瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 好像是新出的病毒~楼主老人家帮忙看下!!!

12   1  /  2  页   跳转

好像是新出的病毒~楼主老人家帮忙看下!!!

好像是新出的病毒~楼主老人家帮忙看下!!!

启动项删不了  一删从起后还会有
iexpl0re.exe  winlog0n  还有一个alga.exe
也没什么症状 就是有时候声音自己就莫名其妙的自己变成静音了
郁闷ing  试了好多专杀都不行
瑞星也没杀出来
大侠帮忙看下是中病毒了 还是别的什么东西
有图:

附件附件:

下载次数:270
文件类型:application/octet-stream
文件大小:
上传时间:2007-1-16 20:19:04
描述:



最后编辑2007-01-16 21:00:48
分享到:
gototop
 

请下载SREng2(最新版) ,使用“智能扫描”,按下“扫描”按钮进行扫描,
扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告
日志文件内容复制-粘贴上来,,日志一次粘不完,分次粘完,请不要修改。

下载地址
http://www.kztechs.com/sreng/sreng2.zip
gototop
 

[CODE]

2007-01-16,20:16:59

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <MSPY2002><C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC>  [(Verified)N/A]
    <Soltek><C:\WINDOWS\system32\autorun.exe>  [N/A]
    <SoundMan><SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
    <dl_accel><C:\Program Files\3721\Dlaccel\YDownloader.exe>  [北京三七二一科技有限公司]
    <Anti-Spy Tools><G:\Program Files\ast\ast.exe -min>  [DSW Lab]
    <7w><C:\WINDOWS\iexpl0re.exe>  [N/A]
    <RfwMain><"g:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <RavTask><"g:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\System32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]

==================================
启动文件夹
[河南网通宽带用户客户端]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\河南网通宽带用户客户端.lnk --> C:\PROGRA~1\RACER-~1\racer.exe [Putian Runway]><N>

==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  <g:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
  <g:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Win32 Display Driver / Win32DDS][Stopped/Auto Start]
  <C:\WINDOWS\system32\\rundll32.exe windds32.dll,start><Microsoft Corporation>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"g:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon][Running/Auto Start]
  <"g:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>

==================================
驱动程序
[Service for WDM 3D Audio Driver / ALCXSENS][Running/Manual Start]
  <system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[AliIde / AliIde][Stopped/Boot Start]
  <\SystemRoot\System32\DRIVERS\aliide.sys><N/A>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[CmdIde / CmdIde][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[HookUrl / HookUrl][Running/Auto Start]
  <\??\g:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
[kcmcme / kcmcme][Stopped/Boot Start]
  <\SystemRoot\\SystemRoot\System32\drivers\kcmcme.sys><N/A>
[MegaIDE / MegaIDE][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\MegaIDE.sys><LSI Logic Corporation.>
[mProcRs / mProcRs][Running/Auto Start]
  <\??\g:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
[NetGroup Packet Filter Driver / NPF][Running/Manual Start]
  <system32\drivers\npf.sys><Politecnico di Torino>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsFwDrv / RsFwDrv][Running/Auto Start]
  <\??\g:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[ViaIde / ViaIde][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[WINIO / WINIO][Stopped/Manual Start]
  <\??\H:\DRIVER\Audio\winio.sys><N/A>
[XPROTECTOR / XPROTECTOR][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\Xprotector.sys><N/A>
[RSPPSYS / RSPPSYS][Running/Auto Start]
  <\??\g:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[ExpScaner / ExpScaner][Running/Auto Start]
  <\??\g:\Program Files\Rising\Rav\ExpScan.sys><>
[HookCont / HookCont][Running/Auto Start]
  <\??\g:\Program Files\Rising\Rav\HOOKCONT.sys><Rising>
[HookSys / HookSys][Running/Auto Start]
  <\??\g:\Program Files\Rising\Rav\HookSys.sys><Rising>
[HookReg / HookReg][Running/Auto Start]
  <\??\g:\Program Files\Rising\Rav\HookReg.sys><>
[MEMSCAN / MEMSCAN][Running/Auto Start]
  <\??\g:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[RsNTGDI / RsNTGDI][Stopped/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>

==================================
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v6.dll, >
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v6.dll, >
[卡卡上网安全助手]
  {AFF6E516-CBE5-4F8A-9C2F-38A68013E766} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[WMHlprObj Class]
  {F5824EFB-728A-4726-A5A5-85A68B20EDC3} <C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll, N/A>
[&使用下载加速专家下载]
  <C:\Program Files\3721\Dlaccel\geturl.htm, N/A>
[上传到QQ网络硬盘]
  <G:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
  <G:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <G:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <G:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
gototop
 

正在运行的进程
[PID: 428][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 484][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 508][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 552][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 564][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 712][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 756][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 824][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 920][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 956][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1192][g:\program files\rising\rfw\rfwsrv.exe]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 30]
    [g:\program files\rising\rfw\RfwRule.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 3]
    [g:\program files\rising\rfw\rfwlog.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 2]
    [g:\program files\rising\rfw\Rfwdrv.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 10]
    [g:\program files\rising\rfw\MonDrv.dll]  [rs, 1, 0, 0, 4]
    [g:\program files\rising\rfw\ProcLib.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 5]
    [g:\program files\rising\rfw\mPorts.dll]  [Beijing Rising Technology Co., Ltd., 4, 0, 0, 3]
[PID: 1336][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1528][g:\program files\rising\rfw\RfwMain.exe]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 70]
    [g:\program files\rising\rfw\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 31]
    [g:\program files\rising\rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [g:\program files\rising\rfw\RfwCtrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [g:\program files\rising\rfw\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [g:\program files\rising\rfw\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\WINDOWS\system32\LgSym.dll]  [N/A, N/A]
[PID: 236][g:\Program Files\Rising\Rav\CCenter.exe]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 384][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 480][C:\WINDOWS\system32\wscntfy.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 816][g:\Program Files\Rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
    [g:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [g:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [g:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [g:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
[PID: 1080][g:\Program Files\Rising\Rav\RavMon.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
    [g:\Program Files\Rising\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
    [g:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [g:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [g:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [g:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [g:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [g:\Program Files\Rising\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [g:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\WINDOWS\system32\LgSym.dll]  [N/A, N/A]
[PID: 1072][g:\Program Files\Rising\Rav\Ravmond.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 43]
    [g:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [g:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [g:\Program Files\Rising\Rav\rfwctrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
    [g:\Program Files\Rising\Rav\RsPPsys.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
    [g:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [g:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [g:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [g:\Program Files\Rising\Rav\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [g:\Program Files\Rising\Rav\HOOKSYS.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 0]
    [g:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
    [g:\Program Files\Rising\Rav\libload.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [g:\Program Files\Rising\Rav\VirusLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [g:\Program Files\Rising\Rav\regmon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 6]
    [g:\Program Files\Rising\Rav\HookWeb.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 1]
    [g:\Program Files\Rising\Rav\MemMon.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
    [g:\Program Files\Rising\Rav\expscan.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [g:\Program Files\Rising\Rav\mPorts.dll]  [Beijing Rising
gototop
 

Technology Co., Ltd., 4, 0, 0, 3]
    [g:\Program Files\Rising\Rav\HookCont.dll]  [Rising, 19, 0, 0, 0]
    [g:\Program Files\Rising\Rav\SpamEng.dll]  [N/A, 18, 0, 0, 6]
    [g:\Program Files\Rising\Rav\engine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
    [g:\Program Files\Rising\Rav\PostTrt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
    [g:\Program Files\Rising\Rav\UnExe.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [g:\Program Files\Rising\Rav\ScanExec.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [g:\Program Files\Rising\Rav\ScanEx.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 34]
    [g:\Program Files\Rising\Rav\ExtFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 23]
    [g:\Program Files\Rising\Rav\NvFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
    [g:\Program Files\Rising\Rav\ScanMac.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
    [g:\Program Files\Rising\Rav\ScanSct.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [g:\Program Files\Rising\Rav\Unpacker.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
    [g:\Program Files\Rising\Rav\RsStore.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [g:\Program Files\Rising\Rav\ExtOLE.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[PID: 1428][g:\Program Files\Rising\Rav\RavStub.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
    [g:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [g:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1704][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.21]
[PID: 1100][C:\WINDOWS\iexpl0re.exe]  [N/A, N/A]
    [C:\WINDOWS\system32\LgSym.dll]  [N/A, N/A]
[PID: 1516][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1864][C:\Program Files\racer-henan-cnc\racer.exe]  [Putian Runway, 2, 0, 51, 92]
    [C:\Program Files\racer-henan-cnc\rwxre.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\nspr4.dll]  [Netscape Communications Corporation, 4.5 Beta]
    [C:\Program Files\racer-henan-cnc\xpcom.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\nss3.dll]  [Netscape Communications Corporation, 3.9.1]
    [C:\Program Files\racer-henan-cnc\softokn3.dll]  [Netscape Communications Corporation, 3.9.1]
    [C:\Program Files\racer-henan-cnc\gkgfx.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\js3250.dll]  [Netscape Communications Corporation, 4.0]
    [C:\Program Files\racer-henan-cnc\components\racer_base_comp.dll]  [Putian Runway, 2,0,47,87]
    [C:\Program Files\racer-henan-cnc\xpcom_compat.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\racer_base.dll]  [Putian Runway, 2,0,47,87]
    [C:\Program Files\racer-henan-cnc\components\pipnss.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\components\gklayout.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\components\jar50.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\components\xpcom_compat_c.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\components\racer_ad_comp.dll]  [Putian Runway, 2,0,47,87]
    [C:\WINDOWS\system32\LgSym.dll]  [N/A, N/A]
    [C:\Program Files\racer-henan-cnc\components\racer_access_dhcpplus.dll]  [Putian Runway, 2,0,47,87]
    [C:\Program Files\racer-henan-cnc\dhcpplus.dll]  [北京润汇科技有限公司, 0, 13, 21, 45]
    [C:\Program Files\racer-henan-cnc\components\racer_nss4_comp.dll]  [Putian Runway, 2,0,47,87]
    [C:\Program Files\racer-henan-cnc\nss4.dll]  [北京普天润汇科技有限公司, 1, 0, 0, 3]
    [C:\Program Files\racer-henan-cnc\wpcap.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\Program Files\racer-henan-cnc\pthreadVC.dll]  [N/A, N/A]
    [C:\Program Files\racer-henan-cnc\packet.dll]  [Politecnico di Torino, 3, 0, 0, 18]
[PID: 3108][C:\Program Files\racer-henan-cnc\RacerKp.exe]  [北京润汇科技有限公司, 1, 0, 0, 1]
[PID: 2324][g:\Program Files\Rising\Rav\Rav.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
    [g:\Program Files\Rising\Rav\PlugIn\RsPgScan.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 17]
    [g:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [g:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [g:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [g:\Program Files\Rising\Rav\RavUI.Dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 30]
    [g:\Program Files\Rising\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
    [g:\Program Files\Rising\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [g:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [g:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
    [g:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\WINDOWS\system32\LgSym.dll]  [N/A, N/A]
    [g:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [g:\Program Files\Rising\Rav\RsStore.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [g:\Program Files\Rising\Rav\RavQu.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [g:\Program Files\Rising\Rav\libload.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [g:\Program Files\Rising\Rav\VirusLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [g:\Program Files\Rising\Rav\MVEngine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
    [g:\Program Files\Rising\Rav\Engine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
    [g:\Program Files\Rising\Rav\ScanExec.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
    [g:\Program Files\Rising\Rav\Unpacker.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
    [g:\Program Files\Rising\Rav\UnExe.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [g:\Program Files\Rising\Rav\ScanEx.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 34]
    [g:\Program Files\Rising\Rav\ExtFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 23]
    [g:\Program Files\Rising\Rav\PostTrt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
    [g:\Program Files\Rising\Rav\ScanMac.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
    [g:\Program Files\Rising\Rav\ScanSct.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [g:\Program Files\Rising\Rav\ScanPack.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 18]
    [g:\Program Files\Rising\Rav\RsVM.dll]  [N/A, 19, 0, 0, 13]
    [g:\Program Files\Rising\Rav\Uroutine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [g:\Program Files\Rising\Rav\Uscript.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
    [g:\Program Files\Rising\Rav\NvFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
    [g:\Program Files\Rising\Rav\ExtMail.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
    [g:\Program Files\Rising\Rav\ExtOLE.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
    [g:\Program Files\Rising\Rav\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
    [g:\Program Files\Rising\Rav\ScanNet.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [g:\Program Files\Rising\Rav\ScanElf.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
    [g:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 2824][C:\WINDOWS\winlog0n.exe]  [N/A, N/A]
[PID: 900][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2072][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2132][C:\WINDOWS\explorer.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\kakatool.dll]  [Beijing Rising Technology Co., Ltd., 2, 0, 2, 6]
    [C:\WINDOWS\system32\LgSym.dll]  [N/A, N/A]
    [g:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [g:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\WINDOWS\system32\WINABCX.IME]  [PKUETI, 5.22.216]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
    [C:\WINDOWS\system32\xunleibho_v6.dll]  [, 4, 4, 0, 31]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
[PID: 3048][G:\Program Files\Tencent\QQ\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [G:\Program Files\Tencent\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [G:\Program Files\Tencent\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [G:\Program Files\Tencent\QQ\BasicCtrlDll.dll]  [Tencent, 6, 0, 200, 320]
    [G:\Program Files\Tencent\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
    [G:\Program Files\Tencent\QQ\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [G:\Program Files\Tencent\QQ\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [G:\Program Files\Tencent\QQ\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [G:\Program Files\Tencent\QQ\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [G:\Program Files\Tencent\QQ\QQMainFrame.dll]  [N/A, N/A]
    [G:\Program Files\Tencent\QQ\CQQApplication.dll]  [N/A, N/A]
    [G:\Program Files\Tencent\QQ\NewSkin.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\LgSym.dll]  [N/A, N/A]
    [G:\Program Files\Tencent\QQ\HostingMgr.dll]  [, 1, 0, 0, 1]
    [G:\Program Files\Tencent\QQ\CameraDll.dll]  [, 1, 0, 0, 1]
    [G:\Program Files\Tencent\QQ\MailSummary.dll]  [, 1, 0, 0, 1]
    [G:\Program Files\Tencent\QQ\QQKnowledgeSearch.dll]  [, 1, 0, 0, 1]
    [G:\Program Files\Tencent\QQ\QQAllInOne.dll]  [N/A, N/A]
    [G:\Program Files\Tencent\QQ\GroupLive.dll]  [N/A, N/A]
    [G:\Program Files\Tencent\QQ\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
    [G:\Program Files\Tencent\QQ\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
    [G:\Program Files\Tencent\QQ\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [G:\Program Files\Tencent\QQ\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [G:\Program Files\Tencent\QQ\QQPlugin.dll]  [N/A, N/A]
    [G:\Program Files\Tencent\QQ\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [G:\Program Files\Tencent\QQ\QRingMng.dll]  [N/A, N/A]
    [G:\Program Files\Tencent\QQ\QQAvatar.dll]  [N/A, N/A]
    [G:\Program Files\Tencent\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [G:\Program Files\Tencent\QQ\LongConnection.dll]  [tencent, 5, 0, 200, 160]
gototop
 

[G:\Program Files\Tencent\QQ\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [G:\Program Files\Tencent\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [G:\Program Files\Tencent\QQ\QQPet.dll]  [, 1, 0, 0, 1]
    [G:\Program Files\Tencent\QQ\QQCustomFace.dll]  [N/A, N/A]
    [G:\Program Files\Tencent\QQ\QQSysMsgMng.dll]  [N/A, N/A]
    [G:\Program Files\Tencent\QQ\QQSettingCtrl.dll]  [, 1, 0, 0, 1]
    [G:\Program Files\Tencent\QQ\BQQApplication.dll]  [N/A, N/A]
    [G:\Program Files\Tencent\QQ\CommercesMng.dll]  [, 1, 0, 0, 1]
    [G:\Program Files\Tencent\QQ\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [G:\Program Files\Tencent\QQ\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 271]
    [G:\Program Files\Tencent\QQ\QQSceneMng.dll]  [N/A, N/A]
    [G:\Program Files\Tencent\QQ\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 3, 30]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [G:\Program Files\Tencent\QQ\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [G:\Program Files\Tencent\QQ\GroupConnection.dll]  [Tencent, 0, 3, 3, 5]
[PID: 3624][C:\Program Files\3721\Dlaccel\YDownloader.exe]  [北京三七二一科技有限公司, 1, 2, 0, 7]
    [C:\Program Files\3721\Dlaccel\boost_thread-vc6-mt-1_31.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\LgSym.dll]  [N/A, N/A]
[PID: 3344][C:\Documents and Settings\Admin\桌面\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
    [C:\WINDOWS\system32\LgSym.dll]  [N/A, N/A]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1cool.47555.com
127.0.0.1www.dosboy.com
127.0.0.1guajfskajiw.43242.com
127.0.0.1www.3448.com
127.0.0.1pkdown.3322.org
127.0.0.1ddos2.sz45.com
127.0.0.1www.113678.com
127.0.0.1www.1861.sh
127.0.0.1www.x44.cn
127.0.0.1www.799789.com
127.0.0.1www.zhengdian.com
127.0.0.1www.9000music.com
127.0.0.1girlchinese.com
127.0.0.1www.yibinren.com
127.0.0.1www.mtv51.com
127.0.0.1www.163[1].com
127.0.0.1www.37021.com
127.0.0.1www.cnqb.net
127.0.0.1www.qq3344.com
127.0.0.1www.qq3344.net
127.0.0.1youlove.3322.net
127.0.0.1www.58589.com
127.0.0.1tty.yyun.net
127.0.0.1www.ftlink.net
127.0.0.1home.kimo.com.tw
127.0.0.1www.pixpox.com
127.0.0.1www.k163.com
127.0.0.1www.dj3344.com
127.0.0.1www.yysky.net
127.0.0.161.145.117.212
127.0.0.1ResponseMedia-ad.flycast.com
127.0.0.1Suissa-ad.flycast.com
127.0.0.1UGO.eu-adcenter.net
127.0.0.1VNU.eu-adcenter.net
127.0.0.1a32.g.a.yimg.com
127.0.0.1ad-adex3.flycast.com
127.0.0.1ad.adsmart.net
127.0.0.1ad.ca.doubleclick.net
127.0.0.1ad.de.doubleclick.net
127.0.0.1ad.doubleclick.net
127.0.0.1ad.fr.doubleclick.net
127.0.0.1ad.jp.doubleclick.net
127.0.0.1ad.linkexchange.com
127.0.0.1ad.linksynergy.com
127.0.0.1ad.nl.doubleclick.net
127.0.0.1ad.no.doubleclick.net
127.0.0.1ad.preferences.com
127.0.0.1ad.sma.punto.net
127.0.0.1ad.uk.doubleclick.net
127.0.0.1ad.webprovider.com
127.0.0.1ad08.focalink.com
127.0.0.1adcontroller.unicast.com
127.0.0.1adcreatives.imaginemedia.com
127.0.0.1adforce.ads.imgis.com
127.0.0.1adforce.imgis.com
127.0.0.1adfu.blockstackers.com
127.0.0.1adimage.blm.net
127.0.0.1adimages.earthweb.com
127.0.0.1adimg.egroups.com
127.0.0.1admedia.xoom.com
127.0.0.1adpick.switchboard.com
127.0.0.1adremote.pathfinder.com
127.0.0.1ads.admaximize.com
127.0.0.1ads.bfast.com
127.0.0.1ads.clickhouse.com
127.0.0.1ads.enliven.com
127.0.0.1ads.fairfax.com.au
127.0.0.1ads.fool.com
127.0.0.1ads.freshmeat.net
127.0.0.1ads.hollywood.com
127.0.0.1ads.i33.com
127.0.0.1ads.infi.net
127.0.0.1ads.jwtt3.com
127.0.0.1ads.link4ads.com
127.0.0.1ads.lycos.com
127.0.0.1ads.madison.com
127.0.0.1ads.mediaodyssey.com
127.0.0.1ads.msn.com
127.0.0.1ads.ninemsn.com.au
127.0.0.1ads.seattletimes.com
127.0.0.1ads.smartclicks.com
127.0.0.1ads.smartclicks.net
127.0.0.1ads.sptimes.com
127.0.0.1ads.tripod.com
127.0.0.1ads.web.aol.com
127.0.0.1ads.x10.com
127.0.0.1ads.xtra.co.nz
127.0.0.1ads.zdnet.com
127.0.0.1ads01.focalink.com
127.0.0.1ads02.focalink.com
127.0.0.1ads03.focalink.com
127.0.0.1ads04.focalink.com
127.0.0.1ads05.focalink.com
127.0.0.1ads06.focalink.com
127.0.0.1ads08.focalink.com
127.0.0.1ads09.focalink.com
127.0.0.1ads1.activeagent.at
127.0.0.1ads10.focalink.com
127.0.0.1ads11.focalink.com
127.0.0.1ads12.focalink.com
127.0.0.1ads14.focalink.com
127.0.0.1ads16.focalink.com
127.0.0.1ads17.focalink.com
127.0.0.1ads18.focalink.com
127.0.0.1ads19.focalink.com
127.0.0.1ads2.zdnet.com
127.0.0.1ads20.focalink.com
127.0.0.1ads21.focalink.com
127.0.0.1ads22.focalink.com
127.0.0.1ads23.focalink.com
127.0.0.1ads24.focalink.com
127.0.0.1ads25.focalink.com
127.0.0.1ads3.zdnet.com
127.0.0.1ads5.gamecity.net
127.0.0.1adserv.iafrica.com
127.0.0.1adserv.quality-channel.de
127.0.0.1adserver.dbusiness.com
127.0.0.1adserver.garden.com
127.0.0.1adserver.janes.com
127.0.0.1adserver.merc.com
127.0.0.1adserver.monster.com
127.0.0.1adserver.track-star.com
127.0.0.1adserver1.ogilvy-interactive.de
127.0.0.1adtegrity.spinbox.net
127.0.0.1antfarm-ad.flycast.com
127.0.0.1au.ads.link4ads.com
127.0.0.1banner.media-system.de
127.0.0.1banner.orb.net
127.0.0.1banner.relcom.ru
127.0.0.1banners.easydns.com
127.0.0.1banners.looksmart.com
127.0.0.1banners.wunderground.com
127.0.0.1barnesandnoble.bfast.com
127.0.0.1beseenad.looksmart.com
127.0.0.1bizad.nikkeibp.co.jp
127.0.0.1bn.bfast.com
gototop
 

127.0.0.1c3.xxxcounter.com
127.0.0.1califia.imaginemedia.com
127.0.0.1cds.mediaplex.com
127.0.0.1click.avenuea.com
127.0.0.1click.go2net.com
127.0.0.1click.linksynergy.com
127.0.0.1cookies.cmpnet.com
127.0.0.1cornflakes.pathfinder.com
127.0.0.1counter.hitbox.com
127.0.0.1crux.songline.com
127.0.0.1erie.smartage.com
127.0.0.1etad.telegraph.co.uk
127.0.0.1fp.valueclick.com
127.0.0.1gadgeteer.pdamart.com
127.0.0.1gm.preferences.com
127.0.0.1gp.dejanews.com
127.0.0.1hg1.hitbox.com
127.0.0.1image.click2net.com
127.0.0.1image.eimg.com
127.0.0.1images2.nytimes.com
127.0.0.1jobkeys.ngadcenter.net
127.0.0.1kansas.valueclick.com
127.0.0.1leader.linkexchange.com
127.0.0.1liquidad.narrowcastmedia.com
127.0.0.1ln.doubleclick.net
127.0.0.1m.doubleclick.net
127.0.0.1macaddictads.snv.futurenet.com
127.0.0.1maximumpcads.imaginemedia.com
127.0.0.1media.preferences.com
127.0.0.1mercury.rmuk.co.uk
127.0.0.1mojofarm.sjc.mediaplex.com
127.0.0.1nbc.adbureau.net
127.0.0.1newads.cmpnet.com
127.0.0.1ng3.ads.warnerbros.com
127.0.0.1ngads.smartage.com
127.0.0.1nsads.hotwired.com
127.0.0.1ntbanner.digitalriver.com
127.0.0.1ph-ad05.focalink.com
127.0.0.1ph-ad07.focalink.com
127.0.0.1ph-ad16.focalink.com
127.0.0.1ph-ad17.focalink.com
127.0.0.1ph-ad18.focalink.com
127.0.0.1realads.realmedia.com
127.0.0.1redherring.ngadcenter.net
127.0.0.1redirect.click2net.com
127.0.0.1regio.adlink.de
127.0.0.1retaildirect.realmedia.com
127.0.0.1s2.focalink.com
127.0.0.1sh4sure-images.adbureau.net
127.0.0.1spin.spinbox.net
127.0.0.1static.admaximize.com
127.0.0.1stats.superstats.com
127.0.0.1sview.avenuea.com
127.0.0.1thinknyc.eu-adcenter.net
127.0.0.1tracker.clicktrade.com
127.0.0.1tsms-ad.tsms.com
127.0.0.1v0.extreme-dm.com
127.0.0.1v1.extreme-dm.com
127.0.0.1van.ads.link4ads.com
127.0.0.1view.accendo.com
127.0.0.1w113.hitbox.com
127.0.0.1w25.hitbox.com
127.0.0.1web2.deja.com
127.0.0.1webads.bizservers.com
127.0.0.1www.PostMasterBannerNet.com
127.0.0.1www.ad-up.com
127.0.0.1www.admex.com
127.0.0.1www.alladvantage.com
127.0.0.1www.burstnet.com
127.0.0.1www.commission-junction.com
127.0.0.1www.eads.com
127.0.0.1www.freestats.com
127.0.0.1www.imaginemedia.com
127.0.0.1www.netdirect.nl
127.0.0.1www.oneandonlynetwork.com
127.0.0.1www.targetshop.com
127.0.0.1www.teknosurf2.com
127.0.0.1www.teknosurf3.com
127.0.0.1www.valueclick.com
127.0.0.1www.websitefinancing.com
127.0.0.1www2.burstnet.com
127.0.0.1www4.trix.net
127.0.0.1www80.valueclick.com
127.0.0.1z.extreme-dm.com
127.0.0.1z0.extreme-dm.com
127.0.0.1z1.extreme-dm.com
127.0.0.1ads.rediff.com
127.0.0.1ads.indya.com
127.0.0.1ads.adflight.com
127.0.0.1ads.beguide.net
127.0.0.1ads.mediaturf.net
127.0.0.1ad1.adcept.net
127.0.0.1ad2.adcept.net
127.0.0.1ad3.adcept.net
127.0.0.1ads.fortunecity.com
127.0.0.1www.139cn.com
127.0.0.1www.7liao.com
127.0.0.1chat.51liao.net
127.0.0.1www.51liao.net
127.0.0.1www.7liao.net
127.0.0.1www.6see.com
127.0.0.1bliao.com
127.0.0.1www.bliao.com
127.0.0.1hao123.net
127.0.0.1www.hao123.net
127.0.0.1www.hao222.net
127.0.0.1www.hao222.com
127.0.0.1www.v111.com
127.0.0.1music.v111.com
127.0.0.1www.qq165.com
127.0.0.1www.xicu.com
127.0.0.1www.haodx.com
127.0.0.1www.haohz.com
127.0.0.1www.265.com
127.0.0.1www.dj99.com
127.0.0.1www.dj99.net
127.0.0.1www.yqdj.com
127.0.0.1www.qq530.com
127.0.0.1www.tt67.com
127.0.0.1ad.t2t2.com
127.0.0.1www.yexr.com
127.0.0.1chat.9see.com
127.0.0.1www.ok816.com
127.0.0.1www.3399.net
127.0.0.1www.ads8.com
127.0.0.1www.5566.net
127.0.0.1www.t2t2.com
127.0.0.1popad.qq.com
127.0.0.1v.jsdownload.com
127.0.0.1www.linktoad.com
127.0.0.1club.homeway.com.cn
127.0.0.1sms1.ctn.com.cn
127.0.0.1sms2.ctn.com.cn
127.0.0.1sms3.ctn.com.cn
127.0.0.1www.331122.com
127.0.0.1mmpic.uni.cc
127.0.0.1www.love34.com
127.0.0.1www.free-movie.org
127.0.0.1www.skyhits.com
127.0.0.1www.rd18.com
127.0.0.1tadsweb.tencent.com
127.0.0.1www.vlike.com
127.0.0.1www.chinasee.net
127.0.0.1www.japansky.net
127.0.0.1www.225.com.cn
127.0.0.1ads.china.com
127.0.0.1www.yes521.com
127.0.0.1www.today6.com
127.0.0.1www.h2004.com
127.0.0.1www.movie4.com
127.0.0.1www.rm88.com
127.0.0.1www.qq300.com
127.0.0.1www.qq500.com
127.0.0.1www.av126.com
127.0.0.1www.kissmm.com
127.0.0.1www.cn808.net
127.0.0.1www.hao168.com
127.0.0.1www.mm91.com
127.0.0.1www.huole.com
127.0.0.1www.kan69.com
127.0.0.1ulinkdir.tom.com
127.0.0.1cpc.sohu.com
127.0.0.1images.sohu.com
127.0.0.1adv.pconline.com.cn
127.0.0.1goto.sohu.com
127.0.0.1images2.sohu.com
127.0.0.1www.sexy-books.com
127.0.0.1www.xxbooks.com
127.0.0.1www.18it.com
127.0.0.1www.cnxxx.com
127.0.0.1www.18-girl.net
127.0.0.1ad.tom.com
127.0.0.1ad4.sina.com.cn
127.0.0.1sina.allyes.com
127.0.0.1adtaobao.allyes.com
127.0.0.1smarttrade.allyes.com
127.0.0.1tom.allyes.com
127.0.0.1szwindow.allyes.com
127.0.0.1eachnetmember.allyes.com
127.0.0.1iplus.allyes.com
127.0.0.1sinatest.allyes.com
127.0.0.1casting9.allyes.com
127.0.0.1yinsha.allyes.com
127.0.0.1stockstar.allyes.com
127.0.0.1www.001x.com
127.0.0.1www.hksexweb.com
127.0.0.1www.99adultx.com
127.0.0.1www2.xfreehosting.com
127.0.0.1www1.xfreehosting.com
127.0.0.1www.w555.net
127.0.0.1www.excitecity.com
127.0.0.1www.0xing.com
127.0.0.1sba.3322.net
127.0.0.1www.zgxl.net
127.0.0.1www.qqpic.com
127.0.0.1webspacecn.com
127.0.0.1www.yeapple.com
127.0.0.1manage.link8.com
127.0.0.1www.web888.org
127.0.0.1www.432.cn
127.0.0.1www.kan123.com
127.0.0.1www.3tom.com
127.0.0.1www.sotop.com
127.0.0.1www3.7789.com
127.0.0.1www.66036.com
127.0.0.1www1.66036.com
127.0.0.1www2.66036.com
127.0.0.1www3.66036.com
127.0.0.1www4.66036.com
127.0.0.1www5.66036.com
127.0.0.1www6.66036.com
127.0.0.1www7.66036.com
127.0.0.1www8.66036.com
127.0.0.1www9.66036.com
127.0.0.1www10.66036.com
127.0.0.1tj4.7789.com
127.0.0.1tj5.7789.com
127.0.0.1tj6.7789.com
127.0.0.1tj7.7789.com
127.0.0.1www.7789.com
127.0.0.1count.zhao123.com
127.0.0.1count1.zhao123.com
127.0.0.1count2.zhao123.com
127.0.0.1count3.zhao123.com
127.0.0.1count4.zhaocount.com
127.0.0.1count5.zhaocount.com
127.0.0.1count6.zhaocount.com
127.0.0.1count7.zhaocount.com
127.0.0.1count8.zhaocount.com
127.0.0.1count9.zhaocount.com
127.0.0.1count10.zhaocount.com
127.0.0.1count11.zhaocount.com
127.0.0.1tj1.mytongji.com
127.0.0.1count1.99count.com
127.0.0.1www.99count.com
127.0.0.1bar.baidu.com
127.0.0.1www2.7789.com
127.0.0.1www.guang.org
127.0.0.1www.dlmovie.com
127.0.0.1www.91look.com
127.0.0.1www.kan51.com
127.0.0.1www.mewo.com
127.0.0.1coolsite21.com
127.0.0.1www.t3j4.com
127.0.0.1www.yun8.com
127.0.0.1film.yun8.com
127.0.0.1www.wo123.com
127.0.0.1www.da123.com
127.0.0.1www.1ya.cn
127.0.0.1www.sleazydream.com
127.0.0.1www.easypic2.com
127.0.0.1serv.sexushost.com
127.0.0.1www.xfreehosting.com
127.0.0.1www.888txt.com
127.0.0.1asiafriendfinder.com
127.0.0.1www3.cool168.com
127.0.0.1www2.cool168.com
127.0.0.1www1.cool168.com
127.0.0.1www.happy8.cn
127.0.0.1www.topsex2k.com
127.0.0.1topxxx.sexushost.com
127.0.0.1www.cool168.com
127.0.0.1www.s6.cn
127.0.0.1popme.163.com
127.0.0.1adclient.163.com
127.0.0.1fadama.com
127.0.0.1www.66vv.com
127.0.0.1www.qqee.com
127.0.0.1www.sohu123.com
127.0.0.1www.xgmm.com
127.0.0.1www.7t7t.com
127.0.0.1www.cnimg.com
127.0.0.1cdn2.cnnic.cn
127.0.0.1cool.vv66.com
127.0.0.1www.vv66.com
127.0.0.1www.freepicturepage.com
127.0.0.1www.snasty.com
127.0.0.1www.yourcage.com
127.0.0.1www.shagadelic.com
127.0.0.1hualiao.net
127.0.0.1www.qq163.com
127.0.0.1www.qq163.net
127.0.0.1www.superdown.com
127.0.0.1web.114.com.cn
127.0.0.1www.114.com.cn
127.0.0.1www.91f.cn
127.0.0.1wwww.tthao.com
127.0.0.1www.91f.org
127.0.0.1www.v23.com
127.0.0.1auto.search.msn.com
gototop
 

127.0.0.1x2.51link.com
127.0.0.1x1.51link.com
127.0.0.1www.textlink.cn
127.0.0.1stat.textclick.com
127.0.0.1www.easyhere.com
127.0.0.1www.xxx168.com
127.0.0.1ally.263.net
127.0.0.1www.hualiao.net
127.0.0.1www.xchina.com
127.0.0.1www.sex.com
127.0.0.1www.3xcn.com
127.0.0.1www.20girl.com
127.0.0.1www.x365x.com
127.0.0.1chat.263.net
127.0.0.1chat.yinsha.com
127.0.0.1chat.tom.com
127.0.0.1chat.xilu.com
127.0.0.1www.aliao.com
127.0.0.1chat.163.com
127.0.0.1www.haoliao.com
127.0.0.1www.liaoliao.com
127.0.0.1www.haoliao.net
127.0.0.1www.haoliao.cn
127.0.0.1www.qqliao.com
127.0.0.1www.qliao.com
127.0.0.1www.loveliao.com
127.0.0.1www.mmliao.com
127.0.0.1chat.qq.com
127.0.0.1vchat.xaonline.com
127.0.0.1www.loveliao.net
127.0.0.1www.chinamp3.com
127.0.0.1www.9sky.com
127.0.0.1www.sogua.com
127.0.0.1www.99music.net
127.0.0.1www.yzskdj.com
127.0.0.1music.feifa.com
127.0.0.1www.aisex.com
127.0.0.1www.movie-down.com
127.0.0.1www2.movie-down.com
127.0.0.1www.tt90.com
127.0.0.1www.tt78.com
127.0.0.1www.tiankong.net
127.0.0.1www.qqchat.cn
127.0.0.1www.yymp3.com
127.0.0.1www.9see.com
127.0.0.1www.woliao.net
127.0.0.1www.woliao.com
127.0.0.1www.kuro.com.cn
127.0.0.1www.wangzhiku.com
127.0.0.1hothack.home.chinaren.com
127.0.0.1www.777888.com
127.0.0.1www.5dsoft.com
127.0.0.1www.wokoo.net
127.0.0.1movie.sx.zj.cn
127.0.0.1xyxy68.8u8.net
127.0.0.1www.youmiss.com
127.0.0.1www.cctv8.net
127.0.0.1www.kuliao.com
127.0.0.1www.yyqy.com
127.0.0.1www.sunvod.com
127.0.0.1www.t168.com
127.0.0.1www.coolcdrom.com
127.0.0.1www.girl008.com
127.0.0.1xajh.15888.net
127.0.0.1www.51bug.com
127.0.0.1www.wplune.com
127.0.0.1www.777888.net
127.0.0.1pollen.my001.net
127.0.0.1www.yule21.com
127.0.0.1www.fish3000.com
127.0.0.1www.666e.com
127.0.0.1qm.8ok.com
127.0.0.1www.guosir.ccoo.com
127.0.0.1www.163mm.com
127.0.0.1www.cnooo.com
127.0.0.1www.es158.com
127.0.0.1www.aisa-girl.net
127.0.0.1www.boliwu.com
127.0.0.1www.89005.com
127.0.0.1www.cctv1.net
127.0.0.1www.play.cn.gs
127.0.0.1newyouth.3322.net
127.0.0.1chinabdkx.363.net
127.0.0.1www.zknew.com
127.0.0.1www.dhchao.com
127.0.0.1www.top666.net
127.0.0.1www.amoisonic.com
127.0.0.1www.markguide.com
127.0.0.1www.xyxc.ccoo.com
127.0.0.1www.flyingwalk.com
127.0.0.1www.yezine.net
127.0.0.1www.mmgirls.com
127.0.0.1www.wa***.net
127.0.0.1www.net5w.com
127.0.0.1www.fbstu.com
127.0.0.1www.qlwl.com
127.0.0.1www.yinshang.com
127.0.0.1www.ncunet.com
127.0.0.1www.555666.net
127.0.0.1www.fm1058.cc
127.0.0.1meim.y365.com
127.0.0.1www.qq520.net
127.0.0.1jjkafei.longcity.net
127.0.0.1chow.yesky.net
127.0.0.1oicq.hk.st
127.0.0.1www.my288.com
127.0.0.1www.laws-online.net
127.0.0.1www.hj168.net
127.0.0.116888.6to23.com
127.0.0.1www.love520.net
127.0.0.1www.qq520.com
127.0.0.1www.ezhgc.com
127.0.0.1www.eastedu.com.cn
127.0.0.1www.435000.com
127.0.0.1sdik.8ok.net
127.0.0.1feiying.coolwww.net
127.0.0.1zhongxuesheng.myrice.com
127.0.0.1www.yes9999.com   
127.0.0.1www.nnptt.com
127.0.0.1vod.hengshui.com
127.0.0.1tv.megajoy.com
127.0.0.1www.h444.net
127.0.0.1update.myxq.com
127.0.0.1www.qq168.net  
127.0.0.1www.777888.com  
127.0.0.1www.5dsoft.com  
127.0.0.1movie.sx.zj.cn   
127.0.0.1www.yeapple.com  
127.0.0.1winzheng.126.com
127.0.0.1www.boliwo.com
127.0.0.1www.pk.com
127.0.0.1www.unionsky.cn
127.0.0.1www.allyes.com
127.0.0.1www.xxx.com
127.0.0.1204.177.92.68
127.0.0.1www.fassia.net        
127.0.0.1www.ehomeday.com    
127.0.0.1www.jinpin.net        
127.0.0.1www.happy666.net
127.0.0.1www.myxq.com
127.0.0.1dvd.qq92.com
127.0.0.1www.16yi.com
127.0.0.1www.ye77.com
127.0.0.1www.7sese.com
127.0.0.1www.1yin.net
127.0.0.1www.77ttt.com
127.0.0.1www.7mao.com
127.0.0.1www.mydj2005.com
127.0.0.1www.vv78.com
127.0.0.1www.v119.com
127.0.0.1100.332233.com
127.0.0.1www.cashbackbuddy.com
127.0.0.1www.10uu.com
127.0.0.1fly950.nease.net

==================================
API HOOK
N/A

==================================


[/CODE]
gototop
 

发完 刚才瑞星查出:Dropper.Agent.fvx
Trojan.PSW.JHOnline.fap      Trojan.DL.Inject.rq
gototop
 

安全模式下删除:
C:\WINDOWS\system32\autorun.exe
C:\WINDOWS\iexpl0re.exe>
C:\WINDOWS\system32\ windds32.dll
C:\WINDOWS\winlog0n.exe
C:\WINDOWS\system32\LgSym.dll

运行sreng 注册表  删除
<Soltek><C:\WINDOWS\system32\autorun.exe> [N/A]
<7w><C:\WINDOWS\iexpl0re.exe> [N/A]

运行sreng 服务 隐藏微软服务  删除.
[Win32 Display Driver / Win32DDS][Stopped/Auto Start]
<C:\WINDOWS\system32\\rundll32.exe windds32.dll,start><Microsoft Corporation>


修复文件关联  全修..


gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT