正在运行的进程
[PID: 148][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 176][\??\C:\WINNT\system32\csrss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 172][\??\C:\WINNT\system32\winlogon.exe] [Microsoft Corporation, 5.00.2195.6898]
[c:\program files\rising\rav\huqvjxzu.dll] [, 1, 0, 0, 11]
[PID: 224][C:\WINNT\system32\services.exe] [Microsoft Corporation, 5.00.2195.6700]
[C:\WINNT\system32\dmserver.dll] [VERITAS Software Corp., 2195.6605.297.3]
[PID: 236][C:\WINNT\system32\lsass.exe] [Microsoft Corporation, 5.00.2195.6902]
[PID: 368][C:\WINNT\System32\SCardSvr.exe] [Microsoft Corporation, 5.00.2195.6609]
[PID: 456][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 484][C:\Program Files\Rising\Rav\CCenter.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[PID: 540][C:\WINNT\system32\spoolsv.exe] [Microsoft Corporation, 5.00.2195.6659]
[PID: 576][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 620][C:\WINNT\system32\regsvc.exe] [Microsoft Corporation, 5.00.2195.6701]
[PID: 644][C:\WINNT\system32\MSTask.exe] [Microsoft Corporation, 4.71.2195.6704]
[PID: 684][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] [Analog Devices, Inc., 3, 2, 6, 0]
[PID: 736][C:\WINNT\System32\WBEM\WinMgmt.exe] [Microsoft Corporation, 1.50.1085.0100]
[PID: 752][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 912][C:\Program Files\Rising\Rav\RavStub.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 16]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 1144][C:\WINNT\Explorer.EXE] [Microsoft Corporation, 5.00.3700.6690]
[c:\program files\rising\rav\huqvjxzu.dll] [, 1, 0, 0, 11]
[C:\WINNT\system32\hazod.dll] [N/A, N/A]
[C:\WINNT\system32\drivers\3shazo.sys] [N/A, N/A]
[C:\WINNT\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
[PID: 1236][C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe] [InstallShield Software Corporation, 3, 10, 100, 1146]
[PID: 1272][C:\WINNT\system32\ep2k_certd_bc.exe] [, 1, 0, 4, 1011]
[C:\WINNT\system32\ep2pk11_bc.dll] [, 2, 4, 4, 1202]
[C:\WINNT\system32\drivers\3shazo.sys] [N/A, N/A]
[C:\WINNT\system32\hazod.dll] [N/A, N/A]
[PID: 1308][C:\WINNT\system32\ep2k_mon_bc.exe] [, 1, 1, 4, 1202]
[C:\WINNT\system32\hazod.dll] [N/A, N/A]
[C:\WINNT\system32\drivers\3shazo.sys] [N/A, N/A]
[PID: 1324][C:\WINNT\system32\rundll32.exe] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\hazod.dll] [N/A, N/A]
[C:\WINNT\system32\drivers\3shazo.sys] [N/A, N/A]
[PID: 1352][C:\WINNT\system32\internat.exe] [Microsoft Corporation, 5.00.2920.0000]
[C:\WINNT\system32\hazod.dll] [N/A, N/A]
[C:\WINNT\system32\drivers\3shazo.sys] [N/A, N/A]
[PID: 1364][C:\WINNT\system32\b0ti7w.exe] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\drivers\3shazo.sys] [N/A, N/A]
[C:\WINNT\system32\hazod.dll] [N/A, N/A]
[PID: 1276][C:\Program Files\Rising\Rav\RsAgent.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 12]
[C:\WINNT\system32\drivers\3shazo.sys] [N/A, N/A]
[C:\WINNT\system32\hazod.dll] [N/A, N/A]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[PID: 1396][C:\WINNT\msagent\AgentSvr.exe] [Microsoft Corporation, 2.00.0.3422]
[C:\WINNT\system32\drivers\3shazo.sys] [N/A, N/A]
[C:\WINNT\system32\hazod.dll] [N/A, N/A]
[PID: 824][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2800.1106]
[C:\WINNT\system32\drivers\3shazo.sys] [N/A, N/A]
[C:\WINNT\system32\hazod.dll] [N/A, N/A]
[C:\WINNT\system32\KakaTool.dll] [Beijing Rising Technology Co., Ltd., 2, 0, 2, 1]
[C:\WINNT\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[C:\WINNT\system32\WINWB86.IME] [Microsoft Corporation, 4.00.950]
[PID: 1128][C:\Documents and Settings\saq\桌面\090\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\WINNT\system32\drivers\3shazo.sys] [N/A, N/A]
[C:\WINNT\system32\hazod.dll] [N/A, N/A]
[C:\WINNT\system32\NpOpenStore.dll] [N/A, N/A]
[C:\WINNT\system32\NPCard.dll] [N/A, N/A]
[C:\WINNT\system32\RsaFun.dll] [N/A, N/A]
[C:\WINNT\system32\GPKPCSC.dll] [N/A, N/A]
==================================
文件关联
.TXT Error. [notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. [hh.exe %1]
.HLP Error. [C:\WINNT\system32\winhlp32.exe %1]
.INI Error. [notepad.exe %1]
.INF Error. [notepad.exe %1]
.VBS Error. [wscript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
125.91.14.230 www.kzdh.com
125.91.14.230 www.7255.com
125.91.14.230 www.7322.com
125.91.14.230 www.7939.com
125.91.14.230 www.piaoxue.com
125.91.14.230 www.feixu.net
125.91.14.230 www.6781.com
125.91.14.230 www.7b.com.cn
125.91.14.230 7b.com.cn
125.91.14.230 www.918188.com
125.91.14.230 hao.allxue.com
125.91.14.230 good.allxue.com
125.91.14.230 baby.allxue.com
125.91.14.230 www.allxue.com
125.91.14.230 about.lank.la
125.91.14.230 www.x114x.com
125.91.14.230 www.37ss.com
125.91.14.230 www.7k.cc
125.91.14.230 www.73ss.com
125.91.14.230 www.hao123.com
125.91.14.230 www.81915.com
125.91.14.230 222.88.90.22
125.91.14.230 www.9991.com
125.91.14.230 www.my123.com
125.91.14.230 www.haokan123.com
125.91.14.230 www.5566.net
125.91.14.230 www.gjj.cc
125.91.14.230 www.2345.com
125.91.14.230 dl.hao318.com
125.91.14.230 www.123wa.com
==================================