瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】TrojanDownloader.Agent.hwa病毒怎么杀啊?在线等答案

1   1  /  1  页   跳转

【求助】TrojanDownloader.Agent.hwa病毒怎么杀啊?在线等答案

【求助】TrojanDownloader.Agent.hwa病毒怎么杀啊?在线等答案

电脑感染了TrojanDownloader.Agent.hwa病毒,用江民能查出来,就是删不掉,是C:\WINDOWS\system32\yhlhe.dll这个有问题,但是他不让删除,而且在安全模式下也查不出来。表现为开机的时候桌面上的图标全都不显示,而且说上面的那个dll文件无法分配内存。这个病毒该怎么杀啊?百度上搜不到,只知道是木马,但用木马剑客杀不掉。高手啊,救救我吧,我已经要疯了!!!!

[CODE]

2007-03-21,10:54:42

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
N/A

==================================
启动文件夹
[Adobe Reader Speed Launch]
  <C:\Documents and Settings\All Users.WINDOWS\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk --> D:\PROGRA~1\Reader\READER~1.EXE [Adobe Systems Incorporated]><N>
[STAV]
  <C:\Documents and Settings\Administrator.8D67D5A55CDD4D1\「开始」菜单\程序\启动\STAV.lnk --> D:\PROGRA~1\木马剑客\STAV.exe [N/A]><N>

==================================
服务
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
  <C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ClipManage / BARCASE][Running/Auto Start]
  <C:\WINDOWS\SYSTEM32\RUNDLL2000.EXE C:\WINDOWS\SYSTEM32\WBEM\FQKZR.DLL,Export 1087><Microsoft Corporation>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[KVSrvXP / KVSrvXP][Running/Auto Start]
  <D:\program files\KV2006\KVSrvXP.exe /Service><Jiangmin Co. Ltd>
[KVWSC / KVWSC][Running/Auto Start]
  <"D:\program files\KV2006\kvwsc.exe"><Jiangmin Co.Ltd>
[MSSQLSERVER / MSSQLSERVER][Running/Auto Start]
  <d:\PROGRA~1\MSSQL\binn\sqlservr.exe><Microsoft Corporation>
[MSSQLServerADHelper / MSSQLServerADHelper][Stopped/Manual Start]
  <C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe><Microsoft Corporation>
[NICCONFIGSVC / NICCONFIGSVC][Running/Auto Start]
  <C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe><Dell Inc.>
[SQLSERVERAGENT / SQLSERVERAGENT][Stopped/Manual Start]
  <d:\PROGRA~1\MSSQL\binn\sqlagent.exe><Microsoft Corporation>
[Indexing Manager / Templates][Running/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\ngowa.dll><Microsoft Corporation>
[Dell Wireless WLAN Tray Service / wltrysvc][Running/Auto Start]
  <C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe><N/A>
[Windows Media Connect Service / WMConnectCDS][Stopped/Manual Start]
  <C:\Program Files\Windows Media Connect 2\wmccds.exe><Microsoft Corporation>
[Windows Driver Foundation - User-mode Driver Framework / WudfSvc][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup-->%SystemRoot%\System32\WUDFSvc.dll><Microsoft Corporation>

==================================
驱动程序
[AMD Processor Driver / AmdK8][Running/System Start]
  <system32\DRIVERS\AmdK8.sys><Advanced Micro Devices>
[APPDRV / APPDRV][Running/System Start]
  <\SystemRoot\SYSTEM32\DRIVERS\APPDRV.SYS><Dell Inc>
[ati2mtag / ati2mtag][Running/Manual Start]
  <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[atiide / atiide][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\atiide.sys><ATI Technologies Inc.>
[DELL 无线网卡驱动程序 / BCM43XX][Running/Manual Start]
  <system32\DRIVERS\bcmwl5.sys><Broadcom Corporation>
[Broadcom 440x 10/100 Integrated Controller XP Driver / bcm4sbxp][Running/Manual Start]
  <system32\DRIVERS\bcm4sbxp.sys><Broadcom Corporation>
[CnsMinKP / CnsMinKP][Running/Boot Start]
  <\SystemRoot\system32\drivers\CnsMinKP.sys><Copyright (C) 3721 Corporation.>
[d347bus / d347bus][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\d347bus.sys><>
[d347prt / d347prt][Running/Boot Start]
  <\SystemRoot\System32\Drivers\d347prt.sys><>
[gwiopm / gwiopm][Stopped/Manual Start]
  <\??\D:\工具\优化大师\wom\gwiopm.sys><N/A>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
  <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HSF_DPV / HSF_DPV][Running/Manual Start]
  <system32\DRIVERS\HSX_DPV.sys><Conexant Systems, Inc.>
[HSXHWAZL / HSXHWAZL][Running/Manual Start]
  <system32\DRIVERS\HSXHWAZL.sys><Conexant Systems, Inc.>
[KRegEx / KRegEx][Running/System Start]
  <\??\D:\PROGRA~1\KV2006\KRegEx.sys><Jiangmin Co. Ltd.>
[KSysCall Service / KSysCall][Running/System Start]
  <\??\D:\PROGRA~1\KV2006\KSysCall.sys><Jiangmin Co. Ltd.>
[KVDP_1 / KVDP_1][Running/Manual Start]
  <\??\D:\program files\KV2006\KVDP_1.sys><Jiangmin Co., Ltd.>
[KvMemon / KvMemon][Running/Manual Start]
  <\??\D:\PROGRA~1\KV2006\KvMemon.sys><Jiangmin Co. Ltd.>
[KVREDIR / KVREDIR][Running/Manual Start]
  <\??\D:\program files\KV2006\KVREDIR.sys><Jiangmin Co. Ltd>
[mdmxsdk / mdmxsdk][Running/Auto Start]
  <system32\DRIVERS\mdmxsdk.sys><Conexant>
[mhkz / mhkzi][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\mhkzi.sys><N/A>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\D:\program files\qq\npkcrypt.sys><INCA Internet Co., Ltd.>
[pelcrfs / pelcrfs][Running/Boot Start]
  <\SystemRoot\\SystemRoot\System32\drivers\pelcrfs.sys><N/A>
[PProtect / PProtect][Running/System Start]
  <\??\D:\PROGRA~1\KV2006\PProtect.sys><Jiangmin Co. Ltd.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[R2A / R2A][Stopped/Disabled]
  <\??\C:\WINDOWS\system32a2.sys><N/A>
[rimmptsk / rimmptsk][Running/Manual Start]
  <system32\DRIVERS\rimmptsk.sys><REDC>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[SigmaTel High Definition Audio CODEC / STHDA][Running/Manual Start]
  <system32\drivers\sthda.sys><SigmaTel, Inc.>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
  <system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[Conexant Setup API / UIUSys][Stopped/Manual Start]
  <system32\DRIVERS\UIUSYS.SYS><N/A>
[winachsf / winachsf][Running/Manual Start]
  <system32\DRIVERS\HSX_CNXT.sys><Conexant Systems, Inc.>
[Windows Driver Foundation - User-mode Driver Framework Platform Driver / WudfPf][Stopped/Manual Start]
  <system32\DRIVERS\WudfPf.sys><Microsoft Corporation>
[Windows Driver Foundation - User-mode Driver Framework Reflector / WudfRd][Stopped/Manual Start]
  <system32\DRIVERS\wudfrd.sys><Microsoft Corporation>
[PCANDIS5 NDIS Protocol Driver / PCANDIS5][Running/Manual Start]
  <\??\C:\WINDOWS\system32\PCANDIS5.SYS><Printing Communications Assoc., Inc. (PCAUSA)>
最后编辑2007-03-21 11:57:08
分享到:
gototop
 

==================================
浏览器加载项
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\program files\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[雅虎助手]
  {406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[FiltrateWebObj Class]
  {42AFACEE-2A77-41EB-9EE2-D9F8AF827F90} <D:\program files\KV2006\KVBHO.dll, Jiangmin Co.Ltd>
[BrowseHelper Class]
  {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} <D:\program files\KV2006\KvShell.dll, Jiangmin Co.Ltd>
[启动迅雷5]
  {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <D:\program files\Thunder.exe, Thunder Networking Technologies,LTD>
[Yahoo 3.5G电邮]
  {507F9113-CD77-4866-BA92-0E86DA3D0B97} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A>
[名品折扣]
  {59BC54A2-56B3-44a0-93E5-432D58746E26} <http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/mall/pro.php?allyesPara=816, N/A>
[雅虎助手]
  {5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A>
[番茄花园]
  {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <http://www.tomatolei.com, N/A>
[雅虎WIDGET]
  {6354ABE6-05F1-49ed-B850-E423120EC338} <http://cn.widget.yahoo.com/index.htm?source=Cns, N/A>
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <D:\PROGRA~1\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[情景聊天]
  {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg, N/A>
[]
  {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A>
[]
  {FD00D911-7529-4084-9946-A29F1BDF4FE5} <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A>
[雅虎助手]
  {406F94F0-504F-4a40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[江民杀毒工具栏]
  {B5A34A93-D538-43A7-8371-864CB6148D12} <D:\program files\KV2006\KvShell.dll, Jiangmin Co.Ltd>
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\program files\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[雅虎助手]
  {406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!>
[FiltrateWebObj Class]
  {42AFACEE-2A77-41EB-9EE2-D9F8AF827F90} <D:\program files\KV2006\KVBHO.dll, Jiangmin Co.Ltd>
[AutoLive]
  {7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2} <C:\PROGRA~1\3721\autolive.dll, >
[BrowseHelper Class]
  {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} <D:\program files\KV2006\KvShell.dll, Jiangmin Co.Ltd>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[江民杀毒工具栏]
  {B5A34A93-D538-43A7-8371-864CB6148D12} <D:\program files\KV2006\KvShell.dll, Jiangmin Co.Ltd>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[&使用迅雷下载]
  <D:\program files\Program\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <D:\program files\Program\getallurl.htm, N/A>
[上传到QQ网络硬盘]
  <D:\program files\qq\AddToNetDisk.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://D:\PROGRA~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <D:\program files\qq\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\program files\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\program files\qq\SendMMS.htm, N/A>
[雅虎搜索]
  <res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246, N/A>
gototop
 

正在运行的进程
[PID: 768][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 832][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 860][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4140]
    [C:\WINDOWS\System32\BCMLogon.dll]  [Broadcom Corporation, 4.10.47.3]
    [C:\WINDOWS\System32\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\System32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\System32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 904][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 916][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\ESPI11.dll]  [DYWT, 1, 1, 0, 0]
[PID: 1064][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4140]
    [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2503]
[PID: 1084][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1204][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\ESPI11.dll]  [DYWT, 1, 1, 0, 0]
[PID: 1360][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\ESPI11.dll]  [DYWT, 1, 1, 0, 0]
    [c:\windows\system32\ngowa.dll]  [Microsoft Corporation, 5.1.2600.0]
    [C:\WINDOWS\system32\wups2.dll]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[PID: 452][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [北京三七二一科技有限公司, 2.5.0.3]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [C:\WINDOWS\system32\WPDShServiceObj.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
    [C:\WINDOWS\system32\PortableDeviceTypes.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\program files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [D:\program files\KV2006\KvShell.dll]  [Jiangmin Co.Ltd, 9, 0, 5, 830]
    [D:\program files\KV2006\UpdateX.dll]  [JiangMin Co.Ltd., 9, 0, 5, 831]
    [D:\program files\KV2006\lang\Kvxp0804.lng]  [N/A, ]
    [D:\program files\KV2006\APIImpl.dll]  [JiangMin Ltd., 9.0.0.500]
    [D:\program files\KV2006\GUIExt.dll]  [Jiangmin Co.Ltd, 9, 0, 5, 927]
    [D:\program files\KV2006\lang\GUIExt0804.lng]  [JiangMin Ltd., 7, 1, 0, 200]
    [D:\program files\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.7.2006011200]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll]  [Yahoo!, 2, 1, 0, 1038]
    [D:\program files\KV2006\KVBHO.dll]  [Jiangmin Co.Ltd, 9.0.6.0113]
    [D:\program files\KV2006\KVAddrDb.dll]  [Jiangmin Co.Ltd, 9, 0, 0, 1018]
    [D:\program files\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
    [D:\program files\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
    [D:\program files\rarext.dll]  [N/A, ]
    [c:\windows\system32\ngowa.dll]  [Microsoft Corporation, 5.1.2600.0]
gototop
 

[PID: 2216][C:\WINDOWS\stsystra.exe]  [SigmaTel, Inc., 1.0.5143.0  nd491 cp1]
    [C:\WINDOWS\system32\STLang.dll]  [SigmaTel, Inc., 1.0.5140.0  nd483 cp1]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [C:\WINDOWS\system32\stacapi.dll]  [SigmaTel, Inc., 1.0.5143.0  nd491 cp1]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\program files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
[PID: 2284][C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE]  [ATI Technologies Inc., 1.11.0.0]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_ef9cbfe7\mscorlib.dll]  [N/A, ]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_fa30068e\system.windows.forms.dll]  [N/A, ]
    [c:\program files\ati technologies\ati.ace\cli.implementation.dll]  [ATI Technologies Inc., 1.2.2460.36578]
    [c:\program files\ati technologies\ati.ace\log.foundation.dll]  [ATI Technologies Inc., 1.2.2208.29985]
    [c:\program files\ati technologies\ati.ace\cli.foundation.dll]  [ATI Technologies Inc., 1.2.2208.29986]
    [c:\program files\ati technologies\ati.ace\log.foundation.service.dll]  [ATI Technologies Inc., 1.2.2460.36737]
    [c:\program files\ati technologies\ati.ace\log.foundation.shared.dll]  [ATI Technologies Inc., 1.2.2208.29991]
    [c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_ee18ad6b\system.dll]  [N/A, ]
    [c:\program files\ati technologies\ati.ace\cli.foundation.xmanifestation.dll]  [ATI Technologies Inc., 1.2.2460.36738]
    [c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_82d05af5\system.xml.dll]  [N/A, ]
    [c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\system32\ESPI11.dll]  [DYWT, 1, 1, 0, 0]
    [c:\program files\ati technologies\ati.ace\cli.component.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36741]
    [c:\program files\ati technologies\ati.ace\aticccom.dll]  [ATI Technologies Inc., 1.0.0.0]
    [c:\program files\ati technologies\ati.ace\aem.foundation.dll]  [ATI Technologies Inc., 1.2.2208.29985]
    [c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_c76111a8\system.drawing.dll]  [N/A, ]
    [c:\program files\ati technologies\ati.ace\cli.caste.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29987]
    [c:\program files\ati technologies\ati.ace\cli.caste.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36732]
    [c:\program files\ati technologies\ati.ace\cli.component.runtime.shared.dll]  [ATI Technologies Inc., 1.2.2208.29988]
    [c:\program files\ati technologies\ati.ace\dem.foundation.dll]  [ATI Technologies Inc., 1.11.0.0]
    [c:\program files\ati technologies\ati.ace\dem.graphics.i0601.dll]  [ATI Technologies Inc., 2.0.2344.17361]
    [c:\program files\ati technologies\ati.ace\ace.graphics.displaysmanager.shared.dll]  [ATI Technologies Inc., 1.11.0.0]
    [c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\system32\atidemgr.dll]  [ATI Technologies Inc., 1.2.2456.36741]
    [c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\WMINet_Utils.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\program files\ati technologies\ati.ace\cli.aspect.multivpu3.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36616]
    [c:\program files\ati technologies\ati.ace\cli.aspect.multivpu3.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2302.19274]
    [c:\program files\ati technologies\ati.ace\cli.aspect.multivpu2.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36575]
    [c:\program files\ati technologies\ati.ace\cli.aspect.multivpu2.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29991]
    [c:\program files\ati technologies\ati.ace\cli.aspect.multivpu.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36640]
    [c:\program files\ati technologies\ati.ace\cli.aspect.multivpu.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.30001]
    [c:\program files\ati technologies\ati.ace\cli.aspect.verylargedesktop.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36615]
    [c:\program files\ati technologies\ati.ace\cli.aspect.verylargedesktop.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29993]
    [c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36658]
    [c:\program files\ati technologies\ati.ace\cli.aspect.radeon3dlegacy.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36655]
    [c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour2.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36622]
    [c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour2.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.30007]
    [c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36689]
    [c:\program files\ati technologies\ati.ace\cli.aspect.displayscolour.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29990]
    [c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36673]
    [c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.30001]
    [c:\program files\ati technologies\ati.ace\cli.aspect.videooverlay.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36648]
    [c:\program files\ati technologies\ati.ace\cli.aspect.videooverlay.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29989]
    [c:\program files\ati technologies\ati.ace\ace.graphics.videooverlay.shared.dll]  [ATI Technologies Inc., 1.11.0.0]
    [c:\program files\ati technologies\ati.ace\cli.aspect.smartgart.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36652]
    [c:\program files\ati technologies\ati.ace\cli.aspect.vpurecover.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36645]
    [c:\program files\ati technologies\ati.ace\cli.aspect.vpurecover.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29988]
    [c:\program files\ati technologies\ati.ace\cli.aspect.workstationconfig.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36643]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36709]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2236.29147]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt2.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36628]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicecrt2.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2236.29162]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36700]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29994]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36622]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29993]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36706]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2341.28028]
    [c:\program files\ati technologies\ati.ace\cli.aspect.customformats.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2341.28007]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36631]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2341.28018]
gototop
 

technologies\ati.ace\cli.aspect.devicetv.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36692]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36702]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2341.28013]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp2.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36625]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicedfp2.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2341.28023]
    [c:\program files\ati technologies\ati.ace\cli.aspect.overdrive3.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36665]
    [c:\program files\ati technologies\ati.ace\cli.aspect.overdrive3.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2279.31385]
    [c:\program files\ati technologies\ati.ace\cli.aspect.overdrive2.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36670]
    [c:\program files\ati technologies\ati.ace\cli.aspect.powerplay3.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36662]
    [c:\program files\ati technologies\ati.ace\cli.aspect.powerplay3.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29989]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\perfcounter.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\program files\ati technologies\ati.ace\cli.aspect.displaysoptions.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36683]
    [c:\program files\ati technologies\ati.ace\cli.aspect.integratedumaframebuffer.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36677]
    [c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36680]
    [c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29990]
    [c:\program files\ati technologies\ati.ace\cli.aspect.hotkeyshandling.graphics.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36634]
    [c:\program files\ati technologies\ati.ace\cli.aspect.hotkeyshandling.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.30002]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2232.28756]
    [c:\program files\ati technologies\ati.ace\cli.aspect.radeon3dlegacy.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2232.28758]
    [c:\program files\ati technologies\ati.ace\dem.graphics.i0600.dll]  [ATI Technologies Inc., 1.11.0.0]
    [c:\program files\ati technologies\ati.ace\cli.aspect.smartgart.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29990]
    [c:\program files\ati technologies\ati.ace\cli.aspect.workstationconfig.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2390.25922]
    [c:\program files\ati technologies\ati.ace\cli.aspect.deviceproperty.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29987]
    [c:\program files\ati technologies\ati.ace\dem.graphics.i0602.dll]  [ATI Technologies Inc., 1.11.0.0]
    [c:\program files\ati technologies\ati.ace\cli.aspect.deviceproperty2.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29986]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicetv2.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2307.27448]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2307.27453]
    [c:\program files\ati technologies\ati.ace\cli.aspect.overdrive2.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2412.27525]
    [C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll]  [Microsoft Corporation, 11.0.6568]
    [c:\program files\ati technologies\ati.ace\cli.aspect.displaysoptions.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29993]
    [c:\program files\ati technologies\ati.ace\cli.aspect.integratedumaframebuffer.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29988]
    [D:\program files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [c:\program files\ati technologies\ati.ace\apm.foundation.dll]  [ATI Technologies Inc., 1.2.2208.30002]
    [C:\WINDOWS\DOWNLO~1\CnsHook.dll]  [北京三七二一科技有限公司, 2.5.0.3]
    [D:\program files\KV2006\KVMonXP.kxp]  [Jiangmin Co.Ltd, 9, 2, 0, 60905]
    [D:\program files\KV2006\UpdateX.dll]  [JiangMin Co.Ltd., 9, 0, 5, 831]
    [D:\program files\KV2006\lang\Kvxp0804.lng]  [N/A, ]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [D:\program files\KV2006\GUIExt.dll]  [Jiangmin Co.Ltd, 9, 0, 5, 927]
    [D:\program files\KV2006\lang\GUIExt0804.lng]  [JiangMin Ltd., 7, 1, 0, 200]
    [D:\program files\KV2006\EngFace.dll]  [Jiangmin Co.Ltd, 9.0.0.50809]
    [D:\program files\KV2006\EngPS.dll]  [Jiangmin Co.Ltd, 9, 2, 0, 50817]
    [D:\program files\KV2006\KvMemory.dll]  [Jiangmin Co. Ltd., 9, 0, 6, 0214]
    [D:\program files\KV2006\KvOffice.dll]  [JiangMin New Tech., 9.0.0.1213]
    [D:\program files\KV2006\lang\KVOffice0804.lng]  [N/A, ]
    [D:\program files\KV2006\VirusUpload.dll]  [, 2, 16, 6, 7260]
    [D:\program files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [D:\program files\KV2006\PProtect.dll]  [Jiangmin Co. Ltd., 9.0.0.921]
    [D:\program files\KV2006\ComUIPS.dll]  [Jiangmin Ltd., 9. 5. 5. 20]
[PID: 2492][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [D:\program files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
[PID: 2580][C:\WINDOWS\system32\wuauclt.exe]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [C:\WINDOWS\system32\wups2.dll]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
    [D:\program files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
[PID: 2608][D:\program files\木马剑客\STAV.exe]  [N/A, ]
    [D:\program files\木马剑客\krnln.fnr]  [, 1, 0, 0, 1]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [D:\program files\木马剑客\edroptarget.fne]  [, 1, 0, 0, 1]
    [D:\program files\木马剑客\iext2.fne]  [, 1, 0, 0, 1]
    [D:\program files\木马剑客\iext.fnr]  [, 1, 0, 0, 1]
    [D:\program files\木马剑客\shell.fne]  [N/A, ]
    [D:\program files\木马剑客\xplib.fne]  [N/A, ]
    [D:\program files\木马剑客\SetPriH.dll]  [N/A, ]
    [D:\program files\木马剑客\eAPI.fne]  [, 1, 0, 0, 1]
    [D:\program files\木马剑客\KVEngin.dll]  [N/A, ]
    [D:\program files\木马剑客\dp1.fne]  [N/A, ]
    [D:\program files\木马剑客\EThread.fne]  [N/A, ]
    [D:\program files\木马剑客\firewall.dll]  [N/A, ]
    [D:\program files\木马剑客\eNetIntercept.fne]  [, 1, 1, 0, 5]
    [C:\WINDOWS\system32\ESPI11.dll]  [DYWT, 1, 1, 0, 0]
    [D:\program files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\program files\KV2006\TrojDie.kxp]  [Jiangmin Co.Ltd, 9.0.6.0413]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
gototop
 

[D:\program files\KV2006\UpdateX.dll]  [JiangMin Co.Ltd., 9, 0, 5, 831]
    [D:\program files\KV2006\lang\TrojDie0804.lng]  [Jiangmin Co.Ltd, 9.0.0.0813]
    [D:\program files\KV2006\GUIExt.dll]  [Jiangmin Co.Ltd, 9, 0, 5, 927]
    [D:\program files\KV2006\lang\GUIExt0804.lng]  [JiangMin Ltd., 7, 1, 0, 200]
    [D:\program files\KV2006\PProtect.dll]  [Jiangmin Co. Ltd., 9.0.0.921]
    [D:\program files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [D:\program files\KV2006\ComUIPS.dll]  [Jiangmin Ltd., 9. 5. 5. 20]
[PID: 3240][D:\program files\KV2006\KRegEx.exe]  [Jiangmin Co.Ltd, 9.0.6.210]
    [D:\program files\KV2006\KRegEx.dll]  [Jiangmin Co. Ltd., 9.0.6.0119]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [D:\program files\KV2006\KRegTrust.dll]  [Jiangmin Co. Ltd., 9.0.0.825]
    [D:\program files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
[PID: 4040][D:\program files\KV2006\UIHost.exe]  [Jiangmin Co. Ltd, 9.2.0.50822]
    [D:\program files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [D:\program files\KV2006\UpdateX.dll]  [JiangMin Co.Ltd., 9, 0, 5, 831]
    [D:\program files\KV2006\ComUI.dll]  [Jiangmin Ltd., 9. 0. 0.509]
    [D:\program files\KV2006\ComUIPS.dll]  [Jiangmin Ltd., 9. 5. 5. 20]
    [D:\program files\KV2006\GUIExt.dll]  [Jiangmin Co.Ltd, 9, 0, 5, 927]
    [D:\program files\KV2006\lang\GUIExt0804.lng]  [JiangMin Ltd., 7, 1, 0, 200]
[PID: 3108][C:\Program Files\ATI Technologies\ATI.ACE\cli.exe]  [ATI Technologies Inc., 1.11.0.0]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_ef9cbfe7\mscorlib.dll]  [N/A, ]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll]  [Microsoft Corporation, 1.1.4322.573]
    [D:\program files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_fa30068e\system.windows.forms.dll]  [N/A, ]
    [c:\program files\ati technologies\ati.ace\cli.implementation.dll]  [ATI Technologies Inc., 1.2.2460.36578]
    [c:\program files\ati technologies\ati.ace\log.foundation.dll]  [ATI Technologies Inc., 1.2.2208.29985]
    [c:\program files\ati technologies\ati.ace\cli.foundation.dll]  [ATI Technologies Inc., 1.2.2208.29986]
    [c:\program files\ati technologies\ati.ace\log.foundation.service.dll]  [ATI Technologies Inc., 1.2.2460.36737]
    [c:\program files\ati technologies\ati.ace\log.foundation.shared.dll]  [ATI Technologies Inc., 1.2.2208.29991]
    [c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_ee18ad6b\system.dll]  [N/A, ]
    [c:\program files\ati technologies\ati.ace\cli.foundation.xmanifestation.dll]  [ATI Technologies Inc., 1.2.2460.36738]
    [c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_82d05af5\system.xml.dll]  [N/A, ]
    [c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\system32\ESPI11.dll]  [DYWT, 1, 1, 0, 0]
    [c:\program files\ati technologies\ati.ace\cli.component.wizard.dll]  [ATI Technologies Inc., 1.2.2460.36607]
    [c:\program files\ati technologies\ati.ace\cli.foundation.clients.dll]  [ATI Technologies Inc., 1.2.2208.29986]
    [c:\program files\ati technologies\ati.ace\cli.component.wizard.shared.dll]  [ATI Technologies Inc., 1.2.2208.29987]
    [c:\program files\ati technologies\ati.ace\cli.component.runtime.dll]  [ATI Technologies Inc., 1.2.2460.36741]
    [c:\program files\ati technologies\ati.ace\aticccom.dll]  [ATI Technologies Inc., 1.0.0.0]
    [c:\program files\ati technologies\ati.ace\cli.caste.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29987]
    [c:\program files\ati technologies\ati.ace\aem.foundation.dll]  [ATI Technologies Inc., 1.2.2208.29985]
    [c:\program files\ati technologies\ati.ace\ace.graphics.displaysmanager.shared.dll]  [ATI Technologies Inc., 1.11.0.0]
    [c:\program files\ati technologies\ati.ace\cli.caste.graphics.wizard.dll]  [ATI Technologies Inc., 1.2.2460.36610]
    [c:\program files\ati technologies\ati.ace\cli.caste.graphics.wizard.shared.dll]  [ATI Technologies Inc., 1.2.2208.29990]
    [c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_c76111a8\system.drawing.dll]  [N/A, ]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.wizard.dll]  [ATI Technologies Inc., 1.2.2460.36597]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.wizard.dll]  [ATI Technologies Inc., 1.2.2460.36600]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.wizard.dll]  [ATI Technologies Inc., 1.2.2460.36592]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.wizard.dll]  [ATI Technologies Inc., 1.2.2460.36616]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.wizard.dll]  [ATI Technologies Inc., 1.2.2460.36587]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicetv2.graphics.wizard.dll]  [ATI Technologies Inc., 1.2.2460.36589]
    [c:\program files\ati technologies\ati.ace\cli.aspect.displaysmanager.graphics.wizard.dll]  [ATI Technologies Inc., 1.2.2460.36604]
    [c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.wizard.dll]  [ , 1.2.2460.36579]
    [c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.wizard.dll]  [ATI Technologies Inc., 1.2.2460.36581]
    [c:\program files\ati technologies\ati.ace\cli.aspect.transcode.local.wizard.dll]  [ATI Technologies Inc., 1.2.2460.36574]
    [c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.wizard.dll]  [ATI Technologies Inc., 1.2.2460.36584]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicecv.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2341.28028]
    [c:\program files\ati technologies\ati.ace\cli.aspect.deviceproperty.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29987]
    [c:\program files\ati technologies\ati.ace\cli.aspect.customformats.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2341.28007]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicecv2.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2341.28018]
    [c:\program files\ati technologies\ati.ace\cli.aspect.deviceproperty2.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29986]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29994]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicelcd2.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29993]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicetv.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2307.27453]
    [c:\program files\ati technologies\ati.ace\cli.aspect.devicetv2.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2307.27448]
    [c:\program files\ati technologies\ati.ace\cli.aspect.radeon3d.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2232.28756]
    [c:\program files\ati technologies\ati.ace\cli.aspect.mmvideo.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.30001]
    [c:\program files\ati technologies\ati.ace\cli.aspect.transcode.local.shared.dll]  [ATI Technologies Inc., 1.2.0.0]
    [c:\program files\ati technologies\ati.ace\atixclib.dll]  [ , 1.0.0.0]
    [c:\program files\ati technologies\ati.ace\cli.aspect.infocentre.graphics.shared.dll]  [ATI Technologies Inc., 1.2.2208.29990]
    [c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\perfcounter.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll]  [Microsoft Corporation, 11.0.6568]
gototop
 

[PID: 1828][D:\program files\8021x.exe]  [锐捷网络, 2, 56, 0, 0]
    [C:\WINDOWS\system32\W32N50.dll]  [Printing Communications Assoc., Inc. (PCAUSA), 5.03.16.54]
    [D:\program files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
[PID: 3212][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\program files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
[PID: 2028][D:\program files\Maxthon\maxthon.exe]  [Maxthon International Ltd., 1, 5, 9, 80]
    [D:\program files\Maxthon\maxzlib.dll]  [ , 1, 0, 0, 2]
    [D:\program files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [D:\program files\ComDlls\XunLeiBHO_007.dll]  [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
    [C:\WINDOWS\system32\odbcbcp.dll]  [Microsoft Corporation, 2000.085.1117.00 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CorperfmonExt.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [d:\PROGRA~1\MSSQL\BINN\SQLCTR80.DLL]  [Microsoft Corporation, 2000.080.0194.00]
    [C:\PROGRA~1\COMMON~1\SYSTEM\MSMAPI\2052\MSMAPI32.DLL]  [Microsoft Corporation, 11.0.5601]
    [C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll]  [Microsoft Corporation, 11.0.6568]
    [C:\WINDOWS\system32\ESPI11.dll]  [DYWT, 1, 1, 0, 0]
    [D:\program files\Maxthon\Services\RealTime\real_time.dll]  [, 1, 0, 0, 1]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll]  [Yahoo!, 2, 1, 0, 1038]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\UNISPIM5.IME]  [北京紫光华宇软件股份有限公司, 5.0.0.5091]
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mdiui.dll]  [Microsoft Corporation, 11.3.1897.0]
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mdigraph.dll]  [Microsoft Corporation, 11.3.1897.0]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
[PID: 2740][D:\program files\WinRAR.exe]  [N/A, ]
    [D:\program files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [C:\WINDOWS\system32\wpdshext.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
    [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.5358.4827 (WMP_11.060509-2009)]
[PID: 3624][C:\DOCUME~1\ADMINI~1.8D6\LOCALS~1\Temp\Rar$EX05.391\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [D:\program files\KV2006\KVHookG.dll]  [Jiangmin Co.Ltd, 9.0.0.1226]
    [C:\WINDOWS\DOWNLO~1\CnsMin.dll]  [北京三七二一科技有限公司, 2, 5, 0, 6]
    [C:\WINDOWS\system32\ESPI11.dll]  [DYWT, 1, 1, 0, 0]
gototop
 

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
    C:\WINDOWS\system32\ESPI11.dll(DYWT, ESPI)
MSAFD Tcpip [UDP/IP]
    C:\WINDOWS\system32\ESPI11.dll(DYWT, ESPI)
MSAFD Tcpip [RAW/IP]
    C:\WINDOWS\system32\ESPI11.dll(DYWT, ESPI)
RSVP UDP Service Provider
    C:\WINDOWS\system32\ESPI11.dll(DYWT, ESPI)
RSVP TCP Service Provider
    C:\WINDOWS\system32\ESPI11.dll(DYWT, ESPI)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
入口点错误:CreateRemoteThread (危险等级: 高,  被下面模块所HOOK: D:\program files\KV2006\KVHookG.dll)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

[ClipManage / BARCASE][Running/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLL2000.EXE C:\WINDOWS\SYSTEM32\WBEM\FQKZR.DLL,Export 1087><Microsoft Corporation>
[Indexing Manager / Templates][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\ngowa.dll><Microsoft Corporation>
服务
------------------------------------------------------------
[pelcrfs / pelcrfs][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\pelcrfs.sys><N/A>
[R2A / R2A][Stopped/Disabled]
<\??\C:\WINDOWS\system32a2.sys><N/A>
驱动
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT