【回复“中毒的小鸟”的帖子】
正在运行的进程
[PID: 440][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 504][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 528][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 572][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 584][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 760][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 808][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 960][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 988][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1204][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\downlo~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\KV2004\KvShell.dll] [JiangMin Lmt, 8.0.0.309]
[C:\KV2004\UpdateX.dll] [JiangMin Ltd., 8.0.0.309]
[C:\KV2004\lang\Kvxp0804.lng] [N/A, N/A]
[C:\KV2004\KVComm.dll] [JiangMin Ltd., 8.0.0.312]
[C:\KV2004\APIImpl.dll] [JiangMin Ltd., 8.0.0.309]
[C:\WINDOWS\downlo~1\CnsHook.dll] [北京三七二一科技有限公司, 1, 0, 3, 7]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [Yahoo! China, 3, 0, 2, 1020]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll] [Yahoo! China, 3, 1, 2, 1018]
[C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll] [yahoo! china, 3, 4, 1, 1092]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] [Yahoo! China, 3, 0, 1, 1010]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll] [Yahoo! China, 3, 0, 4, 1006]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL] [yahoo! china, 3, 0, 1, 1001]
[C:\PROGRA~1\MMSASS~1\mmsass~1.dll] [, 1, 2, 0, 6]
[C:\WINDOWS\SYSTEM32\stdup.dll] [MStdup Co Ltd., 3, 2, 2, 3]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yassist.dll] [Yahoo! China, 3, 1, 0, 1015]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ywiper.dll] [Yahoo! China, 3, 0, 1, 1001]
[PID: 1260][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll] [Windows (R) 2000 DDK provider, 5.00.2195.1620]
[C:\KV2004\KVMonXP.kxp] [JiangMin Ltd., 8.0.0.309]
[C:\KV2004\UpdateX.dll] [JiangMin Ltd., 8.0.0.309]
[C:\KV2004\lang\Kvxp0804.lng] [N/A, N/A]
[C:\KV2004\GUIExt.dll] [JiangMin Ltd., 8.0.0.309]
[C:\KV2004\lang\GUIExt0804.lng] [JiangMin Ltd., 7, 1, 0, 200]
[C:\KV2004\KVEnhP.dll] [JiangMin Ltd., 8.0.0.309]
[C:\KV2004\KvSpiPS.dll] [JiangMin Ltd., 8.0.0.309]
[C:\WINDOWS\downlo~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[PID: 1356][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3512]
[C:\WINDOWS\downlo~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[PID: 1364][C:\WINDOWS\System32\Rundll32.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\downlo~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\WINDOWS\downlo~1\CnsMinIO.dll] [北京三七二一科技有限公司, 1, 0, 3, 7]
[C:\WINDOWS\downlo~1\cnsio.dll] [北京三七二一科技有限公司, 1, 0, 2, 8]
[C:\WINDOWS\downlo~1\CnsMinEx.dll] [国风因特软件(北京)有限公司, 1, 0, 3, 4]
[PID: 1372][C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe] [Yahoo! China, 3, 0, 2, 1003]
[C:\PROGRA~1\Yahoo!\Assistant\shell\yAsMenu.dll] [Yahoo! China, 3, 0, 0, 1001]
[C:\PROGRA~1\Yahoo!\Assistant\shell\yAssecblk.dll] [Yahoo! China, 3, 0, 4, 1006]
[C:\PROGRA~1\Yahoo!\Assistant\shell\yIEAngel.dll] [Yahoo! China, 3, 0, 1, 1001]
[C:\PROGRA~1\Yahoo!\Assistant\shell\yMenuInfo.dll] [Yahoo! China, 3, 0, 0, 1000]
[C:\WINDOWS\downlo~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [Yahoo! China, 3, 0, 2, 1020]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll] [Yahoo! China, 3, 1, 2, 1018]
[PID: 1380][C:\WINDOWS\System32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\downlo~1\CnsMin.dll] [北京三七二一科技有限公司, 1, 5, 3, 9]
[PID: 1580][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1592][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1612][C:\WINDOWS\SYSTEM32\RUNDLL.EXE] [Microsoft Corporation, 5.00.2134.1]
[PID: 1696][C:\WINDOWS\System32\rundll32.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\PROGRA~1\MMSASS~1\MMSSVER.DLL] [, 1, 2, 0, 6]
[PID: 1716][C:\KV2004\KVSrvXP.exe] [JiangMin Ltd., 8.0.0.311]
[C:\KV2004\UpdateX.dll] [JiangMin Ltd., 8.0.0.309]
[C:\KV2004\KVEnhD.dll] [JiangMin Ltd., 8.0.0.311]
[C:\KV2004\KvSPI.dll] [JiangMin Ltd., 8.0.0.312]
[C:\KV2004\KVEnhP.dll] [JiangMin Ltd., 8.0.0.309]
[C:\KV2004\KVEnhM.dll] [JiangMin Ltd., 8.0.0.311]
[C:\KV2004\KVEnhC.DLL] [JiangMin Ltd., 8.0.0.311]
[C:\KV2004\KVEnhO.dll] [JiangMin Ltd., 8.0.0.314]
[C:\KV2004\KVEnhS.dll] [JiangMin Ltd., 8.0.0.313]
[C:\KV2004\KVEnhJ.dll] [JiangMin Ltd., 8.0.0.311]
[C:\KV2004\KVExtCab.dll] [Jiangmin New Tech. Co. Ltd., 8.0.0.309]
[C:\KV2004\KVExtEml.dll] [JiangMin Ltd., 8.0.0.312]
[C:\KV2004\KVExtLZH.dll] [N/A, N/A]
[C:\KV2004\KvExtRar.dll] [Jiangmin New Tech. Co. Ltd., 8.0.0.309]
[C:\KV2004\KvExtZip.dll] [JiangMin Ltd., 8.0.0.309]
[C:\KV2004\KVEnhK.dll] [JiangMin Ltd., 7, 1, 0, 307]
[C:\KV2004\KvSpiPS.dll] [JiangMin Ltd., 8.0.0.309]
[PID: 1756][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1776][C:\WINDOWS\System32\nvsvc32.exe] [NVIDIA Corporation, 5.13.01.2183]
[PID: 1916][C:\WINDOWS\System32\rundll32.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\STDSVER.DLL] [MStdup Co Ltd., 3, 2, 2, 3]
[PID: 2004][C:\WINDOWS\wincup\wincup.exe] [MsWinCup, 1, 0, 0, 0]
[PID: 640][c:\windows\system32\wbem\winlogon.exe] [Microsoft, 1.0.0.0]
[PID: 1188][C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe] [Yahoo! China, 3, 1, 2, 1018]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll] [Yahoo! China, 3, 1, 2, 1018]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [Yahoo! China, 3, 0, 2, 1020]