这下面的就说明是插入那个进程和路径了
[PID: 684][\??\C:\windows\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\windows\system32\C85B5A86.DLL] [Microsoft Corporation, 5.2.3790.1830]
[PID: 1376][C:\windows\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\windows\system32\C85B5A86.DLL] [Microsoft Corporation, 5.2.3790.1830]