[CODE] 2008-06-13,15:28:21 System Repair Engineer 2.5.16.900 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] <%systemroot%\system32\dumprep 0 -k> [N/A] <; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher] <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [N/A] <; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [N/A] <"D:\新建文件夹\Rising\Rav\RavTask.exe" -system> [(Verified)Beijing Rising Science and Technology Corporation Limited] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce] [Beijing Rising Technology Co., Ltd.] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}> [Beijing Rising Technology Co., Ltd.] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}> [(Verified)Beijing Rising Science and Technology Corporation Limited] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Component Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A] ================================== 启动文件夹 N/A ================================== 服务 [Contrl Center of Storm Media / ccosm][Running/Auto Start] <北京暴风网际科技有限公司> [Rising Process Communication Center / RsCCenter][Running/Auto Start] <"D:\新建文件夹\Rising\Rav\CCenter.exe"> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] <"D:\新建文件夹\RISING\RAV\Ravmond.exe"> ================================== 驱动程序 [Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start] [aeaudio / aeaudio][Running/Manual Start] [Service for Avance AC97 Audio (WDM) / ALCXWDM][Stopped/Manual Start] [AMD K8 Processor Driver / AmdK8][Stopped/Manual Start] [Intel(R) PRO Network Connection Driver / E100B][Running/Manual Start] [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start] [HookCont / HookCont][Running/System Start] <\SystemRoot\system32\drivers\HookCont.sys> [HookNtos / HookNtos][Running/System Start] <\SystemRoot\system32\drivers\HookNtos.sys> [HookReg / HookReg][Running/System Start] <\SystemRoot\system32\drivers\HookReg.sys> [HookSys / HookSys][Running/System Start] <\SystemRoot\system32\drivers\HookSys.sys> [ialm / ialm][Running/Manual Start] [npkcrypt / npkcrypt][Stopped/Auto Start] <\??\C:\Program Files\QQ2006\npkcrypt.sys> [nv / nv][Stopped/Manual Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [RsAntiSpyware / RsAntiSpyware][Running/Boot Start] <\SystemRoot\system32\drivers\RsBoot.sys> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [Secdrv / Secdrv][Stopped/Manual Start] [smwdm / smwdm][Running/Manual Start] ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [浩方对战平台] {0A155D3C-68E2-4215-A47A-E800A446447A} [信息检索(&R)] {92780B25-18CC-41C8-B9BE-3C9C571A8263} [卡卡上网安全助手] {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} [AxSubmitControl Class] {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} [PasswordEditCtrl Class] {E787FD25-8D7C-4693-AE67-9406BC6E22DF} [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] ================================== 正在运行的进程 [PID: 648 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 712 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 736 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 780 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 792 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 948 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1012 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1140 / SYSTEM][D:\新建文件夹\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.28] [PID: 1156 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1308 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1356 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1464 / SYSTEM][D:\新建文件夹\RISING\RAV\ravmond.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.76] [D:\新建文件夹\RISING\RAV\BWList.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.4] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [D:\新建文件夹\RISING\RAV\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0] [D:\新建文件夹\RISING\RAV\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16] [D:\新建文件夹\RISING\RAV\RsLog.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.35] [D:\新建文件夹\RISING\RAV\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\新建文件夹\RISING\RAV\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\新建文件夹\RISING\RAV\MonRule.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.29] [D:\新建文件夹\RISING\RAV\Hooksys.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 9] [D:\新建文件夹\RISING\RAV\HookReg.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 4] [D:\新建文件夹\RISING\RAV\HookNtos.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 2] [D:\新建文件夹\RISING\RAV\rswalmon.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 22] [D:\新建文件夹\RISING\RAV\recomp.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 39] [D:\新建文件夹\RISING\RAV\refs.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17] [D:\新建文件夹\RISING\RAV\ffr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 15] [D:\新建文件夹\Rising\Rav\RsStore.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.8] [D:\新建文件夹\RISING\RAV\HookCont.dll] [Beijing Rising Technology Co., Ltd, 22, 0, 0, 1] [D:\新建文件夹\Rising\Rav\fakescan.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.13] [D:\新建文件夹\Rising\Rav\Scanner.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.36] [D:\新建文件夹\RISING\RAV\viruslib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26] [D:\新建文件夹\RISING\RAV\relibldr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [D:\新建文件夹\RISING\RAV\HookWeb.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.2] [D:\新建文件夹\RISING\RAV\extfile.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 29] [D:\新建文件夹\RISING\RAV\pearc.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5] [D:\新建文件夹\RISING\RAV\nvfile.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 6] [D:\新建文件夹\RISING\RAV\scanexec.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\新建文件夹\RISING\RAV\unexe.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5] [D:\新建文件夹\RISING\RAV\scanex.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 76] [D:\新建文件夹\RISING\RAV\scansct.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9] [PID: 1780 / SYSTEM][D:\新建文件夹\RISING\RAV\RavStub.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.9] [D:\新建文件夹\RISING\RAV\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\新建文件夹\RISING\RAV\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\新建文件夹\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [PID: 2000 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [D:\新建文件夹\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [D:\新建文件夹\Thunder\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 17] [D:\新建文件夹\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [D:\新建文件夹\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.16] [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510] [PID: 2016 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [PID: 220 / Administrator][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3.0.0.4396] [C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4396] [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4396] [C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4396] [PID: 252 / Administrator][C:\WINDOWS\system32\igfxpers.exe] [Intel Corporation, 3.0.0.4396] [C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4396] [PID: 372 / Administrator][D:\新建文件夹\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.23] [D:\新建文件夹\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\新建文件夹\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\新建文件夹\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [D:\新建文件夹\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 20.0.0.0] [D:\新建文件夹\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16] [PID: 412 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 416 / Administrator][D:\新建文件夹\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 20.0.01.19] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [D:\新建文件夹\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\新建文件夹\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19] [D:\新建文件夹\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [D:\新建文件夹\Rising\Rav\recomp.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 39] [D:\新建文件夹\Rising\Rav\refs.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17] [D:\新建文件夹\Rising\Rav\viruslib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26] [D:\新建文件夹\Rising\Rav\relibldr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16] [D:\新建文件夹\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0] [D:\新建文件夹\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16] [D:\新建文件夹\Rising\Rav\MonRule.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.29] [D:\新建文件夹\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4] [D:\新建文件夹\Rising\Rav\Rsguilib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 89] [D:\新建文件夹\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0] [PID: 672 / SYSTEM][C:\Program Files\StormII\stormliv.exe] [北京暴风网际科技有限公司, 3, 8, 3, 15] [C:\Program Files\StormII\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0] [PID: 920 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)] [PID: 856 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 2584 / Administrator][D:\新建文件夹\ut\UT Game\UTGame.exe] [新浪网技术(中国)有限公司, 4.00.000] [D:\新建文件夹\ut\UT Game\UTSystem.dll] [新浪网技术(中国)有限公司, 3.00.000] [D:\新建文件夹\ut\UT Game\UTMedia.dll] [新浪信息技术有限公司, 3.00.000] [D:\新建文件夹\ut\UT Game\UTCore.dll] [2005- 新浪网技术(中国)有限公司, 3.00.000] [D:\新建文件夹\ut\UT Game\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [D:\新建文件夹\ut\UT Game\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [D:\新建文件夹\ut\UT Game\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [D:\新建文件夹\ut\UT Game\UTCtrls.dll] [2005- 新浪网技术(中国)有限公司, 3.00.000] [D:\新建文件夹\ut\UT Game\GameLobby.dll] [TODO: <公司名>, 1.0.0.1] [D:\新建文件夹\ut\UT Game\UTCtrlsEx.dll] [新浪网技术(中国)有限公司, 1.0.0.1] [D:\新建文件夹\ut\UT Game\UTHook.dll] [2005- 新浪网技术(中国)有限公司, 3, 0, 0, 0] [D:\新建文件夹\ut\UT Game\UTGameRC.dll] [2005- 新浪网技术(中国)有限公司, 4.00.000] [D:\新建文件夹\ut\UT Game\RICHED20.DLL] [Microsoft Corporation, 5.30.23.1205] [D:\新建文件夹\ut\UT Game\UTBugCatch.dll] [北京新浪信息技术有限公司, 1, 2, 8, 0] [D:\新建文件夹\ut\UT Game\dbghelp.dll] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [D:\新建文件夹\ut\UT Game\UCSocket.DLL] [北京新浪信息技术有限公司, 1, 1, 21, 0] [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.5510] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [D:\新建文件夹\ut\UT Game\UTAudio.DLL] [Beijing Sina Information Technology Co.,Ltd, 3, 4, 0, 3] [D:\新建文件夹\ut\UT Game\UpdateDll.dll] [Beijing Sina Information Technology Co.,Ltd, 1.3.3.0] [C:\WINDOWS\system32\msg711.acm] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [D:\新建文件夹\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0] [D:\新建文件夹\ut\UT Game\UCACodec2.dll] [Bejing Sina Information Technology Co.,Ltd , 1.0.0] [PID: 3952 / Administrator][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [D:\新建文件夹\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.16] [D:\新建文件夹\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [D:\新建文件夹\Thunder\Components\ResWorker\DsBho_00.dll] [, 1, 0, 0, 17] [D:\新建文件夹\Thunder\Components\ResWorker\DataProcessor_00.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [D:\新建文件夹\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3] [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\WINDOWS\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950] [C:\WINDOWS\system32\WINABCX.IME] [PKUETI, 5.22.216] [C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0] [C:\WINDOWS\system32\xpsp3res.dll] [Microsoft Corporation, 5.1.2600.2906 (xpsp_sp2_gdr.060510-2351)] [PID: 2976 / Administrator][D:\新建文件夹\saomao\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900] [D:\新建文件夹\saomao\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] ================================== 文件关联 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 127.0.0.1 tttt.591jx.com 127.0.0.1 jx.llzjz.cn 127.0.0.1 eee.avpkav.com 127.0.0.1 fff.tesekl.info 127.0.0.1 www.dj8910.com 127.0.0.1 test.591jx.com 127.0.0.1 1.9797aiai.com 127.0.0.1 2.9797aiai.com 127.0.0.1 3.9797aiai.com 127.0.0.1 4.9797aiai.com 127.0.0.1 5.9797aiai.com 127.0.0.1 2.kv8.info 127.0.0.1 www.88feel.cn 127.0.0.1 feel.88feel.cn 127.0.0.1 exe.xinniankl.com 127.0.0.1 the.microgood.net 127.0.0.1 xin.xinniankl.com 127.0.0.1 xxx.wofala.info 127.0.0.1 aaa.wd03.info 127.0.0.1 xxx.wd01.info 127.0.0.1 www.ip580.com 127.0.0.1 url.hao365.org 127.0.0.1 xxx.huilaiba.info 127.0.0.1 bankdiyed.cn 127.0.0.1 59.vc 127.0.0.1 086199.service-google.cn 127.0.0.1 bt.etimes888.com 127.0.0.1 www.hua28.com 127.0.0.1 www.wg771.com 127.0.0.1 www.2323938.com 127.0.0.1 xxx.llsj123.com 127.0.0.1 a.topxxxx.cn 127.0.0.1 picon.chinaren.com 127.0.0.1 blog.wcad.cn 127.0.0.1 s101-cnzz.com 127.0.0.1 a.bkyes.com 127.0.0.1 yoooooooo.bkyes.com 127.0.0.1 vestb.lu158.cn 127.0.0.1 xiazai.cpushpop.com 127.0.0.1 iii.chsip.net 127.0.0.1 d.wacsy.com 127.0.0.1 web.haoliuliang.com 127.0.0.1 ad.haoliuliang.com 127.0.0.1 mm.haoliuliang.com 127.0.0.1 www.hao12321.cn 127.0.0.1 www.likeall.cn 127.0.0.1 asdfasdf.88y.net 127.0.0.1 down.laladan.cn 127.0.0.1 psp.kalengzi.cn 127.0.0.1 xxx.zttwp.cn 127.0.0.1 ce.laladan.cn 127.0.0.1 xxx.laladan.cn 127.0.0.1 udd.yooosky.com 127.0.0.1 uee.yooosky.com 127.0.0.1 uff.yooosky.com 127.0.0.1 cc.fockfock.com ================================== 进程特权扫描 特殊特权被允许: SeLoadDriverPrivilege [PID = 2584, D:\新建文件夹\UT\UT GAME\UTGAME.EXE] ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]