==================================
正在运行的进程
[PID: 676][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 740][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 764][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\rsmydpm.dll] [N/A, N/A]
[PID: 812][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\rsmydpm.dll] [N/A, N/A]
[PID: 824][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\rsmydpm.dll] [N/A, N/A]
[PID: 988][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\rsmydpm.dll] [N/A, N/A]
[PID: 1056][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\rsmydpm.dll] [N/A, N/A]
[PID: 1172][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\rsmydpm.dll] [N/A, N/A]
[PID: 1252][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\rsmydpm.dll] [N/A, N/A]
[PID: 1348][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\rsmydpm.dll] [N/A, N/A]
[PID: 1752][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\rsmydpm.dll] [N/A, N/A]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\WINDOWS\System32\shlhook.dll] [Beijing Rising Technology Co., Ltd., 4.0.0.9]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\WINDOWS\system32\rsztcpm.dll] [N/A, N/A]
[C:\WINDOWS\system32\kawdbzy.dll] [N/A, N/A]
[C:\WINDOWS\system32\rarjbpi.dll] [N/A, N/A]
[C:\WINDOWS\System32\xunleibho_v4.dll] [, 4, 3, 2, 29]
[D:\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.0.2003051500]
[E:\FLASHGET\jccatch.dll] [Amaze Soft, 1, 1, 4, 0]
[C:\PROGRA~1\WINZIP\WZSHLSTB.DLL] [WinZip Computing, Inc., 4.1 (32-bit)]
[D:\rar\rarext.dll] [N/A, N/A]
[D:\av\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1860][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\rsmydpm.dll] [N/A, N/A]
[C:\WINDOWS\System32\AdobePDF.dll] [Adobe Systems Incorporated., 6.0.000]
[D:\Acrobat 6.0\Distillr\AdistRes.CHS] [N/A, N/A]
[C:\WINDOWS\system32\CAP3LMK.DLL] [CANON INC., 1.00.0.007]
[C:\WINDOWS\system32\CAP3SMK.DLL] [CANON INC., 1.00.0.007]
[C:\WINDOWS\system32\CAP3PTMN.DLL] [CANON INC., 1.00.0.007]
[C:\WINDOWS\system32\OLFMNT40.DLL] [Microsoft Corporation, 9.0.98.0105]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\olfpnt40.dll] [Microsoft Corporation, 9.0.98.0105]
[C:\WINDOWS\system32\CAP3EMN.DLL] [CANON INC., 1.00.0.007]
[PID: 388][C:\Program Files\Multimedia Card Reader\shwicon2k.exe] [Alcor Micro, Corp., 1, 4, 0, 8]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 404][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 4.0.0.18]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 468][C:\WINDOWS\system32\RunDll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system\cmicnfg.cpl] [C-Media Corporation, 1, 0, 41, 2]
[C:\WINDOWS\System32\udaprop.dll] [C-Media Corporation, 1.0.2.2]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 492][C:\WINDOWS\system32\CAP3RSK.EXE] [CANON INC., 1.00.0.007]
[PID: 572][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\rsmydpm.dll] [N/A, N/A]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 1292][C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE] [CANON INC., 1.00.0.007]
[C:\WINDOWS\system32\rsmydpm.dll] [N/A, N/A]
[C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3PMN.DLL] [CANON INC., 1.00.0.007]
[C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SMK.DLL] [CANON INC., 1.00.0.007]
[PID: 1512][D:\Acrobat 6.0\Distillr\acrotray.exe] [Adobe Systems Inc., 6.0.0.2003051500]
[D:\Acrobat 6.0\Distillr\acrotray.chs] [Adobe Systems Inc., 6.0.0.0]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[PID: 424][C:\WINDOWS\System32\GEARSEC.EXE] [GEAR Software, 1, 0, 0, 3]
[PID: 608][C:\Program Files\Common Files\LightScribe\LSSrvc.exe] [, 1.0.21.1]
[PID: 1196][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\rsmydpm.dll] [N/A, N/A]
[PID: 568][C:\Program Files\Canon\CAL\CALMAIN.exe] [Canon Inc., 8, 0, 0, 21]
[PID: 2344][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 284][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\kawdbzy.dll] [N/A, N/A]
[D:\Acrobat 6.0\Acrobat\AcroIEFavClient.dll] [N/A, N/A]
[D:\Acrobat 6.0\Acrobat\AcroIEFavClient.CHS] [N/A, N/A]
[C:\WINDOWS\System32\xunleibho_v4.dll] [, 4, 3, 2, 29]
[D:\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.0.2003051500]
[D:\BitComet\tools\BitCometBHO_1.1.8.30.dll] [BitComet, 20070830]
[E:\FLASHGET\jccatch.dll] [Amaze Soft, 1, 1, 4, 0]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx] [Adobe Systems, Inc., 9,0,47,0]
[C:\WINDOWS\system32\rsmydpm.dll] [N/A, N/A]
[C:\WINDOWS\system32\rsztcpm.dll] [N/A, N/A]
[C:\WINDOWS\system32\rarjbpi.dll] [N/A, N/A]
[PID: 368][D:\SRE\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
[C:\WINDOWS\system32\rarjbpi.dll] [N/A, N/A]
[C:\WINDOWS\system32\rsztcpm.dll] [N/A, N/A]
[C:\WINDOWS\system32\rsmydpm.dll] [N/A, N/A]
[C:\WINDOWS\system32\kawdbzy.dll] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1 localhost
59.34.148.98 www.hao123.com
59.34.148.98 www.4199.com
59.34.148.98 www.9505.com
59.34.148.98 www.7322.com
218.5.76.175 www.huoche.com.cn
==================================
API HOOK
N/A
==================================