12   2  /  2  页   跳转

中毒 请求解决 带日志

正在运行的进程
[PID: 600][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 688][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 712][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 756][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 768][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 920][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 984][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1076][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1124][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1184][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1500][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\nvcpl.dll]  <NVIDIA Corporation><6.14.10.9133>
    [C:\WINDOWS\system32\NVRSZHC.DLL]  <NVIDIA Corporation><6.14.10.9133>
    [C:\WINDOWS\system32\nvshell.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\xunleibho_v14.dll]  <Thunder Networking Technologies,LTD><4, 6, 0, 62>
[PID: 1872][C:\WINDOWS\system32\nvsvc32.exe]  <NVIDIA Corporation><6.14.10.9133>
[PID: 1904][C:\Program Files\UPHClean\uphclean.exe]  <Microsoft Corporation><1.5.5.21>
[PID: 304][C:\Program Files\VIA\RAID\raid_tool.exe]  <VIA><2, 0, 1, 0>
    [C:\Program Files\VIA\RAID\drvInterface.dll]  <VIA><2, 0, 0, 0>
[PID: 1644][C:\WINDOWS\system32\wuauclt.exe]  <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
[PID: 1984][E:\kav\avp.exe]  <Kaspersky Lab><6.0.0.299>
    [E:\kav\pr_remote.dll]  <Kaspersky Lab><6.0.0.299>
    [E:\kav\FSSync.dll]  <Kaspersky Lab><6.0.5.0>
    [E:\kav\AVPGS.PPL]  <Kaspersky Lab><6.0.0.299>
    [E:\kav\prloader.dll]  <Kaspersky Lab><6.0.0.299>
    [E:\kav\prkernel.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\pxstub.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\params.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\winreg.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\tm.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\nfio.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\fsdrvplgn.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\bl.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\wmihlpr.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\ndetect.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\crpthlpr.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\schedule.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\timer.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\thpimpl.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\lic60.ppl]  <Kaspersky Lab><6.0.0.300>
    [e:\kav\report.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\hashmd5.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\avs.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\avpmgr.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\wdiskio.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\avlib.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\avspm.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\avp3info.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\avpgui.ppl]  <Kaspersky Lab><6.0.0.300>
    [E:\kav\basegui.dll]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\qb.ppl]  <Kaspersky Lab><6.0.0.299>
    [e:\kav\inflate.ppl]  <Kaspersky Lab><6.0.0.16>
[PID: 568][E:\SREng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 

无邪大哥在吗 看下我的日至啊  是按你的要求操作完了 又扫的
  看下还有问题吗
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT