瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 电脑变得好慢,不知道什么原因。

1   1  /  1  页   跳转

电脑变得好慢,不知道什么原因。

电脑变得好慢,不知道什么原因。

领导的机器突然变得好慢,经过日志扫描,发现了一些问题,但是仍然没有根除,希望大家能帮帮忙察看下。谢谢。

下面把日志贴出来。

[CODE]

2007-05-21,16:25:27

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <SoundMan><SOUNDMAN.EXE>  [(Verified)Microsoft Windows Publisher]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Publisher]
    <nwiz><nwiz.exe /install>  []
    <NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <OfficeScanNT Monitor><"C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow>  [Trend Micro Inc.]
    <wosa><C:\DOCUME~1\LUCKYS~1\LOCALS~1\Temp\woso.exe>  [N/A]
    <fysa><C:\DOCUME~1\LUCKYS~1\LOCALS~1\Temp\fyso.exe>  [N/A]
    <jtsa><C:\DOCUME~1\LUCKYS~1\LOCALS~1\Temp\jtso.exe>  [N/A]
    <wmsa><C:\DOCUME~1\LUCKYS~1\LOCALS~1\Temp\wmso.exe>  [N/A]
    <dasa><C:\DOCUME~1\LUCKYS~1\LOCALS~1\Temp\daso.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{03F6E661-0D5F-3FAD-3E2B-E261E3CB6CD2}><C:\Program Files\Internet Explorer\PLUGINS\HiJack.dll>  [Microsoft Corporation]
    <{01F6EB6F-AB5C-1FDD-6E5B-FB6EE3CC6CD6}><C:\Program Files\Internet Explorer\HiJack.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Publisher]
    <CDBurn><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Publisher]
    <WebCheck><%SystemRoot%\system32\webcheck.dll>  [(Verified)Microsoft Windows Publisher]
    <SysTray><C:\WINDOWS\system32\stobject.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
    <WinlogonNotify: ScCertProp><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
    <WinlogonNotify: Schedule><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    <WinlogonNotify: sclgntfy><sclgntfy.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
    <WinlogonNotify: termsrv><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
    <WinlogonNotify: wlballoon><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
    <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    <Microsoft Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
    <浏览器自定义组件><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
    <Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
    <Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe>  [(Verified)Microsoft Windows Publisher]

==================================
启动文件夹
N/A

==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[OfficeScanNT 个人防火墙 / OfcPfwSvc][Running/Auto Start]
  <"C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe"><Trend Micro Inc.>
[OfficeScanNT 侦听程序 / tmlisten][Running/Auto Start]
  <"C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe"><Trend Micro Inc.>
[VRVWatchServer / VRVWatchServer][Running/Auto Start]
  <"C:\WINDOWS\system32\WatchClient.exe" -service><>

==================================
驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Stopped/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
  <system32\drivers\npf.sys><Politecnico di Torino>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Running/Manual Start]
  <system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[SIS AGP Bus Filter / sisagp][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\sisagp.sys><Silicon Integrated Systems Corporation>
[Trend Micro Filter / TmFilter][Running/Auto Start]
  <\??\C:\Program Files\Trend Micro\OfficeScan Client\TmXPFlt.sys><Trend Micro Inc.>
[Trend Micro PreFilter / TmPreFilter][Running/Auto Start]
  <\??\C:\Program Files\Trend Micro\OfficeScan Client\TmPreFlt.sys><Trend Micro Inc.>
[Common Firewall Driver / TM_CFW][Running/Auto Start]
  <\??\C:\Program Files\Trend Micro\OfficeScan Client\tm_cfw.sys><Trend Micro Inc.>
[VRVFW / VRVFW][Running/Boot Start]
  <\SystemRoot\system32\VrvFw.sys><北信源>
[Trend Micro VSAPI NT / VSApiNt][Running/Auto Start]
  <\??\C:\Program Files\Trend Micro\OfficeScan Client\VSApiNt.sys><Trend Micro Inc.>
最后编辑2007-05-22 08:38:18
分享到:
gototop
 

==================================
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v11.dll, Thunder Networking Technologies,LTD>
[ObjWinNTCheck Class]
  {00134F72-5284-44F7-95A8-52A619F70751} <C:\WINDOWS\Downloaded Program Files\WinNTChk.dll, Trend Micro Inc.>
[OfficeScan Corp Edition Web-Deployment SetupCtrl Class]
  {08D75BC1-D2B5-11D1-88FC-0080C859833B} <C:\WINDOWS\Downloaded Program Files\OfficeScanSetup.dll, Trend Micro Inc.>
[OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class]
  {5EFE8CB1-D095-11D1-88FC-0080C859833B} <C:\WINDOWS\Downloaded Program Files\OfficeScanRemoveCtrl.dll, Trend Micro Inc.>
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v11.dll, Thunder Networking Technologies,LTD>
[ObjWinNTCheck Class]
  {00134F72-5284-44F7-95A8-52A619F70751} <C:\WINDOWS\Downloaded Program Files\WinNTChk.dll, Trend Micro Inc.>
[OfficeScan Corp Edition Web-Deployment SetupCtrl Class]
  {08D75BC1-D2B5-11D1-88FC-0080C859833B} <C:\WINDOWS\Downloaded Program Files\OfficeScanSetup.dll, Trend Micro Inc.>
[PeerDraw Class]
  {10072CEC-8CC1-11D1-986E-00A0C955B42E} <C:\Program Files\Common Files\Microsoft Shared\VGX\vgx.dll, Microsoft Corporation>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
  {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class]
  {5EFE8CB1-D095-11D1-88FC-0080C859833B} <C:\WINDOWS\Downloaded Program Files\OfficeScanRemoveCtrl.dll, Trend Micro Inc.>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[AUDIO__MP3 Moniker Class]
  {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
  {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\getallurl.htm, N/A>

==================================
正在运行的进程
[PID: 456][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 512][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1320][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
    [C:\WINDOWS\system32\WINABC.IME]  [PKUETI, 5.22.216]
    [C:\WINDOWS\system32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.8198]
    [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.8198]
    [C:\WINDOWS\system32\nvshell.dll]  [, ]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\WINDOWS\system32\VrvKeyBoard.dll]  [, 1, 0, 0, 1]
[PID: 1508][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5, 1, 0, 51]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
[PID: 1532][C:\WINDOWS\system32\RUNDLL32.EXE]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\NvMcTray.dll]  [NVIDIA Corporation, 6.14.10.8198]
    [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.8198]
    [C:\WINDOWS\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
[PID: 1540][C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe]  [Trend Micro Inc., 7.3.0.1028]
    [C:\Program Files\Trend Micro\OfficeScan Client\loadhttp.dll]  [Trend Micro Inc., 7.3.0.1028]
    [C:\Program Files\Trend Micro\OfficeScan Client\Pwd.dll]  [Trend Micro Inc., 7.3.0.1028]
    [C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInAPI.dll]  [Trend Micro Inc., 7.3.0.1028]
    [C:\Program Files\Trend Micro\OfficeScan Client\OfcPIPC.dll]  [N/A, ]
    [C:\Program Files\Trend Micro\OfficeScan Client\TimeString.dll]  [N/A, ]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Trend Micro\OfficeScan Client\ntmonres.dll]  [Trend Micro Inc., 7.3.0.1028]
    [C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInMain.dll]  [Trend Micro Inc., 7.3.0.1028]
    [C:\Program Files\Trend Micro\OfficeScan Client\OfcPlugInTray.dll]  [Trend Micro Inc., 7.3.0.1028]
    [C:\Program Files\Trend Micro\OfficeScan Client\tmdbg20.dll]  [trend_company_name, 1, 0, 0, 1]
    [C:\WINDOWS\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
    [C:\WINDOWS\system32\VrvKeyBoard.dll]  [, 1, 0, 0, 1]
[PID: 1548][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\vrvhook.dll]  [edp, 6, 4, 19, 15]
[PID: 424][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 392][C:\Documents and Settings\LuckyStar\桌面\软件\日志扫描软件\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\WINDOWS\system32\VrvHook.dll]  [edp, 6, 4, 19, 15]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\VrvKeyBoard.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sfc_os.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A
gototop
 

==================================
HOSTS 文件
127.0.0.1      localhost
0.0.0.0 126gzs.yeah.net
0.0.0.0 16888.6to23.com
0.0.0.0 16898.myrice.com
0.0.0.0 182838.com
0.0.0.0 204.177.92.68
0.0.0.0 204.177.92.68/rotate/r3.jhtml #去TRY看看绝对让你的IE去回收站
0.0.0.0 211.20.72.218
0.0.0.0 265.com
0.0.0.0 3721.net #3721网络实名
0.0.0.0 63581.yeah.net
0.0.0.0 69.22.169.85
0.0.0.0 8qi.net
0.0.0.0 91mm.net
0.0.0.0 94.YES9999.com
0.0.0.0 989898.********
0.0.0.0 989898.126.com
0.0.0.0 9see.com
0.0.0.0 abc.265.com
0.0.0.0 ad.91x.net
0.0.0.0 ad.cn.doubleclick.net #新浪网广告
0.0.0.0 ad.ri999.com
0.0.0.0 ad.t2t2.com
0.0.0.0 ad.tom.com
0.0.0.0 ad2.15hr.com/adinfo.htm
0.0.0.0 ad4.sina.com.cn #新浪网广告
0.0.0.0 adclient.163.com
0.0.0.0 ads.china.com
0.0.0.0 ads.online.sh.cn
0.0.0.0 adtaobao.allyes.com
0.0.0.0 adv.pconline.com.cn
0.0.0.0 aliao.com
0.0.0.0 ally.263.net
0.0.0.0 anhlyiling.free1.51web.cn
0.0.0.0 asiafriendfinder.com
0.0.0.0 asqin123.51.net
0.0.0.0 auto.search.msn.com
0.0.0.0 babe520.5188.org
0.0.0.0 bar.baidu.com
0.0.0.0 bbs.ccjz.com
0.0.0.0 bj.58.com
0.0.0.0 bliao.com
0.0.0.0 book99.3322.net
0.0.0.0 casting9.allyes.com
0.0.0.0 cdn2.cnnic.cn
0.0.0.0 cga01.2008.cc #骗子
0.0.0.0 chat.163.com
0.0.0.0 chat.263.net
0.0.0.0 chat.51liao.net
0.0.0.0 chat.9see.com
0.0.0.0 chat.qq.com
0.0.0.0 chat.tom.com
0.0.0.0 chat.xilu.com
0.0.0.0 chat.yeeyoo.com
0.0.0.0 chat.yinsha.com
0.0.0.0 chinabdkx.363.net
0.0.0.0 chinaour.com
0.0.0.0 chow.yesky.net
0.0.0.0 club.homeway.com.cn
0.0.0.0 cn.cy256.com
0.0.0.0 cn.yimg.com
0.0.0.0 cn333.net
0.0.0.0 cn4sex.com
0.0.0.0 cnlove.bl.am
0.0.0.0 cnsmin.3721.com #3721网络实名
0.0.0.0 cnsmin.3721.net #3721网络实名
0.0.0.0 cool.vv66.com
0.0.0.0 coolsite21.com
0.0.0.0 count.zhao123.com
0.0.0.0 count1.99count.com
0.0.0.0 count1.zhao123.com
0.0.0.0 count10.zhaocount.com
0.0.0.0 count11.zhaocount.com
0.0.0.0 count2.zhao123.com
0.0.0.0 count3.zhao123.com
0.0.0.0 count4.zhaocount.com
0.0.0.0 count5.zhaocount.com
0.0.0.0 count6.zhaocount.com
0.0.0.0 count7.zhaocount.com
0.0.0.0 count8.zhaocount.com
0.0.0.0 count9.zhaocount.com
0.0.0.0 cpc.sohu.com
0.0.0.0 dahau2.7u7.net
0.0.0.0 download.3721.com #3721网络实名
0.0.0.0 download.3721.net #3721网络实名
0.0.0.0 dvd.qq92.com
0.0.0.0 dxy.9126.com
0.0.0.0 e23.3322.net
0.0.0.0 eachnetmember.allyes.com
0.0.0.0 epzj.1m.cn
0.0.0.0 est2000.126.com
0.0.0.0 fadama.com
0.0.0.0 feiying.coolwww.net
0.0.0.0 feiying.coolwww.net
0.0.0.0 film.yun8.com
0.0.0.0 free.tsee.net
0.0.0.0 game.9ii.com
0.0.0.0 girlchinese.com #IE的主页也被改了
0.0.0.0 golsz126.com
0.0.0.0 goto.sohu.com
0.0.0.0 gz.blogland.cn
0.0.0.0 gz.onlinedown.net/soft/36825.htm
0.0.0.0 h444.net
0.0.0.0 haoliao.com
0.0.0.0 hjcz.www30.cnidc.cn
0.0.0.0 home.itdrp.com
0.0.0.0 home.itdrp.com/wg888/me.jpg
0.0.0.0 home.kimo.com.tw
0.0.0.0 home.kimo.com.tw/avnvyou520 #一般性恶意代码
0.0.0.0 hothack.home.chinaren.com
0.0.0.0 hualiao.net
0.0.0.0 images.sohu.com
0.0.0.0 images2.sohu.com
0.0.0.0 inzheng.126.com
0.0.0.0 iplus.allyes.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 ka88.vicp.net:8080
0.0.0.0 kaomm.8m.cn
0.0.0.0 kth.diy.myrice.com
0.0.0.0 lc222.myrice.com
0.0.0.0 liaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 loveliao.com
0.0.0.0 loveliao.net
0.0.0.0 lovemm.8m.cn
0.0.0.0 manage.link8.com
0.0.0.0 manyiyu.8u8.com
0.0.0.0 maomao363.126.com
0.0.0.0 meim.y365.com
0.0.0.0 mm.7h5.com
0.0.0.0 mmliao.com
0.0.0.0 mmpic.uni.cc
0.0.0.0 mov.hy256.com
0.0.0.0 movie.n3389.com
0.0.0.0 movie.sx.zj.cn
0.0.0.0 movie-down.com
0.0.0.0 music.94xp.com
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
0.0.0.0 new.unionsky.cn
0.0.0.0 newyouth.3322.net
0.0.0.0 nicex.126.com
0.0.0.0 oec315.126.com
0.0.0.0 oicq.hk.st
0.0.0.0 online.265.com
0.0.0.0 picture.exe
0.0.0.0 planetside.coolman.com.cn
0.0.0.0 pollen.my001.net
0.0.0.0 popad.qq.com
0.0.0.0 qm.8ok.com
0.0.0.0 qq.34hkk.com
0.0.0.0 qq_com.****net
0.0.0.0 qq_game.y25.cn
0.0.0.0 QQ6ss.126.com
0.0.0.0 qqpic.com
0.0.0.0 qqtwz.********
0.0.0.0 qqtwz.126.com
0.0.0.0 rd.yahoo.com
0.0.0.0 realads.realmedia.com
0.0.0.0 redherring.ngadcenter.net
0.0.0.0 redirect.click2net.com
0.0.0.0 regio.adlink.de
0.0.0.0 retaildirect.realmedia.com
0.0.0.0 s2.focalink.com
0.0.0.0 sba.3322.net
0.0.0.0 sdik.8ok.net
0.0.0.0 serv.sexushost.com
0.0.0.0 serviceQQ.34hkk.com
0.0.0.0 sg51.com #qq病毒
0.0.0.0 sh4sure-images.adbureau.net
0.0.0.0 shop.7cv.com
0.0.0.0 sina.allyes.com
0.0.0.0 sinatest.allyes.com
0.0.0.0 smarttrade.allyes.com
0.0.0.0 sms.61m.com
0.0.0.0 sms1.ctn.com.cn
0.0.0.0 sms2.ctn.com.cn
0.0.0.0 sms3.ctn.com.cn
0.0.0.0 spin.spinbox.net
0.0.0.0 stat.textclick.com
0.0.0.0 static.admaximize.com
0.0.0.0 stats.superstats.com
0.0.0.0 stockstar.allyes.com
0.0.0.0 sview.avenuea.com
0.0.0.0 sx.6to23.com
0.0.0.0 szwindow.allyes.com
0.0.0.0 tadsweb.tencent.com
0.0.0.0 thinknyc.eu-adcenter.net
0.0.0.0 tiankong.net
0.0.0.0 tj1.mytongji.com
0.0.0.0 tj4.7789.com
0.0.0.0 tj5.7789.com
0.0.0.0 tj6.7789.com
0.0.0.0 tj7.7789.com
0.0.0.0 tom.allyes.com
0.0.0.0 topxxx.sexushost.com
0.0.0.0 tracker.clicktrade.com
0.0.0.0 trojan.qqwebaut.a
0.0.0.0 trojan.qqwebaut.b
0.0.0.0 tsms-ad.tsms.com
0.0.0.0 tty.yyun.net #与上述的危害差不多
0.0.0.0 tv.megajoy.com
0.0.0.0 tv.megajoy.com/video/movies
0.0.0.0 twz.126.com
0.0.0.0 tz.ne1.net
0.0.0.0 ulinkdir.tom.com
gototop
 

0.0.0.0 update.myxq.com
0.0.0.0 user.netomia.com
0.0.0.0 v.jsdownload.com
0.0.0.0 vchat.xaonline.com
0.0.0.0 vod.52en.com
0.0.0.0 vod.aogo.net
0.0.0.0 vod.hengshui.com
0.0.0.0 vod.jjpic.com
0.0.0.0 vod.pppic.com
0.0.0.0 wacky.nease.net
0.0.0.0 web.114.com.cn
0.0.0.0 web.aogo.net
0.0.0.0 web.cy07.com
0.0.0.0 webspacecn.com
0.0.0.0 wh8065.*************/rj.htm
0.0.0.0 winzheng.********
0.0.0.0 winzheng.126.com
0.0.0.0 www.00169.net
0.0.0.0 www.001x.com
0.0.0.0 www.0970.net
0.0.0.0 www.0xing.com
0.0.0.0 www.100bao.com
0.0.0.0 www.10662.com
0.0.0.0 www.114.com.cn
0.0.0.0 www.126p.com
0.0.0.0 www.12san.com
0.0.0.0 www.139cn.com
0.0.0.0 www.15hr.com
0.0.0.0 www.163[1].com #也是一个什么音乐网。症状和楼上的差不多。我上次中招后化了一个多小时才改回来还有夹带病毒
0.0.0.0 www.163mm.com
0.0.0.0 www.163z.com
0.0.0.0 www.17777.com
0.0.0.0 www.17go8.net
0.0.0.0 www.17lele.com
0.0.0.0 www.17sun.net #自动安装搜狗
0.0.0.0 www.18-girl.net
0.0.0.0 www.18hi.com #(QQ病毒,网站内也有病毒)
0.0.0.0 www.18it.com
0.0.0.0 www.19ku.com
0.0.0.0 www.1enovo.com
0.0.0.0 www.1ya.cn
0.0.0.0 www.1yun.net
0.0.0.0 www.20girl.com
0.0.0.0 www.20mtv.com
0.0.0.0 www.215000.net
0.0.0.0 www.21rose.com
0.0.0.0 www.225.com.cn
0.0.0.0 www.265.com
0.0.0.0 www.265z.com
0.0.0.0 www.****cn
0.0.0.0 www.331122.com
0.0.0.0 www.3399.net
0.0.0.0 www.34hkk.com
0.0.0.0 www.35935.com
0.0.0.0 www.365wma.com
0.0.0.0 www.365ww.com
0.0.0.0 www.36link.com
0.0.0.0 www.37021.com #可恶讨厌,在你的机器里到处做手脚:注册表\启动\计算机配置文件\还有一个dll文件而且资源管理器无法浏览隐藏文件这个最讨厌
0.0.0.0 www.3721.com #3721网络实名
0.0.0.0 www.3721.net #3721网络实名
0.0.0.0 www.3726.com.cn
0.0.0.0 www.3tom.com
0.0.0.0 www.3xcn.com
0.0.0.0 www.432.cn
0.0.0.0 www.435000.com
0.0.0.0 www.45520.com #(QQ病毒,超强)
0.0.0.0 www.4tb.net
0.0.0.0 www.51115.com
0.0.0.0 www.51944.com
0.0.0.0 www.51bug.com
0.0.0.0 www.51icon.net
0.0.0.0 www.51liao.net
0.0.0.0 www.520.net
0.0.0.0 www.522shop.com #骗子网站
0.0.0.0 www.52av.com
0.0.0.0 www.52rmb.com
0.0.0.0 www.52xyxy.com
0.0.0.0 www.555666.net
0.0.0.0 www.5566.net
0.0.0.0 www.58.com
0.0.0.0 www.58589.com
0.0.0.0 www.58q.com
0.0.0.0 www.5dsoft.com
0.0.0.0 WWW.5dsoft.com
0.0.0.0 www.5xt.net
0.0.0.0 www.66036.com
0.0.0.0 www.666ccc.com
0.0.0.0 www.666e.com
0.0.0.0 www.668yp.com
0.0.0.0 www.66vv.com
0.0.0.0 www.6781.com
0.0.0.0 www.6mb.net
0.0.0.0 www.6see.com
0.0.0.0 www.760li.com
0.0.0.0 www.7720.com
0.0.0.0 www.7758520.com
0.0.0.0 www.777888.com
0.0.0.0 www.777888.net
0.0.0.0 www.7789.com
0.0.0.0 www.78cq.com
0.0.0.0 www.7jianwg.net
0.0.0.0 www.7liao.com
0.0.0.0 www.7liao.net
0.0.0.0 www.7sou.com
0.0.0.0 www.7t7t.com
0.0.0.0 www.7zhao.com
0.0.0.0 www.800so.cn
0.0.0.0 www.800xz.com
0.0.0.0 WWW.8095.COM
0.0.0.0 www.81915.com #改IE首页
0.0.0.0 www.86.net
0.0.0.0 www.888mtv.com
0.0.0.0 www.888txt.com
0.0.0.0 www.88music.com
0.0.0.0 www.89005.com
0.0.0.0 www.8qi.com
0.0.0.0 www.8zhi.com
0.0.0.0 www.918soft.com
0.0.0.0 www.91f.cn
0.0.0.0 www.91f.org
0.0.0.0 www.91look.com
0.0.0.0 www.94135.com
0.0.0.0 www.9991.com
0.0.0.0 www.99adultx.com
0.0.0.0 www.99count.com
0.0.0.0 www.99music.net
0.0.0.0 www.99sw.com
0.0.0.0 www.9jh.com
0.0.0.0 www.9see.com
0.0.0.0 www.a521.com
0.0.0.0 www.adlofashion.com
0.0.0.0 www.ads8.com
0.0.0.0 www.aisa-girl.net
0.0.0.0 www.aisex.com
0.0.0.0 www.aliao.com
0.0.0.0 www.allyes.com #掏宝网广告代理
0.0.0.0 www.amoisonic.com
gototop
 

0.0.0.0 www.aogo.com
0.0.0.0 www.aogo.net
0.0.0.0 www.av126.com
0.0.0.0 www.av178.com
0.0.0.0 www.avvcd.com
0.0.0.0 www.ayzz.com
0.0.0.0 www.bliao.com
0.0.0.0 www.boliwo.com
0.0.0.0 www.boliwu.com
0.0.0.0 www.book.cn.gg
0.0.0.0 www.book8.com
0.0.0.0 www.bt990.com
0.0.0.0 www.bypp.com
0.0.0.0 www.cctv1.net
0.0.0.0 www.cctv8.com
0.0.0.0 www.cctv8.net
0.0.0.0 www.chaxun.com
61.129.15.73 www.chinadforce.com
0.0.0.0 www.chinamp3.com
0.0.0.0 www.chinasee.net
0.0.0.0 www.chnn.net #盗qq网站
0.0.0.0 www.chuangxinkj.com
0.0.0.0 www.cn4sex.com
0.0.0.0 www.cn808.net
0.0.0.0 www.cndown8.cn
0.0.0.0 www.cnimg.com
0.0.0.0 WWW.CNOOO.COM
0.0.0.0 www.cnqb.net #禁止你的注册表,改首页,主页地址栏变灰,改右键
0.0.0.0 www.cnxxx.com
0.0.0.0 www.cool168.com
0.0.0.0 www.coolcdrom.com #要特别小心这个网站,它会在你启动组里做手脚,使得重启以后标题依旧
0.0.0.0 www.crackbest.com
0.0.0.0 www.cz88.net
61.129.15.73 www.d4s.cn
0.0.0.0 www.da123.com
0.0.0.0 www.dd22.com.cn
0.0.0.0 www.dd88.com
0.0.0.0 www.dd888.com
0.0.0.0 www.dddzzz.com
0.0.0.0 www.ddzhz.com
0.0.0.0 www.deepdo.com
0.0.0.0 www.dhchao.com
0.0.0.0 www.didai.com
0.0.0.0 www.dj33344.com
0.0.0.0 www.dj3344.com #打开后,重启时你的主页就变成它的,并通过QQ向他人传播,现在正飙行,奇坏无比
0.0.0.0 www.dj99.com
0.0.0.0 www.dj99.net
0.0.0.0 www.dlmovie.com
0.0.0.0 www.dy16.com
0.0.0.0 www.eastedu.com
0.0.0.0 www.eastedu.com.cn
0.0.0.0 www.easyhere.com
0.0.0.0 www.easypic2.com
0.0.0.0 www.edodo.net #骗子网站
0.0.0.0 www.ehomeday.com
0.0.0.0 www.ehomeday.com #(搜索的时候它会给你一把哦!!)
0.0.0.0 www.eliao.com
0.0.0.0 www.eliao.net
0.0.0.0 www.ent8.com
0.0.0.0 www.es158.com
0.0.0.0 www.excitecity.com
0.0.0.0 www.ezhgc.com
0.0.0.0 www.fassia.net
0.0.0.0 www.fassia.net/wmed/index1.html
0.0.0.0 www.fbstu.com
0.0.0.0 www.film.8716.com
0.0.0.0 www.film3344.com
0.0.0.0 www.film888.com
0.0.0.0 www.fish3000.com
0.0.0.0 www.flyingwalk.com
0.0.0.0 www.fm1058.cc
0.0.0.0 www.fm18.com
0.0.0.0 www.free-movie.org
0.0.0.0 www.freepicturepage.com
0.0.0.0 www.fs286.com
0.0.0.0 www.ftlink.net #一般性恶意代码
0.0.0.0 www.getfreedomain.biz
0.0.0.0 www.girl008.com
0.0.0.0 www.girlchinese.com
0.0.0.0 www.guang.org
0.0.0.0 www.guosir.ccoo.com
0.0.0.0 www.gz38.com/web
0.0.0.0 www.h2004.com
0.0.0.0 www.hahabus.com
0.0.0.0 www.hao114.com
0.0.0.0 www.hao168.com
0.0.0.0 www.hao222.com
0.0.0.0 www.hao222.net
0.0.0.0 www.hao3344.com
0.0.0.0 www.haodx.com
0.0.0.0 www.haody.net
0.0.0.0 www.haohz.com
0.0.0.0 www.haoliao.cn
0.0.0.0 www.haoliao.com
0.0.0.0 www.haoliao.net
0.0.0.0 www.haowz.net
0.0.0.0 www.happy666.net
0.0.0.0 www.happy8.cn
0.0.0.0 www.heike8.com
0.0.0.0 www.henbang.com
0.0.0.0 www.hj168.net
0.0.0.0 www.hksexweb.com
0.0.0.0 www.hualiao.net
0.0.0.0 www.huole.com
0.0.0.0 www.idm.com.cn
0.0.0.0 www.IE136.com
0.0.0.0 www.i-lookup.com
0.0.0.0 www.it.com.cn #安装流氓插件
0.0.0.0 www.japansky.net
0.0.0.0 www.jcwz.com
0.0.0.0 www.jiade68.com
0.0.0.0 www.jinpin.net
0.0.0.0 www.jjpic.com #(开机自动运行他的主页,会加载不明插件,有大量的病毒)
0.0.0.0 www.joyiex.com #(超可恶最新版QQ专杀都没用,注册表也进不去
0.0.0.0 www.jsing.net
0.0.0.0 www.k163.com #狩猎者变种和DJ344、QQ3344、QQ168
0.0.0.0 www.kaidait.com
0.0.0.0 www.kan123.com
0.0.0.0 www.kan51.com
0.0.0.0 www.kan69.com
0.0.0.0 www.kanxs.com
0.0.0.0 www.ki888.net
0.0.0.0 www.kissmm.com
0.0.0.0 www.kk88.com
0.0.0.0 www.ktv530.com
0.0.0.0 www.ku666.com
0.0.0.0 www.kule5.com
0.0.0.0 www.kuliao.com
0.0.0.0 www.kuro.com.cn
0.0.0.0 www.laws-online.net
0.0.0.0 www.leo520.com
0.0.0.0 www.liaoliao.com
0.0.0.0 www.linktoad.com
0.0.0.0 www.love34.com
0.0.0.0 www.love520.net
0.0.0.0 www.loveliao.com
0.0.0.0 www.loveliao.net
0.0.0.0 www.lovese.com
0.0.0.0 www.lsolar3721.com
0.0.0.0 www.markguide.com
0.0.0.0 www.mewo.com
0.0.0.0 www.mir999.com
0.0.0.0 www.mm5i.com
0.0.0.0 www.mm91.com
0.0.0.0 www.mmgirls.com
0.0.0.0 www.mmliao.com
0.0.0.0 www.mmm168.com
0.0.0.0 www.mmm168.com/star
0.0.0.0 www.mmqm.com
0.0.0.0 www.movie321.com
0.0.0.0 www.movie4.com
0.0.0.0 www.movie78.com
0.0.0.0 www.movie-down.com
0.0.0.0 www.mp3tt.com
0.0.0.0 www.mtv365.com
0.0.0.0 www.mtv51.com #什么雪落无声音乐网,恶性:禁止注册表修改,禁止开始菜单“运行”项。开机自动运行他的主页
0.0.0.0 www.mtv68.com
0.0.0.0 www.mtv911.com
0.0.0.0 www.mtvxp.com
0.0.0.0 www.mucopy.com
0.0.0.0 www.my168.net
0.0.0.0 www.my180.com #IE劫持
0.0.0.0 www.my288.com
0.0.0.0 www.mydj2005.com #(QQ病毒,注意等级五个星)
0.0.0.0 www.myxq.com
0.0.0.0 www.ncunet.com
0.0.0.0 www.ncunet.com
0.0.0.0 www.net5w.com
0.0.0.0 www.nic2000.com
0.0.0.0 www.ning.com
0.0.0.0 www.njnu.info
0.0.0.0 www.nnptt.com
0.0.0.0 www.nnptt.com/tv
0.0.0.0 www.ok123.com
0.0.0.0 www.ok520.com
0.0.0.0 www.ok530.com
0.0.0.0 www.ok56.com #恶意修改IE首页
0.0.0.0 www.ok816.com
0.0.0.0 www.okww.net
0.0.0.0 www.onlyy.net
0.0.0.0 www.oovod.com
0.0.0.0 www.op99.com
0.0.0.0 www.orsoon.com
0.0.0.0 www.ourbt.com
0.0.0.0 www.pcbsky.com #病毒
0.0.0.0 www.pcuo.com
0.0.0.0 www.pixpox.com #恶性**网站。会加载不明插件,并且自动开启计算机后门,而且在计算机每个角落都有该网站留下的恶意程序
0.0.0.0 www.pk.com
0.0.0.0 www.play.cn.gs
0.0.0.0 www.pm520.com
0.0.0.0 www.pointsmoney.com
gototop
 

0.0.0.0 www.pp365.com
0.0.0.0 www.qliao.com
0.0.0.0 www.qlwl.com
0.0.0.0 www.qq120.com
0.0.0.0 www.qq163.com
0.0.0.0 www.qq163.net
0.0.0.0 www.qq165.com
0.0.0.0 www.qq168.net #打开后,重启时你的主页就变成它的,并通过QQ向他人传播,而且传波病毒,还狠些!现在正在飙行
0.0.0.0 www.qq18.net
0.0.0.0 www.qq230.com
0.0.0.0 www.qq250.com
0.0.0.0 www.qq300.com
0.0.0.0 www.qq3344.com
0.0.0.0 www.qq3344.net
0.0.0.0 www.qq500.com
0.0.0.0 www.qq520.com
0.0.0.0 www.qq520.net
0.0.0.0 www.qq530.com
0.0.0.0 www.qq550.com
0.0.0.0 WWW.QQ58.com
0.0.0.0 www.QQ588.com
0.0.0.0 www.qq720.com
0.0.0.0 www.qq886.com
0.0.0.0 www.qq888.com
0.0.0.0 www.qq988.com
0.0.0.0 www.qqchat.cn
0.0.0.0 www.qqee.com
0.0.0.0 www.qqliao.com
0.0.0.0 www.qqpic.com
0.0.0.0 www.rd18.com
0.0.0.0 www.rm78.com
0.0.0.0 www.rm88.com
0.0.0.0 www.s6.cn
0.0.0.0 www.sa25.y365.com
0.0.0.0 www.sdfassdfasdfs.com
0.0.0.0 www.searon.com
0.0.0.0 www.seasky.biz
0.0.0.0 www.sex.com
0.0.0.0 www.sexfox.com
0.0.0.0 www.sexhu.com
0.0.0.0 www.sexy-books.com
0.0.0.0 www.shagadelic.com
0.0.0.0 www.shop12345.com
0.0.0.0 www.sinokey.com
0.0.0.0 www.sky8.org #病毒
0.0.0.0 www.skyhits.com
0.0.0.0 www.sleazydream.com
0.0.0.0 www.snasty.com
0.0.0.0 www.sohu123.com
0.0.0.0 www.sooe.cn
0.0.0.0 www.sotop.com
0.0.0.0 www.sq88.com
0.0.0.0 www.sunvod.com
0.0.0.0 www.superdown.com
0.0.0.0 www.t168.com
0.0.0.0 www.t2t2.com
0.0.0.0 www.t3j4.com
0.0.0.0 www.taiwan.co.nz
0.0.0.0 www.textlink.cn
0.0.0.0 www.tian8.com
0.0.0.0 www.tiankong.net
0.0.0.0 www.today6.com
0.0.0.0 www.top123.com
0.0.0.0 www.top666.net
0.0.0.0 www.topsex2k.com
0.0.0.0 www.tt67.com
0.0.0.0 www.tt78.com
0.0.0.0 www.tt90.com
0.0.0.0 www.ttjj.com
0.0.0.0 www.ttjj.com/index.php
0.0.0.0 www.ttlook.com
0.0.0.0 www.tvliao.com
0.0.0.0 www.twsexnet.com
0.0.0.0 www.u4123.com
0.0.0.0 www.u88.cn
0.0.0.0 www.unionsky.cn #掏宝网广告代理
0.0.0.0 www.v111.com
0.0.0.0 www.v23.com
0.0.0.0 www.v256.com
0.0.0.0 www.v357.com
0.0.0.0 www.vlike.com
0.0.0.0 www.vv66.com
0.0.0.0 www.w510.com
0.0.0.0 www.w555.net
0.0.0.0 www.wa***.net
0.0.0.0 www.wakao.net
0.0.0.0 www.wangwang.biz
0.0.0.0 www.wangzhiku.com
0.0.0.0 www.wasex.net
0.0.0.0 www.web888.org
0.0.0.0 www.websamba.com
0.0.0.0 www.windowws.cc
0.0.0.0 www.windowws.cc/hp.htm?id=9
0.0.0.0 www.winfixer.com
0.0.0.0 www.wo111.com
0.0.0.0 www.wo123.com
0.0.0.0 www.wokoo.net
0.0.0.0 www.woliao.com
0.0.0.0 www.woliao.net
0.0.0.0 www.woogood.com #大流氓网站,修改注册表也无法除去它
0.0.0.0 www.wplune.com
0.0.0.0 www.wsy-huayi.com.cn
0.0.0.0 www.x365x.com
0.0.0.0 www.xchina.com
0.0.0.0 www.xfreehosting.com
0.0.0.0 www.xgdown.com #病毒网站,捆绑流氓软件
0.0.0.0 www.xgmm.com
0.0.0.0 www.xh800.com.cn #骗子网站
0.0.0.0 www.xicu.com
0.0.0.0 www.xxbooks.com
0.0.0.0 www.xxx.com
0.0.0.0 www.xxx.xom
0.0.0.0 www.xxx168.com
0.0.0.0 www.xyx1.com
0.0.0.0 www.xyxc.ccoo.com
0.0.0.0 www.xzwang.com
0.0.0.0 www.y56.com #自动安装插件
0.0.0.0 www.y996.net
0.0.0.0 www.ye99.com
0.0.0.0 www.yeapple.com
0.0.0.0 www.yes521.com
0.0.0.0 www.yes9999.com
0.0.0.0 www.yexr.com
0.0.0.0 www.yezine.net
0.0.0.0 www.yibinren.com #更可怕,把IE的默认页都改成他的了
0.0.0.0 www.yinshang.com
0.0.0.0 www.youmiss.com
0.0.0.0 www.yourcage.com
0.0.0.0 www.youxika.net
0.0.0.0 www.yqdj.com
0.0.0.0 www.yule21.com
0.0.0.0 www.yun8.com
0.0.0.0 www.yx.fodao.com
0.0.0.0 www.yx07.com
0.0.0.0 www.yxgou.com
0.0.0.0 www.yymp3.com
0.0.0.0 www.yyqy.com
0.0.0.0 www.yysky.net
0.0.0.0 www.yysky.net
0.0.0.0 www.yyue.com
0.0.0.0 www.yzskdj.com
0.0.0.0 www.zgsj.com
0.0.0.0 www.zgxl.net
0.0.0.0 www.zhao114.com
0.0.0.0 www.zhaowo8.com
0.0.0.0 www.zhengdian.com
0.0.0.0 www.zhengdian.comOE #标题栏也没放过
0.0.0.0 www.zhicheng.com
0.0.0.0 www.zj85.com
0.0.0.0 www.zknew.com
0.0.0.0 www1.66036.com
0.0.0.0 www1.cool168.com
0.0.0.0 www1.xfreehosting.com
0.0.0.0 www10.66036.com
0.0.0.0 www2.66036.com
0.0.0.0 www2.7789.com
0.0.0.0 www2.burstnet.com
0.0.0.0 www2.cool168.com
0.0.0.0 www2.movie-down.com
0.0.0.0 www2.xfreehosting.com
0.0.0.0 www3.66036.com
0.0.0.0 www3.7789.com
0.0.0.0 www3.cool168.com
0.0.0.0 www4.66036.com
0.0.0.0 www4.trix.net
0.0.0.0 www5.66036.com
0.0.0.0 www6.66036.com
0.0.0.0 www7.66036.com
0.0.0.0 www8.66036.com
0.0.0.0 www80.valueclick.com
0.0.0.0 www9.66036.com
0.0.0.0 wwww.tthao.com
0.0.0.0 x1.51link.com
0.0.0.0 x2.51link.com
0.0.0.0 xajh.15888.net
0.0.0.0 xmclub.hc3w.net
0.0.0.0 xyqq.185.cc
0.0.0.0 xywaigua.126.com
0.0.0.0 xyxy68.8u8.net
0.0.0.0 xyz8848@jining.info
0.0.0.0 yanexp.html.533.net
0.0.0.0 ye99.com
0.0.0.0 yeapple.com #黄色网站,打开后,你的程序中将加一些你意想不到的东西
0.0.0.0 YES9999.com
0.0.0.0 yinsha.allyes.com
0.0.0.0 you.3322.net
0.0.0.0 youlove.3322.net #有恶意代码的特性外,还夹带病毒:Trojan.Pwdbox.d
0.0.0.0 z.extreme-dm.com
0.0.0.0 z0.extreme-dm.com
0.0.0.0 z1.extreme-dm.com
0.0.0.0 zbszx.vicp.net
0.0.0.0 zhongxuesheng.myrice.com
0.0.0.0 www.369.com #IE劫持

==================================
API HOOK
入口点错误:NtOpenProcess (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:NtTerminateProcess (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:ZwOpenProcess (危险等级: 一般,  被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:ZwTerminateProcess (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:RegOpenKeyExW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:RegDeleteKeyW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:FindFirstFileExW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:FindFirstFileW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)
入口点错误:FindNextFileW (危险等级: 高,  被下面模块所HOOK: C:\WINDOWS\system32\VrvHook.dll)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

贴完了。。日志怎么变得这么长了?难道版本升级了??

HOSTS文件是什么文件??
gototop
 

SRENG-启动项-注册表-删除
<wosa><C:\DOCUME~1\LUCKYS~1\LOCALS~1\Temp\woso.exe> [N/A]
<fysa><C:\DOCUME~1\LUCKYS~1\LOCALS~1\Temp\fyso.exe> [N/A]
<jtsa><C:\DOCUME~1\LUCKYS~1\LOCALS~1\Temp\jtso.exe> [N/A]
<wmsa><C:\DOCUME~1\LUCKYS~1\LOCALS~1\Temp\wmso.exe> [N/A]
<dasa><C:\DOCUME~1\LUCKYS~1\LOCALS~1\Temp\daso.exe> [N/A]
清空C:\DOCUME~1\LUCKYS~1\LOCALS~1\Temp
C:\WINDOWS\system32\vrvhook.dll至于这个,我也不清楚是什么
SRENG-系统修复-重置HOST
gototop
 

谢谢!!马上去弄。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT