正在运行的进程
[PID: 428][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 500][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 524][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 568][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 580][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 744][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 824][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 896][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 908][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1296][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2600.0000 (xpclient.010817-1148)]
[E:\迅雷\ComDlls\XunLeiBHO_007.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
[PID: 1328][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 1476][D:\RISING\RISING\RAV\RavStub.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
[D:\RISING\RISING\RAV\RsCommX.dll] [rising, 18, 0, 0, 1]
[D:\RISING\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1576][D:\瑞星防火墙\Rising\Rfw\RfwMain.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 70]
[D:\瑞星防火墙\Rising\Rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[D:\瑞星防火墙\Rising\Rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[D:\瑞星防火墙\Rising\Rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[D:\瑞星防火墙\Rising\Rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[D:\瑞星防火墙\Rising\Rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[PID: 2020][C:\WINDOWS\SOUNDMAN.EXE] [Avance Logic, Inc., 5.0.02]
[PID: 2028][C:\WINDOWS\System32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 348][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 360][C:\WINDOWS\System32\upnpsvc.exe] [Microsoft Corporatio, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 420][C:\WINDOWS\System32\nvsvc32.exe] [NVIDIA Corporation, 6.13.10.4109]
[PID: 476][E:\电脑\SREng\SREng2\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 popwin.9983.com
219.129.239.223 www.npjxjy.com
219.129.239.223 quxiuu.com
219.129.239.223 www.23b.cn
219.129.239.223 www.baidulink.com
219.129.239.223 www.ookkw.com
219.129.239.223 www.97725.com
219.129.239.223 www.54699.com
219.129.239.223 www.wu7x.cn
219.129.239.223 d.qbbd.com
219.129.239.223 w.qbbd.com
219.129.239.223 web.77276.com
219.129.239.223 www.77276.com
219.129.239.223 www.npjxjy.com
219.129.239.223 www.baidulink.com
219.129.239.223 www.ookkw.com
219.129.239.223 www.wu7x.cn
219.129.239.223 www.wwwlm.net
219.129.239.223 dm1.yiall.com
219.129.239.223 www.my6688.cn
219.129.239.223 www.union123.com
219.129.239.223 www.ktan.cn
219.129.239.223 www.2t2t.cn
219.129.239.223 www.cq530.com
219.129.239.223 www.365tc.com
219.129.239.223 ad.qucha.net
219.129.239.223 www.tan8.cn
219.129.239.223 www.itjj.net
219.129.239.223 www.start188.com
219.129.239.223 www.at58.cn
219.129.239.223 union.yxad.com
219.129.239.223 www.iptan.com
219.129.239.223 www.ip2008.net
219.129.239.223 www.yqif.com
219.129.239.223 www.2t2t.cn
219.129.239.223 www.688ip.com
219.129.239.223 www.17tc.com
219.129.239.223 www1.6tan.com
219.129.239.223 www2.6tan.com
219.129.239.223 www.6tan.com
219.129.239.223 www.zztan.com
219.129.239.223 www.5tanip.com
219.129.239.223 www.16tc.com
219.129.239.223 www.163se.net
219.129.239.223 www.168080.com
219.129.239.223 www.baidu8.org
219.129.239.223 www.qqwei.com
219.129.239.223 qz.magforum.net
219.129.239.223 www.nze21.com
219.129.239.223 www.437799.com
219.129.239.223 www.168080.com
219.129.239.223 new2.jixie123.cn
219.129.239.223 www.18dmm.com
219.129.239.223 www.souxse.cn
219.129.239.223 x.vvcyin.com
219.129.239.223 dm1.yiall.com
219.129.239.223 www.168080.com
219.129.239.223 www.nze21.com
219.129.239.223 www.puma163.com
219.129.239.223 www.138505.com
==================================
API HOOK
N/A
==================================
[/CODE]