e:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
d:\program files\rising\rfw\RfwMain.exe
E:\Program Files\Rising\Rav\RavTask.exe
E:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Baidu\Disk Search\BaiduDiskSearch.exe
D:\Program Files\Baidu\Disk Search\BaiduCrawl.exe
E:\Program Files\Tencent\QQ\TIMPlatform.exe
E:\Program Files\Tencent\QQ\QQ.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Super Rabbit\MagicSet\MagicSet.exe
D:\Program Files\Super Rabbit\MagicSet\magicset.exe
D:\Program Files\Super Rabbit\MagicSet\winspeed.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\hijavk\HijackThis1991zww.exe
R3 - URLSearchHook: (no name) - {7B585076-5984-4CAE-8E9B-89B245039E8E} - C:\WINDOWS\system32\Hbptj.dll
R3 - URLSearchHook: (no name) - {6563410B-61D5-4A82-B874-809269E731A6} - C:\WINDOWS\system32\Yxeem.dll
O2 - BHO: (no name) - {0688E67C-3F0B-43F6-B4AC-7DDADDA8C2D4} - C:\WINDOWS\system32\Xxgbmr.dll
O2 - BHO: Tencent Browser Helper - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\WINDOWS\Downloaded Program Files\Gqvp.dll (file missing)
O2 - BHO: (no name) - {13B0DA6E-AE8E-498A-8764-382C0B4DE94B} - C:\WINDOWS\system32\Cfoz.dll
O2 - BHO: (no name) - {174D0619-4007-40A2-8B89-7902FEDA25F5} - C:\WINDOWS\system32\Seook.dll
O2 - BHO: (no name) - {22AFE242-B75D-4D05-8440-FE3B2B54BBFB} - C:\WINDOWS\system32\Oazi.dll
O2 - BHO: (no name) - {2E1EB812-DC74-4BF4-8E2C-4C4B923D0A7E} - C:\WINDOWS\system32\Uxeaji.dll
O2 - BHO: (no name) - {2FDB344F-CFD4-44BB-80B5-20E924D112B4} - C:\WINDOWS\system32\Grtfpn.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll
O2 - BHO: (no name) - {3BE44F26-7D58-4B50-A0EB-FF1C648AC54D} - C:\WINDOWS\system32\Vljat.dll
O2 - BHO: (no name) - {3ED0064A-90F2-4242-BD46-6BFC8CE2BDBB} - C:\WINDOWS\system32\Wbco.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O2 - BHO: (no name) - {46184AB7-E4A1-4A4A-95ED-F3D511E21BFC} - C:\WINDOWS\system32\Igwfay.dll
O2 - BHO: (no name) - {48531636-F202-4899-948D-F26CFE2DB677} - C:\WINDOWS\system32\Bmwtz.dll
O2 - BHO: (no name) - {4C9BC1EF-4542-4956-A6FC-EFF67954C9B2} - C:\WINDOWS\system32\Tmfe.dll
O2 - BHO: (no name) - {4D26A06E-8D40-4CE4-ACD3-83A4472BE425} - C:\WINDOWS\system32\Fyxfav.dll
O2 - BHO: (no name) - {4D38B72F-4558-4247-80CA-3E65EE9CA036} - C:\WINDOWS\system32\Pjqj.dll
O2 - BHO: (no name) - {51E1A5AA-4FD3-42DB-9472-55810952E889} - C:\WINDOWS\system32\Fari.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - E:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O2 - BHO: (no name) - {56AF5DE4-7811-4497-916A-265CF93A8092} - C:\WINDOWS\system32\Wiuoy.dll
O2 - BHO: (no name) - {5A95F580-A9BF-4791-8533-7F21BF3A4D01} - C:\WINDOWS\system32\Tzcsbw.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\Program Files\Yahoo!\Assistant\Assist\YDragSearch.dll
O2 - BHO: (no name) - {6563410B-61D5-4A82-B874-809269E731A6} - C:\WINDOWS\system32\Yxeem.dll
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - (no file)
O2 - BHO: IeCapture Class - {67B6599D-1ACF-4EA9-9EAB-578DF0FE6F78} - C:\Program Files\Common Files\Baidu\Disk Search\dsie.dll (file missing)
O2 - BHO: (no name) - {74B75CDE-A1CA-4C19-B078-1DF64C60C991} - C:\WINDOWS\system32\Dtmqkp.dll
O2 - BHO: (no name) - {75694FF9-47BF-42F8-8E9A-35ABCF5542C4} - C:\WINDOWS\system32\Gjin.dll
O2 - BHO: (no name) - {7A67A513-187B-4420-9B84-09F24256EE81} - C:\WINDOWS\system32\Ojtz.dll
O2 - BHO: (no name) - {7B585076-5984-4CAE-8E9B-89B245039E8E} - C:\WINDOWS\system32\Hbptj.dll
O2 - BHO: (no name) - {7DF89808-DC5A-43B4-842C-F07B2EC7C8CC} - C:\WINDOWS\system32\Iaprw.dll
O2 - BHO: (no name) - {8A71FCAD-34BD-4750-9DB8-1C7BE5471EE4} - C:\WINDOWS\system32\Twkd.dll
O2 - BHO: (no name) - {8E56819C-330B-4847-B164-9499DE86E705} - C:\WINDOWS\system32\Nknrv.dll
O2 - BHO: (no name) - {910BE5C5-9880-45FD-AAAE-FA867D5667A3} - C:\WINDOWS\system32\Slpmda.dll
O2 - BHO: (no name) - {9237D2C0-6A52-48E5-907A-566969942E46} - C:\WINDOWS\system32\Adsp.dll
O2 - BHO: (no name) - {A09DF6E0-91F1-4E6F-9697-38BC48B78716} - C:\WINDOWS\system32\Lzbl.dll
O2 - BHO: (no name) - {AB69FD07-552A-4FA9-BCF2-4CED16DB3CF2} - C:\WINDOWS\system32\Mwpd.dll
O2 - BHO: (no name) - {B3989C8E-5AAB-4D0D-ACD5-7291D16A27EA} - C:\WINDOWS\system32\Ivbkw.dll
O2 - BHO: (no name) - {C6FBD089-4E82-4E15-8783-CAFCAD15289B} - C:\WINDOWS\system32\Ugjzxh.dll
O2 - BHO: (no name) - {C71C8290-0DBD-4900-A65C-A3973C073C88} - C:\WINDOWS\system32\Cdduf.dll
O2 - BHO: (no name) - {D1F0BA9A-8C3E-4D06-BB2E-B00B19DA0B64} - C:\WINDOWS\system32\Tblt.dll
O2 - BHO: (no name) - {D6E56477-E593-49BC-961D-0BE03B2166E7} - C:\WINDOWS\system32\Mgrewv.dll
O2 - BHO: (no name) - {E13E7C5D-BFAA-48EB-91AA-B650FABFF357} - C:\WINDOWS\system32\Fdbuta.dll
O2 - BHO: (no name) - {E8A227DF-BE1A-413C-96AE-D3519103DF0D} - C:\WINDOWS\system32\Vqub.dll
O2 - BHO: (no name) - {F46E1A58-1C15-4B89-A24F-F60779D31DA0} - C:\WINDOWS\system32\Hyvz.dll
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\KakaTool.dll
O4 - 启动项HKLM\\Run: [RfwMain] "rem "d:\Program Files\Rising\Rfw\rfwmain.exe" -Startup" -Startup
O4 - 启动项HKLM\\Run: [ATIPTA] ; "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - 启动项HKLM\\Run: [RavTask] "e:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [stup.exe] ; C:\PROGRA~1\TENCENT\Adplus\stup.exe
O4 - 启动项HKLM\\RunOnce: [Super Rabbit Winspeed] "D:\Program Files\Super Rabbit\MagicSet\winspeed.exe" /autokill:96,74,53
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BaiduDs] D:\Program Files\Baidu\Disk Search\BaiduDiskSearch.exe -NoOpen
O4 - Startup: 腾讯QQ.lnk = E:\Program Files\Tencent\QQ\QQ.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - e:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - e:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - E:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 使用Web迅雷下载 - C:\Program Files\Thunder Network\WebThunder\GetUrl.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - D:\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - E:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - E:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - E:\Program Files\Tencent\QQ\SendMMS.htm
O8 - IE右键菜单中的新增项目: 雅虎搜索 - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O9 - 浏览器额外的按钮: (no name) - RsAutorunsDisabled - (no file)
O9 - 浏览器额外的按钮: 启动Web迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)
O9 - 浏览器额外的“工具”菜单项: 启动Web迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing)
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - 浏览器额外的“工具”菜单项: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}? - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}? - C:\Program Files\Messenger\msmsgs.exe
O10 - 未知的文件在 Winsock LSP: d:\program files\baidu\disk search\disksearchservicestub.dll
O10 - 未知的文件在 Winsock LSP: d:\program files\baidu\disk search\disksearchservicestub.dll
O10 - 未知的文件在 Winsock LSP: d:\program files\baidu\disk search\disksearchservicestub.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.ap.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1133942540734
O16 - DPF: {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} (PhotoUploadCtrl Control) - http://imgcache.qq.com/qzone/photo/QzoneMediaTools.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan
Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl
Object) - https://www.tenpay.com/download/qqedit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0C5EAF45-2AFB-4A67-9FF8-5D5D9D35CDD1}: NameServer = 202.99.160.68 202.99.166.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{0C5EAF45-2AFB-4A67-9FF8-5D5D9D35CDD1}: NameServer = 202.99.160.68 202.99.166.4
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - NT 服务: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - NT 服务: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - NT 服务: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwproxy.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - e:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - e:\Program Files\Rising\Rav\Ravmond.exe