==================================
正在运行的进程
[PID: 672][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 740][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 764][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SSMWinlogonEx.dll] <System Safety Limited><2.0.8.582>
[PID: 808][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\wshcon32.dll] <><4, 0, 0, 0>
[PID: 820][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 968][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1032][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\wshcon32.dll] <><4, 0, 0, 0>
[PID: 1068][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[c:\windows\system32\acss.dll] <LINKMEDIA Tech><1, 5, 0, 4>
[c:\windows\system32\nwsapagent.dll] <LINKMEDIA Tech><1, 5, 0, 4>
[C:\WINDOWS\system32\wshcon32.dll] <><4, 0, 0, 0>
[PID: 1112][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1196][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1280][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\AdobePDF.dll] <Adobe Systems Incorporated.><7.0.0.00>
[C:\Program Files\Adobe\Acrobat 7.0\Distillr\AdistRes.CHS] <N/A><N/A>
[PID: 1600][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] <Adobe Systems, Inc.><7.0.0.0>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.CHS] <Adobe Systems, Inc.><7.0.0.0>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] <Adobe Systems Incorporated><7.0.0.2004121400>
[C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll] <Thunder Networking Technologies,LTD><5, 0, 0, 1>
[C:\PROGRA~1\baigoo\baigoohk.dll] < ><1, 0, 0, 1008>
[C:\WINDOWS\system32\wshcon32.dll] <><4, 0, 0, 0>
[C:\PROGRA~1\baigoo\baigoobh.dll] <><1, 0, 1, 1008>
[PID: 1728][C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe] <Roxio><6.1.1.18 >
[C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.LOC] <Roxio><6.1.1.18 >
[C:\PROGRA~1\COMMON~1\ROXIOS~1\DLLSHA~1\apm.dll] <><1, 0, 0, 1>
[C:\WINDOWS\system32\CDRTC.DLL] <Roxio><6.1.1.17 >
[C:\WINDOWS\system32\cdral.DLL] <Roxio><6.1.1.17 >
[PID: 1740][C:\WINDOWS\system32\hkeyman.exe] <Matsushita Electric Industrial Co., Ltd.><6.1.8.0>
[PID: 1748][C:\WINDOWS\system32\pctspk.exe] <><1, 0, 0, 1>
[PID: 1764][C:\WINDOWS\system32\hkcmd.exe] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\system32\hccutils.DLL] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\system32\igfxdev.dll] <Intel Corporation><3,0,0,2104>
[C:\PROGRA~1\baigoo\baigoohk.dll] < ><1, 0, 0, 1008>
[C:\WINDOWS\system32\igfxsrvc.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\system32\igfxhk.dll] <Intel Corporation><3,0,0,2104>
[C:\WINDOWS\system32\igfxres.dll] <Intel Corporation><3,0,0,2104>
[PID: 1772][C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe] <Adobe Systems Inc.><6.0.1.2004121400>
[C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.chs] <Adobe Systems Inc.><6.0.0.0>
[PID: 1780][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.1622>
[PID: 1788][C:\WINDOWS\system32\eventmgr.exe] <Microtek International Inc.><1, 0, 0, 1>
[PID: 1804][C:\Program Files\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[PID: 1812][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 432][C:\Program Files\ewido anti-malware 4.0\guard.exe] <N/A><4, 0, 0, 10>
[C:\Program Files\ewido anti-malware 4.0\engine.dll] <ewido networks GmbH & Co. KG><4, 0, 0, 7>
[PID: 536][C:\PROGRA~1\baigoo\Baigoo.exe] <baigoo.com><1, 0, 0, 1008>
[C:\PROGRA~1\baigoo\baigoohk.dll] < ><1, 0, 0, 1008>
[C:\PROGRA~1\baigoo\Bgooex.dll] <><1, 0, 0, 1008>
[PID: 648][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 684][C:\WINDOWS\system32\MsPMSPSv.exe] <Microsoft Corporation><7.01.00.3055>
[PID: 2176][C:\WINDOWS\system32\wscntfy.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\baigoo\baigoohk.dll] < ><1, 0, 0, 1008>
[PID: 2512][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\wshcon32.dll] <><4, 0, 0, 0>
[PID: 2636][C:\WINDOWS\system32\rundll32.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\sdmAgent20.dll] <LINKMEDIA Tech><1, 5, 0, 4>
[C:\PROGRA~1\baigoo\baigoohk.dll] < ><1, 0, 0, 1008>
[PID: 3864][C:\Program Files\Huawei-3Com\H3C 802.1X 客户端\Dot1XClient.exe] <N/A><N/A>
[C:\WINDOWS\system32\W32N50.dll] <Printing Communications Assoc., Inc. (PCAUSA)><5.03.16.56>
[C:\PROGRA~1\baigoo\baigoohk.dll] < ><1, 0, 0, 1008>
[PID: 4076][C:\WINDOWS\system32\conime.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\baigoo\baigoohk.dll] < ><1, 0, 0, 1008>
[PID: 3708][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\PROGRA~1\baigoo\baigoohk.dll] < ><1, 0, 0, 1008>
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] <Adobe Systems Incorporated><7.0.0.2004121400>
[C:\Program Files\Tencent\qq\QQIEHelper.dll] <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
[C:\PROGRA~1\baigoo\baigoobh.dll] <><1, 0, 1, 1008>
[C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll] <Thunder Networking Technologies,LTD><5, 0, 0, 1>
[C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll] <Adobe Systems Incorporated><7.0.0.0>
[C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.CHS] <Adobe Systems Incorporated><7.0.0.0>
[C:\WINDOWS\system32\CoolBho.dll] <LETSCOOL Network Technology><1, 3, 0, 1>
[C:\PROGRA~1\baigoo\bgook.dll] <baigoo><1, 0, 0, 1008>
[C:\PROGRA~1\baigoo\plugin\bgoobar\bgoobar.dll] <Baigoo><1, 0, 0, 1009>
[C:\PROGRA~1\baigoo\plugin\bgoobar\BRes2052.dll] <Baigoo><1, 0, 0, 1009>
[C:\PROGRA~1\baigoo\plugin\bgoocos\bgoocos.dll] <BAIGOO><1.0.0.1009>
[C:\PROGRA~1\baigoo\plugin\bgoolink\bgoolink.dll] <BAIGOO><1.0.0.1001>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] <Adobe Systems, Inc.><9,0,16,0>
[C:\WINDOWS\system32\wshcon32.dll] <><4, 0, 0, 0>
[C:\WINDOWS\system32\UNISPIM.IME] <北京清华紫光软件股份有限公司><3.0.0.3045>
[C:\WINDOWS\system32\upengine.dll] <北京清华紫光软件股份有限公司><3.0.0.3045>
[PID: 180][C:\Documents and Settings\shirley\桌面\sreng2\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\PROGRA~1\baigoo\baigoohk.dll] < ><1, 0, 0, 1008>
[C:\WINDOWS\system32\wshcon32.dll] <><4, 0, 0, 0>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS Error. [超级解霸3000]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================