==================================
正在运行的进程
[PID: 520][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 600][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 624][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 668][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 680][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 828][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 896][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 992][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\windows\system32\ftvhb.dll] [Microsoft Corporation, 5.1.2600.0]
[PID: 1032][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1156][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1400][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1560][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.0.0.86]
[C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] [Autodesk, 16.0.0.86]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\winform.dll] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\Kvsc3.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Gjzo0.dll] [N/A, ]
[C:\Program Files\Media Player Classic\Codecs\mmfinfo.dll] [N/A, ]
[C:\Program Files\Media Player Classic\Codecs\mkunicode.dll] [N/A, ]
[C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 8.0.0.0]
[C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CHS] [Adobe Systems, Inc., 8.0.0.0]
[C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.10.7181]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\PROGRA~1\COMMON~1\viypdc\wgqxfb.nls] [, 3, 6, 0, 8]
[c:\progra~1\umof\hzbs.dll] [, 1, 0, 0, 6]
[c:\progra~1\umof\megx.dll] [ , 1, 0, 0, 6]
[PID: 1780][C:\Program Files\Common Files\system\Updaterun.exe] [N/A, ]
[PID: 1796][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\progra~1\umof\hzbs.dll] [, 1, 0, 0, 6]
[c:\progra~1\umof\megx.dll] [ , 1, 0, 0, 6]
[C:\PROGRA~1\COMMON~1\viypdc\wgqxfb.nls] [, 3, 6, 0, 8]
[PID: 984][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ac.dll] [ , 1, 0, 0, 3]
[c:\progra~1\umof\hzbs.dll] [, 1, 0, 0, 6]
[c:\progra~1\umof\megx.dll] [ , 1, 0, 0, 6]
[C:\PROGRA~1\COMMON~1\viypdc\wgqxfb.nls] [, 3, 6, 0, 8]
[PID: 500][D:\Program Files\Maxthon\Maxthon.exe] [MY Soft Technology, 1, 2, 4, 18]
[D:\Program Files\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
[c:\progra~1\umof\hzbs.dll] [, 1, 0, 0, 6]
[c:\progra~1\umof\megx.dll] [ , 1, 0, 0, 6]
[C:\PROGRA~1\COMMON~1\viypdc\wgqxfb.nls] [, 3, 6, 0, 8]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.0.0.86]
[C:\WINDOWS\system32\odbcbcp.dll] [Microsoft Corporation, 2000.085.1117.00 (xpsp_sp2_rtm.040803-2158)]
[D:\Program Files\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Gjzo0.dll] [N/A, ]
[C:\WINDOWS\system32\Kvsc3.dll] [N/A, ]
[C:\WINDOWS\system32\winform.dll] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 176][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\COMMON~1\viypdc\wgqxfb.nls] [, 3, 6, 0, 8]
[c:\progra~1\umof\hzbs.dll] [, 1, 0, 0, 6]
[c:\progra~1\umof\megx.dll] [ , 1, 0, 0, 6]
[PID: 3760][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sreng2(1).zip 的临时目录 1\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[c:\progra~1\umof\hzbs.dll] [, 1, 0, 0, 6]
[c:\progra~1\umof\megx.dll] [ , 1, 0, 0, 6]
[C:\PROGRA~1\COMMON~1\viypdc\wgqxfb.nls] [, 3, 6, 0, 8]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Gjzo0.dll] [N/A, ]
[C:\WINDOWS\system32\Kvsc3.dll] [N/A, ]
[C:\WINDOWS\system32\winform.dll] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 popwin.9983.com
61.152.169.246 www.kuaiso.com
61.152.169.246 www.my6688.cn
61.152.169.246 www.union123.com
61.152.169.246 www.ktan.cn
61.152.169.246 www.2t2t.cn
61.152.169.246 www.cq530.com
61.152.169.246 www.365tc.com
61.152.169.246 ad.qucha.net
61.152.169.246 www.tan8.cn
61.152.169.246 www.itjj.net
61.152.169.246 www.start188.com
61.152.169.246 www.at58.cn
61.152.169.246 union.yxad.com
61.152.169.246 www.iptan.com
61.152.169.246 www.ip2008.net
61.152.169.246 www.yqif.com
61.152.169.246 www.2t2t.cn
61.152.169.246 www.17tan8.com
61.152.169.246 17tan8.com
61.152.169.246 www.688ip.com
61.152.169.246 www.17tc.com
61.152.169.246 www.zztan.com
61.152.169.246 www.5tanip.com
61.152.169.246 www.16tc.com
61.152.169.246 www.163se.net
61.152.169.246 www.724tc.com
61.152.169.246 www1.6tan.com
61.152.169.246 www2.6tan.com
61.152.169.246 www.6tan.com
61.152.169.246 quxiuu.com
61.152.169.246 www.quxiuu.com
61.152.169.246 www.23b.cn
61.152.169.246 www.ookkw.com
61.152.169.246 www.97725.com
61.152.169.246 down.97725.com
61.152.169.246 www.54699.com
61.152.169.246 web.77276.com
61.152.169.246 www.77276.com
61.152.169.246 d.77276.com
61.152.169.246 do.77276.com
61.152.169.246 i.96981.com
61.152.169.246 wm.103715.com
61.152.169.246 www.138505.com
61.152.169.246 cool.47555.com
61.152.169.246 www.437799.com
61.152.169.246 www.168080.com
61.152.169.246 w.168080.com
61.152.169.246 q.168080.com
61.152.169.246 www.baidu8.org
61.152.169.246 d.qbbd.com
61.152.169.246 w.qbbd.com
61.152.169.246 www.npjxjy.com
61.152.169.246 www.wwwlm.net
61.152.169.246 new2.jixie123.cn
61.152.169.246 www.18dmm.com
61.152.169.246 www.souxse.cn
61.152.169.246 dm1.yiall.com
61.152.169.246 www.nze21.com
61.152.169.246 www.puma163.com
61.152.169.246 www.hyap98.com
61.152.169.246 www.51liulan.cn
61.152.169.246 s.gcuj.com
61.152.169.246 long.down988.cn
61.152.169.246 x.vvcyin.com
61.152.169.246 w.vvcyin.com
61.152.169.246 cc.wzxqy.com
61.152.169.246 ip.315hack.com
61.152.169.246 ip.54liumang.com
61.152.169.246 www.41ip.com
61.152.169.246 xulao.com
61.152.169.246 www.xulao.com
61.152.169.246 www.heixiou.com
61.152.169.246 www.9cyy.com
61.152.169.246 adnx.yygou.cn
61.152.169.246 www1.cw988.cn
61.152.169.246 www2.cw988.cn
61.152.169.246 www.asdwc.com
61.152.169.246 ceoww.com
61.152.169.246 boolom.com
61.152.169.246 www.boolom.com
61.152.169.246 www.tellumore.com
61.152.169.246 www.o1wg.com
61.152.169.246 www.qq756.com
61.152.169.246 ll.chinasese.net
61.152.169.246 www.cnwangmeng.cn
61.152.169.246 0.82211.net
61.152.169.246 rising.whatthishome.com
61.152.169.246 www.canqiou.com
61.152.169.246 www.if56.cn
61.152.169.246 woai777.com
61.152.169.246 www.cz-kc.com
61.152.169.246 www.f1ash8.net
61.152.169.246 new.hackpp.com
61.152.169.246 ad.taoip.cn
61.152.169.246 www.game53.com
61.152.169.246 up.boolom.com
61.152.169.246 t.gcuj.com
61.152.169.246 w.zpx520.com
61.152.169.246 www.08325.cn
61.152.169.246 d.fangni.net
61.152.169.246 psxiaokan1.mei7.com
61.152.169.246 jd.54liumang.com
61.152.169.246 www.ipvip.info
61.152.169.246 www.tao168188.com
61.152.169.246 ww.qqzheng.cn
61.152.169.246 mmm.021mm8.com
61.152.169.246 www.urlad.cn
61.152.169.246 www.810810.org
61.152.169.246 my.pkgame8.com
61.152.169.246 www.chunliao.net
61.152.169.246 www.89622.com
61.152.169.246 at2.810810.org
61.152.169.246 www.qq.goto.60ad.cn
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]