瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我遇到的最变态的病毒,什么软件都试了,什么方法都用了,不行,附日志

1234   2  /  4  页   跳转

我遇到的最变态的病毒,什么软件都试了,什么方法都用了,不行,附日志

<\SystemRoot\System32\DRIVERS\aic78xx.sys><Microsoft Corporation>
[AliIde / AliIde]
  <\SystemRoot\System32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AMD K8 Processor Driver / AmdK8]
  <System32\DRIVERS\amdk8.sys><Microsoft Corporation>
[arc / arc]
  <\SystemRoot\system32\drivers\arc.sys><Adaptec, Inc.>
[asc / asc]
  <\SystemRoot\System32\DRIVERS\asc.sys><Advanced System Products, Inc.>
[asc3550 / asc3550]
  <\SystemRoot\System32\DRIVERS\asc3550.sys><Advanced System Products, Inc.>
[cd20xrnt / cd20xrnt]
  <C:\WINDOWS\SYSTEM32\DRIVERS\cd20xrnt.SYS><Microsoft Corporation>
[CmdIde / CmdIde]
  <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[dac2w2k / dac2w2k]
  <\SystemRoot\System32\DRIVERS\dac2w2k.sys><Mylex Corporation>
[dpti2o / dpti2o]
  <\SystemRoot\System32\DRIVERS\dpti2o.sys><Microsoft Corporation>
[elxstor / elxstor]
  <\SystemRoot\system32\drivers\elxstor.sys><Emulex>
[FASTSX / FASTSX]
  <\SystemRoot\System32\DRIVERS\FASTSX.SYS><Promise Technology, Inc.>
[fasttrak / fasttrak]
  <\SystemRoot\System32\DRIVERS\fasttrak.sys><Promise Technology, Inc.>
[fasttx2k / fasttx2k]
  <\SystemRoot\System32\DRIVERS\fasttx2k.sys><Promise Technology, Inc.>
[fasttx2k2 / fasttx2k2]
  <\SystemRoot\System32\DRIVERS\fasttx2k2.sys><Promise Technology, Inc.>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS]
  <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[HpCISSs / HpCISSs]
  <\SystemRoot\system32\drivers\hpcisss.sys><Hewlett-Packard Company>
[Hpt366 / Hpt366]
  <\SystemRoot\System32\DRIVERS\Hpt366.sys><Microsoft Corporation>
[HPT371 / HPT371]
  <\SystemRoot\System32\DRIVERS\HPT371.sys><HighPoint Technologies, Inc.>
[hpt374 / hpt374]
  <\SystemRoot\System32\DRIVERS\hpt374.sys><HighPoint Technologies, Inc.>
[hpt3xx / hpt3xx]
  <\SystemRoot\System32\DRIVERS\hpt3xx.sys><HighPoint Technologies, Inc.>
[hptmv / hptmv]
  <\SystemRoot\System32\DRIVERS\hptmv.sys><HighPoint Technologies, Inc.>
[hptpro / hptpro]
  <\SystemRoot\System32\DRIVERS\hptpro.sys><HighPoint Technologies, Inc.>
[Intel Integrated RAID / iaStor]
  <\SystemRoot\system32\drivers\iaStor.sys><Intel Corporation>
[ids00026 / ids00026]
  <\??\C:\Documents and Settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids00026.sys><Kaspersky Labs>
[iirsp / iirsp]
  <\SystemRoot\system32\drivers\iirsp.sys><Intel Corp./ICP vortex GmbH>
[ini910u / ini910u]
  <\SystemRoot\System32\DRIVERS\ini910u.sys><Microsoft Corporation>
[ITERAID_Service_Install / iteraid]
  <\SystemRoot\System32\DRIVERS\iteraid.sys><Integrated Technology Express, Inc.>
[Klick / Klick]
  <\SystemRoot\System32\drivers\klick.sys><Kaspersky Lab>
[Klif / Klif]
  <System32\drivers\klif.sys><Kaspersky Labs>
[Klin / Klin]
  <\SystemRoot\System32\drivers\klin.sys><Kaspersky Lab>
[Klmc / Klmc]
  <System32\drivers\klmc.sys><Kaspersky Lab>
[klstm / klstm]
  <\??\C:\Documents and Settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\klstm.sys><Kaspersky Lab>
[LSI_SAS / LSI_SAS]
  <\SystemRoot\system32\drivers\lsi_sas.sys><LSI Logic>
[LSI_SCSI / LSI_SCSI]
  <\SystemRoot\system32\drivers\lsi_scsi.sys><LSI Logic>
[m5228 / m5228]
  <\SystemRoot\System32\DRIVERS\m5228.sys><ALi Corporation.>
[m5281 / m5281]
  <\SystemRoot\system32\drivers\m5281.sys><ALi Corporation>
[MegaIDE / MegaIDE]
  <\SystemRoot\System32\DRIVERS\MegaIDE.sys><LSI Logic Corporation.>
[megasas / megasas]
  <\SystemRoot\system32\drivers\megasas.sys><LSI Logic Corporation>
[mraid2k / mraid2k]
  <\SystemRoot\System32\DRIVERS\mraid2k.sys><American Megatrends, Inc.>
[mraid35x / mraid35x]
  <\SystemRoot\System32\DRIVERS\mraid35x.sys><American Megatrends Inc.>
[nfrd960 / nfrd960]
  <\SystemRoot\system32\drivers\nfrd960.sys><IBM Corporation>
[NetGroup Packet Filter Driver / NPF]
  <system32\drivers\npf.sys><Politecnico di Torino>
[npkcrypt / npkcrypt]
  <\??\C:\Program Files\QQ2005\npkcrypt.sys><INCA Internet Co., Ltd.>
[npkycryp / npkycryp]
  <\??\C:\Program Files\QQ2005\npkycryp.sys><N/A>
[nv / nv]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Intel SCSI Controller / NvAtaBus]
  <\SystemRoot\System32\DRIVERS\NVATABUS.SYS><NVIDIA Corporation>
[NVIDIA nForce(tm) RAID Class Driver / nvraid]
  <\SystemRoot\system32\DRIVERS\nvraid.sys><NVIDIA Corporation>
[PNP649R / PNP649R]
  <\SystemRoot\System32\DRIVERS\PNP649R.SYS><CMD Technology, Inc.>
[SiI 680 ATA Controller / Pnp680]
  <\SystemRoot\System32\DRIVERS\pnp680.sys><Silicon Image, Inc.>
[Silicon Image SiI 0680 Medley Raid Controller / Pnp680r]
  <\SystemRoot\System32\DRIVERS\pnp680r.sys><Silicon Image, Inc>
[Direct Parallel Link Driver / Ptilink]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[ql1080 / ql1080]
  <\SystemRoot\System32\DRIVERS\ql1080.sys><QLogic Corporation>
[Ql10wnt / Ql10wnt]
  <\SystemRoot\System32\DRIVERS\ql10wnt.sys><Microsoft Corporation>
[ql12160 / ql12160]
  <\SystemRoot\System32\DRIVERS\ql12160.sys><QLogic Corporation>
[ql1280 / ql1280]
  <\SystemRoot\System32\DRIVERS\ql1280.sys><QLogic Corporation>
[QLogic Fibre Channel SCSI Miniport Driver / ql2300]
  <\SystemRoot\system32\drivers\ql2300.sys><QLogic Corporation>
[RAIDSRC / RAIDSRC]
  <\SystemRoot\System32\DRIVERS\RAIDSRC.SYS><Intel/ICP>
[Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp]
  <system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
[S150SX8 / S150SX8]
  <\SystemRoot\System32\DRIVERS\S150SX8.SYS><Promise Technology, Inc.>
[Secdrv / Secdrv]
  <system32\DRIVERS\secdrv.sys><N/A>
[SiI-3512 SATALink Controller / SI3112]
  <\SystemRoot\System32\DRIVERS\SI3112.sys><Silicon Image, Inc.>
[Silicon Image SiI 3512 SATARaid Controller / SI3112r]
  <\SystemRoot\system32\drivers\SI3112r.sys><Silicon Image, Inc>
[SiI-3114 SATALink Controller / SI3114]
  <\SystemRoot\System32\DRIVERS\SI3114.sys><Silicon Image, Inc.>
[SiI-3114 SATARaid Controller / SI3114r]
gototop
 

<\SystemRoot\System32\DRIVERS\SI3114R.sys><Silicon Image, Inc>
[SiI-3124 SATALink Controller / SI3124]
  <\SystemRoot\System32\DRIVERS\SI3124.sys><Silicon Image, Inc.>
[SiI-3124 SATARaid Controller / SI3124r]
  <\SystemRoot\System32\DRIVERS\SI3124R.sys><Silicon Image, Inc>
[SATALink driver accelerator / SiFilter]
  <\SystemRoot\System32\DRIVERS\SiWinAcc.sys><Silicon Image, Inc.>
[SISIDE / SISIDE]
  <\SystemRoot\System32\DRIVERS\SISIDE.SYS><Silicon Integrated Systems Corp.>
[SiSRaid / SiSRaid]
  <\SystemRoot\System32\DRIVERS\SiSRaid.sys><Silicon Integrated Systems>
[SiSRaid1 / SiSRaid1]
  <\SystemRoot\System32\DRIVERS\SiSRaid1.sys><Silicon Integrated Systems>
[SISRAIDS / SISRAIDS]
  <\SystemRoot\System32\DRIVERS\SISRAIDS.SYS><Silicon Integrated Systems Corp>
[USB PC Camera (SNPSTD3) / SNPSTD3]
  <system32\DRIVERS\snpstd3.sys><>
[Sparrow / Sparrow]
  <\SystemRoot\System32\DRIVERS\sparrow.sys><Adaptec, Inc.>
[sptrak / sptrak]
  <\SystemRoot\System32\DRIVERS\sptrak.sys><Promise Technology, Inc.>
[symc810 / symc810]
  <\SystemRoot\System32\DRIVERS\symc810.sys><Symbios Logic Inc.>
[symc8xx / symc8xx]
  <\SystemRoot\System32\DRIVERS\symc8xx.sys><LSI Logic>
[SYMMPI / SYMMPI]
  <\SystemRoot\System32\DRIVERS\SYMMPI.SYS><LSI Logic>
[sym_hi / sym_hi]
  <\SystemRoot\System32\DRIVERS\sym_hi.sys><LSI Logic>
[sym_u3 / sym_u3]
  <\SystemRoot\System32\DRIVERS\sym_u3.sys><LSI Logic>
[TCP/IP Protocol Driver / Tcpip]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[TosIde / TosIde]
  <\SystemRoot\System32\DRIVERS\toside.sys><Microsoft Corporation>
[TSP / TSP]
  <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Labs>
[UlSata / UlSata]
  <\SystemRoot\System32\DRIVERS\ulsata.sys><Promise Technology, Inc.>
[ULSATAS / ULSATAS]
  <\SystemRoot\System32\DRIVERS\ULSATAS.SYS><Promise Technology, Inc.>
[ultra / ultra]
  <\SystemRoot\System32\DRIVERS\ultra.sys><Promise Technology, Inc.>
[ViaIde / ViaIde]
  <\SystemRoot\system32\DRIVERS\viaidexp.sys><VIA Technologies, Inc.>
[viamraid / viamraid]
  <\SystemRoot\system32\DRIVERS\viamraid.sys><VIA Technologies inc,.ltd>
[VIA ATA/ATAPI Host Controller / viapdsk]
  <\SystemRoot\System32\DRIVERS\viapdsk.sys><VIA Technologies, Inc.>
[viaraid / viaraid]
  <\SystemRoot\System32\DRIVERS\viaraid.sys><VIA Technologies inc,.ltd>
[viasraid / viasraid]
  <\SystemRoot\system32\drivers\viasraid.sys><VIA Technologies inc,.ltd>
[Vinyl AC'97 Audio Controller (WDM) / VIAudio]
  <system32\drivers\vinyl97.sys><VIA Technologies, Inc.>
[vmscsi / vmscsi]
  <\SystemRoot\system32\drivers\vmscsi.sys><VMware, Inc.>
[vsdatant / vsdatant]
  <System32\vsdatant.sys><Zone Labs, LLC>
[World Standard Teletext Codec / WSTCODEC]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[Vimicro USB PC Camera (ZC0301PL) / ZSMC301b]
  <System32\Drivers\usbVM31b.sys><VM>

==================================
浏览器加载项
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <D:\软件2\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\软件\Thunder5.4.1.230\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\软件2\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\软件2\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <D:\软件2\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <D:\软件\Thunder5.4.1.230\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[AUDIO__MP3 Moniker Class]
  {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\Flash85.ocx, Macromedia, Inc.>
[卡卡上网安全助手]
  {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\kakatool.dll, Beijing Rising Technology Co., Ltd.>
[&使用迅雷下载]
  <D:\软件\Thunder5.4.1.230\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <D:\软件\Thunder5.4.1.230\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
  <D:\软件2\QQ\AddToNetDisk.htm, N/A>
[使用影音传送带下载]
  <, N/A>
[使用影音传送带下载全部链接]
  <, N/A>
[添加到QQ自定义面板]
  <D:\软件2\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\软件2\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\软件2\QQ\SendMMS.htm, N/A>
[用比特精灵下载(&B)]
  <D:\软件\BitSpirit\bsurl.htm, N/A>

==================================
正在运行的进程
[PID: 564][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 620][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 644][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 688][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 700][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 864][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 928][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1056][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1140][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1260][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1408][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\软件\Thunder5.4.1.230\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [D:\软件2\FYGTCL~1\ftctry\Commenu.dll]  [Fygsoft and Microsoft, 2.0.0.0]
[PID: 1568][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 412][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.9147]
    [C:\WINDOWS\system32\nvapi.dll]  [N/A, N/A]
[PID: 576][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
gototop
 

[PID: 604][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 1892][C:\WINDOWS\system32\wscntfy.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1952][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1532][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3308][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3440][C:\Program Files\racer-henan-cnc\racer.exe]  [Putian Runway, 2, 0, 51, 92]
    [C:\Program Files\racer-henan-cnc\rwxre.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\nspr4.dll]  [Netscape Communications Corporation, 4.5 Beta]
    [C:\Program Files\racer-henan-cnc\xpcom.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\nss3.dll]  [Netscape Communications Corporation, 3.9.1]
    [C:\Program Files\racer-henan-cnc\softokn3.dll]  [Netscape Communications Corporation, 3.9.1]
    [C:\Program Files\racer-henan-cnc\gkgfx.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\js3250.dll]  [Netscape Communications Corporation, 4.0]
    [C:\Program Files\racer-henan-cnc\components\racer_base_comp.dll]  [Putian Runway, 2,0,47,87]
    [C:\Program Files\racer-henan-cnc\xpcom_compat.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\racer_base.dll]  [Putian Runway, 2,0,47,87]
    [C:\Program Files\racer-henan-cnc\components\pipnss.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\components\gklayout.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\components\jar50.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\components\xpcom_compat_c.dll]  [Mozilla Foundation, 1.7.3: 2005040616]
    [C:\Program Files\racer-henan-cnc\components\racer_ad_comp.dll]  [Putian Runway, 2,0,47,87]
    [C:\Program Files\racer-henan-cnc\components\racer_access_dhcpplus.dll]  [Putian Runway, 2,0,47,87]
    [C:\Program Files\racer-henan-cnc\dhcpplus.dll]  [北京润汇科技有限公司, 0, 13, 21, 45]
    [C:\Program Files\racer-henan-cnc\components\racer_nss4_comp.dll]  [Putian Runway, 2,0,47,87]
    [C:\Program Files\racer-henan-cnc\nss4.dll]  [北京普天润汇科技有限公司, 1, 0, 0, 3]
    [C:\Program Files\racer-henan-cnc\wpcap.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\Program Files\racer-henan-cnc\pthreadVC.dll]  [N/A, N/A]
    [C:\Program Files\racer-henan-cnc\packet.dll]  [Politecnico di Torino, 3, 0, 0, 18]
[PID: 2376][C:\Program Files\racer-henan-cnc\RacerKp.exe]  [北京润汇科技有限公司, 1, 0, 0, 1]
[PID: 3156][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\kakatool.dll]  [Beijing Rising Technology Co., Ltd., 2, 0, 0, 9]
    [D:\软件2\QQ\QQIEHelper.dll]  [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5]
    [D:\软件\Thunder5.4.1.230\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 2]
    [D:\软件3\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpscrch.dll]  [Kaspersky Lab, 1.0.227.342]
    [D:\软件3\Kaspersky Lab\Kaspersky Anti-Virus Personal\concl.dll]  [Kaspersky Lab, 1.0.227.3]
    [D:\软件3\Kaspersky Lab\Kaspersky Anti-Virus Personal\FSSync.dll]  [Kaspersky Lab, 5.0.227.0]
    [D:\软件3\Kaspersky Lab\Kaspersky Anti-Virus Personal\ipc.dll]  [Kaspersky Lab, 5.0.227.0]
    [C:\WINDOWS\system32\macromed\flash\Flash85.ocx]  [Macromedia, Inc., 8,5,0,133]
    [C:\WINDOWS\system32\JPWB.IME]  [常诚研制, 4.00.950]
[PID: 3564][D:\软件2\QQ\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [D:\软件2\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQ\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 370]
    [D:\软件2\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [D:\软件2\QQ\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQ\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [D:\软件2\QQ\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [D:\软件2\QQ\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [D:\软件2\QQ\QQMainFrame.dll]  [N/A, N/A]
    [D:\软件2\QQ\CQQApplication.dll]  [N/A, N/A]
    [D:\软件2\QQ\NewSkin.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQ\HostingMgr.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQ\CameraDll.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQ\MailSummary.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQ\QQSpace.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQ\QQAllInOne.dll]  [N/A, N/A]
    [D:\软件2\QQ\GroupLive.dll]  [N/A, N/A]
    [D:\软件2\QQ\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
gototop
 

[D:\软件2\QQ\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQ\QQSysMsgMng.dll]  [N/A, N/A]
    [D:\软件2\QQ\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQ\QQPlugin.dll]  [N/A, N/A]
    [D:\软件2\QQ\QQCustomFace.dll]  [N/A, N/A]
    [D:\软件2\QQ\QQPet.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQ\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [D:\软件2\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [C:\WINDOWS\system32\macromed\flash\Flash85.ocx]  [Macromedia, Inc., 8,5,0,133]
    [D:\软件2\QQ\QRingMng.dll]  [N/A, N/A]
    [D:\软件2\QQ\VqqModule.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQ\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [D:\软件2\QQ\VPortal.dll]  [, 1, 0, 0, 4]
    [D:\软件2\QQ\QQAvatar.dll]  [N/A, N/A]
    [D:\软件2\QQ\GroupConnection.dll]  [Tencent, 0, 3, 3, 5]
    [D:\软件2\QQ\QQSceneMng.dll]  [N/A, N/A]
    [D:\软件2\QQ\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [D:\软件2\QQ\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 240]
    [D:\软件2\QQ\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [D:\软件3\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpscrch.dll]  [Kaspersky Lab, 1.0.227.342]
    [D:\软件3\Kaspersky Lab\Kaspersky Anti-Virus Personal\concl.dll]  [Kaspersky Lab, 1.0.227.3]
    [D:\软件3\Kaspersky Lab\Kaspersky Anti-Virus Personal\FSSync.dll]  [Kaspersky Lab, 5.0.227.0]
    [D:\软件3\Kaspersky Lab\Kaspersky Anti-Virus Personal\ipc.dll]  [Kaspersky Lab, 5.0.227.0]
    [D:\软件2\QQ\BQQApplication.dll]  [N/A, N/A]
    [D:\软件2\QQ\QQMagicFace.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQ\QQZip.dll]  [tencent, 0, 3, 2, 4]
    [D:\软件2\QQGame\GamePublic.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQGame\GameLogCore.Dll]  [, 0, 10, 106, 13]
    [D:\软件2\QQGame\Core.dll]  [é??úêDìú???????ú?μí3óD?T1???, 0, 10, 0, 0]
    [D:\软件2\QQGame\NetCenter.dll]  [é??úêDìú???????ú?μí3óD?T1???, 0, 10, 0, 0]
    [D:\软件2\QQGame\CmdCenter.dll]  [深圳市腾讯计算机系统有限公司, 0, 10, 0, 0]
    [D:\软件2\QQGame\HelpDll.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQGame\ResEx.dll]  [深圳市腾讯计算机系统有限公司, 0, 10, 0, 0]
    [D:\软件2\QQGame\GameLogAidMgr.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQGame\COMToolKit.dll]  [, 1, 0, 0, 3]
    [D:\软件2\QQGame\QQGameAvatar.dll]  [深圳市腾讯计算机系统有限公司                                    Tencent Computer System Ltd., 0, 10, 0, 0]
    [C:\WINDOWS\system32\JPWB.IME]  [常诚研制, 4.00.950]
    [D:\软件2\QQ\QQFileTransfer.dll]  [Tencent, 0, 3, 3, 5]
    [D:\软件2\QQ\CommercesMng.dll]  [, 1, 0, 0, 1]
    [D:\软件2\QQ\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [D:\软件2\QQ\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 0, 6, 60]
[PID: 3628][D:\软件2\QQ\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [D:\软件2\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 3804][D:\软件3\[www.ylmf.com]BossKey.exe]  [The 6th day studio., 5.0.0.2]
[PID: 4032][D:\软件2\QQ\chatroom.exe]  [, 16, 7, 0, 1033]
    [D:\软件2\QQ\RoomPanel.dll]  [, 16, 7, 0, 1032]
    [D:\软件2\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [D:\软件3\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpscrch.dll]  [Kaspersky Lab, 1.0.227.342]
    [D:\软件3\Kaspersky Lab\Kaspersky Anti-Virus Personal\concl.dll]  [Kaspersky Lab, 1.0.227.3]
    [D:\软件3\Kaspersky Lab\Kaspersky Anti-Virus Personal\FSSync.dll]  [Kaspersky Lab, 5.0.227.0]
    [D:\软件3\Kaspersky Lab\Kaspersky Anti-Virus Personal\ipc.dll]  [Kaspersky Lab, 5.0.227.0]
    [C:\WINDOWS\system32\macromed\flash\Flash85.ocx]  [Macromedia, Inc., 8,5,0,133]
    [C:\WINDOWS\system32\JPWB.IME]  [常诚研制, 4.00.950]
[PID: 3608][D:\软件\ha_hijackthis_1991\sreng最新版\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. [C:\WINDOWS\hh.exe %1]
.HLP  Error. [C:\WINDOWS\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
61.135.150.114 www.8000qq.com
61.135.150.114 www.800f.net
61.135.150.114 www.1000sf.cn
61.135.150.114 jfengsha.comfb
61.135.150.114 www.1000yf.net
61.135.150.114 www.159sifu.com
61.135.150.114 www.9s5.cn
61.135.150.114 www.spbuy.net
61.135.150.114 www.wym.cn
61.135.150.114 www.cc4f.cn
61.135.150.114 mafan.net
61.135.150.114 www.6688qn.net
61.135.150.114 www.177z.com
61.135.150.114 www.131sf.net
61.135.150.114 tj.cntg.cn
61.135.150.114 www.spbuy.net
61.135.150.114 www.china45.net
61.135.150.114 www.ok22.com
61.135.150.114 www.17mi.net
61.135.150.114 www.sf8.com.cn
61.135.150.114 www.13177.com
61.135.150.114 ip94.fd4f.com
61.135.150.114 www.521it.net
61.135.150.114 www.ytdj.cn
61.135.150.114 www.fwoool.cn
61.135.150.114 www.5u37.net
61.135.150.114 www.87sf.com
61.135.150.114 ww1.swoool.com
61.135.150.114 wooljsz.cn
61.135.150.114 www.57wool.com
61.135.150.114 www.58816.com
61.135.150.114 www.spbuy.net
61.135.150.114 chuanqisjsf.blwool.com
61.135.150.114 www.woool188.com
61.135.150.114 www.sf1260.com
61.135.150.114 linf23.b12.cnwg.cn
61.135.150.114 www.wooolweb.com
61.135.150.114 www.yq520.net
61.135.150.114 www.cs222.com
61.135.150.114 www.ok22.com
61.135.150.114 www.7100sf.com
61.135.150.114 www.1352sf.com
61.135.150.114 www.458wool.cn
61.135.150.114 www.555woool.cn
61.135.150.114 www.kaosf.com
61.135.150.114 www.siyuwl.com
61.135.150.114 www.csjsz.cn
61.135.150.114 www.13177.com
61.135.150.114 www.458cs.com
61.135.150.114 www.5573.com
61.135.150.114 www.02945.com
61.135.150.114 www.pkchina.net
61.135.150.114 www.5181314.com
61.135.150.114 www.fknf2.com
61.135.150.114 www2.yoursf.com
61.135.150.114 www.paocs.com
61.135.150.114 www.sfboke.com
61.135.150.114 www.tt878.com
61.135.150.114 ww1.woool188.com
61.135.150.114 www.cs119.com
61.135.150.114 www.xdwoool.net
61.135.150.114 www.tt515.com
61.135.150.114 www.cs176.com
61.135.150.114 www.552sf.com
61.135.150.114 www.ipmir.com
61.135.150.114 www.898woool.com
61.135.150.114 www.qqks.com
61.135.150.114 www.368idc.com
61.135.150.114 www.csbaba.com
61.135.150.114 www.4745.cn
61.135.150.114 www.636400.com
61.135.150.114 www.oursf.cn
61.135.150.114 www.laiba173.com
61.135.150.114 www.14455.com
61.135.150.114 www.zheshan.net
61.135.150.114 zt.aaaaasf.cn
61.135.150.114 www.zt1314.cn
61.135.150.114 www.zt4f.net
61.135.150.114 www.zt002.com
61.135.150.114 www.amir3.com
61.135.150.114 www.sf1717.com
61.135.150.114 www.cq333.cn
61.135.150.114 www.3316.cn
61.135.150.114 www.sosmir3.com
61.135.150.114 www.95279.com
61.135.150.114 www.sf1788.com
61.135.150.114 www.4fboss.com
61.135.150.114 www.45net.net
61.135.150.114 www.ytdj.cn
61.135.150.114 www.laiba173.com
61.135.150.114 www.wow1314.com
61.135.150.114 www.zgwow.com
61.135.150.114 www.1000wow.net
61.135.150.114 www.gowowsf.com
61.135.150.114 www.wowsf.com
61.135.150.114 www.wxwow.com
61.135.150.114 520.xinwow.com
61.135.150.114 www.wowhelp.cn
61.135.150.114 www.800wow.com
61.135.150.114 www.56wow.com
61.135.150.114 www.45wow.com
61.135.150.114 www.sfhao123.net
61.135.150.114 www.lian2.cn
61.135.150.114 www.14455.com
61.135.150.114 www.sfgoogle.cn
61.135.150.114 www.45top.com
61.135.150.114 www.915mu.com
61.135.150.114 www.gm911.net
61.135.150.114 www.4000mu.com
61.135.150.114 www.99musf.com
61.135.150.114 www.mu45.com
61.135.150.114 www.369mu.com
61.135.150.114 www.525sf.com
61.135.150.114 www.2345w.com
61.135.150.114 www.3jsf.net
61.135.150.114 www.ttfsf.com
61.135.150.114 www.521ee.com
61.135.150.114 www.997j.com
61.135.150.114 www.wz4f.net
61.135.150.114 www.hott2.com
61.135.150.114 www.398q.com
61.135.150.114 www.tt1314.com
61.135.150.114 www.tt2sf.net
61.135.150.114 www.sifu114.com
61.135.150.114 www.2z2.cn
61.135.150.114 www.haosf.com
61.135.150.114 www.cqsf999.com
61.135.150.114 www.zhaosf.com
61.135.150.114 www.920666.com
61.135.150.114 www.450666.com
61.135.150.114 www.3000ok.com
61.135.150.114 www.3000ok.net
61.135.150.114 www.sf001.com
61.135.150.114 www.92045.com
61.135.150.114 www.45bang.com
61.135.150.114 www.30ok.com
61.135.150.114 www.cqsf999.com
61.135.150.114 www.sf123.com
61.135.150.114 www.sf920.com
61.135.150.114 www.99945.com
61.135.150.114 www.176sf.com
61.135.150.114 www.mir2mir2.com
61.135.150.114 www.33520.com
61.135.150.114 www.xp13.com
61.135.150.114 www.45yes.com
61.135.150.114 www.920666.com
61.135.150.114 www.450666.com
61.135.150.114 www.92095.com
61.135.150.114 www.17ww.com
61.135.150.114 www.4000sf.com
61.135.150.114 www.haouc.com
61.135.150.114 www.921uc.com
61.135.150.114 17126.uc999.com
61.135.150.114 www.45pao.com
61.135.150.114 www.177g.com
61.135.150.114 www.95217.com
61.135.150.114 www.2345sf.com

==================================
gototop
 

用冰刃查查有没有隐藏进程吧,
gototop
 

冰刃有是有,但是我不太懂啊,不会用
gototop
 

[Distributed Link Tracking Server / TrkWks]
<C:\WINDOWS\system32\svchost.exe -k netsvsc-->%SystemRoot%\system32\est.dll><Microsoft Corporation>
查查这一顶
gototop
 

我也问问~~~我家电脑老弹什么    (网络医院,在线问答)  怎么办啊~~???????????我快气死了~~~(重装系统没用的)
gototop
 

开始 运行 regedit  搜索npf.sys删除干净
-----------
运行 SRENG 启动项  驱动
隐藏微软

勾选NetGroup Packet Filter Driver / NPF]
<system32\drivers\npf.sys><Politecnico di Torino>
设置 点否删除
---------------------
重启后 在我的网盘 下载killbox删除
system32\drivers\npf.sys
删除前勾选 删除前结束进程

----------
SRENG 系统修复 文件关联
修复.CHM Error. [C:\WINDOWS\hh.exe %1]
.HLP Error. [C:\WINDOWS\winhlp32.exe %1]

-------
删除所有hosts文件

gototop
 

我问问我家电脑老弹(网络医院,在线问答)怎么办啊~~???????(重装系统也没用!)
gototop
 
1234   2  /  4  页   跳转
页面顶部
Powered by Discuz!NT