瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 超级病毒,反病毒们,高手们快来帮我!!! 打倒病毒

123   2  /  3  页   跳转

超级病毒,反病毒们,高手们快来帮我!!! 打倒病毒

==================================
正在运行的进程
[PID: 624 / SYSTEM][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 712 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 736 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
[PID: 784 / SYSTEM][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 796 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 952 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1016 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1156 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1240 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1496 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1504 / Administrator][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
    [e:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [C:\PROGRA~1\baidu\bar\BaiduBar.dll]  [Baidu.com, Inc., 2, 0, 2, 58]
    [C:\Program Files\Acrobatchs\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
    [C:\WINDOWS\system32\nvcpl.dll]  [NVIDIA Corporation, 6.14.10.8185]
    [C:\WINDOWS\system32\NVRSZHC.DLL]  [NVIDIA Corporation, 6.14.10.8185]
    [C:\WINDOWS\system32\nvshell.dll]  [, ]
    [C:\WINDOWS\HKNTDLL.dll]  [N/A, ]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 1, 3, 1031]
[PID: 1748 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
    [C:\WINDOWS\system32\mdimon.dll]  [Microsoft Corporation, 11.3.1897.0]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll]  [Microsoft Corporation, 11.3.1897.0]
[PID: 1900 / SYSTEM][C:\Program Files\Lenovo\LiveUpdate\liveupdate.exe]  [新思软件技术有限公司, 3, 2, 5, 23]
    [C:\Program Files\Lenovo\LiveUpdate\HttpLink.dll]  [新思软件技术有限公司, 3, 2, 4, 7]
    [C:\Program Files\Lenovo\LiveUpdate\WINHTTP.dll]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\Lenovo\LiveUpdate\GdiImage.dll]  [N/A, ]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
[PID: 1988 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.8185]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
[PID: 252 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 396 / SYSTEM][C:\WINDOWS\system32\sysagent.exe]  [lenovo, 1, 0, 0, 0]
[PID: 1304 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1292 / Administrator][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5, 1, 0, 51]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
[PID: 1412 / Administrator][C:\WINDOWS\LHotkey.exe]  [Chicony, 1. 0. 0. 1]
    [C:\WINDOWS\HKNTDLL.dll]  [N/A, ]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
[PID: 1476 / Administrator][C:\WINDOWS\VM303_STI.EXE]  [Vimicro, 4, 3, 625, 61]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\WINDOWS\system32\VM303Prp.Ax]  [Vimicro, 4.3. 625.61]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 1632 / Administrator][F:\WINPENJR\Win32\pphidpad.exe]  [N/A, ]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
[PID: 1204 / Administrator][C:\Program Files\Rising\AntiSpyware\runiep.exe]  [Beijing Rising Technology Co., Ltd., 4.0.0.18]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
gototop
 

[PID: 1908 / Administrator][C:\Program Files\Tencent\QQLive\MiniQQLive.exe]  [Tencent, 5.01.3358.6]
    [C:\Program Files\Tencent\QQLive\XMLParser.dll]  [Tencent, 5.01.3358.6]
    [C:\Program Files\Tencent\QQLive\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Tencent\QQLive\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Tencent\QQLive\LiveUtlt.dll]  [Tencent, 5.01.3358.6]
    [C:\Program Files\Tencent\QQLive\log.dll]  [N/A, ]
    [C:\Program Files\Tencent\QQLive\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Tencent\QQLive\ExceptCatch.dll]  [Tencent, 5.01.3358.6]
    [C:\Program Files\Tencent\QQLive\Skin.dll]  [Tencent, 5.01.3358.6]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Tencent\QQLive\ADManage.dll]  [Tencent, 5.01.3358.6]
    [C:\Program Files\Tencent\QQLive\Encrypt.dll]  [Tencent, 5.01.3358.6]
    [C:\Program Files\Tencent\QQLive\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Tencent\QQLive\Proxy.dll]  [Tencent, 5.01.3358.6]
    [C:\Program Files\Tencent\QQLive\LiveAPI.dll]  [Tencent, 5.01.3358.6]
    [C:\Program Files\Tencent\QQLive\P2PDownload.dll]  [Tencent, 5.01.3358.6]
    [C:\Program Files\Tencent\QQLive\vqqsdl.dll]  [Tencent Technology (Shenzhen) Company Limited, 2, 0, 107, 6]
    [C:\Program Files\Tencent\QQLive\TNProxy.dll]  [Tencent Technology(Shenzhen) Company Limited, 2, 1, 101, 80]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 1, 3, 1031]
[PID: 2032 / Administrator][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3208]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
[PID: 2076 / Administrator][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
[PID: 2088 / Administrator][C:\Program Files\Skype\Phone\Skype.exe]  [, ]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
[PID: 2104 / Administrator][C:\Program Files\Messenger\msmsgs.exe]  [Microsoft Corporation, 4.7.3001]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2148 / Administrator][C:\Program Files\ChinaNet\VnetClient.exe]  [, 2006, 6, 30, 11]
    [C:\Program Files\ChinaNet\Communicate.dll]  [GDCN, 2006, 2, 15, 1]
    [C:\Program Files\ChinaNet\DialModule.dll]  [GDCN, 2006, 7, 25, 15]
    [C:\Program Files\ChinaNet\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
    [C:\PROGRA~1\ChinaNet\CLIENT~1.DLL]  [, 2004, 2, 28, 1]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\PROGRA~1\ChinaNet\PLUGIN~1.OCX]  [, 2006, 6, 2, 14]
    [C:\PROGRA~1\ChinaNet\sign.dll]  [0, 2004, 12, 1, 1]
    [C:\PROGRA~1\ChinaNet\ADVERT~1.OCX]  [, 2006, 2, 20, 1]
    [C:\PROGRA~1\ChinaNet\Gif89a.dll]  [, 2005, 6, 21, 1]
    [C:\PROGRA~1\ChinaNet\VnetBs.ocx]  [, 2004, 11, 18, 1]
    [C:\PROGRA~1\ChinaNet\VnetSkin.ocx]  [GDDC, 2005, 12, 21, 1]
    [C:\PROGRA~1\ChinaNet\DialogStyle.dll]  [, 1, 0, 0, 1]
    [C:\PROGRA~1\ChinaNet\BDSearch.ocx]  [gdcn, 2005, 12, 22, 1]
    [C:\PROGRA~1\ChinaNet\PageFram.ocx]  [Workgroup, 2006, 9, 21, 21]
    [C:\PROGRA~1\ChinaNet\AccPage.ocx]  [, 6, 12, 6, 11]
    [C:\PROGRA~1\ChinaNet\AccountMgr.dll]  [, 2006, 5, 26, 11]
    [C:\PROGRA~1\ChinaNet\Timer.ocx]  [, 2006, 12, 5, 17]
    [C:\PROGRA~1\ChinaNet\PLUGIN~2.OCX]  [, 2006, 4, 4, 1]
    [C:\PROGRA~1\ChinaNet\NEWMES~1.DLL]  [, 2006, 12, 5, 11]
    [C:\PROGRA~1\ChinaNet\PassCtrl.dll]  [GDCN, 2006, 3, 1, 16]
    [C:\WINDOWS\system32\wpcap.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\WINDOWS\system32\pthreadVC.dll]  [N/A, ]
    [C:\WINDOWS\system32\packet.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\PROGRA~1\ChinaNet\PlugPush.dll]  [, 2004, 12, 21, 1]
    [C:\PROGRA~1\ChinaNet\ALLINT~1.DLL]  [, 2006, 7, 19, 14]
    [C:\PROGRA~1\ChinaNet\VNETLO~1.OCX]  [, 2005, 10, 9, 1]
    [C:\PROGRA~1\ChinaNet\StatNum.dll]  [, 2006, 3, 1, 1]
    [C:\PROGRA~1\ChinaNet\VNETON~1.OCX]  [, 2005, 3, 2, 1]
    [C:\PROGRA~1\ChinaNet\ALLFUN~1.DLL]  [GDCN, 2006, 8, 23, 16]
    [C:\PROGRA~1\ChinaNet\VnetOptLog.dll]  [ , 2006, 5, 10, 14]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 1, 3, 1031]
[PID: 2188 / Administrator][C:\Documents and Settings\Administrator\My Documents\学习号\Lenovo\ZComService.exe]  [Lenovo, 3.4.0.1]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[PID: 1060 / Administrator][C:\Program Files\Skype\Phone\ContentFilter.exe]  [TOM Online Inc., 1.0.2.0]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 3364 / Administrator][E:\Program Files\Rising\Rav\RsAgent.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
    [E:\Program Files\Rising\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 3488 / Administrator][C:\WINDOWS\msagent\AgentSvr.exe]  [Microsoft Corporation, 2.00.0.3424]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 1, 3, 1031]
[PID: 3972 / Administrator][D:\Super Rabbit\MagicSet\sriecli.exe]  [Super Rabbit Soft, 7.76]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [D:\SUPERR~1\MagicSet\shlobj71.ocx]  [Sky Software (http://www.ssware.com), 7, 1, 0, 0]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 1, 3, 1031]
[PID: 1436 / Administrator][C:\Program Files\Rising\AntiSpyware\Ras.exe]  [Beijing Rising Technology Co., Ltd., 4.0.0.57]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
    [C:\Program Files\Rising\AntiSpyware\RasGui.dll]  [Beijing Rising Technology Co., Ltd., 2, 0, 0, 12]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Rising\AntiSpyware\engine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 24]
    [C:\Program Files\Rising\AntiSpyware\zip.dll]  [rising, 13, 0, 0, 1]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 1, 3, 1031]
[PID: 4012 / Administrator][C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe]  [Yahoo! China, 3, 2, 5, 1031]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 1, 3, 1031]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll]  [yahoo! china, 3, 7, 7, 1137]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 3, 1012]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\Program Files\Yahoo!\Assistant\yNotifier.dll]  [yahoo! china, 3, 0, 5, 1006]
[PID: 2664 / Administrator][C:\Program Files\Yahoo!\Assistant\yAssistSe.exe]  [Yahoo! China, 3, 1, 0, 1013]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 1, 3, 1031]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\Program Files\Yahoo!\Assistant\shell\yAssecblk.dll]  [Yahoo! China, 3, 2, 1, 1029]
    [C:\Program Files\Yahoo!\Assistant\shell\yMenuInfo.dll]  [Yahoo! China, 3, 0, 1, 1001]
    [C:\Program Files\Yahoo!\Assistant\shell\yIEAngel.dll]  [Yahoo! China, 3, 0, 4, 1005]
    [C:\Program Files\Yahoo!\Assistant\shell\yAsMenu.dll]  [Yahoo! China, 3, 0, 5, 1007]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
gototop
 

[PID: 2872 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 1, 3, 1031]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll]  [Yahoo! China, 3, 0, 3, 1004]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\yaLive.dll]  [yahoo! china, 3, 7, 7, 1137]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll]  [Yahoo! China, 3, 0, 3, 1012]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [D:\Super Rabbit\MagicSet\haokanbar.dll]  [Xiang Feng Technology, 2, 2, 0, 1612]
    [C:\PROGRA~1\baidu\bar\BaiduBar.dll]  [Baidu.com, Inc., 2, 0, 2, 58]
    [c:\program files\google\googletoolbar.dll]  [Google Inc., 2, 0, 113, 0]
    [C:\WINDOWS\system32\kakatool.dll]  [Beijing Rising Technology Co., Ltd., 4.0.0.4]
    [C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll]  [yahoo! china, 3, 4, 4, 1121]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ysearch.dll]  [Yahoo! China, 3, 2, 5, 1030]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasnoad.dll]  [yahoo! china, 3, 0, 4, 1006]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yzsNetProto.dll]  [Yahoo! China, 3, 0, 5, 1006]
    [C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll]  [Yahoo! China, 3, 1, 2, 1013]
    [C:\Program Files\Yahoo!\Assistant\Assist\yrss.dll]  [Yahoo! China, 3, 0, 8, 1009]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yaswiper.dll]  [Yahoo! China, 3, 1, 0, 1010]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasiesec.dll]  [Yahoo! China, 3, 1, 2, 1014]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YSETTI~1.DLL]  [yahoo! china, 3, 2, 8, 1042]
    [C:\Program Files\Yahoo!\Assistant\Assist\ymailp.dll]  [Yahoo! China, 3, 0, 7, 1013]
    [C:\Program Files\Yahoo!\Assistant\Assist\ymyweb.dll]  [Yahoo! China, 3, 0, 5, 1007]
    [C:\Program Files\Yahoo!\Assistant\Assist\ypagetr.dll]  [, 3, 0, 1, 1006]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll]  [Thunder Networking Technologies,LTD, 1.0.2.9]
    [C:\Program Files\TENCENT\SSPlus\SAddr.dll]  [Tencent, 5, 0, 1, 18]
    [C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll]  [yahoo! china, 3, 0, 7, 1009]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 3, 11]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DsBho_00.dll]  [, 1, 0, 0, 4]
    [C:\Program Files\Thunder Network\Thunder\Components\ResWorker\DataProcessor_00.dll]  [Thunder Networking Technologies,LTD, 1, 0, 0, 6]
    [c:\PROGRA~1\chinanet\VNETTR~1.DLL]  [, 2005, 4, 6, 1]
    [c:\PROGRA~1\chinanet\Communicate.dll]  [GDCN, 2006, 2, 15, 1]
    [C:\PROGRA~1\ChinaNet\CLIENT~1.DLL]  [, 2004, 2, 28, 1]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL]  [yahoo! china, 3, 0, 8, 1010]
    [C:\WINDOWS\system32\SSup.dll]  [TENCENT, 5, 0, 1, 17]
    [C:\Program Files\Yahoo!\Assistant\Assist\yflashdl.dll]  [Yahoo! China, 3, 0, 7, 1021]
    [C:\Program Files\Yahoo!\Assistant\Assist\yassist.dll]  [Yahoo! China, 3, 2, 2, 1028]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\HKNTDLL.dll]  [N/A, ]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\ThunderAgent_Now.dll]  [Thunder Networking Technologies,LTD, 5, 0, 3, 20]
[PID: 3812 / Administrator][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 1, 3, 1031]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
[PID: 2668 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX02.875\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll]  [Yahoo! China, 3, 1, 3, 1031]
    [C:\Program Files\Lenovo\网络爸爸\EagleH.dll]  [N/A, ]
    [C:\WINDOWS\system32\WINWB.IME]  [Microsoft, 4.00.950]
    [C:\Program Files\Rising\AntiSpyware\ieprot.dll]  [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX02.875\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
gototop
 

==================================
文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1412, C:\WINDOWS\LHOTKEY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1476, C:\WINDOWS\VM303_STI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1632, F:\WINPENJR\WIN32\PPHIDPAD.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1204, C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1908, C:\PROGRAM FILES\TENCENT\QQLIVE\MINIQQLIVE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2032, C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2148, C:\PROGRAM FILES\CHINANET\VNETCLIENT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2188, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\MY DOCUMENTS\学习号\LENOVO\ZCOMSERVICE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3364, E:\PROGRAM FILES\RISING\RAV\RSAGENT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3972, D:\SUPER RABBIT\MAGICSET\SRIECLI.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1436, C:\PROGRAM FILES\RISING\ANTISPYWARE\RAS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1436, C:\PROGRAM FILES\RISING\ANTISPYWARE\RAS.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3812, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
    [1640] C:\Program Files\Lenovo\网络爸爸\EagleSvr.exe

==================================


[/CODE]
gototop
 

删除注册表项目
<?{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><> [N/A]
<WPDShServiceObj><?{AAA288BA-9A4C-45B0-95D7-94D524869DB5}> [N/

删除服务
BF6AE772 / BF6AE772][Stopped/Auto Start]
<C:\WINDOWS\system32\EC143C79.EXE -a><Microsoft Corporation>

删除驱动服务
[kbjcsg / kbjcsg][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\kbjcsg.sys><N/A>

删除浏览器加载项
[]
{669751ED-D558-49AE-B01A-3B374CC7910E} <C:\WINDOWS\system32\SSup.dll, TENCENT>
[]
{F79B2338-A6E7-46D4-9202-422AA6E74F43} <C:\WINDOWS\EagleFlt.dll, N/A>

重启删除
C:\WINDOWS\system32\SSup.dll
C:\WINDOWS\system32\EC143C79.EXE
System32\drivers\kbjcsg.sys
:\WINDOWS\system32\SSup.dll
C:\WINDOWS\EagleFlt.dll



F:\WINPENJR\Win32\pphidpad.exe
gototop
 

是要我把你所说的文件删除吗?
那用什么来删呢?
谢谢.
gototop
 

引用:
【保护系统的贴子】是要我把你所说的文件删除吗?
那用什么来删呢?
谢谢.

………………

F:\WINPENJR\Win32\pphidpad.exe

上面这个可能是手写板的进程,请自己百度下或到对应目录下查看一下。
gototop
 

是指记事本吗?
另存为的后缀是什么?
是123.bat吗?
gototop
 

引用:
【保护系统的贴子】是指记事本吗?
另存为的后缀是什么?
是123.bat吗?
………………
手写板是一种用特殊的手写笔在一块特殊的板子上写字或画画,其数据立刻会在电脑显示器上同步响应的一种辅助设备,比较适合一些不会打字的同志(支持模糊识别,如果是写字,电脑上立刻以标准字体显示你所写的字)。
到下面的地址去看看手写板的样子吧:
http://product.pcpop.com/default.aspx?Dummy_ID=2&IngressID=Handle&BrandSN=00000&RefUrl=http://www.baidu.com/s?wd=%CA%D6%D0%B4%B0%E5&cl=3&BackUrl=http://product.pcpop.com/Handle/00000_1.html
gototop
 

那究竟怎样把病毒杀掉呢?是要把那文件删掉吗?
我想上传图片,让你们看一下现在杀毒软件打开的样子,但不知道如何上传
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT