==================================
正在运行的进程
[PID: 160][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 184][\??\C:\WINNT\system32\csrss.exe] [Microsoft Corporation, 5.00.2195.6601]
[PID: 204][\??\C:\WINNT\system32\winlogon.exe] [Microsoft Corporation, 5.00.2195.6714]
[PID: 232][C:\WINNT\system32\services.exe] [Microsoft Corporation, 5.00.2195.6700]
[C:\WINNT\system32\dmserver.dll] [VERITAS Software Corp., 2195.6605.297.3]
[PID: 244][C:\WINNT\system32\lsass.exe] [Microsoft Corporation, 5.00.2195.6695]
[PID: 440][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 584][C:\WINNT\system32\spoolsv.exe] [Microsoft Corporation, 5.00.2195.6659]
[C:\WINNT\system32\CNMLM3D.DLL] [CANON INC., 1.32.2.5]
[PID: 612][C:\WINNT\system32\msdtc.exe] [Microsoft Corporation, 1999.9.3421.3]
[PID: 736][C:\WINNT\system32\tcpsvcs.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 752][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 800][C:\PROGRAM FILES\RISING\RAV\RavStub.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
[C:\PROGRAM FILES\RISING\RAV\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 920][C:\WINNT\System32\llssrv.exe] [Microsoft Corporation, 5.00.2195.6697]
[PID: 1056][C:\WINNT\system32\WINDOW~1\Server\nspmon.exe] [Microsoft Corporation, 4.1.00.3917]
[PID: 1076][C:\WINNT\system32\WINDOW~1\Server\nscm.exe] [Microsoft Corporation, 4.1.00.3930]
[PID: 1120][C:\WINNT\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.7801]
[PID: 1160][C:\WINNT\system32\regsvc.exe] [Microsoft Corporation, 5.00.2195.6701]
[PID: 1196][C:\WINNT\system32\MSTask.exe] [Microsoft Corporation, 4.71.2195.6704]
[PID: 1224][C:\WINNT\System32\snmp.exe] [Microsoft Corporation, 5.00.2195.6605]
[PID: 1256][C:\WINNT\system32\stisvc.exe] [Microsoft Corporation, 5.00.2195.6656]
[PID: 1320][C:\WINNT\System32\WBEM\WinMgmt.exe] [Microsoft Corporation, 1.50.1085.0100]
[PID: 1332][C:\WINNT\System32\wins.exe] [Microsoft Corporation, 5.00.2195.6696]
[PID: 1344][C:\WINNT\system32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 1384][C:\WINNT\system32\Dfssvc.exe] [Microsoft Corporation, 5.00.2195.6664]
[PID: 1428][C:\WINNT\System32\dns.exe] [Microsoft Corporation, 5.00.2195.6715]
[PID: 1480][C:\WINNT\system32\inetsrv\inetinfo.exe] [Microsoft Corporation, 5.00.0984]
[PID: 1504][C:\WINNT\system32\WINDOW~1\Server\nspm.exe] [Microsoft Corporation, 4.1.00.3917]
[C:\WINNT\system32\tssoft32.acm] [DSP GROUP, INC., 1.01]
[C:\WINNT\system32\tsd32.dll] [N/A, N/A]
[C:\WINNT\system32\l3codeca.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
[C:\WINNT\system32\iac25_32.ax] [Intel Corporation, 2.05.53]
[PID: 1652][C:\WINNT\system32\WINDOW~1\Server\nsum.exe] [Microsoft Corporation, 4.1.00.3930]
[PID: 1940][C:\WINNT\Explorer.EXE] [Microsoft Corporation, 5.00.3700.6690]
[C:\Program Files\Internet Explorer\PLUGINS\System64.sys] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINNT\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\WINNT\system32\wintdll.dll] [N/A, N/A]
[C:\WINNT\system32\mppds.dll] [N/A, N/A]
[C:\WINNT\system32\upxdnd.dll] [N/A, N/A]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\PROGRA~1\ftc\Commenu.dll] [Fygsoft and Microsoft, 2.0.0.0]
[C:\WINNT\system32\nvshell.dll] [N/A, N/A]
[C:\Program Files\IDM Computer Solutions\UltraEdit-32\ue32ctmn.dll] [, 1, 0, 0, 2]
[C:\WINNT\system32\nvtuicpl.cpl] [N/A, N/A]
[C:\WINNT\system32\NVWRSZHC.DLL] [NVIDIA Corporation, 6.14.10.10532]
[C:\WINNT\system32\msccrt.dll] [N/A, N/A]
[C:\WINNT\system32\Kvsc3.dll] [N/A, N/A]
[C:\WINNT\system32\nwizAsktao.dll] [N/A, N/A]
[C:\WINNT\system32\nwizhx2.dll] [N/A, N/A]
[C:\WINNT\system32\dh2103.dll] [N/A, N/A]
[PID: 1976][c:\program files\rising\rfw\RfwMain.exe] [Beijing Rising Technology Co., Ltd., 4, 0, 0, 52]
[c:\program files\rising\rfw\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 23]
[c:\program files\rising\rfw\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[c:\program files\rising\rfw\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Internet Explorer\PLUGINS\System64.sys] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2232][C:\WINNT\System32\svchost.exe] [Microsoft Corporation, 5.00.2134.1]
[PID: 2296][C:\WINNT\SOUNDMAN.EXE] [Avance Logic, Inc., 4.1]
[C:\Program Files\Internet Explorer\PLUGINS\System64.sys] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2132][D:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe] [eBay Inc., 2.5000.4.7]
[C:\Program Files\Internet Explorer\PLUGINS\System64.sys] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2112][C:\WINNT\system32\RUNDLL32.EXE] [Microsoft Corporation, 5.00.2134.1]
[C:\WINNT\system32\NvMcTray.dll] [NVIDIA Corporation, 6.14.10.7801]
[C:\Program Files\Internet Explorer\PLUGINS\System64.sys] [N/A, N/A]
[C:\WINNT\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.10.7801]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2020][C:\WINNT\system32\internat.exe] [Microsoft Corporation, 5.00.2920.0000]
[C:\Program Files\Internet Explorer\PLUGINS\System64.sys] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2360][C:\Program Files\MSN Messenger\MsnMsgr.Exe] [Microsoft Corporation, 7.0.0816]
[C:\Program Files\Internet Explorer\PLUGINS\System64.sys] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINNT\system32\msdmo.dll] [N/A, N/A]
[PID: 2516][C:\WINNT\system32\conime.exe] [Microsoft Corporation, 5.00.2195.6655]
[C:\Program Files\Internet Explorer\PLUGINS\System64.sys] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2500][C:\WINNT\IMEINPUTS.EXE] [N/A, N/A]
[PID: 2608][D:\Program Files\Tencent\TT\TTraveler.exe] [腾讯公司, 3.2.200.275]
[C:\Program Files\Internet Explorer\PLUGINS\System64.sys] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINNT\system32\msccrt.dll] [N/A, N/A]
[C:\WINNT\system32\upxdnd.dll] [N/A, N/A]
[C:\WINNT\system32\mppds.dll] [N/A, N/A]
[C:\WINNT\system32\wintdll.dll] [N/A, N/A]
[C:\WINNT\system32\kakatool.dll] [Beijing Rising Technology Co., Ltd., 2, 0, 3, 0]
[D:\Program Files\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll] [腾讯公司, 1, 1, 0, 5]
[D:\Program Files\Tencent\TT\Plugins\TWeather\TWeather.dll] [, 1, 0, 0, 3]
[D:\Program Files\Tencent\TT\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 4]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 312][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2600.0000]
[C:\Program Files\Internet Explorer\PLUGINS\System64.sys] [N/A, N/A]
[d:\Program Files\Tencent\QQ\QQIEHelper.dll] [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINNT\system32\Kvsc3.dll] [N/A, N/A]
[C:\WINNT\system32\msccrt.dll] [N/A, N/A]
[C:\WINNT\system32\upxdnd.dll] [N/A, N/A]
[C:\WINNT\system32\mppds.dll] [N/A, N/A]
[C:\WINNT\system32\wintdll.dll] [N/A, N/A]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINNT\system32\Macromed\Flash\Flash9c.ocx] [Adobe Systems, Inc., 9,0,45,0]
[PID: 660][C:\WINNT\system32\cmd.exe] [Microsoft Corporation, 5.00.2195.6656]
[PID: 2648][C:\Program Files\Rising\Rav\RsLogVw.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[C:\Program Files\Rising\Rav\RsCommx.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\rsguilib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
[C:\Program Files\Rising\Rav\RsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Internet Explorer\PLUGINS\System64.sys] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINNT\system32\Kvsc3.dll] [N/A, N/A]
[C:\WINNT\system32\msccrt.dll] [N/A, N/A]
[C:\WINNT\system32\upxdnd.dll] [N/A, N/A]
[C:\WINNT\system32\mppds.dll] [N/A, N/A]
[C:\WINNT\system32\wintdll.dll] [N/A, N/A]
[C:\Program Files\Rising\Rav\libload.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[C:\Program Files\Rising\Rav\VirusLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
[PID: 2176][G:\PRBAK\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\Program Files\Internet Explorer\PLUGINS\System64.sys] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[C:\WINNT\system32\Kvsc3.dll] [N/A, N/A]
[C:\WINNT\system32\msccrt.dll] [N/A, N/A]
[C:\WINNT\system32\upxdnd.dll] [N/A, N/A]
[C:\WINNT\system32\mppds.dll] [N/A, N/A]
[C:\WINNT\system32\wintdll.dll] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINNT\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS Error. [C:\WINNT\system32\WScript.exe "%1" %*]
.JS Error. [C:\WINNT\system32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
==================================