瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 嘟嘟网的症状,请朋友们帮忙看一看!!

12   2  /  2  页   跳转

嘟嘟网的症状,请朋友们帮忙看一看!!

<IBM><2.101>
    [C:\WINDOWS\system32\AIBMRUNL.dll]  <N/A><N/A>
    [C:\Program Files\IBM\Messages By IBM\AcpPollingEngine.dll]  <><1, 0, 0, 4>
    [C:\WINDOWS\system32\IbmEgath.dll]  <IBM Corporation><3, 0, 0, 18>
[PID: 1516][C:\IBMTOOLS\UTILS\ibmprc.exe]  <IBM Corp.><1, 0, 0, 3>
[PID: 1520][C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe]  <IBM Corporation><1.06>
[PID: 1584][C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE]  <IBM Corp.><3, 7, 1, 0>
    [C:\Program Files\ThinkPad\ConnectUtilities\QCON.dll]  <IBM Corp.><3, 7, 1, 0>
    [C:\Program Files\ThinkPad\ConnectUtilities\MerlinC201.dll]  <Novatel Wireless Inc.><1, 0, 0, 1>
    [C:\Program Files\ThinkPad\ConnectUtilities\QCMurPI.DLL]  <IBM Corp.><3, 7, 1, 0>
    [C:\Program Files\Intel\Wireless\Bin\PfMgrApi.dll]  <Intel Corporation><9, 0, 1, 83>
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  <Intel Corporation><9, 0, 1, 83>
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  <Intel Corporation><9, 0, 1, 83>
    [C:\Program Files\Intel\Wireless\Bin\MurocAPI.dll]  <Intel Corporation><9, 0, 1, 59>
    [C:\Program Files\Intel\Wireless\Bin\S24MUDLL.dll]  <Intel Corporation><9, 0, 1, 83>
    [C:\Program Files\Intel\Wireless\Bin\C1XStngs.dll]  <Intel Corporation><9, 0, 1, 83>
    [C:\Program Files\Intel\Wireless\Bin\C8021CHS.dll]  <Intel Corporation><9, 0, 1, 83>
    [C:\Program Files\Intel\Wireless\Bin\LSAWRAPI.dll]  <Intel Corporation><9, 0, 1, 83>
    [C:\Program Files\ThinkPad\ConnectUtilities\Res\SC\IconRes.dll]  <N/A><N/A>
[PID: 1624][C:\WINDOWS\system32\rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL]  <IBM Corp.><1, 0, 0, 0>
    [C:\PROGRA~1\ThinkPad\UTILIT~1\US\PWRMGRRT.DLL]  <N/A><N/A>
    [C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRIF.DLL]  <N/A><N/A>
    [C:\WINDOWS\system32\Sensor.dll]  <IBM Corporation><1.30.1.0>
    [C:\WINDOWS\system32\OEMDSPIF.DLL]  <Intel Corporation><3.0.0.3984>
    [C:\WINDOWS\system32\igfxdev.dll]  <Intel Corporation><3.0.0.3984>
[PID: 1856][C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe]  <IBM Corp.><3, 7, 1, 0>
    [C:\PROGRA~1\ThinkPad\CONNEC~1\QCON.dll]  <IBM Corp.><3, 7, 1, 0>
    [C:\PROGRA~1\ThinkPad\CONNEC~1\MerlinC201.dll]  <Novatel Wireless Inc.><1, 0, 0, 1>
    [C:\PROGRA~1\ThinkPad\CONNEC~1\Res\SC\TrayRes.dll]  <N/A><N/A>
    [C:\PROGRA~1\ThinkPad\CONNEC~1\QCMurPI.DLL]  <IBM Corp.><3, 7, 1, 0>
    [C:\Program Files\Intel\Wireless\Bin\PfMgrApi.dll]  <Intel Corporation><9, 0, 1, 83>
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  <Intel Corporation><9, 0, 1, 83>
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  <Intel Corporation><9, 0, 1, 83>
    [C:\Program Files\Intel\Wireless\Bin\MurocAPI.dll]  <Intel Corporation><9, 0, 1, 59>
    [C:\Program Files\Intel\Wireless\Bin\S24MUDLL.dll]  <Intel Corporation><9, 0, 1, 83>
    [C:\Program Files\Intel\Wireless\Bin\C1XStngs.dll]  <Intel Corporation><9, 0, 1, 83>
    [C:\Program Files\Intel\Wireless\Bin\C8021CHS.dll]  <Intel Corporation><9, 0, 1, 83>
    [C:\Program Files\Intel\Wireless\Bin\LSAWRAPI.dll]  <Intel Corporation><9, 0, 1, 83>
    [C:\Program Files\Intel\Wireless\Bin\D8021Xps.DLL]  <N/A><N/A>
    [C:\PROGRA~1\ThinkPad\CONNEC~1\ANCA.dll]  <IBM Corp.><8.3>
    [C:\PROGRA~1\ThinkPad\CONNEC~1\ANC.dll]  <IBM Corp.><8.3>
[PID: 1652][C:\Program Files\Winamp\winampa.exe]  <N/A><N/A>
    [C:\Program Files\Winamp\NSCRT.dll]  <Nullsoft, Inc.><7.10.0000>
[PID: 1924][C:\PROGRA~1\KuGoo3\KuGoo.exe]  <><3.2.0.83>
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\scrauth.dll]  <Symantec Corporation><11.0.9.16>
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll]  <Symantec Corporation><11.0.9.16>
    [C:\Program Files\Common Files\Symantec Shared\ccL30.dll]  <Symantec Corporation><103.0.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  <Symantec Corporation><103.0.4.3>
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
[PID: 1936][C:\Program Files\Google\Gmail Notifier\gnotify.exe]  <Google Inc.><1.0.25.0>
[PID: 1960][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1992][C:\WINDOWS\system32\DrvMon.exe]  <Alcor Micro, Corp.><1, 0, 0, 9>
[PID: 2020][C:\Program Files\Digital Line Detect\DLG.exe]  <BVRP Software><1, 0, 0, 1>
    [C:\Program Files\Digital Line Detect\BVRPDIAG.dll]  <BVRP Software><1.0>
    [C:\WINDOWS\system32\MdmXSdk.dll]  <Conexant><1.0.2.006>
[PID: 2052][C:\Program Files\IBM\Bluetooth Software\BTTray.exe]  <Broadcom Corporation><3.0.1.915>
    [C:\WINDOWS\system32\wbtapi.dll]  <Broadcom Corporation><3.0.1.915>
    [C:\WINDOWS\system32\btosif.dll]  <Broadcom Corporation><3.0.1.915>
    [C:\Program Files\IBM\Bluetooth Software\BtBalloon.dll]  <Broadcom Corporation><3.0.1.915>
    [C:\WINDOWS\system32\btrez.dll]  <Broadcom Corporation><3.0.1.915>
    [C:\WINDOWS\system32\CSH.dll]  <Blue Sky Software Corporation><2.00.039>
    [C:\Program Files\IBM\Bluetooth Software\btkeyind.dll]  <N/A><N/A>
[PID: 2060][C:\Program Files\zepsoft\Wallpaper Calendar\WallCal3.exe]  <Zepsoft><3.0.2.85>
    [C:\Program Files\zepsoft\Wallpaper Calendar\MHookWC.dll]  <Zepsoft><1.0.3.3>
[PID: 2676][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2708][C:\WINDOWS\System32\TPHDEXLG.EXE]  <IBM Corporation><1.0.0.1>
[PID: 2732][C:\WINDOWS\system32\TpKmpSVC.exe]  <N/A><N/A>
[PID: 2752][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 4024][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3072][C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe]  <Intel><9, 0, 1, 83>
    [C:\PROGRA~1\Intel\Wireless\Bin\IntelAE5.dll]  <Meetinghouse Data Communications><3, 0, 0, 44>
    [C:\PROGRA~1\Intel\Wireless\Bin\TraceAPI.DLL]  <Intel Corporation><9, 0, 1, 83>
    [C:\PROGRA~1\Intel\Wireless\Bin\PsRegApi.dll]  <Intel Corporation><9, 0, 1, 83>
    [C:\Program Files\Intel\Wireless\Bin\D8021Xps.DLL]  <N/A><N/A>
[PID: 3848][C:\Program Files\MSN Messenger\msnmsgr.exe]  <Microsoft Corporation><8.0.0812.00>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\scrauth.dll]  <Symantec Corporation><11.0.9.16>
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll]  <Symantec Corporation><11.0.9.16>
    [C:\Program Files\Common Files\Symantec Shared\ccL30.dll]  <Symantec Corporation><103.0.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  <Symantec Corporation><103.0.4.3>
    [C:\Program Files\IBM\Bluetooth Software\btkeyind.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\UNISPIM.IME]  <北京清华紫光软件股份有限公司><3.0.0.3045>
    [C:\WINDOWS\system32\upengine.dll]  <北京清华紫光软件股份有限公司><3.0.0.3045>
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
[PID: 1696][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2012][C:\Program Files\eMule\emule.exe]
gototop
 

<http://www.emule.org.cn><0.47.0>
    [C:\Program Files\eMule\VNNClientS.Dll]  <VNN><3.0.22.1>
    [C:\Program Files\eMule\ZipLib.dll]  <VNN><1.0.0.1>
    [C:\Program Files\eMule\vdevstate.dll]  <N/A><N/A>
    [C:\Program Files\eMule\lang\zh_CN.dll]  <http://www.emule-project.net><0.47.0>
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\scrauth.dll]  <Symantec Corporation><11.0.9.16>
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll]  <Symantec Corporation><11.0.9.16>
    [C:\Program Files\Common Files\Symantec Shared\ccL30.dll]  <Symantec Corporation><103.0.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  <Symantec Corporation><103.0.4.3>
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
    [C:\Program Files\IBM\Bluetooth Software\btkeyind.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\UNISPIM.IME]  <北京清华紫光软件股份有限公司><3.0.0.3045>
[PID: 348][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2504][C:\Program Files\Ringz Studio\Storm Codec\mplayerc.exe]  <Gabest><6, 4, 9, 0>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\tssoft32.acm]  <DSP GROUP, INC.><1.01>
    [C:\WINDOWS\system32\tsd32.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\sl_anet.acm]  <Sipro Lab Telecom Inc.><3.02>
    [C:\WINDOWS\system32\iac25_32.ax]  <Intel Corporation><2.05.53>
    [C:\WINDOWS\system32\l3codeca.acm]  <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
    [C:\WINDOWS\system32\vorbis.acm]  <HMS http://hp.vector.co.jp/authors/VA012897/><0, 0, 3, 6>
    [C:\WINDOWS\system32\vct3216.acm]  <Voxware, Inc.><1.6.0.17>
    [C:\WINDOWS\system32\vct3216.dll]  <Voxware, Inc.><1.6.0.12>
    [C:\WINDOWS\system32\msms001.vwp]  <Voxware, Inc.><2.0.2.61>
    [C:\WINDOWS\system32\mvoice.vwp]  <Voxware, Inc.><2.0.0.12.01>
    [C:\WINDOWS\system32\ffdshow.ax]  <N/A><1.0.2.2028>
    [C:\Program Files\Ringz Studio\Storm Codec\Codecs\VSFilter.dll]  <Gabest><1, 0, 1, 3>
    [C:\Program Files\Ringz Studio\Storm Codec\Codecs\TTL2Dec.dll]  <N/A><N/A>
    [C:\Program Files\IBM\Bluetooth Software\btkeyind.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\xvid.ax]  <N/A><N/A>
    [C:\WINDOWS\system32\xvidcore.dll]  <N/A><N/A>
    [C:\Program Files\KuGoo3\kgmpg.dll]  < ><1, 0, 4, 1>
[PID: 2440][D:\常用软件\BALL.EXE]  <m53group><1.2>
    [C:\Program Files\IBM\Bluetooth Software\btkeyind.dll]  <N/A><N/A>
[PID: 3408][C:\Program Files\Maxthon\maxthon.exe]  <Maxthon International Ltd.><1, 5, 6, 42>
    [C:\Program Files\Maxthon\maxzlib.dll]  < ><1, 0, 0, 2>
    [C:\Program Files\Maxthon\Services\RealTime\real_time.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\scrauth.dll]  <Symantec Corporation><11.0.9.16>
    [C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll]  <Symantec Corporation><11.0.9.16>
    [C:\Program Files\Common Files\Symantec Shared\ccL30.dll]  <Symantec Corporation><103.0.4.3>
    [C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll]  <Symantec Corporation><103.0.4.3>
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
    [C:\Program Files\IBM\Bluetooth Software\btkeyind.dll]  <N/A><N/A>
[PID: 224][C:\Program Files\Messenger\msmsgs.exe]  <Microsoft Corporation><4.7.3001>
[PID: 3944][C:\Documents and Settings\Libby Han\桌面\sreng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 

贴完了,请无邪哥看一看!
gototop
 

还有流氓软件
请到www.27814939.ys168.com,点“我的软件”下载KillBox.exe
重新启动电脑, 开机检测完后, 按[F8]键(可以一直按到启动菜单出来为止), 选择安全模式进入Windows

用兔子在安全模式卸载其它的流氓软件。

双击打开KillBox.exe,分别删除
C:\WINDOWS\webwork\webwork.dll
C:\WINDOWS\system32\themeadp.dll
C:\WINDOWS\fonts\msshapi.dll
C:\WINDOWS\system32\bsnviewer.dll
C:\WINDOWS\webwork\webwork.nls
C:\DOCUME~1\LIBBYH~1\LOCALS~1\Temp\themeadp.nls
(删除时勾选“删除前先结束Explorer.EXE进程”不行再试着勾选"删除DLL文件前反注册此文件
打开System Repair Engineer(也就是你的扫描日志软件SREng.exe),使用“系统修复,浏览器加载项”来删除以下选项。
C:\WINDOWS\fonts\msshapi.dll
C:\WINDOWS\system32\bsnviewer.dll
打开System Repair Engineer(也就是你的扫描日志软件SREng.exe),使用“启动项目,注册表”来删除以下选项。
C:\WINDOWS\webwork\webwork.dll
C:\WINDOWS\system32\themeadp.dll
完后重启
再扫个日志粘上来。
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT