1234   3  /  4  页   跳转

这个网站好烦人(www.smscn.be)

RARSFX0的文件夹里有Group和hide.dll两个文件,可否删除,还是把整个文件夹删除。谢谢
gototop
 

把RARSFX0这个文件夹全部删了!这个不是个好东西!
gototop
 

可以?
gototop
 

建议您用KillBox来删除看看

KillBox 的下载地址:http://forum.ikaka.com/topic.asp?board=67&artid=5188931

详细介绍请看这一帖——原创之转帖--介绍 KillBox@Qoo 的使用
http://forum.ikaka.com/topic.asp?board=28&artid=5454397
gototop
 

下载KILL了 用它删除什么文件?
gototop
 

填上C:\WINDOWS\TEMP\RARSFX0\OK.exe

有没有文件,您就知道了。
gototop
 

没找到些文件 不存在或已删除
哈哈谢谢
gototop
 

能否在帮忙看下这个谢先

ProcessPIDCPUDescriptionCompany Name
CCENTER.EXE0xFFFE451FCCenterrising
RPCSS.EXE0xFFFD75C7Distributed COM ServicesMicrosoft Corporation
INTERNAT.EXE0xFFFCD617Keyboard Language Indicator AppletMicrosoft Corporation
DDHELP.EXE0xFFF98433Microsoft DirectX HelperMicrosoft Corporation
IEXPLORE.EXE0xFFFAA8EFMicrosoft Internet ExplorerMicrosoft Corporation
IEXPLORE.EXE0xFFFA623B9.52Microsoft Internet ExplorerMicrosoft Corporation
mmtask.tsk0xFFFEEC8FMultimedia background task support moduleMicrosoft Corporation
PSTORES.EXE0xFFF9E04BProtected storage serverMicrosoft Corporation
QQ.EXE0xFFF6B55B0.73QQTENCENT
RAVMOND.EXE0xFFFE55C70.63RavMonBeijing Rising Technology Co., Ltd.
RAVMON.EXE0xFFFE2F231.36RavMon Rising realtime monitor Beijing Rising Technology Co., Ltd.
RAVTIMER.EXE0xFFFC422F0.18RavTimerBeijing Rising Technology Co., Ltd.
REALSCHED.EXE0xFFFCF703RealNetworks SchedulerRealNetworks, Inc.
PROCEXP.EXE0xFFFA76EB6.17Sysinternals Process ExplorerSysinternals
Idle0x079.87System Idle Process
SYSTRAY.EXE0xFFFCA40FSystem Tray AppletMicrosoft Corporation
TIMPLATFORM.EXE0xFFF51B43TIMPlatformtencent
KERNEL32.DLL0xFF0F5E270.82Win32 Kernel core componentMicrosoft Corporation
MPREXE.EXE0xFFFFE167WIN32 Network Interface Service ProcessMicrosoft Corporation
MSGSRV32.EXE0xFFFF9337Windows 32-bit VxD Message ServerMicrosoft Corporation
EXPLORER.EXE0xFFFECB8F0.09Windows ExplorerMicrosoft Corporation
WMIEXE.EXE0xFFFBD093WMI service exe housingMicrosoft Corporation
FILMSG.EXE0xFFFB3F1B0.09费尔消息服务费尔安全实验室
FASTAIT.EXE0xFFF4EA4F0.54金山快译 2005金山软件股份有限公司

Process: TIMPLATFORM.EXE Pid: FFF51B43

TypeName
EventRPCSS_Initialized_Successfully
MappedFilefileAllocatorMutex
MappedFileDCOMSharedGlobals12321
MappedFilefileAllocatorMutex
MappedFilerpcrt4sharedmem
MutexOLESCMSRVREGLISTMUTEX
MutexOLESCMGETHANDLEMUTEX
MutexOLESCMROTMUTEX
MutexOleDfSharedMemoryMutex
MutexScmWIPMutex
Mutex{423319D9-FF97-429a-B049-D5FD6168C647}
MutexObjectResolverGlobalMutex
MutexMicrosoft RPC UUID Mutex
MutexOLESCMLOCKMUTEX
MutexOleCoSharedStateMtx
ProcessTIMPLATFORM.EXE(FFF51B43)
SemaphoreDocfileAllocatorMutex
SemaphoreDocfileAllocatorMutex


gototop
 

有什么问题吗?
gototop
 

我也不知道呀这是才扫的
好象还有病毒,前几天用费尔查的这几个

backdoor.hupigon.jn.ut.dll

MHTMLRedir.Exploit.c

Script.Htmlstring.Encode

Chm.Exefile.container.s

因为没注册  没有路径



gototop
 
1234   3  /  4  页   跳转
页面顶部
Powered by Discuz!NT