瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 不访问网络的程序也访问网络了连画图都访问网络

12   2  /  2  页   跳转

不访问网络的程序也访问网络了连画图都访问网络

[PID: 348][C:\Documents and Settings\Administrator\桌面\QQPetNurse1104(2.17SP5)\QQPetNurse.exe]  [永恒E网, 2.1.7.5]
    [C:\WINDOWS\system32\idmmbc.dll]  [Tonec Inc., 3, 0, 0, 1]
    [C:\windows\winhle.dll]  [N/A, N/A]
    [C:\Program Files\Internet Download Manager\idmmkb.dll]  [Tonec Inc., 3, 0, 0, 1]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\scrchpg.dll]  [Kaspersky Lab, 5.0.1.18]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\scrch_ag.dll]  [Kaspersky Lab, 5.0.388.1]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\FSSync.dll]  [Kaspersky Lab, 5.0.388.0]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\pr_rmt.dll]  [Kaspersky Lab, 5.0.388.0]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\ccclient.dll]  [Kaspersky Lab, 5.0.388.1]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\klipc.dll]  [Kaspersky Lab, 5.0.388.0]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\KLUtil.dll]  [Kaspersky Lab, 5.0.388.1]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\rpt.dll]  [Kaspersky Lab, 5.0.388.2]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\CCIFACE.dll]  [Kaspersky Lab, 5.0.388.1]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\prloader.dll]  [Kaspersky Lab, 5.0.388.0]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\prkernel.ppl]  [Kaspersky Lab, 5.0.388.0]
    [c:\program files\kaspersky lab\kaspersky anti-virus personal\prstring.ppl]  [Kaspersky Lab, 5.0.388.0]
    [c:\program files\kaspersky lab\kaspersky anti-virus personal\pr_srv.ppl]  [Kaspersky Lab, 5.0.388.0]
    [c:\program files\kaspersky lab\kaspersky anti-virus personal\pr_clnt.ppl]  [Kaspersky Lab, 5.0.388.0]
    [c:\program files\kaspersky lab\kaspersky anti-virus personal\tempfile.ppl]  [Kaspersky Lab, 5.0.388.0]
[PID: 792][C:\Program Files\Thunder Network\WebThunder\WebThunder.exe]  [深圳市迅雷网络技术有限公司, 1, 3, 0, 65]
    [C:\Program Files\Thunder Network\WebThunder\taskmanage.dll]  [Thunder Networking Technologies,LTD, 1, 4, 1, 66]
    [C:\Program Files\Thunder Network\WebThunder\download_interface.dll]  [Thunder Networking Technologies,LTD, 2, 0, 0, 3]
    [C:\Program Files\Thunder Network\WebThunder\asyn_dns.dll]  [N/A, N/A]
    [C:\Program Files\Thunder Network\WebThunder\RegisterDll.dll]  [Thunder Networking Technologies,LTD, 2, 2, 1, 34]
    [C:\WINDOWS\system32\idmmbc.dll]  [Tonec Inc., 3, 0, 0, 1]
    [C:\Program Files\Thunder Network\WebThunder\historyinfo_manage.dll]  [Thunder Networking Technologies,LTD, 5, 3, 0, 228]
    [C:\Program Files\Thunder Network\WebThunder\UpdateDownload.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 8]
    [C:\Program Files\Thunder Network\WebThunder\UpdateExec.dll]  [Thunder Networking Technologies,LTD, 1, 0, 1, 5]
    [C:\Program Files\Thunder Network\WebThunder\iEmbedShell.dll]  [ , 1, 0, 0, 12]
    [C:\Program Files\Thunder Network\WebThunder\iEmbed05.dll]  [ , 2, 3, 1, 41]
    [C:\windows\winhle.dll]  [N/A, N/A]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\scrchpg.dll]  [Kaspersky Lab, 5.0.1.18]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\scrch_ag.dll]  [Kaspersky Lab, 5.0.388.1]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\FSSync.dll]  [Kaspersky Lab, 5.0.388.0]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\pr_rmt.dll]  [Kaspersky Lab, 5.0.388.0]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\ccclient.dll]  [Kaspersky Lab, 5.0.388.1]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\klipc.dll]  [Kaspersky Lab, 5.0.388.0]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\KLUtil.dll]  [Kaspersky Lab, 5.0.388.1]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\rpt.dll]  [Kaspersky Lab, 5.0.388.2]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\CCIFACE.dll]  [Kaspersky Lab, 5.0.388.1]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\prloader.dll]  [Kaspersky Lab, 5.0.388.0]
    [C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\prkernel.ppl]  [Kaspersky Lab, 5.0.388.0]
    [c:\program files\kaspersky lab\kaspersky anti-virus personal\prstring.ppl]  [Kaspersky Lab, 5.0.388.0]
    [c:\program files\kaspersky lab\kaspersky anti-virus personal\pr_srv.ppl]  [Kaspersky Lab, 5.0.388.0]
    [c:\program files\kaspersky lab\kaspersky anti-virus personal\pr_clnt.ppl]  [Kaspersky Lab, 5.0.388.0]
    [c:\program files\kaspersky lab\kaspersky anti-virus personal\tempfile.ppl]  [Kaspersky Lab, 5.0.388.0]
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  [Macromedia, Inc., 8,0,0,434]
    [C:\Program Files\Internet Download Manager\idmmkb.dll]  [Tonec Inc., 3, 0, 0, 1]
[PID: 3544][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, N/A]
    [C:\windows\winhle.dll]  [N/A, N/A]
    [C:\Program Files\Internet Download Manager\idmmkb.dll]  [Tonec Inc., 3, 0, 0, 1]
    [C:\WINDOWS\system32\idmmbc.dll]  [Tonec Inc., 3, 0, 0, 1]
[PID: 1628][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.266\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
    [C:\windows\winhle.dll]  [N/A, N/A]
    [C:\Program Files\Internet Download Manager\idmmkb.dll]  [Tonec Inc., 3, 0, 0, 1]
    [C:\WINDOWS\system32\idmmbc.dll]  [Tonec Inc., 3, 0, 0, 1]

==================================
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
IDM_LAYERED_MSAFD Tcpip [TCP/IP]
    C:\WINDOWS\system32\idmmbc.dll(Tonec Inc., Internet Download Manager LSP dll)
IDM_LAYERED_MSAFD Tcpip [UDP/IP]
    C:\WINDOWS\system32\idmmbc.dll(Tonec Inc., Internet Download Manager LSP dll)
IDM_LAYERED_RSVP UDP Service Provider
    C:\WINDOWS\system32\idmmbc.dll(Tonec Inc., Internet Download Manager LSP dll)
IDM_LAYERED_RSVP TCP Service Provider
    C:\WINDOWS\system32\idmmbc.dll(Tonec Inc., Internet Download Manager LSP dll)
IDM_LP
    C:\WINDOWS\system32\idmmbc.dll(Tonec Inc., Internet Download Manager LSP dll)

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
gototop
 

这个程序无敌了 希望版主快快帮助我啊
好像什么杀毒软件都差不出来!~~
gototop
 

请各位都帮我研究下
gototop
 

等待等待
gototop
 

打开 sreng 启动项 注册表 删除{25E1EECB-E580-4032-97A2-A456D33820D1}><C:\WINDOWS\inf\mqq.dll> [N/A]
<{0AB26BF9-B549-48AB-82F9-69F51E767BAA}><C:\windows\winhle.dll> [N/A]
<PHIME2002A><; > [N/A]
<PHIME2002ASync><; > [N/A]
<RealTray><; C:\Program Files\Real\RealPlayer\Realplay.exe SYSTEMBOOTHIDEPLAYER> [N/A]
重启计算机 删除C:\WINDOWS\inf\mqq.dll
C:\windows\winhle.dll
gototop
 

非产感谢您
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT