[PID: 1436][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 1516][C:\Program Files\Rising\Rav\RavStub.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1664][C:\WINDOWS\system32\Rundll32.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
[C:\WINDOWS\downlo~1\CnsMinIO.dll] <北京三七二一科技有限公司><1, 0, 3, 6>
[C:\WINDOWS\downlo~1\cnsio.dll] <北京三七二一科技有限公司><1, 0, 2, 7>
[PID: 1720][c:\program files\rising\rfw\RfwMain.exe] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 48>
[c:\program files\rising\rfw\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
[c:\program files\rising\rfw\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[c:\program files\rising\rfw\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
[C:\PROGRA~1\3721\helper.dll] <><1, 0, 9, 1324>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[PID: 1860][C:\WINDOWS\system32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 544][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 688][D:\Herosoft\HeroV8\SYSEXPLR.EXE] <N/A><N/A>
[D:\Herosoft\HeroV8\AVCDROM.dll] <N/A><N/A>
[D:\Herosoft\HeroV8\CoolMenu.dll] <N/A><N/A>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
[D:\Herosoft\HeroV8\Sys936.DLL] <N/A><N/A>
[PID: 1156][D:\Program Files\QuickTime\qttask.exe] <Apple Computer, Inc.><6.5.1>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
[PID: 316][D:\Program Files\淘宝网\淘宝旺旺\WangWang.EXE] <淘宝(中国)软件有限公司><1, 5, 5, 1226>
[D:\Program Files\淘宝网\淘宝旺旺\AliViewCtrl.dll] <vline><1, 0, 0, 1>
[D:\Program Files\淘宝网\淘宝旺旺\VLNetwork.dll] <><1, 0, 0, 6>
[D:\Program Files\淘宝网\淘宝旺旺\AliViewMedia.dll] <vline><1, 0, 0, 1>
[D:\Program Files\淘宝网\淘宝旺旺\VideoCAP.dll] <><1, 0, 0, 4>
[D:\Program Files\淘宝网\淘宝旺旺\VLAudio.dll] <><1, 0, 0, 4>
[D:\Program Files\淘宝网\淘宝旺旺\JsmShow.dll] <><1, 0, 0, 3>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
[D:\Program Files\淘宝网\淘宝旺旺\Ali_Res.DLL] <N/A><N/A>
[C:\PROGRA~1\3721\helper.dll] <><1, 0, 9, 1324>
[D:\Program Files\淘宝网\淘宝旺旺\RichOne.dll] <淘宝(中国)软件有限公司><1.0.0.1>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1840][C:\WINDOWS\SOUNDMAN.EXE] <Realtek Semiconductor Corp.><5.0.14>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
[PID: 1976][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.3510>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
[PID: 2180][C:\Program Files\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
[PID: 2204][C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe] < ><2, 0, 0, 1002>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
[C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll] <><2, 1, 6, 1046>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] < ><2, 0, 1, 1007>
[C:\PROGRA~1\3721\helper.dll] <><1, 0, 9, 1324>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Ynotifier.dll] <><1, 0, 0, 5>
[PID: 2212][C:\Program Files\Rising\Rav\Ravmon.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 26>
[C:\Program Files\Rising\Rav\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[PID: 2232][C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe] <Yahoo!><1, 0, 1, 1001>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
[C:\PROGRA~1\Yahoo!\Assistant\shell\yAsMenu.dll] <Yahoo><1, 0, 1, 1006>
[C:\PROGRA~1\Yahoo!\Assistant\shell\yAssecblk.dll] <Yahoo><1, 0, 2, 1002>
[C:\PROGRA~1\Yahoo!\Assistant\shell\yIEAngel.dll] <Yahoo><1, 0, 1, 1001>
[C:\PROGRA~1\Yahoo!\Assistant\shell\yMenuInfo.dll] <Yahoo><1, 0, 0, 2>
[PID: 2256][C:\WINDOWS\system32\rundll32.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\3721\helper.dll] <><1, 0, 9, 1324>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
[C:\PROGRA~1\3721\autolive.dll] <><1, 1, 5, 1324>
[C:\PROGRA~1\3721\alLiveEx.dll] < ><1, 0, 3, 1006>
[C:\PROGRA~1\3721\notifier.dll] <><1, 0, 0, 5>
[PID: 2280][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\3721\helper.dll] <><1, 0, 9, 1324>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
[PID: 2308][C:\Program Files\Messenger\msmsgs.exe] <Microsoft Corporation><4.7.3001>
[C:\PROGRA~1\3721\helper.dll] <><1, 0, 9, 1324>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
[PID: 2320][C:\Program Files\MSN Messenger\MsnMsgr.Exe] <Microsoft Corporation><7.5.0324>
[C:\PROGRA~1\3721\helper.dll] <><1, 0, 9, 1324>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
[C:\WINDOWS\system32\msdmo.dll] <N/A><N/A>
[PID: 2460][C:\Program Files\Sandai Technologies Inc\Thunder\Thunder.exe] <深圳市三代科技开发有限公司><4, 5, 4, 41>
[C:\Program Files\Sandai Technologies Inc\Thunder\log4cplus.dll] <N/A><N/A>
[C:\Program Files\Sandai Technologies Inc\Thunder\ICF.dll] <N/A><N/A>
[C:\Program Files\Sandai Technologies Inc\Thunder\WebBrowserEx.dll] <N/A><N/A>
[C:\Program Files\Sandai Technologies Inc\Thunder\boost_thread-vc6-mt-1_31.dll] <N/A><N/A>
[C:\PROGRA~1\3721\helper.dll] <><1, 0, 9, 1324>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[PID: 2796][C:\WINDOWS\system32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[PID: 3340][C:\Program Files\WinRAR\WinRAR.exe] <N/A><N/A>
[C:\PROGRA~1\3721\helper.dll] <><1, 0, 9, 1324>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
[PID: 3376][C:\DOCUME~1\XIEXIA~1\LOCALS~1\Temp\Rar$EX00.797\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\PROGRA~1\3721\helper.dll] <><1, 0, 9, 1324>
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] <><2, 0, 1, 1018>
[C:\WINDOWS\downlo~1\CnsMin.dll] <北京三七二一科技有限公司><1, 5, 3, 3>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================