==================================
正在运行的进程
[PID: 424][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 488][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\Program Files\rising\rav\ApiHook.dll] <北京瑞星><16, 0, 0, 19>
[C:\Program Files\rising\rav\MemMon.dll] <北京瑞星><16, 0, 0, 20>
[PID: 512][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[C:\Program Files\rising\rav\ApiHook.dll] <北京瑞星><16, 0, 0, 19>
[C:\Program Files\rising\rav\MemMon.dll] <北京瑞星><16, 0, 0, 20>
[PID: 556][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\Program Files\rising\rav\ApiHook.dll] <北京瑞星><16, 0, 0, 19>
[C:\Program Files\rising\rav\MemMon.dll] <北京瑞星><16, 0, 0, 20>
[PID: 568][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[C:\Program Files\rising\rav\ApiHook.dll] <北京瑞星><16, 0, 0, 19>
[C:\Program Files\rising\rav\MemMon.dll] <北京瑞星><16, 0, 0, 20>
[PID: 732][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 784][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\Program Files\rising\rav\ApiHook.dll] <北京瑞星><16, 0, 0, 19>
[C:\Program Files\rising\rav\MemMon.dll] <北京瑞星><16, 0, 0, 20>
[C:\Program Files\rising\rav\RavProxy.dll] <rising><16, 0, 0, 2>
[PID: 928][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\Program Files\rising\rav\ApiHook.dll] <北京瑞星><16, 0, 0, 19>
[C:\Program Files\rising\rav\MemMon.dll] <北京瑞星><16, 0, 0, 20>
[PID: 972][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\Program Files\rising\rav\ApiHook.dll] <北京瑞星><16, 0, 0, 19>
[C:\Program Files\rising\rav\MemMon.dll] <北京瑞星><16, 0, 0, 20>
[C:\Program Files\rising\rav\RavProxy.dll] <rising><16, 0, 0, 2>
[PID: 1108][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.1699 (xpsp2.050610-1533)>
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll] <Windows (R) 2000 DDK provider><5.00.2195.1620>
[C:\Program Files\rising\rav\ApiHook.dll] <北京瑞星><16, 0, 0, 19>
[C:\Program Files\rising\rav\MemMon.dll] <北京瑞星><16, 0, 0, 20>
[PID: 1352][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\Program Files\rising\rav\ApiHook.dll] <北京瑞星><16, 0, 0, 19>
[C:\Program Files\rising\rav\MemMon.dll] <北京瑞星><16, 0, 0, 20>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[C:\WINDOWS\System32\RAVEXT.DLL] <北京瑞星科技股份有限公司><16, 0, 0, 2>
[PID: 1532][C:\PROGRA~1\rising\Rav\RavMon.exe] <rising><16, 0, 0, 17>
[C:\Program Files\rising\rav\ApiHook.dll] <北京瑞星><16, 0, 0, 19>
[C:\Program Files\rising\rav\MemMon.dll] <北京瑞星><16, 0, 0, 20>
[C:\PROGRA~1\rising\Rav\RavMon.dll] <Beijing Rising Tech. Co. Ltd.><16, 0, 0, 24>
[C:\PROGRA~1\rising\Rav\guidll.dll] <rising><16, 0, 0, 31>
[C:\PROGRA~1\rising\Rav\RsCommX.dll] <rising><15, 0, 1, 13>
[C:\PROGRA~1\rising\Rav\Language.dll] <RiSing><15, 0, 0, 17>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[PID: 1556][C:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[C:\Program Files\rising\rav\ApiHook.dll] <北京瑞星><16, 0, 0, 19>
[C:\Program Files\rising\rav\MemMon.dll] <北京瑞星><16, 0, 0, 20>
[PID: 1564][C:\Program Files\Messenger\msmsgs.exe] <Microsoft Corporation><4.7.2010>
[C:\WINDOWS\System32\msdmo.dll] <N/A><N/A>
[C:\Program Files\rising\rav\ApiHook.dll] <北京瑞星><16, 0, 0, 19>
[C:\Program Files\rising\rav\MemMon.dll] <北京瑞星><16, 0, 0, 20>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[PID: 1692][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1764][C:\Program Files\rising\rav\RavMonD.exe] <rising><16, 0, 0, 6>
[C:\Program Files\rising\rav\RavMon.dll] <Beijing Rising Tech. Co. Ltd.><16, 0, 0, 24>
[C:\Program Files\rising\rav\guidll.dll] <rising><16, 0, 0, 31>
[C:\Program Files\rising\rav\RsCommX.dll] <rising><15, 0, 1, 13>
[C:\Program Files\rising\rav\Language.dll] <RiSing><15, 0, 0, 17>
[C:\Program Files\rising\rav\Engine.dll] <rising><16, 0, 0, 41>
[C:\Program Files\rising\rav\LibLoad.dll] <Rising><16, 0, 0, 25>
[C:\Program Files\rising\rav\StoreDll.dll] <Beijing Rising Technology Co., Ltd.><13, 42, 0, 4>
[C:\Program Files\rising\rav\ScanFile.dll] <rising><16, 0, 0, 33>
[C:\Program Files\rising\rav\NVFile.dll] <rising><16, 0, 0, 4>
[C:\Program Files\rising\rav\PostTrt.dll] <Rising><16, 0, 0, 13>
[C:\Program Files\rising\rav\PostTrtX.dll] <瑞星科技股份有限公司><16, 0, 0, 5>
[C:\Program Files\rising\rav\ExtFile.dll] <RiSing><16, 0, 0, 23>
[C:\Program Files\rising\rav\ExtMail.dll] <rising><16, 0, 0, 24>
[C:\Program Files\rising\rav\ScanEx.dll] <rising><16, 0, 0, 30>
[C:\Program Files\rising\rav\UnMacro.dll] <rising><16, 0, 0, 8>
[C:\Program Files\rising\rav\UnExe.dll] <Rising><16, 0, 0, 27>
[C:\Program Files\rising\rav\UnMail.dll] <rising><16, 0, 0, 7>
[C:\Program Files\rising\rav\BtEngine.dll] <rising><16, 0, 0, 30>
[C:\Program Files\rising\rav\ApiHook.dll] <北京瑞星><16, 0, 0, 19>
[C:\Program Files\rising\rav\MemMon.dll] <北京瑞星><16, 0, 0, 20>
[C:\Program Files\rising\rav\zip.dll] <rising><13, 0, 0, 1>
[C:\Program Files\rising\rav\VirusLib.dll] <rs><16, 0, 0, 13>
[PID: 1184][C:\WINDOWS\System32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[C:\Program Files\rising\rav\ApiHook.dll] <北京瑞星><16, 0, 0, 19>
[C:\Program Files\rising\rav\MemMon.dll] <北京瑞星><16, 0, 0, 20>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[PID: 280][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\Program Files\rising\rav\ApiHook.dll] <北京瑞星><16, 0, 0, 19>
[C:\Program Files\rising\rav\MemMon.dll] <北京瑞星><16, 0, 0, 20>
[C:\Program Files\rising\rav\RavProxy.dll] <rising><16, 0, 0, 2>
[C:\WINDOWS\System32\RavScrCh.dll] <><16, 0, 0, 3>
[C:\WINDOWS\System32\UnMail.dll] <rising><16, 0, 0, 7>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[PID: 1080][C:\WINDOWS\system\ntdllf.exe] <UNDEATH><3.02>
[C:\Program Files\rising\rav\ApiHook.dll] <北京瑞星><16, 0, 0, 19>
[C:\Program Files\rising\rav\MemMon.dll] <北京瑞星><16, 0, 0, 20>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[PID: 1856][D:\新建文件夹 (2)\SREng2\SREng.exe] <Smallfrogs Studio><2.0.21.505>
[C:\Program Files\rising\rav\ApiHook.dll] <北京瑞星><16, 0, 0, 19>
[C:\Program Files\rising\rav\MemMon.dll] <北京瑞星><16, 0, 0, 20>
[C:\Herosoft\HeroV8\VCvtShell.dll] <herosoft><1, 0, 0, 1>
[C:\Program Files\rising\rav\RavProxy.dll] <rising><16, 0, 0, 2>