正在运行的进程
[PID: 404][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 668][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\2663ABDF.DLL] [Microsoft Corporation, ]
[PID: 1348][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\WINDOWS\system32\itqqt.dll] [N/A, ]
[C:\WINDOWS\system32\2663ABDF.DLL] [Microsoft Corporation, ]
[c:\progra~1\winp\stub.dll] [, 1, 0, 0, 6]
[c:\progra~1\winp\play.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\winform.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
[C:\WINDOWS\system32\pdkpri.dll] [N/A, ]
[E:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[E:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[d:\Program Files\WinRAR\rarext.dll] [N/A, ]
[F:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_006.dll] [Thunder Networking Technologies,LTD, 5, 0, 0, 3]
[PID: 1780][e:\program files\rising\rfw\RfwMain.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 70]
[e:\program files\rising\rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[C:\WINDOWS\system32\2663ABDF.DLL] [Microsoft Corporation, ]
[e:\program files\rising\rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[e:\program files\rising\rfw\RfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[e:\program files\rising\rfw\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[e:\program files\rising\rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[c:\progra~1\winp\stub.dll] [, 1, 0, 0, 6]
[c:\progra~1\winp\play.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINDOWS\system32\pdkpri.dll] [N/A, ]
[PID: 440][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6]
[C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[c:\progra~1\winp\stub.dll] [, 1, 0, 0, 6]
[c:\progra~1\winp\play.dll] [ , 1, 0, 0, 6]
[PID: 552][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\progra~1\winp\stub.dll] [, 1, 0, 0, 6]
[c:\progra~1\winp\play.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 7788][C:\Documents and Settings\Administrator\桌面\seg\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[c:\progra~1\winp\stub.dll] [, 1, 0, 0, 6]
[c:\progra~1\winp\play.dll] [ , 1, 0, 0, 6]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
127.0.0.1 popwin.9983.com
61.152.169.246 www.kuaiso.com
61.152.169.246 www.my6688.cn
61.152.169.246 www.union123.com
61.152.169.246 www.ktan.cn
61.152.169.246 www.2t2t.cn
61.152.169.246 www.cq530.com
61.152.169.246 www.365tc.com
61.152.169.246 ad.qucha.net
61.152.169.246 www.tan8.cn
61.152.169.246 www.itjj.net
61.152.169.246 www.start188.com
61.152.169.246 www.at58.cn
61.152.169.246 union.yxad.com
61.152.169.246 www.iptan.com
61.152.169.246 www.ip2008.net
61.152.169.246 www.yqif.com
61.152.169.246 www.2t2t.cn
61.152.169.246 www.688ip.com
61.152.169.246 www.17tc.com
61.152.169.246 www.zztan.com
61.152.169.246 www.5tanip.com
61.152.169.246 www.16tc.com
61.152.169.246 www.163se.net
61.152.169.246 www.724tc.com
61.152.169.246 www1.6tan.com
61.152.169.246 www2.6tan.com
61.152.169.246 www.6tan.com
61.152.169.246 quxiuu.com
61.152.169.246 www.quxiuu.com
61.152.169.246 www.23b.cn
61.152.169.246 www.ookkw.com
61.152.169.246 www.97725.com
61.152.169.246 down.97725.com
61.152.169.246 www.54699.com
61.152.169.246 web.77276.com
61.152.169.246 www.77276.com
61.152.169.246 d.77276.com
61.152.169.246 do.77276.com
61.152.169.246 i.96981.com
61.152.169.246 wm.103715.com
61.152.169.246 www.138505.com
61.152.169.246 cool.47555.com
61.152.169.246 www.437799.com
61.152.169.246 www.168080.com
61.152.169.246 www.baidu8.org
61.152.169.246 d.qbbd.com
61.152.169.246 w.qbbd.com
61.152.169.246 www.npjxjy.com
61.152.169.246 www.wwwlm.net
61.152.169.246 new2.jixie123.cn
61.152.169.246 www.18dmm.com
61.152.169.246 www.souxse.cn
61.152.169.246 dm1.yiall.com
61.152.169.246 www.nze21.com
61.152.169.246 www.puma163.com
61.152.169.246 www.hyap98.com
61.152.169.246 www.51liulan.cn
61.152.169.246 s.gcuj.com
61.152.169.246 long.down988.cn
61.152.169.246 x.vvcyin.com
61.152.169.246 w.vvcyin.com
61.152.169.246 cc.wzxqy.com
61.152.169.246 ip.315hack.com
61.152.169.246 ip.54liumang.com
61.152.169.246 www.41ip.com
61.152.169.246 xulao.com
61.152.169.246 www.xulao.com
61.152.169.246 www.heixiou.com
61.152.169.246 www.9cyy.com
61.152.169.246 adnx.yygou.cn
61.152.169.246 www1.cw988.cn
61.152.169.246 www2.cw988.cn
61.152.169.246 www.asdwc.com
61.152.169.246 ceoww.com
61.152.169.246 boolom.com
61.152.169.246 www.boolom.com
61.152.169.246 www.tellumore.com
61.152.169.246 www.o1wg.com
61.152.169.246 www.qq756.com
61.152.169.246 ll.chinasese.net
61.152.169.246 www.cnwangmeng.cn
61.152.169.246 0.82211.net
61.152.169.246 rising.whatthishome.com
61.152.169.246 www.canqiou.com
61.152.169.246 www.if56.cn
61.152.169.246 woai777.com
61.152.169.246 www.cz-kc.com
61.152.169.246 www.f1ash8.net
61.152.169.246 new.hackpp.com
61.152.169.246 ad.taoip.cn
61.152.169.246 www.game53.com
61.152.169.246 up.boolom.com
61.152.169.246 t.gcuj.com
==================================
API HOOK
N/A
==================================
隐藏进程
N/A