瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 斑竹,又要请教您一个问题了,很重要的

123   3  /  3  页   跳转

斑竹,又要请教您一个问题了,很重要的

==================================
正在运行的进程
[PID: 596][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 656][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 688][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\Ati2evxx.dll]  <ATI Technologies Inc.><6.14.10.4119>
[PID: 732][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 744][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 900][C:\WINDOWS\system32\Ati2evxx.exe]  <ATI Technologies Inc.><6.14.10.4119>
    [C:\WINDOWS\system32\Ati2edxx.dll]  <ATI Technologies, Inc.><6, 14, 10, 2497>
[PID: 912][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1012][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1100][C:\Program Files\Rising\Rav\CCenter.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1136][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1216][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1288][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1536][C:\WINDOWS\system32\Ati2evxx.exe]  <ATI Technologies Inc.><6.14.10.4119>
    [C:\WINDOWS\system32\Ati2edxx.dll]  <ATI Technologies, Inc.><6, 14, 10, 2497>
[PID: 1636][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\新建文件夹\ComDlls\XunLeiBHO_002.dll]  <Thunder Networking Technologies,LTD><5, 0, 0, 2>
    [C:\PROGRA~1\FLASHGET\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
    [C:\Program Files\Infofo Bar\infofobar.dll]  <珊瑚虫工作室 泰格工作室><1, 0, 0, 0>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\WINDOWS\system32\RadExe.dll]  <><2, 1, 2033, 0>
[PID: 1696][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\adimon.dll]  <Autodesk, Inc.><3,0,14,176>
    [C:\WINDOWS\system32\heidi3.dll]  <Autodesk, Inc.><3,0,14,176>
[PID: 164][D:\TAXERC~1\广东省~1\FireBird\bin\fbguard.exe]  <The Firebird Project><WI-V1.5.1.4481>
    [D:\TAXERC~1\广东省~1\FireBird\bin\fbclient.dll]  <The Firebird Project><WI-V1.5.1.4481>
[PID: 152][D:\TAXERC~1\广东省~1\FireBird\bin\fbserver.exe]  <The Firebird Project><WI-V1.5.1.4481>
[PID: 272][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1396][C:\WINDOWS\system32\wbem\wmiprvse.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1404][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 564][C:\WINDOWS\system32\msiexec.exe]  <Microsoft Corporation><3.0.3790.2180>
[PID: 156][C:\WINDOWS\system32\wuauclt.exe]  <Microsoft Corporation><5.4.3790.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 736][C:\新建文件夹\Program\Thunder5.exe]  <Thunder Networking Technologies,LTD><5.2.0.207>
    [C:\新建文件夹\Program\UpdateDownload.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 8>
    [C:\新建文件夹\Program\download_interface.dll]  <Thunder Networking Technologies,LTD><1, 0, 3, 70>
    [C:\新建文件夹\Program\log4cplus.dll]  <><1, 0, 2, 1>
    [C:\新建文件夹\Program\stlport_vc646.dll]  <STLport Consulting, Inc.><4.6.2003.1031>
    [C:\新建文件夹\Program\asyn_dns.dll]  <N/A><N/A>
    [C:\新建文件夹\Program\msgmanage.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 15>
    [C:\新建文件夹\Program\historyinfo_manage.dll]  <Thunder Networking Technologies,LTD><5, 2, 0, 148>
    [C:\新建文件夹\Program\RegisterDll.dll]  <Thunder Networking Technologies,LTD><1, 2, 0, 7>
    [C:\新建文件夹\Program\FloatBar.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 2>
    [C:\新建文件夹\Components\InMedia\iEmbedShell.dll]  < ><1, 0, 0, 10>
    [C:\新建文件夹\Components\InMedia\iEmbed03.dll]  < ><2, 2, 1, 33>
    [C:\新建文件夹\Components\P4PClient\P4PClient.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 6>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [C:\WINDOWS\system32\RadExe.dll]  <><2, 1, 2033, 0>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\新建文件夹\Program\iTargetAd.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 60>
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
[PID: 2276][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3888][C:\Program Files\Maxthon\Maxthon.exe]  <MY Soft Technology><1, 1, 0, 90>
    [C:\Program Files\Maxthon\zlib.dll]  <N/A><N/A>
    [C:\新建文件夹\ComDlls\XunLeiBHO_002.dll]  <Thunder Networking Technologies,LTD><5, 0, 0, 2>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Maxthon\Services\RealTime\real_time.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
[PID: 2072][C:\Program Files\WinRAR\WinRAR.exe]  <N/A><N/A>
[PID: 2272][D:\Temp\Rar$EX00.445\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

斑竹啊,帮帮忙拉
gototop
 

其实他们都说的很清楚了.
按着做就行了.
首先删除灰鸽子的病毒,然后卸载瑞星杀毒软件.
再重装.
你试试再说.
gototop
 

请问楼主,你这样做了吗??
C:\WINDOWS\system32\RadExe.dll
请到www.27814939.ys168.com,点“我的软件”下载KillBox.exe
重新启动电脑, 开机检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式进入Windows
双击打开KillBox.exe,删除
C:\WINDOWS\system32\RadExe.dll
(删除时勾选“删除前先结束Explorer.EXE进程”
运行(双击)System Repair Engineer,使用“启动项目,注册表”来删除以下选项。
C:\WINDOWS\system32\RadExe.dll
完成回到正常模式,请再扫份日志粘上来。
注意,它和瑞星C:\WINDOWS\system32\RavExt.dll很像,你要删除 的是C:\WINDOWS\system32\RadExe.dll
修复后,重启回到正常模式,请再扫份日志粘上来。
gototop
 
123   3  /  3  页   跳转
页面顶部
Powered by Discuz!NT