正在运行的进程
[PID: 540][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 604][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 628][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.1557 (xpsp2_gdr.040517-1325)>
[C:\WINDOWS\System32\NavLogon.dll] <N/A><N/A>
[PID: 672][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\MsInfo.rr] <N/A><N/A>
[C:\SPY_WOOOL\SPY_DLL.dll] <N/A><N/A>
[PID: 684][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 864][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 968][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1104][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1136][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1332][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.1699 (xpsp2.050610-1533)>
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll] <Windows (R) 2000 DDK provider><5.00.2195.1620>
[PID: 1560][C:\WINDOWS\Explorer.exe] <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\MsInfo.rr] <N/A><N/A>
[C:\WINDOWS\system32\RavExt.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[C:\WINDOWS\System32\DTSERV~1.DLL] <><1, 3, 0, 0>
[C:\DOCUME~1\abc\LOCALS~1\Temp\f3\fwpxres.dll] <><1, 0, 0, 0>
[C:\SPY_WOOOL\SPY_DLL.dll] <N/A><N/A>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[C:\DOCUME~1\abc\LOCALS~1\Temp\f3\ex\mcl.dll] <N/A><N/A>
[C:\Program Files\CoolWebsite\QuickLink.dll] <Fengcent><1, 0, 0, 2>
[C:\WINDOWS\SYSTEM32\HelperService.dll] <N/A><N/A>
[PID: 1728][C:\WINDOWS\System32\winmer.exe] <Microsoft Corporation><5.1.2600.0>
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\MsInfo.rr] <N/A><N/A>
[C:\SPY_WOOOL\SPY_DLL.dll] <N/A><N/A>
[PID: 1736][C:\WINDOWS\WINLOGON.EXE] <Ce6><0.00.0070>
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\MsInfo.rr] <N/A><N/A>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\SPY_WOOOL\SPY_DLL.dll] <N/A><N/A>
[PID: 1812][C:\Program Files\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\MsInfo.rr] <N/A><N/A>
[C:\SPY_WOOOL\SPY_DLL.dll] <N/A><N/A>
[PID: 1948][C:\WINDOWS\smss.exe] <FCL><0.00.0070>
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\MsInfo.rr] <N/A><N/A>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[C:\SPY_WOOOL\SPY_DLL.dll] <N/A><N/A>
[PID: 2000][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.3427>
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\MsInfo.rr] <N/A><N/A>
[C:\SPY_WOOOL\SPY_DLL.dll] <N/A><N/A>
[PID: 2012][C:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\MsInfo.rr] <N/A><N/A>
[C:\SPY_WOOOL\SPY_DLL.dll] <N/A><N/A>
[PID: 1600][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 1792][C:\WINDOWS\System32\nvsvc32.exe] <NVIDIA Corporation><6.14.10.4502>
[PID: 1768][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1176][C:\WINDOWS\System32\msime.exe] <Microsoft Corporation><5.1.2600.2180>
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\MsInfo.rr] <N/A><N/A>
[C:\SPY_WOOOL\SPY_DLL.dll] <N/A><N/A>
[PID: 1060][C:\DOCUME~1\abc\LOCALS~1\Temp\svchost.exe] <N/A><N/A>
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\MsInfo.rr] <N/A><N/A>
[C:\DOCUME~1\abc\LOCALS~1\Temp\packet.dll] <CACE Technologies><3, 1, 0, 27>
[C:\DOCUME~1\abc\LOCALS~1\Temp\WanPacket.dll] <CACE Technologies><3, 1, 0, 27>
[C:\SPY_WOOOL\SPY_DLL.dll] <N/A><N/A>