瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 顽固病毒无法清除,救助!!!!

1   1  /  1  页   跳转

[求助] 顽固病毒无法清除,救助!!!!

顽固病毒无法清除,救助!!!!

[CODE]
2010-09-15,22:25:42
System Repair Engineer 2.8.2.1321
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 3 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
    进程特权扫描
    计划任务
    Windows 安全更新检查
    API HOOK
    隐藏进程

启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <Keyboard Manager Utility><"C:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe" /lang CN /H>  [Quanta Computer, INC.]
    <SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe>  [Synaptics, Inc.]
    <nwiz><nwiz.exe /install>  []
    <IntelZeroConfig><"C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe">  [Intel(R) Corporation]
    <KSafeTray><"D:\Program Files\KSafe\KSafeTray.exe" -autorun>  [(Verified)Kingsoft Security Co.,Ltd]
    <kxesc><"C:\Program Files\Common Files\Kingsoft\kiscommon\kxetray.exe" -autorun>  [(Verified)Zhuhai  Kingsoft Software Co.,Ltd]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime>  [Apple Inc.]
    <iTunesHelper><"E:\Program Files\iTunes\iTunesHelper.exe">  [(Verified)Apple Inc.]
    <RTHDCPL><RTHDCPL.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [NVIDIA Corporation]
    <IntelWireless><"C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray>  [Intel(R) Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Component Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Component Publisher]
    <CDBurn><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Component Publisher]
    <WebCheck><C:\WINDOWS\system32\webcheck.dll>  [(Verified)Microsoft Windows]
    <SysTray><C:\WINDOWS\system32\stobject.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
    <WinlogonNotify: dimsntfy><%SystemRoot%\System32\dimsntfy.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
    <WinlogonNotify: ScCertProp><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
    <WinlogonNotify: Schedule><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    <WinlogonNotify: sclgntfy><sclgntfy.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
    <WinlogonNotify: termsrv><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
    <WinlogonNotify: wlballoon><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
    <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
    <Internet Explorer 版本更新><C:\WINDOWS\system32\ieudinit.exe>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    <Microsoft Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{56FC482E-1A98-4435-8A12-96B9B3A3B99A}]
    <浏览器自定义设置><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
    <Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
    <Internet Explorer><C:\WINDOWS\system32\ie4uinit.exe -BaseSettings>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><c:\WINDOWS\HOT Live Album.scr>  [MacSourcery]
==================================
启动文件夹
N/A
==================================
服务
[Agere Modem Call Progress Audio / AgereModemAudio][Running/Auto Start]
  <C:\WINDOWS\system32\agrsmsvc.exe><Agere Systems>
[Apple Mobile Device / Apple Mobile Device][Running/Auto Start]
  <"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"><Apple Inc.>
[Bonjour 服务 / Bonjour Service][Running/Auto Start]
  <"C:\Program Files\Bonjour\mDNSResponder.exe"><Apple Inc.>
[CloudServer / CloudServer][Running/Auto Start]
  <F:\Cloud\CloudServer.exe><>
[Intel? PROSet/Wireless Event Log / EvtEng][Running/Auto Start]
  <C:\Program Files\Intel\WiFi\bin\EvtEng.exe><Intel(R) Corporation>
[iPod 服务 / iPod Service][Running/Manual Start]
  <"C:\Program Files\iPod\bin\iPodService.exe"><Apple Inc.>
[Kingsoft Antivirus WebShield Service / Kingsoft Antivirus WebShield Service][Running/Auto Start]
  <d:\Kingsoft\webshield\KSWebShield.exe><Kingsoft Corporation>
[Kingsoft Rescue Service / Kingsoft Rescue Service][Running/Auto Start]
  <e:\kingsoft\KSM\ksmsvc.exe><>
[KSafe service / KSafeSvc][Running/Manual Start]
  <"d:\Program Files\KSafe\KSafeSvc.exe" -svc><Kingsoft Corporation.>
[Kingsoft Core Defend Service / kxedefend][Running/Auto Start]
  <"C:\Program Files\Common Files\Kingsoft\kiscommon\kxedefend.exe" /service kxedefend><Kingsoft Corporation>
[Kingsoft Security App Service / kxesapp][Running/Auto Start]
  <"C:\Program Files\Common Files\Kingsoft\kiscommon\kxesapp.exe" /service kxesapp><Kingsoft Corporation>
[Kingsoft Core Service / kxescore][Running/Auto Start]
  <"C:\Program Files\Common Files\Kingsoft\kiscommon\kxescore.exe" /service kxescore><Kingsoft Corporation>
[Kingsoft Antivirus XEngine Service / KxEServ][Running/Auto Start]
  <"C:\Program Files\Common Files\Kingsoft\kiscommon\kxeserv.exe"><Kingsoft Corporation>
[Kingsoft Antivirus Update Service / KxEUpSrv][Running/Auto Start]
  <"C:\Program Files\Common Files\Kingsoft\kiscommon\upsvc.exe"><Kingsoft Corporation>
[Remote Network Connections to Manage / NrConnmags][Stopped/Auto Start]
  <"C:\WINDOWS\system\csrss.exe"><(File is missing)>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Intel? PROSet/Wireless Registry Service / RegSrvc][Running/Auto Start]
  <C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe><Intel(R) Corporation>
[Intel?PROSet/Wireless WiFi Service / S24EventMonitor][Running/Auto Start]
  <C:\Program Files\Intel\WiFi\bin\S24EvMon.exe><Intel(R) Corporation>
[ServiceLayer / ServiceLayer][Stopped/Manual Start]
  <"C:\Program Files\PC Connectivity Solution\ServiceLayer.exe"><Nokia>
[SolidPDFToolsCreatorReadSpool / SPDFToolsReadSpool][Running/Auto Start]
  <C:\WINDOWS\Installer\MSI9E.tmp><Solid Documents, LLC>
[Tencent Software Update Service / TSUSVC][Stopped/Auto Start]
  <"d:\Program Files\Tencent\QQSoftMgr\1.0.375.203\TencentUpdateSvc.exe" -run><Tencent>
==================================
驱动程序
[Agere Systems Soft Modem / AgereSoftModem][Running/Manual Start]
  <system32\DRIVERS\AGRSM.sys><Agere Systems>
[Ambfilt / Ambfilt][Stopped/Manual Start]
  <system32\drivers\Ambfilt.sys><Creative>
[BC / BC][Running/Boot Start]
  <\SystemRoot\system32\Drivers\BC.sys><Kingsoft Corporation>
[bootsafe / bootsafe][Running/Boot Start]
  <\SystemRoot\system32\Drivers\bootsafe.sys><>
[GEAR ASPI Filter Driver / GEARAspiWDM][Running/Manual Start]
  <system32\DRIVERS\GEARAspiWDM.sys><GEAR Software Inc.>
[Microsoft 用于 High Definition Audio 的 UAA 总线驱动程序 / HDAudBus][Running/Manual Start]
  <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
  <system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
[KAVBootC / KAVBootC][Running/Boot Start]
  <\SystemRoot\system32\drivers\KAVBootC.sys><Kingsoft Corporation>
[KAVSafe / KAVSafe][Running/Auto Start]
  <\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys><Kingsoft Corporation>
[krpr / krpr][Stopped/Manual Start]
  <\??\d:\Kingsoft\webshield\krpr.sys><N/A>
[ksdef / ksdef][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\ksdef.sys><Kingsoft Corporation>
[kwatch32 / kwatch32][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\kwatch32.sys><Kingsoft Corporation>
[LongRADrv / LongRADrv][Running/System Start]
  <\??\F:\Cloud\LongRADrv.sys><long>
[Monfilt / Monfilt][Stopped/Manual Start]
  <system32\drivers\Monfilt.sys><Creative Technology Ltd.>
[Intel(R) Wireless WiFi Link 适配器驱动程序(适用于 Windows XP 32 位) / NETw5x32][Running/Manual Start]
  <system32\DRIVERS\NETw5x32.sys><Intel Corporation>
[Nokia USB Phone Parent / nmwcd][Stopped/Manual Start]
  <system32\drivers\ccdcmb.sys><Nokia>
[Nokia USB Generic / nmwcdc][Stopped/Manual Start]
  <system32\drivers\ccdcmbo.sys><Nokia>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Service for NVIDIA High Definition Audio Driver / NVHDA][Running/Manual Start]
  <system32\drivers\nvhda32.sys><NVIDIA Corporation>
[PCCS Mode Change Filter Driver / pccsmcfd][Stopped/Manual Start]
  <system32\DRIVERS\pccsmcfd.sys><Nokia>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Keyboard Filter Driver / qkbfiltr][Running/Manual Start]
  <system32\DRIVERS\qkbfiltr.sys><KM Software Team>
[Feitian ROCKEY4 Device Service / ROCKEYNT][Running/Manual Start]
  <system32\DRIVERS\Rockey4.sys><Feitian Technologies Co., Ltd.>
[RTS5121.Sys Realtek USB Card Reader / RSUSBSTOR][Running/Manual Start]
  <System32\Drivers\RTS5121.sys><Realtek Semiconductor Corporation>
[Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver / RTLE8023xp][Running/Manual Start]
  <system32\DRIVERS\Rtenicxp.sys><Realtek Semiconductor Corporation>
[WLAN 传输 / s24trans][Running/Auto Start]
  <system32\DRIVERS\s24trans.sys><Intel Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[Synaptics TouchPad Driver / SynTP][Running/Manual Start]
  <system32\DRIVERS\SynTP.sys><Synaptics, Inc.>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[upperdev / upperdev][Stopped/Manual Start]
  <system32\DRIVERS\usbser_lowerflt.sys><Nokia>
[UsbserFilt / UsbserFilt][Stopped/Manual Start]
  <system32\DRIVERS\usbser_lowerfltj.sys><Nokia>
[XLNetDispat Service / xlnetdispat][Stopped/Manual Start]
  <system32\DRIVERS\xlnetdispat.sys><Thunder Networking Technologies,LTD>
[xlnetdispatmp / xlnetdispatmp][Running/Manual Start]
  <system32\DRIVERS\xlnetdispat.sys><Thunder Networking Technologies,LTD>
[Driver for XLPPoEPC Device / XLPPoEPC][Running/Manual Start]
  <system32\DRIVERS\XLPPoEPC.sys><西安信利软件系统公司>

用户系统信息:Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; staticlogin:product=cboxf09&act=login&info=ZmlsZW5hbWU9UG93ZXJ3b3JkMjAwOU94Zi4yNTI2OS40MDExLmV4ZSZtYWM9QkU1RjY2NEZFOEUzNDNFNUExNUU1RTM0QTcyNjBBNTQmcGFzc3BvcnQ9JnZlcnNpb249MjAwOS4wNS4yNS4zLjI3MiZjcmFzaHR5cGU9MQ==&verify=4bb8b0cd723fc247fcf19501140fd7bc; aff-kingsoft-ciba)
分享到:
gototop
 

回复:顽固病毒无法清除,救助!!!!

浏览器加载项
[IDMIEHlprObj Class]
  {0055C089-8582-441B-A0BF-17B458C2A3A8} <E:\Program Files\Internet Download Manager\IDMIECC.dll, (Signed) Tonec Inc.>
[迅雷流媒体探测IE支持]
  {01443AEC-0FD1-40fd-9C87-E93D1494C233} <E:\Thunder Network\ComDlls\TDMediaDetector5.9.27.1554.dll, (Signed) 深圳市迅雷网络技术有限公司>
[IE2EMBHO Class]
  {0A0DDBD3-6641-40B9-873F-BBDD26D6C14E} <E:\easyMule\modules\IE2EM.dll, (Signed) VeryCD.com>
[迅雷网页图片浏览器IE支持]
  {2D90D33C-DE76-42D0-9040-E4466DDC24AC} <E:\Thunder Network\Program\EmbedDetectNow.dll, (Signed) Xunlei>
[迅雷下载IE支持]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <E:\Thunder Network\ComDlls\xunleiBHO_Now.dll, (Signed) 深圳市迅雷网络技术有限公司>
[查看网页全部图片]
  {548BF84E-9665-47f9-B635-7380F8943E90} <, >
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL, (Signed) Microsoft Corporation>
[BitComet]
  {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} <, >
[@xpsp3res.dll,-20001]
  {e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, (Signed) N/A>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, (Signed) Microsoft Corporation>
[EditCtrl Class]
  {488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\system32\aliedit\aliedit.dll, (Signed) >
[]
  {EF0D1A14-1033-41A2-A589-240C01EDC078} <, >
[Microsoft Office Spreadsheet 10.0]
  {0002E551-0000-0000-C000-000000000046} <C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL, (Signed) Microsoft Corporation>
[IDMIEHlprObj Class]
  {0055C089-8582-441B-A0BF-17B458C2A3A8} <E:\Program Files\Internet Download Manager\IDMIECC.dll, (Signed) Tonec Inc.>
[迅雷流媒体探测IE支持]
  {01443AEC-0FD1-40FD-9C87-E93D1494C233} <E:\Thunder Network\ComDlls\TDMediaDetector5.9.27.1554.dll, (Signed) 深圳市迅雷网络技术有限公司>
[VersionFun Class]
  {05EF1822-FC58-4578-B979-1F5863867DD7} <F:\Cloud\CloudFun.dll, (Signed) Lang Hong>
[VersionFun2 Class]
  {05FF1822-FC58-4578-B979-1F5863867DD7} <F:\Cloud\CloudFun2.dll, (Signed) Lang Hong>
[IE2EMBHO Class]
  {0A0DDBD3-6641-40B9-873F-BBDD26D6C14E} <E:\easyMule\modules\IE2EM.dll, (Signed) VeryCD.com>
[Player Class]
  {11F2A418-94B2-4e16-9B0C-B00C0435F903} <d:\Tencent\QQLive\LiveMedia.dll, (Signed) Tencent>
[InstallHelper Class]
  {1DABF8D5-8430-4985-9B7F-A30E53D709B3} <C:\WINDOWS\system32\MMInstaller.dll, (Signed) Tencent>
[iTrusPTA Class]
  {1E0DFFCF-27FF-4574-849B-55007349FEDA} <C:\WINDOWS\system32\aliedit\pta.dll, (Signed) >
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, (Signed) Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <C:\WINDOWS\system32\mshtml.dll, (Signed) Microsoft Corporation>
[]
  {28B3B717-A610-4E32-8555-B8BA4779CF8A} <, >
[XML DOM Document]
  {2933BF90-7B36-11D2-B20E-00C04F983E60} <C:\WINDOWS\system32\msxml3.dll, (Signed) Microsoft Corporation>
[DHTML Edit Control Safe for Scripting for IE5]
  {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, (Signed) Microsoft Corporation>
[迅雷网页图片浏览器IE支持]
  {2D90D33C-DE76-42D0-9040-E4466DDC24AC} <E:\Thunder Network\Program\EmbedDetectNow.dll, (Signed) Xunlei>
[BitComet Helper]
  {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <E:\Program Files\BitComet\tools\BitCometBHO_1.4.1.10.dll, (Signed) BitComet>
[QuickTime Object]
  {4063BE15-3B08-470D-A0D5-B37161CFFD69} <C:\Program Files\QuickTime\QTPlugin.ocx, (Signed) Apple Inc.>
[XML Document]
  {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, (Signed) Microsoft Corporation>
[Thunder Agent Class]
  {485463B7-8FB2-4B3B-B29B-8B919B0EACCE} <E:\Thunder Network\ComDlls\ThunderAgent5.9.27.1554.dll, (Signed) 深圳市迅雷网络技术有限公司>
[IE2EMUrlTaker Class]
  {48618374-565F-4CA0-B8CD-6F496C997FAF} <E:\easyMule\modules\IE2EM.dll, (Signed) VeryCD.com>
[EditCtrl Class]
  {488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\system32\aliedit\aliedit.dll, (Signed) >
[TVAnts ActiveX Control]
  {4C833081-D026-4FF8-968F-7EAB660D2FBA} <d:\Program Files\TVAnts\TvantsX.ocx, Zhejiang University>
[QQPYChecker Class]
  {5052B4D0-9DF7-45ef-88EF-F42C0EA33A43} <d:\Program Files\Tencent\QQPinyin\3.2.805.201\QQImeChecker.dll, (Signed) Tencent>
[]
  {548BF84E-9665-47F9-B635-7380F8943E90} <, >
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <C:\WINDOWS\system32\ieframe.dll, (Signed) Microsoft Corporation>
[WangWangX Class]
  {5D09DD40-CDC4-4C56-B615-0D1E3B357C2B} <E:\Program Files\AliWangWang\AliIMX.dll, (Signed) Alibaba software (Shanghai) Corporation.>
[PowerPlayer Control]
  {5EC7C511-CD0F-42E6-830C-1BD9882F3458} <d:\PROGRA~1\PPStream\POWERP~1.DLL, PPStream Inc.>
[Microsoft Shell UI Helper]
  {64AB4BB7-111E-11D1-8F79-00C04FC2FBE1} <C:\WINDOWS\system32\ieframe.dll, (Signed) Microsoft Corporation>
[QQLiveFile Class]
  {6B232760-90F1-41c3-9902-C8552C1D8A72} <d:\Tencent\QQLive\FileVersion.dll, (Signed) Tencent>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation>
[Access UserInfo by Script]
  {6EE9CD3E-A386-4DAE-9737-A759DBF927AE} <E:\Thunder Network\ComDlls\UserAgent.dll, (Signed) 深圳市迅雷网络技术有限公司>
[QvodShare Class]
  {7139E26A-49CA-4344-B063-C702858627D9} <C:\Program Files\QvodPlayer\ShareModule.dll, (Signed) Shenzhen QVOD Technology Co.,Ltd>
[MediaComm Class]
  {7670648D-461B-42AF-BDFE-46D26AF5EFF2} <E:\Thunder Network\userdata\Components\InMedia\MediaAddin.dll, (Signed) 深圳市迅雷网络技术有限公司>
[IDMDwnlMgr Class]
  {7D11E719-FF90-479C-B0D7-96EB43EE55D7} <E:\Program Files\Internet Download Manager\downlWithIDM.dll, (Signed) Tonec Inc.>
[XDownloaddManager Class]
  {802F530B-A8F6-4631-AE49-6BACAAC6373E} <E:\Thunder Network\ComDlls\xunleiBHO_Now.dll, (Signed) 深圳市迅雷网络技术有限公司>
[Microsoft Web Browser]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\ieframe.dll, (Signed) Microsoft Corporation>
[迅雷下载IE支持]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <E:\Thunder Network\ComDlls\xunleiBHO_Now.dll, (Signed) 深圳市迅雷网络技术有限公司>
[XML DOM 文档 5.0]
  {88D969E5-F192-11D4-A65F-0040963251E5} <C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSXML5.DLL, Microsoft Corporation>
[XML DOM Document 6.0]
  {88D96A05-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml6.dll, (Signed) Microsoft Corporation>
[XML HTTP 6.0]
  {88D96A0A-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml6.dll, (Signed) Microsoft Corporation>
[SopCore Control]
  {8FEFF364-6A5F-4966-A917-A3AC28411659} <d:\Program Files\SopCast\sopocx.ocx, SopCast.com>
[]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <, >
[OFrameObject Class]
  {9701758C-4373-482E-B13C-776C048EC890} <C:\Program Files\Common Files\Thunder Network\KanKan\DapCtrl.2.3.5927.309.(511).dll, (Signed) 深圳市迅雷网络技术有限公司>
[VersionDetector Class]
  {9EFF1953-9694-47B1-AEF6-B2A3FE8BFE9B} <C:\Program Files\Common Files\Thunder Network\KanKan\vd.1.1.0.32.(511).dll, (Signed) 深圳市迅雷网络技术有限公司>
[HallToolkit Class]
  {A24E6133-404F-4431-A296-2DE576FC5AEE} <C:\Program Files\Common Files\Thunder Network\XLGame\HallTool.1.0.0.6.(271).dll, (Signed) Thunder Networking Technologies,LTD>
[DownloadManager Class]
  {A8DC7D60-AD8F-491E-9A84-8FF901E7556E} <E:\Program Files\BitComet\tools\BitCometBHO_1.4.1.10.dll, (Signed) BitComet>
[APlayer Control]
  {A9322148-C691-4B9D-91FC-B9C461DBE9DD} <C:\Program Files\Common Files\Thunder Network\APlayer\APlayer_001.dll, (Signed) ShenZhen Thunder Networking Technologies, LTD>
[RMGetLicense Class]
  {A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, (Signed) Microsoft Corporation>
[DapCtrl Class]
  {ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} <C:\Program Files\Common Files\Thunder Network\KanKan\DapCtrl.2.3.5927.309.(511).dll, (Signed) 深圳市迅雷网络技术有限公司>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A>
[FTNUpload Class]
  {BDEACC50-F56D-4D60-860F-CF6ED1766D65} <C:\Program Files\Common Files\Tencent\TXFTN\TXFTNActiveX.dll, (Signed) Tencent>
[KooPlayer Control]
  {C728DAB8-FDF5-4CD7-89DD-879D25794C77} <c:\Documents and Settings\hh\Application Data\Cbox\CCTVPlayer.ocx, (Signed) CCTV.COM>
[QQPlayerCtrl Class]
  {CD108273-D434-43E6-AA90-1469F97EB398} <d:\Program Files\Tencent\QQMusic\QzoneMusic.dll, (Signed) Tencent>
[AUDIO__X_MS_WMA Moniker Class]
  {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation>
[Microsoft Url Search Hook]
  {CFBFAE00-17A6-11D0-99CB-00C04FD64497} <C:\WINDOWS\system32\ieframe.dll, (Signed) Microsoft Corporation>
[]
  {D18A0B52-D63C-4ED0-AFC6-C1E3DC1AF43A} <, >
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash10i.ocx, (Signed) Adobe Systems, Inc.>
[KuAgent2 Class]
  {D928E486-C465-4A64-976D-F3B24BBECC69} <e:\Program Files\YouKu\iKu\YouKuAgent.dll, (Signed) www.youku.com>
[QQLive Class]
  {D9EBCF5D-3F8F-4b6a-89BA-70577BE73C62} <d:\Tencent\QQLive\LiveAPI.dll, (Signed) Tencent>
[QuickTimeCheck Class]
  {DE4AF3B0-F4D4-11D3-B41A-0050DA2E6C21} <C:\Program Files\QuickTime\QTSystem\QuickTimeCheck.ocx, (Signed) Apple Inc.>
[PlayerCtrl Class]
  {E05BC2A3-9A46-4A32-80C9-023A473F5B23} <d:\Program Files\Tencent\QQMusic\QzoneMusic.dll, (Signed) Tencent>
[]
  {E2E2DD38-D088-4134-82B7-F2BA38496583} <, >
[RevealTrans]
  {E31E87C4-86EA-4940-9B8A-5BD5D179A737} <C:\WINDOWS\system32\Dxtmsft.dll, (Signed) Microsoft Corporation>
[TimwpDll.TimwpCheck]
  {ED4CA2E5-0EEA-44C1-AD7E-74A07A7507A4} <d:\Program Files\Tencent\QQ\Bin\Timwp.dll, (Signed) Tencent>
[XML HTTP Request]
  {ED8C108E-4349-11D2-91A4-00C04F7969E8} <C:\WINDOWS\system32\msxml3.dll, (Signed) Microsoft Corporation>
[]
  {EF0D1A14-1033-41A2-A589-240C01EDC078} <, >
[]
  {F3E70CEA-956E-49CC-B444-73AFE593AD7F} <, >
[XML HTTP 3.0]
  {F5078F35-C551-11D3-89B9-0000F81FE221} <C:\WINDOWS\system32\msxml3.dll, (Signed) Microsoft Corporation>
[XML HTTP]
  {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <C:\WINDOWS\system32\msxml3.dll, (Signed) Microsoft Corporation>
[]
  {FB5F1910-F110-11D2-BB9E-00C04F795683} <, >
[QvodCtrl Class]
  {F3D0D36F-23F8-4682-A195-74C92B03D4AF} <C:\Program Files\QvodPlayer\QvodInsert.dll, (Signed) Shenzhen QVOD Technology Co.,Ltd>
[&使用BitComet下载]
  <res://E:\Program Files\BitComet\BitComet.exe/AddLink.htm, N/A>
[&使用BitComet下载全部链接]
  <res://E:\Program Files\BitComet\BitComet.exe/AddAllLink.htm, N/A>
[&使用BitComet下载本页视频]
  <res://E:\Program Files\BitComet\BitComet.exe/AddVideo.htm, N/A>
[使用 IDM 下载]
  <E:\Program Files\Internet Download Manager\IEExt.htm, N/A>
[使用 IDM 下载所有链接]
  <E:\Program Files\Internet Download Manager\IEGetAll.htm, N/A>
[使用 IDM 下载视频内容]
  <E:\Program Files\Internet Download Manager\IEGetVL.htm, N/A>
[使用电驴下载]
  <E:\easyMule\IE2EM.htm, N/A>
[使用迅雷下载]
  <E:\Thunder Network\Program\GetUrl.htm, N/A>
[使用迅雷下载全部链接]
  <E:\Thunder Network\Program\GetAllUrl.htm, N/A>
[使用迅雷查看图片]
  <E:\Thunder Network\Program\repairimage.htm, N/A>
[使用迅雷离线下载]
  <E:\Thunder Network\Thunder\Program\OfflineDownload.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
gototop
 

回复:顽固病毒无法清除,救助!!!!

正在运行的进程
[PID: 1228 / hh][C:\WINDOWS\Explorer.EXE]  [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Kingsoft\Kingsoft Antivirus\ktaskbar.dll]  [Kingsoft Corporation, 2010,05,26,732]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [C:\WINDOWS\system32\msi.dll]  [Microsoft Corporation, 4.5.6001.22159]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\WINDOWS\system32\netprovcredman.dll]  [Intel(R) Corporation, 12, 0, 0, 0]
    [E:\Thunder Network\ComDlls\xunleiBHO_Now.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\ComDlls\zlib1.dll]  [, 1.2.3]
    [E:\Thunder Network\ComDlls\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [E:\Thunder Network\ComDlls\libexpat.dll]  [N/A, ]
    [E:\Thunder Network\ComDlls\MSVCP71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [E:\Thunder Network\ComDlls\ATL71.DLL]  [Microsoft Corporation, 7.10.6101.0]
    [E:\Thunder Network\userdata\Components\ResWorker\DsBho_01.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 0, 33]
    [E:\Thunder Network\userdata\Components\ResWorker\DataProcessor_01.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 1, 6]
    [C:\WINDOWS\system32\nvcpl.dll]  [NVIDIA Corporation, 6.14.11.7626]
    [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.11.7626]
    [C:\WINDOWS\system32\nvapi.dll]  [NVIDIA Corporation, 6.14.11.7626]
    [C:\WINDOWS\system32\nvshell.dll]  [, ]
    [E:\Program Files\Internet Download Manager\idmmkb.dll]  [Tonec Inc., 5, 16, 1, 0]
    [E:\Program Files\Internet Download Manager\IDMIECC.dll]  [Tonec Inc., 5, 19, 1, 0]
    [E:\Thunder Network\ComDlls\ThunderAgent5.9.27.1554.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [C:\Program Files\WinRAR\rarext.dll]  [, ]
[PID: 3604 / hh][d:\Kingsoft\webshield\kwstray.exe]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kdump.dll]  [Kingsoft Corporation, 2010,08,24,1353]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [d:\Kingsoft\webshield\report\kinfoc.dll]  [Kingsoft Corporation, 2010,05,07,677]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.2.0]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 90, 0, 1]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
[PID: 2808 / hh][C:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe]  [Quanta Computer, INC., 2.3.6.2]
    [C:\Program Files\Keyboard Manager\Manager Utility\QManager.dll]  [N/A, ]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
[PID: 2612 / hh][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe]  [Synaptics, Inc., 10.1.8 06Dec07]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [C:\WINDOWS\system32\SynCOM.dll]  [Synaptics, Inc., 10.1.8 06Dec07]
    [C:\WINDOWS\system32\SynTPAPI.dll]  [Synaptics, Inc., 10.1.8 06Dec07]
[PID: 3040 / hh][C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe]  [Intel(R) Corporation, 12.0.0.8]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll]  [The OpenSSL Project, http://www.openssl.org/, 0.9.8]
    [C:\Program Files\Common Files\Intel\WirelessCommon\PsRegApi.dll]  [Intel(R) Corporation, 12, 0, 0, 0]
    [C:\Program Files\Common Files\Intel\WirelessCommon\TraceApi.dll]  [Intel(R) Corporation, 12, 0, 0, 2]
    [C:\Program Files\Intel\WiFi\bin\LangResources\CHS\ZcSvcCHS.dll]  [Intel(R) Corporation, 12.0.0.8]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [C:\Program Files\Intel\WiFi\bin\MurocApi.dll]  [Intel(R) Corporation, 12, 0, 0, 5]
    [C:\Program Files\Intel\WiFi\bin\IntStngs.dll]  [Intel(R) Corporation, 12, 0, 0, 0]
    [C:\Program Files\Intel\WiFi\bin\S24MUDLL.dll]  [Intel(R) Corporation, 12, 0, 0, 1]
    [C:\Program Files\Intel\WiFi\bin\PfMgrApi.dll]  [Intel(R) Corporation, 12, 0, 0, 2]
    [C:\Program Files\Intel\WiFi\bin\DbEngine.dll]  [Intel(R) Corporation, 12, 0, 0, 0]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
[PID: 3068 / hh][D:\Program Files\KSafe\KSafeTray.exe]  [Kingsoft Corporation., 1.2.2.1078]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [D:\Program Files\KSafe\krunopt.dll]  [Kingsoft Corporation., 1.2.2.1078]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [D:\Program Files\KSafe\ksafevul.dll]  [Kingsoft Corporation., 1.2.2.1078]
    [C:\WINDOWS\system32\msi.dll]  [Microsoft Corporation, 4.5.6001.22159]
    [D:\Program Files\KSafe\ksafeup.dll]  [Kingsoft Corporation., 1.2.2.1078]
    [D:\Program Files\KSafe\zlib1.dll]  [, 1.2.3]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.2.0]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 90, 0, 1]
    [D:\Program Files\KSafe\KEng\ksignup.dll]  [Kingsoft Corporation., 1.0.0.1113]
    [D:\Program Files\KSafe\kplugeng.dll]  [Kingsoft Corporation., 1.5.2.1189]
    [D:\Program Files\KSafe\KEng\KSGMerge.DLL]  [Kingsoft Corporation, 2010,02,26,47]
gototop
 

回复:顽固病毒无法清除,救助!!!!

[PID: 3256 / hh][E:\Program Files\iTunes\iTunesHelper.exe]  [Apple Inc., 9.2.0.61]
    [E:\Program Files\iTunes\iTunesHelper.dll]  [Apple Inc., 9.2.0.61]
    [C:\Program Files\Common Files\Apple\Apple Application Support\CoreFoundation.dll]  [Apple Inc., 1,550,26,13]
    [C:\Program Files\Common Files\Apple\Apple Application Support\pthreadVC2.dll]  [Open Source Software community project, 2, 7, 0, 11200]
    [C:\Program Files\Common Files\Apple\Apple Application Support\objc.dll]  [Apple Inc., 1,435,14,16]
    [C:\Program Files\Common Files\Apple\Apple Application Support\libdispatch.dll]  [Apple Inc., 1,109,4,1]
    [C:\Program Files\Common Files\Apple\Apple Application Support\icuin40.dll]  [IBM Corporation and others, 4, 0, 0, 3204]
    [C:\Program Files\Common Files\Apple\Apple Application Support\icuuc40.dll]  [IBM Corporation and others, 4, 0, 0, 3204]
    [C:\Program Files\Common Files\Apple\Apple Application Support\icudt40.dll]  [IBM Corporation and others, 4, 0, 0, 3204]
    [C:\Program Files\Common Files\Apple\Apple Application Support\ASL.dll]  [Apple, Inc., 1, 0, 0, 20]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [E:\Program Files\iTunes\iTunesHelper.Resources\zh_CN.lproj\iTunesHelperLocalized.DLL]  [Apple Inc., 9.2.0.47]
    [E:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.DLL]  [Apple Inc., 9.2.0.61]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\QuickTime\QTSystem\QuickTime.qts]  [Apple Inc., 7.6.6 (1673)]
    [C:\Program Files\QuickTime\QTSystem\QTCF.dll]  [Apple Inc., 7.6.6 (1673)]
    [C:\Program Files\Common Files\Apple\Apple Application Support\CFNetwork.DLL]  [Apple, Inc., 1, 454, 10, 13]
    [C:\Program Files\Common Files\Apple\Apple Application Support\SQLite3.dll]  [Apple Inc., 3.6.12 (74.2)]
    [C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll]  [, 1.2.3]
    [C:\Program Files\Common Files\Apple\Mobile Device Support\iTunesMobileDevice.dll]  [Apple Inc., 392.8.0.1]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 90, 0, 1]
[PID: 3976 / hh][C:\WINDOWS\RTHDCPL.EXE]  [Realtek Semiconductor Corp., 2.3.1.4]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
[PID: 1200 / hh][C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe]  [Intel(R) Corporation, 12, 0, 0, 0]
    [C:\Program Files\Common Files\Intel\WirelessCommon\PsRegApi.dll]  [Intel(R) Corporation, 12, 0, 0, 0]
    [C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll]  [The OpenSSL Project, http://www.openssl.org/, 0.9.8]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\Common Files\Intel\WirelessCommon\LangResources\CHS\FrWrkCHS.dll]  [Intel(R) Corporation, 12, 0, 0, 0]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [C:\Program Files\Common Files\Intel\WirelessCommon\FrameworkPlugins\WiWiTray.dll]  [Intel(R) Corporation, 12, 0, 0, 1]
    [C:\Program Files\Common Files\Intel\WirelessCommon\LangResources\CHS\WiTrCHS.dll]  [Intel(R) Corporation, 12, 0, 0, 1]
    [C:\Program Files\Common Files\Intel\WirelessCommon\FrameworkPlugins\ConnMgr.dll]  [Intel(R) Corporation, 12.0.0.9]
    [C:\Program Files\Intel\WiFi\bin\LangResources\CHS\IntWACHS.dll]  [Intel(R) Corporation, 12.0.0.9]
    [C:\Program Files\Common Files\Intel\WirelessCommon\TraceAPI.DLL]  [Intel(R) Corporation, 12, 0, 0, 2]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Intel\WiFi\bin\MurocApi.dll]  [Intel(R) Corporation, 12, 0, 0, 5]
    [C:\Program Files\Intel\WiFi\bin\IntStngs.dll]  [Intel(R) Corporation, 12, 0, 0, 0]
    [C:\Program Files\Intel\WiFi\bin\S24MUDLL.dll]  [Intel(R) Corporation, 12, 0, 0, 1]
    [C:\Program Files\Intel\WiFi\bin\PfMgrApi.dll]  [Intel(R) Corporation, 12, 0, 0, 2]
    [C:\Program Files\Intel\WiFi\bin\DbEngine.dll]  [Intel(R) Corporation, 12, 0, 0, 0]
[PID: 2208 / hh][C:\WINDOWS\system32\ctfmon.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
[PID: 2836 / hh][C:\WINDOWS\system32\wbem\unsecapp.exe]  [(Verified) Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
[PID: 5816 / hh][E:\Program Files\renren\xntalk.exe]  [千橡互动, 4.006]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.2.0]
[PID: 4344 / hh][D:\Program Files\Tencent\QQ\Bin\QQ.exe]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\Common.dll]  [Tencent, 1, 50, 1720, 0]
    [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.4053]
    [D:\Program Files\Tencent\QQ\Bin\KernelUtil.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\GF.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\xGraphic32.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\AFUtil.dll]  [Tencent, 1, 50, 1720, 0]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [D:\Program Files\Tencent\QQ\Bin\LoginPanel.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\IM.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\TaskTray.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\AppUtil.dll]  [Tencent, 1, 50, 1720, 0]
    [d:\Program Files\Tencent\QQ\Bin\TXPFProxy.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\MainFrame.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\AppFramework.dll]  [Tencent, 1, 50, 1720, 0]
    [C:\Program Files\Common Files\Tencent\TXSSO\Bin\SSOPlatform.dll]  [Tencent, 1.2.1.10]
    [C:\Program Files\Common Files\Tencent\TXSSO\Bin\SSOCommon.DLL]  [Tencent, 1.2.1.6]
    [D:\Program Files\Tencent\QQ\Bin\SkinMgr.dll]  [Tencent, 1, 50, 1720, 0]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.2.0]
    [D:\Program Files\Tencent\QQ\Bin\AFCtrl.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\SystemMsg.dll]  [Tencent, 1, 50, 1720, 0]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [D:\Program Files\Tencent\QQ\Bin\ConfigCenter.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\ChatFrameApp.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\QInterLive.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\GroupApp.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\AppMisc.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.snsapp\Bin\SNSApp.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.paycenter\Bin\PayCenter.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.qbar\Bin\QBar.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.qqvipmisc\Bin\QQVipMisc.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.wenwen\Bin\WenWen.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\WBlog.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\Contacts.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.netbar\Bin\NetBar.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.paipai\Bin\PaiPai.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.vas\Bin\VAS.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.wireless\Bin\Wireless.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.paipaigift\Bin\PaiPaiGift.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.qqshow\Bin\QQShow.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.qzone\Bin\Qzone.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.audiovideo\Bin\AudioVideo.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.soso\Bin\Soso.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.weather\Bin\Weather.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\InformationBox.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.crm\Bin\CRM.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.advertisement\Bin\Advertisement.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.mail\Bin\Mail.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.memo\Bin\Memo.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.qqgame\Bin\QQGame.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.qqpet\Bin\QQPet.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.qqring\Bin\QQRing.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.qqvip\Bin\QQVip.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.qqwebsite\Bin\QQWebsite.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.today\Bin\Today.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\ContactInfoFrame.dll]  [Tencent, 1, 50, 1720, 0]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 90, 0, 1]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.qqshow\Bin\FlashAvatarDll.dll]  [Tencent, 1.50.1720.0]
    [C:\WINDOWS\system32\Macromed\Flash\Flash10i.ocx]  [Adobe Systems, Inc., 10,1,82,76]
    [D:\Program Files\Tencent\QQ\Bin\vqqsdl.dll]  [Tencent, 5, 0, 3, 24]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.filetransfer\Bin\FileTransfer.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\MsgMgr.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\LongCnn.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.mmog\Bin\MMOG.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.qqlive\Bin\QQLive.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.qqmusic\Bin\QQMusic.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.taotao\Bin\taotao.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.gamelife\Bin\GameLife.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Plugin\com.tencent.sobar\Bin\SoBar.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\CustomFace.dll]  [Tencent, 1, 50, 1720, 0]
    [D:\Program Files\Tencent\QQ\Bin\AddrSearch.dll]  [Tencent, 2, 3, 12, 11]
    [C:\WINDOWS\system32\QQPINYIN.IME]  [Tencent, 3.2.805.201]
    [D:\Program Files\Tencent\QQ\Bin\SoftUpgrade.dll]  [Tencent, 1.0 Beta1 Build 109]
    [D:\Program Files\Tencent\QQ\Bin\KernelMisc.dll]  [Tencent, 1, 50, 1720, 0]
gototop
 

回复:顽固病毒无法清除,救助!!!!

[PID: 4272 / hh][d:\Program Files\Tencent\QQ\Bin\TXPlatform.exe]  [Tencent, 1, 50, 1720, 0]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [d:\Program Files\Tencent\QQ\Bin\TXPFProxy.dll]  [Tencent, 1, 50, 1720, 0]
[PID: 988 / hh][C:\WINDOWS\system32\conime.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
[PID: 5528 / hh][E:\Program Files\TTPlayer\TTPlayer.exe]  [Alen Soft, 5, 6, 3, 0]
    [E:\Program Files\TTPlayer\ttpcomm.dll]  [N/A, ]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [E:\Program Files\TTPlayer\ttpres.dll]  [Alen Soft, 5, 6, 3, 0]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.2.0]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 90, 0, 1]
    [E:\Program Files\TTPlayer\AddIn\ttp_flac.dll]  [N/A, ]
    [E:\Program Files\TTPlayer\AddIn\ttp_lrcsh.dll]  [N/A, ]
[PID: 5832 / hh][e:\Program Files\YouKu\iKu\iKuAcc.exe]  [Youku.com, 0.9.7.6]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.2.0]
[PID: 6100 / hh][e:\Program Files\YouKu\iKu\ikucmc.exe]  [Youku.com, 0.9.6.4]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.2.0]
[PID: 6052 / hh][E:\Thunder Network\Program\Thunder.exe]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\Program\XLI18NEX.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 1]
    [E:\Thunder Network\Program\libexpat.dll]  [N/A, ]
    [E:\Thunder Network\Program\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [E:\Thunder Network\Program\minizip.dll]  [N/A, ]
    [E:\Thunder Network\Program\zlib1.dll]  [, 1.2.3]
    [E:\Thunder Network\Program\MSVCP71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [E:\Thunder Network\Program\XLBugHandler.dll]  [深圳市迅雷网络技术有限公司, 2, 1, 0, 8]
    [E:\Thunder Network\Program\liblua.dll]  [N/A, ]
    [E:\Thunder Network\Program\XLGraphic.dll]  [N/A, ]
    [E:\Thunder Network\Program\libpng13.dll]  [, 1.2.38]
    [E:\Thunder Network\Program\UACTool.dll]  [N/A, ]
    [E:\Thunder Network\Program\XLLuaRuntime.dll]  [N/A, ]
    [E:\Thunder Network\Program\MFC71U.DLL]  [Microsoft Corporation, 7.10.6101.0]
    [E:\Thunder Network\Program\ATL71.DLL]  [Microsoft Corporation, 7.10.6101.0]
    [E:\Thunder Network\Program\sqlite3.dll]  [N/A, ]
    [E:\Thunder Network\Program\mini_unzip_dll.dll]  [N/A, ]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [E:\Thunder Network\Program\SkinEngine2.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\Program\XLGUIPlatform.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\Program\ThunderStorage.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\Program\Thunders.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\Program\download_interface.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 59]
    [E:\Thunder Network\Program\UpdateCtrl.dll]  [深圳市迅雷网络技术有限公司, 2, 8, 2, 221]
    [E:\Thunder Network\Program\DllNewTask.DLL]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\userdata\Components\Streamer\Streamer.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 0, 31]
    [E:\Thunder Network\Program\XLNetU.dll]  [深圳市迅雷网络技术有限公司, 1, 5, 2, 25]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.2.0]
    [E:\Thunder Network\Program\xl_client.dll]  [深圳市迅雷网络技术有限公司, 1, 11, 2, 29]
    [E:\Thunder Network\Program\xl_data.dll]  [深圳市迅雷网络技术有限公司, 1, 11, 2, 29]
    [E:\Thunder Network\Program\asyn_frame.dll]  [深圳市迅雷网络技术有限公司, 1, 4, 2, 41]
    [E:\Thunder Network\Program\mp.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 7]
    [E:\Thunder Network\Program\dl_peer_id.dll]  [深圳市迅雷网络技术有限公司, 3, 1, 2, 14]
    [E:\Thunder Network\Program\xl_stat_client.dll]  [ShenZhen Thunder Networking Technologies Ltd., 1.1.0.32]
    [E:\Thunder Network\Program\XLGUIDevEnv.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\Program\GougouSearch.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\Program\GBLCategory.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\Program\XLWebDownload.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\ComDlls\ThunderAgent5.9.27.1554.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\userdata\Components\BaseCommunity\BaseCommunity.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 158]
    [E:\Thunder Network\Program\libjpeg6b.dll]  [N/A, ]
    [E:\Thunder Network\Program\giflib4.dll]  [N/A, ]
    [E:\Thunder Network\Program\http.dll]  [深圳市迅雷网络技术有限公司, 1.0.2.15]
    [E:\Thunder Network\Program\XLCP.dll]  [深圳市迅雷网络技术有限公司, 1.0.2.26]
    [E:\Thunder Network\Program\XLUser.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 98]
    [E:\Thunder Network\Program\BaseIM.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 14]
    [E:\Thunder Network\Program\MsgBox.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 63]
    [E:\Thunder Network\userdata\Components\InMedia\MediaAddin.dll]  [深圳市迅雷网络技术有限公司, 3, 1, 7, 83]
    [E:\Thunder Network\userdata\Components\ResWorker\DsXlCom.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 12]
    [E:\Thunder Network\userdata\Components\ResWorker\DataProcessor_01.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 1, 6]
    [E:\Thunder Network\userdata\Components\ResWorker\MediaWorker.dll]  [深圳市迅雷网络技术有限公司, 1, 2, 0, 23]
    [E:\Thunder Network\userdata\Components\ResWorker\GSI.dll]  [深圳市迅雷网络技术有限公司, 1.0.0.1]
    [E:\Thunder Network\Program\FloatPanel.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\userdata\Components\Tips\TipsClient.dll]  [深圳市迅雷网络技术有限公司, 3, 0, 3, 159]
    [E:\Thunder Network\userdata\Components\Tips\XLSkin.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 1, 4]
    [E:\Thunder Network\userdata\Components\InMedia\iEmbed.dll]  [深圳市迅雷网络技术有限公司, 3, 4, 12, 141]
    [E:\Thunder Network\userdata\Components\InMedia\XLIPC.DLL]  [深圳市迅雷网络技术有限公司, 1, 0, 0, 4]
    [E:\Thunder Network\userdata\Components\XLMiniGameAdapter\XLMiniGameAdapter.dll]  [深圳市迅雷网络技术有限公司, 1.0.0.236]
    [E:\Thunder Network\userdata\Components\XLMiniGameAdapter\WinIPC.dll]  [深圳市迅雷网络技术有限公司, 1.0.0.6]
    [E:\Thunder Network\userdata\Components\Kankan\XMPPlugin.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 0, 55]
    [E:\Thunder Network\userdata\Components\Despise\Despise.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 39]
    [E:\Thunder Network\userdata\Components\BandWidth\BandWidth.dll]  [深圳市迅雷网络技术有限公司, 1.0.0.14]
    [E:\Thunder Network\userdata\Components\XLMediaCutter\XLMediaCutter.dll]  [深圳市迅雷网络技术有限公司, 4, 0, 0, 42]
    [C:\WINDOWS\system32\Macromed\Flash\Flash10i.ocx]  [Adobe Systems, Inc., 10,1,82,76]
    [E:\Thunder Network\userdata\Components\ThunderSoft\SoftUpdateNum.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 1, 3]
    [E:\Thunder Network\userdata\Components\ThunderSoft\SoftManager.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 25]
    [E:\Thunder Network\userdata\Components\ThunderSoft\Configure.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 8]
    [E:\Thunder Network\userdata\Components\ThunderSoft\Update.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 8]
    [E:\Thunder Network\userdata\Components\ThunderSoft\SoftIdentify.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 10]
    [E:\Thunder Network\userdata\Components\ThunderSoft\ThunderSoft.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 4, 47]
    [E:\Thunder Network\userdata\Components\ThunderSoft\KernelModule.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 0, 2]
    [E:\Thunder Network\userdata\Components\ThunderSoft\DrUIManager.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 0, 7]
gototop
 

回复:顽固病毒无法清除,救助!!!!

[PID: 5944 / hh][C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\ThunderService.exe]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 84]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\ATL71.DLL]  [Microsoft Corporation, 7.10.6101.0]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\MSVCP71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\XLBugHandler.dll]  [深圳市迅雷网络技术有限公司, 2, 1, 0, 8]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\download_engine.dll]  [深圳市迅雷网络技术有限公司, 3, 4, 2, 378]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\mp.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 7]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\XLCrypto.dll]  [N/A, ]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\UACTool.dll]  [N/A, ]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\UpdateCtrl.dll]  [深圳市迅雷网络技术有限公司, 2, 8, 2, 221]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\asyn_frame.dll]  [深圳市迅雷网络技术有限公司, 1, 4, 2, 41]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\backend_agent.dll]  [深圳市迅雷网络技术有限公司, 1, 1, 2, 40]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\zlib1.dll]  [, 1.2.3]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\ptl.dll]  [深圳市迅雷网络技术有限公司, 3, 2, 2, 90]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\dl_peer_id.dll]  [深圳市迅雷网络技术有限公司, 3, 1, 2, 14]
    [C:\Documents and Settings\All Users\Application Data\Thunder Network\Thunder_A30B0AF7-D81B-464e-B4E4-4B6DF996FB46_\Components\DownloadLibDll\md_p_1.0.33\xl_stat.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 9]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.2.0]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\p2p_upload.dll]  [深圳市迅雷网络技术有限公司, 1, 1, 2, 19]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\emule_shell.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 19]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\emule_kernel.dll]  [深圳市迅雷网络技术有限公司, 1, 2, 2, 91]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\fs.dll]  [深圳市迅雷网络技术有限公司, 1, 1, 2, 23]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\down_dispatcher.dll]  [深圳市迅雷网络技术有限公司, 1, 1, 2, 73]
    [C:\Documents and Settings\All Users\Application Data\Thunder Network\Thunder_A30B0AF7-D81B-464e-B4E4-4B6DF996FB46_\Components\DownloadLibDll\md_p_1.0.33\member_stat.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 8]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\al.dll]  [深圳市迅雷网络技术有限公司, 1, 1, 2, 87]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\minizip.dll]  [N/A, ]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\xlnet_manager.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 34]
    [C:\Documents and Settings\All Users\Application Data\Thunder Network\Thunder_A30B0AF7-D81B-464e-B4E4-4B6DF996FB46_\Components\DownloadLibDll\md_p_1.0.33\xl_mole.dll]  [深圳市迅雷网络技术有限公司, 1, 1, 2, 45]
    [C:\Documents and Settings\All Users\Application Data\Thunder Network\Thunder_A30B0AF7-D81B-464e-B4E4-4B6DF996FB46_\Components\DownloadLibDll\md_p_1.0.33\dphubt.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 36]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\p2p.dll]  [深圳市迅雷网络技术有限公司, 1, 1, 2, 113]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\stream.dll]  [深圳市迅雷网络技术有限公司, 2, 1, 2, 1130]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\p2sp.dll]  [深圳市迅雷网络技术有限公司, 1, 1, 2, 125]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\p2p_local_res.dll]  [深圳市迅雷网络技术有限公司, 1, 1, 2, 26]
    [C:\Documents and Settings\All Users\Application Data\Thunder Network\Thunder_A30B0AF7-D81B-464e-B4E4-4B6DF996FB46_\Components\DownloadLibDll\md_p_1.0.33\xldc.dll]  [深圳市迅雷网络技术有限公司, 4, 0, 2, 47]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\media_data.dll]  [深圳市迅雷网络技术有限公司, 1,0,2,11]
    [C:\Documents and Settings\All Users\Application Data\Thunder Network\Thunder_A30B0AF7-D81B-464e-B4E4-4B6DF996FB46_\Components\DownloadLibDll\md_p_1.0.33\sl.dll]  [深圳市迅雷网络技术有限公司, 1,0,2,5]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\task_report.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 6]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\bt_kernel.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 51]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\p2p_session_com.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 82]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\xl_data.dll]  [深圳市迅雷网络技术有限公司, 1, 11, 2, 29]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\liblua.dll]  [N/A, ]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\libexpat.dll]  [N/A, ]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\module_downloader.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 16]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\mini_unzip_dll.dll]  [N/A, ]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\p2p_cloud.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 24]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\p2ptl2.dll]  [深圳市迅雷网络技术有限公司, 1, 2, 2, 14]
    [C:\Program Files\Common Files\Thunder Network\DS\Ver1\1.0.2.84\bt_shell.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 17]
    [C:\Documents and Settings\All Users\Application Data\Thunder Network\Thunder_A30B0AF7-D81B-464e-B4E4-4B6DF996FB46_\Components\DownloadLibDll\md_p_1.0.33\xldcsubtask.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 32]
    [C:\Documents and Settings\All Users\Application Data\Thunder Network\Thunder_A30B0AF7-D81B-464e-B4E4-4B6DF996FB46_\Components\DownloadLibDll\md_p_1.0.33\xldcagent.dll]  [深圳市迅雷网络技术有限公司, 1, 1, 2, 24]
    [C:\Documents and Settings\All Users\Application Data\Thunder Network\Thunder_A30B0AF7-D81B-464e-B4E4-4B6DF996FB46_\Components\DownloadLibDll\md_p_1.0.33\bd.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 2, 22]
[PID: 5592 / hh][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kdump.dll]  [Kingsoft Corporation, 2010,08,24,1353]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [d:\Kingsoft\webshield\kswbc.dll]  [Kingsoft Corporation, 2010,08,25,13]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.2.0]
[PID: 7864 / hh][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kdump.dll]  [Kingsoft Corporation, 2010,08,24,1353]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [d:\Kingsoft\webshield\kswbc.dll]  [Kingsoft Corporation, 2010,08,25,13]
    [E:\Program Files\Internet Download Manager\IDMIECC.dll]  [Tonec Inc., 5, 19, 1, 0]
    [E:\Thunder Network\ComDlls\TDMediaDetector5.9.27.1554.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\ComDlls\ATL71.DLL]  [Microsoft Corporation, 7.10.6101.0]
    [E:\Thunder Network\ComDlls\MSVCP71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [E:\Thunder Network\ComDlls\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [E:\easyMule\modules\IE2EM.dll]  [VeryCD.com, 1.0.0.1]
    [E:\Thunder Network\Program\EmbedDetectNow.dll]  [Xunlei, 1, 0, 1, 45]
    [E:\Thunder Network\ComDlls\xunleiBHO_Now.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\ComDlls\zlib1.dll]  [, 1.2.3]
    [E:\Thunder Network\ComDlls\libexpat.dll]  [N/A, ]
    [E:\Thunder Network\ComDlls\ThunderAgent5.9.27.1554.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\userdata\Components\ResWorker\DsBho_01.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 0, 33]
    [E:\Thunder Network\userdata\Components\ResWorker\DataProcessor_01.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 1, 6]
    [E:\Program Files\Internet Download Manager\idmmkb.dll]  [Tonec Inc., 5, 16, 1, 0]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.2.0]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\WINDOWS\system32\QQPINYIN.IME]  [Tencent, 3.2.805.201]
[PID: 5752 / hh][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kdump.dll]  [Kingsoft Corporation, 2010,08,24,1353]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [d:\Kingsoft\webshield\kswbc.dll]  [Kingsoft Corporation, 2010,08,25,13]
    [E:\Program Files\Internet Download Manager\IDMIECC.dll]  [Tonec Inc., 5, 19, 1, 0]
    [E:\Thunder Network\ComDlls\TDMediaDetector5.9.27.1554.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\ComDlls\ATL71.DLL]  [Microsoft Corporation, 7.10.6101.0]
    [E:\Thunder Network\ComDlls\MSVCP71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [E:\Thunder Network\ComDlls\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [E:\Thunder Network\ComDlls\xunleiBHO_Now.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\ComDlls\zlib1.dll]  [, 1.2.3]
    [E:\Thunder Network\ComDlls\libexpat.dll]  [N/A, ]
    [E:\Thunder Network\userdata\Components\ResWorker\DsBho_01.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 0, 33]
    [E:\Thunder Network\userdata\Components\ResWorker\DataProcessor_01.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 1, 6]
    [E:\Program Files\Internet Download Manager\idmmkb.dll]  [Tonec Inc., 5, 16, 1, 0]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.2.0]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 90, 0, 1]
    [E:\easyMule\modules\IE2EM.dll]  [VeryCD.com, 1.0.0.1]
    [E:\Thunder Network\Program\EmbedDetectNow.dll]  [Xunlei, 1, 0, 1, 45]
    [E:\Thunder Network\ComDlls\ThunderAgent5.9.27.1554.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [C:\WINDOWS\system32\Macromed\Flash\Flash10i.ocx]  [Adobe Systems, Inc., 10,1,82,76]
    [E:\Program Files\Internet Download Manager\idmftype.dll]  [Tonec Inc., 5, 0, 1, 0]
[PID: 2340 / hh][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kdump.dll]  [Kingsoft Corporation, 2010,08,24,1353]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [d:\Kingsoft\webshield\kswbc.dll]  [Kingsoft Corporation, 2010,08,25,13]
    [E:\Program Files\Internet Download Manager\IDMIECC.dll]  [Tonec Inc., 5, 19, 1, 0]
    [E:\Thunder Network\ComDlls\TDMediaDetector5.9.27.1554.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\ComDlls\ATL71.DLL]  [Microsoft Corporation, 7.10.6101.0]
    [E:\Thunder Network\ComDlls\MSVCP71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [E:\Thunder Network\ComDlls\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [E:\easyMule\modules\IE2EM.dll]  [VeryCD.com, 1.0.0.1]
    [E:\Thunder Network\Program\EmbedDetectNow.dll]  [Xunlei, 1, 0, 1, 45]
    [E:\Thunder Network\ComDlls\xunleiBHO_Now.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\ComDlls\zlib1.dll]  [, 1.2.3]
    [E:\Thunder Network\ComDlls\libexpat.dll]  [N/A, ]
    [E:\Thunder Network\ComDlls\ThunderAgent5.9.27.1554.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\userdata\Components\ResWorker\DsBho_01.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 0, 33]
    [E:\Thunder Network\userdata\Components\ResWorker\DataProcessor_01.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 1, 6]
    [E:\Program Files\Internet Download Manager\idmmkb.dll]  [Tonec Inc., 5, 16, 1, 0]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.2.0]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\WINDOWS\system32\QQPINYIN.IME]  [Tencent, 3.2.805.201]
[PID: 6160 / hh][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kdump.dll]  [Kingsoft Corporation, 2010,08,24,1353]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [d:\Kingsoft\webshield\kswbc.dll]  [Kingsoft Corporation, 2010,08,25,13]
    [E:\Program Files\Internet Download Manager\IDMIECC.dll]  [Tonec Inc., 5, 19, 1, 0]
    [E:\Thunder Network\ComDlls\TDMediaDetector5.9.27.1554.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\ComDlls\ATL71.DLL]  [Microsoft Corporation, 7.10.6101.0]
    [E:\Thunder Network\ComDlls\MSVCP71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [E:\Thunder Network\ComDlls\MSVCR71.dll]  [Microsoft Corporation, 7.10.6030.0]
    [E:\easyMule\modules\IE2EM.dll]  [VeryCD.com, 1.0.0.1]
    [E:\Thunder Network\Program\EmbedDetectNow.dll]  [Xunlei, 1, 0, 1, 45]
    [E:\Thunder Network\ComDlls\xunleiBHO_Now.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\ComDlls\zlib1.dll]  [, 1.2.3]
    [E:\Thunder Network\ComDlls\libexpat.dll]  [N/A, ]
    [E:\Thunder Network\ComDlls\ThunderAgent5.9.27.1554.dll]  [深圳市迅雷网络技术有限公司, 5,9,27,1554]
    [E:\Thunder Network\userdata\Components\ResWorker\DsBho_01.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 0, 33]
    [E:\Thunder Network\userdata\Components\ResWorker\DataProcessor_01.dll]  [深圳市迅雷网络技术有限公司, 1, 0, 1, 6]
    [E:\Program Files\Internet Download Manager\idmmkb.dll]  [Tonec Inc., 5, 16, 1, 0]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.2.0]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 90, 0, 1]
gototop
 

回复:顽固病毒无法清除,救助!!!!

[PID: 7188 / hh][E:\Program Files\Internet Download Manager\IDMan.exe]  [Tonec Inc., 5, 19, 2, 1]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.2.0]
    [E:\Program Files\Internet Download Manager\idmftype.dll]  [Tonec Inc., 5, 0, 1, 0]
[PID: 6792 / hh][E:\Program Files\Internet Download Manager\IEMonitor.exe]  [Tonec Inc., 5, 18, 4, 0]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [E:\Program Files\Internet Download Manager\idmmkb.dll]  [Tonec Inc., 5, 16, 1, 0]
[PID: 4520 / hh][C:\Program Files\WinRAR\WinRAR.exe]  [, ]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [C:\WINDOWS\system32\netprovcredman.dll]  [Intel(R) Corporation, 12, 0, 0, 0]
    [E:\Program Files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll]  [Nokia, 7, 1, 108, 0]
    [E:\Program Files\Nokia\Nokia PC Suite 7\NGSCM.DLL]  [Nokia, 7, 1, 156, 0]
    [E:\Program Files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_chi-sc.nlr]  [Nokia, 7, 1, 71, 0]
    [E:\Program Files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr]  [Nokia, 7, 1, 21, 0]
[PID: 3000 / hh][c:\Documents and Settings\hh\Local Settings\Temp\Rar$EX01.859\SReng2.8.2.1321版\运行助手.exe]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
[PID: 6704 / hh][c:\Documents and Settings\hh\Local Settings\Temp\Rar$EX01.859\SReng2.8.2.1321版\sr-engldr.exe]  [Smallfrogs Studio, 2.8.2.1321]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [D:\Program Files\KSafe\ksfmon.dll]  [Kingsoft Corporation., 1.2.2.1096]
    [C:\Program Files\Common Files\Kingsoft\kiscommon\DetectDllHijack.dll]  [Kingsoft Corporation, 2010,08,30,159]
    [d:\Kingsoft\webshield\kwsui.dll]  [Kingsoft Corporation, 2010,09,01,17]
    [d:\Kingsoft\webshield\kswebshield.dll]  [Kingsoft Corporation, 2010,08,28,15]
    [c:\Documents and Settings\hh\Local Settings\Temp\Rar$EX01.859\SReng2.8.2.1321版\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
    [C:\WINDOWS\system32\PrxerNsp.dll]  [Initex Software, 2, 90, 0, 1]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 2.0.2.0]
    [C:\WINDOWS\system32\PrxerDrv.dll]  [Initex Software, 2, 90, 0, 1]

==================================
文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  Error. []
.CHM  Error. ["hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
PROXIFIER MSAFD Tcpip [TCP/IP]
    C:\WINDOWS\system32\PrxerDrv.dll(Initex Software, Proxifier Winsock Layered Service Provider )
PROXIFIER LSP
    C:\WINDOWS\system32\PrxerDrv.dll(Initex Software, Proxifier Winsock Layered Service Provider )

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 2808, C:\PROGRAM FILES\KEYBOARD MANAGER\MANAGER UTILITY\KEYBOARDMANAGER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2612, C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3040, C:\PROGRAM FILES\INTEL\WIFI\BIN\ZCFGSVC.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1200, C:\PROGRAM FILES\COMMON FILES\INTEL\WIRELESSCOMMON\IFRMEWRK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 7188, E:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IDMAN.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 4520, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3000, C:\DOCUMENTS AND SETTINGS\HH\LOCAL SETTINGS\TEMP\RAR$EX01.859\SRENG2.8.2.1321版\运行助手.EXE]

==================================
计划任务
[已启用] AppleSoftwareUpdate.job
        C:\Program Files\Apple Software Update\SoftwareUpdate.exe

==================================
Windows 安全更新检查
Microsoft .NET Framework 版本 1.1,简体中文版
KB907417,  Office 2003 更新 (KB907417)
KB925850,  Windows Media Player 11
KB923618,  Office 2003 Service Pack 3 (SP3)
KB940157,  用于 Windows XP 的 Windows 搜索 4.0 (KB940157)
KB951748,  Windows XP 安全更新程序 (KB951748) MS08-037
KB950974,  Microsoft XP 安全更新程序 (KB950974) MS08-049
KB949810,  Office 正版增值计划通知 (KB949810)-CHS
KB958644,  Windows XP 安全更新程序 (KB958644) MS08-067
KB956802,  Windows XP 安全更新程序 (KB956802) MS08-071
KB909520,  Microsoft 基本智能卡加密服务提供程序包: x86 (KB909520)
KB923561,  Windows XP 安全更新程序 (KB923561) MS09-010
KB952004,  Windows XP 安全更新程序 (KB952004) MS09-012
KB951847,  Microsoft .NET Framework 3.5 Service Pack 1 和 .NET Framework 3.5 Family Update (KB951847) x86
KB951847,  Windows Live 软件包
KB982926,  Microsoft Silverlight (KB982926)
KB931125,  根证书更新 [2010 年 8 月] (KB931125)
KB982670,  用于 Windows XP x86 的 Microsoft .NET Framework 4 Client Profile (KB982670)
KB982671,  用于 Windows XP x86 的 Microsoft .NET Framework 4 (KB982671)
KB2291595,  Outlook 2003 垃圾邮件筛选器更新 (KB2291595)
KB890830,  Windows 恶意软件删除工具 - 2010 年 9 月 (KB890830)

==================================
API HOOK
RVA  错误: LoadLibraryA (危险等级: 一般,  被下面模块所HOOK: C:\WINDOWS\AppPatch\AcLayers.DLL)
RVA  错误: LoadLibraryExA (危险等级: 一般,  被下面模块所HOOK: C:\WINDOWS\AppPatch\AcLayers.DLL)
RVA  错误: LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: C:\WINDOWS\AppPatch\AcLayers.DLL)
RVA  错误: LoadLibraryW (危险等级: 一般,  被下面模块所HOOK: C:\WINDOWS\AppPatch\AcLayers.DLL)
入口点错误:CreateProcessA (危险等级: 高,  被下面模块所HOOK: 0x010D02F1)
入口点错误:CreateProcessW (危险等级: 高,  被下面模块所HOOK: 0x011002F1)
RVA  错误: GetProcAddress (危险等级: 一般,  被下面模块所HOOK: C:\WINDOWS\system32\ShimEng.dll)
入口点错误:ShellExecuteExW (危险等级: 高,  被下面模块所HOOK: 0x011502F1)
入口点错误:ShellExecuteW (危险等级: 高,  被下面模块所HOOK: 0x011402F1)

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT