[PID: 1428][C:\WINNT\System32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[PID: 1488][C:\WINNT\system32\conime.exe] [Microsoft Corporation, 5.00.2195.6655]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
[PID: 1340][C:\Program Files\上海天安信\TAX CSP V2.1\TaxKeyManager.exe] [, 1, 0, 0, 2]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
[PID: 1352][C:\Program Files\95599 Certificate Tools\CIDC\RegCertTool.exe] [CIDC, 1, 0, 0, 10]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
[PID: 1316][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 3]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
[PID: 1568][C:\WINNT\system32\internat.exe] [Microsoft Corporation, 5.00.2920.0000]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
[PID: 1580][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\zts2.exe] [N/A, N/A]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\zts2.dll] [N/A, N/A]
[PID: 1084][C:\Program Files\Netease\POPO2004\popo.exe] [网易(163.com), 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\XGDI.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\XFile.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\P2PMgr.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\XComm.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\Trace.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\Updater.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\UNZIP32.dll] [Info-ZIP, 5.5]
[C:\Program Files\Netease\POPO2004\ResLoc.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\MailChecker.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\ExtraEditor.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\XMP.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\fmod.dll] [Firelight Technologies Pty, Ltd, 3.73]
[C:\Program Files\Netease\POPO2004\UrlObj.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\WebService.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\Bobo.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\SOX.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\share.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\XVideo.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\VCodec.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\XVoice.dll] [, 1, 0, 0, 2]
[C:\Program Files\Netease\POPO2004\GIPSVoiceEngineDLL.dll] [Global IP Sound, 2, 0, 4, 0]
[C:\Program Files\Netease\POPO2004\XEmotion.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\MsgHis.dll] [, 1, 0, 0, 1]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
[C:\Program Files\Netease\POPO2004\plugins\MSN.DLL] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\plugins\LIBCURL.dll] [N/A, N/A]
[C:\Program Files\Netease\POPO2004\plugins\SSLEAY32.dll] [N/A, N/A]
[C:\Program Files\Netease\POPO2004\plugins\LIBEAY32.dll] [N/A, N/A]
[C:\Program Files\Netease\POPO2004\plugins\ppmakeurl.dll] [N/A, N/A]
[C:\WINNT\system32\FREEWB.IME] [Delphi Fan Studio, 5.0]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 288][C:\Documents and Settings\Administrator\My Documents\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\WINNT\system32\windhcp.ocx] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 5]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A