【回复“天月来了”的帖子】
<{22FAACDE-34DA-CCD4-AB4D-DA34485A3422}><C:\WINDOWS\Fonts\rsjzbpm.dll> []
<{F859245F-345D-BC13-AC4F-145D47DA34FF}><C:\WINDOWS\Fonts\avzxomn.dll> []
<{B960356A-458E-DE24-BD50-268F589A56AB}><C:\WINDOWS\Fonts\avwlkmn.dll> []
<{DC87A354-ABC3-DEDE-FF33-3213FD7447CD}><C:\WINDOWS\Fonts\kvdxmma.dll> []
<{E9FA4178-7749-A8D9-F5C8-88645525769E}><C:\WINDOWS\Fonts\kashnzy.dll> []
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[PID: 372 / Yue][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
[C:\WINDOWS\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\labsii.dll] [N/A, ]
[C:\WINDOWS\system32\Kvsc3.dll] [N/A, ]
[C:\WINDOWS\system32\qrtbby.dll] [N/A, ]
[PID: 2420 / Yue][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[C:\WINDOWS\system32\qrtbby.dll] [N/A, ]
[C:\WINDOWS\system32\labsii.dll] [N/A, ]
[PID: 2480 / Yue][c:\program files\common files\symantec shared\ccapp.exe] [Symantec Corporation, 103.5.1.9]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[c:\program files\common files\symantec shared\ccL35.dll] [Symantec Corporation, 103.5.1.9]
[C:\WINDOWS\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll] [Symantec Corporation, 103.5.1.9]
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCALERT.DLL] [Symantec Corporation, 103.5.1.9]
[C:\PROGRA~1\COMMON~1\SYMANT~1\CCEMLPXY.DLL] [Symantec Corporation, 103.5.1.9]
[C:\WINDOWS\system32\SYMREDIR.DLL] [Symantec Corporation, 5.5.1.6]
[C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll] [Symantec Corporation, 103.5.1.9]
[C:\Program Files\Common Files\Symantec Shared\ccProSub.dll] [Symantec Corporation, 103.5.1.9]
[C:\Program Files\Symantec AntiVirus\SavEmail.dll] [Symantec Corporation, 10.0.0.359]
[C:\WINDOWS\system32\qrtbby.dll] [N/A, ]
[C:\WINDOWS\system32\labsii.dll] [N/A, ]
[PID: 224 / Yue][C:\WINDOWS\system32\taskmgr.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\program files\kingsoft\kingsoft internet security 2008\KMailOEBand.DLL] [Kingsoft Corporation, 2007,11,29,128]
[c:\program files\kingsoft\kingsoft internet security 2008\kis.dll] [Kingsoft Corporation, 2007,11,29,128]
[C:\WINDOWS\system32\GOOGLEPINYIN.IME] [Google Inc., ]
[C:\WINDOWS\system32\qrtbby.dll] [N/A, ]
[C:\WINDOWS\system32\labsii.dll] [N/A, ]
[C:\WINDOWS\system32\Kvsc3.dll] [N/A, ]
每个PID后面都有那几个 dll 文件,肯定是病毒把。