瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 中了灰鸽子,刚才用瑞星杀了,不过还有些疑问,请大侠帮忙看一下

123   3  /  3  页   跳转

中了灰鸽子,刚才用瑞星杀了,不过还有些疑问,请大侠帮忙看一下

浏览器加载项
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <E:\Program Files\珊瑚虫2006Beat1\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[相关站点]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[FlashGet]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <E:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <E:\PROGRA~1\FLASHGET\fgiebar.dll, Amaze Soft>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[System Requirements Lab Class]
  {BE833F39-1E0C-468C-BA70-25AAEE55775E} <C:\WINDOWS\Downloaded Program Files\sysreqlab.dll, Husdawg, LLC>
[WebActivater Control]
  {C661F36D-DF85-4EF4-83C7-E107B83D04B1} <C:\WINDOWS\System32\3DShowVM.ocx, QQ>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[使用网际快车下载]
  <E:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <E:\Program Files\FlashGet\jc_all.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://E:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[用比特精灵下载(&B)]
  <, N/A>

==================================
正在运行的进程
[PID: 484][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 548][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 572][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.1557 (xpsp2_gdr.040517-1325)>
[PID: 616][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 628][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 800][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 868][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1000][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1040][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1288][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [e:\Program Files\Super Rabbit\HappyPlayer\Codecs\mmfinfo.dll]  <N/A><N/A>
    [e:\Program Files\Super Rabbit\HappyPlayer\Codecs\mkunicode.dll]  <N/A><N/A>
    [e:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[PID: 1376][E:\Program Files\ASUS\Asus Probe\AsusProb.exe]  <N/A><N/A>
    [C:\WINDOWS\system\VCL35.bpl]  <Borland International><3.0.3.70>
    [C:\WINDOWS\system\cp3240mt.dll]  <Borland International><4.0>
    [C:\WINDOWS\system\borlndmm.dll]  <Borland International><3.0.3.70>
    [e:\Program Files\ASUS\Asus Probe\CODISK.DLL]  <N/A><N/A>
    [E:\Program Files\ASUS\Asus Probe\DiskIco.dll]  <N/A><N/A>
    [e:\Program Files\ASUS\Asus Probe\COLM7578.DLL]  <N/A><N/A>
    [C:\WINDOWS\system\bcbsmp35.bpl]  <><1.0.0.0>
    [C:\WINDOWS\system\vclx35.bpl]  <Borland International><3.0.3.70>
    [e:\Program Files\ASUS\Asus Probe\Asus.dll]  <ASUS><3, 0, 0, 2>
    [E:\Program Files\ASUS\Asus Probe\ASMIAHD.dll]  <ASUS><3, 0, 0, 1>
    [E:\Program Files\ASUS\Asus Probe\AsmiCtrl.dll]  <ASUS><3, 0, 0, 1>
    [E:\Program Files\ASUS\Asus Probe\ASMIDMI.dll]  <ASUS><3, 1, 0, 1>
    [E:\Program Files\ASUS\Asus Probe\AsmiEnum.dll]  <ASUS><3, 0, 0, 1>
    [E:\Program Files\ASUS\Asus Probe\AsmiHwIo.dll]  <ASUS><3, 1, 0, 1>
    [E:\Program Files\ASUS\Asus Probe\Asmi8712.dll]  <N/A><N/A>
    [E:\Program Files\ASUS\Asus Probe\COLMIco.dll]  <N/A><N/A>
    [e:\Program Files\ASUS\Asus Probe\CODMI.DLL]  <N/A><N/A>
[PID: 1396][C:\WINDOWS\System32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 416][E:\Program Files\Rising\Rfw\rfwmain.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 48>
    [E:\Program Files\Rising\Rfw\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 23>
    [E:\Program Files\Rising\Rfw\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [E:\Program Files\Rising\Rfw\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 424][e:\program files\rising\rfw\rfwsrv.exe]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 32>
    [e:\program files\rising\rfw\RfwRule.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 12>
    [e:\program files\rising\rfw\rfwlog.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 6>
    [e:\program files\rising\rfw\Rfwdrv.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 21>
    [e:\program files\rising\rfw\MonDrv.dll]  <rs><1, 0, 0, 4>
    [e:\program files\rising\rfw\ProcLib.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 9>
    [e:\program files\rising\rfw\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
[PID: 260][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [E:\Program Files\珊瑚虫2006Beat1\QQ\QQIEHelper.dll]  <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
    [e:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
[PID: 1924][G:\系统扫描程序\系统扫描程序\sreng2\SREng.exe]  <Smallfrogs Studio><2.0.12.350>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 

日志应该没问题了。
gototop
 

顺便在问问,在C盘发现了dmServer.dll,是什么来的
gototop
 

如果在system32文件夹下,应该是系统文件,具体的到网上搜一下有关资料。
gototop
 

哦,是在那个system32文件里面的。
今天你帮了我个大忙,心里很激动,真的太谢谢你了,我也不会说话,反正一切尽在不言中吧,呵呵
gototop
 
123   3  /  3  页   跳转
页面顶部
Powered by Discuz!NT