==================================
正在运行的进程
[PID: 648][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 928][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1000][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1108][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1120][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1328][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1444][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1564][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1660][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1740][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 260][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Media Player Classic\Codecs\mmfinfo.dll] [N/A, N/A]
[C:\Program Files\Media Player Classic\Codecs\mkunicode.dll] [N/A, N/A]
[C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.10.8421]
[C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.10.8421]
[C:\WINDOWS\system32\nvshell.dll] [N/A, N/A]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\CmdLineExt02.dll] [N/A, N/A]
[C:\Program Files\深圳三代\迅雷\ComDlls\XUNLEIBHO_002.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
[PID: 584][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 748][C:\PROGRAM FILES\RISING\RAV\RavStub.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
[C:\PROGRAM FILES\RISING\RAV\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1360][c:\program files\rising\rfw\RfwMain.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 72]
[c:\program files\rising\rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[c:\program files\rising\rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[c:\program files\rising\rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[c:\program files\rising\rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[c:\program files\rising\rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 1700][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.8421]
[PID: 636][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 1820][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 172][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2932][C:\Program Files\深圳三代\迅雷\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5.4.0.226]
[C:\Program Files\深圳三代\迅雷\Program\UpdateDownload.dll] [N/A, N/A]
[C:\Program Files\深圳三代\迅雷\Program\msgmanage.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 15]
[C:\Program Files\深圳三代\迅雷\Program\stlport_vc646.dll] [STLport Consulting, Inc., 4.6.2003.1031]
[C:\Program Files\深圳三代\迅雷\Program\log4cplus.dll] [, 1, 0, 2, 1]
[C:\Program Files\深圳三代\迅雷\Program\historyinfo_manage.dll] [Thunder Networking Technologies,LTD, 5, 2, 0, 148]
[C:\Program Files\深圳三代\迅雷\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 2, 0, 0, 1]
[C:\Program Files\深圳三代\迅雷\Program\asyn_dns.dll] [N/A, N/A]
[C:\Program Files\深圳三代\迅雷\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 1, 0, 18]
[C:\Program Files\深圳三代\迅雷\Program\FloatBar.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\深圳三代\迅雷\Program\iTargetAd.dll] [Thunder Networking Technologies,LTD, 1, 0, 1, 59]
[C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx] [Macromedia, Inc., 8,0,24,0]
[PID: 3824][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[D:\新建文件夹\征途逍遥游v1.1\antiScanner.dll] [N/A, N/A]
[D:\征途\data\zhengtu.dat] [上海征途网络科技有限公司, 1, 0, 0, 1278]
[D:\新建文件夹\征途逍遥游v1.1\antiScanner.dll] [N/A, N/A]
[D:\征途\data\fmodex.dll] [Firelight Technologies, 4.6.5]
[D:\征途\data\weapon.dat] [上海征途网络科技有限公司, 070109]
[D:\新建文件夹\征途逍遥游v1.1\antiScanner.dll] [N/A, N/A]
[PID: 2276][C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE] [Microsoft Corporation, 11.0.5525]
[PID: 2472][\\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 4056][E:\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
==================================
文件关联
.TXT Error. [Notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 LOCALHOST
219.238.233.202 www.ztztzt.com.cn
219.238.233.202 www.blackzl.com
219.238.233.202 www.555125.com
58.218.179.154 www.youxig.com
58.218.179.154 bbs.youxig.com
58.218.179.154 www.ztztzt.com
58.218.179.154 bbs.ztztzt.com
58.218.179.154 ztztzt.com
219.238.233.202 www.loveuc.com
219.238.233.202 www.wowchian.com
219.238.233.202 wowchian.com
219.238.233.202 www.zhengtusf.com
219.238.233.202 zhengtusf.com
219.238.233.202 zhengtu.uuh.cn
219.238.233.202 www.ztgmme.com.cn
219.238.233.202 ztgmme.com.cn
219.238.233.202 www.zt.yn9.cn
219.238.233.202 www.221122.net
219.238.233.202 www.171737.com
219.238.233.202 www.yxcb.com
219.238.233.202 www.zt930.com
219.238.233.202 zt930.com
219.238.233.202 yxcb.com
219.238.233.202 171737.com
219.238.233.202 www.sy5832.com
219.238.233.202 221122.net
219.238.233.202 18dmm.com
219.238.233.202 www.18dmm.com
219.238.233.202 sa.cn
219.238.233.202 1.sa.cn
219.238.233.202 www.2007ip.com
219.238.233.202 2007ip.com
219.238.233.202 56jb.com
219.238.233.202 iloveck.com
219.238.233.202 www.iloveck.com
219.238.233.202 www.5yip.com
219.238.233.202 mmm.caifu18.net
219.238.233.202 d.qbbd.com
219.238.233.202 www.5117music.com
219.238.233.202 www.union123.com
219.238.233.202 www.wu7x.cn
219.238.233.202 www.54699.com
219.238.233.202 60.169.0.66
219.238.233.202 60.169.1.29
219.238.233.202 www.97725.com
219.238.233.202 down.97725.com
219.238.233.202 ip.315hack.com
219.238.233.202 www.baidulink.com
219.238.233.202 do.77276.com
219.238.233.202 www.down.hunll.com
219.238.233.202 www.hunll.com
219.238.233.202 www.9cyy.com
219.238.233.202 www.heixiou.com
219.238.233.202 xulao.com
219.238.233.202 www.41ip.com
219.238.233.202 www1.cw988.cn
219.238.233.202 d.77276.com
219.238.233.202 i.96981.com
219.238.233.202 www.my6688.cn
219.238.233.202 wm.103715.com
219.238.233.202 www.guazhan.cn
219.238.233.202 www.f5game.com
219.238.233.202 222.73.220.45
219.238.233.202 www1.cw988.cn
219.238.233.202 adnx.yygou.cn
219.238.233.202 cool.47555.com
219.238.233.202 www.asdwc.com
219.238.233.202 55880.cn
219.238.233.202 www.5i73.com
219.238.233.202 mir2.5i73.com
==================================
API HOOK
警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
RVA 错误: LoadLibraryA
RVA 错误: LoadLibraryExA
RVA 错误: LoadLibraryExW
RVA 错误: LoadLibraryW
==================================
[/CODE]