瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 天啊~又是病毒~~~靠~~我狠死了~!!~~!!~有日志

1   1  /  1  页   跳转

天啊~又是病毒~~~靠~~我狠死了~!!~~!!~有日志

天啊~又是病毒~~~靠~~我狠死了~!!~~!!~有日志







[CODE]

2007-12-04,18:16:11

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <nwiz><nwiz.exe /install>  []
    <SoundMan><SOUNDMAN.EXE>  [Realtek Semiconductor Corp.]
    <runeip><"E:\应用软件应用\杀毒\runiep.exe" /startup>  [Beijing Rising Technology Co., Ltd.]
    <360Safetray><D:\应用软件\360安全卫士\360safe\safemon\360Tray.exe /start>  [奇虎网]
    <Anti-Spy Tools><E:\应用软件应用\杀毒\超级巡警\ast\AST.exe -min>  [DSW Lab]
    <360Antiarp><D:\应用软件\360安全卫士\360safe\antiarp\antiarp.exe /start>  [奇虎网]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <360Safe><Rundll32.exe D:\应用软件\360安~1\360safe\AntiAdwa.dll,KillAdware>  [360Safe.com]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><kvdxsjma.dll>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{B859245F-345D-BC13-AC4F-145D47DA34FB}><C:\WINDOWS\system32\avzxkmn.dll>  []
    <{AC87A354-ABC3-DEDE-FF33-3213FD7447CA}><C:\WINDOWS\system32\kvdxjma.dll>  []
    <{AD561258-45F3-A451-F908-A258458226DA}><C:\WINDOWS\system32\kvdxsjma.dll>  []
    <{68907901-1416-3389-9981-372178569986}><C:\WINDOWS\system32\kawdfzy.dll>  []
    <{8A1247C1-53DA-FF43-ABD3-345F323A48D8}><C:\WINDOWS\system32\avwghmn.dll>  []
    <{58847374-8323-FADC-B443-4732ABCD3785}><C:\WINDOWS\system32\sidjezy.dll>  []
    <{D6650011-3344-6688-4899-345FABCD156D}><C:\WINDOWS\system32\ratbmpi.dll>  []
    <{7960356A-458E-DE24-BD50-268F589A56A7}><C:\WINDOWS\system32\avwlgmn.dll>  []
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\system32\夜光时钟.SCR>  []

==================================
启动文件夹
N/A

==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Kingsoft Personal Firewall Service / KPfwSvc][Stopped/Auto Start]
  <><N/A>
[Kingsoft Antivirus KWatch Service / KWatchSvc][Stopped/Auto Start]
  <><N/A>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[P4P Service / P4P Service][Stopped/Auto Start]
  <><N/A>

==================================
驱动程序
[360AntiArp / 360AntiArp][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\360AntiArp.sys><奇虎网>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
  <System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
[RAS Asynchronous Media Driver / AsyncMac][Running/Auto Start]
  <system32\DRIVERS\comint32.sys><N/A>
[comint32 / comint32][Running/Manual Start]
  <\??\C:\WINDOWS\system32\DRIVERS\comint32.sys><N/A>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[kdlhqbr / kdlhqbr][Running/Boot Start]
  <\SystemRoot\\SystemRoot\System32\drivers\kdlhqbr.sys><N/A>
[KNetWch / KNetWch][Stopped/System Start]
  <\??\D:\应用软件\金山杀毒\KNetWch.SYS><N/A>
[KWatch3 / KWatch3][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\KWatch3.SYS><Kingsoft Corporation>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\D:\娱乐软件\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[PciHardDisk / PciHardDisk][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\drivers\pcidisk.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  <\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Running/Manual Start]
  <system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[ZHTU / ZHTU][Stopped/Manual Start]
  <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp29.tmp><N/A>
[Vimicro USB PC Camera (ZC0301PL) / ZSMC301b][Stopped/Manual Start]
  <System32\Drivers\usbVM31b.sys><VM>
[3787750 / 3787750][Running/]
  <2 - 系统找不到指定的文件。
><N/A>

==================================

[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
最后编辑2007-12-06 09:14:17
分享到:
gototop
 

浏览器加载项
[kele8]
  {84920E5F-3788-49cd-A274-E365578DF174} <http://www.kele8.com/, N/A>
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
[SafeMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\应用软件\360安~1\360safe\safemon\safemon.dll, 奇虎网>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>

==================================
正在运行的进程
[PID: 468][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 524][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 548][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 592][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 604][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 756][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 800][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 864][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1520][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5, 1, 0, 52]
    [E:\应用软件应用\杀毒\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\WINDOWS\system32\kvdxsjma.dll]  [N/A, ]
    [E:\应用软件应用\杀毒\超级巡警\ast\AST.dll]  [DSW Lab, 1.0.0.5]
[PID: 1536][E:\应用软件应用\杀毒\runiep.exe]  [Beijing Rising Technology Co., Ltd., 4.0.0.19]
    [E:\应用软件应用\杀毒\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\WINDOWS\system32\kvdxsjma.dll]  [N/A, ]
    [E:\应用软件应用\杀毒\超级巡警\ast\AST.dll]  [DSW Lab, 1.0.0.5]
[PID: 1564][D:\应用软件\360安全卫士\360safe\antiarp\antiarp.exe]  [奇虎网, 1, 0, 1, 1001]
    [E:\应用软件应用\杀毒\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\WINDOWS\system32\kvdxsjma.dll]  [N/A, ]
    [E:\应用软件应用\杀毒\超级巡警\ast\AST.dll]  [DSW Lab, 1.0.0.5]
[PID: 1732][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.8198]
    [C:\WINDOWS\system32\GDMSI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDTLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDZXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWDI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDQQHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDDTHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDJRI32.dll]  [N/A, ]
[PID: 176][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\GDMSI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDTLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDZXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWDI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDQQHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDDTHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDJRI32.dll]  [N/A, ]
[PID: 328][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
    [C:\WINDOWS\system32\GDMSI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDTLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDZXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWDI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDQQHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDDTHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDJRI32.dll]  [N/A, ]
[PID: 3124][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\GDMSI32.dll]  [N/A, ]
    [C:\WINDOWS\System32\GDTLI32.dll]  [N/A, ]
    [C:\WINDOWS\System32\GDWLI32.dll]  [N/A, ]
    [C:\WINDOWS\System32\GDZXI32.dll]  [N/A, ]
    [C:\WINDOWS\System32\GDWDI32.dll]  [N/A, ]
    [C:\WINDOWS\System32\GDQQHXI32.dll]  [N/A, ]
    [C:\WINDOWS\System32\GDDTHXI32.dll]  [N/A, ]
    [C:\WINDOWS\System32\GDJRI32.dll]  [N/A, ]
[PID: 3952][C:\Program Files\Real\RealPlayer\realplay.exe]  [RealNetworks, Inc., 6.0.12.1483]
    [C:\WINDOWS\system32\PNCRT.dll]  [Real Networks, Inc, 6.0.0.0]
    [C:\WINDOWS\system32\GDMSI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDTLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDZXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWDI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDQQHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDDTHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDJRI32.dll]  [N/A, ]
    [C:\Program Files\Common Files\Real\Common\objb3201.dll]  [RealNetworks, Inc., 0.1.0.6391]
    [C:\Program Files\Common Files\Real\Plugins\authmgr.dll]  [RealNetworks, Inc., 10.0.0.1429]
    [C:\Program Files\Common Files\Real\Plugins\cdda3260.dll]  [RealNetworks, Inc., 6.0.3.2258]
    [C:\Program Files\Common Files\Real\Plugins\clbascauth.dll]  [RealNetworks, Inc., 10.0.0.978]
    [C:\Program Files\Common Files\Real\Plugins\httpfsys.dll]  [RealNetworks, Inc., 10.0.0.2779]
    [C:\Program Files\Common Files\Real\Plugins\memfsys.dll]  [RealNetworks, Inc., 10.0.0.966]
    [C:\Program Files\Common Files\Real\Plugins\ntlmauth.dll]  [RealNetworks, Inc., 10.0.0.956]
    [C:\Program Files\Common Files\Real\Plugins\pacplin.dll]  [RealNetworks, Inc., 10.0.0.977]
    [C:\Program Files\Common Files\Real\Plugins\plusplin.dll]  [RealNetworks, Inc., 10.0.0.977]
    [C:\Program Files\Common Files\Real\Plugins\pxcb3210.dll]  [RealNetworks, Inc., 1.0.0.3995]
    [C:\Program Files\Common Files\Real\Plugins\ramfformat.dll]  [RealNetworks, Inc., 10.0.0.2223]
    [C:\Program Files\Common Files\Real\Plugins\ramrender.dll]  [RealNetworks, Inc., 10.0.0.1889]
    [C:\Program Files\Common Files\Real\Plugins\rmfformat.dll]  [RealNetworks, Inc
gototop
 

10.0.0.1201]
    [C:\Program Files\Common Files\Real\Plugins\rn5auth.dll]  [RealNetworks, Inc., 10.0.0.1179]
    [C:\Program Files\Common Files\Real\Plugins\smlfformat.dll]  [RealNetworks, Inc., 10.0.0.1859]
    [C:\Program Files\Common Files\Real\Plugins\smlrender.dll]  [RealNetworks, Inc., 10.0.0.1475]
    [C:\Program Files\Common Files\Real\Plugins\smmrender.dll]  [RealNetworks, Inc., 10.0.0.976]
    [C:\Program Files\Common Files\Real\Plugins\vidsite.dll]  [RealNetworks, Inc., 10.0.0.979]
    [C:\Program Files\Common Files\Real\Plugins\smplfsys.dll]  [RealNetworks, Inc., 10.0.0.1767]
    [C:\Program Files\Common Files\Real\Plugins\zipf3260.dll]  [RealNetworks, Inc., 6.0.8.2550]
    [C:\Program Files\Common Files\Real\Plugins\vsrcplin.dll]  [RealNetworks, Inc., 10.1.0.906]
    [C:\Program Files\Common Files\Real\Plugins\vsrlocal.dll]  [RealNetworks, Inc., 10.1.0.906]
    [C:\Program Files\Common Files\Real\Plugins\rarender.dll]  [RealNetworks, Inc., 10.0.0.986]
    [C:\Program Files\Common Files\Real\Plugins\swfformat.dll]  [RealNetworks, Inc., 10.0.0.1184]
    [C:\Program Files\Common Files\Real\Plugins\rtfformat.dll]  [RealNetworks, Inc., 10.0.0.1183]
    [C:\Program Files\Common Files\Real\Plugins\rtrender.dll]  [RealNetworks, Inc., 10.0.0.976]
    [C:\Program Files\Common Files\Real\Plugins\imgrender.dll]  [RealNetworks, Inc., 10.0.0.993]
    [C:\Program Files\Common Files\Real\Plugins\sdpplin.dll]  [RealNetworks, Inc., 10.0.0.373]
    [C:\Program Files\Common Files\Real\Plugins\mp3render.dll]  [RealNetworks, Inc., 10.0.0.977]
    [C:\Program Files\Common Files\Real\Plugins\mp3metaff.dll]  [RealNetworks, Inc., 10.0.0.965]
    [C:\Program Files\Common Files\Real\Plugins\stubdrm.dll]  [RealNetworks, Inc., 10.0.0.1381]
    [C:\Program Files\Common Files\Real\Plugins\mp4arender.dll]  [RealNetworks, Inc., 10.0.0.780]
    [C:\Program Files\Common Files\Real\Plugins\aacff.dll]  [RealNetworks, Inc., 10.0.0.771]
    [C:\Program Files\Common Files\Real\Plugins\wm9fformat.dll]  [RealNetworks, Inc., 1.0.0.1088]
    [C:\Program Files\Common Files\Real\Plugins\wm9writer.dll]  [RealNetworks, Inc., 1.0.0.1072]
    [C:\Program Files\Common Files\Real\Plugins\wmsechnd.dll]  [RealNetworks, Inc., 1.0.0.407]
    [C:\Program Files\Common Files\Real\Plugins\recf3260.dll]  [RealNetworks, Inc., 6.0.0.2863]
    [C:\Program Files\Common Files\Real\Plugins\cont3260.dll]  [RealNetworks, Inc., 6.0.0.1897]
    [C:\Program Files\Common Files\Real\Plugins\audplin.dll]  [RealNetworks, Inc., 10.0.0.1207]
    [C:\Program Files\Common Files\Real\Plugins\vidplin.dll]  [RealNetworks, Inc., 10.0.0.993]
    [C:\Program Files\Common Files\Real\Plugins\mpgfformat.dll]  [RealNetworks, Inc., 10.0.0.1174]
    [C:\Program Files\Common Files\Real\Plugins\mpgrender.dll]  [RealNetworks, Inc., 10.0.0.956]
    [C:\Program Files\Common Files\Real\Plugins\mp4wrtr.dll]  [N/A, ]
    [C:\Program Files\Common Files\Real\Plugins\rmwrtr.dll]  [RealNetworks, Inc., 6.0.2.1155]
    [C:\Program Files\Common Files\Real\Plugins\security.dll]  [RealNetworks, Inc., 1.0.3.2268]
    [C:\Program Files\Common Files\Real\Plugins\rmxrend.dll]  [RealNetworks, Inc., 1.0.3.2330]
    [C:\Program Files\Common Files\Real\Plugins\rmxfpln.dll]  [RealNetworks, Inc., 1.0.3.2277]
    [C:\Program Files\Common Files\Real\Plugins\tfilesys.dll]  [RealNetworks, Inc., 1.0.3.2238]
    [C:\Program Files\Common Files\Real\Plugins\fpsechnd.dll]  [RealNetworks, Inc., 6.0.9.32]
    [C:\Program Files\Common Files\Real\Plugins\pdgenxferfsys.dll]  [RealNetworks, Inc., 6.0.12.1430]
    [C:\Program Files\Common Files\Real\RCAPlugins\gct23201.dll]  [RealNetworks, Inc., 0.1.0.6324]
    [C:\Program Files\Common Files\Real\RCAPlugins\uisy3201.dll]  [RealNetworks, Inc., 0.1.0.3832]
    [C:\Program Files\Common Files\Real\RCAPlugins\rpcontrols1.dll]  [RealNetworks, Inc., 6.0.1.2234]
    [C:\Program Files\Common Files\Real\Common\pnrs3260.dll]  [RealNetworks, Inc., 6.0.9.4068]
    [C:\Program Files\Common Files\Real\RCAPlugins\rpcontrols2.dll]  [RealNetworks, 6.0.1.2234]
    [C:\Program Files\Common Files\Real\RCAPlugins\gema3201.dll]  [RealNetworks, Inc., 0.1.0.3815]
    [C:\Program Files\Common Files\Real\RCAPlugins\gemx3201.dll]  [RealNetworks, Inc., 0.1.0.5869]
    [C:\Program Files\Common Files\Real\RCAPlugins\xmlc3201.dll]  [RealNetworks, Inc., 0.1.1.2240]
    [C:\Program Files\Common Files\Real\RCAPlugins\sonr3210.dll]  [RealNetworks, Inc., 1.0.0.2330]
    [C:\Program Files\Common Files\Real\RCAPlugins\locd3210.dll]  [RealNetworks, Inc., 1.0.0.2132]
    [C:\Program Files\Common Files\Real\Update_OB\rnqu3270.dll]  [RealNetworks, Inc., 7.0.0.3818]
    [C:\Program Files\Common Files\Real\Update_OB\rnup3270.dll]  [RealNetworks, Inc., 7.0.0.3084]
    [C:\Program Files\Common Files\Real\Update_OB\upgr3270.dll]  [RealNetworks, Inc., 7.0.0.3735]
    [C:\Program Files\Common Files\Real\Update_OB\setu3270.dll]  [RealNetworks, Inc., 7.0.0.4369]
    [C:\Program Files\Common Files\Real\Update_OB\faus3270.dll]  [RealNetworks, Inc., 7.0.0.3206]
    [C:\Program Files\Common Files\Real\Update_OB\rnad3201.dll]  [RealNetworks, Inc., 0.1.0.3510]
    [C:\Program Files\Common Files\Real\Update_OB\pnmi3270.dll]  [RealNetworks, Inc., 7.0.0.1907]
    [C:\Program Files\Common Files\Real\Update_OB\rnms3270.dll]  [RealNetworks, Inc., 7.0.1.3334]
    [C:\Program Files\Real\RealPlayer\rpplugins\cdpl3210.dll]  [RealNetworks, Inc., 1.0.3.2293]
    [C:\Program Files\Common Files\Real\Common\pngu3267.dll]  [RealNetworks, Inc., 6.7.0.2712]
    [C:\Program Files\Real\RealPlayer\rpplugins\MPACore.dll]  [RealNetworks, Inc., 1.0.3.2290]
    [C:\Program Files\Real\RealPlayer\rpplugins\myde3260.dll]  [RealNetworks, Inc., 6.0.10.2499]
    [C:\Program Files\Real\RealPlayer\rpplugins\rjbc3260.dll]  [RealNetworks, Inc., 6.0.1.2279]
    [C:\Program Files\Real\RealPlayer\rpplugins\rjbdll.dll]  [RealNetworks, Inc., 1.0.4.2271]
    [C:\Program Files\Real\RealPlayer\rpplugins\rjbe3260.dll]  [RealNetworks, Inc., 6.0.4.2274]
    [C:\Program Files\Real\RealPlayer\rpplugins\rjbs3260.dll]  [RealNetworks, Inc., 6.0.10.2272]
    [C:\Program Files\Real\RealPlayer\rpplugins\rjbxfade.dll]  [RealNetworks, Inc., 1.0.3.2241]
    [C:\Program Files\Real\RealPlayer\rpplugins\rjmisc.dll]  [RealNetworks, Inc., 1.0.3.2274]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpap3260.dll]  [RealNetworks, Inc., 6.0.9.3039]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpappdemon.dll]  [RealNetworks, Inc., 6.0.12.647]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpcl3260.dll]  [RealNetworks, Inc., 6.0.9.3112]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpcomproxy.dll]  [RealNetworks, Inc., 6.0.12.990]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpgu3260.dll]  [RealNetworks, Inc., 6.0.10.2271]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpme3260.dll]  [RealNetworks, Inc., 6.0.10.2270]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpmn3260.dll]  [RealNetworks, Inc., 6.0.9.2934]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpms3260.dll]  [RealNetworks, Inc., 6.0.1.2271]
    [C:\Program Files\Real\RealPlayer\rpplugins\rppl3260.dll]  [RealNetworks, Inc., 6.0.1.2272]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpqt3260.dll]  [RealNetworks, Inc., 6.0.9.2240]
    [C:\Program Files\Real\RealPlayer\rpplugins\rput3260.dll]  [RealNetworks, Inc., 6.0.9.3088]
    [C:\Program Files\Real\RealPlayer\rpplugins\tmde3210.dll]  [RealNetworks, Inc., 1.0.3.2262]
    [C:\Program Files\Real\RealPlayer\rpplugins\ierpplug.dll]  [RealNetworks, Inc., 1.0.1.2254]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpds3260.dll]  [RealNetworks, Inc., 6.0.9.2274]
    [C:\Program Files\Real\RealPlayer\rpplugins\embd3260.dll]  [RealNetworks, Inc., 6.0.12.1483]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpho3260.dll]  [RealNetworks, Inc., 6.0.10.2197]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpwm3260.dll]  [RealNetworks, Inc., 6.0.9.1000]
    [C:\Program Files\Real\RealPlayer\rpplugins\mpazip.dll]  [RealNetworks, Inc., 1.0.4.2290]
    [C:\Program Files\Real\RealPlayer\rpplugins\pdbu3210.dll]  [RealNetworks, Inc., 1.0.1.1259]
    [C:\Program Files\Real\RealPlayer\rpplugins\fftr3210.dll]  [RealNetworks, Inc., 1.0.1.2511]
    [C:\Program Files\Real\RealPlayer\rpplugins\pdge3260.dll]  [RealNetworks, Inc., 6.0.12.1543]
    [C:\Program Files\Real\RealPlayer\rpplugins\pdctnomad.dll]  [RealNetworks, Inc., 1.0.1.635]
    [C:\Program Files\Real\RealPlayer\rpplugins\pdwmdm.dll]  [RealNetworks, Inc., 1.0.1.666]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpwe3260-.dll]  [RealNetworks, Inc., 6.0.1.2277]
gototop
 

[C:\Program Files\Real\RealPlayer\lang\cdplay_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\dbcomp_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\embed_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\gemctl_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\pngui_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\pdgenxfer_cn.dll]  [N/A, ]
    [C:\Program Files\Real\RealPlayer\lang\rjctl_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rjeq_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rjres_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rjskin_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rjviz_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rjfade_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rjdlg_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rjmisc_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rjprog_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rpapp_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rpclsvc_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rpclutil_cn.dll]  [RealNetworks, Inc., 6.0.12.299]
    [C:\Program Files\Real\RealPlayer\lang\rpdemand_cn.dll]  [RealNetworks, Inc., 6.0.12.299]
    [C:\Program Files\Real\RealPlayer\lang\rpdsplyr_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rpgutil_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rpmnpane_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rpplylst_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rpwebctl_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\tcdinfo_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\tclsvc_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\tdwnmgr_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\tmp3_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\twave_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\teasdk_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\tearm_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\tmdedit_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\mydevices_cn.dll]  [RealNetworks, Inc., 6.0.12.299]
    [E:\应用软件应用\杀毒\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\WINDOWS\system32\kvdxsjma.dll]  [N/A, ]
    [E:\应用软件应用\杀毒\超级巡警\ast\AST.dll]  [DSW Lab, 1.0.0.5]
[PID: 3384][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\GDMSI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDTLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDZXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWDI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDQQHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDDTHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDJRI32.dll]  [N/A, ]
    [E:\应用软件应用\杀毒\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\WINDOWS\system32\kvdxsjma.dll]  [N/A, ]
    [E:\应用软件应用\杀毒\超级巡警\ast\AST.dll]  [DSW Lab, 1.0.0.5]
[PID: 4004][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\GDMSI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDTLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDZXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWDI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDQQHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDDTHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDJRI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\kakatool.dll]  [Beijing Rising Technology Co., Ltd., 2, 0, 2, 6]
    [E:\应用软件应用\杀毒\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [C:\WINDOWS\system32\kvdxsjma.dll]  [N/A, ]
    [E:\应用软件应用\杀毒\超级巡警\ast\AST.dll]  [DSW Lab, 1.0.0.5]
[PID: 4144][D:\应用软件\360安全卫士\360safe\360Safe.exe]  [奇虎网, 3, 7, 0, 1001]
    [C:\WINDOWS\system32\avzxkmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDMSI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDTLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDZXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWDI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDQQHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDDTHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDJRI32.dll]  [N/A, ]
    [D:\应用软件\360安全卫士\360safe\AntiAdwa.dll]  [360Safe.com, 3, 6, 3, 1001]
    [D:\应用软件\360安全卫士\360safe\AntiEng.dll]  [360Safe.com, 3, 6, 4, 1001]
    [D:\应用软件\360安全卫士\360safe\LeakCheck.dll]  [360Safe.com, 3, 6, 4, 1001]
    [D:\应用软件\360安全卫士\360safe\CleanHis.dll]  [奇虎网, 3, 0, 2, 1000]
    [E:\应用软件应用\杀毒\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\WINDOWS\system32\kvdxsjma.dll]  [N/A, ]
    [C:\WINDOWS\system32\kvdxjma.dll]  [N/A, ]
    [C:\WINDOWS\system32\avwghmn.dll]  [N/A, ]
    [D:\应用软件\360安全卫士\360safe\Antispy.dll]  [奇虎网, 3, 6, 3, 1001]
    [C:\WINDOWS\system32\ratbmpi.dll]  [N/A, ]
    [C:\WINDOWS\system32\sidjezy.dll]  [N/A, ]
    [C:\WINDOWS\system32\kawdfzy.dll]  [N/A, ]
    [C:\WINDOWS\system32\avwlgmn.dll]  [N/A, ]
    [D:\应用软件\360安全卫士\360safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
    [D:\应用软件\360安全卫士\360safe\safeext.dll]  [360Safe.com, 1, 0, 0, 1041]
    [E:\应用软件应用\杀毒\超级巡警\ast\AST.dll]  [DSW Lab, 1.0.0.5]
gototop
 

[PID: 6568][C:\WINDOWS\explorer.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\kvdxsjma.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDMSI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDTLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDZXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWDI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDQQHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDDTHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDJRI32.dll]  [N/A, ]
    [E:\应用软件应用\杀毒\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\WINDOWS\system32\avwlgmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\kawdfzy.dll]  [N/A, ]
    [C:\WINDOWS\system32\sidjezy.dll]  [N/A, ]
    [C:\WINDOWS\system32\ratbmpi.dll]  [N/A, ]
    [C:\WINDOWS\system32\avwghmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\kvdxjma.dll]  [N/A, ]
    [C:\WINDOWS\system32\avzxkmn.dll]  [N/A, ]
    [D:\应用软件\360安全卫士\360safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
    [E:\应用软件应用\杀毒\超级巡警\ast\AST.dll]  [DSW Lab, 1.0.0.5]
[PID: 9216][D:\应用软件\360安全卫士\360safe\safemon\360Tray.exe]  [奇虎网, 3, 6, 4, 3002]
    [C:\WINDOWS\system32\GDMSI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDTLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDZXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWDI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDQQHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDDTHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDJRI32.dll]  [N/A, ]
    [D:\应用软件\360安全卫士\360safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
    [D:\应用软件\360安全卫士\360safe\safemon\SafeKrnl.dll]  [奇虎网, 3, 6, 0, 1001]
    [D:\应用软件\360安全卫士\360safe\AntiAdwa.dll]  [360Safe.com, 3, 6, 3, 1001]
    [E:\应用软件应用\杀毒\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\WINDOWS\system32\kvdxsjma.dll]  [N/A, ]
    [D:\应用软件\360安全卫士\360safe\live.dll]  [360safe.com, 1, 0, 1, 1021]
    [C:\WINDOWS\system32\avzxkmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\kvdxjma.dll]  [N/A, ]
    [C:\WINDOWS\system32\avwghmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\ratbmpi.dll]  [N/A, ]
    [C:\WINDOWS\system32\avwlgmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\sidjezy.dll]  [N/A, ]
    [C:\WINDOWS\system32\kawdfzy.dll]  [N/A, ]
    [E:\应用软件应用\杀毒\超级巡警\ast\AST.dll]  [DSW Lab, 1.0.0.5]
[PID: 2480][E:\应用软件应用\杀毒\超级巡警\ast\AST.exe]  [DSW Lab, 1, 8, 6, 0]
    [E:\应用软件应用\杀毒\超级巡警\ast\dbghelp.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [E:\应用软件应用\杀毒\超级巡警\ast\MFC80.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [E:\应用软件应用\杀毒\超级巡警\ast\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [E:\应用软件应用\杀毒\超级巡警\ast\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\WINDOWS\system32\kvdxsjma.dll]  [N/A, ]
    [E:\应用软件应用\杀毒\超级巡警\ast\MFC80CHS.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\WINDOWS\system32\GDMSI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDTLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDZXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWDI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDQQHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDDTHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDJRI32.dll]  [N/A, ]
    [E:\应用软件应用\杀毒\超级巡警\ast\common.dll]  [DSW Lab, 1.4.0.7]
    [D:\应用软件\360安全卫士\360safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
    [E:\应用软件应用\杀毒\超级巡警\ast\AST.dll]  [DSW Lab, 1.0.0.5]
    [E:\应用软件应用\杀毒\超级巡警\ast\AutoRun.dll]  [ DSW Lab, 2.2.2.1]
    [E:\应用软件应用\杀毒\超级巡警\ast\EngineSDK.dll]  [DSW Lab, 2.2.1.23]
    [E:\应用软件应用\杀毒\超级巡警\ast\FileAnalyser.dll]  [DSW Lab , 1.0.1.7]
    [E:\应用软件应用\杀毒\超级巡警\ast\KillModule.dll]  [DSW Lab, 1.2.2.1]
    [E:\应用软件应用\杀毒\超级巡警\ast\ManagerProcess.dll]  [DSW Lab, 1.3.4.1]
    [E:\应用软件应用\杀毒\超级巡警\ast\ManagerService.dll]  [DSW Lab, 1.0.6.0]
    [E:\应用软件应用\杀毒\超级巡警\ast\PortAssociate.dll]  [DSW Lab, 1.0.3.0]
    [E:\应用软件应用\杀毒\超级巡警\ast\SSDT.dll]  [DSW Lab, 1.0.2.1]
    [E:\应用软件应用\杀毒\超级巡警\ast\StateViewer.dll]  [DSW Lab, 1.0.0.1]
    [E:\应用软件应用\杀毒\超级巡警\ast\TIERepair.dll]  [Secward , 1.2.2.0]
    [E:\应用软件应用\杀毒\超级巡警\ast\aScanCom.dll]  [DSW Lab, 2.1.1.27]
    [E:\应用软件应用\杀毒\超级巡警\ast\msvcm80.dll]  [Microsoft Corporation, 8.00.50727.762]
gototop
 

[E:\应用软件应用\杀毒\超级巡警\ast\sm.dll]  [DSW Lab, 1.0.0.1]
    [E:\应用软件应用\杀毒\超级巡警\ast\tRubbishClear.dll]  [Secward , 1.5.2.2]
    [E:\应用软件应用\杀毒\超级巡警\ast\tSecurityOptimize.dll]  [DSW Lab, 1.1.0.6]
    [E:\应用软件应用\杀毒\超级巡警\ast\zDiagnosticTool.dll]  [Secward , 1.2.1.0]
    [E:\应用软件应用\杀毒\超级巡警\ast\smart.dll]  [DSW Lab, 1.0.0.17]
    [E:\应用软件应用\杀毒\超级巡警\ast\unarc.dll]  [DSW Lab, 1.2.5]
    [E:\应用软件应用\杀毒\超级巡警\ast\Monitor.dll]  [DSW Lab, 1.7.8.12]
    [E:\应用软件应用\杀毒\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\WINDOWS\system32\kawdfzy.dll]  [N/A, ]
    [C:\WINDOWS\system32\sidjezy.dll]  [N/A, ]
    [C:\WINDOWS\system32\avwlgmn.dll]  [N/A, ]
    [E:\应用软件应用\杀毒\超级巡警\ast\MScaner.dll]  [DSW Lab, 1.0.0.11]
    [E:\应用软件应用\杀毒\超级巡警\ast\SKEngine.dll]  [DSW Lab, 1.6.5.10]
    [C:\WINDOWS\system32\ratbmpi.dll]  [N/A, ]
    [C:\WINDOWS\system32\avwghmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\kvdxjma.dll]  [N/A, ]
    [C:\WINDOWS\system32\avzxkmn.dll]  [N/A, ]
[PID: 9520][D:\应用软件\系统检测\sreng2\asd.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\WINDOWS\system32\kvdxsjma.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDMSI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDTLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWLI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDZXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDWDI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDQQHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDDTHXI32.dll]  [N/A, ]
    [C:\WINDOWS\system32\GDJRI32.dll]  [N/A, ]
    [E:\应用软件应用\杀毒\超级巡警\ast\AST.dll]  [DSW Lab, 1.0.0.5]
    [D:\应用软件\360安全卫士\360safe\safemon\safemon.dll]  [奇虎网, 3, 6, 4, 1001]
    [E:\应用软件应用\杀毒\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 12]
    [C:\WINDOWS\system32\ratbmpi.dll]  [N/A, ]
    [C:\WINDOWS\system32\avwghmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\kvdxjma.dll]  [N/A, ]
    [C:\WINDOWS\system32\avzxkmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\avwlgmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\sidjezy.dll]  [N/A, ]
    [C:\WINDOWS\system32\kawdfzy.dll]  [N/A, ]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A
gototop
 

API HOOK
入口点错误:CreateProcessW (危险等级: 一般,  被下面模块所HOOK: E:\应用软件应用\杀毒\超级巡警\ast\AST.dll)

==================================
隐藏进程
N/A
gototop
 

楼主愿意的话,格盘重装个新系统。
或者手工处理吧:
将下面文件改名,随便改。
文件是隐藏的系统的属性,你不定能看到,可以用解压工具WinRAR依路径打开找这些文件。
C:\WINDOWS\system32\GDMSI32.dll
C:\WINDOWS\system32\GDTLI32.dll
C:\WINDOWS\system32\GDWLI32.dll
C:\WINDOWS\system32\GDZXI32.dll
C:\WINDOWS\system32\GDWDI32.dll
C:\WINDOWS\system32\GDQQHXI32.dll
C:\WINDOWS\system32\GDDTHXI32.dll
C:\WINDOWS\system32\GDJRI32.dll
C:\WINDOWS\system32\kvdxsjma.dll
C:\WINDOWS\system32\avzxkmn.dll
C:\WINDOWS\system32\kvdxjma.dll
C:\WINDOWS\system32\avwghmn.dll
C:\WINDOWS\system32\ratbmpi.dll
C:\WINDOWS\system32\avwlgmn.dll
C:\WINDOWS\system32\sidjezy.dll
C:\WINDOWS\system32\kawdfzy.dll

重启电脑

————————————————————————————————————
在扫日志的SRENG工具》启动项目》注册表》里面找下面项目删除:

启动项目
注册表
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{B859245F-345D-BC13-AC4F-145D47DA34FB}><C:\WINDOWS\system32\avzxkmn.dll> []
<{AC87A354-ABC3-DEDE-FF33-3213FD7447CA}><C:\WINDOWS\system32\kvdxjma.dll> []
<{AD561258-45F3-A451-F908-A258458226DA}><C:\WINDOWS\system32\kvdxsjma.dll> []
<{68907901-1416-3389-9981-372178569986}><C:\WINDOWS\system32\kawdfzy.dll> []
<{8A1247C1-53DA-FF43-ABD3-345F323A48D8}><C:\WINDOWS\system32\avwghmn.dll> []
<{58847374-8323-FADC-B443-4732ABCD3785}><C:\WINDOWS\system32\sidjezy.dll> []
<{D6650011-3344-6688-4899-345FABCD156D}><C:\WINDOWS\system32\ratbmpi.dll> []
<{7960356A-458E-DE24-BD50-268F589A56A7}><C:\WINDOWS\system32\avwlgmn.dll> []
————————————————————————————————————
在扫日志的SRENG工具》启动项目》注册表》里将下面项目置空(就是选择“编辑”)
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><kvdxsjma.dll> []

<AppInit_DLLs><kvdxsjma.dll> []
置空为
<AppInit_DLLs><> []
————————————————————————————————————
在扫日志的SRENG工具》启动项目》服务》驱动程序》里面找下面各项,将启动类型改为“Disabled”
==================================
驱动程序
[RAS Asynchronous Media Driver / AsyncMac][Running/Auto Start]
<system32\DRIVERS\comint32.sys><N/A>
[comint32 / comint32][Running/Manual Start]
<\??\C:\WINDOWS\system32\DRIVERS\comint32.sys><N/A>

[kdlhqbr / kdlhqbr][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\kdlhqbr.sys><N/A>

[PciHardDisk / PciHardDisk][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\pcidisk.sys><N/A>

[ZHTU / ZHTU][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp29.tmp><N/A>

[3787750 / 3787750][Running/]
<2 - 系统找不到指定的文件。
><N/A>
————————————————————————————————————
再重启电脑,最好重装杀毒软件,并升级至最新版本,全盘杀毒。

然后,可以再扫个新日志以附件形式发来看看。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT