瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 37ss病毒怎么处理,我要被它逼疯了??高手帮忙,在线等~~~(附日志)

1   1  /  1  页   跳转

37ss病毒怎么处理,我要被它逼疯了??高手帮忙,在线等~~~(附日志)

37ss病毒怎么处理,我要被它逼疯了??高手帮忙,在线等~~~(附日志)

我的电脑前一阵中过毒,清了不少。但就是37ss这个老是杀不掉,我用过木马专杀,诺顿都没有用,到底要怎么处理??

2006-11-12,15:54:16

System Repair Engineer 2.2.6.605
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <bgswitch><C:\WINDOWS\system32\bgswitch.exe>  [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <vptray><C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe>  [Symantec Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]

==================================
启动文件夹
N/A

==================================
服务
[ASP.NET State Service / aspnet_state]
  <C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[DefWatch / DefWatch]
  <C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe><Symantec Corporation>
[Human Interface Device Access / HidServ]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Machine Debug Manager / MDM]
  <"C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"><Microsoft Corporation>
[Symantec AntiVirus Client / Norton AntiVirus Server]
  <C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe><Symantec Corporation>
[Distributed Link Tracking Server / TrkWks]
  <C:\WINDOWS\system32\svchost.exe -k netsvsc-->%SystemRoot%\system32\est.dll><Microsoft Corporation>
[Link Server / Wks]
  <C:\WINDOWS\system32\svchost.exe -k netsvs-->%SystemRoot%\system32\wks.dll><Microsoft Corporation>
[Link Server / wkss]
  <C:\WINDOWS\system32\svchost.exe -k netsvs-->%SystemRoot%\system32\wkss.dll><Microsoft Corporation>
[Windows Media Connect Service / WMConnectCDS]
  <C:\Program Files\Windows Media Connect 2\wmccds.exe><Microsoft Corporation>
[Windows Driver Foundation - User-mode Driver Framework / WudfSvc]
  <C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup-->%SystemRoot%\System32\WUDFSvc.dll><Microsoft Corporation>
最后编辑2006-11-12 16:09:49.687000000
分享到:
gototop
 

==================================
驱动程序
[Service for Avance AC97 Audio (WDM) / ALCXWDM]
  <system32\drivers\ALCXWDM.SYS><Avance Logic, Inc.>
[NAVAP / NAVAP]
  <\??\C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVAP.sys><Symantec Corporation>
[NAVAPEL / NAVAPEL]
  <\??\C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAPEL.SYS><Symantec Corporation>
[NAVENG / NAVENG]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061108.024\NAVENG.sys><Symantec Corporation>
[NAVEX15 / NAVEX15]
  <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061108.024\NAVEX15.sys><Symantec Corporation>
[npkcrypt / npkcrypt]
  <\??\D:\Pro\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv]
  <system32\DRIVERS\secdrv.sys><N/A>
[SymEvent / SymEvent]
  <\??\C:\Program Files\Symantec\SYMEVENT.SYS><Symantec Corporation>

==================================
浏览器加载项
[启动迅雷5]
  {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <d:\Pro\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[番茄花园]
  {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.tomatolei.com, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <d:\Pro\Tencent\QQ\QQ.EXE, TENCENT>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[]
  {003169BC-AB68-482F-AEA6-B51A47BDDB83} <C:\WINDOWS\system32\ATIDEMGREDEM.dll, N/A>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[MediaComm Class]
  {7670648D-461B-42AF-BDFE-46D26AF5EFF2} <d:\Pro\Thunder Network\Thunder\Components\InMedia\MediaAddin09.dll, Thunder Networking Technologies,LTD>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <d:\Pro\Thunder Network\Thunder\ComDlls\XunLeiBHO_004.dll, N/A>
[]
  {A9930D97-9CF0-42A0-A10D-4F28836579D5} <D:\Pro\KuGoo3\KuGoo3DownXControl.ocx, N/A>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[AUDIO__MP3 Moniker Class]
  {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AUDIO__WAV Moniker Class]
  {CD3AFA7B-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AUDIO__X_MS_WMA Moniker Class]
  {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
  {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[CPasswordEditCtrl Object]
  {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
[IEHlprObj Class]
  {EAACBF9E-4B91-45FF-93ED-B297093951EA} <C:\Program Files\Internet Explorer\PLUGINS\Flash_Player.dll, Adobe System>
[&使用迅雷下载]
  <d:\Pro\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <d:\Pro\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
  <D:\Pro\Tencent\QQ\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
  <D:\Pro\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\Pro\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\Pro\Tencent\QQ\SendMMS.htm, N/A>
gototop
 

==================================
正在运行的进程
[PID: 440][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 488][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 512][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 556][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 568][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 724][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 784][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 848][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 960][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 988][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1176][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1428][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\xggjpf68.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll]  [Symantec Corporation, 8.1.0.821]
    [d:\Pro\WinRAR\rarext.dll]  [N/A, N/A]
[PID: 1572][C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe]  [Symantec Corporation, 8.1.0.821]
[PID: 1604][C:\WINDOWS\system32\inetsrv\inetinfo.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1692][C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe]  [Symantec Corporation, 8.1.0.821]
    [C:\WINDOWS\system32\CBA.DLL]  [Intel? Corporation, 6.12.0.105 E]
    [C:\WINDOWS\system32\MsgSys.dll]  [Intel? Corporation, 6.12.0.105 E]
    [C:\WINDOWS\system32\NTS.dll]  [Intel? Corporation, 6.12.0.105 E]
    [C:\WINDOWS\system32\PDS.DLL]  [Intel? Corporation, 6.12.0.105 E]
    [C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVLU.dll]  [Symantec Corporation, 8.1.0.821]
    [C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVNTUTL.DLL]  [Symantec/Peter Norton Group, 1, 0, 0, 1]
    [C:\PROGRA~1\SYMANT~1\SYMANT~1\i2ldvp3.dll]  [Symantec Corporation, 8.1.0.821]
    [C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVAPI32.DLL]  [Symantec Corp., 4.2.0.7]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061108.024\NAVEX32a.DLL]  [Symantec Corporation, 20061.3.0.12]
    [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20061108.024\NAVENG32.DLL]  [Symantec Corporation, 20061.3.0.12]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAP32.DLL]  [Symantec Corporation, 9.1.0.26]
    [C:\Program Files\Common Files\Symantec Shared\SSC\scandlgs.dll]  [Symantec Corporation, 8.1.0.821]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DecSDK.dll]  [Symantec Corporation, 3.02.09.07]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2.dll]  [Symantec Corporation, 3.02.09.07]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2ID.dll]  [Symantec Corporation, 3.02.09.07]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2UUE.dll]  [Symantec Corporation, 3.02.09.07]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2AMG.dll]  [Symantec Corporation, 3.02.09.07]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2ARJ.dll]  [Symantec Corporation, 3.02.09.07]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2CAB.dll]  [Symantec Corporation, 3.02.09.07]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2EXE.dll]  [Symantec Corporation, 3.02.09.07]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2GZIP.dll]  [Symantec Corporation, 3.02.09.07]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2HQX.dll]  [Symantec Corporation, 3.02.09.07]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2LHA.dll]  [Symantec Corporation, 3.02.09.07]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2LZ.dll]  [Symantec Corporation, 3.02.09.07]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2MIME.dll]  [Symantec Corporation, 3.02.09.07]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2SS.dll]  [Symantec Corporation, 3.02.09.07]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2RTF.dll]  [Symantec Corporation, 3.02.09.07]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2TAR.dll]  [Symantec Corporation, 3.02.09.07]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2TNEF.dll]  [Symantec Corporation, 3.02.09.07]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Dec2ZIP.dll]  [Symantec Corporation, 3.02.09.07]
[PID: 1736][C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe]  [Symantec Corporation, 8.1.0.821]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Cliscan.dll]  [Symantec Corporation, 8.1.0.821]
    [C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVNTUTL.DLL]  [Symantec/Peter Norton Group, 1, 0, 0, 1]
    [C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Cliproxy.dll]  [Symantec Corporation, 8.1.0.821]
[PID: 1752][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1860][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1884][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1912][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1032][C:\WINDOWS\system32\Sys.exe]  [腾讯公司, 1.00]
[PID: 1788][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 492][C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe]  [Microsoft Corporation, 7.10.3077]
[PID: 2712][d:\Pro\Thunder Network\Thunder\Program\Thunder5.exe]  [Thunder Networking Technologies,LTD, 5, 5, 1, 241]
    [d:\Pro\Thunder Network\Thunder\Program\TaskManager.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 10]
    [d:\Pro\Thunder Network\Thunder\Program\download_interface.dll]  [xunlei.com, 1, 0, 0, 1]
    [d:\Pro\Thunder Network\Thunder\Program\stlport_vc646.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
    [d:\Pro\Thunder Network\Thunder\Program\log4cplus.dll]  [, 1, 0, 2, 1]
    [d:\Pro\Thunder Network\Thunder\Program\asyn_dns.dll]  [N/A, N/A]
    [d:\Pro\Thunder Network\Thunder\Program\iTargetAD.dll]  [Thunder Networking Technologies,LTD, 1, 0, 2, 4]
    [d:\Pro\Thunder Network\Thunder\Program\BHOStub.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 8]
    [d:\Pro\Thunder Network\Thunder\Program\FloatBar.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
    [d:\Pro\Thunder Network\Thunder\Program\LiveUpdate.dll]  [, 1, 0, 0, 9]
    [d:\Pro\Thunder Network\Thunder\Program\UpdateDownload.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 8]
    [d:\Pro\Thunder Network\Thunder\Components\Community\XLCommunity.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 10]
    [d:\Pro\Thunder Network\Thunder\Program\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 2, 1, 33]
    [d:\Pro\Thunder Network\Thunder\Components\P4PClient\P4PClient.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 27]
    [d:\Pro\Thunder Network\Thunder\Components\Search\XLSearch.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
    [d:\Pro\Thunder Network\Thunder\Components\InMedia\iEmbedShell.dll]  [ , 1, 0, 0, 13]
    [d:\Pro\Thunder Network\Thunder\Components\InMedia\iEmbed06.dll]  [ , 3, 0, 0, 55]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
    [d:\Pro\Thunder Network\Thunder\Program\msgmanage.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 15]
[PID: 1744][C:\WINDOWS\system32\Syste.exe]  [腾讯公司, 1.00]
[PID: 3800][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1064][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
gototop
 

[C:\WINDOWS\system32\rmoc3260.dll]  [RealNetworks, Inc., 6.0.9.2533]
    [C:\WINDOWS\system32\PNCRT.dll]  [Real Networks, Inc, 6.0.0.0]
    [C:\Program Files\Common Files\Real\Common\pnrs3260.dll]  [RealNetworks, Inc., 6.0.9.4282]
    [C:\Program Files\Common Files\Real\rpplugins\embd3260.dll]  [RealNetworks, Inc., 6.0.12.1698]
    [C:\Program Files\Common Files\Real\Common\pngu3267.dll]  [RealNetworks, Inc., 6.7.0.2927]
    [C:\Program Files\Common Files\Real\Common\objb3201.dll]  [RealNetworks, Inc., 0.1.0.6691]
    [C:\Program Files\Common Files\Real\rpplugins\rpcl3260.dll]  [RealNetworks, Inc., 6.0.9.3327]
    [C:\Program Files\Common Files\Real\rpplugins\rput3260.dll]  [RealNetworks, Inc., 6.0.9.3303]
    [C:\Program Files\Common Files\Real\Common\pnen3260.dll]  [RealNetworks, Inc., 10.0.0.1250]
    [C:\Program Files\Common Files\Real\Plugins\vsrlocal.dll]  [RealNetworks, Inc., 10.1.0.1147]
    [C:\Program Files\Common Files\Real\Plugins\vidsite.dll]  [RealNetworks, Inc., 10.0.0.1220]
    [C:\Program Files\Common Files\Real\Plugins\clntxres.dll]  [RealNetworks, Inc., 10.0.0.4106]
    [C:\Program Files\Common Files\Real\rpplugins\cn\embed_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Common Files\Real\rpplugins\cn\rpclsvc_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Common Files\Real\Plugins\memfsys.dll]  [RealNetworks, Inc., 10.0.0.1188]
    [C:\Program Files\Common Files\Real\Plugins\ramfformat.dll]  [RealNetworks, Inc., 10.0.0.2446]
    [C:\Program Files\Common Files\Real\Plugins\authmgr.dll]  [RealNetworks, Inc., 10.0.0.1654]
    [C:\Program Files\Common Files\Real\Plugins\smlfformat.dll]  [RealNetworks, Inc., 10.0.0.2081]
    [C:\Program Files\Common Files\Real\Plugins\smlrender.dll]  [RealNetworks, Inc., 10.0.0.1697]
    [C:\Program Files\Common Files\Real\Plugins\httpfsys.dll]  [RealNetworks, Inc., 10.0.0.3001]
    [C:\Program Files\Common Files\Real\Plugins\rmfformat.dll]  [RealNetworks, Inc., 10.0.0.1442]
    [C:\Program Files\Common Files\Real\Plugins\rarender.dll]  [RealNetworks, Inc., 10.0.0.1227]
    [C:\Program Files\Common Files\Real\Codecs\cook.dll]  [RealNetworks, Inc., 10.0.0.2313]
[PID: 3760][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
[PID: 3536][D:\Pro\Tencent\QQ\QQ.exe]  [TENCENT, 14, 27, 0, 082]
    [D:\Pro\Tencent\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [D:\Pro\Tencent\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [D:\Pro\Tencent\QQ\BasicCtrlDll.dll]  [Tencent, 0, 3, 3, 6]
    [D:\Pro\Tencent\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
    [d:\Pro\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [D:\Pro\Tencent\QQ\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [D:\Pro\Tencent\QQ\npkcntc.dll]  [INCA Internet Co., Ltd., 2005, 9, 1, 1]
    [D:\Pro\Tencent\QQ\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [D:\Pro\Tencent\QQ\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [D:\Pro\Tencent\QQ\QQMainFrame.dll]  [N/A, N/A]
    [D:\Pro\Tencent\QQ\CQQApplication.dll]  [N/A, N/A]
    [D:\Pro\Tencent\QQ\NewSkin.dll]  [, 1, 0, 0, 1]
    [D:\Pro\Tencent\QQ\HostingMgr.dll]  [, 1, 0, 0, 1]
    [D:\Pro\Tencent\QQ\MailSummary.dll]  [, 1, 0, 0, 1]
    [D:\Pro\Tencent\QQ\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
    [D:\Pro\Tencent\QQ\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [D:\Pro\Tencent\QQ\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [D:\Pro\Tencent\QQ\QQAvatar.dll]  [N/A, N/A]
    [D:\Pro\Tencent\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
    [D:\Pro\Tencent\QQ\LongConnection.dll]  [tencent, 0, 3, 3, 8]
    [D:\Pro\Tencent\QQ\QQPlugin.dll]  [N/A, N/A]
    [D:\Pro\Tencent\QQ\ShareFiles.dll]  [N/A, N/A]
    [D:\Pro\Tencent\QQ\QQZip.dll]  [tencent, 0, 3, 2, 4]
    [D:\Pro\Tencent\QQ\QRingMng.dll]  [N/A, N/A]
    [D:\Pro\Tencent\QQ\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [D:\Pro\Tencent\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [D:\Pro\Tencent\QQ\QQPet.dll]  [, 1, 0, 0, 1]
    [D:\Pro\Tencent\QQ\QQAllInOne.dll]  [N/A, N/A]
    [D:\Pro\Tencent\QQ\CameraDll.dll]  [, 1, 0, 0, 1]
    [D:\Pro\Tencent\QQ\SCCore.dll]  [N/A, N/A]
    [D:\Pro\Tencent\QQ\QQCustomFace.dll]  [N/A, N/A]
    [D:\Pro\Tencent\QQ\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [D:\Pro\Tencent\QQ\QQMagicFace.dll]  [, 1, 0, 0, 1]
    [D:\Pro\Tencent\QQ\QQSceneMng.dll]  [N/A, N/A]
    [D:\Pro\Tencent\QQ\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [D:\Pro\Tencent\QQ\BQQApplication.dll]  [N/A, N/A]
    [D:\Pro\Tencent\QQ\CommercesMng.dll]  [, 1, 0, 0, 1]
    [D:\Pro\Tencent\QQ\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [D:\Pro\Tencent\QQ\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 4, 0, 200, 32]
    [D:\Pro\Tencent\QQ\QQFileTransfer.dll]  [Tencent, 0, 3, 3, 5]
    [D:\Pro\Tencent\QQ\GroupConnection.dll]  [Tencent, 0, 3, 3, 5]
    [D:\Pro\Tencent\QQ\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 0, 6, 60]
    [D:\Pro\Tencent\QQ\QQSysMsgMng.dll]  [N/A, N/A]
[PID: 3164][d:\Pro\Tencent\QQ\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [d:\Pro\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 3440][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
[PID: 3008][D:\常用软件\sreng2\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
gototop
 

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  Error. ["d:\Pro\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" "%1"]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
61.135.150.114 www.8000qq.com
61.135.150.114 www.800f.net
61.135.150.114 www.1000sf.cn
61.135.150.114 jfengsha.comfb
61.135.150.114 www.1000yf.net
61.135.150.114 www.159sifu.com
61.135.150.114 www.9s5.cn
61.135.150.114 www.spbuy.net
61.135.150.114 www.wym.cn
61.135.150.114 www.cc4f.cn
61.135.150.114 mafan.net
61.135.150.114 www.6688qn.net
61.135.150.114 www.177z.com
61.135.150.114 www.131sf.net
61.135.150.114 tj.cntg.cn
61.135.150.114 www.spbuy.net
61.135.150.114 www.china45.net
61.135.150.114 www.ok22.com
61.135.150.114 www.17mi.net
61.135.150.114 www.sf8.com.cn
61.135.150.114 www.13177.com
61.135.150.114 ip94.fd4f.com
61.135.150.114 www.521it.net
61.135.150.114 www.ytdj.cn
61.135.150.114 www.fwoool.cn
61.135.150.114 www.5u37.net
61.135.150.114 www.87sf.com
61.135.150.114 ww1.swoool.com
61.135.150.114 wooljsz.cn
61.135.150.114 www.57wool.com
61.135.150.114 www.58816.com
61.135.150.114 www.spbuy.net
61.135.150.114 chuanqisjsf.blwool.com
61.135.150.114 www.woool188.com
61.135.150.114 www.sf1260.com
61.135.150.114 linf23.b12.cnwg.cn
61.135.150.114 www.wooolweb.com
61.135.150.114 www.yq520.net
61.135.150.114 www.cs222.com
61.135.150.114 www.ok22.com
61.135.150.114 www.7100sf.com
61.135.150.114 www.1352sf.com
61.135.150.114 www.458wool.cn
61.135.150.114 www.555woool.cn
61.135.150.114 www.kaosf.com
61.135.150.114 www.siyuwl.com
61.135.150.114 www.csjsz.cn
61.135.150.114 www.13177.com
61.135.150.114 www.458cs.com
61.135.150.114 www.5573.com
61.135.150.114 www.02945.com
61.135.150.114 www.pkchina.net
61.135.150.114 www.5181314.com
61.135.150.114 www.fknf2.com
61.135.150.114 www2.yoursf.com
61.135.150.114 www.paocs.com
61.135.150.114 www.sfboke.com
61.135.150.114 www.tt878.com
61.135.150.114 ww1.woool188.com
61.135.150.114 www.cs119.com
61.135.150.114 www.xdwoool.net
61.135.150.114 www.tt515.com
61.135.150.114 www.cs176.com
61.135.150.114 www.552sf.com
61.135.150.114 www.ipmir.com
61.135.150.114 www.898woool.com
61.135.150.114 www.qqks.com
61.135.150.114 www.368idc.com
61.135.150.114 www.csbaba.com
61.135.150.114 www.4745.cn
61.135.150.114 www.636400.com
61.135.150.114 www.oursf.cn
61.135.150.114 www.laiba173.com
61.135.150.114 www.14455.com
61.135.150.114 www.zheshan.net
61.135.150.114 zt.aaaaasf.cn
61.135.150.114 www.zt1314.cn
61.135.150.114 www.zt4f.net
61.135.150.114 www.zt002.com
61.135.150.114 www.amir3.com
61.135.150.114 www.sf1717.com
61.135.150.114 www.cq333.cn
61.135.150.114 www.3316.cn
61.135.150.114 www.sosmir3.com
61.135.150.114 www.95279.com
61.135.150.114 www.sf1788.com
61.135.150.114 www.4fboss.com
61.135.150.114 www.45net.net
61.135.150.114 www.ytdj.cn
61.135.150.114 www.laiba173.com
61.135.150.114 www.wow1314.com
61.135.150.114 www.zgwow.com
61.135.150.114 www.1000wow.net
61.135.150.114 www.gowowsf.com
61.135.150.114 www.wowsf.com
61.135.150.114 www.wxwow.com
61.135.150.114 520.xinwow.com
61.135.150.114 www.wowhelp.cn
61.135.150.114 www.800wow.com
61.135.150.114 www.56wow.com
61.135.150.114 www.45wow.com
61.135.150.114 www.sfhao123.net
61.135.150.114 www.lian2.cn
61.135.150.114 www.14455.com
61.135.150.114 www.sfgoogle.cn
61.135.150.114 www.45top.com
61.135.150.114 www.915mu.com
61.135.150.114 www.gm911.net
61.135.150.114 www.4000mu.com
61.135.150.114 www.99musf.com
61.135.150.114 www.mu45.com
61.135.150.114 www.369mu.com
61.135.150.114 www.525sf.com
61.135.150.114 www.2345w.com
61.135.150.114 www.3jsf.net
61.135.150.114 www.ttfsf.com
61.135.150.114 www.521ee.com
61.135.150.114 www.997j.com
61.135.150.114 www.wz4f.net
61.135.150.114 www.hott2.com
61.135.150.114 www.398q.com
61.135.150.114 www.tt1314.com
61.135.150.114 www.tt2sf.net
61.135.150.114 www.sifu114.com
61.135.150.114 www.2z2.cn
61.135.150.114 www.haosf.com
61.135.150.114 www.cqsf999.com
61.135.150.114 www.zhaosf.com
61.135.150.114 www.920666.com
61.135.150.114 www.450666.com
61.135.150.114 www.3000ok.com
61.135.150.114 www.3000ok.net
61.135.150.114 www.sf001.com
61.135.150.114 www.92045.com
61.135.150.114 www.45bang.com
61.135.150.114 www.30ok.com
61.135.150.114 www.cqsf999.com
61.135.150.114 www.sf123.com
61.135.150.114 www.sf920.com
61.135.150.114 www.99945.com
61.135.150.114 www.176sf.com
61.135.150.114 www.mir2mir2.com
61.135.150.114 www.33520.com
61.135.150.114 www.xp13.com
61.135.150.114 www.45yes.com
61.135.150.114 www.920666.com
61.135.150.114 www.450666.com
61.135.150.114 www.92095.com
61.135.150.114 www.17ww.com
61.135.150.114 www.4000sf.com
61.135.150.114 www.haouc.com
61.135.150.114 www.921uc.com
61.135.150.114 17126.uc999.com
61.135.150.114 www.45pao.com
61.135.150.114 www.177g.com
61.135.150.114 www.95217.com
61.135.150.114 www.2345sf.com

==================================
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT