[0]ID=0;PID=0;N=System Idle Process;T=2013-05-03 19:19:00;P=[System Process];C=;[0]ID=4;PID=0;N=System;T=2013-05-03 19:19:00;P=System;C=;[0]ID=696;PID=4;N=smss.exe;T=2013-05-03 19:20:12;P=\SystemRoot\System32\smss.exe;C=\SystemRoot\System32\smss.exe;[0]ID=752;PID=696;N=csrss.exe;T=2013-05-03 19:20:13;P=C:\WINDOWS\system32\csrss.exe;C=C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16;[0]ID=776;PID=696;N=winlogon.exe;T=2013-05-03 19:20:14;P=C:\WINDOWS\system32\winlogon.exe;C=winlogon.exe;[0]ID=820;PID=776;N=services.exe;T=2013-05-03 19:20:14;P=C:\WINDOWS\system32\services.exe;C=C:\WINDOWS\system32\services.exe;[0]ID=832;PID=776;N=lsass.exe;T=2013-05-03 19:20:14;P=C:\WINDOWS\system32\lsass.exe;C=C:\WINDOWS\system32\lsass.exe;[0]ID=1012;PID=820;N=svchost.exe;T=2013-05-03 19:20:15;P=C:\WINDOWS\system32\svchost.exe;C=C:\WINDOWS\system32\svchost -k DcomLaunch;[0]ID=1100;PID=820;N=svchost.exe;T=2013-05-03 19:20:15;P=C:\WINDOWS\system32\svchost.exe;C=C:\WINDOWS\system32\svchost -k rpcss;[0]ID=1196;PID=820;N=svchost.exe;T=2013-05-03 19:20:15;P=C:\WINDOWS\System32\svchost.exe;C=C:\WINDOWS\System32\svchost.exe -k netsvcs;[0]ID=1292;PID=820;N=svchost.exe;T=2013-05-03 19:20:15;P=C:\WINDOWS\system32\svchost.exe;C=C:\WINDOWS\system32\svchost.exe -k NetworkService;[0]ID=1380;PID=820;N=svchost.exe;T=2013-05-03 19:20:15;P=C:\WINDOWS\system32\svchost.exe;C=C:\WINDOWS\system32\svchost.exe -k LocalService;[0]ID=1412;PID=820;N=zhudongfangyu.exe;T=2013-05-03 19:20:15;P=E:\360\360Safe\deepscan\zhudongfangyu.exe;C="E:\360\360Safe\deepscan\zhudongfangyu.exe";[0]ID=1724;PID=820;N=spoolsv.exe;T=2013-05-03 19:20:16;P=C:\WINDOWS\system32\spoolsv.exe;C=C:\WINDOWS\system32\spoolsv.exe;[0]ID=1740;PID=1680;N=Explorer.EXE;T=2013-05-03 19:20:16;P=C:\WINDOWS\Explorer.EXE;C=C:\WINDOWS\Explorer.EXE;[0]ID=1984;PID=1740;N=RTHDCPL.EXE;T=2013-05-03 19:20:18;P=C:\WINDOWS\RTHDCPL.EXE;C="C:\WINDOWS\RTHDCPL.EXE" ;[0]ID=2008;PID=1740;N=hkcmd.exe;T=2013-05-03 19:20:18;P=C:\WINDOWS\system32\hkcmd.exe;C="C:\WINDOWS\system32\hkcmd.exe" ;[0]ID=2040;PID=1740;N=igfxpers.exe;T=2013-05-03 19:20:18;P=C:\WINDOWS\system32\igfxpers.exe;C="C:\WINDOWS\system32\igfxpers.exe" ;[0]ID=116;PID=1740;N=360Tray.exe;T=2013-05-03 19:20:18;P=E:\360\360Safe\safemon\360Tray.exe;C="E:\360\360Safe\safemon\360Tray.exe" /start;[0]ID=168;PID=1740;N=baidupinyin.exe;T=2013-05-03 19:20:19;P=C:\Program Files\Baidu\BaiduPinyin\2.4.2.281\baidupinyin.exe;C="C:\Program Files\Baidu\BaiduPinyin\2.4.2.281\baidupinyin.exe" ;[0]ID=236;PID=1740;N=ctfmon.exe;T=2013-05-03 19:20:19;P=C:\WINDOWS\system32\ctfmon.exe;C="C:\WINDOWS\system32\ctfmon.exe" ;[0]ID=496;PID=1740;N=360sd.exe;T=2013-05-03 19:20:20;P=E:\360\360sd\360sd.exe;C="E:\360\360sd\360sd.exe" /autorun;[0]ID=568;PID=1740;N=Rainmeter.exe;T=2013-05-03 19:20:20;P=C:\Program Files\Rainmeter\Rainmeter.exe;C="C:\Program Files\Rainmeter\Rainmeter.exe" ;[0]ID=1656;PID=1448;N=SoftManagerLite.exe;T=2013-05-03 19:20:39;P=E:\360\360Safe\SoftMgr\SoftManagerLite.exe;C="E:\360\360Safe\SoftMgr\SoftManagerLite.exe" /OpenSml /DisplayNone /DisplayPosLeft=99 /DisplayPosTop=446;[0]ID=1604;PID=1276;N=360rp.exe;T=2013-05-03 19:20:40;P=E:\360\360sd\360rp.exe;C="E:\360\360sd\360rp.exe" /run;[0]ID=2708;PID=820;N=mDNSResponder.exe;T=2013-05-03 19:20:51;P=C:\Program Files\Bonjour\mDNSResponder.exe;C="C:\Program Files\Bonjour\mDNSResponder.exe";[0]ID=2748;PID=820;N=MDM.EXE;T=2013-05-03 19:20:51;P=C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE;C="C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE";[0]ID=3168;PID=820;N=svchost.exe;T=2013-05-03 19:20:54;P=C:\WINDOWS\system32\svchost.exe;C=C:\WINDOWS\system32\svchost.exe -k imgsvc;[0]ID=3404;PID=820;N=alg.exe;T=2013-05-03 19:20:55;P=C:\WINDOWS\System32\alg.exe;C=C:\WINDOWS\System32\alg.exe;[1]ID=568;T=2013-05-03 19:21:00;[0]ID=3800;PID=1012;N=igfxsrvc.exe;T=2013-05-03 19:21:15;P=C:\WINDOWS\system32\igfxsrvc.exe;C=C:\WINDOWS\system32\igfxsrvc.exe -Embedding;[0]ID=3832;PID=1740;N=rundll32.exe;T=2013-05-03 19:21:19;P=C:\WINDOWS\system32\rundll32.exe;C="C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,Control_RunDLL "C:\WINDOWS\system32\MMSYS.CPL",@0;[1]ID=3800;T=2013-05-03 19:21:22;[0]ID=3888;PID=1012;N=igfxsrvc.exe;T=2013-05-03 19:21:31;P=C:\WINDOWS\system32\igfxsrvc.exe;C=C:\WINDOWS\system32\igfxsrvc.exe -Embedding;[0]ID=3924;PID=3832;N=systray.exe;T=2013-05-03 19:21:35;P=C:\WINDOWS\system32\systray.exe;C=SYSTRAY.EXE 4;[1]ID=3832;T=2013-05-03 19:21:35;[1]ID=3924;T=2013-05-03 19:21:35;[1]ID=3888;T=2013-05-03 19:21:37;[0]ID=3944;PID=1740;N=rundll32.exe;T=2013-05-03 19:21:38;P=C:\WINDOWS\system32\rundll32.exe;C="C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,Control_RunDLL "C:\WINDOWS\system32\MMSYS.CPL",@0;[0]ID=3972;PID=1740;N=rundll32.exe;T=2013-05-03 19:21:38;P=C:\WINDOWS\system32\rundll32.exe;C="C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,Control_RunDLL "C:\WINDOWS\system32\MMSYS.CPL",@0;[1]ID=3972;T=2013-05-03 19:21:38;[0]ID=4004;PID=1740;N=rundll32.exe;T=2013-05-03 19:21:38;P=C:\WINDOWS\system32\rundll32.exe;C="C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,Control_RunDLL "C:\WINDOWS\system32\MMSYS.CPL",@0;[1]ID=4004;T=2013-05-03 19:21:39;[0]ID=4080;PID=116;N=360leakfixer.exe;T=2013-05-03 19:22:01;P=E:\360\360Safe\360leakfixer.exe;C="E:\360\360Safe\360leakfixer.exe" ;[1]ID=4080;T=2013-05-03 19:22:03;[0]ID=516;PID=3944;N=systray.exe;T=2013-05-03 19:22:03;P=C:\WINDOWS\system32\systray.exe;C=SYSTRAY.EXE 4;[1]ID=516;T=2013-05-03 19:22:03;[1]ID=3944;T=2013-05-03 19:22:03;[0]ID=604;PID=1740;N=rundll32.exe;T=2013-05-03 19:22:04;P=C:\WINDOWS\system32\rundll32.exe;C="C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,Control_RunDLL "C:\WINDOWS\system32\MMSYS.CPL",@0;[0]ID=1064;PID=604;N=systray.exe;T=2013-05-03 19:22:09;P=C:\WINDOWS\system32\systray.exe;C=SYSTRAY.EXE 4;[1]ID=604;T=2013-05-03 19:22:09;[1]ID=1064;T=2013-05-03 19:22:09;[0]ID=1236;PID=776;N=logonui.exe;T=2013-05-03 19:22:14;P=C:\WINDOWS\system32\logonui.exe;C=logonui.exe /status;[1]ID=1984;T=2013-05-03 19:22:14;[1]ID=2008;T=2013-05-03 19:22:14;[1]ID=2040;T=2013-05-03 19:22:14;[1]ID=168;T=2013-05-03 19:22:14;[0]ID=0;PID=0;N=System Idle Process;T=2013-05-03 19:19:00;P=[System Process];C=;[0]ID=4;PID=0;N=System;T=2013-05-03 19:19:00;P=System;C=;[0]ID=696;PID=4;N=smss.exe;T=2013-05-03 19:20:12;P=\SystemRoot\System32\smss.exe;C=\SystemRoot\System32\smss.exe;[0]ID=752;PID=696;N=csrss.exe;T=2013-05-03 19:20:13;P=C:\WINDOWS\system32\csrss.exe;C=C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16;[0]ID=776;PID=696;N=winlogon.exe;T=2013-05-03 19:20:14;P=C:\WINDOWS\system32\winlogon.exe;C=winlogon.exe;[0]ID=820;PID=776;N=services.exe;T=2013-05-03 19:20:14;P=C:\WINDOWS\system32\services.exe;C=C:\WINDOWS\system32\services.exe;[0]ID=832;PID=776;N=lsass.exe;T=2013-05-03 19:20:14;P=C:\WINDOWS\system32\lsass.exe;C=C:\WINDOWS\system32\lsass.exe;[0]ID=1012;PID=820;N=svchost.exe;T=2013-05-03 19:20:15;P=C:\WINDOWS\system32\svchost.exe;C=C:\WINDOWS\system32\svchost -k DcomLaunch;[0]ID=1100;PID=820;N=svchost.exe;T=2013-05-03 19:20:15;P=C:\WINDOWS\system32\svchost.exe;C=C:\WINDOWS\system32\svchost -k rpcss;[0]ID=1196;PID=820;N=svchost.exe;T=2013-05-03 19:20:15;P=C:\WINDOWS\System32\svchost.exe;C=C:\WINDOWS\System32\svchost.exe -k netsvcs;[0]ID=1292;PID=820;N=svchost.exe;T=2013-05-03 19:20:15;P=C:\WINDOWS\system32\svchost.exe;C=C:\WINDOWS\system32\svchost.exe -k NetworkService;[0]ID=1380;PID=820;N=svchost.exe;T=2013-05-03 19:20:15;P=C:\WINDOWS\system32\svchost.exe;C=C:\WINDOWS\system32\svchost.exe -k LocalService;[0]ID=1412;PID=820;N=zhudongfangyu.exe;T=2013-05-03 19:20:15;P=E:\360\360Safe\deepscan\zhudongfangyu.exe;C="E:\360\360Safe\deepscan\zhudongfangyu.exe";[0]ID=1724;PID=820;N=spoolsv.exe;T=2013-05-03 19:20:16;P=C:\WINDOWS\system32\spoolsv.exe;C=C:\WINDOWS\system32\spoolsv.exe;[0]ID=2708;PID=820;N=mDNSResponder.exe;T=2013-05-03 19:20:51;P=C:\Program Files\Bonjour\mDNSResponder.exe;C="C:\Program Files\Bonjour\mDNSResponder.exe";[0]ID=2748;PID=820;N=MDM.EXE;T=2013-05-03 19:20:51;P=C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE;C="C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE";[0]ID=3168;PID=820;N=svchost.exe;T=2013-05-03 19:20:54;P=C:\WINDOWS\system32\svchost.exe;C=C:\WINDOWS\system32\svchost.exe -k imgsvc;[0]ID=3404;PID=820;N=alg.exe;T=2013-05-03 19:20:55;P=C:\WINDOWS\System32\alg.exe;C=C:\WINDOWS\System32\alg.exe;[0]ID=1876;PID=3680;N=Explorer.EXE;T=2013-05-03 19:24:15;P=C:\WINDOWS\Explorer.EXE;C=C:\WINDOWS\Explorer.EXE;[0]ID=3540;PID=1876;N=RTHDCPL.EXE;T=2013-05-03 19:24:16;P=C:\WINDOWS\RTHDCPL.EXE;C="C:\WINDOWS\RTHDCPL.EXE" ;[0]ID=1604;PID=1876;N=hkcmd.exe;T=2013-05-03 19:24:16;P=C:\WINDOWS\system32\hkcmd.exe;C="C:\WINDOWS\system32\hkcmd.exe" ;[0]ID=1872;PID=1876;N=igfxpers.exe;T=2013-05-03 19:24:16;P=C:\WINDOWS\system32\igfxpers.exe;C="C:\WINDOWS\system32\igfxpers.exe" ;[0]ID=1504;PID=1876;N=360Tray.exe;T=2013-05-03 19:24:16;P=E:\360\360Safe\safemon\360Tray.exe;C="E:\360\360Safe\safemon\360Tray.exe" /start;[0]ID=236;PID=1876;N=baidupinyin.exe;T=2013-05-03 19:24:16;P=C:\Program Files\Baidu\BaiduPinyin\2.4.2.281\baidupinyin.exe;C="C:\Program Files\Baidu\BaiduPinyin\2.4.2.281\baidupinyin.exe" ;[0]ID=724;PID=1876;N=ctfmon.exe;T=2013-05-03 19:24:16;P=C:\WINDOWS\system32\ctfmon.exe;C="C:\WINDOWS\system32\ctfmon.exe" ;[0]ID=1224;PID=1876;N=360sd.exe;T=2013-05-03 19:24:16;P=E:\360\360sd\360sd.exe;C="E:\360\360sd\360sd.exe" /autorun;[0]ID=3484;PID=1876;N=360se.exe;T=2013-05-03 19:24:30;P=C:\Documents and Settings\Administrator\Application Data\360se6\Application\360se.exe;C="C:\Documents and Settings\Administrator\Application Data\360se6\Application\360se.exe" ;[0]ID=1564;PID=3484;N=360se.exe;T=2013-05-03 19:24:32;P=C:\Documents and Settings\Administrator\Application Data\360se6\Application\360se.exe;C="C:\Documents and Settings\Administrator\Application Data\360se6\Application\360se.exe" --type=renderer --lang=zh-CN --force-fieldtrials=GlobalSdch/global_enable_sdch/ --disable-client-side-phishing-detection --renderer-print-preview --disable-webgl --disable-pepper-3d-for-untrusted-use --disable-gl-multisampling --disable-accelerated-compositing --disable-accelerated-2d-canvas --channel="3484.0.75107847\339845561" /prefetch:3;[0]ID=160;PID=184;N=SoftManagerLite.exe;T=2013-05-03 19:24:53;P=E:\360\360Safe\SoftMgr\SoftManagerLite.exe;C="E:\360\360Safe\SoftMgr\SoftManagerLite.exe" /OpenSml /DisplayNone /DisplayPosLeft=99 /DisplayPosTop=446;[0]ID=2680;PID=1224;N=360rp.exe;T=2013-05-03 19:25:16;P=E:\360\360sd\360rp.exe;C="E:\360\360sd\360rp.exe" /run;[1]ID=1564;T=2013-05-03 19:25:27;[1]ID=3484;T=2013-05-03 19:25:29;[0]ID=2524;PID=1012;N=igfxsrvc.exe;T=2013-05-03 19:25:33;P=C:\WINDOWS\system32\igfxsrvc.exe;C=C:\WINDOWS\system32\igfxsrvc.exe -Embedding;[0]ID=3116;PID=1012;N=igfxsrvc.exe;T=2013-05-03 19:25:40;P=C:\WINDOWS\system32\igfxsrvc.exe;C=C:\WINDOWS\system32\igfxsrvc.exe -Embedding;[1]ID=2524;T=2013-05-03 19:25:41;[0]ID=3588;PID=1876;N=rundll32.exe;T=2013-05-03 19:25:45;P=C:\WINDOWS\system32\rundll32.exe;C="C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,Control_RunDLL "C:\WINDOWS\system32\MMSYS.CPL",@0;[1]ID=3116;T=2013-05-03 19:25:47;[0]ID=3604;PID=1504;N=360leakfixer.exe;T=2013-05-03 19:25:49;P=E:\360\360Safe\360leakfixer.exe;C="E:\360\360Safe\360leakfixer.exe" ;[1]ID=3604;T=2013-05-03 19:25:50;[0]ID=2484;PID=1012;N=igfxsrvc.exe;T=2013-05-03 19:26:03;P=C:\WINDOWS\system32\igfxsrvc.exe;C=C:\WINDOWS\system32\igfxsrvc.exe -Embedding;[0]ID=1244;PID=3588;N=systray.exe;T=2013-05-03 19:26:07;P=C:\WINDOWS\system32\systray.exe;C=SYSTRAY.EXE 4;[1]ID=1244;T=2013-05-03 19:26:07;[1]ID=2484;T=2013-05-03 19:26:09;[0]ID=1664;PID=3588;N=systray.exe;T=2013-05-03 19:26:31;P=C:\WINDOWS\system32\systray.exe;C=SYSTRAY.EXE 4;[1]ID=1664;T=2013-05-03 19:26:31;[0]ID=1668;PID=3588;N=systray.exe;T=2013-05-03 19:26:34;P=C:\WINDOWS\system32\systray.exe;C=SYSTRAY.EXE 4;[1]ID=3588;T=2013-05-03 19:26:34;[1]ID=1668;T=2013-05-03 19:26:34;