12   1  /  2  页   跳转

【关于9505流氓站】附双日志

【关于9505流氓站】附双日志

现在我的电脑问题:第一IE被锁定为9505  第二 我的输入法出了问题只能用微软自带的拼音输入2003 智能ABC 和其他的都用不了. 第三 我的桌面上莫名其妙出了 2个网页激情美女图片和新开亚洲传奇.
以下是日志:
HijackThis_zww汉化版扫描日志 V1.99.1
保存于      13:42:59, 日期 2006-10-4
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NrSvr.exe
C:\Program Files\Apache2\bin\Apache.exe
C:\WINDOWS\system32\Com\SERVICES.EXE
d:\Grandsoft\GrandDog\GrandDog\RockeyServer.exe
C:\WINDOWS\system32\Rundll32.exe
c:\program files\rising\rfw\RfwMain.exe
d:\Grandsoft\施工项目管理系统\GCM3\Tool\GDaemon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apache2\bin\Apache.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\alexa.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NrSvr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Rising\Rav\Ravmon.exe
D:\Grandsoft\施工项目管理系统\GCM3\Tool\DataSend.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
F:\日志\HijackThis1991zww.exe
最后编辑2006-10-04 14:45:45
分享到:
gototop
 

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O1 - Hosts: 219.139.58.97 www.hao123.com
O1 - Hosts: 219.139.58.97 hao123.com
O1 - Hosts: 219.139.58.97 www.7b.com.cn
O1 - Hosts: 219.139.58.97 7b.com.cn
O1 - Hosts: 219.139.58.97 www.7939.com
O1 - Hosts: 219.139.58.97 7939.com
O1 - Hosts: 219.139.58.97 www.maohehe.com
O1 - Hosts: 219.139.58.97 maohehe.com
O1 - Hosts: 219.139.58.97 www.sina-baidu.com
O1 - Hosts: 219.139.58.97 sina-baidu.com
O1 - Hosts: 219.139.58.97 60.191.60.107
O1 - Hosts: 219.139.58.97 www.maipao.com
O1 - Hosts: 219.139.58.97 maipao.com
O1 - Hosts: 219.139.58.97 update.virussky.com
O1 - Hosts: 219.139.58.97 down.virussky.com
O1 - Hosts: 219.139.58.97 219.139.58.97
O1 - Hosts: 219.139.58.97 59.34.148.81
O1 - Hosts: 219.139.58.97 60.191.60.114
O1 - Hosts: 219.139.58.97 www.ycdy.com
O1 - Hosts: 219.139.58.97 ycdy.com
O1 - Hosts: 219.139.58.97 www.2tu.cn
O1 - Hosts: 219.139.58.97 2tu.cn
O1 - Hosts: 219.139.58.97 www.91tu.cn
O1 - Hosts: 219.139.58.97 91tu.cn
O1 - Hosts: 219.139.58.97 www.haotop.com
O2 - BHO: DuDu.com - {00018593-C6BD-46F7-9349-DBA1AA674C90} - E:\卡丁车\dddiemon.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: XBTP08912 - {3F53F529-A79A-4d89-883A-3B628608C170} - C:\PROGRA~1\ADOBEF~1.0\tbu09651\toolbar.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: ltmenu Class - {78C21EFD-53BA-406C-AF1A-33A38ABD3958} - C:\Program Files\LtUcx\1002\c0.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\CnsHook.dll
O2 - BHO: Shockwave Flash Object - {DE8C8BF0-4A16-12DD-CBBD-789569C11983} - C:\WINDOWS\system32\FL23D5~1.DLL
O2 - BHO: XBTP01967 - {F3E19DD9-6D5B-4867-A057-1EFFFC62322E} - C:\DOCUME~1\yan\LOCALS~1\Temp\tbu39\Toolbar.dll
O3 - IE工具栏增项: TT33定向搜索 - {D940F380-49C7-4A05-9E33-53930AF5768F} - C:\DOCUME~1\yan\LOCALS~1\Temp\tbu39\Toolbar.dll
O3 - IE工具栏增项: Adobe Flash player 9.0 - {FB8A3D63-87AE-480C-BC6F-B28D720D5D62} - C:\Program Files\Adobe Flash player 9.0\tbu09651\toolbar.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [FTSafeNetRockeyService4.0] C:\WINDOWS\system32\NrSvr.exe -systray
O4 - 启动项HKLM\\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - 启动项HKLM\\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - 启动项HKLM\\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [GCMSendData] D:\Grandsoft\施工项目管理系统\GCM3\Tool\DataSend.exe
O4 - 启动项HKLM\\Run: [rundll32] rundll32 rscfg.dll s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: AutoCAD 启动加速器.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O8 - IE右键菜单中的新增项目: &使用DuDu下载 - res://E:\卡丁车\dddmext.dll/202
O8 - IE右键菜单中的新增项目: &使用DuDu下载全部链接 - res://E:\卡丁车\dddmext.dll/203
O8 - IE右键菜单中的新增项目: &使用DuDu下载选择链接 - res://E:\卡丁车\dddmext.dll/204
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - 浏览器额外的按钮: (no name) - {0062C9BD-B349-40DE-91A0-755F37ACD559} - (no file)
O9 - 浏览器额外的按钮: Yahoo 3.5G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - 浏览器额外的按钮: 名品折扣 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/mall/pro.php?allyesPara=816 (file missing)
O9 - 浏览器额外的按钮: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - 浏览器额外的按钮: 雅虎WIDGET - {6354ABE6-05F1-49ed-B850-E423120EC338} - http://cn.widget.yahoo.com/index.htm?source=Cns (file missing)
O9 - 浏览器额外的按钮: 视频聊天 - {6924091F-CD97-41E1-B1D4-D9079409D413} - http://www.liantang.net (file missing)
O9 - 浏览器额外的“工具”菜单项: 视频聊天 - {6924091F-CD97-41E1-B1D4-D9079409D413} - http://www.liantang.net (file missing)
O9 - 浏览器额外的按钮: 寻论网--中学作业解答 - {6924091F-CD97-41E1-B1D4-D9079409D423} - http://www.xunlun.com (file missing)
O9 - 浏览器额外的“工具”菜单项: 中学作业 - {6924091F-CD97-41E1-B1D4-D9079409D423} - http://www.xunlun.com (file missing)
O9 - 浏览器额外的按钮: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - 浏览器额外的按钮: 讯通视频语音聊天 - {97C0CDFA-970D-4222-ADDE-6718E89E887C} - http://www.bdsystem.com/ (file missing)
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg (file missing)
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - 浏览器额外的“工具”菜单项: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - 浏览器额外的“工具”菜单项: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O11 - Options group: [!CNS]  中文上网
O15 - “受信任的站点”中添加项: http://www.icbc.com.cn
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - NT 服务: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - NT 服务: FTSafe Net Rockey Service (FTSafeNetRockeyService4.0) - Feitian Technologies Co.,Ltd. - C:\WINDOWS\system32\NrSvr.exe
O23 - NT 服务: GCMApache - Unknown owner - C:\Program Files\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - NT 服务: GCMRockeyServer - 北京广联达慧中软件技术有限公司 - d:\Grandsoft\GrandDog\GrandDog\RockeyServer.exe
O23 - NT 服务: GCSDaemon - 北京广联达慧中软件技术有限公司 - d:\Grandsoft\施工项目管理系统\GCM3\Tool\GDaemon.exe
O23 - NT 服务: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - NT 服务: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - NT 服务: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - NT 服务: Windows信息服务管理 - Unknown owner - C:\WINDOWS\Scen.ini
gototop
 

另一个日志
2006-10-04,13:44:28

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <wow><C:\WINDOWS\system32\Launcher.exe>  [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <FTSafeNetRockeyService4.0><C:\WINDOWS\system32\NrSvr.exe -systray>  [Feitian Technologies Co.,Ltd.]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <SoundMan><SOUNDMAN.EXE>  [(Verified)Realtek Semiconductor Corp.]
    <RemoteControl><"C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe">  [Cyberlink Corp.]
    <InCD><C:\Program Files\Ahead\InCD\InCD.exe>  [Nero AG]
    <NeroFilterCheck><C:\WINDOWS\system32\NeroCheck.exe>  [Ahead Software Gmbh]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot>  [RealNetworks, Inc.]
    <GCMSendData><D:\Grandsoft\施工项目管理系统\GCM3\Tool\DataSend.exe>  [北京广联达慧中软件技术有限公司]
    <rundll32><rundll32 rscfg.dll s>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\Userinit.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
    <{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINDOWS\downlo~1\CnsHook.dll>  [北京三七二一科技有限公司]
    <{6E44887F-5214-41F2-AB46-4728735C4CC6}><C:\Program Files\Internet Explorer\PLUGINS\system3.sys>  [N/A]
    <{9A0CFC58-5A6F-41ba-9FFE-4320F4F62FB1}><C:\WINDOWS\system32\cnscheck100.dll>  [N/A]
    <{9A0CFC58-5A6F-41ba-9FFE-4320F4F62F1A}><C:\WINDOWS\system32\cnscheck010.dll>  [N/A]
    <{9A0CFC58-5A6F-41ba-9FFE-4320F4F621BA}><C:\WINDOWS\system32\cnscheck001.dll>  [N/A]

==================================
启动文件夹
[Utility Tray]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Utility Tray.lnk --> C:\WINDOWS\system32\sistray.exe [Silicon Integrated Systems Corporation]><N>
[AutoCAD 启动加速器]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\AutoCAD 启动加速器.lnk --> C:\PROGRA~1\COMMON~1\AUTODE~1\ACSTAR~1.EXE [Autodesk, Inc]><N>

==================================
服务
[AdsWinIe / AdsWinIe]
  <C:\WINDOWS\system32\AdsWin.exe -service><Microsoft Corporation>
[ASP.NET State Service / aspnet_state]
  <C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Autodesk Licensing Service / Autodesk Licensing Service]
  <"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><Autodesk>
[FTSafe Net Rockey Service / FTSafeNetRockeyService4.0]
  <C:\WINDOWS\system32\NrSvr.exe -dispatch><Feitian Technologies Co.,Ltd.>
[GCMApache / GCMApache]
  <"C:\Program Files\Apache2\bin\Apache.exe" -k runservice><Apache Software Foundation>
[GCMRockeyServer / GCMRockeyServer]
  <d:\Grandsoft\GrandDog\GrandDog\RockeyServer.exe><北京广联达慧中软件技术有限公司>
[GCSDaemon / GCSDaemon]
  <d:\Grandsoft\施工项目管理系统\GCM3\Tool\GDaemon.exe><北京广联达慧中软件技术有限公司>
[Human Interface Device Access / HidServ]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InCD Helper / InCDsrv]
  <C:\Program Files\Ahead\InCD\InCDsrv.exe><Nero AG>
[LexBce Server / LexBceS]
  <C:\WINDOWS\system32\LEXBCES.EXE><Lexmark International, Inc.>
[MSSQLSERVER / MSSQLSERVER]
  <C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe -sMSSQLSERVER><Microsoft Corporation>
[MSSQLServerADHelper / MSSQLServerADHelper]
  <C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe><Microsoft Corporation>
[PopWinIe / PopWinIe]
  <C:\WINDOWS\system32\PopWin.exe -service><Microsoft Corporation>
[Rising Proxy  Service / RfwProxySrv]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[SQLSERVERAGENT / SQLSERVERAGENT]
  <C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE -i MSSQLSERVER><Microsoft Corporation>
[Windows信息服务管理 / Windows信息服务管理]
  <C:\WINDOWS\Scen.ini><N/A>
gototop
 

驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[Rising TDI Base Driver / BaseTDI]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[CnsMinKP / CnsMinKP]
  <\SystemRoot\system32\drivers\CnsMinKP.sys><Copyright (C) 3721 Corporation.>
[EagleNT / EagleNT]
  <\??\C:\WINDOWS\system32\drivers\EagleNT.sys><N/A>
[ExpScaner / ExpScaner]
  <\??\C:\Program Files\Rising\Rav\ExpScan.sys><>
[HookCont / HookCont]
  <\??\C:\Program Files\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg]
  <\??\C:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys]
  <\??\C:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookUrl / HookUrl]
  <\??\C:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[InCD File System / InCDfs]
  <C:\WINDOWS\SYSTEM32\DRIVERS\InCDfs.SYS><Nero AG>
[InCDPass / InCDPass]
  <System32\DRIVERS\InCDPass.sys><Nero AG>
[InCD Reader / incdrm]
  <C:\WINDOWS\SYSTEM32\DRIVERS\incdrm.SYS><Nero AG>
[MEMSCAN / MEMSCAN]
  <\??\C:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[mProcRs / mProcRs]
  <\??\c:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[Netgroup Packet Filter / NPF]
  <system32\drivers\npf.sys><N/A>
[npkcrypt / npkcrypt]
  <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><N/A>
[oreans32 / oreans32]
  <\??\C:\WINDOWS\system32\drivers\oreans32.sys><N/A>
[Direct Parallel Link Driver / Ptilink]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[R2A / R2A]
  <\??\C:\WINDOWS\system32a2.sys><N/A>
[Feitian ROCKEY4 Device Service / ROCKEYNT]
  <system32\DRIVERS\Rockey4.sys><Feitian Technologies Co., Ltd.>
[Feitian ROCKEY4 USB Service / Rockey_USB]
  <system32\DRIVERS\Rockey4USB.sys><Feitian Technologies Co., Ltd.>
[RsFwDrv / RsFwDrv]
  <\??\C:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv]
  <system32\DRIVERS\secdrv.sys><N/A>
[SiS315 / SiS315]
  <system32\DRIVERS\sisgrp.sys><Silicon Integrated Systems Corporation>
[SiSide / SiSide]
  <\SystemRoot\system32\DRIVERS\siside.sys><Silicon Integrated Systems Corp.>
[sisidex / sisidex]
  <\SystemRoot\system32\drivers\sisidex.sys><Windows (R) 2000 DDK provider>
[SiSkp / SiSkp]
  <system32\DRIVERS\srvkp.sys><Silicon Integrated Systems Corporation>
[Add Performance Filter Driver / sisperf]
  <\SystemRoot\system32\drivers\sisperf.sys><Silicon Integrated Systems Corp.>
gototop
 

浏览器加载项
[dddmont Class]
  {00018593-C6BD-46F7-9349-DBA1AA674C90} <E:\卡丁车\dddiemon.dll, N/A>
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx, >
[XBTP08912 Class]
  {3F53F529-A79A-4d89-883A-3B628608C170} <C:\PROGRA~1\ADOBEF~1.0\tbu09651\toolbar.dll, IE Toolbar>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[ltmenu Class]
  {78C21EFD-53BA-406C-AF1A-33A38ABD3958} <C:\Program Files\LtUcx\1002\c0.dll, 北京莲塘软件技术有限公司>
[CnsHook Class]
  {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\downlo~1\CnsHook.dll, 北京三七二一科技有限公司>
[Shockwave Flash Object]
  {DE8C8BF0-4A16-12DD-CBBD-789569C11983} <C:\WINDOWS\system32\FL23D5~1.DLL, Macromedia,Inc.>
[XBTP01967 Class]
  {F3E19DD9-6D5B-4867-A057-1EFFFC62322E} <C:\DOCUME~1\yan\LOCALS~1\Temp\tbu39\Toolbar.dll, IE Toolbar>
[Yahoo 3.5G电邮]
  {507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A>
[名品折扣]
  {59BC54A2-56B3-44a0-93E5-432D58746E26} <http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/mall/pro.php?allyesPara=816, N/A>
[雅虎助手]
  {5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A>
[雅虎WIDGET]
  {6354ABE6-05F1-49ed-B850-E423120EC338} <http://cn.widget.yahoo.com/index.htm?source=Cns, N/A>
[视频聊天]
  {6924091F-CD97-41E1-B1D4-D9079409D413} <http://www.liantang.net, N/A>
[寻论网--中学作业解答]
  {6924091F-CD97-41E1-B1D4-D9079409D423} <http://www.xunlun.com, N/A>
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[讯通视频语音聊天]
  {97C0CDFA-970D-4222-ADDE-6718E89E887C} <http://www.bdsystem.com/, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[情景聊天]
  {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg, N/A>
[]
  {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[]
  {FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A>
[TT33定向搜索]
  {D940F380-49C7-4A05-9E33-53930AF5768F} <C:\DOCUME~1\yan\LOCALS~1\Temp\tbu39\Toolbar.dll, IE Toolbar>
[Adobe Flash player 9.0]
  {FB8A3D63-87AE-480C-BC6F-B28D720D5D62} <C:\Program Files\Adobe Flash player 9.0\tbu09651\toolbar.dll, IE Toolbar>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[dddmont Class]
  {00018593-C6BD-46F7-9349-DBA1AA674C90} <E:\卡丁车\dddiemon.dll, N/A>
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx, >
[XBTP08912 Class]
  {3F53F529-A79A-4D89-883A-3B628608C170} <C:\PROGRA~1\ADOBEF~1.0\tbu09651\toolbar.dll, IE Toolbar>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[ltmenu Class]
  {78C21EFD-53BA-406C-AF1A-33A38ABD3958} <C:\Program Files\LtUcx\1002\c0.dll, 北京莲塘软件技术有限公司>
[CnsHook Class]
  {D157330A-9EF3-49F8-9A67-4141AC41ADD4} <C:\WINDOWS\downlo~1\CnsHook.dll, 北京三七二一科技有限公司>
[Shockwave Flash Object]
  {DE8C8BF0-4A16-12DD-CBBD-789569C11983} <C:\WINDOWS\system32\FL23D5~1.DLL, Macromedia,Inc.>
[XBTP01967 Class]
  {F3E19DD9-6D5B-4867-A057-1EFFFC62322E} <C:\DOCUME~1\yan\LOCALS~1\Temp\tbu39\Toolbar.dll, IE Toolbar>
[&使用DuDu下载]
  <res://E:\卡丁车\dddmext.dll/202, N/A>
[&使用DuDu下载全部链接]
  <res://E:\卡丁车\dddmext.dll/203, N/A>
[&使用DuDu下载选择链接]
  <res://E:\卡丁车\dddmext.dll/204, N/A>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A
gototop
 

正在运行的进程
[PID: 560][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 628][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 652][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 696][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 708][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 856][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 900][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 968][C:\Program Files\Rising\Rav\CCenter.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 988][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1008][C:\Program Files\Ahead\InCD\InCDsrv.exe]  [Nero AG, 4, 3, 18, 0]
    [C:\Program Files\Common Files\Ahead\Lib\DriveLocker.dll]  [Ahead Software AG, 1, 0, 0, 17]
    [C:\Program Files\Ahead\InCD\incdshx.dll]  [Nero AG, 4, 3, 18, 0]
[PID: 1168][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1260][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1280][C:\Program Files\Rising\Rav\Ravmond.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 1, 35]
    [C:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 19]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Rising\Rav\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [C:\Program Files\Rising\Rav\HOOKSYS.dll]  [Beijing Rising Technology Co., Ltd., 18, 1, 0, 11]
    [C:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 32]
    [C:\Program Files\Rising\Rav\libload.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
    [C:\Program Files\Rising\Rav\VirusLib.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
    [C:\Program Files\Rising\Rav\regmon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
    [C:\Program Files\Rising\Rav\HookWeb.dll]  [rising, 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\MemMon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
    [C:\Program Files\Rising\Rav\expscan.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Rising\Rav\mPorts.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
    [C:\Program Files\Rising\Rav\MailMon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\Program Files\Rising\Rav\SpamEng.dll]  [N/A, 18, 0, 0, 6]
    [C:\Program Files\Rising\Rav\engine.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 34]
    [C:\Program Files\Rising\Rav\PostTrt.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 16]
    [C:\Program Files\Rising\Rav\UnExe.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
    [C:\Program Files\Rising\Rav\ScanExec.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
    [C:\Program Files\Rising\Rav\ScanEx.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 27]
    [C:\Program Files\Rising\Rav\RSUnpack.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 17]
    [C:\Program Files\Rising\Rav\NvFile.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 7]
    [C:\Program Files\Rising\Rav\ScanMac.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
    [C:\Program Files\Rising\Rav\ScanSct.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 19]
    [C:\Program Files\Rising\Rav\Unpacker.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\Program Files\Rising\Rav\ScanNet.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\Program Files\Rising\Rav\RsStore.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
[PID: 1348][c:\program files\rising\rfw\rfwsrv.exe]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 33]
    [c:\program files\rising\rfw\RfwRule.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 13]
    [c:\program files\rising\rfw\rfwlog.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 6]
    [c:\program files\rising\rfw\Rfwdrv.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 21]
    [c:\program files\rising\rfw\MonDrv.dll]  [rs, 1, 0, 0, 4]
    [c:\program files\rising\rfw\ProcLib.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 9]
[PID: 1440][C:\WINDOWS\system32\LEXBCES.EXE]  [Lexmark International, Inc., 9.42]
    [C:\WINDOWS\system32\lexp2p32.dll]  [Lexmark International, Inc., 9.42]
    [C:\WINDOWS\system32\lex2kusb.dll]  [Lexmark International, Inc., 9.42]
[PID: 1484][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\LEXLMPM.DLL]  [Lexmark International, Inc., 96.9.42]
    [C:\WINDOWS\system32\LexBce.dll]  [Lexmark International, Inc., 9.42]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\LVCOPP5C.dll]  [Lenovo (Beijing) Ltd., 1.0.1.4]
    [C:\WINDOWS\system32\LVCOpwr.dll]  [Lenovo (Beijing) Ltd., 1, 0, 1, 0]
gototop
 

[PID: 1492][C:\WINDOWS\system32\LEXPPS.EXE]  [Lexmark International, Inc., 9.42]
    [C:\WINDOWS\system32\LEXBCE.DLL]  [Lexmark International, Inc., 9.42]
[PID: 1580][C:\Program Files\Rising\Rav\RavStub.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 16]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 1948][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 16.2.54.0]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
    [C:\WINDOWS\downlo~1\CnsHook.dll]  [北京三七二一科技有限公司, 1, 0, 3, 1]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  [Autodesk, 16.2.54.0]
    [C:\WINDOWS\system32\mywow.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\rscfg.dll]  [N/A, N/A]
    [C:\Program Files\Ahead\InCD\incdshx.dll]  [Nero AG, 4, 3, 18, 0]
    [C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx]  [, 1, 0, 0, 1]
    [C:\Program Files\LtUcx\1002\c0.dll]  [北京莲塘软件技术有限公司, 1, 8, 0, 60]
    [C:\Program Files\LtUcx\ucx0.dll]  [北京莲塘软件技术有限公司, 1, 0, 3, 21]
[PID: 112][C:\WINDOWS\system32\NrSvr.exe]  [Feitian Technologies Co.,Ltd., 1, 0, 10, 1813]
[PID: 228][C:\Program Files\Apache2\bin\Apache.exe]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\bin\libapr.dll]  [Apache Software Foundation, 0.9.7]
    [C:\Program Files\Apache2\bin\libaprutil.dll]  [Apache Software Foundation, 0.9.7]
    [C:\Program Files\Apache2\bin\libapriconv.dll]  [Apache Software Foundation, 0.9.7]
    [C:\Program Files\Apache2\bin\libhttpd.dll]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_access.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_actions.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_alias.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_asis.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_auth.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_autoindex.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_cgi.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_dir.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_env.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_imap.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_include.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_isapi.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_log_config.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_mime.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_negotiation.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_setenvif.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_userdir.so]  [Apache Software Foundation, 2.0.55]
    [C:\WINDOWS\system32\pwsServerProxy.dll]  [N/A, N/A]
[PID: 252][C:\WINDOWS\system32\Com\SERVICES.EXE]  [N/A, N/A]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\WINDOWS\system32\rscfg.dll]  [N/A, N/A]
[PID: 280][d:\Grandsoft\GrandDog\GrandDog\RockeyServer.exe]  [北京广联达慧中软件技术有限公司, 3.5.2.502]
[PID: 292][C:\WINDOWS\system32\Rundll32.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\WINDOWS\downlo~1\CnsMinIO.dll]  [北京三七二一科技有限公司, 1, 0, 3, 7]
    [C:\WINDOWS\downlo~1\cnsio.dll]  [北京三七二一科技有限公司, 1, 0, 2, 8]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
[PID: 312][c:\program files\rising\rfw\RfwMain.exe]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 52]
    [c:\program files\rising\rfw\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 23]
    [c:\program files\rising\rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [c:\program files\rising\rfw\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\WINDOWS\system32\rscfg.dll]  [N/A, N/A]
gototop
 

[PID: 388][d:\Grandsoft\施工项目管理系统\GCM3\Tool\GDaemon.exe]  [北京广联达慧中软件技术有限公司, 3.5.2.502]
    [C:\WINDOWS\system32\midas.dll]  [Borland Software Corporation, 7.0.4.453]
[PID: 492][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  [Microsoft Corporation, 7.00.9466]
[PID: 616][C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe]  [Microsoft Corporation, 2000.080.0194.00]
[PID: 612][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
[PID: 816][C:\Program Files\Apache2\bin\Apache.exe]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\bin\libapr.dll]  [Apache Software Foundation, 0.9.7]
    [C:\Program Files\Apache2\bin\libaprutil.dll]  [Apache Software Foundation, 0.9.7]
    [C:\Program Files\Apache2\bin\libapriconv.dll]  [Apache Software Foundation, 0.9.7]
    [C:\Program Files\Apache2\bin\libhttpd.dll]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_access.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_actions.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_alias.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_asis.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_auth.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_autoindex.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_cgi.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_dir.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_env.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_imap.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_include.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_isapi.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_log_config.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_mime.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_negotiation.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_setenvif.so]  [Apache Software Foundation, 2.0.55]
    [C:\Program Files\Apache2\modules\mod_userdir.so]  [Apache Software Foundation, 2.0.55]
    [C:\WINDOWS\system32\pwsServerProxy.dll]  [N/A, N/A]
[PID: 3324][C:\WINDOWS\system32\dllhost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3568][C:\WINDOWS\system32\msdtc.exe]  [Microsoft Corporation, 2001.12.4414.258]
[PID: 3680][C:\WINDOWS\system32\wscntfy.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\rscfg.dll]  [N/A, N/A]
[PID: 3708][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3924][C:\WINDOWS\system32\alexa.exe]  [N/A, N/A]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\DOCUME~1\yan\LOCALS~1\Temp\nsq4.tmp\InstallOptions.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
[PID: 176][C:\WINDOWS\system32\wuauclt.exe]  [Microsoft Corporation, 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3772][C:\WINDOWS\system32\NrSvr.exe]  [Feitian Technologies Co.,Ltd., 1, 0, 10, 1813]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\rscfg.dll]  [N/A, N/A]
[PID: 3248][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.40]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\WINDOWS\system32\rscfg.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
[PID: 3232][C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe]  [Cyberlink Corp., 6.00.1027]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\Program Files\CyberLink DVD Solution\PowerDVD\CLRCEngine2.dll]  [CyberLink Corp., 3.2.2021 ]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
[PID: 3852][C:\Program Files\Ahead\InCD\InCD.exe]  [Nero AG, 4, 3, 18, 0]
    [C:\Program Files\Ahead\InCD\InCdApi.dll]  [Nero AG, 4, 3, 18, 0]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\Program Files\Common Files\Ahead\Lib\DriveLocker.dll]  [Ahead Software AG, 1, 0, 0, 17]
    [C:\Program Files\Ahead\InCD\incdshx.dll]  [Nero AG, 4, 3, 18, 0]
    [C:\WINDOWS\system32\rscfg.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
[PID: 3004][C:\Program Files\Rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 22]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
gototop
 

[PID: 3016][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.1622]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
[PID: 232][C:\Program Files\Rising\Rav\Ravmon.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 1, 33]
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 26]
    [C:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 19]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\rscfg.dll]  [N/A, N/A]
[PID: 3076][D:\Grandsoft\施工项目管理系统\GCM3\Tool\DataSend.exe]  [北京广联达慧中软件技术有限公司, 3.5.2.502]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\WINDOWS\system32\rscfg.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\midas.dll]  [Borland Software Corporation, 7.0.4.453]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
[PID: 3972][C:\Program Files\Messenger\msmsgs.exe]  [Microsoft Corporation, 4.7.3000]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\WINDOWS\system32\rscfg.dll]  [N/A, N/A]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
[PID: 380][C:\WINDOWS\system32\sistray.exe]  [Silicon Integrated Systems Corporation, 0.0.0.3740]
    [C:\WINDOWS\system32\SiSApCom.dll]  [Silicon Integrated Systems Corporation, 0.0.0.3740]
    [C:\WINDOWS\system32\SiSBase.dll]  [Silicon Integrated Systems Corporation, 6.14.10.3740]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\WINDOWS\system32\rscfg.dll]  [N/A, N/A]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
[PID: 4796][C:\Program Files\Rising\Rav\RsAgent.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\WINDOWS\system32\rscfg.dll]  [N/A, N/A]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
[PID: 4816][C:\WINDOWS\msagent\AgentSvr.exe]  [Microsoft Corporation, 2.00.0.3422]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\WINDOWS\system32\rscfg.dll]  [N/A, N/A]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
[PID: 5396][E:\杀毒工具\sreng2\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
    [C:\WINDOWS\downlo~1\CnsMin.dll]  [北京三七二一科技有限公司, 1, 5, 3, 9]
    [C:\WINDOWS\system32\rscfg.dll]  [N/A, N/A]
    [C:\Program Files\Internet Explorer\PLUGINS\system3.sys]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck001.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck010.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\cnscheck100.dll]  [N/A, N/A]
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost
219.139.58.97  www.hao123.com
219.139.58.97  hao123.com
219.139.58.97  www.7b.com.cn
219.139.58.97  7b.com.cn
219.139.58.97  www.7939.com
219.139.58.97  7939.com
219.139.58.97  www.maohehe.com
219.139.58.97  maohehe.com
219.139.58.97  www.sina-baidu.com
219.139.58.97  sina-baidu.com
219.139.58.97  60.191.60.107
219.139.58.97  www.maipao.com
219.139.58.97  maipao.com
219.139.58.97  update.virussky.com
219.139.58.97  down.virussky.com
219.139.58.97  219.139.58.97
219.139.58.97  59.34.148.81
219.139.58.97  60.191.60.114
219.139.58.97  www.ycdy.com
219.139.58.97  ycdy.com
219.139.58.97  www.2tu.cn
219.139.58.97  2tu.cn
219.139.58.97  www.91tu.cn
219.139.58.97  91tu.cn
219.139.58.97  www.haotop.com

==================================
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT