.243 dnl-us9.kaspersky-labs.com 202.165.102.243 dnl-us10.kaspersky-labs.com 202.165.102.243 dnl-us11.kaspersky-labs.com 202.165.102.243 dnl-us12.kaspersky-labs.com 202.165.102.243 dnl-us13.kaspersky-labs.com 202.165.102.243 dnl-us14.kaspersky-labs.com 202.165.102.243 dnl-us15.kaspersky-labs.com 202.165.102.243 dnl-ru1.kaspersky-labs.com 202.165.102.243 dnl-ru2.kaspersky-labs.com 202.165.102.243 dnl-ru3.kaspersky-labs.com 202.165.102.243 dnl-ru4.kaspersky-labs.com 202.165.102.243 dnl-ru5.kaspersky-labs.com 202.165.102.243 dnl-ru6.kaspersky-labs.com 202.165.102.243 dnl-ru7.kaspersky-labs.com 202.165.102.243 dnl-ru8.kaspersky-labs.com 202.165.102.243 dnl-ru9.kaspersky-labs.com 202.165.102.243 dnl-ru10.kaspersky-labs.com 202.165.102.243 dnl-ru11.kaspersky-labs.com 202.165.102.243 dnl-ru12.kaspersky-labs.com 202.165.102.243 dnl-ru13.kaspersky-labs.com 202.165.102.243 dnl-ru14.kaspersky-labs.com 202.165.102.243 dnl-ru15.kaspersky-labs.com 202.165.102.243 dnl-jp1.kaspersky-labs.com 202.165.102.243 dnl-jp2.kaspersky-labs.com 202.165.102.243 dnl-jp3.kaspersky-labs.com 202.165.102.243 dnl-jp4.kaspersky-labs.com 202.165.102.243 dnl-jp5.kaspersky-labs.com 202.165.102.243 dnl-jp6.kaspersky-labs.com 202.165.102.243 dnl-jp7.kaspersky-labs.com 202.165.102.243 dnl-jp8.kaspersky-labs.com 202.165.102.243 dnl-jp9.kaspersky-labs.com 202.165.102.243 dnl-jp10.kaspersky-labs.com 202.165.102.243 dnl-jp11.kaspersky-labs.com 202.165.102.243 dnl-jp12.kaspersky-labs.com 202.165.102.243 dnl-jp13.kaspersky-labs.com 202.165.102.243 dnl-jp14.kaspersky-labs.com 202.165.102.243 dnl-jp15.kaspersky-labs.com 202.165.102.243 dnl-kr1.kaspersky-labs.com 202.165.102.243 dnl-kr2.kaspersky-labs.com 202.165.102.243 dnl-kr3.kaspersky-labs.com 202.165.102.243 dnl-kr4.kaspersky-labs.com 202.165.102.243 dnl-kr5.kaspersky-labs.com 202.165.102.243 dnl-kr6.kaspersky-labs.com 202.165.102.243 dnl-kr7.kaspersky-labs.com 202.165.102.243 dnl-kr8.kaspersky-labs.com 202.165.102.243 dnl-kr9.kaspersky-labs.com 202.165.102.243 dnl-kr10.kaspersky-labs.com 202.165.102.243 dnl-kr11.kaspersky-labs.com 202.165.102.243 dnl-kr12.kaspersky-labs.com 202.165.102.243 dnl-kr13.kaspersky-labs.com 202.165.102.243 dnl-kr14.kaspersky-labs.com 202.165.102.243 dnl-kr15.kaspersky-labs.com 202.165.102.243 dnl-cd1.kaspersky-labs.com 202.165.102.243 dnl-cd2.kaspersky-labs.com 202.165.102.243 dnl-cd3.kaspersky-labs.com 202.165.102.243 dnl-cd4.kaspersky-labs.com 202.165.102.243 dnl-cd5.kaspersky-labs.com 202.165.102.243 dnl-cd6.kaspersky-labs.com 202.165.102.243 dnl-cd7.kaspersky-labs.com 202.165.102.243 dnl-cd8.kaspersky-labs.com 202.165.102.243 dnl-cd9.kaspersky-labs.com 202.165.102.243 dnl-cd10.kaspersky-labs.com 202.165.102.243 dnl-cd11.kaspersky-labs.com 202.165.102.243 dnl-cd12.kaspersky-labs.com 202.165.102.243 dnl-cd13.kaspersky-labs.com 202.165.102.243 dnl-cd14.kaspersky-labs.com 202.165.102.243 dnl-cd15.kaspersky-labs.com 202.165.102.243 downloads1.kaspersky-labs.com 202.165.102.243 downloads2.kaspersky-labs.com 202.165.102.243 downloads3.kaspersky-labs.com 202.165.102.243 downloads4.kaspersky-labs.com 202.165.102.243 downloads5.kaspersky-labs.com 219.235.3.16 rss.360safe.com 219.235.3.16 x.360safe.com 219.235.3.16 d.360safe.com 219.235.3.16 updatem.360safe.com 219.235.3.16 softm.360safe.com 219.235.3.16 ishare.sina.com.cn 219.235.3.16 zhuansha.duba.net 219.235.3.16 buy.duba.net 219.235.3.16 kad.www.duba.net 219.235.3.16 cu001.www.duba.net 219.235.3.16 cu002.www.duba.net 219.235.3.16 cu003.www.duba.net 219.235.3.16 cu004.www.duba.net 219.235.3.16 cu005.www.duba.net 219.235.3.16 cu010.www.duba.net 219.235.3.16 client.download.duba.net 219.235.3.16 www.star111.net 219.235.3.16 www.dtdtdk.net 219.235.3.16 www.tongji123.org 219.235.3.16 www.kiss1231.net 219.235.3.16 my.myloveliuliang.cn 219.235.3.16 www.abc998801.cn 219.235.3.16 microgood.net 219.235.3.16 www.microgood.net ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 684, C:\PROGRAM FILES\RACER-CCN-RACERPC-HA\RACER.EXE] ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]