==================================
正在运行的进程
[PID: 472][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 528][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 552][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 600][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 612][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 748][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 840][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 880][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 960][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1024][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1160][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 1260][C:\WINDOWS\system32\drivers\CDAC11BA.EXE] <Macrovision><4.20.020>
[PID: 1284][D:\Ewido主程序\ewido anti-malware\ewidoctrl.exe] <ewido networks><3, 0, 0, 1>
[D:\Ewido主程序\ewido anti-malware\lang.dll] <privat><1, 0, 0, 1>
[PID: 1308][D:\Ewido主程序\ewido anti-malware\ewidoguard.exe] <ewido networks><3, 0, 0, 1>
[D:\Ewido主程序\ewido anti-malware\framework.dll] <ewido networks><1, 0, 0, 249>
[D:\Ewido主程序\ewido anti-malware\lang.dll] <privat><1, 0, 0, 1>
[D:\Ewido主程序\ewido anti-malware\configuration.dll] <ewido networks><1, 0, 0, 1>
[D:\Ewido主程序\ewido anti-malware\update_core.dll] <N/A><N/A>
[D:\Ewido主程序\ewido anti-malware\wizard.dll] <N/A><N/A>
[D:\Ewido主程序\ewido anti-malware\engine.dll] <ewido networks GmbH & Co. KG><4, 0, 0, 2>
[D:\Ewido主程序\ewido anti-malware\scan.dll] <ewido networks><1, 0, 0, 2>
[D:\Ewido主程序\ewido anti-malware\tray_dll.dll] <N/A><N/A>
[PID: 1352][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE] <Microsoft Corporation><7.00.9466>
[PID: 1388][C:\WINDOWS\system32\slserv.exe] <Smart Link><3.80.01MC15>
[PID: 1412][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1600][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1868][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\AcSignIcon.dll] <Autodesk><16.0.0.86>
[C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] <Autodesk><16.0.0.86>
[C:\WINDOWS\system32\wldll.dll] <N/A><N/A>
[C:\WINDOWS\system32\soundmix.dll] <><1, 4, 0, 0>
[C:\WINDOWS\system32\ztdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\msdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\tdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\xunleibho_v14.dll] <Thunder Networking Technologies,LTD><4, 6, 0, 62>
[C:\PROGRA~1\baidu\bar\BaiduBar.dll] <Baidu.com, Inc.><2, 0, 2, 106>
[D:\Thunder\ComDlls\XunLeiBHO_002.dll] <Thunder Networking Technologies,LTD><5, 0, 0, 2>
[D:\Ewido主程序\ewido anti-malware\shellhook.dll] <N/A><N/A>
[PID: 2024][D:\Program Files\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[D:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[D:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[D:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\WINDOWS\system32\ztdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\msdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\wldll.dll] <N/A><N/A>
[C:\WINDOWS\system32\tdll.dll] <N/A><N/A>
[PID: 2032][C:\WINDOWS\command\rundll32.exe] <N/A><N/A>
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\5.dll] <N/A><N/A>
[C:\WINDOWS\system32\tdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\ztdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\msdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\wldll.dll] <N/A><N/A>
[PID: 2040][C:\WINDOWS\Download\svhost32.exe] <N/A><N/A>
[C:\WINDOWS\system32\wldll.dll] <N/A><N/A>
[C:\WINDOWS\system32\ztdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\msdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\tdll.dll] <N/A><N/A>
[PID: 168][C:\Program Files\Microsoft\svhost32.exe] <N/A><N/A>
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cdjhk79.dll] <N/A><N/A>
[C:\WINDOWS\system32\msdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\ztdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\wldll.dll] <N/A><N/A>
[C:\WINDOWS\system32\tdll.dll] <N/A><N/A>
[PID: 184][C:\WINDOWS\Intel\rundll32.exe] <N/A><N/A>
[C:\WINDOWS\system32\ztdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\msdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\wldll.dll] <N/A><N/A>
[C:\WINDOWS\system32\tdll.dll] <N/A><N/A>
[PID: 264][C:\WINDOWS\system32\conime.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\tdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\ztdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\msdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\wldll.dll] <N/A><N/A>
[PID: 1832][D:\wrar\WinRAR.exe] <N/A><N/A>
[C:\WINDOWS\system32\AcSignIcon.dll] <Autodesk><16.0.0.86>
[C:\WINDOWS\system32\tdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\ztdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\msdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\wldll.dll] <N/A><N/A>
[PID: 1056][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.748\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\WINDOWS\system32\tdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\ztdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\msdll.dll] <N/A><N/A>
[C:\WINDOWS\system32\wldll.dll] <N/A><N/A>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
且不时弹出采铃网页
两个杀毒软件“瑞星、Ewido”都启动不了