==================================
启动文件夹
服务
[Crypkey License / Crypkey License]
<crypserv.exe><Kenonic Controls Ltd.>
[IMAPI CD-Burning COM Service / ImapiService]
<H:\WINDOWS\System32\imapi.exe><Microsoft Corporation>
[Rising Process Communication Center / RsCCenter]
<"c:\Program Files\Rising\Rav\CCenter.exe"><N/A>
[SmartLinkService / SLService]
<slserv.exe><>
[RsRavMon Service / RsRavMon]
<"d:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Symantec Event Manager / ccEvtMgr]
<"H:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"><Symantec Corporation>
[Symantec Password Validation / ccPwdSvc]
<"H:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"><Symantec Corporation>
[Symantec Settings Manager / ccSetMgr]
<"H:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"><Symantec Corporation>
[Symantec Network Drivers Service / SNDSrvc]
<"H:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"><Symantec Corporation>
[Symantec AntiVirus Definition Watcher / DefWatch]
<"H:\Program Files\Symantec AntiVirus\DefWatch.exe"><Symantec Corporation>
[SavRoam / SavRoam]
<"H:\Program Files\Symantec AntiVirus\SavRoam.exe"><symantec>
==================================
浏览器加载项
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <H:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <H:\WINDOWS\System32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
==================================
正在运行的进程
[PID: 540][\??\H:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 608][H:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 620][H:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 864][H:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 992][H:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1080][H:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1544][H:\WINDOWS\System32\igfxtray.exe] <Intel Corporation><3.0.0.2285>
[H:\WINDOWS\System32\hccutils.DLL] <Intel Corporation><3.0.0.2285>
[H:\WINDOWS\System32\igfxdev.dll] <Intel Corporation><3.0.0.2285>
[H:\WINDOWS\System32\igfxsrvc.dll] <Intel Corporation><3.0.0.2285>
[H:\WINDOWS\System32\igfxres.dll] <Intel Corporation><3.0.0.2285>
[H:\WINDOWS\System32\igfxress.dll] <Intel Corporation><3.0.0.2285>
[PID: 1836][H:\WINDOWS\explorer.exe] <Microsoft Corporation><6.00.2600.0000 (xpclient.010817-1148)>
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] <Adobe Systems Incorporated><6.0.1.2003110300>
[H:\WINDOWS\System32\igfxpph.dll] <Intel Corporation><3.0.0.2285>
[H:\WINDOWS\System32\hccutils.DLL] <Intel Corporation><3.0.0.2285>
[H:\WINDOWS\System32\igfxres.dll] <Intel Corporation><3.0.0.2285>
[H:\WINDOWS\System32\igfxsrvc.dll] <Intel Corporation><3.0.0.2285>
[H:\WINDOWS\System32\igfxdev.dll] <Intel Corporation><3.0.0.2285>
[H:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[d:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 3620][H:\Program Files\摩贝德通信\MobiData CDMA Modem\MobiData CDMA Modem.exe] <><1, 0, 0, 1>
[PID: 728][H:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 2288][H:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.0 (XPClient.010817-1148)>
[PID: 2408][H:\WINDOWS\System32\conime.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 2660][H:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 2104][c:\Program Files\WinRAR\WinRAR.exe] <N/A><N/A>
[PID: 964][H:\DOCUME~1\LiuHua\LOCALS~1\Temp\Rar$EX00.844\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["H:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================