瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我的妈呀,这什么病毒删都删不掉!

12   2  /  2  页   跳转

我的妈呀,这什么病毒删都删不掉!

[C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
    [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [D:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [D:\Program Files\Rising\Rav\Scanner.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
    [D:\Program Files\Rising\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [c:\documents and settings\唐飞\application data\ppstream\bin\1.0.0.2\vodrc.dll]  [ppstream.com, 1.0.0.2]
    [C:\WINDOWS\system32\ieframe.dll]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [C:\WINDOWS\system32\rsztdpm.dll]  [N/A, ]
    [C:\WINDOWS\system32\avwgdmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\avzxdmn.dll]  [N/A, ]
    [D:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [D:\Program Files\Rising\Rav\libload.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [D:\Program Files\Rising\Rav\VirusLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
    [D:\Program Files\Rising\Rav\MVEngine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
    [D:\Program Files\Rising\Rav\Engine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 30]
    [D:\Program Files\Rising\Rav\ScanExec.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [D:\Program Files\Rising\Rav\Unpacker.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 22]
    [D:\Program Files\Rising\Rav\UnExe.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
    [D:\Program Files\Rising\Rav\ScanEx.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 84]
    [D:\Program Files\Rising\Rav\ExtFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
    [D:\Program Files\Rising\Rav\PostTrt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
    [D:\Program Files\Rising\Rav\ScanMac.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
    [D:\Program Files\Rising\Rav\ScanSct.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 21]
    [D:\Program Files\Rising\Rav\ScanPack.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 25]
    [D:\Program Files\Rising\Rav\RsVM.dll]  [, 19, 0, 0, 22]
    [D:\Program Files\Rising\Rav\Uroutine.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 60]
    [D:\Program Files\Rising\Rav\Uscript.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
    [D:\Program Files\Rising\Rav\NvFile.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
    [D:\Program Files\Rising\Rav\ExtMail.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
    [D:\Program Files\Rising\Rav\ExtOLE.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
    [D:\Program Files\Rising\Rav\ScanNet.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [D:\Program Files\Rising\Rav\RsStore.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [D:\Program Files\Rising\Rav\RsLog.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 20]
    [D:\Program Files\Rising\Rav\posttrtx.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[PID: 2164 / 唐飞][D:\Program Files\Tencent\QQ\TIMPlatform.exe]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock Corporation, 5.01]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
    [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 22]
    [C:\Program Files\Internet Explorer\PLUGINS\WinSys88.Sys]  [N/A, ]
    [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
    [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [D:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 2412 / 唐飞][D:\Program Files\Tencent\QQ\QQ.exe]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\QQBaseClassInDll.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\QQHelperDll.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\BasicCtrlDll.dll]  [TENCENT, 7, 0, 431, 1723]
    [D:\Program Files\Tencent\QQ\MFC42.DLL]  [Microsoft Corporation, 6.00.8665.0]
    [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
    [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [C:\WINDOWS\system32\avzxdmn.dll]  [N/A, ]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock Corporation, 5.01]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
    [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 22]
    [C:\Program Files\Internet Explorer\PLUGINS\WinSys88.Sys]  [N/A, ]
    [D:\Program Files\Tencent\QQ\RICHED32.DLL]  [Microsoft Corporation, 5.00.2134.1]
    [D:\Program Files\Tencent\QQ\RICHED20.dll]  [Microsoft Corporation, 5.31.23.1218]
    [D:\Program Files\Tencent\QQ\QQAPI.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [D:\Program Files\Tencent\QQ\LoginCtrl.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\LoginCtrlRes.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\QQRes.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\QQMainFrame.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\gdiplus.dll]  [Microsoft Corporation, 5.1.3102.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\Program Files\Tencent\QQ\UnReadMsgMgr.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\CQQApplication.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [D:\Program Files\Tencent\QQ\NewSkin.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\MailSummary.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\QQKnowledgeSearch.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\QQAllInOne.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\SCCore.dll]  [TENCENT, 1, 6, 0, 2]
    [D:\Program Files\Tencent\QQ\CameraDll.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\QQSpace.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\vbscript.dll]  [Microsoft Corporation, 5.6.0.7426]
    [C:\WINDOWS\system32\avwgdmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\rsztdpm.dll]  [N/A, ]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [D:\Program Files\Tencent\QQ\QQGroupMng.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\UserDefinedHead.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\QQPlugin.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\QQConfigPlugin.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\QQAvatar.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\QQCustomFace.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\QQPet.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\LongConnection.dll]  [TENCENT, 7,0,431,1723]
    [C:\WINDOWS\system32\ieframe.dll]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [D:\Program Files\Tencent\QQ\QRingMng.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\PhoneAPI.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [D:\Program Files\Tencent\QQ\BQQApplication.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\QQSettingCtrl.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\QQSysMsgMng.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\CommercesMng.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [D:\Program Files\Tencent\QQ\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 310]
    [D:\Program Files\Tencent\QQ\AddrSearch.dll]  [腾讯科技(深圳)有限公司, 2, 1, 9, 95]
    [D:\Program Files\Tencent\QQ\ImageOle.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\QQLiveQMng.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\QQMagicFace.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQ\QQSceneMng.dll]  [N/A, ]
    [D:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [D:\Program Files\Tencent\QQ\GroupConnection.dll]  [TENCENT, 7,0,431,1723]
    [D:\Program Files\Tencent\QQGAME\GamePublic.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQGAME\Common\Utility.dll]  [N/A, ]
gototop
 

[D:\Program Files\Tencent\QQGAME\Factory.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQGAME\Logic\UIStyle.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQGAME\ProtHand\QQProt.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQGAME\Socket\NetMod.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\QQMsgFriendMng.dll]  [N/A, ]
    [D:\Program Files\Tencent\QQ\QQZip.dll]  [TENCENT, 7,0,431,1723]
    [C:\WINDOWS\system32\sidjazy.dll]  [N/A, ]
[PID: 896 / 唐飞][D:\Program Files\Maxthon2\Maxthon.exe]  [Maxthon International ltd., 2, 0, 3, 4020]
    [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
    [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [D:\Program Files\Maxthon2\MxExt.dll]  [N/A, ]
    [D:\Program Files\Maxthon2\mxpp.dll]  [Maxthon, 1, 0, 0, 61]
    [D:\Program Files\Maxthon2\MxSk.dll]  [Maxthon, 1, 0, 0, 119]
    [D:\Program Files\Maxthon2\MxProxy2.dll]  [, 1, 0, 0, 3528]
    [D:\Program Files\Maxthon2\IMxWebBoost.dll]  [Maxthon, 1, 0, 0, 67]
    [D:\Program Files\Maxthon2\mxdb.dll]  [N/A, ]
    [D:\Program Files\Maxthon2\mxsafe.dll]  [Maxthon, 1, 0, 0, 475]
    [C:\WINDOWS\system32\rsztdpm.dll]  [N/A, ]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock Corporation, 5.01]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
    [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 22]
    [C:\Program Files\Internet Explorer\PLUGINS\WinSys88.Sys]  [N/A, ]
    [D:\Program Files\Maxthon2\MxFav.dll]  [Maxthon, 1, 0, 0, 220]
    [D:\Program Files\Maxthon2\maxzlib.dll]  [, 1.2.3]
    [D:\Program Files\Maxthon2\mxtool.dll]  [, 1, 0, 0, 1]
    [D:\Program Files\Maxthon2\mxfeedU.dll]  [, 1, 0, 45, 82]
    [C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL]  [Microsoft Corporation, 11.0.5510]
    [C:\WINDOWS\system32\avwgdmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\avzxdmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\ieframe.dll]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [D:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
    [C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll]  [Microsoft Corporation, 2.0.50727.832 (QFE.050727-8300)]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx]  [Adobe Systems, Inc., 9,0,47,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\Program Files\Internet Explorer\ieproxy.dll]  [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
    [D:\Program Files\FlashGet\jccatch_1.dll]  [www.flashget.com, 1, 8, 4, 1007]
[PID: 1256 / 唐飞][D:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
    [C:\WINDOWS\system32\rsztdpm.dll]  [N/A, ]
    [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
    [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock Corporation, 5.01]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
    [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 22]
    [C:\Program Files\Internet Explorer\PLUGINS\WinSys88.Sys]  [N/A, ]
    [c:\documents and settings\唐飞\application data\ppstream\bin\1.0.0.2\vodrc.dll]  [ppstream.com, 1.0.0.2]
    [C:\WINDOWS\system32\wpdshext.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\PortableDeviceApi.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\Audiodev.dll]  [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
    [C:\WINDOWS\system32\ieframe.dll]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [C:\WINDOWS\system32\avzxdmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\avwgdmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\sidjazy.dll]  [N/A, ]
[PID: 3484 / 唐飞][G:\Temp\Rar$EX06.735\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [C:\WINDOWS\system32\Normaliz.dll]  [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
    [C:\WINDOWS\system32\iertutil.dll]  [Microsoft Corporation, 7.00.6000.16512 (vista_gdr.070625-1522)]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll]  [Stardock Corporation, 5.01]
    [D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll]  [Stardock.Net, Inc, 4.01]
    [C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll]  [TENCENT, 5, 0, 1, 22]
    [C:\Program Files\Internet Explorer\PLUGINS\WinSys88.Sys]  [N/A, ]
    [C:\WINDOWS\system32\avwgdmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\avzxdmn.dll]  [N/A, ]
    [C:\WINDOWS\system32\rsztdpm.dll]  [N/A, ]
    [G:\Temp\Rar$EX06.735\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
    [C:\WINDOWS\system32\sidjazy.dll]  [N/A, ]
gototop
 

==================================
文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  Error. [winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 1548, C:\WINDOWS\EXPLORER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1548, C:\WINDOWS\EXPLORER.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1988, D:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 360, D:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 360, D:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1984, D:\PROGRAM FILES\RISING\RAV\RAVMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1984, D:\PROGRAM FILES\RISING\RAV\RAVMON.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2216, C:\WINDOWS\IGM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2216, C:\WINDOWS\IGM.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2656, D:\PROGRAM FILES\TENCENT\QQDOWNLOAD\QDAUTOUPDATE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2656, D:\PROGRAM FILES\TENCENT\QQDOWNLOAD\QDAUTOUPDATE.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 400, D:\PROGRAM FILES\RISING\RAV\RAV.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 400, D:\PROGRAM FILES\RISING\RAV\RAV.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1256, D:\PROGRAM FILES\WINRAR\WINRAR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1256, D:\PROGRAM FILES\WINRAR\WINRAR.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A
gototop
 

提交完毕,请帮忙分析下,谢谢!
gototop
 

注意:删除病毒可能会具有一定的危险性 所以强烈建议操作前要把重要资料转移至非系统分区!
打开sreng
启动项目 注册表 删除如下项目
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Intel Chipset Monitor><G:\Temp\a17.exe> [N/A]
<VIPv3_Auto_Update><C:\WINDOWS\VIPv3\CheckForUpdates.exe> []
<WinSysM><C:\WINDOWS\IGM.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<MSDEG32><LYLoader.exe> [N/A]
<MSDWG32><LYLoadbr.exe> [N/A]
<MSDCG32 ><LYLeador.exe> [N/A]
<MSDOG32><LYLoador.exe> [N/A]
<MSDSG32><LYLoadar.exe> [N/A]
<MSDHG32><LYLoadhr.exe> [N/A]
<MSDQG32><LYLoadqr.exe> [N/A]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><sidjazy.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{0EA66AD2-CF26-2E23-532B-B292E22F3266}><C:\Program Files\Internet Explorer\PLUGINS\NewTemp.dll> [N/A]
<{4E32FA58-3453-FA2D-BC49-F340348ACCE4}><C:\WINDOWS\system32\rsmydpm.dll> [N/A]
<{E418E9ED-9221-4661-B1F3-4AA35BD83832}><C:\Program Files\Internet Explorer\PLUGINS\WinSys88.Sys> []
<{5B681598-AD5F-BC8C-77DC-748FAC8D3FB5}><C:\WINDOWS\system32\kafyezy.dll> [N/A]
<{2598FF45-DA60-F48A-BC43-10AC47853D52}><C:\WINDOWS\system32\rarjbpi.dll> [N/A]
<{2A321487-4977-D98A-C8D5-6488257545A2}><C:\WINDOWS\system32\kapjbzy.dll> [N/A]
<{4859245F-345D-BC13-AC4F-145D47DA34F4}><C:\WINDOWS\system32\avzxdmn.dll> []
<{18847374-8323-FADC-B443-4732ABCD3781}><C:\WINDOWS\system32\sidjazy.dll> []
<{3C87A354-ABC3-DEDE-FF33-3213FD7447C3}><C:\WINDOWS\system32\kvdxcma.dll> [N/A]
<{3A1247C1-53DA-FF43-ABD3-345F323A48D3}><C:\WINDOWS\system32\avwgcmn.dll> [N/A]
<{66650011-3344-6688-4899-345FABCD1566}><C:\WINDOWS\system32\ratbfpi.dll> [N/A]
<{2D561258-45F3-A451-F908-A258458226D2}><C:\WINDOWS\system32\kvdxsbma.dll> [N/A]
<{334345F1-DACF-3452-CB7D-4620F34A1533}><C:\WINDOWS\system32\rsztcpm.dll> [N/A]
<{2960356A-458E-DE24-BD50-268F589A56A2}><C:\WINDOWS\system32\avwlbmn.dll> [N/A]
<{5E32FA58-3453-FA2D-BC49-F340348ACCE5}><C:\WINDOWS\system32\rsmyepm.dll> [N/A]
<{434345F1-DACF-3452-CB7D-4620F34A1534}><C:\WINDOWS\system32\rsztdpm.dll> []
<{4A1247C1-53DA-FF43-ABD3-345F323A48D4}><C:\WINDOWS\system32\avwgdmn.dll> []

用SRENG扫描工具删除以下驱动程序
[mseam / mseam][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\mseam.sys><N/A>

重启计算机进入安全模式下删除
<Intel Chipset Monitor><G:\Temp\a17.exe> [N/A]
<WinSysM><C:\WINDOWS\IGM.exe> []
<MSDEG32><LYLoader.exe> [N/A]
<MSDWG32><LYLoadbr.exe> [N/A]
<MSDCG32 ><LYLeador.exe> [N/A]
<MSDOG32><LYLoador.exe> [N/A]
<MSDSG32><LYLoadar.exe> [N/A]
<MSDHG32><LYLoadhr.exe> [N/A]
<MSDQG32><LYLoadqr.exe> [N/A]
<{0EA66AD2-CF26-2E23-532B-B292E22F3266}><C:\Program Files\Internet Explorer\PLUGINS\NewTemp.dll> [N/A]
<{4E32FA58-3453-FA2D-BC49-F340348ACCE4}><C:\WINDOWS\system32\rsmydpm.dll> [N/A]
<{E418E9ED-9221-4661-B1F3-4AA35BD83832}><C:\Program Files\Internet Explorer\PLUGINS\WinSys88.Sys> []
<{5B681598-AD5F-BC8C-77DC-748FAC8D3FB5}><C:\WINDOWS\system32\kafyezy.dll> [N/A]
<{2598FF45-DA60-F48A-BC43-10AC47853D52}><C:\WINDOWS\system32\rarjbpi.dll> [N/A]
<{2A321487-4977-D98A-C8D5-6488257545A2}><C:\WINDOWS\system32\kapjbzy.dll> [N/A]
<{4859245F-345D-BC13-AC4F-145D47DA34F4}><C:\WINDOWS\system32\avzxdmn.dll> []
<{18847374-8323-FADC-B443-4732ABCD3781}><C:\WINDOWS\system32\sidjazy.dll> []
<{3C87A354-ABC3-DEDE-FF33-3213FD7447C3}><C:\WINDOWS\system32\kvdxcma.dll> [N/A]
<{3A1247C1-53DA-FF43-ABD3-345F323A48D3}><C:\WINDOWS\system32\avwgcmn.dll> [N/A]
<{66650011-3344-6688-4899-345FABCD1566}><C:\WINDOWS\system32\ratbfpi.dll> [N/A]
<{2D561258-45F3-A451-F908-A258458226D2}><C:\WINDOWS\system32\kvdxsbma.dll> [N/A]
<{334345F1-DACF-3452-CB7D-4620F34A1533}><C:\WINDOWS\system32\rsztcpm.dll> [N/A]
<{2960356A-458E-DE24-BD50-268F589A56A2}><C:\WINDOWS\system32\avwlbmn.dll> [N/A]
<{5E32FA58-3453-FA2D-BC49-F340348ACCE5}><C:\WINDOWS\system32\rsmyepm.dll> [N/A]
<{434345F1-DACF-3452-CB7D-4620F34A1534}><C:\WINDOWS\system32\rsztdpm.dll> []
<{4A1247C1-53DA-FF43-ABD3-345F323A48D4}><C:\WINDOWS\system32\avwgdmn.dll> []
<\??\C:\WINDOWS\system32\mseam.sys><N/A>
最后用SRENG扫描工具/系统修复,把winsock供应者修复。
gototop
 

生命不息,杀毒不止
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT