O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.powernum123.com
O1 - Hosts: 127.0.0.1 www.powernum123.com.cn
O1 - Hosts: 127.0.0.1 powernum123.com
O1 - Hosts: 127.0.0.1 powernum123.com.cn
O1 - Hosts: 127.0.0.1 www.chebl.com
O1 - Hosts: 127.0.0.1 www.chebl.cn
O1 - Hosts: 127.0.0.1 www.chebl.com.cn
O1 - Hosts: 127.0.0.1 chebl.com
O1 - Hosts: 127.0.0.1 chebl.com.cn
O1 - Hosts: 127.0.0.1 chebl.cn
O1 - Hosts: 127.0.0.1 www.chebuluo.com.cn
O1 - Hosts: 127.0.0.1 www.chebuluo.com
O1 - Hosts: 127.0.0.1 www.chebuluo.cn
O1 - Hosts: 127.0.0.1 chebuluo.com.cn
O1 - Hosts: 127.0.0.1 chebuluo.com
O1 - Hosts: 127.0.0.1 chebuluo.cn
O1 - Hosts: 127.0.0.1 www.17sp.com
O1 - Hosts: 127.0.0.1 www.17sp.com.cn
O1 - Hosts: 127.0.0.1 17sp.com
O1 - Hosts: 127.0.0.1 17sp.com.cn
O1 - Hosts: 127.0.0.1 www.feikong.com
O1 - Hosts: 127.0.0.1 www.feikong.com.cn
O1 - Hosts: 127.0.0.1 www.feikong.cn
O1 - Hosts: 127.0.0.1 feikong.com
O1 - Hosts: 127.0.0.1 feikong.com.cn
O1 - Hosts: 127.0.0.1 feikong.cn
O1 - Hosts: 127.0.0.1 www.hacong.com
O1 - Hosts: 127.0.0.1 hacong.com
O1 - Hosts: 127.0.0.1 www.xbxb*****com
O1 - Hosts: 127.0.0.1 www.sobt.com
O1 - Hosts: 127.0.0.1 www.sobt.com.cn
O1 - Hosts: 127.0.0.1 www.sobt.cn
O1 - Hosts: 127.0.0.1 www.sobt.net
O1 - Hosts: 127.0.0.1 sobt.com
O1 - Hosts: 127.0.0.1 sobt.com.cn
O1 - Hosts: 127.0.0.1 sobt.cn
O1 - Hosts: 127.0.0.1 sobt.net
O1 - Hosts: 127.0.0.1 www.xbxbxb*****com
O1 - Hosts: 127.0.0.1 xbxb*****com
O1 - Hosts: 127.0.0.1 xbxbxb*****com
O1 - Hosts: 127.0.0.1 www.nfsinfo.com
O1 - Hosts: 127.0.0.1 nfsinfo.com
O1 - Hosts: 127.0.0.1 CRMEASE.COM
O1 - Hosts: 127.0.0.1 HONGBANGZHU.COM
O1 - Hosts: 127.0.0.1 LINUX007.COM
O1 - Hosts: 127.0.0.1 LOSPLE.COM
O1 - Hosts: 127.0.0.1 LOSTEMPLE.COM
O1 - Hosts: 127.0.0.1 www.CRMEASE.COM
O1 - Hosts: 127.0.0.1 www.HONGBANGZHU.COM
O1 - Hosts: 127.0.0.1 www.LINUX007.COM
O1 - Hosts: 127.0.0.1 www.LOSPLE.COM
O1 - Hosts: 127.0.0.1 www.LOSTEMPLE.COM
O1 - Hosts: 127.0.0.1 SMARTALLYES.COM
O1 - Hosts: 127.0.0.1 51CPM.NET
O1 - Hosts: 127.0.0.1 51CPM.COM
O1 - Hosts: 127.0.0.1 YIQILAI.COM
O1 - Hosts: 127.0.0.1 update.smartallyes.com
O1 - Hosts: 127.0.0.1 mdmdmdmdmd.com
O1 - Hosts: 127.0.0.1 www.SMARTALLYES.COM
O1 - Hosts: 127.0.0.1 www.51CPM.NET
O1 - Hosts: 127.0.0.1 www.51CPM.COM
O1 - Hosts: 127.0.0.1 www.YIQILAI.COM
O1 - Hosts: 127.0.0.1 www.mdmdmdmdmd.com
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - (file missing)
O2 - BHO: SafeMe Internet Explorer Helper - {3AE06CEE-58A6-4F5F-AF89-6C5350842F16} - C:\WINDOWS\System32\SafeHelper12.dll
O2 - BHO: ra
Object Class - {46F194EB-B7DB-4B7A-BD42-5FF39FD17664} - C:\PROGRA~1\pcast\hbcast.dll
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O2 - BHO: IEHlpObj Class - {A1A2C6B8-1C34-40E7-B07F-4EC85AC27CF4} - C:\Program Files\Colorwo\Daily.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: - {ACC24EEC-037F-4B88-8D76-45EC1B2E64F1} - C:\WINDOWS\system32\aspaerdev.dll
O2 - BHO: Shockwave Flash
Object - {B88DBC3F-41FB-40AE-AFB0-4220E842B710} - C:\WINDOWS\System32\flash9.dll
O2 - BHO: Webacc Class - {CAC068F3-A608-406B-8581-458788A67694} - C:\WINDOWS\System32\svchost.dll
O2 - BHO: InteSearch - {EBBC6E6D-7B65-46be-B509-86CED2D17876} - C:\WINDOWS\system32\Inte32.dll
O2 - BHO: IEHlpObj Class - {EFBCA345-14DC-4640-994E-4AF1DFDEB4FD} - C:\Program Files\Riptide\Plugin\Plugin.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\kakatool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\CTFMON.EXE
O4 - HKCU\..\Run: [Realplayer.exe] C:\WINDOWS\System32\Realplayer.exe
O4 - HKCU\..\Run: [updatereal] C:\WINDOWS\realupdate.exe other
O4 - HKCU\..\Run: [msnnt] C:\WINDOWS\winampc.exe
O4 - HKCU\..\Run: [svc] C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [realtpsk] C:\WINDOWS\system\realsched.exe
O4 - HKLM\..\Run: [Realplayer.exe] C:\WINDOWS\System32\Realplayer.exe
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDATE2\Update.exe
O4 - HKLM\..\Run: [svc] C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [Daily] C:\Program Files\Colorwo\Daily.exe
O4 - HKLM\..\Run: [RichMedia] C:\WINDOWS\System32\Rundll32.exe "C:\PROGRA~1\pcast\hbcast.dll",WaitWindows
O4 - Startup: desktop.ini =
O4 - Global Startup: desktop.ini =
O8 - Extra context menu item: &_找本网页音视频链接_ - C:\Program Files\Riptide\Plugin\Monitor.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - E:\qq\AddToNetDisk.htm
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\qq\SendMMS.htm
O8 - Extra context menu item: 访问通用网址 - C:\Program Files\CNNIC\Cdn\cnnic.htm
O9 - Extra Button: 酷标 - {1D901067-2529-4A9B-9B6B-7A1DB3A44CB5} - C:\Program Files\coolsign\coolsign.dll
O9 - Extra Button: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra Button: 发现音视频地址 - {CFB84BBD-959B-4fcb-9A03-22ACE091043C} - C:\Program Files\Riptide\Monitor.exe
O9 - Extra 'Tools' menuitem: 发现音视频地址 - {CFB84BBD-959B-4fcb-9A03-22ACE091043C} - C:\Program Files\Riptide\Monitor.exe
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O11 - Options group: [CDNCLIENT] 中文上网
O14 - IERESET.INF: START_PAGE_URL=
about:blank
O16 - DPF: DirectAnimation Java Classes -
file://C:\WINDOWS\Java\classes\dajava.cab
O16 - DPF: {2354A44B-3CEB-4829-9940-545B03103538} (PowerPlr Control) - http://5151c.wz16300.com/plugin/PowerPlr3200.ocx
O16 - DPF: {817C90B5-1688-42BE-9044-58422DB088B2} (PortalCom R01) - http://61.172.97.52/PortalAX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{24FFA503-5F60-4549-99DA-F2EE06E06BDB}: NameServer = 61.153.177.196 61.153.177.198
O18 - Filter : application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll
O18 - Filter : application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll
O18 - Filter : application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\System32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\System32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\System32\msdxm.ocx
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\System32\wiascr.dll
O23 - Service: Ati HotKey Poller (Ati HotKey Poller) - - C:\WINDOWS\System32\ati2evxx.exe
O23 - Service: ATI Smart (ATI Smart) - - C:\WINDOWS\System32\ati2sgag.exe
O23 - Service: Human Interface Device Access (HidServ) - - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: NetMeeting Remote Desktop Agent (Nwsapagent) - LINKMEDIA Tech - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Spectrum24 Events Monitor (IPRIP) - LINKMEDIA Tech - C:\WINDOWS\System32\svchost.exe -k netsvcs
O23 - Service: Windows Install Helper (DATEING) - - C:\WINDOWS\System32\rundll.exe c:\windows\system32\wbem\smtpconfs.dll,export 1087