正在运行的进程(中毒后)
[PID: 440][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 492][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 516][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\kusn433sd3.dll] [Microsoft Corporation, ][PID: 1460][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] [N/A, ]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewTemp.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\System64.Sys] [N/A, ] [C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\nvcpl.dll] [NVIDIA Corporation, 6.14.10.9381]
[C:\WINDOWS\system32\NVRSZHC.DLL] [NVIDIA Corporation, 6.14.10.9381]
[C:\WINDOWS\system32\nvapi.dll] [N/A, ]
[C:\WINDOWS\system32\nvshell.dll] [, ]
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] [N/A, ]
[C:\Program Files\Internet Explorer\IEXPLORE.win] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\Ravs0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\LgSy0r.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\Msxo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\qjzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\Gjzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\LgSy0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\fyzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\txzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\zxzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\tlzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\LgSy1.dll] [N/A, ]
[C:\WINDOWS\system32\kusn433sd3.dll] [Microsoft Corporation, ] [E:\迅雷\Components\ResWorker\DSIeHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
[E:\迅雷\Components\ResWorker\DataProcessor.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Founder\Emergency Center\SBHotkey.dll] [N/A, ]
[E:\迅雷\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 2, 17]
[C:\KAV2006\KAVEXT.DLL] [Kingsoft Corporation, 2007, 5, 11, 28]
[PID: 1556][C:\KAV2006\KAVStart.exe] [Kingsoft Corporation, 2007, 5, 9, 272]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71CHS.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2006\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\KAV2006\SvcTimer.DLL] [Kingsoft Corporation, 2006.12.22.84]
[C:\Program Files\Internet Explorer\PLUGINS\System64.Sys] [N/A, ] [C:\KAV2006\KAVPassp.dll] [Kingsoft Corporation, 2006, 9, 7, 270]
[C:\KAV2006\PopSprt3.dll] [Kingsoft Corporation, 2007, 1, 16, 45]
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] [N/A, ] [C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\LgSy1.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\tlzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\zxzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\txzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\fyzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\LgSy0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\Gjzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\qjzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\Msxo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\LgSy0r.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\Ravs0.dll] [N/A, ][PID: 1588][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\System64.Sys] [N/A, ] [C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] [N/A, ][PID: 1596][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]
[C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]
[C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_zh-CN.dll] [Google Inc., 2, 0, 301, 7164]
[C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
[C:\Program Files\Internet Explorer\PLUGINS\System64.Sys] [N/A, ]
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] [N/A, ]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] [N/A, ][PID: 1820][C:\KAV2006\KMailMon.EXE] [Kingsoft Corporation, 2007, 2, 25, 948]
[C:\KAV2006\KAntiSpm.dll] [Kingsoft Corporation, 2007, 2, 25, 129]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2006\KAVIPC2.DLL] [Kingsoft Corporation, 2004, 12, 28, 20]
[C:\Program Files\Internet Explorer\PLUGINS\System64.Sys] [N/A, ] [C:\KAV2006\KAECall2.DLL] [Kingsoft Corporation, 2004, 12, 28, 7]
[C:\KAV2006\KAEPlat.DLL] [Kingsoft Corp., 2006, 8, 29, 60]
[C:\KAV2006\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\KAV2006\KAEUnpack.DAT] [Kingsoft Corp., 2007, 5, 9, 120]
[C:\KAV2006\KAConfig.DLL] [Kingsoft Corporation, 2007, 1, 11, 41]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] [N/A, ]
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] [N/A, ][PID: 2732][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Internet Explorer\PLUGINS\System64.Sys] [N/A, ][PID: 2024][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3736][C:\WINDOWS\system32\l.exe] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\System64.Sys] [N/A, ][PID: 3780][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Internet Explorer\PLUGINS\System64.Sys] [N/A, ]
[PID: 3796][C:\program files\internet explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Internet Explorer\PLUGINS\System64.Sys] [N/A, ][PID: 2328][C:\WINDOWS\system32\dgd4bs.exe] [N/A, ]
[C:\WINDOWS\system32\MSVBVM60.DLL] [Microsoft Corporation, 6.00.9690]
[C:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\Program Files\Internet Explorer\PLUGINS\System64.Sys] [N/A, ]
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] [N/A, ]
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] [N/A, ][PID: 936][C:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1601, 4978]
[E:\迅雷\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.0.4]
[E:\迅雷\Components\ResWorker\DSIeHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
[E:\迅雷\Components\ResWorker\DataProcessor.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
[E:\迅雷\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 2, 17]
[C:\KAV2006\KAVAFish.DLL] [Kingsoft Corporation, 2006, 10, 25, 27]
[C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
[C:\Program Files\Internet Explorer\PLUGINS\System64.Sys] [N/A, ] [C:\KAV2006\KAScript.DLL] [Kingsoft Corporation, 2006, 12, 11, 72]
[C:\KAV2006\KAEPlat.DLL] [Kingsoft Corp., 2006, 8, 29, 60]
[C:\KAV2006\KAEMem.DAT] [Kingsoft, 2006, 9, 25, 16]
[C:\KAV2006\KAEUnpack.DAT] [Kingsoft Corp., 2007, 5, 9, 120]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\xpsp3res.dll] [Microsoft Corporation, 5.1.2600.2838 (xpsp_sp2_gdr.060131-1513)]
[PID: 344][I:\abc\abc.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\KAV2006\KMailOEBand.dll] [Kingsoft Corporation, 2006, 12, 1, 139]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\KAV2006\KASocket.dll] [Kingsoft Corporation, 2005, 2, 22, 233]
[C:\Program Files\Internet Explorer\PLUGINS\System64.Sys] [N/A, ]
[C:\Program Files\Internet Explorer\IEXPLORE.Dat] [N/A, ]
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\LgSy1.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\tlzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\zxzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\txzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\fyzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\LgSy0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\Gjzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\qjzo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\Msxo0.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\LgSy0r.dll] [N/A, ]
[C:\DOCUME~1\user\LOCALS~1\Temp\Ravs0.dll] [N/A, ]