瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】高手看看扫描哦【求助】

1   1  /  1  页   跳转

【求助】高手看看扫描哦【求助】

【求助】高手看看扫描哦【求助】

[CODE]

2007-12-08,23:01:08

System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
    进程特权扫描


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <360Safetray><d:\Program Files\360safe\safemon\360tray.exe /start>  [奇虎网]
    <360Antiarp><d:\Program Files\360safe\antiarp\antiarp.exe /start>  [奇虎网]
    <360Safebox><"d:\Program Files\360Safebox\safeboxTray.exe" /r>  [奇虎网]
    <RavTask><"d:\Program Files\Rising\Rav\RavTask.exe" -system>  [(Verified)Beijing Rising Science and Technology Corporation Limited]
    <BigDogPath><C:\WINDOWS\VM_STI.EXE USB PC Camera 301P>  [N/A]
    <NvCplDaemon><; RUNDLL32.EXE NvQTwk,NvCplDaemon initialize>  [N/A]
    <nwiz><; nwiz.exe /installquiet>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [(Verified)Beijing Rising Science and Technology Corporation Limited]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [N/A]

==================================

[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
最后编辑2007-12-09 13:35:04
分享到:
gototop
 

启动文件夹
N/A

==================================
服务
[Contrl Center of Storm Media / ccosm][Running/Auto Start]
  <d:\Program Files\StormII\stormliv.exe /asservice><北京暴风网际科技有限公司>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NVIDIA Driver Helper Service / NVSvc][Stopped/Disabled]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"d:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"D:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>

==================================
驱动程序
[360AntiArp / 360AntiArp][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><奇虎网>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[AliIde / AliIde][Stopped/Disabled]
  <\SystemRoot\System32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
  <System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
[atiide / atiide][Stopped/Disabled]
  <\SystemRoot\system32\DRIVERS\atiide.sys><ATI Technologies Inc.>
[CmdIde / CmdIde][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[Intel(R) PRO Network Connection Driver / E100B][Running/Manual Start]
  <system32\DRIVERS\e100b325.sys><Intel Corporation>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[HookCont / HookCont][Running/System Start]
  <\SystemRoot\system32\drivers\HookCont.sys><Beijing Rising Technology Co., Ltd>
[HookNtos / HookNtos][Running/System Start]
  <\SystemRoot\system32\drivers\HookNtos.sys><Beijing Rising Technology Co., Ltd>
[HookReg / HookReg][Running/System Start]
  <\SystemRoot\system32\drivers\HookReg.sys><Beijing Rising Technology Co., Ltd>
[HookSys / HookSys][Running/System Start]
  <\SystemRoot\system32\drivers\HookSys.sys><Beijing Rising Technology Co., Ltd>
[mv61xx / mv61xx][Stopped/Disabled]
  <\SystemRoot\system32\DRIVERS\mv61xx.sys><Marvell Semiconductor, Inc.>
[WinPcap Packet Driver (NPF) / NPF][Stopped/Manual Start]
  <system32\drivers\NPF.sys><CACE Technologies>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[p2pfilter / p2pfilter][Stopped/Manual Start]
  <\??\D:\Program Files\p2pover\p2pfilter.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
[SafeBoxKrnl / SafeBoxKrnl][Running/System Start]
  <\??\d:\Program Files\360Safebox\SafeBoxKrnl.sys><奇虎网>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[SMC IrCC Miniport Device Driver / SMCIRDA][Running/Manual Start]
  <system32\DRIVERS\smcirda.sys><SMC>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[USB PC Camera 301P / ZSMC301b][Running/Manual Start]
  <System32\Drivers\usbVM31b.sys><VM>

==================================
浏览器加载项
[ThunderAtOnce Class]
  {01443AEC-0FD1-40fd-9C87-E93D1494C233} <d:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <d:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[SafeMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <d:\Program Files\360safe\safemon\safemon.dll, 奇虎网>
[启动迅雷5]
  {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <d:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[ThunderAtOnce Class]
  {01443AEC-0FD1-40FD-9C87-E93D1494C233} <d:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[Thunder Agent Class]
  {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <d:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD>
[XMP Class]
  {6483F145-A768-4C41-AACC-52D4D7845851} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work, >
[XDRM]
  {693571CB-54A3-4E90-9D52-EEAE1334E2D3} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xdrm.dll_1_work, >
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[MediaComm Class]
  {7670648D-461B-42AF-BDFE-46D26AF5EFF2} <d:\Program Files\Thunder Network\Thunder\Components\InMedia\MediaAddin14.dll, Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <d:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[RMGetLicense Class]
  {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation>
[Thunder DapCtrl]
  {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} <d:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DapCtrl1.1.8.11.44.dll, ShenZhen Thunder Networking Technologies Ltd.>
[SafeMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <d:\Program Files\360safe\safemon\safemon.dll, 奇虎网>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
[Thunder DapPlayer]
  {EEDD6FF9-13DE-496B-9A1C-D78B3215E266} <d:\Program Files\Thunder Network\Thunder\Components\DownAndPlay\DapPlayer3.0.39.63.44.dll, ShenZhen Thunder Networking Technologies Ltd.>
[XPPlayer Class]
  {F3E70CEA-956E-49CC-B444-73AFE593AD7F} <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\pplayer.dll_1_work, Thunder>
[使用迅雷下载]
  <d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[使用迅雷下载全部链接]
  <d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>

==================================
gototop
 

正在运行的进程
[PID: 636 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 704 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 728 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 776 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\AppPatch\AcAdProc.dll]  [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
[PID: 788 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 940 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1004 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1144 / SYSTEM][d:\Program Files\Rising\Rav\CCenter.exe]  [Beijing Rising Technology Co., Ltd., 20.0.0.28]
[PID: 1160 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1228 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1348 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1360 / SYSTEM][D:\PROGRAM FILES\RISING\RAV\Ravmond.exe]  [Beijing Rising Technology Co., Ltd., 20.0.0.60]
    [D:\PROGRAM FILES\RISING\RAV\BWList.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.4]
    [C:\WINDOWS\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [D:\PROGRAM FILES\RISING\RAV\RSAPPMGR.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.0]
    [D:\PROGRAM FILES\RISING\RAV\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.10]
    [D:\PROGRAM FILES\RISING\RAV\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.27]
    [D:\PROGRAM FILES\RISING\RAV\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\PROGRAM FILES\RISING\RAV\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\PROGRAM FILES\RISING\RAV\MonRule.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.24]
    [D:\PROGRAM FILES\RISING\RAV\Hooksys.dll]  [Beijing Rising Technology Co., Ltd, 22, 0, 0, 7]
    [D:\PROGRAM FILES\RISING\RAV\HookReg.dll]  [Beijing Rising Technology Co., Ltd, 22, 0, 0, 2]
    [D:\PROGRAM FILES\RISING\RAV\HookNtos.dll]  [Beijing Rising Technology Co., Ltd, 22, 0, 0, 2]
    [D:\PROGRAM FILES\RISING\RAV\rswalmon.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 21]
    [D:\PROGRAM FILES\RISING\RAV\recomp.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [D:\PROGRAM FILES\RISING\RAV\refs.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9]
    [D:\PROGRAM FILES\RISING\RAV\ffr.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9]
    [D:\PROGRAM FILES\RISING\RAV\extfile.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 18]
    [d:\Program Files\Rising\Rav\RsStore.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.8]
    [D:\PROGRAM FILES\RISING\RAV\HookCont.dll]  [Beijing Rising Technology Co., Ltd, 22, 0, 0, 1]
    [d:\Program Files\Rising\Rav\fakescan.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.13]
    [d:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.34]
    [D:\PROGRAM FILES\RISING\RAV\viruslib.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 14]
    [D:\PROGRAM FILES\RISING\RAV\relibldr.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 12]
    [D:\PROGRAM FILES\RISING\RAV\HookWeb.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.2]
    [D:\PROGRAM FILES\RISING\RAV\pearc.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5]
    [D:\PROGRAM FILES\RISING\RAV\nvfile.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
    [D:\PROGRAM FILES\RISING\RAV\scanexec.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 11]
    [D:\PROGRAM FILES\RISING\RAV\unexe.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4]
    [D:\PROGRAM FILES\RISING\RAV\scanex.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 21]
    [D:\PROGRAM FILES\RISING\RAV\scanpack.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5]
    [D:\PROGRAM FILES\RISING\RAV\revm.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 8]
    [D:\PROGRAM FILES\RISING\RAV\uroutine.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 22]
    [D:\PROGRAM FILES\RISING\RAV\scriptci.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 2]
    [D:\PROGRAM FILES\RISING\RAV\scansct.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 6]
gototop
 

[PID: 1728 / lxwjf123][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
    [C:\WINDOWS\system32\WPDShServiceObj.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [D:\Program Files\360safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
    [C:\WINDOWS\system32\PortableDeviceTypes.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1852 / SYSTEM][D:\PROGRAM FILES\RISING\RAV\RavStub.exe]  [Beijing Rising Technology Co., Ltd., 20.0.0.9]
    [D:\PROGRAM FILES\RISING\RAV\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\PROGRAM FILES\RISING\RAV\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
[PID: 1884 / lxwjf123][D:\PROGRAM FILES\RISING\RAV\RavMon.exe]  [Beijing Rising Technology Co., Ltd., 20.0.01.05]
    [C:\WINDOWS\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [D:\PROGRAM FILES\RISING\RAV\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\PROGRAM FILES\RISING\RAV\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [D:\PROGRAM FILES\RISING\RAV\recomp.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [D:\PROGRAM FILES\RISING\RAV\refs.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9]
    [D:\PROGRAM FILES\RISING\RAV\viruslib.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 14]
    [D:\PROGRAM FILES\RISING\RAV\relibldr.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 12]
    [D:\PROGRAM FILES\RISING\RAV\RSAPPMGR.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.0]
    [D:\PROGRAM FILES\RISING\RAV\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.10]
    [D:\PROGRAM FILES\RISING\RAV\MonRule.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.24]
    [D:\PROGRAM FILES\RISING\RAV\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
    [D:\PROGRAM FILES\RISING\RAV\Rsguilib.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 79]
    [D:\PROGRAM FILES\RISING\RAV\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0]
[PID: 1944 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 2012 / lxwjf123][D:\Program Files\360safe\safemon\360tray.exe]  [奇虎网, 3, 6, 4, 3002]
    [D:\Program Files\360safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
    [D:\Program Files\360safe\safemon\SafeKrnl.dll]  [奇虎网, 3, 6, 0, 1001]
    [D:\Program Files\360safe\AntiAdwa.dll]  [360Safe.com, 3, 6, 3, 1001]
    [D:\Program Files\360safe\live.dll]  [360safe.com, 1, 0, 1, 1021]
[PID: 2036 / lxwjf123][D:\Program Files\360safe\antiarp\antiarp.exe]  [奇虎网, 1, 0, 1, 1002]
[PID: 164 / lxwjf123][D:\Program Files\360Safebox\safeboxTray.exe]  [奇虎网, 1, 1, 4, 1001]
    [D:\Program Files\360Safebox\safeboxapi.dll]  [奇虎网, 1, 1, 3, 1002]
    [D:\Program Files\360safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
    [D:\Program Files\360Safebox\liveupdate.dll]  [奇虎网, 1, 1, 3, 1002]
[PID: 216 / lxwjf123][D:\Program Files\Rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 20.0.0.20]
    [D:\Program Files\Rising\Rav\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\Program Files\Rising\Rav\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [D:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 20.0.0.0]
    [D:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.10]
[PID: 228 / lxwjf123][C:\WINDOWS\VM_STI.EXE]  [VM., 4.2.610.4]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\WINDOWS\system32\VM31bPrp.Ax]  [VM, 4.2.711.31]
[PID: 312 / lxwjf123][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 452 / SYSTEM][d:\Program Files\StormII\stormliv.exe]  [北京暴风网际科技有限公司, 3, 7, 11, 26]
    [d:\Program Files\StormII\MSVCP60.dll]  [Microsoft Corporation, 6.02.3104.0]
[PID: 680 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1308 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2512 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2544 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2860 / lx1314000][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
    [C:\WINDOWS\system32\WPDShServiceObj.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\PortableDeviceTypes.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.17]
    [d:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [d:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll]  [, 1, 0, 0, 12]
    [d:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 13]
[PID: 3000 / lx1314000][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3716 / lx1314000][C:\PROGRA~1\MOZILL~1\FIREFOX.EXE]  [Mozilla Corporation, 1.8.1: 2006101023]
    [C:\PROGRA~1\MOZILL~1\js3250.dll]  [Netscape Communications Corporation, 4.0]
    [C:\PROGRA~1\MOZILL~1\nspr4.dll]  [Netscape Communications Corporation, 4.6.3]
    [C:\PROGRA~1\MOZILL~1\xpcom_core.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [C:\PROGRA~1\MOZILL~1\plc4.dll]  [Netscape Communications Corporation, 4.6.3]
    [C:\PROGRA~1\MOZILL~1\plds4.dll]  [Netscape Communications Corporation, 4.6.3]
    [C:\PROGRA~1\MOZILL~1\smime3.dll]  [Mozilla Foundation, 3.11.3 Basic ECC]
    [C:\PROGRA~1\MOZILL~1\nss3.dll]  [Mozilla Foundation, 3.11.3 Basic ECC]
    [C:\PROGRA~1\MOZILL~1\softokn3.dll]  [Mozilla Foundation, 3.11.3 Basic ECC]
    [C:\PROGRA~1\MOZILL~1\ssl3.dll]  [Mozilla Foundation, 3.11.3 Basic ECC]
    [C:\PROGRA~1\MOZILL~1\xpcom_compat.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [D:\Program Files\360safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
    [C:\PROGRA~1\MOZILL~1\components\jar50.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [C:\PROGRA~1\MOZILL~1\components\jsd3250.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [C:\PROGRA~1\MOZILL~1\components\myspell.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [C:\PROGRA~1\MOZILL~1\components\spellchk.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [C:\PROGRA~1\MOZILL~1\components\xpinstal.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [C:\PROGRA~1\MOZILL~1\components\ThunderComponent.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 8]
    [C:\PROGRA~1\MOZILL~1\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metrics.dll]  [N/A, ]
    [C:\PROGRA~1\MOZILL~1\xpcom.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [C:\PROGRA~1\MOZILL~1\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll]  [N/A, ]
    [C:\PROGRA~1\MOZILL~1\freebl3.dll]  [Mozilla Foundation, 3.11.3 Basic ECC]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2500 / lx1314000][D:\Program Files\Rising\Rav\Rav.exe]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 54]
    [D:\Program Files\Rising\Rav\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\Program Files\Rising\Rav\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\Program Files\Rising\Rav\Rsguilib.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 79]
    [C:\WINDOWS\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [D:\Program Files\Rising\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0]
    [D:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
    [D:\Program Files\Rising\Rav\RsCommon.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [D:\Program Files\Rising\Rav\ravpagem.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.73]
    [D:\Program Files\Rising\Rav\htmllib.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.14]
    [D:\Program Files\Rising\Rav\ravpagew.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 1, 73]
    [D:\Program Files\Rising\Rav\RSAPPMGR.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.0]
    [D:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.10]
    [D:\Program Files\Rising\Rav\fakescan.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.13]
    [D:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.34]
    [D:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.4]
    [D:\Program Files\Rising\Rav\recomp.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [D:\Program Files\Rising\Rav\refs.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9]
    [D:\Program Files\Rising\Rav\viruslib.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 14]
gototop
 

[D:\Program Files\Rising\Rav\SysMail.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.10]
    [D:\Program Files\Rising\Rav\relibldr.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 12]
    [D:\Program Files\Rising\Rav\mvengine.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4]
    [D:\Program Files\Rising\Rav\posttrt.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 8]
    [D:\Program Files\Rising\Rav\ffr.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9]
    [D:\Program Files\Rising\Rav\nvfile.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
    [D:\Program Files\Rising\Rav\scanexec.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 11]
    [D:\Program Files\Rising\Rav\unexe.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 4]
    [D:\Program Files\Rising\Rav\scanex.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 21]
    [D:\Program Files\Rising\Rav\pearc.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5]
    [D:\Program Files\Rising\Rav\extfile.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 18]
    [D:\Program Files\Rising\Rav\extole.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5]
    [D:\Program Files\Rising\Rav\scansct.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 6]
    [D:\Program Files\Rising\Rav\extmail.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9]
    [D:\Program Files\Rising\Rav\scanpack.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 5]
    [D:\Program Files\Rising\Rav\revm.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 8]
    [D:\Program Files\Rising\Rav\uroutine.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 22]
    [D:\Program Files\Rising\Rav\scriptci.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 2]
    [D:\Program Files\Rising\Rav\scanmac.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 6]
[PID: 956 / lx1314000][D:\Program Files\Rising\Rav\RavMon.exe]  [Beijing Rising Technology Co., Ltd., 20.0.01.05]
    [C:\WINDOWS\system32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [D:\Program Files\Rising\Rav\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\Program Files\Rising\Rav\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [D:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [D:\Program Files\Rising\Rav\recomp.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [D:\Program Files\Rising\Rav\refs.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 9]
    [D:\Program Files\Rising\Rav\viruslib.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 14]
    [D:\Program Files\Rising\Rav\relibldr.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 12]
    [D:\Program Files\Rising\Rav\RSAPPMGR.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.0]
    [D:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.10]
    [D:\Program Files\Rising\Rav\MonRule.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.24]
    [D:\Program Files\Rising\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
    [D:\Program Files\Rising\Rav\Rsguilib.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 79]
    [D:\Program Files\Rising\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 0]
[PID: 2148 / lx1314000][D:\Downloads\软件\病毒\sreng-v2.5\sreng-v2.5\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [D:\Downloads\软件\病毒\sreng-v2.5\sreng-v2.5\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
[PID: 1140 / lx1314000][C:\PROGRA~1\MOZILL~1\FIREFOX.EXE]  [Mozilla Corporation, 1.8.1: 2006101023]
    [C:\PROGRA~1\MOZILL~1\js3250.dll]  [Netscape Communications Corporation, 4.0]
    [C:\PROGRA~1\MOZILL~1\nspr4.dll]  [Netscape Communications Corporation, 4.6.3]
    [C:\PROGRA~1\MOZILL~1\xpcom_core.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [C:\PROGRA~1\MOZILL~1\plc4.dll]  [Netscape Communications Corporation, 4.6.3]
    [C:\PROGRA~1\MOZILL~1\plds4.dll]  [Netscape Communications Corporation, 4.6.3]
    [C:\PROGRA~1\MOZILL~1\smime3.dll]  [Mozilla Foundation, 3.11.3 Basic ECC]
    [C:\PROGRA~1\MOZILL~1\nss3.dll]  [Mozilla Foundation, 3.11.3 Basic ECC]
    [C:\PROGRA~1\MOZILL~1\softokn3.dll]  [Mozilla Foundation, 3.11.3 Basic ECC]
    [C:\PROGRA~1\MOZILL~1\ssl3.dll]  [Mozilla Foundation, 3.11.3 Basic ECC]
    [C:\PROGRA~1\MOZILL~1\xpcom_compat.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [C:\PROGRA~1\MOZILL~1\components\myspell.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [C:\PROGRA~1\MOZILL~1\components\jar50.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [C:\PROGRA~1\MOZILL~1\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metrics.dll]  [N/A, ]
    [C:\PROGRA~1\MOZILL~1\xpcom.dll]  [Mozilla Foundation, 1.8.1: 2006101023]
    [C:\PROGRA~1\MOZILL~1\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll]  [N/A, ]
    [C:\PROGRA~1\MOZILL~1\freebl3.dll]  [Mozilla Foundation, 3.11.3 Basic ECC]
    [C:\PROGRA~1\MOZILL~1\components\spellchk.dll]  [Mozilla Foundation, 1.8.1: 2006101023]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A
gototop
 

==================================
HOSTS 文件
***********************************
《电脑报》黑榜(R)恶意网址屏蔽文件
版本号:2007.11.12
***********************************
127.0.0.1 localhost
127.0.0.1 www.zzzz1.com
127.0.0.1 zzzz1.com
127.0.0.1 www.baidu345.com
127.0.0.1 baidu345.com
127.0.0.1 www.ttsou.cn
127.0.0.1 ttsou.cn
127.0.0.1 www.zhaomeimei.cn
127.0.0.1 www.511u.com
127.0.0.1 www.37698.com
127.0.0.1 37698.com
127.0.0.1 www.2345.com
127.0.0.1 2345.com
127.0.0.1 www.hk0707.com
127.0.0.1 www.hk0909.com
127.0.0.1 www2.99vod.net
127.0.0.1 www.99vod.net
127.0.0.1 www.51mxd.com
127.0.0.1 www.meizi7472831.com
127.0.0.1 www.game929.com
127.0.0.1 www.91d2d.com
127.0.0.1 91d2d.com
127.0.0.1 www.flydown.net
127.0.0.1 flydown.net
127.0.0.1 www.wangxiangad.com
127.0.0.1 music.wangxiangad.com
127.0.0.1 www.91d2d.com
127.0.0.1 www.59552.com
127.0.0.1 qq.59552.com
127.0.0.1 2007.5ixp.com
127.0.0.1 www.lmaq.com
127.0.0.1 lmaq.com
127.0.0.1 www.3yyy.cn
127.0.0.1 old.3yyy.cn
127.0.0.1 www.kkpic.net
127.0.0.1 kkpic.net
127.0.0.1 www.habao.net
127.0.0.1 habao.net
127.0.0.1 www.sms591.com
127.0.0.1 www.sms591.net
127.0.0.1 www.kx99.cn
127.0.0.1 www.odwy.com
127.0.0.1 www.99mmm.com
127.0.0.1 www.sqqd.com
127.0.0.1 www.sqqd.net
127.0.0.1 www.6781.com
127.0.0.1 www.dj015.com
127.0.0.1 www.mtvrm.com
127.0.0.1 a.d3a.us
127.0.0.1 www.69262.com
127.0.0.1 www.an188.com
127.0.0.1 www.bobcn.net
127.0.0.1 www.pkzz.net
127.0.0.1 www.pkzz.net
127.0.0.1 www.jily.net
127.0.0.1 jily.net
127.0.0.1 cn.errorsafe.com
127.0.0.1 www.errorsafe.com
127.0.0.1 www.1717kan.cn
127.0.0.1 www.verycr.com
127.0.0.1 verycr.com
127.0.0.1 www.82wg.com
127.0.0.1 www.kuaiso.com
127.0.0.1 www.64xz.com
127.0.0.1 64xz.com
127.0.0.1 www.newok.com
127.0.0.1 www.top000.com
127.0.0.1 top000.com
127.0.0.1 www.tianmp3.cn
127.0.0.1 tianmp3.cn
127.0.0.1 www.59552.com
127.0.0.1 59552.com
127.0.0.1 www.xf520.cn
127.0.0.1 www.ysbr.cn
127.0.0.1 www.lvrzj.com
127.0.0.1 lvrzj.com
127.0.0.1 www.toxx.info
127.0.0.1 www.11990.com
127.0.0.1 www.xzqx88.com
127.0.0.1 xzqx88.com
127.0.0.1 11990.com
127.0.0.1 www.qbbd.com
127.0.0.1 w.qbbd.com
127.0.0.1 www.wuyeav.com
127.0.0.1 wuyeav.com
127.0.0.1 www.87895.com
127.0.0.1 87895.com
127.0.0.1 www.henbang.net
127.0.0.1 files.henbang.net
127.0.0.1 www.yayalao.com
127.0.0.1 yayalao.com
127.0.0.1 yxgm78.com
127.0.0.1 www.88888888888888888888888888888888888888888888888888.com
127.0.0.1 www.50-8.com
127.0.0.1 www.50ge8.com
127.0.0.1 www.klyx8.com
127.0.0.1 klyx8.com
127.0.0.1 www.53yes.com
127.0.0.1 www.jk1001.com
127.0.0.1 4255.biz
127.0.0.1 www.zhaoxl.cn
127.0.0.1 zhaoxl.cn
127.0.0.1 www.0hu.net
127.0.0.1 0hu.net
127.0.0.1 www.pic00.com
127.0.0.1 pic00.com
127.0.0.1 www.17xxz.com
127.0.0.1 17xxz.com
127.0.0.1 www.900666.com
127.0.0.1 pp.900666.com
127.0.0.1 www.jetdown.com
127.0.0.1 jetdown.com
127.0.0.1 7y7.us
127.0.0.1 12rr.com
127.0.0.1 www.12rr.com
127.0.0.1 www.ycdy.com
127.0.0.1 ycdy.com
127.0.0.1 www.zqqa.com
127.0.0.1 zqqa.com
127.0.0.1 www.zpx520.com
127.0.0.1 zpx520.com
127.0.0.1 12706.com
127.0.0.1 down.12706.com
127.0.0.1 www.12706.com
127.0.0.1 www.xrlyy.com
127.0.0.1 xrlyy.com
127.0.0.1 laji.xrlyy.com
127.0.0.1 www.51meinv.cn
127.0.0.1 16a.us
127.0.0.1 www.n85853.cn
127.0.0.1 n85853.cn
127.0.0.1 www.chenxinsms.com
127.0.0.1 chenxinsms.com
127.0.0.1 www.1cdzx.cn
127.0.0.1 1cdzx.cn
127.0.0.1 www.1008y.cn
127.0.0.1 1008y.cn
127.0.0.1 www.18dmm.com
127.0.0.1 18dmm.com
127.0.0.1 www.08325.cn
127.0.0.1 08325.cn
127.0.0.1 www.vchome.net
127.0.0.1 vchome.net
127.0.0.1 www.hsstone.net
127.0.0.1 mp3.hsstone.net
127.0.0.1 hsstone.net
127.0.0.1 5y5.us
127.0.0.1 www.yyor.com
127.0.0.1 yyor.com
127.0.0.1 www.wvyi.com
127.0.0.1 wvyi.com
127.0.0.1 s.gcuj.com
127.0.0.1 www.gcuj.com
127.0.0.1 gcuj.com
127.0.0.1 www.hyap98.com
127.0.0.1 www.126621.com
127.0.0.1 126621.com
127.0.0.1 www.if56.cn
127.0.0.1 if56.cn
127.0.0.1 www.453888.com
127.0.0.1 www.uu500.com
127.0.0.1 uu500.com
127.0.0.1 www.money-you.cn
127.0.0.1 money-you.cn
127.0.0.1 9166.biz
127.0.0.1 www.2cdma.cn
127.0.0.1 2cdma.cn
127.0.0.1 www.jygame88.com
127.0.0.1 y66.us
127.0.0.1 www.qinlo.com
127.0.0.1 qinlo.com
127.0.0.1 1234.89111.cn
127.0.0.1 www.1234ya.com
127.0.0.1 1234ya.com
127.0.0.1 Ttwd.net
127.0.0.1 www.Ttwd.net
127.0.0.1 www.level-qq.cn
127.0.0.1 level-qq.cn
127.0.0.1 www.36xp.com
127.0.0.1 36xp.com
127.0.0.1 3.36xp.com
127.0.0.1 www.puma163.com
127.0.0.1 puma163.com
127.0.0.1 www.11sss.com
127.0.0.1 11sss.com
127.0.0.1 www.mty366.com
127.0.0.1 mty366.com
127.0.0.1 www.kaspersky7.com.cn
127.0.0.1 kaspersky7.com.cn
127.0.0.1 boolom.com
127.0.0.1 www.sl952571.cn
127.0.0.1 sl952571.cn
127.0.0.1 878772.cn
127.0.0.1 www.878772.cn
127.0.0.1 www.44xp.com
127.0.0.1 44xp.com
127.0.0.1 a.44xp.com
127.0.0.1 b.44xp.com
127.0.0.1 c.44xp.com
127.0.0.1 d.44xp.com
127.0.0.1 3.11xp.com
127.0.0.1 www.virusprotectpro.com
127.0.0.1 virusprotectpro.com
127.0.0.1 ck1.in
127.0.0.1 xyaq163.cn
127.0.0.1 1111.845845.cn
127.0.0.1 www.8749.com
127.0.0.1 8749.com
127.0.0.1 yinlew.com
127.0.0.1 up.yinlew.com
127.0.0.1 www.edqb.com
127.0.0.1 6658588.cn
127.0.0.1 a.11sss.com
127.0.0.1 www.11sss.com
127.0.0.1 iv1qq.cn
127.0.0.1 www.xlzyxz.cn
127.0.0.1 xlzyxz.cn
127.0.0.1 www.832821.cn
127.0.0.1 832821.cn
127.0.0.1 www.digiall.cn
127.0.0.1 digiall.cn
127.0.0.1 new.flywings.cn
127.0.0.1 www.flywings.cn
127.0.0.1 www.qqqsss.com
127.0.0.1 www.17xzb.com
127.0.0.1 17xzb.com
127.0.0.1 aaa.369678.cn
127.0.0.1 www.qqqqqqqqqqqqqqqqqqqqqqqqqqqqqq.com
127.0.0.1 qqqqqqqqqqqqqqqqqqqqqqqqqqqqqq.com
127.0.0.1 www.9991818.com
127.0.0.1 9991818.com
127.0.0.1 xx.wzxqy.com
127.0.0.1 wzxqy.com
127.0.0.1 md55.net
127.0.0.1 www.md55.net
127.0.0.1 www1.winopen.cn
127.0.0.1 winopen.cn
127.0.0.1 www.winopen.cn
127.0.0.1 www.baibaoxiang.cn
127.0.0.1 baibaoxiang.cn
127.0.0.1 www.tql2l.com
127.0.0.1 tql2l.com
127.0.0.1 www.f1ash512.com
127.0.0.1 f1ash512.com
127.0.0.1 www.b1ueidea.com
127.0.0.1 www.b1ueidea.com
127.0.0.1 b1ueidea.com
127.0.0.1 ip.8dunet.com
127.0.0.1 8dunet.com
127.0.0.1 325604.com
127.0.0.1 www.325604.com
127.0.0.1 www.kkwyx.com
127.0.0.1 www.mtsou.com
127.0.0.1 www.zuola.net
127.0.0.1 zuola.net
127.0.0.1 so.klyx8.com
127.0.0.1 www.kkwyx.com
127.0.0.1 smallt.vicp.cc
127.0.0.1 www.zhaowoooool.com
127.0.0.1 wb900.com
127.0.0.1 www.wb900.com
127.0.0.1 s.wb900.com
127.0.0.1 mm.987999.com
127.0.0.1 987999.com
127.0.0.1 www.987999.com
127.0.0.1 www.lwktbg.cn
127.0.0.1 lwktbg.cn
127.0.0.1 www.blyee.cn
127.0.0.1 blyee.cn
127.0.0.1 www.98307.com
127.0.0.1 98307.com
127.0.0.1 www.digtlera.com
127.0.0.1 www.88889999.info
127.0.0.1 88889999.info
127.0.0.1 rrr.rfhwfhw.com
127.0.0.1 www.55dj.net
127.0.0.1 55dj.net
127.0.0.1 www.souxse.cn
127.0.0.1 cc.wzxqy.com
127.0.0.1 cool.47555.com
127.0.0.1 web.21575.com
127.0.0.1 www.qqtx.cn
127.0.0.1 www.loveqq8.com
127.0.0.1 soft.yqdown.com
127.0.0.1 www.yqdown.com
127.0.0.1 yqdown.com
127.0.0.1 www.grendown.cn
127.0.0.1 www.k333.cn
127.0.0.1 k333.cn
127.0.0.1 movie.yl0708.cn
127.0.0.1 welcome.aeeboo.com
127.0.0.1 www.qqcom.net.cn
127.0.0.1 web.123563.com
127.0.0.1 ora.3168a.com
127.0.0.1 123.blog5460.com.cn
127.0.0.1 www.851733.cn
127.0.0.1 xxcom.cn
127.0.0.1 www.uhq.cn
127.0.0.1 uhq.cn
127.0.0.1 vip.my.qq.com.qqncn.cn
127.0.0.1 www.161816.com
127.0.0.1 www.121161.com
127.0.0.1 9.11xp.com
127.0.0.1 22kao.com
127.0.0.1 5.22kao.com
127.0.0.1 www.22kao.com
127.0.0.1 15gan.com
127.0.0.1 www.15gan.com
127.0.0.1 3.15gan.com
127.0.0.1 5.15gan.com
127.0.0.1 9.15gan.com
127.0.0.1 www.520018.com
127.0.0.1 www.11se.com
127.0.0.1 z.11se.com
127.0.0.1 cc.wzxqy.com
127.0.0.1 www.debae.cn
127.0.0.1 www.520018.com
127.0.0.1 down.dj7788.cn
127.0.0.1 www.safewebnavigate.com
127.0.0.1 virusprotectionproonline.com
127.0.0.1 q.103829.com
127.0.0.1 q.1030829.com
127.0.0.1 www.antivirgear.com
127.0.0.1 antivirgear.com
127.0.0.1 www.mukks.cn
127.0.0.1 www.asvcfr.com.cn
127.0.0.1 asvcfr.com.cn
127.0.0.1 ad.jud1l.com
127.0.0.1 777.za123.cn
127.0.0.1 music.mukks.cn
127.0.0.1 www.eqifa.com
127.0.0.1 eqifa.com
127.0.0.1 book.uubks.cn
127.0.0.1 mb.wzxqy.com
127.0.0.1 www.yoowan.com
127.0.0.1 www.mydirvers.net
127.0.0.1 mydirvers.net
127.0.0.1 mlcro-soft.cn
127.0.0.1 m.w2op.cn
127.0.0.1 www.puma166.com
127.0.0.1 xx.9365.org
127.0.0.1 qq4.web9.bootchina.com
127.0.0.1 www.avonshop.cn
127.0.0.1 avonshop.cn
127.0.0.1 88.hoo88.cn
127.0.0.1 www.hoo88.cn
127.0.0.1 xx.522love.cn
127.0.0.1 news.chinaons.net
127.0.0.1 net.hao234.org
127.0.0.1 www.hao234.org
127.0.0.1 sj-qq.cn
127.0.0.1 www.sj-qq.cn
127.0.0.1 www.geself.com
127.0.0.1 geself.com
127.0.0.1 366ip.com
127.0.0.1 www.366ip.com
127.0.0.1 xx.520sqwyt.com
127.0.0.1 520sqwyt.com
127.0.0.1 www.asinatop.com
127.0.0.1 asinatop.com
127.0.0.1 55sss.com
127.0.0.1 1.55sss.com
127.0.0.1 2.55sss.com
127.0.0.1 3.55sss.com
127.0.0.1 4.55sss.com
127.0.0.1 www.55sss.com
127.0.0.1 www.52q-q.cn
127.0.0.1 52q-q.cn
127.0.0.1 www.bpwmrh.cn
127.0.0.1 bpwmrh.cn
127.0.0.1 xxx.cslr1.com
127.0.0.1 zzz.cslr1.com
127.0.0.1 www.baiwanll.cn
127.0.0.1 www.yzxia.cn
127.0.0.1 yzxia.cn
127.0.0.1 avddd.com
127.0.0.1 www.avddd.com
127.0.0.1 15197.com
127.0.0.1 www.15197.com
127.0.0.1 count.16.vg
gototop
 

127.0.0.1 16.vg
127.0.0.1 www.16.vg
127.0.0.1 mayisf.com
127.0.0.1 www.mayisf.com
127.0.0.1 ho.884579.cn
127.0.0.1 www.884579.cn
127.0.0.1 thesafetyfiles.com
127.0.0.1 www.thesafetyfiles.com
127.0.0.1 www.321soo.cn
127.0.0.1 so.321soo.cn
127.0.0.1 www.smsunionmm.com
127.0.0.1 11se.37yin.cn
127.0.0.1 ad.s3rt8.com
127.0.0.1 news.hook163.com
127.0.0.1 ao.98bb.in
127.0.0.1 www.xxxmmm.net
127.0.0.1 www.84730.cn
127.0.0.1 a.228xx.com
127.0.0.1 b.228xx.com
127.0.0.1 c.228xx.com
127.0.0.1 d.228xx.com
127.0.0.1 e.228xx.com
127.0.0.1 o1.o1wy.com
127.0.0.1 jj.smmbbs.com
127.0.0.1 a.17xmm.com
127.0.0.1 b.17xmm.com
127.0.0.1 c.17xmm.com
127.0.0.1 d.17xmm.com
127.0.0.1 e.17xmm.com
127.0.0.1 f.17xmm.com
127.0.0.1 g.17xmm.Com
127.0.0.1 b.55qs55.cn
127.0.0.1 a.55qs55.cn
127.0.0.1 abc.djxcn.com
127.0.0.1 2.13yin.com
127.0.0.1 1.13yin.com
127.0.0.1 5.hhwyt.cn
127.0.0.1 eee.jopenqc.com
127.0.0.1 link99.in
127.0.0.1 1.saosese.cn
127.0.0.1 2.saosese.cn
127.0.0.1 1.lv19.com
127.0.0.1 2.lv19.com
127.0.0.1 f.41xn.com
127.0.0.1 cao1.92rb.com
127.0.0.1 qq1.moyu.com
127.0.0.1 sood.cn
127.0.0.1 www.sood.cn
127.0.0.1 pop.yoyo59.com
127.0.0.1 tbzp.com
127.0.0.1 qqq.aishengho.com
127.0.0.1 040828.gxtupian.cn
127.0.0.1 11ri.com
127.0.0.1 1.11ri.com
127.0.0.1 2.11ri.com
127.0.0.1 3.11ri.com
127.0.0.1 4.11ri.com
127.0.0.1 5.11ri.com
127.0.0.1 6.11ri.com
127.0.0.1 7.11ri.com
127.0.0.1 8.11ri.com
127.0.0.1 9.11ri.com
127.0.0.1 10.11ri.com
127.0.0.1 a.11ri.com
127.0.0.1 b.11ri.com
127.0.0.1 c.11ri.com
127.0.0.1 d.11ri.com
127.0.0.1 e.11ri.com
127.0.0.1 www.11ri.com
127.0.0.1 1.sexzzz.net
127.0.0.1 2.sexzzz.net
127.0.0.1 a.sexzzz.net
127.0.0.1 b.sexzzz.net
127.0.0.1 c.sexzzz.net
127.0.0.1 www.qqv99.cn
127.0.0.1 chat.selang.cc
127.0.0.1 chat1.selang.cc
127.0.0.1 chat2.selang.cc
127.0.0.1 chat3.selang.cc
127.0.0.1 selang.cc
127.0.0.1 yourprivacyguard.com
127.0.0.1 www.yourprivacyguard.com
127.0.0.1 bw321.com
127.0.0.1 www.bw321.com
127.0.0.1 xiaoshuoxz.com
127.0.0.1 www.xiaoshuoxz.com
127.0.0.1 www.any2000.com
127.0.0.1 3.77bbb.com
127.0.0.1 1.77bbb.com
127.0.0.1 77bbb.com
127.0.0.1 www.77bbb.com
127.0.0.1 pic.16.vg
127.0.0.1 www.zhanzt.com
127.0.0.1 zhanzt.com
127.0.0.1 www.petqqa.com.cn
127.0.0.1 petqqa.com.cn
127.0.0.1 www.ip540.com
127.0.0.1 1.ddddx.com
127.0.0.1 2.ddddx.com
127.0.0.1 c.sisbbs.com
127.0.0.1 www.mimibbs.com
127.0.0.1 aa.tygzs.cn
127.0.0.1 downs12.tygzs.cn
127.0.0.1 www.kshou.com
127.0.0.1 xuxianren.com
127.0.0.1 www.xuxianren.com
127.0.0.1 www.jk007.com
127.0.0.1 jk007.com
127.0.0.1 www.acnow.net
127.0.0.1 aaa.520ping.com
127.0.0.1 boc.sbb22.com
127.0.0.1 bbb.mm5208.com
127.0.0.1 mat.jqxx.org
127.0.0.1 www.ip530.com
127.0.0.1 ip530.com
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1
127.0.0.1

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 728, C:\WINDOWS\SYSTEM32\WINLOGON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3716, C:\PROGRA~1\MOZILL~1\FIREFOX.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1140, C:\PROGRA~1\MOZILL~1\FIREFOX.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

HOSTS 文件
127.0.0.1 localhost
只留这一项其余的全部删除!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT