瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 急救!! 帮忙解决 已中的3回了 有日志

1   1  /  1  页   跳转

急救!! 帮忙解决 已中的3回了 有日志

急救!! 帮忙解决 已中的3回了 有日志

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <internat><\WINDOWS\System32\internat.exe>  [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <BigDogPath><C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera>  [N/A]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup>  [NVIDIA Corporation]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [(Verified)"RealNetworks, Inc."]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <WIAWizardMenu><RUNDLL32.EXE C:\WINDOWS\System32\sti_ci.dll,WiaCreateWizardMenu>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows XP Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Cubiz]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rpcc]
    <WinlogonNotify: rpcc><C:\WINDOWS\System32\rpcc.dll>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
    <浏览器自定义组件><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
    <Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
    <Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe>  [Microsoft Corporation]

==================================
启动文件夹
N/A

==================================
服务
[COM+ System Application / COMSysApp][Stopped/Disabled]
  <C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}><Microsoft Corporation>
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Disabled]
  <C:\WINDOWS\System32\dmadmin.exe /com><Microsoft Corp., Veritas Software>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Distributed Transaction Coordinator / MSDTC][Stopped/Manual Start]
  <C:\WINDOWS\System32\msdtc.exe><Microsoft Corporation>
[Windows Installer / MSIServer][Stopped/Manual Start]
  <C:\WINDOWS\System32\msiexec.exe /V><Microsoft Corporation>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[Remote Procedure Call (RPC) Locator / RpcLocator][Stopped/Manual Start]
  <C:\WINDOWS\System32\locator.exe><Microsoft Corporation>
[Smart Card Helper / SCardDrv][Stopped/Disabled]
  <C:\WINDOWS\System32\SCardSvr.exe><Microsoft Corporation>
[Smart Card / SCardSvr][Stopped/Disabled]
  <C:\WINDOWS\System32\SCardSvr.exe><Microsoft Corporation>
[Windows User Mode Driver Framework / UMWdf][Stopped/Manual Start]
  <C:\WINDOWS\System32\wdfmgr.exe><Microsoft Corporation>
[WMI Performance Adapter / WmiApSrv][Stopped/Manual Start]
  <C:\WINDOWS\System32\wbem\wmiapsrv.exe><Microsoft Corporation>

==================================
驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[VIA Rhine-Family Fast Ethernet Adapter Driver Service / FETND5BV][Running/Manual Start]
  <System32\DRIVERS\fetnd5bv.sys><VIA Technologies, Inc.>
[Input and output operations / ntio256][Running/Disabled]
  <\??\C:\WINDOWS\System32\ntio256.sys><N/A>
[nv / nv][Running/Manual Start]
  <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
  <System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <System32\DRIVERS\secdrv.sys><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <System32\DRIVERS\tcpip.sys><N/A>
[VIA AGP Filter / viaagp1][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
[videX32 / videX32][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\videX32.sys><VIA Technologies, Inc.>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\xfilt.sys><VIA Technologies,Inc>
[VIMICRO USB PC Camera / ZSMC302][Running/Manual Start]
  <System32\Drivers\usbVM31b.sys><VM>
最后编辑2007-05-23 22:31:47
分享到:
gototop
 

==================================
驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[VIA Rhine-Family Fast Ethernet Adapter Driver Service / FETND5BV][Running/Manual Start]
  <System32\DRIVERS\fetnd5bv.sys><VIA Technologies, Inc.>
[Input and output operations / ntio256][Running/Disabled]
  <\??\C:\WINDOWS\System32\ntio256.sys><N/A>
[nv / nv][Running/Manual Start]
  <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
  <System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <System32\DRIVERS\secdrv.sys><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <System32\DRIVERS\tcpip.sys><N/A>
[VIA AGP Filter / viaagp1][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
[videX32 / videX32][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\videX32.sys><VIA Technologies, Inc.>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[VIA SATA IDE Hot-plug Driver / xfilt][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\xfilt.sys><VIA Technologies,Inc>
[VIMICRO USB PC Camera / ZSMC302][Running/Manual Start]
  <System32\Drivers\usbVM31b.sys><VM>

==================================
浏览器加载项
[ThunderAtOnce Class]
  {01443AEC-0FD1-40fd-9C87-E93D1494C233} <E:\bak\tools\常用软件\xunlei\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD>
[IeHelper Class]
  {0D42E1BD-09DD-4873-A826-9C7E793EB7B6} <E:\bak\tools\常用软件\xunlei\Components\ResWorker\DSIeHelper.dll, Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <E:\bak\tools\常用软件\xunlei\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD>
[启动迅雷5]
  {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <E:\bak\tools\常用软件\xunlei\Thunder.exe, Thunder Networking Technologies,LTD>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[使用迅雷下载]
  <E:\bak\tools\常用软件\xunlei\Program\GetUrl.htm, N/A>
[使用迅雷下载全部链接]
  <E:\bak\tools\常用软件\xunlei\Program\GetAllUrl.htm, N/A>

==================================
正在运行的进程
[PID: 356][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\ntdll.dll]  [Microsoft Corporation, 5.1.2600.1217 (xpsp2.030429-2131)]
[PID: 416][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\ntdll.dll]  [Microsoft Corporation, 5.1.2600.1217 (xpsp2.030429-2131)]
    [C:\WINDOWS\system32\CSRSRV.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\basesrv.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\winsrv.dll]  [Microsoft Corporation, 5.1.2600.1134 (xpsp2.020921-0842)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.1.2600.1255 (xpsp2.030804-1745)]
    [C:\WINDOWS\system32\KERNEL32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.1.2600.1254 (xpsp2.030801-1834)]
    [C:\WINDOWS\System32\LPK.DLL]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\USP10.dll]  [Microsoft Corporation, 1.0409.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\sxs.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
gototop
 

[PID: 912][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1221 (xpsp2.030511-1403)]
    [C:\WINDOWS\System32\ntdll.dll]  [Microsoft Corporation, 5.1.2600.1217 (xpsp2.030429-2131)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.1.2600.1254 (xpsp2.030801-1834)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.1.2600.1255 (xpsp2.030804-1745)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.2800.1226]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.2800.1233 (xpsp2.030604-1804)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.1.2600.1263 (xpsp2.030819-2129)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 3.50.5016.0]
    [C:\WINDOWS\System32\BROWSEUI.dll]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\SHDOCVW.dll]  [Microsoft Corporation, 6.00.2800.1203]
    [C:\WINDOWS\System32\UxTheme.dll]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\IMM32.DLL]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\LPK.DLL]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\USP10.dll]  [Microsoft Corporation, 1.0409.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\comctl32.dll]  [Microsoft Corporation, 5.82 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\msctfime.ime]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\appHelp.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\CLBCATQ.DLL]  [Microsoft Corporation, 2001.12.4414.42]
    [C:\WINDOWS\System32\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.42]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\cscui.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\CSCDLL.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\themeui.dll]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\Secur32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\MSIMG32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\netapi32.dll]  [Microsoft Corporation, 5.1.2600.2952 (xpsp_sp2_gdr.060714-0446)]
    [C:\WINDOWS\system32\urlmon.dll]  [Microsoft Corporation, 6.00.2800.1259]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\LINKINFO.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\ntshrui.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\ATL.DLL]  [Microsoft Corporation, 3.00.9435]
    [C:\WINDOWS\System32\WINSTA.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\webcheck.dll]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\INDICDLL.dll]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\WINDOWS\system32\stobject.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\BatMeter.dll]  [Microsoft Corporation, 6.00.2600.0000 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\POWRPROF.dll]  [Microsoft Corporation, 6.00.2600.0000 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\SETUPAPI.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\WTSAPI32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\upnpui.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\upnp.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\WININET.dll]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\CRYPT32.dll]  [Microsoft Corporation, 5.131.2600.1123 (xpsp2.020921-0842)]
    [C:\WINDOWS\system32\MSASN1.dll]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\system32\SSDPAPI.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\WS2_32.dll]  [Microsoft Corporation, 5.1.2600.1240 (xpsp2.030618-0119)]
    [C:\WINDOWS\system32\WS2HELP.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\iphlpapi.dll]  [Microsoft Corporation, 5.1.2600.1240 (xpsp2.030618-0119)]
    [C:\WINDOWS\system32\netshell.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\credui.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.6177]
    [C:\WINDOWS\system32\comdlg32.dll]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\WINSPOOL.DRV]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\OLEACC.dll]  [Microsoft Corporation, 4.2.5406.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\MSVCP60.dll]  [Microsoft Corporation, 6.00.8972.0]
    [C:\WINDOWS\System32\PSAPI.DLL]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.6177]
    [C:\WINDOWS\System32\browselc.dll]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [E:\bak\tools\常用软件\xunlei\Components\ResWorker\DSIeHelper.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 2]
    [E:\bak\tools\常用软件\xunlei\Components\ResWorker\DataProcessor.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
    [C:\WINDOWS\system32\MPR.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\ntlanman.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\NETUI0.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\NETUI1.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\NETRAP.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\SAMLIB.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\sti.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\CFGMGR32.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\WINTRUST.dll]  [Microsoft Corporation, 5.131.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\IMAGEHLP.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\rsaenh.dll]  [Microsoft Corporation, 5.1.2600.1029 (xpsp1.020426-1800)]
    [E:\bak\tools\常用软件\xunlei\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 2, 17]
    [C:\WINDOWS\System32\wiashext.dll]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, ]
    [C:\WINDOWS\System32\shdoclc.dll]  [Microsoft Corporation, 6.00.2600.0000 (xpclient.010817-1148)]
[PID: 1036][C:\WINDOWS\VM_STI.EXE]  [BIGDOG, 4, 2, 610, 4]
    [C:\WINDOWS\System32\ntdll.dll]  [Microsoft Corporation, 5.1.2600.1217 (xpsp2.030429-2131)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.1.2600.1255 (xpsp2.030804-1745)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.1.2600.1254 (xpsp2.030801-1834)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.1.2600.1263 (xpsp2.030819-2129)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 3.50.5016.0]
    [C:\WINDOWS\system32\MSVCRT.DLL]  [Microsoft Corporation, 7.0.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\ksproxy.ax]  [Microsoft Corporation, 5.3.0000000.900 built by: DIRECTX]
    [C:\WINDOWS\System32\SETUPAPI.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\ksuser.dll]  [Microsoft Corporation, 5.3.0000000.900 built by: DIRECTX]
    [C:\WINDOWS\System32\IMM32.DLL]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\LPK.DLL]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\USP10.dll]  [Microsoft Corporation, 1.0409.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\CLBCATQ.DLL]  [Microsoft Corporation, 2001.12.4414.42]
    [C:\WINDOWS\System32\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.42]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\msdmo.dll]  [, ]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.2800.1226]
    [C:\WINDOWS\system32\COMCTL32.dll]  [Microsoft Corporation, 5.82 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\devenum.dll]  [Microsoft Corporation, 6.05.01.0902]
    [C:\WINDOWS\system32\WINMM.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\kswdmcap.ax]  [Microsoft Corporation, 5.3.0000000.900 built by: DIRECTX]
    [C:\WINDOWS\System32\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\WINDOWS\System32\MFC42LOC.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\WINDOWS\System32\VM31bPrp.Ax]  [Vimicro, 1.00.01.00]
    [C:\WINDOWS\system32\comdlg32.dll]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.2800.1233 (xpsp2.030604-1804)]
gototop
 

[PID: 1052][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3760]
    [C:\WINDOWS\System32\ntdll.dll]  [Microsoft Corporation, 5.1.2600.1217 (xpsp2.030429-2131)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.1.2600.1263 (xpsp2.030819-2129)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.1.2600.1255 (xpsp2.030804-1745)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.1.2600.1254 (xpsp2.030801-1834)]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\IMM32.DLL]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\LPK.DLL]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\USP10.dll]  [Microsoft Corporation, 1.0409.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\shell32.dll]  [Microsoft Corporation, 6.00.2800.1233 (xpsp2.030604-1804)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.2800.1226]
    [C:\WINDOWS\system32\comctl32.dll]  [Microsoft Corporation, 5.82 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\SETUPAPI.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\msctfime.ime]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\NTMARTA.DLL]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\WLDAP32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\SAMLIB.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1064][C:\WINDOWS\System32\internat.exe]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\WINDOWS\System32\ntdll.dll]  [Microsoft Corporation, 5.1.2600.1217 (xpsp2.030429-2131)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\USER32.DLL]  [Microsoft Corporation, 5.1.2600.1255 (xpsp2.030804-1745)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.1.2600.1254 (xpsp2.030801-1834)]
    [C:\WINDOWS\system32\COMCTL32.DLL]  [Microsoft Corporation, 5.82 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\IMM32.DLL]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\SETUPAPI.DLL]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\SHELL32.DLL]  [Microsoft Corporation, 6.00.2800.1233 (xpsp2.030604-1804)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.2800.1226]
    [C:\WINDOWS\System32\LPK.DLL]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\USP10.dll]  [Microsoft Corporation, 1.0409.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\msctfime.ime]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\ole32.dll]  [Microsoft Corporation, 5.1.2600.1263 (xpsp2.030819-2129)]
    [C:\WINDOWS\System32\INDICDLL.dll]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\WINDOWS\System32\Cabinet.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1924][E:\bak\tools\常用软件\xunlei\Program\Thunder5.exe]  [Thunder Networking Technologies,LTD, 5, 6, 1, 292]
    [C:\WINDOWS\System32\ntdll.dll]  [Microsoft Corporation, 5.1.2600.1217 (xpsp2.030429-2131)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\WINMM.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.1.2600.1255 (xpsp2.030804-1745)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.1.2600.1254 (xpsp2.030801-1834)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.2800.1226]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\WINDOWS\system32\comdlg32.dll]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\COMCTL32.dll]  [Microsoft Corporation, 5.82 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.2800.1233 (xpsp2.030604-1804)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.1.2600.1263 (xpsp2.030819-2129)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 3.50.5016.0]
    [C:\WINDOWS\System32\MSVCP60.dll]  [Microsoft Corporation, 6.00.8972.0]
    [C:\WINDOWS\system32\IMAGEHLP.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\IMM32.DLL]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\LPK.DLL]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\USP10.dll]  [Microsoft Corporation, 1.0409.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\MFC42LOC.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\WINDOWS\System32\RICHED32.DLL]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\RICHED20.dll]  [Microsoft Corporation, 5.30.23.1211]
    [C:\WINDOWS\System32\INDICDLL.dll]  [Microsoft Corporation, 5.00.2920.0000]
    [E:\bak\tools\常用软件\xunlei\Program\TaskManager.dll]  [Thunder Networking Technologies,LTD, 1, 1, 0, 20]
gototop
 

[E:\bak\tools\常用软件\xunlei\Program\download_interface.dll]  [Thunder Networking Technologies,LTD, 2, 14, 2, 77]
    [C:\WINDOWS\System32\WS2_32.dll]  [Microsoft Corporation, 5.1.2600.1240 (xpsp2.030618-0119)]
    [C:\WINDOWS\System32\WS2HELP.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [E:\bak\tools\常用软件\xunlei\Program\stlport_vc646.dll]  [STLport Consulting, Inc., 4.6.2003.1031]
    [E:\bak\tools\常用软件\xunlei\Program\asyn_dns.dll]  [Thunder Networking Technologies,LTD, 2, 14, 2, 77]
    [C:\WINDOWS\System32\iphlpapi.dll]  [Microsoft Corporation, 5.1.2600.1240 (xpsp2.030618-0119)]
    [C:\WINDOWS\system32\WININET.dll]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\CRYPT32.dll]  [Microsoft Corporation, 5.131.2600.1123 (xpsp2.020921-0842)]
    [C:\WINDOWS\system32\MSASN1.dll]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\MSWSOCK.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\wshtcpip.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\CLBCATQ.DLL]  [Microsoft Corporation, 2001.12.4414.42]
    [C:\WINDOWS\System32\COMRes.dll]  [Microsoft Corporation, 2001.12.4414.42]
    [C:\WINDOWS\system32\mlang.dll]  [Microsoft Corporation, 6.00.2600.0000 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\DNSAPI.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\winrnr.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\WLDAP32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\rasadhlp.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\msctfime.ime]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [E:\bak\tools\常用软件\xunlei\Program\iTargetAD.dll]  [Thunder Networking Technologies,LTD, 1, 0, 2, 26]
    [C:\WINDOWS\System32\OLEPRO32.DLL]  [Microsoft Corporation, 5.0.5014]
    [C:\WINDOWS\System32\asycfilt.dll]  [Microsoft Corporation, 3.50.5014]
    [C:\WINDOWS\System32\msimg32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [E:\bak\tools\常用软件\xunlei\Program\BHOStub.dll]  [Thunder Networking Technologies,LTD, 1, 1, 0, 8]
    [E:\bak\tools\常用软件\xunlei\Components\DownAndPlay\DownAndPlay.dll]  [, 1, 0, 0, 2]
    [C:\WINDOWS\System32\ATL.DLL]  [Microsoft Corporation, 3.00.9435]
    [C:\WINDOWS\system32\appHelp.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\SETUPAPI.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
    [C:\WINDOWS\System32\WSOCK32.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\urlmon.dll]  [Microsoft Corporation, 6.00.2800.1259]
    [C:\WINDOWS\System32\Secur32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\RASAPI32.DLL]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\rasman.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\NETAPI32.dll]  [Microsoft Corporation, 5.1.2600.2952 (xpsp_sp2_gdr.060714-0446)]
    [C:\WINDOWS\System32\TAPI32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\rtutils.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\wdmaud.drv]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\MSACM32.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\midimap.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\SXS.DLL]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [E:\bak\tools\常用软件\xunlei\Components\InMedia\iEmbedShell.dll]  [ , 1, 0, 0, 17]
    [E:\bak\tools\常用软件\xunlei\Components\Community\XLCommunity.dll]  [Thunder Networking Technologies,LTD, 1, 0, 8, 30]
    [E:\bak\tools\常用软件\xunlei\Program\LiveUpdate.dll]  [Thunder Networking Technologies,LTD, 1, 1, 1, 20]
    [E:\bak\tools\常用软件\xunlei\Components\Search\XLSearch.dll]  [Thunder Networking Technologies,LTD, 1, 1, 1, 10]
    [E:\bak\tools\常用软件\xunlei\Components\P4PClient\P4PClient.dll]  [Thunder Networking Technologies,LTD, 2, 2, 1, 46]
    [E:\bak\tools\常用软件\xunlei\Components\DiagnoseHelper\DiagnoseHelper.dll]  [Thunder Networking Technologies,LTD, 1, 1, 1, 16]
    [C:\WINDOWS\system32\schannel.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [E:\bak\tools\常用软件\xunlei\Components\ExplorerHelper\ExplorerHelper.dll]  [Thunder Networking Technologies,LTD, 1, 0, 4, 15]
    [E:\bak\tools\常用软件\xunlei\Components\Tips\TipsClient.dll]  [Thunder Networking Technologies,LTD, 2, 1, 3, 58]
    [E:\bak\tools\常用软件\xunlei\Components\VPSHELL\VPSHELL.dll]  [XunLei, 1, 2, 0, 8]
    [E:\bak\tools\常用软件\xunlei\Components\UserExperience\UserExperience.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
    [E:\bak\tools\常用软件\xunlei\Components\ResWorker\DsXlCom.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 4]
    [E:\bak\tools\常用软件\xunlei\Components\InMedia\iEmbed09.dll]  [ , 3, 3, 0, 80]
    [E:\bak\tools\常用软件\xunlei\Program\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 13, 2, 61]
    [C:\WINDOWS\system32\msxml3.dll]  [Microsoft Corporation, 8.30.9926.0]
    [C:\WINDOWS\System32\shdocvw.dll]  [Microsoft Corporation, 6.00.2800.1203]
    [C:\WINDOWS\System32\shdoclc.dll]  [Microsoft Corporation, 6.00.2600.0000 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\mshtml.dll]  [Microsoft Corporation, 6.00.2800.1264]
    [C:\WINDOWS\system32\MSIMTF.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\MSCTF.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\MSLS31.DLL]  [Microsoft Corporation, 3.10.349.0]
    [C:\WINDOWS\System32\UXTHEME.dll]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [E:\bak\tools\常用软件\xunlei\Plugins\BhoAdv\bho_adv.dll]  [深圳市迅雷网络技术有限公司, 1.0.1.0]
    [C:\WINDOWS\system32\jscript.dll]  [Microsoft Corporation, 5.6.0.8513]
    [E:\bak\tools\常用软件\xunlei\Components\VPSHELL\VideoPicture.dll]  [XunLei, 1, 2, 0, 9]
    [E:\bak\tools\常用软件\xunlei\Components\ResWorker\DataProcessor.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 1]
    [E:\bak\tools\常用软件\xunlei\Program\XLNet.Dll]  [Thunder Networking Technologies,LTD, 1, 2, 0, 8]
    [E:\bak\tools\常用软件\xunlei\Components\ResWorker\MediaWorker.dll]  [Thunder Networking Technologies,LTD, 1, 2, 0, 8]
    [C:\WINDOWS\System32\WMVCore.DLL]  [Microsoft Corporation, 10.00.00.3802 built by: dnsrv(bld4act)]
    [C:\WINDOWS\System32\WMASF.DLL]  [Microsoft Corporation, 10.00.00.3802 built by: dnsrv(bld4act)]
gototop
 

[PID: 916][D:\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
    [C:\WINDOWS\System32\ntdll.dll]  [Microsoft Corporation, 5.1.2600.1217 (xpsp2.030429-2131)]
    [C:\WINDOWS\system32\kernel32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\USER32.dll]  [Microsoft Corporation, 5.1.2600.1255 (xpsp2.030804-1745)]
    [C:\WINDOWS\system32\GDI32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\ADVAPI32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\RPCRT4.dll]  [Microsoft Corporation, 5.1.2600.1254 (xpsp2.030801-1834)]
    [C:\WINDOWS\system32\comdlg32.dll]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\SHLWAPI.dll]  [Microsoft Corporation, 6.00.2800.1226]
    [C:\WINDOWS\system32\msvcrt.dll]  [Microsoft Corporation, 7.0.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\SHELL32.dll]  [Microsoft Corporation, 6.00.2800.1233 (xpsp2.030604-1804)]
    [C:\WINDOWS\System32\WINSPOOL.DRV]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\oledlg.dll]  [Microsoft Corporation, 1.0 (XPClient.010817-1148)]
    [C:\WINDOWS\system32\ole32.dll]  [Microsoft Corporation, 5.1.2600.1263 (xpsp2.030819-2129)]
    [C:\WINDOWS\system32\OLEAUT32.dll]  [Microsoft Corporation, 3.50.5016.0]
    [C:\WINDOWS\system32\VERSION.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\CRYPT32.dll]  [Microsoft Corporation, 5.131.2600.1123 (xpsp2.020921-0842)]
    [C:\WINDOWS\system32\MSASN1.dll]  [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
    [C:\WINDOWS\System32\WINMM.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\WS2_32.dll]  [Microsoft Corporation, 5.1.2600.1240 (xpsp2.030618-0119)]
    [C:\WINDOWS\System32\WS2HELP.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\WININET.dll]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\IMM32.DLL]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\LPK.DLL]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\USP10.dll]  [Microsoft Corporation, 1.0409.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\RICHED20.DLL]  [Microsoft Corporation, 5.30.23.1211]
    [C:\WINDOWS\System32\INDICDLL.dll]  [Microsoft Corporation, 5.00.2920.0000]
    [C:\WINDOWS\System32\msctfime.ime]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\UxTheme.dll]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\sfc.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\sfc_os.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\WINTRUST.dll]  [Microsoft Corporation, 5.131.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\IMAGEHLP.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\Sensapi.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\Secur32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\wsock32.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\RASAPI32.DLL]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\rasman.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\NETAPI32.dll]  [Microsoft Corporation, 5.1.2600.2952 (xpsp_sp2_gdr.060714-0446)]
    [C:\WINDOWS\System32\TAPI32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\rtutils.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\USERENV.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\urlmon.dll]  [Microsoft Corporation, 6.00.2800.1259]
    [C:\WINDOWS\System32\mswsock.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\DNSAPI.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\iphlpapi.dll]  [Microsoft Corporation, 5.1.2600.1240 (xpsp2.030618-0119)]
    [C:\WINDOWS\System32\winrnr.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\WLDAP32.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\wshtcpip.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\System32\rasadhlp.dll]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\rsaenh.dll]  [Microsoft Corporation, 5.1.2600.1029 (xpsp1.020426-1800)]
    [D:\sreng2\Plugins\NWMON.SRE]  [Smallfrogs Studio, 1, 0, 0, 8]
    [C:\WINDOWS\System32\SETUPAPI.dll]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\System32\cryptnet.dll]  [Microsoft Corporation, 5.131.2600.0 (xpclient.010817-1148)]
gototop
 

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
API HOOK
入口点错误:NtCreateFile (危险等级: 高,  被下面模块所HOOK: Dest Addr: 0x7FF922F2)
入口点错误:NtCreateProcess (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0x7FF92346)
入口点错误:NtCreateProcessEx (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0x7FF92353)
入口点错误:ZwCreateFile (危险等级: 高,  被下面模块所HOOK: Dest Addr: 0x7FF922F2)
入口点错误:ZwCreateProcess (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0x7FF92346)
入口点错误:ZwCreateProcessEx (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0x7FF92353)
入口点错误:ZwOpenFile (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0x7FF9233F)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

谢谢 你
API HOOK
入口点错误:NtCreateFile (危险等级: 高, 被下面模块所HOOK: Dest Addr: 0x7FF922F2)
入口点错误:NtCreateProcess (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0x7FF92346)
入口点错误:NtCreateProcessEx (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0x7FF92353)
入口点错误:ZwCreateFile (危险等级: 高, 被下面模块所HOOK: Dest Addr: 0x7FF922F2)
入口点错误:ZwCreateProcess (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0x7FF92346)
入口点错误:ZwCreateProcessEx (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0x7FF92353)
入口点错误:ZwOpenFile (危险等级: 一般, 被下面模块所HOOK: Dest Addr: 0x7FF9233F)

这个怎么修复啊 现在发现很多的EXE文件都无法使用了 还有就是瑞星还是无法安装 不过很感谢你了 我现在用另外一台机器拉来杀 不知道怎样
gototop
 

病毒名:Trojan.Agent.afx
Agent?? 妈的 老是中这个我都气死了 估计是这个下载病毒
Win32.Virut.GEN 这个病毒破坏EXE文件 使杀毒软件无法正常工作及安装
瑞星杀毒中ing…… 再次感谢你
gototop
 

刚找到的关于这个病毒的文章 大有来头哦 最近在论坛发现部分电脑中了一种virut的病毒,在联系珠海求证后,得知该病毒是近期出现的,少有的技术型病毒。virut是加密变形病毒,简单说就是每感染一个文件,病毒特征就会变一次,杀毒引擎想通过特征码查杀来修复被感染的文件,困难重重。因此,到目前为止,还没有发现哪个杀毒软件能够修复被virut感染的EXE,只能选择隔离。这样一来,中此病毒的系统,将会很惨,可能不得不备份文档后重装系统。毒霸研发部在拿到virut第一个样本的当晚加班处理了这个病毒的应急,当晚完成了针对virut病毒的免疫功能,以最大可能降低用户损失。
  提醒用户及早升级防范virut病毒,如果不幸中招,可根据受损程度处理。如果系统EXE破坏严重,可以采用备份进行还原,没有备份的情况下,覆盖安装可以最大程度减少损失。

  说明一下,发现BLOG的回复中有不少人认为应该把病毒扔别处,有本事别在国内放。这个不能苟同,造病毒放哪儿都有害。己所不欲,勿施于人。另外,这个病毒使用的加密引擎来自波兰,那个IRC服务器域名为 proxim.ircgalaxy.pl,貌似也是波兰的域名。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT