正在运行的进程
[PID: 496][\SystemRoot\System32\smss.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[PID: 560][\??\D:\WINDOWS\system32\csrss.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[PID: 584][\??\D:\WINDOWS\system32\winlogon.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[PID: 628][D:\WINDOWS\system32\services.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[D:\WINDOWS\system32\quartz32.dll] ()(4, 0, 0, 0)
[PID: 640][D:\WINDOWS\system32\lsass.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[PID: 788][D:\WINDOWS\system32\svchost.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[PID: 856][D:\WINDOWS\system32\svchost.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[D:\WINDOWS\system32\quartz32.dll] ()(4, 0, 0, 0)
[PID: 920][D:\Program Files\Rising\Rav\CCenter.exe] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 3)
[PID: 936][D:\WINDOWS\System32\svchost.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[D:\WINDOWS\system32\quartz32.dll] ()(4, 0, 0, 0)
[C:\oracle\bin\oci.dll] (Oracle Corporation)(8.1.7.0.0)
[PID: 1060][D:\WINDOWS\system32\svchost.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[PID: 1140][D:\WINDOWS\system32\svchost.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[PID: 1156][D:\Program Files\Rising\Rav\Ravmond.exe] (Beijing Rising Technology Co., Ltd.)(18, 0, 1, 33)
[D:\Program Files\Rising\Rav\BWList.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 19)
[D:\Program Files\Rising\Rav\RsCommX.dll] (rising)(18, 0, 0, 1)
[D:\Program Files\Rising\Rav\RSAPPMGR.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 2)
[D:\Program Files\Rising\Rav\CfgDll.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 11)
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[D:\Program Files\Rising\Rav\RsLog.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 20)
[D:\Program Files\Rising\Rav\HOOKSYS.dll] (Beijing Rising Technology Co., Ltd.)(18, 1, 0, 11)
[D:\Program Files\Rising\Rav\Scanner.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 30)
[D:\Program Files\Rising\Rav\libload.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 10)
[D:\Program Files\Rising\Rav\VirusLib.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 10)
[D:\Program Files\Rising\Rav\regmon.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 6)
[D:\Program Files\Rising\Rav\HookWeb.dll] (rising)(18, 0, 0, 2)
[D:\Program Files\Rising\Rav\MemMon.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 10)
[D:\Program Files\Rising\Rav\expscan.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[D:\Program Files\Rising\Rav\mPorts.dll] (Beijing Rising Technology Co., Ltd.)(4, 0, 0, 3)
[D:\Program Files\Rising\Rav\MailMon.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 5)
[D:\Program Files\Rising\Rav\SpamEng.dll] (N/A)(18, 0, 0, 6)
[D:\Program Files\Rising\Rav\engine.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 30)
[D:\WINDOWS\system32\quartz32.dll] ()(4, 0, 0, 0)
[D:\Program Files\Rising\Rav\PostTrt.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 12)
[D:\Program Files\Rising\Rav\UnExe.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 11)
[D:\Program Files\Rising\Rav\ScanExec.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 11)
[D:\Program Files\Rising\Rav\ScanEx.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 14)
[D:\Program Files\Rising\Rav\NvFile.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 7)
[D:\Program Files\Rising\Rav\ScanMac.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 9)
[D:\Program Files\Rising\Rav\ScanSct.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 18)
[D:\Program Files\Rising\Rav\Unpacker.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 3)
[D:\Program Files\Rising\Rav\ScanNet.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 5)
[D:\Program Files\Rising\Rav\ExtOLE.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 6)
[D:\Program Files\Rising\Rav\RsStore.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 5)
[PID: 1320][D:\WINDOWS\system32\spoolsv.exe] (Microsoft Corporation)(5.1.2600.2696 (xpsp_sp2_gdr.050610-1519))
[D:\WINDOWS\system32\ZLhp1020.DLL] (Zenographics, Inc.)(5, 53, 2317, 0)
[D:\WINDOWS\system32\ZLM.dll] (Zenographics, Inc.)(5, 50, 1416, 0)
[D:\WINDOWS\System32\spool\PRTPROCS\W32X86\IMFPrint.DLL] (Zenographics, Inc.)(5, 54, 330, 0)
[D:\WINDOWS\system32\Imf32.dll] (Zenographics, Inc.)(5, 60, 1204, 0)
[D:\WINDOWS\system32\ZTAG32.dll] (Zenographics, Inc.)(5, 60, 1210, 0)
[D:\WINDOWS\system32\ZSPOOL.dll] (Zenographics, Inc.)(5, 51, 709, 0)
[PID: 1400][D:\Program Files\Rising\Rav\RavStub.exe] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 16)
[D:\Program Files\Rising\Rav\RsCommX.dll] (rising)(18, 0, 0, 1)
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[PID: 1628][D:\WINDOWS\system32\rundll32.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[D:\PROGRA~1\MMSASS~1\MMSSVER.DLL] ()(1, 2, 0, 6)
[D:\WINDOWS\system32\quartz32.dll] ()(4, 0, 0, 0)
[PID: 344][D:\WINDOWS\System32\alg.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[D:\WINDOWS\system32\quartz32.dll] ()(4, 0, 0, 0)
[PID: 1728][D:\WINDOWS\system32\mouser.exe] (N/A)(N/A)
[D:\WINDOWS\system32\quartz32.dll] ()(4, 0, 0, 0)
[D:\WINDOWS\system32\sisserver.dll] ()()
[D:\WINDOWS\system32\SoarInfoIO.dll] (SoarInfo Software Studio.)(3, 0, 0, 0)
[PID: 1800][D:\WINDOWS\Explorer.EXE] (Microsoft Corporation)(6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))
[D:\WINDOWS\system32\RavExt.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 21)
[D:\WINDOWS\system32\sisserver.dll] ()()
[D:\WINDOWS\system32\SoarInfoIO.dll] (SoarInfo Software Studio.)(3, 0, 0, 0)
[D:\Program Files\Internet Download Manager\IDMIECC.dll] (Internet Download Manager Corp., Tonec Inc.)(1, 0, 2, 1)
[D:\WINDOWS\fonts\msshapi.dll] ()(1, 0, 0, 1)
[D:\Program Files\Internet Download Manager\idmmkb.dll] (N/A)(N/A)
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[D:\Program Files\WinRAR\rarext.dll] (N/A)(N/A)
[D:\PROGRA~1\sanlink\INPUT_~1\contmenu.dll] (N/A)(N/A)
[PID: 260][D:\Program Files\Rising\Rav\RavTask.exe] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 22)
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[D:\Program Files\Rising\Rav\RSAPPMGR.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 2)
[D:\Program Files\Rising\Rav\CfgDll.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 11)
[D:\Program Files\Rising\Rav\RsCommX.dll] (rising)(18, 0, 0, 1)
[D:\WINDOWS\system32\sisserver.dll] ()()
[D:\WINDOWS\system32\SoarInfoIO.dll] (SoarInfo Software Studio.)(3, 0, 0, 0)
[PID: 276][D:\Program Files\Rising\Rav\Ravmon.exe] (Beijing Rising Technology Co., Ltd.)(18, 0, 1, 30)
[D:\Program Files\Rising\Rav\RsGuiLib.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 24)
[D:\Program Files\Rising\Rav\BWList.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 19)
[D:\Program Files\Rising\Rav\RSAPPMGR.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 2)
[D:\Program Files\Rising\Rav\CfgDll.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 11)
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[D:\Program Files\Rising\Rav\RsCommX.dll] (rising)(18, 0, 0, 1)
[D:\Program Files\Rising\Rav\PngDll.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 5)
[D:\WINDOWS\system32\sisserver.dll] ()()
[D:\WINDOWS\system32\SoarInfoIO.dll] (SoarInfo Software Studio.)(3, 0, 0, 0)
[PID: 456][D:\WINDOWS\system32\SiSServer.exe] ()()
[D:\WINDOWS\system32\sisserver.dll] ()()
[D:\WINDOWS\system32\SoarInfoIO.dll] (SoarInfo Software Studio.)(3, 0, 0, 0)
[PID: 1976][D:\WINDOWS\system32\ctfmon.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[D:\WINDOWS\system32\sisserver.dll] ()()
[D:\WINDOWS\system32\SoarInfoIO.dll] (SoarInfo Software Studio.)(3, 0, 0, 0)
[PID: 1912][D:\WINDOWS\system32\rundll32.exe] (Microsoft Corporation)(5.1.2600.2180 (xpsp_sp2_rtm.040803-2158))
[D:\DOCUME~1\王进杰\TEMPLA~1\eb76e9c\1.dll] (千橡互联)(3, 0, 1, 0)
[D:\WINDOWS\system32\sisserver.dll] ()()
[D:\WINDOWS\system32\SoarInfoIO.dll] (SoarInfo Software Studio.)(3, 0, 0, 0)
[D:\DOCUME~1\王进杰\TEMPLA~1\eb76e9c\3.dll] (千橡互联)(3, 0, 1, 0)
[D:\DOCUME~1\王进杰\TEMPLA~1\eb76e9c\4.dll] (千橡互联)(3, 0, 1, 0)
[D:\WINDOWS\system32\quartz32.dll] ()(4, 0, 0, 0)
[PID: 4092][D:\Program Files\Tencent\TT\TTraveler.exe] (腾讯公司)(3.0.0.250)
[D:\WINDOWS\system32\sisserver.dll] ()()
[D:\WINDOWS\system32\SoarInfoIO.dll] (SoarInfo Software Studio.)(3, 0, 0, 0)
[D:\Program Files\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll] (腾讯公司)(1, 1, 0, 5)
[D:\Program Files\Tencent\TT\Plugins\TWeather\TWeather.dll] ()(1, 0, 0, 3)
[D:\Program Files\Tencent\TT\PersonalDesktop.dll] (深圳市腾讯计算机系统公司QQ工作小组)(1, 0, 0, 4)
[D:\WINDOWS\system32\quartz32.dll] ()(4, 0, 0, 0)
[D:\Program Files\Rising\Rav\RavScrCh.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[D:\WINDOWS\system32\PYJJ4.IME] (加加工作组)(4.0.0.20)
[D:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx] (Macromedia, Inc.)(8,0,24,0)
[PID: 3916][D:\Documents and Settings\王进杰\桌面\20066121353032646\SREng\SREng.exe] (Smallfrogs Studio)(2.0.21.505)
[D:\WINDOWS\system32\sisserver.dll] ()()
[D:\WINDOWS\system32\SoarInfoIO.dll] (SoarInfo Software Studio.)(3, 0, 0, 0)
[D:\WINDOWS\system32\quartz32.dll] ()(4, 0, 0, 0)
[PID: 736][D:\Program Files\jj4\jjsvr4.exe] (加加开发组)(4.0.0.19)
[D:\WINDOWS\system32\sisserver.dll] ()()
[D:\WINDOWS\system32\SoarInfoIO.dll] (SoarInfo Software Studio.)(3, 0, 0, 0)
--------------------------------------------------------------------------------
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["D:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]