- 积分
- 18105
- 威望
- 35074
- 元宝
- 4
- 铜钱
- 16593
  
|
6楼
发表于 2008-9-22 10:34
| 只看该作者
==================================
正在运行的进程
[PID: 564][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 624][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 648][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 692][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 704][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 876][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 964][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\wrm32.dll] [N/A, ]
[PID: 1060][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\wrm32.dll] [N/A, ]
[PID: 1112][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\mshta.dll] [Microsoft Corporation, 7.00.5730.13 (longhorn(wmbla).070711-1130)]
[PID: 1400][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.8166.2]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.8166.2]
[PID: 1632][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
[C:\WINDOWS\system32\ecbyllfl.dll] [N/A, ]
[C:\WINDOWS\system32\avicapwm.dll] [N/A, ]
[C:\WINDOWS\system32\iedlemyw.dll] [N/A, ]
[C:\WINDOWS\system32\yabhgmla.dll] [N/A, ]
[C:\WINDOWS\system32\bkwmyndl.dll] [N/A, ]
[C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll] [Thunder Networking Technologies,LTD, 1.0.5.29]
[C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 96]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 20]
[C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_01.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 16]
[C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll] [Thunder Networking Technologies,LTD, 5, 0, 8, 74]
[C:\WINDOWS\system32\mshta.dll] [Microsoft Corporation, 7.00.5730.13 (longhorn(wmbla).070711-1130)]
[C:\WINDOWS\Fonts\Framdee.ttf] [N/A, ]
[C:\WINDOWS\AppPatch\AcXtrnel.sdb] [N/A, ]
[C:\WINDOWS\AppPatch\AcSpecf.dll] [N/A, ]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\wrm32.dll] [N/A, ]
[C:\WINDOWS\system32\kildh3l.dll] [N/A, ]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[PID: 1920][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\Update.dll] [N/A, ]
[C:\WINDOWS\system32\bkwmyndl.dll] [N/A, ]
[C:\WINDOWS\system32\yabhgmla.dll] [N/A, ]
[C:\WINDOWS\system32\iedlemyw.dll] [N/A, ]
[C:\WINDOWS\system32\avicapwm.dll] [N/A, ]
[C:\WINDOWS\system32\ecbyllfl.dll] [N/A, ]
[PID: 1944][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\bkwmyndl.dll] [N/A, ]
[C:\WINDOWS\system32\yabhgmla.dll] [N/A, ]
[C:\WINDOWS\system32\iedlemyw.dll] [N/A, ]
[C:\WINDOWS\system32\avicapwm.dll] [N/A, ]
[C:\WINDOWS\system32\ecbyllfl.dll] [N/A, ]
[PID: 1956][C:\Program Files\duowan\yy\DuoSpeak.exe] [广州多玩信息技术有限公司, 1.0.0.1]
[C:\Program Files\duowan\yy\BIZ.dll] [广州多玩信息技术有限公司, 1.0.0.1]
[C:\Program Files\duowan\yy\xgdi.dll] [N/A, ]
[C:\Program Files\duowan\yy\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\duowan\yy\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\duowan\yy\LCtrl.dll] [广州多玩信息技术有限公司, 1.0.0.1]
[C:\Program Files\duowan\yy\PUBFUNC.dll] [N/A, ]
[C:\Program Files\duowan\yy\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\duowan\yy\AudioCodec.dll] [N/A, ]
[C:\Program Files\duowan\yy\Timer.dll] [N/A, ]
[C:\Program Files\duowan\yy\log.dll] [广州多玩信息技术有限公司, 1.0.0.1]
[C:\Program Files\duowan\yy\audio.dll] [N/A, ]
[C:\Program Files\duowan\yy\llayout.dll] [N/A, ]
[C:\Program Files\duowan\yy\XML.dll] [N/A, ]
[C:\Program Files\duowan\yy\XEditor.dll] [广州多玩信息技术有限公司, 1.0.0.1]
[C:\Program Files\duowan\yy\XUUID.dll] [广州多玩信息技术有限公司, 1.0.0.1]
[C:\Program Files\duowan\yy\ExtraLayout.dll] [N/A, ]
[C:\Program Files\duowan\yy\LVDownloader.dll] [广州多玩信息技术有限公司, 1.0.0.1]
[C:\Program Files\duowan\yy\Smile.dll] [广州多玩信息技术有限公司, 1.0.0.1]
[C:\Program Files\duowan\yy\crashreport.dll] [N/A, ]
[C:\WINDOWS\system32\bkwmyndl.dll] [N/A, ]
[C:\WINDOWS\system32\yabhgmla.dll] [N/A, ]
[C:\WINDOWS\system32\iedlemyw.dll] [N/A, ]
[C:\WINDOWS\system32\avicapwm.dll] [N/A, ]
[C:\WINDOWS\system32\ecbyllfl.dll] [N/A, ]
[C:\Program Files\duowan\yy\protocol.dll] [N/A, ]
[C:\WINDOWS\system32\wrm32.dll] [N/A, ]
[C:\WINDOWS\system32\kildh3l.dll] [N/A, ]
[PID: 1996][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\wrm32.dll] [N/A, ]
[PID: 2040][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 6.14.11.6375]
[C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.6375]
[PID: 424][C:\WINDOWS\system32\taskmgr.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\bkwmyndl.dll] [N/A, ]
[C:\WINDOWS\system32\yabhgmla.dll] [N/A, ]
[C:\WINDOWS\system32\iedlemyw.dll] [N/A, ]
[C:\WINDOWS\system32\avicapwm.dll] [N/A, ]
[C:\WINDOWS\system32\ecbyllfl.dll] [N/A, ]
[C:\WINDOWS\system32\kildh3l.dll] [N/A, ]
[PID: 280][F:\新建文件夹 (2)\SRE796940c0.EXE] [Smallfrogs Studio, 2.6.16.1161]
[C:\WINDOWS\system32\kildh3l.dll] [N/A, ]
[C:\WINDOWS\system32\bkwmyndl.dll] [N/A, ]
[C:\WINDOWS\system32\yabhgmla.dll] [N/A, ]
[C:\WINDOWS\system32\iedlemyw.dll] [N/A, ]
[C:\WINDOWS\system32\avicapwm.dll] [N/A, ]
[C:\WINDOWS\system32\ecbyllfl.dll] [N/A, ]
[C:\WINDOWS\system32\wrm32.dll] [N/A, ] |
提问请注意详细描述现象、操作过程,如果是病毒报告,应说明病毒名,染毒文件路径、文件名等,什么现象都不描述只发一个日志的帖子将被直接删除。
系统还原是中毒后恢复最节约成本的好工具,新手请不要随意禁止系统还原
请新会员关注新手杀毒教程 |
|