[CODE] 2008-08-20,17:43:40 System Repair Engineer 2.6.12.1018 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能 以下内容被选中: 所有的启动项目(包括注册表、启动文件夹、服务等) 浏览器加载项 正在运行的进程(包括进程模块信息) 文件关联 Winsock 提供者 Autorun.inf HOSTS 文件 进程特权扫描 启动项目 注册表 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Windows Publisher] <"C:\Program Files\SogouInput\OlympicNews.exe"> [(Verified)Sogou.com] <"F:\程序\WangWang\WangWang.exe"> [(Verified)"Alibaba Software(Shanghai)Co,. Ltd"] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] <"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Windows Hardware Compatibility Publisher] [(Verified)Microsoft Corporation] <"F:\程序\瑞星防火墙\rfwmain.exe" -Startup> [(Verified)Beijing Rising Information Technology Corporation Limited] <"F:\程序\瑞星杀软\RavTask.exe" -system> [(Verified)Beijing Rising Information Technology Corporation Limited] <"F:\程序\卡卡\rstray.exe" /startup> [File is missing] [File is missing] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Windows Component Publisher] [(Verified)Microsoft Windows Publisher] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{32CD708B-60A7-4C00-9377-D73EAA495F0F}> [(Verified)Beijing Rising Information Technology Corporation Limited] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] [(Verified)Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] <%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] <"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] [(Verified)Microsoft Windows Publisher] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing] ================================== 启动文件夹 [QQ游戏启动加速程序] F:\程序\QQGame\Accel.exe [深圳市腾讯计算机系统有限公司]> ================================== 服务 [Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start] [Contrl Center of Storm Media / ccosm][Running/Auto Start] <北京暴风网际科技有限公司> [Human Interface Device Access / HidServ][Stopped/Disabled] %SystemRoot%\System32\hidserv.dll> [HP Port Resolver / HP Port Resolver][Stopped/Manual Start] [HP Status Server / HP Status Server][Stopped/Manual Start] [Pml Driver HPZ12 / Pml Driver HPZ12][Running/Auto Start] [Rising Proxy Service / RfwProxySrv][Running/Auto Start] [Rising Personal Firewall Service / RfwService][Running/Auto Start] [Rising Process Communication Center / RsCCenter][Running/Auto Start] <"F:\程序\瑞星杀软\CCenter.exe"> [Rising RealTime Monitor / RsRavMon][Stopped/Auto Start] <"F:\程序\瑞星杀软\Ravmond.exe"> ================================== 驱动程序 [ati2mtag / ati2mtag][Running/Manual Start] [HP Dot4USB Filter / dot4ufd][Stopped/Manual Start] [Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start] [HookCont / HookCont][Running/System Start] <\SystemRoot\system32\drivers\HookCont.sys> [HookNtos / HookNtos][Running/System Start] <\SystemRoot\system32\drivers\HookNtos.sys> [HookReg / HookReg][Running/System Start] <\SystemRoot\system32\drivers\HookReg.sys> [HookSys / HookSys][Running/System Start] <\SystemRoot\system32\drivers\HookSys.sys> [HookUrl / HookUrl][Running/Auto Start] <\??\F:\程序\瑞星防火墙\HookUrl.sys> [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start] [Direct Parallel Link Driver / Ptilink][Running/Manual Start] [Rising Rfwbase Driver / RfwBase][Running/Auto Start] [RsFwDrv / RsFwDrv][Running/System Start] <\??\F:\程序\瑞星防火墙\RsFwDrv.sys> [RsNTGDI / RsNTGDI][Running/Boot Start] <\SystemRoot\system32\Drivers\RsNTGdi.sys> [Secdrv / Secdrv][Stopped/Manual Start] [Winbond Trusted Platform Module / TPM][Running/Manual Start] [NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller / yukonwxp][Running/Manual Start] ================================== 浏览器加载项 [ThunderAtOnce Class] {01443AEC-0FD1-40fd-9C87-E93D1494C233} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [启动迅雷5] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} [信息检索(&R)] {92780B25-18CC-41C8-B9BE-3C9C571A8263} [Messenger] {FB5F1910-F110-11d2-BB9E-00C04F795683} [UUSeeInstaller Control] {1345F3CB-7C40-41C2-9AC2-87CF8B68E34E} [Windows Genuine Advantage Validation Tool] {17492023-C23A-453E-A040-C7C580BBF700} [EditCtrl Class] {488A4255-3236-44B3-8F27-FA1AECAA8844} [AxInputControl Class] {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} [CCTVUpdateInstall] {AC414988-E5BB-4C2C-873B-EA53D2F3D23A} [ScreenCapture Class] {BFB79EE1-04AE-4D4A-B85E-27EE5F30C095} [ThunderAtOnce Class] {01443AEC-0FD1-40FD-9C87-E93D1494C233} [] {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <, > [Player Class] {11F2A418-94B2-4E16-9B0C-B00C0435F903} [UUSeeInstaller Control] {1345F3CB-7C40-41C2-9AC2-87CF8B68E34E} [InstallHelper Class] {1DABF8D5-8430-4985-9B7F-A30E53D709B3} [iTrusPTA Class] {1E0DFFCF-27FF-4574-849B-55007349FEDA} [Windows Media Player] {22D6F312-B0F6-11D0-94AB-0080C74C7E95} [HTML Document] {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, (Signed) N/A> [DHTML Edit Control Safe for Scripting for IE5] {2D360201-FFF5-11D1-8D03-00A0C959BC0A} [IETag Factory] {38481807-CA0E-42D2-BF39-B33AF135CC4D} [Thunder Agent Class] {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} [EditCtrl Class] {488A4255-3236-44B3-8F27-FA1AECAA8844} [HHCtrl Object] {52A2AAAE-085D-4187-97EA-8C30DB990436} [] {5EC7C511-CD0F-42E6-830C-1BD9882F3458} <, > [XMP Class] {6483F145-A768-4C41-AACC-52D4D7845851} [XDRM] {693571CB-54A3-4E90-9D52-EEAE1334E2D3} [StormPlayer Object] {6BE52E1D-E586-474F-A6E2-1A85A9B4D9FB} [Windows Media Player] {6BF52A52-394A-11D3-B153-00C04F79FAA6} [WangWangObj Class] {6E213FC7-DD5A-4115-B7E6-D4C7838C361E} [AxInputControl Class] {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} [MediaComm Class] {7670648D-461B-42AF-BDFE-46D26AF5EFF2} [Microsoft Web 浏览器] {8856F961-340A-11D0-A96B-00C04FD705A2} [Thunder Browser Helper] {889D2FEB-5411-4565-8998-1DD2C5261283} [AxSubmitControl Class] {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} [] {92780B25-18CC-41C8-B9BE-3C9C571A8263} <, > [卡卡上网安全助手] {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} [CCTVUpdateInstall] {AC414988-E5BB-4C2C-873B-EA53D2F3D23A} [DapCtrl Class] {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} [Microsoft Scriptlet Component] {AE24FDAE-03C6-11D1-8B76-0080C744F389} [SearchAssistantOC] {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A> [RDS.DataSpace] {BD96C556-65A3-11D0-983A-00C04FC29E36} [ScreenCapture Class] {BFB79EE1-04AE-4D4A-B85E-27EE5F30C095} [KooPlayer Control] {C728DAB8-FDF5-4CD7-89DD-879D25794C77} [Acrobat Control-用于 ActiveX] {CA8A9780-280D-11CF-A24D-444553540000} [AUDIO__MP3 Moniker Class] {CD3AFA76-B84F-48F0-9393-7EDC34128127} [AUDIO__X_MS_WMA Moniker Class] {CD3AFA84-B84F-48F0-9393-7EDC34128127} [RealPlayer G2 Control] {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [PlayerCtrl Class] {E05BC2A3-9A46-4A32-80C9-023A473F5B23} [UPlayer Control] {EAB7A1CC-C77B-45E5-9AC2-AD037D047BCC} [Thunder DapPlayer] {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} [XPPlayer Class] {F3E70CEA-956E-49CC-B444-73AFE593AD7F} [] {FB5F1910-F110-11D2-BB9E-00C04F795683} <, > [iSee 保存所有图片] [iSee保存Flash] [iSee保存所有图片] [iSee读取Exif] [使用迅雷下载] [使用迅雷下载全部链接] [导出到 Microsoft Office Excel(&X)] [添加到QQ表情] [添加相册用户到iSee收藏] ================================== 正在运行的进程 [PID: 656 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 720 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 756 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4176] [C:\WINDOWS\system32\WgaLogon.dll] [Microsoft Corporation, 1.7.0018.7] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 800 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 812 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 968 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4183] [C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2513] [C:\WINDOWS\system32\atipdlxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2526] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 996 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 1068 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 1172 / SYSTEM][F:\程序\瑞星杀软\CCenter.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.33] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 1188 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)] [PID: 1304 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 1344 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 1384 / SYSTEM][F:\程序\瑞星杀软\ravmond.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.80] [F:\程序\瑞星杀软\BWList.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.5] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [F:\程序\瑞星杀软\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [F:\程序\瑞星杀软\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [F:\程序\瑞星杀软\RsLog.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.36] [F:\程序\瑞星杀软\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [F:\程序\瑞星杀软\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [F:\程序\瑞星杀软\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.29] [F:\程序\瑞星杀软\Hooksys.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 12] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [F:\程序\瑞星杀软\HookReg.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 6] [F:\程序\瑞星杀软\HookNtos.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 5] [F:\程序\瑞星杀软\rswalmon.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 24] [F:\程序\瑞星杀软\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 40] [F:\程序\瑞星杀软\refs.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 18] [F:\程序\瑞星杀软\ffr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 16] [F:\程序\瑞星杀软\RsStore.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.9] [F:\程序\瑞星杀软\HookCont.dll] [Beijing Rising Information Technology Co., Ltd., 22, 0, 0, 3] [F:\程序\瑞星杀软\fakescan.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.14] [F:\程序\瑞星杀软\Scanner.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.39] [F:\程序\瑞星杀软\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27] [F:\程序\瑞星杀软\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [F:\程序\瑞星杀软\HookWeb.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.3] [F:\程序\瑞星杀软\nvfile.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7] [F:\程序\瑞星杀软\extfile.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 32] [F:\程序\瑞星杀软\pearc.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 8] [F:\程序\瑞星杀软\scanexec.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [F:\程序\瑞星杀软\unexe.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 6] [F:\程序\瑞星杀软\scanex.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 87] [F:\程序\瑞星杀软\extmail.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [F:\程序\瑞星杀软\scansct.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [F:\程序\瑞星杀软\scanpack.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 10] [F:\程序\瑞星杀软\revm.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 11] [F:\程序\瑞星杀软\urutils.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 7] [F:\程序\瑞星杀软\ur000.dat] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 19] [F:\程序\瑞星杀软\scriptci.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 4] [F:\程序\瑞星杀软\ur001.dat] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 4] [PID: 1400 / SYSTEM][F:\程序\瑞星防火墙\rfwsrv.exe] [Beijing Rising Information Technology Co., Ltd., 7.0.0.76] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [F:\程序\瑞星防火墙\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [F:\程序\瑞星防火墙\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [F:\程序\瑞星防火墙\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [F:\程序\瑞星防火墙\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [F:\程序\瑞星防火墙\RfwRule.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.17] [F:\程序\瑞星防火墙\rfwlog.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.16] [F:\程序\瑞星防火墙\Rfwdrv.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.48] [F:\程序\瑞星防火墙\ijt_ctrl.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.0] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [F:\程序\瑞星防火墙\unvdet.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.8] [F:\程序\瑞星防火墙\mPorts.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.6] [PID: 1448 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4183] [C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2513] [C:\WINDOWS\system32\atipdlxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2526] [C:\WINDOWS\system32\ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4176] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 1628 / SYSTEM][F:\程序\瑞星防火墙\rfwProxy.exe] [Beijing Rising Information Technology Co., Ltd., 7.0.0.37] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [F:\程序\瑞星防火墙\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [F:\程序\瑞星防火墙\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [F:\程序\瑞星防火墙\RfwRule.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.17] [F:\程序\瑞星防火墙\urlrule.dll] [Beijing Rising Information Technology Co., Ltd., 1.0.0.15] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [F:\程序\瑞星防火墙\MonMid.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.6] [PID: 1768 / Administrator][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.18] [F:\程序\xunlei\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29] [F:\程序\xunlei\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [F:\程序\xunlei\Components\ResWorker\DsBho_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20] [F:\程序\xunlei\Components\ResWorker\DataProcessor_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\PROGRA~1\MICROS~2\OFFICE11\MCPS.DLL] [Microsoft Corporation, 11.0.6551] [PID: 1968 / SYSTEM][F:\程序\瑞星防火墙\rfwstub.exe] [Beijing Rising Information Technology Co., Ltd., 7.0.0.12] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [F:\程序\瑞星防火墙\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 416 / SYSTEM][F:\程序\瑞星杀软\RavStub.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.10] [F:\程序\瑞星杀软\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [F:\程序\瑞星杀软\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [F:\程序\瑞星杀软\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 520 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.2175.0] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\hpzpp053.DLL] [Hewlett-Packard Corporation, 60.053.43.00] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.2175.0] [PID: 404 / Administrator][F:\程序\瑞星防火墙\RfwMain.exe] [Beijing Rising Information Technology Co., Ltd., 7.0.1.70] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [F:\程序\瑞星防火墙\RsGuiLib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 90] [F:\程序\瑞星防火墙\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [F:\程序\瑞星防火墙\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [F:\程序\瑞星防火墙\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [F:\程序\瑞星防火墙\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [F:\程序\瑞星防火墙\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [F:\程序\瑞星防火墙\RfwCtrl.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [F:\程序\瑞星防火墙\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [F:\程序\瑞星防火墙\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [F:\程序\瑞星防火墙\RfwRule.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.17] [PID: 1324 / SYSTEM][C:\Program Files\StormII\stormliv.exe] [北京暴风网际科技有限公司, 3, 8, 3, 15] [C:\Program Files\StormII\MSVCP60.dll] [Microsoft Corporation, 6.02.3104.0] [PID: 1484 / SYSTEM][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE] [Microsoft Corporation, 7.00.9466] [C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\2052\mdmui.dll] [Microsoft Corporation, 7.00.9466] [PID: 1536 / SYSTEM][C:\WINDOWS\system32\HPZipm12.exe] [HP, 10, 1, 1, 2] [PID: 2444 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 2612 / Administrator][C:\WINDOWS\RTHDCPL.EXE] [Realtek Semiconductor Corp., 2.1.6.7] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 2660 / Administrator][F:\程序\瑞星杀软\RavTask.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.0.24] [F:\程序\瑞星杀软\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [F:\程序\瑞星杀软\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [F:\程序\瑞星杀软\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [F:\程序\瑞星杀软\RSAPPMGR.DLL] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [F:\程序\瑞星杀软\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [PID: 2688 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 2696 / Administrator][C:\Program Files\SogouInput\OlympicNews.exe] [Sogou.com Inc., 3.5.0.0] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\Program Files\SogouInput\pxpnet.dll] [Sohu.com Inc., 1, 0, 0, 18] [PID: 2704 / Administrator][F:\程序\WangWang\WangWang.exe] [阿里巴巴软件(上海)有限公司, 5, 7, 0, 5] [F:\程序\WangWang\AliViewCtrl.dll] [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 2] [F:\程序\WangWang\VLNetwork.dll] [阿里巴巴软件(上海)有限公司, 1, 0, 0, 6] [F:\程序\WangWang\MFC80.DLL] [Microsoft Corporation, 8.00.50727.762] [F:\程序\WangWang\MSVCR80.dll] [Microsoft Corporation, 8.00.50727.762] [F:\程序\WangWang\MSVCP80.dll] [Microsoft Corporation, 8.00.50727.762] [F:\程序\WangWang\AliViewMedia.dll] [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 2] [F:\程序\WangWang\VideoCap.dll] [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 4] [F:\程序\WangWang\VLAudio.dll] [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 5] [F:\程序\WangWang\JsmShow.dll] [ 阿里巴巴软件(上海)有限公司, 1, 0, 0, 4] [F:\程序\WangWang\AliSkin.dll] [阿里巴巴软件(上海)有限公司, 1.0.0.1] [F:\程序\WangWang\PngLib.dll] [阿里巴巴软件(上海)有限公司, 1, 0, 0, 1] [F:\程序\WangWang\zlib.dll] [, 1.2.3] [F:\程序\WangWang\ww_network.dll] [, 2, 1, 0, 1] [F:\程序\WangWang\MFC80CHS.DLL] [Microsoft Corporation, 8.00.50727.762] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [F:\程序\WangWang\Ali_Res.DLL] [N/A, ] [C:\WINDOWS\system32\aliedit\aliedit.dll] [, 2, 1, 2, 1] [F:\程序\WangWang\WangWangX6.dll] [阿里巴巴软件(上海)有限公司, 1, 0, 0, 5] [F:\程序\WangWang\RICHED32.DLL] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [F:\程序\WangWang\RICHED20.dll] [Microsoft Corporation, 5.30.23.1221] [F:\程序\WangWang\RichOne.dll] [阿里巴巴软件(上海)有限公司, 1.0.0.1] [F:\程序\WangWang\TBProgress.dll] [阿里巴巴软件(上海)有限公司, 1.0.0.1] [F:\程序\WangWang\MessageNotify.dll] [, 1, 0, 0, 1] [F:\程序\瑞星杀软\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [C:\WINDOWS\system32\msdmo.dll] [, ] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 2752 / Administrator][F:\程序\瑞星杀软\Ravmon.exe] [Beijing Rising Information Technology Co., Ltd., 20.0.01.24] [C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0] [C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [F:\程序\瑞星杀软\ProcCom.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [F:\程序\瑞星杀软\RsCommX2.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 20] [F:\程序\瑞星杀软\RSCOMMON.DLL] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [F:\程序\瑞星杀软\recomp.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 40] [F:\程序\瑞星杀软\refs.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 18] [F:\程序\瑞星杀软\viruslib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 27] [F:\程序\瑞星杀软\relibldr.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 17] [F:\程序\瑞星杀软\RSAPPMGR.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.1] [F:\程序\瑞星杀软\CfgDll.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.19] [F:\程序\瑞星杀软\MonRule.dll] [Beijing Rising Information Technology Co., Ltd., 20.0.0.29] [F:\程序\瑞星杀软\PngDll.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [F:\程序\瑞星杀软\Rsguilib.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 90] [F:\程序\瑞星杀软\RsXML.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 2] [PID: 2972 / Administrator][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [F:\程序\xunlei\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29] [F:\程序\xunlei\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96] [F:\程序\xunlei\Components\ResWorker\DsBho_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20] [F:\程序\xunlei\Components\ResWorker\DataProcessor_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16] [C:\WINDOWS\system32\urlFilter.dll] [Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 15] [F:\程序\卡卡\UrlRule.dll] [Beijing Rising Information Technology Co., Ltd., 1.0.0.15] [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510] [F:\程序\瑞星杀软\RavScrCh.dll] [Beijing Rising Information Technology Co., Ltd., 20, 0, 0, 5] [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 3112 / NETWORK SERVICE][C:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [PID: 3496 / Administrator][C:\Program Files\WinRAR\WinRAR.exe] [N/A, ] [PID: 3516 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.032\SREngLdr.EXE] [Smallfrogs Studio, 2.6.12.1018] [PID: 3524 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.032\SREfe0be0bf.EXE] [Smallfrogs Studio, 2.6.12.1018] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.032\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15] [C:\PROGRA~1\MICROS~2\OFFICE11\MCPS.DLL] [Microsoft Corporation, 11.0.6551] [PID: 3584 / SYSTEM][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)] [F:\程序\瑞星防火墙\ijt_base.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.21] [F:\程序\瑞星防火墙\olemon.dll] [Beijing Rising Information Technology Co., Ltd., 7.0.0.9] [C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)] ================================== 文件关联 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock 提供者 N/A ================================== Autorun.inf N/A ================================== HOSTS 文件 127.0.0.1 localhost 219.235.3.16 search.114.vnet.cn 219.235.3.16 keyword.vnet.cn 219.235.3.16 auto.search.msn.com 219.235.3.16 search.msn.com 219.235.3.16 cnweb.search.live.com 219.235.3.16 www.360safe.com 219.235.3.16 www.k369.com 219.235.3.16 www.5566.net 219.235.3.16 360safe.com 202.165.102.243 update.360safe.com 219.235.3.16 dl.360safe.com 219.235.3.16 down.360safe.com 219.235.3.16 bbs.360safe.com 219.235.3.16 kaba.360safe.com 219.235.3.16 baike.360safe.com 219.235.3.16 www.360.cn 219.235.3.16 360.cn 219.235.3.16 wopti.360.cn 202.165.102.243 update.360.cn 219.235.3.16 dl.360.cn 219.235.3.16 down.360.cn 219.235.3.16 bbs.360.cn 219.235.3.16 kaba.360.cn 219.235.3.16 baike.360.cn 219.235.3.16 360.qihoo.com 219.235.3.16 360safe.qihoo.com 219.235.3.16 forum.ikaka.com 219.235.3.16 www.ikaka.com 202.165.102.243 update.ikaka.com 219.235.3.16 forum.jiangmin.com 202.165.102.243 update.jiangmin.com 219.235.3.16 tieba.baidu.com 219.235.3.16 post.baidu.com 219.235.3.16 zhidao.baidu.com 219.235.3.16 www.baidu.com 202.165.102.243 update.rising.com.cn 219.235.3.16 online.rising.com.cn 202.165.102.243 center.rising.com.cn 219.235.3.16 up.duba.net 219.235.3.16 vi.duba.net 219.235.3.16 shadu.baidu.com 219.235.3.16 du.baidu.com 219.235.3.16 security.symantec.com 219.235.3.16 shadu.duba.net 219.235.3.16 bbs.duba.net 219.235.3.16 www.duba.net 219.235.3.16 online.jiangmin.com 219.235.3.16 cn.mcafee.com 219.235.3.16 www.ahn.com.cn 219.235.3.16 www.kaspersky.com.cn 219.235.3.16 www.pcav.cn 219.235.3.16 www.luosoft.com 219.235.3.16 www.im286.com 219.235.3.16 an.baidu.com 219.235.3.16 ma.baidu.com 219.235.3.16 bbs.htmlman.net 202.165.102.243 download.rising.com.cn 202.165.102.243 rsup08.rising.com.cn 219.235.3.16 10000.286er.com 219.235.3.16 im286.net 219.235.3.16 ju.qihoo.com 219.235.3.16 bbs.chinaz.com 219.235.3.16 www.qihoo.com 202.165.102.243 dnl-cn1.kaspersky-labs.com 202.165.102.243 dnl-cn2.kaspersky-labs.com 202.165.102.243 dnl-cn3.kaspersky-labs.com 202.165.102.243 dnl-cn4.kaspersky-labs.com 202.165.102.243 dnl-cn5.kaspersky-labs.com 202.165.102.243 dnl-cn6.kaspersky-labs.com 202.165.102.243 dnl-cn7.kaspersky-labs.com 202.165.102.243 dnl-cn8.kaspersky-labs.com 202.165.102.243 dnl-cn9.kaspersky-labs.com 202.165.102.243 dnl-cn10.kaspersky-labs.com 202.165.102.243 dnl-cn11.kaspersky-labs.com 202.165.102.243 dnl-cn12.kaspersky-labs.com 202.165.102.243 dnl-cn13.kaspersky-labs.com 202.165.102.243 dnl-cn14.kaspersky-labs.com 202.165.102.243 dnl-cn15.kaspersky-labs.com 202.165.102.243 dnl-eu1.kaspersky-labs.com 202.165.102.243 dnl-eu2.kaspersky-labs.com 202.165.102.243 dnl-eu3.kaspersky-labs.com 202.165.102.243 dnl-eu4.kaspersky-labs.com 202.165.102.243 dnl-eu5.kaspersky-labs.com 202.165.102.243 dnl-eu6.kaspersky-labs.com 202.165.102.243 dnl-eu7.kaspersky-labs.com 202.165.102.243 dnl-eu8.kaspersky-labs.com 202.165.102.243 dnl-eu9.kaspersky-labs.com 202.165.102.243 dnl-eu10.kaspersky-labs.com 202.165.102.243 dnl-eu11.kaspersky-labs.com 202.165.102.243 dnl-eu12.kaspersky-labs.com 202.165.102.243 dnl-eu13.kaspersky-labs.com 202.165.102.243 dnl-eu14.kaspersky-labs.com 202.165.102.243 dnl-eu15.kaspersky-labs.com 202.165.102.243 dnl-us1.kaspersky-labs.com 202.165.102.243 dnl-us2.kaspersky-labs.com 202.165.102.243 dnl-us3.kaspersky-labs.com 202.165.102.243 dnl-us4.kaspersky-labs.com 202.165.102.243 dnl-us5.kaspersky-labs.com 202.165.102.243 dnl-us6.kaspersky-labs.com 202.165.102.243 dnl-us7.kaspersky-labs.com 202.165.102.243 dnl-us8.kaspersky-labs.com 202.165.102.243 dnl-us9.kaspersky-labs.com 202.165.102.243 dnl-us10.kaspersky-labs.com 202.165.102.243 dnl-us11.kaspersky-labs.com 202.165.102.243 dnl-us12.kaspersky-labs.com 202.165.102.243 dnl-us13.kaspersky-labs.com 202.165.102.243 dnl-us14.kaspersky-labs.com 202.165.102.243 dnl-us15.kaspersky-labs.com 202.165.102.243 dnl-ru1.kaspersky-labs.com 202.165.102.243 dnl-ru2.kaspersky-labs.com 202.165.102.243 dnl-ru3.kaspersky-labs.com 202.165.102.243 dnl-ru4.kaspersky-labs.com 202.165.102.243 dnl-ru5.kaspersky-labs.com 202.165.102.243 dnl-ru6.kaspersky-labs.com 202.165.102.243 dnl-ru7.kaspersky-labs.com 202.165.102.243 dnl-ru8.kaspersky-labs.com 202.165.102.243 dnl-ru9.kaspersky-labs.com 202.165.102.243 dnl-ru10.kaspersky-labs.com 202.165.102.243 dnl-ru11.kaspersky-labs.com 202.165.102.243 dnl-ru12.kaspersky-labs.com 202.165.102.243 dnl-ru13.kaspersky-labs.com 202.165.102.243 dnl-ru14.kaspersky-labs.com 202.165.102.243 dnl-ru15.kaspersky-labs.com 202.165.102.243 dnl-jp1.kaspersky-labs.com 202.165.102.243 dnl-jp2.kaspersky-labs.com 202.165.102.243 dnl-jp3.kaspersky-labs.com 202.165.102.243 dnl-jp4.kaspersky-labs.com 202.165.102.243 dnl-jp5.kaspersky-labs.com 202.165.102.243 dnl-jp6.kaspersky-labs.com 202.165.102.243 dnl-jp7.kaspersky-labs.com 202.165.102.243 dnl-jp8.kaspersky-labs.com 202.165.102.243 dnl-jp9.kaspersky-labs.com 202.165.102.243 dnl-jp10.kaspersky-labs.com 202.165.102.243 dnl-jp11.kaspersky-labs.com 202.165.102.243 dnl-jp12.kaspersky-labs.com 202.165.102.243 dnl-jp13.kaspersky-labs.com 202.165.102.243 dnl-jp14.kaspersky-labs.com 202.165.102.243 dnl-jp15.kaspersky-labs.com 202.165.102.243 dnl-kr1.kaspersky-labs.com 202.165.102.243 dnl-kr2.kaspersky-labs.com 202.165.102.243 dnl-kr3.kaspersky-labs.com 202.165.102.243 dnl-kr4.kaspersky-labs.com 202.165.102.243 dnl-kr5.kaspersky-labs.com 202.165.102.243 dnl-kr6.kaspersky-labs.com 202.165.102.243 dnl-kr7.kaspersky-labs.com 202.165.102.243 dnl-kr8.kaspersky-labs.com 202.165.102.243 dnl-kr9.kaspersky-labs.com 202.165.102.243 dnl-kr10.kaspersky-labs.com 202.165.102.243 dnl-kr11.kaspersky-labs.com 202.165.102.243 dnl-kr12.kaspersky-labs.com 202.165.102.243 dnl-kr13.kaspersky-labs.com 202.165.102.243 dnl-kr14.kaspersky-labs.com 202.165.102.243 dnl-kr15.kaspersky-labs.com 202.165.102.243 dnl-cd1.kaspersky-labs.com 202.165.102.243 dnl-cd2.kaspersky-labs.com 202.165.102.243 dnl-cd3.kaspersky-labs.com 202.165.102.243 dnl-cd4.kaspersky-labs.com 202.165.102.243 dnl-cd5.kaspersky-labs.com 202.165.102.243 dnl-cd6.kaspersky-labs.com 202.165.102.243 dnl-cd7.kaspersky-labs.com 202.165.102.243 dnl-cd8.kaspersky-labs.com 202.165.102.243 dnl-cd9.kaspersky-labs.com 202.165.102.243 dnl-cd10.kaspersky-labs.com 202.165.102.243 dnl-cd11.kaspersky-labs.com 202.165.102.243 dnl-cd12.kaspersky-labs.com 202.165.102.243 dnl-cd13.kaspersky-labs.com 202.165.102.243 dnl-cd14.kaspersky-labs.com 202.165.102.243 dnl-cd15.kaspersky-labs.com 202.165.102.243 downloads1.kaspersky-labs.com 202.165.102.243 downloads2.kaspersky-labs.com 202.165.102.243 downloads3.kaspersky-labs.com 202.165.102.243 downloads4.kaspersky-labs.com 202.165.102.243 downloads5.kaspersky-labs.com 219.235.3.16 rss.360safe.com 219.235.3.16 x.360safe.com 219.235.3.16 d.360safe.com 219.235.3.16 updatem.360safe.com 219.235.3.16 softm.360safe.com 219.235.3.16 ishare.sina.com.cn 219.235.3.16 search.cn.yahoo.com 219.235.3.16 www.google.com 219.235.3.16 google.com 219.235.3.16 www.google.cn 219.235.3.16 www.yahoo.com.cn 219.235.3.16 cn.yahoo.com 219.235.3.16 search.tom.com 219.235.3.16 zhuansha.duba.net 219.235.3.16 buy.duba.net 219.235.3.16 kad.www.duba.net 219.235.3.16 cu001.www.duba.net 219.235.3.16 cu002.www.duba.net 219.235.3.16 cu003.www.duba.net 219.235.3.16 cu004.www.duba.net 219.235.3.16 cu005.www.duba.net 219.235.3.16 cu010.www.duba.net 219.235.3.16 client.download.duba.net 219.235.3.16 page.so.163.com 219.235.3.16 www.soso.com 219.235.3.16 sou.china.com 219.235.3.16 test.591jx.com 219.235.3.16 a.topxxxx.cn 219.235.3.16 picon.chinaren.com 219.235.3.16 www.5566.net 127.0.0.1 p.qqkx.com 127.0.0.1 news.netandtv.com 127.0.0.1 z.neter888.cn 127.0.0.1 b.myblank.cn 127.0.0.1 wvw.wokutu.com 127.0.0.1 unionch.qyule.com 127.0.0.1 www.qyule.com 127.0.0.1 it.itjc.cn 127.0.0.1 www.linkwww.com 127.0.0.1 vod.kaicn.com 127.0.0.1 www.tx8688.com 127.0.0.1 b.neter888.cn 127.0.0.1 promote.huanqiu.com 127.0.0.1 www.huanqiu.com 127.0.0.1 www.haokanla.com 127.0.0.1 play.unionsky.cn 127.0.0.1 www.52v.com 127.0.0.1 www.gghka.cn 127.0.0.1 icon.ajiang.net 127.0.0.1 new.ete.cn 127.0.0.1 www.stiae.cn 127.0.0.1 o.neter888.cn 127.0.0.1 comm.jinti.com 127.0.0.1 www.google-analytics.com 127.0.0.1 hz.mmstat.com 127.0.0.1 www.game175.cn 127.0.0.1 x.neter888.cn 127.0.0.1 z.neter888.cn 127.0.0.1 p.etimes888.com 127.0.0.1 hx.etimes888.com 127.0.0.1 abc.qqkx.com 127.0.0.1 dm.popdm.cn 127.0.0.1 www.yl9999.com 127.0.0.1 www.dajiadoushe.cn 127.0.0.1 down.nihao29.cn 127.0.0.1 v.onondown.com.cn 127.0.0.1 www.interoo.net 127.0.0.1 bally1.bally-bally.net 127.0.0.1 www.bao5605509.cn 127.0.0.1 down.nihao29.cn 127.0.0.1 www.mzd020.cn 127.0.0.1 jzm015.cn 127.0.0.1 down.hs7yue.cn 127.0.0.1 new.doups.cn 127.0.0.1 w.qq-uc.cn 127.0.0.1 down.nihao69.cn 127.0.0.1 www.rty456.cn 127.0.0.1 www.werqwer.cn 127.0.0.1 1.360-1.cn 127.0.0.1 5.360-5.cn 127.0.0.1 user1.23-16.net 127.0.0.1 user1.23-18.net 127.0.0.1 www.guccia.net 127.0.0.1 www.interoo.net 127.0.0.1 upa.netsool.net 127.0.0.1 pua.lianxiac.net 127.0.0.1 js.users.51.la 127.0.0.1 vip2.51.la 127.0.0.1 web.51.la 127.0.0.1 qq.gong2008.com 127.0.0.1 2008tl.copyip.com 127.0.0.1 tla.laozihuolaile.cn 127.0.0.1 www.tx6868.cn 127.0.0.1 p001.tiloaiai.com 127.0.0.1 s1.tl8tl.com 127.0.0.1 s1.gong2008.com 127.0.0.1 mm1.laozihuolaile.cn 127.0.0.1 mm2.laozihuolaile.cn 127.0.0.1 tlbm2.laozihuolaile.cn 127.0.0.1 tlbm3.laozihuolaile.cn 127.0.0.1 www.6161q1.cn 127.0.0.1 www.6161q2.cn 127.0.0.1 www.6161h1.cn 127.0.0.1 www.6161h2.cn ================================== 进程特权扫描 特殊特权被允许: SeDebugPrivilege [PID = 3496, C:\PROGRAM FILES\WINRAR\WINRAR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3496, C:\PROGRAM FILES\WINRAR\WINRAR.EXE] 特殊特权被允许: SeDebugPrivilege [PID = 3516, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RAR$EX00.032\SRENGLDR.EXE] 特殊特权被允许: SeLoadDriverPrivilege [PID = 3516, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RAR$EX00.032\SRENGLDR.EXE] ================================== API HOOK N/A ================================== 隐藏进程 N/A ================================== [/CODE]