[PID: 1892][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\system32\fpv5b.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\nmprt.sys] [N/A, N/A]
[C:\WINDOWS\system32\igfxpph.dll] [Intel Corporation, 3.0.0.4704]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4704]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4704]
[C:\WINDOWS\system32\igfxress.dll] [Intel Corporation, 3.0.0.4704]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4704]
[C:\PROGRA~1\FlashGet\jccatch.dll] [FlashGet, 1, 1, 5, 0]
[C:\WINDOWS\System32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 19]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[PID: 1980][C:\Program Files\Analog Devices\SoundMAX\SMTray.exe] [Analog Devices, Inc., 3, 2, 18, 0]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\system32\drivers\nmprt.sys] [N/A, N/A]
[C:\WINDOWS\system32\fpv5b.dll] [N/A, N/A]
[PID: 1988][C:\Program Files\IBM\Messages By IBM\ibmmessages.exe] [IBM, 2.012]
[C:\WINDOWS\system32\AIBMRUNL.dll] [N/A, N/A]
[C:\Program Files\IBM\Messages By IBM\AcpPollingEngine.dll] [, 1, 0, 0, 4]
[C:\WINDOWS\System32\IbmEgath.dll] [IBM Corporation, 3, 0, 0, 11]
[C:\WINDOWS\system32\drivers\nmprt.sys] [N/A, N/A]
[C:\WINDOWS\system32\fpv5b.dll] [N/A, N/A]
[PID: 1996][C:\IBMTOOLS\UTILS\ibmprc.exe] [IBM Corp., 1, 0, 0, 3]
[C:\WINDOWS\system32\drivers\nmprt.sys] [N/A, N/A]
[C:\WINDOWS\system32\fpv5b.dll] [N/A, N/A]
[PID: 2024][C:\Program Files\Rising\Rav\RavTray.exe] [Rising, 18, 0, 0, 35]
[C:\Program Files\Rising\Rav\RavUILib.dll] [, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\RavTray936.dll] [Rising, 18, 0, 0, 35]
[C:\Program Files\Rising\Rav\RsCommx.dll] [rising, 18, 0, 0, 1]
[C:\WINDOWS\system32\drivers\nmprt.sys] [N/A, N/A]
[C:\WINDOWS\system32\fpv5b.dll] [N/A, N/A]
[PID: 2044][C:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 22]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\WINDOWS\system32\drivers\nmprt.sys] [N/A, N/A]
[C:\WINDOWS\system32\fpv5b.dll] [N/A, N/A]
[PID: 264][C:\Program Files\Rising\Rav\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 1, 30]
[C:\Program Files\Rising\Rav\RsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 24]
[C:\Program Files\Rising\Rav\BWList.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 18]
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[C:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 10]
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[C:\Program Files\Rising\Rav\PngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[C:\WINDOWS\system32\fpv5b.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\nmprt.sys] [N/A, N/A]
[PID: 284][C:\WINDOWS\system32\hkcmd.exe] [Intel Corporation, 3.0.0.4704]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.4704]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4704]
[C:\WINDOWS\system32\igfxres.dll] [Intel Corporation, 3.0.0.4704]
[C:\WINDOWS\system32\drivers\nmprt.sys] [N/A, N/A]
[C:\WINDOWS\system32\fpv5b.dll] [N/A, N/A]
[PID: 308][C:\WINDOWS\system32\igfxpers.exe] [Intel Corporation, 3.0.0.4704]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.4704]
[C:\WINDOWS\system32\fpv5b.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\nmprt.sys] [N/A, N/A]
[PID: 424][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\system32\fpv5b.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\nmprt.sys] [N/A, N/A]
[PID: 468][C:\Program Files\MSN Messenger\MsnMsgr.Exe] [Microsoft Corporation, 7.5.0324]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\system32\fpv5b.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\nmprt.sys] [N/A, N/A]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[PID: 524][C:\Program Files\jj4\jiajiasr.exe] [加加工作组, 4, 0, 1, 33]
[C:\WINDOWS\system32\fpv5b.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\nmprt.sys] [N/A, N/A]
[PID: 576][C:\Program Files\Messenger\msmsgs.exe] [Microsoft Corporation, 4.7.3000]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\system32\fpv5b.dll] [N/A, N/A]
[C:\WINDOWS\system32\drivers\nmprt.sys] [N/A, N/A]
[PID: 592][C:\WINDOWS\system32\4eku0ag.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\drivers\nmprt.sys] [N/A, N/A]
[C:\WINDOWS\system32\fpv5b.dll] [N/A, N/A]
[PID: 1208][C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe] [, 4,0,0,4026]
[PID: 1236][C:\Program Files\Rising\Rav\RavService.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 43]
[C:\Program Files\Rising\Rav\DLCenter.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 27]
[C:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[PID: 1760][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] [Analog Devices, Inc., 3, 2, 6, 0]
[PID: 2208][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 2668][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\drivers\nmprt.sys] [N/A, N/A]
[C:\WINDOWS\system32\fpv5b.dll] [N/A, N/A]
[C:\WINDOWS\system32\kakatool.dll] [Beijing Rising Technology Co., Ltd., 2, 0, 2, 0]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\PROGRA~1\FlashGet\jccatch.dll] [FlashGet, 1, 1, 5, 0]
[C:\PROGRA~1\FlashGet\getflash.dll] [N/A, 1, 0, 0, 1]
[C:\Program Files\Rising\Rav\RavScrCh.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0]
[PID: 1372][C:\Documents and Settings\王于\桌面\sreng2\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\WINDOWS\system32\drivers\nmprt.sys] [N/A, N/A]
[C:\WINDOWS\system32\fpv5b.dll] [N/A, N/A]
[C:\WINDOWS\system32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
218.201.94.20 localhost
218.201.94.20 www.5566.net
218.201.94.20 www.gjj.cc
218.201.94.20 www.hao123.com
218.201.94.20 www.hao222.com
218.201.94.20 www.9991.com
218.201.94.20 www.2345.com
218.201.94.20 www.7939.com
218.201.94.20 forum.ikaka.com
218.201.94.20 bbs.360safe.com
218.201.94.20 www.360safe.com
218.201.94.20 www.piaoxue.com
218.201.94.20 61.129.58.12
218.201.94.20 forum.jiangmin.com
218.201.94.20 luosoft.com
218.201.94.20 cn.zs.yahoo.com
218.201.94.20 www.znmq.com
218.201.94.20 auto.search.msn.com
218.201.94.20 www.pcav.cn
218.201.94.20 www.cnhx.com.cn
218.201.94.20 btbaicai.com
218.201.94.20 219.239.102.77
218.201.94.20 hz.mop-hz.com
218.201.94.20 www.jacai.com
218.201.94.20 bbs.168safe.com
218.201.94.20 ok.mop-hz.com
218.201.94.20 www.haokan123.com
218.201.94.20 www.7255.com
218.201.94.20 220.181.34.241
218.201.94.20 www.my123.com
==================================