[PID: 620][\??\C:\windows\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 668][C:\windows\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\windows\system32\quartz32.dll] <><4, 0, 0, 0>
[PID: 680][C:\windows\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\windows\system32\TcpIpDog0.dll] <N/A><N/A>
[PID: 832][C:\windows\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 916][C:\windows\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\windows\system32\quartz32.dll] <><4, 0, 0, 0>
[C:\windows\system32\TcpIpDog0.dll] <N/A><N/A>
[C:\windows\system32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 1000][C:\Program Files\Rising\Rav\CCenter.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1020][C:\windows\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\windows\system32\TcpIpDog0.dll] <N/A><N/A>
[C:\windows\system32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[C:\windows\system32\quartz32.dll] <><4, 0, 0, 0>
[PID: 1092][C:\windows\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\windows\system32\TcpIpDog0.dll] <N/A><N/A>
[PID: 1284][C:\windows\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\windows\system32\TcpIpDog0.dll] <N/A><N/A>
[PID: 1328][C:\windows\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\windows\system32\SynTPFcs.dll] <Synaptics, Inc.><7.12.7 04Nov04>
[C:\木马专杀大师\Sockethook.dll] <N/A><N/A>
[C:\windows\system32\quartz32.dll] <><4, 0, 0, 0>
[C:\windows\system32\TcpIpDog0.dll] <N/A><N/A>
[PID: 1412][c:\program files\rising\rfw\rfwsrv.exe] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 32>
[c:\program files\rising\rfw\RfwRule.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 13>
[c:\program files\rising\rfw\rfwlog.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
[c:\program files\rising\rfw\Rfwdrv.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
[c:\program files\rising\rfw\MonDrv.dll] <rs><1, 0, 0, 4>
[c:\program files\rising\rfw\ProcLib.dll] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
[PID: 1544][C:\windows\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[C:\windows\system32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 1800][c:\program files\rising\rfw\RfwMain.exe] <Beijing Rising Technology Co., Ltd.><4, 0, 0, 51>
[c:\program files\rising\rfw\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
[c:\program files\rising\rfw\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[c:\program files\rising\rfw\PngDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[C:\木马专杀大师\Sockethook.dll] <N/A><N/A>
[C:\windows\system32\SynTPFcs.dll] <Synaptics, Inc.><7.12.7 04Nov04>
[PID: 1912][C:\windows\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1944][C:\windows\system32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 1112][C:\windows\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\windows\system32\quartz32.dll] <><4, 0, 0, 0>
[C:\windows\system32\TcpIpDog0.dll] <N/A><N/A>
[PID: 1748][C:\windows\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\木马专杀大师\Sockethook.dll] <N/A><N/A>
[PID: 1776][C:\Program Files\Synaptics\SynTP\SynTPLpr.exe] <Synaptics, Inc.><7.12.7 04Nov04>
[C:\windows\system32\SynCOM.dll] <Synaptics, Inc.><7.12.7 04Nov04>
[C:\windows\system32\SynTPFcs.dll] <Synaptics, Inc.><7.12.7 04Nov04>
[C:\木马专杀大师\Sockethook.dll] <N/A><N/A>
[PID: 1940][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] <Synaptics, Inc.><7.12.7 04Nov04>
[C:\windows\system32\SynCOM.dll] <Synaptics, Inc.><7.12.7 04Nov04>
[C:\windows\system32\SynTPAPI.dll] <Synaptics, Inc.><7.12.7 04Nov04>
[C:\windows\system32\SynTPFcs.dll] <Synaptics, Inc.><7.12.7 04Nov04>
[C:\木马专杀大师\Sockethook.dll] <N/A><N/A>
[PID: 556][C:\Program Files\Rising\Rav\RavTask.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\木马专杀大师\Sockethook.dll] <N/A><N/A>
[PID: 356][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.3510>
[C:\windows\system32\SynTPFcs.dll] <Synaptics, Inc.><7.12.7 04Nov04>
[C:\木马专杀大师\Sockethook.dll] <N/A><N/A>
[PID: 1628][C:\windows\VM_STI.EXE] <VM.><4.2.610.4>
[C:\windows\system32\SynTPFcs.dll] <Synaptics, Inc.><7.12.7 04Nov04>
[C:\windows\system32\msdmo.dll] <N/A><N/A>
[C:\windows\system32\VM31bPrp.Ax] <VM><4.2.711.31>
[C:\木马专杀大师\Sockethook.dll] <N/A><N/A>
[PID: 364][C:\木马专杀大师\木马专杀大师.exe] <木马专杀大师><2.6.0.0>
[C:\windows\system32\SynTPFcs.dll] <Synaptics, Inc.><7.12.7 04Nov04>
[C:\木马专杀大师\Sockethook.dll] <N/A><N/A>
[PID: 2244][C:\Program Files\北京城市热点资讯有限公司\Dr.COM 宽带客户端\ishare_user.exe] <N/A><N/A>
[C:\Program Files\北京城市热点资讯有限公司\Dr.COM 宽带客户端\cw3220.DLL] <Borland International><2.0>
[C:\windows\system32\SynTPFcs.dll] <Synaptics, Inc.><7.12.7 04Nov04>
[C:\木马专杀大师\Sockethook.dll] <N/A><N/A>
[C:\windows\system32\TcpIpDog0.dll] <N/A><N/A>
[C:\windows\system32\cdnns.dll] <CNNIC><2, 0, 0, 0>
[PID: 2272][C:\windows\system32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[PID: 2564][C:\windows\system32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[C:\windows\system32\SynTPFcs.dll] <Synaptics, Inc.><7.12.7 04Nov04>
[C:\木马专杀大师\Sockethook.dll] <N/A><N/A>
[PID: 2992][C:\Program Files\Rising\Rav\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><18, 0, 1, 29>
[C:\Program Files\Rising\Rav\BWList.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
[C:\Program Files\Rising\Rav\RsCommX.dll] <rising><18, 0, 0, 1>
[C:\Program Files\Rising\Rav\RSAPPMGR.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
[C:\Program Files\Rising\Rav\CfgDll.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
[C:\Program Files\Rising\Rav\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[C:\Program Files\Rising\Rav\RsLog.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
[C:\Program Files\Rising\Rav\HOOKSYS.dll] <Rising><18, 1, 0, 9>
[C:\Program Files\Rising\Rav\Scanner.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>