==================================
正在运行的进程
[PID: 468][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 536][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 560][\??\C:\WINDOWS\SYSTEM32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\SYSTEM32\Ati2evxx.dll] <ATI Technologies Inc.><6.14.10.4107>
[C:\WINDOWS\SYSTEM32\SSMWinlogonEx.dll] <System Safety Limited><2.0.0.558>
[PID: 604][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 616][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\KvWspXp.dll] <JiangMin Ltd.><9, 0, 5, 324>
[PID: 776][C:\WINDOWS\system32\Ati2evxx.exe] <ATI Technologies Inc.><6.14.10.4107>
[C:\WINDOWS\system32\Ati2edxx.dll] <ATI Technologies, Inc.><6, 14, 10, 2495>
[PID: 788][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 844][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\KvWspXp.dll] <JiangMin Ltd.><9, 0, 5, 324>
[PID: 920][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\KvWspXp.dll] <JiangMin Ltd.><9, 0, 5, 324>
[c:\windows\system32\beyqdmqm.dll] <N/A><N/A>
[PID: 972][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\KvWspXp.dll] <JiangMin Ltd.><9, 0, 5, 324>
[PID: 1016][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1264][C:\WINDOWS\SYSTEM32\Ati2evxx.exe] <ATI Technologies Inc.><6.14.10.4107>
[C:\WINDOWS\SYSTEM32\Ati2edxx.dll] <ATI Technologies, Inc.><6, 14, 10, 2495>
[PID: 1340][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\KV2005\KvShell_2.dll] <JiangMin Lmt><9, 0, 5, 1205>
[C:\Program Files\KV2005\UpdateX.dll] <JiangMin Ltd.><8, 0, 0, 0>
[C:\Program Files\KV2005\lang\Kvxp0804_1.lng] <N/A><N/A>
[C:\Program Files\KV2005\APIImpl.dll] <JiangMin Ltd.><9.0.0.500>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[E:\SPYBOT~1\SDHelper.dll] <Safer Networking Limited><1, 4, 0, 0>
[PID: 1440][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 1508][C:\WINDOWS\SOUNDMAN.EXE] <Realtek Semiconductor Corp.><5.1.0.30>
[C:\Program Files\KV2005\KVMonXP_1.kxp] <JiangMin Co.Ltd><9, 2, 0, 60118>
[C:\Program Files\KV2005\UpdateX.dll] <JiangMin Ltd.><8, 0, 0, 0>
[C:\Program Files\KV2005\lang\Kvxp0804_1.lng] <N/A><N/A>
[C:\Program Files\KV2005\GUIExt.dll] <JiangMin Ltd.><9.0.0.501>
[C:\Program Files\KV2005\lang\GUIExt0804.lng] <JiangMin Ltd.><7, 1, 0, 200>
[C:\Program Files\KV2005\KVEnhP.dll] <JiangMin Ltd.><9, 0, 5, 405>
[C:\Program Files\KV2005\KvSpiPS.dll] <JiangMin Ltd.><9.0.0.501>
[C:\Program Files\KV2005\KvOffice.dll] <JiangMin New Tech.><9.0.0.1213>
[C:\Program Files\KV2005\lang\KVOffice0804.lng] <N/A><N/A>
[C:\Program Files\KV2005\VirusUpload.dll] <N/A><2, 0, 0, 0>
[C:\Program Files\KV2005\PProtect.dll] <北京江民新科技术公司><1.0.121>
[PID: 1608][D:\PROGRA~1\SKYNET\FIREWALL\PFW.exe] <广州众达天网技术有限公司><2.7.7.1001>
[D:\PROGRA~1\SKYNET\FIREWALL\SKYMISC.DLL] <N/A><N/A>
[D:\PROGRA~1\SKYNET\FIREWALL\COMPRESSWRAP.DLL] <N/A><N/A>
[C:\WINDOWS\system32\KvWspXp.dll] <JiangMin Ltd.><9, 0, 5, 324>
[PID: 1616][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] <RealNetworks, Inc.><0.1.0.3427>
[PID: 1672][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1884][C:\PROGRA~1\KV2005\KVSrvXP.exe] <JiangMin New Tech Ltd.><9, 0, 5, 720>
[C:\PROGRA~1\KV2005\UpdateX.dll] <JiangMin Ltd.><8, 0, 0, 0>
[C:\Program Files\KV2005\KVEnhD.dll] <JiangMin Ltd.><9, 1, 5, 423>
[C:\Program Files\KV2005\KvSPI.dll] <JiangMin New Tech. Ltd.><9, 0, 5, 720>
[C:\PROGRA~1\KV2005\PProtect.dll] <北京江民新科技术公司><1.0.121>
[C:\Program Files\KV2005\KVEnhP.dll] <JiangMin Ltd.><9, 0, 5, 405>
[C:\Program Files\KV2005\KVEnhM.dll] <JiangMin Ltd.><9.0.0.500>
[C:\Program Files\KV2005\KvSpiPS.dll] <JiangMin Ltd.><9.0.0.501>
[C:\WINDOWS\system32\KvWspXp.dll] <JiangMin Ltd.><9, 0, 5, 324>
[C:\Program Files\KV2005\KVEnhC.DLL] <JiangMin Ltd.><9, 1, 5, 603>
[C:\Program Files\KV2005\KVEnhO.dll] <JiangMin New Tech Ltd.><9, 0, 5, 507>
[C:\Program Files\KV2005\KVEnhS.dll] <JiangMin New Tech Ltd.><9, 0, 5, 607>
[C:\Program Files\KV2005\KVEnhJ.dll] <JiangMin New Tech. Ltd.><9, 1, 5, 508>
[C:\Program Files\KV2005\KVExtEml.dll] <JiangMin New Tech. Ltd.><9, 0, 0, 503>
[C:\Program Files\KV2005\KVExtLZH.dll] <N/A><N/A>
[C:\Program Files\KV2005\KVExtZ.dll] <Jiangmin New Tech.><9.1.0.503>
[C:\Program Files\KV2005\KVExtCab.dll] <JiangMin New Tech. Ltd.><9, 0, 5, 621>
[C:\Program Files\KV2005\KvExtRar.dll] <JiangMin Ltd.><9, 1, 0, 804>
[C:\Program Files\KV2005\KvExtZip.dll] <JiangMin Ltd.><9, 0, 5, 420>
[C:\Program Files\KV2005\KVExtGz.dll] <Jiangmin New Tech.><9, 0, 5, 420>
[C:\Program Files\KV2005\KVExtTar.dll] <Jiangmin New Tech.><9, 0, 5, 420>
[C:\Program Files\KV2005\KVEnhK.dll] <JiangMin Ltd.><9, 1, 5, 507>
[PID: 1908][C:\Program Files\KV2005\kvwsc.exe] <Jiangmin Co.Ltd><9, 0, 0, 502>
[C:\Program Files\KV2005\KVEnhP.dll] <JiangMin Ltd.><9, 0, 5, 405>
[C:\Program Files\KV2005\TrojDie.kxp] <Jiangmin Co.Ltd><9, 0, 5, 916>
[C:\Program Files\KV2005\UpdateX.dll] <JiangMin Ltd.><8, 0, 0, 0>
[C:\Program Files\KV2005\lang\TrojDie0804.lng] <N/A><N/A>
[C:\Program Files\KV2005\GUIExt.dll] <JiangMin Ltd.><9.0.0.501>
[C:\Program Files\KV2005\lang\GUIExt0804.lng] <JiangMin Ltd.><7, 1, 0, 200>
[C:\Program Files\KV2005\PProtect.dll] <北京江民新科技术公司><1.0.121>
[C:\Program Files\KV2005\ComUIPS.dll] <N/A><9. 5. 5. 20>
[PID: 1180][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\KvWspXp.dll] <JiangMin Ltd.><9, 0, 5, 324>
[PID: 1396][C:\Program Files\KV2005\KRegEx.exe] <Jiangmin><1.0.1.0413>
[C:\Program Files\KV2005\KRegEx.dll] <N/A><N/A>
[C:\Program Files\KV2005\KRegTrust.dll] <Jiangmin Co. Ltd.><9.0.0.825>
[PID: 2008][C:\WINDOWS\system32\DllHost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\Program Files\KV2005\ComUI.dll] <Jiangmin Ltd.><9. 5. 5. 20>
[C:\Program Files\KV2005\UpdateX.dll] <JiangMin Ltd.><8, 0, 0, 0>
[C:\Program Files\KV2005\ComUIPS.dll] <N/A><9. 5. 5. 20>
[C:\Program Files\KV2005\GUIExt.dll] <JiangMin Ltd.><9.0.0.501>
[C:\Program Files\KV2005\lang\GUIExt0804.lng] <JiangMin Ltd.><7, 1, 0, 200>
[PID: 2204][C:\WINDOWS\system32\wuauclt.exe] <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[PID: 2612][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2800][F:\sreng\SREng.exe] <Smallfrogs Studio><2.0.12.350>
[C:\WINDOWS\system32\KvWspXp.dll] <JiangMin Ltd.><9, 0, 5, 324>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
C:\WINDOWS\system32\KvWspXp.dll(JiangMin Ltd., KVWspXP)
MSAFD Tcpip [UDP/IP]
C:\WINDOWS\system32\KvWspXp.dll(JiangMin Ltd., KVWspXP)
MSAFD Tcpip [RAW/IP]
C:\WINDOWS\system32\KvWspXp.dll(JiangMin Ltd., KVWspXP)
==================================
在一大虾的指点下,我删除了c:\windows\system32 中的beyqdmqm.dll及beyqdmqm.sys文件,注册表中的beyqdmqm项,红色ie进程不见了,但ssdt项里还有很多红色线程,如图,请问如何处理