==================================
正在运行的进程
[PID: 560][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1040][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1064][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\System32\NavLogon.dll] <Symantec Corporation><9.0.0.338>
[PID: 1108][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1120][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1304][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1396][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1620][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1652][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1692][C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe] <Symantec Corporation><2.2.0.577>
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] <Symantec Corporation><2.2.0.577>
[PID: 1812][C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe] <Symantec Corporation><2.2.0.577>
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] <Symantec Corporation><2.2.0.577>
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCSETEVT.DLL] <Symantec Corporation><2.2.0.577>
[PID: 1932][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.0 (XPClient.010817-1148)>
[C:\WINDOWS\system32\EBPMON2.DLL] <SEIKO EPSON CORPORATION><2, 20, 0, 0>
[C:\WINDOWS\system32\HPBMMON.DLL] <Hewlett-Packard><10.00.16>
[C:\WINDOWS\system32\hpdomon.dll] <Hewlett-Packard><03.42.00>
[C:\WINDOWS\system32\HPBHealr.dll] <N/A><N/A>
[C:\WINDOWS\system32\PSNTMON.DLL] <Microsoft Corporation><4.00.950>
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\IMFPrint.DLL] <Zenographics, Inc.><5, 54, 330, 0>
[C:\WINDOWS\system32\Imf32.dll] <Zenographics, Inc.><5, 60, 1204, 0>
[C:\WINDOWS\system32\ZTAG32.dll] <Zenographics, Inc.><5, 60, 1210, 0>
[C:\WINDOWS\system32\ZSPOOL.dll] <Zenographics, Inc.><5, 51, 709, 0>
[PID: 156][C:\Program Files\Symantec AntiVirus\DefWatch.exe] <Symantec Corporation><9.0.0.338>
[PID: 164][C:\PROGRA~1\广东省~1\FireBird\bin\fbguard.exe] <The Firebird Project><WI-V1.5.1.4481>
[C:\PROGRA~1\广东省~1\FireBird\bin\fbclient.dll] <The Firebird Project><WI-V1.5.1.4481>
[PID: 204][C:\PROGRA~1\广东省~1\FireBird\bin\fbserver.exe] <The Firebird Project><WI-V1.5.1.4481>
[PID: 312][C:\Program Files\Symantec AntiVirus\SavRoam.exe] <symantec><1.5.0.0>
[C:\Program Files\Common Files\Symantec Shared\SSC\Transman.dll] <Symantec Corporation><9.0.0.338>
[C:\WINDOWS\system32\CBA.DLL] <Intel? Corporation><6.12.0.112 E>
[C:\WINDOWS\system32\MsgSys.dll] <Intel? Corporation><6.12.0.112 E>
[C:\WINDOWS\system32\NTS.dll] <Intel? Corporation><6.12.0.112 E>
[C:\WINDOWS\system32\PDS.DLL] <Intel? Corporation><6.12.0.112 E>
[PID: 520][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\System32\MSMUSD5.DLL] <Microtek International Inc.><5.80>
[PID: 548][C:\Program Files\Symantec AntiVirus\Rtvscan.exe] <Symantec Corporation><9.0.0.338>
[C:\WINDOWS\system32\CBA.DLL] <Intel? Corporation><6.12.0.112 E>
[C:\WINDOWS\system32\MsgSys.dll] <Intel? Corporation><6.12.0.112 E>
[C:\WINDOWS\system32\NTS.dll] <Intel? Corporation><6.12.0.112 E>
[C:\WINDOWS\system32\PDS.DLL] <Intel? Corporation><6.12.0.112 E>
[C:\Program Files\Symantec AntiVirus\NAVLU.dll] <Symantec Corporation><9.0.0.338>
[C:\Program Files\Symantec AntiVirus\I2ldvp3.dll] <Symantec Corporation><9.0.0.338>
[C:\Program Files\Symantec AntiVirus\ecmldr32.DLL] <Symantec Corp.><1.1.0.3>
[C:\Program Files\Symantec AntiVirus\SAVRT32.DLL] <Symantec Corporation><9.3.0.28>
[C:\Program Files\Symantec AntiVirus\NAVNTUTL.DLL] <Symantec Corporation><9.0.0.338>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060510.019\ecmsvr32.dll] <Symantec Corporation><61.1.0.11>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060510.019\NAVEX32a.DLL] <Symantec Corporation><20061.1.0.14>
[C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060510.019\NAVENG32.DLL] <Symantec Corporation><20061.1.0.14>
[C:\Program Files\Symantec AntiVirus\IMail.dll] <Symantec Corporation><9.0.0.338>
[C:\Program Files\Symantec AntiVirus\NotesExt.dll] <Symantec Corporation><9.0.0.338>
[C:\Program Files\Symantec AntiVirus\vpmsece.dll] <Symantec Corporation><9.0.0.338>
[C:\Program Files\Symantec AntiVirus\DecSDK.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2ID.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2ZIP.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2SS.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2GZIP.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2CAB.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2LHA.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2ARJ.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2TNEF.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2LZ.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2AMG.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2TAR.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2RTF.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Symantec AntiVirus\Dec2Text.dll] <Symantec Corporation><3.02.11.32>
[C:\Program Files\Common Files\Symantec Shared\SSC\scandlgs.dll] <Symantec Corporation><9.0.0.338>
[PID: 452][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2600.0000 (xpclient.010817-1148)>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 1>
[C:\WINDOWS\downlo~1\CnsHook.dll] <北京三七二一科技有限公司><1, 0, 2, 4>
[C:\WINDOWS\System32\igfxpph.dll] <Intel Corporation><3.0.0.2249>
[C:\WINDOWS\System32\hccutils.DLL] <Intel Corporation><3.0.0.2249>
[C:\WINDOWS\System32\igfxres.dll] <Intel Corporation><3.0.0.2249>
[C:\WINDOWS\System32\igfxsrvc.dll] <Intel Corporation><3.0.0.2249>
[C:\WINDOWS\System32\igfxdev.dll] <Intel Corporation><3.0.0.2249>
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll] <Yahoo! China><1, 1, 3, 1035>
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll] <Yahoo!><2, 1, 7, 1047>
[C:\WINDOWS\System32\igfxress.dll] <Intel Corporation><3.0.0.2249>
[PID: 720][C:\WINDOWS\System32\Rundll32.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 1>
[C:\WINDOWS\downlo~1\CnsMinIO.dll] <北京三七二一科技有限公司><1, 0, 3, 4>
[C:\WINDOWS\downlo~1\cnsio.dll] <北京三七二一科技有限公司><1, 0, 2, 5>
[C:\WINDOWS\downlo~1\CnsMinEx.dll] <国风因特软件(北京)有限公司><1, 0, 3, 1>
[PID: 932][C:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 1>
[PID: 1596][C:\Program Files\Messenger\msmsgs.exe] <Microsoft Corporation><4.0.0155>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 1>
[PID: 1680][C:\WINDOWS\System32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 1>
[PID: 3136][C:\Program Files\Windows Media Player\wmplayer.exe] <Microsoft Corporation><8.00.00.4477>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 1>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\WINDOWS\System32\l3codeca.acm] <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
[C:\WINDOWS\System32\ffdshow.ax] <N/A><1, 0, 1,1>
[C:\Program Files\Ringz Studio\Storm Codec\Codecs\VSFilter.dll] <Gabest><1, 0, 0, 9>
[PID: 2084][C:\Program Files\Outlook Express\msimn.exe] <Microsoft Corporation><6.00.2600.0000 (xpclient.010817-1148)>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 1>
[C:\WINDOWS\downlo~1\CnsHook.dll] <北京三七二一科技有限公司><1, 0, 2, 4>
[PID: 2420][C:\WINDOWS\system32\rundll32.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 1>
[PID: 1348][C:\Program Files\WinRAR\WinRAR.exe] <N/A><N/A>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 1>
[PID: 1512][C:\DOCUME~1\acc\LOCALS~1\Temp\Rar$EX00.079\SREng.exe] <Smallfrogs Studio><2.0.12.350>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 1>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================