12   2  /  2  页   跳转

fuzh/job00病毒作怪,谁有办法?

[C:\PROGRA~1\SkyNet\FireWall\SKYMISC.DLL]  <N/A><N/A>
    [C:\PROGRA~1\SkyNet\FireWall\COMPRESSWRAP.DLL]  <N/A><N/A>
    [C:\WINDOWS\system32\ESPI11.dll]  <DYWT><1, 1, 0, 0>
    [C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\LGMOUSHK.dll]  <Logitech Inc.                    ><9.70.216>
[PID: 316][C:\Program Files\DAEMON Tools\daemon.exe]  <DT Soft Ltd.><4.03.0.0>
    [C:\Program Files\DAEMON Tools\daemon.dll]  <DT Soft Ltd.><4.03.0.0>
    [C:\Program Files\DAEMON Tools\PFCTOC.DLL]  <Padus(R), Inc.><1, 0, 0, 12>
    [C:\Program Files\DAEMON Tools\Plugins\Images\bw5mount.dll]  <N/A><1.0.6.0>
    [C:\Program Files\DAEMON Tools\Plugins\Images\ccdmount.dll]  <GENERIC><1.10.0.0>
    [C:\Program Files\DAEMON Tools\Plugins\Images\mdsmount.dll]  <GENERIC><1.12.0.0>
    [C:\Program Files\DAEMON Tools\Plugins\Images\nrgmount.dll]  <GENERIC><1.11.0.0>
    [C:\Program Files\DAEMON Tools\Plugins\Images\pdimount.dll]  <GENERIC><1.01.0.0>
[PID: 324][C:\WINDOWS\system32\RUNDLL32.EXE]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\NvMcTray.dll]  <NVIDIA Corporation><6.14.10.8412>
    [C:\WINDOWS\system32\NVRSZHC.DLL]  <NVIDIA Corporation><6.14.10.8412>
[PID: 360][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 456][C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE]  <Nokia.><6, 60, 33, 1>
    [C:\WINDOWS\system32\NclTools.dll]  <Nokia.><6, 60, 11, 0>
    [C:\Program Files\Common Files\PCSuite\Transports\NCLIrDAMM.dll]  <Nokia Corp.><6, 60, 17, 0>
    [C:\Program Files\Common Files\PCSuite\Transports\NclMSBTMM.dll]  <Nokia.><6, 60, 26, 1>
    [C:\Program Files\Common Files\PCSuite\Transports\NCLRSMM.dll]  <Nokia><6, 60, 25, 1>
    [C:\Program Files\Common Files\PCSuite\Transports\NCLUSBMM.dll]  <Nokia><6, 60, 26, 0>
[PID: 708][C:\WINDOWS\system32\inetsrv\inetinfo.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\ESPI11.dll]  <DYWT><1, 1, 0, 0>
[PID: 724][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  <Microsoft Corporation><7.00.9466>
[PID: 1140][C:\WINDOWS\system32\nvsvc32.exe]  <NVIDIA Corporation><6.14.10.8412>
[PID: 1316][C:\WINDOWS\System32\snmp.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\ESPI11.dll]  <DYWT><1, 1, 0, 0>
[PID: 1412][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1588][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 2408][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\ESPI11.dll]  <DYWT><1, 1, 0, 0>
[PID: 2780][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3024][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\kakatool.dll]  <Beijing Rising Technology Co., Ltd.><2, 0, 0, 8>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  <Adobe Systems Incorporated><7.0.7.2006011200>
    [D:\DBVR\tencentQQ\QQIEHelper.dll]  <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
    [C:\PROGRA~1\FlashGet\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
    [C:\PROGRA~1\HBClient\tbhelper.dll]  <Shanghai Henbang Technology Co., Ltd><1, 1, 3, 2>
    [C:\WINDOWS\system32\ESPI11.dll]  <DYWT><1, 1, 0, 0>
    [C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\LGMOUSHK.dll]  <Logitech Inc.                    ><9.70.216>
    [C:\WINDOWS\system32\UNISPIM.IME]  <北京清华紫光软件股份有限公司><3.0.0.3045>
    [C:\WINDOWS\system32\upengine.dll]  <北京清华紫光软件股份有限公司><3.0.0.3045>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8a.ocx]  <Macromedia, Inc.><8,0,24,0>
[PID: 3304][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\kakatool.dll]  <Beijing Rising Technology Co., Ltd.><2, 0, 0, 8>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  <Adobe Systems Incorporated><7.0.7.2006011200>
    [D:\DBVR\tencentQQ\QQIEHelper.dll]  <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
    [C:\PROGRA~1\FlashGet\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
    [C:\PROGRA~1\HBClient\tbhelper.dll]  <Shanghai Henbang Technology Co., Ltd><1, 1, 3, 2>
    [C:\WINDOWS\system32\ESPI11.dll]  <DYWT><1, 1, 0, 0>
    [C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\LGMOUSHK.dll]  <Logitech Inc.                    ><9.70.216>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8a.ocx]  <Macromedia, Inc.><8,0,24,0>
    [C:\WINDOWS\system32\UNISPIM.IME]  <北京清华紫光软件股份有限公司><3.0.0.3045>
    [C:\WINDOWS\system32\upengine.dll]  <北京清华紫光软件股份有限公司><3.0.0.3045>
[PID: 2232][C:\WINDOWS\system32\Rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\HBClient\tbhelper.dll]  <Shanghai Henbang Technology Co., Ltd><1, 1, 3, 2>
[PID: 2812][C:\serng\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\LGMOUSHK.dll]  <Logitech Inc.                    ><9.70.216>
    [C:\WINDOWS\system32\ESPI11.dll]  <DYWT><1, 1, 0, 0>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
    C:\WINDOWS\system32\ESPI11.dll(DYWT, ESPI)
MSAFD Tcpip [UDP/IP]
    C:\WINDOWS\system32\ESPI11.dll(DYWT, ESPI)
MSAFD Tcpip [RAW/IP]
    C:\WINDOWS\system32\ESPI11.dll(DYWT, ESPI)
RSVP UDP Service Provider
    C:\WINDOWS\system32\ESPI11.dll(DYWT, ESPI)
RSVP TCP Service Provider
    C:\WINDOWS\system32\ESPI11.dll(DYWT, ESPI)

==================================
gototop
 

到添加删除程序卸载“很棒小秘书”删除C:\PROGRA~1\HBClient
C:\WINDOWS\system32\ESPI11.dll是什么东东,楼主可知道??
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT