[D:\KAV2006\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[D:\KAV2006\KAECall2.DLL] [Kingsoft Corporation, 2004, 12, 28, 7]
[D:\KAV2006\KAEPlat.DLL] [Kingsoft Corp., 2006, 8, 29, 60]
[D:\KAV2006\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[D:\KAV2006\KAEUnpack.DAT] [Kingsoft Corp., 2007, 3, 12, 114]
[D:\KAV2006\KAConfig.DLL] [Kingsoft Corporation, 2007, 1, 11, 41]
[D:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[D:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\201a.dll] [N/A, ]
[C:\WINDOWS\system32\c142.dll] [ , 1, 0, 0, 3]
[PID: 2408][C:\Program Files\racer-henan-cnc\RacerKp.exe] [北京润汇科技有限公司, 1, 0, 0, 1]
[D:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[D:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\WINDOWS\system32\201a.dll] [N/A, ]
[C:\WINDOWS\system32\c142.dll] [ , 1, 0, 0, 3]
[PID: 2904][C:\WINDOWS\system32\MSRundll.exe] [N/A, ]
[C:\WINDOWS\system32\c142.dll] [ , 1, 0, 0, 3]
[D:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[D:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[PID: 3020][D:\Maxthon\Maxthon.exe] [Maxthon International Ltd., 1, 5, 9, 80]
[D:\Maxthon\maxzlib.dll] [ , 1, 0, 0, 2]
[D:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[D:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[D:\BitComet\tools\BitCometBHO_1.1.3.19.dll] [BitComet, 20070319]
[C:\WINDOWS\system32\odbcbcp.dll] [Microsoft Corporation, 2000.085.1117.00 (xpsp_sp2_rtm.040803-2158)]
[D:\Maxthon\Services\RealTime\real_time.dll] [, 1, 0, 0, 1]
[D:\KAV2006\KAScript.DLL] [Kingsoft Corporation, 2006, 12, 11, 72]
[D:\KAV2006\KAEPlat.DLL] [Kingsoft Corp., 2006, 8, 29, 60]
[D:\KAV2006\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[D:\KAV2006\KAEUnpack.DAT] [Kingsoft Corp., 2007, 3, 12, 114]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[D:\KAV2006\Flash.OCX] [Macromedia, Inc., 7,0,19,0]
[PID: 2656][D:\KAV2006\KAV32.EXE] [Kingsoft Corporation, 2007, 4, 3, 123]
[D:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[D:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[D:\KAV2006\KAV32Res.dll] [Kingsoft Corporation, 2007, 3, 26, 108]
[D:\KAV2006\KAEPlat.DLL] [Kingsoft Corp., 2006, 8, 29, 60]
[D:\KAV2006\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[D:\KAV2006\KAEUnpack.DAT] [Kingsoft Corp., 2007, 3, 12, 114]
[D:\KAV2006\KAConfig.DLL] [Kingsoft Corporation, 2007, 1, 11, 41]
[D:\KAV2006\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[D:\KAV2006\KAVPassp.DLL] [Kingsoft Corporation, 2006, 12, 30, 271]
[D:\KAV2006\DBAgent.DLL] [Kingsoft Corporation, 2005, 10, 27, 9]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]
[D:\KAV2006\KAScript.DLL] [Kingsoft Corporation, 2006, 12, 11, 72]
[D:\KAV2006\KWindUp.DLL] [Kingsoft Corp., 2006, 1, 10, 18]
[D:\KAV2006\KAEPrev.dll] [Kingsoft Corporation, 2006, 12, 7, 20]
[D:\KAV2006\KAEMemEx.dll] [, 2006, 10, 17, 16]
[D:\KAV2006\KAEMalDt.dll] [, 2006, 12, 7, 20]
[D:\KAV2006\KAERemov.dll] [, 2006, 12, 7, 20]
[PID: 1104][D:\BitComet\BitComet.exe] [www.BitComet.com, 0.85]
[D:\BitComet\dbghelp.dll] [Microsoft Corporation, 6.3.0011.3 (DbgBuild.040120-1256)]
[D:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[D:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[D:\KAV2006\KAScript.DLL] [Kingsoft Corporation, 2006, 12, 11, 72]
[D:\KAV2006\Flash.OCX] [Macromedia, Inc., 7,0,19,0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 2836][C:\DOCUME~1\HJF\LOCALS~1\Temp\Rar$EX04.328\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[D:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[D:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\DOCUME~1\HJF\LOCALS~1\Temp\Rar$EX04.328\Plugins\NWMON.SRE] [Smallfrogs Studio, 1, 0, 0, 8]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP Error. [winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 popwin.9983.com
61.152.169.246 www.npjxjy.com
61.152.169.246 quxiuu.com
61.152.169.246 www.23b.cn
61.152.169.246 www.baidulink.com
61.152.169.246 www.ookkw.com
61.152.169.246 www.97725.com
61.152.169.246 www.54699.com
61.152.169.246 www.wu7x.cn
61.152.169.246 d.qbbd.com
61.152.169.246 w.qbbd.com
61.152.169.246 web.77276.com
61.152.169.246 www.77276.com
61.152.169.246 www.npjxjy.com
61.152.169.246 www.baidulink.com
61.152.169.246 www.ookkw.com
61.152.169.246 www.wu7x.cn
61.152.169.246 www.wwwlm.net
61.152.169.246 dm1.yiall.com
61.152.169.246 www.my6688.cn
61.152.169.246 www.union123.com
61.152.169.246 www.ktan.cn
61.152.169.246 www.2t2t.cn
61.152.169.246 www.cq530.com
61.152.169.246 www.365tc.com
61.152.169.246 ad.qucha.net
61.152.169.246 www.tan8.cn
61.152.169.246 www.itjj.net
61.152.169.246 www.start188.com
61.152.169.246 www.at58.cn
61.152.169.246 union.yxad.com
61.152.169.246 www.iptan.com
61.152.169.246 www.ip2008.net
61.152.169.246 www.yqif.com
61.152.169.246 www.2t2t.cn
61.152.169.246 www.688ip.com
61.152.169.246 www.17tc.com
61.152.169.246 www1.6tan.com
61.152.169.246 www2.6tan.com
61.152.169.246 www.6tan.com
61.152.169.246 www.zztan.com
61.152.169.246 www.5tanip.com
61.152.169.246 www.16tc.com
61.152.169.246 www.163se.net
61.152.169.246 www.168080.com
61.152.169.246 www.baidu8.org
61.152.169.246 www.qqwei.com
61.152.169.246 qz.magforum.net
61.152.169.246 www.nze21.com
61.152.169.246 www.437799.com
61.152.169.246 www.168080.com
61.152.169.246 new2.jixie123.cn
61.152.169.246 www.18dmm.com
61.152.169.246 www.souxse.cn
61.152.169.246 x.vvcyin.com
61.152.169.246 dm1.yiall.com
61.152.169.246 www.168080.com
61.152.169.246 www.nze21.com
61.152.169.246 www.puma163.com
61.152.169.246 www.138505.com
61.152.169.246 www.hyap98.com
61.152.169.246 x.vvcyin.com
61.152.169.246 www.puma163.com
61.152.169.246 www.51liulan.cn
==================================
API HOOK
入口点错误:LoadLibraryExW (危险等级: 一般, 被下面模块所HOOK: D:\KAV2006\KASocket.dll)
==================================
隐藏进程
N/A
==================================
[/CODE]
好长啊。...~!~ 谢谢.辛苦您了