瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】请各位高手帮忙看一下!谢谢了!!!急!!!

12   2  /  2  页   跳转

【求助】请各位高手帮忙看一下!谢谢了!!!急!!!

[F:\qq\TIMProxy.dll]  <tencent><0, 3, 2, 4>
[PID: 1524][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1660][C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE]  <Network Associates, Inc.><8.0.0.912>
    [C:\Program Files\Network Associates\VirusScan\SHUTIL.dll]  <Network Associates, Inc.><8.0.0.912>
    [C:\Program Files\Network Associates\VirusScan\naiwmain.dll]  <Network Associates, Inc.><8.0.0.912>
    [C:\Program Files\Network Associates\VirusScan\RES04\shstat.dll]  <Network Associates, Inc.><8.0.0.912>
    [C:\Program Files\Network Associates\VirusScan\RES04\Product.dll]  <Network Associates, Inc.><8.0.0.912>
    [C:\Program Files\Network Associates\VirusScan\RES04\McShield.dll]  <Network Associates, Inc.><8.0.0.251>
    [C:\Program Files\Network Associates\VirusScan\RES04\Shutilrc.dll]  <Network Associates, Inc.><8.0.0.912>
    [C:\Program Files\Network Associates\VirusScan\Graphics.dll]  <Network Associates, Inc.><8.0.0.912>
[PID: 1700][C:\WINDOWS\VM303_STI.EXE]  <Vimicro><4, 2, 429, 7>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\VM303Prp.Ax]  <Vimicro><4.2. 0507.45>
[PID: 1732][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3208>
[PID: 1740][C:\WINDOWS\bittorrent.exe]  <N/A><N/A>
[PID: 1828][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1956][C:\Program Files\Network Associates\Common Framework\FrameworkService.exe]  <Network Associates, Inc.><3.5.0.412>
    [C:\Program Files\Network Associates\Common Framework\nailog.dll]  <Network Associates, Inc.><3.5.0.474>
    [C:\Program Files\Network Associates\Common Framework\naXML.dll]  <Network Associates, Inc.><3.5.0.474>
    [C:\Program Files\Network Associates\Common Framework\naCmnLib.dll]  <Network Associates, Inc.><3.5.0.474>
    [C:\Program Files\Network Associates\Common Framework\applib.dll]  <Network Associates, Inc.><3.5.0.412>
    [C:\Program Files\Network Associates\Common Framework\0804\AgentRes.dll]  <Network Associates, Inc.><3.5.0.412>
    [C:\Program Files\Network Associates\Common Framework\Logging.dll]  <Network Associates, Inc.><3.5.0.412>
    [C:\Program Files\Network Associates\Common Framework\InternetManager.dll]  <Network Associates, Inc.><3.5.0.412>
    [C:\Program Files\Network Associates\Common Framework\naInet.dll]  <Network Associates, Inc.><3.5.0.474>
    [C:\Program Files\Network Associates\Common Framework\UserSpace.dll]  <Network Associates, Inc.><3.5.0.412>
    [C:\Program Files\Network Associates\Common Framework\SecureFrameworkFactory.dll]  <Network Associates, Inc.><3.5.0.412>
    [C:\Program Files\Network Associates\Common Framework\Management.dll]  <Network Associates, Inc.><3.5.0.412>
    [C:\Program Files\Network Associates\Common Framework\cmalib.dll]  <Network Associates, Inc.><3.5.0.412>
    [C:\Program Files\Network Associates\Common Framework\naPolicyManager.dll]  <Network Associates, Inc.><3.5.0.412>
    [C:\Program Files\Network Associates\Common Framework\ScriptSubSys.dll]  <Network Associates, Inc.><3.5.0.412>
    [C:\Program Files\Network Associates\Common Framework\UpdateSubSys.dll]  <Network Associates, Inc.><3.5.0.412>
    [C:\Program Files\Network Associates\Common Framework\Scheduler.dll]  <Network Associates, Inc.><3.5.0.412>
    [C:\Program Files\Network Associates\Common Framework\TCSubSys.dll]  <Network Associates, Inc.><3.5.0.412>
    [C:\WINDOWS\system32\EntApi.dll]  <Network Associates, Inc><8.0.0.277>
[PID: 1980][C:\Program Files\Network Associates\VirusScan\Mcshield.exe]  <Network Associates, Inc.><8.0.0.251>
    [C:\Program Files\Network Associates\VirusScan\Res04\McShield.DLL]  <Network Associates, Inc.><8.0.0.251>
    [C:\Program Files\Network Associates\VirusScan\FTL.Dll]  <Network Associates, Inc.><8.0.0.135>
    [C:\Program Files\Network Associates\VirusScan\naiann.dll]  <Network Associates, Inc.><8.0.0.251>
    [C:\Program Files\Network Associates\VirusScan\mytilus.dll]  <Network Associates, Inc.><8.0.0.251>
    [C:\Program Files\Network Associates\Common Framework\GenEvtInf.dll]  <Network Associates, Inc.><3.5.0.412>
    [C:\Program Files\Network Associates\VirusScan\NaEventU.DLL]  <Network Associates, Inc.><8.0.0.342>
    [C:\Program Files\Network Associates\VirusScan\Res04\naEvtRes.dll]  <Network Associates, Inc.><8.0.0.342>
    [C:\Program Files\Network Associates\VirusScan\VSIDSvr.dll]  <Network Associates, Inc.><8.0.0.251>
    [C:\Program Files\Common Files\Network Associates\Engine\MCSCAN32.DLL]  <McAfee, Inc.><4.4.00>
    [C:\Program Files\Network Associates\Common Framework\SecureFrameworkFactory.dll]  <Network Associates, Inc.><3.5.0.412>
    [C:\Program Files\Network Associates\VirusScan\EntSrv.Dll]  <Network Associates, Inc><8.0.0.277>
[PID: 2008][C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe]  <Network Associates, Inc.><3.5.0.412>
    [C:\PROGRA~1\NETWOR~1\COMMON~1\nailog.dll]  <Network Associates, Inc.><3.5.0.474>
    [C:\PROGRA~1\NETWOR~1\COMMON~1\naCmnLib.dll]  <Network Associates, Inc.><3.5.0.474>
    [C:\PROGRA~1\NETWOR~1\COMMON~1\naXML.dll]  <Network Associates, Inc.><3.5.0.474>
    [C:\PROGRA~1\NETWOR~1\COMMON~1\0804\AgentRes.dll]  <Network Associates, Inc.><3.5.0.412>
    [C:\WINDOWS\system32\EntApi.dll]  <Network Associates, Inc><8.0.0.277>
[PID: 168][C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe]  <Network Associates, Inc.><8.0.0.912>
    [C:\Program Files\Network Associates\VirusScan\SHUTIL.dll]  <Network Associates, Inc.><8.0.0.912>
    [C:\Program Files\Network Associates\VirusScan\naiwmain.dll]  <Network Associates, Inc.><8.0.0.912>
    [C:\Program Files\Network Associates\VirusScan\naicondl.dll]  <Network Associates, Inc.><8.0.0.912>
    [C:\Program Files\Network Associates\VirusScan\RES04\VsTskMgr.dll]  <Network Associates, Inc.><8.0.0.912>
    [C:\Program Files\Network Associates\VirusScan\MIDUtil.Dll]  <McAfee, Inc.><8.0.0.152>
[PID: 304][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\EntApi.dll]  <Network Associates, Inc><8.0.0.277>
[PID: 528][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 352][C:\WINDOWS\SYSTEM32\RUNDLL.EXE]  <Microsoft Corporation><5.00.2134.1>
[PID: 1212][C:\WINDOWS\system32\rundll32.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\sdmAgent22.dll]  <LINKMEDIA Tech><1, 5, 0, 7>
[PID: 2216][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2948][C:\WINDOWS\system32\wuauclt.exe]  <Microsoft Corporation><5.4.3790.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\EntApi.dll]  <Network Associates, Inc><8.0.0.277>
gototop
 

[PID: 1988][F:\qq\QQ.exe]  <TENCENT><0, 0, 0, 0>
    [F:\qq\QQBaseClassInDll.dll]  <><1, 0, 0, 1>
    [F:\qq\QQHelperDll.dll]  <><1, 0, 0, 1>
    [F:\qq\BasicCtrlDll.dll]  <Tencent><5, 0, 200, 370>
    [F:\qq\QQAPI.dll]  <><1, 0, 0, 1>
    [F:\qq\TIMProxy.dll]  <tencent><0, 3, 2, 4>
    [F:\qq\LoginCtrl.dll]  <><1, 0, 0, 1>
    [F:\qq\npkcntc.dll]  <INCA Internet Co., Ltd.><2006, 6, 27, 1>
    [F:\qq\npkpdb.dll]  <INCA Internet Co., Ltd.><2003, 10, 1, 1>
    [F:\qq\QQRes.dll]  <tencent><1, 0, 0, 1>
    [F:\qq\WizardCtrl.dll]  <><1, 0, 0, 1>
    [F:\qq\QQMainFrame.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\macromed\flash\Flash.ocx]  <Macromedia, Inc.><7,0,19,0>
    [F:\qq\CQQApplication.dll]  <N/A><N/A>
    [F:\qq\NewSkin.dll]  <><1, 0, 0, 1>
    [F:\qq\HostingMgr.dll]  <><1, 0, 0, 1>
    [F:\qq\CameraDll.dll]  <><1, 0, 0, 1>
    [F:\qq\MailSummary.dll]  <><1, 0, 0, 1>
    [F:\qq\QQSpace.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [F:\qq\QQGroupMng.dll]  <><1, 0, 0, 1>
    [F:\qq\GroupLive.dll]  <N/A><N/A>
    [F:\qq\QRingMng.dll]  <N/A><N/A>
    [F:\qq\UserDefinedHead.dll]  <><1, 0, 0, 1>
    [F:\qq\QQPlugin.dll]  <N/A><N/A>
    [F:\qq\QQConfigPlugin.dll]  <><1, 0, 0, 1>
    [F:\qq\FlashAvatarDll.dll]  <><1, 4, 0, 1>
    [F:\qq\QQAvatar.dll]  <N/A><N/A>
    [F:\qq\LongConnection.dll]  <tencent><5, 0, 200, 160>
    [F:\qq\PhoneAPI.dll]  <><1, 0, 0, 1>
    [F:\qq\DialerAllinOne.dll]  <tencent><1, 4, 0, 0>
    [F:\qq\VPortal.dll]  <><1, 0, 0, 4>
    [F:\qq\QQNetDisk.dll]  <深圳腾讯科技><8, 0, 101, 14>
    [F:\qq\QQFileTransfer.dll]  <Tencent><0, 3, 3, 5>
    [F:\qq\QQPet.dll]  <><1, 0, 0, 1>
    [F:\qq\BQQApplication.dll]  <N/A><N/A>
    [F:\qq\QQSettingCtrl.dll]  <><1, 0, 0, 1>
    [F:\qq\QQSysMsgMng.dll]  <N/A><N/A>
    [F:\qq\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
    [F:\qq\CommercesMng.dll]  <><1, 0, 0, 1>
    [F:\qq\QQAddr.dll]  <深圳市腾讯计算机系统有限公司><5, 0, 101, 240>
    [F:\qq\QQSceneMng.dll]  <N/A><N/A>
    [F:\qq\QQPhoneHelper.dll]  <腾讯科技(深圳)有限公司><2, 0, 6, 60>
    [F:\qq\QQAllInOne.dll]  <N/A><N/A>
    [F:\qq\SCCore.dll]  <TENCENT><2, 0, 0, 1>
    [F:\qq\videodevice.dll]  <Tencent><1, 6, 0, 0>
    [F:\qq\inplus.dll]  <Tencent><1, 6, 0, 0>
    [C:\WINDOWS\system32\l3codeca.acm]  <Fraunhofer Institut Integrierte Schaltungen IIS><1, 9, 0, 0305>
    [F:\qq\QQTProxy.dll]  <><1, 0, 0, 1>
    [F:\qq\zlib1.dll]  <N/A><1.2.1>
[PID: 2352][F:\qq\TIMPlatform.exe]  <tencent><0, 3, 1, 8>
    [F:\qq\TIMProxy.dll]  <tencent><0, 3, 2, 4>
[PID: 3956][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\EntApi.dll]  <Network Associates, Inc><8.0.0.277>
    [C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5001.dll]  <Microsoft Corporation><1, 3, 5, 0>
    [F:\qq\QQIEHelper.dll]  <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll]  <Thunder Networking Technologies,LTD><5, 0, 0, 2>
    [D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX]  <N/A><N/A>
    [C:\WINDOWS\system32\macromed\flash\Flash.ocx]  <Macromedia, Inc.><7,0,19,0>
[PID: 3024][C:\Documents and Settings\Administrator\桌面\新建文件夹 (2)\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
gototop
 

运行(双击)SRENG2,点“启动项目,服务,点“Win32服务应用程序”
勾选“隐藏微软服务”选中病毒服务Microsoft Update Service ,选择“删除服务”
点“设置”选择“否”

运行SREng2,使用“启动项目”--注册表--选中以下的项删除
C:\WINDOWS\system32\IntelFile.exe

运行SREng2,使用:系统修复--浏览器加载项--查找以下的项--删除所选内容
C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5001.dll

显示隐藏文件删除
C:\WINDOWS\SYSTEM32\WBEM\SMTPCONFS.DLL
C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5001.dll
C:\WINDOWS\system32\IntelFile.exe
gototop
 

楼主修复后,重启。
删除原扫描软件
请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改。
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT