[F:\下载\RISING\RAV\scriptci.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[F:\下载\RISING\RAV\ur001.dat] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[F:\下载\RISING\RAV\uroutine.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26]
[F:\下载\RISING\RAV\ur023.dat] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 1]
[F:\下载\RISING\RAV\extmail.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9]
[PID: 1488 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[PID: 1944 / SYSTEM][F:\下载\RISING\RAV\RavStub.exe] [Beijing Rising Technology Co., Ltd., 20.0.0.9]
[F:\下载\RISING\RAV\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[F:\下载\RISING\RAV\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[F:\下载\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[PID: 252 / SYSTEM][C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe] [Ulead Systems, Inc., 1, 0, 0, 4]
[PID: 300 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[PID: 1292 / Administrator][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[C:\WINDOWS\system32\UNISPIM6.IME] [北京紫光华宇软件股份有限公司, 6.1.0.6223]
[PID: 1304 / Administrator][C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe] [Microsoft Corporation, 8.5.1302.1018]
[C:\Program Files\Windows Live\Messenger\MSNCore.dll] [Microsoft Corporation, 8.5.1302.1018]
[C:\Program Files\Windows Live\Messenger\msidcrl40.dll] [Microsoft Corporation, 4.100.313.1]
[C:\Program Files\Windows Live\Messenger\ContactsUX.dll] [Microsoft Corporation, 8.5.1302.1018]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[C:\Program Files\Windows Live\Messenger\msgslang.8.5.1302.1018.dll] [Microsoft Corporation, 8.5.1302.1018]
[C:\Program Files\Windows Live\Messenger\msgsres.dll] [Microsoft Corporation, 8.5.1302.1018]
[C:\WINDOWS\system32\UNISPIM6.IME] [北京紫光华宇软件股份有限公司, 6.1.0.6223]
[C:\Program Files\Windows Live\Messenger\MSGSWCAM.dll] [Microsoft Corporation, 8.5.1302.1018]
[C:\WINDOWS\system32\sirenacm.dll] [Microsoft Corporation, 8.5.1302.1018]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\Program Files\Windows Live\Messenger\lmcdata.dll] [Microsoft Corporation, 8.5.1302.1018]
[C:\Program Files\Windows Live\Messenger\abssm.dll] [Microsoft Corporation, 8.5.1302.1018]
[C:\Program Files\Windows Live\Messenger\custsat.dll] [Microsoft Corporation, 9.0.3790.2428 (srv03_sp1_qfe.050422-1043)]
[F:\下载\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[PID: 116 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[PID: 1260 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\RtkBtMnt.EXE] [Realtek Semiconductor Corp., 1.0.0.4]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[C:\WINDOWS\system32\UNISPIM6.IME] [北京紫光华宇软件股份有限公司, 6.1.0.6223]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2492 / Administrator][E:\QQGAME\Accel.exe] [深圳市腾讯计算机系统有限公司, 2, 0, 103, 5]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[C:\WINDOWS\system32\MAPI32.dll] [Microsoft Corporation, 1.0.2536.0 (XPClient.010817-1148)]
[C:\WINDOWS\system32\UNISPIM6.IME] [北京紫光华宇软件股份有限公司, 6.1.0.6223]
[E:\QQGAME\Common\Utility.dll] [N/A, ]
[E:\QQGAME\Tenio\TenFact.dll] [Tencent, 07.1.01.001]
[E:\QQGAME\Tenio\TenHall.dll] [Tencent, 07.1.01.001]
[PID: 976 / Administrator][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[C:\WINDOWS\system32\UNISPIM6.IME] [北京紫光华宇软件股份有限公司, 6.1.0.6223]
[PID: 2852 / Administrator][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[C:\WINDOWS\system32\UNISPIM6.IME] [北京紫光华宇软件股份有限公司, 6.1.0.6223]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[F:\下载\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29]
[F:\下载\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96]
[F:\下载\Thunder\Components\ResWorker\DsBho_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20]
[F:\下载\Thunder\Components\ResWorker\DataProcessor_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
[F:\下载\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.17]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[F:\下载\AVG Anti-Spyware 7.5\context.dll] [GRISOFT s.r.o., 7, 5, 1, 36]
[C:\WINDOWS\system32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
[PID: 1900 / Administrator][F:\方正证券\fzwmb.exe] [上海核新软件技术有限公司, 2007, 3, 16, 0]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[F:\方正证券\RICHED20.dll] [Microsoft Corporation, 5.30.23.1205]
[C:\WINDOWS\system32\UNISPIM6.IME] [北京紫光华宇软件股份有限公司, 6.1.0.6223]
[PID: 3240 / Administrator][F:\方正证券\zxt.exe] [上海核新软件技术有限公司, 2006, 10, 16, 1]
[F:\方正证券\sqlite30.dll] [上海核新软件技术有限公司, 2005, 5, 12, 0]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[F:\方正证券\RICHEDTW.DLL] [Microsoft Corporation, 5.00.2134.1]
[F:\方正证券\RICHED20.dll] [Microsoft Corporation, 5.30.23.1205]
[C:\WINDOWS\system32\UNISPIM6.IME] [北京紫光华宇软件股份有限公司, 6.1.0.6223]
[PID: 3980 / Administrator][F:\方正证券\zdsj.exe] [上海核新软件技术有限公司, 2007, 3, 16, 0]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[F:\方正证券\RICHED20.dll] [Microsoft Corporation, 5.30.23.1205]
[C:\WINDOWS\system32\UNISPIM6.IME] [北京紫光华宇软件股份有限公司, 6.1.0.6223]
[PID: 1904 / Administrator][F:\下载\遨游\Maxthon2\Maxthon.exe] [Maxthon International ltd., 2, 1, 0, 2082]
[F:\下载\遨游\Maxthon2\mxpp.dll] [Maxthon International ltd., 1, 0, 0, 107]
[F:\下载\遨游\Maxthon2\MxSk.dll] [Maxthon, 1, 0, 0, 351]
[F:\下载\遨游\Maxthon2\MxProxy2.dll] [Maxthon International ltd., 1, 0, 0, 4030]
[F:\下载\遨游\Maxthon2\MxExt.dll] [N/A, ]
[F:\下载\遨游\Maxthon2\MxUI.dll] [Maxthon International, 3, 2, 2, 16]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[C:\WINDOWS\system32\UNISPIM6.IME] [北京紫光华宇软件股份有限公司, 6.1.0.6223]
[PID: 2184 / Administrator][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[C:\WINDOWS\system32\UNISPIM6.IME] [北京紫光华宇软件股份有限公司, 6.1.0.6223]
[PID: 1920 / Administrator][F:\下载\qq2008\QQ.exe] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\QQBaseClassInDll.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\QQHelperDll.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\BasicCtrlDll.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\MFC42.DLL] [Microsoft Corporation, 6.00.8665.0]
[F:\下载\qq2008\MSIMG32.dll] [N/A, ]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[C:\WINDOWS\system32\UNISPIM6.IME] [北京紫光华宇软件股份有限公司, 6.1.0.6223]
[F:\下载\qq2008\gdiplus.dll] [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
[F:\下载\qq2008\彩虹QQ\CaiHong.dll] [N/A, ]
[F:\下载\qq2008\彩虹QQ\Reporter.dll] [N/A, ]
[F:\下载\qq2008\RICHED32.DLL] [Microsoft Corporation, 5.00.2134.1]
[F:\下载\qq2008\RICHED20.dll] [Microsoft Corporation, 5.31.23.1218]
[F:\下载\qq2008\QQAPI.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\LoginCtrl.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\LoginCtrlRes.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\QQRes.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\WizardCtrl.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\QQMainFrame.dll] [N/A, ]
[F:\下载\qq2008\QQPlugin.dll] [N/A, ]
[F:\下载\qq2008\UnReadMsgMgr.dll] [N/A, ]
[F:\下载\qq2008\CQQApplication.dll] [N/A, ]
[F:\下载\qq2008\FlashAvatarDll.dll] [, 1, 4, 0, 1]
[F:\下载\qq2008\NewSkin.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\MailSummary.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\vbscript.dll] [Microsoft Corporation, 5.6.0.7426]
[F:\下载\qq2008\QQAllInOne.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\SCCore.dll] [TENCENT, 1, 6, 0, 2]
[F:\下载\qq2008\CameraDll.dll] [TENCENT, 8,0,776,1805]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[F:\下载\qq2008\OEMApplication.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\QQKnowledgeSearch.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\QQGroupMng.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\QQPet.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\QQSpace.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\UserDefinedHead.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\QQConfigPlugin.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\QQCustomFace.dll] [N/A, ]
[F:\下载\qq2008\LongConnection.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\QRingMng.dll] [N/A, ]
[F:\下载\qq2008\QQSysMsgMng.dll] [N/A, ]
[F:\下载\qq2008\QQLiveQMng.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\QQAvatar.dll] [N/A, ]
[F:\下载\qq2008\PhoneAPI.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\DialerAllinOne.dll] [tencent, 1, 4, 0, 0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[F:\下载\qq2008\GroupConnection.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\BQQApplication.dll] [N/A, ]
[F:\下载\qq2008\ImageOle.dll] [TENCENT, 8,0,776,1805]
[F:\下载\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0]
[F:\下载\qq2008\QQMagicFace.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\QQSceneMng.dll] [N/A, ]
[F:\下载\qq2008\CommercesMng.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\PersonalDesktop.dll] [TENCENT, 8,0,776,1805]
[F:\下载\qq2008\QQAddr.dll] [深圳市腾讯计算机系统有限公司, 5, 0, 101, 330]
[F:\下载\qq2008\AddrSearch.dll] [腾讯科技(深圳)有限公司, 2, 2, 1, 15]
[PID: 236 / Administrator][F:\下载\遨游\Maxthon2\Maxthon.exe] [Maxthon International ltd., 2, 1, 0, 2082]
[F:\下载\遨游\Maxthon2\mxpp.dll] [Maxthon International ltd., 1, 0, 0, 107]
[F:\下载\遨游\Maxthon2\MxSk.dll] [Maxthon, 1, 0, 0, 351]
[F:\下载\遨游\Maxthon2\MxProxy2.dll] [Maxthon International ltd., 1, 0, 0, 4030]
[F:\下载\遨游\Maxthon2\MxExt.dll] [N/A, ]
[F:\下载\遨游\Maxthon2\MxUI.dll] [Maxthon International, 3, 2, 2, 16]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[C:\WINDOWS\system32\UNISPIM6.IME] [北京紫光华宇软件股份有限公司, 6.1.0.6223]
[F:\下载\遨游\Maxthon2\mxtool.dll] [, 1, 0, 0, 1]
[F:\下载\遨游\Maxthon2\maxzlib.dll] [, 1.2.3]
[F:\下载\遨游\Maxthon2\mxfeedU.dll] [, 1, 0, 45, 92]
[F:\下载\遨游\Maxthon2\Modules\MxWebBoost\MxWebBoost.dll] [Maxthon, 1,0,2,1187]
[F:\下载\遨游\Maxthon2\mxdb.dll] [Max, 3, 5, 3, 125]
[F:\下载\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[F:\下载\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96]
[C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx] [Adobe Systems, Inc., 9,0,124,0]
[PID: 3128 / Administrator][F:\下载\Rising\Rav\RavMon.exe] [Beijing Rising Technology Co., Ltd., 20.0.01.19]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[F:\下载\Rising\Rav\ProcCom.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[F:\下载\Rising\Rav\RsCommX2.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
[F:\下载\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[F:\下载\Rising\Rav\recomp.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 39]
[F:\下载\Rising\Rav\refs.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 17]
[F:\下载\Rising\Rav\viruslib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 26]
[F:\下载\Rising\Rav\relibldr.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[F:\下载\Rising\Rav\RSAPPMGR.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.0]
[F:\下载\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.16]
[F:\下载\Rising\Rav\MonRule.dll] [Beijing Rising Technology Co., Ltd., 20.0.0.29]
[F:\下载\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4]
[C:\WINDOWS\system32\UNISPIM6.IME] [北京紫光华宇软件股份有限公司, 6.1.0.6223]
[F:\下载\Rising\Rav\Rsguilib.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 89]
[F:\下载\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0]
[PID: 3620 / Administrator][F:\下载\程序\系统日志\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\WINDOWS\system32\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 18]
[C:\WINDOWS\system32\UNISPIM6.IME] [北京紫光华宇软件股份有限公司, 6.1.0.6223]
[F:\下载\程序\系统日志\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
0.0.0.0 182838.com
0.0.0.0 204.177.92.68
0.0.0.0 asiafriendfinder.com
0.0.0.0 asqin123.51.net
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
0.0.0.0
www.jpbeauty.com0.0.0.0 beautishow.com
0.0.0.0 goodmovies88.com
0.0.0.0 hothack.home.chinaren.com
0.0.0.0 hualiao.net
0.0.0.0 iplus.allyes.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 asqin123.51.net
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
219.153.32.215 auto.search.msn.com
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1260, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\RTKBTMNT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1900, F:\方正证券\FZWMB.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3240, F:\方正证券\ZXT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3980, F:\方正证券\ZDSJ.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1904, F:\下载\遨游\MAXTHON2\MAXTHON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1904, F:\下载\遨游\MAXTHON2\MAXTHON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 236, F:\下载\遨游\MAXTHON2\MAXTHON.EXE]
==================================
API HOOK
入口点错误:NtCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003C42B5)
入口点错误:NtWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003C4355)
入口点错误:ZwCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003C42B5)
入口点错误:ZwWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003C4355)
==================================
隐藏进程
N/A
==================================
[/CODE]