[C:\DOCUME~1\Admin\LOCALS~1\Temp\upx1.dll] [N/A, N/A]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[PID: 1404][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\fppmon1.dll] [FinePrint Software, LLC, 1.57]
[C:\WINDOWS\system32\fppr132.dll] [细致打印软件公司, 1.57]
[C:\WINDOWS\system32\SSGR3MK.DLL] [Samsung Electronics., 1.0.0.0]
[PID: 1492][C:\Program Files\Rising\Rav\RavStub.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1772][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1856][C:\WINDOWS\system32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 120][C:\Program Files\jj4\jjsvr4.exe] [加加开发组, 4.0.0.20]
[C:\WINDOWS\system32\PYJJ4.IME] [加加工作组, 4.0.0.21]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 180][C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe] [Adobe Systems Incorporated, 3.0.0.52115]
[C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdboot.dll] [Adobe Systems Incorporated, 3.0.0.52115]
[C:\WINDOWS\system32\PYJJ4.IME] [加加工作组, 4.0.0.21]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 188][C:\WINDOWS\Twain_32\Fjscan32\SOP\FtLnSOP.exe] [PFU LIMITED, 1, 0, 1, 2]
[C:\WINDOWS\system32\PYJJ4.IME] [加加工作组, 4.0.0.21]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 176][C:\WINDOWS\Twain_32\fjscan32\FjtwSetup.exe] [FUJITSU LIMITED, 1, 1, 8, 1]
[C:\WINDOWS\system32\PYJJ4.IME] [加加工作组, 4.0.0.21]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 200][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\WINDOWS\system32\PYJJ4.IME] [加加工作组, 4.0.0.21]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 204][C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis1.exe] [FinePrint Software, LLC, 1.57]
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppr132.dll] [细致打印软件公司, 1.57]
[C:\WINDOWS\system32\PYJJ4.IME] [加加工作组, 4.0.0.21]
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppint1.dll] [FinePrint Software, LLC, 1.57]
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppgraf1.dll] [FinePrint Software, LLC, 1.57]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 264][C:\Program Files\Rising\AntiSpyware\runiep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 3]
[C:\Program Files\Rising\AntiSpyware\iep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\WINDOWS\system32\PYJJ4.IME] [加加工作组, 4.0.0.21]
[PID: 280][C:\WINDOWS\wls3.exe] [N/A, N/A]
[C:\DOCUME~1\Admin\LOCALS~1\Temp\wls0.dll] [N/A, N/A]
[PID: 440][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\PYJJ4.IME] [加加工作组, 4.0.0.21]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 276][C:\Program Files\Netease\POPO2004\popo.exe] [网易(163.com), 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\XGDI.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\XFile.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\P2PMgr.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\XComm.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\Trace.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\Updater.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\UNZIP32.dll] [Info-ZIP, 5.5]
[C:\Program Files\Netease\POPO2004\ResLoc.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\MailChecker.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\ExtraEditor.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\XMP.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\fmod.dll] [Firelight Technologies Pty, Ltd, 3.73]
[C:\Program Files\Netease\POPO2004\UrlObj.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\WebService.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\Bobo.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\SOX.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\share.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\XVideo.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\VCodec.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\XVoice.dll] [, 1, 0, 0, 2]
[C:\Program Files\Netease\POPO2004\GIPSVoiceEngineDLL.dll] [Global IP Sound, 2, 0, 4, 0]
[C:\Program Files\Netease\POPO2004\XEmotion.dll] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\MsgHis.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\PYJJ4.IME] [加加工作组, 4.0.0.21]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\Program Files\Netease\POPO2004\plugins\MSN.DLL] [, 1, 0, 0, 1]
[C:\Program Files\Netease\POPO2004\plugins\LIBCURL.dll] [N/A, N/A]
[C:\Program Files\Netease\POPO2004\plugins\SSLEAY32.dll] [N/A, N/A]
[C:\Program Files\Netease\POPO2004\plugins\LIBEAY32.dll] [N/A, N/A]
[C:\DOCUME~1\Admin\LOCALS~1\Temp\wls0.dll] [N/A, N/A]
[C:\Program Files\Netease\POPO2004\plugins\ppmakeurl.dll] [N/A, N/A]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 1680][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2252][C:\Program Files\Rising\Rav\RsAgent.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\WINDOWS\system32\PYJJ4.IME] [加加工作组, 4.0.0.21]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[PID: 2280][C:\WINDOWS\msagent\AgentSvr.exe] [Microsoft Corporation, 2.00.0.3422]
[C:\WINDOWS\system32\PYJJ4.IME] [加加工作组, 4.0.0.21]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\DOCUME~1\Admin\LOCALS~1\Temp\wls0.dll] [N/A, N/A]
[PID: 1728][C:\Documents and Settings\Admin\My Documents\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\WINDOWS\system32\PYJJ4.IME] [加加工作组, 4.0.0.21]
[C:\Program Files\Rising\AntiSpyware\ieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 8]
[C:\DOCUME~1\Admin\LOCALS~1\Temp\wls0.dll] [N/A, N/A]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
繠?dテ
==================================