[PID: 1964][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2004][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]
[PID: 140][C:\WINDOWS\system32\MsPMSPSv.exe] [Microsoft Corporation, 7.00.00.1954]
[C:\WINDOWS\G_Server123123] [N/A, N/A]
[PID: 212][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3018]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\0C5D07FF.dll] [N/A, N/A]
[C:\WINDOWS\system32\Cnscheck010.dll] [N/A, N/A]
[C:\WINDOWS\system32\cnscheck100.dll] [N/A, N/A]
[C:\WINDOWS\system32\quartz32.dll] [, 4, 1, 0, 0]
[C:\WINDOWS\G_Server12Key.DLL] [N/A, N/A]
[C:\WINDOWS\system32\xydll.dll] [N/A, N/A]
[PID: 220][C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe] [ATI Technologies, Inc., 6.14.10.5142]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\0C5D07FF.dll] [N/A, N/A]
[C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll] [ATI Technologies, Inc., 6.14.10.5142]
[C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.CHS] [ATI Technologies, Inc., 6.14.10.5142]
[C:\Program Files\ATI Technologies\ATI Control Panel\atipdxxx.dll] [ATI Technologies, Inc., 6.14.10.5142]
[C:\WINDOWS\system32\Cnscheck010.dll] [N/A, N/A]
[C:\WINDOWS\system32\cnscheck100.dll] [N/A, N/A]
[C:\WINDOWS\system32\quartz32.dll] [, 4, 1, 0, 0]
[C:\WINDOWS\G_Server12Key.DLL] [N/A, N/A]
[C:\WINDOWS\system32\xydll.dll] [N/A, N/A]
[PID: 252][C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe] [Creative Technology Ltd, 1.4.1.0]
[C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.crl] [Creative Technology Ltd, 1.3.5.0]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\0C5D07FF.dll] [N/A, N/A]
[C:\Program Files\Creative\Shared Files\CTTheme.dll] [Creative Technology Ltd, 2.0.17.0]
[C:\Program Files\Creative\Shared Files\CtrlSrc.dll] [Creative Technology Ltd, 2.0.12.0]
[C:\Program Files\Creative\Shared Files\CTIniF.dll] [Creative Technology Ltd, 1.1.0.0]
[C:\Program Files\Creative\Shared Files\RTXCtrl.skc] [Creative Technology Ltd, 2.0.15.0]
[C:\Program Files\Creative\Shared Files\GDICtrl.skc] [Creative Technology Ltd, 2.0.18.0]
[C:\Program Files\Creative\Shared Files\mxlib.dll] [Creative Technology Ltd., 1.00.0.13]
[C:\WINDOWS\system32\Cnscheck010.dll] [N/A, N/A]
[C:\WINDOWS\system32\cnscheck100.dll] [N/A, N/A]
[C:\WINDOWS\system32\quartz32.dll] [, 4, 1, 0, 0]
[C:\WINDOWS\G_Server12Key.DLL] [N/A, N/A]
[C:\WINDOWS\system32\xydll.dll] [N/A, N/A]
[PID: 308][C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe] [Cyberlink Corp., 5.00.0000]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\0C5D07FF.dll] [N/A, N/A]
[C:\Program Files\CyberLink\Shared Files\CLRCEngine2.dll] [CyberLink Corp., 3.20.0000]
[C:\WINDOWS\system32\Cnscheck010.dll] [N/A, N/A]
[C:\WINDOWS\system32\cnscheck100.dll] [N/A, N/A]
[C:\WINDOWS\system32\quartz32.dll] [, 4, 1, 0, 0]
[C:\WINDOWS\G_Server12Key.DLL] [N/A, N/A]
[C:\WINDOWS\system32\xydll.dll] [N/A, N/A]
[PID: 360][C:\WINDOWS\VM_STI.EXE] [BIGDOG, 4, 2, 610, 4]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\0C5D07FF.dll] [N/A, N/A]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[C:\WINDOWS\system32\Cnscheck010.dll] [N/A, N/A]
[C:\WINDOWS\system32\cnscheck100.dll] [N/A, N/A]
[C:\WINDOWS\system32\quartz32.dll] [, 4, 1, 0, 0]
[C:\WINDOWS\G_Server12Key.DLL] [N/A, N/A]
[C:\WINDOWS\system32\xydll.dll] [N/A, N/A]
[PID: 1332][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\0C5D07FF.dll] [N/A, N/A]
[C:\WINDOWS\system32\cnscheck100.dll] [N/A, N/A]
[C:\WINDOWS\system32\Cnscheck010.dll] [N/A, N/A]
[C:\WINDOWS\system32\quartz32.dll] [, 4, 1, 0, 0]
[C:\WINDOWS\G_Server12Key.DLL] [N/A, N/A]
[C:\WINDOWS\system32\xydll.dll] [N/A, N/A]
[PID: 2804][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\quartz32.dll] [, 4, 1, 0, 0]
[PID: 4036][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\G_Server12Key.DLL] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\0C5D07FF.dll] [N/A, N/A]
[C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll] [www.yok.com, 2.0.1.7]
[C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_013.dll] [Thunder Networking Technologies,LTD, 6, 0, 0, 4]
[C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx] [, 1, 0, 0, 1]
[C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5059.dll] [Microsoft Corporation, 1, 3, 7, 0]
[C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
[D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX] [N/A, N/A]
[c:\program files\google\googletoolbar1.dll] [Google Inc., 3, 0, 131, 0]
[C:\WINDOWS\system32\mskey32.dll] [Microsoft, 1, 0, 0, 1]
[C:\WINDOWS\system32\IEHelper.dll] [N/A, 1, 0, 0, 1]
[C:\WINDOWS\system32\cnscheck100.dll] [N/A, N/A]
[C:\WINDOWS\system32\Cnscheck010.dll] [N/A, N/A]
[C:\WINDOWS\system32\quartz32.dll] [, 4, 1, 0, 0]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\JPWB.IME] [常诚研制, 4.00.950]
[C:\WINDOWS\system32\xydll.dll] [N/A, N/A]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[PID: 3176][C:\jijy1.exe] [N/A, N/A]
[PID: 1508][C:\jijy1.exe] [N/A, N/A]
[C:\WINDOWS\system32\xydll.dll] [N/A, N/A]
[C:\WINDOWS\system32\Cnscheck010.dll] [N/A, N/A]
[C:\WINDOWS\system32\cnscheck100.dll] [N/A, N/A]
[C:\WINDOWS\G_Server12Key.DLL] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\0C5D07FF.dll] [N/A, N/A]
[PID: 3496][C:\DOCUME~1\user\LOCALS~1\Temp\luxrar.exe] [WHITEHOUSE, 1.1.1.0]
[C:\DOCUME~1\user\LOCALS~1\Temp\5zlyxvu9.dll] [N/A, N/A]
[C:\WINDOWS\G_Server12Key.DLL] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\0C5D07FF.dll] [N/A, N/A]
[C:\WINDOWS\system32\quartz32.dll] [, 4, 1, 0, 0]
[C:\DOCUME~1\user\LOCALS~1\Temp\packet.dll] [CACE Technologies, 3, 1, 0, 27]
[C:\DOCUME~1\user\LOCALS~1\Temp\WanPacket.dll] [CACE Technologies, 3, 1, 0, 27]
[C:\WINDOWS\system32\cnscheck100.dll] [N/A, N/A]
[C:\WINDOWS\system32\Cnscheck010.dll] [N/A, N/A]
[C:\WINDOWS\system32\xydll.dll] [N/A, N/A]
[PID: 3580][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\cnscheck100.dll] [N/A, N/A]
[PID: 3000][C:\Documents and Settings\user\桌面\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\WINDOWS\G_Server12Key.DLL] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\0C5D07FF.dll] [N/A, N/A]
[C:\WINDOWS\system32\Cnscheck010.dll] [N/A, N/A]
[C:\WINDOWS\system32\cnscheck100.dll] [N/A, N/A]
[C:\WINDOWS\system32\xydll.dll] [N/A, N/A]
[C:\WINDOWS\system32\quartz32.dll] [, 4, 1, 0, 0]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MSTCPChain Provider
C:\WINDOWS\system32\quartz32.dll(, MFClDLL)
MSTCP Provider
C:\WINDOWS\system32\quartz32.dll(, MFClDLL)
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
61.188.38.64 www.gamezt.com.cn
61.188.38.64 meng.nicemm.cn
61.188.38.64 www.hyap98.com
61.188.38.64 upd.etsoft.com.cn
61.188.38.64 www.essonarts.com
61.188.38.64 ert0003.e76.163ns.com
61.188.38.64 sky001.e11.163ns.com
61.188.38.64 woool.100888290cs.com
61.188.38.64 rxjh.100888290cs.com
61.188.38.64 www.yowoool.com
61.188.38.64 13511.com
61.188.38.64 www.13511.com
61.188.38.64 ywg.cn
==================================