瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【讨论】貌似中毒了额..瑞星和卡巴查不出 请高手费心指点~(附扫描报告)

123   3  /  3  页   跳转

【讨论】貌似中毒了额..瑞星和卡巴查不出 请高手费心指点~(附扫描报告)


2007-02-19,11:18:12

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <swg><C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe>  [(Verified)Google Inc.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <run><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <BigDog303><C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)>  [N/A]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <avp6_post_uninstall><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]

==================================
启动文件夹
[Adobe Reader Speed Launch]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk --> D:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [Adobe Systems Incorporated]><N>
[cmd]
  <C:\Documents and Settings\Queenya\「开始」菜单\程序\启动\cmd.lnk --> C:\WINDOWS\Temp\serlass.exe [N/A]><N>

==================================
服务
[F6EF7AE4 / F6EF7AE4][Stopped/Auto Start]
  <C:\WINDOWS\system32\F6EF7AE4.EXE -service><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>

==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[kl1 / kl1][Running/Disabled]
  <system32\drivers\kl1.sys><N/A>
[klif / klif][Running/]
  <2 - 系统找不到指定的文件。
><N/A>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[sptd / sptd][Running/Boot Start]
  <\SystemRoot\System32\Drivers\sptd.sys><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[vmfilter303 / vmfilter303][Running/Manual Start]
  <system32\drivers\vmfilter303.sys><Vimicro Corporation>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[AONI PC Cam(Vimicro301 Neptune) / ZSMC303][Running/Manual Start]
  <System32\Drivers\usbVM303.sys><Vimicro Corporation>

==================================
浏览器加载项
[快速搜索]
  {BF5DC4AE-258C-43d5-9D80-1F7ACD734DD8} <C:\WINDOWS\Temp\sjbbx.exe, N/A>
[Adobe PDF Reader Link Helper]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, N/A>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
  {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, N/A>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Google Toolbar Helper]
  {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, N/A>
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>

==================================
gototop
 

重启后打开我的电脑,工具,文件夹选项,查看,显示所有文件和文件夹,把“隐藏受保护的系统文件”的勾去掉删除
:\WINDOWS\system32\F6EF7AE4.EXE
这个文件夹所有文件
C:\WINDOWS\Temp
C:\DOCUME~1\Queenya\LOCALS~1\Temp
gototop
 

正在运行的进程
[PID: 532][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 620][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 644][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 688][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 700][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 856][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 904][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 980][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1068][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1124][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1292][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1472][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1836][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 336][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [d:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
[PID: 432][C:\WINDOWS\system32\wscntfy.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 692][C:\WINDOWS\VM303_STI.EXE]  [Vimicro, 4, 3, 625, 61]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\VM303Prp.Ax]  [Vimicro, 3, 6, 411, 13]
[PID: 1748][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3536]
[PID: 1756][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1760][C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe]  [Google Inc., 1, 2, 911, 3380]
    [C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\res_zh-CN.dll]  [Google Inc., 1, 2, 911, 3380]
    [C:\Program Files\Google\GoogleToolbarNotifier\1.2.911.3380\swg.dll]  [Google Inc., 1, 2, 911, 3380]
[PID: 3632][C:\DOCUME~1\Queenya\LOCALS~1\Temp\Rar$EX01.578\Iparmo\Iparmor\iparmor.exe]  [luosoft.com, 5.5.0.0]
    [C:\DOCUME~1\Queenya\LOCALS~1\Temp\Rar$EX01.578\Iparmo\Iparmor\getportlistxp.dll]  [, 1, 0, 0, 1]
    [C:\DOCUME~1\Queenya\LOCALS~1\Temp\Rar$EX01.578\Iparmo\Iparmor\hookhookdll.dll]  [N/A, N/A]
[PID: 3964][C:\Program Files\BitComet\BitComet.exe]  [www.BitComet.com, 0.82]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  [Adobe Systems, Inc., 9,0,16,0]
[PID: 2924][c:\program files\internet explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3656][C:\Program Files\Real\RealPlayer\realplay.exe]  [RealNetworks, Inc., 6.0.12.1506]
    [C:\WINDOWS\system32\PNCRT.dll]  [Real Networks, Inc, 6.0.0.0]
    [C:\Program Files\Common Files\Real\Common\objb3201.dll]  [RealNetworks, Inc., 0.1.0.6442]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpap3260.dll]  [RealNetworks, Inc., 6.0.9.3064]
    [C:\Program Files\Common Files\Real\Common\pnrs3260.dll]  [RealNetworks, Inc., 6.0.9.4093]
    [C:\Program Files\Real\RealPlayer\lang\cdplay_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\dbcomp_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\embed_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\gemctl_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\pngui_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\pdgenxfer_cn.dll]  [N/A, N/A]
    [C:\Program Files\Real\RealPlayer\lang\rjctl_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rjeq_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rjres_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rjskin_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rjviz_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rjfade_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rjdlg_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rjmisc_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rjprog_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rpapp_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rpclsvc_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rpclutil_cn.dll]  [RealNetworks, Inc., 6.0.12.299]
    [C:\Program Files\Real\RealPlayer\lang\rpdemand_cn.dll]  [RealNetworks, Inc., 6.0.12.299]
    [C:\Program Files\Real\RealPlayer\lang\rpdsplyr_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rpgutil_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rpmnpane_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rpplylst_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\rpwebctl_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\tcdinfo_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\tclsvc_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\tdwnmgr_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\tmp3_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\twave_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\teasdk_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\tearm_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\tmdedit_cn.dll]  [RealNetworks, Inc., 6.0.12.298]
    [C:\Program Files\Real\RealPlayer\lang\mydevices_cn.dll]  [RealNetworks, Inc., 6.0.12.299]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpcl3260.dll]  [RealNetworks, Inc., 6.0.9.3137]
    [C:\Program Files\Common Files\Real\RCAPlugins\uisy3201.dll]  [RealNetworks, Inc., 0.1.0.3858]
    [C:\Program Files\Common Files\Real\Plugins\zipf3260.dll]  [RealNetworks, Inc., 6.0.8.2575]
    [C:\Program Files\Common Files\Real\Plugins\smplfsys.dll]  [RealNetworks, Inc., 10.0.0.1989]
    [C:\Program Files\Common Files\Real\RCAPlugins\rpcontrols1.dll]  [RealNetworks, Inc., 6.0.1.2259]
    [C:\Program Files\Common Files\Real\Plugins\pxcb3210.dll]  [RealNetworks, Inc., 1.0.0.4020]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpmn3260.dll]  [RealNetworks, Inc., 6.0.9.2960]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpwe3260.dll]  [RealNetworks, Inc., 6.0.1.2303]
    [C:\Program Files\Common Files\Real\RCAPlugins\rpcontrols2.dll]  [RealNetworks, 6.0.1.2259]
    [C:\Program Files\Real\RealPlayer\rpplugins\rpms3260.dll]  [RealNetworks, Inc., 6.0.1.2297]
    [C:\Program Files\Real\RealPlayer\rpplugins\MPACore.dll]  [RealNetworks, Inc., 1.0.3.2316]
    [C:\Program Files\Real\RealPlayer\rpplugins\rppl3260.dll]  [RealNetworks, Inc., 6.0.1.2298]
    [C:\Program Files\Common Files\Real\Common\pngu3267.dll]  [RealNetworks, Inc., 6.7.0.2737]
    [C:\Program Files\Real\RealPlayer\rpplugins\myde3260.dll]  [RealNetworks, Inc., 6.0.10.2524]
    [C:\Program Files\Real\RealPlayer\rjwmapln.dll]  [RealNetworks, Inc., 6.0.8.1795]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\Real\Common\pnen3260.dll]  [RealNetworks, Inc., 10.0.0.1250]
    [C:\Program Files\Common Files\Real\Plugins\vsrlocal.dll]  [RealNetworks, Inc., 10.1.0.1147]
    [C:\Program Files\Common Files\Real\Plugins\vidsite.dll]  [RealNetworks, Inc., 10.0.0.1220]
    [C:\Program Files\Common Files\Real\Plugins\clntxres.dll]  [RealNetworks, Inc., 10.0.0.4106]
    [C:\Program Files\Common Files\Real\Plugins\smlfformat.dll]  [RealNetworks, Inc., 10.0.0.2081]
    [C:\Program Files\Real\RealPlayer\rpplugins\rjbe3260.dll]  [RealNetworks, Inc., 6.0.4.2299]
    [C:\Program Files\Common Files\Real\Plugins\ramfformat.dll]  [RealNetworks, Inc., 10.0.0.2446]
    [C:\Program Files\Common Files\Real\Plugins\smlrender.dll]  [RealNetworks, Inc., 10.0.0.1697]
    [C:\Program Files\Common Files\Real\Plugins\authmgr.dll]  [RealNetworks, Inc., 10.0.0.1654]
    [C:\Program Files\Common Files\Real\Common\rjbviz.dll]  [RealNetworks, Inc., 1.0.2.3917]
    [C:\Program Files\Common Files\Real\Codecs\hxltcolor.dll]  [RealNetworks, Inc., 10.0.0.1077]
    [C:\Program Files\Real\RealPlayer\rpplugprot.dll]  [RealNetworks, Inc., 6.0.10.2264]
    [C:\Program Files\Common Files\Real\Common\twebbrowse.dll]  [RealNetworks, Inc., 1.0.2.1619]
    [C:\Program Files\Common Files\Real\RCAPlugins\gemx3201.dll]  [RealNetworks, Inc., 0.1.0.5895]
    [C:\Program Files\Common Files\Real\Visualizations\Annabelle.rpv]  [RealNetworks, Inc., 1.0.0.2]
    [C:\Program Files\Real\RealPlayer\plugins\rjrmjpln.dll]  [RealNetworks, Inc., 1.0.3.2270]
    [C:\Program Files\Common Files\Real\Plugins\rmfformat.dll]  [RealNetworks, Inc., 10.0.0.1442]
    [C:\Program Files\Common Files\Real\Plugins\rarender.dll]  [RealNetworks, Inc., 10.0.0.1227]
    [C:\Program Files\Common Files\Real\Plugins\rvrender.dll]  [RealNetworks, Inc., 10.0.0.1611]
    [C:\Program Files\Common Files\Real\Update_OB\rnad3201.dll]  [RealNetworks, Inc., 0.1.0.3536]
    [C:\Program Files\Common Files\Real\RCAPlugins\gema3201.dll]  [RealNetworks, Inc., 0.1.0.3841]
    [C:\Program Files\Real\RealPlayer\rpplugins\rjbc3260.dll]  [RealNetworks, Inc., 6.0.1.2304]
    [C:\Program Files\Real\RealPlayer\tnetdtct.dll]  [RealNetworks, Inc., 1.0.3.2264]
    [C:\Program Files\Common Files\Real\Codecs\cook.dll]  [RealNetworks, Inc., 10.0.0.2313]
    [C:\Program Files\Common Files\Real\Codecs\RV40.DLL]  [RealNetworks, Inc., 10.0.0.1707]
    [C:\Program Files\Common Files\Real\Codecs\drvc.dll]  [RealNetworks, Inc., 10.0.0.1707]
[PID: 3576][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3500][d:\Program Files\WinRAR\WinRAR.exe]  [N/A, N/A]
[PID: 2228][C:\DOCUME~1\Queenya\LOCALS~1\Temp\Rar$EX00.375\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
gototop
 

:\WINDOWS\system32\F6EF7AE4.EXE 米有了...不见了。 ..我也米删除....
C:\WINDOWS\Temp
C:\DOCUME~1\Queenya\LOCALS~1\Temp
额..重启还素删不掉 ~
安全模式怀疑被破坏 ..卡巴已经被病毒挂掉瑞星已经被我删掉 现在除了IE主页 继续被劫http://www.china3q.com/index.htm?hh持外 有3个IE进程
gototop
 

PS:机器里貌似还有WORM.VIKING.BB的残余势力
由于空间限制 重装系统是下下策...OTL.............
gototop
 
123   3  /  3  页   跳转
页面顶部
Powered by Discuz!NT