PID: 504][C:\KAV2007\KPFW32.EXE] [Kingsoft Corporation, 2007, 2, 2, 687]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2006, 12, 21, 241]
[C:\KAV2007\KAVIPC2.DLL] [Kingsoft Corporation, 2007, 1, 15, 30]
[C:\KAV2007\KAConfig.DLL] [Kingsoft Corporation, 2007, 1, 11, 41]
[C:\KAV2007\FiltList.dll] [N/A, ]
[C:\KAV2007\KAVPassp.DLL] [Kingsoft Corporation, 2006, 12, 30, 271]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\Kvsc3.dll] [N/A, ]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
[C:\DOCUME~1\new\LOCALS~1\Temp\qjso0.dll] [N/A, ]
[C:\DOCUME~1\new\LOCALS~1\Temp\ztso0.dll] [N/A, ]
[C:\WINDOWS\system32\winform.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\shualai.dll] [N/A, ]
[PID: 512][C:\Progra~1\Eset\1explore.exe] [N/A, ]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2836][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2006, 12, 21, 241]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2796][C:\Program Files\WinRAR\WinRAR.exe] [N/A, ]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2006, 12, 21, 241]
[C:\WINDOWS\system32\Audiodev.dll] [Microsoft Corporation, 5.2.3802.3802 built by: dnsrv(bld4act)]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\Kvsc3.dll] [N/A, ]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
[C:\DOCUME~1\new\LOCALS~1\Temp\qjso0.dll] [N/A, ]
[C:\DOCUME~1\new\LOCALS~1\Temp\ztso0.dll] [N/A, ]
[C:\WINDOWS\system32\winform.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\shualai.dll] [N/A, ]
[C:\WINDOWS\system32\pdkpri.dll] [N/A, ]
[PID: 2996][C:\DOCUME~1\new\LOCALS~1\Temp\Rar$EX00.890\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\KAV2007\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2007\KASocket.dll] [Kingsoft Corporation, 2006, 12, 21, 241]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\Kvsc3.dll] [N/A, ]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
[C:\DOCUME~1\new\LOCALS~1\Temp\qjso0.dll] [N/A, ]
[C:\DOCUME~1\new\LOCALS~1\Temp\ztso0.dll] [N/A, ]
[C:\WINDOWS\system32\winform.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\shualai.dll] [N/A, ]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP Error. [winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 popwin.9983.com
61.152.169.246 www.kuaiso.com
61.152.169.246 www.my6688.cn
61.152.169.246 www.union123.com
61.152.169.246 www.ktan.cn
61.152.169.246 www.2t2t.cn
61.152.169.246 www.cq530.com
61.152.169.246 www.365tc.com
61.152.169.246 ad.qucha.net
61.152.169.246 www.tan8.cn
61.152.169.246 www.itjj.net
61.152.169.246 www.start188.com
61.152.169.246 www.at58.cn
61.152.169.246 union.yxad.com
61.152.169.246 www.iptan.com
61.152.169.246 www.ip2008.net
61.152.169.246 www.yqif.com
61.152.169.246 www.2t2t.cn
61.152.169.246 www.17tan8.com
61.152.169.246 17tan8.com
61.152.169.246 www.688ip.com
61.152.169.246 www.17tc.com
61.152.169.246 www.zztan.com
61.152.169.246 www.5tanip.com
61.152.169.246 www.16tc.com
61.152.169.246 www.163se.net
61.152.169.246 www.724tc.com
61.152.169.246 www1.6tan.com
61.152.169.246 www2.6tan.com
61.152.169.246 www.6tan.com
61.152.169.246 quxiuu.com
61.152.169.246 www.quxiuu.com
61.152.169.246 www.23b.cn
61.152.169.246 www.ookkw.com
61.152.169.246 www.97725.com
61.152.169.246 down.97725.com
61.152.169.246 www.54699.com
61.152.169.246 web.77276.com
61.152.169.246 www.77276.com
61.152.169.246 d.77276.com
61.152.169.246 do.77276.com
61.152.169.246 i.96981.com
61.152.169.246 wm.103715.com
61.152.169.246 www.138505.com
61.152.169.246 cool.47555.com
61.152.169.246 www.437799.com
61.152.169.246 www.168080.com
61.152.169.246 w.168080.com
61.152.169.246 q.168080.com
61.152.169.246 www.baidu8.org
61.152.169.246 d.qbbd.com
61.152.169.246 w.qbbd.com
61.152.169.246 www.npjxjy.com
61.152.169.246 www.wwwlm.net
61.152.169.246 new2.jixie123.cn
61.152.169.246 www.18dmm.com
61.152.169.246 www.souxse.cn
61.152.169.246 dm1.yiall.com
61.152.169.246 www.nze21.com
61.152.169.246 www.puma163.com
61.152.169.246 www.hyap98.com
61.152.169.246 www.51liulan.cn
61.152.169.246 s.gcuj.com
61.152.169.246 long.down988.cn
61.152.169.246 x.vvcyin.com
61.152.169.246 w.vvcyin.com
61.152.169.246 cc.wzxqy.com
61.152.169.246 ip.315hack.com
61.152.169.246 ip.54liumang.com
61.152.169.246 www.41ip.com
61.152.169.246 xulao.com
61.152.169.246 www.xulao.com
61.152.169.246 www.heixiou.com
61.152.169.246 www.9cyy.com
61.152.169.246 adnx.yygou.cn
61.152.169.246 www1.cw988.cn
61.152.169.246 www2.cw988.cn
61.152.169.246 www.asdwc.com
61.152.169.246 ceoww.com
61.152.169.246 boolom.com
61.152.169.246 www.boolom.com
61.152.169.246 www.tellumore.com
61.152.169.246 www.o1wg.com
61.152.169.246 www.qq756.com
61.152.169.246 ll.chinasese.net
61.152.169.246 www.cnwangmeng.cn
61.152.169.246 0.82211.net
61.152.169.246 rising.whatthishome.com
61.152.169.246 www.canqiou.com
61.152.169.246 www.if56.cn
61.152.169.246 woai777.com
61.152.169.246 www.cz-kc.com
61.152.169.246 www.f1ash8.net
61.152.169.246 new.hackpp.com
61.152.169.246 ad.taoip.cn
61.152.169.246 www.game53.com
61.152.169.246 up.boolom.com
61.152.169.246 t.gcuj.com
61.152.169.246 w.zpx520.com
61.152.169.246 www.08325.cn
61.152.169.246 d.fangni.net
61.152.169.246 psxiaokan1.mei7.com
61.152.169.246 jd.54liumang.com
61.152.169.246 www.ipvip.info
61.152.169.246 www.tao168188.com
==================================
API HOOK
入口点错误:LoadLibraryExW (危险等级: 一般, 被下面模块所HOOK: C:\KAV2007\KASocket.dll)
==================================
隐藏进程
[188] C:\Program Files\msn\msn.cc
[2644] C:\Program Files\Common Files\Bitoot
==================================
[/CODE]