==================================
正在运行的进程
[PID:488][\SystemRoot\System32\smss.exe]<MicrosoftCorporation><5.1.2600.2180(xpsp_sp2_rtm.040803-2158)>
[PID:544][\??\C:\WINDOWS\system32\csrss.exe]<MicrosoftCorporation><5.1.2600.2180(xpsp_sp2_rtm.040803-2158)>
[PID:568][\??\C:\WINDOWS\system32\winlogon.exe]<MicrosoftCorporation><5.1.2600.2180(xpsp_sp2_rtm.040803-2158)>
[PID:612][C:\WINDOWS\system32\services.exe]<MicrosoftCorporation><5.1.2600.2180(xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\cn_spiEx.dll]<N/A><N/A>
[C:\ProgramFiles\InternetExplorer\PLUGINS\system.sys]<N/A><N/A>
[C:\WINDOWS\system32\msdll.dll]<N/A><N/A>
[PID:624][C:\WINDOWS\system32\lsass.exe]<MicrosoftCorporation><5.1.2600.2180(xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\cn_spiEx.dll]<N/A><N/A>
[PID:776][C:\WINDOWS\system32\svchost.exe]<MicrosoftCorporation><5.1.2600.2180(xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\msdll.dll]<N/A><N/A>
[C:\ProgramFiles\InternetExplorer\PLUGINS\system.sys]<N/A><N/A>
[PID:824][C:\WINDOWS\system32\svchost.exe]<MicrosoftCorporation><5.1.2600.2180(xpsp_sp2_rtm.040803-2158)>
[PID:896][c:\ProgramFiles\Rising\Rav\CCenter.exe]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,3>
[PID:912][C:\WINDOWS\System32\svchost.exe]<MicrosoftCorporation><5.1.2600.2180(xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\cn_spiEx.dll]<N/A><N/A>
[PID:972][C:\WINDOWS\system32\svchost.exe]<MicrosoftCorporation><5.1.2600.2180(xpsp_sp2_rtm.040803-2158)>
[PID:1108][C:\WINDOWS\system32\svchost.exe]<MicrosoftCorporation><5.1.2600.2180(xpsp_sp2_rtm.040803-2158)>
[PID:1192][c:\ProgramFiles\Rising\Rav\Ravmond.exe]<BeijingRisingTechnologyCo.,Ltd.><18,0,1,35>
[c:\ProgramFiles\Rising\Rav\BWList.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,19>
[c:\ProgramFiles\Rising\Rav\RsCommX.dll]<rising><18,0,0,1>
[c:\ProgramFiles\Rising\Rav\RSAPPMGR.DLL]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,2>
[c:\ProgramFiles\Rising\Rav\CfgDll.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,11>
[c:\ProgramFiles\Rising\Rav\RSCOMMON.DLL]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,4>
[c:\ProgramFiles\Rising\Rav\RsLog.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,20>
[c:\ProgramFiles\Rising\Rav\HOOKSYS.dll]<BeijingRisingTechnologyCo.,Ltd.><18,1,0,11>
[c:\ProgramFiles\Rising\Rav\Scanner.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,32>
[c:\ProgramFiles\Rising\Rav\libload.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,10>
[c:\ProgramFiles\Rising\Rav\VirusLib.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,12>
[c:\ProgramFiles\Rising\Rav\regmon.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,6>
[c:\ProgramFiles\Rising\Rav\HookWeb.dll]<rising><18,0,0,2>
[c:\ProgramFiles\Rising\Rav\MemMon.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,10>
[c:\ProgramFiles\Rising\Rav\expscan.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,4>
[c:\ProgramFiles\Rising\Rav\mPorts.dll]<BeijingRisingTechnologyCo.,Ltd.><4,0,0,3>
[c:\ProgramFiles\Rising\Rav\MailMon.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,5>
[c:\ProgramFiles\Rising\Rav\SpamEng.dll]<N/A><18,0,0,6>
[c:\ProgramFiles\Rising\Rav\engine.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,34>
[C:\WINDOWS\system32\cn_spiEx.dll]<N/A><N/A>
[c:\ProgramFiles\Rising\Rav\PostTrt.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,13>
[c:\ProgramFiles\Rising\Rav\UnExe.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,11>
[c:\ProgramFiles\Rising\Rav\ScanExec.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,11>
[c:\ProgramFiles\Rising\Rav\ScanEx.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,20>
[c:\ProgramFiles\Rising\Rav\RSUnpack.dll]<BeijingRisingTechnologyCo.,Ltd.><1,0,0,13>
[c:\ProgramFiles\Rising\Rav\NvFile.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,7>
[c:\ProgramFiles\Rising\Rav\ScanMac.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,9>
[c:\ProgramFiles\Rising\Rav\ScanSct.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,18>
[c:\ProgramFiles\Rising\Rav\Unpacker.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,4>
[PID:1288][c:\programfiles\rising\rfw\rfwsrv.exe]<BeijingRisingTechnologyCo.,Ltd.><4,0,0,32>
[c:\programfiles\rising\rfw\RfwRule.dll]<BeijingRisingTechnologyCo.,Ltd.><4,0,0,13>
[c:\programfiles\rising\rfw\rfwlog.dll]<BeijingRisingTechnologyCo.,Ltd.><4,0,0,6>
[c:\programfiles\rising\rfw\Rfwdrv.dll]<BeijingRisingTechnologyCo.,Ltd.><4,0,0,21>
[c:\programfiles\rising\rfw\MonDrv.dll]<rs><1,0,0,4>
[c:\programfiles\rising\rfw\ProcLib.dll]<BeijingRisingTechnologyCo.,Ltd.><4,0,0,9>
[C:\WINDOWS\system32\cn_spiEx.dll]<N/A><N/A>
[PID:1488][C:\WINDOWS\Explorer.EXE]<MicrosoftCorporation><6.00.2900.2180(xpsp_sp2_rtm.040803-2158)>
[C:\ProgramFiles\InternetExplorer\PLUGINS\system.sys]<N/A><N/A>
[C:\WINDOWS\system32\msdll.dll]<N/A><N/A>
[D:\ProgramFiles\Adobe\Acrobat7.0\ActiveX\PDFShell.dll]<AdobeSystems,Inc.><7.0.0.0>
[C:\WINDOWS\system32\cn_spiEx.dll]<N/A><N/A>
[D:\ProgramFiles\Adobe\Acrobat7.0\ActiveX\AcroIEHelper.dll]<AdobeSystemsIncorporated><7.0.5.2005092300>
[d:\ProgramFiles\ThunderNetwork\Thunder\ComDlls\XunLeiBHO_002.dll]<ThunderNetworkingTechnologies,LTD><5,0,0,2>
[c:\ProgramFiles\Rising\Rav\RSCOMMON.DLL]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,4>
[PID:1600][C:\WINDOWS\system32\spoolsv.exe]<MicrosoftCorporation><5.1.2600.2180(xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\hpzsnt10.dll]<HP><2.323.0.0>
[PID:1704][c:\ProgramFiles\Rising\Rav\RavStub.exe]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,16>
[c:\ProgramFiles\Rising\Rav\RsCommX.dll]<rising><18,0,0,1>
[c:\ProgramFiles\Rising\Rav\RSCOMMON.DLL]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,4>
[PID:1988][C:\ProgramFiles\Rising\Rav\RavTask.exe]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,22>
[C:\ProgramFiles\Rising\Rav\RSCOMMON.DLL]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,4>
[C:\ProgramFiles\Rising\Rav\RSAPPMGR.DLL]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,2>
[C:\ProgramFiles\Rising\Rav\CfgDll.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,11>
[C:\ProgramFiles\Rising\Rav\RsCommX.dll]<rising><18,0,0,1>
[C:\ProgramFiles\InternetExplorer\PLUGINS\system.sys]<N/A><N/A>
[C:\WINDOWS\system32\msdll.dll]<N/A><N/A>
[PID:2032][C:\ProgramFiles\Microsoft\svhost32.exe]<N/A><N/A>
[C:\WINDOWS\system32\msdll.dll]<N/A><N/A>
[C:\ProgramFiles\InternetExplorer\PLUGINS\system.sys]<N/A><N/A>
[PID:120][C:\ProgramFiles\Microsoft\svhost32.exe]<N/A><N/A>
[PID:168][C:\WINDOWS\system32\ctfmon.exe]<MicrosoftCorporation><5.1.2600.2180(xpsp_sp2_rtm.040803-2158)>
[C:\ProgramFiles\InternetExplorer\PLUGINS\system.sys]<N/A><N/A>
[C:\WINDOWS\system32\msdll.dll]<N/A><N/A>
[PID:296][C:\WINDOWS\system32\inetsrv\inetinfo.exe]<MicrosoftCorporation><5.1.2600.2180(xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\cn_spiEx.dll]<N/A><N/A>
[PID:424][C:\WINDOWS\system32\svchost.exe]<MicrosoftCorporation><5.1.2600.2180(xpsp_sp2_rtm.040803-2158)>
[PID:3788][C:\WINDOWS\system32\wuauclt.exe]<MicrosoftCorporation><5.4.3790.2180(xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\cn_spiEx.dll]<N/A><N/A>
[PID:4088][C:\WINDOWS\system32\winmer.exe]<MicrosoftCorporation><5.1.2600.0>
[C:\WINDOWS\system32\msdll.dll]<N/A><N/A>
[C:\ProgramFiles\InternetExplorer\PLUGINS\system.sys]<N/A><N/A>
[PID:1532][c:\programfiles\rising\rfw\RfwMain.exe]<BeijingRisingTechnologyCo.,Ltd.><4,0,0,52>
[c:\programfiles\rising\rfw\RsGuiLib.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,23>
[c:\programfiles\rising\rfw\RSCOMMON.DLL]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,4>
[c:\programfiles\rising\rfw\PngDll.dll]<BeijingRisingTechnologyCo.,Ltd.><18,0,0,5>
[C:\WINDOWS\system32\cn_spiEx.dll]<N/A><N/A>
[C:\ProgramFiles\InternetExplorer\PLUGINS\system.sys]<N/A><N/A>
[C:\WINDOWS\system32\msdll.dll]<N/A><N/A>
[PID:3700][D:\ProgramFiles\sreng2\SREng.exe]<SmallfrogsStudio><2.0.21.505>
[C:\WINDOWS\system32\cn_spiEx.dll]<N/A><N/A>
[C:\ProgramFiles\InternetExplorer\PLUGINS\system.sys]<N/A><N/A>
[C:\WINDOWS\system32\msdll.dll]<N/A><N/A>
[PID:3848][C:\WINDOWS\system32\vsjitdebugger.exe]<MicrosoftCorporation><8.0.50727.42(RTM.050727-4200)>
[PID:3868][C:\WINDOWS\system32\vsjitdebugger.exe]<MicrosoftCorporation><8.0.50727.42(RTM.050727-4200)>
[C:\WINDOWS\system32\cn_spiEx.dll]<N/A><N/A>
[C:\ProgramFiles\InternetExplorer\PLUGINS\system.sys]<N/A><N/A>
[C:\WINDOWS\system32\msdll.dll]<N/A><N/A>
==================================
文件关联
.TXTOK.[%SystemRoot%\system32\NOTEPAD.EXE%1]
.EXEOK.["%1"%*]
.COMOK.["%1"%*]
.PIFOK.["%1"%*]
.REGOK.[regedit.exe"%1"]
.BATOK.["%1"%*]
.SCROK.["%1"/S]
.CHMOK.["C:\WINDOWS\hh.exe"%1]
.HLPOK.[%SystemRoot%\System32\winhlp32.exe%1]
.INIOK.[%SystemRoot%\System32\NOTEPAD.EXE%1]
.INFOK.[%SystemRoot%\System32\NOTEPAD.EXE%1]
.VBSOK.[%SystemRoot%\System32\WScript.exe"%1"%*]
.JSOK.[%SystemRoot%\System32\WScript.exe"%1"%*]
.LNKOK.[{00021401-0000-0000-C000-000000000046}]
请高手帮忙,怎么能杀的彻底