es\WinRAR\WinRAR.exe] [N/A, ]
[C:\WINDOWS\system32\HBTL.dll] [N/A, ]
[C:\WINDOWS\system32\HBmhly.dll] [N/A, ]
[C:\WINDOWS\system32\HBASKTAO.dll] [N/A, ]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16705 (vista_gdr.080618-1506)]
[C:\WINDOWS\system32\HBXMJ.dll] [N/A, ]
[C:\WINDOWS\system32\HBWOW.dll] [N/A, ]
[C:\WINDOWS\system32\HBLYFX.dll] [N/A, ]
[C:\WINDOWS\system32\DFEC5CB7.dll] [N/A, ]
[C:\WINDOWS\system32\2EF0D734.dll] [N/A, ]
[C:\WINDOWS\system32\56BC86C7.dll] [N/A, ]
[C:\WINDOWS\system32\A1A6BC2E.dll] [N/A, ]
[C:\WINDOWS\system32\16AF66EB.dll] [N/A, ]
[C:\WINDOWS\system32\122B901E.dll] [N/A, ]
[C:\WINDOWS\system32\DFB3DAC5.dll] [N/A, ]
[C:\WINDOWS\system32\E783C505.dll] [N/A, ]
[C:\WINDOWS\system32\08223B03.dll] [N/A, ]
[C:\WINDOWS\system32\F65BDEC7.dll] [N/A, ]
[C:\WINDOWS\system32\E0D39066.dll] [N/A, ]
[C:\WINDOWS\system32\9CA963CA.dll] [N/A, ]
[C:\WINDOWS\system32\E1384213.dll] [N/A, ]
[C:\WINDOWS\system32\198FF3D8.dll] [N/A, ]
[C:\WINDOWS\system32\BA7EDF54.dll] [N/A, ]
[C:\WINDOWS\system32\1FD51F1F.dll] [N/A, ]
[C:\WINDOWS\system32\E4814792.dll] [N/A, ]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16705 (vista_gdr.080618-1506)]
[PID: 2060 / liuJ][C:\DOCUME~1\liuJ\LOCALS~1\Temp\Rar$EX00.766\SREngLdr.EXE] [Smallfrogs Studio, 2.6.12.1018]
[C:\WINDOWS\system32\HBmhly.dll] [N/A, ]
[C:\WINDOWS\system32\HBASKTAO.dll] [N/A, ]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16705 (vista_gdr.080618-1506)]
[C:\WINDOWS\system32\HBWOW.dll] [N/A, ]
[C:\WINDOWS\system32\HBTL.dll] [N/A, ]
[C:\WINDOWS\system32\HBLYFX.dll] [N/A, ]
[C:\WINDOWS\system32\HBXMJ.dll] [N/A, ]
[PID: 3372 / liuJ][C:\DOCUME~1\liuJ\LOCALS~1\Temp\Rar$EX00.766\SREcead1a71.EXE] [Smallfrogs Studio, 2.6.12.1018]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16705 (vista_gdr.080618-1506)]
[C:\WINDOWS\system32\HBmhly.dll] [N/A, ]
[C:\WINDOWS\system32\HBASKTAO.dll] [N/A, ]
[C:\WINDOWS\system32\HBWOW.dll] [N/A, ]
[C:\WINDOWS\system32\HBTL.dll] [N/A, ]
[C:\WINDOWS\system32\HBLYFX.dll] [N/A, ]
[C:\WINDOWS\system32\HBXMJ.dll] [N/A, ]
[C:\WINDOWS\system32\DFEC5CB7.dll] [N/A, ]
[C:\WINDOWS\system32\2EF0D734.dll] [N/A, ]
[C:\WINDOWS\system32\56BC86C7.dll] [N/A, ]
[C:\WINDOWS\system32\A1A6BC2E.dll] [N/A, ]
[C:\WINDOWS\system32\16AF66EB.dll] [N/A, ]
[C:\WINDOWS\system32\122B901E.dll] [N/A, ]
[C:\WINDOWS\system32\DFB3DAC5.dll] [N/A, ]
[C:\WINDOWS\system32\E783C505.dll] [N/A, ]
[C:\WINDOWS\system32\08223B03.dll] [N/A, ]
[C:\DOCUME~1\liuJ\LOCALS~1\Temp\Rar$EX00.766\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]
[C:\Program Files\Bonjour\mdnsNSP.dll] [Apple Computer, Inc., 1,0,3,1]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 v.onondown.com.cn
127.0.0.2 ymsdasdw1.cn
127.0.0.3 h96b.info
127.0.0.0
www.bypk.com127.0.0.1 va9sdhun23.cn
127.0.0.2 bnasnd83nd.cn
127.0.0.0
www.gamehacker.com.cn127.0.0.0 gamehacker.com.cn
127.0.0.3 adlaji.cn
127.0.0.1 858656.com
127.1.1.1 bnasnd83nd.cn
127.1.1.1 555.hfdy2828.com
127.1.1.1 666.hfdy2828.com
127.0.1.1 59.34.216.143
127.0.0.1 my123.com
127.0.0.0 user1.12-27.net
127.0.0.1 8749.com
127.0.0.0 fengent.cn
127.0.0.1 4199.com
127.0.0.1 user1.16-22.net
127.0.0.1
www.oiuyt.net127.0.0.1 61.164.118.209
127.0.0.1 7379.com
127.0.0.1 2be37c5f.3f6e2cc5f0b.com
127.0.0.1 7255.com
127.0.0.1 user1.23-12.net
127.0.0.1 59.34.216.225
127.0.0.1 avzhan.3322.org
127.0.0.1 avzhan.3322.org
127.0.0.1 down.ombb888.cn
127.0.0.1 down.ombb888.cn
127.0.0.1
www.mmd178.cn127.0.0.1 61.160.210.41
127.0.0.1 61.160.210.42
127.0.0.1 61.160.210.43
127.0.0.1 61.160.210.44
127.0.0.1 61.160.210.45
127.0.0.1 61.160.210.46
127.0.0.1 3448.com
127.0.0.1
www.guccia.net127.0.0.1 7939.com
127.0.0.1 a.o1o1o1.nEt
127.0.0.1 8009.com
127.0.0.1 user1.12-73.cn
127.0.0.1 piaoxue.com
127.0.0.1 3n8nlasd.cn
127.0.0.1 kzdh.com
127.0.0.0
www.sony888.cn127.0.0.1 about.blank.la
127.0.0.0 user1.asp-33.cn
127.0.0.1 6781.com
127.0.0.0
www.netkwek.cn127.0.0.1 7322.com
127.0.0.0 ymsdkad6.cn
127.0.0.1 localhost
127.0.0.0
www.lkwueir.cn127.0.0.1 06.jacai.com
127.0.1.1 user1.23-17.net
127.0.0.1 1.jopenkk.com
127.0.0.0 upa.luzhiai.net
127.0.0.1 1.jopenqc.com
127.0.0.0
www.guccia.net127.0.0.1 1.joppnqq.com
127.0.0.0 4m9mnlmi.cn
127.0.0.1 1.xqhgm.com
127.0.0.0 mm119mkssd.cn
127.0.0.1 100.332233.com
127.0.0.0 61.128.171.115:8080
127.0.0.1 121.11.90.79
127.0.0.0
www.1119111.com127.0.0.1 121565.net
127.0.0.0 win.nihao69.cn
127.0.0.1 125.90.88.38
127.0.0.1 16888.6to23.com
127.0.0.1 2.joppnqq.com
127.0.0.0 puc.lianxiac.net
127.0.0.1 204.177.92.68
127.0.0.0 pud.lianxiac.net
127.0.0.1 210.74.145.236
127.0.0.0 210.76.0.133
127.0.0.1 219.129.239.220
127.0.0.0 61.166.32.2
127.0.0.1 219.153.40.221
127.0.0.0 218.92.186.27
127.0.0.1 219.153.46.27
127.0.0.0
www.fsfsfag.cn127.0.0.1 219.153.52.123
127.0.0.0 ovo.ovovov.cn
127.0.0.1 221.195.42.71
127.0.0.0 dw.com.com
127.0.0.1 222.73.218.115
127.0.0.1 203.110.168.233:80
127.0.0.1 3.joppnqq.com
127.0.0.1 203.110.168.221:80
127.0.0.1 363xx.com
127.0.0.1 www1.ip10086.com.cm
127.0.0.1 4199.com
127.0.0.1 blog.ip10086.com.cn
127.0.0.1 43242.com
127.0.0.1
www.ccji68.cn127.0.0.1 5.xqhgm.com
127.0.0.0 t.myblank.cn
127.0.0.1 520.mm5208.com
127.0.0.0 x.myblank.cn
127.0.0.1 59.34.131.54
127.0.0.1 210.51.45.5
127.0.0.1 59.34.198.228
127.0.0.1
www.ew1q.cn127.0.0.1 59.34.198.88
127.0.0.1 59.34.198.97
127.0.0.1 60.190.114.101
127.0.0.1 60.190.218.34
127.0.0.0 qq-xing.com.cn
127.0.0.1 60.191.124.252
127.0.0.1 61.145.117.212
127.0.0.1 61.157.109.222
127.0.0.1 75.126.3.216
127.0.0.1 75.126.3.217
127.0.0.1 75.126.3.218
127.0.0.0 59.125.231.177:17777
127.0.0.1 75.126.3.220
127.0.0.1 75.126.3.221
127.0.0.1 75.126.3.222
127.0.0.1 772630.com
127.0.0.1 832823.cn
127.0.0.1 8749.com
127.0.0.1 888.jopenqc.com
127.0.0.1 89382.cn
127.0.0.1 8v8.biz
127.0.0.1 97725.com
127.0.0.1 9gg.biz
127.0.0.1
www.9000music.com127.0.0.1 test.591jx.com
127.0.0.1 a.topxxxx.cn
127.0.0.1 picon.chinaren.com
127.0.0.1
www.5566.net127.0.0.1 p.qqkx.com
127.0.0.1 news.netandtv.com
127.0.0.1 z.neter888.cn
127.0.0.1 b.myblank.cn
127.0.0.1 wvw.wokutu.com
127.0.0.1 unionch.qyule.com
127.0.0.1
www.qyule.com127.0.0.1 it.itjc.cn
127.0.0.1
www.linkwww.com127.0.0.1 vod.kaicn.com
127.0.0.1
www.tx8688.com127.0.0.1 b.neter888.cn
127.0.0.1 promote.huanqiu.com
127.0.0.1
www.huanqiu.com127.0.0.1
www.haokanla.com127.0.0.1 play.unionsky.cn
127.0.0.1
www.52v.com127.0.0.1
www.gghka.cn127.0.0.1 icon.ajiang.net
127.0.0.1 new.ete.cn
127.0.0.1
www.stiae.cn127.0.0.1 o.neter888.cn
127.0.0.1 comm.jinti.com
127.0.0.1
www.google-analytics.com127.0.0.1 hz.mmstat.com
127.0.0.1
www.game175.cn127.0.0.1 x.neter888.cn
127.0.0.1 z.neter888.cn
127.0.0.1 p.etimes888.com
127.0.0.1 hx.etimes888.com
127.0.0.1 abc.qqkx.com
127.0.0.1 dm.popdm.cn
127.0.0.1
www.yl9999.com127.0.0.1
www.dajiadoushe.cn127.0.0.1 v.onondown.com.cn
127.0.0.1
www.interoo.net127.0.0.1 bally1.bally-bally.net
127.0.0.1
www.bao5605509.cn127.0.0.1
www.rty456.cn127.0.0.1
www.werqwer.cn127.0.0.1 1.360-1.cn
127.0.0.1 user1.23-16.net
127.0.0.1 61.160.213.143
127.0.0.1 qq.xiaoxiao02.cn
127.0.0.1 baoge.9966.org
127.0.0.1
www.oiuyt.net127.0.0.1
www.guccia.net127.0.0.1
www.interoo.net127.0.0.1 upa.netsool.net
127.0.0.1 qq.gong2008.com
127.0.0.1 2008tl.copyip.com
127.0.0.1 tla.laozihuolaile.cn
127.0.0.1
www.tx6868.cn127.0.0.1 p001.tiloaiai.com
127.0.0.1 s1.tl8tl.com
127.0.0.1 s1.gong2008.com
127.0.0.1 js.users.51.la
127.0.0.1 vip2.51.la
127.0.0.1 web.51.la
127.0.0.1 4b3ce56f9g.3f6e2cc5f0b.com
127.0.0.1 2be37c5f.3f6e2cc5f0b.com
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 2860, C:\WINDOWS\SYSTEM32\DLA\DLACTRLW.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2860, C:\WINDOWS\SYSTEM32\DLA\DLACTRLW.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2868, C:\PROGRAM FILES\GRIDSERVICE\PEER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2868, C:\PROGRAM FILES\GRIDSERVICE\PEER.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2904, C:\WINDOWS\SYSTEM32\SYSTEM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2904, C:\WINDOWS\SYSTEM32\SYSTEM.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 532, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 532, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2060, C:\DOCUME~1\LIUJ\LOCALS~1\TEMP\RAR$EX00.766\SRENGLDR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2060, C:\DOCUME~1\LIUJ\LOCALS~1\TEMP\RAR$EX00.766\SRENGLDR.EXE]
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]